MFAã¯ã å€èŠçŽ èªèšŒ(Multi-Factor Authentication)ãã®ç¥ã§ã å€èŠçŽ èªèšŒ ã®åã®éããã¢ããªã±ãŒã·ã§ã³ããŠã§ããµã€ãããŸãã¯ãã®ä»ã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèŠæ±ãã人ã®èº«å ã確èªããããã«è€æ°ã®èŠçŽ ã䜿çšããèªèšŒæ¹æ³ã§ããäŸãã°ãåã«ãã¹ã¯ãŒããå ¥åããã ãã§ã¢ã¯ã»ã¹ããã®ãšããã¹ã¯ãŒãã«å ããŠã¯ã³ã¿ã€ã ãã¹ã¯ãŒãïŒOTPïŒãã»ãã¥ãªãã£è³ªåãžã®åçãæ±ããããã®ãšã§ã¯ãå€èŠçŽ èªèšŒã®å·®ãçŸããŸãã
è€æ°ã®æ¹æ³ã§èº«å ã確èªããããšã§ãå€èŠçŽ èªèšŒã¯ãŠãŒã¶ã䞻匵ããæ¬äººã§ããããšããã確å®ã«èšŒæã§ãããããæ©å¯ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ã®ãªã¹ã¯ã軜æžããŸããããšãã°ãçãŸãããã¹ã¯ãŒããå ¥åããã ãã§ã¢ã¯ã»ã¹ãåŸãã®ã¯æ¯èŒçç°¡åã§ãããçãŸãããã¹ã¯ãŒãã«å ããæ£åœãªãŠãŒã¶ã®ã¹ããŒããã©ã³ã«éä¿¡ãããOTPãå ¥åããå¿ èŠãããå Žåã¯ãã¢ã¯ã»ã¹ãããå°é£ã«ãªããŸãã
2ã€ä»¥äžã®èŠçŽ ãçµã¿åãããå Žåãããã¯å€èŠçŽ èªèšŒãšã¿ãªãããŸãããŸãã2ã€ã®èŠçŽ ã®ã¿ã䜿çšããå Žåã¯ãäºèŠçŽ èªèšŒïŒTwo-Factor AuthenticationïŒãšåŒã°ããããšããããŸãã
ã¹ããã1 â ãŠãŒã¶åãšãã¹ã¯ãŒãã®å ¥å
å€èŠçŽ èªèšŒããã»ã¹ã®æåã®ã¹ãããã¯ãéåžžããŠãŒã¶ãèªåã®åºæã®ãŠãŒã¶åãšãã¹ã¯ãŒããå ¥åããããšããå§ãŸããŸãããã®åŸæ¥åã®èªèšŒæ¹æ³ã¯ãäžæ£ã¢ã¯ã»ã¹ã«å¯Ÿããåæã®é²åŸ¡æ段ãšããŠæ©èœããŸãããŠãŒã¶ã¯ãå®å šãªãã°ã€ã³ããŒãžã§è³æ Œæ å ±ã®å ¥åãæ±ããããŸãããããããŠãŒã¶åãšãã¹ã¯ãŒãã®ã¿ã«äŸåããããšã¯ããã£ãã·ã³ã°æ»æããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãäžéè æ»æïŒAdversary-in-the-Middle AttackïŒããŸãã¯ãµãŒãããŒãã£ã®ããŒã¿äŸµå®³ã«ãã£ãŠè³æ Œæ å ±ãè åšã¢ã¯ã¿ãŒã«æµåºãããªã©ãããŸããŸãªè åšã®ããã«äžååã§ããå ŽåããããŸãã
