Building a post-quantum certificate authority with Merkle Tree Certificates
Cloudflare is launching a new certificate authority capable of issuing Merkle Tree Certificates (MTC). This implementation addresses the data size overhead associated with post-quantum cryptographic signatures in TLS handshakes.
Verified State Diff
Impact & Verification Analysis
Enterprise security teams, developers implementing post-quantum TLS, and infrastructure providers managing certificate transparency logs.
It solves the critical architectural bottleneck of PQC adoption, enabling quantum-resistant security without degrading network performance or breaking existing certificate transparency infrastructure.
Full Fact Overview
The transition to post-quantum cryptography (PQC) introduces significant challenges for existing Public Key Infrastructure (PKI), specifically the increased size of post-quantum signatures which can lead to packet fragmentation and latency in TLS handshakes. Cloudflare's adoption of Merkle Tree Certificates (MTC) allows for the aggregation of multiple certificates into a single Merkle tree, significantly reducing the payload size required for authentication. By integrating this into their certificate authority, Cloudflare provides a scalable mechanism to maintain certificate transparency and auditability without the performance penalties typically associated with large PQC signature schemes.