Google Cloud Platform
Fortanix for Google Cloud Platform
Experience enhanced control, security, and authority over your data and cryptographic keys for Google Cloud Platform with Google External Key Management and Client-Side Encryption.
Overview
As organizations construct multi-cloud frameworks and slide data across various cloud platforms—they have little to no control over the CSP’s data security and key management practices. Not surprisingly, these limitations present severe security and compliance risks. Hence, businesses must advance beyond cloud-vendor-specific data security solutions. And that is precisely what Google is trying to achieve with Google External Key Manager and Google Client-Side Encryption.

Fortanix Solution
Services running on GCP, such as Big Query and GCE, currently can use an encryption key hosted by Google Cloud KMS or Cloud HSM to secure their data at rest. An envelope encryption scheme is followed where the data is encrypted using a local data encryption key (DEK), which in turn is encrypted using a key encryption key (KEK) in Cloud KMS or Cloud HSM. Google allays the concerns of customers who don’t want to trust the public cloud by extending the envelope encryption scheme to allow the KEK to be encrypted using an externally managed key encryption key (EKEK).

Benefits

Simplified and Centralized Encryption
Fortanix with Google Cloud’s External Key Manager provides a single, simple, and centralized encryption platform that accelerates moving applications to public cloud, while also providing a single set of cryptographic services to on-premises, hybrid, and cloud workload.

No Access to Plain-Text Content
Your Google Workspace data gets encrypted in the browser before taking off to the Google servers. If Google needs access to this data, it will need explicit customer authorization on a per-file basis.

Meet Compliance Requirements
Fortanix offers a FIPS 140-2 Level 3 certified appliance, to store the cloud keys on-premises and enabling financial services, healthcare, and other regulated industries to meet compliance requirements.

Key Provenance
Control the location and distribution of your Google Workspace keys.

Unmatched Scalability
Collaborate and scale globally over Google Workspace with zero worries of keys storage location and management. Keys are never cached on Google cloud and access can be revoked anytime.
Featured Resource
Protect Private Data in Google Cloud
Resources



On-Demand Webinar