Cloudflare Plans Public Certificate Authority for Quantum-Safe TLS

Batch-signed Merkle tree certificates aim to avoid the size penalty of post-quantum signatures

By LineZotpaper
Published
Read Time2 min
Cloudflare has announced plans to operate a free public Certificate Authority that would issue quantum-safe Transport Layer Security (TLS) certificates, targeting a critical bottleneck in the web's transition away from classical public key cryptography: the enormous size of post-quantum digital signatures.

Cloudflare has announced plans to operate a free public Certificate Authority that would issue quantum-safe Transport Layer Security (TLS) certificates, targeting what it describes as a critical structural bottleneck in modern web infrastructure: the impending move away from classical public key cryptography.

Post-quantum key exchange algorithms have already seen active production rollouts, but post-quantum authentication across the Web Public Key Infrastructure has lagged. The reason, the company says, is the immense payload size of quantum-resistant digital signatures. Current internet authentication depends almost entirely on classical asymmetric primitives such as RSA and elliptic-curve cryptography. NIST-standardised algorithms including ML-DSA and Falcon are designed to protect against cryptanalytic attacks powered by Shor's algorithm, but their signatures and public keys require dramatically more data than their classical predecessors.

Directly substituting post-quantum signature algorithms into traditional hierarchical X.509 certificate chains would inflate the volume of cryptographic handshake data by roughly forty times, according to Cloudflare. That would cause acute TCP segmentation, packet loss on constrained networks and extra round trips during the handshake phase. Certificate Transparency logs, which record every publicly trusted certificate issued by a Certificate Authority, would also come under severe operational strain.

To avoid that scaling penalty, Cloudflare's new authority will use Merkle Tree Certificates, an alternative authentication model being advanced within the IETF PLANTS working group. Instead of signing each server certificate with an isolated individual signature from an intermediate authority, the system batches certificate issuances into an append-only Merkle tree structure. The company says the approach is designed to give enterprise engineering teams and site operators backwards-compatible, low-latency quantum resistance ahead of production trust-store deadlines.

§

Analysis

Why This Matters

  • Web authentication currently rests on RSA and elliptic-curve cryptography, algorithms a sufficiently powerful quantum computer could one day break. Post-quantum key exchange is already in production, but the authentication side still lags.
  • Quantum-resistant signatures are far larger than classical ones. A naive swap into existing X.509 certificate chains would inflate handshake data by roughly forty times, degrading performance for constrained networks and straining Certificate Transparency logs.
  • The outcome will determine how smoothly the internet can move to quantum-safe certificates before production trust stores set their own deadlines.

Background

Web security depends on a public key infrastructure in which certificate authorities issue and sign the X.509 certificates that authenticate websites during TLS handshakes. Nearly all of those signatures use classical asymmetric algorithms. NIST has standardised a new generation of post-quantum algorithms, but they carry a steep size cost. The IETF PLANTS working group is developing Merkle Tree Certificates as a way to authenticate many certificates together in a compact batch, and Cloudflare's announcement is an early attempt to deploy that model as a free public service.

Key Perspectives

Cloudflare: The company sees a gap between post-quantum key exchange, which is already rolling out, and post-quantum authentication, which is not. Its proposed authority uses batched Merkle tree signing to keep handshakes small and backwards compatible.

IETF PLANTS working group: The standard Cloudflare plans to rely on is still a draft. Its acceptance will shape whether Merkle Tree Certificates become a viable alternative to hierarchical X.509 chains.

Site operators and trust stores: Browsers, operating systems and trust stores ultimately decide which certificates are accepted. Adoption depends on when they support the new model, and enterprises will weigh whether to move before the standard is finalised.

What to Watch

  • Progress of the Merkle Tree Certificates draft through the IETF PLANTS working group toward standardisation.
  • Whether major browsers and operating systems add support for Merkle Tree Certificates in their trust stores.
  • Industry deadlines for post-quantum readiness in production trust stores, which will set the pace for adoption.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.