AI NewsInfrastructureAnnouncement

Cloudflare built an AI tool called CryptoLabe to find cryptography in its own code before its 2029 post-quantum migration deadline

Cloudflare published a post on 29 September describing CryptoLabe, an internal tool that uses AI models to find where cryptography sits in its own codebase, so it can migrate to post-quantum algorithms by 2029.

AI News

Editorial3 min read

LinkedInX
Cloudflare blog card for the CryptoLabe post on AI-driven cryptography discovery

Image: Cloudflare

Why it mattersA team that needs to know where its code uses RSA, ECDSA or classical key exchange can borrow this pattern, because grep for algorithm names both overcounts unused code and misses defaults hidden in dependencies.

An engineer who wants to migrate a large codebase off classical cryptography before quantum computers arrive faces a first question that grep cannot answer on its own. Cloudflare published a post on 29 September describing CryptoLabe, an internal tool it built to answer that question with AI models, ahead of its 2029 target for full post-quantum readiness.

Cloudflare gives three reasons a text search will not do this job on its own. Cryptography is scattered across many repositories. It rarely announces itself with a plain algorithm name. And even when it does, matching on words like "RSA" or "X25519" overcounts unused code and undercounts defaults hidden in dependencies and configuration files. A classical ECDSA signature could sit inside a JWT, IPsec, TLS or SSH, and each has a completely different migration path.

What the tool does at each stage

CryptoLabe runs in two stages. The first stage maps a repository, then searches source, configuration, manifests, lockfiles, scripts, tests and documentation for uses of key agreement, signatures, asymmetric encryption, PKI, tokens and credentials. It returns raw observations. The second stage rechecks each observation against the source, follows the use across other repositories where needed, and passes over its own conclusions to look for missing or conflicting evidence.

The model then classifies each finding. Cloudflare lists categories including Classical encryption for ECDHE and RSA key agreement broken by Shor's algorithm; Classical signature for any RSA or ECDSA signature; Classical token as a special class for RS256 and ES256 JWTs, which RFC 9964 defines a post-quantum replacement for; PQ-ready hybrid key exchange, which covers X25519MLKEM768 in TLS 1.3 and is the most common post-quantum cryptography in its codebase; and PQ-ready for other post-quantum uses. When the evidence is thin, the model returns "More evidence needed", "External dependency" or "Unknown" rather than guessing.

How the model actually reads the code

CryptoLabe sits inside two Cloudflare Workers: a scanner Worker that reads code and an inventory Worker that serves a dashboard and stores results in D1. Each Workflow restores a snapshot of a repository at an exact commit into a short-lived Cloudflare Sandbox, and the model interacts with the code through a small set of read-only tools. The isolation is there so the model cannot damage the codebase and so a scan reads the same state even if the repository changes mid-scan. Requests go through AI Gateway to open-weight models hosted on Workers AI, and a single global Durable Object paces every model request across every scan, so a shared cooldown replaces independent retries that would otherwise make a rate limit worse.

The tool also groups findings by prerequisites. If a JWT migration needs libraries that can validate a post-quantum JWT, or a token issuer that can produce one, every affected repository sits in one bucket with a shared blocker, so Cloudflare can decide which prerequisites to invest in first. A separate, shorter prompt runs across all repositories at once to find "hard cases": custom cryptographic constructions, size-constrained fields carrying certificates, and protocols with no post-quantum standard.

Cloudflare is keeping CryptoLabe internal, since the tool is tied to its own repositories, ticketing system and documentation. It has published selected prompts so other teams can adapt the pattern, and it advises most organisations to start with the systems whose compromise would matter most rather than scanning every repository at once. For teams already routing traffic through Cloudflare, its post-quantum encryption at the edge acts as a compensating control during discovery.

Source

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX