|
1 | | -# Post-Quantum Cryptography (PQC) User Guide for Google Cloud Java Client Libraries |
| 1 | +# Post-Quantum Cryptography (PQC) Support |
2 | 2 |
|
3 | | -## Overview |
| 3 | +To protect against the "Store Now, Decrypt Later" attack, Google Cloud is implementing Post-Quantum Cryptography (PQC) across its services. |
4 | 4 |
|
5 | | -**Post-Quantum Cryptography (PQC)** refers to cryptographic algorithms designed to protect encrypted communications against attacks from future quantum computers. The primary threat addressed today is **Store-Now, Decrypt-Later (SNDL)**—where encrypted network traffic is intercepted and stored today by an adversary with the goal of decrypting it once cryptographically relevant quantum computers emerge. |
| 5 | +For more information on Google Cloud's approach, see [Post-Quantum Cryptography on Google Cloud](https://cloud.google.com/security/resources/post-quantum-cryptography?hl=en) and [Additional Resources](#7-additional-resources). |
6 | 6 |
|
7 | | -To defend against this without sacrificing stability, Google Cloud Java client libraries adopt **Hybrid Key Exchange** (combining classical algorithms like `X25519` with standardized post-quantum algorithms like `ML-KEM-768`). This ensures connections remain secure even if an unforeseen mathematical weakness is discovered in either algorithm. |
| 7 | +## Post-Quantum key exchange |
8 | 8 |
|
9 | | -For in-depth background on PQC, NIST standards, and Google's quantum-safe roadmap, refer to the following resources: |
10 | | -- [Google Cloud Post-Quantum Cryptography Resources](https://cloud.google.com/security/resources/post-quantum-cryptography) |
11 | | -- [How Google is preparing for a post-quantum world](https://cloud.google.com/blog/products/identity-security/how-google-is-preparing-for-a-post-quantum-world/?e=48754805) |
12 | | -- [PQC in Plaintext: Google Cloud's Post-Quantum Cryptography Roadmap](https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap) |
13 | | -- [Post-Quantum Cryptography Standards: What you need to know](https://security.googleblog.com/2024/08/post-quantum-cryptography-standards.html) |
| 9 | +Google Cloud client libraries support post-quantum key exchange using the `X25519MLKEM768` hybrid mechanism for TLS 1.3 connections. |
14 | 10 |
|
15 | 11 | ### What Changes in Google Cloud Java Client Libraries? |
16 | 12 | Enabling PQC in Google Cloud Java client libraries requires **zero changes to application business logic**: |
@@ -414,3 +410,12 @@ We recommend using Google Cloud's `libraries-bom` (version `26.88.0+`), which ce |
414 | 410 | The OpenJDK community is integrating standardized post-quantum algorithms directly into the Java platform: |
415 | 411 | - **[JEP 496](https://openjdk.org/jeps/496) (ML-KEM)**: Introduces native implementations of NIST FIPS 203 (Module-Lattice-Based Key-Encapsulation Mechanism) into OpenJDK's standard security providers (`SunJSSE` and `SunJCE`), targeted for **JDK 27+**. |
416 | 412 | - **What this means for Google Cloud Java**: On JDK 27+, applications configuring standard JDK security providers (see **Option 2** in Section 4.1 and Section 4.2) will negotiate post-quantum TLS natively using `SunJSSE`, without requiring Conscrypt or JNI native shared libraries. |
| 413 | + |
| 414 | +--- |
| 415 | + |
| 416 | +## 7. Additional Resources |
| 417 | + |
| 418 | +For in-depth background on PQC, NIST standards, and Google's quantum-safe roadmap, refer to the following resources: |
| 419 | +- [How Google is preparing for a post-quantum world](https://cloud.google.com/blog/products/identity-security/how-google-is-preparing-for-a-post-quantum-world/?e=48754805) |
| 420 | +- [PQC in Plaintext: Google Cloud's Post-Quantum Cryptography Roadmap](https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap) |
| 421 | +- [Post-Quantum Cryptography Standards: What you need to know](https://security.googleblog.com/2024/08/post-quantum-cryptography-standards.html) |
0 commit comments