ROIã®ä¿¡é Œæ§ãšéææ§ãé«ããããã«ããã®æçš¿ã§èª¬æãããŠããããªãåçŽãªãœãªã¥ãŒã·ã§ã³ãé©çšã§ããŸãã ãŠãŒã¶ãŒãä»»æã®ã€ãã·ã¢ããã«è³æãå察ããŸãã¯æ€åããå ŽåãROIã¯ç¹å¥ãªæ€èšŒã³ãŒããçæããå¿ èŠããããŸããããŠãŒã¶ãŒã®å人æ å ±ã¯å«ãŸããŸããã ãã®ãããªã³ãŒãã®ãªã¹ãã¯å ¬éãããŠããå¿ èŠããããŸãã ãããã£ãŠã誰ããæ祚ããããªãã¯ãã¡ã€ã³ã«èšé²ããçµæã確èªã§ããŸãã ãã®æè¡çãªè§£æ±ºçã¯ã·ã³ãã«ã§ããã祚ã®éèšãããçšåºŠå¶åŸ¡ã§ãããããROIã«å¯Ÿããåžæ°ã®ä¿¡é Œãé«ãŸããŸãã
ææ¡ãããè¡åãããã³ã«ã
ãŸããROIã¯2048ãããã®RSAããŒãã¢ïŒSKãPKïŒãçæããŠãé»åããžã¿ã«çœ²åïŒEDSïŒãšããŠäœ¿çšããŸããSKã¯ç§å¯ããŒã§ãPKã¯å ¬éããŒã§ãã å ¬éããŒã¯ãããªãã¯ãã¡ã€ã³ã§å ¬éãããã·ãŒã¯ã¬ããã¯ROIãµãŒããŒã§ã®ã¿ä¿åããã³äœ¿çšãããŸãã ãã®ãããªããŒã¯ãROIå šäœã«å¯ŸããŠ1ã€ã§ããã€ãã·ã¢ããããšã«å€ãã®ããŒã§ãããŸããŸããã ããšãã°ãã€ãã·ã¢ããããšã«ç¬èªã®åå¥ã®ããŒãçæã§ããŸãã ãŸãã¯ãROIå šäœã®ããŒãéææŽæ°ããŸãã ããŒãèå¥ããããã«ããããŒããŒãžã§ã³ãïŒãŸãã¯ã€ã³ããã¯ã¹ãããŒçªå·ïŒã®æŠå¿µã䜿çšããŸãã ããã«ãã·ã¹ãã ã®æåã®ããŒãžã§ã³ã«ã¯ãŸã£ããå¿ èŠã§ã¯ãããŸããããROIã¯ããŒèšŒææžãå ¬éã§ããŸãã
å ¬çã«å©çšã§ããã¯ãã®ã³ãŒãã®æ§é ãšçæã
1.ãŠãŒã¶ãŒãæ祚ãããšãROIã¯æ¬¡ã®ãã¯ãã«VïŒ49ãã€ãé·ïŒã圢æããŸãã
ããŒããŒãžã§ã³ïŒæ°å€ïŒïŒ4ãã€ã
åæçªå·ïŒ4ãã€ã
ã€ãã³ãæéïŒUTCæéïŒïŒ8ãã€ã
ã€ãã³ãã¿ã€ãïŒ1ãã€ãïŒFORãAGAINSTãREVIEWïŒ
次ã®ããã«èšç®ããããŠãŒã¶ãŒã®æ祚ããã·ã¥
H = SHA256ïŒUserSecret; SNILS; Initiative NumberïŒïŒ32ãã€ãã
UserSecretã¯ç§å¯ã§ããããã®ãœãŒã¹ã¯ãŠãŒã¶ãŒèªèº«ã§ãã ããšãã°ãæ祚æã«ãŠãŒã¶ãŒãROI Webãµã€ãã§å ¥åããæ祚ã®ãã¹ã¯ãŒãã«ããããšãã§ããŸãã ROIãæè¡çã«èš±å¯ããŠããå ŽåãROIãŸãã¯ãã®ããã·ã¥ãå ¥åãããšãã«ãã¹ã¯ãŒãã«ããããšãã§ããŸãããã®å ŽåãROIã¯ãã£ãŒã«ãã§èªåçã«çœ®ãæããããšãã§ããŸãã ãããã«ãããããã¯ãŠãŒã¶ãŒããã®ãã®ã§ããã圌ã¯ä»ã®èª°ãç¥ããªãããšãå¿ èŠã§ãã ã€ãããŒã·ã§ã³ã®çç±ã«ã€ããŠ-ãã¿ãã¬ã³ã¡ã³ããèªãã§ãã ããã
