<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://communities.bentley.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Secure Document Proposal</title><link>https://communities.bentley.com/products/projectwise/f/projectwise-di-forum/80090/secure-document-proposal</link><description>Recently a group asked me to create a folder within their datasource to use for a high-security sub-project. I worked with them to set up a top level folder that only their group can view and access, but there is still some concern about file security</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>Re: Secure Document Proposal</title><link>https://communities.bentley.com/thread/221395?ContentTypeID=1</link><pubDate>Mon, 17 Sep 2012 17:31:31 GMT</pubDate><guid isPermaLink="false">6dad98f5-dbc9-4c4d-a9ba-e9da8dc6aa8e:9dcd1f13-ae3f-4bb6-9bc9-ae8db1d1d9e9</guid><dc:creator>Stephen Herrick</dc:creator><description>&lt;p&gt;Excellent,&lt;/p&gt;
&lt;p&gt;Thank you&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Secure Document Proposal</title><link>https://communities.bentley.com/thread/221367?ContentTypeID=1</link><pubDate>Mon, 17 Sep 2012 13:43:48 GMT</pubDate><guid isPermaLink="false">6dad98f5-dbc9-4c4d-a9ba-e9da8dc6aa8e:12e68e3e-5161-4c3d-a854-c35cc10cbdfe</guid><dc:creator>Rimantas Varanavicius</dc:creator><description>&lt;p&gt;Hi Stephen,&lt;/p&gt;
&lt;p&gt;Bull&amp;#39;s eye!:) &lt;/p&gt;
&lt;p&gt;We are indeed looking to integrate Bentley Transmittal Services with the DRM.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Rimantas&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Secure Document Proposal</title><link>https://communities.bentley.com/thread/221298?ContentTypeID=1</link><pubDate>Sat, 15 Sep 2012 01:57:04 GMT</pubDate><guid isPermaLink="false">6dad98f5-dbc9-4c4d-a9ba-e9da8dc6aa8e:464ef3e1-bc91-40a9-b6e6-5984605bd889</guid><dc:creator>Stephen Herrick</dc:creator><description>&lt;p&gt;Hello John,&lt;/p&gt;
&lt;p&gt;My first thought when reading this thread was &amp;quot; How can this be used with Bentley Transmittals &amp;quot; I know there will be times when a transmittal is sent to a user and then we need to revoke if for some reason or another. &amp;nbsp;Would the DRM functionality be able to do that?&lt;/p&gt;
&lt;p&gt;Thank you&lt;/p&gt;
&lt;p&gt;Stephen&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Secure Document Proposal</title><link>https://communities.bentley.com/thread/221147?ContentTypeID=1</link><pubDate>Thu, 13 Sep 2012 22:41:33 GMT</pubDate><guid isPermaLink="false">6dad98f5-dbc9-4c4d-a9ba-e9da8dc6aa8e:7ac6ce44-d9df-46c3-b20d-3d64771d10d3</guid><dc:creator>John Simmons</dc:creator><description>&lt;p&gt;Yes, Kevin is correct in that we are working on a DRM solution for us with both ProjectWise and eB. We use the acronym DRM to refer to Dynamic Rights Management. It’s also referred to in other forums as Digital Rights Management, Information Rights Management, and Content Rights Management. We prefer the usage of “Dynamic” since it reflects the real-time nature of the control that you have over documents that have DRM applied to them. &lt;/p&gt;
&lt;p&gt;In a nutshell, DRM Protects digital content from unauthorized access through a content-centric security model using encryption and embedded policies. This model allows you to have real-time control over your deliverables to control access, audit usage, revoke out-dated information like construction drawings. Initially, DRM will support PDF and Office formats, but the intent is to extend it to other Bentley deliverables, like i-models. &lt;/p&gt;
&lt;p&gt;The target for this functionality is not information stored in PW or eB – that’s already secure. It’s also not targeted for files that you copy/check in-out of those repositories either for WIP since encrypting/descrypting in and out of the managed environment isn’t a good thing to do either. Rather, the focus will be on deliverables – documents that are finalized and being distributed to others. DRM gives you the ability to control access and usage (view, print, comment, modify) of those documents anywhere, anytime. &lt;/p&gt;
&lt;p&gt;One good use case is that I’ve issued drawings for construction, and there’s been an engineering change that requires new drawings be issues. With DRM, you can revoke the previous drawings that have been issued ,and as users access those drawings they will be informed of the revocation and offered to access the updated drawings – all from the same interface. There are other use cases as well, but I think you get the idea.&lt;/p&gt;
