決ããŠä¿¡çšãããåžžã«æ€èšŒãã â å¢çããŒã¹ã®ã»ãã¥ãªãã£ãããã¹ãŠã®ãŠãŒã¶ãŒãšããã€ã¹ã«å¯ŸããIDäžå¿ã®ãç¶ç¶çã«æ€èšŒãããã¢ã¯ã»ã¹ã«çœ®ãæããŸãã

åŸæ¥ã®å¢çããŒã¹ã®ã»ãã¥ãªãã£ã¢ãã«ã¯ãäŒæ¥ãããã¯ãŒã¯å ã®ãã¹ãŠãä¿¡é ŒãããŠãããšä»®å®ããŠããŸããããã®ä»®å®ã¯ãªã¢ãŒãã¯ãŒã¯ãã¯ã©ãŠããã¡ãŒã¹ãã¢ãŒããã¯ãã£ããµãã©ã€ãã§ãŒã³ã®äŸµå®³ã«ãã£ãŠæã¡ç ŽãããŸãããäŒæ¥ãæ¿åºæ©é¢ã¯ãåäžã®äŸµå®³ãããèªèšŒæ å ±ãæ»æè ã«ãããã¯ãŒã¯ã»ã°ã¡ã³ãå šäœãžã®ã¢ã¯ã»ã¹ãèš±å¯ããæ€åºããããŸã§ã«å¹³å21æ¥éã®æ»çæéãããã©ãã©ã«ã ãŒãã¡ã³ãæ»æã«æ©ãŸãããŠããŸããVPNããŒã¹ã®ãªã¢ãŒãã¢ã¯ã»ã¹ã¯ãããã©ãŒãã³ã¹ã®ããã«ããã¯ãçã¿åºãããã¹ãŠã®æ¥ç¶ããããšã³ããã€ã³ãã«ãããã¯ãŒã¯å šäœãé²åºãããŸããã¬ã¬ã·ãŒãªãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã¯ãã©ã®ããŒã ãå®å šã«çè§£ããŠããªãæ°åãã®ç«¶åããããªã·ãŒã«èç©ãããæ»æè ãæ¥åžžçã«æªçšããç²ç¹ãçã¿åºããŠããŸãã
Executive Order 14028ãNIST SP 800-207ãªã©ã®æ¿åºã®çŸ©åã¯ãçŸåšãŒããã©ã¹ãã®å°å ¥ã矩åä»ããŠãããããã¯ã»ãã¥ãªãã£äžã®å¿ èŠæ§ã ãã§ãªããã³ã³ãã©ã€ã¢ã³ã¹äžã®å¿ é äºé ãšãªã£ãŠããŸãã
次ã®ãããžã§ã¯ãã®ããã®å®è£ ãã«ãŒããªã³ãããã£ãšèŠã€ãã

æ£è ããŒã¿ãå®å¿ããŠä¿è· â å®å šå¯Ÿçãèªååãããªã¹ã¯ãç£èŠããç£æ»äººã®èŠæ±ãæºããããšã³ãããŒãšã³ãã® HIPAA ã³ã³ãã©ã€ã¢ã³ã¹ã

MicrocosmWorksã¯ããªãœãŒã¹ã¢ã¯ã»ã¹ãèš±å¯ããåã«ãåå人ããã€ã¹ã®OSãããã¬ãã«ãæå·åç¶æ³ãã¢ã³ããŠã€ã«ã¹ãœãããŠã§ã¢ã®æç¡ãããã³ãžã§ã€ã«ãã¬ã€ã¯æ€åºãè©äŸ¡ããããã€ã¹ãã¹ãã£è©äŸ¡ãå®è£ ããŠããŸããåæèªèšŒåŸããã·ã¹ãã ã¯ããã€ã¹ã®ä¿¡é Œã·ã°ãã«ãç¶ç¶çã«åè©äŸ¡ããæ©å¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã管çäžã«ããããã€ã¹ãŸãã¯ã³ã³ãã©ã€ã¢ã³ã¹ã«æºæ ããããã€ã¹ã®ã¿ã«å¶éã§ããé©å¿åã¢ã¯ã»ã¹ããªã·ãŒãé©çšããŸãã
