Skip to main content

Encryption at Rest

Qpher encrypts every PQC private key before storing it. In production, each private key is encrypted by a key held in Google Cloud KMS.

How a private key is stored (production)​

The Cloud KMS key never leaves Cloud KMS. To store a private key, the KMS-Orchestrator sends it to Cloud KMS over TLS and writes the ciphertext it gets back; to use the key, it sends the envelope to Cloud KMS, which returns the private key.

PropertyValue
KMS providerGoogle Cloud KMS
AlgorithmCloud KMS symmetric encryption (AES-256-GCM)
Key locationprojects/qpher-production/locations/us-east1/keyRings/pqc-keys/cryptoKeys/private-key-kek
Stored file{tenant}/{algorithm}/{version}.key.envelope in the KMS-Orchestrator's key store
Protection levelSOFTWARE (a Cloud KMS software key)
Why AES-256-GCM?

AES-256-GCM is widely considered quantum-resistant for symmetric encryption. While Grover's algorithm could theoretically reduce the effective key strength to 128 bits, 128-bit security remains far beyond practical attack capabilities.

How a private key is used​

When an operation needs a private key (decrypting a ciphertext or signing a message), the KMS-Orchestrator:

  1. Reads the key's record and checks its status: decrypting needs active or retired, signing needs active; archived keys are refused.
  2. Reads {tenant}/{algorithm}/{version}.key.envelope from the key store.
  3. Calls Cloud KMS Decrypt on the envelope.
  4. Performs the operation (decapsulate or sign) with the private key in memory.
  5. Returns only the result (a plaintext, shared secret, unwrapped key or signature).

Tamper detection​

Cloud KMS encryption is authenticated: a modified envelope fails to decrypt, and the KMS-Orchestrator refuses the operation with an error.

Backups​

Qpher maintains automated database backups with point-in-time recovery, giving a Recovery Point Objective (RPO) of well under one hour for database data. Cryptographic private-key material is replicated daily to a separate geographic region (US-WEST1), and object versioning provides a 30-day recovery window against accidental deletion. All backups are encrypted at rest (AES-256). Disaster recovery procedures are documented; periodic restoration rehearsals are planned as we onboard customers and have not yet been conducted. Backup copies made before this scheme was introduced in May 2026 are encrypted with AES-256-GCM under a key kept in Google Secret Manager.

Level 1 (development)​

Local development uses Level 1: private keys are encrypted with AES-256-GCM under a key-encryption key read from the QPHER_KEY_ENCRYPTION_KEY environment variable, and stored as {version}.key files (a 12-byte IV followed by the ciphertext). Production used Level 1 until May 2026.