çŸä»£ã§ã¯ããœãããŠã§ã¢éçºããŸããŸãè€éã«ãªããå€ãã®æ å ±ã»ãã¥ãªãã£ã®è åšãååšããŠããŸãããã®ãã¬ã³ãã«è¿œãã€ãããã«ãèªèšŒå¯Ÿèªå¯ã¡ã«ããºã ããã®åé¡ã解決ããããã«çãŸãããœãããŠã§ã¢ã®ã»ãã¥ãªãã£åäžã«å¯äžããŠããŸãã
1. èªèšŒãšã¯äœã§ããïŒäžéšã®äººæ°ã®ããèªèšŒæ¹æ³

èªèšŒã¯ãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ã¬ãã«ãåäžãããæ å ±èªèšŒã®äžåœ¢æ ã§ããåºå ž: globalsign.com
1.1. ã³ã³ã»ãã
èªèšŒã¯ããŠãŒã¶ãŒæ å ±ãšãã¹ã¯ãŒããèªèšŒããŠããŠãŒã¶ãŒã®èº«å ãæ€èšŒããç¹å®ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©ããããã©ããã確èªããããã»ã¹ã§ãã
1.2. åé¡
èªèšŒã«ã¯2ã€ã®ã¿ã€ãããããŸãïŒHTTPããŒã·ãã¯èªèšŒãšå€èŠçŽ èªèšŒã§ãã
– HTTPããŒã·ãã¯èªèšŒ
HTTPããŒã·ãã¯èªèšŒã¯ãHTTPãããã³ã«ãä»ããŠã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãåäžãããããã®èªèšŒåœ¢åŒã§ãããã®åœ¢åŒã§ã¯ããœãããŠã§ã¢ã䜿çšããéã«ãŠãŒã¶ãŒã«ãã°ã€ã³åãšãã¹ã¯ãŒãã®æäŸãæ±ããŸãããµãŒããŒã¯ãã©ãŠã¶äžã§ãŠãŒã¶ãŒæ å ±ãåéããŠããŒã¿ãä¿è·ããŸãã
– å€èŠçŽ èªèšŒïŒMFAïŒ
å€èŠçŽ èªèšŒã¯ãè€æ°ã®èªèšŒã¹ããããå¿ èŠãšããã»ãã¥ãªãã£ã·ã¹ãã ã§ãããã«ã¯ãã°ã€ã³ãä»ã®åœ¢åŒã®ãã©ã³ã¶ã¯ã·ã§ã³ãå«ãŸããŸãã
å€èŠçŽ èªèšŒã¯ããã¹ã¯ãŒããã»ãã¥ãªãã£ããŒã¯ã³ãçäœèªèšŒãªã©ã®èŠçŽ ãçµã¿åãããããšãäžè¬çã§ãã
å€ãã®èŠçŽ ãçµã¿åãããããšã§ãã¢ããªã±ãŒã·ã§ã³ã«å åºãªã»ãã¥ãªãã£ã¬ã€ã€ãŒãäœæããããã«ãŒããã®äžæ£ã¢ã¯ã»ã¹ãé²ããŸãã
1.3. ããã€ãã®äººæ°ã®ããèªèšŒæ¹æ³
– ãã¹ã¯ãŒã
ãã¹ã¯ãŒãã¯æãã·ã³ãã«ã§å°å ¥ãç°¡åãªèªèšŒæ¹æ³ã§ãããŠãŒã¶ãŒã«ã¯ãã¹ã¯ãŒãã®å ¥åãæ±ããããã·ã¹ãã ã¯æ å ±ãåæ¹åã®æå·å圢åŒã§ä¿åãããããã³ã°ãããŠããã¹ã¯ãŒããå埩ã§ããªãããã«ããŸãã
– å ¬éé»åéµ
å ¬é鵿å·ã¯ãå ¬ééµãšç§å¯éµã䜿çšããæå·ã¢ã«ãŽãªãºã ãä»ããèªèšŒæ¹æ³ã§ããã·ã¹ãã ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããã«ã¯ãããã€ã¹ã«å人ã®éµãæã£ãŠããå¿ èŠãããããã°ã€ã³æ å ±ãèŠããŠããªããŠãã¢ããªã±ãŒã·ã§ã³ã«ãã°ã€ã³ã§ããŸãã
