Cloudflare Bolsters IPsec Against Quantum Downgrade Attacks
Cloudflare introduces a new IPsec protocol extension to defend against quantum downgrade attacks, ensuring connections default to post-quantum cryptography.

Cloudflare has developed and beta-released an extension for the Internet Protocol Security (IPsec) protocol designed to thwart quantum downgrade attacks. These sophisticated attacks aim to trick network endpoints into reverting to weaker, classical cryptographic standards, thereby rendering them vulnerable to decryption by future quantum computers. The new mechanism, developed in collaboration with the IETF, adds a crucial layer of downgrade protection to IPsec, ensuring that connections prioritize and default to post-quantum cryptography (PQC) even when they must maintain compatibility with older, classical cryptographic methods.
The global race to develop functional quantum computers presents a significant new threat to current cybersecurity infrastructure. While quantum computers promise advancements, they also possess the capability to break widely used classical encryption algorithms. The cybersecurity community is actively migrating to PQC, which is believed to be resistant to quantum computation. This migration involves replacing classical key agreement mechanisms like Diffie-Hellman with PQC alternatives such as ML-KEM, and classical signature schemes like ECDSA and RSA with PQC schemes like ML-DSA.
Despite the ongoing PQC migration, it will take years for all internet clients and servers to adopt these new standards. During this transition period, modern devices must continue to support classical cryptography to ensure interoperability with legacy endpoints. This necessity for backward compatibility, however, introduces a new risk: downgrade attacks. In such an attack, an on-path adversary can manipulate communication between two endpoints, tricking them into believing their peer does not support PQC, thereby forcing a fallback to weaker classical cryptography.
Cloudflare's new IPsec extension specifically addresses a design flaw within the IPsec protocol that enables a more advanced downgrade attack. This vulnerability, even when both classical and post-quantum authentication methods are supported, can allow an attacker to decrypt traffic between PQC-capable endpoints. While the attack requires a real-time quantum computation during the protocol handshake, making it difficult to execute currently, the rapid advancements in quantum computing capabilities necessitate proactive defense measures.
IPsec, which operates at the IP layer of the network stack, is a fundamental component of various Cloudflare products, including Cloudflare IPsec, Cloudflare WAN, and Magic Transit. Its low-level operation makes it deeply integrated into modern network infrastructure. Cloudflare utilizes IPsec to extend secure connections over its global network and to protect customer networks from threats like DDoS attacks.
To mitigate this specific quantum downgrade threat to IPsec, Cloudflare has implemented the IETF-developed extension. This extension requires support from both communicating parties to be effective. Cloudflare has rolled out beta support for this feature in its Cloudflare WAN and Magic Transit products, which customers can enable by requesting their account managers to activate the ipsec_downgrade_protection flag. The company is urging the broader IPsec ecosystem to adopt this crucial security enhancement.
The development and beta release of this IPsec extension underscore Cloudflare's commitment to securing internet infrastructure against emerging threats, particularly those posed by the advent of quantum computing. By proactively addressing potential vulnerabilities like quantum downgrade attacks, Cloudflare aims to ensure the continued security and integrity of internet communications during the critical transition to post-quantum cryptography.