ēä½čŖčؼćć¼ćæćØćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć使ēØććå®å ØćŖćć°ć¤ć³ć®ććć®å¼·åćŖęØęŗć§ććWebčŖčؼAPIćę¢ę±ććć°ćć¼ćć«ćŖćŖć³ć©ć¤ć³ć»ćć„ćŖćć£ćå¼·åćć¾ćć
WebčŖčؼAPIļ¼ēä½čŖčؼćØćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć«ććć»ćć„ćŖćć£ć®åäø
ä»ę„ć®ēøäŗę„ē¶ćććććøćæć«ē°å¢ć§ćÆććŖć³ć©ć¤ć³ć¢ć«ć¦ć³ćć®ć»ćć„ćŖćć£ćÆęéč¦ć§ććä¼ēµ±ēćŖćć¹ćÆć¼ććć¼ć¹ć®čŖčؼę¹ę³ćÆćåŗćę®åćć¦ćć¾ććććć£ćć·ć³ć°ććÆć¬ćć³ć·ć£ć«ć¹ćæććć£ć³ć°ććć«ć¼ććć©ć¼ć¹ę»ęćŖć©ć®å·§å¦ćŖćµć¤ćć¼ę»ęć«åƾćć¦ć¾ćć¾ćčå¼±ć«ćŖć£ć¦ćć¾ćććććÆćććå ē¢ć§ć¦ć¼ć¶ć¼ćć¬ć³ććŖć¼ćŖčŖčؼć½ćŖć„ć¼ć·ć§ć³ć«åƾććäøēēćŖéč¦ćäæé²ćć¾ćććććć§ē»å “ććć®ććW3Cć®ē»ęēćŖęØęŗć§ććWebčŖčؼAPIļ¼ćć°ćć°WebAuthnćØå¼ć°ćć¾ćļ¼ć§ćććć¦ć¼ć¶ć¼ććŖć³ć©ć¤ć³ćµć¼ćć¹ć«ć¢ćÆć»ć¹ććę¹ę³ć«é©å½ćććććć¦ćć¾ćć
WebAuthnćÆćFIDOļ¼Fast Identity Onlineļ¼ć¢ć©ć¤ć¢ć³ć¹ć®ćććć³ć«ćØé£ęŗćć¦ćć¦ć§ććµć¤ććć¢ććŖć±ć¼ć·ć§ć³ćå®å Øć§ćć¹ćÆć¼ćć¬ć¹ćŖćć°ć¤ć³ä½éØćęä¾ć§ććććć«ćć¾ćććććÆćēä½čŖčؼćć¼ćæļ¼ęē“ćé”čŖčļ¼ććć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®ćććŖćå¼·åć§ćć£ćć·ć³ć°ć«å¼·ćčŖčؼč¦ē“ ć®ä½æēØćåÆč½ć«ććććØć§ćććéęćć¾ćććć®ććć°čØäŗć§ćÆćWebčŖčؼAPIćę·±ćęćäøćććć®ä»ēµćæćēä½čŖčؼćć°ć¤ć³ćØćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®å©ē¹ćććć¦ć°ćć¼ćć«ćŖćŖć³ć©ć¤ć³ć»ćć„ćŖćć£ćøć®é大ćŖå½±éæćę¢ćć¾ćć
WebčŖčؼAPIļ¼WebAuthnļ¼ć®ēč§£
WebčŖčؼAPIćÆćć¦ć§ćć¢ććŖć±ć¼ć·ć§ć³ćēµćæč¾¼ćæć®ćć©ćććć©ć¼ć čŖčؼę å ±ć¾ććÆå¤éØčŖčؼę å ±ļ¼ć»ćć„ćŖćć£ćć¼ćŖć©ļ¼ć使ēØćć¦ć¦ć¼ć¶ć¼ćē»é²ććć³ćć°ć¤ć³ć§ććććć«ććć¦ć§ćęØęŗć§ćććććÆććć©ć¦ć¶ćØćŖćć¬ć¼ćć£ć³ć°ć·ć¹ćć ććććć®čŖčؼę å ±ćØåÆ¾č©±ććććć®ęØęŗåćććć¤ć³ćæć¼ćć§ć¼ć¹ćęä¾ćć¾ćć
