wolfSSL Advances Embedded Security with wolfIP, New Post-Quantum Capabilities and AURIX™ TC4xx Support

wolfSSL announced three advances for embedded systems: the deterministic wolfIP TCP/IP stack, broader post-quantum support spanning NIST-validated algorithms and native Falcon and FrodoKEM implementations, and wolfHSM support for the Infineon AURIX™ TC4xx. Together, these capabilities support predictable networking, the transition to post-quantum cryptography, and isolated cryptographic services for automotive systems.

EDMONDS, Wash., Sept. 21, 2026 /PRNewswire-PRWeb/ — wolfSSL Inc., the recognized leader in embedded security, today announced new capabilities spanning deterministic networking, expanded post-quantum cryptography, and hardware-isolated cryptographic services. The announcement includes wolfIP, a deterministic TCP/IP stack with no dynamic memory allocation; NIST-validated post-quantum algorithms and native Falcon and FrodoKEM implementations in wolfCrypt; and wolfHSM support for the Infineon AURIX™ TC4xx.

wolfIP Brings Determinism to Embedded Networking

wolfIP is a lightweight TCP/IP stack for bare-metal and RTOS-based embedded systems. It uses no dynamic memory allocation. Socket tables and RX/TX packet buffers are sized at build time, creating a fixed memory model that developers can analyze before deployment. This defined resource usage supports predictable operation and simplifies verification.

wolfIP’s endpoint-focused TCP/IP core is approximately four times smaller than lwIP and includes TCP, UDP, DHCP, and DNS. Direct integration with wolfSSL TLS 1.3 secures TCP connections without introducing a separate network architecture.

For resource-constrained and safety-critical systems, these defined limits can reduce verification complexity and support certification efforts.

NIST Validates wolfCrypt Post-Quantum Algorithms

wolfCrypt Post-Quantum has received validation through the NIST Cryptographic Algorithm Validation Program under certificate #A8437. The validation covers implementations of ML-KEM, ML-DSA, and SLH-DSA, along with LMS and XMSS signature verification.

Certificate #A8437 also covers supporting cryptographic functions, including SHA-2, SHA-3, SHAKE, HMAC, and SHA-512 Hash DRBG. This gives developers tested implementations for embedded systems preparing for CNSA 2.0 requirements and the transition to post-quantum cryptography.

The certificate marks an important step toward wolfSSL’s planned wolfCrypt FIPS 140-3 v7.0.0 module submission. The upcoming module is planned to bring ML-KEM, ML-DSA, SLH-DSA, LMS verification and XMSS verification within the validated boundary.

wolfCrypt Adds Native Falcon and FrodoKEM Support

wolfCrypt now includes native implementations of Falcon-512 and Falcon-1024, removing the previous dependency on liboqs. The implementation supports embedded, desktop, and Linux kernel environments, with accelerated options for x86-64 and Arm. Crypto callbacks enable hardware offload, while verify-only and reduced-memory configurations help limit resource use on constrained devices. Falcon support remains experimental while NIST finalizes FN-DSA.

wolfCrypt also adds FrodoKEM support across three parameter sets, with SHAKE- and AES-based matrix generation. Developers can select only the parameter sets and operations their applications require, reducing unnecessary code. The implementation includes optimized paths for x86-64 and Arm, crypto callback support, and ASN.1 and X.509 integration for handling FrodoKEM keys in certificates and certificate requests.

wolfHSM Extends AURIX™ Support to TC4xx

wolfHSM now supports the Infineon AURIX™ TC4xx, extending its existing support for the widely deployed TC3xx family. The TC4xx port carries forward wolfHSM’s client-server architecture and wolfCrypt-backed cryptography.

“wolfHSM gives automotive developers a consistent security architecture across the AURIX™ TC3xx and TC4xx families,” said Todd Ouska, Chief Technology Officer at wolfSSL. “That continuity gives automotive programs a path to post-quantum algorithms and wolfCrypt FIPS 140-3 validated cryptography without redesigning how the application communicates with the HSM.”

wolfHSM provides a common cryptographic service for secure boot, OTA updates, diagnostics, secure communications, and SecOC. Applications send sensitive operations to the isolated HSM core rather than implementing key protection separately for each function. AUTOSAR integration connects this service with established automotive software architectures, while an available ASIL-D certification package supports safety-critical development.

Meet wolfSSL at Booth #6027 during embedded world North America. To schedule a meeting or request technical and integration support, contact facts@wolfssl.com.

If you have questions about any of the above, please contact us at facts@wolfssl.com or call us at +1 425 245 8247.

Download wolfSSL Now