BT

Facilitating the Spread of Knowledge and Innovation in Professional Software Development

Write for InfoQ

Topics

Choose your language

InfoQ Homepage News Cloudflare Plans Public Certificate Authority to Issue Quantum-Safe TLS Certificates

Cloudflare Plans Public Certificate Authority to Issue Quantum-Safe TLS Certificates

Listen to this article -  0:00

Cloudflare announced plans to operate a free public Certificate Authority designed to issue quantum-safe Transport Layer Security certificates. The initiative tackles one of the most critical structural bottlenecks facing modern web infrastructure, namely the impending transition away from classical public key cryptography. While post-quantum key exchange algorithms have already seen active production rollouts, post-quantum authentication across the Web Public Key Infrastructure has lagged due to the immense payload size of quantum-resistant digital signatures. By coupling standard X.509 issuance with emerging Merkle Tree Certificates, the platform aims to provide enterprise engineering teams and site operators with backwards-compatible, low-latency quantum resistance ahead of production trust-store deadlines.

Current internet authentication depends almost entirely on classical asymmetric primitives such as RSA and elliptic-curve cryptography. In a post-quantum environment, algorithms standardised by the National Institute of Standards and Technology, including ML-DSA and Falcon, protect against cryptanalytic attacks powered by Shor's algorithm. However, these post-quantum signatures and public keys require dramatically more data than their classical predecessors.

Directly substituting post-quantum signature algorithms into traditional hierarchical X.509 certificate chains inflates the volume of cryptographic handshake data by roughly forty times. In practical terms, exchanging multi-kilobyte certificate chains during every initial TLS connection causes acute TCP segmentation, triggers packet loss on constrained networks, and forces extra round-trip times during the handshake phase. Furthermore, Certificate Transparency logs, which record every publicly trusted certificate issued by a Certificate Authority, would experience severe operational strain under the sheer weight of these enlarged signatures.

To circumvent this scaling penalty, Cloudflare's new public authority embraces Merkle Tree Certificates, an alternative authentication model currently advancing within the IETF PLANTS working group. Rather than signing each server certificate with an isolated, individual signature from an intermediate authority, the system batches certificate issuances into an append-only Merkle tree structure.

Generated with Gemini based on information present in the Cloudflare blog post

The architectural premise behind Merkle Tree Certificates redefines the relationship between certificate creation and public transparency. In the conventional Web Public Key Infrastructure, a Certificate Authority generates an X.509 certificate and asynchronously submits it to third-party Certificate Transparency logs to obtain Signed Certificate Timestamps. Under the Merkle Tree Certificate model, issuance and logging become a single unified process. The Certificate Authority logs an entry by inserting it into a tree, and the certificate itself consists of an inclusion proof referencing a signed tree head.

Because the Certificate Authority signs only the root of the Merkle tree with a post-quantum signature, individual leaf nodes rely on compact cryptographic hashes. Instead of delivering multiple heavy signatures over the wire, a server presents its leaf entry alongside an authentication path of intermediate hashes measuring logarithmic in size relative to the total tree depth. To optimise transmission further, clients and browsers can cache synchronised tree head checkpoints, termed landmarks. When a client already trusts a recent landmark, the server only transmits the truncated inclusion proof between its leaf and that landmark, bringing handshake payload sizes down to parity with legacy elliptic-curve connections.

Cloudflare's implementation issues certificates in a hybrid arrangement. Edge endpoints receive both a traditional X.509 certificate and an accompanying Merkle Tree Certificate. During the TLS negotiation, modern clients that indicate support for Merkle Tree Certificate authentication receive the compact tree-based proof, whereas legacy clients fall back seamlessly to the standard X.509 certificate chain.

Generated with Gemini based on information present in the Cloudflare blog post

Following production experiments conducted in partnership with the Google Chrome engineering team, Cloudflare observed that the architecture successfully maintained low handshake latency while preserving full auditable transparency. Mari Galicer, who detailed the initiative for Cloudflare, highlighted that making logging an architectural prerequisite of issuance prevents untracked certificates from entering circulation.

For enterprise teams, transitioning to post-quantum transport security involves navigating significant architectural trade-offs. Merkle Tree Certificates alter how certificate revocation and validity intervals operate. Because Merkle tree heads update at a continuous cadence, certificates are tied to short-lived validity windows, aligning with industry pushes toward shorter certificate lifespans and automated renewal pipelines such as ACME.

Cloudflare plans to open standard issuance at no charge to all web properties, with broad public issuance targeting early 2027 to coincide with root store inclusions. As client-side ecosystems like Chrome's Quantum-resistant Root Store mature, infrastructure engineers must audit automated certificate managers, verify client-side cryptographic library compatibility, and prepare internal edge topologies for hybrid verification schemes.

About the Author

Rate this Article

Adoption
Style

BT