Cloudflare Boosts TLS 1.3 Security with Automated Post-Quantum Cryptography Integration

September 11, 2026
Cloudflare Boosts TLS 1.3 Security with Automated Post-Quantum Cryptography Integration
  • Cloudflare is implementing an automated, proactive integration of post-quantum cryptography into TLS handshakes, designed to maintain compatibility and minimize handshake failures.

  • The system automatically selects post-quantum key exchange for connections to compatible origin servers, strengthening TLS 1.3 security and reducing handshake latency.

  • Independent coverage from SDx Central highlights the security and performance impact of post-quantum key exchange in Cloudflare’s large-scale traffic.

  • This approach resolves a TLS 1.3 handshake limitation where the client shares a key before the server signals its preference, which could cause retries and higher latency.

  • Cloudflare reports protecting about 45 billion connections per day and a notable drop in handshake delays, with HelloRetryRequest shares falling from roughly 52% to 3.7%.

  • Deployment is on by default for new and existing Cloudflare domains whose origins support TLS 1.3, with ongoing work to add finer-grained controls and improved detection.

  • The Automatic Key Exchange capability probes origin servers to identify supported algorithms and selects the strongest compatible option, prioritizing the hybrid post-quantum X25519MLKEM768, with fallback to classical algorithms when necessary.

Summary based on 1 source


Get a daily email with more Tech stories

More Stories