çµç¹ããã«ãã¯ã©ãŠãæŠç¥ãæ¡çšããã¬ãžãªãšã³ã¹ãæè»æ§ãã¯ãŒã¯ããŒãã®ããŒã¿ããªãã£ãåäžãããäžã§ãçŽé¢ããæãéèŠãªèª²é¡ã®äžã€ã¯ããã©ãããã©ãŒã éã§å®å šãã€äžè²«æ§ã®ããéµç®¡çã確ä¿ããããšã§ããåã¯ã©ãŠããããã€ããŒã¯ãç¬èªã®ãã€ãã£ãéµç®¡çã·ã¹ãã ãæäŸããŠãããããããç°ãªãAPIãæå·åã¢ãã«ãIAMå¶åŸ¡ãã©ã€ããµã€ã¯ã«ããªã·ãŒãã³ã³ãã©ã€ã¢ã³ã¹å¢çãåããŠããŸãããããã®ã·ã¹ãã ã¯åç¬ã§ãåé¡ãªãæ©èœããŸãããçµ±åã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ã«çµ±åããã®ã¯ã¯ããã«è€éã§ããç¶¿å¯ãªèª¿æŽãè¡ããªããšããã«ãã¯ã©ãŠãå±éã§ã¯ãæå·åã®èšå®ãã¹ãéµã©ã€ããµã€ã¯ã«ã®æçåãã¢ã¯ã»ã¹ããªã·ãŒã®äžäžèŽãç£æ»ã®å¯èŠæ§ã«ãããã®ã£ãããšãã£ããªã¹ã¯ãçããŸãããããã®ãªã¹ã¯ã¯ããã«ãã¯ã©ãŠãã«é¢ããè°è«ã§ææãããŠããã¢ãŒããã¯ãã£ã®äžäžèŽãšé¡äŒŒããŠããŸãã äŒæ¥ã®è¿ä»£åæŠç¥.
ã¢ããªã±ãŒã·ã§ã³ãè€æ°ã®ç°å¢ã«åæã«ãŸãããã«ã€ããŠãè€éãã¯å¢å€§ããŸãããã€ããªãããã€ãã©ã€ã³ãã¯ã©ãŠãéããŒã¿ãããŒãã³ã³ããåããããã€ã¯ããµãŒãã¹ã忣ã€ãã³ãããªãã³ã¯ãŒã¯ããŒãã§ã¯ãæå·éµãžã®ãªã¢ã«ã¿ã€ã ã¢ã¯ã»ã¹ãé »ç¹ã«å¿ èŠã«ãªããŸããåãããã€ããŒãç°ãªãIDãèªèšŒãããŒããŒã·ã§ã³ã¡ã«ããºã ãé©çšããå Žåãéçšäžã®æ©æŠãå¢å€§ããã»ãã¥ãªãã£ãªã¹ã¯ãå¢å€§ããŸããããã«ãã¯ã©ãŠããã€ãã£ããµãŒãã¹ã¯ãç·å¯ã«é£æºãããããã€ããŒçµ±åã«äŸåããããšãå€ããçµç¹ã¯ãã€ãã£ãKMSæ©èœã«é Œãã¹ããããããšãäžå€®éæš©çãªãªãŒã±ã¹ãã¬ãŒã·ã§ã³ã®èåŸã«æœè±¡åãã¹ãããšããåé¡ã«çŽé¢ããããšã«ãªããŸãããããã®èª²é¡ã¯ãããŒã ãåæããéã«çºèŠãããåé¡ãšéãªããŸãã å€§èŠæš¡ã³ãŒãããŒã¹ã«ãããã»ãã¥ãªãã£è匱æ§.
KMSæŠç¥ãçµ±åãã
çµ±åãããç£æ»å¯Ÿå¿ã®ãã«ãã¯ã©ãŠãæå·åã¢ãŒããã¯ãã£ãæ§ç¯ SMART TS XLã®æ·±ãäŸåé¢ä¿ãããã³ã°ã
ä»ããæ¢çŽ¢ããéçšäžã®æžå¿µã«å ãããã«ãã¯ã©ãŠãKMSçµ±åã¯ãã¬ããã³ã¹ããã³ããŒäžç«æ§ããããŠé·æçãªæå·æè¡ã®ä¿ææ§ã«é¢ããæŠç¥çãªè²¬ä»»ããããããŸããPCI DSSãHIPAAãFedRAMPãéèèŠå¶ãªã©ã®ã³ã³ãã©ã€ã¢ã³ã¹ãã¬ãŒã ã¯ãŒã¯ã§ã¯ãããããç°å¢ã§äžè²«ãããã°èšé²ãããŒããŒã·ã§ã³ã倱å¹ãã¢ã¯ã»ã¹æ€èšŒãæ±ããããŸããåãã©ãããã©ãŒã ãç°ãªãã€ãã³ãã»ãã³ãã£ã¯ã¹ãããªã·ãŒæ§æãç£æ»ã¡ã«ããºã ãå ¬éããŠããå Žåããã®çµ±äžæ§ãå®çŸããããšã¯å°é£ã«ãªããŸãããã®åé¡ã¯ãäŒæ¥ãKMSã®ç¶æç®¡çã«ãããŠçŽé¢ããå°é£ã«äŒŒãŠããŸãã ã¯ãã¹ãã©ãããã©ãŒã ãªã¹ã¯ç®¡ç ã·ã¹ãã ã®åäœãç°å¢ã«ãã£ãŠç°ãªãå Žåã
ãããããã¬ãã·ã£ãŒãããçµç¹ã¯ãã«ãã¯ã©ãŠãKMSã¢ãŒããã¯ãã£ã§å©çšå¯èœãªã³ã¢çµ±åãã¿ãŒã³ãçè§£ãããããã®ããã©ãŒãã³ã¹ãããã¡ã€ã«ãã»ãã¥ãªãã£äœå¶ãã¬ããã³ã¹ã®ãªãŒããŒãããã®éããçè§£ããããšãäžå¯æ¬ ã«ãªããŸãããããã®ãã¿ãŒã³ãæ§é åãããã¢ãããŒãã§æ€èšŒããããšã§ãããŒã ã¯éçšäžã®ãµã€ãåãæãããšãªãã匷åãªæå·åä¿èšŒãç¶æããã¢ãŒããã¯ãã£ãèšèšã§ããŸãããã®èšäºã®åŸåã§ã¯ããã®æ¹æ³ã«ã€ããŠãèå¯ããŸãã SMART TS XL çµ±åã®äŸåé¢ä¿ããããã³ã°ããã·ã¹ãã éã®åäœãæ€èšŒããã¢ãŒããã¯ãã£ã®ç²ç¹ãæããã«ããããšã§ããã«ãã¯ã©ãŠãKMSã®ä¿¡é Œæ§ã匷åããŸãã é ããã¬ã€ãã³ã·é¢é£ã®ã³ãŒããã¹ é²åããã·ã¹ãã å šäœã«ããã£ãŠã
ãã«ãã¯ã©ãŠã ã»ãã¥ãªã㣠ã¢ãŒããã¯ãã£ã«ããã KMS ã®åœ¹å²ãçè§£ãã
éµç®¡çã·ã¹ãã ã¯ã忣ã¯ãŒã¯ããŒãããµãŒãã¹ãããŒã¿ãããŒå šäœã«ããã£ãŠäžè²«ããæå·åå¢çã匷å¶ãããããçŸä»£ã®äŒæ¥ã»ãã¥ãªãã£ã®åºç€èŠçŽ ãšãªã£ãŠããŸãããã«ãã¯ã©ãŠãç°å¢ã§ã¯ããã®è²¬ä»»ã¯é£èºçã«æ¡å€§ããŸããåã¯ã©ãŠããããã€ããŒã¯ãç¬èªã®APIãµãŒãã§ã¹ãIAMããžãã¯ãéµã¹ãã¬ãŒãžã¢ãã«ãããŒããŒã·ã§ã³ããªã·ãŒãåããKMSãæäŸãããããçµç¹ããªãŒãžã§ã³ãã¯ã©ãŠãããªã³ãã¬ãã¹ã·ã¹ãã å šäœã§æå·åæŠç¥ãçµ±äžããããšãããšãããã«æçåãçããŸããçµ±äžãããèšèšããªããã°ãæå·åéµã®äžäžèŽãããŒããŒã·ã§ã³ã®äžè²«æ§ã®æ¬ åŠããããŠã¬ããã³ã¹å¶åŸ¡ã®ã°ããŒãã«ãªé©çšãå°é£ã«ãªããŸããã ãããããKMSã®èšèšã¯åãªãæ©èœäžã®èæ ®äºé ã§ã¯ãªãããã«ãã¯ã©ãŠããšã³ã·ã¹ãã ã®ã»ãã¥ãªãã£äœå¶å šäœã圢äœãã¢ãŒããã¯ãã£äžã®æ±ºå®ãªã®ã§ãããããã®èª²é¡ã®å€ãã¯ã ãšã³ã¿ãŒãã©ã€ãºçµ±ååºç€ ã·ã¹ãã ã®äžæŽåã«ããäžæµã«è匱æ§ãçããŸãã
ãã«ãã¯ã©ãŠãKMSã®å©çšã¯ãéçšäžã®çŠç¹ãåçŽãªéµä¿ç®¡ãããã¡ã€ã³éã®ä¿¡é ŒãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãžãšç§»è¡ãããŸããã¯ã©ãŠãéãç§»åããã¯ãŒã¯ããŒãã¯ããããã€ããå®ããèªèšŒãç£æ»ãããªã·ãŒå¢çãé©çšããªããããæå·éµãžã®éåããããšã®ãªãã¢ã¯ã»ã¹ãç¶æããå¿ èŠããããŸãããã€ããªããã¢ããªã±ãŒã·ã§ã³ãã³ã³ãããã©ãããã©ãŒã ããµãŒããŒã¬ã¹é¢æ°ãã¡ãã»ãŒãžãããŒã«ãŒãã€ãã³ãããªãã³ãã€ãã©ã€ã³ã«ãŸãããå Žåãããã¯ããã«è€éã«ãªããŸããåç°å¢ã¯éµã®ãªã¯ãšã¹ãããã£ãã·ã¥ã埩å·åã«ç¬èªã®æ¹æ³ãå°å ¥ããŠãããäžæŽåããããšè匱æ§ãæ©èœåæ¢ãçããå¯èœæ§ããããŸãããããã£ãŠããã«ãã¯ã©ãŠãKMSçµ±åã«ã¯ãéµã¢ã¯ã»ã¹åäœãIDãããã³ã°ãã©ã€ããµã€ã¯ã«ç®¡çããã¹ãŠã®ç°å¢ã§æŽåããããæè»ãã€æ éã«ç®¡çãããèšèšãå¿ èŠã§ããããŒã ãéµãçºèŠããæ¹æ³ãšåæ§ã«ã ãã©ãããã©ãŒã éã®ãªã¹ã¯ãã¿ãŒã³KMS ã¢ãŒããã¯ãã£ã§ã¯ãä¿¡é Œå¢çãå€åããå Žæãšããã®å€åãã»ãã¥ãªãã£ä¿èšŒã«ã©ã®ããã«åœ±é¿ããããæããã«ããå¿ èŠããããŸãã
ãã«ãã¯ã©ãŠãæå·åèŠä»¶ãKMSèšèšã«äžãã圱é¿
ãã«ãã¯ã©ãŠãç°å¢ã§ã¯ãåäžã¯ã©ãŠããåŸæ¥ã®ãªã³ãã¬ãã¹ã¢ãŒããã¯ãã£ã«æ¯ã¹ãŠãã¯ããã«åçã忣çããã€çžäºäŸåæ§ã®é«ãæå·åèŠä»¶ãæ±ããããŸããåã¯ã©ãŠããããã€ããŒã¯ãç¬èªã®APIã³ã³ãã©ã¯ããIDã¢ãã«ããªãŒãžã§ã³å¢çããšã³ãããŒãæå·åãã¿ãŒã³ãé©çšããŸããäŸãã°ãAWS KMSã¯IAMããŒã¹ã®èªèšŒãå¿ èŠãšããAzure Key Vaultã¯AADã«ãã€ã³ããããããªã³ã·ãã«ã䜿çšããGoogle Cloud KMSã¯ç¬èªã®IAMã¹ã³ãŒãã®ã¢ã¯ã»ã¹ã»ãã³ãã£ã¯ã¹ãé©çšããŸããã¯ãŒã¯ããŒãããããã®ç°å¢ã«ãŸãããå ŽåãäŒæ¥ã¯ãããã®ã«ãŒã«ã«éåããããšãªããéµãžã®ã¢ã¯ã»ã¹ãç£æ»ããããŠå®å šãªç®¡çã確å®ã«è¡ãå¿ èŠããããŸãããã®ããã«ã¯ããã©ãããã©ãŒã éã§ç°ãªãæå·åããªããã£ããéµã¹ãã¬ãŒãžããã¯ãšã³ãããããŠã©ã€ããµã€ã¯ã«å¶çŽãèæ ®ããèšèšãå¿ èŠã§ãã
ã¢ããªã±ãŒã·ã§ã³ãã¯ã©ãŠãéã§ããŒã¿ãç§»åãããããã€ããªããã¯ãŒã¯ãããŒãå®è¡ããããããšããããã®èŠä»¶ã¯ããã«è€éã«ãªããŸããããç°å¢ã§æå·åãããããŒã¿ãå¥ã®ç°å¢ã§åŸ©å·ããå¿ èŠãããå ŽåããããŸãããããã¯åæ¹ãäºææ§ã®ããæå·åã¢ãã«ããµããŒãããŠããå Žåã«ã®ã¿çºçããŸããããã¯ããšã³ãããŒãæå·åãåæå·åãã€ãã©ã€ã³ããã§ãã¬ãŒã·ã§ã³IDã®äŒæã«é¢ããã¢ãŒããã¯ãã£äžã®æ±ºå®ããããããŸãããŸããããŒã ã¯ãéµãç°ãªãééã§ããŒããŒã·ã§ã³ããããç°å¢éã§äžè²«æ§ã®ãªãåœåãã¿ã°ä»ãã®ãã¿ãŒã³ã«åŸã£ããããéçšäžã®ããªããã«ã泚æããå¿ èŠããããŸãããããã®äžäžèŽã¯ãå€ãã®å Žåã ã¯ãã¹ãã©ãããã©ãŒã ãªã¹ã¯ç®¡çç°å¢ã®æçåãã²ããã«è匱æ§ãçã¿åºããŠããç¶æ³ã§ããã¯ã©ãŠãå šäœã«ãããäºæž¬å¯èœã§çµ±åçãªæå·åãèšèšããã«ã¯ãã¯ãŒã¯ããŒããåçã«å€åããå Žåã§ããéµãã©ã®ããã«ä¿åãã¢ã¯ã»ã¹ãæ€èšŒããããã詳现ã«å¯èŠåããå¿ èŠããããŸãã
KMSã®ãŠãŒã¹ã±ãŒã¹ãåçŽãªæå·åã«ãšã©ãŸãããã·ãŒã¯ã¬ããã®ååŸãããŒã¯ã³åãæ§æã®ã·ãŒãªã³ã°ãã©ã³ã¿ã€ã èªèšŒãžãšæ¡å€§ãããšãè€éãã¯åå¢ããŸããåã¯ãŒã¯ãããŒã¯ãã°ããŒãã«ã¬ããã³ã¹ã¢ãã«ãžã®åå ãç¶æããªããããããã€ããŒåºæã®ãã¹ããã©ã¯ãã£ã¹ã«æºæ ããå¿ èŠããããŸãããã®ãããææ°ã®KMSã¢ãŒããã¯ãã£ã¯ãã¯ã©ãŠãéã®æå·åã ãã§ãªããå°å ¥ããããžã«é¢ä¿ãªãæå·ã®æŽåæ§ãç¶æãããå®å šã«åæãããããªã·ãŒããªãã³ã®ãã¬ãŒã ã¯ãŒã¯ããµããŒãããå¿ èŠããããŸããKMSããã¡ãŒã¹ãã¯ã©ã¹ã®ã¢ãŒããã¯ãã£ã³ã³ããŒãã³ãã§ã¯ãªãããã¯ã°ã©ãŠã³ããµãŒãã¹ãšããŠæ±ãäŒæ¥ã¯ãç£æ»å¯èœæ§ãéµã®å¯èŠæ§ãã³ã³ãã©ã€ã¢ã³ã¹ã®æŽåæ§ã«ãããŠå¿ ç¶çã«åé¡ã«çŽé¢ããŸãããã«ãã¯ã©ãŠãæå·åã®èŠä»¶ãã¢ãŒããã¯ãã£ã®æ©ã段éã§æ éã«çµ±åããããšã§ãçµç¹ã¯ç°å¢ãå€åããŠãã»ãã¥ãªãã£ã®äžè²«æ§ã確ä¿ã§ããŸãã
ãã«ãã¯ã©ãŠãã®ä¿¡é Œå¢çã«åŒ·åãªKMSçµ±åå¶åŸ¡ãå¿ èŠãªçç±
ãã«ãã¯ã©ãŠãç°å¢ã§ã¯ãä¿¡é Œå¢çã¯åäžã®ãããã€ããŒã®IAMã¢ãã«ãããã¯ã©ãŠããã€ãã£ããªIDããã§ãã¬ãŒã·ã§ã³ããªã·ãŒããããŠãããã€ããŒéã®èªèšŒäº€æã®ã¡ãã·ã¥ãžãšæ¡å€§ããŸãããããã€ããŒéãç§»è¡ããã¢ããªã±ãŒã·ã§ã³ã¯ãããŒãå®å šã«èŠæ±ããããã®ID蚌æãä¿æããå¿ èŠããããŸãããåã¯ã©ãŠãã¯IDãç°ãªãæ¹æ³ã§æ€èšŒããŸããAWSã§èªèšŒãããã¯ãŒã¯ããŒãã¯ããã§ãã¬ãŒã·ã§ã³ãŸãã¯ä»²ä»ãããä¿¡é Œããªããã°ãAzureãŸãã¯GCPã§èªåçã«èªèšŒããããšã¯ã§ããŸããããã®ãããäŒæ¥ã¯KMSã¢ã¯ã»ã¹ã«ãŒã«ã«æºæ ããæå°æš©éã®é©çšãç¶æããIDããªããžã³ã°ãŸãã¯IDãããŒã«ãŒãªã³ã°ãã¿ãŒã³ãå®è£ ããå¿ èŠããããŸãããã®ãããªæŽåæ§ããªããã°ãããŒã¢ã¯ã»ã¹ã倱æããããçµç¹ãæå³ããã¢ã¯ã»ã¹ç¯å²ãæ¡å€§ãããŒããã©ã¹ãååãæãªãããŸãã
ããããåºç¯ãªä¿¡é Œå¢çã¯ãæå·éµã®çæãä¿åãããŒããŒã·ã§ã³ã«ã圱é¿ãäžããŸããå€ãã®äŒæ¥ã§ã¯ãéµã¯1ã€ã®ã¯ã©ãŠãã§çæãããå¥ã®ã¯ã©ãŠãããåç §ãããŸããç¹ã«ãã¯ã©ãŠãéããŒã¿ãã€ãã©ã€ã³ãå ±æåæãã©ãããã©ãŒã ã§å ±éã®éµãããªã¢ã«ãå¿ èŠãªå Žåã«é¡èã§ãããã®ãããªã¯ãŒã¯ãããŒã§ã¯ãéµã®äŒæãããŒãžã§ã³ç®¡çã倱å¹ã«é¢ãã峿 Œãªç®¡çãæ±ããããŸããããç°å¢ã§éµã®ããŒããŒã·ã§ã³ãçºçããŠããå¥ã®ã¯ã©ãŠãã®å¯Ÿå¿ããã¯ãŒã¯ããŒããåç §ãæŽæ°ããªãå Žåãæå·åã®äžæŽåãçºçããã¢ããªã±ãŒã·ã§ã³ã忢ãããããµã€ã¬ã³ãããŒã¿æå€±ãçºçãããããŸããããã¯ã é ããã¬ã€ãã³ã·é¢é£ã®ã³ãŒããã¹å®è¡æã«ã®ã¿ççŸããåäœãçºçããŸãã
匷åãªçµ±åå¶åŸ¡ã«ãããKMSã¯åç°å¢ã®ä¿¡é Œã¢ãã«ã®äžå¿çãªæ€èšŒãã€ã³ããšããŠæ©èœããŸããäŸãã°ãã¯ã©ãŠãAã®ã¯ãŒã¯ããŒãã¯ã¯ã©ãŠãBãçºè¡ããããŒã¯ã³ãŸãã¯èšŒææžã«äŸåããŠãããéµãžã®ã¢ã¯ã»ã¹ãèš±å¯ããåã«æ€èšŒãå¿ èŠãšãªãå ŽåããããŸããäžå çãªç£æ»ãšãã°èšé²ããªããã°ãã¯ã©ãŠãéã®éµã¢ã¯ã»ã¹ã¯äžéæã«ãªããã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒã¯ã»ãŒäžå¯èœã«ãªããŸãããããã£ãŠãå ç¢ãªKMSã¢ãŒããã¯ãã£ã§ã¯ãã¯ã©ãŠãéã®ä¿¡é Œæ€èšŒã匷å¶ãããã§ãã¬ãŒã·ã§ã³ç£æ»èšŒè·¡ããµããŒãããéµã®äœ¿çšãå ã®IDã³ã³ããã¹ããšåžžã«äžèŽããããã«ããå¿ èŠããããŸãããããã®å®å šå¯Ÿçã¯ãå¯èŠæ§ãå¶åŸ¡æ§ãæãªãããšãªãæ¡åŒµå¯èœãªãå®å šãªãã«ãã¯ã©ãŠãã¢ãŒããã¯ãã£ãç¶æããäžã§äžå¿çãªåœ¹å²ãæãããŸãã
KMS ã忣ç°å¢å šäœã§äžè²«ããã¬ããã³ã¹ã宿œããæ¹æ³
ãã«ãã¯ã©ãŠãç°å¢å šäœã«ãããäžè²«ããã¬ããã³ã¹ã¯ãä¿¡é Œæ§ãç£æ»å¯èœæ§ãã³ã³ãã©ã€ã¢ã³ã¹ã®ç¶æã«äžå¯æ¬ ã§ããããããèŠå¶å¯Ÿè±¡æ¥çã§ã¯ãäž»èŠãªéçšããããŒããŒã·ã§ã³ééãã¢ã¯ã»ã¹å¢çãä¿æèŠä»¶ã倱广é ãªã©ã確ç«ãããããªã·ãŒã«æºæ ããŠããããšã蚌æããå¿ èŠããããŸããåäžã¯ã©ãŠãç°å¢ã§ã¯ãã¬ããã³ã¹ã¯è€éã§ãã管çå¯èœã§ãããããããã«ãã¯ã©ãŠãç°å¢ã§ã¯ãã¬ããã³ã¹ã¯åæ£åã®èª²é¡ãšãªããŸããåãããã€ããŒã¯ãã€ãã³ãã®ãã°èšé²æ¹æ³ãå ¬éããã¡ããªãã¯ãããªã·ãŒç®¡ççšã®ã€ã³ã¿ãŒãã§ãŒã¹ãããããç°ãªããŸããçµ±äžããªããã°ãçµç¹ã¯ã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãã°ããŒãã«ã«é©çšããããæ©å¯æ å ±ã®æŒæŽ©ã«ã€ãªããå¯èœæ§ã®ããäžæŽåãæ€åºãããããããšãå°é£ã«ãªããŸãã
ãã«ãã¯ã©ãŠãKMSã¬ããã³ã¹æŠç¥ã§ã¯ãéµç®¡çã€ãã³ããäžå åãããç£æ»ã»ç£èŠãã€ãã©ã€ã³ãšé£æºãããŸããããã«ã¯ãéµã®äœæãã¢ã¯ã»ã¹è©Šè¡ãããŒããŒã·ã§ã³ãããªã·ãŒå€æŽãæš©éæŽæ°ãæå·åãŸãã¯åŸ©å·åã®å€±æã®è¿œè·¡ãå«ãŸããŸãã課é¡ã¯ãåãããã€ããŒã®ã»ãã³ãã£ã¯ã¹ãå°éããªããããããã®ã€ãã³ããçµ±äžãããã¬ããã³ã¹ã¢ãã«ã«æšæºåããããšã§ãããã®ãããªèª¿åã¯ã ãšã³ã¿ãŒãã©ã€ãºçµ±åã¢ãŒããã¯ãã£è€æ°ã®ã·ã¹ãã ãå ±éã®æäœã»ãã³ãã£ã¯ã¹ã«æ²¿ã£ãŠèª¿æŽãããå¿ èŠããããŸãã
ã¬ããã³ã¹ã¯ãèšŒææžç®¡çãã·ãŒã¯ã¬ããéçšããšã³ãããŒãæå·åããªã·ãŒããããŠç°å¢éã³ã³ãã©ã€ã¢ã³ã¹ã«ãŒã«ã«ãåã³ãŸããäŸãã°ãPCI DSSã§ã¯ãéµã¢ã¯ã»ã¹ã¯ãŒã¯ãããŒã«ããã峿 Œãªãã°èšé²ãšè·ååé¢ã矩åä»ããããŠããŸããçµ±äžãããã¬ããã³ã¹å±€ããªããã°ã3ïœ4瀟ã®ã¯ã©ãŠããããã€ããŒã«ãŸããã£ãŠãããã矩åãæããããšã¯ããšã©ãŒãçºçãããããæç¶äžå¯èœã«ãªããŸãããã®ãããçµç¹ã¯ãäžå åãããããã·ã¥ããŒããããªã·ãŒã»ã¢ãºã»ã³ãŒãã»ãã¬ãŒã ã¯ãŒã¯ããããŠçµ±åãèæ ®ããç£æ»æ©èœãçšããŠãæåããã¬ããã³ã¹ã®æŽåæ§ãçµã¿èŸŒãã KMSã·ã¹ãã ãèšèšããå¿ èŠããããŸããç°å¢å šäœã§ã¬ããã³ã¹ãäžè²«ããŠé©çšãããŠããã°ãçµç¹ã¯ã¯ãŒã¯ããŒãã®å Žæã«é¢ä¿ãªããæå·åã®åäœãäºæž¬å¯èœã§ã³ã³ãã©ã€ã¢ã³ã¹ã«æºæ ããŠããããšã確信ã§ããŸãã
ãã«ãã¯ã©ãŠãã¯ãŒã¯ããŒããé«åºŠãªããŒã©ã€ããµã€ã¯ã«èŠä»¶ãæšé²ããæ¹æ³
éµã©ã€ããµã€ã¯ã«ç®¡çã¯ããã«ãã¯ã©ãŠãã¢ãŒããã¯ãã£ã«ãããKMSçµ±åã«ãããŠæãå°é£ãªåŽé¢ã®äžã€ã§ããã¯ãŒã¯ããŒãã確å®ã«ããŒã¿ã埩å·ã§ããããã«ããã«ã¯ãéµã®ããŒããŒã·ã§ã³ã倱å¹ãåé€ãã¢ãŒã«ã€ããããŒãžã§ã³ç®¡çããããã€ããŒéã§åæãããå¿ èŠããããŸããããç°å¢ã§éµãããŒããŒã·ã§ã³ããŠããäžæ¹ã§ãå¥ã®ç°å¢ã§ã¯å€ãããŒãžã§ã³ãåç §ããŠããå Žåãã¯ãŒã¯ããŒãã¯äžæããŸããããç°å¢ã§ã¯å€±å¹ãçºçããå¥ã®ç°å¢ã§ã¯çºçããªãå Žåãã¢ã¯ã»ã¹ã®ã£ãããã»ãã¥ãªãã£ãªã¹ã¯ãçºçããŸãããããã®äžæŽåã¯ã以äžã®æé ã§ç¹å®ãããäŸåé¢ä¿ã®äžæŽåãåæ ããŠããŸãã ãªã¹ã¯åæææ³ 忣ã·ã¹ãã ã«ãããŠã
ãã«ãã¯ã©ãŠãã¯ãŒã¯ããŒãã§ã¯ãæšæºçãªããŒããŒã·ã§ã³ãè¶ ããåçãªã©ã€ããµã€ã¯ã«ç®¡çãæ±ããããŸããäŸãã°ããµãŒããŒã¬ã¹ãã©ãããã©ãŒã ãã³ã³ããã§å®è¡ãããäžæçãªã¯ãŒã¯ããŒãã§ã¯ããžã£ã¹ãã€ã³ã¿ã€ã ã®éµããããžã§ãã³ã°ããæå¹æéã«åºã¥ããèªåæå¹æéåããæ±ããããå ŽåããããŸããã¯ã©ãŠãéããŒã¿ãåŠçããåæãã€ãã©ã€ã³ã§ã¯ãåæå·åãã€ãã©ã€ã³ãèªåéµå€æã¬ã€ã€ãŒãå¿ èŠã«ãªãå ŽåããããŸãã忣ããããŒã ã¯ãéäžç®¡çã«ãã£ãŠæŽåæ§ã確ä¿ãããªãéããç°å¢ããšã«ç°ãªãã©ã€ããµã€ã¯ã«ããªã·ãŒãé©çšããå¯èœæ§ããããŸããã©ã€ããµã€ã¯ã«ã®èªååæããªããã°ãçµç¹ã¯éµã®ããªãããäžè²«æ§ã®ãªã倱å¹åäœããããã¯éæºæ ãªä¿æãã¿ãŒã³ãšãã£ãåé¡ã«çŽé¢ããããšã«ãªããŸãã
ã©ã€ããµã€ã¯ã«èŠä»¶ã¯ãé·ææå·åããŒã¿ã®ã¢ãŒã«ã€ãã¯ãŒã¯ãããŒã«ãé©çšãããŸããã¯ã©ãŠãAã®ã¢ãŒã«ã€ãã«åŸæ¥ã¯ã©ãŠãBããã¢ã¯ã»ã¹ããå¿ èŠãããå Žåãäž¡ç°å¢ã§äºææ§ã®ããã©ã€ããµã€ã¯ã«ãšåŸ©å·åæ©èœãé·å¹Žã«ããã£ãŠç¶æããå¿ èŠããããŸãããã®ããã«ã¯ãã¡ã¿ããŒã¿ã®ä¿æãKMSéµããŒãžã§ã³ç®¡çã茞åºç®¡çã埩å·åãã¹ãŠã§ã€ãç¶¿å¯ã«èšç»ããå¿ èŠããããŸãã匷åãªã©ã€ããµã€ã¯ã«ã¬ããã³ã¹ã¯ãã¯ãŒã¯ããŒããé²åããŠãããã«ãã¯ã©ãŠããšã³ã·ã¹ãã ã®éçšæ§ãã³ã³ãã©ã€ã¢ã³ã¹ããããŠåŸ©å åãç¶æããŸããé©åã«èšèšãããã©ã€ããµã€ã¯ã«ããã»ã¹ã«ãããäŒæ¥ã¯éçšäžã®è匱æ§ãæãããšãªããå®å šãªãã«ãã¯ã©ãŠãèªååãå€§èŠæš¡ã«ãµããŒãã§ããŸãã
ã¯ã©ãŠããã€ãã£ã KMS æ©èœããããã€ããŒéã§ãããã³ã°
ãã«ãã¯ã©ãŠãã¢ãŒããã¯ãã£ã¯ãã€ãã£ãKMSæ©èœã«å€§ããäŸåããŸãããåã¯ã©ãŠããããã€ããŒã¯æå·åãã¢ã€ãã³ãã£ãã£ãããã³ã°ããã°èšé²ãã©ã€ããµã€ã¯ã«ç®¡çæ©èœãããããç°ãªãæ¹æ³ã§å®è£ ããŠããŸããAWSã¯ã»ãŒãã¹ãŠã®ãµãŒãã¹ã«æ·±ãçµ±åããããšã³ãããŒãæå·åãéèŠããAzureã¯åŒ·åãªã¬ããã³ã¹ããã¯ãåããçµ±åãããããŒã«ãããŒã¹ã®å¶åŸ¡ã¢ãã«ã«éç¹ã眮ããŠããŸãããŸããGoogle Cloudã¯ç¢ºå®çãªéµæäœãšæ£ç¢ºãªIAMã¹ã³ãŒãèšå®ãæäŸããŠããŸãããããã®éãã¯ãç°å¢éã§äžè²«ããæå·ååäœãå¿ èŠãšãããã«ãã¯ã©ãŠãã¯ãŒã¯ããŒããèšèšããéã«éèŠã«ãªããŸããåãããã€ããŒãKMSåºç€ãã©ã®ããã«æ§ç¯ããŠãããã詳现ã«çè§£ããŠããªããã°ãããªã·ãŒé©çšã®äžæŽåãããŒããŒã·ã§ã³åäœã®äžè²«æ§ã®æ¬ åŠããŸãã¯æå·åã¯ãŒã¯ãããŒã®ç§»æ€æ§ã®æ¬ åŠãšãã£ããªã¹ã¯ãçããŸãããããã®åé¡ã®å€ãã¯ã ãšã³ã¿ãŒãã©ã€ãºçµ±ååºç€ ç°å¢éã®æŽåæ§ãé·æçãªå®å®æ§ã決å®ããŸãã
ã¯ãŒã¯ããŒããç°ãªãã¯ã©ãŠãéã§æ¡åŒµãããã«ã€ããŠãKMSã»ãã³ãã£ã¯ã¹ã®ããããªéããéçšã®ä¿¡é Œæ§ã«åœ±é¿ãäžããå¯èœæ§ããããŸããAWSãšAzureã¯ç°ãªãéµéå±€ã¢ãã«ã䜿çšããGCPã¯ç¢ºå®çãªæäœã«é¢ããç¬èªã®æå·åä¿èšŒããµããŒãããOCI Vaultã¯ç°ãªããªãŒãžã§ã³ã¹ã³ãŒããšã¬ããªã±ãŒã·ã§ã³åäœãé©çšããŸãããŸããåã¯ã©ãŠãã¯ç°ãªãã¬ã€ãã³ã·ç¹æ§ãšã¢ã¯ã»ã¹ãã¿ãŒã³ãæã¡ãã¢ããªã±ãŒã·ã§ã³ãæ©å¯ããŒã¿ã埩å·ãããŒããŒã·ã§ã³ãæ€èšŒããé »åºŠã«åœ±é¿ãäžããŸãããã«ãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ããããã®ãµãŒãã¹ã«çŽæ¥äŸåããå ŽåãIAMã«ãŒã«ã®äžäžèŽãã·ãŒã¯ã¬ããååŸã¯ãŒã¯ãããŒã®äºææ§ã®æ¬ åŠãç£æ»ã»ãã³ãã£ã¯ã¹ã®äžè²«æ§ã®æ¬ åŠãšãã£ãã¢ãŒããã¯ãã£äžã®æ©æŠãçããŸãããããã®éãã調åãããçµ±äžãããæŠç¥ããªããã°ãæå·ååäœã¯ã¯ã©ãŠãéã§æçåãããŸãããããã®èª²é¡ã¯ãåè¿°ã®æ§é çãªäžæŽåãåæ ããŠããŸãã ãã©ãããã©ãŒã éã®ãªã¹ã¯ç®¡ç åºç€ãµãŒãã¹ãåå²ãããšã忣ç°å¢ãäºæž¬äžèœãªåäœãããŸãã
ããŒéå±€ã¢ãã«ã®æ¯èŒãšãã«ãã¯ã©ãŠãããŒã¿ããªãã£ãžã®åœ±é¿
åã¯ã©ãŠãã¯ç¬èªã®ããŒéå±€ãå®è£ ããŠããããã¹ã¿ãŒããŒãããŒã¿ããŒã掟çããŒãç°å¢éã§ã©ã®ããã«åäœãããã«åœ±é¿ãäžããŸããAWS KMSã¯ããšã³ãããŒãæå·åã䜿çšããã«ã¹ã¿ããŒãã¹ã¿ãŒããŒãããã©ã«ãã¢ãã«ãšããŠäœ¿çšããŸããAzure Key Vaultã¯ãããŒããŠã§ã¢ããŒã¹ã®ããŒãšãœãããŠã§ã¢ããŒãçµ±åãããããŒã«ãã¬ããã³ã¹ã®äžã§åé¢ããŸããGoogle Cloud KMSã¯ãæ£ç¢ºãªIAMã¹ã³ãŒãã®ã¢ã¯ã»ã¹ãåããããŒãªã³ã°ãšããŒããŒãžã§ã³ã掻çšããŸããOCI Vaultã¯ãã¬ããªã±ãŒã·ã§ã³ãšã©ã€ããµã€ã¯ã«å¶åŸ¡ãåããéäžåã®ããŒã«ããªãŒãžã§ã³ã¢ãã«ã«åŸããŸãããããã®æ§é ã®éãã«ãããããŒã®äŒææ¹æ³ãããŒããŒã·ã§ã³æ¹æ³ããããŠã¯ã©ãŠãéã§ã®ããŒã¿ã¢ã¯ã»ã¹ãã¿ãŒã³ã®ã¹ã±ãŒãªã³ã°æ¹æ³ã決ãŸããŸãã
ããŒã¿ããªãã£ã®èгç¹ããèŠããšãéå±€ã¢ãã«ã®äžäžèŽã¯éçšäžã®å€§ããªèª²é¡ããããããŸããAWSãCMKãããŒããŒã·ã§ã³ããéãããŒããŒã·ã§ã³åäœã¯Azureã®VaultããŒçœ®æãGoogleã®ããŒããŒãžã§ã³ç®¡çã»ãã³ãã£ã¯ã¹ãšã¯ç°ãªããŸããäºæž¬å¯èœãªããŒããŒã·ã§ã³åäœã«äŸåããã¯ãŒã¯ããŒãã¯ããããã®éããèæ ®ããå¿ èŠããããŸããããããªããšã埩å·ãã¹ãç Žæãããªã¹ã¯ããããŸããéçè§£æãã©ãããã©ãŒã ã¯ãã¢ããªã±ãŒã·ã§ã³ãããŒéå±€ãããŒããŒãžã§ã³ã¢ã¯ã»ã¹ã«é¢ãããããã€ããŒåºæã®æ³å®ã«äŸåããŠããç®æãæããã«ããã®ã«åœ¹ç«ã¡ãŸããããã¯ãããŒã ãè©äŸ¡ããéã«åŸãããæç¢ºããåæ ããŠããŸãã ããŒã¿ãšå¶åŸ¡ãããŒã®åäœ è€éãªã·ã¹ãã å šäœã«ããã£ãŠã
ãã«ãã¯ã©ãŠãã®ããŒã¿ãã€ãã©ã€ã³ã§å ±æãã€ããŒãããšã³ã³ãŒããŸãã¯ãã³ãŒãããå¿ èŠãããå Žåãéå±€æ§é ã®äžäžèŽãããã«å€§ããªåœ±é¿ãåãŒããŸããããã¯ã©ãŠãã§æå·åãè¡ããããã®éå±€æ§é ãå¥ã®ã¯ã©ãŠãã§ã¯ãµããŒããããŠããªãå Žåãã¯ã©ãŠãéã®ããŒã¿ããªãã£ã¯æãªãããŸããäžè²«æ§ãç¶æããããã«ãçµç¹ã¯åãããã€ããŒã®éå±€æ§é ãå ±éã®æœè±¡ã¢ãã«ã«ãããã³ã°ãããããšã³ãããŒãæå·åãæŽ»çšããŠã€ã³ã¿ã©ã¯ã·ã§ã³ãæšæºåããå¿ èŠããããŸãããããã®ãã¥ã¢ã³ã¹ãçè§£ããããšã§ãããšãäž»èŠãªéå±€æ§é ãããã¯ã°ã©ãŠã³ãã§å€§ããç°ãªã£ãŠããŠãããã«ãã¯ã©ãŠãã¢ãŒããã¯ãã£ã®å ç¢æ§ãç¶æã§ããŸãã
IAM ã®éããã¯ã©ãŠãéã®ã¢ã¯ã»ã¹ãšããŒã®æš©éã«äžãã圱é¿
IAMã¯ãè€æ°ã®ã¯ã©ãŠããããã€ããŒéã§KMSãµãŒãã¹ãçµ±åããéã®æå€§ã®æ©æŠæºã®äžã€ã§ããAWS IAMããªã·ãŒãAzure AADããŒã«ãGCP IAMãã€ã³ãã£ã³ã°ã¯ãããããã¢ã¯ã»ã¹å®çŸ©ãç°ãªããŸããAWSã§èªèšŒãããããªã³ã·ãã«ã¯AzureãGoogle Cloudã«èªåçã«ã¯ååšããªããããä¿¡é Œå¢çãåããããã«ãã§ãã¬ãŒã·ã§ã³ãããŒã¯ã³äº€æãã¿ãŒã³ãå¿ èŠãšãªããŸããããããID倿ã®ã®ã£ããã«ãããç¶¿å¯ãªèšèšãªãã«ã¯ãã¯ã©ãŠãéã®åŸ©å·åãæå·åããããã¯éµããŒããŒã·ã§ã³ã®åäœãçµ±äžããããšã¯å°é£ã§ãã
IAMã®éãã¯ãæš©éã®çްååã«ã圱é¿ãåãŒããŸããAWSããªã·ãŒã¯ãã¢ã¯ã·ã§ã³ããªãœãŒã¹ãæ¡ä»¶ã«åºã¥ããŠæäœãå¶éã§ããŸããAzureã¯ãIDãããã€ããŒã«çŽä»ããããããŒã«ããŒã¹ã®æš©éãé©çšããŸããGoogle Cloud IAMã¯ãã现ããªæš©éèšå®ããµããŒãããŸãããç¶æ¿ã®è§£éæ¹æ³ãä»ã®ãããã€ããŒãšã¯ç°ãªããŸããããããäžäžèŽã«ãããçµç¹ãç°å¢éã§ããªã·ãŒãè€è£œããããšããéã«ãã»ãã¥ãªãã£äžã®æ¬ é¥ãé床ã«ç·©ãèšå®ãçããå¯èœæ§ããããŸããã¯ã©ãŠãã«ãã£ãŠã¢ã¯ã»ã¹å¶åŸ¡ã®è§£éæ¹æ³ãç°ãªããããæå°æš©éã®é©çšã¯ããå°é£ã«ãªããŸãããããã®èª²é¡ã¯ãã¢ãŒããã¯ãã£ã®äžæŽåãšé¢é£ããŠããŸãã äŒæ¥ã¬ãã«ã®ãªã¹ã¯æŠç¥ IAM ã¢ãã«ã®äžæŽåã«ããã»ãã¥ãªãã£ã®ä¿¡é Œæ§ãäœäžããŸãã
ããããå·®ç°ã軜æžããããã«ãäŒæ¥ã¯KMSæäœãžã®ã¢ã¯ã»ã¹ã瀟å ã®ã¢ã€ãã³ãã£ãã£ã·ã¹ãã ã«ãã£ãŠä»²ä»ããæœè±¡åãæ§ç¯ããããšããããããŸããããã«ããããããã€ããŒã¬ãã«ã®IAMã»ãã³ãã£ã¯ã¹ãç°ãªã£ãŠããŠããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ã¢ã¯ã»ã¹ã®äžè²«æ§ã確ä¿ãããŸããIAMã¢ãã«ãçµ±äžãããããªã·ãŒæ§é ã«ãããã³ã°ããããšã¯ãã¹ã±ãŒã©ãã«ãªãã«ãã¯ã©ãŠãKMSçµ±åã®åºæ¬çãªèŠä»¶ãšãªããŸãã
ã¯ã©ãŠããã€ãã£ãã®ãã°èšé²ãšç£æ»ãã³ã³ãã©ã€ã¢ã³ã¹ã®æŽåã«äžãã圱é¿
åãããã€ããŒã¯ããããç°ãªãç£æ»æ©èœãæäŸããŠããŸããAWS CloudTrailã¯ããŒã®äœ¿çšç¶æ³ããã现ããèšé²ããAzureã¯MonitorãšKey Vault蚺æãéããŠéäžçãªãã°èšé²ãæäŸããŸããäžæ¹ãGoogle Cloudã®Cloud Audit Logsã¯è©³çްãªã€ãã³ãå顿©èœãåããŠããŸããåã·ã¹ãã ã¯åŒ·åãªç£æ»æ©èœãæäŸããŸãããã»ãã³ãã£ã¯ã¹ãç°ãªããä¿åæéã®ããã©ã«ããç°ãªããã€ãã³ãã«ããŽãªãçŽæ¥ãããã³ã°ãããŸããããã®ãããPCI DSSãHIPAAãFedRAMPãISO 27001ãªã©ã®çµ±åç£æ»èšŒè·¡ãå¿ èŠãšããã³ã³ãã©ã€ã¢ã³ã¹ãã¬ãŒã ã¯ãŒã¯ã«æºæ ããããšããçµç¹ã«ãšã£ãŠã倧ããªè€éããçããŸãã
ãããã®éãã¯ãçµç¹ããã€ãã£ããµãŒãã¹çµ±åã«äŸåããŠããå Žåã«é¡èã«ãªããŸããAWSã¯ãLambdaãS3ãKinesisããçºä¿¡ããã埩å·ãªã¯ãšã¹ããç°ãªãæ¹æ³ã§ãã°ã«èšé²ããŸããAzureã¯ã鵿äœãVaultã¢ã¯ã»ã¹ã¬ã€ã€ãŒã«åºã¥ããŠåé¡ããŸããGoogle Cloudã®ãã°ã¯ãæå·åæäœããªãœãŒã¹ãã¹ã«ãã£ãŠåé¡ããŸããæ£èŠåããªããã°ããã«ãã¯ã©ãŠãç£æ»ã®æŽåæ§ãç¶æããããšã¯å°é£ã«ãªããŸãããããã®äžäžèŽã¯ãäŒæ¥ãè©äŸ¡ãè¡ãéã«çŽé¢ããã®ãšåã課é¡ãåæ ããŠããŸãã ç°å¢éã§ã®é ããéçšäžã®äžäžèŽ.
ã³ã³ãã©ã€ã¢ã³ã¹ã®æçåãåé¿ããã«ã¯ããã¹ãŠã®ãã°ãäžå åãããSIEMãŸãã¯ã¬ããã³ã¹ã¬ã€ã€ãŒã«ã«ãŒãã£ã³ã°ããã€ãã³ããçµ±äžãããã¹ããŒãã«æ£èŠåããå¿ èŠããããŸãããã°èšé²ãé©åã«èª¿æŽãããããšã§ãã»ãã¥ãªãã£éçšããŒã ã¯ç°åžžãæ€ç¥ããããªã·ãŒã®é©çšç¶æ³ãæ€èšŒããã¯ã©ãŠãå¢çãè¶ããŠäžè²«ããç£æ»å¯èœæ§ãç¶æã§ããããã«ãªããŸãã
KMS éçšã«ãããããã©ãŒãã³ã¹ãšã¬ã€ãã³ã·ã®å€åãçè§£ãã
KMSã®ããã©ãŒãã³ã¹ã¯ãæå·åããã¯ãšã³ããããŒããŠã§ã¢ã¢ã¯ã»ã©ã¬ãŒã·ã§ã³ããããã¯ãŒã¯ã¢ãŒããã¯ãã£ããµãŒãã¹çµ±åãã¹ã®éãã«ããããããã€ããŒéã§å€§ããç°ãªããŸããAWSã¯ãå€ãã®ãµãŒãã¹ãå éšã§æå·åæäœãå®è¡ãããããæ¥µããŠäœã¬ã€ãã³ã·ã®ãšã³ãããŒãæå·åãæäŸããŠããŸããAzure Key Vaultã®åŸ©å·åã§ã¯ãéå±€ãšãªãŒãžã§ã³ã«ãã£ãŠã¯è¿œå ã®ã¬ã€ãã³ã·ãçºçããå¯èœæ§ããããŸããGoogle Cloud KMSã®ããã©ãŒãã³ã¹ã¯é«ãäºæž¬å¯èœæ§ãèªããŸãããè€æ°ã®ãªãŒãžã§ã³ãè€æ°ã®ãããžã§ã¯ãã«ãŸãããã¯ãŒã¯ãããŒã§äœ¿çšãããšã远å ã®ãªãŒããŒããããçºçããå¯èœæ§ããããŸãã
åæåŸ©å·ãã·ãŒã¯ã¬ããååŸã«äŸåãããã«ãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã¯ãããããã¬ã€ãã³ã·ã®éããèæ ®ããªããã°ãç°å¢éã§ããã©ãŒãã³ã¹ã®äžè²«æ§ãä¿ãŠãªããªã¹ã¯ããããŸããã¯ã©ãŠãAã®ãµãŒãã¹ãã¯ã©ãŠãBã§æå·åãããããŒã¿ã埩å·ããå¿ èŠãããå Žåããããã¯ãŒã¯åºéã®ã¬ã€ãã³ã·ãšãããã€ãåºæã®æå·åã³ã¹ããéãªããéçšäžã®é å»¶ã«ã€ãªããå¯èœæ§ããããŸããããããããã©ãŒãã³ã¹ã®äžäžèŽã¯ã以äžã®åæã§ç¹å®ãããããã«ããã¯ã«äŒŒãŠããŸãã ã·ã¹ãã ã¬ãã«ã®ããã©ãŒãã³ã¹ã®éå¹çæ§ ããããæé€ããã«ã¯ãã¢ãŒããã¯ãã£ã®åæ§ç¯ãå¿ èŠã«ãªãããšããããããŸãã
çµç¹ã¯ããšã³ãããŒãæå·åã埩å·ããŒã¿ã®å®å šãªãã£ãã·ã¥ããŸãã¯å¯èœãªéãã¯ã©ãŠãããŒã«ã«æäœãå©çšããããšã§ãKMSã®ããã©ãŒãã³ã¹ãå¹çåã§ããŸãããããã€ããŒåºæã®ã¬ã€ãã³ã·ãããã¡ã€ã«ãçè§£ããããšã§ãæå·åã®éèŠãé«ãå Žåã§ãããã«ãã¯ã©ãŠãã¯ãŒã¯ããŒãã®å¿çæ§ãç¶æã§ããŸãã
ã¯ã©ãŠãå šäœã«ãããçµ±äžãããæå·åãšéµã©ã€ããµã€ã¯ã«æŠç¥ã®èšèš
è€æ°ã®ã¯ã©ãŠããããã€ããŒã«ãŸãããçµ±äžãããæå·åæŠç¥ãæ§ç¯ããã«ã¯ãæè¡çãªå¶åŸ¡ãæŽåãããã ãã§ã¯äžååã§ããçžäºéçšæ§ãæ³å®ããŠããªãç°å¢éã§ãããªã·ãŒãéµã®åœåèŠåãã©ã€ããµã€ã¯ã«ã®å¢çãæå·åã¢ãŒããã¬ããã³ã¹ã¯ãŒã¯ãããŒã調åããããäžè²«æ§ã®ããã¢ãŒããã¯ãã£ãã¬ãŒã ã¯ãŒã¯ãå¿ èŠã§ããAWSãAzureãGoogle CloudãOCIã¯ãããããéµã®ããŒããŒã·ã§ã³ããšã³ãããŒãã®æå·åãç£æ»ã»ãã³ãã£ã¯ã¹ãããªã·ãŒé©çšã«ã€ããŠç¬èªã®ã¢ãããŒããå®çŸ©ããŠããŸãããããã®åäœãç°ãªãå Žåããã«ãã¯ã©ãŠãã¯ãŒã¯ããŒãã§ã¯ãæå·åã«ãŒã«ãããŒãžã§ã³ã·ãŒã±ã³ã¹ãæå¹æéã埩å·åã®æåŸ å€ã®éã§ããã«ãããçããŸãããã®çµæãéçšäžã®è匱æ§ãäºæãã¬é害ãã³ã³ãã©ã€ã¢ã³ã¹ã®ã£ãããçããŸããçµ±äžãããæŠç¥ã確ç«ããããšã§ãã¯ãŒã¯ããŒãã®å®è¡å Žæã«é¢ä¿ãªããåãæå·åä¿èšŒããã¹ãŠã®ã¯ãŒã¯ããŒãã«åäžã«é©çšãããŸãããã®ã¬ãã«ã®äžè²«æ§ã¯ã äŒæ¥çµ±åæŠç¥ ç°å¢éã®åäžæ§ãé·æçãªä¿¡é Œæ§ã決å®ããŸãã
çµ±äžãããéµã©ã€ããµã€ã¯ã«æŠç¥ã¯ãã¢ããªã±ãŒã·ã§ã³ããã€ãã©ã€ã³ãããŒã¿ãããŒãæéã®çµéãšãšãã«ã©ã®ããã«é²åããããèæ ®ããå¿ èŠããããŸããçµç¹ã¯ãã¯ãŒã¯ããŒããããã¯ã©ãŠãã«å°å ¥ãããã®åŸå¥ã®ã¯ã©ãŠãã«ç§»è¡ããããã¬ã€ãã³ã·ãå埩åãã³ã¹ãã¡ãªããã®ããã«è€æ°ã®ã¯ã©ãŠãã«åæ£ãããããããšããããããŸããã¯ãŒã¯ããŒããå€åãããšãéµã®äŸåé¢ä¿ãå€åããŸããéµã¯ãã¯ãŒã¯ããŒããå®è¡ãããå Žæã«é¢ä¿ãªããã¢ã¯ã»ã¹å¯èœã§ã埩å·å¯èœã§ãããé©åã«ããŒãžã§ã³ç®¡çãããŠããå¿ èŠããããŸããããã«ã¯ãäžè²«ããããŒããŒã·ã§ã³ééãåæããã倱å¹åäœãäžå åãããã©ã€ããµã€ã¯ã«ã®å¯èŠæ§ããããã€ããŒéã®çµ±åã¡ã¿ããŒã¿ç®¡çãå«ãŸããŸããäžè²«æ§ã®ãªãã©ã€ããµã€ã¯ã«éçšã¯ãããŒãžã§ã³åç §ã®äžäžèŽãæå·æã®å€ãããŸãã¯æ°å¹ŽåŸã®ã¢ãŒã«ã€ãããŒã¿ã®åŸ©å·å€±æã«ã€ãªããå¯èœæ§ããããŸãããã®è€éãã¯ãåè¿°ã®ãã«ãç°å¢ãªã¹ã¯ãã¿ãŒã³ãåæ ããŠããŸãã ã¯ãã¹ã¯ã©ãŠããªã¹ã¯ç®¡ççµ±äžãããããªã·ãŒã®æœè¡ãæ¬ åŠããŠãããããã·ã¹ãã å šäœã®è匱æ§ãçããŸãã
ã¯ã©ãŠããããã€ããŒéã§ã®æå·åããªã·ãŒã®èª¿å
åã¯ã©ãŠããããã€ããŒã¯æå·åæ©èœãæäŸããŠããŸããããã®åºç€ãšãªãããªã·ãŒã¢ãã«ã¯ç°ãªããŸããAWSã¯æå·åã³ã³ããã¹ããã©ã¡ãŒã¿ãšIDã«åºã¥ãã¢ã¯ã»ã¹æ¡ä»¶ãé©çšããŸããAzureã¯ãããŒã«ãããªã·ãŒãã³ãã¬ãŒãã«çŽä»ããããããŒã«ããŒã¹ã®å¶åŸ¡ã䜿çšããŸããGoogle Cloudã¯ã詳现ãªIAMãã€ã³ãã£ã³ã°ãšãªãœãŒã¹ã¹ã³ãŒãã®ããŒããŒã«ãæäŸããŸããOCIã¯ããªãŒãžã§ã³ãèæ ®ããããŒã«ãã¬ãã«ã®ããªã·ãŒã䜿çšããŸããçµç¹ãè€æ°ã®ã¯ã©ãŠãã«åãã¯ãŒã¯ããŒããå±éããå Žåããã¹ãŠã®ç°å¢ã§çµ±äžãããæå·åã¬ããã³ã¹æ§é ãæ¡çšããªãéãããããã®éãã«ãã£ãŠããªã·ãŒã®æçåãçããŸãã
çµ±äžãããããªã·ãŒãã¬ãŒã ã¯ãŒã¯ã§ã¯ãéµã®åœåæ¹æ³ãã¹ã³ãŒãã®èšå®æ¹æ³ãã¢ããªã±ãŒã·ã§ã³ã«ããéµã®ãªã¯ãšã¹ãæ¹æ³ãããŒããŒã·ã§ã³ã€ãã³ãã®äŒææ¹æ³ãå®çŸ©ããå¿ èŠããããŸããå€ãã®äŒæ¥ã¯ããã©ãããã©ãŒã åºæã®ã¡ã«ããºã ãæœè±¡åããç§»æ€æ§ã«åªãããããã€ãã«äŸåããªãæœè±¡åãå®çŸãããšã³ãããŒãæå·åãåºç€ãšããŠæ¡çšããŠããŸãããšã³ãããŒãæå·åã§ã¯ãã¢ããªã±ãŒã·ã§ã³ã¯ããŒã¿éµãããŒã«ã«ã§åŸ©å·åããããã䜿çšããŠã³ã³ãã³ãã®æå·åãšåŸ©å·ãè¡ããããåºç€ãšãªãKMSãããã€ããšã®çŽæ¥çãªAPI飿ºã軜æžãããŸããããã«ããããããã€ãéã®éäºææ§ã軜æžãããã°ããŒãã«æå·åã«ãŒã«ã®é©çšãç°¡çŽ åãããŸããåæ§ã®çµ±åææ³ã¯ãããŒã ãæšæºåãè¡ãéã«ã䜿çšãããŸãã è€éãªçµ±åäŸåé¢ä¿ ç°æ©çš®ã·ã¹ãã éã§ã
ããªã·ãŒã®æœè±¡åã確ç«ããããšããããã€ããŒã¯ããŒã¿ããªãã£ãæãªãããšãªããããŒã«ã«ã§ã®æ¡åŒµæ©èœãé©çšã§ããŸããAWSã¯è¿œå ã®æå·åã³ã³ããã¹ãã«ãŒã«ãé©çšããAzureã¯Vault Tierãé©çšããGCPã¯ãããžã§ã¯ãå¢çãèšå®ããå¯èœæ§ããããŸããããããã¬ãã«ã®æœè±¡åã¯äžè²«ããŠããŸãããã®ã¢ãããŒãã«ãããåºç€ãšãªããã©ãããã©ãŒã ãé²åããŠãããã«ãã¯ã©ãŠãæå·åã®äºæž¬å¯èœæ§ãç¶æãããŸãã
ã¯ã©ãŠãéã§ã®ããŒããŒããŒã·ã§ã³ãšããŒãžã§ã³ç®¡çã®åäœã®èª¿æŽ
ããŒã®ããŒããŒã·ã§ã³ã¯ããã«ãã¯ã©ãŠãç°å¢ã«ãããŠçµ±åãæãé£ããã¿ã¹ã¯ã®äžã€ã§ããããã¯ãåãããã€ããŒãããŒãžã§ã³ç®¡çãããŒããŒã·ã§ã³ããªã¬ãŒãããŒåç §ãããããç°ãªãæ¹æ³ã§åŠçããããã§ããAWSã¯ãè«çããŒIDãç¶æããªããæ°ããããã¯ã¢ããããŒãäœæããããšã§CMKãããŒããŒã·ã§ã³ããŸããAzureã¯ãããŒã«ãå±€ã«å¿ããŠããŒã«ãããŒãé »ç¹ã«çœ®æãŸãã¯åçæããŸããGoogle Cloudã¯ãã¢ããªã±ãŒã·ã§ã³ãæ£ç¢ºã«åç §ããå¿ èŠããããæç€ºçã«ããŒãžã§ã³ç®¡çãããããŒãäœæããŸããOCIã§ã¯ããªãŒãžã§ã³ã¹ã³ãŒãã®ã¬ããªã±ãŒã·ã§ã³ã«é¢ããèæ ®äºé ãå°å ¥ãããŠããŸããã©ã€ããµã€ã¯ã«åæããªããšãããã¯ã©ãŠãã§ã®ããŒããŒã·ã§ã³ã«ãã£ãŠãå¥ã®ã¯ã©ãŠãã®ã¯ãŒã¯ããŒãã§ã¯åŸ©å·ã§ããªãæå·æãçæãããå ŽåããããŸãã
çµ±äžãããæŠç¥ã¯ãããŒãžã§ã³åœåãšã¡ã¿ããŒã¿ãããã³ã°ã«é¢ããæç¢ºãªèŠåŸãåããã°ããŒãã«ãªããŒããŒã·ã§ã³ãµã€ã¯ã«ãå°å ¥ããŸããããã«ããããã¹ãŠã®ã¯ã©ãŠããåãã¿ã€ã ã©ã€ã³ã«åŸã£ãŠéµãããŒããŒã·ã§ã³ããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®éµåç §ã®äžè²«æ§ãç¶æãããŸããå¯èœã§ããã°ãäŒæ¥ã¯ã°ããŒãã«ããŒããŒã·ã§ã³ã³ã³ãããŒã©ãŸãã¯ã€ãã³ãé§ååãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãã€ãã©ã€ã³ãå®è£ ããŠããããã€ããŒåºæã®ããŒããŒã·ã§ã³æäœãåæãããŸãããã®ã¢ãããŒãã«ãããå€ãæå·æã埩å·ãã¹ã®äžäžèŽãç£æ»æã®ããŒãžã§ã³ã®æ··ä¹±ãªã©ã®ãªã¹ã¯ã軜æžãããŸãããããã®ã©ã€ããµã€ã¯ã«äžã®èª²é¡ã¯ããããã³ã°æã«æããã«ãªãäžäžèŽã®åé¡ãšéåžžã«ãã䌌ãŠããŸãã ã·ã¹ãã éã®ããŒã¿ãããŒäŒæäžäžèŽããããšãå®è¡æã«äºæž¬ã§ããªãåäœãçºçããŸãã
äŒæ¥ã¯ãã¢ãŒã«ã€ãããŒã¿ãèŠå¶å¯Ÿè±¡ããŒã¿ã®é·æçãªããŒãžã§ã³ä¿åãç¶æããå¿ èŠããããŸããæå·åãæ°å¹Žã«ãããå Žåãéå»ã®ããŒããŒã·ã§ã³ãã¹ãåçŸããæ©èœãäžå¯æ¬ ã«ãªããŸããã¯ã©ãŠãéã§éµã®ã©ã€ããµã€ã¯ã«ãçµ±äžããããšã§ãã¢ãŒã«ã€ããã©ãã«ä¿åãããŠããŠããåžžã«åŸ©å·å¯èœãªç¶æ ãç¶æã§ããŸãã
ã¡ã¿ããŒã¿ãã¿ã°ä»ããããã³ããŒèå¥ã¢ãã«ã®æšæºå
ã¡ã¿ããŒã¿ã¯ããã«ãã¯ã©ãŠãæå·åæŠç¥ã«ãããŠéèŠãªåœ¹å²ãæãããŸããçµç¹ã¯ã¡ã¿ããŒã¿ã䜿çšããããšã§ãç°å¢ããŸããã§éµã®äœ¿çšç¶æ³ãåé¡ãè¿œè·¡ãæ€èšŒã§ããŸããããããã¯ã©ãŠãããšã«ã¡ã¿ããŒã¿ãã£ãŒã«ããã¿ã°ä»ãã¢ãã«ãããªã·ãŒã»ãã³ãã£ã¯ã¹ã¯ç°ãªããŸããAWSã¯æ¡ä»¶ä»ãé©çšã«ãããªããã¿ã°æ©èœãæäŸããŠããŸããAzure Key Vaultã¯ããªã·ãŒããŒã¹ã®ã¿ã°ä»ãããµããŒãããŠããŸãããç²åºŠã¯ç°ãªããŸããGoogle Cloudã¯ãªãœãŒã¹ã©ãã«ã䜿çšããŸãããã¡ã¿ããŒã¿ã»ãã³ãã£ã¯ã¹ã¯ä»ãšã¯ç°ãªããŸããOCIã®ã¿ã°ä»ãã¯ãã³ã³ããŒãã¡ã³ããšããã³ã·ãŒã¢ãŒããã¯ãã£ã«ãã£ãŠãç°ãªããŸãã
çµ±äžãããã¡ã¿ããŒã¿ã¢ãã«ã¯ããããã®éããæœè±¡åããŠãããŒã ãç®çãæ©å¯æ§ãã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã³ãèŠå¶ç¯å²ãã©ã€ããµã€ã¯ã«æ®µéããšã«ããŒã確å®ã«åé¡ã§ããããã«ããå¿ èŠããããŸããã¡ã¿ããŒã¿ã®æšæºåã¯ãäžè²«ããã¬ããã³ã¹ã確ä¿ããç£æ»ãç°¡çŽ åããã¯ã©ãŠãéã®ã¬ããŒããã€ãã©ã€ã³ã®èªååãå¯èœã«ããŸãããã®èª¿æŽããã»ã¹ã¯ãæšæºåã«å¿ èŠãªæšæºåã«ãåæ ãããŠããŸãã ç°å¢å šäœã®ãªã¹ã¯è©äŸ¡éçµ±äžãªã¡ã¿ããŒã¿ãç²ç¹ã«ã€ãªããå Žåã
çµ±åã¡ã¿ããŒã¿ã¯ãèªåããŒããŒã·ã§ã³ã廿¢ãã¢ã¯ã»ã¹ã¬ãã¥ãŒã«ã圹ç«ã¡ãŸããã¡ã¿ããŒã¿æ§é ãæŽåãããŠããã°ãçµç¹ã¯ã°ããŒãã«ããã·ã¥ããŒããæ§ç¯ããã©ã®éµãå€ããªã£ãããéå°ã«äœ¿çšãããŠãããããããã¯èª€ã£ãŠèšå®ãããŠããããææ¡ã§ããŸããããã«ãããéçšäžã®ããªããã軜æžããããã«ãã¯ã©ãŠãç°å¢å šäœã«ãããæå·åã®å¥å šæ§ãåäžããŸãã
æå·åæäœãšã©ã€ããµã€ã¯ã«ã¹ããŒã¿ã¹ã®éäžãã¥ãŒã®äœæ
åã¯ã©ãŠããéµãããŒã«ã«ã«ç®¡çããŠããå Žåã§ããçµç¹ã¯éµã®ã©ã€ããµã€ã¯ã«ãã¢ã¯ã»ã¹é »åºŠãããŒããŒã·ã§ã³ç¶æ³ããããŠå šãããã€ããŒã«ãããã¬ããã³ã¹ã®æŽåæ§ãå¯èŠåããããã®äžå åããããã©ãããã©ãŒã ãå¿ èŠãšããŸããäžå çãªå¯èŠæ§ããªããã°ãã©ã€ããµã€ã¯ã«ã®äžæŽåãæ°ã¥ããªããã¡ã«èç©ãããããŒããŒã·ã§ã³ã®äžæŽåãéµã®å€ãããããã¯ç£èŠãããŠããªãã¢ã¯ã»ã¹ãã¿ãŒã³ãªã©ã«ã€ãªãããŸããçµ±åãã¥ãŒã«ãããã¯ã©ãŠãéã®éµå©çšã«ãããäžè²«æ§ãã³ã³ãã©ã€ã¢ã³ã¹ããããŠäºæž¬å¯èœæ§ã確ä¿ãããŸãã
äžå 管çã¯ãSIEMçµ±åãå°çšã®ã¬ããã³ã¹ããã·ã¥ããŒãããŸãã¯ç€Ÿå ã©ã€ããµã€ã¯ã«ç®¡çãã©ãããã©ãŒã ãéããŠå®çŸã§ããŸãããã©ãããã©ãŒã ã¯ããã°ãåã蟌ã¿ãã¡ã¿ããŒã¿ãæ£èŠåããããŒãžã§ã³ã®éãã調æŽããåããŒã®ç¶æ ã«é¢ããä¿¡é Œã§ãããã¥ãŒãæäŸããå¿ èŠããããŸããããã¯ãããŒã ãåæãè¡ãéã«äœ¿çšãããçµ±åæ¹æ³ãšäŒŒãŠããŸãã é ããéçšäžã®äŸåé¢ä¿ è€éãªã·ã¹ãã å šäœã«ããã£ãŠã
äžå åãããã©ã€ããµã€ã¯ã«ãã¥ãŒã¯ãèŠå¶ã®å³ããæ¥çãé·æã¢ãŒã«ã€ãèŠä»¶ã«å¯Ÿå¿ããçµç¹ã«ãšã£ãŠç¹ã«éèŠã§ããããã«ãããã¢ããªã±ãŒã·ã§ã³ããããžã®å€åãããŒã ã®å€æŽãã¯ã©ãŠããããã€ããŒã®æ©èœæŽæ°ãªã©ããã£ãŠãããã«ãã¯ã©ãŠãæå·åã®èé害æ§ãç¶æã§ããŸããçµ±åãããã¬ããã³ã¹ãšã©ã€ããµã€ã¯ã«ã®æŽåæ§ã«ãããäŒæ¥ã¯ãã«ãã¯ã©ãŠããšã³ã·ã¹ãã å šäœã§äžè²«ããæå·åä¿èšŒãç¶æã§ããŸãã
éäžåããŒç®¡çãšåæ£åããŒç®¡çã®ãã¿ãŒã³
è€æ°ã®ã¯ã©ãŠãã«ãŸãããæå·éµã®ç®¡çæ¹æ³ãèšèšããããšã¯ãåºæ¬çãªã¢ãŒããã¯ãã£äžã®æ±ºå®ããå§ãŸããŸããéµç®¡çãåäžã®æš©åšã·ã¹ãã ã«éäžãããã¹ããããããšãåã¯ã©ãŠããããã€ããŒã®ãã€ãã£ãKMSã«åæ£ãããã¹ããïŒã©ã¡ãã®ãã¿ãŒã³ã«ãé åçãªå©ç¹ããããŸãããã¢ããªã±ãŒã·ã§ã³ã®èп𡿡倧ãããŒã¿ãããŒã®ã¯ã©ãŠãéåãèŠå¶å§åã®åŒ·åã«äŒŽããéçšäžã®èª²é¡ãé¡èã«ãªããŸããéäžåã¢ãã«ã¯ãçµ±äžãããã¬ããã³ã¹ãäžè²«ããã©ã€ããµã€ã¯ã«ããªã·ãŒãçµ±åç£æ»ãä¿èšŒããŸããããããé å»¶ãäŸåæ§ã®ãªã¹ã¯ãè€éãªçµ±åãã¹ãçããå¯èœæ§ããããŸãã忣åKMSã¢ãŒããã¯ãã£ã¯ãåã¯ã©ãŠãã®ãã€ãã£ãæ©èœã掻çšããŠé床ãšå埩åãé«ããŸãããããªãããäžè²«æ§ã®ãªãããŒããŒã·ã§ã³ãã¢ã¯ã»ã¹å¶åŸ¡ã®æçåãé²ãããã®æ éãªèª¿æŽãå¿ èŠã§ãããããã®ãã¬ãŒããªãã¯ã ãšã³ã¿ãŒãã©ã€ãºçµ±ååºç€ã¢ãŒããã¯ãã£ã®éžæã«ãã£ãŠç°å¢éã®äžè²«æ§ã決ãŸããŸãã
ãã«ãã¯ã©ãŠãã¯ãŒã¯ããŒããé²åããã«ã€ããäŒæ¥ã¯äž¡æ¹ã®ã¢ãã«ããã€ããªããã«éçšããã±ãŒã¹ãå¢ããŠããŸããäžéšã®æå·åã¯ãŒã¯ãããŒã¯ãããã©ãŒãã³ã¹ãšããŒã«ã«ã³ã³ãã©ã€ã¢ã³ã¹ã®ããã«ã¯ã©ãŠããã€ãã£ãã®KMSãšç·å¯ã«é£æºãããŸãŸã§ãããã°ããŒãã«ããŒã¿ã»ãããèŠå¶å¯Ÿè±¡ãã¡ã€ã³ã¯ãäžå€®éæš©çãªä¿¡é Œã®ã«ãŒãã«äŸåããŠããŸãããã®ãã€ããªããç¶æ ã管çããã«ã¯ãã€ã³ããªãžã§ã³ããªããªã·ãŒãããã³ã°ãã©ã€ããµã€ã¯ã«åæããããŠã¯ã©ãŠãéã®ã¢ã€ãã³ãã£ãã£ãã€ã³ãã£ã³ã°ã®æ éãªåŠçãå¿ èŠã§ãããã®é£æºããªããã°ãç°å¢éã§æå·åãã©ã¯ãã£ã¹ãç°ãªããšãã匱ç¹ãçãããªã¹ã¯ããããŸãããããã®äžäžèŽã¯ãåè¿°ã®éçšãªã¹ã¯ãåæ ããŠããŸãã ãã«ãç°å¢ãªã¹ã¯æŠç¥å調æ§ã®ãªãã¬ããã³ã¹ã¯ãé ããè匱æ§ãçã¿åºããŸããåãã¿ãŒã³ã®åäœãšçµ±åãžã®åœ±é¿ãçè§£ããããšã¯ãã¹ã±ãŒã©ãã«ã§å®å šãªãã«ãã¯ã©ãŠãéµç®¡çãèšèšããããã«äžå¯æ¬ ã§ãã
