Cloud EKM
Cloud EKM is one of the newest offerings for data protection. With Cloud EKM, you use the keys that you manage within an EKM partner.
Cloud EKM provides several benefits:
- Key provenance: You control the location and distribution of your externally managed keys. Externally managed keys are never cached or stored within Google Cloud. Instead, Cloud EKM communicates directly with the external key management partner for each request.
- Access control: You manage access to your externally managed keys. Before you can use an externally managed key to encrypt or decrypt data in Google Cloud, you must grant the Google Cloud project access to use the key. You can revoke this access at any time.
- Centralized key management: You can manage your keys and access policies from a specific location and user interface, whether the data they protect resides in the cloud or on your premises.
In all cases, the key resides on the external system and is never sent to Google...