Follow
Subscribe via Email!

Enter your email address to subscribe to this platform and receive notifications of new posts by email.

Cloudflare Unveils Merkle Tree Certificates for Web PKI

Cloudflare announced plans to launch a public certificate authority issuing Merkle Tree Certificates, eliminating post-quantum signature bloat across modern browsers by 2027.
Cloudflare corporate facilities where engineers are developing Merkle Tree Certificates

Can global web communications withstand the impending arrival of quantum computing systems? Cloudflare Inc. announced plans on September 29 to establish a public certificate authority that issues Merkle Tree Certificates to shield future network traffic from quantum decryption. The initiative addresses an escalating architectural crisis across the Web Public Key Infrastructure, where standard post-quantum cryptographic replacements threaten to cause severe network transmission delays. To prevent connection latency, the new authority integrates transparency logging directly into credential creation while scheduling production deployment for the first quarter of 2027 [1].

Post-Quantum Certificates and the Scaling Crisis

The fundamental technical obstacle confronting the next-generation internet centers directly on payload size. Newly standardized post-quantum signature algorithms generate individual payloads reaching 2,420 bytes. Elliptic curve schemes consume 64 bytes. Because an ordinary web handshake transmits several distinct cryptographic signatures and public keys simultaneously, directly injecting these heavy algorithms into existing transmission frameworks would trigger crippling connection latency across global browsing routes, degrading performance at scale [2].

Today, the Web PKI authenticates roughly one billion TLS servers across the globe without forcing client software to preload public keys for every target destination. Over the past decade, ecosystem security enhancements have introduced mandatory certificate transparency logging and automated key revocation checks into standard browser connections. A typical secure handshake now processes five cryptographic signatures and two separate public keys. Technical assessments published by Cloudflare indicate that embedding individual post-quantum signatures into traditional certificates would balloon the storage volume that public transparency logs must ingest by 40 times [2].

Cloudflare anticipates that quantum hardware capable of breaking modern public-key encryption will emerge within years. The company targets 2029 [2]. Upgrading billions of active web connections prior to this defensive deadline represents an immense operational undertaking across hardware vendors, certificate authorities, and browser developers worldwide. Matthew Prince, Chief Executive of Cloudflare, characterized the transition as “one of the biggest coordination challenges in the history of the internet” [1].

Exterior view of Cloudflare corporate facilities connected to Merkle Tree Certificates infrastructure.
The Cloudflare corporate facility where engineers are developing infrastructure for the new certificate authority. (Credit: SiliconANGLE)

How Merkle Tree Certificates Work

To resolve the transmission bottleneck, Cloudflare co-authored the formal specification for Merkle Tree Certificates within the IETF PLANTS working group. The PLANTS group drafts standards. Rather than attaching a standalone post-quantum signature to every single certificate, the issuing authority batches thousands of issued credentials into an append-only Merkle tree structure. The authority signs only the root head of that collective cryptographic tree. Client software validates domain authenticity using an inclusion proof (a compact sequence of cryptographic hashes proving ledger inclusion) rather than downloading individual signature chains [2].

The system operates on an explicit rule: “don’t log what you issue, issue by logging.” Transparency becomes mandatory rather than an add-on [2].

Merkle Tree Certificates accommodate two deployment modes within standard X.509 certificate envelopes. In standalone form, the certificate carries both the cosigned root tree head and the inclusion proof inside the handshake payload, supplying complete verification data during the initial server exchange. Alternatively, the landmark-relative format achieves maximal network efficiency by distributing designated subtrees to clients through out-of-band browser updates. Under this landmark optimization, TLS handshakes transmit only the lightweight inclusion proof, completely eliminating heavy post-quantum digital signatures from real-time connection negotiations [2].

Legacy Root Stores and Hardware Hurdles

Deploying a newly formed public certificate authority introduces an immediate distribution obstacle across millions of legacy client devices worldwide. Older mobile smartphones and embedded systems that no longer receive software updates cannot incorporate newly generated root certificates into their local trust stores. Because unpatched devices reject unfamiliar cryptographic roots, establishing widespread adoption requires backward compatibility with existing operating systems [1].

Cloudflare plans to resolve this hardware compatibility impasse by purchasing an established root certificate that older operating systems already recognize, ensuring immediate operational functionality on devices that will never receive firmware patches. Chrome and Apple run root programs. The company has not publicly disclosed the identity or current corporate owner of the acquired root asset. Simultaneously, Cloudflare submitted formal applications to join the official root programs managed by Google Chrome, Apple Inc., Microsoft Corp., and Mozilla Corp [1].