UPDïŒåçã®å€æŽãã¢ãããŒã·ã§ã³ H = SHA256ïŒSK; SNILS;ã€ãã·ã¢ããçªå·ïŒïŒ32ãã€ãã
è°è«ã®çµæãã·ã¹ãã ã«ç©Žãããããšãæããã«ãªããŸããã 次ã®ã·ããªãªãæ³åããŠãã ãããROIã¯çµæããã£ãã·ã¥ãã5åããšã«1åçºè¡ããŸãã ãããŠãŒã¶ãŒãæ祚ããæ£ããã³ãŒããçæãããŠåœŒã«éä¿¡ããããšããŸãããïŒVxãSxïŒã ãã®5åéã§ä»ã®èª°ããæ祚ãããšãROIã¯åœŒã«æ°ããã³ãŒãã§ã¯ãªããåã®ãŠãŒã¶ãŒïŒVxãSxïŒã®ã³ãŒããéä¿¡ã§ãããšä»®å®ããŸãã åŸã§ãã³ãŒãããã§ãã¯ãããšãäž¡æ¹ã®ãŠãŒã¶ãŒã¯ã³ãŒããã¹ããŒãã¡ã³ãå ã«ããããšã確èªããŸãããROIã®ã«ãŠã³ã¿ãŒã¯1ã ãå¢å ããããã¯æ€èšŒã§ããŸããã ã€ãŸããROIã§é³å£°ãæ¶ããã·ããªãªãååŸããŸãã ããã§ã®åŒ±ããªã³ã¯ã¯ãHxãã¯ãã«ã§ãã ãããã£ãŠããŠãŒã¶ãŒèªèº«ããã®ãã¯ãã«ã®åæããŒã¿ã®æ£ç¢ºæ§ãæ€èšŒã§ããå¿ èŠããããŸãããä»ã®èª°ãæ€èšŒã§ããŸããã ããã«ãããã·ã¹ãã ãå°ãè€éã«ãªããŸãã
ãŠãŒã¶ãŒãè€æ°ã®ã¢ã¯ã·ã§ã³ïŒããšãã°ãFOR-REVIEW-AGAINSTïŒãå®è¡ããå ŽåãUserSecretã¯ããããã¹ãŠã®ã¢ã¯ã·ã§ã³ã«å¯ŸããŠå€æŽãããªãããã«ããå¿ èŠããããŸãããããã£ãŠãHxãã°ã§ã¯ã1人ã®ãŠãŒã¶ãŒãšéžæãããã€ãã·ã¢ããã®ãããã®æäœãåãã«ãªããŸãã é³å£°ãæãåºãããšãäžå¯èœãªå ŽåïŒçŸåšã®ROIã«ããããã«ïŒããã®è³ªåã¯é¢é£æ§ããªããªããåé¡ã¯ãããŸããã
çµæïŒãŠãŒã¶ãŒã¯ãèªåã®ã³ãŒãïŒVxãSxïŒãã¢ããããŒãããããã°ã®ãªã¹ãã«ããããšã確èªããã ãã§ãªããVxããäžæã®ãã¯ãã«Hxãæ£ããçæãããããšã確èªããå¿ èŠããããŸãã
è°è«ã®çµæãã·ã¹ãã ã«ç©Žãããããšãæããã«ãªããŸããã 次ã®ã·ããªãªãæ³åããŠãã ãããROIã¯çµæããã£ãã·ã¥ãã5åããšã«1åçºè¡ããŸãã ãããŠãŒã¶ãŒãæ祚ããæ£ããã³ãŒããçæãããŠåœŒã«éä¿¡ããããšããŸãããïŒVxãSxïŒã ãã®5åéã§ä»ã®èª°ããæ祚ãããšãROIã¯åœŒã«æ°ããã³ãŒãã§ã¯ãªããåã®ãŠãŒã¶ãŒïŒVxãSxïŒã®ã³ãŒããéä¿¡ã§ãããšä»®å®ããŸãã åŸã§ãã³ãŒãããã§ãã¯ãããšãäž¡æ¹ã®ãŠãŒã¶ãŒã¯ã³ãŒããã¹ããŒãã¡ã³ãå ã«ããããšã確èªããŸãããROIã®ã«ãŠã³ã¿ãŒã¯1ã ãå¢å ããããã¯æ€èšŒã§ããŸããã ã€ãŸããROIã§é³å£°ãæ¶ããã·ããªãªãååŸããŸãã ããã§ã®åŒ±ããªã³ã¯ã¯ãHxãã¯ãã«ã§ãã ãããã£ãŠããŠãŒã¶ãŒèªèº«ããã®ãã¯ãã«ã®åæããŒã¿ã®æ£ç¢ºæ§ãæ€èšŒã§ããå¿ èŠããããŸãããä»ã®èª°ãæ€èšŒã§ããŸããã ããã«ãããã·ã¹ãã ãå°ãè€éã«ãªããŸãã