éäžéµç®¡çãæã䟡å€ãçºæ®ããå Žå
éäžåã®éµç®¡çã¯ãããããç°å¢ã«ãããéµã®çæãããŒããŒã·ã§ã³ãç£æ»ãæ€èšŒãåäžã®ä¿¡é Œã§ããæ©é¢ãæ ããšããç¹ã§é åçã§ãããã®ã¢ãããŒãã«ãããçµ±äžãããã¬ããã³ã¹ãäžè²«ããã©ã€ããµã€ã¯ã«éçšããããŠã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ã®éäžçãªé©çšãå®çŸããŸããéèãå»çãæ¿åºãªã©ã®èŠå¶ã®å³ããæ¥çã§ã¯ãç£æ»èšŒè·¡ãç°¡çŽ åãããã¯ã©ãŠãéã§æå·ååäœã«äžæŽåãçããå¯èœæ§ãäœããªããããéäžåã®KMSã¢ãã«ã奜ãŸããåŸåããããŸãããã¹ãŠã®éµæäœãåäžã®ã·ã¹ãã ãçµç±ããŠè¡ããããããããªã·ãŒã®é©çšãäºæž¬å¯èœã«ãªããéžè±ã容æã«æ€åºã§ããŸãã
éäžåKMSã·ã¹ãã ã¯ãé·æçãªã¢ãŒã«ã€ãä¿èšŒãå¿ èŠãšããã°ããŒãã«ã«åæ£ããããŒã¿ã»ããã管çããçµç¹ã«ãšã£ãŠç¹ã«äŸ¡å€ããããŸããéµã®ããŒãžã§ã³ç®¡çãšå€±å¹ã«é¢ããåäžã®æš©åšãããœãŒã¹ãç¶æããããšã§ãäŒæ¥ã¯å±¥æŽããŒã¿ãä¿åå Žæã«é¢ããã埩å·å¯èœã§ããããšãä¿èšŒããŸããããã¯ãããã¯ã¢ããããã°ãã³ã³ãã©ã€ã¢ã³ã¹ã¢ãŒã«ã€ããåæãã€ãã©ã€ã³ã«ãšã£ãŠéåžžã«éèŠã§ããéäžåã¢ãã«ã¯æå·åã®ä¿ææ§ããµããŒããããããçµç¹ã¯åã¯ã©ãŠãã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ããžãã¯ã倿Žããããšãªããæå·åã¢ã«ãŽãªãºã ãç§»è¡ããããæ°ããæšæºãæ¡çšãããããããšãã§ããŸãã
ããããéäžåã«ã¯æ°ããªéçšäžã®èæ ®äºé ã䌎ããŸããé éå°ãç°ãªãã¯ã©ãŠããããã¯ãŒã¯ã«ããã¢ããªã±ãŒã·ã§ã³ã¯äžå€®ã®KMSã«æ¥ç¶ããå¿ èŠããããã¬ã€ãã³ã·ã®å¢å ãã¯ã©ãŠãéã®äŸåé¢ä¿ã®ãªã¹ã¯ãçããå¯èœæ§ããããŸããã¯ã©ãŠããã€ãã£ããµãŒãã¹ã®äžã«ã¯ããã€ãã£ããµãŒãã¹ã®ããã«å€éšã®KMSãããã€ããŒãã·ãŒã ã¬ã¹ã«å©çšã§ããªããã®ããããçµ±åã¬ã€ã€ãŒããµã€ãã«ãŒãããã·ãå¿ èŠã«ãªããŸããããããè€éãã¯ãåè¿°ã®ã¢ãŒããã¯ãã£ã®äŸåé¢ä¿ãšäŒŒãŠããŸãã å¶åŸ¡ãããŒèª¿æ»å€éšãšã®ãããšããã·ã¹ãã ã®æ·±éšã«ãããåäœã«åœ±é¿ãäžãããããã°ãã·ã¹ãã ãã§ããéäžåKMSã¯ãæ éã«å®è£ ããããšã§ããã£ãã·ã¥ããšã³ãããŒãæå·åãã«ãŒãã£ã³ã°æé©åãéããŠããã©ãŒãã³ã¹ãç¶æããªãããäžè²«ããã°ããŒãã«ããªã·ãŒãå®çŸããŸãã
忣åã¯ã©ãŠããã€ãã£ãKMSãã¿ãŒã³ãæç¢ºãªå©ç¹ãæäŸããå Žå
忣éµç®¡çã¯åã¯ã©ãŠããããã€ããŒã®ãã€ãã£ãKMSãæŽ»çšããããšã§ãæå·åãªãã¬ãŒã·ã§ã³ãé«éãã€ãªãŒãžã§ã³ããŒã«ã«ã«ä¿ã¡ãã¯ã©ãŠããµãŒãã¹ãšç·å¯ã«çµ±åããŸããAWS KMSã¯ãS3ãDynamoDBãLambdaãEKSããããŠæ°å€ãã®ãã€ãã£ããµãŒãã¹ãšç·å¯ã«çµ±åãããŠããŸããAzure Key Vaultã¯ãApp ServicesãAKSãFunctionsãSQLãšã®ã·ãŒã ã¬ã¹ãªçµ±åãæäŸããŸããGoogle Cloud KMSã¯ãCloud StorageãBigQueryãPub/SubãCloud Runãšç·å¯ã«é£æºããŸãããããã®çµ±åã«ããã忣ãã¿ãŒã³ã«ãã£ãŠãéäžåKMSã·ã¹ãã ã§ã¯å¿ ãããå®çŸã§ããªãããã©ãŒãã³ã¹ãšéçšã®ã·ã³ãã«ããå®çŸã§ããŸãã
忣KMSã¢ãŒããã¯ãã£ã¯ãã¯ãŒã¯ããŒããã¯ã©ãŠããã€ãã£ããµãŒãã¹ãšå¯æ¥ã«çµåãããŠããå ŽåããŸãã¯ã¬ã€ãã³ã·ãžã®æåºŠã極ããŠé«ãå Žåã«åªããæ§èœãçºæ®ããŸããé »ç¹ã«åŸ©å·åãè¡ãã¢ããªã±ãŒã·ã§ã³ã倧éã®ããŒã¿å€æãå®è¡ããã¢ããªã±ãŒã·ã§ã³ããŸãã¯ãªã¢ã«ã¿ã€ã ã®ã·ãŒã¯ã¬ããããããžã§ãã³ã°ãå¿ èŠãšããã¢ããªã±ãŒã·ã§ã³ã¯ãããŒã«ã«ã§ã®æå·åæäœã®ã¡ãªããã享åã§ããŸãããã®è¿æ¥æ§ã«ãããã¯ã©ãŠãéã®ã©ãŠã³ãããªãããåé¿ããå€éšäŸåé¢ä¿ã®é害ãªã¹ã¯ã軜æžã§ããŸãããã ãããã®ãã¬ãŒããªããšããŠãåã¯ã©ãŠããç¬èªã®ããŒããŒã·ã§ã³ããªã·ãŒãIAMã«ãŒã«ãããã³ãã°ã»ãã³ãã£ã¯ã¹ãé©çšãããšããç¹ããããŸããçµ±äžãããã¬ããã³ã¹ãªãŒããŒã¬ã€ããªããã°ã忣KMSã®ãããã€ã¡ã³ãã¯ããã«å€åããŠããŸããŸãã
忣KMSãã¿ãŒã³ã§ã¯ãããŒãžã§ã³ç®¡çã®äžäžèŽãããŒããŒã·ã§ã³ã¹ã±ãžã¥ãŒã«ã®äžäžèŽãã¢ã¯ã»ã¹å¢çã®çžéãé²ãããã«ã匷åãªé£æºãå¿ èŠã§ãããããã®åé¡ã¯ãããŒã ãçµ±äžã詊ã¿ãéã«èŠãããäžäžèŽãšäŒŒãŠããŸãã 忣ã·ã¹ãã ã®äŸåé¢ä¿ é²åãããã©ãããã©ãŒã éã§ã®é£æºãçµç¹ã忣KMSãå°å ¥ããå Žåãåºç€ãšãªãKMSå®è£ ãç°ãªãå Žåã§ããã¯ãŒã¯ããŒãããããã€ããŒéã§äžè²«ããåäœãããããã«ãæœè±¡åã¬ã€ã€ãŒãŸãã¯ããªã·ãŒã¬ã€ã€ãŒã远å ããå¿ èŠããããŸãã
éäžåã¬ããã³ã¹ãšåæ£åå®è¡ãçµã¿åããããã€ããªãã KMS ã¢ãã«
å€ãã®çµç¹ã¯æçµçã«ãéäžåã®ã¬ããã³ã¹ãšåæ£å®è¡ãçµã¿åããããã€ããªããã¢ãã«ãæ¡çšããŸãããã®ãã¿ãŒã³ã§ã¯ãäžå€®ã·ã¹ãã ãããªã·ãŒãããŒããŒã·ã§ã³ã«ãŒã«ãã¡ã¿ããŒã¿æ§é ãã¢ã¯ã»ã¹å¢çãã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãå®çŸ©ããŸãããã€ãã£ãã¯ã©ãŠãKMSã·ã¹ãã ã¯æå·åãšåŸ©å·åã®æäœãããŒã«ã«ã§å®è¡ããããšã§ã匷åãªããã©ãŒãã³ã¹ãšãããã€ããŒãµãŒãã¹ãšã®ã·ãŒã ã¬ã¹ãªçµ±åãå®çŸããŸãããã®ãã€ããªããã¢ãã«ã¯ãã°ããŒãã«ãªäžè²«æ§ãšããŒã«ã«ãªæå·åããã©ãŒãã³ã¹ã®ãã©ã³ã¹ãåããŠãããããã¯ã©ãŠããã€ãã£ããµãŒãã¹ãšã¯ãã¹ã¯ã©ãŠãã¯ãŒã¯ãããŒã®äž¡æ¹ãåããçµç¹ã«ç¹ã«å¹æçã§ãã
ãã€ããªããèšèšã§ã¯ãããªã·ãŒã®äŒæã«é¢ãã課é¡ãçããŸããã€ãŸããããŒããŒã·ã§ã³ã€ãã³ãã倱å¹ã¢ã¯ã·ã§ã³ãããªã·ãŒå€æŽãåã¯ã©ãŠããããã€ããŒã«äžè²«ããŠäŒéãããããã«ããããšã§ãããã®èª²é¡ã«å¯ŸåŠãããããäŒæ¥ã¯å€ãã®å Žåãã°ããŒãã«ã«ãŒã«ããããã€ããŒåºæã®ããªã·ãŒã«å€æããããªã·ãŒã»ã¢ãºã»ã³ãŒãã»ãã¬ãŒã ã¯ãŒã¯ãå®è£ ããŸããããŒã«ã¯ã¯ã©ãŠããã€ãã£ãã®ãã°èšé²ããã³ç£èŠãã©ãããã©ãŒã ãšçµ±åãããéçšäžã®æŽå¯ãéäžåã¬ããã³ã¹å±€ã«ããŒã«ããã¯ãããŸãããããã®çµ±åãã¥ãŒã¯ã ããŒã¿ãããŒã®å¯èŠæ§ 忣åãšã³ã·ã¹ãã å šäœã«ããã£ãŠã
ãã€ããªããKMSã·ã¹ãã ã«ã¯ãä¿¡é Œæ§ã®é«ãåæ¹åã®çµ±åãã¹ãå¿ èŠã§ããäžå€®ã·ã¹ãã ã¯ã¯ã©ãŠããã€ãã£ãã®KMSã€ãã³ããä¿¡é Œããå¿ èŠããããã¯ã©ãŠããããã€ããŒã¯äºæž¬å¯èœãªæ¹æ³ã§ã¬ããã³ã¹ã«ãŒã«ãé©çšããå¿ èŠããããŸããé©åã«èšèšããããã€ããªããã¢ãŒããã¯ãã£ã«ãããäŒæ¥ã¯è€éãªãã«ãç°å¢ã¯ãŒã¯ãããŒããµããŒãããªãããæå·ã®æŽåæ§ãç¶æã§ããŸãã
æœè±¡åã¬ã€ã€ãŒãé©çšããŠã¯ã©ãŠããããã€ããŒéã®ã¢ã¯ã»ã¹ãçµ±äžãã
ãŸããŸãäžè¬çã«ãªãã€ã€ããKMSçµ±åãã¿ãŒã³ã¯ãæœè±¡åã¬ã€ã€ãŒãçšããŠè€æ°ã®ãããã€ããŒéã§ã®éµã¢ã¯ã»ã¹ãæšæºåãããã®ã§ããã¢ããªã±ãŒã·ã§ã³ã¯AWS KMSãAzure Key VaultããŸãã¯Google Cloud KMSãçŽæ¥åŒã³åºã代ããã«ãçµ±åã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠæäœããããã€ããŒåºæã®åŒã³åºãã«å€æããŸãããã®ãã¿ãŒã³ã«ãããã¢ããªã±ãŒã·ã§ã³ããããã€ããŒåºæã®æå·åã®è©³çްãçè§£ããå¿ èŠããªããªããç§»è¡ãç°¡çŽ åãããã¯ã©ãŠãããŒã¿ããªãã£ããµããŒããããŸãã
æœè±¡åã¬ã€ã€ãŒã¯ã³ãŒãã®çµåæ§ãå€§å¹ ã«äœæžããã¹ã±ãŒãªã³ã°æã«ç Žç¶»ãããããã€ãåºæã®æ³å®ãå°å ¥ãããªã¹ã¯ãæå°éã«æããŸããããããIAMã»ãã³ãã£ã¯ã¹ãããŒããŒã·ã§ã³ããªã¬ãŒãç£æ»åäœãšãã£ããããã€ãåºæã®æ©èœãæ éã«ãããã³ã°ããå¿ èŠããããŸããæ£ç¢ºãªãããã³ã°ããªããã°ãæœè±¡åã¬ã€ã€ãŒã¯éçšäžã®ããªãããæå·ååäœã®äžè²«æ§ã®ãªãã«ã€ãªããéèŠãªå·®ç°ãé èœããå¯èœæ§ããããŸãããããã®ãªã¹ã¯ã¯ã ã¯ãã¹ãã©ãããã©ãŒã ãªã¹ã¯åææœè±¡åã«ãã£ãŠãåŸã§é害ã®åå ãšãªãæ§é äžã®ççŸãé ãããŸãã
匷åãªã¬ããã³ã¹ãšã©ã€ããµã€ã¯ã«ã®æŽåæ§ãåããŠå®è£ ãããæœè±¡åã¬ã€ã€ãŒã¯ãã¯ã©ãŠããã€ãã£ãæ©èœãç ç²ã«ããããšãªããäžè²«ããã¢ã¯ã»ã¹ãã¿ãŒã³ãå®çŸããŸããçµç¹ã¯ã¯ã©ãŠãå šäœã§çµ±äžãããæå·åã«ãŒã«ãé©çšã§ãããšåæã«ããšã³ãžãã¢ãªã³ã°ããŒã ã«ã¯ãŒã¯ããŒããå Žæãåããèªç±ã«ã¹ã±ãŒãªã³ã°ããèªç±ãæäŸããŸãã
ã¯ãã¹ã¯ã©ãŠãããŒã¢ã¯ã»ã¹ãšãã§ãã¬ãŒã·ã§ã³ã®ããã®ã¢ãŒããã¯ãã£ã¢ãããŒã
ã¯ã©ãŠãéã®éµã¢ã¯ã»ã¹ã¯ãçŸä»£ã®ãã«ãã¯ã©ãŠãã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ã«ãããæãå°é£ãªåŽé¢ã®äžã€ãšãªã£ãŠããŸããããã¯ãåã¯ã©ãŠããããã€ããŒãIDã®æ€èšŒãKMSãªã¯ãšã¹ãã®æ¿èªããããŠä¿¡é Œå¢çã®æ§ç¯ãããããç°ãªãæ¹æ³ã§è¡ã£ãŠããããã§ããã¯ãŒã¯ããŒããAWSãAzureãGoogle CloudãOCIã«ãŸãããå Žåãç°ãªãã¯ã©ãŠãã§çæãããå¯èœæ§ã®ããæå·éµãžã®ã·ãŒã ã¬ã¹ãªã¢ã¯ã»ã¹ãæ±ããããããšããããããŸãããã®ãããããã©ãŒãã³ã¹ãéçšã®ç¬ç«æ§ãæãªãããšãªãå®å šãªéµã¢ã¯ã»ã¹ã確ä¿ããããã®ãã§ãã¬ãŒã·ã§ã³ã¢ãã«ãID倿ãããŒã¯ã³äº€æã¡ã«ããºã ããããŠä¿¡é Œã®æ©æž¡ãæŠç¥ãå¿ èŠã«ãªããŸãããããã®è€éãã¯ãåè¿°ã®äŸåé¢ä¿ã®èª¿æŽã«é¢ãã課é¡ãåæ ããŠããŸãã ãšã³ã¿ãŒãã©ã€ãºçµ±ååºç€ç¬ç«ããŠèšèšãããã·ã¹ãã ã確å®ã«é£æºããå¿ èŠãããç°å¢ã§ããçµç¹ãã¯ã©ãŠãéã®é£æºãå¢ããã«ã€ããŠãå ç¢ãªãã§ãã¬ãŒã·ã§ã³ã®ã¢ãŒããã¯ãã£ã«å¯ŸããããŒãºã¯é£èºçã«é«ãŸããŸãã
ããã«ãã¯ãã¹ã¯ã©ãŠãã¢ãŒããã¯ãã£ã§ã¯ãã¹ã±ãŒã«ã¢ãŠãã€ãã³ããç§»è¡ããã«ããªãŒãžã§ã³ãã§ã€ã«ãªãŒããŒæã®ã¢ããªã±ãŒã·ã§ã³ã¯ãŒã¯ããŒãã®æåãèæ ®ããå¿ èŠããããŸããAWSã§éå§ãããã¯ãŒã¯ããŒãã¯ãAzureã«ä¿åãããŠããéµãžã®äžæçãŸãã¯æ°žç¶çãªã¢ã¯ã»ã¹ãå¿ èŠãšããå Žåããããåæãžã§ãã¯Google Cloudã§æå·åãããããŒã¿ã埩å·åããããšããããŸããå®å šãªãã§ãã¬ãŒã·ã§ã³ã¡ã«ããºã ããªããã°ããããã®çžäºäœçšã¯è匱ã§äžè²«æ§ã®ãªããã®ã«ãªããŸããIDãããã€ããŒãããŒã¯ã³ãããŒã«ãŒãã²ãŒããŠã§ã€ãµãŒãã¹ãæå·åãããã·ã¯ãæå°æš©éã®é©çšãç¶æããªãããåãããã€ããŒã®KMSã»ãã³ãã£ã¯ã¹ã«æºæ ããå¿ èŠããããŸãããã®æŽåæ§ããªããã°ãçµç¹ã¯ç¡å¶éã®ä¿¡é Œã®é²åºãéå°ãªæš©éä»äžããŸãã¯ç£èŠãããŠããªãã¯ãã¹ã¯ã©ãŠã埩å·ãããŒã®ãªã¹ã¯ã«ãããããŸãããããã®ãªã¹ã¯ã¯ãã§åŒ·èª¿ãããŠãããã«ãç°å¢ã®äžæŽåã«ãã䌌ãŠããŸãã äŒæ¥ãªã¹ã¯æŠç¥çµ±äžãããå¶åŸ¡ã®æ¬ åŠã¯äºæž¬äžå¯èœãªåäœã«ã€ãªãããŸãããã§ãã¬ãŒã·ã§ã³æè¡ãšã¯ã©ãŠãéã®ã¢ã¯ã»ã¹ãã¿ãŒã³ãçè§£ããããšã¯ãèé害æ§ã®é«ããã«ãã¯ã©ãŠãæå·åæŠç¥ãæ§ç¯ããäžã§äžå¯æ¬ ãšãªããŸãã
ã¯ãã¹ã¯ã©ãŠãããŒèªèšŒã®ããã®ãã§ãã¬ãŒã·ã§ã³IDã¢ãã«
ãã§ãã¬ãŒã·ã§ã³IDã¢ãã«ã¯ããã«ãã¯ã©ãŠãã«ãããæãå°é£ãªèª²é¡ã®1ã€ãã€ãŸããããã¯ã©ãŠãã§èªèšŒãããã¯ãŒã¯ããŒãããå¥ã®ã¯ã©ãŠãã®KMSã«å¯ŸããŠã©ã®ããã«ãã®IDã蚌æããããšããåé¡ã解決ããŸããAWS IAMãAzure Active DirectoryãGoogle Cloud IAMã¯äºææ§ããªããåãããã€ããŒã¯ããŒã¯ã³ã®æ€èšŒæ¹æ³ãããããç°ãªããŸãããã§ãã¬ãŒã·ã§ã³ã¯ãããIDã·ã¹ãã ãå¥ã®IDã·ã¹ãã ã«ãããã³ã°ããããšã§ä¿¡é Œé¢ä¿ãæ§ç¯ããã¯ãŒã¯ããŒããç°å¢ããŸããã§å®å šã«ããŒãèŠæ±ã§ããããã«ããŸããããã¯ãOpenID ConnectãSAMLããŒã¹ã®ãã§ãã¬ãŒã·ã§ã³ãã¯ãŒã¯ããŒãIDãã§ãã¬ãŒã·ã§ã³ããŸãã¯ããŒã¯ã³å€æãµãŒãã¹ã䜿çšããŠå®çŸã§ããŸãããããã®å Žåããå ã®ã¯ã©ãŠãã®IDã¢ãµãŒã·ã§ã³ãå®å ã¯ã©ãŠãã®KMSã«ãã£ãŠå®å šã«èªèãããããšãä¿èšŒããããšãç®æšã§ãã
å®éã«ã¯ããã§ãã¬ãŒã·ã§ã³IDã·ã¹ãã ã¯ãäœã¬ã€ãã³ã·ã®æ€èšŒãã¹ãã¢ã¯ã»ã¹æš©éã®å³å¯ãªã¹ã³ãŒãèšå®ããããŠãããã€ãéã§è¿ éã«äŒæãã倱å¹ã¡ã«ããºã ã確ä¿ããå¿ èŠããããŸããèšå®ãã¹ããããšããã§ãã¬ãŒã·ã§ã³ã¯é床ã«å¯å®¹ãªåœ¹å²ãç¡å¶éã®ä¿¡é Œåæãçã¿åºããé倧ãªè匱æ§ãçã¿åºããŸããåæ§ã®åé¡ã¯ãåè¿°ã®ã·ã¹ãã éäŸåé¢ä¿ãããã³ã°ã§ãçºçããŸãã ããŒã¿ãããŒåæã®æŽå¯ é ãããä¿¡é Œãã¹ãã»ãã¥ãªãã£ã®ç²ç¹ãçã¿åºããŸãã
å ç¢ãªãã§ãã¬ãŒã·ã§ã³ã¢ãã«ã¯ããµãŒããŒã¬ã¹é¢æ°ãã³ã³ãããªã©ãæå¹æéã®çãèªèšŒæ å ±ãå¿ èŠãšããäžæçãªã¯ãŒã¯ããŒãããµããŒãããŸãããããã®ã¯ãŒã¯ããŒãã¯ãé·æçãªã·ãŒã¯ã¬ãããä¿åãã代ããã«ãããŒã¯ã³ãåçã«ååŸããããã䜿çšããŠã¯ã©ãŠãéã§ããŒãèŠæ±ããŸãããã§ãã¬ãŒã·ã§ã³ã«ããããããã®ããŒã¯ã³ãæ®éçã«çè§£ãããããšãä¿èšŒããããšåæã«ãã¯ãŒã¯ããŒãã®å®è¡å Žæã«é¢ä¿ãªãæå°æš©éã®é©çšãç¶æãããŸããäŒæ¥ããã«ãã¯ã©ãŠãã¢ãŒããã¯ãã£ãæ¡åŒµããã«ã€ããŠããã§ãã¬ãŒã·ã§ã³IDã¯äžè²«æ§ãšã»ãã¥ãªãã£ã«åªããããŒã¢ã¯ã»ã¹ã®åºç€ãšãªããããŒã¿ããªãã£ãå¶éããã¯ã©ãŠãåºæã®èªèšŒã¡ã«ããºã ãžã®äŸåãæé€ââããŸãã
ãã«ãã¯ã©ãŠã KMS ã¢ã¯ã»ã¹ã®ããã®ãããŒã«ãŒä¿¡é Œããã³ããŒã¯ã³äº€æã²ãŒããŠã§ã€
ãããŒã«ãŒãã»ãã©ã¹ãã¯ãè€æ°ã®ã¯ã©ãŠãããã®IDãæ€èšŒãããããã€ããŒåºæã®ããŒã¯ã³ãçºè¡ãããéäžåã®ãã©ã¹ãã»ãããŒã«ãŒãªã³ã°ã»ãµãŒãã¹ãå°å ¥ããŸããAWSãšAzureããŸãã¯AzureãšGoogle Cloudéã®çŽæ¥ãã§ãã¬ãŒã·ã§ã³ã§ã¯ãªããã¯ãŒã¯ããŒãã¯ãã©ã¹ãã»ãããŒã«ãŒã«å¯ŸããŠèªèšŒãè¡ãããã©ã¹ãã»ãããŒã«ãŒãå®å ã¯ã©ãŠãã®KMSã«é©ããããŒã¯ã³ãçæããŸãããã®ãã¿ãŒã³ã¯ãIDãããŒããããã€ããŒãšã®çŽæ¥çãªé¢ä¿ããåãé¢ããããŒã¿ããªãã£ãåäžãããã¯ã©ãŠãéã®æ§æã®è€éãã軜æžããŸãã
ãããŒã«ãŒã«ããä¿¡é Œã¯ãè€æ°ã®ãããã€ãããã®éµã«åæã«ã¢ã¯ã»ã¹ããå¿ èŠããããå€èšèªã¯ãŒã¯ããŒããæã€å€§èŠæš¡åæ£ã·ã¹ãã ã«ãšã£ãŠç¹ã«éèŠã§ãããããŒã«ãŒã¯ããœãŒã¹IDãæ€èšŒããã°ããŒãã«ããªã·ãŒãé©çšããåãããã€ãã«åãããŠã«ã¹ã¿ãã€ãºãããçåœããŒã¯ã³ãçºè¡ããŸããããã«ããããããã€ãã®ããªã·ãŒã倿ŽãããŠããäžè²«ããã¢ã¯ã»ã¹å¶åŸ¡ãä¿èšŒãããŸããããŒã¯ã³ãããŒã«ãŒã¯ãç£æ»ãã€ãã©ã€ã³ãã¡ã¿ããŒã¿ã·ã¹ãã ãããã³ã°ããŒãã«ã¬ããã³ã¹ã¬ã€ã€ãŒãšçµ±åããå¿ èŠããããŸããããã¯ã çµ±åäžè²«æ§ãã¬ãŒã ã¯ãŒã¯.