– çäœèªèšŒ
çäœèªèšŒã¯ãæçŽãé¡ãªã©ã®äººéã®çç©åŠçèŠå ã䜿çšããèªèšŒæ¹æ³ã§ãããã®æ¹æ³ã¯éåžžããŠãŒã¶ãŒãå¿ããå Žåã®IDãšãã¹ã¯ãŒããšçµã¿åãããããŸãã
2. ãŠãŒã¶ãŒãã°ã€ã³ä¿åã¡ã«ããºã
åºæ¬çãªãŠãŒã¶ãŒãã°ã€ã³ä¿åã¡ã«ããºã ã«ã¯3ã€ãããŸãïŒåºæ¬èªèšŒãã»ãã·ã§ã³ããŒã¹ã®èªèšŒãããã³ããŒã¯ã³ããŒã¹ã®èªèšŒã
2.1. åºæ¬èªèšŒ
åºæ¬èªèšŒã¯ããŠã§ãã¢ããªã±ãŒã·ã§ã³ã®ããã®æãåçŽãªèªèšŒã¡ã«ããºã ã§ãããå€ãã®ãµãŒããŒã§ç°¡åã«èªåçã«çµ±åãããŸãã

ã»ãã·ã§ã³ããŒã¹ã®èªèšŒã¯ããŠãŒã¶ãŒæ å ±ãä¿åããããã«ã¯ãããŒã䜿çšããŸããåºå ž: dienmaycholon.vn

ããŒã¯ã³ããŒã¹ã®èªèšŒã¯ãå€ãã®ã¯ã©ã€ã¢ã³ãã«é©ãããŠãŒã¶ãŒæ å ±ãä¿åããã¡ã«ããºã ã§ããåºå ž: hackernoon.com
3.1. ã³ã³ã»ãã
èªå¯ã¯ããŠãŒã¶ãŒã«å¯Ÿããã¢ããªã±ãŒã·ã§ã³å ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©ã決å®ããããã»ã¹ã§ããèªå¯ããã»ã¹ã¯ãèå¥ããã»ã¹ã®åŸã«çºçãããã¡ã€ã«ãããŒã¿ããŒã¹ãã¢ããªã±ãŒã·ã§ã³ããŸãã¯ä»ã®ãªãœãŒã¹ã®äœ¿çšèš±å¯ã¬ãã«ã決å®ããŸãã
èªå¯ã®ç®çã¯ããŠãŒã¶ãŒã«ã©ã€ã»ã³ã¹ãããæš©å©ãè¡äœ¿ãããä¿è·ãããããŒã§ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããæªæ¿èªã®ãŠãŒã¶ãŒããã®æ»æãé²ãããšã§ãã
3.2. ããã€ãã®èªå¯æ¹æ³ïŒ
– API ããŒ
API ããŒã¯ãéåžžç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ã«é¢é£ä»ãããããAPI ããŒã䜿çšããŠãããŠãŒã¶ãŒãç¹å®ããããã®èªå¯ã®åœ¢åŒã§ããAPI ã¯å ¬ééµãšç§å¯éµããæãããµãŒããŒãšãŠãŒã¶ãŒéã®éä¿¡ããµããŒãããŸãã
– åºæ¬èªèšŒ
åºæ¬èªèšŒã¯ããŠãŒã¶ãŒã HTTPS çµç±ã§ããããŒã«ãã°ã€ã³åãšãã¹ã¯ãŒããå ¥åããèªå¯ã®åœ¢åŒã§ããåºæ¬ç㪠HTTP èªèšŒãå®è£ ããããšã¯ãã¢ããªã±ãŒã·ã§ã³ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããããã®æãç°¡åãªæ¹æ³ã§ãã
– HMAC
HMAC ã¯ãããžã¿ã«çœ²åã¢ã«ãŽãªãºã ãä»ããŠã¡ãã»ãŒãžãèªèšŒããã³ãŒãããŒã¹ã®èªå¯ããã»ã¹ã§ããHMAC ã¯ãéä¿¡è ãšåä¿¡è ã ããã¢ããªã±ãŒã·ã§ã³ã®ãªãœãŒã¹ã䜿çšããããã®ã»ãã¥ãªãã£ããŒã«ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
– OAuth
OAuth ã¯ããã¹ã¯ãŒããæäŸããã«ã€ã³ã¿ãŒããããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³æ å ±ã«ã¢ã¯ã»ã¹ã§ããããã«ããèªå¯ã®åœ¢åŒã§ãã
OAuth ã¯ãAmazonãGoogleãFacebookãMicrosoft ãªã©å€ãã®å€§äŒæ¥ã«ãã£ãŠé©çšãããŠããããŠãŒã¶ãŒããµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ãšã®éã§ã¢ã«ãŠã³ãã«é¢ããæ å ±ã亀æã§ããããã«ããŸãã
4. èªèšŒãšèªå¯ã®éã

èªèšŒãšèªå¯ã¯ãå®å šã«ç°ãªãèªèšŒããã»ã¹ã§ããåºå ž: ssl2buy.com
èªèšŒãšèªå¯ã¯ãæ··åãããããäºã€ã®çšèªã§ãããããããããã¯å®å šã«ç°ãªãæŠå¿µã§ãããããã€ãã®éãããããŸãã
Authentication | Authorization |
èªèšŒã¯èªå¯ã®æåã®ã¹ãããã§ãã | èªå¯ã¯ãæåããèªèšŒã®åŸã®ã¹ãããã§ãã |
èªèšŒã¯ãã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããããã«èº«å ã確èªããã®ã«åœ¹ç«ã¡ãŸãã | èªå¯ã¯ãã¢ããªã±ãŒã·ã§ã³å ã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹æš©ãå®çŸ©ããã®ã«åœ¹ç«ã¡ãŸãã |
éåžžããŠãŒã¶ãŒåãšãã¹ã¯ãŒããå¿ èŠã§ãã | ã»ãã¥ãªãã£ã«ãã£ãŠã¯ãç°ãªãèªèšŒèŠçŽ ãå¿ èŠã§ãã |
èªèšŒã衚瀺ããããŠãŒã¶ãŒã¯ãã®éšåã倿Žã§ããŸãã |
çµè«
èªèšŒãšèªå¯ã¯ãœãããŠã§ã¢ã»ãã¥ãªãã£ã®éèŠãªåŽé¢ã§ããèªèšŒã¯ãŠãŒã¶ãŒã®èº«å ã確èªããèªå¯ã¯ã¢ã¯ã»ã¹ãå¶åŸ¡ããŸãããããäºã€ã®èŠçŽ ã®æè»ãªçµã¿åããã¯ãããžãã¹ãã·ã¹ãã ã®æŽåæ§ãšå®å šæ§ã確ä¿ããä¿¡é Œæ§ã®ãããœãããŠã§ã¢éçºç°å¢ãæ§ç¯ããã®ã«åœ¹ç«ã¡ãŸãã
çŸåšãBAP Softwareã¯ä¿¡é Œæ§ã®ããæ å ±æè¡ãµãŒãã¹äŒæ¥ã®äžã€ã§ãããç¹ã«ãœãããŠã§ã¢ãµãŒãã¹ãæäŸããŠããŸãããµããŒããã¢ããã€ã¹ãå¿ èŠãªå Žåã¯ãBAP Softwareã«ããã«ãåãåãããã ããïŒç§ãã¡ã¯åžžã«24æé察å¿ã§ãµããŒããæäŸããŠããŸãã