Interestana
Home/News/Cloudflare to Offer Quantum-Resistant TLS Certificates, Acquiring GlobalSign Root
Ars Technica••4 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Cloudflare to Offer Quantum-Resistant TLS Certificates, Acquiring GlobalSign Root

Cloudflare to Offer Quantum-Resistant TLS Certificates, Acquiring GlobalSign Root

Cloudflare announced on Tuesday its strategic initiative to begin issuing quantum-proof Transport Layer Security (TLS) certificates. This move positions the internet infrastructure provider as one of the earliest authorities to offer such certificates, which are designed to withstand the advanced cryptographic attacks anticipated from future quantum computers. TLS, a foundational protocol for secure communication over the internet, relies on public-key cryptography to authenticate websites and encrypt data exchanged between users and servers. The advent of powerful quantum computers threatens to break many of the current encryption algorithms used in TLS, necessitating a transition to quantum-resistant cryptography. Cloudflare plans to implement this transition by utilizing an open-source platform that will issue both traditional, or "classic," TLS certificates and a new post-quantum equivalent known as Merkle Tree Certificates. These hybrid certificates are designed to offer a dual layer of security, ensuring compatibility with existing systems while preparing for the quantum threat. Crucially, Cloudflare stated that these hybrid certificates will be made available free of charge to all users, encompassing both paying and non-paying customers, thereby promoting broad adoption. To accelerate the integration and ensure widespread trust within the complex TLS ecosystem, Cloudflare is set to acquire an already established and trusted certificate root from CA GlobalSign. GlobalSign is a well-recognized and long-standing Certificate Authority (CA), meaning its root certificate is already embedded in many operating systems and browsers, providing a foundation of trust. Cloudflare anticipates that this acquisition and its new certificate issuance capabilities will enable millions of websites to adopt post-quantum certificates with remarkable ease, described as a simple "flip of a switch," without any discernible increase in performance overhead. This initiative represents a significant undertaking, signaling a fundamental architectural shift required within the web's Public Key Infrastructure (WebPKI). The WebPKI is the system of trust that underpins secure web browsing, and its overhaul is essential to maintain website encryption and authentication safety in the coming post-quantum era. A key technical challenge involves developing quantum-proof signature schemes that are not only secure against quantum attacks but also efficient enough for transmission during standard web requests. Furthermore, these signatures must be readily recordable in certificate transparency logs to effectively prevent the issuance of counterfeit certificates assigned to malicious websites. This comprehensive modernization of web security protocols is expected to be a multi-year endeavor, demanding the collaborative efforts of a vast number of engineers across various domains, including operating system developers, browser vendors, certificate authorities, and other internet infrastructure specialists. The global transition to quantum-resistant cryptography is a critical and ongoing effort, driven by the rapid advancements in quantum computing technology and the potential risks it poses to the security of online transactions and sensitive data.

Original source — read the full reporting at the publisher:

Read on Ars Technica

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next