Cloudflare adds post-quantum ML-DSA authentication to origin server connections
Cloudflare has updated its Authenticated Origin Pulls and Custom Origin Trust Store products to support post-quantum authentication using the ML-DSA signature algorithm. This move aims to secure connections between their edge network and customer origin servers against future quantum computing-based impersonation attacks.
Key Takeaways
- Supports all FIPS 204 parameter sets including ML-DSA-44, ML-DSA-65, and ML-DSA-87 for origin authentication.
- Integrated into Authenticated Origin Pulls (AOP) for mutual TLS and Custom Origin Trust Store (COTS) for individual CA management.
- Updates to the Go-based control plane utilize Cloudflare’s CIRCL library until native ML-DSA support arrives in Go 1.27.
- Data plane relies on a significant April 2026 BoringSSL update to support the new post-quantum signature schemes.
- Addresses 'harvest-now/decrypt-later' risks by shifting focus from encryption-only to full post-quantum authentication.
Why It Matters
Securing the 'second hop' between the CDN edge and origin servers is a critical defense for streaming providers handling sensitive user data and proprietary content. While post-quantum encryption protects data in transit, ML-DSA authentication prevents quantum-capable adversaries from forging credentials to spoof legitimate origin servers. In the broader ecosystem, this move aligns with Google’s 2029 goal for full system-wide resilience and places pressure on other CDNs to adopt NIST FIPS 204 standards. For technical leads, the success of this rollout depends on avoiding downgrade attacks by strictly disabling legacy, quantum-vulnerable authentication mechanisms once the new ML-DSA certificates are deployed.
Additional Context
The rollout of ML-DSA (Module-Lattice-Based Digital Signature Algorithm) follows the August 2024 finalization of three key NIST standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). Per Quantum Computing Report (April 2026), the urgency for these upgrades has intensified following research from Google’s Quantum AI team and startups like Oratomic, which suggested a 20-fold reduction in the resources required to break current cryptographic standards. Major cloud providers have accelerated their timelines accordingly; for instance, AWS expanded its post-quantum support to Certificate Manager and Secrets Manager in early 2026, while Google transitioned internal traffic to ML-KEM by February 2026.
Industry leaders are now prioritizing authentication alongside encryption to counter 'harvest-now, decrypt-later' threats. Apple’s PQ3 protocol, introduced for iMessage in February 2024, set an early benchmark for at-scale post-quantum messaging, using periodic rekeying to maintain security. Per Fierce Network (April 2026), the NIST 2030 deadline for deprecating RSA has become a non-negotiable requirement for critical infrastructure procurement. This coordinated shift across Cloudflare, Google, and AWS indicates that the industry is moving toward a standard where post-quantum resilience is no longer a premium feature but a fundamental layer of the network stack.
Operational challenges remain, particularly regarding signature sizes. ML-DSA signatures range from 2.4 KB to 4.6 KB, significantly larger than classical ECDSA signatures. This overhead necessitated the April 2026 update to BoringSSL that Cloudflare utilized. According to Quantum Zeitgeist (May 2026), the next major milestone is the expected 2026-2027 finalization of FIPS 206 (FN-DSA), a compact lattice-based signature scheme designed for bandwidth-constrained environments like IoT and mobile streaming apps where ML-DSA's size might impact performance.
Read full article at blog.cloudflare.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source