運用權(quán)管理服務(wù)實現(xiàn)文件控管稽核_第1頁
運用權(quán)管理服務(wù)實現(xiàn)文件控管稽核_第2頁
運用權(quán)管理服務(wù)實現(xiàn)文件控管稽核_第3頁
運用權(quán)管理服務(wù)實現(xiàn)文件控管稽核_第4頁
運用權(quán)管理服務(wù)實現(xiàn)文件控管稽核_第5頁
已閱讀5頁,還剩59頁未讀, 繼續(xù)免費閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領(lǐng)

文檔簡介

運用版權(quán)管理服務(wù)實現(xiàn)文件控管稽核

主講人:精誠公司恆逸教育訓(xùn)練中心資深講師:張書源大綱版權(quán)管理服務(wù)架構(gòu)版權(quán)管理服務(wù)的設(shè)定與部署如何利用版權(quán)管理服務(wù)保護文件安全性TheU.S.DeptofJusticeestimatesthatintellectualpropertytheftcostenterprises$250billionin2004Lossofrevenue,marketcapitalization,andcompetitiveadvantageInformationLossisCostly

Informationloss–whetherviatheftoraccidentalleakage–iscostlyonseverallevelsLeakedexecutivee-mailscanbeembarrassingUnintendedforwardingofsensitiveinformationcanadverselyimpactthecompany’simageand/orcredibilityIncreasingregulation:SOX,HIPAA,GLBABringingacompanyintocompliancecanbecomplexandexpensiveNon-compliancecanleadtosignificantlegalfees,finesand/orsettlementsFinancialImage&CredibilityLegal&RegulatoryComplianceInformationleakageistop-of-mindwithBusinessDecisionMakers0%10%20%30%40%50%60%70%Lossofdigitalassets,restoredE-mailpiracyPasswordcompromiseLossofmobiledevicesUnintendedforwardingofe-mails20%22%22%35%36%63%“Aftervirusinfections,businessesreportunintendedforwardingofe-mailsandlossofmobiledevicesmorefrequentlythantheydoanyothersecuritybreach” JupiterResearchReport,2004VirusinfectionTraditionalsolutionsprotectinitialaccess…AccessControlListPerimeterNoYesTrustedNetworkAuthorizedUsersUnauthorizedUsersInformationLeakageUnauthorizedUsers…butnotongoingusageToday’spolicyexpression……lacksenforcementtoolsHowdoesRMSaddressthis?Supportsdevelopmentofrich,third-partysolutionsontopofRMSviatheRMSSoftwareDevelopmentKit(SDK)Providesflexibilitytointegratewithanenterprise’sexistinginternalapplicationsEncryptssensitivecontentProtectsinsideandoutsidethetrustednetworkProtectsduringandafterdeliveryAllowsorganizationstoestablishandapplycentrally-managedpoliciesAllowsorganizationstotracktheinformation’slifecycleSupportssmartcardauthenticationAugmentsExistingTechnologiestoProvidePersistentProtectionEnforcesOrganizationalPoliciesProvidesaplatformforvalue-addedsolutionsCommonUsageScenariosServer-sideScenariosRegulatorycompliance&IPprotectionSecurebusinessprocessautomationCentralcontrolofinformationprotectionClient-sideScenariosDo-not-forwarde-mailPersistentdocumentprotectionMixed-versionOfficeenvironmentsPlatformandManagementScenariosCentrallydefineandmanagepermissiontemplatesLogandauditwhohasaccessedrights-protectedinformationExtendRMSplatformtoapplyandenforcerightsprotectiononHTMLcontentviatheRightsManagementAdd-onforIE(RMA)UserswithoutOffice2003canviewrights-protectedfilesviaInternetExplorerDoesnotprovideauthoringcapabilityRightsManagementAdd-onforIE(RMA)ClientUsageScenariosReduceinternal/externalforwardingofconfidentialinformationKeepsensitivee-mailwhereitbelongsOutlook2003RequiresRMS