Architectural diagram outlining Merkle Tree Certificates issuance within post-quantum Web PKI.
An engineering diagram detailing how append-only logs and Merkle trees handle post-quantum validation. (Credit: Cloudflare Blog)

While enterprise infrastructure operators defend against active cybersecurity emergencies, such as the breach of Australia’s Medicare statistics portal, network security architects emphasize that foundational cryptographic defense must be established and thoroughly battle-tested years ahead of practical quantum breakthroughs [1]. Transitioning web properties to Merkle Tree Certificates also necessitates rigorous certificate transparency monitoring. Organizations that adopt post-quantum authentication must actively monitor public transparency ledgers (formerly tracked via Merkle Town on Cloudflare Radar) to identify unexpected classical certificates and block malicious downgrade attacks against web traffic [2].

Issuing Merkle Tree Certificates Through Boulder

Building an operational certificate authority requires coordinating compliance standards with modernized issuance software designed for Merkle Tree Certificates. Cloudflare is constructing its core infrastructure around ACME (the Automatic Certificate Management Environment), maintaining an internal software fork. Boulder powers Let’s Encrypt [2]. Cloudflare intends to contribute its architectural modifications back upstream as the nonprofit prepares its own production rollout for 2027 [1].

When a client initiates an automated request, the ACME controller executes domain validation before serializing metadata and committing the record to an append-only cryptographic ledger. The issuing authority calculates the updated log state and signs a checkpoint attesting that every Merkle tree entry has been validly recorded. Next, the authority forwards the checkpoint to an independent mirroring cosigner to confirm strict append-only consistency. Under the draft policy formulated for Chrome’s newly launched Quantum-resistant Root Store, every trusted certificate must carry at least two distinct cosignatures, requiring validation from both the issuing certificate authority and an independent mirroring cosigner operated by a distinct external organization. Cloudflare implemented its mirroring cosigner within Azul, an open-source Rust transparency log executing the c2sp mirror protocol to guarantee auditable ledger synchronization [2].

Technical diagram illustrating Merkle Tree Certificates data structures and inclusion proofs.
Technical documentation showing cryptographic data structures designed for post-quantum certificate transparency. (Credit: Cloudflare Blog)

To eliminate single points of failure across the web, Cloudflare will operate independent mirrors for other participating certificate authorities while mandating external cosignatures on its own issuance checkpoints. Nimbus launched in 2016. Raio introduces static logs. The company has maintained that family of certificate transparency logs for a decade and is currently deploying Raio as a modern sequence of static transparency logs. Running independent mirrors and multi-party cosignatures guarantees that issuance ledgers remain fully auditable even if primary infrastructure experiences service disruptions [2].

Browser Adoption and Automated Revocation Signals

A joint experimental deployment conducted with Google LLC’s Chrome engineering team concluded successfully in October 2025, confirming that Merkle Tree Certificates operate efficiently under realistic browsing conditions. Cloudflare intends to provide standard post-quantum certificate issuance at zero cost, following its established tradition of offering strong cryptographic tools without charge. Universal SSL launched in 2014. That complimentary program supplied digital certificates to millions of customer websites, doubling the total volume of encrypted web traffic almost overnight [1].

Establishing a proprietary certificate authority represents a major strategic shift for Cloudflare, which previously relied on three external commercial issuers (including Let’s Encrypt) to sign customer credentials. Matthew Prince identified heavy industry concentration among a tiny cluster of providers as a systemic risk for the internet. If one dominant provider experiences severe outages or security compromises, millions of hosted domains risk immediate disconnection [1].

The newly established authority will emphasize operational transparency by publishing reproducible code builds and hosting an active public health dashboard, moving beyond the periodic compliance audits that govern legacy certificate authorities. Modern operations will incorporate RFC 9773, an internet standard defining automated certificate renewal signals. If a private signing key suffers a compromise, Cloudflare can trigger automated background certificate replacements across millions of customer websites simultaneously without administrative intervention, safeguarding global web infrastructure as full production rollout approaches in the first quarter of 2027 [1].

Sources
  1. ONLINE NEWS Riley, D. (2026, September 29). Cloudflare to become a public certificate authority with post-quantum certificates. SiliconANGLE. [Article Link]
  2. WEBSITE Cloudflare. (2026, September 29). Building a post-quantum certificate authority with Merkle Tree Certificates. Cloudflare Blog. [Article Link]

Leave a Comment

Related Posts
Total
0
Share