MicrocosmWorksã¯éåžžããŒããã©ã¹ãç§»è¡ã3ã6ãæã®ãã§ãŒãºã§èšç»ãããŸãã¢ã€ãã³ãã£ãã£äžå¿ã®å¶åŸ¡ãšéèŠãªè³ç£ã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ããéå§ãããã®åŸãããã¯ãŒã¯å šäœãã«ããŒããããã«æ¡åŒµããŸããåŸæ¥å¡æ°500ã2,000人ã®äžèŠæš¡äŒæ¥ã®å Žåãå šäœçãªå€é©ã«ã¯éåžž12ã18ãæããããéçºããã³ã³ã³ãµã«ãã£ã³ã°æéã¯1æéããã30ã50ãã«ãšãªããŸãã
MicrocosmWorksã®ãã«ãŒããªã³ãã¯ãã¯ãŒã¯ããŒãã¬ãã«ã§ç²åºŠã®é«ããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãå®è£ ããŠããŸããããã§ã¯ãããããã¢ããªã±ãŒã·ã§ã³ãããŒã¿ããŒã¹ããµãŒãã¹ããçžäºTLSèªèšŒã䌎ãããªã·ãŒé©çšåã®æå·åããããã³ãã«ãä»ããŠéä¿¡ããŸããæ»æè ã1ã€ã®ã¯ãŒã¯ããŒãã䟵害ãããšããŠãããããªããããã¯ãŒã¯ã»ã°ã¡ã³ãéã«ãæé»ã®ä¿¡é Œé¢ä¿ãäžåãªãããã飿¥ããã·ã¹ãã ãçºèŠãããã¢ã¯ã»ã¹ãããããããšã¯ã§ããŸããã
ã¯ããMicrocosmWorks ã¯ãã¬ã¬ã·ãŒã¢ããªã±ãŒã·ã§ã³ã®åé¢ã«ã¢ã€ãã³ãã£ãã£èªèåãããã·ãšã¢ããªã±ãŒã·ã§ã³ã³ãã¯ã¿ãé åããææ°ã® OIDC/SAML èªèšŒããã¬ã¬ã·ãŒã·ã¹ãã ããµããŒããã圢åŒïŒNTLMãKerberosãããããŒããŒã¹èªèšŒãªã©ïŒã«å€æããŸãããã®ã¢ãããŒãã«ãããæ¢åã®ã¢ããªã±ãŒã·ã§ã³ã«ã³ãŒã倿Žãäžåå ããããšãªããã¬ã¬ã·ãŒã·ã¹ãã ããŒããã©ã¹ãããªã·ãŒã®é©çšäžã«çœ®ãããšãå¯èœã«ãªããŸãã
MicrocosmWorksã¯ãããã¯ã°ã©ãŠã³ãã§éãã«è¡åãã€ãªã¡ããªã¯ã¹ãããã€ã¹ã·ã°ãã«ããããã¯ãŒã¯ã³ã³ããã¹ããããã³ã»ãã·ã§ã³ç°åžžãè©äŸ¡ãããªã¹ã¯ããŒã¹ã®ç¶ç¶çèªèšŒãå®è£ ããŠããŸããã¹ãããã¢ããèªèšŒã¯ããªã¹ã¯ã¹ã³ã¢ãèšå®å¯èœãªéŸå€ãè¶ ããå Žåã«ã®ã¿ããªã¬ãŒããããããæ£åœãªãŠãŒã¶ãŒã¯ã·ãŒã ã¬ã¹ãªã¢ã¯ã»ã¹ãäœéšã§ããçãããã»ãã·ã§ã³ã¯èªåçã«ãã£ã¬ã³ãžããããããŸãã¯çµäºãããŸãã
å°éããŒã ãã客æ§ã®ããžãã¹ã®ããã«ãã®ãœãªã¥ãŒã·ã§ã³ãæ§ç¯ããæ¹æ³ã«ã€ããŠãåãåãããã ããã
ãåãåããMicrocosmWorksã¯ãå æ¬çãªãŒããã©ã¹ãã¢ãŒããã¯ãã£ãå®è£ ã§ããŸããããã¯ãããã€ã¹ã®æ å¢ããŠãŒã¶ãŒè¡åããªãœãŒã¹ã®æ©å¯æ§ããªã¢ã«ã¿ã€ã ã®ãªã¹ã¯ã·ã°ãã«ã«å¯ŸããŠç¶ç¶çã«æ€èšŒããããŸã§ããã¹ãŠã®ã¢ã¯ã»ã¹èŠæ±ãä¿¡é Œããªããã®ãšããŠæ±ãããã¹ãŠã®ã¬ã€ã€ãŒã§IDäžå¿ã®ã»ãã¥ãªãã£ã匷å¶ããŸããç§ãã¡ã®ã¢ãããŒãã¯ããã©ãããªãããã¯ãŒã¯ä¿¡é Œããã现ããªãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã«çœ®ãæããåäžã®ãšã³ããã€ã³ãã䟵害ãããå Žåã§ããã©ãã©ã«ã ãŒãã¡ã³ãããããã¯ãããããã«ããŸãããã¹ãŠã®éä¿¡ãã£ãã«ã¯ãšã³ãããŒãšã³ãã§æå·åããããªã¢ã«ã¿ã€ã ã§ã³ã³ããã¹ããè©äŸ¡ããäžå€®ã®Policy Decision Pointãä»ããŠãæå°ç¹æš©ã¢ã¯ã»ã¹ããªã·ãŒãåçã«åŒ·å¶ãããŸããè¡ååæã¯ã»ãã·ã§ã³ã¢ã¯ãã£ããã£ãç¶ç¶çã«ç£èŠããç°åžžãæ€åºãããå Žåãèªåçã«èªèšŒã匷åããããã¢ã¯ã»ã¹ãåãæ¶ãããããŠãèªå·±é²è¡åã®ãããã¯ãŒã¯ãã¡ããªãã¯ãäœæããŸãã
ãã®ã¢ãŒããã¯ãã£ã¯ãäžå åãããPolicy Decision Point (PDP)ãšããã¹ãŠã®ãããã¯ãŒã¯å¢çãã¢ããªã±ãŒã·ã§ã³ã²ãŒããŠã§ã€ãã¯ã©ãŠãã¢ã¯ã»ã¹ãã€ã³ãã«å±éããã忣åã®Policy Enforcement
Points (PEP)ã§æ§æãããPolicy Enforcement Meshãäžå¿ã«æ§ç¯ãããŠããŸããIDãã¡ããªãã¯ããã¹ãŠã®ã¢ã¯ã»ã¹æ±ºå®ã®åºç€ãšãªããActive DirectoryãOktaãAzure ADã
PKIèšŒææžãªã©ãè€æ°ã®ãœãŒã¹ããã®IDãçµ±åãããªã¢ã«ã¿ã€ã ã§èšç®ãããçµ±äžããããã©ã¹ãã¹ã³ã¢ã«ããŸããããŒã¿ãã¬ãŒã³ã¯ããã¹ãŠã®ãã©ãã£ãã¯ãã€ã³ã©ã€ã³æ€æ»ä»ãã®æå·åããããã³ãã«ãä»ããŠã«ãŒãã£ã³ã°ããäžæ¹ãå¥ã®ã³ã³ãããŒã«ãã¬ãŒã³ã¯ããã€ããªããã¯ã©ãŠãããã³ãªã³ãã¬ãã¹ç°å¢å šäœã§ããªã·ãŒã®é åžããã¬ã¡ããªåéãã³ã³ãã©ã€ã¢ã³ã¹ã¬ããŒãã管çããŸãã
ã«ããããã¹ãŠã®ã¢ã¯ã»ã¹æ±ºå®ã管çããåçãªãã©ã¹ãã¹ã³ã¢ãçæ
ãŸãŒã³ã«åå²ããeast-westãã©ãã£ãã¯ã®æ€æ»ãšããªã·ãŒé©çšãè¡ã
決å®ããšã«10ããªç§æªæºã§ãå®å šãªç£æ»ãã°ä»ã
èªåèšŒææžããŒããŒã·ã§ã³ãšHSM察å¿ã®éµç®¡çãåãã
ã»ãã·ã§ã³åé¢ããŸãã¯ãªã¹ã¯ãããå€ã«åºã¥ããèªååãæ¶ã
