Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Cloudflare’s New Certificate Design Aims to Make Quantum-Safe HTTPS Actually Practical
Cloudflare’s New Certificate Design Aims to Make Quantum-Safe HTTPS Actually Practical
Read Time:3 Minute, 57 Second

Cloudflare is building a new type of certificate authority meant to solve a looming problem for the encrypted web: how to protect HTTPS connections against future quantum computers without weighing down every single website visit with oversized cryptographic signatures. The company says it is targeting early 2027 to join Chrome’s forthcoming Quantum-resistant Root Store, and that standard certificate issuance under the new system will remain free.

Why Today’s Certificate System Doesn’t Scale to Post-Quantum Signatures

The web’s current trust model relies on certificate authorities to confirm that a website controls its domain and to bind that domain to a cryptographic public key, while a public auditing system called Certificate Transparency logs every certificate that gets issued so misissuance can be caught. That system works well today, but Cloudflare’s own estimates suggest that swapping in post-quantum-safe signatures could balloon Certificate Transparency storage requirements by as much as 40 times current levels — on top of a TLS handshake that already has to carry multiple signatures and keys for every connection.

With billions of websites, browsers, transparency logs, and certificate renewals happening across the internet at any given moment, that kind of overhead isn’t a minor inconvenience — it threatens to make quantum-safe encryption too slow and too expensive to deploy at web scale.

Rethinking Certificates Around a Merkle Tree

Cloudflare’s answer is a format it calls Merkle Tree Certificates, or MTCs, which restructure how certificates get issued and verified. Instead of signing every individual certificate and separately submitting it to a transparency log after the fact, the certificate authority records each certificate inside an append-only Merkle tree and signs a single “checkpoint” that represents the entire tree’s current state.

A website then receives what’s called an inclusion proof — essentially a short chain of hashes demonstrating that its certificate is genuinely part of that signed tree. The practical effect is a shift from “log what you issue” to “issue by logging,” folding the transparency step directly into the issuance process rather than bolting it on afterward.

Cloudflare’s workflow will use the ACME protocol for certificate requests and domain validation, built on a fork of Boulder — the open-source software that powers Let’s Encrypt, which is separately adding its own MTC support. After a domain is validated, the certificate data is logged, a new checkpoint is signed, and that checkpoint is sent to an independent mirroring service that verifies the log hasn’t been tampered with and keeps its own copy, preventing the certificate authority from quietly showing different parties different versions of its log.

Chrome’s draft policy for accepting this format requires two independent cosignatures: one from the issuing certificate authority and one from a separate, recognized mirror operator. Cloudflare plans to run its own mirror using Azul, an open-source Rust-based transparency-log tool it has built, while also supporting an interoperable mirroring protocol so other organizations’ mirrors can cross-check its logs.

Where the Speed Gains Actually Come From

The performance benefit hinges on something Cloudflare calls landmark-relative certificates. Browsers periodically receive compact tree “landmarks” through a separate update channel, outside of any individual website visit. During an actual TLS handshake, a server only needs to send its own certificate data plus a lightweight proof linking it back to a landmark the browser already trusts — skipping the need to transmit a full, heavyweight post-quantum signature on every connection. Full standalone certificates are still used as a fallback for browsers that are new, offline, or missing a current landmark.

In a trial covering half of Chrome Beta’s user base, Cloudflare says it served billions of these certificates for free-tier domains. Handshakes using the landmark approach needed only a single public key, one signature, and a sub-1-KB inclusion proof, yielding a median 9 percent speed improvement over conventional certificate chains — though Cloudflare acknowledges the test used classical (non-quantum-safe) signatures, and that a meaningful share of that gain simply came from eliminating an intermediate certificate from the chain.

Still a Work in Progress

The MTC format remains an active draft inside an IETF working group rather than a finalized internet standard, and Cloudflare still has to pass through Chrome’s formal root-program review before any browser will actually trust certificates it issues this way. Scaling the model will also require proving that a diverse set of independent monitors, multiple competing certificate authorities, and various mirror operators can reliably process these logs at full internet scale.

For security teams, the practical takeaway for now is to keep an eye on Certificate Transparency monitoring as post-quantum authentication schemes mature — an unexpected legacy certificate showing up for a domain that has otherwise moved to newer protections can be an early sign of a downgrade attack.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Cloudflare’s New Certificate Design Aims to Make Quantum-Safe HTTPS Actually Practical, use the discussion on Forum.

>> forum community

Comments

Leave a Reply