æ¥ãŠããããã¹ãŠã®äººã«æè¬ããŸããä»æ¥ã¯å®å
šãªããŒããã£ã¹ã¯æå·åïŒFDEïŒã«ã€ããŠã話ããŸããããã¯ããªããæã£ãŠããã»ã©å®å
šã§ã¯ãããŸããã æãæããŠãã³ã³ãã¥ãŒã¿ãŒã®HDDãæå·åããŸãã ãããïŒ ããã§ã¯ãDefConãžããããïŒ
ããªãã®90ïŒ
ããã©ã€ããæå·åããŠãç£æ»ã§ããããã«ããããã«ãªãŒãã³ãœãŒã¹ãœãããŠã§ã¢ã䜿çšããŠããããã§ãã ããã§ãã³ã³ãã¥ãŒã¿ãŒãæŸçœ®ããå Žåã«ã³ã³ãã¥ãŒã¿ãŒã®é»æºãåã人ã¯æãæããŠãã ããã åºåžè
ã®çŽ20ïŒ
ãšæããŸãã ã³ã³ãã¥ãŒã¿ãŒãæ°æéæŸçœ®ããå Žåãã ããã³ã³ãã¥ãŒã¿ãŒã®é»æºããªã³ã«ããããªãã«ãããã¯éèŠã§ããïŒ ç§ããããã®è³ªåãããããšãèããŠãã ãããããªãããŸã³ãã§ãªããŠãç ã£ãŠããªãããšã確ãããŠãã ããã ã»ãšãã©ãã¹ãŠã®äººããå°ãªããšãæ°åéã¯ã³ã³ãã¥ãŒã¿ãŒãé¢ããªããã°ãªããªãã£ããšæããŸãã
ã§ã¯ããªãã³ã³ãã¥ãŒã¿ãŒãæå·åããã®ã§ããïŒ ãã®è³ªåããã人ãèŠã€ããã®ã¯é£ããã®ã§ãã»ãã¥ãªãã£ã®åéã§ã®ç¹å®ã®è¡åã®åæ©ãå®åŒåããããšã¯æ¬åœã«éèŠã ãšæããŸãã ãããè¡ããªããšããã®äœæ¥ãæŽçããæ¹æ³ãç解ã§ããªããªããŸãã
ãã£ã¹ã¯æå·åãœãããŠã§ã¢ã«ã¯ããœãããŠã§ã¢ã®æ©èœã䜿çšããã¢ã«ãŽãªãºã ããã¹ã¯ãŒããªã©ã説æããããã¥ã¡ã³ããå€æ°ãããŸããããããè¡ãããŠããçç±ã¯ã»ãšãã©èª¬æãããŠããŸããã
ãã®ãããããŒã¿ãå¶åŸ¡ãããããã³ã³ãã¥ãŒã¿ãŒã®æå·åãè¡ããŸããããŒã¿ã®æ©å¯æ§ãä¿èšŒãã誰ãç¥ããªããã¡ã«ããŒã¿ãçãã ãå€æŽãããã§ããªãããã«ããŸãã ããŒã¿ãã©ãåŠçãããã決å®ãã圌ã«äœãèµ·ããããå¶åŸ¡ãããã®ã§ãã
ããšãã°ãåŒè·å£«ãã¯ã©ã€ã¢ã³ãã®æ©å¯æ
å ±ãæã€å»åž«ã§ããå Žåãªã©ãããŒã¿ã®æ©å¯æ§ã確ä¿ããå¿
èŠãããå ŽåããããŸãã åãããšã財åæžé¡ãšäŒèšæžé¡ã«ãåœãŠã¯ãŸããŸãã äŒæ¥ã¯ãçãŸããè»ã«ä¿è·ãããŠããªãã©ãããããã眮ãå¿ããå Žåãªã©ãããããæ
å ±ã®æŒæŽ©ã«ã€ããŠé¡§å®¢ã«éç¥ãã矩åãããããã®æ©å¯æ
å ±ã¯ã€ã³ã¿ãŒãããäžã§èªç±ã«å
¥æã§ããããã«ãªããŸããã
ããã«ãã³ã³ãã¥ãŒã¿ãŒãžã®ç©ççãªã¢ã¯ã»ã¹ãå¶åŸ¡ããç©ççãªè¡æããã³ã³ãã¥ãŒã¿ãŒãä¿è·ããå¿
èŠããããŸããããã¯ã誰ããã³ã³ãã¥ãŒã¿ãŒãç©ççã«å¶åŸ¡ããŠãFDEã圹ã«ç«ããªãããã§ãã
ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã確ä¿ãããå Žåã¯ããšã³ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããå¿
èŠããããŸãã åãšã³ããŠãŒã¶ãŒã®ã»ãã¥ãªãã£ã確ä¿ããã«å®å
šãªã€ã³ã¿ãŒããããæ§ç¯ããããšã¯ã§ããŸããã
ããã§ããã£ã¹ã¯æå·åã®å¿
èŠæ§ã®çè«çåŽé¢ãææ¡ããŸããã ä¹±æ°ãçæããŠããŒã®ã»ãã¥ãªãã£ã確ä¿ããæ¹æ³ããã£ã¹ã¯ãå®å
šã«æå·åããããã«äœ¿çšããããããã¯æå·åã¢ãŒããå¶åŸ¡ããæ¹æ³ããã¹ã¯ãŒãã®ããŒãå®å
šã«ç¶æ¿ããæ¹æ³ãç¥ã£ãŠããã®ã§ãããã·ã¥å€§çµ±é ãè¿°ã¹ãããã«ããããã·ã§ã³ãå®äºããã空æ¯ã«ä¹ã£ãŠã ããããããªãã¯ãããããã§ã¯ãªãããšãç¥ã£ãŠããŸãããããŠãç§ãã¡ã¯ãããå®äºããããã«ãŸã ããã¹ãããšããããããããŸãã
å®ç§ãªæå·åæ¹åŒããããã¯ã©ãã¯ããããšã¯ã»ãšãã©äžå¯èœã ãšããã£ãŠããŠãããããã«ããŠããä¿¡é Œã§ããããã©ãã¯ããã¯ã¹ãã®é¡äŒŒç©ããªãå®éã®ã³ã³ãã¥ãŒã¿ãŒã«å®è£
ããå¿
èŠããããŸãã æ»æè
ã¯ããã£ã¹ã¯å
šäœã®æå·åã解èªããããšããŠããå Žåãæå·åãæ»æããå¿
èŠã¯ãããŸããã ãããè¡ãã«ã¯ãã³ã³ãã¥ãŒã¿ãŒèªäœãæ»æããããäœããã®æ¹æ³ã§ãŠãŒã¶ãŒãã ãŸããŠãã¹ã¯ãŒãã®å
¥åãä¿ãããããŒãã¬ãŒããŒããããŒãªã©ã䜿çšããã ãã§ãã
æå·åã®å®éã®äœ¿çšã¯ãFDEã»ãã¥ãªãã£ã¢ãã«ãšäžèŽããŸããã ãã«ãã£ã¹ã¯æå·åçšã«èšèšããããœãããŠã§ã¢ãæ€èšããå Žåããã®äœæè
ã¯æå·åã®çè«çåŽé¢ã«å€ãã®æ³šæãæã£ãããšãããããŸãã TrueCrypt Webãµã€ãã®æè¡ææžããã®æç²ãåŒçšããŸãããæ»æè
ãTrueCryptã®èµ·ååãŸãã¯æäœäžã«ã³ã³ãã¥ãŒã¿ãŒã«ç©ççã«ã¢ã¯ã»ã¹ã§ããå Žåãããã°ã©ã ã¯ã³ã³ãã¥ãŒã¿ãŒäžã®ããŒã¿ãä¿è·ããŸãããã
ååãšããŠããããã®ã»ãã¥ãªãã£ã¢ãã«å
šäœã¯æ¬¡ã®ããã«ãªããŸãããããã°ã©ã ããã£ã¹ã¯ãæ£ããæå·åãããã£ã¹ã¯ãæ£ãã埩å·åããã°ãäœæ¥ãå®äºããŸãããã 次ã®ã¹ã©ã€ãã«è¡šç€ºãããããã¹ãããizeã³ç³ãäžããŸããèªã¿ã«ããå Žåã¯ãèªåã§ãããŸãã ãããã¯ããã¯ãªãŒããŒãã®æ»æã«é¢ããTrueCryptéçºè
ãšã»ãã¥ãªãã£ç 究è
