Post-Quantum Authentication Support Begins for Origins
Key point
Cloudflare has begun supporting post-quantum authentication to origin servers via the ML-DSA algorithm.
Details
Cloudflare has introduced Post-Quantum (PQ) authentication support in its Authenticated Origin Pulls and Custom Origin Trust Store products. This leverages ML-DSA (Module-Lattice-Based Digital Signature Algorithm) signatures to protect connections between Cloudflare and customers' origin servers.
Until now, Cloudflare's focus has been on post-quantum encryption to prevent 'Harvest-now/Decrypt-later' attacks. However, as advances in quantum computing increase the risk of breaking classical credentials to carry out impersonation attacks, Cloudflare is now expanding its response to post-quantum authentication as well.
Web traffic is broadly divided into two connections:
- Connection 1 (Visitor-to-Cloudflare): The connection between the visitor and Cloudflare
- Connection 2 (Cloudflare-to-Origin): The connection between Cloudflare and the customer's origin server
Cloudflare already completed post-quantum encryption support for Connection 1 and Connection 2 in 2022 and 2023, respectively. This update achieves an important milestone in the overall security roadmap by applying the final piece of the puzzle—post-quantum authentication—to origin connections.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.