ãã®ãããåŸæ¥ã®MFAããã»ã¹ãå®äºããå Žåã§ãããã¹ã¯ãŒããè¶ ããèªèšŒãç®æãå Žåã§ããçµç¹ã®ã»ãã¥ãªãã£äœå¶ã匷åããããã«ã¯ãè¿œå ã®ç¢ºèªæ¹æ³ãå¿ èŠã§ãã
ã¹ããã2 â ããŒã¯ã³ãŸãã¯PINã®å ¥å
ãŠãŒã¶åãšãã¹ã¯ãŒããæ£åžžã«å ¥åããåŸãã»ãšãã©ã®MFAããã»ã¹ã§ã¯ããŠãŒã¶ã«äžæçãªå人èå¥çªå·ïŒPINïŒãŸãã¯ã¯ã³ã¿ã€ã ãã¹ã³ãŒãïŒOTPïŒã®å ¥åãæ±ããŸãããã®ã¹ãããã®äž»ãªç¹åŸŽã¯ãããŒã¯ã³ãæéã«ææã§ãããéåžžã¯å®æçã«å€æŽãããããšã§ããã€ãŸããæªæã®ããæ»æè ããŠãŒã¶ã®ãã¹ã¯ãŒããååŸããå Žåã§ãããã°ã€ã³ããã»ã¹ãå®äºããããã«ã¯ããŒã¯ã³ãžã®ã¢ã¯ã»ã¹ãå¿ èŠãšãªããããã»ãã¥ãªãã£ãå€§å¹ ã«åŒ·åãããŸãããã®äºéèªèšŒã®èŠæ±ã«ãããäŸµå ¥è ãã¢ã¯ã»ã¹ãåŸãã®ãéåžžã«å°é£ã«ãªããŸãã
OTPã第äºã®èªèšŒèŠçŽ ãšããŠäœ¿çšããããšã¯ããã¹ã¯ãŒãã®ã¿ã䜿çšãããããã¯ããã«å®å šã§ãããä»ã®ãããã³ã«ã»ã©å®å šã§ã¯ãããŸãããããã«ãOTPãã©ã®ããã«å ±æããããèªèšŒããã»ã¹å šäœã®ã»ãã¥ãªãã£ã«ãããŠéèŠãªèŠçŽ ã§ãããSMSãã¡ãŒã«ã¯äžè¬çã«ã»ãã¥ãªãã£ãäœããšèŠãªãããŠããŸãã
ã¹ããã3 â æçŽãŸãã¯ãã®ä»ã®çäœèªèšŒã®ç¢ºèª
å€èŠçŽ èªèšŒããã»ã¹ã®æçµã¹ãããã§ã¯ãæçŽã¹ãã£ã³ãé¡èªèãè¹åœ©ã¹ãã£ã³ãªã©ã®çäœèªèšŒããŸãã¯ããã€ã¹ã«çŽã¥ãããããã¹ããŒã®ãããªææç©ã«ããèªèšŒãè¡ãããŸããçäœèªèšŒã¯ãè€è£œãåœé ãéåžžã«å°é£ãªãŠããŒã¯ãªèº«äœçç¹åŸŽã«äŸåããŠããŸãããŠãŒã¶åããã¹ã¯ãŒããããŒã¯ã³ã«å ããŠçäœèªèšŒãèŠæ±ããããšã«ãããMFAã¯ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããããšããŠãã人ç©ã確å®ã«èªèšŒããããŠãŒã¶ã§ããããšãä¿èšŒããŸãããã®ã¹ãããã¯ãæçŽèªèšŒãé¡èªèæè¡ãæèŒããå€ãã®ããã€ã¹ãããã¢ãã€ã«ç°å¢ã§ã¯ç¹ã«äŸ¡å€ããããŸããçäœèªèšŒãå°å ¥ããããšã§ãã»ãã¥ãªãã£ã匷åãããã ãã§ãªãããŠãŒã¶ã¯è€éãªã³ãŒããèŠããå¿ èŠãªããè¿ éãã€ç°¡åã«èªåã®èº«å ã確èªã§ãããããã·ãŒã ã¬ã¹ã§ãŠãŒã¶ãã¬ã³ããªãŒãªäœéšãæäŸãããŸãã
