Cloud KMS adds quantum-safe digital signatures and post-quantum key encapsulation
Google Cloud Key Management Service (Cloud KMS) now offers general availability for quantum-safe digital signatures (ML-DSA, SLH-DSA) and post-quantum key encapsulation (ML-KEM) to protect data integrity against future quantum computers. This update addresses the challenge of signing large data payloads efficiently and supports compliance with evolving regulatory mandates. The new capabilities are available now for all Cloud KMS users.
- →Quantum-safe digital signatures (ML-DSA, SLH-DSA) now generally available in Cloud KMS
- →Post-quantum key encapsulation (ML-KEM) support introduced
- →External-µ variants improve signing performance for large payloads
- →Migration planning and compliance support
Features (2) ›
- Quantum-safe digital signatures (ML-DSA, SLH-DSA) now generally available in Cloud KMS
Cloud KMS now supports ML-DSA and SLH-DSA digital signature algorithms, including efficient external-µ variants, to help organizations transition to quantum-safe cryptography. These algorithms provide support for signing large data payloads with reduced bandwidth and processing issues, aiding long-term data integrity.
- Post-quantum key encapsulation (ML-KEM) support introduced
Complementing the digital signatures, Cloud KMS also introduces support for post-quantum key encapsulation mechanisms (ML-KEM). This feature enables customers to begin migrating to post-quantum cryptographic standards.
Enhancements (1) ›
- External-µ variants improve signing performance for large payloads
The inclusion of external-µ variants for ML-DSA in Cloud KMS allows for efficient signing of large data payloads by enabling external hashing. This approach maintains bandwidth efficiency and compatibility with pure ML-DSA verifiers, while also providing non-resignability.
Notes (1) ›
- Migration planning and compliance support
The introduction of these PQC algorithms in Cloud KMS aims to help organizations prepare for quantum threats and comply with evolving regulatory requirements, such as those from the NSA and NIST. Google Cloud plans to continue updating services with future NIST standards.
https://cloud.google.com/blog/products/identity-security/future-proofing-data-integrity-quantum-safe-digital-signatures-in-cloud-kms/
Related releases
- Cloud SDK 578.0.0: Database Migration default change, AlloyDB backup DR GA, BigQuery improvements Google Cloud release notes ·
- GKE: Opt-out of Arm taint, CORS for Gateways Google Cloud release notes ·
- Confidential VM: August 2026 kernel update may impact AMD SEV-SNP instances Google Cloud release notes ·
- Security Command Center ServiceNow Integration Updates Google Cloud release notes ·
- Compute Engine C4D Instances Increase Hyperdisk Throughput Google Cloud release notes ·
- Spanner allows creating tables without explicit primary keys Google Cloud release notes ·