ãµãã©ã€ãã§ãŒã³ãªã¹ã¯ã®æ°ããªèгç¹ãšããŠãITåºç€ã§å©çšãããããŒããŠã§ã¢ãããã補é ããã³ã³ããŒãã³ããã®ãã®ã®ä¿¡é Œæ§ãšãããã«å¯Ÿããã»ãã¥ãªãã£äžã®è åšã®ååšã泚ç®ããã€ã€ããã
ãã®ç¶æ³ããµãŸããããŒããŠã§ã¢ãã®ãã®ã«å¯Ÿããã»ãã¥ãªãã£å¯Ÿçããæ°å¹Žåããç±³åœã§è¡ãããŠãããNIST(ç±³åœåœç«æšæºæè¡ç ç©¶æ)ãã¬ãŒã ã¯ãŒã¯ãžã®å¯Ÿå¿ãªã©ãç±³åœã§ã®åããäžå¿ã«ãITåºç€ã«ããŒããŠã§ã¢ãäŸçµŠããçŸå Žã§ãã©ã®ãããªåãçµã¿ãè¡ãããŠããã®ã玹ä»ããã
ããŒããŠã§ã¢ã¯ç¡æ¡ä»¶ã«ä¿¡é Œã§ããã®ãïŒ
å·¥å Žã§çç£ããããã€ãã¯è£œåãããã€ã§ã奜ããªã¿ã€ãã³ã°ã§è²·ãããšãã§ãããå°ãåãŸã§ã¯åœããåã ã£ãããä»ã¯ããã§ã¯ãªãã
åºã䜿ãããŠããx86ãµãŒããèŠãŠã補åã®è£œé ã«å¿ èŠãªããããããµãã©ã€ãã§ãŒã³ãã¡ã¢ãªãCPUãªã©ã³ã³ããŒãã³ãäŸçµŠã®é£éã¯ãéåžžã«è€éãã€å€æ§ã ãè¿å¹Žãå°æ¿åŠãªã¹ã¯ãçµæžå®å šä¿éãªã©ã®èšèãšãšãã«ããµãã©ã€ãã§ãŒã³ã«ãªã¹ã¯ãæœåšããããšãå€ãã®äººãèªèããŠããããšã ããã
ãããããµãã©ã€ãã§ãŒã³ã®ãªã¹ã¯ã«ã¯ãäŸçµŠãã®ãã®ãšã¯å¥ã®ããã1ã€ã®åŽé¢ããããè€éã«çµã¿äžããããã³ã³ããŒãã³ããšããããã«æèŒãããOSãã¢ããªã±ãŒã·ã§ã³ããããã£ãšäœãã¬ã€ã€ã«ååšãããããã€ã¹å¶åŸ¡çšã®ãœãããŠã§ã¢ãã€ãŸããã¡ãŒã ãŠã§ã¢ã®ä¿¡é Œæ§ã§ããã
ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®å¢çã¯ç·åŒããé£ãããäŸãã°ããã䜿ãããã³ã³ããŒãã³ãã§ããSSDã«ãããã¡ãŒã ãŠã§ã¢ãå ¥ã£ãŠãããããŒã¿ã®æžã蟌ã¿ãšèªã¿åºããæçµçã«æ ããœãããŠã§ã¢ã§ããããéåžžã¯ããŒããŠã§ã¢ã³ã³ããŒãã³ããšããŠã®SSDã®äžéšãšèŠãªããããã®ååšãæèãããããšã¯ãªããéçšã§ãã¡ãŒã ãŠã§ã¢ã¢ããããŒãäœæ¥ãããŠããæ¹ããSSDã®ãã¡ãŒã ãŠã§ã¢ã®ããŒãžã§ã³ãå€ãã£ãŠããã®ãçšã«ç®ã«ãããããã ããã
çŸåšããœãããŠã§ã¢ã®ã»ãã¥ãªãã£å¯Ÿçã¯æ§æªèª¬ãåºæ¬ã ãã¢ããªã±ãŒã·ã§ã³ã¯ä¿¡é Œãããã¹ãã¢ãã¬ããžããªããããŠã³ããŒããããã®ããšããèªèã¯ãã§ã«åžžèãšãªã£ãŠãããæ§å説ã¯éå»ã®ãã®ã«ãªããæªæãããœãããŠã§ã¢ãžã®å¯Ÿçãããã®20幎ã§é£èºçã«é²ãã ã