+ControlaccesstosensitivecontentSetgranularpermissionsperuserDeterminelengthofaccessWord2003Excel2003PowerPoint2003CommunicateinaMixedVersionEnvironmentDo-Not-ForwardE-mailProtectSensitiveFilesImprovedconfidentialityGreatend-useradoptionduetointuitiveintegrationinOffice2003StrongplatformforextendedinformationprotectionsolutionsSensitiveexecutivee-mailsandinternalconfidentialdocumentsneededtobeprotectedforcompetitivereasonsTestedRMS/IRMforsixmonths,thenconductedpilotevaluationPositiveend-userfeedbackdroveafullrolloutofOffice2003plusRMSto19,000desktopsCaseStudy:SwisscomBenefitSituationSolution“TheintegrationofRMSwithOffice2003,combinedwiththeproduct’seaseofdeploymentandmanagement,makesiteasyforvirtuallyallofSwisscom’semployeestokeeptheircriticaldocumentsandinformationsafe–withouthavingtolearnacumbersomesetofnewtechnologies.” HeinzSch?r

MemberofManagement

SwisscomITServicesAGServerUsageScenariosExtendsprotectiontomanagedcontentstoredbydocumentandrecordsmanagementsolutionsEnablesarchivalofRMS-protectede-mailsProtectedcontentcanbesecurelyindexedandsearchedEnablesworkflowenginestoextendinformationprotectiontobusinessprocessautomationAppliesrightsprotectioninacentralizedwayEnablescontentinspectiongatewaystoinspect

