Cloudflare targets 2029 for full post-quantum security (opens in new tab)
Cloudflare is accelerating its post-quantum security timeline and now aims to complete the transition by 2029, including post-quantum authentication. The company argues that recent advances in quantum algorithms, neutral-atom hardware, and error correction could bring “Q-Day”—when quantum computers can break today’s cryptography—as early as 2029–2030. While Cloudflare has largely addressed harvest-now/decrypt-later risks through post-quantum encryption, it now considers authentication the more urgent priority.
Cloudflare’s Post-Quantum Roadmap
- Cloudflare began preparing for post-quantum migration in 2019.
- It enabled post-quantum encryption for all websites and APIs in 2022.
- More than 65% of human traffic to Cloudflare is now post-quantum encrypted.
- The remaining challenge is upgrading authentication, including certificates, signatures, and access credentials.
- Cloudflare now targets 2029 for full post-quantum security.
New Evidence That Q-Day May Arrive Earlier
- Google announced a major improvement to an undisclosed quantum algorithm for breaking elliptic-curve cryptography.
- Google provided a zero-knowledge proof of the algorithm rather than revealing its details.
- Oratomic published estimates for breaking RSA-2048 and P-256 using neutral-atom quantum computers.
- Its estimate for P-256 requires only about 10,000 qubits.
- Important implementation details were intentionally omitted.
- These developments led Google to move its own migration target to 2029.
- Google has emphasized quantum-secure authentication, suggesting concern that Q-Day could arrive around 2030.
- IBM Quantum Safe’s CTO has said that “moonshot attacks” against valuable targets might be possible as early as 2029.
- Public progress estimates may become less reliable because researchers could stop disclosing details that would help adversaries.
Progress Across Three Quantum-Computing Fronts
Hardware
- Competing approaches include:
- Neutral atoms
- Superconducting qubits
- Ion traps
- Photonics
- Topological qubits
- Most approaches have made substantial progress, although none has yet demonstrated the scalability needed to break deployed cryptography.
- Neutral-atom systems appear particularly promising, and it would be risky to assume every competing approach will fail to scale.
Error Correction
- Quantum computers are inherently noisy and require error-correcting codes.
- Conventional superconducting systems may need roughly 1,000 physical qubits per logical qubit because of noise and limited connectivity.
- Neutral-atom systems offer highly connected, reconfigurable qubits that can use more efficient error-correcting codes.
- Oratomic estimates that only about 3–4 physical neutral atoms may be needed per logical qubit.
Quantum Software
- Improvements to quantum algorithms can substantially reduce the resources required to break cryptography.
- Google’s work reportedly accelerated attacks against P-256.
- Oratomic added architecture-specific optimizations for reconfigurable neutral-atom systems.
Why Authentication Requires Immediate Attention
- Post-quantum encryption primarily protects against harvest-now/decrypt-later attacks:
- Attackers collect encrypted traffic today.
- They decrypt it later after obtaining a capable quantum computer.
- This has been Cloudflare’s main focus since 2022.
- Authentication presents a different threat:
- Quantum computers could forge signatures, impersonate servers, or create unauthorized credentials.
- If Q-Day were decades away, deploying post-quantum authentication would provide little immediate benefit.
- If Q-Day could occur within a few years, authentication systems must be migrated before attackers can exploit them.
Cloudflare’s recommendation is to treat post-quantum migration as an urgent, multi-year project rather than waiting for quantum computers to become publicly available. Organizations should continue protecting stored data with post-quantum encryption while prioritizing the migration of authentication, certificates, and digital signatures before 2029.