ããã€ã¹ã«çŽã¥ãããããã¹ããŒããã®ä»ã®ããŒããŠã§ã¢èªèšŒè£ 眮ãããŒããŠã§ã¢ããŒã¯ã³ãã»ãã¥ãªãã£ã匷åããŸããããã€ã¹ã«çŽã¥ãããããã¹ããŒã¯ãç¹å®ã®ãã»ãã¥ãªãã£ããŒãããã€ã¹ã«ãã¹ããããéµãã¢ã¯åäžã®ããã€ã¹ã§çæãããä¿åãããŸããããã«ãéµèªäœã¯ãã®ããã€ã¹ããé¢ããããšããªããããããå®å šãªèªèšŒãããŒãå®çŸããŸãã
å€èŠçŽ èªèšŒã®æ¹æ³ã¯ãéåžžã以äžã®3ã€ã®ã«ããŽãªãŒã«åé¡ãããŸãïŒ
1.ç¥èèŠçŽ â PINããã¹ã¯ãŒãããŸãã¯ã»ãã¥ãªãã£è³ªåã®çã
ãã¹ã¯ãŒããPINã¯ãç¥èèŠçŽ ãã®äŸã§ãããããã¯ãŠãŒã¶ãç¥ã£ãŠããç§å¯ã§ãããé²åŸ¡ã®æåã®ã©ã€ã³ãšããŠæ©èœããŸããMFAã®äžéšãšããŠããããã¯ãŠãŒã¶ãèšæ¶ããŠãããšãããä»è ã«ã¯ã¢ã¯ã»ã¹ã§ããªãæ å ±ã«åºã¥ããŠã»ãã¥ãªãã£ã確ä¿ããŸãã
2.ææèŠçŽ â OTPãããŒã¯ã³ãä¿¡é Œãããããã€ã¹ãã¹ããŒãã«ãŒãããããžãããã€ã¹ããŠã³ããã¹ããŒ
ããŒããŠã§ã¢ããŒã¯ã³ãããã€ã¹ã«çŽã¥ãããããã¹ããŒããŸãã¯æºåž¯é»è©±ãªã©ã®ç©ççããã€ã¹ãææããããšã¯ãææèŠçŽ ãã«è©²åœããŸãããããã®ã¢ã€ãã ã¯æå·éµãä¿æããŠããããèªèšŒã³ãŒããåä¿¡ããèœåãæã£ãŠãããäžæ£ã¢ã¯ã»ã¹ã®ããã®è¿œå ã®éå£ãæäŸããŸããææèŠçŽ ã䜿çšããå Žåããã¹ã¯ãŒããç¥ã£ãŠããã ãã§ã¯äžååã§ããŠãŒã¶ãç©ççã«æã£ãŠãããã®ãå¿ èŠãšãªããŸãã
3.çäœèŠçŽ â é¡ãæçŽã網èã¹ãã£ã³ããã®ä»ã®çäœèªèšŒ
ãçäœèŠçŽ ãã¯å人ã®çäœçç¹åŸŽã«é¢é£ããŸããäŸãšããŠã¯ãæçŽãé¡èªèãé³å£°ãã¿ãŒã³ãããã«ã¯ç¶²èã¹ãã£ã³ãªã©ããããŸãããããã®èŠçŽ ã¯äººéã®çç©åŠçç¹åŸŽã®ãŠããŒã¯ãã掻çšããŠãããæœåšçãªäŸµå ¥è ã«ãšã£ãŠå€§ããªéå£ãæäŸããŸãã
以äžã®ããããã®æ¹æ³ããã¹ã¯ãŒããšçµã¿åãããŠäœ¿çšããããšã§ãå€èŠçŽ èªèšŒãå®çŸã§ããŸãã
