Google Calendar
Last updated
Last updated
When an organizer creates an encrypted event in Google Calendar:
DEK Generation: Google generates a unique Data Encryption Key (DEK) specifically for that individual calendar event.
Metadata Encryption: Google encrypts the sensitive fields (Title, Description, and Attachments) using this local DEK.
Key Protection Request: Google sends the DEK to Oten KMS to be wrapped.
Key Wrapping: Oten KMS wraps (encrypts) the DEK using your Customer Managed Key (CMK) after verifying the organizer's permissions.
Encrypted Storage: The encrypted event data and the wrapped DEK are stored by Google. Accessing the event details requires the key to be unwrapped.
When an invitee or the organizer views the encrypted event:
Authorization Check: Google retrieves the encrypted event and sends the wrapped DEK to Oten KMS.
Key Unwrapping: Oten KMS verifies the identity of the user (checking if they are on the guest list or have proper access) and unwraps the DEK using the CMK.
Client-Side Decryption: The plain-text DEK is returned to the user’s browser, which then decrypts the event details locally.
Private Viewing: The user sees the meeting title and description clearly, while Google’s servers only see encrypted "blobs" of data.

To optimize the use of this features across browsers and mobile apps, please configure your settings as follows:
For mobile app:
Update the related apps to the latest version for the best experience (example: Gmail is 6.0.260406).
Chrome is the recommended default browser.
Android: If it does not work properly in the app, clear the cache and try again.
For desktop app browser: Chrome (or Chromium core browser) is the recommended default browser.
These features work reliably in web browsers. On the mobile app, availability depends on the app version and Google's support, so usage may vary by version and is not always consistent.
Google Calendar
Web browser
Android mobile app
iOS mobile app
Note:
To optimize the use of Google Calendar, you must fully configure the Client ID for all related services: Calendar, Drive, Meet, and Gmail.
For Android, users need to install Chrome and set it as the default browser in order to use it.
For mobile app: Chrome is the recommended default browser.
Any content other than the event description, attachments, and Meet data, such as:
Event description
Attached Drive files (if CSE for Drive is turned on)
Meet audio and video streams (if CSE for Meet is turned on)
Event title
Event starting and ending times
Attendees list
Booked rooms
Join by phone numbers
Link for Meet