RMS-protectedcontentandapplyRMS-protectioncentrallyEnablesISVstodevelopserver-basedsolutionsEnableRegulatoryCompliance&IPProtectionSecureBusinessProcessAutomationControlInformationProtectionCentrallyWindowsRMSWorkflowInformationAuthorTheRecipientRMSServerSQLServerActiveDirectory2345Authordefinesasetofusagerightsandrulesfortheirfile;Applicationcreatesa““publishinglicense”andencryptsthefileAuthordistributesfileRecipientclicksfiletoopen,theapplicationcallstotheRMSserverwhichvalidatestheuserandissuesa““uselicense”ApplicationrendersfileandenforcesrightsAuthorreceivesanidentitycertificatethefirsttimetheyrights-protectinformation1OSOSRMSRMSAppAppHowdoesRMSwork?OSRMSAppOSRMSAppRMSAppUsertriestopublishorconsumecontentApplicationcallsintoRMSClienttocreateanewsessionUsertriestopublishorconsumecontentOSRMSAppUsertriestopublishorconsumecontentApplicationcallsintoRMSClienttocreateanewsessionMachineActivationRMSClientstartsbootstrappingprocess……MachineActivationRMSClientgenerates1024-bitRSAkeypairPrivatekeysecuredbyCAPIPublickeystoredinsecurityprocessorcertificate(SPC)SPCsignedbyclientOSRMSAppRMSClientgenerates1024-bitRSAkeypairPrivatekeysecuredbyCAPIPublickeystoredinsecurityprocessorcertificate(SPC)SPCsignedbyclientMachineActivationOSRMSAppPrivatekeysecuredbyCAPIPublickeystoredinsecurityprocessorcertificate(SPC)SPCMachineActivationSPCsignedbyclientRMSClientgenerates1024-bitRSAkeypairTheuser’sidentitymustbeestablishedonthemachinebyaccountcertification.NewforSP1:TheRMSClientisactivatedwithoutcontactingaserverorrequiringadminprivileges.OSRMSAppSPCRMSAccountCertificationSPCRMSClientcontactsRMSServerwithacertificationrequest,sendingSPCRMSUserisauthenticatedDOMAIN\usernameSIDE-mailaddressisretrievedfromADDOMAIN\usernameSIDUser’s1024-bitRSAkeypairisgeneratedandstoredindatabaseSIDAccountCertificationSPCServervalidatesSPCAccountCertificationRMSSPCSPCRMSClientcontactsRMSServerwithacertificationrequest,sendingSPCUserisauthenticatedE-mailaddressisretrievedfromADUser’s1024-bitRSAkeypairisgeneratedandstoredindatabaseUser’sprivatekeyisencryptedwithmachinepublickeyServervalidatesSPCDOMAIN\usernameSIDRACAccountCertificationRMSSPCRACiscreatedanduser’se-mailaddressandpublickeyareaddedServersignsRACUser’sprivatekeyisencryptedwithmachinepublickeyDOMAIN\usernameSIDSPCRACAccountCertificationRMSRACisreturnedtoclientRACiscreatedanduser’se-mailaddressandpublickeyareaddedServersignsRACUser’sprivatekeyisencryptedwithmachinepublickeyTheusernowhasaRACthatcanbeusedforconsumption.Inordertopublish,theuserneedsaClientLicensorCertificate(CLC).RACClientEnrollmentRMSRMSClientcontactsRMSServerforclientenrollment,sendingRACServergeneratesCLC1024-bitRSAkeypairCLCprivatekeyisencryptedwithRACpublickeySPCRACRMSServervalidatesRACCLCRACClientEnrollmentRMSRMSClientcontactsRMSServerforclientenrollment,sendingRACServergeneratesCLC1024-bitRSAkeypairCLCprivatekeyisencryptedwithRACpublickeyCLCisgenerated,grantingtheusertherighttopublishSPCRACRMSServervalidatesRACServerinformation,suchasURLandserverpublickey,isalsoaddedtoCLCCLCClientEnrollmentRMSServersignsCLCSPCRACServerinformation,suchasURLandserverpublickey,isalsoaddedtoCLCCLCCLCisreturnedtoclientTheclientisnowreadyforbothpublishingandconsumptionofprotectedcontent.OSRMSAppRMSAppPublishingRMSUsercreatescontentusingRMS-enabledapplicationApplicationcallsintoRMSClientforpublishingUserspecifiesrecipients,rights,andconditionstopublishcontent,orchoosesatemplategroup@ read,print expires30daysCLCSPCRACApplicationcallsintoRMSClientforpublishingPLPublishingRMSgroup@ read,print expires30daysRMSClientgenerates128-bitAEScontentkeyClientencryptscontentClientcreatespublishinglicense(PL)CLCSPCRACOSRMSAppCLCSPCRACClientcreatespublishinglicense(PL)PLPublishingRMSRightsdataandcontentkeyareencryptedbyserverpublickeyfromCLCgroup@ read,print expires30daysServerURLisaddedtoPLgroup@ read,print expires30daysCLCsignsPLOSRMSAppPublishingRMSCLCsignsPLTheclientreturnsthePLtotheapplicationTheapplicationcannowpackagethePLwiththecontentPLgroup@ read,print expires30daysPLgroup@ read,print expires30daysThecontentcannowbesenttoitsrecipientsCLCSPCRACOSRMSRMSAppOSRMSAppThecontentcannowbesenttoitsrecipientsCLCSPCRACPublishingRMSPLgroup@ read,print expires30daysPublishersendsprotectedcontenttorecipientusinganymechanismAssumerecipienthasalreadybeenbootstrappedTherecipientneedsauselicenseinordertoaccessthecontentCLCSPCRACRecipientopensdocumentinRMS-enabledapplicationLicensingRMSApplicationcallsRMSClienttoretrieveauselicense.PLgroup@ read,print expires30daysRMSClientsendsPLandRACtoRMSServerRACServervalidatesRACandPLDatafromPLisdecryptedPLgroup@ read,print expires30daysgroup@ read,print expires30daysCLCSPCRACOSRMSAppRMSAppRACULgroup@ read,print expires30daysLicensingRMSIfcontentwaspublishedtoagroup,serverchecksgroupmembershipintheADPLgroup@ read,print expires30daysIfidentityinRACmatchesPLorgroupmembership,serverbeginsconstructinguselicense(UL)DatafromPLisdecryptedRightsaregrantedtouserCLCSPCRACOSRMSAppuser@ read,print expires30daysgroup@ read,print expires30daysuser@ read,print expires30daysRACULread,printexpires30daysLicensingRMSContentkeyencryptedbyRACpublickeyPLgroup@ read,print expires30daysEncryptedkeyaddedtoULRightsaregrantedtouserULreturnedtoclientULsignedbyserverCLCSPCRACOSRMSAppLicensingRMSPLgroup@ read,print expires30daysCLCSPCRACContentkeyencryptedbyRACpublickeyEncryptedkeyaddedtoULRightsaregrantedtouserULreturnedtoclientULsignedbyserverRecipientcannowbindthelicenseandopenthecontentULuser@ read,print expires30daysOSRMSAppOSRMSAppULuser@ read,print expires30daysAccessingContentPLgroup@ read,print expires30daysSPCRACCLCSPCULuser@ read,print expires30daysRACOSRMSAppOSRMSAppRMSAppAccessingContentSPCULread,printexpires30daysRACRMSClientusessecurityprocessortodecryptRACprivatekeyApplicationcallsRMSClienttobindlicenseanddecryptcontentRACprivatekeydecryptscontentkeyAccessingContentSPCULread,printexpires30daysRACRMSClientdecryptscontentRACprivatekeydecryptscontentkeyApplicationrenderscontentandenforcesrightsOSRMSRMSAppRMSClientsoftwareAnRMS-enabledapplicationRequiredforcreatingorviewingrights-protectedcontentMicrosoftOffice2003Editions