è€éãªç¹ã¯ãããŒã¯ã³ã®æå¹æéã倱å¹åäœã屿§ãããã³ã°ããããã€ããŒéã§äžè²«æ§ãä¿ã€ããã«ããããšã§ãããããŒã«ãŒãççŸããã¯ã¬ãŒã ãæã€ããŒã¯ã³ãçºè¡ããå Žåãããã¯ã©ãŠãã§ã¯ã¢ã¯ã»ã¹ãèš±å¯ãããäžæ¹ã§ãå¥ã®ã¯ã©ãŠãã§ã¯ã¢ã¯ã»ã¹ãæåŠãããå¯èœæ§ããããŸããããã¯ããã«ãã¯ã©ãŠãéçšã§ããèŠãããç°å¢éããªããåé¡ã«äŒŒãé害ã«ã€ãªããå¯èœæ§ããããŸããä¿¡é Œæ§ã®é«ããããŒã«ãŒåä¿¡é Œã·ã¹ãã ã¯ãå®å®ãããã«ãã¯ã©ãŠãKMSçµ±åã®åºç€ãšãªããŸãã
ã¯ã©ãŠãéããŒã¢ã¯ã»ã¹ãã¹ã®ããã®æå·åãµã€ãã«ãŒãšãããã·
ã¢ããªã±ãŒã·ã§ã³ãå€éšã®KMSã·ã¹ãã ãšçŽæ¥ããåãã§ããªãå Žåãæå·åãµã€ãã«ãŒãŸãã¯ãããã·ã仲ä»åœ¹ãšããŠæ©èœããŸãããµã€ãã«ãŒã³ã³ãããŸãã¯ããŒã¢ã³ã¯ãã¯ãŒã¯ããŒãã«ä»£ãã£ãŠéµãªã¯ãšã¹ãã埩å·åæäœãããŒããŒã·ã§ã³èª¿æŽãåŠçããŸãããµã€ãã«ãŒã¯ãKMSããžãã¯ãã¢ããªã±ãŒã·ã§ã³ã«åã蟌ãã®ã§ã¯ãªããã¯ã©ãŠãéã®å·®ç°ãæœè±¡åããã¯ãŒã¯ããŒãæ§æã«åºã¥ããŠãªã¯ãšã¹ããé©åã«ã«ãŒãã£ã³ã°ããŸãã
ãµã€ãã«ãŒã¯ããããã€ããŒåºæã®è€éããæšæºåãããã³ã³ããŒãã³ãã«éçŽããããšã§ããã«ãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã®ã³ãŒããç°¡çŽ åããŸãããŸãã埩å·åãããããŒã¿ããŒãããŒã«ã«ã«ãã£ãã·ã¥ããããšã§ãã¯ã©ãŠãéã®ã©ãŠã³ãããªãããåæžããããã©ãŒãã³ã¹ãåäžãããŸãããããããµã€ãã«ãŒã¯ãç£èŠãšæ€èšŒãå¿ èŠãªã¢ãŒããã¯ãã£äžã®äŸåé¢ä¿ããããããŸããããã¯ãã¯ã©ãŠãã«ãããé ããå®è¡ãã¹ã«äŒŒãŠããŸãã å®è¡æã®åäœèª¿æ».
é©åã«å®è£ ããããµã€ãã«ãŒã¯ãã¢ã¯ã»ã¹å¶åŸ¡ã®é©çšãIDããŒã¯ã³ã®æ€èšŒããããŠã¯ãŒã¯ããŒãã®ç§»è¡æã§ãäžè²«ããã°ããŒãã«æå·åããªã·ãŒã®é©çšãå®çŸããŸãããŸãããã°èšé²ãšããŒäœ¿çšç¶æ³ã®ãã¬ã¡ããªãçµ±åããããšã§ãç°å¢éã®ã¬ããã³ã¹ãšã³ã³ãã©ã€ã¢ã³ã¹ã®æŽåæ§ãåäžãããŸãã
ãšã³ãããŒãæå·åã䜿çšããå®å šãªã¯ãã¹ã¯ã©ãŠãæå·åãã€ãã©ã€ã³ã®èšèš
ãšã³ãããŒãæå·åã¯ãããŒã¿æå·åãKMSåºæã®æäœããåé¢ãããããå®å šãªã¯ãã¹ã¯ã©ãŠãæå·åãå®çŸããããã®æã广çãªããŒã«ã®äžã€ã§ããã¯ã©ãŠãéã§ã³ã³ãã³ãã埩å·ãã代ããã«ãã¯ãŒã¯ããŒãã¯é©åãªKMSã䜿çšããŠããŒã«ã«ã§ããŒã¿éµã埩å·ããã¯ãã¹ã¯ã©ãŠããžã®çŽæ¥ã¢ã¯ã»ã¹ãªãã§æå·åæäœãå®è¡ããŸããããã«ããããã«ãã¯ã©ãŠãæå·åã¯ãŒã¯ãããŒã«å¿ èŠãªä¿¡é Œæ§ã®åæãšAPIã®é£æºãå€§å¹ ã«åæžãããŸãã
ãšã³ãããŒãæå·åã«ãããã¯ãŒã¯ããŒããã¯ã©ãŠãéãç§»è¡ããå Žåã§ããããŒã¿ããŒãæå·åããããŒã«ã¢ã¯ã»ã¹ã§ããéããããŒã¿ãå®å šã«åŸ©å·ã§ããŸãããŸããã¯ã©ãŠãéã®ããŒã¿ç§»åãšã¢ãŒã«ã€ããç°¡çŽ åãããŸããããã¯ãããŒã¿ããŒã®ã¿ãã¯ã©ãŠãéã®ããåããå¿ èŠãšããåºç€ãšãªãã³ã³ãã³ãã¯å¿ èŠãšããªãããã§ãããã®æœè±¡åã«ãããªã¹ã¯ã軜æžããããã«ãã¯ã©ãŠãèšèšã§ãã°ãã°çºçããæçåã鲿¢ã§ããŸãããã®æœè±¡åã«ãã£ãŠããããããæç¢ºãã¯ãã¯ã©ãŠãã«ãããæœè±¡åã®åœ¹å²ãšäŒŒãŠããŸãã ããŒã¿ãããŒäžè²«æ§åæ.
ãšã³ãããŒãæå·åãå°å ¥ããäŒæ¥ã¯ãã¢ãŒããã¯ãã£ã®æè»æ§ã匷åãªããã©ãŒãã³ã¹ããããŠã¯ã©ãŠãéã§äžè²«æ§ã®ããæå·åã»ãã³ãã£ã¯ã¹ãç²åŸã§ããŸãããšã³ãããŒãæå·åã¯ãã¯ãŒã¯ããŒããç°å¢éã§åçã«å€åããŠããéµã¢ã¯ã»ã¹ã®äºæž¬å¯èœæ§ãšå®å šæ§ãç¶æãããã¹ã±ãŒã©ãã«ãªãã«ãã¯ã©ãŠãèšèšã®åºç€ãšãªããŸãã
äžè²«ããã¢ã¯ã»ã¹å¶åŸ¡ã«ãããã«ãã¯ã©ãŠãã·ãŒã¯ã¬ãã管çã®å®è£
è€æ°ã®ã¯ã©ãŠããããã€ããŒã«ãŸãããã·ãŒã¯ã¬ããã®ç®¡çã¯ãçŸä»£ã®ã¢ãŒããã¯ãã£ã«ãããŠæãç¹çްãªèª¿æŽèª²é¡ã®äžã€ãšãªããŸããã·ãŒã¯ã¬ããã¯ãAWS Secrets ManagerãAzure Key Vault SecretsãGoogle Secret ManagerãOCI Vault ããããã§ãä¿åãããŒãžã§ã³ç®¡çãããŒããŒã·ã§ã³ãã¢ã¯ã»ã¹æ¹æ³ãç°ãªããŸããã¢ããªã±ãŒã·ã§ã³ãè€æ°ã®ç°å¢ã«ãŸãããå Žåãåã·ã¹ãã ã¯ç¬èªã®APIãã¢ã€ãã³ãã£ãã£ã«ãŒã«ãã¢ã¯ã»ã¹ã»ãã³ãã£ã¯ã¹ãå ¬éãããããã¯ã©ãŠãéã®çµ±äžæ§ãè€éã«ãªããŸããäžè²«ããã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ããªããã°ãã·ãŒã¯ã¬ããã¯æéã®çµéãšãšãã«å€åããæå¹æéããªã·ãŒã忣ããããã¢ã¯ã»ã¹ããŒã«ã«äžè²«æ§ããªããªã£ãããã¡ã¿ããŒã¿ã®äžäžèŽã«ããç£æ»ã倱æãããããŸãããããã®åé¡ã¯ãéçšäžã®äžæŽåã«äŒŒãŠããŸãã ã¯ãã¹ãã©ãããã©ãŒã ãªã¹ã¯æŠç¥èšèšã«ãã£ãŠçµ±äžãããŠããªãéããç°å¢ã«ãã£ãŠã«ãŒã«ã®é©ç𿹿³ãç°ãªããŸãã
ãã€ã¯ããµãŒãã¹ããµãŒããŒã¬ã¹é¢æ°ãã³ã³ããåãããã¯ãŒã¯ããŒããè€æ°ã®ã¯ã©ãŠãã«ãŸããã£ãŠåæã«å®è¡ãããå Žåãè€éãã¯å¢å€§ããŸããAWSã«ãããã€ããããµãŒãã¹ã¯Azureã«ä¿åãããŠããããŒã¿ããŒã¹ã®ãã¹ã¯ãŒããžã®äžæçãªã¢ã¯ã»ã¹ãå¿ èŠã«ãªãå ŽåããããGoogle CloudããŒã¹ã®ãã€ãã©ã€ã³ã¯AWSã«ä¿åãããŠããèªèšŒæ å ±ãå¿ èŠã«ãªãå ŽåããããŸãããããã®ã¯ã©ãŠãéã®ã·ãŒã¯ã¬ããã®ããåãã«ã¯ãæš©éã®äžäžèŽãèªèšŒæ å ±ã®éå°ãªé²åºãé²ããããæ éãªãªãŒã±ã¹ãã¬ãŒã·ã§ã³ã匷åãªID飿ºããããŠçµ±åã¢ã¯ã»ã¹å¶åŸ¡ã«ãŒã«ãå¿ èŠã§ãããã«ãã¯ã©ãŠããã€ãã©ã€ã³ã§ã¯ãã¯ãŒã¯ããŒãã®ç§»è¡ãã¹ã±ãŒã«ã¢ãŠãããã§ã€ã«ãªãŒããŒãçºçããŠããã·ãŒã¯ã¬ããã®ååŸãäºæž¬å¯èœã§ããå¿ èŠããããŸããã¬ããã³ã¹ã®æŽåæ§ããªããã°ãéçšäžã®éžè±ã¯ãåè¿°ã®äžæŽåãªå®è¡ãã¹ãšåæ§ã«ãäºæž¬äžå¯èœãªé害ãã»ãã¥ãªãã£ã®ã£ããããŸãã¯é ããä¿¡é Œã®é²åºã«ã€ãªãããŸãã å®è¡æåäœåæ.
ã¯ã©ãŠããããã€ããŒéã§ã®ã·ãŒã¯ã¬ããã¢ã¯ã»ã¹ã¢ãã«ã®çµ±å
åã¯ã©ãŠãã¯ãã·ãŒã¯ã¬ããã®ååŸã«ç¬èªã®ã¡ã«ããºã ãå®çŸ©ããŠããŸããAWSã¯Secrets Managerããã®ååŸãæ¿èªããããã«IAMã䜿çšããAzure Key Vaultã¯Azure ADãä»ããããŒã«å²ãåœãŠã䜿çšããGoogle Secret Managerã¯IAMãã€ã³ãã£ã³ã°ã«äŸåããOCIã¯ã³ã³ããŒãã¡ã³ãããŒã¹ã®ããªã·ãŒã䜿çšããŸãããããã®éãã«ãããããŒã ã¯ãããã€ããŒããšã«ã«ã¹ã¿ã ããžãã¯ãäœæããå¿ èŠããããã³ãŒãã®è€éããæ§æã®æ¡æ£ãéçšäžã®è匱æ§ãå¢å€§ããŸããã¯ã©ãŠãéã®äžè²«æ§ãå®çŸããããã®ç¬¬äžæ©ã¯ãã¢ã¯ã»ã¹ã¢ãã«ãçµ±äžããã¢ããªã±ãŒã·ã§ã³ããããã€ããŒã«é¢ä¿ãªãã·ãŒã¯ã¬ããã®ååŸãåäžã®ãã¿ãŒã³ãšããŠæ±ãããã«ããããšã§ãã
çµ±åã«ã¯éåžžãæœè±¡åã¬ã€ã€ãŒããµãŒãã¹ã¡ãã·ã¥æ¡åŒµããŸãã¯ã·ãŒã¯ã¬ãããããŒã«ãŒãé¢äžããŸãããããã®ã·ã¹ãã ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ãªã¯ãšã¹ããé©åãªãããã€ããŒåºæã®APIåŒã³åºãã«å€æããIDãæ€èšŒããã°ããŒãã«ã¢ã¯ã»ã¹ããªã·ãŒãé©çšããŸããããã«ãããAWSåãã«äœæãããã¯ãŒã¯ããŒãã¯ãã³ãŒãã倿ŽããããšãªãAzureãŸãã¯GCPããã·ãŒã¯ã¬ãããã·ãŒã ã¬ã¹ã«ååŸã§ããããã«ãªããŸãããã®ã¢ãããŒãã¯ã ãšã³ã¿ãŒãã©ã€ãºçµ±ååºç€ æœè±¡åã«ãããã¢ããªã±ãŒã·ã§ã³ã¯ãã©ãããã©ãŒã åºæã®è©³çްããä¿è·ãããŸãã
é·æçãªäžè²«æ§ãç¶æããã«ã¯ãã·ãŒã¯ã¬ããã®åœåèŠåãããŒãžã§ã³ç®¡çã«ãŒã«ãã¿ã°ãã¡ã¿ããŒã¿æ§é ãæšæºåããå¿ èŠããããŸããçµ±äžãããã¡ã¿ããŒã¿ããªããã°ãç°ãªãã¯ã©ãŠãã«ããã·ãŒã¯ã¬ãããäžè²«ããŠç£æ»ããããšã¯ã§ããŸãããã°ããŒãã«ãªã·ãŒã¯ã¬ããã¢ã¯ã»ã¹ã¢ãã«ã«ãããã¯ã©ãŠããããã€ããŒãAPIãé²åãããããäŒæ¥ãæ°ãããªãŒãžã§ã³ã«é²åºãããããå Žåã§ããã¯ãŒã¯ããŒããäºæž¬ã©ããã«èªèšŒæ å ±ãååŸããã³ããŒããŒã·ã§ã³ã§ããããã«ãªããŸãã
ã¯ã©ãŠãéã§ã·ãŒã¯ã¬ããã®ããŒããŒã·ã§ã³ãšæå¹æéããªã·ãŒãåæãã
ããŒããŒã·ã§ã³ãšæå¹æéã®ããªã·ãŒã¯ãã¯ã©ãŠããããã€ããŒã«ãã£ãŠå®è£ æ¹æ³ãç°ãªããŸããAWSã¯Lambda颿°ã«ããèªåããŒããŒã·ã§ã³ããµããŒãããAzure Key Vaultã¯ã©ã€ããµã€ã¯ã«èšå®ãéããŠããŒããŒã·ã§ã³ããªã·ãŒãå ¬éããGoogle Secret Managerã¯ããŒãžã§ã³ããŒã«ãªãŒããŒããµããŒãããOCIã¯ããªã·ãŒããŒã¹ã®æå¹æéã䜿çšããŸãããã«ãã¯ã©ãŠãã¯ãŒã¯ããŒãããããã®ã·ãŒã¯ã¬ããã«äŸåããŠããå Žåãããªã·ãŒã®äžäžèŽã«ããããŒããŒã·ã§ã³ã®äžæŽåãçºçããèªèšŒãäžæãããããã€ãã©ã€ã³ãäžæããããããŠã³ã¿ã€ã ãçºçãããããå¯èœæ§ããããŸãã
ããªãããé²ãã«ã¯ãçµç¹ã¯åã¯ã©ãŠãããããã€ããŒåºæã®ã¡ã«ããºã ãçšããŠç¬ç«ããŠå®è£ ããã°ããŒãã«ãªããŒããŒã·ã§ã³ãšæå¹æéã®ãªãºã ã確ç«ããå¿ èŠããããŸããäžå€®ããªã·ãŒã¯ãããŒããŒã·ã§ã³ééãããŒãžã§ã³ä¿ææéãæå¹æéåãæã®ã¢ã¯ã·ã§ã³ã倱å¹åäœãå®çŸ©ããŸãããããŠãã³ã³ãããŒã©ãŒãŸãã¯ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãã€ãã©ã€ã³ããããã®ã«ãŒã«ããã¹ãŠã®ç°å¢ã«é©çšããç£èŠããŸãããã®åæããã»ã¹ã¯ãè€éãªã¯ãŒã¯ãããŒã«é©çšãããæšæºåãããã©ã€ããµã€ã¯ã«ã®äžè²«æ§ã«äŒŒãŠããŸãã ããŒã¿ãããŒã¬ããã³ã¹ææ³éäžåãããã«ãŒã«ã«ããã忣ã·ã¹ãã éã§ã®çžéã鲿¢ãããŸãã
çµ±åãããã·ãŒã¯ã¬ããããŒããŒã·ã§ã³æŠç¥ã«ãããã©ã®ç°å¢ã§ãå€ãã·ãŒã¯ã¬ãããä¿æãããããå€ãããŒãžã§ã³ã䜿çšãããããä¿æããªã·ãŒã«éåãããããããšããªããªããŸããããã«ããã«ãã¯ã©ãŠããã€ãã©ã€ã³ã«ãããŠããããããã€ããŒã®å€ãèªèšŒæ å ±ãå¥ã®ãããã€ããŒã®ã¯ããäžæµã§é害ãåŒãèµ·ãããããªãé£éçãªé害ãé²ãã®ã«ã圹ç«ã¡ãŸãã匷åãªåæã«ãããçµç¹ã¯ã·ãŒã¯ã¬ããã«äŸåãããã¹ãŠã®ã¯ãŒã¯ããŒãã®æŽåæ§ãç¶æã§ããŸãã
ã¯ãã¹ã¯ã©ãŠãã¯ãŒã¯ããŒãåãã®ã·ãŒã¯ã¬ãããã§ãã¬ãŒã·ã§ã³ã®å®è£
ã·ãŒã¯ã¬ãããã§ãã¬ãŒã·ã§ã³ãšã¯ãããã¯ã©ãŠãã§èªèšŒãããã¯ãŒã¯ããŒãããé·æçãªèªèšŒæ å ±ãä¿æããããšãªããå¥ã®ã¯ã©ãŠãã«ä¿åãããŠããã·ãŒã¯ã¬ãããååŸã§ããããã«ããããã»ã¹ã§ããããŒãã§ãã¬ãŒã·ã§ã³ãšåæ§ã«ãã·ãŒã¯ã¬ãããã§ãã¬ãŒã·ã§ã³ã¯ãããŒã¯ã³äº€æãOIDCä¿¡é Œé¢ä¿ããŸãã¯IDãæ€èšŒããŠæå°æš©éãé©çšãããããŒã«ãŒåIDãµãŒãã¹ã«äŸåããŸãããã§ãã¬ãŒã·ã§ã³ã¯ããã«ãã¯ã©ãŠãCI/CDãã€ãã©ã€ã³ã忣åãã€ã¯ããµãŒãã¹ããŸãã¯è€æ°ã®ãããã€ããŒã®ã·ãŒã¯ã¬ããã«ã¢ã¯ã»ã¹ããå¿ èŠãããã°ããŒãã«ã«å±éãããã¢ããªã±ãŒã·ã§ã³ã«ãããŠç¹ã«éèŠã§ãã
ã·ãŒã¯ã¬ãããã§ãã¬ãŒã·ã§ã³ã§ã¯ãã¯ã©ãŠãéã®äžæ£ã¢ã¯ã»ã¹ãé²ãããã«ã峿 ŒãªèªèšŒã«ãŒã«ãããŒã¯ã³ã®æå¹æéãããŒã«ãã€ã³ãã£ã³ã°ãé©çšããå¿ èŠããããŸããæ£ããå®è£ ãããŠããã°ãã¯ãŒã¯ããŒãã¯ä»ã®ã¯ã©ãŠãã®èªèšŒæ å ±ãä¿åããããšã¯ãªãã圱é¿ç¯å²ãçž®å°ãããã·ãŒã¯ã¬ããã®é·æçãªæ¡æ£ãé²ãããšãã§ããŸãããã®ã¢ãããŒãã¯ãã»ãã¥ã¢ãã©ã¹ãã¢ããªã³ã°ã®ååãåæ ããŠããŸãã è€éãªçµ±åãšã³ã·ã¹ãã äžè²«ããèªèšŒã«ãããããŸããŸãªãã©ãããã©ãŒã éã§ã®å®å šãªããåããä¿èšŒãããŸãã
ãã§ãã¬ãŒã·ã§ã³ã¯ããµãŒããŒã¬ã¹é¢æ°ãããããžã§ããè€æ°ã®ã¯ã©ãŠãã«ãŸãããã³ã³ããåãããã¿ã¹ã¯ãšãã£ãåçãªã¯ãŒã¯ããŒãããµããŒãããŸãããããã®ã¯ãŒã¯ããŒãã¯æ¥éã«ã¹ã±ãŒã«ããããšãå€ããããé«éã§å®å šãã€ç§»æ€æ§ã®é«ãã·ãŒã¯ã¬ããã¢ã¯ã»ã¹ãæ±ããããŸããé©åãªãã§ãã¬ãŒã·ã§ã³ã«ãããç°å¢åºæã®èªèšŒæ å ±ãäžèŠã«ãªããã»ãã¥ãªãã£ãç ç²ã«ããããšãªããã·ãŒã ã¬ã¹ãªã¯ãã¹ã¯ã©ãŠãéçšãå¯èœã«ãªããŸãã
éäžåã·ãŒã¯ã¬ããã¬ããã³ã¹å±€ã®æ§ç¯
äžå åãããã·ãŒã¯ã¬ããã¬ããã³ã¹ã¬ã€ã€ãŒã¯ããã¹ãŠã®ã¯ã©ãŠãã«ãããå¯èŠæ§ãç£æ»å¯èœæ§ããããŠããªã·ãŒé©çšãå®çŸããŸããã·ãŒã¯ã¬ããã忣åã®ã¯ã©ãŠããã€ãã£ãã·ã¹ãã ã«ä¿åãããŠããå Žåã§ããã¬ããã³ã¹ã¯ã°ããŒãã«ã§ããå¿ èŠããããŸããããã«ã¯ãã·ãŒã¯ã¬ããã®äœæãããŒããŒã·ã§ã³ãã¢ã¯ã»ã¹è©Šè¡ãæå¹æéåãã€ãã³ãã倱å¹åäœã®è¿œè·¡ãå«ãŸããŸããäžå åãããã¬ããã³ã¹ããªããã°ãçµç¹ã¯ã©ã®ã·ãŒã¯ã¬ããã䜿çšãããŠãããã誰ãã¢ã¯ã»ã¹ãããããããã¯ã©ã®ã¯ãŒã¯ããŒããå€ãèªèšŒæ å ±ãèšå®ãã¹ã®ããèªèšŒæ å ±ã«äŸåããŠããããææ¡ã§ããªããªããŸãã
