Google and Cloudflare Test Merkle Trees for Quantum-Resistant Web Security
Google has proposed Merkle trees as a way to help protect the WebPKI—the system that secures HTTPS certificates—from future quantum-computing threats. Google and Cloudflare are testing the approach in a limited pilot program.
A Merkle tree is a hierarchical data structure that uses cryptographic hashes to verify large amounts of information by checking only a small portion of the underlying data. The design could reduce certificate-handshake data to about 40 kilobytes, roughly the amount currently processed.
How Merkle trees could simplify certificate verification
Today’s WebPKI relies on certificate chains, in which multiple links and cryptographic signatures prove that a certificate is authentic. Replacing those signatures with quantum-resistant algorithms can require significantly more resources. Merkle tree certificates address this challenge by replacing much of the chain with a compact proof.
Under the proposed design, a certificate authority signs a single “tree head” representing millions of certificates. In most cases, a browser processes only lightweight evidence—known as a Merkle proof or inclusion proof—showing that a particular certificate is included in the tree.
Why certificate transparency matters
Industry rules require TLS certificates to be published in an append-only, distributed ledger known as a public certificate transparency log. Website owners can monitor these logs to verify that fraudulent certificates have not been issued for their domains.
The importance of certificate transparency became clear after the 2011 DigiNotar hack. The Netherlands-based certificate authority authorized the creation of 500 fake certificates for Google and other websites. Some of those certificates were used to spy on Iranian web users.
Preparing for quantum attacks on public-key cryptography
If Shor’s algorithm becomes viable on a sufficiently powerful quantum computer, attackers could potentially forge traditional cryptographic signatures and public keys recorded in certificate logs. They could also manipulate the timestamp on a signed certificate intended to prove that the certificate was registered with a browser or operating system.
In current PKI systems, updates are handled by adding new links to a signature chain. Merkle trees can provide evidence for those chains without explicitly listing every individual link.
The design could also make certificate transparency a built-in part of certificate issuance. Today, certificate issuance and transparency logging are separate processes. With Merkle tree certificates, logging becomes an operational requirement rather than an optional add-on.
“Combining publishing and logging makes transparency an operational requirement rather than an add-on,” said Mari Galicer, a Cloudflare engineer.
Cloudflare’s plans for quantum-resistant certificates
Cloudflare is exploring several related designs, including an automated certificate management environment based on ACME. The open-source mechanism issues certificates and continually renews them before they expire.
Quantum-resistant certificates could also support out-of-band signature delivery, such as through browser updates, if updated Merkle proofs cannot be received because a server is unavailable or another technical problem occurs.
Cloudflare said it plans to begin issuing these certificates in the first quarter of 2027.
Source: arstechnica.com


