ãéåãžã®åãããåãçŽãäŒæ¥ITã®å¯¿åœèšèšâPost-Quantum Cryptographyæšæºåããããããã©ãã€ã ã·ãã
ãããããã®å°æ¥ãåŸ ã€ããšãªããäžçã®ã»ãã¥ãªãã£ã³ãã¥ããã£ã¯ãã§ã«äžå¯éãªè»¢æç¹ãè¶ ããŠããã2020幎代ååãç±³åœæšæºæè¡å±ïŒNISTïŒã«ããPost-Quantum CryptographyïŒPQCïŒèéåèšç®æ©æå·ïŒã®æšæºåããã»ã¹ãæçµæ®µéãè¿ããæ°ããªé£éŠæšæºïŒFIPSïŒãšããŠçµå®ããããšããŠããããã ãããã¯åãªãæè¡ä»æ§ã®æ¹å®ã§ã¯ãªããã€ã³ã¿ãŒãããã®é»ææããçŸä»£ã«è³ããŸã§ãããžã¿ã«ã®ä¿¡é Œãæ ¹åºã§æ¯ããŠããRSAæå·ãæ¥åæ²ç·æå·ãšãã£ããçŸä»£æå·ã®çµçããšãããã«ä»£ãããæ¬¡äžä»£æå·ãžã®ç§»è¡ããšãããæ°å幎åäœã®å·šå€§ãªå°æ®»å€åãå§ãŸã£ãããšãæå³ããŠãããGoogleãCloudflareãšãã£ããã¯ãããžãŒã®å·šäººã¯ãã§ã«ãã©ãŠã¶ããããã¯ãŒã¯ã¬ãã«ã§ã®å®è£ å®éšãç¹°ãè¿ããŠããã倧æã¯ã©ãŠããã³ããŒãæ°Žé¢äžã§å¯Ÿå¿ãé²ããŠãããæ¬çš¿ã§ã¯ããŸã èŠã¬è åšã§ããã¯ãã®éåèšç®æ©å¯Ÿçãããªãä»ãäŒæ¥ã®å«ç·ã®èª²é¡ãšããŠæµ®äžããŠããã®ãããããŠPQCãžã®ç§»è¡ãäŒæ¥ITã®é·ææŠç¥ã«ã©ã®ãããªå€é©ãè¿«ãã®ãããæè¡çèæ¯ãšçµå¶çãªã¹ã¯ã®äž¡é¢ãã詳説ããã
ãHarvest Now, Decrypt Laterãã®è åšãšæšæºåã®å é
äžè¬ã«ãéåã³ã³ãã¥ãŒã¿ã«ããæå·è§£èªã®è©±é¡ãåºããšãå€ãã®çµå¶è ãIT責任è ã¯ããŸã å®çšåã«ã¯æéããããããèªåãçŸåœ¹ã®éã¯é¢ä¿ãªãããšæããã¡ã§ããã確ãã«ãShorã®ã¢ã«ãŽãªãºã ãçšããŠçŸåšã®å ¬é鵿å·ãçŸå®çãªæéã§ç Žãããã«å¿ èŠãªãå€§èŠæš¡ãã€èª€ãèšæ£æ©èœãåããéåã³ã³ãã¥ãŒã¿ã®å®çŸã¯ãäŸç¶ãšããŠæè¡çãªããŒãã«ãé«ããããããäŒæ¥ãçŽé¢ããŠãããªã¹ã¯ã®å®äœã¯ãå°æ¥ã®è§£èªèœåãã®ãã®ã§ã¯ãªããçŸåšã®ããŒã¿ãæªæ¥ã®æç¹ã§å±éºã«æããããšããæé軞ã®ãºã¬ã«ããã ã»ãã¥ãªãã£æ¥çã§ãHarvest Now, Decrypt