Back to updates
New releaseSep 19, 2026

wolfCOSE v2.0.0

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

Share

wolfCOSE

wolfCOSE is a lightweight and fast C library implementing core CBOR and COSE standards, backed by wolfSSL for cryptography.

Supported Standards & RFCs

  • Core Specifications:
    • RFC 8949 - Concise Binary Object Representation (CBOR)
    • RFC 9052 - CBOR Object Signing and Encryption (COSE)
    • RFC 9053 - COSE algorithms
    • RFC 9864 - Fully-Specified Algorithms for JOSE and COSE
    • RFC 9338 - COSE Countersignatures
  • Post-Quantum Cryptography:
  • Attestation:
    • RFC 9783 - PSA Attestation Token Profile of EAT

Main Features

  • Complete COSE Suite (RFC 9052): Full support for all six message types, including COSE_Sign1, COSE_Encrypt0, and COSE_Mac0.
  • V2 Countersignatures (RFC 9338): Full and abbreviated in-place countersignatures across all six tagged COSE message types.
  • Post-Quantum Cryptography:
    • ML-DSA (FIPS 204 / RFC 9964) at all security levels.
    • HSS/LMS stateful hash-based signing (RFC 8778 / CNSA 2.0).
  • Fast Performance: On an Intel i9-11950H, end-to-end COSE_Sign1 reaches 66,538 sign/s and 26,437 verify/s with ES256, and 21,986 sign/s and 53,686 verify/s with ML-DSA-44. See the performance and footprint details and wolfCOSE vs. The Field.
  • PSA Attestation: EAT / PSA Token issuance and verification with delegated HSM signing support.
  • 41 Cryptographic Algorithms: Broad algorithm coverage across signing, encryption, MAC, and key distribution.
  • Embedded-First Design: Zero dynamic memory allocation (no heap, zero .data/.bss). Operates on caller-supplied buffers with bounded stack usage.
  • FIPS 140-3 Path: Uses wolfCrypt (FIPS Certificate #4718) as its sole cryptographic dependency.
  • STM32 Integrated: Drop-in STM32Cube pack (I-CUBE-wolfCOSE) available for STM32CubeMX / IDE (Details).

Supported Algorithms

  • Digital Signatures:
    • Classical: ESP256, ESP384, ESP512, Ed25519, Ed448, PS256, PS384, PS512
    • Post-Quantum: ML-DSA-44, ML-DSA-65, ML-DSA-87
    • Stateful Hash-Based: HSS-LMS
  • Encryption (AEAD):
    • AES-GCM (128 / 192 / 256)
    • AES-CCM (variants)
    • ChaCha20-Poly1305
  • Message Authentication (MAC):
    • HMAC-SHA256, HMAC-SHA384, HMAC-SHA512
    • AES-MAC
  • Key Distribution:
    • Direct
    • AES Key Wrap
    • ECDH-ES + HKDF

COSE Message Types (RFC 9052)

wolfCOSE has implemented all RFC 9052 messages both single-actor and multi-actor variants:

MessageRFC 9052APIPurpose
COSE_Sign1Sec. 4.2wc_CoseSign1_Sign / wc_CoseSign1_VerifySingle-signer signature
COSE_SignSec. 4.1wc_CoseSign_Sign / wc_CoseSign_VerifyMulti-signer (independent signatures over the same payload)
COSE_Encrypt0Sec. 5.2wc_CoseEncrypt0_Encrypt / wc_CoseEncrypt0_DecryptSingle-recipient AEAD
COSE_EncryptSec. 5.1wc_CoseEncrypt_Encrypt / wc_CoseEncrypt_DecryptMulti-recipient (one ciphertext, many recipients via Direct / AES-KW / ECDH-ES)
COSE_Mac0Sec. 6.2wc_CoseMac0_Create / wc_CoseMac0_VerifySingle-recipient MAC
COSE_MacSec. 6.1wc_CoseMac_Create / wc_CoseMac_VerifyMulti-recipient MAC (shared MAC key, distributed to recipients)
COSE_Key / COSE_KeySetSec. 7wc_CoseKey_Encode / wc_CoseKey_DecodeKey serialization for all key types

RFC 9338 countersignatures can be attached to any tagged message in this table. Use wc_Cose_AddCounterSignature() or wc_Cose_AddCounterSignature0() to add one, then verify it independently with the corresponding wc_Cose_VerifyCounterSignature*() API.

Dependencies (wolfSSL)

wolfCOSE requires wolfSSL as its crypto backend. Minimum supported version: v5.8.0-stable. Some optional algorithms require newer releases; see Getting Started for feature-specific dependency floors and build instructions. HSS/LMS (RFC 8778) requires v5.9.2-stable or later.

Choose a build configuration based on the algorithms you need.

Minimal Build (ECC + AES-GCM)

This gives you COSE Sign1 (ESP256/384/512) and Encrypt0 (AES-GCM):

cd wolfssl
./autogen.sh
./configure --enable-ecc --enable-aesgcm \
            --enable-sha384 --enable-sha512 --enable-keygen
make && sudo make install
sudo ldconfig

Algorithms enabled: ESP256, ESP384, ESP512, AES-GCM-128/192/256

For a smaller wolfCrypt footprint, add --enable-cryptonly to drop the TLS stack and disable the algorithms a Sign1 + Encrypt0 build never uses:

./configure --enable-cryptonly --enable-ecc --enable-aesgcm \
            --enable-sha384 --enable-sha512 --enable-keygen \
            --enable-lowresource \
            --disable-dh --disable-rsa --disable-aescbc \
            --disable-sha --disable-md5 --disable-chacha --disable-poly1305 \
            --disable-errorstrings

See Tuning for Size and Tuning for Speed for squeezing wolfCOSE and wolfCrypt further on MCUs.

Minimal Build (Post-Quantum / ML-DSA only)

For pure post-quantum signing with ML-DSA-44/65/87:

cd wolfssl
./autogen.sh
./configure --enable-cryptonly --enable-mldsa
make && sudo make install
sudo ldconfig

Algorithms enabled: ML-DSA-44, ML-DSA-65, ML-DSA-87 (SHAKE-128/256 are pulled in automatically by --enable-mldsa. The wc_MlDsaKey API requires wolfSSL newer than v5.9.1-stable.)

Full Build (All Algorithms)

cd wolfssl
./autogen.sh
./configure --enable-ecc --enable-ed25519 --enable-ed448 \
            --enable-curve25519 --enable-aesgcm --enable-aesccm \
            --enable-sha384 --enable-sha512 --enable-keygen \
            --enable-rsapss --enable-chacha --enable-poly1305 \
            --enable-mldsa --enable-lms \
            --enable-hkdf --enable-aeskeywrap
make && sudo make install
sudo ldconfig

Build

# Core library (libwolfcose.a)
make

# Run unit tests
make test

# Build and run CLI tool round-trip tests (all algorithms)
make tool-test

# Run lifecycle demo (11 algorithms)
make demo

Build Targets

Categories