top of page

Cloudflare’s Quantum-Safe Internet Plan: How Merkle Tree Certificates Could Transform HTTPS

7 minutes ago
10 min read
External References here: https://blog.cloudflare.com/cloudflare-certificate-authority/ https://arstechnica.com/security/2026/09/cloudflare-plans-to-issue-quantum-safe-tls-certificates/ https://blog.cloudflare.com/post-quantum-visibility/

The next major transformation in Internet security may not be visible to most users. Websites will continue to display familiar padlock icons, applications will continue establishing encrypted connections, and browsers will continue validating digital certificates. Underneath that familiar experience, however, the cryptographic machinery that makes HTTPS trustworthy is beginning to undergo a fundamental redesign.

Cloudflare has announced plans to become a public certificate authority while simultaneously preparing to issue post-quantum certificates, including Merkle Tree

Certificates designed to address the unusual constraints created by quantum-resistant cryptography. The company expects to begin issuing certificates in the first quarter of 2027, subject to the necessary root program processes.


The significance extends well beyond Cloudflare. Certificate authorities are foundational components of the Web Public Key Infrastructure, or WebPKI, which allows browsers and operating systems to determine whether a website's cryptographic identity can be trusted. Moving that infrastructure toward quantum resistance requires changes to certificate issuance, transparency logging, browser compatibility, cryptographic algorithms, and operational processes.

At the same time, Cloudflare is giving customers increasingly detailed visibility into whether their Internet traffic already uses post-quantum encryption. That combination, visibility today and architectural preparation for tomorrow, illustrates how the transition to quantum-safe Internet security is becoming an operational requirement rather than a distant theoretical exercise.


Why Quantum Computing Changes the HTTPS Security Model

HTTPS depends on cryptographic mechanisms that were designed for classical computers. Two major families, RSA and elliptic-curve cryptography, have played central roles in authenticating Internet connections and establishing secure communications.

A sufficiently capable quantum computer could fundamentally alter that security equation.

Shor's algorithm provides a theoretical method for efficiently solving mathematical problems underlying widely deployed public-key cryptography. If large-scale fault-tolerant quantum computers become practical, cryptographic systems based on vulnerable mathematical assumptions could eventually become breakable.

The threat is particularly important because encrypted information can have value long after it is transmitted.


An attacker can capture encrypted communications today and retain them for future decryption. This is commonly described as a "harvest now, decrypt later" threat. Information with long-term sensitivity, including government, financial, healthcare, telecommunications, and strategic data, may therefore require protection against quantum attacks before cryptographically relevant quantum computers actually exist.

The migration problem has two separate dimensions:

  1. Post-quantum key establishment, which protects the process of creating encryption keys.

  2. Post-quantum authentication, which protects the certificates and signatures used to establish that a website is genuinely who it claims to be.

The Internet has made considerably more progress on the first problem than the second.


Hybrid ML-KEM Is Already Changing TLS

Cloudflare's current post-quantum deployment relies heavily on hybrid key exchange using ML-KEM.

In TLS 1.3, X25519MLKEM768 combines the established X25519 elliptic-curve key exchange with ML-KEM, a standardized post-quantum key encapsulation mechanism.

The hybrid approach is important because it does not require the Internet to abandon classical cryptography overnight.

The two mechanisms independently contribute secret material. TLS combines the resulting secrets before using them to protect application traffic. The architecture therefore provides a transitional security model in which the connection benefits from both classical and post-quantum assumptions.

Cloudflare reports that approximately 70% of browser-generated traffic reaching its network already uses post-quantum encryption through hybrid ML-KEM. By comparison, only about 15% of origins that Cloudflare connects to currently use hybrid ML-KEM.


That difference reveals an important characteristic of the transition: upgrading the Internet is not simply a matter of changing one server setting. Different parts of the connection can move toward quantum resistance at different speeds.

A modern web request can therefore involve multiple cryptographic relationships:

Connection

Security Question

Browser to Cloudflare

Does the visitor negotiate post-quantum key exchange?

Cloudflare to origin

Does the backend server support post-quantum key exchange?

Website authentication

Is the certificate itself resistant to future quantum attacks?

Transparency infrastructure

Can certificate issuance remain verifiable in a quantum era?

Cloudflare's new visibility tools are intended to make these distinctions measurable.


The Certificate Problem Is Harder Than Changing an Algorithm

Replacing vulnerable encryption algorithms sounds straightforward until the architecture of the WebPKI is considered.

Website certificates are not isolated cryptographic objects. They exist within trust chains involving certificate authorities, root certificates, browsers, operating systems, certificate transparency systems, and millions of devices.

Post-quantum signatures can also be substantially larger than traditional signatures. If conventional certificate chains were simply replaced with large quantum-resistant signatures, the additional data could place significant pressure on TLS handshakes.

The supplied research notes that straightforward quantum-proof versions of conventional X.509 certificates could require roughly 40 times the data associated with current TLS handshakes.

That is potentially unacceptable for a global system handling enormous volumes of connections.

The solution being explored by Cloudflare and other industry participants is a different architectural approach based on Merkle Trees.


How Merkle Tree Certificates Could Compress WebPKI

A Merkle Tree is a hierarchical cryptographic data structure that allows a system to prove that a particular item belongs to a large collection without transmitting the entire collection.

Applied to certificates, this concept changes how certificate authenticity can be represented.

Instead of requiring every certificate in a chain to carry a large quantum-resistant signature, a certificate authority can organize certificates into a tree and sign a compact representation of the tree. A browser can then receive a smaller proof demonstrating that a particular certificate belongs to that authenticated structure.

The resulting proof can be dramatically smaller than a conventional post-quantum certificate chain.

Cloudflare and Google have been exploring this approach, with the supplied material indicating that Merkle Tree designs can bring the handshake data requirement to approximately 40 kilobytes, around the scale of what the Internet already processes.

This is more than a performance optimization. It represents a possible architectural bridge between today's WebPKI and a future in which quantum-resistant signatures become necessary.


Transparency Becomes Part of Certificate Issuance

Certificate Transparency has become a critical component of the modern WebPKI.

Publicly trusted certificates are published in append-only transparency logs, allowing domain owners and security systems to monitor certificate issuance and identify potentially fraudulent certificates.

The importance of transparency became particularly clear following the 2011 DigiNotar compromise, in which attackers obtained fraudulent certificates for major websites, including Google domains. Some of those certificates were subsequently associated with surveillance activity.

Merkle Tree Certificates offer another architectural opportunity because certificate issuance and transparency can be more tightly integrated.

Instead of treating certificate logging as a separate process layered onto issuance, the cryptographic structure itself can incorporate evidence that the certificate exists within an authenticated tree.

This creates a deeper relationship between authentication and transparency.

For the future WebPKI, that could make transparency not merely an auditing mechanism but a fundamental property of certificate operation.


Cloudflare Wants to Become a Public Certificate Authority

Cloudflare has historically been one of the world's largest consumers of publicly trusted certificates without operating a public certificate authority of its own.

That is now changing.

The company has applied for inclusion in the Chrome, Apple, Microsoft, and Mozilla root programs and has agreed to acquire an established, widely trusted root from GlobalSign.

The strategy addresses a fundamental problem with launching a new certificate authority: trust does not automatically exist simply because a new root certificate has been created.

A newly approved root must propagate across browsers, operating systems, and devices. Older systems may never receive the necessary updates.

Cloudflare therefore plans to combine an established trust anchor with new roots designed for future WebPKI requirements.

The approach can be viewed as a compatibility strategy:

  • Existing trusted root: broad reach across current and older devices.

  • New roots: alignment with evolving browser and root program policies.

  • Classical certificates: continued support during the transition.

  • Merkle Tree Certificates: preparation for post-quantum authentication.

This dual-path architecture recognizes that the Internet cannot be upgraded simultaneously.


Why Certificate Authority Redundancy Matters

Cloudflare's entry into public certificate issuance also addresses concentration risk.

Let's Encrypt has become a major source of free automated certificates, issuing on the order of ten million certificates per day and serving more than 500 million sites, according to the supplied Cloudflare material. It passed four billion active certificates in 2025.

That scale represents a major success for Internet encryption, but it also illustrates why certificate authority resilience matters.

If a dominant free certificate provider experienced a serious operational or security incident, millions of websites could potentially require alternative certificate infrastructure quickly.

Cloudflare argues that public CA competition can create another layer of redundancy.

Its own infrastructure already uses multiple certificate authorities, with primary and backup certificates designed to help maintain service during outages, revocation events, or other failures.

Extending that philosophy to a public CA could create another source of automated certificate issuance for the broader Internet.


ACME Could Make the Transition Easier

Cloudflare plans to make its public certificate authority ACME-first.

The Automated Certificate Management Environment is an open protocol widely used to automate certificate issuance and renewal.

That matters because the certificate ecosystem increasingly depends on automation. Shorter certificate lifetimes mean organizations cannot realistically rely on manual renewal procedures for millions of domains.

Cloudflare also plans to require renewal automation through support for ACME Renewal Information, or ARI.

The underlying philosophy is straightforward: certificate infrastructure should be designed so that replacement happens before an incident turns into an outage.

This becomes especially important when certificates need to be revoked because of a compromised key, incorrect issuance, policy violation, or other security event. A highly automated ecosystem can replace affected certificates progressively rather than forcing enormous numbers of organizations into emergency manual processes.


Post-Quantum Visibility Is Becoming a Security Requirement

Cryptographic migration cannot be managed effectively without measurement.

Cloudflare has therefore added post-quantum visibility to its HTTP Traffic Analytics, Log Explorer, and Logpush products.

Customers can inspect the key exchange group used for individual connections and determine how much traffic uses X25519MLKEM768 compared with classical algorithms.

A new ClientTLSKeyExchangeGroup field provides connection-level telemetry, while OriginTLSKeyExchangeGroup provides visibility into the Cloudflare-to-origin side.

This allows organizations to identify specific sources of cryptographic weakness instead of relying solely on aggregate statistics.

For security teams, that can support several practical activities:

  • Measuring quantum-readiness across domains

  • Identifying legacy clients

  • Finding origins that still depend on classical cryptography

  • Monitoring migration progress

  • Supporting compliance assessments

  • Investigating unexpected TLS configurations

  • Prioritizing infrastructure modernization

The significance is similar to observability in cloud infrastructure. Organizations cannot reliably manage a complex technical transition if they cannot see what their systems are actually doing.


Legacy Systems Do Not Necessarily Need Immediate Replacement

One of the most practical aspects of Cloudflare's approach is its treatment of older origin infrastructure.

Legacy servers may not support modern post-quantum cryptography. Replacing them can be expensive, risky, or operationally impractical.

Cloudflare Tunnel provides one potential migration path by establishing a TLS 1.3 connection between the origin environment and Cloudflare using X25519MLKEM768, even when the underlying origin server itself cannot directly implement the newer cryptographic configuration.

This illustrates a broader principle in infrastructure modernization: transition layers can often extend the useful life of legacy systems while the wider ecosystem evolves.

That does not eliminate the need to modernize vulnerable systems, but it can reduce the pressure for simultaneous replacement.


The 2027 Milestone and the Longer Quantum Transition

Cloudflare expects to begin issuing certificates in the first quarter of 2027, including production Merkle Tree Certificates.

The transition, however, will not be completed in 2027.

For years, and potentially decades, classical and post-quantum certificate systems will coexist. Browsers, operating systems, servers, embedded devices, enterprise applications, and specialized infrastructure all have different upgrade cycles.

