None
EN
Cloud cryptography demystified: Google Cloud Platform
['Scott Arciszewski']
The Trail of Bits Blog
This post, the second in our series on cryptography in the cloud, provides an overview of the cloud cryptography services offered within Google Cloud Platform (GCP): when to use them, when not to use them, and important usage considerations. Cloud KMS with software keys Cloud HSM, which performs all cryptographic operations in the HSM hardware Cloud EKM, where keys are stored in an external provider, for customers that need to maintain sovereignty over their encryption materials Tink is the sole cryptography library developed by Google that GCP customers are encouraged to use for client-side encryption for Google’s cloud products.