Cybersecurity

Cloudflare Develops Protection for the IPsec Protocol Against Quantum Encryption Downgrade Attacks

Cloudflare worked with the IETF’s IPSECME team to develop an extension that authenticates the complete IKEv2 session transcript, aiming to prevent an attacker with a quantum computer from downgrading an IPsec tunnel to weaker traditional encryption. The company launched experimental support for the extension in Cloudflare WAN and Magic Transit through optional account-level activation.

2026-09-29
4 min read
8 views
certi.news Editorial Team
Cloudflare Develops Protection for the IPsec Protocol Against Quantum Encryption Downgrade Attacks

Cloudflare announced experimental support for a new mechanism that protects IPsec tunnels from attacks that downgrade encryption to traditional algorithms, a class of attacks that could allow an attacker with a quantum computer to decrypt communications between two endpoints that originally support post-quantum encryption. The company developed the mechanism in cooperation with the IETF’s IPSECME team, in preparation for turning it into an RFC standard.

The protection targets an extension to the IKEv2 protocol called IKE_SA_INIT_FULL_TRANSCRIPT_AUTH. The extension addresses a flaw in IPsec’s design that allows each party to sign only its outgoing messages instead of signing the complete handshake transcript. As a result, an attacker who controls the communication path can create what resembles “two separate views” of the conversation: one seen by the client and another seen by the other endpoint.

How does the downgrade risk arise?

IKEv2 allows negotiation of the use of post-quantum key exchanges, such as ML-KEM, while retaining support for traditional encryption to maintain compatibility with devices that have not yet been updated. A man-in-the-middle attacker can modify negotiation messages so that one endpoint believes the other does not support post-quantum encryption, causing a traditional Diffie-Hellman exchange to be selected.

In the quantum scenario, the attacker can use its ability to break the Diffie-Hellman exchange to recover the encryption key for subsequent handshake messages. The source describes the attack as relatively difficult because it requires performing the quantum computation during the handshake, rather than offline as in “harvest now, decrypt later” attacks. Nevertheless, Cloudflare believes that accelerating estimates of the resources required for quantum attacks justify early preparation, and these concerns led it to bring forward its transition date to 2029.

What does the extension change?

The extension adds authentication for the entire handshake transcript. The two endpoints announce their support through a notification message sent unconditionally during the initial exchange. If one endpoint sees the support notification, it switches to the new authentication logic and expects the other endpoint to sign the same transcript.

Sending the notification unconditionally prevents some attempts to remove it in transit. If the attacker removes the notification from one side, the two endpoints will use different signing logic, causing authentication to fail. If the attacker removes the notification from both sides, the endpoints will fall back to the old logic, but carrying out a successful attack will require the attacker to forge both endpoints’ signatures, rather than only one endpoint’s signature.

Availability and practical limitations

Cloudflare implemented experimental support in Cloudflare WAN and Magic Transit, and customers can request activation through their account management teams using the ipsec_downgrade_protection flag. In a later description of the activation mechanism, the company indicates that the feature is controlled by an account-specific flag and that it will expand activation to all customers after the experimental tests end.

The extension requires support from both endpoints to be effective, and Cloudflare has therefore kept activation optional in anticipation of customers or IKEv2 implementations that do not handle the new protocol notification correctly. The announcement therefore does not represent an immediate solution for all IPsec tunnels, but rather a transitional step that depends on the rest of the IPsec ecosystem adopting the extension and on its completion of the IETF process.

Why does this news matter?

The development shows that the transition to post-quantum encryption is not limited to adding new algorithms such as ML-KEM or ML-DSA; the negotiation and authentication mechanisms themselves may allow this protection to be bypassed if the endpoints do not prove that they saw the same handshake. For organizations that use IPsec for network interconnection or infrastructure protection, monitoring extension support among service providers and endpoint equipment becomes part of planning the post-quantum transition, while the date on which a practical quantum attack will become feasible remains uncertain.

News source
Cloudflare Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news