版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)
文檔簡介
運用版權(quán)管理服務(wù)實現(xiàn)文件控管稽核
主講人:精誠公司恆逸教育訓(xùn)練中心資深講師:張書源大綱版權(quán)管理服務(wù)架構(gòu)版權(quán)管理服務(wù)的設(shè)定與部署如何利用版權(quán)管理服務(wù)保護文件安全性TheU.S.DeptofJusticeestimatesthatintellectualpropertytheftcostenterprises$250billionin2004Lossofrevenue,marketcapitalization,andcompetitiveadvantageInformationLossisCostly
Informationloss–whetherviatheftoraccidentalleakage–iscostlyonseverallevelsLeakedexecutivee-mailscanbeembarrassingUnintendedforwardingofsensitiveinformationcanadverselyimpactthecompany’simageand/orcredibilityIncreasingregulation:SOX,HIPAA,GLBABringingacompanyintocompliancecanbecomplexandexpensiveNon-compliancecanleadtosignificantlegalfees,finesand/orsettlementsFinancialImage&CredibilityLegal&RegulatoryComplianceInformationleakageistop-of-mindwithBusinessDecisionMakers0%10%20%30%40%50%60%70%Lossofdigitalassets,restoredE-mailpiracyPasswordcompromiseLossofmobiledevicesUnintendedforwardingofe-mails20%22%22%35%36%63%“Aftervirusinfections,businessesreportunintendedforwardingofe-mailsandlossofmobiledevicesmorefrequentlythantheydoanyothersecuritybreach” JupiterResearchReport,2004VirusinfectionTraditionalsolutionsprotectinitialaccess…AccessControlListPerimeterNoYesTrustedNetworkAuthorizedUsersUnauthorizedUsersInformationLeakageUnauthorizedUsers…butnotongoingusageToday’spolicyexpression……lacksenforcementtoolsHowdoesRMSaddressthis?Supportsdevelopmentofrich,third-partysolutionsontopofRMSviatheRMSSoftwareDevelopmentKit(SDK)Providesflexibilitytointegratewithanenterprise’sexistinginternalapplicationsEncryptssensitivecontentProtectsinsideandoutsidethetrustednetworkProtectsduringandafterdeliveryAllowsorganizationstoestablishandapplycentrally-managedpoliciesAllowsorganizationstotracktheinformation’slifecycleSupportssmartcardauthenticationAugmentsExistingTechnologiestoProvidePersistentProtectionEnforcesOrganizationalPoliciesProvidesaplatformforvalue-addedsolutionsCommonUsageScenariosServer-sideScenariosRegulatorycompliance&IPprotectionSecurebusinessprocessautomationCentralcontrolofinformationprotectionClient-sideScenariosDo-not-forwarde-mailPersistentdocumentprotectionMixed-versionOfficeenvironmentsPlatformandManagementScenariosCentrallydefineandmanagepermissiontemplatesLogandauditwhohasaccessedrights-protectedinformationExtendRMSplatformtoapplyandenforcerightsprotectiononHTMLcontentviatheRightsManagementAdd-onforIE(RMA)UserswithoutOffice2003canviewrights-protectedfilesviaInternetExplorerDoesnotprovideauthoringcapabilityRightsManagementAdd-onforIE(RMA)ClientUsageScenariosReduceinternal/externalforwardingofconfidentialinformationKeepsensitivee-mailwhereitbelongsOutlook2003RequiresRMS
+ControlaccesstosensitivecontentSetgranularpermissionsperuserDeterminelengthofaccessWord2003Excel2003PowerPoint2003CommunicateinaMixedVersionEnvironmentDo-Not-ForwardE-mailProtectSensitiveFilesImprovedconfidentialityGreatend-useradoptionduetointuitiveintegrationinOffice2003StrongplatformforextendedinformationprotectionsolutionsSensitiveexecutivee-mailsandinternalconfidentialdocumentsneededtobeprotectedforcompetitivereasonsTestedRMS/IRMforsixmonths,thenconductedpilotevaluationPositiveend-userfeedbackdroveafullrolloutofOffice2003plusRMSto19,000desktopsCaseStudy:SwisscomBenefitSituationSolution“TheintegrationofRMSwithOffice2003,combinedwiththeproduct’seaseofdeploymentandmanagement,makesiteasyforvirtuallyallofSwisscom’semployeestokeeptheircriticaldocumentsandinformationsafe–withouthavingtolearnacumbersomesetofnewtechnologies.” HeinzSch?r
