what component encrypt files organisation (os indeterminate prefered)?
say have garland files.
say store meta information files.
say, meta attributes called "encryption"
say everybody certified feeling during files, nonetheless given encrypted, wholly know decrypt indeed review contents.
say, each given value "encryption", organisation share trust decrypt files noted value.
say wish means programmatically, an os indeterminate proceed (if possible)
what values "encryption"?
how store keys?
how classify opening keys?
i am now arrangement towards following implementation:
- the value domain "encryption" contains name key, presumably also denoting algorithm used
- each user opening garland keys. tangible roles user an ldap/activedirectory structure, only files secure office users profile/home directory.
- on regard file, spectator (i'm perplexing build request supervision system) checks users keys decrypts record relating pivotal found.
what encryption use? symmetric (aes)? uneven (what good ones)?
using uneven keys have additional advantage origination inadequacy between reading record minute file: opening private pivotal required minute file, opening open pivotal (only roughly public, wholly certain roles have opening it) grant reading file. am i totally mistaken here?
what common systems solve problems used little center sized businesses?
edit: seems there concept sollutions. so, i state problem i am perplexing solve small some-more clearly:
imagine request supervision component operates distributed fashion: any request copied several nodes (company controlled, private) p2p network. an algorithm assuring excess papers used pledge backups papers (including revisions). component works use / daemon credentials shovels papers fro.
this means, users finish adult papers substantially meant internal workstation (a association tranquil pc laptop something - sourroundings such sme man sets adult controls biased p2p network).
this manners out office opening formed schemes, user substantially means data. am i mistaken here? internal folder encrypted such wholly accessed domain user? secure that?
i am wakeful users pity decrypted versions files - that tough conceal technically. problem i am perplexing solve.
Comments
Post a Comment