ãŠãŒã¶ãŒãè€æ°ã®ã¢ã¯ã·ã§ã³ïŒããšãã°ãFOR-REVIEW-AGAINSTïŒãå®è¡ããå ŽåãUserSecretã¯ããããã¹ãŠã®ã¢ã¯ã·ã§ã³ã«å¯ŸããŠå€æŽãããªãããã«ããå¿ èŠããããŸãããããã£ãŠãHxãã°ã§ã¯ã1人ã®ãŠãŒã¶ãŒãšéžæãããã€ãã·ã¢ããã®ãããã®æäœãåãã«ãªããŸãã é³å£°ãæãåºãããšãäžå¯èœãªå ŽåïŒçŸåšã®ROIã«ããããã«ïŒããã®è³ªåã¯é¢é£æ§ããªããªããåé¡ã¯ãããŸããã
çµæïŒãŠãŒã¶ãŒã¯ãèªåã®ã³ãŒãïŒVxãSxïŒãã¢ããããŒãããããã°ã®ãªã¹ãã«ããããšã確èªããã ãã§ãªããVxããäžæã®ãã¯ãã«Hxãæ£ããçæãããããšã確èªããå¿ èŠããããŸãã
2.ããã«ãROIã¯ãã³ãŒãã®2çªç®ã®éšåã§ããããžã¿ã«çœ²åïŒEDSïŒãåä¿¡ããããã«ã察å¿ããRSAç§å¯éµSKã䜿çšããŸãã
S = RSA_SignïŒSK; VïŒ-çµæã¯256ãã€ãã«ãªããŸãã
3.ãã¢ïŒV; SïŒãæ祚ãããŠãŒã¶ãŒã«é»åã¡ãŒã«ã§éä¿¡ãããäžè¬å ¬éãããŸãïŒããšãã°ãPEMããã¹ã圢åŒïŒã
é·æïŒ
â¢ãã¢ã®ãªãŒãã³ãªã¹ã{V; S}ã䜿çšããŠãã人ã¯ãéžæããã€ãã·ã¢ããã®ç·æ祚æ°ãèšç®ã§ããŸããããã¯ãROIã®å ¬éããŒã䜿çšããŠåVxå€ãäºåã«æ€èšŒããRSA_VerifyïŒPK; Sx; VxïŒå€ãsuccessããŸãã¯ãnotæåãã å®éããã®é¢æ°ã¯PKå ¬éããŒã䜿çšããŠSx眲åã埩å·åããæåãšçããå Žåã¯Vxã«å¯ŸããŠçµæããã§ãã¯ããŸãã
â¢ãªã¹ã{V; S}ã®èª°ã§ãæ祚ã³ãŒããèŠã€ããããšãã§ããŸããæ祚ã³ãŒãã¯ãæ祚åŸããã«ãŠãŒã¶ãŒã«é»åã¡ãŒã«ã§éä¿¡ããå¿ èŠãããããã§ãã äžè¬ãªã¹ãã«ã³ãŒããèŠã€ãããªãå ŽåããŠãŒã¶ãŒã¯ã¢ã«ãŠã³ãïŒVxãSxïŒãã¢ã«ãŠã³ãã®ãªãé³å£°ã®èšŒæ ãšããŠæ瀺ã§ããŸãã ããã«ããŠãŒã¶ãŒã¯ãROIãåããã¢ïŒVxãSxïŒã2人ã®ãŠãŒã¶ãŒã«éä¿¡ãã1ã€ã®æ祚ã®ã¿ãèæ ®ããã·ããªãªã®å¯èœæ§ãé€ããVxããã®ç¬èªã®ãã¯ãã«Hxãæ£ããçæãããããšã確èªããå¿ èŠããããŸãã
â¢ãµãŒãããŒãã£ã¯ãé©åãªSx眲åãã¢ãæäŸããªããšãVxé³å£°ã®ã¢ã«ãŠã³ããªãã«ã€ããŠè©±ãããšãã§ããŸãããããã¯ãROIç§å¯éµãç¥ãå¿ èŠãããããã§ãã ãããã£ãŠãROIã¯ãã®çš®ã®äžåœãªäž»åŒµããä¿è·ãããŸãã
