This document describes the features, configurations and APIs in Cloud Key Management Service that align
with the controls for supported control packages. This document assumes that
you're using Assured Workloads .
Show All
India Data Boundary
Australia Data Boundary and Support
Canada Data Boundary and Support
EU Data Boundary and Support
Israel Data Boundary and Support
Japan Data Boundary
US Data Boundary and Support
Data Boundary for CJIS
Data Boundary for Canada Protected B
Data Boundary for FedRAMP High
Data Boundary for FedRAMP Moderate
Data Boundary for IRS Publication 1075
Data Boundary for ITAR
Data Boundary for Impact Level 2 (IL2)
Data Boundary for Impact Level 4 (IL4)
Data Boundary for Impact Level 5 (IL5)
EU Data Boundary with Access Justifications
Kingdom of Saudi Arabia (KSA) Data Boundary with Access Justifications
Sovereign Controls Advanced KSA CNTXT
Sovereign Controls Foundation KSA CNTXT
Sovereign Controls by Indra / Minsait
Sovereign Controls by PSN (TIM)
Sovereign Controls by S3NS / Thales
Sovereign Controls by T-Systems
US Data Boundary for Healthcare and Life Sciences
India Data Boundary
Supported services
The following table lists the Cloud Key Management Service APIs and versions that meet the requirements of India Data Boundary.
Service
Version
Status
cloudkms.googleapis.com
v1
SUPPORTED
API fields for sensitive data
Resource: cloudkms.googleapis.com/CryptoKey
The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.
API Method
Protected fields
Service: cloudkms.googleapis.com
REST API: GET /v1/{parent=projects/*/locations/*/keyRings/*}/cryptoKeys
RPC methods:
google.cloud.kms.v1.KeyManagementService.ListCryptoKeys
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/**}:encrypt
RPC methods:
google.cloud.kms.v1.KeyManagementService.Encrypt
additionalAuthenticatedData
additionalAuthenticatedDataChecksum.crc32c.value
additionalAuthenticatedDataCrc32c.value
plaintext
plaintextChecksum.crc32c.value
plaintextCrc32c.value
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*}:decrypt
RPC methods:
google.cloud.kms.v1.KeyManagementService.Decrypt
additionalAuthenticatedData
additionalAuthenticatedDataCrc32c.value
ciphertext
ciphertextCrc32c.value
Service: cloudkms.googleapis.com
REST API: POST /v1/{parent=projects/*/locations/*/keyRings/*}/cryptoKeys
RPC methods:
google.cloud.kms.v1.KeyManagementService.CreateCryptoKey
Resource: cloudkms.googleapis.com/CryptoKeyVersion
The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.
API Method
Protected fields
Service: cloudkms.googleapis.com
REST API: GET /v1/{parent=projects/*/locations/*/keyRings/*/cryptoKeys/*}/cryptoKeyVersions
RPC methods:
google.cloud.kms.v1.KeyManagementService.ListCryptoKeyVersions
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:asymmetricDecrypt
RPC methods:
google.cloud.kms.v1.KeyManagementService.AsymmetricDecrypt
ciphertext
ciphertextCrc32c.value
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:asymmetricSign
RPC methods:
google.cloud.kms.v1.KeyManagementService.AsymmetricSign
data
dataCrc32c.value
digest.externalMu
digest.sha256
digest.sha384
digest.sha512
digestCrc32c.value
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:decapsulate
RPC methods:
google.cloud.kms.v1.KeyManagementService.Decapsulate
ciphertext
ciphertextCrc32c.value
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:macSign
RPC methods:
google.cloud.kms.v1.KeyManagementService.MacSign
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:macVerify
RPC methods:
google.cloud.kms.v1.KeyManagementService.MacVerify
data
dataCrc32c.value
mac
macCrc32c.value
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:rawDecrypt
RPC methods:
google.cloud.kms.v1.KeyManagementService.RawDecrypt
additionalAuthenticatedData
additionalAuthenticatedDataCrc32c.value
ciphertext
ciphertextCrc32c.value
initializationVector
initializationVectorCrc32c.value
Service: cloudkms.googleapis.com
REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:rawEncrypt
RPC methods:
google.cloud.kms.v1.KeyManagementService.RawEncrypt
additionalAuthenticatedData
additionalAuthenticatedDataCrc32c.value
initializationVector
initializationVectorCrc32c.value
plaintext
plaintextCrc32c.value
Resource: cloudkms.googleapis.com/ImportJob
The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.
API Method
Protected fields
Service: cloudkms.googleapis.com
REST API: GET /v1/{name=projects/*/locations/*/keyRings/*/importJobs/*}
RPC methods:
google.cloud.kms.v1.KeyManagementService.GetImportJob
Service: cloudkms.googleapis.com
REST API: GET /v1/{parent=projects/*/locations/*/keyRings/*}/importJobs
RPC methods:
google.cloud.kms.v1.KeyManagementService.ListImportJobs
Service: cloudkms.googleapis.com
REST API: POST /v1/{parent=projects/*/locations/*/keyRings/*}/importJobs
RPC methods:
google.cloud.kms.v1.KeyManagementService.CreateImportJob
Resource: cloudkms.googleapis.com/KeyRing
The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.
API Method
Protected fields
Service: cloudkms.googleapis.com
REST API: GET /v1/{parent=projects/*/locations/*}/keyRings
RPC methods:
google.cloud.kms.v1.KeyManagementService.ListKeyRings
Service: cloudkms.googleapis.com
REST API: POST /v1/{parent=projects/*/locations/*}/keyRings
RPC methods:
google.cloud.kms.v1.KeyManagementService.CreateKeyRing
Resource: cloudkms.googleapis.com/Location
The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.
API Method
Protected fields
Service: cloudkms.googleapis.com
REST API: POST /v1/{location=projects/*/locations/*}:generateRandomBytes
RPC methods:
google.cloud.kms.v1.KeyManagementService.GenerateRandomBytes
lengthBytes
location
protectionLevel
Resource: cloudkms.googleapis.com/PublicKey
The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.
API Method
Protected fields
Service: cloudkms.googleapis.com
REST API: GET /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}/publicKey
RPC methods:
google.cloud.kms.v1.KeyManagementService.GetPublicKey
Fields not intended for Sensitive data
The following table provides an illustrative list of field categories and specific fields that aren't suitable for sensitive information. To maintain compliance, avoid placing protected data in these fields. For a complete list, contact your Google Cloud representative.
Category
Fields
Contextual information
callerProvidedContext.fields.key
callerProvidedContext.fields.value.stringValue
Filtering and sorting
Key access controls
cryptoKeyVersion.externalProtectionLevelOptions.ekmConnectionBackendOverride
cryptoKeyVersion.externalProtectionLevelOptions.externalKeyUri
ekmConnection.serviceResolvers.endpointFilter
ekmConnection.serviceResolvers.hostname
ekmConnection.serviceResolvers.serviceDirectoryService
keyAccessJustificationsPolicyConfig.name