ãã£ãã·ã³ã°ãžã®å¯Ÿçãæ¥åã§ãããšãã話ã¯ããè³ã«ãããã確ãã«ãã£ãã·ã³ã°ã¯å€§ããªè åšã§ããã ãã«ã¹ã±ã¢ãå€ãã ãŸãã ãã£ããªãã£æä¿¡ ãå®èšŒããã
ãã£ãã·ã³ã°ã¯ãµã€ããŒæ»æã®äžçš®ã§ãæ»æè ããŠãŒã¶ãŒãéšããŠã¯ã¬ãã³ã·ã£ã«ãæ©å¯æ å ±ãé瀺ããããã®ã§ãããå€ãã®å Žåãè©æ¬ºçãªé»åã¡ãŒã«ããŠã§ããµã€ãããŸãã¯ã¡ãã»ãŒãžãéããŠè¡ãããããã¹ã¯ãŒãã¬ã¹ã»ã¢ãããŒããå«ããã£ãã·ã³ã°ã«èæ§ã®ããèªèšŒæ¹æ³ã¯ãèªèšŒãããã€ã¹ãŸãã¯ãªãªãžã³ã«ãã€ã³ãããå ±æãããç§å¯ãæé€ããããšã«ãã£ãŠãã¯ã¬ãã³ã·ã£ã«ã®çé£ãé²ãããã«èšèšãããŠããã
ãã¹ã¯ãŒãã¬ã¹èªèšŒïŒäœãåŸ ã£ãŠããã®ãïŒ
ãŸããM-22-09ãExecutive Order 14028ãM24-14ã®ãããªæä»€ã¯ãåãªãå€èŠçŽ èªèšŒïŒMFAïŒä»¥äžã®ãã®ãèŠæ±ããŠããããã£ãã·ã³ã°ã«åŒ·ãçµç¹ãäœãäžã§ãã¹ã¯ãŒãã¬ã¹èªèšŒã®éèŠæ§ã«ã€ããŠãããè³ã«ãããOMB - M-22-09ã¯æ¬¡ã®ããã«è¿°ã¹ãŠããïŒ ãåæ©é¢ã¯ãèªèšŒã·ã¹ãã ãè¿ä»£åããéã«ããã¹ã¯ãŒããªãã®å€èŠçŽ èªèšŒã®å©çšãæ¡å€§ããããšã奚å±ãããã
ãããããã¹ã¯ãŒãã¬ã¹ã®å¿ èŠæ§ã¯ããã£ãã·ã³ã°å¯Ÿçã«ãšã©ãŸãããããåºç¯ã«ãããããçš®é¡ã®ãµã€ããŒæ»æãæéããçŸå®çãªä¿è·ãæäŸããèªèšŒç°å¢ãæ§ç¯ããããšã«ãããã¬ãŒãããŒç€Ÿã®ã¬ããŒã ãã¹ã¯ãŒãã¬ã¹èªèšŒãžã®ç§»è¡ã«ããã»ãã¥ãªãã£åŒ·åãšUXã®æé©å ãšææããïŒ
ãå€èŠçŽ èªèšŒïŒMFAïŒã®äžéšã§ãã£ãŠããã¹ã¯ãŒãã«äŸåãç¶ããçµç¹ã¯ããã¹ã¯ãŒãã¬ã¹æ¹åŒã«ç§»è¡ããçµç¹ãããå®å šæ§ãäœãã
RSAã§ã¯ããªãå€ãã®çµç¹ããã¹ã¯ãŒãã¬ã¹èªèšŒã®æ¡çšã«åããŠãã倧ããªåé²ãéããããªãã®ãããã°ãã°äžæè°ã«æã£ãŠããŸããGartner瀟ã®ã¬ããŒãã§ã¯ãçµç¹ã®è¶³ãããšãªã£ãŠããèŠå ãæ·±ãæãäžããåé²ããããã®å®è·µçãªæšå¥šäºé ãå ±æãããã¹ã¯ãŒãã¬ã¹èªèšŒã«ç§»è¡ããããããæ©äŒãæããããã®æ®µéçãªã¢ãããŒãã瀺ããŠããŸãã
ãã¹ã¯ãŒãã¬ã¹ã«ç§»è¡ããéã«èæ ®ããªããã°ãªããªãæåãã·ã¹ãã ã®èª¿æŽãèãããšãçµç¹ãèºèºããã®ã¯åœç¶ãããããªããããããã¯ã¬ãã³ã·ã£ã«çé£ã®ãªã¹ã¯ãå®èšŒãããŠããããšãèããã°ãé ããæ©ããè¡åãèµ·ããããšã¯çã«ããªã£ãŠããããŠãŒã¶ãŒã®ãã¹ã¯ãŒããå€ããã°å€ãã»ã©ããªã¹ã¯ã¯å€§ãããªãã
