wolfSSL now supports hardware-accelerated crypto on the Silicon Labs EFR32 Series 2 Secure Element using wolfCrypt crypto callbacks. Simply define WOLFSSL_SILABS_CRYPTOCB. wolfCrypt automatically registers the Secure Element at startup and routes supported operations to hardware, including: Symmetric Ciphers: AES (ECB, CBC, CTR, GCM, CCM), ChaCha20-Poly1305 MAC & KDF: AES-CMAC, HKDF, PBKDF2 Hashing: SHA-2 Asymmetric: ECDSA, […]
Read MoreMore TagCategory: Uncategorized
Post-Quantum Secure Boot on the NXP i.MX95 Cortex-M7
We ported wolfBoot to the Cortex-M7 on NXP’s i.MX95, running on a Toradex SMARC iMX95 module, and measured ML-DSA-87 verified boot with the core at 800 MHz. Verification and boot completed in 5.25 ms, and the ML-DSA-87 build of wolfBoot came out 940 bytes smaller than the ECDSA P-256 build of the same target. Algorithm […]
Read MoreMore TagAnnouncing wolfTPM v4.2.0
wolfTPM 4.2.0 centers on TCG TPM 2.0 v1.85 specification compliance in the firmware TPM (fwTPM), expanded post-quantum support up to TLS 1.3 authentication, and new platform backends. The result is a portable, hardware-backed root of trust that is standards-compliant and quantum-ready on hardware ranging from microcontrollers to Linux edge devices. TPM 2.0 v1.85 Specification Compliance […]
Read MoreMore TagPost-Quantum Benchmarks on the NXP i.MX95 and Toradex SMARC
We benchmarked wolfSSL’s post-quantum algorithms against OpenSSL on a Toradex SMARC iMX95 Hexa 8GB module running Torizon OS 7.7.0. Both stacks ran on the same silicon, one Cortex-A55 core, governor pinned at 1800 MHz, one second per measurement. Torizon ships OpenSSL 3.5.7, which has native ML-KEM and ML-DSA, so this compares two builds you can […]
Read MoreMore TagwolfBoot Adds Secure Boot Support for Altera Agilex 5
wolfSSL is adding a native wolfBoot port for the Altera Agilex 5 SoC FPGA. The port integrates with the existing Agilex 5 platform boot flow and verifies signed Linux FIT images before they are launched. This gives Agilex 5 platforms a portable wolfSSL secure boot layer without replacing the vendor’s platform initialization or security services. […]
Read MoreMore TagTLS 1.3 in 30.8 KB: wolfSSL vs MbedTLS
wolfSSL’s new tinytls13 profile against a parity-matched MbedTLS, measured on Cortex-M33, x86_64, and aarch64. wolfSSL and MbedTLS both target small embedded TLS, but configured and built with parity options they are not the same size. The new tinytls13 profile is a TLS 1.3-only build that strips everything which is not TLS 1.3 and defaults to […]
Read MoreMore TagwolfBOOT and wolfHSM Yocto Recipes
The wolfBoot recipes in the meta-wolfssl (https://github.com/wolfSSL/meta-wolfssl) Yocto layer can now build wolfCrypt from a wolfSSL source tree you supply. Set `WOLFBOOT_WOLFSSL_SRC = “/path/to/wolfssl”` in `local.conf` and that tree is used in place of the copy the recipe would otherwise fetch into `lib/wolfssl`. The wolfSSL entry drops out of `SRC_URI` entirely, so nothing is downloaded. […]
Read MoreMore TagMongoDB FIPS 140-3 Support with wolfProvider
MongoDB is a document-oriented database platform used to store, manage, and query application data. wolfSSL is currently lab validating MongoDB with wolfProvider to verify operation with wolfCrypt FIPS. Once validation is complete, MongoDB can use FIPS 140-3 validated cryptography through wolfProvider with no code changes to MongoDB and potentially no code changes to applications using […]
Read MoreMore TagLive Webinar – wolfBoot: Achieving CRA Compliance with Secureboot and firmware updates (EU-Friendly Time)
CRA compliance does not end when a product ships. Engineers must maintain firmware integrity, deliver secure updates, manage vulnerabilities, and document the software included in every build. Join us on September 16 at 15:00 CEST (6:00 AM PT) to learn how these CRA obligations translate into firmware design and maintenance decisions. Follow the implementation path […]
Read MoreMore TagIntroducing wolfTrust
wolfTrust is a trusted firmware platform for Arm Cortex-M, now under development at wolfSSL, that brings the full wolfSSL security stack into a single secure runtime. It implements the Arm Firmware Framework for M (FF-M) with source-compatible PSA client interfaces, so applications written for Trusted Firmware-M (TF-M) keep their psa_* calls and simply swap the […]
Read MoreMore Tag
