Home / Blog / Google announces quantum-safe key import in Cloud KMS
Tech News

Google announces quantum-safe key import in Cloud KMS

Enterprise security teams adopting multicloud architectures rely on BYOK functionality to maintain strict data sovereignty over critical cloud workloads.

By Dillip Chowdary • Oct 10, 2026 • Source: Google Cloud Blog

Google announces quantum-safe key import in Cloud KMS

Google Cloud launched quantum-safe key import in preview for software-based cryptographic keys within Cloud Key Management Service (Cloud KMS) on August 21, 2026, as announced by Senior Software Engineer Alessio Buraggina and Senior Product Manager Erlander Lo in Google Cloud Blog's report. The feature provides updated bring your own key (BYOK) capabilities designed to help protect customer encryption keys during network transfer before cryptographically-relevant quantum computers emerge. Alongside the preview feature, Google Cloud introduced the general availability of Cloud KMS PQC insights, a visual dashboard that categorizes asymmetric keys according to their underlying cryptographic algorithms.

This article details the mechanics of the quantum-resistant transit envelope, the specific cryptographic primitives employed by Google Cloud, the exact API workflow steps required for implementation, and the target enterprise workloads for post-quantum security migration. It provides security administrators, cloud architects, and cryptographic engineers with the technical specification needed to migrate existing software key import pipelines to post-quantum standards.

Google quantum-safe key import in Cloud KMS: the announcement

Google Cloud expanded its post-quantum cryptography (PQC) portfolio within Cloud Key Management Service by introducing a preview of quantum-safe key import for software-based keys. Developed by Alessio Buraggina and Erlander Lo, this capability updates classical bring your own key import methods to defend enterprise cryptographic material against emerging quantum computing threats. Enterprise security teams adopting multicloud architectures rely on BYOK functionality to maintain strict data sovereignty over critical cloud workloads. This update represents the initial step in the next phase of Google Cloud's PQC migration timeline, following earlier releases of quantum-safe digital signatures and quantum-safe key encapsulation mechanisms (KEMs) in Cloud KMS.

To complement the preview of quantum-safe key import, Google Cloud announced the general availability of Cloud KMS PQC insights. This visual tool offers high-level visibility into an organization's post-quantum security posture by categorizing asymmetric keys based on their algorithm classifications. Enterprise security teams can use these insights to assess existing cryptographic assets, map out long-term modernization plans, and strengthen overall infrastructure resilience against future decryption technologies.

What actually changed with Google quantum-safe key import in Cloud KMS

Google announces quantum-safe key import in Cloud KMS
Illustration · Pexels

Traditional key import protocols rely on classical asymmetric encryption standards to wrap key material during transit across external networks. While classical algorithms adequately defend data against current interception techniques, adversaries can intercept and store encrypted key traffic today to decrypt it later using a cryptographically-relevant quantum computer (CRQC). Quantum-safe key import neutralizes these Store Now, Decrypt Later (SNDL) attacks by enclosing incoming key material inside a post-quantum transit envelope from the moment of transmission.

The post-quantum transit mechanism uses Hybrid Public Key Encryption (HPKE) integrated directly into the standard Cloud KMS API workflow. Customers initiate an import job by requesting a post-quantum HPKE method, prompting the server to generate a post-quantum KEM private key and expose the matching public key to the client. Using a compatible client-side cryptographic library such as Tink or OpenSSL, the client executes an HPKE Seal() operation to derive an ephemeral AES key via HKDF-SHA256 and encrypt the target key material. The client transmits the concatenated encapsulated ciphertext and encrypted payload to Cloud KMS, where an HPKE Open() operation decrypts the key within the secure boundary using algorithm options including X-Wing, ML-KEM-768, or ML-KEM-1024 alongside HKDF-SHA-256 and AES-256-GCM with 12-byte nonces.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Who should care about Google quantum-safe key import in Cloud KMS

Security engineers, cryptographic managers, and compliance officers responsible for high-value enterprise workloads should evaluate quantum-safe key import to mitigate long-term data exposure risks. Organizations bound by strict regulatory standards or data sovereignty mandates must ensure that keys transferred over public or shared cloud networks cannot be compromised retroactively by state-sponsored actors executing SNDL attacks. By adopting post-quantum wrapping mechanisms early, enterprises protect sensitive master keys that safeguard critical databases, confidential compute instances, and financial transaction records against future decryption.