CISOãã¢ã€ãã³ãã£ãã£ã»ã¢ã¯ã»ã¹ç®¡çïŒIAMïŒãªãŒããŒããæ°ãããã¹ã¯ãŒãã¬ã¹ã»ãã¯ãããžãŒã«æ©æ¥ã«æè³ããããšãæžå¿µããŠããã®ã§ããã°ããã®éã«ã¯ã¬ãã³ã·ã£ã«ã»ããŒã¹ã®æ»æã®ç ç²ã«ãªããšããéåžžã«çŸå®çãªãªã¹ã¯ã«çŽé¢ããããšã«ãªãããã®ãããªãµã€ããŒã»ãã¥ãªãã£äžã®ãªã¹ã¯ã¯ãã»ãšãã©ã®çµç¹ã®èºèºãåé§ããŠããããã ã
FIDOã¢ã©ã€ã¢ã³ã¹ã¯ã87%ã®äŒæ¥ãã»ãã¥ãªãã£ãšUXã匷åããããã«ãã¹ããŒãå°å ¥ããŠããããå°å ¥ããäºå®ã§ãããšå ±åããŠããããããŠãããã¯äŒæ¥ã ãã§ã¯ãããŸããïŒæ¶è²»è ã¯ãŸããŸããã¹ã¯ãŒãã¬ã¹èªèšŒã«ç§»è¡ããŠãããçŸåš1å7500äžäººä»¥äžã®Amazon顧客ããã°ã€ã³ã«ãã¹ããŒã䜿çšããŠããŸãã
è匱ãªMFAãåé¿ããäžè¬çãªãã£ãã·ã³ã°ã®æå£
åŸæ¥ã®MFAã䜿çšããŠããçµç¹ã§ãã£ãŠããèªèšŒæ¹æ³ããã£ãã·ã³ã°ã«èæ§ããªããã°è匱ã«ãªãå¯èœæ§ãããïŒ
- ã¯ã¬ãã³ã·ã£ã«ã®ååïŒSMSãé»åã¡ãŒã«ãèªèšŒã¢ããªçµç±ã§éä¿¡ãããã¯ã³ã¿ã€ã ãã¹ã¯ãŒãããã£ããã£ã§ããã
- äžéè æ»æïŒæ»æè ã¯ãŠãŒã¶ãŒãéšããåœã®ãã°ã€ã³ããŒã¿ã«ãä»ããŠèªèšŒæ å ±ãæäŸãããã
- ãã«ãŠã§ã¢ã®ããŒãã¬ãŒïŒãã¹ã¯ãŒããã¯ã³ã¿ã€ã ãã¹ã¯ãŒããå«ãããŒå ¥åãèšé²ãããœãããŠã§ã¢ã
- ãã£ãã·ã³ã°ã»ãããïŒèªååãããæ»æãã¬ãŒã ã¯ãŒã¯ã¯ãããã€ã¹ããªãªãžã³ã«æå·çã«ãã€ã³ããããŠããªã MFA ã¡ãœãããæšçã«ããã
ã¬ãŒãããŒã®ã¬ããŒãã§ã¯ãçµç¹ã¯ç®¡çå¯èœãªæ®µéãèžãã§ãã¹ã¯ãŒãã¬ã¹ãå°å ¥ããããšã§æåã§ãããšææããŠããïŒãIAMãªãŒããŒã¯æ®µéçãªã¢ãããŒãããšãã¹ãã§ããã
å ±åæžã¯ãçµç¹ãåãã¹ã4ã€ã®å ·äœçãªã¹ããããææ¡ããŠããïŒ
- ãã¹ã¯ãŒãã䜿çšãããŠããå Žæã®ç®é²ããå§ããŠããŠãŒã¹ã±ãŒã¹ãç¹å®ããã
- ã»ãã¥ãªãã£ãšUXã®ç®æšã«åºã¥ãç®æšç¶æ ã«åæããã
- ããŸããŸãªæ¹æ³ãšãããŒã«ããã奜ã¿ã確èªããã
- åŽååãšé¡§å®¢ã®äœ¿çšäŸã«é¢ããããŒãããããäœæããã
ã§ RSACã«ã³ãã¡ã¬ã³ã¹2025, ãã¹ã¯ãŒãã¬ã¹ã¯ãå°æ¥ã®èšç»ãšåãããããçŸåšã®èªèšŒæ¹æ³ãšMFAã®å±éã®ç£æ»ãå¿ èŠãªæ ã§ããããšã説æãããçµç¹ã¯ãçŸåšåŒ·åãªèªèšŒãå°å ¥ããŠããå Žåããã¹ã¯ãŒãã¬ã¹ãžã®éåã°ã§ããããšã«æ°ã¥ããããããªãã
ãã£ãã·ã³ã°ã«åŒ·ãMFAã¯ãèªèšŒããŠãŒã¶ãŒã®ããã€ã¹ãšãªãªãžã³ã«ãã€ã³ããããããã¯ãŒã¯äžã®å ±æç§å¯ãæé€ããããšã§æ©èœãããæ¹æ³ã«ã¯ä»¥äžãå«ãŸããïŒ
- ãã¹ããŒãšã¢ããªããŒã¹ã®ããã·ã¥éç¥ïŒãŠãŒã¶ãŒã¯ããã¹ã¯ãŒãããããã¯ãŒã¯çµç±ã§éä¿¡ããããšãªããã¢ãã€ã«ããã€ã¹ããèªèšŒèŠæ±ãæ¿èªãŸãã¯æåŠããããšãã§ããŸãã
- ããã€ã¹ããŒã¹ã®èŠå ïŒæ¬äººç¢ºèªã¯ãå ±æãããã¯ã¬ãã³ã·ã£ã«ã§ã¯ãªããç¹å®ã®ããã€ã¹ã«çµã³ä»ããããã
- ããŒããŠã§ã¢ããŒã¹ã®èªèšŒïŒRSA iShield Key 2ã·ãªãŒãºããã³RSA DS100èªèšŒåšã¯ãFIDO2ãã¹ã¯ãŒãã¬ã¹èªèšŒããµããŒãããŠããŸãã
- çäœèªèšŒïŒAndroidãiOSãWindowsããã€ã¹ã§ã®æçŽèªèšŒãšé¡èªèšŒã
- ã¹ããŒãã«ãŒãïŒPKIèšŒææžïŒæ¿åºæ©é¢ãèŠå¶ã®å³ããæ¥çã§äžè¬çã
äŒæ¥ããã£ãã·ã³ã°ã«åŒ·ãMFAãå¿ èŠãšããçç±
- OTPãåŸæ¥ã®MFAãçã£ããã£ãã·ã³ã°æ»æã®å·§åŠå
- èŠå¶ãã©ã€ãïŒNIST 800-63Bã倧統é 什 14028ãCISA ãŒãã»ãã©ã¹ãã»ã¬ã€ãã³ã¹ïŒ
- çŸå®äžçã®ã¯ã¬ãã³ã·ã£ã«çé£ãªã¹ã¯
- åŸæ¥ã®MFAãããã»ãã¥ãªãã£ãšãŠãŒã¶ãŒäœéšãåäž
ã¬ãŒãããŒç€Ÿã®ã¬ããŒãã¯ããIAMãªãŒããŒã¯ã容æã«ãµããŒãããããã¹ã¯ãŒãã¬ã¹æ¹åŒãå°å ¥ãããã¹ã¯ãŒãã¬ã¹èªèšŒãä»ã®ãŠãŒã¹ã±ãŒã¹ã«æ¡å€§ããããã®ãããªãè¡åããšãã¹ãã§ããããšè¿°ã¹ãŠãããâ
ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ã®å°å ¥ãæ€èšããŠããçµç¹åãã«ãRSAã¯ãAIãæèŒããRSA Unified Identity Platformå ã§å©çšå¯èœãªãç¹å®ã®ãã¹ã¯ãŒãã¬ã¹æ©èœãšãªãœãŒã¹ãå¹ åºãæäŸããŠããŸãã
- ãã¹ããŒïŒRSA㯠RSA Authenticator ã¢ããª, ããã¯ããŠãŒã¶ãŒãããã€ã¹ããã¹ããŒãšããŠç»é²ãããã¹ã¯ãŒããªãã®èªèšŒã«äœ¿çšã§ããããã«ãããã®ã§ããã