WebAuthnć®äø»č¦ć³ć³ćć¼ćć³ćļ¼
- Relying Party (RP)ļ¼ä¾åå½äŗč ļ¼ļ¼čŖčؼćåæ č¦ćØććć¦ć§ććµć¤ćć¾ććÆć¢ććŖć±ć¼ć·ć§ć³ć§ćć
- Clientļ¼ćÆć©ć¤ć¢ć³ćļ¼ļ¼ć¦ć¼ć¶ć¼ćØčŖčؼę å ±ć®äøéč ćØćć¦ę©č½ććć¦ć§ććć©ć¦ć¶ć¾ććÆćć¤ćć£ćć¢ććŖć±ć¼ć·ć§ć³ć§ćć
- Platform Authenticatorļ¼ćć©ćććć©ć¼ć čŖčؼę å ±ļ¼ļ¼ć¹ćć¼ććć©ć³ć®ęē“ć¹ćć£ćć¼ćć©ććććććć¾ććÆé”čŖčć·ć¹ćć ļ¼ä¾ļ¼Windows HelloćAppleć®Face IDļ¼ćŖć©ćć¦ć¼ć¶ć¼ć®ććć¤ć¹ć«ēµćæč¾¼ć¾ććčŖčؼę å ±ć§ćć
- Roaming Authenticatorļ¼ćć¼ćć³ć°čŖčؼę å ±ļ¼ļ¼č¤ę°ć®ććć¤ć¹ć§ä½æēØć§ććå¤éØćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ļ¼ä¾ļ¼YubiKeyćGoogle Titan Keyļ¼ć§ćć
- Authenticator Assertionļ¼čŖčؼę å ±ć¢ćµć¼ć·ć§ć³ļ¼ļ¼čŖčؼę å ±ć«ćć£ć¦ēęćććććøćæć«ē½²åä»ćć”ćć»ć¼ćøć§ćä¾åå½äŗč ćøć®ć¦ć¼ć¶ć¼ć®čŗ«å ć証ęćć¾ćć
WebAuthnć®ä»ēµćæļ¼ē°”ē„åćććććć¼
ććć»ć¹ć«ćÆćē»é²ćØčŖčؼć®2ć¤ć®äø»č¦ćŖę®µéćå«ć¾ćć¾ćć
1. ē»é²ļ¼
- ć¦ć¼ć¶ć¼ćę°ććć¢ć«ć¦ć³ććē»é²ććććę°ććčŖčؼę¹ę³ćčæ½å ććććććØćä¾åå½äŗč ļ¼ć¦ć§ććµć¤ćļ¼ććć©ć¦ć¶ļ¼ćÆć©ć¤ć¢ć³ćļ¼ć«ē»é²ćŖćÆćØć¹ććéå§ćć¾ćć
- ꬔć«ććć©ć¦ć¶ćÆć¦ć¼ć¶ć¼ć«čŖčؼę å ±ļ¼ä¾ļ¼ęē“ć使ēØćććć»ćć„ćŖćć£ćć¼ćęæå „ććļ¼ćéøęććććć«äæćć¾ćć
- čŖčؼę å ±ćÆććć®ć¦ć¼ć¶ć¼ćØćć®ē¹å®ć®ć¦ć§ććµć¤ćć«åŗęć®ę°ććå ¬é/ē§åÆéµćć¢ćēęćć¾ćć
- čŖčؼę å ±ćÆćē§åÆéµć§å ¬ééµćØćć®ä»ć®ē»é²ćć¼ćæćē½²åćććć©ć¦ć¶ć«čæćć¾ćć
- ćć©ć¦ć¶ćÆććć®ē½²åä»ććć¼ćæćä¾åå½äŗč ć«č»¢éććä¾åå½äŗč ćÆć¦ć¼ć¶ć¼ć®ć¢ć«ć¦ć³ćć«é¢é£ä»ććććå ¬ééµćäæåćć¾ććē§åÆéµćÆć¦ć¼ć¶ć¼ć®čŖčؼę å ±ććę±ŗćć¦é¢ćć¾ććć
2. čŖčؼļ¼
- ć¦ć¼ć¶ć¼ććć°ć¤ć³ć試ćæććØćä¾åå½äŗč ćÆćć£ć¬ć³ćøļ¼ć©ć³ćć ćŖćć¼ćæļ¼ććć©ć¦ć¶ć«éäæ”ćć¾ćć
- ćć©ć¦ć¶ćÆććć®ćć£ć¬ć³ćøćć¦ć¼ć¶ć¼ć®čŖčؼę å ±ć«ę示ćć¾ćć
