Meta tags:
Headings (most frequently used words):
keys, rotate, and, key, rotation, stay, organized, with, collections, save, categorize, content, based, on, your, preferences, why, how, often, to, after, you, considerations, for, asymmetric, what, next, products, pricing, support, resources, engage,
Text of the page (most frequently used words):
key (81), and (46), the (42), cloud (34), keys (29), for (25), data (24), #rotation (22), version (21), you (17), google (14), with (14), create (14), your (12), rotate (11), that (11), security (11), encryption (10), use (10), kms (10), asymmetric (9), new (9), encrypt (9), application (9), overview (9), resources (7), thumb (7), can (7), management (7), see (6), access (6), automatic (6), rotating (6), encrypted (6), schedule (6), number (6), ekm (6), hsm (6), manage (5), code (5), samples (5), more (5), decrypt (5), versions (5), compromised (5), regular (5), messages (5), using (5), view (5), import (5), português (4), español (4), about (4), support (4), down (4), encrypting (4), disable (4), not (4), costs (4), manual (4), algorithm (4), manually (4), validate (4), symmetric (4), service (4), industry (4), tools (4), usage (4), monitor (4), reference (4), signatures (4), cmek (4), autokey (4), sign (3), information (3), need (3), content (3), this (3), are (3), enable (3), must (3), public (3), portion (3), applications (3), does (3), additional (3), before (3), destroying (3), destroy (3), previous (3), when (3), automatically (3), require (3), based (3), either (3), guides (3), monitoring (3), troubleshoot (3), external (3), resource (3), set (3), organization (3), wrapping (3), product (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), terms (2), site (2), youtube (2), events (2), started (2), system (2), pricing (2), products (2), understand (2), other (2), last (2), updated (2), 2026 (2), utc (2), otherwise (2), noted (2), page (2), licensed (2), under (2), details (2), policies (2), license (2), send (2), feedback (2), learn (2), used (2), distribute (2), update (2), because (2), considerations (2), loss (2), active (2), doesn (2), delete (2), how (2), after (2), also (2), suspect (2), migrate (2), stronger (2), date (2), time (2), modify (2), existing (2), some (2), such (2), occurs (2), same (2), lifetime (2), bytes (2), recommended (2), specific (2), documentation (2), sdk (2), languages (2), frameworks (2), infrastructure (2), storage (2), observability (2), networking (2), migration (2), solutions (2), distributed (2), hybrid (2), multicloud (2), databases (2), analytics (2), pipelines (2), compute (2), hosting (2), development (2), audit (2), logging (2), get (2), encapsulation (2), mechanisms (2), mac (2), workspace (2), verify (2), end (2), api (2), control (2), policy (2), wrap (2), openssl (2), single (2), tenant (2), console (2), cross (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, action, join, cookies, privacy, tech, twitter, blog, engage, training, certification, architecture, center, getting, github, status, release, notes, community, forums, contact, sales, marketplace, all, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missing, missingtheinformationsamplesineed, otherdown, tell, except, java, registered, trademark, oracle, its, affiliates, developers, apache, creative, commons, attribution, what, next, incorporate, into, grant, private, afterward, specify, calls, method, signature, cryptokeyversions, asymmetricsign, signing, steps, required, still, cause, permanent, responsibility, ensure, safe, responsible, outages, compliance, issues, result, from, warning, make, sure, longer, creates, but, remain, incur, until, they, destroyed, removes, reliance, old, allowing, them, avoid, incurring, don, rely, irregular, primary, component, isn, note, should, has, been, guidelines, future, pause, impact, regulations, periodic, defined, period, every, days, increases, minimal, administrative, complexity, recommend, defines, frequency, optionally, first, age, volume, often, different, ensures, resilient, whether, due, breach, cryptographic, procedures, real, life, incident, soon, possible, revoke, event, limits, actual, vulnerable, compromise, limiting, helps, prevent, attacks, enabled, cryptanalysis, recommendations, depend, well, produced, total, example, galois, counter, mode, gcm, https, nvlpubs, nist, gov, nistpubs, legacy, nistspecialpublication800, 38d, pdf, provides, several, benefits, document, periodically, practice, standards, pci, dss, payment, card, standard, why, discusses, process, creating, replace, reduce, potential, consequences, being, instructions, save, categorize, preferences, stay, organized, collections, home, via, vpc, errors, failed, imports, adjust, quotas, state, changes, inventory, restore, tags, label, post, quantum, cryptography, pqc, insights, attest, retrieve, metrics, project, states, consistency, encapsulate, decapsulate, kems, share, secrets, digital, onboard, client, side, tink, integrity, raw, authenticated, envelope, generate, random, sort, filter, list, results, grpc, apis, secure, destruction, custom, constraints, contraints, iam, roles, connection, over, internet, imported, configure, format, ring, automate, creation, instances, best, practices, separation, duties, purposes, algorithms, locations, compatible, services, architectures, protection, levels, discover, start, free, skip, main,
Text of the page (random words):
key rotation cloud key management service google cloud documentation skip to main content technology areas close ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage cross product tools close access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools console english deutsch español español américa latina français indonesia italiano português português brasil עברית 中文 简体 中文 繁體 日本語 한국어 sign in cloud kms start free overview guides reference samples resources technology areas more overview guides reference samples resources cross product tools more console discover product overview protection levels overview cloud hsm overview single tenant cloud hsm overview cloud ekm overview reference architectures for cloud ekm cmek overview cloud kms with autokey compatible services cloud hsm for google workspace locations get started cloud kms resources key purposes and algorithms separation of duties create and use encryption keys cmek best practices cmek key rotation create and manage single tenant cloud hsm instances create keys automate key creation autokey overview enable autokey create a resource with autokey create a key ring create a key import keys about key import key wrapping format a key for import manually wrap a key for import configure openssl for manual key wrapping wrap a key using openssl set up automatic key wrapping import a key version verify an imported key version create external keys set up cloud ekm over the internet create an ekm connection create an external key control access manage iam roles use organization policy contraints create custom organization policy constraints for cloud kms cmek organization policies control key destruction secure data using keys key apis use grpc access the api sort and filter api list results generate random bytes use cloud kms keys in google cloud encrypt and decrypt data envelope encryption additional authenticated data asymmetric encryption encrypt and decrypt data with a symmetric key encrypt and decrypt data with a raw symmetric key encrypt and decrypt data with an asymmetric key verify end to end data integrity encrypt application data set up client side encryption with tink onboard to cloud hsm for google workspace sign and validate data digital signatures create and validate signatures mac signatures create and validate mac signatures share secrets using key encapsulation mechanisms key encapsulation mechanisms encapsulate and decapsulate using kems manage keys resource consistency key version states view keys and key details view keys by project view encryption metrics view key usage get a cloud kms resource id retrieve a public key attest a cloud hsm key view post quantum cryptography pqc insights label a key create and manage tags enable and disable a key version destroy and restore a key version delete cloud kms resources rotate keys about key rotation rotate a key re encrypt data update external key reference monitor using cloud audit logging cloud kms inventory service audit logging monitor state changes monitor and adjust quotas use cloud monitoring monitor ekm usage troubleshoot troubleshoot failed imports troubleshoot ekm via vpc errors ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools home documentation security cloud kms guides send feedback key rotation stay organized with collections save and categorize content based on your preferences this page discusses key rotation in cloud key management service key rotation is the process of creating new encryption keys to replace existing keys by rotating your encryption keys on a regular schedule or after specific events you can reduce the potential consequences of your key being compromised for specific instructions to rotate a key see rotating keys why rotate keys for symmetric encryption periodically and automatically rotating keys is a recommended security practice some industry standards such as payment card industry data security standard pci dss require the regular rotation of keys cloud key management service does not support automatic rotation of asymmetric keys see considerations for asymmetric keys in this document rotating keys provides several benefits limiting the number of messages encrypted with the same key version helps prevent attacks enabled by cryptanalysis key lifetime recommendations depend on the key s algorithm as well as either the number of messages produced or the total number of bytes encrypted with the same key version for example the