æå·
æå·çè«, åã³æå·æè¡(Cryptography)ã«ã€ããŠã®ãŸãšã.
ðæå·çè«
ðæ å ±çè«ãåºç€ã«ããŠãã. æå·ã®çåŠ.
ðæå·æè¡
ðæå·çè«ã®çŸå®ã®æŽ»çš, æå·ã®å·¥åŠ.
å ±ééµæå·
æå·åãšåŸ©å·ã«åäžã® (å ±éã®) éµãçšããæå·æ¹åŒ.
AES
ã¢ã¡ãªã«åœé²çã®ã®æå·æ¹åŒ.
DES (ãããã¯æå·)
RC4 (ã¹ããªãŒã æå·)
ã¯ã³ã¿ã€ã ããã
å ¬ééµæå·
æå·åãšåŸ©å·ã«å¥åã®éµ (æé ) ã䜿ãæå·åã®çºã®éµãå ¬éã§ããããã«ããæå·æ¹åŒ.
- æå·éµã§ lock ãããã®ã¯å ¬ééµã§ãã unlock ã§ããªã
- å ¬ééµã§ lock ãããã®ã¯ç§å¯éµã§ãã unlock ã§ããªã
ãã¡ãªãã
- åºæ¬çã«äžæ¹éè¡ã®äœ¿ãæ¹ããã§ããªã.
éä¿¡åŽã«å¯ŸããŠä»åºŠã¯åä¿¡åŽããæå·åããããŒã¿ãéä¿¡ããããšããå Žå, éä¿¡åŽã§ç§å¯éµãšå ¬ééµãäœæã, å ¬ééµãå ¬éããŠããå¿ èŠããããŸã.
- åŠçãè€éã«ãªãããåŠçé床ãé ããªãåŸåããã
ããžã¿ã«çœ²å
ç§å¯éµã§ lock ããŠ, å ¬ééµã§ unlock ãã.
ðRSAæå·
æ¡æ°ã倧ããåææ°ã®çŽ å æ°å解åé¡ãå°é£ã§ããããšãå®å šæ§ã®æ ¹æ ãšããå ¬ééµæå·ã®äžã€.
倧åŠã§ 2 åãåãè¬çŸ©ãããããã©, ãã£ããå¿ãããšãããã®.
ðæ¥åæ²ç·æå·
æ¥åæ²ç·æå· (ECC). ðãããã¯ãã§ãŒã³ã®åºç€æè¡ããã.
ããã倧åŠã§ãã£ã. ã¬ããŒããããã®èŠããŠã. ãã£ããå¿ãã.
ElGamal
æå·åéä¿¡
ðssh
SSL
SSH ãš SSL ã®éã
SSH 㯠AP å±€ã§èªèšŒã»æå·åãè¡ããŸã. SSL/TLS ã¯, AP å±€ã®äžã®å±€ã§ã®èªèšŒã»æå·åãè¡ããã®ã§ã.
- SSH
- OSI : Application Layer (7 å±€) ã«äœçœ®.
- ã¯ã©ã€ã¢ã³ããšãµãŒãéã®å šãŠã®ãã©ãã£ãã¯ãå®å šã«æå·å.
- ã³ãã³ãã©ã€ã³ãªã© CUI ã¢ã¯ã»ã¹ã管çã³ã³ãœãŒã«ã¢ã¯ã»ã¹ã®å Žåã«å©çšããã.
- Version2 ã§ã¯, 第äžè ã亀æããŒã¿ãåœé ã«å¯Ÿãä¿è·æ©èœããã.
- SSL / TLS
- OSI : Transport Layer (4 å±€) ã®äžäœã«äœçœ®.
- HTTP/Web ãã©ãã£ãã¯ã代衚ãšã, SMTP,POP,IMAP ãªã©ã®ãã©ãã£ãã¯ãã»ãã¥ãªãã£ä¿è·ããå Žåã«å©çš.
- æå·å,èªèšŒ,æ¹ç«æ€åºã®æ©èœãæäŸ.
-
links
HTTPS
èªèšŒ
PKI
å ¬ééµåºç€ã¯, å©çšè ã®èº«å ã«ã€ããŠãä¿¡é Œã§ãã第äžè ãã審æ»ãè¡ã, ä¿èšŒãå®çŸããä»çµã¿.
BASIC èªèšŒ
HTTP ã§å®çŸ©ãããèªèšŒæ¹åŒã®äžã€.
- Basic èªèšŒã§ã¯, ãŠãŒã¶åãšãã¹ã¯ãŒãã®çµã¿ãã³ãã³ â:â ã§ã€ãªã
- Base64 ã§ãšã³ã³ãŒãããŠéä¿¡ãã.
- çèŽãæ¹ç«ãç°¡å
- ã»ãŒå šãŠã® Web ãµãŒãããã³ãã©ãŠã¶ã§å¯Ÿå¿ããŠãã
åèãªã³ã¯.
Appatch ã§ã®èšå®
- ãŠã§ããµãŒãã®èšå®ãèšè¿°ããã.htaccess ããã¡ã€ã«
- åºæ¬èªèšŒçšã® ID ãšãã¹ã¯ãŒããèšè¿°ããã.htpasswd ããã¡ã€ã«
LDAP èªèšŒ
LDAP ã¯, ãã£ã¬ã¯ããªã»ãµãŒãã¹ã«æ¥ç¶ããããã«äœ¿çšããããããã³ã«
ã€ã³ã¿ãŒããããã€ã³ãã©ããããªã©ã® TCP/IP ãããã¯ãŒã¯ã§, ãã£ã¬ã¯ããªããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããããã®ãããã³ã«.