- çäœèªèšŒ â æçŽãé¡ã®ç¹åŸŽãç®ã®ç¶²èãè¹åœ©ãªã©ãããã€ã¹ãã¢ããªã±ãŒã·ã§ã³ãèªèããçäœçç¹åŸŽã«åºã¥ãèªèšŒæ¹æ³
- ããã·ã¥éç¥ã«ããæ¿èª â ãŠãŒã¶ãã¢ã¯ã»ã¹èŠæ±ãæ¿èªããããã«ãããã€ã¹ã®ç»é¢ãã¿ããããããã«æ±ããããéç¥
- ã¯ã³ã¿ã€ã ãã¹ã¯ãŒã (OTP) â 1åéãã®ãã°ã€ã³ã»ãã·ã§ã³ãŸãã¯ååŒã®èªèšŒã«äœ¿çšããããèªåçã«çæãããæåå
- ããŒããŠã§ã¢ããŒã¯ã³ ãŸãã¯ããã€ã¹ããŠã³ããã¹ã㌠â å°åã®æºåž¯å¯èœãªOTPçæããã€ã¹ã§ãæã«ã¯ ãRSA iShield Key 2ã·ãªãŒãºã ãRSA DS100ããŒããŠã§ã¢èªèšŒåšã®ããã«ããŒãã©ããšåŒã°ããããšããã
- ãœãããŠã§ã¢ããŒã¯ã³ ãŸãã¯ãœãããŠã§ã¢èªèšŒåš â ã¹ããŒããã©ã³ããã®ä»ã®ããã€ã¹äžã«ã¢ããªãšããŠååšããããŒã¯ã³ã§ãç©ççãªããŒã¯ã³ã§ã¯ãªããRSAã®Authenticatorã¢ããªã®ãããªãã®ã§iOSãAndroidã«å¯Ÿå¿ã
ã»ãã¥ãªãã£ã®åäž
å€èŠçŽ èªèšŒã¯ã»ãã¥ãªãã£ã匷åããŸããçµå±ã®ãšãããã¢ã¯ã»ã¹ã®ãã€ã³ããå®ãã¡ã«ããºã ã1ã€ïŒäŸãã°ãã¹ã¯ãŒãïŒã®ã¿ã§ããã°ãæªæã®ããè ãã¢ã¯ã»ã¹ãåŸãããã«å¿ èŠãªããšã¯ããã®ãã¹ã¯ãŒããæšæž¬ãããçãã ãããæ¹æ³ãèŠã€ããããšã ãã§ãããã®ãããããŒã¿æŒæŽ©ã®å€ãã¯ã䟵害ãããèªèšŒæ å ±ããèªèšŒæ å ±ãçãããã®ãã£ãã·ã³ã°ããå§ãŸããŸãã
ããããããã¢ã¯ã»ã¹ããããã«ã2çªç®ïŒãããã¯3çªç®ïŒã®èªèšŒèŠçŽ ãå¿ èŠãšãªãã°ãç¹ã«ãããæšæž¬ãçé£ãé£ããçäœèªèšŒã®ãããªãã®ã§ããã°ãäŸµå ¥ãããã«å°é£ã«ãªããŸãã
ãŸããMFAã¯çµç¹ã®ãŒããã©ã¹ãæç床ãåäžããããã£ãã·ã³ã°ã«å¯Ÿæãããã£ãã·ã³ã°èæ§ã®ããèªèšŒãæäŸããŸãã
ããžã¿ã«ã€ãã·ã¢ããã®å®çŸ
ä»æ¥ã ãªã¢ãŒãã¯ãŒã¯ ãå°å ¥ããçµç¹ãå¢ããæ¶è²»è ãåºèã§ã¯ãªã ãªã³ã©ã€ã³ã§è²·ãç© ãããŠãããã«å€ãã®çµç¹ãã¢ããªããªãœãŒã¹ã ã¯ã©ãŠãã«ç§»è¡ããŠããäžã§ãå€èŠçŽ èªèšŒã¯åŒ·åãªæ¯æŽãšãªããŸããããžã¿ã«æ代ã«ãããŠãçµç¹ãeã³ããŒã¹ã®ãªãœãŒã¹ãä¿è·ããããšã¯ææŠçã§ãããå€èŠçŽ èªèšŒã¯ãªã³ã©ã€ã³ã§ã®ããåããååŒãå®å šã«ä¿ã€ããã«éåžžã«è²Žéãªåœ¹å²ãæãããŸãã