éäžåã«ã¯ããã¹ãŠã®ã¯ã©ãŠããããã€ããŒããã®ãã°ãéçŽããã¡ã¿ããŒã¿ãæ£èŠåããçµ±åãããã¬ããã³ã¹ããã·ã¥ããŒããçæããããšãå«ãŸããŸããããã¯ã ãã«ãç°å¢ãªã¹ã¯æŠç¥ äžè²«æ§ã®ãªãã¬ããŒãã¯ç²ç¹ãçã¿åºããŸããã¬ããã³ã¹ã·ã¹ãã ã¯ãã°ããŒãã«ãªåœåèŠåãä¿æããªã·ãŒãã¢ã¯ã»ã¹å¢çãé©çšããããšã§ããããã€ããŒç°å¢å šäœã§é·æçãªäžè²«æ§ã確ä¿ããŸãã
匷åãªã¬ããã³ã¹ ã¬ã€ã€ãŒã¯ãçµç¹ãã¯ã©ãŠãéç£æ»ãå®è¡ããç°åžžãæ€åºããã·ãŒã¯ã¬ããã®æµåºãé²ããPCI DSSãHIPAAãGDPRãSOC 2 ãªã©ã®ãã¬ãŒã ã¯ãŒã¯ãžã®ã³ã³ãã©ã€ã¢ã³ã¹ãç¶æããã®ã«åœ¹ç«ã¡ãŸããããã«ãããã¢ããªã±ãŒã·ã§ã³ã®æ¡åŒµãã¯ãŒã¯ããŒãã®ç§»åããã£ãŠããã·ãŒã¯ã¬ãã ã¬ããã³ã¹ãäºæž¬å¯èœãã€ç£èŠå¯èœã§ãããäŒæ¥ã®ã»ãã¥ãªãã£ç®æšãšäžèŽããŠããããšãä¿èšŒãããŸãã
ãã«ãã¯ã©ãŠã KMS ã¢ãŒããã¯ãã£ã«ãããã³ã³ãã©ã€ã¢ã³ã¹ãç£æ»å¯èœæ§ãã¬ããã³ã¹ã®ç¢ºä¿
äŒæ¥ãAWSãAzureãGoogle CloudãOCIã«ãŸããã£ãŠäºæ¥ãæ¡å€§ããã«ã€ããäžè²«ããã³ã³ãã©ã€ã¢ã³ã¹ãšç£æ»å¯èœæ§ãç¶æããããšããŸããŸãå°é£ã«ãªã£ãŠããŸããåã¯ã©ãŠããããã€ããŒã¯ãç¬èªã®ãã°èšé²ã»ãã³ãã£ã¯ã¹ãä¿ææéã®ããã©ã«ããã¢ã¯ã»ã¹å¶åŸ¡ã¢ãã«ãã¬ããã³ã¹ããŒã«ãå ¬éããŠããŸãããããã®æ©èœã¯ããããã®ãã©ãããã©ãŒã å ã§ã¯åŒ·åã§ããããã«ãã¯ã©ãŠãã®èгç¹ããèŠããšå€§ããç°ãªããŸããPCI DSSãHIPAAãFFIECãFedRAMPãSOXãGDPRãªã©ã®ã³ã³ãã©ã€ã¢ã³ã¹ãã¬ãŒã ã¯ãŒã¯ã§ã¯ãæå·åããŒãšã·ãŒã¯ã¬ããã®äœæãããŒããŒã·ã§ã³ãã¢ã¯ã»ã¹ã廿£ã倱广¹æ³ã«ã€ããŠçµ±äžãããå šäœåãæ±ããããŠããŸããçµ±äžãããã¬ããã³ã¹æŠç¥ããªããã°ããããã®æŽ»åã¯æçåãããç£æ»ã®ã®ã£ãããéžè±ãçããèŠå¶äœå¶ã®ç¶æãå°é£ã«ãªããŸãããããã®åé¡ã¯ãåè¿°ã®ãã«ãç°å¢ã«ãããäžæŽåã«äŒŒãŠããŸãã ãšã³ã¿ãŒãã©ã€ãºãªã¹ã¯ç®¡ç ççŸãã·ã¹ãã å šäœã®è匱æ§ãšãªãå Žåã
ç£æ»å¯èœæ§ãå®çŸããã«ã¯ãã»ãã¥ãªãã£ããŒã ãã¯ã©ãŠãéã§ã€ãã³ããåéããã ãã§ãªããçžé¢é¢ä¿ã®åæãã€ã³ã·ãã³ã調æ»ãé·æçãªã³ã³ãã©ã€ã¢ã³ã¹ã¬ããŒãäœæãå¯èœã«ããå ±éã¹ããŒãã«æ£èŠåããå¿ èŠããããŸãããã€ãã£ãç£æ»ãã°ã¯ãç²åºŠãåœåèŠåãã€ãã³ãã»ãã³ãã£ã¯ã¹ãç°ãªãå Žåãå€ããããŸããAWS CloudTrailãAzure MonitorãGoogle Cloud Audit LogsãOCI Auditã¯ããããç°ãªãæ§é ã䜿çšããŠãããããã¯ã©ãŠãéã®æŽåæ§ç¢ºä¿ã¯å®¹æã§ã¯ãããŸãããæå·åã¯ãŒã¯ããŒããè€æ°ã®ç°å¢ã«ãŸãããå Žåãçµ±äžãããã¡ã¿ããŒã¿ã«ãŒã«ãäžè²«ããã¿ã°ä»ãããããŠäžå åãããããªã·ãŒã»ã¢ãºã»ã³ãŒãã»ãã¬ãŒã ã¯ãŒã¯ã®é©çšãäžå¯æ¬ ã«ãªããŸãããããã®æŽåæ§ç¢ºä¿æŽ»åã¯ãã¯ã©ãŠãéã§äœ¿çšãããŠããæ£èŠåæŠç¥ãåæ ããŠããŸãã çµ±åã¢ãŒããã¯ãã£ã®åºç€ ã¯ãã¹ãã©ãããã©ãŒã ã®äžè²«æ§ãé·æçãªä¿å®æ§ã決å®ããŸãã
KMSéçšã®ããã®çµ±åãã«ãã¯ã©ãŠãç£æ»èšŒè·¡ã®æ§ç¯
ã¯ã©ãŠãéã§çµ±äžãããç£æ»èšŒè·¡ãäœæããã«ã¯ãåãããã€ããŒã®KMSãã°ãçµ±åãããããã®ã€ãã³ããå ±æã¹ããŒãã«ãããã³ã°ããå¿ èŠããããŸããããã«ãããã»ãã¥ãªãã£ããŒã ã¯è€æ°ã®ç°å¢ã§å®è¡ãããŠããã¯ãŒã¯ããŒãå šäœã«ããã£ãŠããªã¢ã«ã¿ã€ã ç£èŠãç°åžžã®èª¿æ»ãã³ã³ãã©ã€ã¢ã³ã¹æ€èšŒãå®è¡ã§ããŸããããããåã¯ã©ãŠãããã°ã«èšé²ããã€ãã³ã屿§ãç°ãªãããšã課é¡ãšãªã£ãŠããŸããAWSã¯æ£ç¢ºãªåŸ©å·è©Šè¡ãšæå·åã³ã³ããã¹ããèšé²ããAzureã¯ããŒã«ãã¬ãã«ã®èšºææ©èœãæäŸããGoogle Cloudã¯ãããžã§ã¯ãåäœã®KMSã€ãã³ããèšé²ããOCIã¯ã³ã³ããŒãã¡ã³ãåäœã®ã¢ã¯ãã£ããã£ãåºåããŸãã
çµ±åç£æ»å±€ã§ã¯ãéµã¢ã¯ã»ã¹ãããŒããŒã·ã§ã³ã€ãã³ããéå®³ãæš©é倿Žã倱å¹ã¢ã¯ãã£ããã£ãåé¡ããæšæºçãªã€ãã³ãå顿³ãçšããŠããããã®å·®ç°ãæ£èŠåããå¿ èŠããããŸãããã®ã¢ãããŒãã¯ã ã¯ãã¹ã¯ã©ãŠãããŒã¿ãããŒåæ ã·ã¹ãã ã«ãã£ãŠçæãããããŸããŸãªã¡ã¿ããŒã¿ã調æŽããŠãåäœãæ£ç¢ºã«çè§£ããå¿ èŠããããŸãã
ãã°ãæ£èŠåããããšã§ãäŒæ¥ã¯ã¯ã©ãŠãéã®ã€ãã³ããçžé¢ãããçãããã¯ãã¹ãã©ãããã©ãŒã ã¢ã¯ã»ã¹ãã¿ãŒã³ãæ€åºããããéå°ã«äœ¿çšãããŠããéµãèšå®ãã¹ã®ããéµãç¹å®ãããã§ããããã«ãªããŸããçµ±åç£æ»ã¯ãã€ã³ã·ãã³ã察å¿ã«ãããŠç¹ã«éèŠã«ãªããŸãããã«ãã¯ã©ãŠãã¯ãŒã¯ããŒãã§ã¯ãæ»æè ã¯ãããã€ããŒã®ç£æ»ã¬ã€ã€ãŒéã®äžæŽåãç²ç¹ãæªçšããå¯èœæ§ããããŸããããŒã¿ãåäžã®ã¬ããã³ã¹ãã€ãã©ã€ã³ã«çµ±åããããšã§ãçµç¹ã¯ã¯ã©ãŠããå€ç«ããã»ãã¥ãªãã£ã¢ã€ã©ã³ãã«ãªãããšãé²ãããã¹ãŠã®æå·åã€ãã³ããäžå åãããã»ãã¥ãªãã£ããã°ã©ã å ã§å¯èŠåã§ããŸãã
ã¯ã©ãŠãé KMS ã¬ããã³ã¹ã®ããã®ããªã·ãŒã»ã¢ãºã»ã³ãŒãã®å®è£
ããªã·ãŒã»ã¢ãºã»ã³ãŒãã¯ããã«ãã¯ã©ãŠãã¬ããã³ã¹ã確å®ã«å®çŸããæã广çãªæ¹æ³ã®äžã€ãšãªã£ãŠããŸããäŒæ¥ã¯ãåã¯ã©ãŠãã§KMSããªã·ãŒãæåã§èšå®ãã代ããã«ãã»ãã¥ãªãã£ã«ãŒã«ãããŒãžã§ã³ç®¡çãããã³ãŒããšããŠå®çŸ©ããç°å¢å šäœã«èªåçã«é©çšããŸããããã«ããããã©ãããã©ãŒã ã®åäœãå€åããŠãäžè²«æ§ãä¿èšŒãããŸããããªã·ãŒã»ã¢ãºã»ã³ãŒãã»ãã¬ãŒã ã¯ãŒã¯ã¯ãããŒããŒã·ã§ã³ééãIAMãããã³ã°ãéµäœ¿çšã«ãŒã«ãã¡ã¿ããŒã¿æ§é ãåœåèŠåã倱å¹èŠä»¶ã匷å¶é©çšããŸãã
äž»ãªã¡ãªããã¯ãã¬ããã³ã¹ãåçŸå¯èœãã€ãã¹ãå¯èœã«ãªãããšã§ããã€ã³ãã©ã¹ãã©ã¯ãã£ã»ã¢ãºã»ã³ãŒãã»ãã€ãã©ã€ã³ã¯ãæ§æã®ããªãããæ€èšŒããããªã·ãŒã®äžæŽåãæ€åºããã³ã³ãã©ã€ã¢ã³ã¹ã«ãŒã«ã«éåãããããã€ã¡ã³ãã鲿¢ã§ããŸããããã¯ã ã¯ãã¹ãã©ãããã©ãŒã ãªã¹ã¯æŠç¥ èªååãããç£èŠã«ãããããªãããéãã«èç©ãããã®ãé²ããŸãã
ã¬ããã³ã¹ã®é©çšãèªååããããšã§ãçµç¹ã¯ã³ã³ãã©ã€ã¢ã³ã¹éåã«ã€ãªããããšãå€ãããšã©ãŒãçºçããããæäœæ¥ã®ã¿ã¹ã¯ãæé€ã§ããŸãããŸããããªã·ãŒã»ã¢ãºã»ã³ãŒãã¯ç¶ç¶çãªã³ã³ãã©ã€ã¢ã³ã¹ãå®çŸããKMSæ§æãç¶ç¶çã«ç£èŠã»ä¿®æ£ããŸããããã«ãããããŒã ãæ°ããã¯ãŒã¯ããŒããå±éããããæ°ãããªãŒãžã§ã³ã«æ¡å€§ããããæ°ããã¯ã©ãŠããã€ãã£ããµãŒãã¹ãå°å ¥ãããããå Žåã§ããKMSã¬ããã³ã¹ã®çµ±äžæ§ãç¶æãããŸãã匷åãªããªã·ãŒèªååã«ããããã«ãã¯ã©ãŠãKMSã¬ããã³ã¹ã¯ãå€§èŠæš¡ç°å¢ã§ãäºæž¬å¯èœã§èä¹ æ§ã®é«ããã®ã«ãªããŸãã
ç°ãªãã¯ã©ãŠããããã€ããŒéã§ã³ã³ãã©ã€ã¢ã³ã¹ãã¬ãŒã ã¯ãŒã¯ã調æŽãã
åã¯ã©ãŠããããã€ããŒã¯ã³ã³ãã©ã€ã¢ã³ã¹èªèšŒãæšæºã§æäŸããŠããŸãããèŠå¶èŠä»¶ã®è§£éã¯ããããç°ãªããŸããäŸãã°ãAWSãšAzureã§ã¯å ±æè²¬ä»»ã®å¢çãç°ãªã£ãŠå®è£ ãããŠããå ŽåããããŸãããŸããGoogle CloudãšOCIã§ã¯ç£æ»ãã°ãéµä¿æãªãã·ã§ã³ãç°ãªãå ŽåããããŸããçµç¹ããããã®ã¯ã©ãŠããã€ãã£ããªã³ã³ãããŒã«ã«äŸåããŠããå Žåãçµ±äžãããã¬ããã³ã¹ã¢ãã«ãéããŠæŽåæ§ã確ä¿ããªãéããã³ã³ãã©ã€ã¢ã³ã¹ã«äžè²«æ§ããªããªããŸãã
ã¯ã©ãŠãéã®ã³ã³ãã©ã€ã¢ã³ã¹èª¿æŽã¯ããããã€ããŒåºæã®æ©èœãå ±æã³ã³ãã©ã€ã¢ã³ã¹ãããªãã¯ã¹ã«ãããã³ã°ããããšããå§ãŸããŸãããã®ãããªãã¯ã¹ã¯ãã©ã®ã³ã³ãããŒã«ããã€ãã£ãã«é©çšãããã©ã®ã³ã³ãããŒã«ãè£è¶³çãªãã¬ãŒã ã¯ãŒã¯ãå¿ èŠãšããã©ã®ã³ã³ãããŒã«ãäžå 管çãããå¿ èŠãããããç¹å®ããŸããå€ãã®çµç¹ã¯ãã¯ã©ãŠãéã®ã³ã³ãã©ã€ã¢ã³ã¹èª¿æŽã«ãããŠããã®ãããã³ã°ã¢ãããŒããæ¡çšããŠããŸãã çµ±åã¬ããã³ã¹ãã¿ãŒã³ ãã©ãããã©ãŒã ã®äžæŽåãè§£æ¶ããå¿ èŠããã倿§ãªç°å¢ã«ããã£ãŠã
çµ±åã³ã³ãã©ã€ã¢ã³ã¹ã«ãããæå·åãIDãã¢ã¯ã»ã¹ãããŒããŒã·ã§ã³ãç£æ»èŠä»¶ããããã€ããŒãåããäžè²«ããŠé©çšãããŸãããŸããç£æ»æ åœè ããã«ãã¯ã©ãŠãæå·åã¢ãŒããã¯ãã£ãæ¥çèŠä»¶ãæºãããŠãããã©ãããæ€èšŒããã®ã«ã圹ç«ã¡ãŸãããã¬ãŒã ã¯ãŒã¯ã飿ºãããããšã§ãçµç¹ã¯ãããã¯ã©ãŠãã®ã¬ããã³ã¹ãä»ã®ã¯ã©ãŠããããç·©ããªã£ãå Žåã«æ»æè ãæªçšããééãæé€ã§ããŸãã
KMSæ§æã®ãªã¢ã«ã¿ã€ã ã¬ããã³ã¹ãšããªããæ€åºã®ç¢ºç«
ããªã·ãŒã»ã¢ãºã»ã³ãŒããšçµ±åç£æ»ãå°å ¥ããŠããããªããã¯äŸç¶ãšããŠå€§ããªèª²é¡ã§ããã¯ã©ãŠããããã€ããŒã¯æ¥éã«é²åããæ°ããKMSæ©èœãIAMã®åŒ·åããã°èšé²ã®æåãªã©ãå°å ¥ããŠããŸããããŒã ã¯æå³ããããŒã®æš©éã倿ŽããããããŒããŒã·ã§ã³èšå®ã倿Žããããã¡ã¿ããŒã¿ã®æŽåæ§ã厩ãããããå¯èœæ§ããããŸããç©æ¥µçãªããªããæ€åºããªããã°ããããã®å€æŽã¯æ°ã¥ãããã«èç©ãããã¬ããã³ã¹æŠç¥ãæãªããŸãã
ãªã¢ã«ã¿ã€ã ã®ããªããæ€åºæ©èœã¯ãè€æ°ã®ãããã€ããŒéã§ãæãŸããç¶æ ãšå®éã®KMSæ§æãç¶ç¶çã«æ¯èŒããŸããå·®ç°ãçºçããå Žåã¯ã峿ã®ä¿®åŸ©ã¢ã¯ã·ã§ã³ãŸãã¯ã»ãã¥ãªãã£ã¢ã©ãŒããããªã¬ãŒãããŸãããã®ããã¢ã¯ãã£ããªã¬ããã³ã¹ã¢ãã«ã¯ã ããŒã¿ãããŒå¯èŠåãã¬ãŒã ã¯ãŒã¯ ã·ã¹ãã ãäºæ³ãããåäœããã®éžè±ãèªåçã«æ€åºããŸãã
ããªããæ€åºã«ãããã¬ããã³ã¹å質ã«ãããŠç°åžžå€ãšãªãã¯ã©ãŠããååšããªãããšãä¿èšŒãããŸãããŸããç¶ç¶çã«æ€èšŒãããã³ã³ãã©ã€ã¢ã³ã¹ç¶æ ãç¶æããããšã§ãç£æ»æºåæéãççž®ããŸãããªã¢ã«ã¿ã€ã ã®ããªããæ€åºãé©åã«å®è£ ããããšã§ããã«ãã¯ã©ãŠãKMSã¬ããã³ã¹ã¯ãæŽåæ§ã倱ãããšãªãç°å¢ã®å€åã«é©å¿ã§ããèªå·±ä¿®åŸ©åã®ã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ãžãšé²åããŸãã
SMART TS XL ãã«ãã¯ã©ãŠã KMS åã: äŸåé¢ä¿ãããã³ã°ãããªã·ãŒããªããæ€åºãä¿¡é Œã§ããæå·åã¯ãŒã¯ãããŒ
çµç¹ãAWSãAzureãGoogle CloudãOCIãžãšæ¡å€§ããã«ã€ããäžè²«ããæå·åããªã·ãŒãéµã®äŸåé¢ä¿ãã·ãŒã¯ã¬ããã¯ãŒã¯ãããŒããããŠKMSããŒã¹ã®ã¢ã¯ã»ã¹ãã¿ãŒã³ãç¶æããè€éãã¯é£èºçã«å¢å€§ããŸãããã«ãã¯ã©ãŠãã¢ãŒããã¯ãã£ã§ã¯ãé ããäŸåé¢ä¿ãææžåãããŠããªãéµãã¹ãäžè²«æ§ã®ãªãIAMãããã³ã°ããããŠç°å¢éã§åŸ®åŠã«ç°ãªãæå·ååäœãèç©ãããããšããããããŸãããããã®äžæŽåã¯ãã·ã¹ãã 忢ãã³ã³ãã©ã€ã¢ã³ã¹ã®ã£ããããããã¯ã¯ã©ãŠãéã®åŸ©å·åãšã©ãŒãåŒãèµ·ãããŸã§ãã»ãšãã©ç®ã«èŠããªããŸãŸã§ãã SMART TS XL äŒæ¥ããããã®é ããKMSã€ã³ã¿ã©ã¯ã·ã§ã³ãæããã«ãããããããã©ãããã©ãŒã éã§æå·åã¯ãŒã¯ãããŒãçµ±åããããã«å¿ èŠãªã¢ãŒããã¯ãã£ã®å¯èŠæ§ãæäŸããŸããç°å¢éã®äŸåé¢ä¿ãããã³ã°æ©èœã¯ã ããŒã¿ãããŒè§£æææ³ããã«ãããå€§èŠæš¡ã§é²åããã³ãŒãããŒã¹å šäœã§ã®æå·åãšããŒã¢ã¯ã»ã¹ã®åäœã远跡ããã®ã«æé©ã§ãã
å¯èŠæ§ãè¶ ããŠã SMART TS XL ããªã·ãŒã®éžè±ãèšå®ãã¹ãIAMã®äžæŽåããããŠæéã®çµéãšãšãã«ã¯ã©ãŠãå šäœã«åºããå¯èœæ§ã®ããããŒã©ã€ããµã€ã¯ã«ã®ç°åžžãç¹å®ããŸãããã«ãã¯ã©ãŠãKMSã¬ããã³ã¹ã«ã¯ç¶ç¶çãªèª¿æŽãå¿ èŠã§ãããå€ãã®çµç¹ã¯æåç£æ»ããã©ãããã©ãŒã åºæã®ããŒã«ã«äŸåããŠãããå šäœåã®äžéšããææ¡ã§ããŸããã SMART TS XLã»ãã¥ãªãã£ããŒã ã¯ãéµã®äœ¿çšãããŒããŒã·ã§ã³ã¯ãŒã¯ãããŒãã·ãŒã¯ã¬ããã®ååŸãã¯ã©ãŠãéã®ã¢ã¯ã»ã¹èªèšŒã«ã€ããŠãäžè²«ãããã¿ãŒã³ãå¯èŠåãæ€èšŒãé©çšã§ããŸããããã¯ããã«ããã©ãããã©ãŒã ã¬ããã³ã¹ã®ååãšå¯æ¥ã«é£æºããŠããŸãã äŒæ¥ãªã¹ã¯æŠç¥å éšã®äžè²«æ§ãé·æçãªå埩åãæ±ºå®ããŸãã SMART TS XL ã¯ãŒã¯ããŒãããã«ãã¯ã©ãŠãç°å¢éã§ç§»è¡ããªãã¡ã¯ã¿ãªã³ã°ãæ¡åŒµãããå Žåã§ããæå·åã®æŽåæ§ãç¶æãããããšãä¿èšŒããŸãã
