RSAã»ãã¥ãªãã£å ¬é鵿å·ã®ãã¬ãŒã¯ã¹ã«ãŒããã¢ã€ãã³ãã£ãã£ã»ã»ãã¥ãªãã£ã®æªæ¥ãŸã§
嵿¥ä»¥æ¥ãRSAã»ãã¥ãªãã£ã¯ãµã€ããŒã»ãã¥ãªãã£ã®ãã€ãªãã¢ãšããŠãæ¿åºæ©é¢ãéèãµãŒãã¹ããšãã«ã®ãŒããã«ã¹ã±ã¢ããã®ä»ã®èŠå¶ã®å³ããæ¥çã®ãªãŒããŒãã¡ã«ãIDããã³ã¢ã¯ã»ã¹ç®¡çïŒIAMïŒãIDã¬ããã³ã¹ããã³ç®¡çïŒIGAïŒãã¢ã¯ã»ã¹ãå€èŠçŽ èªèšŒïŒMFAïŒã®æ©èœãæäŸããŠããŸããã
RSAã»ãã¥ãªãã£ã¯ã1977幎ã«RSAæå·åã¢ã«ãŽãªãºã ãéçºãããã³ã»ãªãã¹ããã¢ãã£ã»ã·ã£ãã¢ãã¬ããŒãã»ã¢ãã«ãã³ã«ãã£ãŠ1982幎ã«èšç«ãããããã®å ¬é鵿å·èŠæ Œã¯2000幎ã«ãããªãã¯ãã¡ã€ã³ãšããŠå ¬éãããçŸåšã§ã¯RSAã»ãã¥ãªãã£ç€Ÿãææã販売ã管çããŠããããã§ã¯ãªãããRSAã®ç©èªã«ãããéèŠãª1ç« ã象城ããŠããã
RSA Securityã¯èšç«ä»¥æ¥ããã£ãã·ã³ã°ããã«ãŠã§ã¢ããœãŒã·ã£ã« ãšã³ãžãã¢ãªã³ã°ããã®ä»ã®ç¹°ãè¿ãçºçããè åšã®ãã¯ãã«ããçµç¹ãé²åŸ¡ããæ¯æŽãè¡ã£ãŠããŸãããRSAã¯ããã£ãŒããã§ã€ã¯ãAIãæŽ»çšããæ»æãITãã«ããã¹ã¯ã®ãã€ãã¹ãªã©ãæ°ããªè åšã«å¯Ÿããæè¡é©æ°ãç¶ããŠããŸãããŸããäžçãéåã³ã³ãã¥ãŒãã£ã³ã°ã®æ°æä»£ã«è¿ã¥ãã«ã€ããRSAã¯æªè³ªãªè¡çºè ã®äžæ©å ãè¡ãçµç¹ãæ¯æŽãããããæè¡é©æ°ãç¶ããŠããŸãã
ã¢ã€ãã³ãã£ãã£ã»ã»ãã¥ãªãã£ã®æåç·ã«ç«ã€RSAã®æŽå²ãšæªæ¥ã«ã€ããŠã以äžã®ç« ããèªã¿ãã ããïŒ
1977幎ãå®å šãªéµäº€æãå¿ èŠãšããå ±é鵿巿¹åŒã®éçã«å¯Ÿãã解決çãšããŠãå ¬é鵿å·ã®æŠå¿µãç»å ŽãããRSAã¢ã«ãŽãªãºã ã¯ãæå·åçšã®å ¬ééµãšåŸ©å·åçšã®ç§å¯éµãšããäžå¯Ÿã®éµãå©çšããããšã§ããã®èª²é¡ã«å¯ŸåŠããããããã®ã㢠RSAã㌠ã¯RSAæå·ã·ã¹ãã ã®ããã¯ããŒã³ã圢æããä¿¡é ŒãããŠããªããããã¯ãŒã¯äžã§ãå®å šãªããŒã¿äŒéãå¯èœã«ããããã®æè¡é©æ°ã«ãããäºåã«éµäº€æãããããšãªããä¿¡é ŒãããŠããªããã£ãã«äžã§ã®å®å šãªéä¿¡ãå¯èœã«ãªã£ããRSAã®å®å šæ§ã¯ã倧ããªçŽ æ°ãå æ°åè§£ããèšç®ã®é£ããã«åºã¥ããŠãããäžæ£ãªããŒã¿ã»ã¢ã¯ã»ã¹ã«å¯ŸããæãããããŒã«ãšãªã£ãŠããã
ããµãã¥ãŒã»ããå·¥ç§å€§åŠ(MIT)ã¯ã2012幎7æããããµãã¥ãŒã»ããå·¥ç§å€§åŠè³ããåè³ããã ç¹èš± 1983幎ã«RSAã¢ã«ãŽãªãºã ã®ç¹èš±ãååŸããç¹èš±æéã¯17幎ã«èšå®ãããã
RSAæå·ã·ã¹ãã ãåºãæ¡çšãããããšã§ãããžã¿ã«èšŒææžãšå ¬é鵿å·åã管çãããã¬ãŒã ã¯ãŒã¯ã§ããRSAå ¬ééµåºç€ïŒPKIïŒãéçºããããRSA PKIã¯ãé»ååååŒãå®å šãªé»åã¡ãŒã«ãããžã¿ã«çœ²åã«äžå¯æ¬ ãªSSL/TLSãªã©ã®ãããã³ã«ãæ¯ããã€ã³ã¿ãŒããããä»ããå®å šãªéä¿¡ã®ç¢ºç«ã«è²¢ç®ããŸããã
RSAã»ãã¥ãªãã£ã¯ãæå·åã¢ã«ãŽãªãºã ããããªãã¯ãã¡ã€ã³ãšããŠå ¬éããã 2000幎9æ6æ¥.ãã®ãªãªãŒã¹ã«ãããã誰ã§ããã®ã¢ã«ãŽãªãºã ã®ç¬èªã®å®è£ ãçµã¿èŸŒãã 補åãäœãããšãã§ããããã«ãªããããã¯ãRSAã»ãã¥ãªãã£ç€Ÿãã2000幎9æ6æ¥ä»¥éã«çºçããRSAã¢ã«ãŽãªãºã ãå«ãéçºæŽ»åã«å¯ŸããŠãç¹èš±ãè¡äœ¿ããæš©å©ãæŸæ£ããããšãæå³ããã"仿¥ããã®ã¢ã«ãŽãªãºã ã¯ãããªãã¯ã»ã¹ã¿ã³ããŒã(FIPS 186-5).
RSAã»ãã¥ãªãã£ãæå·åã¢ã«ãŽãªãºã ããããªãã¯ãã¡ã€ã³ã«ãªãªãŒã¹ããŠãã20幎以äžãRSAã»ãã¥ãªãã£ã¯ãµã€ããŒã»ãã¥ãªãã£ã®èª²é¡ã«å¯Ÿããæ°ãããœãªã¥ãŒã·ã§ã³ãéçºãç¶ããŠããŸãã
çŸåšãRSAã»ãã¥ãªãã£ã¯ã¢ã€ãã³ãã£ãã£ã»ã»ãã¥ãªãã£ã«ç¹åããããŸããŸãªã¢ã¯ã»ã¹ãèªèšŒãã¬ããã³ã¹ãã©ã€ããµã€ã¯ã«ã»ãœãªã¥ãŒã·ã§ã³ãæäŸããããšã§ãçµç¹ã®ãªã¹ã¯é²æ¢ãè åšã®æ€åºãã³ã³ãã©ã€ã¢ã³ã¹ã®å®çŸãçç£æ§ã®åäžãæ¯æŽããŠããŸãïŒ
- RSA® ID Plus ã¯ãã¯ã©ãŠãããã€ããªããããªã³ãã¬ãã¹ã®åç°å¢ã«ãããŠããã¹ã¯ãŒãã¬ã¹MFAãSSOãã³ã³ãã¯ã¹ãã¥ã¢ã«ã»ã¢ã¯ã»ã¹ããã€ã¯ããœããããã®ä»ã®ãµãŒãããŒãã£ãšã®çµ±åãã¯ã©ãŠãã»ãã£ã¬ã¯ããªã»ãµãŒãã¹ãªã©ãããããIAMæ©èœãæäŸããã
