Cloudflare announced Tuesday its intention to issue quantum-proof TLS certificates, positioning itself as one of the first authorities to offer such certificates. These certificates utilize a form of cryptography believed to be resistant to quantum computer attacks.
The internet infrastructure provider stated it will employ an open-source platform that issues both traditional TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. These hybrid certificates will be provided free of charge to all users, both paying and non-paying. To facilitate the widespread adoption of this system and ensure its ubiquity within the TLS ecosystem, Cloudflare is acquiring a pre-trusted certificate root from CA GlobalSign. This acquisition, according to Cloudflare, will enable millions of websites to adopt post-quantum certificates with minimal effort and no additional performance impact.
Fundamental architectural changes ahead
Cloudflare's initiative is part of a significant overhaul of the Web Public Key Infrastructure (WebPKI) necessary to secure website encryption and authentication for the impending post-quantum era. A primary challenge involves developing quantum-proof signatures that can be efficiently transmitted during web requests and logged in transparency logs to prevent the issuance of counterfeit certificates for websites. This transformation is expected to take years, requiring the efforts of numerous engineers involved in designing operating systems, browsers, certificate authorities, and internet infrastructure.
"We are not issuing certificates yet, and it will be a little while before we do," wrote Cloudflare's Steve Goldsmith. "What we are doing is committing to the work in public, sharing the milestones as they land, and telling you exactly what we are building while working with the root programs and other members of the WebPKI community to achieve this."
Protecting the WebPKI from quantum threats is a complex task that necessitates fundamental architectural changes, rather than merely replacing algorithms. Quantum-proof versions of current X.509 certificates would increase the data required for a TLS handshake—which occurs every time a new session is established between a browser and a server—by approximately 40 times. The increased computational and bandwidth demands of such a system would disrupt the internet as we know it.
In February, Google introduced a solution: Merkle Trees. These hierarchical data structures use cryptographic hashes and other mathematical principles to verify large amounts of information using only a small subset of that information. The design, which Google and Cloudflare have been testing in limited pilot programs, reduces the handshake data to about 40 kilobytes, comparable to current levels.
The existing WebPKI relies on a multi-link chain of quantum-vulnerable signatures to authenticate certificates. As replacing these signatures with quantum-resistant ones is resource-intensive, the chains are being replaced with compact Merkle Tree proofs. To complete such a proof, a certificate authority signs a single "tree head" that can represent millions of certificates. In most scenarios, the data handled by a browser is a "landmark," a lightweight proof confirming the certificate's location within the tree.
Industry regulations mandate that TLS certificates be published in append-only distributed ledgers known as public transparency logs. Website operators monitor these logs in real time to ensure that no unauthorized certificates are issued for their domains. These transparency programs were established following the 2011 DigiNotar hack, which led to the issuance of 500 counterfeit certificates for Google and other websites, some of which were used for espionage against users in Iran.
Once viable, Shor's algorithm could be used to forge classical encryption signatures and the public keys of certificate logs. Ultimately, an attacker could forge signed certificate timestamps, which are used to prove to a browser or operating system that a certificate has been registered when it has not.
Under the current PKI system, updates are managed by adding a new link to the signature chain. Merkle Trees offer proof of a signature chain without explicitly listing each link. This design offers another significant advantage: while current transparency logs are a separate process from certificate issuance, Merkle Tree Certificates integrate logging as a core part of the issuance process. "By coupling issuance and logging, transparency becomes a requirement for operation, rather than an add-on," stated Cloudflare engineer Mari Galicer.
Cloudflare's plan also incorporates other designs, such as the Automated Certificate Management Environment (ACME), an open-source mechanism for issuing and continuously renewing certificates shortly before their expiration. The quantum-resistant certificates will also include a method for signatures to be transmitted out-of-band—for example, via a browser update—if a server outage or other technical issue prevents the receipt of a landmark update. Cloudflare anticipates beginning certificate issuance in the first quarter of 2027.




