
wolfCOSE v2.0.0
A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.
wolfCOSE
wolfCOSE is a lightweight and fast C library implementing core CBOR and COSE standards, backed by wolfSSL for cryptography.
Supported Standards & RFCs
- Core Specifications:
- Post-Quantum Cryptography:
- Attestation:
- RFC 9783 - PSA Attestation Token Profile of EAT
Main Features
- Complete COSE Suite (RFC 9052): Full support for all six message types, including
COSE_Sign1,COSE_Encrypt0, andCOSE_Mac0. - V2 Countersignatures (RFC 9338): Full and abbreviated in-place countersignatures across all six tagged COSE message types.
- Post-Quantum Cryptography:
- ML-DSA (FIPS 204 / RFC 9964) at all security levels.
- HSS/LMS stateful hash-based signing (RFC 8778 / CNSA 2.0).
- Fast Performance: On an Intel i9-11950H, end-to-end
COSE_Sign1reaches 66,538 sign/s and 26,437 verify/s with ES256, and 21,986 sign/s and 53,686 verify/s with ML-DSA-44. See the performance and footprint details and wolfCOSE vs. The Field. - PSA Attestation: EAT / PSA Token issuance and verification with delegated HSM signing support.
- 41 Cryptographic Algorithms: Broad algorithm coverage across signing, encryption, MAC, and key distribution.
- Embedded-First Design: Zero dynamic memory allocation (no heap, zero
.data/.bss). Operates on caller-supplied buffers with bounded stack usage. - FIPS 140-3 Path: Uses wolfCrypt (FIPS Certificate #4718) as its sole cryptographic dependency.
- STM32 Integrated: Drop-in STM32Cube pack (
I-CUBE-wolfCOSE) available for STM32CubeMX / IDE (Details).
Supported Algorithms
- Digital Signatures:
- Classical:
ESP256,ESP384,ESP512,Ed25519,Ed448,PS256,PS384,PS512 - Post-Quantum:
ML-DSA-44,ML-DSA-65,ML-DSA-87 - Stateful Hash-Based:
HSS-LMS
- Classical:
- Encryption (AEAD):
AES-GCM(128 / 192 / 256)AES-CCM(variants)ChaCha20-Poly1305
- Message Authentication (MAC):
HMAC-SHA256,HMAC-SHA384,HMAC-SHA512AES-MAC
- Key Distribution:
DirectAES Key WrapECDH-ES + HKDF
COSE Message Types (RFC 9052)
wolfCOSE has implemented all RFC 9052 messages both single-actor and multi-actor variants:
| Message | RFC 9052 | API | Purpose |
|---|---|---|---|
COSE_Sign1 | Sec. 4.2 | wc_CoseSign1_Sign / wc_CoseSign1_Verify | Single-signer signature |
COSE_Sign | Sec. 4.1 | wc_CoseSign_Sign / wc_CoseSign_Verify | Multi-signer (independent signatures over the same payload) |
COSE_Encrypt0 | Sec. 5.2 | wc_CoseEncrypt0_Encrypt / wc_CoseEncrypt0_Decrypt | Single-recipient AEAD |
COSE_Encrypt | Sec. 5.1 | wc_CoseEncrypt_Encrypt / wc_CoseEncrypt_Decrypt | Multi-recipient (one ciphertext, many recipients via Direct / AES-KW / ECDH-ES) |
COSE_Mac0 | Sec. 6.2 | wc_CoseMac0_Create / wc_CoseMac0_Verify | Single-recipient MAC |
COSE_Mac | Sec. 6.1 | wc_CoseMac_Create / wc_CoseMac_Verify | Multi-recipient MAC (shared MAC key, distributed to recipients) |
COSE_Key / COSE_KeySet | Sec. 7 | wc_CoseKey_Encode / wc_CoseKey_Decode | Key serialization for all key types |
RFC 9338 countersignatures can be attached to any tagged message in this
table. Use wc_Cose_AddCounterSignature() or
wc_Cose_AddCounterSignature0() to add one, then verify it independently with
the corresponding wc_Cose_VerifyCounterSignature*() API.
Dependencies (wolfSSL)
wolfCOSE requires wolfSSL as its crypto backend. Minimum supported version: v5.8.0-stable. Some optional algorithms require newer releases; see Getting Started for feature-specific dependency floors and build instructions. HSS/LMS (RFC 8778) requires v5.9.2-stable or later.
Choose a build configuration based on the algorithms you need.
Minimal Build (ECC + AES-GCM)
This gives you COSE Sign1 (ESP256/384/512) and Encrypt0 (AES-GCM):
cd wolfssl
./autogen.sh
./configure --enable-ecc --enable-aesgcm \
--enable-sha384 --enable-sha512 --enable-keygen
make && sudo make install
sudo ldconfig
Algorithms enabled: ESP256, ESP384, ESP512, AES-GCM-128/192/256
For a smaller wolfCrypt footprint, add --enable-cryptonly to drop the TLS
stack and disable the algorithms a Sign1 + Encrypt0 build never uses:
./configure --enable-cryptonly --enable-ecc --enable-aesgcm \
--enable-sha384 --enable-sha512 --enable-keygen \
--enable-lowresource \
--disable-dh --disable-rsa --disable-aescbc \
--disable-sha --disable-md5 --disable-chacha --disable-poly1305 \
--disable-errorstrings
See Tuning for Size and Tuning for Speed for squeezing wolfCOSE and wolfCrypt further on MCUs.
Minimal Build (Post-Quantum / ML-DSA only)
For pure post-quantum signing with ML-DSA-44/65/87:
cd wolfssl
./autogen.sh
./configure --enable-cryptonly --enable-mldsa
make && sudo make install
sudo ldconfig
Algorithms enabled: ML-DSA-44, ML-DSA-65, ML-DSA-87
(SHAKE-128/256 are pulled in automatically by --enable-mldsa. The
wc_MlDsaKey API requires wolfSSL newer than v5.9.1-stable.)
Full Build (All Algorithms)
cd wolfssl
./autogen.sh
./configure --enable-ecc --enable-ed25519 --enable-ed448 \
--enable-curve25519 --enable-aesgcm --enable-aesccm \
--enable-sha384 --enable-sha512 --enable-keygen \
--enable-rsapss --enable-chacha --enable-poly1305 \
--enable-mldsa --enable-lms \
--enable-hkdf --enable-aeskeywrap
make && sudo make install
sudo ldconfig
Build
# Core library (libwolfcose.a)
make
# Run unit tests
make test
# Build and run CLI tool round-trip tests (all algorithms)
make tool-test
# Run lifecycle demo (11 algorithms)
make demo