- RSA® ã¬ããã³ã¹ïŒã©ã€ããµã€ã¯ã« äŒæ¥ã¯ãã¢ããªã±ãŒã·ã§ã³ãã·ã¹ãã ãããŒã¿å šäœã«IGAæ©èœãå°å ¥ããèŠæš¡ã«å¿ããå®å šãªã¢ã¯ã»ã¹ã管çããããšã§ãã³ã³ãã©ã€ã¢ã³ã¹ãæ¹åãããªã¹ã¯ãäœæžããæ¥åãæé©åããããšãã§ããŸãã
- RSA SecurID® ã»ãã¥ã¢ãªã¢ã¯ã»ã¹ãèªèšŒãã¢ã€ãã³ãã£ãã£ã»ã©ã€ããµã€ã¯ã«ç®¡çæ©èœã«ããããªã³ãã¬ãã¹ã®ãªãœãŒã¹ãä¿è·ããŸãã
çŸåšã®RSAãœãªã¥ãŒã·ã§ã³ã®è©³çްã«ã€ããŠã¯ããã¡ããã芧ãã ããã ãåãåããã¯ãã¡ã ããã ããã ä»ããID Plusã®ç¡æãã©ã€ã¢ã«ãéå§.
éåã³ã³ãã¥ãŒã¿ã®é²æ©ã¯ããã£ãã£ãŒã»ãã«ãã³ïŒDHïŒéµäº€æãæ¥åæ²ç·æå·ïŒECCïŒãRSAæå·ã¢ã«ãŽãªãºã ãªã©ãå€å žçãªæå·åã¢ã«ãŽãªãºã ã«è åšãäžããæ¥ãæ¥ããããããªããéåã³ã³ãã¥ãŒã¿ã¯ãæŽæ°ã®å æ°åè§£ãªã©ã®è€éãªæ°åŠçåé¡ããå€å žçãªã³ã³ãã¥ãŒã¿ãããææ°é¢æ°çã«éãè§£ãå¯èœæ§ãç§ããŠããã
RSAã¢ã«ãŽãªãºã ãã倧ããªçŽ æ°ãå æ°åè§£ããèšç®ã®é£ããã«åºã¥ããŠããããšãèãããšãã·ã§ãŒã«ã®ãããªéåã¢ã«ãŽãªãºã ã¯ãæçµçã«RSAéµãè§£èªããããã«äœ¿ãããå¯èœæ§ãããããã£ãã£ãŒã»ãã«ãã³ïŒDHïŒãæ¥åæ²ç·ïŒECCïŒã®éµãåæ§ã ãECCã¯å¥ã®æ°åŠçåé¡ã«åºã¥ããŠããããåºæ¬çã«ã¯ã·ã§ãŒã«ã®ã¢ã«ãŽãªãºã ã§ãè§£èªå¯èœã§ãããå®éãè§£èªã«å¿ èŠãªqãããã®æ°ã¯ãåçã®åŒ·åºŠãæã€RSA/DHéµãããå°ãªããŠæžãã ããã
ãã®ãªã¹ã¯ã«åãããããNISTã¯åæã¬ã€ãã³ã¹ã®èæ¡ãå ¬è¡šããïŒããã¹ãéåæå·æšæºãžã®ç§»è¡ãïŒã NIST IR 85472024幎ã«ã¯ãå°ãªããšã112ãããã®ã»ãã¥ãªãã£åŒ·åºŠïŒ2048ãããã®RSAéµïŒãæšå¥šãã2030幎以éã¯å°ãªããšã4096ãããã®RSAéµïŒ128ãããã®ã»ãã¥ãªãã£åŒ·åºŠïŒãå©çšããããšãç®æšãšããŠãããNISTã¯ããã®ã¬ã€ãã³ã¹ã®èæ¡ã§ã2035幎以éã¯ãããªããµã€ãºã®éµã§ãRSAæå·åã䜿çšããªãããšãæšå¥šããŠããã çµç¹ã¯ãããŸã§ãéµã®é·ããšéµã®ããŒããŒã·ã§ã³ã«é¢ãããã¹ãã»ãã©ã¯ãã£ã¹ãç¶ç¶ããæå·åã®å®å šæ§ãä¿ã€ã¹ãã§ãããææ°ã®ãŠã§ãã»ãã©ãŠã¶ã¯4096ãããã®éµã«å¯Ÿå¿ããŠãããNISTã®2030幎ã®RSAéµã¬ã€ãã³ã¹ãšäžèŽããŠããã
