Cloud KMS adds quantum-safe digital signatures and post-quantum key encapsulation
Google Cloud Key Management Service (Cloud KMS) now offers general availability for quantum-safe digital signatures (ML-DSA, SLH-DSA) and post-quantum key encapsulation (ML-KEM) to protect data integrity against future quantum computers. This update addresses the challenge of signing large data payloads efficiently and supports compliance with evolving regulatory mandates. The new capabilities are available now for all Cloud KMS users.
- →Quantum-safe digital signatures (ML-DSA, SLH-DSA) now generally available in Cloud KMS
- →Post-quantum key encapsulation (ML-KEM) support introduced
- →External-µ variants improve signing performance for large payloads
- →Migration planning and compliance support
Features (2) ›
- Quantum-safe digital signatures (ML-DSA, SLH-DSA) now generally available in Cloud KMS
Cloud KMS now supports ML-DSA and SLH-DSA digital signature algorithms, including efficient external-µ variants, to help organizations transition to quantum-safe cryptography. These algorithms provide support for signing large data payloads with reduced bandwidth and processing issues, aiding long-term data integrity.
- Post-quantum key encapsulation (ML-KEM) support introduced
Complementing the digital signatures, Cloud KMS also introduces support for post-quantum key encapsulation mechanisms (ML-KEM). This feature enables customers to begin migrating to post-quantum cryptographic standards.
Enhancements (1) ›
- External-µ variants improve signing performance for large payloads
The inclusion of external-µ variants for ML-DSA in Cloud KMS allows for efficient signing of large data payloads by enabling external hashing. This approach maintains bandwidth efficiency and compatibility with pure ML-DSA verifiers, while also providing non-resignability.
Notes (1) ›
- Migration planning and compliance support
The introduction of these PQC algorithms in Cloud KMS aims to help organizations prepare for quantum threats and comply with evolving regulatory requirements, such as those from the NSA and NIST. Google Cloud plans to continue updating services with future NIST standards.
https://cloud.google.com/blog/products/identity-security/future-proofing-data-integrity-quantum-safe-digital-signatures-in-cloud-kms/
Related releases
- GKE introduces Agent Substrate to scale agentic workloads efficiently Google Cloud release notes ·
- Apigee X fixes SemanticCacheLookup incompatibility with Vertex AI Vector Search PSC Google Cloud release notes ·
- Cluster Toolkit v1.102.0 Enhances GKE with MTC, Flex Volumes, and HPC Capabilities Google Cloud release notes ·
- Google Cloud's Managed Apache Airflow receives new features and improved resilience Google Cloud release notes ·
- Google Cloud CCaaS v6.12 Adds Cold Transfer Auto-Resume, HubSpot DNC, & Network Diagnostics Google Cloud release notes ·
- Google Addresses Security Vulnerabilities in Slurm for Cluster Toolkit Google Cloud release notes ·