MemberofManagement
SwisscomITServicesAGServerUsageScenariosExtendsprotectiontomanagedcontentstoredbydocumentandrecordsmanagementsolutionsEnablesarchivalofRMS-protectede-mailsProtectedcontentcanbesecurelyindexedandsearchedEnablesworkflowenginestoextendinformationprotectiontobusinessprocessautomationAppliesrightsprotectioninacentralizedwayEnablescontentinspectiongatewaystoinspect
RMS-protectedcontentandapplyRMS-protectioncentrallyEnablesISVstodevelopserver-basedsolutionsEnableRegulatoryCompliance&IPProtectionSecureBusinessProcessAutomationControlInformationProtectionCentrallyWindowsRMSWorkflowInformationAuthorTheRecipientRMSServerSQLServerActiveDirectory2345Authordefinesasetofusagerightsandrulesfortheirfile;Applicationcreatesa““publishinglicense”andencryptsthefileAuthordistributesfileRecipientclicksfiletoopen,theapplicationcallstotheRMSserverwhichvalidatestheuserandissuesa““uselicense”ApplicationrendersfileandenforcesrightsAuthorreceivesanidentitycertificatethefirsttimetheyrights-protectinformation1OSOSRMSRMSAppAppHowdoesRMSwork?OSRMSAppOSRMSAppRMSAppUsertriestopublishorconsumecontentApplicationcallsintoRMSClienttocreateanewsessionUsertriestopublishorconsumecontentOSRMSAppUsertriestopublishorconsumecontentApplicationcallsintoRMSClienttocreateanewsessionMachineActivationRMSClientstartsbootstrappingprocess……MachineActivationRMSClientgenerates1024-bitRSAkeypairPrivatekeysecuredbyCAPIPublickeystoredinsecurityprocessorcertificate(SPC)SPCsignedbyclientOSRMSAppRMSClientgenerates1024-bitRSAkeypairPrivatekeysecuredbyCAPIPublickeystoredinsecurityprocessorcertificate(SPC)SPCsignedbyclientMachineActivationOSRMSAppPrivatekeysecuredbyCAPIPublickeystoredinsecurityprocessorcertificate(SPC)SPCMachineActivationSPCsignedbyclientRMSClientgenerates1024-bitRSAkeypairTheuser’sidentitymustbeestablishedonthemachinebyaccountcertification.NewforSP1:TheRMSClientisactivatedwithoutcontactingaserverorrequiringadminprivileges.OSRMSAppSPCRMSAccountCertificationSPCRMSClientcontactsRMSServerwithacertificationrequest,sendingSPCRMSUserisauthenticatedDOMAIN\usernameSIDE-mailaddressisretrievedfromADDOMAIN\usernameSIDUser’s1024-bitRSAkeypairisgeneratedandstoredindatabaseSIDAccountCertificationSPCServervalidatesSPCAccountCertificationRMSSPCSPCRMSClientcontactsRMSServerwithacertificationrequest,sendingSPCUserisauthenticatedE-mailaddressisretrievedfromADUser’s1024-bitRSAkeypairisgeneratedandstoredindatabaseUser’sprivatekeyisencryptedwithmachinepublickeyServervalidatesSPCDOMAIN\usernameSIDRACAccountCertificationRMSSPCRACiscreatedanduser’se-mailaddressandpublickeyareaddedServersignsRACUser’sprivatekeyisencryptedwithmachinepublickeyDOMAIN\usernameSIDSPCRACAccountCertificationRMSRACisreturnedtoclientRACiscreatedanduser’se-mailaddressandpublickeyareaddedServersignsRACUser’sprivatekeyisencryptedwithmachinepublickeyTheusernowhasaRACthatcanbeusedforconsumption.Inordertopublish,theuserneedsaClientLicensorCertificate(CLC).RACClientEnrollmentRMSRMSClientcontactsRMSServerforclientenrollment,sendingRACServergeneratesCLC1024-bitRSAkeypairCLCprivatekeyisencryptedwithRACpublickeySPCRACRMSServervalidatesRACCLCRACClientEnrollmentRMSRMSClientcontactsRMSServerforclientenrollment,sendingRACServergeneratesCLC1024-bitRSAkeypairCLCprivatekeyisencryptedwithRACpublickeyCLCisgenerated,grantingtheusertherighttopublishSPCRACRMSServervalidatesRACServerinformation,suchasURLandserverpublickey,isalsoaddedtoCLCCLCClientEnrollmentRMSServersignsCLCSPCRACServerinformation,suchasURLandserverpublickey,isalsoaddedtoCLCCLCCLCisreturnedtoclientTheclientisnowreadyforbothpublishingandconsumptionofprotectedcontent.OSRMSAppRMSAppPublishingRMSUsercreatescontentusingRMS-enabledapplicationApplicationcallsintoRMSClientforpublishingUserspecifiesrecipients,rights,andconditionstopublishcontent,orchoosesatemplategroup@ read,print expires30daysCLCSPCRACApplicationcallsintoRMSClientforpublishingPLPublishingRMSgroup@ read,print expires30daysRMSClientgenerates128-bitAEScontentkeyClientencryptscontentClientcreatespublishinglicense(PL)CLCSPCRACOSRMSAppCLCSPCRACClientcreatespublishinglicense(PL)PLPublishingRMSRightsdataandcontentkeyareencryptedbyserverpublickeyfromCLCgroup@ read,print expires30daysServerURLisaddedtoPLgroup@ read,print expires30daysCLCsignsPLOSRMSAppPublishingRMSCLCsignsPLTheclientreturnsthePLtotheapplicationTheapplicationcannowpackagethePLwiththecontentPLgroup@ read,print expires30daysPLgroup@ read,print expires30daysThecontentcannowbesenttoitsrecipientsCLCSPCRACOSRMSRMSAppOSRMSAppThecontentcannowbesenttoitsrecipientsCLCSPCRACPublishingRMSPLgroup@ read,print expires30daysPublishersendsprotectedcontenttorecipientusinganymechanismAssumerecipienthasalreadybeenbootstrappedTherecipientneedsauselicenseinordertoaccessthecontentCLCSPCRACRecipientopensdocumentinRMS-enabledapplicationLicensingRMSApplicationcallsRMSClienttoretrieveauselicense.PLgroup@ read,print expires30daysRMSClientsendsPLandRACtoRMSServerRACServervalidatesRACandPLDatafromPLisdecryptedPLgroup@ read,print expires30daysgroup@ read,print expires30daysCLCSPCRACOSRMSAppRMSAppRACULgroup@ read,print expires30daysLicensingRMSIfcontentwaspublishedtoagroup,serverchecksgroupmembershipintheADPLgroup@ read,print expires30daysIfidentityinRACmatchesPLorgroupmembership,serverbeginsconstructinguselicense(UL)DatafromPLisdecryptedRightsaregrantedtouserCLCSPCRACOSRMSAppuser@ read,print expires30daysgroup@ read,print expires30daysuser@ read,print expires30daysRACULread,printexpires30daysLicensingRMSContentkeyencryptedbyRACpublickeyPLgroup@ read,print expires30daysEncryptedkeyaddedtoULRightsaregrantedtouserULreturnedtoclientULsignedbyserverCLCSPCRACOSRMSAppLicensingRMSPLgroup@ read,print expires30daysCLCSPCRACContentkeyencryptedbyRACpublickeyEncryptedkeyaddedtoULRightsaregrantedtouserULreturnedtoclientULsignedbyserverRecipientcannowbindthelicenseandopenthecontentULuser@ read,print expires30daysOSRMSAppOSRMSAppULuser@ read,print expires30daysAccessingContentPLgroup@ read,print expires30daysSPCRACCLCSPCULuser@ read,print