- ã¢ããªããŒã¹ã®ããã·ã¥éç¥ïŒRSAã¯ãã¢ããªããŒã¹ã®ããã·ã¥éç¥ãæäŸããŠããããŠãŒã¶ãŒã¯ã¢ãã€ã«ã»ããã€ã¹ããèªèšŒèŠæ±ã®æ¿èªãŸãã¯æåŠãè¡ãããšãã§ããŸãã
- ããã€ã¹ããŒã¹ã®èŠå RSA æ¬äººç¢ºèª æ©èœã«ã¯ããã£ãã·ã³ã°ããã®ä»ã®æ»æã§æšçã«ãããå¯èœæ§ã®ããäžé£ã®èªèšŒæ å ±ã§ã¯ãªããID ãç¹å®ã®ããã€ã¹ã«ãªã³ã¯ããããšãå«ãŸããã
- ããŒããŠã§ã¢ããŒã¹ã®èªèšŒïŒããŒããŠã§ã¢èªèšŒã¯ RSA iShield Key 2 ã·ãªãŒãº èªèšŒæ©é¢ãš RSA DS100 authenticatorã¯ã©ã¡ãããå»çåŸäºè ããããŒã«æè¢ããã¹ã¯ãççšããå¿ èŠãããå Žåããã€ã³ã¿ãŒãããæ¥ç¶ããã€ã¹ãèš±å¯ãããŠããªãã¯ãªãŒã³ã«ãŒã ãªã©ãçäœèªèšŒãæºåž¯é»è©±ãé©ããŠããªããŠãŒã¹ã±ãŒã¹åãã«ãFIDO2ããŒã¹ã®ãã¹ã¯ãŒãã¬ã¹èªèšŒãæäŸããŠããã
- çäœèªèšŒïŒRSAã¯ãAndroidãšiOSããã€ã¹ã®äž¡æ¹ã§æçŽèªèšŒãšé¡èªèšŒããµããŒãããŠããŸãããŸããWindowsãŠãŒã¶ãŒã®çäœèªèšŒæ¹æ³ãšããŠWindows HelloããµããŒãããŠããŸãã
RSAã®ãã¹ã¯ãŒãã¬ã¹ã»ãœãªã¥ãŒã·ã§ã³ãããã€ã¹ããŒã¹ã»ãœãªã¥ãŒã·ã§ã³ä»¥å€ã«ããäŒæ¥ã¯ãã£ãã·ã³ã°ã«åŒ·ãMFAãã¯ãããžãŒã掻çšããŠã»ãã¥ãªãã£ã匷åããããšãã§ããŸãïŒ
- ã¹ããŒãã«ãŒã / PKIèšŒææžïŒ ã»ãã¥ã¢ãªããã€ã¹ã«ä¿åãããèšŒææžã§ãæ¿åºæ©é¢ãèŠå¶ã®å³ããæ¥çã§åŒ·åãªèªèšŒã®ããã«ãã䜿çšãããã
- ã¢ãã€ã«ãšãã¹ã¯ãããçšã®ãã¹ããŒïŒ ãã©ãããã©ãŒã éã§ã·ãŒã ã¬ã¹ãªãã¹ã¯ãŒãã¬ã¹ãã°ã€ã³ãå¯èœã«ããããã€ã¹ãã€ã³ãèªèšŒæ å ±ã
- é©å¿åMFAïŒ ããã€ã¹ã®ä¿¡å·ãå°ççäœçœ®ãããã³ãŠãŒã¶ãŒã®è¡åãçµã¿åãããŠããªã¹ã¯ãæ€åºããããšãã«ããã匷åãªæ€èšŒã宿œããã³ã³ããã¹ãèªèèªèšŒã
- ãœãããŠã§ã¢ã»ã»ãã¥ãªãã£ã»ããŒã¯ã³ïŒ ãã£ãã·ã³ã°ã«åŒ·ãåºæºãæºãããã»ãã¥ã¢ãªã¢ããªïŒFIDO2æºæ ã®ã¢ããªãªã©ïŒã«æå·çã«çæãããéµãä¿åããã
ãããã®æè¡ã段éçãªå°å ¥æŠç¥ãšçµã¿åãããããšã§ãäŒæ¥ã¯ãåŸæ¥å¡ãšé¡§å®¢ã®äž¡æ¹ã® ID ãä¿è·ãããå±€æ§é ã®èãã£ãã·ã³ã°èªèšŒãã¬ãŒã ã¯ãŒã¯ãæ§ç¯ããããšãã§ããŸãã
