Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC)
Fine-grained control over DKE key usage based on user-defined policies
What is Access Control Policy?
The Access Control Policy for DuoKey DKE is designed to provide organizations with the ability to control and restrict the use of encryption keys based on predefined roles and attributes. This feature is pivotal for organizations seeking to implement stringent security measures to protect sensitive information from unauthorized access.
Supported Access Control Policies
User Restriction
Allow or block specific UPNs
Device Restriction
Control access by source IP
Geographic Restriction
Limit by geographic location
Group Management
Azure AD group integration
Core Principles of Zero Trust
Zero Trust is a security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are sitting within or outside of the network perimeter.
DuoKey DKE integrates this model by ensuring:
- No implicit trust is granted to assets or user accounts based solely on their physical or network location
- Authentication and authorization (both subject and device) are discrete functions performed before a session to an enterprise resource is established
Architecture and Components
| Component | Description |
|---|---|
| DKE Console (Cockpit) | Central hub for configuring and managing access control policies |
| DKE Web Service API | Interfaces with Microsoft environments to manage encryption/decryption |
| Policy Enforcer | Validates access requests against configured policies |
| DKE Cryptographic Service | Secure generation and storage of DKE keys in MPC |
Policy Enforcement
The policy engine (ABAC) defines who can access what resources, under which conditions. These policies are stored in a flexible and maintainable format, making it easy to update rules as organizational needs evolve.
The engine evaluates the context of each access request, such as the user's location, the device state, and membership in specific Azure AD groups, to make real-time decisions about whether to allow access to a decryption key.
Secure Content Key Decryption
When a user attempts to access an encrypted document in Office 365, DKE 365 intercepts this request to determine if the user should be granted access.
The access control engine consults the defined policy, evaluates the user's context, and either permits or denies the decryption key based on the policy's criteria.
Security Targets
Prevention
Prevent unauthorized users and devices from accessing sensitive encrypted data
Compliance
Support compliance with data protection laws by ensuring access controls meet standards
Data Security
Protect sensitive information from data breaches with authorized-only decryption
Threat Mitigation
| Asset | Threat | Mitigation Strategy |
|---|---|---|
| Encryption Keys | Unauthorized Access | Granular access controls based on roles, IP, location, and group membership |
| Encryption Keys | Insider Threats | RBAC and strict policy enforcement to limit access based on necessity |
| User Data | Spoofing Identity | Robust authentication and dynamic policy enforcement based on JWT claims |
| User Data | Data Exfiltration | Data encrypted at all times; keys managed in MPC with strict policies |
| Access Policies | Policy Tampering | Audit trails and logging; regular policy reviews |
| System Integrity | Denial of Service | Redundancy, failover, rate limiting, and monitoring |
Configure RBAC
Create RBAC Policy
Log in to DuoKey Cockpit
Navigate to cockpit.duokey.cloud
Open Access Control Policy
In the Administration Tab, open DuoKey - DKE: Access Control Policy
Create New Policy
- Click Create New Access Policy
- Enter Conditional Access Policy name
- Select an Action → Allow
- Select the Organisation Unit
Configure Policy Rules
Choose what type of access policy needs to be applied by selecting the different tabs and filling the mandatory fields.
Actions
Allow
The following example lets any user with a given email address and UPN reach the application:
| Action | Rule Type | Selector | Value |
|---|---|---|---|
| Allow | Any Of | [email protected] |
Block
For example, this configuration blocks every request to the application that tries to log in with the IP Address from Brazil, except those from Australia:
| Action | Rule Type | Device | Value |
|---|---|---|---|
| Block | Include (IP Only) | IP Only | Brazil: 101.33.22.0 |
| Block | Exclude (IP Only) | IP Only | Australia: 1.178.144.0 |
Bypass
The Bypass action allows all access requests and will not verify any policy rule.
Policy Configuration Tabs
Apply RBAC Policy to DKE Web Service
Open Apps Tab
Navigate to DuoKey - Apps
Select App
Select the App you wish to enforce the newly generated RBAC Policy
Edit App
Click Actions → Edit
Navigate to Access Control
Click Next three times until you see Your DKE Access control policy
Select Policy
Select your RBAC-Policy
Finish Wizard
Complete the DKE-App Wizard
The RBAC Policy is immediately applied to DKE-Decrypt Requests when submitting the configuration.