Post-quantum authentication to origins is now supported
Blog post from Cloudflare
Cloudflare has implemented post-quantum authentication for its Authenticated Origin Pulls and Custom Origin Trust Store products, marking a significant step in its roadmap towards full post-quantum security by 2029. This initiative aims to protect against future quantum computer threats that could compromise classical encryption methods. The new capability supports Module-Lattice-Based Digital Signature Algorithm (ML-DSA) signatures to secure connections between Cloudflare and customer origin servers, differentiating in approach from visitor-to-Cloudflare connections. The company has also collaborated with Google and the IETF on developing Merkle Tree Certificates for fast post-quantum web certificates, targeting 2027 for initial deployments. Cloudflare's deployment is ahead of the broader WebPKI implementation, allowing the use of custom PKIs to expedite post-quantum authentication without the typical public infrastructure constraints. The company offers flexible configuration options, enabling customers to upload ML-DSA CAs to the Custom Origin Trust Store and configure Authenticated Origin Pulls with ML-DSA certificates. Furthermore, Cloudflare has updated its control and data plane services to support these new post-quantum features, and plans to integrate future updates as the ecosystem evolves, including anticipated native support for ML-DSA in Go 1.27.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.