Regulatory support in Cloud Key Management Service

This document describes the features, configurations and APIs in Cloud Key Management Service that align with the controls for supported control packages. This document assumes that you're using Assured Workloads.

India Data Boundary

Supported services

The following table lists the Cloud Key Management Service APIs and versions that meet the requirements of India Data Boundary.

Service Version Status
cloudkms.googleapis.com v1 SUPPORTED

API fields for sensitive data

Resource: cloudkms.googleapis.com/CryptoKey

The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.

API Method Protected fields

Service: cloudkms.googleapis.com

REST API: GET /v1/{parent=projects/*/locations/*/keyRings/*}/cryptoKeys

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.ListCryptoKeys
  • filter
  • orderBy

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/**}:encrypt

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.Encrypt
  • additionalAuthenticatedData
  • additionalAuthenticatedDataChecksum.crc32c.value
  • additionalAuthenticatedDataCrc32c.value
  • plaintext
  • plaintextChecksum.crc32c.value
  • plaintextCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*}:decrypt

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.Decrypt
  • additionalAuthenticatedData
  • additionalAuthenticatedDataCrc32c.value
  • ciphertext
  • ciphertextCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{parent=projects/*/locations/*/keyRings/*}/cryptoKeys

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.CreateCryptoKey
  • cryptoKeyId

Resource: cloudkms.googleapis.com/CryptoKeyVersion

The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.

API Method Protected fields

Service: cloudkms.googleapis.com

REST API: GET /v1/{parent=projects/*/locations/*/keyRings/*/cryptoKeys/*}/cryptoKeyVersions

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.ListCryptoKeyVersions
  • filter
  • orderBy

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:asymmetricDecrypt

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.AsymmetricDecrypt
  • ciphertext
  • ciphertextCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:asymmetricSign

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.AsymmetricSign
  • data
  • dataCrc32c.value
  • digest.externalMu
  • digest.sha256
  • digest.sha384
  • digest.sha512
  • digestCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:decapsulate

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.Decapsulate
  • ciphertext
  • ciphertextCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:macSign

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.MacSign
  • data
  • dataCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:macVerify

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.MacVerify
  • data
  • dataCrc32c.value
  • mac
  • macCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:rawDecrypt

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.RawDecrypt
  • additionalAuthenticatedData
  • additionalAuthenticatedDataCrc32c.value
  • ciphertext
  • ciphertextCrc32c.value
  • initializationVector
  • initializationVectorCrc32c.value

Service: cloudkms.googleapis.com

REST API: POST /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}:rawEncrypt

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.RawEncrypt
  • additionalAuthenticatedData
  • additionalAuthenticatedDataCrc32c.value
  • initializationVector
  • initializationVectorCrc32c.value
  • plaintext
  • plaintextCrc32c.value

Resource: cloudkms.googleapis.com/ImportJob

The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.

API Method Protected fields

Service: cloudkms.googleapis.com

REST API: GET /v1/{name=projects/*/locations/*/keyRings/*/importJobs/*}

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.GetImportJob
  • publicKeyFormat

Service: cloudkms.googleapis.com

REST API: GET /v1/{parent=projects/*/locations/*/keyRings/*}/importJobs

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.ListImportJobs
  • filter
  • orderBy

Service: cloudkms.googleapis.com

REST API: POST /v1/{parent=projects/*/locations/*/keyRings/*}/importJobs

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.CreateImportJob
  • importJobId

Resource: cloudkms.googleapis.com/KeyRing

The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.

API Method Protected fields

Service: cloudkms.googleapis.com

REST API: GET /v1/{parent=projects/*/locations/*}/keyRings

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.ListKeyRings
  • filter
  • orderBy

Service: cloudkms.googleapis.com

REST API: POST /v1/{parent=projects/*/locations/*}/keyRings

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.CreateKeyRing
  • keyRingId

Resource: cloudkms.googleapis.com/Location

The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.

API Method Protected fields

Service: cloudkms.googleapis.com

REST API: POST /v1/{location=projects/*/locations/*}:generateRandomBytes

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.GenerateRandomBytes
  • lengthBytes
  • location
  • protectionLevel

Resource: cloudkms.googleapis.com/PublicKey

The following table specifies the API resources and fields that are designed to handle data that is protected under India Data Boundary.

API Method Protected fields

Service: cloudkms.googleapis.com

REST API: GET /v1/{name=projects/*/locations/*/keyRings/*/cryptoKeys/*/cryptoKeyVersions/*}/publicKey

RPC methods:

  • google.cloud.kms.v1.KeyManagementService.GetPublicKey
  • publicKeyFormat

Fields not intended for Sensitive data

The following table provides an illustrative list of field categories and specific fields that aren't suitable for sensitive information. To maintain compliance, avoid placing protected data in these fields. For a complete list, contact your Google Cloud representative.

Category Fields
Contextual information
  • callerProvidedContext.fields.key
  • callerProvidedContext.fields.value.stringValue
Filtering and sorting
  • filter
  • orderBy
  • pageToken
Key access controls
  • cryptoKeyVersion.externalProtectionLevelOptions.ekmConnectionBackendOverride
  • cryptoKeyVersion.externalProtectionLevelOptions.externalKeyUri
  • ekmConnection.serviceResolvers.endpointFilter
  • ekmConnection.serviceResolvers.hostname
  • ekmConnection.serviceResolvers.serviceDirectoryService
  • keyAccessJustificationsPolicyConfig.name