Back
Cloudflare and IETF ship IPsec protection against quantum downgrade attacks
SiTech AI Team3 წთ. საკითხავი

Cloudflare and IETF ship IPsec protection against quantum downgrade attacks

Cloudflare has worked with the IETF on a new IKEv2 extension that stops an attacker from downgrading an IPsec connection to classical cryptography. Beta support is live in Cloudflare WAN and Magic Transit.

For Birthday Week, Cloudflare announced it worked with the IETF to add protection against quantum downgrade attacks to IPsec, one of the Internet's core security protocols, and has rolled out beta support in its IPsec products.

The industry is migrating to post-quantum (PQ) cryptography: Diffie-Hellman key agreement is giving way to mechanisms such as ML-KEM, while classical signatures like ECDSA and RSA are replaced by PQ schemes such as ML-DSA. Until every client and server is upgraded, devices must still support classical cryptography.

That compatibility opens the door to a downgrade attack: an on-path attacker rewrites the messages between two endpoints so each side believes its peer does not support PQ, pushing the connection back to classical algorithms a quantum computer could eventually break.

A design flaw in IPsec

Adding PQ primitives alone is therefore not enough. Like TLS, IPsec is vulnerable to a simple downgrade, but Cloudflare found a more sophisticated variant that works whatever authentication method is used. In IKEv2, each party signs only its own outbound messages, not the full handshake transcript as in TLS 1.3. An attacker can exploit that split view to make the endpoints see different conversations and decrypt traffic between PQ-capable devices.

The attack is hard to pull off: the quantum computation must run online, during the handshake, unlike harvest-now, decrypt-later threats, which are offline. Even so, Cloudflare has moved its post-quantum transition deadline up to 2029, as estimates for attacking public-key cryptography fell sharply.

Full transcript authentication

With the IETF's IPsec Maintenance (IPSECME) working group, Cloudflare developed an IKEv2 extension called IKE_SA_INIT_FULL_TRANSCRIPT_AUTH that adds full transcript authentication. Instead of signing only outbound messages, each endpoint signs the whole transcript and expects the same from its peer.

Support is signalled with a notify message in the initial exchange, sent unconditionally: the initiator always notifies, and the responder notifies even if the initiator did not. If an attacker drops it from one side, the parties fall back to different authentication logic, the signatures do not match, and authentication fails with an AUTHENTICATION_FAILURE. Dropping both would force the attacker to forge signatures from both endpoints.

Availability and next steps

The feature sits behind a flag scoped to each customer account: customers can ask their account team to enable `ipsec_downgrade_protection`, and Cloudflare plans to switch it on for all accounts after beta testing. Support is already live in Cloudflare WAN and Magic Transit.

The extension is on track to become an RFC, and co-author Valery Smyslov also spotted the trick that makes it downgrade-resistant. The flaw behind the IPsec downgrade has been known for at least ten years, and Cloudflare argues other protocols in use today may harbour similar latent bugs.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.