Post-Quantum Cryptography Is Coming to the wolfSSL Ada Wrapper

Ada is the language of systems that stay in service for decades — avionics, rail signalling, spacecraft, defense platforms. That lifetime is the problem. This makes you susceptible to “Trust now, Forge Later” type attacks if you aren’t building in agility into your software maintenance practices.

The wolfSSL Ada/SPARK binding, available in the main wolfSSL repository and through the Alire package index, covers TLS 1.2/1.3, DTLS 1.2/1.3, and a set of wolfCrypt primitives. Next, we’ll be bringing post-quantum algorithms.

The algorithms are already in wolfCrypt as native implementations with assembly optimizations:

  • ML-KEM (FIPS 203) — key establishment
  • ML-DSA (FIPS 204) — signatures
  • SLH-DSA (FIPS 205) — stateless hash-based signatures
  • LMS and XMSS (SP 800-208) — stateful hash-based signatures for firmware signing

The work ahead is simple plumbing. Post-quantum artifacts suit SPARK well. Key, ciphertext and signature sizes are fixed at compile time by the parameter set, so they model cleanly as constrained arrays with no dynamic allocation and no secondary stack usage.

Here at wolfSSL, priorities are driven by user demand. If you’re building in Ada or SPARK, let us know which algorithms you need, your use case, and what your certification constraints look like. If you are using ADA, you likely have FIPS 140-3 or DO-178 requirements.

Contact us at facts@wolfssl.com or +1 425 245 8247, or open an issue on GitHub.

Download wolfSSL Now