expires30daysRACOSRMSAppOSRMSAppRMSAppAccessingContentSPCULread,printexpires30daysRACRMSClientusessecurityprocessortodecryptRACprivatekeyApplicationcallsRMSClienttobindlicenseanddecryptcontentRACprivatekeydecryptscontentkeyAccessingContentSPCULread,printexpires30daysRACRMSClientdecryptscontentRACprivatekeydecryptscontentkeyApplicationrenderscontentandenforcesrightsOSRMSRMSAppRMSClientsoftwareAnRMS-enabledapplicationRequiredforcreatingorviewingrights-protectedcontentMicrosoftOffice2003Editions
includesRMS-enabledapplications––Word,Excel,PowerPoint,OutlookOfficeProfessional2003isrequiredforcreatingorviewingrights-protectedcontentOtherOffice2003Editionsallowsuserstoview––butnotcreate––rights-protectedcontent.RightsManagementAdd-on(RMA)forInternetExplorer6.0Allowsuserstoviewrights-protectedcontentinIEEnablesdown-levelviewingsupportforcontentprotectedbyOffice2003RMSSolutionComponentsServerRMSServerRunsonWindowsServer2003(Standard,Enterprise,WeborDatacenterEditions)ProvidescertificationandlicensingActiveDirectory?directoryserviceWindowsServer2000orlaterProvidesawell-knownuniqueidentifierforeachuserE-mailaddresspropertyforeachusermustbepopulatedDatabaseServerMicrosoftSQLServer??(recommended)orMSDEStoresconfiguration,userkeys,andloggingdataClientRMSServerRMSserverisanASP.NETWebserviceProtocolisSOAPoverHTTP/HTTPSInternetInformationServer(IIS)6onlySinglerequest/responsetransactionmodelStatelessformostrequests––allprocessingonfrontendDBsuchasSQL(orMSDE)usedforconfiguration&loggingRequestsMachineActivation:OnetimeprocesstocreateanddownloadsecuretrustedrootpermachineCertificationandClientEnrollment:Bindingauserkeypair
toaspecificmachine.OnetimeperuserpermachineLicensing:requestingalicensetouseapieceofcontent(“UseLicense”);OnetimepercontentperuserXrML-basedinput/outputPluggableCryptoProviderRMSServerRMSServerisanASP.NETapplicationUsesADforauthenticatingusers,determiningemailaddressesforusers,confirmingmembershipofusersingroupsUsesMSMQtoforwardloggingentriestoSQLServerUsesSQLServertostoreRMSconfiguration,ADgroupexpansioncache,andallloggedclientactivitiesUsesIIS(WindowsIntegratedauthentication)toauthenticateallusersTechnologiesSupportingWindowsRMSAD&LDAPStoreuseraccounts,DLs,providedirectoryofemailaddresses,SCPlocation.NETFramework&ASP.NETApplicationenvironmentforallcriticalRMSserverapplicationcodeMSMQ&SQLStoresRMSconfigurationinformation,userkeypairs,activitylogs,cacheofADgroupsforexpansionXrMLstandard*inwhichallthelicenses,certificatesarestructuredSOAPProtocolstandardforallmessageexchangesbetweenclientandserver,serverandMSN,andclientandMSNUDDIDirectoryforfindingtheMSNRMSservicesRMS-EnabledApplicationsRMS-enabledapplicationsmayimplementRMSfeaturessuchaspre-licensing,contentaccess,certificaterequestsApplicationscanbebasedontheServerSDK(e.g.sample““RMS-enabledSPSserver””fromServerSDK)ApplicationscanbebasedontheClientSDK(e.g.OfficeWord2003,OfficeOutlook2003,RMA)ApplicationsneedtohaveallRMS-enabledlibrariesandexecutablessignedwithanRMScode-signingprivatekeyThesignatureisincludedinamanifest(XMLfile)fortheapplicationThemanifestisasignedXMLfilecontaininghashesofalllistedfilesThemanifestshouldincludeallfilesthatcallRMSClientAPIsRMSClientAPIsvalidatethehashesinthemanifestagainstalllistedfilesbeforeunlockingrights-protectedinformationRMSClientComponents&APIsClientComponents&theirAPIsarethegluebetweenRMS-enabledapplicationsandthelockboxMsdrm.dll,Msdrmhid.dll,Msdrmctrl.dllAllRMS-enabledapplicationsperformtheirworkthroughtheseAPIs,andanyapplicationscanprogramtotheseAPIs(ClientSDK),e.g.:RequestingmachineactivationFindingRMSservicesRequesting,parsinglicenses&certificatesManaginglicenses(enumerate,store)CreatingofflinepublishinglicensesClientcomponentscallthelockboxtoperformthesecurityoperationsADSQLScalinganRMSDeploymentBalancerRMSSSLFirewall79,000uniqueusers23,000uniqueusersperweek71,000contentlicensesissuedperweek10RMS-relatedhelpdeskcallsperweekOverallhelpdeskvolumeis11,000callsperweek20%escalatedtoTier2clientsupportMediantimetocertify<1secondOver1,000,000uselicensesservedRMSatMicrosoftFY05DeploymentStatisticsRMSdoesnotprotectagainstanalogattacks…RMSProductRoadmapKeyScenariosPlatformEnhancementsRMS-enabledMicrosoftAppsTodayEnterpriseinformationpolicyexpressionandenforcementIntra-companycontentexchangeIntegrationwithserver-based,centrallymanagedsolutionsActiveDirectoryintegrationFIPScomplianceSmartcardsupportOffice2003:Outlook,Word,PowerPoint,ExcelFY07AdditionalclientandserverapplicationsBroaderexternalcollaborationscenariosIncreasedsecuritywhilemaintainingeaseofuseImproveddeploymentandmanagementModifiedtrustinfrastructureExpandedauthenticationsupportFY06AccessprotectedcontentonWindowsMobiledevicesRMSVersionRMSv1withSP1RMSv1withSP1RMSforWindowsMobileRMSv2(Longhorn)WindowsMobilesupportPocketInboxAuthoringRights-ProtectedInformationwithRMSandWord2003CreatingaDo-Not-Forwarde-mailwithRMSandOutlook2003ConsumingRights-ProtectedInformationwithRMSandOutlook2003andExcel2003ResourcesRMSWebsite:/rmsRMSBlog:/rmsRMSTechNetVirtualLab:/technet/traincert/virtuallab/rms.mspxMicrosoftSecurity:/securityMicrosoftIT’sRMSdeployment:/technet/itsolutions/msit/infowork/deprmswp.mspxRMSSDKonMSDN:/library/en-us/dnanchor/html/rm_sdks_overview.aspQuestions?9、靜夜四無鄰鄰,荒居舊業(yè)業(yè)貧。。12月-2212月-22Saturday,December31,202210、雨中黃葉葉樹,燈下下白頭人。。。15:30:0115:30:0115:3012/31/20223:30:01PM11、以我我獨沈沈久,,愧君君相見見頻。。。12月月-2215:30:0115:30Dec-2231-Dec-2212、故人江江海別,,幾度隔隔山川。。。15:30:0115:30:0115:30Saturday,December31,202213、乍乍見見翻翻疑疑夢夢,,相相悲悲各各問問年年。。。。12月月-2212月月-2215:30:0115:30:01December31,202214、他鄉(xiāng)鄉(xiāng)生白白發(fā),,舊國國見青青山。。。31十十二二月20223:30:01下下午15:30:0112月月-2215、比不了了得就不不比,得得不到的的就不要要。。。十二月223:30下午午12月-2215:30December31,202216、行動出成果果,工作出財財富。。
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 2024年度餐廳VIP客戶管理軟件合同
- 2024版二手電動自行車買賣及售后服務(wù)保障合同3篇
- 2024版企業(yè)間投資借款合作合同3篇
- 2024年商鋪轉(zhuǎn)租合同范本:商業(yè)物業(yè)租賃合作協(xié)議2篇
- 2024年教育培訓(xùn)機構(gòu)特許加盟合同
- 2024版二手摩托車經(jīng)銷商授權(quán)經(jīng)營協(xié)議3篇
- 2024年度西安建筑工程臨時用電供應(yīng)合同3篇
- 2024年智能鎖具鋁合金零部件采購合同范本3篇
- 2024年校園區(qū)域照明優(yōu)化路燈工程協(xié)議匯編版B版
- 2024版出租車司機培訓(xùn)與就業(yè)保障服務(wù)合同3篇
- 學(xué)校紀檢監(jiān)察工作制度樣本
- 2023-2024年人教版九年級上冊化學(xué)期末實驗題復(fù)習(xí)
- 當(dāng)前臺海局勢分析課件
- 五金采購工作總結(jié)
- 蘇教版三年級上冊解決問題的策略應(yīng)用題100題及答案
- 質(zhì)量管理中的流程改進與優(yōu)化
- 成長賽道-模板參考
- 室外晾衣棚施工方案
- 兒童健康管理服務(wù)總結(jié)分析報告
- 殯葬行業(yè)的風(fēng)險分析
- 通信工程冬季施工安全培訓(xùn)
評論
0/150
提交評論