Cloudflare is pioneering a new approach to enhance internet security in the quantum era. The company is developing a certificate authority (CA) that incorporates Merkle Tree Certificates (MTCs) to facilitate post-quantum website authentication without imposing large signatures on TLS connections.
Innovative Certificate Authority Approach
Anticipating the need for quantum-resistant solutions, Cloudflare plans to issue conventional certificates alongside MTCs, aiming for integration into Chrome’s Quantum-resistant Root Store by early 2027. The issuance of these MTCs will be cost-free, addressing existing gaps in web public key infrastructure. Currently, browsers rely on certificate authorities to verify domain control and link a site’s identity to a public key, while Certificate Transparency (CT) logs allow for issuance auditing.
Cloudflare highlights that post-quantum signatures could significantly inflate CT storage needs, estimating a 40-fold increase. This is critical because quantum-safe authentication must maintain security and responsiveness across numerous websites and browsers globally.
Merkle Tree Certificates: A New Paradigm
MTCs revolutionize the certificate issuance process by employing an append-only Merkle tree structure. Instead of signing each certificate individually, the CA logs certificate data and signs a checkpoint representing the tree’s state. Websites receive an inclusion proof, a hash sequence confirming their certificate’s inclusion in the signed tree, shifting the model from “log what you issue” to “issue by logging.” This approach embeds transparency into the issuance process itself.
Research from Cloudflare outlines the use of ACME for certificate requests and domain validation, utilizing Boulder software from Let’s Encrypt for MTC support. Post-validation, the CA logs the certificate data, signs the updated checkpoint, and submits it to a mirroring cosigner. This independent service ensures append-only consistency and stores a backup, preventing conflicting log views.
Performance and Challenges
Chrome’s draft policy mandates a cosignature from the issuing CA and a separate recognized mirror. Cloudflare plans to establish its mirror using Azul, open-source Rust-based software, and support the C2SP tlog-mirror protocol for seamless interoperability. Only after obtaining the necessary cosignatures does the CA compile the public key, inclusion proof, and signatures into a standalone MTC.
Performance improvements stem from landmark-relative certificates, allowing browsers to receive tree substructures, or landmarks, via an out-of-band channel. During TLS negotiation, the server transmits only its certificate data and a minimal proof linking it to a trusted landmark, thereby bypassing cumbersome post-quantum signatures. A trial involving 50% of Chrome Beta 146 users showed a 9% median speed increase, demonstrating the potential of this approach.
Despite promising results, the MTC design is still under development. It remains an active draft in the IETF PLANTS working group, and Cloudflare must undergo Chrome’s root-program review before its certificates gain browser trust. Successful large-scale deployment will require reliable log processing by independent monitors, various CAs, and diverse cosigners.
For vigilance, CT monitoring remains crucial: organizations adopting post-quantum authentication should remain alert to unexpected legacy certificates that could enable security downgrades.