â¢éžæããã€ãã·ã¢ããã®ãã¬ãŒã ã¯ãŒã¯å ã§åããŠãŒã¶ãŒã®ã¢ã¯ã·ã§ã³ãäžæã«èå¥ããããã«ããã£ãŒã«ãHãè¡Vã«è¿œå ãããŸãã ããšãã°ãPROCESS-CANCELã·ãŒã±ã³ã¹ãç¹å®ã®ãŠãŒã¶ãŒã«é¢é£ä»ããŠã{V; S}ã€ãã³ããªã¹ãã§ãã®ã·ãŒã±ã³ã¹ã远跡ã§ããããã«ããå¿ èŠããããŸãã åæã«ãROIãµãŒããŒã§çæãããããã·ã¥ã«ROIã®ç§å¯éµãå«ãŸããŠããããããŠãŒã¶ãŒèªèº«ã®SNILSã¯äœ¿çšã§ããŸããã ããã·ã¥ã§ã¯ãå人ã®ç§å¯éµãSNILSãèªèã§ããŸããã ãŸããSNILSãããã£ãŠããŠããããã·ã¥ã§ROIã®ç§å¯éµãèŠã€ããããšã¯ã§ããŸããã ãŸããSNILSãšHã®éã®æ¥ç¶ã¯å ¬éæ å ±ã§ã¯ãªããããSNILSãç¥ã£ãŠãã1人ãŸãã¯å¥ã®äººãã©ã®ããã«æ祚ããããæ€èšŒããããšã¯ã§ããŸãããæ祚è ãšæ祚ã®çµæã ããç¥ãããŠããŸãããã®æ å ±ã¯çŸåšãé»åã¡ãŒã«ã§ãŠãŒã¶ãŒã«éä¿¡ãããŸãã ãããã£ãŠããã®èšèšã¯ãå人æ å ±ã®çŸåšã®ã»ãã¥ãªãã£ã¬ãã«ïŒäººãæ祚ããå ŽåïŒãå€æŽãããSNILSãŸãã¯ROIç§å¯éµãä»ããæ å ±ã®æŒæŽ©ã¯ãããŸããã
â¢å€±ããããŠãŒã¶ãŒïŒVxãSxïŒãç¹å®ã®ãŠãŒã¶ãŒã«ãã£ãŠå ¬éããããšãé³å£°ãšç¹å®ã®äººç©ã®éã«æ¥ç¶ãã¢ãäœæããããã®ç¹å®ã®äººç©ã®æ祚æ¹æ³ãå šå¡ã«æããã«ãªããŸãã ããããä»ã¯ç¶æ³ã¯äŒŒãŠããŸã-ç§ãæ祚ããç§ã®æ祚ãæ°ããããªãã£ãå Žåããããè¿°ã¹ãŠãç§ã¯ç§ãæ祚ããæ¹æ³ã«é¢ããæ å ±ãå ¬éããŸãã ãã ãããã©ã¹ã¯ã倱ãããé³å£°ïŒVxãSxïŒããããã£ãŠROIãžã®èŠæ±ããç¹å®ã®ãŠãŒã¶ãŒãšã®æ¥ç¶ãæäŸããã«å¿åã§ãããªãã¯ã¹ããŒã¹ã«è»¢éã§ããããšã§ãã
çæïŒ
â¢ROIãååšããªãSNILSã«å¯ŸããŠFORãŸãã¯AGAINST祚ãè¿œå ã§ããã·ããªãªã远跡ããããšã¯ã§ããŸããã ãããããã®ã·ããªãªã¯çŸåšå¯èœã§ãã
æè¡çãªå®è£ ïŒ
ãã®ã¢ã€ãã¢ãå®è£ ããããã«ãROIã¯OpenSSLïŒå€ãã®ã·ã¹ãã ã§åºã䜿çšãããŠãããªãŒãã³ãªç¡æã®æå·åã©ã€ãã©ãªã§ãããIPæ¥ç¶ããã©ãŠã¶ãŒããã®ä»ã®å€ãã®ã¢ããªã±ãŒã·ã§ã³ã§æå·åããããã£ãã«ãèšå®ããïŒãã€ã³ã¹ããŒã«ããäžèšã®ãã¹ãŠã®æäœã«ã¹ã¯ãªãããã䜿çšã§ããŸãïŒçæRSAããŒïŒããžã¿ã«çœ²åçšïŒãSHA256ã®çœ²åãšããã·ã¥ã ããŒã®çæã¯é