床éãªãæ å ±æŒæŽ©äºä»¶ããã®è¢«å®³ç¶æ³ãç®ã®åœããã«ããŠãèªç€Ÿã®ã»ãã¥ãªãã£åŒ·åã«åãçµãããšããŠããäŒæ¥ãå€ãããšã ããããããããèšãããããã«ãããã«ãŒã«ããæ»æææ³ãšã»ãã¥ãªãã£å¯Ÿçã¯ããã¡ãã£ãã ããããã¯ãŒã¯ã«ææ°ã§åŒ·åºãªãå£ããã€ãã£ãŠãããããã¯ãããäžåãæ»æææ³ãç·šã¿åºãããŠããŸãããã®ãããªç¶æ³ã§æ³šç®ãéããŠããã®ãæå·åã ãä»®ã«ããŒã¿ãæŒæŽ©ãããšããŠããæå·åãããŠããã°ããã¯ãã ã®æååã«ãããªãããŸãããã«ãŒãè§£èªã«åãçµãã ãšããŠããæå·ãè€éã§ããã°ããã»ã©ãååãªå¯Ÿå¿ããšãããã®æéã皌ãããšãã§ããã
ãšã¯ãããæå·åããšåãã€ãã°ã©ããåããšããããã§ã¯ãªãããšãã³ã¿ã»ãã¥ãªãã£ã·ã¹ãã ãº æ¥æ¬æ³äººã®ä»£è¡šåç· åœ¹ç€Ÿé· é³è²å(ãžã³ã»ãžã§ã³ã)æ°ã¯èšããã§ã¯ãã®å·®ã¯äžäœã©ãã«ããã®ã ããããæè¿ãæ§ã ãªã·ãŒã³ã§å©çšãããããã«ãªã£ããªãŒãã³ãœãŒã¹ã»ããŒã¿ããŒã¹(OSS-DB)ã®æå·åãœãªã¥ãŒã·ã§ã³ãäŸã«ããã®å®å šæ§ã«ã€ããŠè§£èª¬ããŠããã£ãã
![]() |
ãã³ã¿ã»ãã¥ãªãã£ã·ã¹ãã ãº æ¥æ¬æ³äºº 代衚åç· åœ¹ç€Ÿé· é³è²åæ° |
OSS-DBã®æå·åæ©èœãšã»ãã¥ãªãã£åŒ·åºŠ
OSS-DBã®æå·åãè¡ãã²ãšã€ã®ææ®µãšããŠã¯ãDBã®ãªãã·ã§ã³æ©èœãäœ¿ãæ¹æ³ããã³ã¿ã»ãã¥ãªãã£ã·ã¹ãã ãºã®ãããªãµãŒãããŒãã£ã®ãœãªã¥ãŒã·ã§ã³ãäœ¿ãæ¹æ³ã®ã倧ããåããŠäºã€ããããOSS-DBã«éãããDBä»å±ã®æå·åæ©èœãšããŠçŸåšã¡ãžã£ãŒãªã®ããTDE(Transparent Data Encryption ééåæå·å)ã ãããŒãã«ã¹ããŒã¹(衚é å)æå·åãšãåŒã°ããéããDBã®ããŒãã«ãããŒãã«é åãåºæºãšããŠå éšçã«æå·åã埩å·ãè¡ãã¹ãã¬ãŒãžã«ä¿åããæ¹åŒã§ãããæ§æ¥ã®DB-APIãå©çšããããŒã¿åäœã®æå·åã«æ¯ã¹ããšãç°¡åã«åæ±ãããšãã§ãããããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒã«ãšã£ãŠã¯ãæå·åã埩å·ãæèããããšãªããééçãã€ã¹ã ãŒã¹ã«ããŒã¿ãå©çšã§ããã®ãç¹é·ãšãªã£ãŠãããããèããšãããããšããããã«æãããâŠâŠé³æ°ã¯ãéä¿¡ã¯çŠç©ã ãšèªãã
ãTDEã§æå·åãããããŒãã«ãåŒã³åºããŠå©çšããéã埩å·ãããããŒãã«ã¯ã¡ã¢ãªãŒäžã«å±éãããŸããã€ãŸããäŸµå ¥è ã¯ã¡ã¢ãªãã³ããã¡ã€ã«ãDBã¢ã«ãŠã³ããäžæ£ã«å ¥æããããšããã§ããã°ãå¹³æã®ããŒã¿ãæã«å ¥ãããããšããããšã§ãã
TDEã«ã€ããŠã¯æåã§å°å ¥ãéçšã®ãµããŒããè¡ãäŒæ¥ãåºãŠããŠãããæŽ»çšãæ€èšããŠããäŒæ¥ã¯ããããã£ãäºæ¥è ã«ã»ãã¥ãªãã£åŒ·åºŠãé«ãããããããªå¯Ÿçãçžè«ããæ¹ãããã ããã
ã»ãã¥ãªãã£ã®åŒ·åºŠã枬ã3ã€ã®ãã€ã³ã
æå·åãœãªã¥ãŒã·ã§ã³ã®åŒ·åºŠããã§ãã¯ãããã€ã³ããšããŠã鳿°ã¯ã(1)éµã®æ©å¯æ§ (2)察å¿ããã¢ã«ãŽãªãºã (3)ãæå·ããŒã¿ãã«å¯Ÿããã¢ã¯ã»ã¹å¶åŸ¡ãšèšŒè·¡ç®¡çâŠâŠã®3ã€ãæããã
(1)ãéµãã®æ©å¯æ§
埩å·ã«äœ¿ããéµãã¯ãDB管çè
ãšããã©ããã®å
容ã«ç¡é¢ä¿ã®äººå¡ãç¥ãã¹ããã®ã§ã¯ãªããDBæå·åã«ããã£ãŠã¯DB管çè
ãšã¯å¥ã«ã»ãã¥ãªãã£ç®¡çè
ãé
眮ããè·è²¬ã«å¿ããæš©éã®åé¢ãè¡ãããšãçæ³ã§ãããã»ãã¥ãªãã£ã®åŒ·åºŠãé«ããããšã«ã€ãªããã
ãTDEã¯ããããDB管çè ãéçšã»ç®¡çããããšãåæã«ã€ããããŠããã®ã§ãã®æš©éåé¢ãã§ããŠããããéçšã«ã¯ååæ³šæããå¿ èŠããããŸãã(鳿°)
(2)察å¿ããã¢ã«ãŽãªãºã
æšå¥šãããã¢ã«ãŽãªãºã ã¯æéãšãšãã«å€ãã£ãŠãããã®ã ãããã®æç¹ã®åœãæ¿åºæ©é¢ãæšå¥šããã¢ã«ãŽãªãºã ã«ã¯å¯Ÿå¿ããŠããå¿
èŠãããããŸãæå·åã®ã¢ã«ãŽãªãºã ã«ã¯ã忹忧ã®ãã®ãšäžæ¹åæ§ã®ãã®ããããäžæ¹åæ§ã®ãã®ãšã¯ãäŸãã°(埩å·ã®å¿
èŠã®ãªã)ãã¹ã¯ãŒãã®æå·åãªã©ãèªèšŒç®çã«ããå©çšããããã®ã忹忧ã¢ã«ãŽãªãºã ããæããªããœãªã¥ãŒã·ã§ã³ã§ã¯ãéµç®¡çã®äžåŸ¹åºã«ããæå·åæãããã¹ã¯ãŒããå²ãåºãããŠããŸãå±éºæ§ããããTDEã¯ããŒã¿ã埩å·ããŠäœ¿çšããã®ãåæãšãªããã®ãããªçšéã«ã¯äžåããªãããæå·åã·ã¹ãã ã®å°å
¥ã«ããã£ãŠã¯äžæ¹åæ§ã®ã¢ã«ãŽãªãºã ã§ããSHA-2ã«å¯Ÿå¿ããããšãéžæè¢ã®äžã€ãšãªãã ããã
(3)ãæå·åããŒã¿ãã«å¯Ÿããã¢ã¯ã»ã¹å¶åŸ¡ãšèšŒè·¡ç®¡ç
ãéµãã®æ©å¯æ§ãšãé¢é£ããããé©åãªãŠãŒã¶ãŒã®ã¿ã«åŸ©å·æš©éãä»äžã誰ããã€ãæå·åããŒã¿ããå©çšãã(埩å·ãå®è¡ããããåã¯æåŠããã)ã®ããèšé²ç£æ»ããä»çµã¿ãæŽããããšã§ãçµç¹å
ã®äžæ£ãç¯çœªãææ¢ããããšãã§ããããã®ãããªå
æ¬çãªã»ãã¥ãªãã£æ©èœã¯ãããŒã¿ã®æå·åãšã¢ã¯ã»ã¹æš©éã®æŠå¿µã䜵ãæã€ãœãªã¥ãŒã·ã§ã³ã§ã®ã¿å®çŸå¯èœãšãªãã
ãç°¡åã§å®äŸ¡ã ãããšå°å ¥ãããœãªã¥ãŒã·ã§ã³ã ã£ãã®ã«ãåŸã çºèŠããè匱æ§ã«å¯Ÿå¿ããããã«å°éã®ãšã³ãžãã¢ãéããªããã°ãªããªããªã£ãããæå·åã§ç¢ºå®ã«å®ãããŠãããšæã£ãæ å ±ãæŒæŽ©ããŠå·šé¡ã®è³ åéãæ¯æãããšã«ãªã£ããããã®ã§ããã°ãäŸ¡æ Œãå©äŸ¿æ§ã ãã§ãªãã»ãã¥ãªãã£ã®åŒ·åºŠã«éç¹ã眮ããŠãœãªã¥ãŒã·ã§ã³éžå®ããã¹ãã§ãããã(鳿°)
çŸåšOSS-DBã®æå·åãæ€èšãããŠãããªããæ¬çš¿ãåèã«ã匷床ãšã³ã¹ãã®ãã©ã³ã¹ãåãããœãªã¥ãŒã·ã§ã³ãéžå®ããŠããã ããã°å¹žãã ã
ãªãä»å解説ããé¡ããã鳿°ãç±ã眮ããã³ã¿ã»ãã¥ãªãã£ã·ã¹ãã ãºã§ã¯ãMySQLãMariaDBãPerconaDBãšãã£ãOSS-DBã«å¯Ÿå¿ããæå·åãœãªã¥ãŒã·ã§ã³ãMyDiamo(ãã€ãã£ã¢ã¢)ããæäŸããŠãããæ¬çš¿ã§åãäžãããããªTDEã®åé¡ç¹ã¯ã¯ãªã¢ããããŸãéçšæã«ã·ã¹ãã ã®ããã©ãŒãã³ã¹ã«äžãã圱é¿ã7ïŒ æªæº(åç€Ÿã®æž¬å®)ã«æãããããšããã詳现ã¯äžèšãµã€ãã§ç¢ºèªã§ããã®ã§ããã¡ãããã²åèã«ããããã
â MyDiamoæ¥æ¬èªãµã€ã
(ãã€ãããã¥ãŒã¹åºåäŒç» ïŒ æäŸ ãã³ã¿ã»ãã¥ãªãã£ã·ã¹ãã ãº)
[PR]æäŸïŒ