ã¯ã©ãŠãéã®ããŒäŸåé¢ä¿ãšæå·åãããŒã®èªåãããã³ã°
å€§äŒæ¥ã§ã¯ãKMSæäœãã·ãŒã¯ã¬ããååŸãããŒãæå·åããªããã£ãã«æé»çã«äŸåããã³ãŒããã¹ã®æ°ãéå°è©äŸ¡ããŠããããšããããããŸãããããã®äŸåé¢ä¿ã¯ãAPIãSDKåŒã³åºããæ§æãã¡ã€ã«ãç°å¢å€æ°ãã³ã³ããå®çŸ©ãCI/CDãã€ãã©ã€ã³ã«ãŸã§åã³ãŸãã詳现ãªåæãè¡ããªããšãé ããæå·ååç §ãæ°ã¥ãããªããŸãŸèç©ãããŠããŸããŸãã SMART TS XL ãããã®äŸåé¢ä¿ããã¹ãŠã®ã¯ã©ãŠãã«ããã£ãŠèªåçã«ãããã³ã°ããã©ã®ã¢ããªã±ãŒã·ã§ã³ãã©ã®ãããã€ããŒã«ããŒãèŠæ±ããŠãããããšã³ãããŒãæå·åãã©ãã§é©çšãããŠããããç°å¢éã§ã·ãŒã¯ã¬ãããã©ã®ããã«ååŸãããããå ¬éããŸãã
ãã®ãããã³ã°ã¯ãäžæµã®é害ãé²ãããã«äžå¯æ¬ ã§ããäŸãã°ãAWS ã®ããŒããŒã·ã§ã³ããªã·ãŒã®å€æŽã¯ãå ±æããŒã¿ããŒã«äŸåãã Azure ã GCP ã§å®è¡ãããŠããã¯ãŒã¯ããŒãã«éæ¥çã«åœ±é¿ããå¯èœæ§ããããŸããå¯èŠæ§ããªããã°ãããŒã ã¯æ¬çªç°å¢ã§åŸ©å·ãšã©ãŒãçºçãããšãã«åããŠéå®³ã«æ°ä»ãããšã«ãªããŸãã SMART TS XLã®KMS察å¿åæãšã³ãžã³ã¯ããããã®é¢ä¿æ§ãèŠèŠåããŸããããã¯ã çµ±åãããã³ã°ã®åºç€æé»çãªäŸåé¢ä¿ãèŠéãããªãããã«ããŸãã
ã¯ã©ãŠãéã®äŸåé¢ä¿ã®å¯èŠæ§ãäžå åããããšã§ã SMART TS XL ãšã³ãžãã¢ãªã³ã°ããŒã ã¯ãç§»è¡èšç»ã®æ€èšŒã圱é¿ç¯å²ã®äºæž¬ãã¢ãŒããã¯ãã£äžã®ç²ç¹ã®åé¿ãå¯èœã«ãªããŸããããã¯ãæå·åã®äžè²«æ§ã蚌æå¯èœãã€ç£æ»å¯èœã§ããããšãæ±ããããèŠå¶ç£æ¥ã«ãšã£ãŠç¹ã«éèŠã«ãªããŸãã SMART TS XL ããŒã ãã¯ãã¹ã¯ã©ãŠãæäœãäžå®å®ã«ããå¯èœæ§ã®ãã倿Žãè¡ãåã«ããã¹ãŠã®ããŒãã¹ãã·ãŒã¯ã¬ãã ãããŒãæå·åã®äŸåé¢ä¿ãå®å šã«ãããã³ã°ãããŠããããšã確èªããŸãã
ã¯ã©ãŠãå šäœã§ã®ããªã·ãŒããªãããšKMSã®èª€èšå®ã®æ€åº
ããªã·ãŒã®éžè±ã¯ããã«ãã¯ã©ãŠãKMSã¬ããã³ã¹ã«ãããæå€§ã®èª²é¡ã®äžã€ã§ããéµã®ããŒããŒã·ã§ã³ééãç°ãªã£ãããIAMããªã·ãŒã忣ããããã¿ã°ã®æŽåæ§ã倱ãããããã·ãŒã¯ã¬ããã«å€ãããŒãžã§ã³ãèç©ããããããå¯èœæ§ããããŸããæéã®çµéãšãšãã«ãç°å¢ã®æŽåæ§ã厩ããã³ã³ãã©ã€ã¢ã³ã¹éåãçºçããããã¢ããªã±ãŒã·ã§ã³ã®ã¯ãŒã¯ããŒãã«æ¯éãçãããããŸãã SMART TS XL ãã¹ãŠã®ã¯ã©ãŠãã«ããã£ãŠ KMS ããã³ã·ãŒã¯ã¬ããé¢é£ã®æ§æãç¶ç¶çã«åæããéçšäžã®ãªã¹ã¯ã«ãªãåã«äžæŽåã匷調衚瀺ããŸãã
ããŒããŒã·ã§ã³ééã®äžäžèŽãæå¹æéã«ãŒã«ã®äžäžèŽãIAMãã€ã³ãã£ã³ã°ã®éå°ãªèš±å¯ãå€ç«ããããŒããŒãžã§ã³ãéæšæºã®åœåèŠåãæªäœ¿çšãŸãã¯ã·ã£ããŠãããã·ãŒã¯ã¬ãããæ€åºããŸãããã®ã¬ãã«ã®æ€åºã¯ãåè¿°ã®ããã¢ã¯ãã£ããªããªããèå¥ãšé¡äŒŒããŠããŸãã ã¯ãã¹ãã©ãããã©ãŒã ã¬ããã³ã¹ã®æŽå¯æãŸããããªã·ãŒç¶æ ãšå®éã®æ§æãæ¯èŒããããšã«ããã SMART TS XL é·æçãªçžéãé²ãããã¹ãŠã®ç°å¢ãçµ±äžãããã»ãã¥ãªã㣠ã«ãŒã«ã«æºæ ããããšãä¿èšŒããŸãã
SMART TS XL ãŸããæšæºã¿ã°ä»ããã¡ã¿ããŒã¿ã®æŽåãããªã·ãŒã»ã¢ãºã»ã³ãŒãèŠä»¶ãªã©ãçµç¹å šäœã«ããããã¿ãŒã³ãé©çšããããšãã§ããŸããç¶ç¶çãªç£èŠã«ãããäŒæ¥ã¯ããªã·ãŒã®éžè±ãæ°ã¥ããªããã¡ã«èç©ãããããšãé²ãããã«ãã¯ã©ãŠãæå·åã¯ãŒã¯ãããŒã®å®å šæ§ãäžè²«æ§ãã³ã³ãã©ã€ã¢ã³ã¹ãç¶æã§ããŸãã
KMS ã¢ã¯ã»ã¹ã®ã¯ãã¹ã¯ã©ãŠã IAM ãšä¿¡é Œå¢çã®æ€èšŒ
AWSãAzureãGoogle Cloud éã® IAM ã®éãããããŒã¢ã¯ã»ã¹ã®äžè²«æ§ã®ãªããæå³ããªãæš©éæ¡åŒµã®æ ¹æ¬åå ãšãªãããšããããããŸãã SMART TS XL ãããããããã€ããŒã®ã¢ã€ãã³ãã£ãã£ãããã³ã°ãšæš©éæ§é ãåæããä¿¡é Œå¢çãã°ããŒãã«ããªã·ãŒãšäžèŽããŠããªãç®æãæããã«ããŸããããŒã«ã«éå°ãªæš©éãä»äžãããŠããå ŽåãããŒã¯ã³ã®æ³å®ãéžè±ããŠããå Žåããããã¯ã¯ã©ãŠãéã®ã¢ã¯ã»ã¹ãã¹ã«ãã£ãŠé ãããšã¹ã«ã¬ãŒã·ã§ã³ãçºçããŠããå Žåãªã©ãæããã«ããŸãã
ãããã®æŽå¯ã¯ã ã©ã³ã¿ã€ã ã³ãŒããã¹èª¿æ»é ããé¢ä¿ãã·ã¹ãã ã®åäœã«åœ±é¿ãäžããŸãã SMART TS XL æš©éã®äžäžèŽãäžè²«æ§ã®ãªãããŒã«äŒæã倱å¹ã«ãŒã«ã®æ¬ èœããããŸããªæš©éç¶æ¿ãªã©ã® IAM ç°åžžãæ€åºããŸãã
ã¯ã©ãŠãéã§IAMã®äžè²«æ§ãæ€èšŒããããšã§ã SMART TS XL ã¯ã©ãŠãéã®KMSéçšãæå°æš©éã®ååã«åŸãããšãä¿èšŒããŸããããã«ãããããŒã ãè€æ°ã®ç°å¢ã«ã¯ãŒã¯ããŒããå±éããéã«ãIDã®éžè±ãæš©éã®äžæŽåãæå·åæš©éã®å¶çºçãªæ¡åŒµãšãã£ããªã¹ã¯ããçµç¹ãä¿è·ããŸãã
æå·åã¯ãŒã¯ãããŒã®å€æŽãæ¬çªç°å¢ã«åœ±é¿ãäžããåã«ã·ãã¥ã¬ãŒã·ã§ã³ãã
ã®äžã€ SMART TS XLã®æã䟡å€ããæ©èœã¯ãã¯ã©ãŠãå šäœã§ã®æå·å倿Žã®åœ±é¿ããå°å ¥åã«ã·ãã¥ã¬ãŒãã§ããããšã§ããäŒæ¥ãããŒããŒã·ã§ã³é »åºŠã®å€æŽãKMSçµ±åã©ã€ãã©ãªã®å€æŽãã·ãŒã¯ã¬ããã¹ãã¬ãŒãžã®åæ§ç¯ãããŒã¿ãã€ãã©ã€ã³ã®ç§»è¡ãªã©ãèšç»ããŠããå Žåã§ãã SMART TS XL ãããã®å€æŽãäŸåããã¯ãŒã¯ããŒãã«ã©ã®ããã«åœ±é¿ããããäºæž¬ã§ããŸãã
ã·ãã¥ã¬ãŒã·ã§ã³ãšã³ãžã³ã¯ãã¯ã©ãŠãéã®ããŒãã¹ãäŸåé¢ä¿ãã§ãŒã³ãã©ã€ããµã€ã¯ã«èŠä»¶ãã·ãŒã¯ã¬ããã®ã¢ã¯ã»ã¹ãã¿ãŒã³ãè©äŸ¡ããé害ãçºçããå¯èœæ§ã®ããå Žæãç¹å®ããŸããããã¯ã ããŒã¿ãããŒäžè²«æ§ãã¬ãŒã ã¯ãŒã¯ããã«ãããããŒã ã¯åé¡ããŠãŒã¶ãŒã«å°éãããã£ãšåã«ãããäºæž¬ã§ããããã«ãªããŸãã
ã·ãã¥ã¬ãŒã·ã§ã³ãå°å ¥ããããšã§ãçµç¹ã¯ååž°ãå°å ¥ããããšãªããæ°ããæå·åææ³ãæ¡çšããããããŒãããªã¢ã«ãç§»è¡ããããã¯ã©ãŠãéã®ã¯ãŒã¯ãããŒããªãã¡ã¯ã¿ãªã³ã°ããããæ°ãããªãŒãžã§ã³ã«æ¡åŒµãããããããšãã§ããŸãã SMART TS XL 倿Žãæ€èšŒãã忢ãé²ããå€§èŠæš¡ãªæå·åã®å®å®æ§ã匷åããæ©æèŠåã·ã¹ãã ã«ãªããŸãã
ãã«ãã¯ã©ãŠã KMS ã¯ãŒã¯ãããŒã«ãããããã©ãŒãã³ã¹ãã¬ã€ãã³ã·ãä¿¡é Œæ§ã®ç¶æ
çµç¹ãè€æ°ã®ã¯ã©ãŠããããã€ããŒã«ãŸããã£ãŠæå·åãã·ãŒã¯ã¬ãã管çãKMSããŒã¹ã®èªèšŒãæ¡åŒµããã«ã€ããããã©ãŒãã³ã¹ãšä¿¡é Œæ§ã¯éèŠãªæžå¿µäºé ãšãªããŸããåã¯ã©ãŠãã§ã¯ã埩å·ãéµååŸããšã³ãããŒãæå·åãIAMããŒã¯ã³æ€èšŒã®ã¬ã€ãã³ã·ç¹æ§ãç°ãªããŸããã¯ãŒã¯ããŒãããªã¢ãŒãKMSãµãŒãã¹ãšããåãããããè€æ°ã®ãªãŒãžã§ã³ã«ãŸããã£ãŠã·ãŒã¯ã¬ãããååŸãããããå Žåãã¬ã€ãã³ã·ã®å°ããªå€åãéãªããé床äœäžããžãã¿ãŒããããã¯é£éçãªã¿ã€ã ã¢ãŠããåŒãèµ·ãããŸãããã«ãã¯ã©ãŠãã¯ãŒã¯ããŒãã§ã¯ãKMSæäœããç°ãªãæå·åããã¯ãšã³ããAPIã¬ã¹ãã³ã¹ä¿èšŒãæã€ãããã€ããŒãŸãã¯ãªãŒãžã§ã³ããçºä¿¡ããããšããçç±ã ãã§ãããã©ãŒãã³ã¹ã®äžè²«æ§ãæãªãããå¯èœæ§ããããŸããããããããã©ãŒãã³ã¹ã®äžè²«æ§ã®ãªãã¯ã ã·ã¹ãã ã¬ãã«ã®ããã©ãŒãã³ã¹ã®ããã«ãã㯠å°ããªéå¹çæ§ãäžæµã«å€§ããªåœ±é¿ãåãŒããŸãã
æå·åã¯ãŒã¯ããŒãã®æ¡å€§ã«äŒŽããä¿¡é Œæ§ã¯ããã©ãŒãã³ã¹ãšåæ§ã«éèŠã«ãªããŸãããã«ãã¯ã©ãŠãKMSã¢ãŒããã¯ãã£ã§ã¯ããããã€ããŒã®åæ¢ããããã¯ãŒã¯ã®åæããããã¯ãªãŒãžã§ã³ã®ãã§ã€ã«ãªãŒããŒãçºçããå Žåã§ããéµãžã®ã¢ã¯ã»ã¹ã確ä¿ãããªããã°ãªããŸãããåé·æ§ããã§ã€ã«ãªãŒããŒãèæ ®ããéµãã¹ããããŠé©åãªãã£ãã·ã¥æŠç¥ããªããã°ãã¯ãŒã¯ããŒãã¯åäžã®KMSãšã³ããã€ã³ãã«å¯çµåãããé ããåäžé害ç¹ãçºçããå¯èœæ§ããããŸããåæ§ã«ããã©ã€ããªãªãŒãžã§ã³ã§ããŠã³ã¿ã€ã ãçºçãããšãã·ãŒã¯ã¬ããååŸãã€ãã©ã€ã³ãããŒã¯ã³æ€èšŒãããŒã忢ããå¯èœæ§ããããŸãããããã®é害ã¢ãŒãã¯ãå³1ã§æããã«ãªã£ãé ããå®è¡ãã¹ã«äŒŒãŠããŸãã å®è¡æåäœåæ äºæãã¬äŸåé¢ä¿ã¯ãã¹ãã¬ã¹äžã§ã®è匱æ§ãçã¿åºããŸããé«å¯çšæ§ãç¶æããã«ã¯ãåé·æ§ãèæ ®ããèšèšãæå·åãããªã¢ã«ã®äºåçæããããŠãã¹ãŠã®ã¯ã©ãŠãéã§ã®ãã§ã€ã«ãªãŒããŒãã¿ãŒã³ã®æŽåãå¿ èŠã§ãã
ã¯ã©ãŠããããã€ããŒéã§ã®äœé å»¶æå·åã¯ãŒã¯ãããŒã®èšèš
äœã¬ã€ãã³ã·ã®æå·åã¯ãŒã¯ãããŒã§ã¯ãå¯èœãªéãKMSã®çŽæ¥åŒã³åºããæå°éã«æããå¿ èŠããããŸããKMSãåºç€ãšããæäœã¯å®å šã§ãããããŒã«ã«æå·åæäœãããé ããªããŸããé »ç¹ãªæå·åãŸãã¯åŸ©å·åã®åŒã³åºããå¿ èŠãšããé«ããªã¥ãŒã ãµãŒãã¹ã§ã¯ãäžè²«ããããã©ãŒãã³ã¹ãç¶æããããã«ããšã³ãããŒãæå·åãããŒã«ã«ããŒã¿ããŒãã£ãã·ã¥ãããã³ãªãŒãžã§ã³KMSãšã³ããã€ã³ããæ¡çšããå¿ èŠããããŸããAWS KMSãAzure Key VaultãGoogle Cloud KMSã¯ããããããªãŒãžã§ã³ããã£ã¢ãããã³äœ¿çšã¢ãŒãã«å¿ããŠç°ãªãã¬ã€ãã³ã·ãããã¡ã€ã«ãæäŸããŸãã
ã¯ã©ãŠãéã§ããŒã¿ãåæããã¢ããªã±ãŒã·ã§ã³ã¯ããããã¯ãŒã¯é å»¶ãäºæž¬äžå¯èœãªã¬ã€ãã³ã·ãããããã¯ã©ãŠãéKMSåŒã³åºããåé¿ããå¿ èŠããããŸãã代ããã«ãã¯ãŒã¯ããŒãã¯åã¯ã©ãŠãã®ãã¡ã€ã³å ã§ããŒã«ã«ããŒãŸãã¯ãã£ãã·ã¥ãããããŒã¿ããŒã䜿çšããŠããŒã¿ã埩å·ããã³åæå·åããå¿ èŠããããŸãããã®æŠç¥ã¯ã ã³ãŒãå¹çã®æ¹å ãªãŒããŒããããæé€ããããã«èšç®ãããŒã¿ ãã¹ã®è¿ãã«ç§»åããŸãã
äœã¬ã€ãã³ã·èšèšã¯ãåæå®è¡ãèæ ®ããããŒãªã¯ãšã¹ãã®ã¹ã±ãžã¥ãŒãªã³ã°ãäžæçãªããŒã¯ã³çæããããŠãã«ãã¯ã©ãŠãKMSã¿ã€ã ã¢ãŠãã«æé©åãããå詊è¡ã¢ã«ãŽãªãºã ã«ãäŸåããŠããŸããé©åã«å®è£ ãããŠããã°ãã¯ãŒã¯ããŒããã¯ã©ãŠãéã§æ¡å€§ããŠããæå·åã¯ãŒã¯ãããŒã¯ç·åœ¢ã«æ¡åŒµã§ããŸãã
ãšã³ãããŒãæå·åã䜿çšããŠã¯ã©ãŠãéã®KMSã©ãŠã³ãããªãããåæžãã
ãšã³ãããŒãæå·åã¯ãKMSã®å埩çãªæäœã®å¿ èŠæ§ãå€§å¹ ã«åæžããŸãããã¹ãŠã®ã³ã³ãã³ããã¯ã©ãŠãKMSã§çŽæ¥æå·åããã®ã§ã¯ãªããã¢ããªã±ãŒã·ã§ã³ã¯ããŒã¿ããŒãäžåºŠèŠæ±ãããããå®å šã«ãã£ãã·ã¥ããŠã髿§èœãªæå·åæäœã«ç¹°ãè¿ã䜿çšããŸããããã«ããããã«ãã¯ã©ãŠãç°å¢ã§ã¯ã³ã¹ããšé床ãå¢å€§ãããKMSã®å埩çãªåŒã³åºãã«ããã¬ã€ãã³ã·ãšã³ã¹ããåæžãããŸãã
ãšã³ãããŒãæå·åã¯ããŒã¿æå·åãšéµç®¡çãåé¢ãããããã¯ãŒã¯ããŒãã®å¯æ¬æ§ãåäžããŸããã¯ãŒã¯ããŒããå¥ã®ã¯ã©ãŠãã«ç§»è¡ããå Žåã§ããé¢é£ããKMSããããŒã¿éµãååŸããŠåŸ©å·ã§ããéããã³ã³ãã³ãã埩å·ã§ããŸããããã¯ã çµ±åäžè²«æ§ãã¬ãŒã ã¯ãŒã¯ ã³ã¢ããžãã¯ã¯ãã©ãããã©ãŒã åºæã®è©³çްããåé¢ããããŸãŸã§ãã
ãšã³ãããŒãæå·åã¯ã忣åæãã€ãã©ã€ã³ãå€§èŠæš¡ããŒã¿ç§»åãã€ãã³ãããªãã³ã¢ãŒããã¯ãã£ã«ãäžå¯æ¬ ã§ããåæKMSåŒã³åºããžã®äŸåãæžããããšã§ããšã³ãããŒãæå·åã¯ãŠãŒã¶ãŒåŽã®ã¬ã€ãã³ã·ãã¹ã«ãŒãããããããŠã·ã¹ãã ã¬ãã«ã®å®å®æ§ãåäžãããŸãã
ãã«ãã¯ã©ãŠã KMS ã¢ãŒããã¯ãã£å šäœã§é«å¯çšæ§ãšãã§ã€ã«ãªãŒããŒã確ä¿ãã
ä¿¡é Œæ§ã®é«ããã«ãã¯ã©ãŠãKMSã¢ãŒããã¯ãã£ã¯ãã·ã¹ãã 忢ããªãŒãžã§ã³é害ãAPIã¹ããããªã³ã°ã€ãã³ããã¯ã©ãŠã鿥ç¶ã®åé¡ãªã©ã«å¯Ÿå¿ããå¿ èŠããããŸããKMSãµãŒãã¹ã¯é«ãèé害æ§ãåããŠããŸããããããã¯ãŒã¯ç¶æ³ãIAMããŒã¯ã³ãµãŒãã¹ããããã€ããŒåºæã®APIã¯ã©ãŒã¿ãªã©ãæ§ã ãªèŠå ã«äŸåããŸãããã©ã€ããªKMSãšã³ããã€ã³ããå©çšã§ããªããªã£ãå Žåã代æ¿ãã¹ãååšããªãéããåæåŸ©å·ã«äŸåããã¯ãŒã¯ããŒãã¯å³åº§ã«æ©èœããªããªãå¯èœæ§ããããŸãã
é«å¯çšæ§ãå®çŸããã«ã¯ãåé·åãããKMSãšã³ããã€ã³ãããã§ã€ã«ãªãŒããŒå¯Ÿå¿ã¯ã©ã€ã¢ã³ãã©ã€ãã©ãªããããŠæå·åæœè±¡åã¬ã€ã€ãŒã«çµã¿èŸŒãŸãããã©ãŒã«ããã¯ããžãã¯ã®çµã¿åãããå¿ èŠã§ããã¯ãŒã¯ããŒãã«ãã£ãŠã¯ãã»ã«ã³ããªããŒããããã€ããŒéã§ã®ãã©ãŒãªã³ã°ãããããŒããããã¯ãã©ãŒã«ããã¯åŸ©å·ååœä»€ãå¿ èŠã«ãªãå ŽåããããŸãããããã®ãã§ã€ã«ãªãŒããŒæŠç¥ã¯ã è€æ°ç°å¢ãªã¹ã¯è»œæž åé·æ§ãšåé¢ã«ããé£éçãªåœ±é¿ã鲿¢ããŸãã
