
Cloudflare plans to issue quantum-secure TLS certificates
In February, Google announced a solution: Merkle Trees. These hierarchical data structures use cryptographic hashes and other mathematics to verify the contents of large amounts of information using a small fraction of their contents. The design, which Google and Cloudflare have tested in limited pilot programs, reduces the amount of trading data to about 40 kilobytes, about the same amount as is processed now.
Current WebPKI relies on a multi-linked chain of vulnerable quantum signatures to prove the authenticity of a certificate. Since replacing signatures with quantum-resistant signatures requires prohibitive resources, chains are replaced with compact Merkle Tree proofs. To complete such proof, a certification authority signs only a single “tree head” which can represent millions of certificates. In most cases, the data processed by a browser constitutes a “landmark”, a light-hearted proof that the certificate is located somewhere in the tree.
Industry-wide rules require that TLS certificates be published in appendix-only distributed ledgers, called public transparency logs. Website owners check logs in real time to ensure that no malicious certificates have been issued for the domains they use. The transparency programs were implemented in response to the 2011 hack of Netherlands-based DigiNotar, which allowed the creation of 500 counterfeit certificates for Google and other websites, some of which were used to spy on Internet users in Iran.
Once viable, Shor’s algorithm could forge traditional encryption signatures and the public keys of certificate logs. Ultimately, an attacker could forge signed certificate timestamps used to prove to a browser or operating system that a certificate was saved when it was not.
In the current PKI system, updates are handled by adding a new link to the signature chain. Merkle trees provide proof of a signature chain without explicitly listing each individual link. The design has another major advantage. In the current system, transparency logs are a separate process from issuing certificates. In contrast, with Merkle Tree certificates, logging is an essential part of the issuance. “By combining emitting and logging, transparency becomes a operational requirement, rather than an add-on,” said Mari Galicer, an engineer at Cloudflare.
There are a host of other designs included in the Cloudflare plan. One of them is the Automated Certificate Management Environment (ACME), an open source mechanism for issuing certificates and continuously renewing them shortly before they expire. Quantum-resistant certificates will also provide a mechanism to send signatures out-of-band, for example via a browser update, if a down server or other technical issue prevents a historical update from being received. Cloudflare said it plans to start issuing certificates in the first quarter of 2027.
Gn tech