CryptoDB
Crypto Agility and Post-Quantum Cryptography @ Google
Authors: | |
---|---|
Download: | |
Abstract: | In this talk we will present challenges Google faces with key management, and how we built a system to instrument our cryptographic libraries to gain extensive observability into how our services use cryptographic key material in practice. This allows us to enforce best practices like key rotation, deleting old keys and respecting data limits, across global large scale distributed systems. Within Google, our tooling covers thousands of internal teams with diverse use cases, improving both security and reliability on a large scale. This talk also shows how we deployed post-quantum cryptography to Google's internal transport layer security protocol (ALTS), and made it the default option. We will talk about the challenges, both technical and organisational when making such a large-scale change to a global infrastructure as run by Google. We will share insights on the performance impact and discuss our design decisions and trade-offs. |
Video: | https://youtu.be/IAOWRO9Qn10?t=107 |
BibTeX
@misc{rwc-2023-35437, title={Crypto Agility and Post-Quantum Cryptography @ Google}, note={Video at \url{https://youtu.be/IAOWRO9Qn10?t=107}}, howpublished={Talk given at RWC 2023}, author={Stefan Kölbl and Anvita Pandit and Rafael Misoczki and Sophie Schmieg}, year=2023 }