- čŖčؼę å ±ćÆćē»é²äøć«ä»„åēęććē§åÆéµć使ēØćć¦ććć£ć¬ć³ćøć«ē½²åćć¾ćć
- čŖčؼę å ±ćÆćē½²åććććć£ć¬ć³ćøććć©ć¦ć¶ć«čæćć¾ćć
- ćć©ć¦ć¶ćÆćē½²åććććć£ć¬ć³ćøćä¾åå½äŗč ć«éäæ”ćć¾ćć
- ä¾åå½äŗč ćÆćäæåććć¦ććå ¬ééµć使ēØćć¦ē½²åćę¤čؼćć¾ććē½²åćęå¹ć§ććć°ćć¦ć¼ć¶ć¼ćÆę£åøøć«čŖčؼććć¾ćć
ćć®å ¬ééµęå·åć¢ćć«ćÆćēć¾ćććę¼ę“©ćććććåÆč½ę§ć®ććå ±ęē§åÆć«ä¾åććŖćććććć¹ćÆć¼ććć¼ć¹ć®ć·ć¹ćć ćććę ¹ę¬ēć«å®å Øć§ćć
WebAuthnć«ććēä½čŖčؼćć°ć¤ć³ć®å
ēä½čŖčؼćÆćć¦ć¼ć¶ć¼ć®čŗ«å ć確čŖććććć«ć¦ćć¼ćÆćŖēē©å¦ēē¹ę§ćę“»ēØćć¾ććWebAuthnć使ēØćććØćęę°ććć¤ć¹ć§äøč¬ēć§ä¾æå©ćŖćććć®ę©č½ćå©ēØćć¦ćå®å ØćŖćŖć³ć©ć¤ć³ć¢ćÆć»ć¹ćå®ē¾ć§ćć¾ćć
ćµćć¼ćććć¦ććēä½čŖčؼć®ēØ®é”ļ¼
- ęē“ć¹ćć£ć³ļ¼ć¹ćć¼ććć©ć³ććæćć¬ćććć©ćććććć§åŗćå©ēØåÆč½ć§ćć
- é”čŖčļ¼Appleć®Face IDćWindows HelloćŖć©ć®ććÆćććøć¼ćÆćå®å ØćŖé”ć¹ćć£ć³ćęä¾ćć¾ćć
- č¹å½©ć¹ćć£ć³ļ¼ę¶č²»č åćććć¤ć¹ć§ćÆäøč¬ēć§ćÆććć¾ććććéåøøć«å®å ØćŖēä½čŖčؼć¢ććŖćć£ć§ćć
- é³å£°čŖčļ¼čŖčؼć®ććć®ć»ćć„ćŖćć£å¼·åŗ¦ć«ć¤ćć¦ćÆć¾ć é²åäøć§ććć
ēä½čŖčؼćć°ć¤ć³ć®å©ē¹ļ¼
- å¼·åćććć¦ć¼ć¶ć¼ćØćÆć¹ććŖćØć³ć¹ļ¼č¤éćŖćć¹ćÆć¼ććč¦ććåæ č¦ćććć¾ćććčæ éćŖć¹ćć£ć³ć§ååćŖå “åćå¤ćć§ććććć«ććććć°ć¤ć³ććć»ć¹ćććéćć¹ć ć¼ćŗć«ćŖććå¤ę§ćŖć°ćć¼ćć«åøå “ć§ć®ć¦ć¼ć¶ć¼ē¶ęćØęŗč¶³åŗ¦ć«ćØć£ć¦éč¦ćŖč¦å ćØćŖćć¾ćć
- å¼·åćŖć»ćć„ćŖćć£ļ¼ēä½čŖčؼćć¼ćæćÆćč¤č£½ćēé£ćę¬č³Ŗēć«å°é£ć§ćććć¹ćÆć¼ććØćÆē°ćŖććęē“ćé”ćē°”åć«ćć£ćć·ć³ć°ćććęØęø¬ćććććććØćÆć§ćć¾ććććććÆćäøč¬ēćŖćŖć³ć©ć¤ć³č©ę¬ŗćØć®ę¦ćć«ćć㦠significant ćŖå©ē¹ćęä¾ćć¾ćć
- ćć£ćć·ć³ć°čę§ļ¼čŖčؼę å ±ļ¼ććŖćć®ēä½ę å ±ļ¼ćÆććŖćć®ććć¤ć¹ćØććŖćčŖčŗ«ć«ēµć³ć¤ćć¦ćććććć¦ć¼ć¶ć¼ććć¹ćÆć¼ććę¼ę“©ćććććć«éØććć£ćć·ć³ć°ę»ęć®å½±éæćåćć¾ććć
- ć¢ćÆć»ć·ććŖćć£ļ¼äøēäøć®å¤ćć®ć¦ć¼ć¶ć¼ćē¹ć«čåēćä½ćå°åćå¾ę„ć®čŗ«å 証ęęøé”ćøć®ć¢ćÆć»ć¹ćéććć¦ććć¦ć¼ć¶ć¼ć«ćØć£ć¦ćēä½čŖčؼćÆććć¢ćÆć»ć¹ććććčŗ«å 確čŖć®å½¢ę ćęä¾ć§ćć¾ććććØćć°ćå¤ćć®ēŗå±éäøå½ć§ć®ć¢ćć¤ć«ę±ŗęøć·ć¹ćć ćÆćć¢ćÆć»ć·ććŖćć£ćØć»ćć„ćŖćć£ć®ććć«ēä½čŖčؼć«å¤§ććä¾åćć¦ćć¾ćć
- ććć¤ć¹ēµ±åļ¼WebAuthnćÆćć©ćććć©ć¼ć čŖčؼę å ±ćØć·ć¼ć ć¬ć¹ć«ēµ±åććććććé»č©±ćć©ćććććć®ēä½čŖčؼć»ć³ćµć¼ćÆćå„éćć¼ćć¦ć§ć¢ćŖćć§ē“ę„ććŖććčŖčؼć§ćć¾ćć
ēä½čŖčؼć®ć°ćć¼ćć«ćŖä¾ćØčę ®äŗé ļ¼
å¤ćć®ć°ćć¼ćć«ćµć¼ćć¹ćÆćć§ć«ēä½čŖčؼćę“»ēØćć¦ćć¾ćć
- ć¢ćć¤ć«ćć³ćć³ć°ļ¼äøēäøć®éč”ć大ęå½éę©é¢ććå°č¦ęØ”ćŖå°åéč”ć¾ć§ćć¢ćć¤ć«ć¢ććŖć®ćć°ć¤ć³ćåå¼ęæčŖć«ęē“ć¾ććÆé”čŖčćäøč¬ēć«ä½æēØćć¦ćććå¤ę§ćŖé”§å®¢ćć¼ć¹ć«å©ä¾æę§ćØć»ćć„ćŖćć£ćęä¾ćć¦ćć¾ćć
- Eć³ćć¼ć¹ļ¼AmazonćŖć©ć®ćć©ćććć©ć¼ć ćÆćć¦ć¼ć¶ć¼ćć¢ćć¤ć«ććć¤ć¹ć§ēä½čŖčؼć使ēØćć¦č³¼å „ćčŖčؼć§ććććć«ćć¦ćććä½ē¾äøäŗŗćć®å½éēćŖč²·ćē©å®¢ć«ćØć£ć¦ćć§ććÆć¢ć¦ćććć»ć¹ćåēåćć¦ćć¾ćć
- ęæåŗćµć¼ćć¹ļ¼ć¤ć³ćć®ććć«ćAadhaarć·ć¹ćć ćęć¤å½ć§ćÆćēä½čŖčؼćÆåŗå¤§ćŖäŗŗå£ć®čŗ«å 確čŖć®åŗę¬ć§ććććć¾ćć¾ćŖå ¬å ±ćµć¼ćć¹ćéčååćøć®ć¢ćÆć»ć¹ćåÆč½ć«ćć¦ćć¾ćć
ćć ććčę ®äŗé ćććć¾ćć
- ćć©ć¤ćć·ć¼ć«é¢ććęøåæµļ¼äøēäøć®ć¦ć¼ć¶ć¼ćÆćēä½čŖčؼćć¼ćæć®å ±ęć«åƾććåæ«é©ćć®ć¬ćć«ćē°ćŖćć¾ćććć®ćć¼ćæćć©ć®ććć«äæåććć³ä½æēØććććć«ć¤ćć¦ć®éęę§ćéč¦ć§ććWebAuthnćÆćēä½čŖčؼćć¼ćæćććć¤ć¹äøć§ćć¼ć«ć«ć«å¦ēććććµć¼ćć¼ć«éäæ”ćććŖćććć«ććććØć§ćććć解決ćć¾ćć
- 精度ćØćŖććć¾ćļ¼äøč¬ēć«å®å Øć§ćććēä½čŖčؼć·ć¹ćć ć«ćÆčŖ¤ę¤åŗć¾ććÆčŖ¤ęå¦ćēŗēććåÆč½ę§ćććć¾ććé«åŗ¦ćŖć·ć¹ćć ćÆććŖććć¾ćļ¼ä¾ļ¼é”čŖčćéØćććć«åēć使ēØććļ¼ćé²ćććć«ć©ć¤ććć¹ę¤åŗćę”ēØćć¦ćć¾ćć
- ććć¤ć¹ćøć®ä¾åļ¼ēä½čŖčØ¼åÆ¾åæććć¤ć¹ćęććŖćć¦ć¼ć¶ć¼ćÆć代ęæć®čŖčؼę¹ę³ćåæ č¦ć«ćŖćå “åćććć¾ćć
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®ęŗćććŖćå¼·ć
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ćÆćéåøøć«é«ćć¬ćć«ć®ć»ćć„ćŖćć£ćęä¾ććē©ēććć¤ć¹ć§ććććććÆććć£ćć·ć³ć°ć«å¼·ćčŖčؼć®åŗē¤ć§ćććå ē¢ćŖćć¼ćæäæč·ćęøåæµććåäŗŗćēµē¹ć«ćć£ć¦äøēäøć§ć¾ćć¾ćę”ēØććć¦ćć¾ćć
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ćØćÆļ¼
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ćÆćęå·åęä½ēØć®ē§åÆéµćå«ćå°ććŖćć¼ćæćć«ććć¤ć¹ļ¼USBć”ć¢ćŖć«ä¼¼ć¦ććććØćå¤ćļ¼ć§ććUSBćNFCćć¾ććÆBluetoothēµē±ć§ć³ć³ćć„ć¼ćæć¾ććÆć¢ćć¤ć«ććć¤ć¹ć«ę„ē¶ćććčŖčؼććć«ćÆē©ēēćŖęä½ļ¼ććæć³ć«č§¦ćććPINćå „åćććŖć©ļ¼ćåæ č¦ć§ćć
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®äø»č¦ćŖä¾ļ¼
- YubiKeyļ¼Yubicoļ¼ļ¼FIDO U2FćFIDO2ļ¼WebAuthnć®åŗē¤ļ¼ćŖć©ć®ćć¾ćć¾ćŖćććć³ć«ććµćć¼ććććåŗćčŖčććć¦ććå¤ę©č½ć»ćć„ćŖćć£ćć¼ć§ćć
- Google Titan Security Keyļ¼Googleć®ęä¾åć§ćå ē¢ćŖćć£ćć·ć³ć°äæč·ć®ććć«čØčØććć¦ćć¾ćć
- SoloKeysļ¼ćŖć¼ćć³ć½ć¼ć¹ć§ęé ćŖä¾”ę ¼ć®ćŖćć·ć§ć³ć§ćć»ćć„ćŖćć£ćå¼·åćć¾ćć
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®å©ē¹ļ¼
- åŖćććć£ćć·ć³ć°čę§ļ¼ćććę大ć®å©ē¹ć§ććē§åÆéµćÆćć¼ćć¦ć§ć¢ćć¼ćÆć³ććé¢ććććØćÆćŖććčŖčؼć«ćÆē©ēēćŖååØćåæ č¦ćŖćććć¦ć¼ć¶ć¼ć«čŖčؼę å ±ćå½ć®ćć°ć¤ć³ććć³ćććęæčŖćććććć«éØćććØćććć£ćć·ć³ć°ę»ęćÆå¹ęććŖććŖćć¾ćććććÆććć¹ć¦ć®ę„ēćå°ēēćŖå “ęć®ć¦ć¼ć¶ć¼ć®ę©åÆę å ±ćäæč·ććććć« critical ć§ćć
- å¼·åćŖęå·åäæč·ļ¼å ē¢ćŖå ¬ééµęå·åćå©ēØćć¦ććć侵害ćéåøøć«å°é£ć§ćć
- 使ććććļ¼ć»ććć¢ććå¾ļ¼ļ¼åęē»é²å¾ćć»ćć„ćŖćć£ćć¼ć®ä½æēØćÆćę„ē¶ćć¦ććæć³ć«č§¦ćććPINćå „åććć®ćØåććććē°”åć§ććććØćććććć¾ćććć®ä½æćććććÆćęč”ēćŖēæēåŗ¦ćē°ćŖćć°ćć¼ćć«ćŖå“ååć§ć®ę”ēØć«ćØć£ć¦ crucial ć§ććåÆč½ę§ćććć¾ćć
