• 8 mins read
  • Published

Cloudflare Builds a Quantum-Resistant Certificate Authority

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

Cloudflare Builds a Quantum-Resistant Certificate Authority Science.Report © science.report
Cloudflare Builds a Quantum-Resistant Certificate Authority © science.report

Cloudflare plans a publicly trusted certificate authority that combines legacy TLS coverage with Merkle Tree Certificates designed to reduce the cost of post-quantum web security

Cloudflare is building a public Certificate Authority around a problem that could determine whether post-quantum security reaches the Web without slowing it down: the size of cryptographic signatures. The company announced on September 29, 2026, that it had applied for inclusion in the root programs operated by Chrome, Apple, Microsoft, and Mozilla. It plans to issue conventional TLS certificates while developing Merkle Tree Certificates for a future in which larger post-quantum signatures could otherwise strain handshakes and Certificate Transparency logs.

  • Trust at web scale

    The initiative was announced during Cloudflare's annual Birthday Week and remains dependent on approvals that have not yet been completed. Cloudflare has also signed a definitive agreement to acquire publicly trusted root certificate key material from GlobalSign. The arrangement is intended to extend compatibility to older smartphones, operating systems, and embedded devices whose trust stores may not recognize a newly created root immediately.

    That combination addresses two different engineering problems. GlobalSign's legacy root coverage is intended to reach older and unpatched hardware, while the new root-store applications are intended to establish Cloudflare's standing under newer browser policies, including Chrome's planned Quantum-Resistant Root Store. Neither step is equivalent to universal browser approval: conventional certificate issuance is expected to begin only after the relevant root-program processes are completed.

    The acquisition is expected to close within two months. Cloudflare says it will operate as its own "Customer Zero" by routing its global edge network through the new CA stack; the company reports that this network handles more than 20% of global web traffic. That scale could provide a demanding operational environment for testing issuance, revocation, logging, and certificate deployment, but it is not independent evidence that the wider ecosystem has already adopted the model.

  • The signature bottleneck

    Post-quantum cryptography is designed to protect conventional computers and networks against future quantum attacks. The immediate engineering issue is not that current web traffic is being decrypted by a quantum computer. It is that some post-quantum algorithms produce signatures substantially larger than the RSA or ECDSA signatures used in today's certificates.

    Cloudflare describes signatures from algorithms such as ML-DSA and SLH-DSA as potentially up to 40 times larger than classical alternatives. Repeating those signatures across certificate chains could increase the data exchanged during TLS handshakes and add substantial volume to public Certificate Transparency logs. The concern is consistent with the broader transition challenge recognized by NIST's post-quantum cryptography program: security algorithms must be evaluated not only for mathematical resistance, but also for key size, signature size, bandwidth, latency, and implementation cost.

    For comparison, the quantum threat is usually explained through Shor's algorithm, which would undermine widely used public-key systems if a sufficiently capable fault-tolerant quantum computer became available. Grover's algorithm affects symmetric cryptography differently, reducing the effective security margin of exhaustive search and motivating suitable key-length choices. Neither algorithm means that today's quantum processors can break deployed Internet encryption; the practical concern is long-term exposure and the possibility of "harvest now, decrypt later" attacks.

    Cloudflare's response is Merkle Tree Certificates, or MTCs, a standards-based specification co-authored by Cloudflare within the IETF PLANTS working group. The design changes the unit that receives a post-quantum signature. Instead of signing every certificate separately with a large post-quantum key, the CA groups certificate requests in an append-only Merkle tree and signs a tree-head checkpoint.

  • How MTCs work

    A server using an MTC would present a compact inclusion proof during the TLS handshake. The proof consists of a sequence of cryptographic hashes connecting the server's public key to a trusted landmark subtree distributed to browsers out of band. The browser can therefore verify that the certificate belongs to the logged tree without carrying a separate heavy signature for every issued certificate.

    A Merkle tree is a data structure that summarizes many records through layers of cryptographic hashes. Each certificate can be checked with a short proof showing its position in the tree, while the CA signs the tree's checkpoint instead of every individual record. This reduces signature overhead without making issuance invisible to audit. The approach is an efficiency mechanism for post-quantum trust infrastructure, not a quantum computer and not quantum cryptography.

    This is not an escape from auditability. The append-only tree preserves a record of issuance while moving the expensive signature operation to a checkpoint. Its security and operational value depend on the browser trust model, the handling of landmark information, the integrity of the tree, and eventual standards and implementation decisions. The available material describes the specification as standards-based but does not establish that it has become a universal Web PKI standard.

    The underlying design reflects a familiar principle in computer science research at institutions such as MIT and CERN: when an operation is expensive, systems can often improve throughput by authenticating a compact aggregate and proving membership for individual records later. In MTCs, however, the cryptographic details and browser governance are decisive. A shorter proof does not remove the need for secure tree construction, reliable checkpoints, protected signing keys, and mechanisms for detecting inconsistent views.

    Cloudflare reports that production trials across its domains using Chrome Beta 146 produced a 9% net median performance speedup for landmark-relative MTCs compared with classical signature chains. That is a specific trial result rather than a general guarantee for every browser, certificate chain, network, or server. The available description does not provide a peer-reviewed sample size, confidence interval, or p-value, so the result should be treated as an engineering benchmark rather than a statistically generalized finding.

  • Deployment still ahead

    Cloudflare's timetable separates the conventional and post-quantum parts of the plan. Classical certificate issuance is expected to start after browser root approvals, while production MTC issuance is scheduled for the first quarter of 2027. The GlobalSign transaction is expected to close within two months, but the available information does not state that the acquisition has already closed or that any browser has approved Cloudflare's applications.

    The strategic logic is stronger than a simple product launch. Certificate authorities sit at a narrow point of control in web security, and Cloudflare already operates an edge network that can serve as a large internal test environment. Its earlier experiment with the Chrome team was reported as successful and helped support the plan for MTCs in Chrome's Quantum-Resistant Root Store. Even so, a successful experiment does not demonstrate ecosystem-wide compatibility, long-term governance, or resistance to every implementation failure.

    Peer-reviewed work in Nature and related cryptography literature has repeatedly emphasized that cryptographic migration is socio-technical as well as mathematical: algorithms, libraries, hardware, certificate policies, monitoring, and software-update practices must change together. That lesson is particularly important for legacy devices, which may remain in service long after browsers and cloud platforms have adopted new defaults.

    The security case also belongs in the longer timeline of "harvest now, decrypt later" campaigns. Encrypted traffic captured today may become more valuable if future quantum computers can break vulnerable public-key systems, but there is no claim that current quantum machines can perform that decryption. The practical response described here is migration of the Web PKI before such a capability exists, not a repair for an active quantum breach.

    For readers tracking the broader migration from hardware protections to network infrastructure, the contrast is useful with earlier hardware protection: a TPM approach isolates keys inside embedded hardware, whereas Cloudflare's proposal targets the certificate issuance layer that authenticates web connections.

    Merkle Tree Certificates address a real scaling constraint by reducing how often large post-quantum signatures must be used, and Cloudflare's reported 9% median trial improvement gives the design a concrete performance claim rather than a purely theoretical appeal. Yet the decisive milestones remain external: browser root approval, completion of the GlobalSign transaction, standards and implementation scrutiny, and production issuance planned for the first quarter of 2027. On the evidence provided, Cloudflare has proposed a credible infrastructure path and begun testing it, but it has not yet delivered a universally trusted post-quantum Web PKI.

  • Related articles