Quantum Computing

How Cloudflare Uses AI to Map the Migration to Post-Quantum Cryptography

Cloudflare is developing an internal tool called CryptoLabe to discover uses of cryptography in its repositories and measure its readiness to transition to post-quantum cryptography by 2029. The experiment reveals that AI can track indirect uses and dependencies, but its results require review by engineers, and the tool is not available to customers.

2026-09-29
5 min read
5 views
certi.news Editorial Team
How Cloudflare Uses AI to Map the Migration to Post-Quantum Cryptography

Cloudflare is working toward full readiness for post-quantum cryptography by 2029, using an AI-powered internal tool called CryptoLabe for this task. Its function is not merely to search for the names of known algorithms, but to discover where cryptography is used in code, configurations, and dependencies, then interpret its role and determine what is needed to upgrade it.

The company says it has moved a large number of its products to post-quantum cryptography through TLS 1.3, but it is still working to cover the remaining communications and support post-quantum authentication. Cloudflare is adopting an approach it describes as “post-quantum cryptography for everything,” given its role as an infrastructure provider, with the aim of protecting customer traffic from future quantum-computing threats.

Why Is Text Search Not Enough?

The inventory process faces three main problems: code is spread across a large number of repositories; cryptography is hidden inside shared libraries or configurations far from the code that invokes it; and test or abandoned paths may produce misleading results. Searching for terms such as RSA or X25519 may also overestimate actual uses or miss indirect uses and protocol defaults.

The appearance of an ECDSA signature, for example, does not identify the required migration path; it may be used in JWT, TLS, SSH, or IPsec, and each case has different dependencies and steps. The algorithm choice may also depend on the other party in the connection, not solely on the server configuration.

How Does CryptoLabe Work?

The tool divides its work into discovery and analysis phases. The first phase begins by mapping the repository and searching the code, configuration files, metadata, lockfiles, tests, and documentation. This process produces initial findings about key exchange, signatures, asymmetric encryption, PKI, tokens, hardware security module environments, and other areas.

In the second phase, the model reexamines each finding against the code and tracks its use during execution, the repository’s role, and the internal and external parties that depend on it. It also looks for conflicts or missing evidence, such as configuration overrides or test code, and then classifies the result. When sufficient evidence is absent, it uses classifications such as “needs more evidence,” “external dependency,” or “unknown” instead of guessing.

Current classifications include conventional encryption, signatures, and tokens; hybrid key exchange ready for the post-quantum era; and other ready uses. Examples include X25519MLKEM768 in TLS 1.3 and JWT tokens based on RS256 or ES256, for which Cloudflare indicates that a post-quantum alternative exists using ML-DSA under RFC 9964.

What Changes in Practice?

CryptoLabe runs on Cloudflare Workers, with one worker for scanning and another for the inventory, dashboard, and D1 database, and they communicate through Service Bindings. Each repository uses a continuous coordinator built on a Durable Object, while Cloudflare Workflows manages the discovery, analysis, merging, and publishing stages, with resume and retry capabilities.

The tool downloads the repository at a specific revision and stores a snapshot of it in R2, then restores it inside an isolated Cloudflare Sandbox with read-only tools. This helps stabilize the scan result even if the repository changes during execution. To control cost and capacity, model requests pass through AI Gateway to open-weight models hosted on Workers AI, with a global Durable Object coordinating requests and sharing cooldown periods when 429 rate-limit errors appear.

Obstacles the Tool Cannot Solve on Its Own

Cloudflare uses the concept of “prerequisites” for cases that a product team cannot solve on its own, such as when a particular library lacks support for post-quantum JWT tokens or when the token issuer cannot produce them. The tool also looks for “hard cases,” such as custom protocols, cryptography embedded in hardware, limited-size fields, and dependence on external parties that do not yet support post-quantum cryptography.

One example the company found was a certificate sent inside an HTTP header; the larger size of post-quantum certificates and signatures could break an application or intermediary’s assumptions about the maximum size. This case shows that migration is not always a matter of replacing one algorithm with another, but may require measuring system limits and examining the entire usage path.

certi.news’s Take

The practical value of Cloudflare’s experiment is that it transforms post-quantum migration from a list of algorithms into a process for managing dependencies and risks. However, the source acknowledges important limitations: the company does not yet have a reference dataset for comparing the performance of different prompts in a reproducible manner, it does not guarantee coverage of all uses, and every result requires review by the engineers responsible for the system.

Cloudflare therefore does not recommend starting with a comprehensive inventory of every repository. The proposed path is to select an important system that handles sensitive or long-term data, authenticates users, or is exposed to the internet; discover its uses; verify the results with the responsible team; and determine what can be upgraded and what is blocked by shared dependencies. CryptoLabe itself is not a product available to customers, but an internal experiment whose lessons and some prompts Cloudflare is publishing as starting points for other organizations.

News source
Cloudflare Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news