PostQuantum.FileEncryption.Gcp
1.6.0
Requires NuGet 6.0.0 or higher.
dotnet add package PostQuantum.FileEncryption.Gcp --version 1.6.0
NuGet\Install-Package PostQuantum.FileEncryption.Gcp -Version 1.6.0
<PackageReference Include="PostQuantum.FileEncryption.Gcp" Version="1.6.0" />
<PackageVersion Include="PostQuantum.FileEncryption.Gcp" Version="1.6.0" />
<PackageReference Include="PostQuantum.FileEncryption.Gcp" />
paket add PostQuantum.FileEncryption.Gcp --version 1.6.0
#r "nuget: PostQuantum.FileEncryption.Gcp, 1.6.0"
#:package PostQuantum.FileEncryption.Gcp@1.6.0
#addin nuget:?package=PostQuantum.FileEncryption.Gcp&version=1.6.0
#tool nuget:?package=PostQuantum.FileEncryption.Gcp&version=1.6.0
PostQuantum.FileEncryption.Gcp
Envelope encryption with Google Cloud KMS — your master key never leaves Google Cloud.
GcpKmsContentKeyProvider plugs Cloud KMS into
PostQuantum.FileEncryption's
IContentKeyProvider seam: every file is encrypted under a fresh per-file content key that
Cloud KMS Encrypt wraps under your key-ring key; decryption sends only the small wrapped
blob back to Cloud KMS Decrypt.
dotnet add package PostQuantum.FileEncryption.Gcp
Usage
using Google.Cloud.Kms.V1;
using PostQuantum.FileEncryption;
using PostQuantum.FileEncryption.Gcp;
var kms = await KeyManagementServiceClient.CreateAsync(); // credentials from Application Default Credentials
var provider = new GcpKmsContentKeyProvider(kms,
"projects/my-project/locations/global/keyRings/my-ring/cryptoKeys/my-app-key");
await new PqFileEncryptor().EncryptFileAsync("report.pdf", "report.pdf.pqfe", provider);
await new PqFileDecryptor().DecryptFileAsync("report.pdf.pqfe", "report.pdf", provider);
Optionally bind extra additional authenticated data (required to unwrap):
var provider = new GcpKmsContentKeyProvider(kms, cryptoKeyName,
Encoding.UTF8.GetBytes("tenant=contoso"));
Security behavior
- The master key stays in Cloud KMS. Cloud KMS has no server-side data-key generation,
so the per-file content key is generated locally and crosses the boundary once, for
wrapping — the same envelope pattern Google's Tink library uses. Rotation re-wraps the
small content key — multi-gigabyte payloads are never re-encrypted — and unwrap works
across key rotation because the ciphertext itself names the
CryptoKeyVersion. - Bound wraps. Every wrap carries library-specific additional authenticated data (plus
your bytes), and unwrap targets only the configured
CryptoKey— a blob wrapped under a different key or AAD fails closed withPqDecryptionException, indistinguishable from tampering. - CRC32C end to end. The integrity checksums Cloud KMS offers are populated on every request and verified on every response (the .NET SDK does not do this for you); a mismatch fails the operation instead of trusting a corrupted round-trip.
- Operational errors stay operational. Missing keys, permission denial, throttling, and network failures surface as the gRPC/SDK's own exceptions, not as decryption failures.
- IAM permission needed:
cloudkms.cryptoKeyVersions.useToEncryptto encrypt,cloudkms.cryptoKeyVersions.useToDecryptto decrypt (both inroles/cloudkms.cryptoKeyEncrypterDecrypter).
Versioning
Kept in lockstep with PostQuantum.FileEncryption. No change to the .pqfe v2 container
format, which remains FROZEN for the 1.x line.
To God be the glory — 1 Corinthians 10:31.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Google.Cloud.Kms.V1 (>= 3.25.0)
- PostQuantum.FileEncryption (>= 1.6.0)
-
net8.0
- Google.Cloud.Kms.V1 (>= 3.25.0)
- PostQuantum.FileEncryption (>= 1.6.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.6.0 | 241 | 7/11/2026 |
Initial release of the Google Cloud KMS envelope-key provider, completing the AWS KMS / Azure Key Vault / Google Cloud KMS trio over the IContentKeyProvider seam. No change to the .pqfe v2 container format, which remains FROZEN for the 1.x line. See CHANGELOG.md.