| ã¬ã€ã€ãŒ | ãã¯ãããžãŒ |
|---|---|
| ããã¯ãšã³ã | Go, Rust, Python, gRPC, Envoy Proxy |
| AI / ML | TensorFlow, scikit-learn, Apache Flink, ã«ã¹ã¿ã UEBAã¢ãã« |
| ããã³ããšã³ã | React, TypeScript, Grafana, ã«ã¹ã¿ã 管çããŒã¿ã« |
| ããŒã¿ããŒã¹ | CockroachDB, etcd, Redis, TimescaleDB |
| ã€ã³ãã©ã¹ãã©ã¯ã㣠| Kubernetes, Istio, Terraform, HashiCorp Vault, Consul, AWS/Azure ãã€ããªãã |
| 枬å®é ç® | æ¹å | 詳现 |
|---|---|---|
| ã©ãã©ã«ã ãŒãã¡ã³ããªã¹ã¯ | 97%åæž | ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã«ãã䟵害ãåäžã®ã¯ãŒã¯ããŒããŸãŒã³ã«éå® |
| ã¢ã¯ã»ã¹ããªã·ãŒé©çš | 100%ã«ã㌠| ãã¹ãŠã®ãªã¯ãšã¹ãã¯æé»ã®ä¿¡é Œãªãã«ããªã·ãŒãšã³ãžã³ãéé |
| èªèšŒã¬ã€ãã³ã· | 10ããªç§æªæº | 髿§èœãªPDPã¯ãŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ã«ç¡èŠã§ããã»ã©ã®ãªãŒããŒãããã远å |
| ã³ã³ãã©ã€ã¢ã³ã¹äœå¶ | NIST 800-207æºæ | é£éŠæ¿åºã®ãŒããã©ã¹ã矩åãšCISAæç床ã¢ãã«ãæºãã |
| ã€ã³ã·ãã³ãå°ã蟌ãæé | 88%é«éå | èªåã»ã°ã¡ã³ããŒã·ã§ã³ãšã»ãã·ã§ã³åãæ¶ãã«ããè åšãæ°ç§ã§éé¢ |
1. 1ã3é±ç®: IDã€ã³ãã©ã¹ãã©ã¯ãã£è©äŸ¡ããã£ã¬ã¯ããªãã§ãã¬ãŒã·ã§ã³èšå®ããã©ã¹ãã¹ã³ã¢ã¢ãã«èšèš
2. 4ã7é±ç®: PDP/PEPå±éãéèŠã¯ãŒã¯ããŒãåãåæãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³å±éãmTLSæå¹å
3. 8ã11é±ç®: è¡ååæãã£ãªãã¬ãŒã·ã§ã³ãã¢ãããã£ãã¢ã¯ã»ã¹ããªã·ãŒãã¥ãŒãã³ã°ãeast-westæå·åæ¡åŒµ
4. 12ã14é±ç®: ãã«ãããã¯ãŒã¯ã«ããŒç¯å²ãã¬ã¬ã·ãŒVPN廿¢èšç»ãã³ã³ãã©ã€ã¢ã³ã¹ã¬ããŒãæå¹å
5. 15ã18é±ç®: å šç€Ÿå±éããŠãŒã¶ãŒç ä¿®ãç¶ç¶çæé©åãNIST 800-207ç£æ»æºå
ç¶ç¶çãªAIæ¯æŽåã»ãã¥ãªãã£æ€èšŒ â æ»æè ãããæ©ãè匱æ§ãçºèŠã»ä¿®æ£ããæäœæ¥ã®ãªãŒããŒãããããŒãã«ã