Encryption, Security Program Controls/Technologies, Security Architecture

Cloudflare enhances security with automatic post-quantum key exchange

Quantum computing

Cloudflare has begun automatically selecting post-quantum key exchange for connections to compatible origin servers, a move that has seen protected traffic reach about 45 billion connections per day while reducing transport layer security (TLS) handshake delays, with further coverage provided by SDx Central.

The new Automatic Key Exchange capability probes origin servers to identify supported cryptographic algorithms and selects the strongest compatible option for TLS 1.3 connections, prioritizing the hybrid post-quantum algorithm X25519MLKEM768 and falling back to classical algorithms when necessary. This feature addresses a limitation in the TLS 1.3 handshake where clients must send a key share before the server indicates its preference, often leading to a retry and increased latency. Cloudflare's proactive scanning and gradual deployment strategy, coupled with daily rescans, minimize connection failures caused by larger post-quantum key shares and legacy infrastructure. The company reports a significant reduction in handshake delays, with the proportion of connections requiring a HelloRetryRequest falling from approximately 52% to 3.7%. This enhancement is enabled by default for new and existing Cloudflare domains whose origins support TLS 1.3, with ongoing development for more granular control and detection methods.

Source: SDx Central

You can skip this ad in 5 seconds