
Cloudflare said this week it intends to issue TLS certificates resistant to quantum computing attacks, positioning itself among the earliest certificate authorities to deploy such technology. The company will operate an open source platform capable of issuing both conventional TLS certificates and post-quantum variants called Merkle Tree Certificates. These hybrid certificates will be available at no cost to all users, whether they pay for Cloudflare services or not. To facilitate deployment at scale, Cloudflare is acquiring a trusted certificate root from CA GlobalSign, enabling millions of websites to adopt post-quantum certificates with minimal effort and without performance degradation.
The initiative represents a critical component of a broader modernization of the web public key infrastructure needed to secure online communications in an era when quantum computers may pose significant threats. A fundamental challenge involves implementing quantum-proof signatures that remain compact enough for transmission during web requests and suitable for recording in transparency logs that verify legitimate certificate issuance. This comprehensive transformation will require sustained effort from numerous engineers across multiple sectors, including those developing operating systems, browsers, certificate authorities, and internet infrastructure platforms.
Quantum-resistant versions of standard X.509 certificates would expand the data required during TLS handshakes by approximately 40 times, creating computational and bandwidth demands that would render current internet systems impractical. Google proposed Merkle Trees as a solution earlier in the year, utilizing hierarchical data structures based on cryptographic hashing to verify extensive information using minimal data. Testing conducted jointly by Google and Cloudflare in pilot programs demonstrated that this approach reduces handshake data to approximately 40 kilobytes, comparable to current levels. Rather than relying on chains of quantum-vulnerable signatures, this architecture replaces them with compact Merkle Tree proofs, where certificate authorities sign a single tree head representing millions of certificates.
Transparency and logging mechanisms represent another critical element. Certificate transparency requirements emerged following the 2011 breach of DigiNotar, which resulted in over 500 counterfeit certificates. Under the proposed system, logging becomes integral to certificate issuance rather than a separate process, ensuring transparency functions as an operational requirement. Cloudflare’s implementation will incorporate ACME, an open source protocol for automated certificate management and renewal, alongside provisions for out-of-band signature delivery when technical issues prevent standard updates. The company expects to commence certificate issuance during the first quarter of 2027.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI