認証技術
NIST SP 800-175B Rev. 1 は「認証」という語をどう扱っているか。
一般的な用法では「認証」が出所の認証か身元の認証のどちらかだけを指して使われていると指摘し、 文書内では source authentication(出所)、identity authentication(身元)、 integrity authentication(完全性)の 3 つの用語で使い分けるとしている。 使い分ける理由は、この注記には書かれていない。
FIPS 200 と SP 800-57 Part 1 Rev. 5 の認証の定義は、確かめる対象の範囲がどう違うか。
FIPS 200 は利用者・プロセス・デバイスの身元の検証とする。 SP 800-57 Part 1 Rev. 5 は、情報の出所と完全性についての保証を与える過程、 または主体の身元についての保証を与える過程とし、より広い。
NIST SP 800-175B Rev. 1 は、一般的な用法では「認証」が出所か身元の認証のどちらかだけを指すと注記し、文書内では source authentication(出所)、identity authentication(身元)、integrity authentication(完全性)の 3 つの用語で使い分けるとしている。
| 確かめる対象 | NIST SP 800-175B Rev. 1 の用語 |
|---|---|
| 情報の出所 | source authentication |
| 主体の身元 | identity authentication |
| 情報が改変されていないこと | integrity authentication |
FIPS 200 は認証を “Verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.” と定義している。 すなわち利用者・プロセス・デバイスの身元を検証することであり、多くの場合、 情報システムの資源へのアクセスを許す前提として行われる。
FIPS 201-3 は「真正性への確信を確立する過程」とし、この場合は人の身元と認証器 (PIV カードや派生した資格情報など)の妥当性を対象とする。
NIST SP 800-57 Part 1 Rev. 5 の定義はより広い。 “A process that provides assurance of the source and integrity of information in communications sessions, messages, documents or stored data or that provides assurance of the identity of an entity interacting with a system.” すなわち、通信セッション・メッセージ・文書・保存データにおける 情報の出所と完全性についての保証を与える過程、または、システムと対話する主体の身元についての 保証を与える過程である。
一語が複数の意味を持つこと
Section titled “一語が複数の意味を持つこと”NIST SP 800-175B Rev. 1 はこの点を明示的に注記している。 “Note that in common practice, the term ‘authentication’ is used to mean either source or identity authentication only. This document will differentiate the multiple uses of the word by the terms source authentication, identity authentication, or integrity authentication, where appropriate.”
つまり、一般的な用法では「認証」が出所の認証か身元の認証のどちらかだけを指して使われているが、 この文書では 3 つの用語で使い分けるとしている。
完全性との関係
Section titled “完全性との関係”FIPS 200 の完全性の定義は “Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity.” であり、 否認防止(non-repudiation)と真正性(authenticity)の確保を含んでいる。 SP 800-175B Rev. 1 の 3 つの用語が、この定義のどの部分に対応するかは、ここで根拠にした資料には書かれていない。
前提
関連