ã®Joanna Rutkovskayaéã®éä¿¡ããã®æç²ã§ãã
TrueCryptïŒ ãããŒããŠã§ã¢æ»æã®å¯èœæ§ãèæ
®ãããææªã®äºæ
ãæ³å®ããŠããŸãã æ»æè
ãã³ã³ãã¥ãŒã¿ã§ãåãããåŸã¯ãæ©å¯æ
å ±ã®ä¿åã«äœ¿çšããã®ããããå¿
èŠããããŸãã TPMæå·åããã»ããµã¯ãããŒãã¬ãŒãªã©ã䜿çšããããŒããŠã§ã¢æ»æãé²ãããšã¯ã§ããŸããã
ãžã§ã¢ã³ãã»ã«ãã³ãã¹ã«ã€ã¯åœŒãã«å°ããŸããïŒãã©ãããããããã€ãæã¡æ©ããŠããããã§ã¯ãªãã®ã§ãæ»æè
ãããªãã®ã³ã³ãã¥ãŒã¿ãŒã§åãããã©ãããã©ããã£ãŠå€æã§ããŸããïŒããéçºè
ã¯çããŸããïŒããŠãŒã¶ãŒãã©ã®ããã«å®å
šãšã»ãã¥ãªãã£ã確ä¿ãããã¯æ°ã«ããŸããã䜿ãã®ã³ã³ãã¥ãŒã¿ãŒã ããšãã°ããŠãŒã¶ãŒã¯ããã¯å¯èœãªãã£ãããããé庫ã«ããªãéã«ããã¯ã䜿çšããããã©ãããããã眮ãããããããšãã§ããŸãã ãžã§ã¢ã³ãã¯éåžžã«æ£ç¢ºã«çããŸããããããã¯ãŸãã¯é庫ã䜿çšããå Žåããªãæå·åãå¿
èŠãªã®ã§ããïŒã
ãããã£ãŠããã®ãããªæ»æã®å¯èœæ§ãç¡èŠããããšã¯ããã§ããããããè¡ãããšã¯ã§ããŸããïŒ ç§ãã¡ã¯ããããã®ã·ã¹ãã ãååšããçžäºäœçšãã䜿çšããçŸå®ã®äžçã«äœãã§ããŸãã ãã©ãã·ã¥ãã©ã€ããªã©ã®ãœãããŠã§ã¢ã®ã¿ã䜿çšããŠå®è¡ããã10åéã®æ»æããããŒããŠã§ã¢ã®ã¿ã§ã·ã¹ãã ãæäœããŠå®è¡ã§ããæ»æãšæ¯èŒããæ¹æ³ã¯ãããŸããã
ãããã£ãŠã圌ããäœãšèšã£ãŠããç©ççãªã»ãã¥ãªãã£ãšç©ççãªæ»æã«å¯Ÿããå埩åã¯FDEã«äŸåããŠããŸãã ã»ãã¥ãªãã£ã¢ãã«ã§äœãæŸæ£ãããã¯é¢ä¿ãããŸãããå°ãªããšã責任ãåããããªãå Žåã¯ãæäŸããä¿è·ãããã«ç°¡åã«ãããã³ã°ã§ããããéåžžã«æ確ãã€æ£çŽã«ãŠãŒã¶ãŒã«èª¬æããå¿
èŠããããŸãã
次ã®ã¹ã©ã€ãã¯ãçŸä»£ã®ã»ãšãã©ã®ã³ã³ãã¥ãŒã¿ãŒã§äœ¿çšãããŠããæœè±¡çãªFDEããŒãå³ã瀺ããŠããŸãã
ãåç¥ã®ããã«ãããŒãããŒããŒã¯BIOSã䜿çšããŠSSD / HDDããããŒããããããŒã¿è»¢éãã¹ã®ã¹ãã¬ãŒãžã³ã³ãããŒã©ãŒ-PCIãã¹-ãã©ãããã©ãŒã ã³ã³ãããŒã©ãŒããã«æ²¿ã£ãŠã¡ã€ã³ã¡ã¢ãªã«ã³ããŒãããŸãã 次ã«ãããŒãããŒããŒã¯ãŠãŒã¶ãŒã«ãã¹ã¯ãŒããã¹ããŒãã«ãŒãããŒãªã©ã®èªèšŒæ
