wolfSSL announced three advances for embedded systems: the deterministic wolfIP TCP/IP stack, broader post-quantum support spanning NIST-validated algorithms and native Falcon and FrodoKEM implementations, and wolfHSM support for the Infineon AURIX™ TC4xx. Together, these capabilities support predictable networking, the transition to post-quantum cryptography, and isolated cryptographic services for automotive systems.
EDMONDS, Wash., Sept. 21, 2026 /PRNewswire-PRWeb/ -- wolfSSL Inc., the recognized leader in embedded security, today announced new capabilities spanning deterministic networking, expanded post-quantum cryptography, and hardware-isolated cryptographic services. The announcement includes wolfIP, a deterministic TCP/IP stack with no dynamic memory allocation; NIST-validated post-quantum algorithms and native Falcon and FrodoKEM implementations in wolfCrypt; and wolfHSM support for the Infineon AURIX™ TC4xx.
wolfIP Brings Determinism to Embedded Networking
wolfIP is a lightweight TCP/IP stack for bare-metal and RTOS-based embedded systems. It uses no dynamic memory allocation. Socket tables and RX/TX packet buffers are sized at build time, creating a fixed memory model that developers can analyze before deployment. This defined resource usage supports predictable operation and simplifies verification.
wolfIP's endpoint-focused TCP/IP core is approximately four times smaller than lwIP and includes TCP, UDP, DHCP, and DNS. Direct integration with wolfSSL TLS 1.3 secures TCP connections without introducing a separate network architecture.
For resource-constrained and safety-critical systems, these defined limits can reduce verification complexity and support certification efforts.
NIST Validates wolfCrypt Post-Quantum Algorithms
wolfCrypt Post-Quantum has received validation through the NIST Cryptographic Algorithm Validation Program under certificate #A8437. The validation covers implementations of ML-KEM, ML-DSA, and SLH-DSA, along with LMS and XMSS signature verification.
Certificate #A8437 also covers supporting cryptographic functions, including SHA-2, SHA-3, SHAKE, HMAC, and SHA-512 Hash DRBG. This gives developers tested implementations for embedded systems preparing for CNSA 2.0 requirements and the transition to post-quantum cryptography.
The certificate marks an important step toward wolfSSL's planned wolfCrypt FIPS 140-3 v7.0.0 module submission. The upcoming module is planned to bring ML-KEM, ML-DSA, SLH-DSA, LMS verification and XMSS verification within the validated boundary.
wolfCrypt Adds Native Falcon and FrodoKEM Support
wolfCrypt now includes native implementations of Falcon-512 and Falcon-1024, removing the previous dependency on liboqs. The implementation supports embedded, desktop, and Linux kernel environments, with accelerated options for x86-64 and Arm. Crypto callbacks enable hardware offload, while verify-only and reduced-memory configurations help limit resource use on constrained devices. Falcon support remains experimental while NIST finalizes FN-DSA.
wolfCrypt also adds FrodoKEM support across three parameter sets, with SHAKE- and AES-based matrix generation. Developers can select only the parameter sets and operations their applications require, reducing unnecessary code. The implementation includes optimized paths for x86-64 and Arm, crypto callback support, and ASN.1 and X.509 integration for handling FrodoKEM keys in certificates and certificate requests.
wolfHSM Extends AURIX™ Support to TC4xx
wolfHSM now supports the Infineon AURIX™ TC4xx, extending its existing support for the widely deployed TC3xx family. The TC4xx port carries forward wolfHSM's client-server architecture and wolfCrypt-backed cryptography.
"wolfHSM gives automotive developers a consistent security architecture across the AURIX™ TC3xx and TC4xx families," said Todd Ouska, Chief Technology Officer at wolfSSL. "That continuity gives automotive programs a path to post-quantum algorithms and wolfCrypt FIPS 140-3 validated cryptography without redesigning how the application communicates with the HSM."
wolfHSM provides a common cryptographic service for secure boot, OTA updates, diagnostics, secure communications, and SecOC. Applications send sensitive operations to the isolated HSM core rather than implementing key protection separately for each function. AUTOSAR integration connects this service with established automotive software architectures, while an available ASIL-D certification package supports safety-critical development.
Meet wolfSSL at Booth #6027 during embedded world North America. To schedule a meeting or request technical and integration support, contact [email protected].
About wolfSSL
wolfSSL delivers high-performance, lightweight security solutions focused on speed, size, portability, and standards compliance. Our TLS products and wolfCrypt cryptography library power secure designs across industries like government, automotive, and avionics. Our wolfBoot secure bootloader ensures the integrity of firmware updates, adding another layer of protection. For government clients, wolfSSL excels with FIPS 140-3 certification, making us the trusted choice for securing sensitive systems and winning contracts. In avionics, we support RTCA DO-178C Level A certification, and in automotive, our solutions comply with MISRA-C standards. We fully support the latest TLS 1.3 and DTLS 1.3 protocols. Our simplified API and OpenSSL compatibility layer are backed by the robust wolfCrypt library. As an open-source company, we offer transparency, allowing customers to look under the hood. Additionally, our Post-Quantum Cryptography solutions support CNSA 2.0 standards to protect against quantum threats. With a response time under 36 hours for vulnerability fixes and 24/7 commercial support, wolfSSL provides the most rigorously tested cryptography on the market. For more information, visit wolfssl.com.
Media Contact
Shizuka Ishikiriyama, wolfSSL Inc., 1 425 245 8247, [email protected], https://www.wolfssl.com/
SOURCE wolfSSL Inc.
Share this article