UXP Security Server 1.26: faster performance and future-ready security with post-quantum cryptography

header

Unified eXchange Platform (UXP) is an industry-leading interoperability platform designed with distributed architecture and advanced cryptography, ensuring trust among stakeholders. Cryptography has been one of Cybernetica's most important focal points in ensuring integrity and resilience of e-governance solutions. Our solutions are built on modern cryptography – from interoperability and digital identity to privacy and maritime surveillance technologies.

With the threat of the conception of the quantum computer creeping in, Cybernetica has been dedicated to researching post-quantum cryptography since 2017. Additionally, we have already established a clear roadmap for the transition to post-quantum cryptography for our core products, including UXP.

The newly-released UXP 1.26 builds upon its native capabilities while leveraging Cybernetica's deep expertise in information security and cryptography. The core objective of this release is to help customers accelerate the speed of communication and lay the groundwork for the next era of cryptography.

HTTP/2 support: faster, smarter communication

As the foundational standard for all data moving over the web, HTTP impacts speed, reliability, and user experience. It is the universal protocol that defines how applications talk to servers. However, legacy HTTP/1.1 protocols are increasingly becoming a bottleneck for data exchange transiting through modern security infrastructure. They suffer from limitations like head-of-line blocking, where multiple requests cannot be processed efficiently over a single TCP connection, forcing subsequent traffic to wait in line. Additionally, older text-based headers introduce unnecessary overhead to every exchange.

UXP 1.26 addresses this with native HTTP/2 support. By enabling multiplexing, multiple requests and responses can now flow simultaneously over a single HTTP connection, reducing latency and improving throughput. Internal benchmarking shows a 50% average improvement in transaction processing speed compared to version 1.25.

HTTP/2 is now enabled by default for communication between security servers. It can also be used for connections with services and client applications and can be enabled for information systems through security server configuration parameters. We strongly recommend validating these connections in non-production environments to ensure compatibility before rolling out to production.

Post-quantum TLS: preparing for the quantum future

Although the threat that quantum computing poses to current encryption standards is on the distant horizon, its potential impact demands immediate attention and preparation to mitigate future risks. Rather than waiting for international post-quantum cryptography standards to be finalised, we recommend already taking a proactive approach to ensure the confidentiality of sensitive data. With "harvest now, decrypt later" attacks becoming a tangible threat, UXP 1.26 offers early access to Post-Quantum TLS feature, providing a practical means to begin testing immediately.

This allows organisations to test hybrid cryptographic approaches that combine classical and quantum-resistant algorithms. The feature is designed to address long-term security concerns regarding potential data leakage risks from quantum computing advances.

Note: As international post-quantum cryptography standards are still being finalised, this remains a non-default feature recommended only for testing in non-production environments. This early-access feature is designed for teams who want to get ahead of long-term data security risks — particularly those managing sensitive information that must remain protected well into the future. As the standards landscape continues to evolve, we'll be tracking developments closely and updating accordingly.

Ready to upgrade?

UXP Security Server 1.26 is available now. As always, we recommend starting upgrades on non-production instances before moving to production.

For upgrade guidance, reach out to your local partner or Cybernetica account manager.