Separating different ecryptfs mounts

is it possible with ecryptfs to have two different ecryptfs mounts, e.g.,

plain1 -> raw1
plain2 -> raw2

using two different openssl keys, and to ensure that each key is _only_
used by its own mount? That is, I want to prevent that files copied between 
raw1 and raw2 are automatically decrypted. 

To my understanding of the IBM paper about ecryptfs, it should be possible to 
set a policy defining which mount is allowed to use which key, but I could not 
find any documentation about it. 

When it is possible, can you explain or point me to some docs describing how I 
can do this?


