- Implementation of hybrid key exchanges in TLS 1.3 using the JDK to mitigate quantum risks.
- Adoption of NIST-standardized algorithms such as ML-KEM and ML-DSA to protect data.
- Evolution of the JVM with improvements in memory management and concurrency to support modern workloads.
You've probably noticed that the world of cybersecurity is about to undergo a complete transformation. With the arrival of quantum computers, the methods we use today to encrypt information could become obsolete overnight, leaving our secrets exposed to anyone with sufficient computing power.
To avoid being caught off guard, the Java ecosystem has started moving quickly. It's no longer just about theory, but about implementing real solutions in the JDK so that companies can rest easy knowing their communications are protected against future threats.
The threat of "Collect now, decipher later"
There's a very specific risk with a rather unsettling name: harvest now, decrypt later . Essentially, some attackers are storing encrypted data today in the hope that, when they have a powerful quantum computer, they can open it like a can of preserves. This is a critical problem for data that needs to remain secret for decades, such as intellectual property or financial records.
To combat this, Post-Quantum Cryptography (PQC) has emerged. Unlike classical cryptography, which relies on mathematical algorithms such as the factorization of giant prime numbers, PQC uses algorithms designed to withstand the power of qubits, the basic unit of quantum computing, which allow for exponentially faster information processing thanks to superposition.
Java 27 and the hybrid exchange revolution
Oracle has taken a giant leap forward by integrating a hybrid key exchange system for TLS 1.3 into Java 27. The beauty of this approach is that it doesn't discard what already works, but rather combines conventional cryptography with post-quantum layers . Thus, if the new algorithm fails, we remain protected by the old one, and if the old one falls to a quantum attack, the PQC layer saves us.
This improvement comes via JEP 527, making it easier for enterprise applications to adapt without requiring drastic changes to their architecture. Because it's integrated directly into the JDK, it simplifies adoption in cloud services, APIs, and microservices that already use the TLS 1.3 protocol.
Key algorithms and NIST standards
It's not about reinventing the wheel, but about using what experts recommend. NIST has been evaluating candidates for years and has already approved algorithms such as ML-KEM, BIKE, HQC, and Frodo . These are the pillars that allow security to remain strong even as quantum computing advances by leaps and bounds.
Within the ecosystem, tools like Oracle Jipher 20 already offer compatibility with ML-KEM and ML-DSA, relying on OpenSSL modules validated under the FIPS 140-3 standard. This is crucial for those working in regulated sectors where governance and commercial support are mandatory.
Beyond security: JVM optimization
But Java hasn't just focused on quantum hackers; it's also taken the opportunity to clean house. Compact object headers are now enabled by default , reducing virtual machine memory consumption. For those managing containers or very lean instances, this can result in significant infrastructure cost savings.
In addition, significant performance improvements have been made:
- G1 as a memory collector default to avoid surprises in migrations.
- La structured concurrency (in its seventh preview) to better manage parallel tasks and prevent orphaned processes when something fails.
- La Vector API, which allows for accelerated artificial intelligence calculations and data analysis by leveraging the processor's hardware.
Looking to the future: Projects Valhalla and Leyden
If we want to talk about what's coming next, we have to mention early access to JDK 28. This is where Project Valhalla comes in, which aims to make Java objects much denser and more efficient , bringing them closer to the performance of primitive types. This is pure gold for financial or scientific computing applications that handle massive volumes of data.
On the other hand, Project Leyden focuses on making applications start up faster and reach peak performance in less time. All of this, combined with improvements in handling PEM encodings and the ability to clean sensitive data in Java Flight Recorder (JEP 536), makes Java a robust and modern platform.
The transition to a quantum-resistant world has already begun in the JDK, allowing organizations to test hybrid encryption while optimizing their resources through memory and concurrency improvements, ensuring their systems are not only fast, but virtually impenetrable to future technology.