ãã£ã¬ã¯ããªãµãŒãã¹
ãã£ã¬ã¯ããªãµãŒãã¹ãšã¯, ãããã¯ãŒã¯ãå©çšãããŠãŒã¶ã®ã¡ãŒã«ã¢ãã¬ã¹ãç°å¢ã«é¢ããæ å ±ã管çãããµãŒãã¹ã®ããšã§, ãŠãŒã¶åãããããã®æ å ±ãæ€çŽ¢ããããšãã§ãã.
- èªã¿åããé«é
- åæ£åã®æ å ±æ ŒçŽã¢ãã«
- é«åºŠãªæ€çŽ¢æ©èœãæã€
ã¡ãŒã«ã¢ãã¬ã¹ç®¡çãšãã.
NTLM èªèšŒ
Windows NT 4.0 以åã® Windows NT ã·ãªãŒãºã® OS ã§æšæºçã«äœ¿ãããŠãã, ãããã¯ãŒã¯ãã°ãªã³ã®ããã®ãŠãŒã¶èªèšŒæ¹åŒ. NT 4.0 ã®åŸç¶ã«ããã Windows 2000 ããã¯ããã©ã«ãã®èªèšŒæ¹åŒã« Kerberos èªèšŒãæ¡çšãããã, æ§ç°å¢ãšã®äºææ§ãä¿ã€ãã NTLM èªèšŒãå©çšå¯èœãšãªã£ãŠãã.
- NTLM èªèšŒãšã¯ ã Windows NT LAN Manager authentication ã
- Windows NTLM èªèšŒãšãã³ã»ã€ã³ã»ã¶ã»ããã«æ»æ
ãã£ã¬ã³ãž/ ã¬ã¹ãã³ã¹æ¹åŒ
- ã¯ã©ã€ã¢ã³ãããµãŒãã«å¯Ÿã, ãŠãŒã¶èªèšŒã®èŠæ±ãçºè¡ãã
- ãµãŒãã¯èªèšŒèŠæ±ãåã, ã©ã³ãã ãªãã€ãåããã£ã¬ã³ãžããéãè¿ã
- ã¯ã©ã€ã¢ã³ãã¯, ãã£ã¬ã³ãžãšãã¹ã¯ãŒãæ å ±ã«åºã¥ããŠãã¬ã¹ãã³ã¹ããçæã, ãµãŒãã«éã
- ãµãŒãåŽã§ãå ã»ã©éã£ããã£ã¬ã³ãžãšãã¹ã¯ãŒãæ å ±ãåºã«ã¬ã¹ãã³ã¹ãçæãã
- ã¯ã©ã€ã¢ã³ãããéãããã¬ã¹ãã³ã¹ãš, èªãçæããã¬ã¹ãã³ã¹ãæ¯èŒããããšã«ãã, ã¯ã©ã€ã¢ã³ãåŽãšãµãŒãåŽäž¡æ¹ã®ãã¹ã¯ãŒãæ å ±ãåäžã§ããããšã確èªãã
- ãã¹ã¯ãŒãæ å ±ã®åäžæ§ã確èªã§ããå Žå, ã¯ã©ã€ã¢ã³ãã«ãã°ãªã³èš±å¯ãäžãã
- ã¯ã©ã€ã¢ã³ãåŽã§ã¯ãã°ãªã³èš±å¯ãåã, ãã°ãªã³åŠçãå®è¡ãã
ã±ã«ããã¹èªèšŒ
å ±ééµæå·ã«ãã£ãŠæå·å.
ãã®ããŒãžã«ã¢ãã¡ãŒã·ã§ã³ã€ãã®éµã®ãããšãããã.
ðOAuth
API å©çšåŽããŠãŒã¶èªèšŒã API æäŸãµãŒãã¹åŽã«ãã£ãŠãããããã®ä»æ§. çŸåšã¯OAuth2.0.
OAuth ã¯, 以äžã®ç¹åŸŽãæã€ãèªå¯æ å ±ã®å§è²ãã®ããã®ä»æ§ã§ã.
- ãããããä¿¡é Œé¢ä¿ãæ§ç¯ãããµãŒãã¹éã§
- ãŠãŒã¶ã®åæã®ããšã«
- ã»ãã¥ã¢ã«ãŠãŒã¶ã®æš©éãåãæž¡ããã
ç»å Žäººç©
- 1 ã€ç®ã¯ OAuth Service Provider ãšåŒã°ãã, ãŠãŒã¶ã®èªå¯æ å ±ã第äžè ã«æž¡ããµãŒãã¹.
- 2 ã€ç®ã¯ OAuth Consumer ãšåŒã°ãã, Service Provider ããèªå¯æ å ±ãåãåã, ãŠãŒã¶ã«ä»£ã£ãŠãããããªæ å ±ã«ã¢ã¯ã»ã¹ãããå€æŽ/ è¿œå ãè¡ã£ãããããµãŒãã¹.
- 3 ã€ãã, User ã§ã. User 㯠Service Provider ã Consumer ã«èªå¯æ å ±ãæž¡ãããšãèš±å¯ããã, ãã§ã«åãæž¡ããèªå¯æ å ±ãç¡å¹ã«ãããšãã£ãããšãã§ããŸã