Google Cloud 默认启用传输加密,以便在传输前加密请求,并使用传输层安全协议 (TLS) 保护原始数据。
将数据传输到 Google Cloud 进行存储后, Google Cloud默认会应用静态加密。为了更好地控制静态加密数据的方式,Google Cloud 客户可以使用 Cloud Key Management Service 并根据自己的政策生成、使用、轮替和销毁加密密钥。这些密钥称为客户管理的加密密钥 (CMEK)。
如果您需要更好地控制用于对Google Cloud Google Cloud项目中的静态数据进行加密的密钥,而不是 Google Cloud的默认加密提供的密钥,则 Google Cloud 服务提供了使用客户在 Cloud KMS 中管理的加密密钥来保护数据的功能。这些加密密钥称为客户管理的加密密钥 (CMEK)。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-03-06。"],[[["Google Cloud employs default encryption for data both in transit, using TLS, and at rest, ensuring data protection."],["Customers can utilize Cloud Key Management Service (Cloud KMS) to create, manage, rotate, and destroy their own encryption keys, known as customer-managed encryption keys (CMEK), for enhanced control over data at rest."],["Assured Workloads offers the option to deploy a CMEK project alongside a resources project for specific control packages, allowing customers more control over data encryption."],["Google-owned and managed encryption keys, which are FIPS-140-2 compliant, are available as a default option and can support most control packages, but it is recommended that you choose between them or CMEK keys before creating your Assured Workloads folder."],["Cloud KMS provides detailed information and guides on managing CMEK, including tutorials and quickstarts for users seeking to implement customer-managed encryption."]]],[]]