Home / Companies / Cloudflare / Blog / Post Details
Content Deep Dive

Using HPKE to Encrypt Request Payloads

Blog post from Cloudflare

Post Details
Company
Date Published
Author
Miguel de Moura, Andre Bluehs
Word Count
1,766
Company Posts That Month
10
Language
English
Hacker News Points
2
Post removed?
No
Summary

The Managed Rules team at Cloudflare has implemented a feature allowing Enterprise users to debug Firewall Rules by viewing the part of a request that matched the rule, while ensuring secure storage of debugging data. They chose Hybrid Public Key Encryption (HPKE) for its combination of symmetric and public-key cryptography, aiming to provide a single, future-proof, robust, interoperable solution. HPKE is an emerging standard developed by the Crypto Forum Research Group (CFRG), with a high level of security in a generic manner and necessary hooks to tie messages to their context. The team implemented HPKE in Rust due to its native primitives and ability to compile to WebAssembly, allowing reuse across the edge component that encrypts payloads and the UI and CLI that decrypt them.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.