SYSTEM Cited by 1 source
Cloudflare Automatic Key Exchange¶
What¶
Automatic Key Exchange (announced 2026-09-08) is a Cloudflare feature — an extension of Automatic SSL/TLS — that eliminates wasted TLS-1.3 round trips on the Cloudflare → origin hop by replacing a static key-agreement guess with a per-origin measurement. Cloudflare, acting as the TLS client to the origin, previously always led with a classical X25519 keyshare in its first ClientHello (see predictive key exchange). When the origin preferred another group it replied with a HelloRetryRequest, costing a second round trip. Automatic Key Exchange scans each origin, learns which groups it supports, and leads with the strongest — preferring the post-quantum hybrid X25519MLKEM768 — so post-quantum origin handshakes complete in one round trip with no customer configuration. (Source: sources/2026-09-08-cloudflare-automatic-key-exchange-faster-post-quantum-secure-origin-han)
Why it exists¶
TLS 1.3 requires committing to a key-agreement group and sending a keyshare in the first packet. A static X25519 guess was safe (>95% of origins support X25519) but suboptimal for ~30% of origins, and it forced every post-quantum-capable origin through an HRR because PQ was only advertised, not led with. Leading with a PQ keyshare directly was blocked by size: an X25519MLKEM768 keyshare is 1,216 bytes vs X25519's 32 bytes, pushing the ClientHello past one packet, and ~0.34% of origins fail on a split ClientHello. Automatic Key Exchange resolves this by measuring per-origin capability out-of-band, so it only leads with PQ where the origin and the network path are confirmed to handle it.
How it works¶
- Active out-of-band probing. For each TLS 1.3 origin, run a few lightweight handshakes, each offering exactly one group (X25519, P-256, P-384, P-521, X25519MLKEM768). Off the production path, so origin + network are confirmed before real traffic depends on the stronger group. This is the measure-don't-guess pattern — passive observation can't reveal full capability because origins often accept X25519 without signalling PQ preference.
- Per-subdomain, traffic-weighted aggregation. Each subdomain (which may
resolve to a different origin) is evaluated independently and weighted by
actual HTTP traffic, so busy
www/apiendpoints dominate the domain-wide preference. - Strict priority selection. X25519MLKEM768 → then fastest accepted classical (X25519 → P-256 → P-384 → P-521).
- Monitored progressive rollout with rollback. New preference ships to a small traffic slice while HRR/failure rate is watched; if retries exceed the origin's baseline, roll back. Worst case = one extra round trip, never a broken connection — same revert discipline as Automatic SSL/TLS encryption- mode upgrades. See patterns/staged-rollout.
- Daily rescan. Origins change (new load balancer, TLS library ships PQ, operator disables a curve); rescanning daily re-derives the preference.
Compliance requirements (intent-based)¶
A new control restricts what Automatic Key Exchange may negotiate:
- Post-quantum hybrid — X25519MLKEM768 only; every successful TLS 1.3 origin connection is guaranteed PQ-secure (removes classical groups entirely).
- FIPS — FIPS-compliant groups only.
Selecting both requires an algorithm satisfying both; no overlap → config rejected. You configure intent, so the algorithm set stays current as standards evolve. Footgun: enforcing PQ-hybrid on an origin lacking X25519MLKEM768 leaves no mutual algorithm → all TLS 1.3 connections fail; Cloudflare advises leaving both unset absent a hard policy mandate.
Impact (measured)¶
- HRR on scanned origins 52% → 3.7%; >150 ms off p90 handshake latency.
- PQ origin handshakes completing in one round trip 0% → 99.2%.
- PQ origin traffic ~25B → 45B connections/day.
- Preference assigned to >1 million domains so far (~9,000 more/day move off X25519, nearly all to PQ). First cohort: 64% stayed X25519, 33% → X25519MLKEM768, 3% other classical curve.
Particularly benefits dynamic requests and CDN cache misses that need a fresh origin TLS connection; keep-alive traffic is unaffected.
Roadmap¶
- Per-origin/per-subdomain preference granularity (today decisions are domain-level, so one weak origin holds a whole domain back).
- On-demand rescans from dashboard/API + as a diagnostic tool.
- Automatic PQ origin authentication — extend scanning to detect ML-DSA cert (later Merkle Tree Certificates) support and auto-disable classical fallback to close the downgrade gap.
Seen in¶
- sources/2026-09-08-cloudflare-automatic-key-exchange-faster-post-quantum-secure-origin-han — launch/announcement post. Full mechanism (5-step probe → weight → select → monitored rollout → daily rescan), the 1,216-vs-32-byte keyshare cliff, the compliance controls, and the 52%→3.7% / 0%→99.2% / 25B→45B numbers.
Related¶
- systems/cloudflare-automatic-ssl-tls — parent product + shared scanning pipeline.
- systems/cloudflare-universal-ssl — 2014 free-TLS precedent in the same default-on arc.
- tls-1-3-predictive-key-exchange — the guess this optimizes.
- hello-retry-request — the round trip it eliminates.
- concepts/post-quantum-cryptography — the X25519MLKEM768 construction preferred.
- concepts/harvest-now-decrypt-later — the threat PQ key agreement defeats.
- measure-dont-guess-via-active-probing — the core pattern.
- patterns/default-on-security-upgrade — the posture it embodies.
- companies/cloudflare — the operator.