å ±ãèŠæ±ããŸãã 次ã«ããã¹ã¯ãŒããããŒããŒãããããã»ããµã«éããããã®åŸããŒãããŒããŒãå¶åŸ¡ãååŸããŸããããã£ã¹ã¯ã®æå·åããã³åŸ©å·åããã»ã¹ã®éææ§ã確ä¿ããããã«ãOSãšããŒã®äž¡æ¹ã®ã³ã³ããŒãã³ããã¡ã¢ãªã«æ®ããŸãã ããã¯ããã»ã¹ã®çæ³åããããã¥ãŒã§ããã誰ãä»å
¥ãè©Šã¿ãªãããšã瀺åããŠããŸãã ããªãã¯ããããããã³ã°ããããã€ãã®æ¹æ³ãããç¥ã£ãŠãããšæãã®ã§ã誰ããããªããæ»æããããšããå Žåã«ããŸããããªãå¯èœæ§ããããã®ããªã¹ãããŸãããã æ»æã3ã€ã®ã¬ãã«ã«åããŸãã
1ã€ã¯ãã«ãŠã§ã¢ã®ãªããã©ãã·ã¥ãã©ã€ãã䜿çšããŠå®è¡ããããããã³ã³ãã¥ãŒã¿ãŒã®ãã£ããã£ãå¿
èŠãšããªãé䟵襲çã§ãã PCIã«ãŒããExpressCardãThunderboltãªã©ã®ããŒããŠã§ã¢ã³ã³ããŒãã³ãïŒPCIãã¹ãžã®ãªãŒãã³ã¢ã¯ã»ã¹ãæäŸããææ°ã®Appleã¢ããã¿ãŒïŒãç°¡åã«æ¥ç¶ã§ããå Žåãã·ã¹ãã ããå解ãããå¿
èŠã¯ãããŸããã
第2ã¬ãã«ã®æ»æã«ã¯ãã©ã€ããŒãå¿
èŠã§ããããã¯ãã䜿çšã®å°èŠæš¡ãªç°å¢ã§ã·ã¹ãã ã®ã³ã³ããŒãã³ãã«å¯ŸåŠããããã«ãäžæçã«ã·ã¹ãã ã®ã³ã³ããŒãã³ããåé€ããå¿
èŠãããããã§ãã 3çªç®ã®ã¬ãã«ãã€ãŸããã¯ãã ããŠæ»æãã¯æãé£ãããã®ã§ããããã§ã¯ãããããªã©ã®ã·ã¹ãã ã³ã³ããŒãã³ããç©ççã«è¿œå ãŸãã¯å€æŽããŠãããããã¯ã©ãã¯ããããšããŸãã
第1ã¬ãã«ã®æ»æã®1ã€ã¯ãã·ã¹ãã ã®ããŒãããã»ã¹ã®äžéšãšããŠæå·åãããŠããªãã³ãŒããå®è¡ããå¿
èŠããããã€ãŒãã«ã¡ã€ããæ»æãšãåŒã°ãã䟵害ãããããŒãããŒããŒã§ããããŒããã©ã€ãã§æå·åãããæ®ãã®ããŒã¿ã«ã¢ã¯ã»ã¹ããŸãã ãããè¡ãã«ã¯ããã€ãã®ç°ãªãæ¹æ³ããããŸãã ã¹ãã¬ãŒãžã·ã¹ãã ã®ããŒãããŒããŒãç©ççã«å€æŽã§ããŸãã BIOSãå±éºã«ããããããæªæã®ããBIOSãããŒãããããããšãããŒããŒãã¢ããã¿ãŒãŸãã¯ãã£ã¹ã¯èªã¿åãæé ãå¶åŸ¡ããããŒããã£ã¹ã¯ã®åãå€ãã«èããããããã«å€æŽã§ããŸãã ãããããããã«ããããŠãŒã¶ãŒããã¹ã¯ãŒããå
¥åãããšãã«ãæå·åãããŠããªã圢åŒã§ãã£ã¹ã¯ã«æžã蟌ãããåæ§ã®æäœãè¡ãããã«ã·ã¹ãã ãå€æŽããããšãã§ããŸãã
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¬ãã«ã§ãåæ§ã®ããšãã§ããŸãã ããã¯ããã«ãã£ã¹ã¯æå·åã§ã¯ãªããã³ã³ããæå·åã䜿çšããå Žåã«ç¹ã«åœãŠã¯ãŸããŸãã
ããã¯ãã·ã¹ãã ããšã¯ã¹ããã€ãã«ãã£ãŠæ»æããããšãã«ãçºçããå¯èœæ§ããããŸããããã«ãããæ»æè
