MIP SDK无法使用DKE敏感度标签问题求助
我正在开发一款Windows应用,使用C# MIP SDK(NuGet包Microsoft.InformationProtection.File,版本1.13.161)处理受Double Key Encryption(DKE)保护的文件。
我按照官方指南配置MIP SDK,并通过向FileEngineSettings.ConfiguredFunctionality字典添加DoubleKeyProtection和DoubleKeyUserDefinedProtection键启用了DKE功能。
借助IFileEngine可以获取所有敏感度标签(包括DKE标签),也能正常处理单密钥加密的“机密”标签保护文件。但每当尝试使用带DKE的敏感度标签时,都会收到NotSupportedError: Double key protection is disabled错误。该异常会在设置标签后提交文件句柄,以及尝试从受DKE标签保护的文件初始化文件句柄时抛出。
根据MIP日志,错误源于内部HTTPS请求返回HTTP 400状态:
MIP [Info] - message: Received HTTP response: ID: aa43de0d-3a0a-44d4-8499-83fd0de7d1c2, Status: 400, Time: 2023-06-07T20:20:04Z, Body: {"Code":"Microsoft.RightsManagement.Exceptions.BadInputException","InnerError":{"Resource":"[dke_service_url]","Code":"DoubleKeyEncryptionParametersMissing","Message":""},"Message":"Parameter DoubleKeyEncryptionPolicy is invalid."}, Headers['Date'] = 'Wed, 07 Jun 2023 20:20:03 GMT', Headers['Pragma'] = 'no-cache', Headers['Expires'] = '-1', Headers['X-Cache'] = 'CONFIG_NOCACHE', Headers['Content-Type'] = 'application/json; charset=utf-8', Headers['X-MSEdge-Ref'] = 'Ref A: 99DEEE7B27304EDC97E061BC77E9808F Ref B: AMS231032601031 Ref C: 2023-06-07T20:20:03Z', Headers['X-Powered-By'] = 'ASP.NET', Headers['Cache-Control'] = 'no-cache', Headers['CorrelationId'] = 'aa43de0d-3a0a-44d4-8499-83fd0de7d1c2', Headers['Content-Length'] = '250', Headers['X-AspNet-Version'] = '4.0.30319', Headers['client-request-id'] = 'aa43de0d-3a0a-44d4-8499-83fd0de7d1c2', Headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains', func: 'anonymous-namespace'::LogHttpOperationDetails at src\core\api_impl\http\http_director_impl.cpp (38)
我已尝试以下操作:
- 在FileEngine和PolicyEngine上均启用双密钥加密
- 为引擎设置不同的缓存存储类型
- 在尝试之间清除MIP缓存
- 使用不同的用户账户
但结果始终相同:抛出NotSupportedError: Double key protection is disabled错误。
我的测试设备和账户均已配置DKE,在MIP SDK中失效的同一敏感度标签,在MS Office应用和AIP客户端中可正常使用。DKE标签是按照官方指南配置的,DKE服务使用的是示例DoubleKeyEncryptionService。
请问是我在配置中遗漏了什么,还是MIP SDK存在bug?
示例代码(当前项目仅为POC,部分值为硬编码)
MIP初始化:
MIP.Initialize(MipComponent.File); ApplicationInfo appInfo = new() { ApplicationId = _userIdentity.ClientId, ApplicationName = "MIP tester", ApplicationVersion = "1.0.0", }; MipConfiguration mipConfiguration = new(appInfo, path, Microsoft.InformationProtection.LogLevel.Trace, false); mipConfiguration.LoggerDelegateOverride = this; _mipContext = MIP.CreateMipContext(mipConfiguration);
File引擎初始化:
FileProfileSettings profileSettings = new( _mipContext, CacheStorageType.InMemory, new ConsentDelegate() ); _fileProfile = await Task.Run(async () => await MIP.LoadFileProfileAsync(profileSettings).ConfigureAwait(false)); if (_fileProfile is null) { throw new MipServiceException("Loaded file profile is null!"); } FileEngineSettings engineSetings = new($"file_engine_{_userIdentity.UserName}", this, string.Empty, "en-US"); engineSetings.Identity = new Identity(_userIdentity.UserName); // Enable DKE var functionsDict = engineSetings.ConfiguredFunctionality ?? new Dictionary<FunctionalityFilterType, bool>(); functionsDict[FunctionalityFilterType.DoubleKeyProtection] = true; functionsDict[FunctionalityFilterType.DoubleKeyUserDefinedProtection] = true; engineSetings.ConfiguredFunctionality = functionsDict; _fileEngine = await Task.Run(async () => await _fileProfile.AddEngineAsync(engineSetings).ConfigureAwait(false));
设置敏感度标签:
public async Task<string> SetLabel(Stream fileStream, string fileName, string labelId, string userName) { if (_fileEngine is not null) { try { Label newLabel = _fileEngine.GetLabelById(labelId); IFileHandler fileHandler = await _fileEngine.CreateFileHandlerAsync(fileStream, fileName, true); fileHandler.SetLabel(newLabel, new LabelingOptions { AssignmentMethod = AssignmentMethod.Auto, IsDowngradeJustified = true, JustificationMessage = "I just want to do it :-)", }, new ProtectionSettings { DelegatedUserEmail = userName, PFileExtensionBehavior = PFileExtensionBehavior.Default, }); MemoryStream protectedStream = new MemoryStream(); bool success = await fileHandler.CommitAsync(protectedStream); //This line throws an exception when setting DKE label return System.Convert.ToBase64String(protectedStream.ToArray()); } catch (Exception e) { return $"Exception setting sensitivity label: {e}"; } } return "Failure"; }
读取受保护文件内容:
IFileHandler fileHandler = await _fileEngine.CreateFileHandlerAsync(fileStream, fileName, true); //This line throws an exception when opening DKE protected file
内容的提问来源于stack exchange,提问作者Petr Hoffman

