Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)

What Happened

Cloudflare’s Automatic Key Exchange replaces the default X25519 key agreement with a measured algorithm per origin, preferring the post‑quantum hybrid X25519MLKEM768 when supported. The rollout reduced HelloRetryRequests from ~52% to 3.7%, cutting more than 150 ms off p90 handshake latency. Hundreds of thousands of domains now have post‑quantum origin connections without manual configuration, and the number grows daily.

Why It Matters

Enterprise architects can expect lower latency and fewer handshake retries on TLS 1.3 connections, improving user experience and reducing server load. The automatic adoption of post‑quantum algorithms eases compliance with future quantum‑resistance standards, lowering long‑term security risk and governance overhead.

The Limitation

The feature is currently limited to Cloudflare‑managed origins; sites not using Cloudflare or with custom TLS stacks may not benefit immediately.

What You Can Do

Deploy Cloudflare’s Automatic Key Exchange on your origin infrastructure to automatically select the optimal key agreement and enable post‑quantum protection.

Source

Read original source
← Back to all articles