Chinaunix首页 | 论坛 | 博客
  • 博客访问: 323964
  • 博文数量: 72
  • 博客积分: 3030
  • 博客等级: 中校
  • 技术积分: 820
  • 用 户 组: 普通用户
  • 注册时间: 2006-12-22 16:11
文章分类

全部博文(72)

文章存档

2016年(2)

2015年(1)

2014年(1)

2011年(2)

2010年(3)

2009年(7)

2008年(15)

2007年(40)

2006年(1)

我的朋友

分类: 网络与安全

2007-08-14 14:34:44

Windows RMS is information protection technology that works with RMS-enabled applications to help safeguard digital information from unauthorized use. RMS combines Windows Server 2003 features, developer tools, and industry security technologies–including encryption, XrML-based certificates, and authentication–to help organizations create reliable information protection solutions for their valuable and sensitive business file content.

The Windows RMS solution requires:

·         Windows RMS for Windows Server 2003

·         RMS client application programming interface (API) for Windows clients (Windows 98 Second Edition and later)

·         eXtensible rights Markup Language (XrML), a powerful rights expression implementation of the eXtensible Markup Language (XML) for the integration of powerful digital rights technology

·         RMS client and server software development kits (SDKs) that enable Windows-based client and server applications to become “rights-enabled”

RMS is a premium information protection service of Windows Server 2003 and is responsible for all machine activation, licensing, enrollment, and other administration-related activities. The creation and consumption of RMS-enabled documents is the responsibility of RMS-enabled client software such as the Microsoft Office 2003 Editions, or an RMS-enabled browser such as Microsoft Internet Explorer with the Rights Management Add-on (RMA). RMS allows users to apply information protection with great ease and efficiency from within their customary software environment. Any Windows platform application can work with the API in the SDK to support RMS. RMS must establish a trust ecosystem, where a PC, user, application, and server are all integral and trusted components. This trust is established and validated through the use of XrML certificates for each component. Every PC must receive a “Machine Certificate” and RMS “lockbox” to become “trusted” and each user must receive a Rights Management Account Certificate (RAC) to be recognized by RMS.  Additionally, each user must have a Client Licensor Certificate (CLC) if they wish to publish rights-protected content on their machine without a connection to RMS. 

RMS-enabled client software also works closely with Microsoft Active Directory®[1] directory services technology, a component of the Microsoft Windows Server operating system, to identify users and distribution groups and to assist in assigning/enforcing access and usage rights. Through the use of Active Directory roles and group policies, information managers can create a wide range of distinct user communities, each of which can have different information access rights.

RMS deployment is straight-forward and demands minimal resources. Organizations can roll out RMS across the network by using, for example, Microsoft Systems Management Server. Users do not need to have administrative privileges to active RMS on their desktops, nor do they need access to the Internet. RMS, for that reason, deploys in air-gap networks as easily as it does within LANs and WANs with Internet access.



[1] RMS requires Active Directory 2000 or later.

阅读(1653) | 评论(0) | 转发(0) |
给主人留下些什么吧!~~