You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

MIP SDK无法使用DKE敏感度标签问题求助

使用C# MIP SDK处理DKE加密文件时遇到"Double key protection is disabled"错误

我正在开发一款Windows应用,使用C# MIP SDK(NuGet包Microsoft.InformationProtection.File,版本1.13.161)处理受Double Key Encryption(DKE)保护的文件。

我按照官方指南配置MIP SDK,并通过向FileEngineSettings.ConfiguredFunctionality字典添加DoubleKeyProtection和DoubleKeyUserDefinedProtection键启用了DKE功能。

借助IFileEngine可以获取所有敏感度标签(包括DKE标签),也能正常处理单密钥加密的“机密”标签保护文件。但每当尝试使用带DKE的敏感度标签时,都会收到NotSupportedError: Double key protection is disabled错误。该异常会在设置标签后提交文件句柄,以及尝试从受DKE标签保护的文件初始化文件句柄时抛出。

根据MIP日志,错误源于内部HTTPS请求返回HTTP 400状态:

MIP [Info] - message: Received HTTP response: ID: aa43de0d-3a0a-44d4-8499-83fd0de7d1c2, Status: 400, Time: 2023-06-07T20:20:04Z, Body: {"Code":"Microsoft.RightsManagement.Exceptions.BadInputException","InnerError":{"Resource":"[dke_service_url]","Code":"DoubleKeyEncryptionParametersMissing","Message":""},"Message":"Parameter DoubleKeyEncryptionPolicy is invalid."}, Headers['Date'] = 'Wed, 07 Jun 2023 20:20:03 GMT', Headers['Pragma'] = 'no-cache', Headers['Expires'] = '-1', Headers['X-Cache'] = 'CONFIG_NOCACHE', Headers['Content-Type'] = 'application/json; charset=utf-8', Headers['X-MSEdge-Ref'] = 'Ref A: 99DEEE7B27304EDC97E061BC77E9808F Ref B: AMS231032601031 Ref C: 2023-06-07T20:20:03Z', Headers['X-Powered-By'] = 'ASP.NET', Headers['Cache-Control'] = 'no-cache', Headers['CorrelationId'] = 'aa43de0d-3a0a-44d4-8499-83fd0de7d1c2', Headers['Content-Length'] = '250', Headers['X-AspNet-Version'] = '4.0.30319', Headers['client-request-id'] = 'aa43de0d-3a0a-44d4-8499-83fd0de7d1c2', Headers['Strict-Transport-Security'] = 'max-age=31536000; includeSubDomains', func: 'anonymous-namespace'::LogHttpOperationDetails at src\core\api_impl\http\http_director_impl.cpp (38)

我已尝试以下操作:

  • 在FileEngine和PolicyEngine上均启用双密钥加密
  • 为引擎设置不同的缓存存储类型
  • 在尝试之间清除MIP缓存
  • 使用不同的用户账户

但结果始终相同:抛出NotSupportedError: Double key protection is disabled错误。

我的测试设备和账户均已配置DKE,在MIP SDK中失效的同一敏感度标签,在MS Office应用和AIP客户端中可正常使用。DKE标签是按照官方指南配置的,DKE服务使用的是示例DoubleKeyEncryptionService。

请问是我在配置中遗漏了什么,还是MIP SDK存在bug?


示例代码(当前项目仅为POC,部分值为硬编码)

MIP初始化:

MIP.Initialize(MipComponent.File);

ApplicationInfo appInfo = new()
{
    ApplicationId = _userIdentity.ClientId,
    ApplicationName = "MIP tester",
    ApplicationVersion = "1.0.0",
};

MipConfiguration mipConfiguration = new(appInfo, path, Microsoft.InformationProtection.LogLevel.Trace, false);
mipConfiguration.LoggerDelegateOverride = this;

_mipContext = MIP.CreateMipContext(mipConfiguration);

File引擎初始化:

FileProfileSettings profileSettings = new(
    _mipContext,
    CacheStorageType.InMemory,
    new ConsentDelegate()
);

_fileProfile = await Task.Run(async () => await MIP.LoadFileProfileAsync(profileSettings).ConfigureAwait(false));

if (_fileProfile is null)
{
    throw new MipServiceException("Loaded file profile is null!");
}

FileEngineSettings engineSetings = new($"file_engine_{_userIdentity.UserName}", this, string.Empty, "en-US");
engineSetings.Identity = new Identity(_userIdentity.UserName);

// Enable DKE
var functionsDict = engineSetings.ConfiguredFunctionality ?? new Dictionary<FunctionalityFilterType, bool>();
functionsDict[FunctionalityFilterType.DoubleKeyProtection] = true;
functionsDict[FunctionalityFilterType.DoubleKeyUserDefinedProtection] = true;
engineSetings.ConfiguredFunctionality = functionsDict;

_fileEngine = await Task.Run(async () => await _fileProfile.AddEngineAsync(engineSetings).ConfigureAwait(false));

设置敏感度标签:

public async Task<string> SetLabel(Stream fileStream, string fileName, string labelId, string userName)
{
    if (_fileEngine is not null)
    {
        try
        {
            Label newLabel = _fileEngine.GetLabelById(labelId);

            IFileHandler fileHandler = await _fileEngine.CreateFileHandlerAsync(fileStream, fileName, true);

            fileHandler.SetLabel(newLabel, new LabelingOptions
            {
                AssignmentMethod = AssignmentMethod.Auto,
                IsDowngradeJustified = true,
                JustificationMessage = "I just want to do it :-)",
            },
            new ProtectionSettings
            {
                DelegatedUserEmail = userName,
                PFileExtensionBehavior = PFileExtensionBehavior.Default,
            });

            MemoryStream protectedStream = new MemoryStream();
            bool success = await fileHandler.CommitAsync(protectedStream); //This line throws an exception when setting DKE label

            return System.Convert.ToBase64String(protectedStream.ToArray());
        }
        catch (Exception e)
        {
            return $"Exception setting sensitivity label: {e}";
        }
    }
    return "Failure";
}

读取受保护文件内容:

IFileHandler fileHandler = await _fileEngine.CreateFileHandlerAsync(fileStream, fileName, true); //This line throws an exception when opening DKE protected file

内容的提问来源于stack exchange,提问作者Petr Hoffman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 22:44:55