wolfSSL is adding RFC 8778 HSS/LMS stateful hash-based signature support to wolfCOSE, giving COSE a NIST-approved, quantum-resistant signing option today. Hash-based signatures are attractive for firmware and long-lived attestation because their security rests only on the hash function, and bringing LMS to COSE lets customers adopt post-quantum signing inside the compact CBOR message formats they already use for secure boot, updates, and device identity.
The feature set includes:
- COSE algorithm HSS-LMS (-46) with COSE_Key type kty 5
- Signing and verification in COSE_Sign1, multi-signer COSE_Sign, and delegated signing
- Public-key COSE_Key encode and decode
- New wc_CoseKey_SetLms() API, two examples, and unit tests
- WOLFCOSE_LEAN_LMS and WOLFCOSE_LEAN_VERIFY_LMS build profiles for verify-only devices
LMS support requires wolfSSL built with –enable-lms, and verify-only builds pair with WOLFSSL_LMS_VERIFY_ONLY. XMSS is out of scope for now, as it has no COSE codepoints yet.
For additional information regarding this feature, interested parties may contact wolfSSL at facts@wolfssl.com or call +1 425 245 8247. See the PR #72.
Download wolfSSL Now

