Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)
Cloudflare has introduced Automatic Key Exchange to proactively probe TLS 1.3-capable origins for supported key agreement algorithms. The system now automatically prioritizes post-quantum cryptographic algorithms during the TLS handshake process.
Verified State Diff
Impact & Verification Analysis
Cloudflare customers utilizing TLS 1.3-capable origin servers.
This feature reduces handshake latency and provides automated, transparent migration to post-quantum cryptography, significantly improving long-term data confidentiality for enterprise traffic.
Full Fact Overview
Automatic Key Exchange functions as an intelligent negotiation layer between Cloudflare's edge network and customer origin servers. By performing background probes to identify supported key exchange mechanisms, the system eliminates the latency overhead of traditional fallback negotiations. By prioritizing post-quantum algorithms, Cloudflare is hardening the transit layer against future 'harvest now, decrypt later' attacks, effectively upgrading the security posture of the origin-to-edge connection without requiring manual configuration from the customer.