惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
T
Tailwind CSS Blog
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
P
Proofpoint News Feed
Simon Willison's Weblog
Simon Willison's Weblog
Microsoft Azure Blog
Microsoft Azure Blog
MongoDB | Blog
MongoDB | Blog
腾讯CDC
月光博客
月光博客
A
Arctic Wolf
T
Threatpost
Jina AI
Jina AI
博客园 - 聂微东
美团技术团队
V
V2EX
云风的 BLOG
云风的 BLOG
宝玉的分享
宝玉的分享
Recent Commits to openclaw:main
Recent Commits to openclaw:main
M
MIT News - Artificial intelligence
S
Secure Thoughts
Martin Fowler
Martin Fowler
Webroot Blog
Webroot Blog
V
Vulnerabilities – Threatpost
爱范儿
爱范儿
人人都是产品经理
人人都是产品经理
Help Net Security
Help Net Security
Google Online Security Blog
Google Online Security Blog
博客园 - Franky
The Last Watchdog
The Last Watchdog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
S
Schneier on Security
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Know Your Adversary
Know Your Adversary
Latest news
Latest news
有赞技术团队
有赞技术团队
AWS News Blog
AWS News Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Y
Y Combinator Blog
G
Google Developers Blog
NISL@THU
NISL@THU
H
Heimdal Security Blog
L
LangChain Blog
T
Troy Hunt's Blog
I
InfoQ
U
Unit 42
C
Check Point Blog
Engineering at Meta
Engineering at Meta

A10 Networks

Secure, High-Performance Networking Solutions | A10 Battling Bots, Fraud & AI Threats Summit | Retail IT & Cybersecurity What Is Healthcare Data Compliance? | A10 Networks Interop Best of Show Runner's Up - People's Choice | A10 Networks Interop Best of Show Runner's Up - Security for AI | A10 Networks What Is FIX Protocol Trading? | A10 Networks A10 Joins OpenAI's Trusted Access for Cyber Flexible Licensing for Multiple Clouds | A10 Networks A10 Acquires TrojAI to Advance Enterprise AI Security HFT Infrastructure: High Frequency Trading Explained | A10 Networks A10 Networks Acquires TrojAI Inc., Expanding AI Roadmap | A10 Networks What Is Low-latency Trading? | A10 Networks Multi-Vector DDoS: 11 Amplification Vectors | A10 Healthcare Cloud Compliance: HIPAA & GDPR Guide | A10 LLM Unbounded Consumption & DoS Attacks | OWASP LLM10 LLM Hallucination & Misinformation | OWASP LLM09:2025 Healthcare Network Protection for Hospitals & Clinics RAG Security: Vector & Embedding Weaknesses | OWASP LLM08 System Prompt Leakage | OWASP LLM07:2025 Explained LLM Excessive Agency | OWASP LLM06:2025 Explained LLM Supply Chain Security | OWASP LLM03:2025 Trust, Control and Security in the Age of Agentic AI Summit | A10 Networks LLM Improper Output Handling | OWASP LLM05:2025 Data Poisoning Attacks in LLMs | OWASP LLM04:2025 Sensitive Information Disclosure | OWASP LLM02:2025 Game Over for DDoS Attacks in Gaming | How to Achieve Resilience Prompt Injection | OWASP LLM01:2025 Explained Beyond PCI Summit: Battling Bots, Fraud, and AI-powered Threats Web Application Security Best Practices for 2026 | A10 Networks A10’s 5 Key Takeaways on Application & API Security Trends Securing Financial Applications in the AI Era Summit Unified Application Delivery, Security, and AI Protection for Financial Services The Most Famous DDoS Attacks in History Real-time DDoS Carpet-bombing: NTP Amplification Evasion Shadow AI | Glossary AI & LLM Security: Hype vs. Reality and What to Prioritize App Delivery in the Age of AI Summit | Hybrid & Cloud-Native Strategies A Day in the Life of a Stressed Web Application | ADC & WAF Resilience Avans University of Applied Sciences Modernizes Hybrid Application Delivery with A10 Networks Preparing Government Infrastructure for AI Adoption | Expert Summit Report: IDC Spotlight Report: Modernizing Application Delivery Infrastructure for AI-powered Applications Broken Object Level Authorization (BOLA): The #1 API Security Risk | Free Webinar | A10 Networks Product Demo: A10 AI Firewall by A10 Networks AI Firewall for Enterprise AI Security | A10 Networks API Traffic Management for AI and Agentic Systems | Expert Summit AI is Here: How Ready Is Your Infrastructure? | A10 Networks Pulse Campaign Analysis: Brazil ISPs Expose Next-Gen DDoS Automation Trends Tech Companies Lead GenAI Adoption but Face Infrastructure Gaps Cyber Defense Magazine's 2026 Global InfoSec award – Editor's Choice – API Security | A10 Networks Load Balancing Solutions for Availability & Security | A10 Networks Top 9 Generative AI Security Risks in 2026 LLM Security: Protecting AI Models & Applications
Post-quantum Cryptography Comes to A10 SSL/TLS Data Plane
Suman Rajaraman · 2026-05-08 · via A10 Networks