äŒæ¥ã¯ã·ãŒã¯ã¬ããã®ãã§ã€ã«ãªãŒããŒã«ã€ããŠãèšç»ããå¿ èŠããããŸãããããããã€ããŒã«ä¿åãããŠããã·ãŒã¯ã¬ããã¯ããµãŒãã¹ã®ç¶ç¶æ§ã確ä¿ããããã«ãå¥ã®ã¯ã©ãŠãã«è€è£œãŸãã¯åæããå¿ èŠããããŸãããã§ã€ã«ãªãŒããŒããã»ã¹ã¯èªååãããå®å šã§ãç·æ¥æã«å€ãèªèšŒæ å ±ã埩å·ãããããšãé²ããããããŒããŒã·ã§ã³ããªã·ãŒã«æºæ ããŠããå¿ èŠããããŸãã
ã¯ã©ãŠãå šäœã®ããã©ãŒãã³ã¹ã䜿çšãã¿ãŒã³ãKMS ãã«ã¹ ã¡ããªãã¯ã®ç£èŠ
ãã«ãã¯ã©ãŠãKMSã¯ãŒã¯ãããŒã«ãããŠããã©ãŒãã³ã¹ãšä¿¡é Œæ§ãç¶æããã«ã¯ãã¢ãã¿ãªã³ã°ãäžå¯æ¬ ã§ããåãããã€ããŒã¯ãã¢ãã¿ãªã³ã°ãã©ãããã©ãŒã ãéããŠããã«ã¹ã¡ããªã¯ã¹ãã¹ããããªã³ã°ã€ã³ãžã±ãŒã¿ãŒããšã©ãŒã³ãŒããã¬ã€ãã³ã·ã·ã°ãã«ãéä¿¡ããŸããAWSã¯CloudWatchãšé£æºããAzureã¯Monitorãšé£æºããŠããŸããGoogle Cloudã¯Cloud MonitoringãéããŠã¡ããªã¯ã¹ãå ¬éããOCIã¯ãã¬ã¡ããªãµãŒãã¹ãéããŠVaultã¡ããªã¯ã¹ãæäŸããŠããŸãã
ãããããããã®ææšã¯åœåãæ§é ããããŠã»ãââã³ãã£ã¯ã¹ãç°ãªããŸããçµ±äžãããå¯èŠæ§ãç¶æããããã«ã¯ãçµç¹ã¯ããããéçŽããå ±æããã·ã¥ããŒãã«æšæºåããå¿ èŠããããŸãããã®æšæºåãããå¯èŠæ§ã¯ãåè¿°ã®ãã«ãç°å¢çµ±åãã¿ãŒã³ãåæ ããŠããŸãã ããŒã¿ãããŒå¯èŠæ§ã¢ãã«ã·ã¹ãã ã®åäœãç·åçã«çè§£ããã«ã¯ã倿§ãªãã¬ã¡ã㪠ã·ã¹ãã ã調æŽããããšãäžå¯æ¬ ã§ãã
çµ±åç£èŠã«ãããããŒã ã¯é床äœäžã®æ€ç¥ãã¹ããããªã³ã°ãªã¹ã¯ã®äºæž¬ãäžé©åãªããŒããŒã·ã§ã³ããªã·ãŒã®èšå®ã®ç¹å®ãã¯ã©ãŠãéã®ç°åžžãªã¢ã¯ã»ã¹ãã¿ãŒã³ã®è¿œè·¡ãå¯èœã«ãªããŸããæ£ç¢ºãªãã¬ã¡ããªã«ãããäŒæ¥ã¯KMSã®äžè²«ããä¿¡é Œæ§ãç¶æãããŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ã®äœäžã«ã€ãªããã¯ã©ãŠãéã®ããã«ããã¯ãè¿ éã«ç¹å®ã§ããŸãã
ã¹ã±ãŒã©ãã«ãªãã«ãã¯ã©ãŠãæå·åéçšã®éåç
çµç¹ãã¯ã©ãŠãã®ãããããªã³ããæ¡å€§ããã«ã€ããæå·éçšã¯ãããããã¯ãŒã¯ããŒãããµããŒããããã¹ã±ãŒã©ãã«ã§å埩åããããã¯ã©ãŠãã«äŸåããªãåºç€ãžãšé²åããå¿ èŠããããŸãããã«ãã¯ã©ãŠãç°å¢ã§ã¯ã倿§ãªæå·åAPIãç°æ©ç𮿷·åšã®ä¿¡é Œå¢çãäžè²«æ§ã®ãªãã©ã€ããµã€ã¯ã«ã»ãã³ãã£ã¯ã¹ãå°å ¥ãããäžè²«ããæŠç¥ã«åºã¥ããŠçµ±åãããŠããªãå Žåãæå·åäœãæçåãããå¯èœæ§ããããŸããã¹ã±ãŒã©ãã«ãªãã«ãŒããªã³ãã§ã¯ãæå·éµã®çæãšäœ¿ç𿹿³ã ãã§ãªããAWSãAzureãGoogle CloudãOCIå šäœã§ã®ããŒããŒã·ã§ã³ããã£ãã·ã¥ç®¡çãã¡ã¿ããŒã¿ã®èª¿æŽãIAMã®é©ç𿹿³ãå®çŸ©ããå¿ èŠããããŸãããããã®ã¢ãŒããã¯ãã£èŠä»¶ã¯ã ãšã³ã¿ãŒãã©ã€ãºçµ±ååºç€ç°å¢ã远å ããããã³ã«è€éããå¢ããäžè²«æ§ãé·æçãªã¹ã±ãŒã©ããªãã£ã®äžå¿çãªèŠä»¶ã«ãªããŸãã
ã¹ã±ãŒã©ãã«ãªæå·åæäœã«ã¯ãã¢ããªã±ãŒã·ã§ã³ããžãã¯ãDevSecOpsãã€ãã©ã€ã³ãKMSãããã€ããŒããããŠã·ãŒã¯ã¬ããã¬ããã³ã¹ããŒã«éã®ç·å¯ãªé£æºãå¿ èŠã§ããã¯ãŒã¯ããŒããå¢å ã倿§åããã«ã€ããŠãæå·åã¯ãã€ã¯ããµãŒãã¹ããµãŒããŒã¬ã¹é¢æ°ãã€ãã³ããã€ãã©ã€ã³ãåæãã©ãããã©ãŒã ããããŠããã¯ã°ã©ãŠã³ãã¿ã¹ã¯éã§å ±æãããåæ£è²¬ä»»ãžãšå€åããŸããçµ±äžãããæå·åãã¬ãŒã ã¯ãŒã¯ããªããã°ãåã³ã³ããŒãã³ãã®åäœã¯ç°ãªããä¿¡é Œå¢çã®æçåãéµäœ¿çšã®åæã®ããããããŠäºæž¬äžå¯èœãªã©ã³ã¿ã€ã åäœã«ã€ãªãããŸãããããã®ãªã¹ã¯ã¯ããã«ãã¯ã©ãŠãããªããã«é¡äŒŒããŠããŸãã ãªã¹ã¯ç®¡çæŠç¥ äžè²«æ§ã®ãªãããªã·ãŒã¯ãã·ã¹ãã å šäœã®è匱æ§ãç¡æèã®ãã¡ã«èç©ããŠãããŸãããããã£ãŠããã«ãã¯ã©ãŠãã®ãã«ãŒããªã³ãã§ã¯ãç°å¢éã§æå·åæäœã調åãããªãããã¢ããªã±ãŒã·ã§ã³ã®æ¡å€§ã«åãããŠæè»ã«æ¡åŒµããå¿ èŠããããŸãã
ãã¹ãŠã®ã¯ã©ãŠãã®ããã®æ®éçãªæå·åæœè±¡åã¬ã€ã€ãŒã®å®çŸ©
ãŠãããŒãµã«ãªæå·åæœè±¡åã¬ã€ã€ãŒã«ãããã¢ããªã±ãŒã·ã§ã³ã³ãŒããšãããã€ããŒåºæã®KMSå®è£ éã®çŽæ¥çãªçµåãæé€ãããŸããAWS KMSãAzure Key VaultãGoogle Cloud KMSã®ããžãã¯ãåå¥ã«èšè¿°ãã代ããã«ããšã³ãžãã¢ãªã³ã°ããŒã ã¯çµ±åã€ã³ã¿ãŒãã§ãŒã¹ãå©çšããŠãæå·ååŒã³åºããã¯ã©ãŠãåºæã®ã¢ã¯ã·ã§ã³ãžãšããã¯ã°ã©ãŠã³ãã§å€æããŸããããã«ãããéçºãç°¡çŽ åãããç§»æ€æ§ãåäžãããããã€ããŒãAPIã»ãã³ãã£ã¯ã¹ã倿Žãããæ°æ©èœãå°å ¥ãããããå Žåã§ãã圱é¿ç¯å²ãçž®å°ãããŸãã
æœè±¡åã¬ã€ã€ãŒã¯ãããŒã®ååŸãæå·åã埩å·åãããŒããŒã·ã§ã³ããªã¬ãŒãã¡ã¿ããŒã¿æ§é ãã¢ã¯ã»ã¹å¶åŸ¡ãæšæºåããå¿ èŠããããŸãããŸããã¯ãŒã¯ããŒãã®å®è¡å Žæã«é¢ä¿ãªããæå°æš©éããªã·ãŒãé©çšããç°å¢éã§äžè²«æ§ã®ãªãIAMãããã³ã°ãæŒæŽ©ããã®ãé²ãå¿ èŠããããŸããããã¯ã çµ±åäžè²«æ§ãã¬ãŒã ã¯ãŒã¯ æœè±¡åã«ããç°æ©çš®ã·ã¹ãã å šäœã«å®å®æ§ãããããããŸãã
å ç¢ãªæœè±¡åã¬ã€ã€ãŒã¯ãã³ãŒã倿Žãå¿ èŠãšããã«ããšã³ãããŒãæå·åãããŒã«ã«ããŒã¿ããŒãã£ãã·ã¥ããã§ãã¬ãŒã·ã§ã³IDãç£æ»ã®æ£èŠåããµããŒãããŸãããã®çµæããã«ãã¯ã©ãŠãã¢ããªã±ãŒã·ã§ã³ã¯ããªãŒãžã§ã³ããããã€ããŒãã¢ãŒããã¯ãã£ããŸããã§æ¡åŒµããŠããã»ãã¥ãªãã£ãšäžè²«æ§ãç¶æã§ããŸãã
é«ã¹ã«ãŒãããã®ãã«ãã¯ã©ãŠãã¯ãŒã¯ããŒãã®ããã®æè»ãªããŒäœ¿çšãã¿ãŒã³ã®äœæ
é«ã¹ã«ãŒãããã¢ããªã±ãŒã·ã§ã³ã¯é«éãªæå·åã»åŸ©å·ååŠçã«äŸåããŠããããã«ãã¯ã©ãŠãç°å¢ã§ã¯ã¬ã€ãã³ã·ã®å€åãçããæ éã«èšèšããªããšã¹ã«ãŒããããäœäžããå¯èœæ§ããããŸããæè»ãªéµäœ¿çšãã¿ãŒã³ã¯ãããŒã¿éµãããŒã«ã«ã«ãã£ãã·ã¥ããæå·åãããªã¢ã«ãããªãã§ããããåæKMSåŒã³åºããæå°éã«æããããšã§ãã¯ãŒã¯ããŒãã®æå·ååŠçãã¹ã±ãŒã«ããããšãå¯èœã«ããŸãããããã®æè¡ã¯ãåè¿°ã®ããã©ãŒãã³ã¹åé¡ã«é¡äŒŒããããã«ããã¯ã軜æžããŸãã ã·ã¹ãã ã¬ãã«ã®ã³ãŒãå¹ç äžèŠãªæäœãç¹°ãè¿ããããšããã¹ãé ããªããŸãã
åŒŸåæ§ã®ããæå·åãã¿ãŒã³ã¯ãããŒã¯æã«æ¥éã«æ¡å€§ããåæã¯ãŒã¯ããŒãããµããŒãããŸããã¯ãŒã¯ããŒãã¯ãªã¢ãŒãKMSåŒã³åºããåŸ ã€ä»£ããã«ã匷åãªæå¹æéããžãã¯ãåããçåœã®ãã£ãã·ã¥ããŒãå©çšãããããæ¥µããŠé«ãè² è·äžã§ãäºæž¬å¯èœãªããã©ãŒãã³ã¹ãå®çŸããŸãããããã®ãã¿ãŒã³ã¯ãåã ã®ãããã€ããŒã®é床äœäžãåé¢ããé£éçãªã¬ã€ãã³ã·ã®æ¥å¢ãé²ããããã¯ãã¹ã¯ã©ãŠãã¢ãŒããã¯ãã£ã«ã¡ãªããããããããŸãã
ã¹ã±ãŒã©ãã«ãªãã«ãŒããªã³ãã§ã¯ããããã®æè»ãªäœ¿çšãã¿ãŒã³ã圢åŒåãããã£ãã·ã¥ãããŒãšãŒãžã³ã°ã«ãŒã«ãåæå®è¡ãããå€ããã©ãŒã«ããã¯æäœã®ããªã·ãŒãå®çŸ©ããŠããã¹ãŠã®ã¯ã©ãŠããè² è·äžã§ãäžè²«ããŠåäœããããã«ããå¿ èŠããããŸãã
æå·åã¯ãŒã¯ãããŒã«ã°ããŒãã«åé·æ§ãšãã§ã€ã«ãªãŒããŒãçµã¿èŸŒã
ãã«ãã¯ã©ãŠãæå·éçšã«ã¯åé·æ§ãäžå¯æ¬ ã§ãããããããã€ããŒã®KMS APIãå©çšã§ããªããªã£ãå Žåãã¯ãŒã¯ããŒãã¯ã³ã³ãã©ã€ã¢ã³ã¹ããã¬ãŒãµããªãã£ãã»ãã¥ãªãã£ä¿èšŒãæãªãããšãªããã·ãŒã ã¬ã¹ã«ä»£æ¿æå·åãã¹ã«ãã§ã€ã«ãªãŒããŒããå¿ èŠããããŸããåé·æ§ãèæ ®ããèšèšãšã¯ãã¯ã©ãŠãéã§ãã©ãŒãªã³ã°ãããéµãåæãããããŒããŒã·ã§ã³ããªã·ãŒããããŠãã©ãŒã«ããã¯åŸ©å·ã¯ãŒã¯ãããŒãç¶æããããšãæå³ããŸãã
ã¯ãŒã¯ããŒãã¯ãKMSã®éå®³ãæ€ç¥ãããªãŒãžã§ã³ã¬ããªã«ã«åãæ¿ããäžè²«ããããªã·ãŒã䜿çšããŠæäœãå詊è¡ã§ããå¿ èŠããããŸããã·ãŒã¯ã¬ãã管çãã€ãã©ã€ã³ã§ã¯ããããã€ããŒã®åæ¢æã§ãèªèšŒæ å ±ã«ã¢ã¯ã»ã¹ã§ãããããåæãããã¬ããªã«ãå¿ èŠã§ãããããã®ååŸ©åæŠç¥ã¯ããã«ãç°å¢ç¶ç¶æ§ã®æŠå¿µãšäžŠè¡ããŠããŸãã äŒæ¥ãªã¹ã¯æŠç¥ åé·æ§ã«ãããåäžé害ç¹ã«ããã°ããŒãã«éçšã®äžæã鲿¢ããŸãã
ã¹ã±ãŒã©ãã«ãªãã«ãã¯ã©ãŠã ãã«ãŒããªã³ãã¯åé·æ§èŠä»¶ã圢åŒåãããã¹ãŠã®ãããã€ããŒãåäžã®ãã§ã€ã«ãªãŒã㌠ããžãã¯ãšã©ã€ããµã€ã¯ã« ãã©ã¡ãŒã¿ããµããŒãããããšãä¿èšŒããŸãã
宣èšåã¬ããã³ã¹ãšèªååã«ãããã«ãã¯ã©ãŠãæå·åã®æ¡åŒµ
é·æçãªã¹ã±ãŒã©ããªãã£ãå®çŸããã«ã¯ãæå·åæäœãæåã§ã¯ãªã宣èšçã«ç®¡çããå¿ èŠããããŸããããªã·ãŒã»ã¢ãºã»ã³ãŒããèªåããªããæ€åºãã¡ã¿ããŒã¿ã®æ£èŠåããã€ãã©ã€ã³ã®é©çšã«ãããããŒã ãæ°ããã¯ãŒã¯ããŒããå±éããããæ°ããªãªãŒãžã§ã³ã«æ¡åŒµãããããŠããããããç°å¢ã§æå·åã®äžè²«æ§ãç¶æãããŸãã
宣èšåã¬ããã³ã¹ã«ãããããŒããŒã·ã§ã³ããªã·ãŒãæå¹æéã«ãŒã«ãIAMå¶çŽãããŒãžã§ã³ç®¡çããããã¹ãå¯èœã§ãèªåçã«é©çšãããŸããèªååããªããã°ããã«ãã¯ã©ãŠãã¢ãŒããã¯ãã£ã«ããã倧éã®éµãšã·ãŒã¯ã¬ããã®æäœã¯ããã«ç®¡çäžèœã«é¥ããŸãããããã®èªååãããã¬ããã³ã¹ååã¯ã ããŒã¿ãããŒã¬ããã³ã¹ ããªã·ãŒå®çŸ©ã«ãã£ãŠã·ã¹ãã ã®åäœãå€§èŠæš¡ã«å¶åŸ¡ãããŸãã
ã¬ããã³ã¹ãèªååããããšãçµç¹ã¯ããªãããæé€ããæ§æãã¹ãé²ããåºç€ãšãªãã¯ã©ãŠã ãã©ãããã©ãŒã ã«é¢ä¿ãªãæå·åæäœã®ã¹ã±ãŒã©ããªãã£ãç¶æã§ããããã«ãªããŸãã
çµ±ååã§äºæž¬å¯èœãã»ãã¥ãªãã£éèŠã®ãã«ãã¯ã©ãŠã KMS ã®æªæ¥ãæ§ç¯
å®å šã§ã¹ã±ãŒã©ãã«ãªãã«ãã¯ã©ãŠãKMSã¢ãŒããã¯ãã£ã®èšèšã¯ããã¯ãããããªèŠä»¶ã§ã¯ãããŸãããAWSãAzureãGoogle CloudãOCIã«ã¯ãŒã¯ããŒãã忣ããèé害æ§ã坿¬æ§ããããŠã°ããŒãã«å±éã远æ±ããäŒæ¥ã«ãšã£ãŠãã³ã¢ã³ã³ããã³ã·ãŒãšãªã£ãŠããŸããããããçµ±äžãããæå·åæŠç¥ããªããã°ãã¯ã©ãŠãã®æ®åã¯æå·ååäœãã¢ã¯ã»ã¹å¶åŸ¡ãããŒããŒã·ã§ã³ããžãã¯ããããŠã·ãŒã¯ã¬ããã¬ããã³ã¹ã«æçåããããããŸãããããã®äžæŽåã¯ã忢ãã³ã³ãã©ã€ã¢ã³ã¹ã®ã£ããããããã¯ç£æ»äžåãšããŠè¡šé¢åãããŸã§ãéãã«èç©ãããŠãããŸããé·æçãªä¿¡é Œæ§ãå®çŸããã«ã¯ãKMSãã¯ã©ãŠãåºæã®ãŠãŒãã£ãªãã£çŸ€ã§ã¯ãªããã¢ãŒããã¯ãã£äžã®å¶åŸ¡ãã¬ãŒã³ãšããŠæ±ãå¿ èŠããããŸãããã®ã¢ãŒããã¯ãã£äžã®èŠåŸã¯ã ãšã³ã¿ãŒãã©ã€ãºçµ±ååºç€æç¶å¯èœãªé²åã«ã¯çµ±äžãããæŠç¥ãäžå¯æ¬ ã§ãã
äºæž¬å¯èœãªãã«ãã¯ã©ãŠãæå·åæŠç¥ã¯ãå ±éã®æœè±¡åãäžè²«ããã©ã€ããµã€ã¯ã«ããªã·ãŒããã§ãã¬ãŒã·ã§ã³ã¢ã¯ã»ã¹ã¢ãã«ããšã³ãããŒãæå·åãã¿ãŒã³ããããŠã°ããŒãã«ã«æŽåãããã¬ããã³ã¹ãã¬ãŒã ã¯ãŒã¯ã«äŸåããŸãããããã®èŠçŽ ã飿ºããããšã§ãçµç¹ã¯ããªãããæé€ããã¯ã©ãŠãéã®è匱æ§ã軜æžããããããæå·åæäœã®ããã®ä¿¡é Œã§ããåºç€ãæ§ç¯ã§ããŸããã¯ãŒã¯ããŒããã¯ã©ãŠãéã§ç§»è¡ãèªåã¹ã±ãŒãªã³ã°ããã§ã€ã«ãªãŒããŒãããŠããæå·åã®åäœã¯å®å®ããŠããŸããã³ã³ãã©ã€ã¢ã³ã¹ã®ç¶æã容æã«ãªããéçšããŒã ã¯ããããã€ããŒåºæã®éãã«é¢ããããKMSã®ã€ã³ã¿ã©ã¯ã·ã§ã³ãã©ãã§ãåãããã«åäœãããšãã確信ãåŸãããšãã§ããŸãã
SMART TS XL é ããæå·åäŸåé¢ä¿ãæããã«ããIAMå¢çãæ€èšŒããã¯ã©ãŠãéã®ããªãããæ€ç¥ããæ¬çªç°å¢ãžã®å°å ¥åã«æå·å倿Žã®åœ±é¿ãã·ãã¥ã¬ãŒã·ã§ã³ããããšã§ããã®å®å®æ§ãå®çŸããäžã§éèŠãªåœ¹å²ãæãããŸããã¯ãã¹ãã©ãããã©ãŒã ã»ã€ã³ããªãžã§ã³ã¹ã«ãããããŒãã¹ãã·ãŒã¯ã¬ãããããŒãä¿¡é Œå¢çãã©ã€ããµã€ã¯ã«ãªãã¬ãŒã·ã§ã³ãç°å¢éã§åæãããç¶æ ãç¶æããŸããããã«ããããã«ãã¯ã©ãŠãã»ãã¥ãªãã£ã¯ãã¯ã©ãŠããã€ãã£ããªã³ã³ããŒãã³ãã®å¯ãéããããäºæž¬å¯èœãªåäœãšèšŒæå¯èœãªã¬ããã³ã¹ãåããçµ±åãããæå·åã·ã¹ãã ãžãšé²åããŸãã
çµ±ååã§èªååäž»å°åããããŠè±å¯ãªã€ã³ãµã€ãã«åºã¥ãæå·åæŠç¥ã«æè³ããäŒæ¥ã¯ãå®å šæ§ã ãã§ãªããå埩åãæ¡åŒµæ§ãç£æ»å¯Ÿå¿æ§ãåãããã«ãã¯ã©ãŠãç°å¢ãæ§ç¯ããŸããé©åãªã¢ãŒããã¯ãã£ãã¿ãŒã³ãšé«åºŠãªå¯èŠæ§ããŒã«ã掻çšããããšã§ãçµç¹ã¯ããžã¿ã«ãããããªã³ãå šäœã«ããã£ãŠä¿¡é Œã§ããæå·åä¿èšŒãç¶æããªãããã¯ã©ãŠããšã³ã·ã¹ãã ãèªä¿¡ãæã£ãŠé²åãæ¡åŒµããããŠè¿ä»£åããããšãã§ããŸãã