includesRMS-enabledapplications––Word,Excel,PowerPoint,OutlookOfficeProfessional2003isrequiredforcreatingorviewingrights-protectedcontentOtherOffice2003Editionsallowsuserstoview––butnotcreate––rights-protectedcontent.RightsManagementAdd-on(RMA)forInternetExplorer6.0Allowsuserstoviewrights-protectedcontentinIEEnablesdown-levelviewingsupportforcontentprotectedbyOffice2003RMSSolutionComponentsServerRMSServerRunsonWindowsServer2003(Standard,Enterprise,WeborDatacenterEditions)ProvidescertificationandlicensingActiveDirectory?directoryserviceWindowsServer2000orlaterProvidesawell-knownuniqueidentifierforeachuserE-mailaddresspropertyforeachusermustbepopulatedDatabaseServerMicrosoftSQLServer??(recommended)orMSDEStoresconfiguration,userkeys,andloggingdataClientRMSServerRMSserverisanASP.NETWebserviceProtocolisSOAPoverHTTP/HTTPSInternetInformationServer(IIS)6onlySinglerequest/responsetransactionmodelStatelessformostrequests––allprocessingonfrontendDBsuchasSQL(orMSDE)usedforconfiguration&loggingRequestsMachineActivation:OnetimeprocesstocreateanddownloadsecuretrustedrootpermachineCertificationandClientEnrollment:Bindingauserkeypair

toaspecificmachine.OnetimeperuserpermachineLicensing:requestingalicensetouseapieceofcontent(“UseLicense”);OnetimepercontentperuserXrML-basedinput/outputPluggableCryptoProviderRMSServerRMSServerisanASP.NETapplicationUsesADforauthenticatingusers,determiningemailaddressesforusers,confirmingmembershipofusersingroupsUsesMSMQtoforwardloggingentriestoSQLServerUsesSQLServertostoreRMSconfiguration,ADgroupexpansioncache,andallloggedclientactivitiesUsesIIS(WindowsIntegratedauthentication)toauthenticateallusersTechnologiesSupportingWindowsRMSAD&LDAPStoreuseraccounts,DLs,providedirectoryofemailaddresses,SCPlocation.NETFramework&ASP.NETApplicationenvironmentforallcriticalRMSserverapplicationcodeMSMQ&SQLStoresRMSconfigurationinformation,userkeypairs,activitylogs,cacheofADgroupsforexpansionXrMLstandard*inwhichallthelicenses,certificatesarestructuredSOAPProtocolstandardforallmessageexchangesbetweenclientandserver,serverandMSN,andclientandMSNUDDIDirectoryforfindingtheMSNRMSservicesRMS-EnabledApplicationsRMS-enabledapplicationsmayimplementRMSfeaturessuchaspre-licensing,contentaccess,certificaterequestsApplicationscanbebasedontheServerSDK(e.g.sample““RMS-enabledSPSserver””fromServerSDK)ApplicationscanbebasedontheClientSDK(e.g.OfficeWord2003,OfficeOutlook2003,RMA)ApplicationsneedtohaveallRMS-enabledlibrariesandexecutablessignedwithanRMScode-signingprivatekeyThesignatureisincludedinamanifest(XMLfile)fortheapplicationThemanifestisasignedXMLfilecontaininghashesofalllistedfilesThemanifestshouldincludeallfilesthatcallRMSClientAPIsRMSClientAPIsvalidatethehashesinthemanifestagainstalllistedfilesbeforeunlockingrights-protectedinformationRMSClientComponents&APIsClientComponents&theirAPIsarethegluebetweenRMS-enabledapplicationsandthelockboxMsdrm.dll,Msdrmhid.dll,Msdrmctrl.dllAllRMS-enabledapplicationsperformtheirworkthroughtheseAPIs,andanyapplicationscanprogramtotheseAPIs(ClientSDK),e.g.:RequestingmachineactivationFindingRMSservicesRequesting,parsinglicenses&certificatesManaginglicenses(enumerate,store)CreatingofflinepublishinglicensesClientcomponentscallthelockboxtoperformthesecurityoperationsADSQLScalinganRMSDeploymentBalancerRMSSSLFirewall79,000uniqueusers23,000uniqueusersperweek71,000contentlicensesissuedperweek10RMS-relatedhelpdeskcallsperweekOverallhelpdeskvolumeis11,000callsperweek20%escalatedtoTier2clientsupportMediantimetocertify<1secondOver1,000,000uselicensesservedRMSatMicrosoftFY05DeploymentStatisticsRMSdoesnotprotectagainstanalogattacks…RMSProductRoadmapKeyScenariosPlatformEnhancementsRMS-enabledMicrosoftAppsTodayEnterpriseinformationpolicyexpressionandenforcementIntra-companycontentexchangeIntegrationwithserver-based,centrallymanagedsolutionsActiveDirectoryintegrationFIPScomplianceSmartcardsupportOffice2003:Outlook,Word,PowerPoint,ExcelFY07AdditionalclientandserverapplicationsBroaderexternalcollaborationscenariosIncreasedsecuritywhilemaintainingeaseofuseImproveddeploymentandmanagementModifiedtrustinfrastructureExpandedauthenticationsupportFY06AccessprotectedcontentonWindowsMobiledevicesRMSVersionRMSv1withSP1RMSv1withSP1RMSforWindowsMobileRMSv2(Longhorn)WindowsMobilesupportPocketInboxAuthoringRights-ProtectedInformationwithRMSandWord2003CreatingaDo-Not-Forwarde-mailwithRMSandOutlook2003ConsumingRights-ProtectedInformationwithRMSandOutlook2003andExcel2003ResourcesRMSWebsite:/rmsRMSBlog:/rmsRMSTechNetVirtualLab:/technet/traincert/virtuallab/rms.mspxMicrosoftSecurity:/securityMicrosoftIT’sRMSdeployment:/technet/itsolutions/msit/infowork/deprmswp.mspxRMSSDKonMSDN:/library/en-us/dnanchor/html/rm_sdks_overview.aspQuestions?9、靜夜四無鄰鄰,荒居舊業(yè)業(yè)貧。。12月-2212月-22Saturday,December31,202210、雨中黃葉葉樹,燈下下白頭人。。。15:30:0115:30:0115:3012/31/20223:30:01PM11、以我我獨沈沈久,,愧君君相見見頻。。。12月月-2215:30:0115:30Dec-2231-Dec-2212、故人江江海別,,幾度隔隔山川。。。15:30:0115:30:0115:30Saturday,December31,202213、乍乍見見翻翻疑疑夢夢,,相相悲悲各各問問年年。。。。12月月-2212月月-2215:30:0115:30:01December31,202214、他鄉(xiāng)鄉(xiāng)生白白發(fā),,舊國國見青青山。。。31十十二二月20223:30:01下下午15:30:0112月月-2215、比不了了得就不不比,得得不到的的就不要要。。。十二月223:30下午午12月-2215:30December31,202216、行動出成果果,工作出財財富。。

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責(zé)。
  • 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

評論

0/150

提交評論