Google Online Security Blog
Follow
Cultivating a robust and efficient quantum-safe HTTPS
Google Chrome is implementing a new program to secure HTTPS certificates against quantum computers using Merkle Tree Certificates (MTCs). MTCs replace traditional certificate chains with lightweight proofs, improving performance and bandwidth efficiency. Chrome's rollout includes three phases, starting with feasibility studies with Cloudflare, which are currently underway. Phase two, planned for Q1 2027, involves bootstrapping public MTCs with existing Certificate Transparency (CT) log operators. Phase three, slated for Q3 2027, will introduce the Chrome Quantum-resistant Root Store (CQRS) for MTCs, alongside the existing Chrome Root Program. The CQRS will cater specifically to a post-quantum web environment. This phased approach ensures a smooth transition and maintains security for all users throughout the process. Chrome will also support traditional X.509 certificates with quantum-resistant algorithms for private PKIs. Simultaneously, Chrome focuses on enhancing existing practices via ACME-only workflows and better revocation status communication. The team is actively contributing to industry standards and fostering transparency through approaches like DCV monitoring. Chrome prioritizes security, simplicity, and resilience in its approach to the quantum-resistant web. The program aims to create a more secure and reliable web ecosystem for the future.