&lt;p&gt;We think that it will be pretty handy, but what really matters is what you think. &lt;/p&gt;
&lt;p&gt;So what do you guys think?&lt;/p&gt;
&lt;p&gt;Thanks - John&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Secure Document Proposal</title><link>https://communities.bentley.com/thread/221037?ContentTypeID=1</link><pubDate>Thu, 13 Sep 2012 03:35:54 GMT</pubDate><guid isPermaLink="false">6dad98f5-dbc9-4c4d-a9ba-e9da8dc6aa8e:e6cda22d-d7df-4ad7-8e7c-adf8620de536</guid><dc:creator>Kevin van Haaren</dc:creator><description>&lt;p&gt;The only way to truly offer this is for Bentley to create viewers for the various file types that are part of the project that enforces the restrictions and then all users would have to use PW Explorer to access the project (web browsers would need a local copy of the file, as Mike mentions.)&lt;/p&gt;
&lt;p&gt;Just opening the file from the server (say via some protected windows files) wouldn&amp;#39;t solve the problem -- all applications that open files locally, or from the network, have a Save As... function that would all users to make their own local copies. &amp;nbsp;You have to have completely trusted applications as well, so the viewer would have to be made with this purpose in mind.&lt;/p&gt;
&lt;p&gt;Some of Bentley&amp;#39;s new DRM stuff coming from the publishing group can help with this. &amp;nbsp;For example you can produce documents that are locked for a particular duration and unopenable after that. The documents can be revoked even after issued so if you suspect a document has leaked you can kill it. But you&amp;#39;ll have a limited number of viewers that work with this level of DRM.&lt;/p&gt;
&lt;p&gt;John Simmons did a session on this at the last Mid-America CADD community conference. &amp;nbsp;They might be doing another at a user conf in Seattle.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Secure Document Proposal</title><link>https://communities.bentley.com/thread/220893?ContentTypeID=1</link><pubDate>Tue, 11 Sep 2012 23:58:01 GMT</pubDate><guid isPermaLink="false">6dad98f5-dbc9-4c4d-a9ba-e9da8dc6aa8e:e9b0a02f-5ea2-42d2-a1ca-3d1de2dd6eac</guid><dc:creator>Michael McCarty</dc:creator><description>&lt;p&gt;Just my &lt;strong&gt;personal&lt;/strong&gt; thoughts here:&lt;/p&gt;
&lt;p&gt;The design of most (if not all) non-web-browser content viewing applications requires that the content to be viewed be accessible as a file on the filesystem. Even a file opened via a web browser is typically downloaded to a file to some temporary location, then handed off to the viewing application.&lt;/p&gt;
&lt;p&gt;For what you propose to work, the &lt;strong&gt;application&lt;/strong&gt; would need to support a method of displaying the content from some non-predictable volatile location (e.g., read a binary blob from memory, a proposition that is fraught with its own particular sort of peril).&lt;/p&gt;
&lt;p&gt;Some options you may want to consider (I&amp;#39;m sure that others out there will have their own opinions and solutions):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;BitLocker (or some other local volume-level encryption technology). This would ensure that only the authorized user would be able to decrypt and view the local content. It does assume that your users can be trusted enough to not manually copy said content. Personally, I regard that as a problem that no software can truly solve.&lt;/li&gt;
&lt;li&gt;Put the working directory on a RAM disk. Pros: content is deleted when the volume is dismounted or the system is rebooted. Cons: content is deleted when the volume is dismounted or the system is rebooted :-)&lt;/li&gt;
&lt;li&gt;Enforce draconian workstation-level security (no filesystem access, restricted desktop, USB/Firewire ports disabled by domain security policy, tamper-proof HDD).&amp;nbsp; Drawbridge and moat are optional. :-)&lt;/li&gt;
&lt;li&gt;Remote Desktop, or Citrix (or other workstation virtualization technologies). YMMV here, I&amp;#39;m not really familiar with that kind of stuff.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Mike&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>