wolfCOSE Adds COSE HPKE Encryption

wolfSSL is adding Hybrid Public Key Encryption (HPKE) support to wolfCOSE. HPKE, standardized in RFC 9180, combines a KEM, a KDF, and an AEAD into a modern, misuse-resistant public-key encryption scheme, and bringing it to COSE lets constrained and IoT devices encrypt CBOR-based messages to one or many recipients without hand-rolled key wrapping. The feature is off by default and enabled through WOLFCOSE_EXPERIMENTAL plus a per-operation macro, so the core library stays lean.

The feature set includes:

  • Single-recipient COSE_Encrypt0 and multi-recipient COSE_Encrypt HPKE
  • All six HPKE enable selectors, each independently gated
  • Paired command-line commands, self-tests, and a runnable HPKE example
  • Negative acknowledgement tests confirming the feature stays off unless opted in
  • Full CLI validation of 44 tests with zero failures

HPKE support currently lands as experimental (P0) groundwork with a documented graduation path, and requires WOLFCOSE_EXPERIMENTAL plus each selected HPKE operation macro.


For additional information regarding this feature, interested parties may contact wolfSSL at facts@wolfssl.com or call +1 425 245 8247. See the PR #70.

Download wolfSSL Now