- å ±ęē§åÆćŖćļ¼ćć¹ćÆć¼ććSMS OTPć§ćććååćććććµć¼ćć¼ć«å®å Øć§ćŖćę¹ę³ć§äæåććććććå ±ęē§åÆćÆććć¾ććć
- ęŗåøÆę§ćØę±ēØę§ļ¼å¤ćć®ćć¼ćÆč¤ę°ć®ćććć³ć«ććµćć¼ććć¦ććććć¾ćć¾ćŖććć¤ć¹ććµć¼ćć¹ć§ä½æēØć§ćććććäøč²«ććć»ćć„ćŖćć£ä½éØćęä¾ćć¾ćć
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®ć°ćć¼ćć«ćŖę”ēØćØć¦ć¼ć¹ć±ć¼ć¹ļ¼
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ćÆć仄äøć«ćØć£ć¦äøåÆę¬ ć«ćŖć£ć¦ćć¾ćć
- é«ćŖć¹ćÆć®åäŗŗļ¼äøå®å®ćŖå°åć®ćøć£ć¼ććŖć¹ććę“»åå®¶ćęæę²»å®¶ćÆćå½å®¶ęÆę“ć®ćććć³ć°ćē£č¦ć®é »ē¹ćŖęØēć§ććććć¼ćęä¾ććé«åŗ¦ćŖäæč·ćć immense ć«ę©ęµćåćć¦ćć¾ćć
- ćØć³ćæć¼ćć©ć¤ćŗć»ćć„ćŖćć£ļ¼ę©åÆę§ć®é«ć锧客ćć¼ćæćē„ēč²”ē£ćę±ćäøēäøć®ä¼ę„ćÆćć¢ć«ć¦ć³ćć®ä¹ć£åćććć¼ćæä¾µå®³ćé²ćććć«ćå¾ę„å”ć«ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ćć¾ćć¾ć義åä»ćć¦ćć¾ććGooglećŖć©ć®ä¼ę„ćÆććć¼ćć¦ć§ć¢ćć¼ćę”ēØćć¦ä»„ę„ćć¢ć«ć¦ć³ćć®ä¹ć£åććå¤§å¹ ć«ęøå°ćććØå ±åćć¦ćć¾ćć
- éēŗč ćØITćććć§ćć·ć§ćć«ļ¼éč¦ćŖć¤ć³ćć©ć¹ćć©ćÆćć£ć¾ććÆę©åÆę§ć®é«ćć³ć¼ććŖććøććŖćē®”ēććäŗŗć ćÆćå®å ØćŖć¢ćÆć»ć¹ć«ćć¼ćć¦ć§ć¢ćć¼ćä¾åććććØćććććć¾ćć
- č¤ę°ć®ć¢ć«ć¦ć³ććęć¤ć¦ć¼ć¶ć¼ļ¼å¤ę°ć®ćŖć³ć©ć¤ć³ć¢ć«ć¦ć³ććē®”ēććäŗŗćŖćčŖ°ć§ććēµ±äøćććéåøøć«å®å ØćŖčŖčؼę¹ę³ććę©ęµćåććććØćć§ćć¾ćć
ćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®ę”ēØćÆćå·§å¦ćŖćµć¤ćć¼č åØć«åƾććčŖčć®é«ć¾ćć«ćć£ć¦ęØé²ćććć°ćć¼ćć«ćŖćć¬ć³ćć§ćććØć¼ććććåē±³ćć¢ćøć¢ć®ēµē¹ćÆćć¹ć¦ćććå¼·åćŖčŖčؼę¹ę³ćęØé²ćć¦ćć¾ćć
ć¢ććŖć±ć¼ć·ć§ć³ćøć®WebAuthnć®å®č£
WebAuthnćWebć¢ććŖć±ć¼ć·ć§ć³ć«ēµ±åććććØć§ćć»ćć„ćŖćć£ćå¤§å¹ ć«åäøćććććØćć§ćć¾ććåŗē¤ćØćŖćęå·åćÆč¤éć§ććåÆč½ę§ćććć¾ććććć¾ćć¾ćŖć©ć¤ćć©ćŖććć¬ć¼ć ćÆć¼ćÆćéćć¦éēŗććć»ć¹ćććć¢ćÆć»ć¹ćććććŖćć¾ććć