ãã£ãã·ã³ã°ã«åŒ·ãMFAã®ã¡ãªãã
- ã¯ã¬ãã³ã·ã£ã«ã»ãã£ãã·ã³ã°ãšãªãã¬ã€æ»æã黿¢ãã
- ã³ã³ãã©ã€ã¢ã³ã¹çŸ©åããã³èŠå¶åºæºã«é©å
- OTPããŒã¹ã®MFAãšæ¯èŒããŠãŠãŒã¶ãŒã»ãšã¯ã¹ããªãšã³ã¹ãåäž
- äŒæ¥ããã³é¡§å®¢ã®ã·ã¹ãã å šäœã§ã¢ã«ãŠã³ãæŒæŽ©ã®ãªã¹ã¯ãäœæž
ãšã³ã¿ãŒãã©ã€ãºã°ã¬ãŒãã®ããŒããŠã§ã¢èªèšŒããæ±ãã®äŒæ¥ã«ã¯ RSA iShield Key 2 ã·ãªãŒãº ã¯ãå®å šã§ã³ã³ãã©ã€ã¢ã³ã¹ã«æºæ ããã䜿ãããããœãªã¥ãŒã·ã§ã³ãæäŸããŸããRSAã®ãã¹ã¯ãŒãã¬ã¹ããã³ãã£ãã·ã³ã°èæ§ã®MFAãªãã·ã§ã³ã®ãã«ã¹ã€ãŒããšçµã¿åãããããšã§ããŠãŒã¶ãŒ ã¢ã¯ã»ã¹ãç°¡çŽ åããªãããææ°ã®ã¯ã¬ãã³ã·ã£ã«æ»æããçµç¹ãä¿è·ã§ããŸãã
ã«ã€ããŠãã£ãšç¥ã ãã¹ã¯ãŒãã¬ã¹æ©èœ ã®äžéšãšããŠå©çšã§ããã RSA ID Plus, ã ç¡æäœéšãç³ã蟌ã ãã¯ãªãã¯ããŠãRSAãã©ã®ããã«ãã¹ã¯ãŒãã¬ã¹èªèšŒãžã®ç§»è¡ãå éãããããšãã§ããããã確èªãã ããã
ã¬ãŒãããŒç€Ÿãã¹ã¯ãŒãã¬ã¹èªèšŒãžã®ç§»è¡ã«ããã»ãã¥ãªãã£åŒ·åãšUXã®æé©åãã¢ã³ãã»ã¢ã©ã³ããžã§ãŒã ãºã»ããŒããŒ2024幎8æ30æ¥çºè¡
GARTNERã¯ãç±³åœããã³ãã®ä»ã®åœã«ãããã¬ãŒãããŒç€Ÿããã³ïŒãŸãã¯ãã®é¢é£äŒç€Ÿã®ç»é²åæšããã³ãµãŒãã¹ããŒã¯ã§ãããèš±å¯ãåŸãŠäœ¿çšããŠããŸããç¡æè€åã»è»¢èŒãçŠããŸãã
FIDO2ã»ãã¥ãªãã£ããŒããã¹ããŒãã¹ããŒãã«ãŒããããã€ã¹ãã€ã³ããã€ãªã¡ããªã¯ã¹ã
NIST 800-63Bã倧統é 什 14028ãããã³ CISA ãŒããã©ã¹ãã»ã¬ã€ãã³ã¹ã
ãŠã§ããµã€ãã®ãªãªãžã³ãæ€èšŒããããã€ã¹ã«ãã€ã³ããããæå·éµã䜿çšããããšã§ãå ±æç§å¯ãæé€ããã
èªèšŒèŠçŽ ãããã€ã¹ãŸãã¯ãªãªãžã³ã«ãã€ã³ããããããã¯ãŒã¯äžã®å ±æç§å¯ãåé¿ããã
ããããOTPã¯æ»æè ã«ååãããããåçããããããå¯èœæ§ããããŸãã
ãããææ°ã®MFAãœãªã¥ãŒã·ã§ã³ã¯ãäŒæ¥ã®IAMã·ã¹ãã ãSSOãã¯ã©ãŠãã¢ããªãšã®çµ±åããµããŒãããŠããã
段éçãªã¢ãããŒãããšãããŠãŒã¶ãŒãã¬ã³ããªãŒãªèªèšŒæ¹æ³ãéžæããæç¢ºãªãã¬ãŒãã³ã°ãšãµããŒããæäŸããã