Overview of Key Access Justifications

This page provides an overview of Key Access Justifications. Key Access Justifications is a part of Google's long-term commitment to transparency, user trust, and customer ownership of their data. Key Access Justifications directs Google systems to generate access justification codes for each cryptographic operation involving enrolled Cloud Key Management Service (Cloud KMS) keys.

Key Access Justifications works alongside Access Approval and Access Transparency in the following way: Access Approval lets you authorize requests from Google personnel to access Customer Data, Access Transparency helps you discover information about when Customer Data is accessed, and Key Access Justifications provides key access control for all interactions with at-rest Customer Data that is encrypted by a customer-managed key. Together, each of these products provide access management capabilities that give you control over and context for administrative requests to access Customer Data.

Overview

Key Access Justifications lets you set a policy on Cloud Key Management Service (Cloud KMS) keys to view, approve, and deny key access requests depending on the provided justification code. For select external key management partners, you can configure Key Access Justifications policies outside of Google Cloud to be exclusively enforced by the external key manager rather than by Cloud KMS.

Depending on the Assured Workloads control package you choose, the following Key Access Justifications features are available:

  • For select regional control packages, Key Access Transparency logs these justification codes in your Cloud KMS audit logs.
  • For select regional, regulatory, or sovereign control packages, Key Access Justifications lets you set a policy on your keys to approve or deny key access requests depending on the provided justification code. Some regional data boundaries provide this feature in addition to Key Access Transparency.
  • For select sovereign control packages, you can use a supported external key management partners to configure Key Access Justifications policies outside of Google Cloud. These policies are exclusively enforced by the external key manager rather than by Cloud KMS.

In addition to these features, the Assured Workloads control package you choose will also determine which of the following Cloud KMS key types are available:

How encryption at rest works

Google Cloud encryption at rest works by encrypting your data stored on Google Cloud with an encryption key that lives outside the service where the data is stored. For example, if you encrypt data in Cloud Storage, the service only stores the encrypted information you have stored, whereas the key used to encrypt that data is stored in Cloud KMS (if you are using customer-managed encryption keys (CMEK)) or in your external key manager (if you are using Cloud EKM).

When you use a Google Cloud service, you want your applications to continue working as described, and this will require your data to be decrypted. For example, if you run a query using BigQuery, the BigQuery service needs to decrypt your data to be able to analyze it. BigQuery accomplishes this by making a decryption request to the key manager to get the required data.

Why would my keys be accessed?

Your encryption keys are most often accessed by automated systems while servicing your own requests and workloads on Google Cloud.

In addition to customer-initiated accesses and automated system accesses, a Google employee might need to initiate operations which use your encryption keys for the following reasons:

  • Back up your data: Google might need to access your encryption keys to back up your data for disaster recovery reasons.

  • Resolve a support request: A Google employee might need to decrypt your data to fulfill the contractual obligation of providing support.

  • Manage and troubleshoot systems: Google personnel can initiate operations which use your encryption keys to perform technical debugging needed for a complex support request or investigation. Access might also be needed to remediate storage failure or data corruption.

  • Ensure data integrity and compliance, and protect against fraud and abuse: Google might need to decrypt data for the following reasons:

    • To ensure the safety and security of your data and accounts.
    • To make sure that you are using Google services in compliance with the Google Cloud Terms of Service.
    • To investigate complaints by other users and customers, or other signals of abusive activity.
    • To verify that Google Cloud services are being used in accordance with applicable regulatory requirements, such as anti-money laundering regulations.