ã¯ã«ãŒãæš©éãååŸããã¡ã€ã³ã¡ã¢ãªããããŒãèªã¿åãããšãã§ããŸããããã¯éåžžã«äžè¬çãªæ»ææ¹æ³ã§ãã ãã®ããŒã¯ãåŸã§æ»æè
ã䜿çšããããã«ãã¬ãŒã³ããã¹ããšããŠããŒããã£ã¹ã¯ã«ä¿åãããããããã¯ãŒã¯çµç±ã§ã³ãã³ãïŒã³ã³ãããŒã«ã·ã¹ãã ã«éä¿¡ã§ããŸãã
å¥ã®å¯èœæ§ã¯ããœãããŠã§ã¢ãããŒããŠã§ã¢ããŸãã¯ããŒãã«ã¢ã€ã«ã¡ã©ããã€ã¯ãªã©ã®ãšããŸããã¯ãªãã®ã§ãããã©ããã«é¢ä¿ãªããããŒãã¬ãŒã䜿çšããããŒããŒãã€ã³ã¿ãŒã»ããã§ããããŒã ã·ã¹ãã ã®å€éšã«ããã³ã³ããŒãã³ããæœåšçã«å«ãŸããããããã®ãããªæ»æãé²ãããšã¯å°é£ã§ãã
ãŸããã³ãŒã«ãããŒãæ»æãšããŠç¥ãããŠããããŒã¿å埩æ»æã«ã€ããŠãèšåããããšæããŸãã 5幎åã«ã³ã³ãã¥ãŒã¿ãŒã«ç²ŸéããŠãã人ã§ãããã¡ã€ã³ã¡ã¢ãªã®ã»ãã¥ãªãã£æ©èœã«ã€ããŠå°ãããšãé»æºãåããšããŒã¿ã¯ããã«æ¶ããŠããŸããšèšãããŸãã
ãããã2008幎ã«ãPrincetonã«ãã£ãŠåªããç 究ãçºè¡šãããŸãããPrincetonã¯ã宀枩ã§ããæ°ç§éRAMã¡ã¢ãªã®ããŒã¿æ倱ãã»ãšãã©ãªãããšãçºèŠããŸããã ãŸããã¢ãžã¥ãŒã«ã極äœæž©ãŸã§å·åŽãããšãæ°åãããããšããããŸããããã®éãã¡ã€ã³ã¡ã¢ãªå
ã®ããŒã¿ã®ããããªå£åã®ã¿ãçºçããŸãã
ãããã£ãŠãããŒãã¡ã€ã³ã¡ã¢ãªã«ããã誰ããã¢ãžã¥ãŒã«ãã³ã³ãã¥ãŒã¿ããåé€ããå Žåã圌ãã¯ã¯ãªã¢ã§ã¡ã€ã³ã¡ã¢ãªã®ã©ãã«ããããçºèŠããããšã§ããŒãæ»æã§ããŸãã ããŒããŠã§ã¢ã¬ãã«ã§ããã«å¯Ÿæããç¹å®ã®æ¹æ³ããããŸããããšãã°ãé»æºããªãã«ãªã£ããšãããªããŒããããšãã«ã¡ã¢ãªã®å
容ã匷å¶çã«ã¯ãªã¢ããŸããã誰ããåã«ã¢ãžã¥ãŒã«ãåŒãåºããŠå¥ã®ã³ã³ãã¥ãŒã¿ãŒãŸãã¯æ©åšã®å°çšéšåã«å
¥ããŠã¡ã¢ãªã®å
容ãæœåºããå Žåã¯åœ¹ã«ç«ã¡ãŸããã
æåŸã«ãã¡ã¢ãªãžã®çŽæ¥ã¢ã¯ã»ã¹ã®å¯èœæ§ããããŸãã ã䜿ãã®ã³ã³ãã¥ãŒã¿ãŒã®PCIããã€ã¹ã«ã¯ãéåžžã¢ãŒãã§ã¡ã€ã³ã¡ã¢ãªãŒã®ã»ã¯ã¿ãŒã®å
容ãèªã¿æžãããæ©èœããããŸãã 圌ãã¯äœã§ãã§ããŸãã
ããã¯ãã³ã³ãã¥ãŒã¿ãŒã®åŠçé床ãã¯ããã«é
ããã¡ã€ã³ã¡ã¢ãªããããã€ã¹ãžã®ããŒã¿ã®è»¢éããšã«äžå€®åŠçè£
