äž»ãªã¿ã¹ã¯ïŒ
-çœå®³åŸ©æ§ã®ããã«ä»»æã®åœ¢åŒã§ããŒã¿ãããã¯ã¢ããããæ©èœã
-æš©éã®ãªã人ã«ãããã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ã®é€å€ã
-ãµãŒããŒã®ç·æ¥ã·ã£ããããŠã³äžã«ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ãããå€éšã¡ãã£ã¢ããèµ·åã§ããªãã
-ééçãªãŠãŒã¶ãŒã¯ããµãŒããŒäžã®ãã¡ã€ã«ãã³ã³ãã³ããæäœããŸãã
-OS FreeBSD 7.2ããã³å®è£ ãªãã·ã§ã³ã®éžæã«ãããæ³ååã®æ倧ç¯å²ã
nçªç®ã®æéã®åŸã次ã®ãã¹ãæ§æã圢ã«ãªããŸããã
GELI -GEOM_ELIïŒcryptoïŒ9ïŒãã¬ãŒã ã¯ãŒã¯ã䜿çšããŠFreeBSDã«çµã¿èŸŒãŸããæå·åãµãã·ã¹ãã ïŒããŒããŠã§ã¢ããã³ãœãããŠã§ã¢æå·åïŒïŒ
GBDE -GEOM_BDE [Geom Based Disk Encryption]ïŒFreeBSDã«çµã¿èŸŒãŸããæå·åãµãã·ã¹ãã ïŒ
TrueCrypt -TrueCrypt 6.1aã®ç§»æ€ããŒãžã§ã³ïŒãã¥ãŒãºã䜿çšïŒ
cryptofs-ãã¥ãŒãºã䜿çšããcryptofs
encfs -fuseã䜿çšããencfs
UPDïŒã¯ãªãŒã³ãªãã¡ã€ã«ã·ã¹ãã ãšæå·åããããã¡ã€ã«ã·ã¹ãã ã®é床ãæ¯èŒããè¡šã
䜿çšããæå·åã·ã¹ãã ã®åé¡ããå§ããŸãããã
æåã®2ã€ã®ã·ã¹ãã ã¯ãGEOMã§èå¥ãããããã€ã¹ã䜿çšããŸãã ããã¯ãç©çãã©ã€ãïŒda0ïŒãããŒãã£ã·ã§ã³ïŒda0s1ïŒãã¹ã©ã€ã¹ïŒda0s1aïŒãããã³mdconfigãggatelãªã©ã«ãã£ãŠäœæãããä»ã®åæããã€ã¹ã§ãã
mdconfigã¯ã geom_mdã䜿çšããŠãæ¢åã®RAMãŸãã¯ãã£ã¹ã¯ãŸãã¯ãã®ä»ã®ã¡ãã£ã¢äžã®ãã¡ã€ã«ããä»®æ³ããã€ã¹ã圢æãããŠãŒãã£ãªãã£ã§ãã
ggatelã¯ããã®ã¯ã©ã¹ã®GEOMã¯ã©ã¹ã«å²ãåœãŠãããšãã§ããªãããã€ã¹ãŸãã¯ãã¡ã€ã«ã転éã§ãããŠãŒãã£ãªãã£ã§ãã
TrueCryptã¯ãèªåŸçãªã¯ãã¹ãã©ãããã©ãŒã ã®æå·ã³ã³ãããŒæå·åã·ã¹ãã ã§ãã
fuse_cryptofs-æ§æãã¡ã€ã«ã§æå®ãããã¢ã«ãŽãªãºã ã䜿çšããŠãã¡ã€ã«åãšãã®å 容ãæå·åãããã£ã¹ã¯ããŒã¿ã®ãã¹ã¯ãŒãæå·åãµãã·ã¹ãã ã
fuse_encfs-ãã¡ã€ã«ã®å€æŽãå¶åŸ¡ããŠãã¡ã€ã«åãšãã®å 容ãæå·åãããã£ã¹ã¯ããŒã¿ã®ãã¹ã¯ãŒãããŒæå·åãµãã·ã¹ãã ã
ãã¹ãŠã®ãã¹ãã¯ãP4 2.8HT / 1GB RAM / 40GB IDE /ãšããç¹æ§ãæã€ã·ã¹ãã ã§å®è¡ãããŸããã
äœæ¥é床ãè©äŸ¡ããããã«ã ddãšbonnieã䜿çšãããŸãã ã
äžæçãªæå·ã³ã³ãããã¡ã€ã«ãšãã¡ã€ã«ãã£ã¬ã¯ããªã¯ã/ varã»ã¯ã·ã§ã³ã«é 眮ãããŸããã
# dmesg | grep ad0 <br/>ad0: 38166MB <Seagate ST340014A 3 . 06 > at ata0-master UDMA100<br/> # mount | grep var <br/>/dev/ad0s1g on /var (ufs, local , soft-updates) <br/>
æåã®ã¹ãããã¯ãããŒã¯æã®ããŒããã©ã€ããžã®ç·åœ¢æžã蟌ã¿é床ãè©äŸ¡ããããšã§ããã
<br/>testcrypt # /usr/bin/time dd if=/dev/random of=testfile.dump bs=1m count=4096 <br/> 4096 + 0 records in <br/> 4096 + 0 records out<br/> 4294967296 bytes transferred in 151 . 801076 secs ( 28293392 bytes/sec)<br/> 151 . 82 real 0 . 00 user 132 . 96 sys <br/>
ã€ãŸã ã¹ããªãŒãã³ã°é²é³ã§ã¯ãå¯èœãªéãçŽ27ã¡ã¬ãã€ã/ç§ãæåŸ ã§ããŸãã
GEOMãããã€ããŒã®é床ãåæããããã«ã4GBãã¡ã€ã«ãäœæããããããmdconfigããã³ggatelã«é çªã«æ¥ç¶ãããŸãã ïŒã»ã¯ã¿ãŒãµã€ãºã¯4Kã§æ±ºå®ãããŸããïŒã ããã«ããã¹ãã«æ²¿ã£ãŠãã³ãŒãã®æ¿å ¥ããäžèŠãªãªãŒããŒãããæ å ±ãå¯èœãªéãé€å€ããããã«ããŸãã
GEOMãããã€ããŒãéããŠç·åœ¢èšé²é床ã確èªããŸããã
