Google’s Cloud Key Management Service (Cloud KMS) gets quantum-safe digital signatures to align with the National Institute of Standards and Technology (NIST) post-quantum cryptography (PQC) standards.
Google Cloud launches quantum-safe digital signatures
Google announced that it’s implementing quantum-safe digital signatures in its KMS system to align with the National Institute of Standards and Technology’s post-quantum cryptography standards and prepare for future risks from quantum computers breaking current encryption methods to secure its user’s sensitive data, which include government agencies and financial institutions.
Google wrote on its Cloud blog that it is โworking to make Google Cloud KMS quantum-safe,โ and the new standards software implementations will be available to its Cloud KMS clients as open-source software.
Future-proofing data
Google confirmed adding quantum-safe digital signatures to its key management service (KMS) to secure its users’ data from future attacks, such as โharvest now, decrypt laterโ (HNDL), in which cyber attackers steal encrypted data and store it until quantum computer capabilities enable them to decrypt it.
Google Cloudโs KMS aims to remove the risk of using public-key cryptography and allow users to encrypt and sign digital data securely. Businesses looking to enhance cloud security and implement quantum-resistant cryptography should consider hiring cloud developers with expertise in secure key management solutions.
Google said the update will counteract the security threat that experimental quantum computing will soon pose to traditional public-key cryptography systems currently used for encrypting data.
As businesses rely more heavily on cloud-hosted applications and workspaces, protecting data within those environments is becoming just as important as securing the devices used to access them. This is one reason security should be a key consideration when comparing desktop as a service providers, particularly for organizations that manage sensitive or regulated data in the cloud.
- โThe potential for sufficiently large, cryptographically relevant quantum computers to break these algorithms highlights the need for developers to build and implement quantum-resistant cryptography now.โ
Google added it will adapt to any future quantum cryptanalytic changes:
- โWe commit to staying on top of developments in post-quantum cryptography, including incorporating any future algorithm standards from NIST. We are prepared to adapt to any changes that may arise as the quantum cryptanalytic landscape evolves over time, particularly if future cryptanalysis demonstrates attacks that would materially affect the security of Google Cloud customers or their data.โ
Encryption protocol threat only years away
Google Cloud’s senior staff security engineer, Jennifer Fernick, and Cloud KMS engineering manager, Andrew Foster, said the risk of quantum computing breaking current encryption methods may be years away, but we must take action now.
Fernick and Foster wrote on Google’s blog:
- โWhile that future [where quantum computing helps breaking current encryption methods] may be years away, those deploying long-lived roots-of-trust or signing firmware for devices managing critical infrastructure should consider mitigation options against this threat vector now.โ
Adding:
- โThe sooner we’re able to secure these signatures, the more resilient the digital world’s foundation of trust becomes.โ
Google Cloud announced implementing quantum-safe digital signatures only days after Microsoft released the worldโs first quantum chip. Microsoft said during the release that quantum computers will break current encryption protocols in the next few years, not decades as previously expected.



