Introduction to SHIELD DRM Service
SHIELD DRM service is a cloud-native DRM service. It provides security for data distributed in a cloud environment and is designed to be compatible with legacy security systems.
Main Features and Characteristics
1. Data Security
- Providing security through encryption of data distributed as File Document
2. Providing DRM Compatibility
- Upload DRM encrypted documents existing on the local PC for immediate use.
- Support for BYOK (Bring Your Own Key) and HYOK (Hold Your Own Key)
3. Cloud-Native Encryption
- Cloud-Native Encryption Optimized for Work Collaboration Tools Used in Organizations
- Eligible targets: Microsoft 365 (OneDrive · SharePoint · Teams), Google Workspace (Google Drive's My Drive · Shared Drive)
4. Security Policy Linkage
- Providing operational convenience and visibility of security policies
- Establishment of security policies that can be easily linked to existing security policies in the Cloud environment.
Document Encryption
SHIELD DRM service provides encryption for File Documents and protects organizations from data breaches through Document Centric Security and a shared responsibility model.
The document encryption method varies depending on the cloud service used.
Microsoft 365
Microsoft 365 users apply MIP labels when uploading files to OneDrive/SharePoint. Uploading existing DRM encrypted documents automatically converts them to MIP documents using SHIELD DRM.
MIP (Microsoft Information Protection) is Microsoft's information protection and management solution, used to protect and manage organizational data through labels, classifications, and security policies.
Google Workspace
In a Google Workspace environment, it detects changes in Google Drive (My Drive · Shared Drives) to evaluate conditional policies and decrypt DRM documents that correspond to the policies. During processing, it switches the document to a locked state to block editing by other users, and once processing is complete, it unlocks the document and reflects the changes in the same file.
Google Workspace does not have a server-side encryption system corresponding to MIP. Google Drive labels provide the functionality of document classification information but do not include encryption and access enforcement, and Google's client-side encryption (CSE) is browser environment-specific, making it unusable for document conversion on the server. Therefore, DRM protection for documents is reapplied by Document Security at the point when the user downloads the document to their local PC.
SHIELD DRM Security Integration and Cloud-Native Encryption Process
Microsoft 365 Standards
- Upload DRM files to the File Document environment such as Teams, OneDrive, etc.
- SHIELD DRM automatically converts the uploaded DRM documents into MIP (Microsoft Information Protection) documents.
- The converted MIP document can be viewed/edited/co-edited in the Microsoft 365 environment.
Google Workspace Standards
- Upload DRM files to Google Drive (My Drive · Shared Drive).
- SHIELD DRM detects changes in Google Drive and evaluates conditional policies.
- If it is a policy target, lock the document, then decrypt it, and unlock it to reflect it in the same file.
- You can view/edit/collaboratively edit decrypted documents in the Google Workspace environment.
- If you download this document to your local PC, Document Security will reapply DRM protection.
Google Workspace environment does not provide automatic encryption and label conversion at the time of upload. Policies do not operate on drives where the event channel is not installed.
Providing DRM Integration and Compatibility on Local PC
Microsoft 365
You can convert DRM documents to MIP or vice versa through the Document Security 365 feature.
Main Features:
- Document Conversion via DRM / MIP through Mouse Right-Click Shell Menu
- Provide conversion to each associated encryption policy by mapping the DRM policy and MIP policy.
In Document Security 365, the icon of documents with MIP labels is displayed, and you can check the encryption status by the label color.
Google Workspace
Documents downloaded from Google Drive have Document Security reapply DRM protection.
Operating Environment and Precautions
Microsoft 365
- Document Security 365 feature is included in the SHIELD DRM plan, and you must subscribe to Microsoft Business Premium or a plan of E3 or higher to use it.
Google Workspace
- You need to enable the Google Drive API in your Google Cloud project.
- You need to create a service account and approve Domain-Wide Delegation. The setup requires Google Workspace Super Admin privileges.
- To use a shared drive as a policy target, you must add a service account as a member with at least participant access to that shared drive. If you do not add it, the policy will not be applied.