testcrypt # mdconfig -a -t vnode -f /var/test/testfile.dump -S 4096 -u 0 <br/>testcrypt # /usr/bin/time dd if=/dev/random of=/dev/md0 bs=1m <br/> 4294967296 bytes transferred in 306 . 514082 secs ( 14012300 bytes/sec)<br/> 306 . 55 real 0 . 02 user 120 . 03 sys<br/>testcrypt # mdconfig -d -u 0 <br/> <br/>testcrypt # ggatel create -s 4096 -u 0 /var/test/testfile.dump <br/>testcrypt # /usr/bin/time dd if=/dev/random of=/dev/ggate0 bs=1m <br/> 4294967296 bytes transferred in 319 . 859650 secs ( 13427662 bytes/sec)<br/> 319 . 91 real 0 . 02 user 133 . 34 sys<br/>testcrypt # ggatel destroy -u 0 <br/>
ãã¹ããããããããã«ãæžã蟌ã¿é床ã¯ã»ãŒ2åäœäžãã ggateãããã€ããŒã¯mdãããããé ãããšãå€æããŸãããã ggateã¯ã·ã¹ãã ã«mdãããå°ãå€ãè² è·ããããŸãããååãšããŠããã¯ç¹ã«éèŠã§ã¯ãããŸããã
次ã®ã¹ãããã¯ãGEOMãããã€ããŒãä»ããŠæ©èœãããã¡ã€ã«ã·ã¹ãã ã®è² è·å®¹éã確èªããããšã§ãã æåã«ãã¹ããããã®ã¯mdã§ãã
testcrypt # mdconfig -a -t vnode -f /var/test/testfile.dump -S 4096 -u 0 <br/>testcrypt # newfs /dev/md0 <br/>/dev/md0: 4096 .0MB ( 8388608 sectors) block size 16384 , fragment size 4096 <br/> using 13 cylinder groups of 336 .98MB, 21567 blks, 21568 inodes.<br/>super-block backups ( for fsck -b #) at: <br/> 160 , 690304 , 1380448 , 2070592 , 2760736 , 3450880 , 4141024 , 4831168 , 5521312 ,<br/> 6211456 , 6901600 , 7591744 , 8281888 <br/>testcrypt # mount /dev/md0 /mnt <br/>testcrypt # /usr/bin/time dd if=/dev/random of=/mnt/testfile.dump bs=1m <br/> 4220518400 bytes transferred in 235 . 262614 secs ( 17939605 bytes/sec)<br/> 235 . 28 real 0 . 03 user 136 . 49 sys<br/>testcrypt # umount /mnt <br/>testcrypt # mdconfig -d -u 0 <br/>
ã芧ã®ãšããããã¡ã€ã«ã®åŠçé床ãåäžãã17.1ã¡ã¬ãã€ã/ç§ã«éããŸããã
2çªç®ã«ãã¹ããããggate ã
<br/>testcrypt # ggatel create -s 4096 -u 0 /var/test/testfile.dump <br/>testcrypt # newfs /dev/ggate0 <br/>/dev/ggate0: 4096 .0MB ( 8388608 sectors) block size 16384 , fragment size 4096 <br/> using 13 cylinder groups of 336 .98MB, 21567 blks, 21568 inodes.<br/>super-block backups ( for fsck -b #) at: <br/> 160 , 690304 , 1380448 , 2070592 , 2760736 , 3450880 , 4141024 , 4831168 , 5521312 , 6211456 , 6901600 , 7591744 , 8281888 <br/>testcrypt # mount /dev/ggate0 /mnt <br/>testcrypt # /usr/bin/time dd if=/dev/random of=/mnt/testfile.dump bs=1m <br/> 4220518400 bytes transferred in 228 . 256445 secs ( 18490249 bytes/sec)<br/> 228 . 29 real 0 . 00 user 137 . 80 sys<br/>testcrypt # umount /mnt <br/>testcrypt # ggatel destroy -u 0 <br/>
ãã¹ãŠãçããå Žåã ggateã¯mdãšæ¯èŒããŠé床ãåäžããŸãã-17.6ã¡ã¬ãã€ã/ç§ã
ããããã®æå·ãããã€ããŒãšgeomãããã€ããŒããã¹ããããšããæ¥ãŸããã ãããè¡ãããã«ãä»åŸã®ãã¹ãã§äœ¿çšãããã©ã³ãã ããŒãäœæããŸããã
testcrypt # dd if=/dev/random of=/var/test/my.key bs=4k count=1
Geliæå·åã³ã³ãããŒã®åæå
testcrypt # mdconfig -a -t vnode -f /var/test/testfile.dump -S 4096 -u 0 <br/>testcrypt # /usr/bin/time geli init -s 4096 -K my.key /dev/md0 <br/>Enter new passphrase:<br/>Reenter new passphrase:<br/> 13 . 34 real 9 . 61 user 0 . 00 sys<br/>
æéã®åºåãããããããã«ã geli initã¯é·ãéããã¹ã¯ãŒãã䜿çšããŠäžé£ã®æå·åããŒãèšç®ãããã£ã¹ã¯ã«æžã蟌ã¿ãŸãã
testcrypt # geli list <br/>Geom name: md0.eli<br/>EncryptionAlgorithm: AES-CBC<br/>KeyLength: 128 <br/>Crypto: software<br/>UsedKey: 0 <br/>Flags: NONE<br/>Providers:<br/> 1 . Name: md0.eli<br/> Mediasize: 4294963200 ( 4 .0G)<br/> Sectorsize: 4096 <br/> Mode: r0w0e0<br/>Consumers:<br/> 1 . Name: md0<br/> Mediasize: 4294967296 ( 4 .0G)<br/> Sectorsize: 4096 <br/> Mode: r1w1e1<br/>
æå·ã³ã³ãããŒãäœæãããæ¥å°ŸèŸ.eliãä»ããæ°ããããã€ã¹ã圢æãããŸãããããã¯éåžžã®ãããã¯ããã€ã¹ãšããŠäœ¿çšã§ããŸãã ããŒã¯ã¢ããããŠãããŒãã£ã·ã§ã³ãšãã¡ã€ã«ã·ã¹ãã ãäœæããŸãã
æå·ã³ã³ããäžã«æ°ãããã¡ã€ã«ã·ã¹ãã ãäœæããé床ããã¹ãããŸãã
testcrypt # newfs /dev/md0.eli <br/>/dev/md0.eli: 4096 .0MB ( 8388600 sectors) block size 16384 , fragment size 4096 <br/> using 13 cylinder groups of 336 .98MB, 21567 blks, 21568 inodes.<br/>super-block backups ( for fsck -b #) at: <br/> 160 , 690304 , 1380448 , 2070592 , 2760736 , 3450880 , 4141024 , 4831168 , 5521312 , 6211456 , 6901600 , 7591744 , 8281888 <br/>testcrypt # /usr/bin/time dd if=/dev/random of=/mnt/testfile.dump bs=1m <br/> 4220518400 bytes transferred in 277 . 940331 secs ( 15184980 bytes/sec)<br/> 277 . 96 real 0 . 03 user 145 . 50 sys<br/>
ã芧ã®ãšãããé床ã¯14.5ã¡ã¬ãã€ã/ç§ã«äœäžããŸããã ggate + geli bundle markup and testing unitã¯ã geli + mdãããã¯ãšåããªã®ã§ã¹ãããããŸãã èšé²ãµã€ã¯ã«ã ãã§ã¯äœæ¥é床ãè©äŸ¡ã§ããªããããè¿œå åæã®ããã«ãããŒãå®è¡ããŸãã
ãã¹ãŠã®ãã³ãã«ã«é¢ãããããŒã®äœæ¥ã®æŠèŠã¯ãèšäºã®æåŸã«èšèŒãããŸãã
testcrypt # bonnie -s 1024 <br/> File './Bonnie.1145' , size: 1073741824 <br/>
é 次åºå é æ¬¡å ¥å ã©ã³ãã 1æåããã ãããã¯ãã æžãæãã 1æåããã ãããã¯ãã æ±ãã æ©æ¢° MB K /ç§ ïŒ CPU K /ç§ ïŒ CPU K /ç§ ïŒ CPU K /ç§ ïŒ CPU K /ç§ ïŒ CPU /ç§ ïŒ CPU ãžã§ãª+ md 1024 17178 25.7 18324 8.4 5684 2.2 14492 15.1 15185 2.3 139.8 0.7 ã²ãª+ ggate 1024 13855 20.6 12018 5.2 6388 2.7 19021 21.8 22473 4.2 136.5 0.7
ã芧ã®ãšããã ggateã¯æžã蟌ã¿ãµã€ã¯ã«ã§ã¯é ããªããŸãããèªã¿åããµã€ã¯ã«ã§ã¯ãã£ãšéããªããŸãã ãããããããã¯mdããã³ggateã®æžã蟌ã¿ãããã¡ãªã³ã°ããã³ããŸããŸãªãããã¡ãã©ãã·ã¥ã¡ãœããã«ãããã®ã§ãã ééã£ãããŒãã¡ã€ã«ãŸãã¯ãã¹ã¯ãŒããå ¥åããããšãããšã geliã¯ãã¡ã€ã«ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããããã®ããã€ã¹ãäœæããŸããããŸããå éšã®ã³ã³ãããŒãã¡ã€ã«ã¯/ dev / randomã®å 容ã«äŒŒãŠããããã埩å·åã¯åçŽã«éçŸå®çã§ãã ãã¡ã€ã«ãå šäœããããŸããã geliã®å©ç¹ã®1ã€ã¯ãè€æ°ã®æå·åããŒïŒãã¹ã¿ãŒããŒãšãŠãŒã¶ãŒããŒãªã©ïŒã䜿çšã§ããããšã§ãã
GBDEã³ã³ãããåæåããŸãã
testcrypt # mdconfig -a -t vnode -f /var/test/testfile.dump -S 4096 -u 0 <br/>testcrypt # gbde init /dev/md0 -i -K my.key -L /var/tmp/md0.lock -P testcrypt <br/>testcrypt # ll /var/tmp/md* <br/>md0.lock<br/>testcrypt # gbde attach /dev/md0 -l /var/tmp/md0.lock -k my.key -p testcrypt <br/>testcrypt # ll /dev/md* <br/>crw-r----- 1 root operator 0 , 98 Apr 21 13 : 25 /dev/md0<br/>crw-r----- 1 root operator 0 , 100 Apr 21 10 : 15 /dev/md0.bde<br/>crw------- 1 root wheel 0 , 78 Apr 21 10 : 15 /dev/mdctl
ããã€ã¹ãäœæãããšãã gbdeã¯çŸåšã®ããŒãå«ãããã¯ãã¡ã€ã«ã䜿çšããŠã æå·ã³ã³ãããŒãåæåããŸãã æå·åã³ã³ããåæåã·ã¹ãã ã«ã¯å¯éããŒã¿å埩æé ããªãããããã¹ã¯ãŒããå¿ããå Žåãããã¯ãã¡ã€ã«ãçŽå€±ããå Žåã¯ãæå·åã³ã³ããå ã®ãã¹ãŠã®ããŒã¿ã倱ãããŸãã cryptocontainerãåæåããåŸã gbdeã¯ãµãã£ãã¯ã¹.bdeãæã€ããã€ã¹ãäœæããŸããããã¯c .eliãšåãæ¹æ³ã§åŠçã§ããŸãã
äž¡æ¹ã®ã·ã¹ãã ã䜿çšããããã®è©³çŽ°ãªã¬ã€ãã¯ã ããã«ãããŸã ã bonnieãèµ·åããŠã gbde + mdããã³gbde + ggateãã³ãã«ããã¹ãããŸãã
testcrypt # bonnie -s 1024 <br/> File './Bonnie.1145' , size: 1073741824 <br/>
é 次åºå é æ¬¡å ¥å ã©ã³ãã 1æåããã ãããã¯ãã æžãæãã 1æåããã ãããã¯ãã æ±ãã æ©æ¢° MB K /ç§ ïŒ CPU K /ç§ ïŒ CPU K /ç§ ïŒ CPU K /ç§ ïŒ CPU K /ç§ ïŒ CPU /ç§ ïŒ CPU gbde + md 1024 4436 5.3 4349 1.7 2695 1.2 12920 13.7 17078 2.9 130.1 0.7 gbde + ggate 1024 1971幎 2.2 1970 0.8 1480 0.6 13812 15.2 17206 3.0 120.3 0.6
gbdeãµãã·ã¹ãã ã¯ããªãäœãããã©ãŒãã³ã¹å€ã瀺ããŸããããè¡šãããããããã«ã geliãšã¯ç°ãªããããã»ããµãŒæéã¯å®éã«ã¯äœ¿çšãããŸããã§ãã ã ç§ãæåŸãŸã§ããããèŠã€ããããªãã£ãçç±ã¯äœã§ããã
ãããã¯ãŒã¯äžã®FreeBSDã§éå ¬åŒã®TrueCrypt 6.1aããŒããèŠã€ããã®ã§ãè©ŠããŠã¿ãããšã«ããŸããã
TrueCryptã¯ããã¥ãŒãºãä»ããŠFreeBSDã§åäœããã¯ãã§ãããå®éã«ã¯ããã¹ãŠãããã§ã¯ãªãããšãå€æããŸããã
ãã®ããŒããã³ã³ãã€ã«ããããšãããšãxorgãglibãgtkãgnomeãwxWidgetsãããã³ãã®ä»ã®ãžã£ã³ã¯ãã·ã¹ãã ã«ãã©ãã°ããããšããäºå®ã«è³ããŸããã 詳现ãªåæã«ãããGUIã€ã³ã¿ãŒãã§ãŒã¹ã¯wxWidgetsã®ããã§ããããšãæããã«ãªããŸããã GUIã¯å¿ èŠãªãã£ããããè©Šè¡é¯èª€ãç¹°ãè¿ããŠããã¹ãã·ã¹ãã ã§TrueCryptãåéããgmakeã®ããžãã¯ã·ãŒã±ã³ã¹ãèŠã€ãããŸããã
gmake NOGUI= 1 WX_ROOT=/usr/ local /tmp/wx wxbuild<br/> gmake NOGUI= 1 WXSTATIC= 1 PKCS11_INC=/usr/ local /include/pkcs11/<br/>
TrueCryptã¯ã次ã®ããã«èšã£ãŠããå§ããŸããïŒ
testcrypt # truecrypt <br/> 13 : 35 : 34 : Error: Cannot convert from the charset 'US-ASCII' !
宣èªãšã¯ãTrueCryptããã«ããLANG = Cããen_US.UTF-8ã«å€æã§ããªãã£ãããšãæããŸããããã¯ãœãŒã¹ã«çµã¿èŸŒãŸããŠããŸãã
testcrypt # /usr/bin/time truecrypt -c --filesystem=ufs -k /var/test/my.key --random-source=/dev/random /var/test/truecrypt.dump /mnt <br/>Volume type :<br/> 1 ) Normal<br/> 2 ) Hidden<br/> Select [ 1 ]:<br/> <br/>Enter volume size (sizeK/size[M]/sizeG): 4G<br/> <br/>Encryption algorithm:<br/> 1 ) AES<br/> 2 ) Serpent<br/> 3 ) Twofish<br/> 4 ) AES-Twofish<br/> 5 ) AES-Twofish-Serpent<br/> 6 ) Serpent-AES<br/> 7 ) Serpent-Twofish-AES<br/> 8 ) Twofish-Serpent<br/> Select [ 1 ]:<br/> <br/> Hash algorithm:<br/> 1 ) RIPEMD- 160 <br/> 2 ) SHA- 512 <br/> 3 ) Whirlpool<br/> Select [ 1 ]:<br/> <br/>Filesystem:<br/> 1 ) FAT<br/> 2 ) None<br/> Select [ 1 ]:<br/> <br/>Enter password:<br/>WARNING: Short passwords are easy to crack using brute force techniques!<br/>We recommend choosing a password consisting of more than 20 characters. Are you sure you want to use a short password? (y=Yes/n=No) [No]: y<br/>Re-enter password:<br/> Done : 100 , 000 % Speed: 31 MB/s Left: 0 s<br/>The TrueCrypt volume has been successfully created.<br/> 139 , 42 real 204 , 75 user 13 , 80 sys
äœæãããããŒãã£ã·ã§ã³ã¯åé¡ãªãããŠã³ããããŸããã
testcrypt # truecrypt -k /var/test/my.key --mount /var/test/truecrypt.dump /mnt <br/>Enter password for /var/ test /truecrypt.dump:<br/>Protect hidden volume? (y=Yes/n=No) [No]:<br/> <br/>testcrypt # mount <br/>...<br/>/dev/fuse0 on /var/tmp/.truecrypt_aux_mnt1 (fusefs, local , synchronous)<br/>/dev/md0 on /mnt (msdosfs, local )<br/> <br/>testcrypt # mdconfig -l -v <br/>md0 vnode 4 .0G /var/tmp/.truecrypt_aux_mnt1/volume<br/>testcrypt # ll /var/tmp/.truecrypt_aux_mnt1/ <br/>total 0 <br/>-rw------- 1 root wheel 1522 21 15 : 51 control<br/>-rw------- 1 root wheel 4294705152 21 15 : 51 volume
ããããç§ãã¡ã¯æ®é ·ã«å€±æããŸããã fusefã®äºæ³ããã䜿çšã«åããŠãTrueCryptã¯mdãä»ããŠãšã³ããã€ã³ããã¡ã€ã«ã®å€æã䜿çšãå§ããŸããã ãããã£ãŠãæå·ã³ã³ãããŒã®å€æã«å¥ã®ãžã£ã³ã¯ã·ã§ã³ãè¿œå ãããŸããã ããŠã³ããããTrueCryptããªã¥ãŒã ã«ããŒã¿ãæžã蟌ãããšãããšãã«ãvfsã®æžã蟌ã¿ãããã¡ã䜿ãæããããåŸã«ãããããã¯ãåãåã£ããšãã倱æã¯ããã«å€§ãããªããŸããã TrueCryptã®åšãã®ã¿ã³ããªã³ãšã®ãã³ã¹ãvfsèšå®ãªã©ã¯äœã®åœ¹ã«ãç«ãããTrueCryptã®éåžžã®ãã¹ãã®ã¢ã€ãã¢ãæŸæ£ããŸããã æ®å¿µãªãããçŸåšã®TrueCryptãã«ãã§ã¯ãOSãFATãNTFSã«é¢ä¿ãªã2ã€ã®ãã¡ã€ã«ã·ã¹ãã ããäœæã§ããŸãããããã¯ãœãŒã¹ã³ãŒãã«ããŒãã³ãŒããããŠããŸãã ããŠã³ããããŠããªãããªã¥ãŒã ã«ãã¡ã€ã«ã·ã¹ãã ãäœæãããšãmsdosfsã䜿çšããåé¡ã¯å®å šã«è§£æ±ºããŸããããããããã¯ã®åé¡ã¯è§£æ±ºããŸããã
ãã¹ãæžã¿ã®æå·ã³ã³ãããŒãäžè¶³ããŠããããããããã®ã³ã³ãããŒã«äœããã®ããã¯ã¢ããã¹ããŒã ãå®è£ ããããšããŸããã äžè¬çã«ãããã§ã¯TrueCryptã®åé¡ã»ã©æ²ããç¶æ³ã¯ãããŸããã§ããã ããŠã³ããããæå·ã³ã³ãããŒãé 眮ãããŠãããã¡ã€ã«ã·ã¹ãã ã§ã¹ãããã·ã§ãããäœæããããããã³ã³ãããŒãã¡ã€ã«ãããã¯ããŠãã®å 容ã確èªããããšããŸããã ãããã圌ãã¯åé¡ãèŠã€ããŸããã æå·ã³ã³ããã䜿çšããã¢ã¯ãã£ããªãã¡ã€ã«æäœã§ã¯ãã¹ãããã·ã§ãããäœæããããšãããšãããããã¯ãçºçããŸãã ã·ã¹ãã ã¯çšŒåããŠããããã«èŠããŸãããåæã«ããŠã³ããããã³ã³ããã«ã¢ã¯ã»ã¹ããããšã¯äžå¯èœã§ããããã®åŸããã¹ãŠã®ã·ã¹ãã ããŒãã£ã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããªããªããŸã:(
æå·ã³ã³ããã§ã®æäœããªãå Žåãã¹ãããã·ã§ããã¯éåžžçºçããŸããããã®åŸã®ãããããã¯ã®å¯èœæ§ããããŸãã ããã«ã mdããã€ã¹ã§ã¯ãåé¡ã¯ggateãããæ©ãçŸããŸãã ãããããã¯ãšããã«ç¶ã匷å¶çãªããŒãã£ïŒãªããŒã-qnïŒãªããŒãã®åŸãæåã«æå·ã³ã³ãããŒãfsckã§ãã§ãã¯ããå¿ èŠããããŸããããããªããšãããŠã³ããããŸããã ã¹ãããã·ã§ããããåãåºãããæå·ã³ã³ãããŒã¯ãå®éã«ã¯ããã¡ã€ã«ã·ã¹ãã ãæ¬ èœããŠãããããŒã¿ããªãããã«ç ŽæããŠããããšãå€æããŸããã ãšãŠãæ²ããããšã§ãã ãŸãã倧äžå€«ããªã³ã©ã€ã³ããã¯ã¢ããã¯äœ¿çšã§ããªãã®ã§ã100ïŒ ãªãã©ã€ã³ããã¯ã¢ããã䜿çšã§ããŸãã æå·ã³ã³ããã§ããããããŸãã
ãã¹ãã®2çªç®ã®éšåã§ã¯ãfusefsã䜿çšããŸãã
ãã¹ãã«ã¯ãcryptofsãšencfsãéžæãããŸããã ã·ã¹ãã éã®éãã¯å°ãããäž»ãªéãã¯ãencfsããã¡ã€ã«ã®æŽåæ§ããã§ãã¯ããåå·çãªã»ãã¥ãªãã£ã¢ãŒãããµããŒãããŠããããšã§ãã
testcrypt # cryptofs -r /var/crypto/ <br/>Enter password:<br/>testcrypt # mount_fusefs /dev/fuse0 /mnt <br/>testcrypt # df -h | grep mnt <br/>Filesystem Size Used Avail Capacity Mounted on<br/>/dev/fuse0 18G 5 .1G 12G 30 % /mnt
cryptofsã¯ããã·ã³äžã®éåžžã®ãã¡ã€ã«ã·ã¹ãã ã䜿çšããŠãŠãŒã¶ãŒãèšå®ãããã¹ã¯ãŒãã䜿çšããŠãééããããŒã¿ãæå·åããã²ãŒããŠã§ã€ãäœæããŸãã ã·ã¹ãã ãæ©èœããããã«ã¯ãããŒã ãšãªããã£ã¬ã¯ããªã«.cryptofsèšå®ãã¡ã€ã«ãé 眮ããå¿ èŠããããŸã
# See README for details on each parameter <br/> <br/>[CryptoFS]<br/>cipher=AES256<br/>md=MD5<br/>blocksize=2048<br/>salts=256
èšå®ã¯ãäœæ¥ã§äœ¿çšãããæå·åã¢ã«ãŽãªãºã ã®ãªã¹ãã§ãã æ®å¿µãªããããã¡ã€ã«ã®å Žæã¯å€æŽã§ããŸãã:(
testcrypt # cp /etc/defaults/* /mnt <br/>testcrypt # ls /mnt/ <br/>bluetooth.device.conf devfs.rules pccard.conf periodic.conf rc.conf<br/>testcrypt # ls /var/crypto/ <br/>.cryptofs JuSxlpX8BzEtClI= MuKkkZS2WycuAUc= IO2ylZK9GjApQUWQR697gAD3Valf MOLpk4m8Ew== MuS1mYm2HCdvDE6bVw==
ãã®ã·ã¹ãã ã¯éåžžã«äœ¿ããããã§ãããæ¬ ç¹ã1ã€ãããŸãã ãã¹ã¯ãŒããå ¥åãããšãã«èª€ã£ãŠæåãæ°åãééããå Žåãã·ã¹ãã ã¯å ¥åãããšããã®ãã¹ã¯ãŒãã§ããŒã¿ãæå·åããŸãã ããã«ããã«æ°ä»ããªãå¯èœæ§ãéåžžã«é«ãããŠãŒã¶ãŒã¯æ¢ã«æ°ãããã¹ã¯ãŒãã§æå·åããããã¡ã€ã«ãã¢ããããŒãããŠããŸãã ééã£ããã¹ã¯ãŒããå ¥åãããšããã¡ã€ã«ã·ã¹ãã ã¯æ¬¡ã®ããã«ãªããŸãã
testcrypt # cryptofs -r /var/crypto <br/>Enter password:<br/>testcrypt # mount_fusefs /dev/fuse0 /mnt <br/>testcrypt # ls /mnt/ <br/>i+???F9&??tg? i-???F~&T?} k-???L6 {"???M?1SA?l?????y??? }+????"0W?h<br/> <br/>
encfsã«ã¯ãã®åé¡ã¯ãããŸãããããã§ã«ããåºãæå·åèšå®ããããæ§æãã¡ã€ã«ã«äžæã®ããŒãäœæããŸãã ãã®ããŒã䜿çšããŠã encfsã¯ãã¹ã¯ãŒããšã³ããªã®æ£ç¢ºæ§ããã¡ã€ã«æå·åã®æ£ç¢ºæ§ãããã³è¡šç€ºãããã¡ã€ã«ãšè¡šç€ºããªããã¡ã€ã«ã決å®ããŸãïŒã€ãŸãããã®ããŒã§æå·åãããŸãïŒã ãã¹ã¯ãŒããå¿ããå Žåã¯ããã¹ãŠã®ããŒã¿ãå®å šã«åé€ã§ããŸããã埩å ããããšã¯ã§ããŸããã äœæ¥ã®ããã»ã¹ã¯æ¬¡ã®ãšããã§ãã
testcrypt # encfs /var/crypto /mnt <br/>Creating new encrypted volume.<br/>Please choose from one of the following options:<br/> enter "x" for expert configuration mode,<br/> enter "p" for pre-configured paranoia mode,<br/> anything else , or an empty line will select standard mode.<br/>?><br/> <br/>Standard configuration selected.<br/> <br/>Configuration finished. The filesystem to be created has<br/>the following properties:<br/>Filesystem cipher: "ssl/aes" , version 2 : 1 : 1 <br/>Filename encoding: "nameio/block" , version 3 : 0 : 1 <br/>Key Size: 192 bits<br/>Block Size: 1024 bytes<br/>Each file contains 8 byte header with unique IV data.<br/>Filenames encoded using IV chaining mode.<br/> <br/>Now you will need to enter a password for your filesystem.<br/>You will need to remember this password, as there is absolutely<br/>no recovery mechanism. However, the password can be changed<br/>later using encfsctl.<br/> <br/>New Encfs Password:<br/>Verify Encfs Password:<br/>testcrypt # mount | grep mnt <br/>/dev/fuse0 on /mnt (fusefs, local , synchronous)<br/>testcrypt # cp /etc/defaults/* /mnt <br/>testcrypt # ls /mnt <br/>bluetooth.device.conf devfs.rules pccard.conf periodic.conf rc.conf<br/> <br/>testcrypt # ls /var/crypto/ <br/>.cryptofs Nq2IBppvuCpNNHuYS1k5dn-q wiNUtxqXvJqCLs3s-u1qwJrA<br/>.encfs6.xml gNsHASsB,5N2H1TZlWTJjldR<br/>B7rx58O9WjTGrjeTaiFXjREamAQzW7u3oK3NOK1KuN4Rp- sTZaWdYP4B-oXrW1d1COMMNV
ããŒã¿ã®ããã¯ã¢ããã¯ãã¹ãããã·ã§ãããããŒãã£ã·ã§ã³ããåé€ããéåžžã®æ¹æ³ãšããã¡ã€ã«ãç®çã®å Žæã«çŽæ¥ã³ããŒããããšã«ãã£ãŠå®è¡ã§ããŸããäž»ãªããšã¯ãé埩å·åã®å¯èœæ§ã®ããã«ããŒãä¿åããããšã§ãã
çµè«ïŒãã®èšäºã§åãäžãããã£ã¹ã¯äžã®ããŒã¿ãæå·åããæ¹æ³ã¯ãã¹ãŠãæ¥åžžç掻ã§äœ¿çšããè³æ ŒããããŸãã 䜿çšããæå·åã·ã¹ãã ã«å¿ããŠãå¿ èŠãªæ©èœãçæéã§å ¥æã§ããŸãã ç§ããã¹ãããã·ã¹ãã ã®äžã§ãç§ã¯ãŸã geliãšencfsãéžã¶ã§ãããã æåã®ã·ã¹ãã ã¯ãããŒããŠã§ã¢æå·åã¢ãžã¥ãŒã«ã®äœ¿çšãšãã芳ç¹ããéåžžã«é åçã§ããã©ã®ããã»ããµæéã䜿çšããŠããŒã¿æå·åã«è²»ãããªãããããŒãã£ã·ã§ã³å šäœãæå·åããæ©èœã䜿çšããŸãã 2çªç®ã®ã·ã¹ãã ã¯ãæå·åããããã¡ã€ã«ã®æŽåæ§å¶åŸ¡ã¢ãŒããšå€ãã®ãã©ã¡ãŒã¿ãŒãå€æŽããæ©èœã«ãšã£ãŠèå³æ·±ããã®ã§ãã encfsã«æ¬æãæã£ãŠãæã¡éã³ãå¿ èŠãªããã€ãã®å€éšã©ã€ãã©ãªãžã®ã·ã¹ãã ã®äŸåé¢ä¿ã«æ³šæããããšæããŸãã åã³geliã§ã¯ã倧ããªã¢ã¬ã€ã®ããã¯ã¢ããã«åé¡ããããããããŸããã ãŸããããã¯åºæ¬çã«ããã§ãã ãã®è³æããèªã¿ããã ãããããšãããããŸãã
ãã¹ãŠã®ã·ã¹ãã ã®Bonnieãã³ãããŒã¯æ¯èŒãã£ãŒã ã
é 次åºå | é æ¬¡å ¥å | ã©ã³ãã | |||||||||||
1æåããã | ãããã¯ãã | æžãæãã | 1æåããã | ãããã¯ãã | æ±ãã | ||||||||
æ©æ¢° | MB | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | /ç§ | ïŒ CPU |
ãžã§ãª+ md | 1024 | 17178 | 25.7 | 18324 | 8.4 | 5684 | 2.2 | 14492 | 15.1 | 15185 | 2.3 | 139.8 | 0.7 |
ã²ãª+ ggate | 1024 | 13855 | 20.6 | 12018 | 5.2 | 6388 | 2.7 | 19021 | 21.8 | 22473 | 4.2 | 136.5 | 0.7 |
gbde + md | 1024 | 4436 | 5.3 | 4349 | 1.7 | 2695 | 1.2 | 12920 | 13.7 | 17078 | 2.9 | 130.1 | 0.7 |
gbde + ggate | 1024 | 1971幎 | 2.2 | 1970 | 0.8 | 1480 | 0.6 | 13812 | 15.2 | 17206 | 3.0 | 120.3 | 0.6 |
fusefs + cryptofs | 1024 | 17207 | 23.8 | 21015 | 10.7 | 6494 | 3.5 | 16202 | 17.1 | 16829 | 3.2 | 70.1 | 1.2 |
fusefs + encfs | 1024 | 19073 | 25.3 | 23250 | 11.4 | 7676 | 3.9 | 16402 | 18.4 | 19187 | 3.5 | 70.3 | 1.2 |
UPDïŒã¯ãªãŒã³ãªãã¡ã€ã«ã·ã¹ãã ãšæå·åããããã¡ã€ã«ã·ã¹ãã ã®é床ãæ¯èŒããè¡šã ãœããã¢ããããŒãã®ãªã³ãšãªããåãæ¿ããŸãã
é 次åºå | é æ¬¡å ¥å | ã©ã³ãã | |||||||||||
1æåããã | ãããã¯ãã | æžãæãã | 1æåããã | ãããã¯ãã | æ±ãã | ||||||||
æ©æ¢° | MB | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | K /ç§ | ïŒ CPU | /ç§ | ïŒ CPU |
fusefs + cryptofs | 1024 | 17207 | 23.8 | 21015 | 10.7 | 6494 | 3.5 | 16202 | 17.1 | 16829 | 3.2 | 70.1 | 1.2 |
fusefs + encfs | 1024 | 19073 | 25.3 | 23250 | 11.4 | 7676 | 3.9 | 16402 | 18.4 | 19187 | 3.5 | 70.3 | 1.2 |
cleanfs + su_on | 4096 | 33745 | 33.5 | 32517 | 12.8 | 10681 | 4.4 | 34911 | 35.9 | 39035 | 7.7 | 80.1 | 0.5 |
cleanfs + su_off | 4096 | 34918 | 33.4 | 35108 | 12.9 | 11188 | 4.5 | 37268 | 38.3 | 39513 | 7.6 | 84.6 | 0.5 |
(C) Aborche 2009