ããã§ã¯ãããŒããŠã§ã¢ã®ã»ãã¥ãªãã£å¯Ÿçã¯ã©ãããããŒããŠã§ã¢ã¯å€ãã®å Žåãæ§å説(ãããæªããšèšãããã®ã§ã¯ãªã)ãåºæ¬ãšããŠãããããœãããŠã§ã¢ã«æ¯ã¹ããšã©ã€ããµã€ã¯ã«å šäœã§èŠãã»ãã¥ãªãã£å¯Ÿçã®æ®åã¯ãŸã ãŸã ãšèšããããšã¯ãããå€ãã®äººéãäœå¹ŽãåãããããŒããŠã§ã¢ã¬ã€ã€ã§ã®ã»ãã¥ãªãã£å¯Ÿçã«åãçµãã§ããããªãã§ãç±³åœã¯ãããããåãçµã¿ã®å é²å°ã§ããã
ç±³åœããå§ãŸã£ãã»ãã¥ã¢ãªããŒããŠã§ã¢å®çŸãžã®åãçµã¿
çè ã¯ãµãŒããæ²¢å±±äœã£ãŠããäŒç€Ÿã®äººéãªã®ã§ããµãŒãã§å§ãŸã£ãåãçµã¿äŸã玹ä»ããã2010幎代äžé ãç±³HPEããæ°äžä»£ã®ãµãŒãã®èšèšãéå§ããã«ããã£ãŠãæåã«ãŠãŒã¶ãŒããã®ãã¢ãªã³ã°ãè¡ã£ãã®ã¯é²è¡ãšéèã®ã»ã¯ã¿ãŒã ã£ãããªãã§ãåœé²ç·çãªã©ã®é£éŠæ¿åºæ©é¢ããå°æ¥èŠæ±ããŠãã調éåºæºãæºããããšã¯ãå瀟補åã®èšèšã®åºæ¬çãªæ¹åæ§ã決ããããã§éèŠã§ãã£ãã
ãã®çµæãäž¡ã»ã¯ã¿ãŒããããããã©ã€ãªãªãã£ãšããŠæããããŠããã®ããã»ãã¥ãªãã£ã ã£ãããµãŒãããŒããŠã§ã¢ã«ãããã£ããã®ãæ±ããããããšã¯ãåœææ¥æ¬ã§ã¯äžè¬çã§ã¯ãªãã£ãã
ããã§äžæŠãç±³åœé£éŠæ¿åºã®å ¬çãªåããæ¯ãè¿ã£ãŠã¿ãã2010幎ã«å€§çµ±é 什13556ã§ã管çãã¹ãéèŠæ å ±(CUI)ã«ã€ããŠã®æç€ºããééãããç±³æ¿åºå šäœãšããŠæ å ±ã»ãã¥ãªãã£åŒ·åã®åãçµã¿ãã¯ããŸã£ãã2015幎ã«ã¯ãNISTããã³ã³ãã¥ãŒã¿ã»ãã¥ãªãã£ã¬ããŒããšããŠç¥ãããSP800ã·ãªãŒãºææžã®1ã€ãšããŠãSP800-171(é£éŠæ¿åºå€ã®ã·ã¹ãã ãšçµç¹ã«ããã管çãããéæ Œä»ãæ å ±ã®ä¿è·)ããªãªãŒã¹ããããããã¯ãçŸåšãåºãåç §ãããŠãããCUIã®ã»ãã¥ãªãã£èŠä»¶ãæç€ºããææžã§ããã
2016幎ã«å ¬ç€ºããããDFARS(åœé²ç調éèŠå) 252.204-7012âSafeguarding Covered Defense Information and Cyber Incident Reportingâã§ã¯ãã»ãã¥ãªãã£èŠä»¶éµå®ã®å¯Ÿå¿æéã2017幎12æ31æ¥ãŸã§ãšããããã€ãŸããç±³åœã¯åœé²ç·çã®èª¿éèŠä»¶ãšããŠãSP800-171ãžã®2017幎æ«ãžã®å¯Ÿå¿ãæ°éã®çŽå ¥æ¥è ã«èŠæ±ããã®ã§ããã