recommended key lifetime for symmetric encryption keys in galois counter mode gcm is based on the number of messages encrypted as noted at https nvlpubs nist gov nistpubs legacy sp nistspecialpublication800 38d pdf in the event that a key is compromised regular rotation limits the number of actual messages vulnerable to compromise if you suspect that a key version is compromised disable it and revoke access to it as soon as possible regular key rotation ensures that your system is resilient to manual rotation whether due to a security breach or the need to migrate your application to a stronger cryptographic algorithm validate your key rotation procedures before a real life security incident occurs you can also manually rotate a key either because it is compromised or to modify your application to use a different algorithm how often to rotate keys we recommend that you rotate keys automatically on a regular schedule a rotation schedule defines the frequency of rotation and optionally the date and time when the first rotation occurs the rotation schedule can be based on either the key s age or the number or volume of messages encrypted with a key version some security regulations require periodic automatic key rotation automatic key rotation at a defined period such as every 90 days increases security with minimal administrative complexity you should also manually rotate a key if you suspect that it has been compromised or when security guidelines require you to migrate an application to a stronger key algorithm you can schedule a manual rotation for a date and time in the future manually rotating a key does not pause modify or otherwise impact an existing automatic rotation schedule for the key note when you rotate a key data encrypted with previous key versions isn t automatically re encrypted with the new key version for more information see re encrypting data don t rely on irregular or manual rotation as a primary component of your application s security after you rotate keys rotating keys creates new active key versions but doesn t re encrypt your data and doesn t disable or delete previous key versions previous key versions remain active and incur costs until they are destroyed re encrypting data removes your reliance on old key versions allowing you to destroy them to avoid incurring additional costs to learn how to re encrypt your data see re encrypting data you must make sure that a key version is no longer in use before destroying the key version warning destroying a key version that is still in use can cause permanent data loss it s your responsibility to ensure that a key version is safe to destroy google is not responsible for outages loss of data or compliance issues that result from you destroying a key version considerations for asymmetric keys cloud kms does not support automatic rotation for asymmetric keys because additional steps are required before you can use the new asymmetric key version for asymmetric keys used for signing you must distribute the public key portion of the new key version afterward you can specify the new key version in calls to the cryptokeyversions asymmetricsign method to create a signature and update applications to use the new key version for asymmetric keys used for encryption you must distribute and incorporate the public portion of the new key version into applications that encrypt data and grant access to the private portion of the new key version for applications that decrypt data what s next rotate a key enable or disable a key learn more about re encrypting data send feedback except as otherwise noted the content of this page is licensed under the creative commons attribution 4 0 license and code samples are licensed under the apache 2 0 license for details see the google developers site policies java is a registered trademark of oracle and or its affiliates last updated 2026 07 17 utc need to tell us more easy to understand easytounderstand thumb up solved my problem solvedmyproblem thumb up other otherup thumb up hard to understand hardtounderstand thumb down incorrect information or sample code incorrectinformationorsamplecode thumb down missing the information samples i need missingtheinformationsamplesineed thumb down other otherdown thumb down last updated 2026 07 17 utc products and pricing see all products google cloud pricing google cloud marketplace contact sales support community forums support release notes system status resources github getting started with google cloud code samples cloud architecture center training and certification engage blog events x twitter google cloud on youtube google cloud tech on youtube about google privacy site terms google cloud terms manage cookies our third decade of climate action join us sign up for the google cloud newsletter subscribe english deutsch español español américa latina français indonesia italiano português português brasil עברית 中文 简体 中文 繁體 日本語 한국어
|