
On Tuesday, Google made client-side encryption available to select Gmail and Calendar users, giving them more control over who can see sensitive communications and schedules.
Client-side encryption is a generic term for any type of encryption applied to data before it is sent from a user device to a server. In contrast, with server-side encryption, client devices send data to a central server. A central server encrypts and stores data using a key that it owns. That’s what Google is doing today. (For clarity, data is sent encrypted over HTTPS, but decrypted as soon as it is received by Google.)
Google’s client-side encryption occupies a middle ground between the two. Data is encrypted on the client device before being sent (over HTTPS) to Google. Data can only be decrypted on the endpoint his machine with the same key used by the sender. This provides an added benefit as the data cannot be read by malicious Google insiders or hackers who have successfully compromised Google servers.
Client-side encryption, abbreviated as CSE, was already available for Google Drive, Docs, Slides, Sheets, and Meet for users of Google Workspace, which the company sells to businesses. Starting Tuesday, Google is rolling this out to his Gmail and Calendar Workspace customers.
Ganesh Chilakapati, Group Product Manager for Google Workspace at Google and Andy Wen, Director of Product Management for Google Workspace Security, wrote: “Client-side encryption takes this encryption capability to the next level by giving customers sole control over their encryption keys, giving them complete control over all access to their data. ”
It’s no exaggeration to say that Google’s CSE gives customers “sole control” of their encryption keys. This is because his CSE key can be managed by several external cryptographic key services partnered with Google. Technically, this means that these providers have at least some control over your keys. Google offers his CSE users the option to configure their own core services using the Google programming interface.
CSE is very different from PGP (Pretty Good Privacy) email encryption, which was popular with security-minded people a decade ago. That system provided true end-to-end encryption, as the content could only be decrypted with a key owned by the recipient. The difficulty of managing different keys for each party eventually proved to be cumbersome, especially at large scale, so the use of PGP was largely abandoned in favor of end-to-end encryption apps such as Signal. It has been replaced.
Below is an overview of which workspace data CSE protects and which it does not.
| service | Client-side encrypted data | data that no Client-side encryption |
|---|---|---|
| google drive |
|
|
| Gmail |
|
|
| Google Calendar |
|
Content other than event descriptions, attachments, and Meet data, such as:
|
| Google Meet |
|
|
The neutral position CSE is intended to occupy is aimed at organizations with strict compliance requirements mandated by law or contractual obligations. CSE gives these customers more control over the data Google stores, while allowing authorized users to easily decrypt it for sharing and collaboration.
“Users can continue to collaborate across other critical apps in Google Workspace, and IT and security teams can ensure sensitive data is compliant with regulations,” said Google on Tuesday. the post said. “The customer has control over and access to encryption keys and her identity management service, so sensitive data cannot be deciphered by Google or any other external entity.”
Last year Google published this video designed to show what the user experience is like.
Solving digital sovereignty issues with Google Workspace.
A blue circle with a shield in the image below indicates that the Documents, Calendar, or Video Chat content is protected by CSE.
Of course, CSE only works if the software hasn’t been modified. All bets will be void if maliciously altered to store a copy of the key or unencrypted data.
Overall, CSE is an improvement over the protection currently provided by Google. People and organizations with specific uses and requirements may find them useful, but the general public is unlikely to demand them immediately.