LaterïŒä»åéããåŸã§è§£èªããïŒããšåŒã°ããæ»æææ³ãžã®æžå¿µããååœã®æšæºåãæ¥ãããæå€§ã®èŠå ãšãªã£ãŠãããæ»æè ã¯ãããšãçŸæç¹ã§ã¯æå·ãè§£èªã§ããªããšããã¿ãŒã²ãããšããäŒæ¥ã®éä¿¡ããŒã¿ãæå·åããããã¡ã€ã«ãä»ã®ãã¡ã«å€§éã«åéã»ä¿åããŠããããšãå¯èœã§ããããããŠãå°æ¥çã«ååãªæ§èœãæã€éåã³ã³ãã¥ãŒã¿ãç»å Žããç¬éã«ãéå»ã«èç©ããããŒã¿ãäžæ°ã«è§£èªã«ãããã®ã ããã®ã·ããªãªã«ãããŠãæå·åéä¿¡ã®å®å šæ§ã¯ãéä¿¡ããŠããç¬éãã ãã§ã¯å®çµããªãããã®æ å ±ãæã€æ©å¯æ§ã®ä¿ææéãšãæå·æè¡ãç ŽããããŸã§ã®æéã®ç«¶èµ°ãšãªãã
ããšãã°ãåœå®¶æ©å¯ã«é¢ããå€äº€ææžãç¥ç財ç£ãšãªãæ°è¬ã®ç ç©¶ããŒã¿ããããã¯å人ã®éºäŒåæ å ±ãé·æã®éèè³ç£èšé²ãªã©ã¯ã10幎ããæ°å幎ãšããæ¥µããŠé·ãæéã«ããã£ãŠæ©å¯æ§ãç¶æããå¿ èŠãããããã2030幎代ãããã¯2040幎代ã«éåèšç®æ©ãå®çšåããããšä»®å®ããã°ã仿¥éä¿¡ãããŠããé·æä¿åããŒã¿ã®å€ãã¯ããã§ã«å±éºæ°Žåã«å ¥ã£ãŠãããšèšããã ãããNISTãéžå®ããCRYSTALS-KyberïŒéµå ±ææ¹åŒãæšæºååç§°ïŒML-KEMïŒãCRYSTALS-DilithiumïŒçœ²åæ¹åŒãæšæºååç§°ïŒML-DSAïŒãšãã£ãæ°ããã¢ã«ãŽãªãºã ã¯ããããããæªæ¥ã®è åšã«ããçŸåšã®ãªã¹ã¯ããå°ã蟌ããããã®é²æ³¢å €ã§ããããããã¯åŸæ¥ã®çŽ å æ°åè§£ã颿£å¯Ÿæ°åé¡ãšã¯ç°ãªããæ Œåæå·ãªã©ã®æ°åŠçé£åãå®å šæ§ã®æ ¹æ ãšããŠãããéåèšç®æ©ã«ããæ»æã«èããããšèããããŠããããã§ã«ãããã®ã¢ã«ãŽãªãºã ã¯FIPSïŒé£éŠæ å ±åŠçæšæºïŒãšããŠææžåãé²ã¿ãTLSïŒTransport Layer SecurityïŒãVPNãé»å眲åãšãã£ã瀟äŒã€ã³ãã©ã®æ·±å±€ãžã®çµã¿èŸŒã¿ãåæãšãªãã€ã€ãããã€ãŸããPQCã¯é ãæªæ¥ã®æè¡ã§ã¯ãªãããã§ã«å®è£ ãã§ãŒãºã«å ¥ã£ããçŸä»£ã®æè¡ããªã®ã§ããã
ã¢ã«ãŽãªãºã ã®ããªãã¬ãŒã¹ããè¶ ããã·ã¹ãã åºç€ãžã®è¡æ
PQCãžã®ç§»è¡ãäŒæ¥ITã«ãšã£ãŠæ¥µããŠåä»ãªã®ã¯ããããåãªããœãããŠã§ã¢ã®ã¢ããããŒãããèšå®ãã¡ã€ã«ã®æžãæãçšåºŠã§ã¯æžãŸãªãå¯èœæ§ãé«ããšããç¹ã«ããããã€ãŠDESããAESãžããããã¯SHA-1ããSHA-2ãžãšæå·ã¢ã«ãŽãªãºã ãç§»è¡ããéãçžå¿ã®åŽåãèŠããããä»åã®PQCç§»è¡ã¯ããããšã¯æ¯èŒã«ãªããªãã»ã©ã·ã¹ãã åºç€ãžã®ç©ççã»è«ççãªã€ã³ãã¯ãã倧ããã ãã®æå€§ã®èŠå ã¯ãéµãµã€ãºãšçœ²åããŒã¿ãµã€ãºã®è¥å€§åã§ãããããšãã°ãéµå ±æã¡ã«ããºã ã§ããML-KEMã¯ãçŸåšäž»æµã®æ¥åæ²ç·æå·ïŒECDHãªã©ïŒãšæ¯èŒããŠãéµé·ãæå·æã®ãµã€ãºãæ¡éãã«å€§ãããªãåŸåããããåæ§ã«ãé»å眲åã«çšããããML-DSAããåŸæ¥ã®RSAãECDSAã«æ¯ã¹ãŠçœ²åãµã€ãºãå¢å€§ãããææ°ã®é«æ§èœãµãŒããŒã倪ã垯åãæã€ããã¯ããŒã³åç·ã§ããã°ããã®çšåºŠã®ãªãŒããŒãããã¯èš±å®¹ç¯å²ãããããªãããããããªãœãŒã¹ãå³ããå¶éãããç°å¢ã«ãããŠã¯ããã®ãéãããèŽåœçãªããã«ããã¯ãšãªãåŸãã
å ·äœçã«åœ±é¿ãæžå¿µãããã®ã¯ãIoTïŒInternet of ThingsïŒãOTïŒOperational TechnologyïŒã®é åã§ãããå·¥å Žå ã®ã»ã³ãµãŒãèªåè»ã®å¶åŸ¡ãŠããããã¹ããŒãã¡ãŒã¿ãŒããããã¯å»ççšåã蟌ã¿ããã€ã¹ãªã©ã¯ã極ããŠéãããã¡ã¢ãªãšèšç®èœåã§åäœããŠãããé信垯åãçãå Žåãå€ããããã«ãµã€ãºã®å€§ããªPQCããã®ãŸãŸå°å ¥ããããšããã°ããã±ããåå²ã«ããé å»¶ã®å¢å€§ãã¡ã¢ãªäžè¶³ã«ããåäœäžå®å®ããããã¯ãã³ãã·ã§ã€ã¯åŠçã«ããããããªãŒæ¶è²»ã®æ¿å¢ãšãã£ãåé¡ãé¡åšåããæããããã ããã«ãæ¢åã®ãããã³ã«ãããŒã¿ãã©ãŒãããããããã»ã©å€§ããªéµã眲åãæ ŒçŽããããšãæ³å®ããŠããªãã±ãŒã¹ãå€ã ãããX.509èšŒææžã«PQCã®å ¬ééµã眲åãåã蟌ãã çµæãèšŒææžã®ãµã€ãºãè¥å€§åããåŸæ¥ã®UDPããŒã¹ã®éä¿¡ã§ãã±ãããµã€ãºå¶éã«æµè§Šããããå€ãããã«ãŠã§ã¢ããããã¡ãªãŒããŒãããŒãèµ·ãããããããªã¹ã¯ãææãããŠããã
ãŸããç§»è¡æç¹æã®è€éããšããŠããã€ããªããæå·ãã®éçšãæãããããPQCã®ã¢ã«ãŽãªãºã ã¯æ¯èŒçæ°ãããããå°æ¥çã«æªç¥ã®è匱æ§ãèŠã€ããå¯èœæ§ãå®å šã«ã¯åŠå®ã§ããªãããã®ãããç§»è¡æéäžã¯ãé·å¹Žã®å®çžŸãããåŸæ¥ã®æ¥åæ²ç·æå·ãšãæ°ããPQCã¢ã«ãŽãªãºã ãçµã¿åãããŠäºéã«éµå ±æãè¡ãããã€ããªããæ¹åŒããæšå¥šãããŠãããããã¯å®å šæ§ã«ãããä¿éºãšããŠã¯åççã ããã·ã¹ãã éçšåŽããèŠãã°ã管çãã¹ãéµã®çš®é¡ãå¢ããåŠçè² è·ãå¢å€§ãããã©ãã«ã·ã¥ãŒãã£ã³ã°ãè€éåããããšãæå³ãããæ¢åã®RSAãECDSAã®ã¿ã«å¯Ÿå¿ããã¬ã¬ã·ãŒæ©åšãšãPQC察å¿ã®ææ°æ©åšãæ··åšããç°å¢ããã»ãã¥ãªãã£ããªã·ãŒã®äžè²«æ§ãä¿ã¡ãªããã©ãçµ±å管çããŠããã®ããäŒæ¥ã¯ããããã¯ãŒã¯æ©åšã®è²·ãæ¿ããµã€ã¯ã«ãã¢ããªã±ãŒã·ã§ã³ã®æ¹ä¿®èšç»ãå«ãããé·æçãªããŒããããã®çå®ãè¿«ãããããšã«ãªãã
æå·ã©ã€ããµã€ã¯ã«ç®¡çïŒCLMïŒãšãã¯ãªããã»ã¢ãžãªãã£ãã®ç¢ºç«
ãã®ãããªæè¡çã»éçšçãªèª²é¡ãåã«ããŠãäŒæ¥ã¯ã©ã®ãããªæŠç¥ãæã€ã¹ããªã®ããæãéèŠãªèŠç¹ã¯ãPQC察å¿ãåãªãã20XX幎åé¡ãã®ãããªæéä»ãã®å¯ŸåŠçæ³ãšããŠæããã®ã§ã¯ãªããçµç¹å šäœã®ãæå·ã®ç®¡çèœåïŒã¯ãªããã»ã¢ãžãªãã£ïŒããææ¬çã«åŒ·åããæ©äŒãšæããããšã§ããã ã¯ãªããã»ã¢ãžãªãã£ãšã¯ã䜿çšããŠããæå·ã¢ã«ãŽãªãºã ã«å±æ®åïŒå®å šæ§ãæãªãããããšïŒãè匱æ§ãçºèŠãããéã«ãã·ã¹ãã å šäœãžã®åœ±é¿ãæå°éã«æãã€ã€ãè¿ éãã€ã¹ã ãŒãºã«æ°ããå®å šãªã¢ã«ãŽãªãºã ãžåãæ¿ããèœåãæãããããŸã§å€ãã®äŒæ¥ã·ã¹ãã ã§ã¯ãæå·ã¢ã«ãŽãªãºã ã¯äžåºŠå®è£ ãããã°ãã·ã¹ãã ã廿£ããããŸã§å¡©æŒ¬ãã«ãããããšãäžè¬çã§ãã£ããã¢ããªã±ãŒã·ã§ã³ã®ã³ãŒãã®äžã«ããŒãã³ãŒããããŠããããããŒããŠã§ã¢ãããã«çŒãä»ããããŠãããããŠã容æã«å€æŽã§ããªãæ§é ã«ãªã£ãŠããããšãå€ãã£ãã®ã§ãããPQCãžã®ç§»è¡ã¯ããããã硬çŽçãªæ§é ãæç Žããæå·éšåããã€ã§ã亀æå¯èœãªãéšåããšããŠççµååããã¢ãŒããã¯ãã£ãžã®è»¢æãä¿ããã®ã§ããã
å ·äœçãªç¬¬äžæ©ãšããŠæ±ããããã®ã¯ãèªç€Ÿã®ã·ã¹ãã è³ç£ã«ãããæå·äŸåé¢ä¿ã®å®å šãªæ£åžãã§ããããããè¿å¹Žã§ã¯ãCBOMïŒCryptography Bill of MaterialsïŒæå·éšå衚ïŒããšåŒã¶åãããããã©ã®ãµãŒããŒã®ã©ã®ã©ã€ãã©ãªã§ãã©ã®ããŒãžã§ã³ã®OpenSSLãåããŠããã®ããç¬èªéçºã®ã¢ããªã±ãŒã·ã§ã³å ã§ãã©ã®ãããªæå·é¢æ°ãåŒã³åºãããŠããã®ããå€éšãšæ¥ç¶ããVPNè£ çœ®ããã¯ã©ãŠããµãŒãã¹ãšã®API飿ºã«ãããŠãã©ã®æå·ã¹ã€ãŒãã䜿ãããŠããã®ãããããŠäœãããããããã®ã·ã¹ãã ã§æ±ãããŠããããŒã¿ã®ä¿åæéã¯ã©ãããããªã®ããããããç¶²çŸ çã«å¯èŠåããªãéããã©ãããæãã€ããã¹ããã®åªå é äœããæ±ºããããšãã§ããªãã ç¹ã«ãæ å ±ã®ã寿åœããšæå·ã®ã寿åœãã®ã®ã£ããã倧ããé åããããæåªå ã§å¯Ÿçãè¬ããã¹ããããã¹ããããšãªããããšãã°ãæ³å®ä¿åæéãé·ãææžç®¡çã·ã¹ãã ãã補å寿åœã20幎ã«åã¶ã€ã³ãã©èšåã®å¶åŸ¡ã·ã¹ãã ãªã©ã¯ãæ±çšçãªITæ©åšãããã¯ããã«æ©ã段éã§PQC察å¿ããããã¯ãã€ããªããæ§æãžã®ç§»è¡èšç»ãç«ãŠãå¿ èŠãããã ãããéã«ãæ°æéã§äŸ¡å€ã倱ãäžæçãªãã°ããŒã¿ããçæéã§ç Žæ£ããããã£ãã·ã¥ããŒã¿ã§ããã°ãçŽã¡ã«ã³ã¹ãããããŠPQCãå°å ¥ããå¿ èŠæ§ã¯äœããããããªãã
çµå±ã®ãšãããPost-Quantumæä»£ã«ãããã»ãã¥ãªãã£æŠç¥ãšã¯ãæ¥ãã¹ãéåã³ã³ãã¥ãŒã¿ã®è åšã«æ¯ããããšã§ã¯ãªããèªç€Ÿãå®ãã¹ãæ å ±ã®äŸ¡å€ãšæé軞ãåå®çŸ©ãããããå®ãããã®æè¡åºç€ããæŽæ°å¯èœãªç¶æ ãã«ä¿ã¡ç¶ããããã»ã¹ãã®ãã®ã§ãããšèšãããéåæè¡ã®é²å±é床ã¯ãäžäŒæ¥ã®ã³ã³ãããŒã«ãè¶ ããå€éšèŠå ã§ãããããããèªç€Ÿã®ã·ã¹ãã ãå€ãæå·æè¡ãšå¿äžããã®ãããããšãæ°ããæè¡ãæè»ã«åãå ¥ããããäœè³ªã«å€ããã®ãã¯ãçµå¶ã®æææ±ºå®ã«ããã£ãŠãããPQCæšæºåãšããæ³¢ã¯ãæå·ãšãããèŠããªãã€ã³ãã©ããçµå¶ã¢ãžã§ã³ããžãšæŒãäžããéçã ã£ãã»ãã¥ãªãã£éçšãåçã§ããªãããªãã®ãžãšé²åãããããã®ã匷åãªè§ŠåªãšããŠæ©èœããŠããã®ã§ããã