RSAã»ãã¥ãªãã£ã¯ããããã®å§åããªã¹ã¯ã«åºã¥ããé©åãªå¯Ÿçã§ãããšèããŠããŸããéåã³ã³ãã¥ãŒãã£ã³ã°ã¯ãŸã çºå±éäžã§ãããåäœã«ã¯èšå€§ãªãªãœãŒã¹ãå¿ èŠã§ããããšãããéåã³ã³ãã¥ãŒãã£ã³ã°ãæå·åã«ãšã£ãŠçŽã¡ã«è åšãšãªãããšã¯ãããŸãããæã匷åãªéåã³ã³ãã¥ãŒã¿ã¯ãæè¿1000éåãããïŒqubitsïŒãè¶ ããããå®å®ããåäœãç¶æã§ããã®ã¯1ïœ2ããªç§ã«éããªããããã«æ¯ã¹ãçè«çã«ã¯ 2000äžéåãããã»ã³ã³ãã¥ãŒã¿ãŒ 2048ãããã®RSAæå·éµ1ã€ãè§£èªããã®ã«8æéãèŠãããNIST IR 8547ãå°å ¥ããããšã§ãäŒæ¥ã¯éåã³ã³ãã¥ãŒãã£ã³ã°ããã€ããããããããããªããªã¹ã¯ã«å æãæã€ããšãã§ããã
RSAã»ãã¥ãªãã£ã¯ãèªç€Ÿã®ãœãªã¥ãŒã·ã§ã³ã«ãããã®ã¬ã€ãã©ã€ã³ãå°å ¥ããŠãããä»åŸãNISTã®ãã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠãããŸãã
NIST ã®ãã¹ãéåã¬ã€ãã©ã€ã³ã宿œããããšã«å ããçµç¹ã¯çŸåšã® IT ã€ã³ãã©ãææ¡ããããšã«åªããã¹ãã§ãããçŸåšã®ã¢ããªã±ãŒã·ã§ã³ã®ã«ã¿ãã°åããœãããŠã§ã¢ã®ææ°ããŒãžã§ã³ãžã®æŽæ°ãåºæ¬çãªãµã€ããŒè¡ç管çã¯ãçµç¹ãçŸåšã®è åšãã身ãå®ããéåã³ã³ãã¥ãŒãã£ã³ã°ã®ãããªæ°ããªãªã¹ã¯ã«åããããã«äžå¯æ¬ ãªãµã€ããŒã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã§ããã
çµç¹ã¯ãçè«äžã®ãªã¹ã¯ã«å æãæã€ããã«ãNIST ã®éåã³ã³ãã¥ãŒãã£ã³ã°ã»ã¬ã€ãã³ã¹ãèªèãã宿œãã¹ãã§ããããããããªãŒããŒã¯ãµã€ããŒã»ãã¥ãªãã£ã«å¯ŸããŠãªã¹ã¯ããŒã¹ã®ã¢ãããŒããåããæãå¯èœæ§ãé«ããæã圱é¿ã®å€§ããæ»æã«åããã¹ãã§ãããçè«çãªéåã³ã³ãã¥ãŒãã£ã³ã°ã®ãªã¹ã¯ãåªå ãããããšã¯ããµã€ããŒç¯çœªè ã仿¥æåãåããŠãããéåžžã«æç¢ºã§ãçŽæ¥çã§ãèœåçãªè åšãèŠèœãšãããšã«ãªããŸãïŒ
