What extended encryptions are available?
In the table, you can see a comparison between the available encryption methods.
Cloud KMS with hardware-generated keys (Cloud HSM) is the recommended method.
Encryption Method | Description | Pros | Cons |
---|---|---|---|
Default encryption | All data at rest in Google Cloud is encrypted by default using Google-managed encryption keys. |
|
|
Cloud KMS with software-generated keys | Customer-managed encryption keys (CMEK) that are stored and managed in Google Cloud Key Management Service (Cloud KMS). |
|
|
Cloud KMS with hardware-generated keys (Cloud HSM) |
| CMEK that are stored and managed in a dedicated hardware security module (HSM) in Google Cloud. |
|
Cloud KMS with external key manager (Cloud EKM )
Local EHSM | CMEK that are stored and managed in a third-party key management service (HYOKM hold your own key manager).
External HSM enables clients to install an HSM module from an external HSM module manufacturer within the client's network. |
|
|