å®č£ ć®äø»č¦ćŖć¹ćććļ¼
- ćµć¼ćć¼ćµć¤ćććøććÆļ¼ćµć¼ćć¼ćÆćē»é²ćć£ć¬ć³ćøćØčŖčؼćć£ć¬ć³ćøć®ēęćććć³ćÆć©ć¤ć¢ć³ćććčæćććē½²åä»ćć¢ćµć¼ć·ć§ć³ć®ę¤čؼćå¦ēććåæ č¦ćććć¾ćć
- ćÆć©ć¤ć¢ć³ććµć¤ćJavaScriptļ¼ćć©ć¦ć¶ć§JavaScriptć使ēØćć¦ćWebAuthn APIļ¼ē»é²ć®å “åćÆ
navigator.credentials.create()
ćčŖčؼć®å “åćÆnavigator.credentials.get()
ļ¼ćØåÆ¾č©±ćć¾ćć - ć©ć¤ćć©ćŖć®éøęļ¼ććć¤ćć®ćŖć¼ćć³ć½ć¼ć¹ć©ć¤ćć©ćŖļ¼ä¾ļ¼Node.jsēØć®
webauthn-lib
ćPythonēØć®py_webauthn
ļ¼ćÆććµć¼ćć¼ćµć¤ćć®å®č£ ćē°”ē“ åć§ćć¾ćć - ć¦ć¼ć¶ć¼ć¤ć³ćæć¼ćć§ć¤ć¹ćć¶ć¤ć³ļ¼ć¦ć¼ć¶ć¼ć«ē»é²ćØćć°ć¤ć³ć®éå§ćäæćę確ćŖććć³ćććä½ęććéøęććčŖčؼę å ±ć使ēØććććć»ć¹ćć¬ć¤ććć¾ćć
ć°ćć¼ćć«ćŖć¦ć¼ć¶ć¼åćć®čę ®äŗé ļ¼
- ćć©ć¼ć«ćććÆć”ć«ććŗć ļ¼ēä½čŖčؼć¾ććÆćć¼ćć¦ć§ć¢ćć¼čŖčؼć«ć¢ćÆć»ć¹ć§ććŖććć¾ććÆę £ćć¦ććŖćć¦ć¼ć¶ć¼ć®ććć«ćåøøć«ćć©ć¼ć«ćććÆčŖčؼę¹ę³ļ¼ä¾ļ¼ćć¹ćÆć¼ć+ OTPļ¼ćęä¾ćć¦ćć ććććććÆććć¾ćć¾ćŖåøå “ć§ć®ć¢ćÆć»ć·ććŖćć£ć«ćØć£ć¦ crucial ć§ćć
- čØčŖćØćć¼ć«ć©ć¤ćŗļ¼WebAuthnć«é¢é£ćććć¹ć¦ć®ććć³ćććØę示ćććæć¼ć²ćććØććć°ćć¼ćć«ć¦ć¼ć¶ć¼ć«ćØć£ć¦ēæ»čسćććęåēć«é©åć§ććććØć確čŖćć¦ćć ććć
- ććć¤ć¹äŗęę§ļ¼ćć¾ćć¾ćŖå°åć§äøč¬ēćŖćć¾ćć¾ćŖćć©ć¦ć¶ććŖćć¬ć¼ćć£ć³ć°ć·ć¹ćć ćććć¤ć¹ć§å®č£ ććć¹ććć¦ćć ććć
- č¦å¶éµå®ļ¼WebAuthnčŖä½ććć©ć¤ćć·ć¼ćäæč·ććććć«čØčØććć¦ćć¾ćććé¢é£ććåÆč½ę§ć®ćććć¼ćæć®å¦ēć«é¢ćć¦ććć¾ćć¾ćŖå°åć®ćć¼ćæćć©ć¤ćć·ć¼č¦å¶ļ¼GDPRćCCPAćŖć©ļ¼ćčŖčćć¦ćć ććć
čŖčؼć®ęŖę„ļ¼ćć¹ćÆć¼ćć¬ć¹ćØćć仄é
WebčŖčؼAPIćÆććć¹ćÆć¼ććę代é ćć«ćŖćęŖę„ćøć® significant ćŖäøę©ć§ćććć¹ćÆć¼ćć¬ć¹čŖčؼćøć®ē§»č”ćÆććć¹ćÆć¼ćć®åŗęć®å¼±ē¹ćØćå®å Øć§ć¦ć¼ć¶ć¼ćć¬ć³ććŖć¼ćŖä»£ęæęꮵć®å „ęåÆč½ę§ć®å¢å ć«ćć£ć¦ęØé²ććć¦ćć¾ćć
