Skip to content
INTERNET INFRASTRUCTURE & NETWORKS

Cloudflare Enhances Security Suite with New Post-Quantum Cryptography Visibility Tools

Cloudflare has introduced advanced post-quantum (PQ) cryptography visibility tools across its Application Security and Logs products, giving organizations granular, real-time telemetry to audit their cryptographic postures, assess compliance, and identify gaps across their digital domains. With this update, enterprise teams and domain administrators can now inspect and graph the adoption of post-quantum TLS 1.3 encryption for live web traffic directly from the HTTP Traffic Analytics dashboard, Log Explorer, and Logpush.

By surfacing the precise key exchange algorithm negotiated on every incoming visitor request, Cloudflare aims to bridge the gap between macro-level Internet statistics and domain-specific oversight. This rollout marks a critical milestone in the company’s broader roadmap, which targets full post-quantum security by the year 2029. Executing such a massive cryptographic transition at global scale requires detailed, actionable telemetry, and the newly released tools are designed to provide the deep visibility that security teams need as they work toward looming quantum-readiness deadlines around 2030.

The urgency surrounding post-quantum cryptography stems from the looming threat of "harvest-now-decrypt-later" attacks. Malicious actors and nation-state adversaries are currently intercepting and storing encrypted data flowing across the Internet, waiting for the day when sufficiently powerful quantum computers become operational to break classical encryption algorithms like RSA and Elliptic Curve Cryptography (ECC). Recognizing this risk, the National Institute of Standards and Technology (NIST) stated in 2024 that legacy algorithms should be deprecated by 2030, a timeline that has since been widely endorsed by governments and regulatory bodies worldwide.

Organizations handling sensitive data that retains value over a three-to-ten-year window—such as public sector entities, defense agencies, financial institutions, telecommunications providers, and healthcare organizations—are heavily encouraged to protect their traffic immediately. Cloudflare has already deployed post-quantum encryption across a vast array of its products, including its cloud-proxy platform and its Secure Access Service Edge (SASE) architecture. To ease the migration burden for its customers, the platform has made post-quantum encryption the default setting wherever possible, while actively sharing insights gathered from internal cryptographic discovery tools.

Bringing post-quantum visibility to the domain level

While macro-level insights have previously been accessible through initiatives like Cloudflare Radar—which tracks global post-quantum adoption across the wider Internet—customers have increasingly demanded the ability to analyze the cryptographic behavior of their own individual domains. Radar telemetry indicates that approximately 70% of browser-generated traffic hitting Cloudflare’s network on visitor-to-Cloudflare connections is currently protected using hybrid post-quantum encryption. However, that figure drops significantly when looking at origin servers, where only about 15% of connections leverage hybrid ML-KEM algorithms.

To help close this gap, Cloudflare recently launched Automatic Key Exchange for Cloudflare-to-origin connections, which automatically detects and negotiates the strongest cryptographic algorithms supported by an origin server. Despite these platform-wide innovations, until now, administrators lacked a straightforward way to answer granular questions about individual properties, such as the exact fraction of traffic to a specific domain utilizing post-quantum encryption. Providing this clarity is essential for organizations navigating complex regulatory compliance frameworks, troubleshooting infrastructure migrations, and sealing potential vulnerabilities against future quantum adversaries.

Understanding post-quantum cryptography in TLS

Is your domain using post-quantum encryption? Now you can see for yourself

To fully leverage the new visibility tools, security teams must understand how post-quantum cryptography operates within the Transport Layer Security (TLS) protocol. In modern TLS 1.3 implementations, the designated key exchange group for post-quantum security is X25519MLKEM768, which relies on a hybrid cryptographic approach combining the classical X25519 elliptic curve with the standardized ML-KEM algorithm, formally designated under NIST FIPS 203. This hybrid architecture functions as a security belt-and-suspenders measure, ensuring that as long as at least one of the two underlying key exchanges remains secure, the resulting shared secret cannot be compromised by future quantum computers.

Major web browsers have enthusiastically adopted X25519MLKEM768 as a preferred key exchange mechanism for TLS 1.3 connections. Older TLS versions, such as TLS 1.2, do not support post-quantum encryption and continue to rely on quantum-vulnerable classical algorithms like standard ECDHE or legacy RSA. While post-quantum encryption focuses primarily on protecting data confidentiality in transit, the broader cryptographic community is also working to address post-quantum authentication, which involves upgrading the certificates and signatures used in TLS handshakes away from traditional algorithms and toward advanced alternatives like ML-DSA and emerging Merkle Tree Certificates. Nevertheless, deployment of post-quantum encryption currently outpaces authentication across the global web ecosystem.

Bringing post-quantum visibility to the visitor-to-Cloudflare connection

With the integration of new analytics and logging capabilities, administrators can now inspect the exact extent to which post-quantum key agreement is utilized for any domain connecting to Cloudflare. By navigating to the HTTP Traffic Analytics dashboard within the Cloudflare control panel, users can view a dedicated card detailing the distribution of TLS key exchange groups utilized by incoming visitors.

The analytics interface clearly delineates traffic protected by post-quantum X25519MLKEM768 under TLS 1.3 from traffic relying on classical ECDHE curves or older cryptographic methods. Connections utilizing legacy RSA key agreements in TLS 1.2 or operating without TLS are categorized accordingly, while legacy transition algorithms from the early standardization phases are tracked to help maintain backward compatibility for specialized clients. For domains showing little to no adoption of post-quantum standards, platform recommendations advise confirming that TLS 1.3 is enabled within Edge Certificate settings, as Cloudflare automatically negotiates post-quantum parameters whenever compatible client browsers connect.

In addition to aggregate dashboard views, organizations requiring deep forensic analysis can utilize individual log lines via Logpush and Log Explorer. By enabling the newly introduced ClientTLSKeyExchangeGroup field within the HTTP Requests dataset, security engineers can extract precise per-connection telemetry and ingest raw log data into external security information and event management systems for continuous compliance auditing and monitoring.

Visibility to origins and beyond

The introduction of key exchange group analytics represents only the first major phase in Cloudflare’s ongoing cryptographic visibility initiative. The underlying telemetry pipeline has been architected for scalability, allowing it to ingest and process a wider variety of cryptographic parameters extracted directly from active TLS handshakes over time.

As part of this expansion, Cloudflare has also surfaced the key exchange group utilized on the backend connection between its network and origin servers through the corresponding OriginTLSKeyExchangeGroup log field. This provides comprehensive end-to-end visibility from the initial visitor connection all the way to the origin infrastructure. For organizations operating legacy origin servers that lack native support for modern post-quantum cryptography, alternative architectural patterns—such as deploying a Cloudflare Tunnel—allow traffic to be securely bridged over TLS 1.3 with X25519MLKEM768 without requiring immediate, disruptive hardware or software upgrades to ossified backend systems. As broader industry deployment matures, Cloudflare plans to extend similar granular visibility features to post-quantum authentication mechanisms and certificate signing algorithms.

Leave a Reply

Your email address will not be published. Required fields are marked *