
Summary
Cloudflare said Tuesday it plans to issue quantum-proof TLS certificates, making it one of the first authorities to issue such certificates that use a form of cryptography that is widely believed to withstand attacks from quantum computers. The Internet infrastructure provider said it will use an open source platform that issues both classic TLS certificates and a post-quantum equivalent known as Merkle Tree Certificates. The hybrid certificates will be free to both paying and non-paying users. To help build the massive system and establish ubiquity across the sprawling TLS ecosystem, Cloudflare will be acquiring an already trusted certificate root from CA GlobalSign. Cloudflare said the move will let millions of websites use post-quantum certificates at the flip of a switch and without incurring any increased performance overhead. Fundamental architectural changes ahead Cloudflare’s plans are part of a major overhaul in the web public key infrastructure (WebPKI) required to make website encryption and authentication safe for the coming post-quantum age. A major challenge is using quantum-proof signatures that can be easily transmitted during web requests and recorded in transparency logs to ensure counterfeit certificates aren’t assigned to websites. The makeover will take years to complete, because it requires the work of an untold number of engineers who design operating systems, browsers, certificate authorities, and Internet infrastructure. “We are not issuing certificates yet, and it will be a little while before we do,” Cloudflare’s Steve Goldsmith wrote. “What we are doing is committing to the work in public, sharing the milestones as they land, and telling you exactly what we are building while working with the root programs and other members of the WebPKI community to achieve this.” Safeguarding the WebPKI against quantum attacks is a tall order that requires fundamental architectural changes rather than simply swapping algorithms. Quantum-proof versions of today’s classical X.509 certificates would add roughly 40 times the amount of data required for a TLS handshake, which takes place each time a browser or other application establishes a new session with a server. The added computation and bandwidth required to implement such a system would break the Internet as we know it.