ćć¹ćÆć¼ćć¬ć¹ćŖęŖę„ć®å©ē¹ļ¼
- ę»ę対豔é åć®å¤§å¹ ćŖåęøļ¼ćć¹ćÆć¼ććęé¤ććććØć§ćå¤ćć®äøč¬ēćŖćµć¤ćć¼ę»ęć®äø»č¦ćŖććÆćć«ććŖććŖćć¾ćć
- ć¦ć¼ć¶ć¼ć®å©ä¾æę§ć®åäøļ¼ć¹ć ć¼ćŗćŖćć°ć¤ć³ä½éØćÆćć¦ć¼ć¶ć¼ć®ęŗč¶³åŗ¦ćØēē£ę§ćåäøććć¾ćć
- å¼·åćććć»ćć„ćŖćć£ä½å¶ļ¼ēµē¹ćÆććÆććć«é«ćć¬ćć«ć®ć»ćć„ćŖćć£äæčؼćéęć§ćć¾ćć
ććÆćććøć¼ćé²ę©ććć¦ć¼ć¶ć¼ć®ę”ēØćå¢ććć«ć¤ćć¦ćWebAuthnć®ćććŖęØęŗć«ćć£ć¦ē¢ŗē«ćććå¼·åćŖåŗē¤ć®äøć«ę§ēÆććććććć«ę“ē·“ććēµ±åćććčŖčؼę¹ę³ćåŗē¾ććććØćęå¾ ć§ćć¾ććå¼·åćććēä½čŖčؼć»ć³ćµć¼ććććé«åŗ¦ćŖćć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ć½ćŖć„ć¼ć·ć§ć³ć¾ć§ćå®å Øć§ęéć®ććććŖćććøćæć«ć¢ćÆć»ć¹ćøć®éćÆé čŖæć«é²ćć§ćć¾ćć
ēµč«ļ¼ććå®å ØćŖććøćæć«äøēć®ę”ēØ
WebčŖčؼAPIćÆććŖć³ć©ć¤ć³ć»ćć„ćŖćć£ć«ććććć©ćć¤ć ć·ććć蔨ćć¦ćć¾ććēä½čŖčؼćć°ć¤ć³ććć¼ćć¦ć§ć¢ć»ćć„ćŖćć£ćć¼ć®ćććŖå¼·åć§ćć£ćć·ć³ć°ć«å¼·ćčŖčؼę¹ę³ć®ä½æēØćåÆč½ć«ććććØć§ćé²åćē¶ććč åØć©ć³ćć¹ć±ć¼ćć«åƾććå ē¢ćŖé²å¾”ćęä¾ćć¾ćć
ć¦ć¼ć¶ć¼ć«ćØć£ć¦ćÆććććÆćć大ććŖå©ä¾æę§ć§å¼·åćććć»ćć„ćŖćć£ćęå³ćć¾ććéēŗč ćä¼ę„ć«ćØć£ć¦ćÆćę©åÆćć¼ćæćäæč·ććć°ćć¼ćć«ćŖé”§å®¢ćć¼ć¹ćØć®äæ”é ¼ćę§ēÆćććććå®å Øć§ć¦ć¼ć¶ć¼ćć¬ć³ććŖć¼ćŖć¢ććŖć±ć¼ć·ć§ć³ćę§ēÆććę©ä¼ćęä¾ćć¾ććWebAuthnćę”ēØććććØćÆćåć«ę°ććććÆćććøć¼ćę”ēØććććØć§ćÆććć¾ććććććÆććć¹ć¦ć®äŗŗććć¹ć¦ć®å “ęć®ććć«ćććå®å Øć§ć¢ćÆć»ć¹ććććććøćæć«ęŖę„ćē©ę„µēć«ę§ēÆććććØć§ćć
ććå®å ØćŖčŖčؼćøć®ē§»č”ćÆē¶ē¶ēćŖććć»ć¹ć§ćććWebAuthnćÆćć®ććŗć«ć® critical ćŖäøéØć§ćććµć¤ćć¼ć»ćć„ćŖćć£ć®č åØć«åƾććäøēēćŖęčćé«ć¾ćē¶ććć«ć¤ćć¦ććććć®é«åŗ¦ćŖčŖčؼę¹ę³ć®ę”ēØćÆééććŖćå éććåäŗŗćØēµē¹ć®äø”ę¹ć«ćØć£ć¦ććå®å ØćŖćŖć³ć©ć¤ć³ē°å¢ćåµé ćć¾ćć