- ãã«ã¹ã±ã¢ãå€ãã çãŸããèªèšŒæ å ±ã«ãã£ãŠäŸµå®³ãããäžéšã®ã¢ã«ãŠã³ãã§MFAãæå¹ã«ãªã£ãŠããªãã£ãã
- æ£èè æ°åãã«ã®æå€±ããããããã©ã³ãµã ãŠã§ã¢æ»æã仿ããããã«ãITãã«ããã¹ã¯ã®ã¹ã¿ããã説åŸããŠMFAèªèšŒæ å ±ãç¡å¹åãŸãã¯ãªã»ãããããã
- ã³ããã¢ã«ã»ãã€ãã©ã€ã³VPNã¢ã«ãŠã³ãã«äŸµå ¥ãããã
- ããŒãº87168 ãããã®é©çšãããŠããªãè匱æ§ãæªçšãããªã©ã¯ã«ã»ã¯ã©ãŠããã600äžä»¶ã®ããŒã¿ã»ã¬ã³ãŒããçãã ãšäž»åŒµããŠããã
éåã³ã³ãã¥ãŒãã£ã³ã°ã«ã¯å·šé¡ã®è³éãšãªãœãŒã¹ãå¿ èŠã ããããã®ããŒã¿æŒæŽ©ã¯ããã§ã¯ãªãã仿¥ã®èšå€§ãªéã®æ»æã¯ããã£ãã·ã³ã°ããœãŒã·ã£ã«ã»ãšã³ãžãã¢ãªã³ã°ããã¹ã¯ãŒãããŒã¹ã®èªèšŒãããããé©çšãããŠããªãã·ã¹ãã ããããã¯ãŒã¯ã®ã¢ã¯ã»ã¹ã»ããããžã§ãã³ã°ã«äŸåããæåããŠããããããã®ãªã¹ã¯ã¯ãçµç¹ãæ©æ¥ã«æ³šæãæãã察çãè¬ããæè³ããå¿ èŠãããã
å€å žçRSAæå·ãšãã¹ãéåæå·ã®æ¯èŒ
ç¹åŸŽ
å€å žçRSAæå·
ãã¹ãéåæå·
ã³ã¢ã»ã¢ã«ãŽãªãºã
æŽæ°åè§£ïŒã¢ãžã¥ã©ãŒæ°åŠïŒ
ã©ãã£ã¹ããŒã¹ãããã·ã¥ããŒã¹ãã³ãŒãããŒã¹
ããŒã¿ã€ã
RSAéµïŒå ¬é/ç§å¯ãã¢ïŒ
èéåéµãã¢
éåã«å¯Ÿããè匱æ§
ã·ã§ãŒã«ã®ã¢ã«ãŽãªãºã ã«åœ±é¿ããããã
éåæ»æã«èããèšèš
åŸæ¥ã®æ»æã«å¯Ÿããè匱æ§
50幎ã«ãããåºç¯å²ã«ç ç©¶ãããŠãããCPUãã¯ãŒã®å¢å ïŒããã¯ããŒãµã€ãºãé·ãããããšã§å¯Ÿçå¯èœïŒä»¥å€ã«åºæ¬çãªåŒ±ç¹ã¯ãªãã
ãã¹ãéåã¢ã«ãŽãªãºã ãäœå幎ãåããååšããŠããããæå·è§£æã®ç ç©¶ã¯ããŸãè¡ãããŠããªãã
ããŒã®é·ã
2048ïœ4096ãããïŒæéãšãšãã«å¢å ïŒ
äžè¬çã«å€§ããããããå®å š
çŸåšã®äœ¿çšäŸ
PKIãããžã¿ã«çœ²åãVPN
ãã¹ããšè©Šéšçå°å ¥
æšæºåç¶æ³
é·ãæŽå²ãæã€ïŒäŸïŒRSA-PSSãPKCSïŒ
審æ»äžïŒNIST PQCãã¡ã€ããªã¹ããªã©ïŒ
ç¹åŸŽ
ã³ã¢ã»ã¢ã«ãŽãªãºã
å€å
žçãªRSAæå·ïŒ
æŽæ°åè§£ïŒã¢ãžã¥ã©ãŒæ°åŠïŒ
ãã¹ãéåæå·ïŒ
