Active Directory Rights Management Services Experts

Using Rights Management Services for Security and Policy Enforcement
Miles Consulting Corp's Active Directory Consultants employ Rights Management Services (RMS) as an information protection technology.  This works with RMS enabled applications to safeguard digital information from unauthorized use - both online and offline - inside and outside of your organization's firewall.
 
AD DC
Authentication users of AD RMS
Group expansion for AD RMS
Stores AD RMS Service Discovery Location
 
SQL Server
(Seprates SQL server or, for small configurations, SQL on AD RMS server)
 
Configuration Database stores:
Data needed to manage account certification, licensing & publishing
Primary key pairs for secure rights management
 
AD RMS Server
Root Certification Server - Provides certification to AD RMS enabled clients
 
License AD RMS protected content
Enroll servers and users
Administer AD RMS functions
 
AD RMS enabled client installed.
AD RMS enabled applications. For example: IE, Office 2003/2007. Office SharePoint Server 2007.
AD RMS-Protected Content (XrML) (contains usage rules)
Each consumer of content recives unique license that enforces rules.
  Software-based key protection is the default for AD RMS. For added protection. AD RMS can store its keys in a harware security module.
 
Windows Server 2008 delievers a fully integrated federated enterprise rights management solution. This integration combines Active Directory Federation Services (AD FS) and Active Directory Rights management Services (AD RMS) to extend AD RMS to external users.
AD RMS is included in Windows Server 2008 as a server role.
 
Author uses AD RMS for the first time - recieves Rights Account Certificate (RAC) and client Licensor Certificate (CLC). Happens once and enables user to publish online or offline and consume rights-protected content.
Using AD RMS-enabled application, author creates file and specifies user rights. Policy license containing user policies is generated.
Application generates content key, encrypts content with it.
Online Publish - Encrypts content key with AD RMS server public key and sends to AD RMS server. Server creates and signs publishing license (PL).
Offline Publish - Encrypts content key with CLC public key, encrypts copy of key with AD RMS server public key. Creates PL and signs with CLC private key.
Append PL to encrypted content.
AD RMS protected content file sent to Information Recipient. AD RMS-protected content may also be represented by e-mail.
Recipient recives file, opens using AD RMS enabled application or browser. If no account certificate on the current computer, the AD RMS server will issue one (AD RMS document notifies applications of the AD RMS server URL).
Application sends request for use license to AD RMS server that issued publishing license (if file published offline. send to server that issues the CLC). Request includes RAC and PL for file.
AD RMS server confirms recipient is authorized, checks for a named user, and creates use license for the user. Server decrypts content key using private key of server and re-encrypts content key with public key of recipient. then adds encrypted session key to the use license. This means only the intended recipient can access the file.
AD RMS server sends use license to information recipient's computer.
Application examines both the license and the recipient's account certificate to determine whether any certificate in either chain of trust requires a revocation list. user granted access as specified by information author.
© 2012 Miles Consulting Corp | Sitemap | Legal