ããå®å šãªã¢ã¯ã»ã¹ç°å¢ãäœãéçšã§ãå©äŸ¿æ§ãäœäžããå¯èœæ§ããããŸãããããæ¬ ç¹ãšãªãããšããããŸããïŒããã¯ã ãŒããã©ã¹ããããããã¯ãŒã¯ããã®äžã§åäœããŠããã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ãæœåšçãªè åšãšèŠãªããšããèãæ¹ããå®å šãªã¢ã¯ã»ã¹ã®åºç€ãšããŠåºãŸãã€ã€ããçŸåšãç¹ã«åœãŠã¯ãŸããŸããïŒåŸæ¥å¡ã¯æ¯æ¥ãã°ã€ã³ããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã®éã«è€æ°ã®é害ãåŠçããããã«äœåãªæéã䜿ãããã¯ãªããæ¥ãã§è²·ãç©ãéè¡ååŒãæžãŸãããæ¶è²»è ããè€æ°ã®èªèšŒèŠä»¶ã«éªéãããããšãæãã§ããŸãããéèŠãªã®ã¯ãã»ãã¥ãªãã£ãšå©äŸ¿æ§ã®ãã©ã³ã¹ãåãããšã§ããã¢ã¯ã»ã¹ãå®å šã§ããããšã¯éèŠã§ãããæ£åœãªçç±ã§ã¢ã¯ã»ã¹ãå¿ èŠãªäººã ã«ãšã£ãŠé床ã®äžäŸ¿ãçããããªãããã«ããããšãæ±ããããŸãã
ã»ãã¥ãªãã£ã確ä¿ãã€ã€å©äŸ¿æ§ãä¿ã€ããã®æ¹æ³ã®äžã€ã¯ãã¢ã¯ã»ã¹èŠæ±ã«é¢é£ãããªã¹ã¯ã«å¿ããŠèªèšŒèŠä»¶ã匷åãŸãã¯ç·©åããããšã§ããããã ãªã¹ã¯ããŒã¹èªèšŒïŒRisk-Based AuthenticationïŒãšåŒã°ãããã®ã§ãããªã¹ã¯ã¯ãã¢ã¯ã»ã¹ãããå 容ãã¢ã¯ã»ã¹ãèŠæ±ããŠãã人ç©ããŸãã¯ãã®äž¡æ¹ã«é¢é£ããŠããŸãã
- ã¢ã¯ã»ã¹ãããå 容ã«ãããªã¹ã¯: äŸãã°ã誰ããéè¡å£åº§ãžã®ããžã¿ã«ã¢ã¯ã»ã¹ãèŠæ±ããå Žåãããã¯è³é移åã®ãããããããšããã§ã«éå§ããã転éã®ã¹ããŒã¿ã¹ã確èªãããããïŒ ãŸãã誰ãããªã³ã©ã€ã³ã·ã§ããã³ã°ãµã€ããã¢ããªãšããåãããŠããå Žåãããã¯äœãã泚æãããããããããšãæ¢åã®æ³šæã®é éç¶æ³ã確èªãããããïŒ åŸè ã®å ŽåããŠãŒã¶åãšãã¹ã¯ãŒãã§ååã§ãããé«äŸ¡ãªè³ç£ããªã¹ã¯ã«ãããããŠããå Žåã«ã¯ãå€èŠçŽ èªèšŒãçã«ããªã£ãŠããŸãã