Hybrid KEM Support in ACOS 7.0.3

The U.S. National Institute of Standards and Technology finalized its first post-quantum cryptographic standards in 2024. While large-scale, cryptographically relevant quantum computers may still be years away, the security decisions we make today must account for tomorrow’s threats. One of the most serious cyber threats is “harvest now, decrypt later,” where encrypted traffic is captured today and stored for future decryption. This risk arises because current public-key cryptography can be broken by future quantum computers. Post-quantum cryptography and hybrid key exchange are required now to ensure long-term data confidentiality.

To address this reality, we are launching a software platform built from the ground up around the NIST-standardized post-quantum algorithm, hybrid post-quantum cryptography (PQC) support in Advanced Core Operating System (ACOS) 7.0.3, enabling customers to begin their PQC transition now, without waiting for new hardware or ecosystem maturity.

Why Post-quantum Cryptography Matters Now

Conventional public‑key cryptography relies on mathematical problems that are difficult for classical computers to solve but are expected to become vulnerable with the rise of quantum computing—putting widely used algorithms such as RSA and elliptic‑curve cryptography at long-term risk.

Post‑quantum cryptography addresses this threat by introducing quantum resistant algorithms designed to protect data against future quantum adversaries.

Rather than abruptly replacing proven cryptographic methods, A10 implements the industry standard which is a hybrid KEM approach, combining classical and post‑quantum algorithms in parallel. With both key exchanges executed simultaneously, an attacker would need to break both to compromise a session.

For SSL/TLS, A10 prioritizes key establishment, as the security of the entire session ultimately depends on the strength of the key exchange. Even the strongest encryption and authentication mechanisms cannot protect a session if the key exchange itself is compromised—making hybrid KEM the most practical and secure first step toward quantum resilience.

PQC Strategy in ACOS 7.0.3

With ACOS 7.0.3, A10 introduces hybrid KEM support in the SSL/TLS data plane using OpenSSL 3.5.

  • Post‑quantum Key Exchange: Establishes encryption keys using hybrid mechanisms that pair classical cryptography with postquantum algorithms to remain secure even against future quantum computers.
  • Elliptic‑curve Cryptography (Classical Component): Provides proven, efficient cryptographic security today and serves as a trusted component within hybrid post-quantum designs during the transition to quantum‑safe standards.
  • Hybrid Key Establishment Algorithms Supported
    • X25519 + ML‑KEM‑768
    • secp256r1 + ML‑KEM‑768
    • secp384r1 + ML‑KEM‑1024
Client-side SSL (7.0.3)Server-side SSL (ACOS 7.0.3)
PQC enabled by defaultCrypto-agile by design using dual-key share model
Cryptographic preference order:
  • X25519 + ML-KEM-768 (hybrid KEM)
  • X25519
  • secp256r1
  • secp384r1
  • secp521r1
Configure both hybrid KEM and legacy groups using same classical curve
Auto negotiates the strongest supported groupBack-end servers can select either hybrid or legacy key share during the TLS handshake
Administrators can explicitly control behavior using supported-group configuration under SSL templateNo additional handshake messages, preserving performance and saving one RTT
Operationally simple and transparent to existing clientsEnables seamless coexistence for mixed client/server population during PQC transition
Provides immediate PQC protection for inbound TLSAllows gradual, risk-managed PQC rollout without compatibility penalties

This enables PQC adoption without new hardware, allowing customers to:

  • Begin PQC testing and validation immediately
  • Gain operational experience with PQ algorithms

And align with evolving NIST standards while maintaining production safety.

Preparing for a Moving Target—Safely

Post-quantum cryptography is not a single event. It’s a journey. Algorithms will evolve. Standards will change. Some candidates may be deprecated.

A10’s philosophy is simple:

  • Start with software
  • Adopt hybrid models
  • Preserve crypto agility

With software based PQC support in ACOS 7.0.3, A10 customers can confidently begin their post‑quantum journey today—without disrupting existing deployments or betting on unproven assumptions.



Suman Rajaraman