ãæäœã§ããããŸãã§ãïŒäžåºŠãŸãã¯æ°ããã€ãã·ã¢ãããéããšãïŒã ç§å¯éµã®çœ²åãšããã·ã¥ã¯é«éãªæäœã§ãã OpenSSLã¯ãã³ãã³ãã©ã€ã³ãŸãã¯ã¹ã¯ãªããã®äž¡æ¹ãããããã³C / C ++ãªã©ã®ããŸããŸãªã³ã³ãã€ã«æžã¿ããã°ã©ãã³ã°èšèªã®äž¡æ¹ãã䜿çšã§ããŸãã å®è£ ã«ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ããã®ä»ã®è€éãªæé ã¯å¿ èŠãããŸããããŸããã¹ã¯ãªãããŸãã¯ã³ãŒãã®è€æ°ã®è¡ã«é©åããå ŽåããããŸãã
UPDïŒèªè ã®èŠæ±ã«å¿ãã説æãšè¿œå ã
ç§ã¯ãã¹ãŠã®æèŠãæããããŸãããšããŒãã«ãªããšæããŠããŸãã ããããç§ã¯ããããšããŸãïŒ
1. EDSãšããŠäœ¿çšããããã«RSAããŒãROIåŽã§çæããããšããããã¹ããæ確ã«ããŸããã ãŸããRSA_Encrypt / RSA_Decryptã¯ãããããRSA_Sign / RSA_Verifyã«çœ®ãæããããŸããã
2. ECDSA 256ãããïŒæ¥åæ²ç·ããžã¿ã«çœ²åã¢ã«ãŽãªãºã ïŒã§ã¯ãªãã®ããšããçåããããŸããã ã¯ããããžã¿ã«çœ²åSã®éã«ã¯å©ç¹ããããŸããRSAã®å Žåã®ããã«256ãã€ãã§ã¯ãªãã72ãã€ãããããŸããããããé床ã«ãæ¬ ç¹ããããŸãã RSA_Verifyæäœã¯ãECDSA_Sign and Verifyãããäœåãé«éã§ãã ãããŠãRSA_Sign / VerifyãRSA_Encrypt / Decryptã«å€æŽããPKã§ã¯ãªãSKãçºè¡ããã ãã§ãECDSAãããäœåãé«éã«çœ²åã§ãããµãŒããŒãåŸãããŸãã
3.ãªãGOSTã§ã¯ãªãã®ã§ããïŒ ãœããšãã®æšæºã«ã€ããŠè³ã®é ããèããããšããããŸããããããã®ããã€ãã¯å€åœã®ã¢ã€ãã¢ããã³ããŒãããããã«äœããç°ãªã£ãŠèŠããããã«è¿œå ãããããšãç¥ã£ãŠããŸãã äŸãšããŠã¯ãKGBã§äœæãããGOSTã³ãŒãããããŸãïŒç§åŠçã§ã¯ãã®ååã§ç¥ã£ãŠããŸãïŒã3DESãããããªããªãšãŒã·ã§ã³ã§ã³ããŒããŸãã GOSTããã·ã¥ã¢ã«ãŽãªãºã ã«ãããšãåã質å-ç§ã«ã¯ããããªãã
4. 2ã3é ã®ããã«ãäžåœäººãåæ§ã®è³ªåãããã®ãé²ãããã«ïŒç¬èªã®è³ªåããããŸãïŒãããã«çœ®ãæããŸããé察称ã¢ã«ãŽãªãºã ãXãããã·ã¥ã¢ã«ãŽãªãºã Yã«ããã©ã¡ããéžæããããéžæããŸãã 䜿çšããã¢ã«ãŽãªãºã ã®å°ãªããšã128ãããïŒã§ããã°256ïŒã®ã»ãã¥ãªãã£ã¬ãã«ã«åŸãã ãã§ããããã以å€ã®å Žåã¯éžæã®åé¡ã§ãããæ¬è³ªã«å€§ããªåœ±é¿ã¯ãããŸããã
ãããããé¡ãããŸãïŒ