AI Briefing
Sign in

Cloudflare adds post-quantum TLS visibility tools to Security and Logs products

·2026.09.29 22:00

Key point

Customers can now inspect per-connection post-quantum adoption via Logpush, Log Explorer, and HTTP Traffic Analytics to audit compliance and identify cryptographic gaps.

Details

Cloudflare has introduced new post-quantum (PQ) cryptography visibility tools into its Application Security and Logs products. These features allow customers to inspect and graph the adoption of post-quantum TLS 1.3 encryption for live traffic directly within Logpush, Log Explorer, and the HTTP Traffic Analytics dashboard. By surfacing the key exchange algorithm negotiated on every incoming request, Cloudflare provides granular, per-connection telemetry to help customers audit their post-quantum posture, assess compliance, and identify cryptographic gaps across their domains.

Macro-Level Adoption Statistics

While Cloudflare Radar previously offered macro-level visibility into Internet-wide post-quantum adoption, the new tools allow for domain-level analysis. Current aggregate statistics show that approximately 70% of browser-generated traffic hitting Cloudflare's network (visitor-to-Cloudflare connection) is protected with post-quantum encryption using hybrid ML-KEM (FIPS 203). In contrast, only about 15% of origins that Cloudflare connects to currently use hybrid ML-KEM. The recently launched Automatic Key Exchange feature helps reveal which cryptographic algorithms are supported by a given origin, addressing issues where outdated configurations might force classical cryptography despite PQ support.

Technical Context and Algorithms

The visibility tools focus on the key exchange group used in TLS 1.3, specifically X25519MLKEM768, which is the only recommended algorithm for post-quantum encryption in TLS 1.3. This hybrid approach combines Elliptic Curve Diffie-Hellman Key Exchange (ECDHE) over curve X25519 with the post-quantum Module Lattice Key Encapsulation Mechanism (ML-KEM). This ensures security as long as one of the two key exchanges remains secure. NIST has stated that RSA and Elliptic Curve Cryptography (ECC) should be deprecated by 2030, driving the need for immediate protection against harvest-now-decrypt-later attacks for organizations with long-term data value.

New Features and Implementation

The new visibility features are available in three main areas:

  • HTTP Traffic Analytics Dashboard: A dedicated card displays TLS Key Exchange groups for the visitor-to-Cloudflare connection. Users can filter traffic to identify connections not using X25519MLKEM768.
  • Log Explorer and Logpush: A new field, ClientTLSKeyExchangeGroup, is available under the TLS category in the HTTP Requests dataset, allowing visibility into individual post-quantum key exchanges in log lines.
  • Origin Visibility: The OriginTLSKeyExchangeGroup field in Logpush provides end-to-end visibility from the visitor to the origin server.

For domains showing no PQ usage, customers should ensure TLS 1.3 is enabled in the Cloudflare dashboard, as PQ encryption is negotiated automatically when TLS 1.3 is active and the visitor supports it. For legacy origin servers that cannot support modern PQ cryptography, Cloudflare recommends placing them behind a Cloudflare Tunnel to secure the connection to Cloudflare using TLS 1.3 with X25519MLKEM768 without upgrading the origin itself. Cloudflare is targeting 2029 for full post-quantum security.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.