You can either experiment with other TLS libraries or investigate whether a more powerful device wouldn't make your life easier.
[1]: https://datatracker.ietf.org/doc/draft-ietf-ace-mqtt-tls-pro...
Usually devices of that size will use a dedicated crypto chip to store and manipulate the keys.
Elliptic curve algorithms fit better into that RAM footprint, if you can afford to sacrifice protocol compatibility.
If you can drop the SSL/TLS requirement and fall back to authenticating and encrypting your payloads over HTTP, RC5/SHA might suffice. Hash some unique serial number on your device and use that as a key. Auth is provided with a secret key burned into your device -- but this opens up big risks if your physical device or its firmware are compromised.
(Perhaps consider https://teserakt.io/ for the securing-MQTT part.)
Also apparently many "IoT" labeled devices are not actually on the internet, but are using some kindof gateway to the net. In this case you would lose end-to-end security by just using TLS to the gateway.