- ã¢ã¯ã»ã¹èŠæ±è ã«ãããªã¹ã¯: ãªã¢ãŒãã®åŸæ¥å¡ãå¥çŽè ããæ¯æ¥åãéœåžããåãã©ãããããã䜿çšããŠäŒæ¥ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ãèŠæ±ããå Žåããã®äººç©ã§ãããšçãçç±ã¯ã»ãšãã©ãããŸãããããããããæãããã¢ããªã¹ã®ã¡ã¢ãªãŒããã®ãªã¯ãšã¹ããã¢ã¹ã¯ã¯ããæ¥ãå Žåã¯ã©ãã§ããããïŒ ãã®æœåšçãªãªã¹ã¯ïŒæ¬åœã«åœŒå¥³ãªã®ãïŒïŒã¯ãè¿œå ã®èªèšŒãèŠæ±ããçç±ã«ãªããŸãã
å€èŠçŽ èªèšŒã¯ãçµç¹ã«ãšã£ãŠããå®å šã§ããŠãŒã¶ã«ãšã£ãŠã¯ãã䟿å©ãªã¢ã¯ã»ã¹ãæäŸããããã«é²åãç¶ããŠããŸããçäœèªèšŒã¯ãã®èãæ¹ã®è¯ãäŸã§ããæçŽãé¡ãçãããšã¯é£ãããããå®å šã§ããããŸãããŠãŒã¶ã¯ãã¹ã¯ãŒãã®ãããªãã®ãèŠããããä»ã®å€§ããªåªåãããå¿ èŠããªãããããã䟿å©ã§ãã以äžã¯ãçŸåšå€èŠçŽ èªèšŒã圢äœã£ãŠããããã€ãã®é²å±ã§ãã
- 人工ç¥èœïŒAIïŒãšæ©æ¢°åŠç¿ïŒMLïŒâ AIãšMLã¯ãäžããããã¢ã¯ã»ã¹èŠæ±ããæ£åžžãã§ãããè¿œå ã®èªèšŒãå¿ èŠãªãããšã瀺ãè¡åãèªèããããã«äœ¿çšã§ããŸãïŒãŸãã¯ãéã«ãç°åžžãªè¡åãèªèããŠè¿œå ã®èªèšŒãå¿ èŠã§ããããšã瀺ãããšãã§ããŸãïŒã
- FIDOïŒFast Identity OnlineïŒ â FIDOèªèšŒã¯ãFIDOã¢ã©ã€ã¢ã³ã¹ããæäŸãããç¡æã§ãªãŒãã³ãªæšæºã«åºã¥ããŠããŸããããã«ããããã¹ã¯ãŒãã§ã®ãã°ã€ã³ããå®å šã§è¿ éãªãã°ã€ã³äœéšã«çœ®ãæããããšãã§ããŸãã
- ãã¹ã¯ãŒãã¬ã¹èªèšŒâ ãã¹ã¯ãŒããäž»ãªèªèšŒæ段ãšããŠäœ¿çšããä»ã®éãã¹ã¯ãŒãæ段ã§è£å®ããã®ã§ã¯ãªãããã¹ã¯ãŒãã¬ã¹èªèšŒã¯ãã¹ã¯ãŒããèªèšŒæ段ãšããŠæé€ããŸãã
å€èŠçŽ èªèšŒã¯ããŠãŒã¶ãèªåãèšã£ãŠããéãã®äººç©ã§ããããšã確å®ã«èšŒæããæ¹æ³ã暡玢ãç¶ããäžã§ãå€åãšæ¹åãç¶ããããšã¯ééããããŸããã
ãã©ã€ã¢ã« ID Plusã¯ã©ãŠãå€èŠçŽ èªèšŒïŒMFAïŒãœãªã¥ãŒã·ã§ã³- åžå Žã§æãå®å šãªè£œåã®1ã€ã§ãããäžçã§æãå°å ¥ãããŠããMFAã§ãããã®çç±ãç¥ãããæ¹ã¯ãç¡æã®45æ¥éãã©ã€ã¢ã«ã«ãµã€ã³ã¢ããããŠãã ããã