Prevent user from editing doc without both encryption keys

A doc encrypted with two keys should not be editable to a user who has only one of the keys. But the user with one key can get to the doc properties and remove the key he does not have, then he can edit the doc. My question: Is it possible to avoid this problem?
Encrypt a field on the form with one or both of the keys. The field will not be visible unless someone has both keys.

This was first published in April 2002