Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Кіріспе
Active Directory Rights Management Services (AD RMS, Windows Server 2008 алдында Rights Management Services немесе RMS деп аталатын) - Windows Server-мен бірге жеткізілетін ақпараттық құқықтарды басқару үшін серверлік бағдарламалық қамтамасыз ету. Ол корпоративтік электрондық пошта, Microsoft Word құжаттары және веб-беттер сияқты құжаттарға қол жеткізуді шектеу үшін шифрлау мен таңдамалы функционалдылықты бас тарту түрін қолданады және оларға уәкілетті пайдаланушылар орындай алатын операцияларды жүзеге асырады. Компаниялар осы технологияны осындай құжат форматтарында сақталған ақпаратты шифрлауға пайдалана алады және құжаттарға енгізілген саясаттар арқылы қорғалған мазмұнды белгілі бір адамдар немесе топтар, белгілі бір орталарда, белгілі бір жағдайларда және белгілі бір уақыт аралығында шифрлаудан басқасының алдын алады. Контент авторлары жекелеген мазмұн үшін басып шығару, көшіру, өңдеу, жіберу және жою сияқты нақты операцияларға рұқсат беруі немесе рұқсат бермеуі мүмкін, ал RMS әкімшілері осы құқықтарды алдын ала белгіленген құқықтарға біріктіретін RMS үлгілерін қолдана алады. RMS Windows Server 2003-те дебют жасады, клиенттік API кітапханалары Windows 2000 және одан кейінгі нұсқаларға қол жетімді болды. Құқықтарды басқару клиенті Windows Vista-ға кіреді және одан кейінгі нұсқалары Windows XP, Windows 2000 немесе Windows Server 2003 үшін қол жетімді. Сонымен қатар, OS X-те құқықтарды қорғауды пайдалану үшін Mac үшін Office-те AD RMS-ті іске асыру бар және Android, Blackberry OS, iOS және Windows RT-де құқықтарды қорғауды пайдалану үшін кейбір үшінші тарап өнімдері бар.
Active Directory Rights Management Services (AD RMS, known as Rights Management Services or RMS before Windows Server 2008) is a server software for information rights management shipped with Windows Server. It uses encryption and a form of selective functionality denial for limiting access to documents such as corporate e mails, Microsoft Word documents, and web pages, and the operations authorized users can perform on them. Companies can use this technology to encrypt information stored in such document formats, and through policies embedded in the documents, prevent the protected content from being decrypted except by specified people or groups, in certain environments, under certain conditions, and for certain periods of time. Specific operations like printing, copying, editing, forwarding, and deleting can be allowed or disallowed by content authors for individual pieces of content, and RMS administrators can deploy RMS templates that group these rights together into predefined rights that can be applied en masse. RMS debuted in Windows Server 2003, with client API libraries made available for Windows 2000 and later. The Rights Management Client is included in Windows Vista and later, is available for Windows XP, Windows 2000 or Windows Server 2003. In addition, there is an implementation of AD RMS in Office for Mac to use rights protection in OS X and some third party products are available to use rights protection on Android, Blackberry OS, iOS and Windows RT.
Саясатты жүзеге асыру мүмкіндіктеріне шабуыл жасау
2016 жылдың сәуірінде RMS іске асырылуына (оның ішінде Azure RMS) шабуыл жасалды деп күтілуде және ол Microsoft-қа хабарланды. Жарияланған код RMS қорғалған құжатты көру құқығын алған уәкілетті пайдаланушыға қорғанысты алып тастауға және файлдың пішімдеуін сақтауға мүмкіндік береді. Бұл түрдегі манипуляция пайдаланушыға мазмұнды көру үшін оны шифрлау құқығын беруді талап етеді. Құқықтарды басқару қызметі рұқсатсыз пайдаланушылардың қорғалған мазмұнға қол жеткізе алмауына қатысты қауіпсіздік туралы белгілі бір мәлімдемелер жасаса да, рұқсат етілген пайдаланушылар үшін әртүрлі пайдалану құқықтарының айырмашылығы оның саясатты қолдану мүмкіндіктерінің бөлігі болып саналады, оны Microsoft "ең жақсы күш" ретінде іске асырады деп мәлімдейді, сондықтан оны Microsoft қауіпсіздік мәселесі деп емес, саясат қолданудың шектеулері деп санайды. Бұрын RMS SDK RMS мүмкіндіктерін пайдалана отырып, кодқа қол қоюды талап етті, бірақ бұл мүмкіндік кейіннен RMS-пен өзара әрекеттесетін қосымшаларға белгілі бір деңгейде бақылау жасау үшін алынып тасталды, өйткені мұндай мінез-құлықты шектеу мүмкіндігі шектеулі болғандықтан, бағдарламаларды жазу мүмкіндігі берілген. мазмұнды шифрлау үшін лицензия алу үшін веб-қызметтерді тікелей пайдаланыңыз. Сонымен қатар, осы әдісті қолдану арқылы қорғалған құжатты көруге құқығы бар пайдаланушы құжаттың мазмұнын манипуляциялаудың ізін қалдырмай, оны өзгерте алады. Azure RMS - бұл бас тартуға қарсы шешім емес және құжат қол қою шешімдерінен айырмашылығы, ол бұзылмауға қарсы мүмкіндіктер береді деп мәлімдемейді, ал өзгерістерді тек құжатқа құқық берілген пайдаланушылар ғана жасай алады, сондықтан Microsoft соңғы мәселені RMS-тің мәлімделген мүмкіндіктеріне шабуыл деп қарамайды. Зерттеушілер GitHub арқылы нәтижелерді бағалауға мүмкіндік беретін тұжырымдаманың дәлелін ұсынады.
In April 2016, an alleged attack on RMS implementations (including Azure RMS) was published and reported to Microsoft. The published code allows an authorized user that has been granted the right to view an RMS protected document to remove the protection and preserve the file formatting. This sort of manipulation requires that the user has been granted rights to decrypt the content to be able to view it. While Rights Management Services makes certain security assertions regarding the inability for unauthorized users to access protected content, the differentiation between different usage rights for authorized users is considered part of its policy enforcement capabilities, which Microsoft claims to be implemented as "best effort", so it is not considered by Microsoft to be a security issue but a policy enforcement limitation. Previously the RMS SDK enforced signing of code using the RMS capabilities in order to provide some level of control on which applications interacted with RMS, but this capability was later removed due to its limited ability to restrict such behaviors given the possibility to write applications use the web services directly to obtain licenses to decrypt the content. In addition, using this same technique, a user that has been granted rights to view a protected document can manipulate the content of the document without leaving traces of the manipulation. Since Azure RMS is not a non repudiation solution and, unlike document signing solutions, does not claim to provide anti tampering capabilities, and since the changes can only be made by users that are granted rights to the document, Microsoft does not consider the later issue to be an actual attack against the claimed capabilities of RMS. The researchers provide a proof of concept tool, to allow evaluation of the results, via GitHub.