Cloud architects managing multicloud environments also benefit from adopting Cloud KMS PQC insights alongside the updated import jobs. Security administrators responsible for tracking cryptographic asset lifecycles need a unified view of asymmetric key deployments across their organization. PQC insights allows teams to audit algorithm compliance, locate legacy asymmetric key pairs vulnerable to quantum attacks, and prioritize migration schedules without disrupting ongoing production operations.

How to try Google quantum-safe key import in Cloud KMS

Organizations can begin evaluating the feature by initiating a new quantum-safe key import job through the Cloud KMS API endpoint. Security teams must configure their local client environments with supported external cryptographic libraries, such as Google Tink or OpenSSL, to handle the client-side wrapping process. During import job creation, administrators explicitly select a post-quantum HPKE import method and specify their preferred key encapsulation algorithm from the supported options: X-Wing, ML-KEM-768, or ML-KEM-1024.

Once the job is configured, the local application retrieves the server's post-quantum public key and executes the HPKE Seal() procedure. This step establishes a shared secret, derives an ephemeral AES-256 key via HKDF-SHA-256, and wraps the software key using AES-256-GCM with standard 12-byte nonces. The resulting payload—comprising the encapsulated ciphertext concatenated with the encrypted key material—is transmitted directly to the Cloud KMS endpoint, where the service executes HPKE Open() to store the key securely within the Cloud KMS boundary. Detailed setup instructions are available in the official Cloud KMS quantum-safe key import documentation.

What to watch after Google quantum-safe key import in Cloud KMS

As post-quantum standards mature, enterprise security teams should monitor ongoing developments in algorithm standardization and client library integration. Google Cloud continues to advance its PQC migration roadmap, meaning future updates may expand quantum-safe import support beyond software keys to include hardware security module (HSM) key boundaries. Security personnel should track updates to external tools like Tink and OpenSSL to maintain compatibility with Cloud KMS API specifications.

Additionally, organizations should integrate Cloud KMS PQC insights into their regular operational security reviews to measure post-quantum migration progress over time. Monitoring the proportion of legacy asymmetric keys versus quantum-resistant keys enables security managers to report compliance metrics accurately to leadership. As cryptographically-relevant quantum computing capabilities move closer to reality, early adoption of post-quantum transit envelopes ensures enterprise data remains protected against intercept-and-store operations.

Developer Action Items

  • ☐ Verify the claim on the official Google page (or Google Cloud Blog), not from this recap alone.
  • ☐ Name the surface that moved — API, policy, model, hardware, or commercial terms — before you Slack the thread.
  • ☐ Assign one owner a day to read the primary material and decide: this-sprint, this-quarter, or noise.
  • ☐ Do not change production on day-one coverage. Watch the vendor changelog and one independent write-up first.

Google quantum-safe key import in Cloud KMS FAQ

What algorithms does Google Cloud KMS support for quantum-safe key import?

Cloud KMS supports X-Wing, ML-KEM-768, and ML-KEM-1024 for the key encapsulation layer, HKDF-SHA-256 for key derivation, and AES-256-GCM with 12-byte nonces for symmetric key wrapping.

What is a Store Now, Decrypt Later (SNDL) attack?

An SNDL attack occurs when an adversary intercepts and stores encrypted network traffic today with the intention of decrypting the stored key material in the future using a cryptographically-relevant quantum computer.

What libraries can developers use for client-side key wrapping?

Developers can use supported cryptographic libraries such as Google Tink or OpenSSL to perform the client-side HPKE Seal() operation required for quantum-safe key wrapping.

Is Cloud KMS PQC insights generally available?

Yes, Cloud KMS PQC insights is generally available and provides visual tracking of asymmetric keys based on their cryptographic algorithm classifications.

Sources

Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →