äžçäžã®ãŠãŒã¶ãŒã®ã»ãã¥ãªãã£ã匷åãããããSMSããŒã¹ã®äºèŠçŽ èªèšŒïŒ2FAïŒå°å ¥ã®å©ç¹ããã¹ããã©ã¯ãã£ã¹ãããã³ã°ããŒãã«ãªèæ ®äºé ãæ¢ããŸãã
äžçãå®å šã«ïŒäºèŠçŽ èªèšŒã®ããã®SMS飿ºã®å æ¬çãªã¬ã€ã
仿¥ã®çžäºæ¥ç¶ãããäžçã«ãããŠãã»ãã¥ãªãã£ã¯æãéèŠã§ããããŒã¿äŸµå®³ãäžæ£ã¢ã¯ã»ã¹ã¯ãŸããŸãå·§åŠåããŠãããå ç¢ãªèªèšŒæ¹æ³ãæ±ããããŠããŸããäºèŠçŽ èªèšŒïŒ2FAïŒã¯ãã¢ã«ãŠã³ã䟵害ã®ãªã¹ã¯ãå€§å¹ ã«è»œæžããæ¥µããŠéèŠãªã»ãã¥ãªãã£å±€ãšããŠç»å ŽããŸããããã®ã¬ã€ãã§ã¯ã2FAã®ããã®SMS飿ºã®åãæ¢ãããã®å©ç¹ããã¹ããã©ã¯ãã£ã¹ãããã³ã°ããŒãã«ãªèæ ®äºé ãæ€èšããããšã§ããŠãŒã¶ãŒãã©ãã«ããŠã广çã«ã»ãã¥ãªãã£ã確ä¿ã§ããããæ¯æŽããŸãã
äºèŠçŽ èªèšŒïŒ2FAïŒãšã¯ïŒ
äºèŠçŽ èªèšŒïŒ2FAïŒã¯ãå€èŠçŽ èªèšŒïŒMFAïŒãšãåŒã°ããåŸæ¥ã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã«ãããã°ã€ã³ããã»ã¹ã«ã远å ã®ã»ãã¥ãªãã£å±€ãå ãããã®ã§ãããŠãŒã¶ãŒãç¥ã£ãŠãããã®ïŒãã¹ã¯ãŒãïŒã ãã«é Œãã®ã§ã¯ãªãã2FAã¯ãéåžžãŠãŒã¶ãŒãæã£ãŠãããã®ïŒæºåž¯é»è©±ãªã©ïŒãŸãã¯ã§ãããã®ïŒçäœèªèšŒãªã©ïŒãšãã第2ã®æ€èšŒèŠçŽ ãèŠæ±ããŸããããã«ãããæ»æè ããŠãŒã¶ãŒã®ãã¹ã¯ãŒããå ¥æã§ãããšããŠããäžæ£ã¢ã¯ã»ã¹ãè¡ãããšãã¯ããã«å°é£ã«ãªããŸãã
æãäžè¬çãª2FAæ¹æ³ã¯ä»¥äžã®éãã§ãã
- SMSããŒã¹ã®2FA: ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãïŒOTPïŒãSMSçµç±ã§ãŠãŒã¶ãŒã®æºåž¯é»è©±ã«éä¿¡ãããŸãã
- èªèšŒã¢ããª: Google AuthenticatorãAuthyã®ãããªã¢ããªãæéããŒã¹ã®OTPãçæããŸãã
- Eã¡ãŒã«ããŒã¹ã®2FA: OTPããŠãŒã¶ãŒã®ç»é²æžã¿Eã¡ãŒã«ã¢ãã¬ã¹ã«éä¿¡ãããŸãã
- ããŒããŠã§ã¢ããŒã¯ã³: OTPãçæããç©çããã€ã¹ã§ãã
- çäœèªèšŒ: æçŽã¹ãã£ã³ãé¡èªèããã®ä»ã®çäœèªèšŒæ¹æ³ã§ãã
ãªã2FAã«SMS飿ºãéžã¶ã®ãïŒ
æ§ã ãª2FAæ¹æ³ãååšããŸãããSMS飿ºã¯åºç¯ãªå°éæ§ãšäœ¿ãããããããäŸç¶ãšããŠäººæ°ããããã¢ã¯ã»ã¹ããããéžæè¢ã§ããäž»ãªå©ç¹ã¯ä»¥äžã®éãã§ãã
- æ®åæ§: æºåž¯é»è©±ã¯äžçäžã§æ®åããŠãããSMSã¯ã»ãšãã©ã®ãŠãŒã¶ãŒã«ãšã£ãŠããã«å©çšã§ãããã£ãã«ã§ããããã¯ãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãéãããŠããå°åãã¹ããŒããã©ã³ã®æ®åãé²ãã§ããªãå°åã§ç¹ã«éèŠã§ããäŸãã°ãå€ãã®çºå±éäžåœã§ã¯ãåºæ¬çãªæºåž¯é»è©±ãã¹ããŒããã©ã³ãããã¯ããã«äžè¬çã§ããSMS 2FAã¯ãããåºç¯ãªãŠãŒã¶ãŒå±€ãå©çšã§ããã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãæäŸããŸãã
- 䜿ãããã: SMS OTPãåä¿¡ããŠå ¥åããããã»ã¹ã¯ã·ã³ãã«ã§ãã»ãšãã©ã®ãŠãŒã¶ãŒãçŽæçã«çè§£ã§ããŸããç¹å¥ãªãœãããŠã§ã¢ãæè¡çãªå°éç¥èã¯å¿ èŠãããŸããã
- è²»çšå¯Ÿå¹æ: SMSããŒã¹ã®2FAã¯ãç¹ã«å€§èŠæš¡ãªãŠãŒã¶ãŒããŒã¹ãæã€äŒæ¥ã«ãšã£ãŠãè²»çšå¯Ÿå¹æã®é«ããœãªã¥ãŒã·ã§ã³ãšãªãåŸãŸããSMSã¡ãã»ãŒãžãããã®ã³ã¹ãã¯éåžžäœããç«¶äºåã®ããäŸ¡æ Œèšå®ã®SMS APIãå©çšããå Žåã«ç¹ã«é¡èã§ãã
- 芪ãã¿ããã: ãŠãŒã¶ãŒã¯SMSã¡ãã»ãŒãžã®åä¿¡ã«äžè¬çã«æ £ããŠãããSMS 2FAã¯ãªãã¿ã®ãªãèªèšŒæ¹æ³ãšæ¯èŒããŠãéªéã«ãªãã«ãããå°å ¥ã容æã§ãã
- ãã©ãŒã«ããã¯ã¡ã«ããºã : ä»ã®2FAæ¹æ³ãæ©èœããªãå¯èœæ§ã®ããç¶æ³ïŒäŸïŒèªèšŒã¢ããªã®çŽå€±ãçäœèªèšŒã»ã³ãµãŒã®èª€äœåïŒã§ã¯ãSMSã¯ä¿¡é Œæ§ã®é«ããã©ãŒã«ããã¯ãªãã·ã§ã³ãšããŠæ©èœããŸãã
SMS 2FAã®ä»çµã¿ïŒã¹ããããã€ã¹ãããã¬ã€ã
SMSããŒã¹ã®2FAã®ããã»ã¹ã¯ãé垞以äžã®ã¹ããããå«ã¿ãŸãã
- ãŠãŒã¶ãŒãã°ã€ã³è©Šè¡: ãŠãŒã¶ãŒã¯ãŠã§ããµã€ããŸãã¯ã¢ããªã±ãŒã·ã§ã³ã«ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããå ¥åããŸãã
- 2FAããªã¬ãŒ: ã·ã¹ãã ã¯2FAã®å¿ èŠæ§ãèªèããSMS OTPçæããã»ã¹ãããªã¬ãŒããŸãã
- OTPçæãšSMSéä¿¡: ãµãŒããŒã«ãã£ãŠäžæã®ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãïŒOTPïŒãçæãããŸãããã®OTPã¯ãSMSã²ãŒããŠã§ã€ãŸãã¯APIãä»ããŠããŠãŒã¶ãŒã®ç»é²æžã¿æºåž¯é»è©±çªå·ã«SMSã§éä¿¡ãããŸãã
- OTPæ€èšŒ: ãŠãŒã¶ãŒã¯OTPãå«ãSMSã¡ãã»ãŒãžãåä¿¡ãããŠã§ããµã€ããŸãã¯ã¢ããªã±ãŒã·ã§ã³ã®æå®ããããã£ãŒã«ãã«å ¥åããŸãã
- ã¢ã¯ã»ã¹èš±å¯: ã·ã¹ãã ã¯ãçæããã³éä¿¡ãããOTPãšç §åããŠOTPãæ€èšŒããŸããOTPãäžèŽããæå¹ãªæéæ å ã§ããå ŽåããŠãŒã¶ãŒã¯ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹ãèš±å¯ãããŸãã
SMS 2FAå®è£ ã®ãã¹ããã©ã¯ãã£ã¹
SMS 2FAå®è£ ã®å¹æãšã»ãã¥ãªãã£ã確ä¿ããããã«ã以äžã®ãã¹ããã©ã¯ãã£ã¹ãæ€èšããŠãã ããã
- ä¿¡é Œã§ããSMS APIãããã€ããŒãéžã¶: ã°ããŒãã«ã«ãã¬ããžãé«ãé ä¿¡çãå ç¢ãªã»ãã¥ãªãã£å¯Ÿçãåããä¿¡é Œã§ããSMS APIãããã€ããŒãéžã³ãŸãããã皌åæéSLAããµããŒãã®å©çšå¯èœæ§ãGDPRãHIPAAãªã©ã®ã³ã³ãã©ã€ã¢ã³ã¹èªèšŒãšãã£ãèŠçŽ ãèæ ®ããŠãã ãããã¡ãã»ãŒãžãã¥ãŒã€ã³ã°ãé ä¿¡ã¬ããŒããçªå·æ€èšŒãªã©ã®æ©èœãæäŸãããããã€ããŒãæ¢ããŸããããäŸãã°ãTwilioãMessageBirdãVonageã®ãããªäŒæ¥ã¯ãã°ããŒãã«ãª2FAå®è£ ã®ããã®ä¿¡é Œæ§ã®é«ãSMS APIãæäŸããŠããŸãã
- 匷åãªOTPçæãå®è£ ãã: æå·åŠçã«å®å šãªä¹±æ°ãžã§ãã¬ãŒã¿ãŒã䜿çšããŠãäºæž¬ãå°é£ãªOTPãäœæããŸããåèªèšŒè©Šè¡ã«å¯ŸããŠOTPãäžæã§ããããšã確èªããŠãã ããã
- çãOTPæå¹æéãèšå®ãã: OTPã®æå¹æéãçãïŒäŸïŒ30ïœ60ç§ïŒå¶éããååãããå Žåã®äžæ£äœ¿çšã®ãªã¹ã¯ãæå°éã«æããŸãã
- é»è©±çªå·ãæ€èšŒãã: ãŠãŒã¶ãŒã«å¯ŸããŠSMS 2FAãæå¹ã«ããåã«ãæäŸãããé»è©±çªå·ãæå¹ã§ããããã®ãŠãŒã¶ãŒã®ãã®ã§ããããšã確èªããŸããããã¯ããŠãŒã¶ãŒããŠã§ããµã€ããŸãã¯ã¢ããªã±ãŒã·ã§ã³ã§å ¥åããå¿ èŠãããäžæã®ã³ãŒããå«ãæ€èšŒSMSãéä¿¡ããããšã§è¡ãããšãã§ããŸãã
- ã¬ãŒãå¶éãå®è£ ãã: æ»æè ãOTPãç¹°ãè¿ãæšæž¬ããããšãããã«ãŒããã©ãŒã¹æ»æãé²ãããã«ãã¬ãŒãå¶éãå®è£ ããŸããç¹å®ã®æéæ å ã§åäžã®IPã¢ãã¬ã¹ãŸãã¯é»è©±çªå·ããã®OTPãªã¯ãšã¹ãã®æ°ãå¶éããŸãã
- SMSã²ãŒããŠã§ã€éä¿¡ãä¿è·ãã: ãµãŒããŒãšSMSã²ãŒããŠã§ã€éã®éä¿¡ãHTTPSïŒSSL/TLSïŒæå·åã䜿çšããŠä¿è·ãããŠããããšã確èªããŸãã
- ãŠãŒã¶ãŒãæè²ãã: SMS 2FAã®äœ¿ç𿹿³ã«ã€ããŠããŠãŒã¶ãŒã«æç¢ºã§ç°¡æœãªæç€ºãæäŸããŸããæºåž¯é»è©±ãå®å šã«ä¿ã¡ãOTPã誰ãšãå ±æããªãããšã®éèŠæ§ã説æããŸãããã£ãã·ã³ã°ã®è©Šã¿ãèªèããåé¿ããããã®ãã³ããå«ããŸãã
- ãã©ãŒã«ããã¯ã¡ã«ããºã ãå®è£ ãã: ãŠãŒã¶ãŒãæºåž¯é»è©±ãžã®ã¢ã¯ã»ã¹ã倱ã£ãå ŽåãSMSã¡ãã»ãŒãžã®åä¿¡ã«åé¡ãããå Žåã«åããŠã代æ¿ã®2FAæ¹æ³ïŒäŸïŒèªèšŒã¢ããªãããã¯ã¢ããã³ãŒãïŒããã©ãŒã«ããã¯ãšããŠæäŸããŸãã
- 掻åãç£èŠããã³ãã°ã«èšé²ãã: ç¹°ãè¿ã倱æãããã°ã€ã³è©Šè¡ãç°åžžãªå Žæããã®OTPãªã¯ãšã¹ããªã©ãçããããã¿ãŒã³ããªããSMS 2FA掻åãç£èŠããŸããç£æ»ããã³ã»ãã¥ãªãã£åæã®ç®çã§ããã¹ãŠã®2FAã€ãã³ãããã°ã«èšé²ããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹ãšèŠå¶: ãŠãŒã¶ãŒãæåšããå°åã®é¢é£ããããŒã¿ãã©ã€ãã·ãŒèŠå¶ãèªèããéµå®ããŠãã ãããããã«ã¯ããšãŒãããã®GDPRãã«ãªãã©ã«ãã¢ã®CCPAãããã³ãã®ä»ã®é¡äŒŒã®æ³åŸãå«ãŸããŸããSMS 2FAã®ããã«ãŠãŒã¶ãŒã®é»è©±çªå·ãåéããã³åŠçããåã«ãé©åãªåæãåŸãããã«ããŠãã ããã
SMS 2FAã«é¢ããã°ããŒãã«ãªèæ ®äºé
SMS 2FAãã°ããŒãã«èŠæš¡ã§å®è£ ããã«ã¯ããœãªã¥ãŒã·ã§ã³ã®ä¿¡é Œæ§ãšæå¹æ§ã«åœ±é¿ãäžããå¯èœæ§ã®ããæ§ã ãªèŠå ãæ éã«èæ ®ããå¿ èŠããããŸãã
é»è©±çªå·ã®æžåŒèšå®ãšæ€èšŒ
é»è©±çªå·ã®æžåŒã¯åœã«ãã£ãŠå€§ããç°ãªããŸããåœéé»è©±çªå·ã®æ€èšŒããµããŒãããæšæºåãããé»è©±çªå·æžåŒèšå®ã©ã€ãã©ãªã䜿çšããããšãéèŠã§ããããã«ããããŠãŒã¶ãŒã®æåšå°ã«é¢ä¿ãªããé»è©±çªå·ãæ£ç¢ºã«è§£æãæ€èšŒãæžåŒèšå®ã§ããŸããlibphonenumberã®ãããªã©ã€ãã©ãªããã®ç®çã§åºã䜿çšãããŠããŸãã
SMSã®å°éæ§
SMSã®å°éæ§ã¯ãåœãã¢ãã€ã«ãããã¯ãŒã¯ã«ãã£ãŠå€§ããç°ãªããŸããå°åã®èŠå¶ããããã¯ãŒã¯ã®æ··éãã¹ãã ãã£ã«ã¿ãªã³ã°ãªã©ã®èŠå ãSMSã®é ä¿¡çã«åœ±é¿ãäžããå¯èœæ§ããããŸããã¿ãŒã²ããå°åã§åºç¯ãªã°ããŒãã«ã«ãã¬ããžãšé«ãå°éçãæã€SMS APIãããã€ããŒãéžæããããšãäžå¯æ¬ ã§ããSMSé ä¿¡ã¬ããŒããç£èŠããå°éæ§ã®åé¡ãç¹å®ããŠå¯ŸåŠããŠãã ããã
SMSã²ãŒããŠã§ã€ã®å¶é
äžéšã®åœã§ã¯ãéä¿¡è IDã®èŠä»¶ãã³ã³ãã³ããã£ã«ã¿ãªã³ã°ãªã©ãSMSãã©ãã£ãã¯ã«é¢ããç¹å®ã®èŠå¶ãå¶éããããŸãããããã®å¶éã«æ³šæããSMSã¡ãã»ãŒãžãå°åã®èŠå¶ã«æºæ ããŠããããšã確èªããŠãã ãããSMS APIãããã€ããŒãšååããŠãããã®è€éããä¹ãè¶ããã¡ãã»ãŒãžãæ£åžžã«é ä¿¡ãããããã«ããŠãã ããã
èšèªãµããŒã
è±èªã話ããªããŠãŒã¶ãŒã«ãããè¯ããŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ãæäŸããããã«ãSMSã¡ãã»ãŒãžã§å€èšèªããµããŒãããããšãæ€èšããŠãã ããã翻蚳ãµãŒãã¹ã䜿çšããŠãOTPã¡ãã»ãŒãžãç°ãªãèšèªã«æ£ç¢ºã«ç¿»èš³ããŸããããSMS APIãããã€ããŒãUnicodeãšã³ã³ãŒãã£ã³ã°ããµããŒãããŠããããšã確èªããç°ãªãæåã»ãããåŠçã§ããããã«ããŠãã ããã
ã³ã¹ãã«é¢ããèæ ®äºé
SMSã®ã³ã¹ãã¯ãåœãã¢ãã€ã«ãããã¯ãŒã¯ã«ãã£ãŠå€§ããç°ãªããŸããã¿ãŒã²ããå°åã§ã®SMSæéãèªèããã³ã¹ããæå°éã«æããããã«SMSã®äœ¿çšãæé©åããŠãã ãããããã·ã¥éç¥ãWhatsAppãªã©ããããã®ãã£ãã«ã«ã¢ã¯ã»ã¹ã§ãããŠãŒã¶ãŒã«ã¯ä»£æ¿ã®ã¡ãã»ãŒãžã³ã°ãã£ãã«ã®äœ¿çšãæ€èšããŠãã ããã
ãã©ã€ãã·ãŒãšããŒã¿ã»ãã¥ãªãã£
é»è©±çªå·ãšOTPãä¿è·ããããã«é©åãªã»ãã¥ãªãã£å¯Ÿçãå®è£ ãããŠãŒã¶ãŒã®ãã©ã€ãã·ãŒãšããŒã¿ã»ãã¥ãªãã£ãä¿è·ããŸããé»è©±çªå·ã¯ä¿åæããã³è»¢éæã«æå·åããŠãã ãããGDPRãCCPAãªã©ã®é¢é£ããããŒã¿ãã©ã€ãã·ãŒèŠå¶ã«æºæ ããŠãã ãããSMS 2FAã®ããã«ãŠãŒã¶ãŒã®é»è©±çªå·ãåéããã³åŠçããåã«ããŠãŒã¶ãŒããæç€ºçãªåæãåŸãããã«ããŠãã ããã
ã¿ã€ã ãŸãŒã³
OTPã®æå¹æéãèšå®ããéã¯ããŠãŒã¶ãŒãOTPãåä¿¡ããŠå ¥åããã®ã«ååãªæéã確ä¿ã§ããããããŠãŒã¶ãŒã®ã¿ã€ã ãŸãŒã³ãèæ ®ããŠãã ãããã¿ã€ã ãŸãŒã³ããŒã¿ããŒã¹ã䜿çšããŠãã¿ã€ã ã¹ã¿ã³ãããŠãŒã¶ãŒã®çŸå°æéã«æ£ç¢ºã«å€æããŠãã ããã
ã¢ã¯ã»ã·ããªãã£
SMS 2FAã®å®è£ ããéãããæã€ãŠãŒã¶ãŒã«ãå©çšå¯èœã§ããããšã確èªããŠãã ãããé³å£°ããŒã¹ã®OTPé ä¿¡ãèªèšŒã¢ããªãªã©ãSMSã¡ãã»ãŒãžãåä¿¡ã§ããªããŠãŒã¶ãŒã®ããã«ä»£æ¿ã®èªèšŒæ¹æ³ãæäŸããŠãã ããã
SMS APIãããã€ããŒã®éžæïŒèæ ®ãã¹ãäž»èŠãªæ©èœ
é©åãªSMS APIãããã€ããŒãéžæããããšã¯ãSMS 2FAã®å®è£ ãæåãããäžã§äžå¯æ¬ ã§ããæœåšçãªãããã€ããŒãè©äŸ¡ããéã«ã以äžã®æ©èœãèæ ®ããŠãã ããã
- ã°ããŒãã«ã«ãã¬ããž: ãããã€ããŒãåºç¯ãªã°ããŒãã«ã«ãã¬ããžãæã¡ãã¿ãŒã²ããå°åã§ã®SMSé ä¿¡ããµããŒãããŠããããšã確èªããŠãã ããã
- é«ãå°éç: é«ãSMSå°éçã®å®çžŸãæã€ãããã€ããŒãæ¢ããŸãããã
- ä¿¡é Œæ§ãšçšŒåæé: å ç¢ãªã€ã³ãã©ã¹ãã©ã¯ãã£ãšé«ã皌åæéSLAãæã€ãããã€ããŒãéžã³ãŸãããã
- ã»ãã¥ãªãã£: ãããã€ããŒãããŒã¿ãä¿è·ããäžæ£ã¢ã¯ã»ã¹ãé²ãããã®åŒ·åãªã»ãã¥ãªãã£å¯Ÿçãè¬ããŠããããšã確èªããŠãã ããã
- ã¹ã±ãŒã©ããªãã£: ãŠãŒã¶ãŒããŒã¹ã®å¢å ã«äŒŽãSMSéãåŠçã§ãããããã€ããŒãéžæããŸãããã
- æé: ç°ãªããããã€ããŒéã§æéãæ¯èŒããäºç®ã«åã£ããã©ã³ãéžã³ãŸãããã
- APIããã¥ã¡ã³ã: å æ¬çã§çè§£ããããAPIããã¥ã¡ã³ããæäŸãããããã€ããŒãæ¢ããŸãããã
- ãµããŒã: ä¿¡é Œæ§ãé«ããå¿çæ§ã®è¯ãã«ã¹ã¿ããŒãµããŒããæäŸãããããã€ããŒãéžã³ãŸãããã
- æ©èœ: é»è©±çªå·ãæ€èšŒããè©æ¬ºãæžããããã®çªå·ã«ãã¯ã¢ããæ©èœã
SMS 2FAã®ä»£æ¿ææ®µ
SMS 2FAã¯å¹ åºãã¢ã¯ã»ã¹æ§ãæäŸããŸããããã®éçãèªèãã代æ¿ã®2FAæ¹æ³ãæ€èšããããšãäžå¯æ¬ ã§ãã
- èªèšŒã¢ããªïŒäŸïŒGoogle AuthenticatorãAuthyïŒ: æéããŒã¹ã®OTPãçæããŸããSMSååã®åœ±é¿ãåããªããããSMSãããå®å šãªä»£æ¿ææ®µãšãªããŸãã
- Eã¡ãŒã«2FA: ãŠãŒã¶ãŒã®Eã¡ãŒã«ã¢ãã¬ã¹ã«OTPãéä¿¡ããŸããèªèšŒã¢ããªããã¯å®å šæ§ãäœãã§ããããã©ãŒã«ããã¯ãšããŠæ©èœããŸãã
- ããŒããŠã§ã¢ã»ãã¥ãªãã£ããŒïŒäŸïŒYubiKeyïŒ: OTPãçæãããããã¹ã¯ãŒãã¬ã¹èªèšŒã®ããã«FIDO2/WebAuthnæšæºã䜿çšãããããç©çããã€ã¹ã§ããéåžžã«å®å šã§ããããŠãŒã¶ãŒãç©çããŒãè³Œå ¥ããŠç®¡çããå¿ èŠããããŸãã
- çäœèªèšŒ: æçŽã¹ãã£ã³ãé¡èªèããã®ä»ã®çäœããŒã¿ã䜿çšããŠèªèšŒããŸãã䟿å©ã§ããããã©ã€ãã·ãŒã«é¢ããæžå¿µããããç¹å®ã®ç¶æ³ã§ã¯ä¿¡é Œæ§ãäœãå ŽåããããŸãã
- ããã·ã¥éç¥: ãŠãŒã¶ãŒã®ã¢ãã€ã«ããã€ã¹ã«ããã·ã¥éç¥ãéä¿¡ãããã°ã€ã³è©Šè¡ãæ¿èªãŸãã¯æåŠããããä¿ããŸãããŠãŒã¶ãŒãã¬ã³ããªãŒã§å®å šã§ãããå°çšã®ã¢ãã€ã«ã¢ããªãå¿ èŠã§ãã
çæ³çãª2FAæ¹æ³ã¯ãç¹å®ã®ã»ãã¥ãªãã£èŠä»¶ããŠãŒã¶ãŒããŒã¹ãããã³äºç®ã«ãã£ãŠç°ãªããŸãããŠãŒã¶ãŒã«æè»æ§ãæäŸããç°ãªã奜ã¿ãèœåã«å¯Ÿå¿ããããã«ãè€æ°ã®2FAæ¹æ³ã®çµã¿åãããæäŸããããšãæ€èšããŠãã ããã
èªèšŒã®æªæ¥ïŒSMS 2FAã®ãã®å
èªèšŒã®ç¶æ³ã¯åžžã«é²åããŠããŸããæ°ããæè¡ãšæšæºã¯ãããå®å šã§ãŠãŒã¶ãŒãã¬ã³ããªãŒãªèªèšŒæ¹æ³ãžã®éãéããŠããŸããäž»ãªãã¬ã³ãã«ã¯ä»¥äžãå«ãŸããŸãã
- ãã¹ã¯ãŒãã¬ã¹èªèšŒ: çäœèªèšŒãFIDO2/WebAuthnãªã©ã®æ¹æ³ã䜿çšããŠããã¹ã¯ãŒãã®å¿ èŠæ§ãå®å šã«æé€ããŸãã
- é©å¿åèªèšŒ: ãŠãŒã¶ãŒã®ãªã¹ã¯ãããã¡ã€ã«ãšè¡åã«åºã¥ããŠãèªèšŒèŠä»¶ãåçã«èª¿æŽããŸãã
- è¡åçäœèªèšŒ: ãŠãŒã¶ãŒã®è¡åãã¿ãŒã³ïŒäŸïŒã¿ã€ãã³ã°é床ãããŠã¹ã®åãïŒãåæããŠèº«å ã確èªããŸãã
- 忣åID: ãŠãŒã¶ãŒãèªèº«ã®IDããŒã¿ã管çããç°ãªããµãŒãã¹ãšéžæçã«å ±æã§ããããã«ããŸãã
çµè«
äºèŠçŽ èªèšŒã®ããã®SMS飿ºã¯ããµã€ããŒè åšãçµ¶ãéãªãå¢å ããäžçã«ãããŠãã»ãã¥ãªãã£ã匷åããããã®è²ŽéãªããŒã«ã§ããç¶ããŠããŸãããã®å©ç¹ããã¹ããã©ã¯ãã£ã¹ãããã³ã°ããŒãã«ãªèæ ®äºé ãçè§£ããããšã§ããŠãŒã¶ãŒã®æåšå°ã«é¢ä¿ãªãããŠãŒã¶ãŒãšããŒã¿ãä¿è·ãã广çãªSMS 2FAãœãªã¥ãŒã·ã§ã³ãå®è£ ã§ããŸããèªèšŒæè¡ãé²åãç¶ããäžã§ãå®å šã§ä¿¡é Œã§ãããªã³ã©ã€ã³ç°å¢ãç¶æããããã«ã¯ãæ å ±ã«ç²Ÿéããã»ãã¥ãªãã£æŠç¥ãé©å¿ãããããšãéèŠã§ããããŒãºãæ éã«è©äŸ¡ããé©åãªSMS APIãããã€ããŒãéžæãããŠãŒã¶ãŒãæè²ããŠSMS 2FAå®è£ ã®å¹æãæå€§åããŠãã ãããé·æçãªã»ãã¥ãªãã£ãšãŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ã確ä¿ããããã«ãæ°ããªèªèšŒæè¡ã«é¢ããææ°æ å ±ãåžžã«å ¥æããããã«å¿ããŠã»ãã¥ãªãã£æŠç¥ãé©å¿ãããããšãå¿ããªãã§ãã ããã