Cloudflare's plan to support both conventional certificates and Merkle Tree Certificates under a unified CA is designed around this reality.

Organizations will not necessarily need to choose between the old and new Internet at a single moment. Instead, quantum readiness can develop progressively as clients, servers, certificate authorities, browsers, and trust programs adopt compatible standards.


What Cloudflare's Strategy Means for Cybersecurity

The emerging transition changes the definition of long-term cybersecurity planning.

Quantum readiness is no longer solely a research question about whether a sufficiently powerful quantum computer will eventually exist. It is becoming a lifecycle-management problem involving cryptographic inventories, certificate infrastructure, software updates, network telemetry, supply-chain dependencies, and data retention periods.

Organizations should increasingly understand where cryptography is used, which algorithms protect their communications, how certificates are issued and renewed, and how quickly vulnerable systems can be replaced.

This is especially relevant for information whose confidentiality must survive for many years.

The transition also demonstrates why cryptographic agility matters. Systems designed to accommodate new algorithms without complete architectural reconstruction will be easier to migrate as standards evolve.


The Internet Is Preparing for a Different Cryptographic Era

Cloudflare's quantum-safe TLS initiative represents a broader transformation in the infrastructure beneath HTTPS.

The immediate objective is not simply to replace RSA or elliptic-curve cryptography. It is to redesign enough of the WebPKI that post-quantum authentication can become practical at Internet scale without overwhelming bandwidth, computation, certificate transparency systems, or device compatibility.

Hybrid ML-KEM is addressing the key-exchange side of the transition. Merkle Tree Certificates target the authentication challenge. New visibility tools allow organizations to measure progress. Automated certificate management provides the operational foundation for rapid renewal and migration. A new public certificate authority introduces another potential source of redundancy into a critical Internet ecosystem.

Taken together, these developments point toward an Internet where quantum resistance becomes part of ordinary security infrastructure rather than a specialized feature reserved for high-security environments.


For Dr. Shahid Masood and the expert team at 1950.ai, the significance extends beyond cryptography itself. The post-quantum transition sits at the intersection of artificial intelligence, cybersecurity, cloud infrastructure, digital identity, and emerging computing architectures. As quantum computing progresses, organizations that understand their cryptographic dependencies today will be better positioned to manage the security requirements of tomorrow.


The central lesson is clear: quantum-safe security cannot be installed at the last minute. The WebPKI, TLS, certificates, browsers, operating systems, data centers, and enterprise networks form a deeply interconnected ecosystem. Preparing that ecosystem will take years.

The race for quantum-safe Internet security has therefore already begun, not because cryptographically capable quantum computers are here, but because rebuilding the trust infrastructure of the global Internet is itself a long-term engineering project.


Key Takeaways

  • Cloudflare plans to become a public certificate authority and has applied to major browser and operating-system root programs.

  • The company plans to issue post-quantum Merkle Tree Certificates, targeting the first quarter of 2027.

  • Merkle Tree Certificates address the large certificate and signature sizes that could otherwise make post-quantum WebPKI impractical.

  • Hybrid X25519MLKEM768 is already protecting a substantial share of browser-generated traffic reaching Cloudflare.

  • Cloudflare reports approximately 70% post-quantum adoption for browser-to-Cloudflare traffic, compared with roughly 15% for Cloudflare-to-origin connections.

  • New telemetry in Cloudflare analytics and logging allows organizations to measure post-quantum TLS adoption at the domain and connection levels.

  • ACME automation and renewal mechanisms will become increasingly important as certificate lifetimes shrink and cryptographic transitions accelerate.

  • Post-quantum migration involves both encryption and authentication, and the two are progressing at different rates.

  • The quantum-safe Internet will require coordinated changes across certificate authorities, browsers, operating systems, servers, transparency logs, and enterprise infrastructure.


External References

Comments


bottom of page