Cloudflare has announced plans to operate a free public Certificate Authority that would issue quantum-safe Transport Layer Security (TLS) certificates, targeting what it describes as a critical structural bottleneck in modern web infrastructure: the impending move away from classical public key cryptography.
Post-quantum key exchange algorithms have already seen active production rollouts, but post-quantum authentication across the Web Public Key Infrastructure has lagged. The reason, the company says, is the immense payload size of quantum-resistant digital signatures. Current internet authentication depends almost entirely on classical asymmetric primitives such as RSA and elliptic-curve cryptography. NIST-standardised algorithms including ML-DSA and Falcon are designed to protect against cryptanalytic attacks powered by Shor's algorithm, but their signatures and public keys require dramatically more data than their classical predecessors.
Directly substituting post-quantum signature algorithms into traditional hierarchical X.509 certificate chains would inflate the volume of cryptographic handshake data by roughly forty times, according to Cloudflare. That would cause acute TCP segmentation, packet loss on constrained networks and extra round trips during the handshake phase. Certificate Transparency logs, which record every publicly trusted certificate issued by a Certificate Authority, would also come under severe operational strain.
To avoid that scaling penalty, Cloudflare's new authority will use Merkle Tree Certificates, an alternative authentication model being advanced within the IETF PLANTS working group. Instead of signing each server certificate with an isolated individual signature from an intermediate authority, the system batches certificate issuances into an append-only Merkle tree structure. The company says the approach is designed to give enterprise engineering teams and site operators backwards-compatible, low-latency quantum resistance ahead of production trust-store deadlines.