HPEãã»ãã¥ãªãã£ã«äž»çŒã眮ãããµãŒã補åã®æ°äžä»£ããªãªãŒã¹ããã®ã¯2017幎ã§ãããç±³åœã®ãããªãã¯ã¯ã©ãŠããã³ããŒã®ããŒããŠã§ã¢ã»ãã¥ãªãã£èŠæ ŒãããªãªãŒã¹ãããã®ãŒããšå€ããåãææã«ããã£ãŠããã
äžæ¹ã2017å¹Žåœæãã»ãã¥ãªãã£ã«äž»çŒã眮ãããµãŒãã®æ°è£œåããšããåãå£ã¯æ¥æ¬åžå Žã§ã¯ãªããªã泚ç®ãããªãã£ãããšããã®ãæ£çŽãªãšããã ã
æ¹ããã»åœé ãå°é£ãªãã§ãã¯æ©æ§ã§ä¿¡é Œæ§ãæ ä¿
ããããæ¥æ¬ã§ã®ç¶æ³ããããæ°å¹Žã§å€ããã€ã€ããããã®5幎éã§IoTã5Gãšãã£ãçšéã®æ®åã«ãããããŒã¿çæå Žæã®ãã©ãã€ã ã·ãããé²è¡ããããµãŒãã®èšçœ®å Žæã¯ããŒã¿ã»ã³ã¿ãŒã®å³éãªã²ãŒãã®å åŽããã山奥ã®åºå°å±ã®äžãå·¥å Žã®ç£æ¥æ©æ¢°ã®æšªãæžå€ã®é»æ±ã®äžãªã©ãåŸæ¥ãšã¯ç°ãªããªã¹ã¯ã®æãå Žæãžãšæ¡å€§ãããç©ççã«ç®ã®å±ããªãããããå Žæã«çœ®ãããããŒããŠã§ã¢ã®ã»ãã¥ãªãã£ããã©ã®ããã«æ ä¿ããã®ããçšéã®æ¡å€§ãšãšãã«ãããŒããŠã§ã¢èªäœãžã®ã»ãã¥ãªãã£å¯Ÿçã®å¿ èŠæ§ããåºãçŸå®ã®èª²é¡ãšããŠèªèãããããã«ãªã£ãŠããã
ããŒããŠã§ã¢ã»ãã¥ãªãã£ã«æ±ããããå ·äœçãªèŠä»¶ããå ã«èšåããNIST SP800ã·ãªãŒãºææžã®äžã«èŠãŠã¿ãããNIST SP800-193 âPlatform Firmware Resiliency Guidelinesâãããã«ããããHPEãä»ã®ãã³ããŒãã³ã³ããªãã¥ãŒã¿ãšããŠååãé£ããŠããã2017幎ã«ãã©ããçãçºè¡ããã2018å¹Žã«æ£åŒãªãªãŒã¹ãããããã®ææžã¯ããŸãã«ããŒããŠã§ã¢ã»ãã¥ãªãã£ã®éµãšãªãããã¡ãŒã ãŠã§ã¢ã»ãã¥ãªãã£ã®å®è£ æ¹æ³ã«ã€ããŠå ·äœçã«èšè¿°ããŠããããã®äžã§ããã¡ãŒã ãŠã§ã¢ã®æ¹ãããç Žå£ãšãã£ããã»ãã¥ãªãã£äŸµå®³ãžã®å¯ŸæçãšããŠåºãå®è£ ãæ±ããåœ¢ã§æç€ºãããŠããæ©æ§ããRoT(Root of Trustãä¿¡é Œã®æ ¹)ã§ãããRoTã®ãããªå ·äœçãªããŒããŠã§ã¢ã»ãã¥ãªãã£æ©æ§ã2017å¹Žã®æ®µéãããããããææžã«ãŸãšããããæ®åã«åããŠã®åããé²ãã§ããã®ã§ããã
