Google Cloud EKM (External Key Manager)
1 min
within google cloud key management service (kms), there are several different sub offerings, and google cloud external key manager (ekm) is one of them with google cloud ekm, you can use keys that you manage within a supported external key management partner (such as the {{vc}} enterprise key management service) to protect data within google cloud you can protect data at rest in google bigquery or compute engine persistent storage services or by calling the cloud key management service api directly key benefits the google cloud ekm {{vc}} integration provides the following benefits key provenance you control the location and distribution of your externally managed keys externally managed keys are never cached or stored within google cloud instead, cloud ekm communicates directly with virtucrypt for each request access control you manage access to your externally managed keys before you can use an externally managed key to encrypt or decrypt data in google cloud, you must grant the google cloud project access to use the key you can revoke this access at any time centralized key management you can manage your keys and access policies from a single location and user interface, whether the data they protect resides in the cloud or on your premises in all cases, the key resides in {{vc}} and is never sent to google