Post‑Quantum Migration: Cloudflare Deploys ML‑KEM Encryption and ML‑DSA Signatures
Patch TLS to use ML‑KEM encryption and ML‑DSA signatures for post‑quantum security and monitor for upcoming signature standards.
Migrate TLS to ML‑DSA signatures and monitor for upcoming signature standards to ensure post‑quantum security.
Summary
Cloudflare has begun migrating to post‑quantum cryptography by deploying ML‑KEM encryption for TLS connections and ML‑DSA signatures to protect authentication systems.
ML‑KEM is already in use for the majority of traffic, shielding data from harvest‑now‑decrypt attacks, while ML‑DSA, the NIST‑standardized lattice‑based signature scheme, provides quantum‑resistant authentication.
Although ML‑DSA is larger on the wire and lacks some RSA/ECC tricks, it is the current baseline for signing and verification. NIST has announced several other signature schemes in the third round, but ML‑DSA remains the only standardized option until further standards are finalized.
Cloudflare targets full post‑quantum security by 2029 and is monitoring upcoming signature standards such as FN‑DSA, ensuring that the migration to ML‑DSA is performed now while future options are evaluated.
Key changes
- ML‑KEM encryption already protects majority of traffic
- ML‑DSA signatures deployed to secure authentication
- ML‑DSA is NIST‑standardized and quantum‑resistant
- ML‑DSA larger on wire but baseline for signing and verification
- Other NIST third‑round signatures announced but not yet standardized
- Target 2029 for full post‑quantum security
- Migration to ML‑DSA needed now due to quantum threat
- Monitoring for future standards like FN‑DSA