ã©ãã£ã¹ããŒã¹ãããã·ã¥ããŒã¹ãã³ãŒãããŒã¹
ç¹åŸŽ
ããŒã¿ã€ã
å€å
žçãªRSAæå·ïŒ
RSAéµïŒå
¬é/ç§å¯ãã¢ïŒ
ãã¹ãéåæå·ïŒ
èéåéµãã¢
ç¹åŸŽ
éåã«å¯Ÿããè匱æ§
å€å
žçãªRSAæå·ïŒ
ã·ã§ãŒã«ã®ã¢ã«ãŽãªãºã ã«åœ±é¿ããããã
ãã¹ãéåæå·ïŒ
éåæ»æã«èããèšèš
ç¹åŸŽ
åŸæ¥ã®æ»æã«å¯Ÿããè匱æ§
å€å
žçãªRSAæå·ïŒ
50幎ã«ãããåºç¯å²ã«ç ç©¶ãããŠãããCPUãã¯ãŒã®å¢å ïŒããã¯ããŒãµã€ãºãé·ãããããšã§å¯Ÿçå¯èœïŒä»¥å€ã«åºæ¬çãªåŒ±ç¹ã¯ãªãã
ãã¹ãéåæå·ïŒ
ãã¹ãéåã¢ã«ãŽãªãºã ãäœå幎ãåããååšããŠããããæå·è§£æã®ç ç©¶ã¯ããŸãè¡ãããŠããªãã
ç¹åŸŽ
ããŒã®é·ã
å€å
žçãªRSAæå·ïŒ
2048ïœ4096ãããïŒæéãšãšãã«å¢å ïŒ
ãã¹ãéåæå·ïŒ
äžè¬çã«å€§ããããããå®å
š
ç¹åŸŽ
çŸåšã®äœ¿çšäŸ
å€å
žçãªRSAæå·ïŒ
PKIãããžã¿ã«çœ²åãVPN
ãã¹ãéåæå·ïŒ
ãã¹ããšè©Šéšçå°å
¥
ç¹åŸŽ
æšæºåç¶æ³
å€å
žçãªRSAæå·ïŒ
é·ãæŽå²ãæã€ïŒäŸïŒRSA-PSSãPKCSïŒ
ãã¹ãéåæå·ïŒ
審æ»äžïŒNIST PQCãã¡ã€ããªã¹ããªã©ïŒ
ãã¹ãéåæå·ã¢ã«ãŽãªãºã ã¯éåã³ã³ãã¥ãŒãã£ã³ã°æ»æã«å¯Ÿããèæ§ããããšèããããŠãããããã®ãããªãã¬ãŒã ã¯ãŒã¯ã§ããããäŒçµ±çãªãæå·è§£èªãã³ã³ãã¥ãŒãã£ã³ã°ææ³ã«ãã£ãŠæ»æãããå±éºæ§ãããããšã«æ³šæããããšãéèŠã§ãããçµç¹ããã¹ãéåæå·åã¢ã«ãŽãªãºã ã䜿çšããå Žåããã¹ãéåæ»æããã¯å®å šã§ããã¹ãã ãããã¬éåæ¹åŒã«ããæ»æã«ãã£ãŠãããã³ã°ãããå¯èœæ§ããããRSA/ECC/DHã®ãããªäŒçµ±çãªã¢ã«ãŽãªãºã ã¯äœå幎ãç ç©¶ãããŠããã
嵿¥ä»¥æ¥ãRSAã¯ãµã€ããŒã»ãã¥ãªãã£ã®åœ¢æã«è²¢ç®ããŠããŸãããRSAæå·ã·ã¹ãã ã®ãã€ãªãã¢ãããã¹ã¯ãŒãã¬ã¹èªèšŒã®ãªãŒããŒãŸã§ãRSAã®ã¬ã¬ã·ãŒã¯ãã€ãããŒã·ã§ã³ãšã»ãã¥ãªãã£ãžã®æºãããªãã³ãããã¡ã³ãã«ãã£ãŠç¹åŸŽä»ããããŸããRSAã¯ãã客æ§ã®å®å šãå®ãã¢ã€ãã³ãã£ãã£ã»ã»ãã¥ãªãã£æè¡ãéçºããããšã§ããã®éºç£ãå®ãç¶ããŠãããŸãã