February 20, 2025

Google Cloud announces quantum-safe digital signatures in Cloud KMS

Investing.com -- Today, Google (NASDAQ: GOOGL ) announced the introduction of quantum-safe digital signatures (FIPS 204/FIPS 205) in Google Cloud Key Management Service (Cloud KMS) for software-based keys, which are currently available in preview. Google also provided a broad overview of its post-quantum strategy for Google Cloud encryption products, including Cloud KMS and Hardware Security Modules (Cloud HSM).

Google is actively working to make Google Cloud KMS quantum-safe. This comprehensive approach to quantum safety includes offering software and hardware support for standardized quantum-safe algorithms, supporting migration paths for existing keys, protocols, and customer workloads to adopt PQC, quantum-proofing Google's underlying core infrastructure, analyzing the security and performance of PQC algorithms and implementations, and contributing technical comments to PQC advocacy efforts in standards bodies and government organizations.

The Cloud KMS PQC roadmap includes support for the NIST post-quantum cryptography standards (FIPS 203, FIPS 204, FIPS 205, and future standards), in both software (Cloud KMS) and hardware (Cloud HSM). This can help customers perform quantum-safe key import and key exchange, encryption and decryption operations, and digital signature creation.

Google's underlying software implementations of these standards for Cloud KMS clients will be available as open-source software. They will also be maintained as part of the Google-authored, open-source cryptographic libraries BoringCrypto and Tink to enable full transparency and code-audibility of Google's algorithmic implementations to its customers and to the broader security community.

Google is also working closely with HSM vendors and Google Cloud External Key Manager (EKM) partners to strategize and enable successful quantum-safe cryptography for its customers.

Cloud KMS now offers quantum-safe digital signatures, allowing customers to use Google's existing API to cryptographically sign data and validate signatures using NIST-standardized quantum-safe cryptography with key pairs stored in Cloud KMS. This paves the way for testing and integrating these signing schemes into existing workflows ahead of broader adoption.

This article was generated with the support of AI and reviewed by an editor. For more information see our T&C.

OK