RoTãšã¯ãããŒããŠã§ã¢ã®åºåºãšãªãéšåã«æ¹ããã»åœé ãæ¥µããŠå°é£ãªãã§ãã¯æ©æ§ãå®è£ ãããã®æ©æ§ãåºã«ããŠãã¡ãŒã ãŠã§ã¢ã®ã»ãã¥ãªãã£ãæ ä¿ããä»çµã¿ã§ãããRoTã®èãæ¹ã®æ ¹æ¬ã«ããã®ã¯ãèšŒææžã䜿ã£ãŠããŒããŠã§ã¢ãšãã¡ãŒã ãŠã§ã¢ã®æ£åœæ§ãæ€èšŒãããšããèãæ¹ã ãHPEã§ã¯RoTã«ã€ããŠãããŒããã©ã¹ãã®èãæ¹ãããŒããŠã§ã¢ã€ã³ãã©ã«ãé©çšããããšèª¬æããŠããã
ä»ç€Ÿãå«ããçŸåšã®å®è£ ã§ãã®ä»çµã¿ãã«ããŒããŠããã®ã¯ããã¶ãŒããŒãäžã®æ žå¿çãªéšåã®ãã¡ãŒã ãŠã§ã¢ã«ã»ãŒéãããŠãããããããå°æ¥çã«ã¯ããã¹äžã«ã€ãªããããããã³ã³ããŒãã³ããæ€èšŒãçžäºã«è¡ããããªå®è£ 圢æ ãããåŸãã ãããæ§æªèª¬ã®äžçã§ãä¿¡é Œãæ ä¿ã§ããããŒããŠã§ã¢ã®ä»çµã¿ãäœã£ãŠãããããšããã®ããæ°ããªãµãã©ã€ãã§ãŒã³ãªã¹ã¯ã泚ç®ãããŠããäžã§ã®ãããŒããŠã§ã¢ãã¶ã€ã³ã®æ¹åæ§ã§ããã
-

HPEã§ã®RoTã®å®è£ äŸãHPEã§ã¯ç¬èªéçºã®ASICã§ãããiLO 5ãCPUãšã¯å¥ã«å®è£ ããèã¿ã³ããŒæ§ãé«ããSilicon Root of TrustãšããŠå®è£ ããŠãããäžè¬çã«ã¯ãTPM(Trusted Platform Module)ã䜿çšããŠRoTãšããŠå®è£ ããããšãå€ã
äžéšã®ã¹ããŒããã©ã³ã§ã¯ããã§ã«å éšã®ã³ã³ããŒãã³ãåäœã®èªèšŒãã¯ãããŠãããã®ããããäžèŠãããšåºæäžæã®äºæéšåãžã®å¯Ÿçã«ãèŠããããããã補é ããã¡ã³ããã³ã¹ãŸã§å«ããŠã極ããŠé·å€§ã§è€éãªã³ã³ã·ã¥ãŒãåã補åã®ãµãã©ã€ãã§ãŒã³ã®ä¿¡é Œæ§ãæ ä¿ããããã®ãéåžžã«æå¹ãªä»æããšæããããšãã§ããã ããã
ãã®ãããªæµãã¯ãã³ã³ãã¥ãŒã¿çãªã¢ãŒããã¯ãã£ãæã€ãããŸããŸãªãã©ãããã©ãŒã ã§é²ãã§ãããå·¥å Žã§å€§éçç£ã»æµéããã補åã«ãããŠã補é ãã廿£ã»åå©çšãŸã§ã®ã©ã€ããµã€ã¯ã«å šäœãéããŠãå®å šæ§ãæ£åœæ§ã人æã«ããç£èŠãæžé¡ã®ããåãã§æ ä¿ããã®ã¯äžå¯èœã ã
ããã§ã¯ãªããŠãããŒããŠã§ã¢èªèº«ã«ã³ã³ããŒãã³ãã®å®å šæ§ãçèŽãæ€èšŒãããä»çµã¿ãæãããããšããæ¹åæ§ããä»åŸã¯ããã¡ã¯ãã¹ã¿ã³ããŒããªã£ãŠãããšæãããããŸãããŠãŒã¶ãŒã®ç«å Žããã¯ãããŒããŠã§ã¢éžå®ã®éã«ããŒããŠã§ã¢ã¬ã€ã€ã§ã®ã»ãã¥ãªãã£ãè©äŸ¡è»žã®1ã€ã«å«ããããšããåããåºãŸã£ãŠãããšèããããã