Google Cloud Blog
Follow
Announcing quantum-safe key import in Cloud KMS
Enterprises adopt multicloud, making Bring Your Own Key (BYOK) vital for data sovereignty and protecting cloud workloads. Quantum computing's advancement necessitates re-evaluating secure encryption key transfer. Google Cloud KMS now offers a preview of quantum-safe key import for software-based cryptographic keys. This new BYOK capability is the first step in their post-quantum cryptography migration. It helps protect sensitive keys before a cryptographically-relevant quantum computer emerges. Alongside this, Cloud KMS's generally available PQC insights allow monitoring of the post-quantum posture. Traditional key import methods are vulnerable to "store now, decrypt later" attacks by future quantum computers. Quantum-safe key import mitigates these attacks by wrapping keys in a quantum-resistant envelope from the start. The new transit mechanism uses hybrid public key encryption (HPKE) with client-side wrapping and server-side unwrapping. This process integrates into the existing Cloud KMS API workflow, minimizing user effort and providing built-in data-in-transit protection.