眮ãããããŒã·ãããããããšãæãŸãªãå Žåã§ãéçºãããŸããã ãããã£ãŠãããã€ã¹ã¯ã¡ã¢ãªã«çŽæ¥ã¢ã¯ã»ã¹ã§ããããã»ããµã¯ããã€ã¹ã«åçŽã«å®äºã§ããæ瀺ãäžããããšãã§ããŸãããããŒã¿ã¯å¿
èŠãªãšãã«ãã€ã§ãã¡ã¢ãªã«æ®ããŸãã
PCIããã€ã¹ã¯åããã°ã©ã ã§ããããããããåé¡ã§ãã ãããã®å€ãã«ã¯æžã蟌ã¿å¯èœãªãã¡ãŒã ãŠã§ã¢ããããæµå¯Ÿçãªãã®ã«ç°¡åã«ã¢ããã°ã¬ãŒãã§ããŸãã ãŸããOSèªäœãå€æŽããããããŒãçŽæ¥æœåºãããããå Žåã§ãããããã圢æ
ã®æ»æãå¯èœã«ãªãããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã å
šäœã®ã»ãã¥ãªãã£ãå±éºã«ãããããå¯èœæ§ããããŸãã ã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ã«ã¯ãç¯çœªã調æ»ããéçšã§ãã®ãããªãã®ã®ããã«èšèšãããæ©åšããããŸããã³ã³ãã¥ãŒã¿ãŒã«äœããæ¥ç¶ããã¡ã¢ãªãŒã®å
容ãåŒãåºããŸãã FireWireãExpressCardããŸãã¯Thunderboltã䜿çšããŠãããå®è¡ã§ããŸããå®éããããã¯ãã¹ãŠãå
éšã·ã¹ãã ãã¹ãžã®ã¢ã¯ã»ã¹ãæäŸããå€éšããŒãã§ãã
ãããã£ãŠãRAMãã»ãã¥ãªãã£ã®èŠ³ç¹ããã¯ããŸãä¿¡é Œæ§ããªãããšã瀺ããã®ã§ãããŒãRAMã«ä¿åããªãããšãå¯èœã§ããã°ãããšæããŸãã å°çšã®ããŒã¹ãã¢ãŸãã¯ç¹å¥ãªæå·åæ©åšã¯ãããŸããïŒ ã¯ãããããŸãã WebãµãŒããŒã®æå·åã¢ã¯ã»ã©ã¬ãŒã¿ãŒã䜿çšããŠã1ç§ãããã«ããå€ãã®SSLãã©ã³ã¶ã¯ã·ã§ã³ãåŠçã§ããŸãã äžæ£å¹²æžã«å¯Ÿããèæ§ããããŸãã CAã®èšŒææ©é¢ã«ã¯å®å
šã«ç§å¯ã®ããŒãä¿åãããã®ããããŸãããå®éã«ã¯ãã£ã¹ã¯æå·åã®äœ¿çšãªã©ã®é«æ§èœãªæäœã®ããã«èšèšãããŠããŸããã ä»ã®ãªãã·ã§ã³ã¯ãããŸããïŒ
ããã»ããµãäžçš®ã®æ¬äŒŒããŒããŠã§ã¢æå·ã¢ãžã¥ãŒã«ãšããŠäœ¿çšã§ããŸããïŒ CPUã®å¯Ÿç§°AESãããã¯æå·åã¢ã«ãŽãªãºã ã®ãããªãã®ããRAMã®ä»£ããã«CPUã¬ãžã¹ã¿ã®ãããªãã®ã ãã䜿çšããŠèšç®ã§ããŸããïŒ
IntelãšAMDã¯ãAESãå®è¡ãããžã§ããåŠçããããã»ããµã«çŽ æŽãããæ°ããåœä»€ãè¿œå ããããã1ã€ã®åçŽãªãã«ãåœä»€ã§ããªããã£ããããã¯æå·åæäœãå®è¡ã§ããŸãã åé¡ã¯ãããŒãã¡ã¢ãªã«æ®ããŠããããšãã§ããã®ããã¡ã€ã³ã¡ã¢ãªã«äŸåããã«ãã®ããã»ã¹ãå®è¡ã§ããã®ãããšããããšã§ãã ææ°ã®x86ããã»ããµã«ã¯ããªã倧ããªã¬ãžã¹ã¿ã»ãããããããããã®ãããããã¹ãŠè¿œå ããããšãããšãçŽ4ãããã€ãã«ãªããŸãã ãããã£ãŠãå®éã«ããã€ãã®CPUã䜿çšããŠããŒãä¿åããæå·åæäœçšã®ã¹ããŒã¹ãäœæã§ããŸãã
1ã€ã®å¯èœæ§ã¯ããã¬ãŒã¯ãã€ã³ãã®ãããã°ã«ããŒããŠã§ã¢ã¬ãžã¹ã¿ã䜿çšããããšã§ãã å
žåçãªIntelããã»ããµã«ã¯4ã€ã®ãã®ãããªã¬ãžã¹ã¿ããããx64ã·ã¹ãã ã§ã¯ããããã«64ããããã€ã³ã¿ãå«ãŸããŸãã ããã¯ãã»ãšãã©ã®äººã決ããŠäœ¿çšããªã256ãããã®æœåšçãªãã£ã¹ã¯å®¹éã§ãã ãã¡ããããããã°ã¬ãžã¹ã¿ã䜿çšããå©ç¹ã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã¿ããããã°ã¬ãžã¹ã¿ã«ã¢ã¯ã»ã¹ã§ããããããã®ç¹æš©ã§ãã ããã«ã¯ä»ã«ãçŽ æŽãããå©ç¹ããããŸããããšãã°ãã·ã¹ãã ã®é»æºãåã£ãããã¹ãªãŒãã¢ãŒãã«ç§»è¡ãããšãã«ããã»ããµã®é»æºãåããšãã¬ãžã¹ã¿ã®å
容å
šäœã倱ãããããããã³ãŒã«ããªã¹ã¿ãŒãããæããããšã¯ã§ããŸããã
ãã€ãã®ç·Tilo Mullerã¯ã2011幎ã«TRESOR for LinuxãšåŒã°ãããã®é¡äŒŒã®ãã®ãå®è£
ããŸããã 圌ã¯ããã®ãããªã·ã¹ãã ã®ããã©ãŒãã³ã¹ããã¹ããããœãããŠã§ã¢ã«ããéåžžã®AESèšç®ãããé
ãåäœããªããšçµè«ä»ããŸããã
1ã€ã®ããŒã®ä»£ããã«2ã€ã®128ãããããŒãä¿åããã®ã¯ã©ãã§ããïŒ ããã«ããããã倧ããªæå·ã¢ãžã¥ãŒã«ã¹ããŒã¹ã«ãªããŸãã ããŒãæã«ããã»ããµããé¢ããããšã®ãªããã¹ã¿ãŒããŒã1ã€ä¿åããè¿œå ã®æäœãå®è¡ããŠè¿œå ã®ã¿ã¹ã¯ã解決ããããã«å¿
èŠãªããŒããŒãžã§ã³ãããŒãããã³ã¢ã³ããŒãã§ããŸãã
åé¡ã¯ãã³ãŒããŸãã¯ããŒãã¡ã€ã³ã¡ã¢ãªã®å€éšã«ä¿åã§ããããšã§ãããCPUã¯äŸç¶ãšããŠã¡ã¢ãªã®å
容ãåŠçããŸãã ãããã£ãŠãDMAããã€ã¬ã¯ãã¡ã¢ãªã¢ã¯ã»ã¹ãã¯ãããžãŒãäžå€®åŠçè£
眮ã®ãã€ãã¹ããŸãã¯ãã®ä»ã®æäœã䜿çšãããšããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãå€æŽãããã®ãã³ããã¡ã€ã³ã¡ã¢ãªã¬ãžã¹ã¿ã®å€éšããŸãã¯ãããšããŸããã¯ãªæ¹æ³ã䜿çšãããå Žåã¯ãããã°ã¬ãžã¹ã¿ã®å€éšã«ä¿åã§ããŸãã
DMAã®æ»æã®è§åºŠã§äœãã§ããŸããïŒ çµå±ã®ãšãããã¯ããã§ããŸãã æè¿ããµãŒããŒã®ä»®æ³åãé«ããããã®æ°ãããã¯ãããžãŒã®äžéšãšããŠãããã©ãŒãã³ã¹äžã®çç±ããã人ã
ã¯ãããšãã°ãããã¯ãŒã¯ã¢ããã¿ãŒãä»®æ³ãµãŒããŒã«æ¥ç¶ã§ããããã«ãªãããã®ã§ããã€ããŒãã€ã¶ãŒãä»ããŠæ¥ç¶ããå¿
èŠããããŸãã
IOMMUãã¯ãããžãŒã¯ãã·ã¹ãã å
ã®ä»»æã®å Žæã§åæã«èªã¿æžãã§ããªãPCIããã€ã¹ããç¬èªã®å°ããªã¡ã¢ãªããŒãã£ã·ã§ã³ã«åé¢ã§ããããã«èšèšãããŠããŸãã : IOMMU , , .
, , , TRESOR BitVisor, . , , - . , , IOMMU , - .
, , , , , . , â , .
, , . , RAM , , . , , , , SSH-, PGP-, « », .
: RAM? , , , , .
, , , â , ! 2010 RAM. â : âclearâ, , , . 10-50 . , , , -, â 10% . , . , , ? , TPM , , , .
-, , . , , - CPU.
, . , , , . , , - . , ? , . ? , - , , , â â , .
, . , , . â Trusted Platform Module â , . , , , , TPM . , «» , . , , . , , .
? -. - , - «» , . , .
, â -, . , RSA/SHA1, , , - . - , . , .
23:10
DEFCON 21. , «» . ããŒã2
ãæ»åšããã ãããããšãããããŸãã ç§ãã¡ã®èšäºã奜ãã§ããïŒ ããèå³æ·±ãè³æãèŠããã§ããïŒ æ³šæããããå人ã«æšèŠããããšã§ãç§ãã¡ããµããŒãããŸããç§ãã¡ãããªãã®ããã«çºæãããšã³ããªãŒã¬ãã«ã®ãµãŒããŒã®ãŠããŒã¯ãªã¢ããã°ã®HabrãŠãŒã¶ãŒã®ããã«30ïŒ
ã®å²åŒïŒ VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒã«ã€ããŠã®çå®20ãã«ãŸãã¯ãµãŒããŒãåå²ããæ¹æ³ïŒ ïŒãªãã·ã§ã³ã¯RAID1ããã³RAID10ãæ倧24ã³ã¢ãæ倧40GB DDR4ã§å©çšå¯èœã§ãïŒã
VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1GbpsãŸã§ 6ãæã®æéãæ¯æãå Žåã æ¥ãŸã§ç¡æ㧠ã ããã§æ³šæã§ããŸã ã
Dell R730xdã¯2åå®ãã§ããïŒ ãªã©ã³ããšç±³åœã§249ãã«ããIntel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TVã2å°æã£ãŠããã ãã§ãïŒ ã€ã³ãã©ã¹ãã©ã¯ãã£ãã«ã®æ§ç¯æ¹æ³ã«ã€ããŠèªãã§ãã ããã ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