ืื™ื ื˜ืœ ืžืคืชื—ืช ืืช ืคืจื•ื˜ื•ืงื•ืœ HTTPA ื›ื“ื™ ืœื”ืฉืœื™ื ืืช HTTPS

ืžื”ื ื“ืกื™ื ืžืื™ื ื˜ืœ ื”ืฆื™ืขื• ืคืจื•ื˜ื•ืงื•ืœ HTTPA ื—ื“ืฉ (HTTPS Attestable), ื”ืžืจื—ื™ื‘ ืืช ื”-HTTPS ืขื ืขืจื‘ื•ื™ื•ืช ื ื•ืกืคื•ืช ืœืื‘ื˜ื—ืช ื”ื—ื™ืฉื•ื‘ื™ื ืฉื‘ื•ืฆืขื•. HTTPA ืžืืคืฉืจืช ืœื”ื‘ื˜ื™ื— ืืช ืฉืœืžื•ืช ืขื™ื‘ื•ื“ ื‘ืงืฉืช ื”ืžืฉืชืžืฉ ื‘ืฉืจืช ื•ืœื•ื•ื“ื ืฉืฉื™ืจื•ืช ื”ืื™ื ื˜ืจื ื˜ ืืžื™ืŸ ื•ื”ืงื•ื“ ื”ืคื•ืขืœ ื‘ืกื‘ื™ื‘ืช TEE (Trusted Execution Environment) ื‘ืฉืจืช ืœื ื”ืฉืชื ื” ื›ืชื•ืฆืื” ืžืคืจื™ืฆื” ืื• ื—ื‘ืœื” ืขืœ ื™ื“ื™ ื”ืžื ื”ืœ.

HTTPS ืžื’ืŸ ืขืœ ื”ื ืชื•ื ื™ื ื”ืžื•ืขื‘ืจื™ื ื‘ืžื”ืœืš ืฉื™ื“ื•ืจ ื‘ืจืฉืช, ืืš ืื™ื ื• ื™ื›ื•ืœ ืœืžื ื•ืข ืืช ื”ืคืจืช ืฉืœืžื•ืชื ื›ืชื•ืฆืื” ืžื”ืชืงืคื•ืช ืขืœ ื”ืฉืจืช. ืžื•ื‘ืœืขื•ืช ืžื‘ื•ื“ื“ื•ืช, ืฉื ื•ืฆืจื• ื‘ืืžืฆืขื•ืช ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื›ื’ื•ืŸ Intel SGX (Software Guard Extension), ARM TrustZone ื•-AMD PSP (Platform Security Processor), ืžืืคืฉืจื•ืช ืœื”ื’ืŸ ืขืœ ืžื—ืฉื•ื‘ ืจื’ื™ืฉ ื•ืœื”ืคื—ื™ืช ืืช ื”ืกื™ื›ื•ืŸ ืœื“ืœื™ืคื” ืื• ืฉื™ื ื•ื™ ืฉืœ ืžื™ื“ืข ืจื’ื™ืฉ ื‘ืฆื•ืžืช ื”ืงืฆื”.

ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืืช ืžื”ื™ืžื ื•ืช ื”ืžื™ื“ืข ื”ืžื•ืขื‘ืจ, HTTPA ืžืืคืฉืจ ืœืš ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ื”ืื™ืฉื•ืจ ื”ืžืกื•ืคืงื™ื ื‘-Intel SGX, ื”ืžืืฉืจื™ื ืืช ื”ืื•ืชื ื˜ื™ื•ืช ืฉืœ ื”ืžื•ื‘ืœืขืช ืฉื‘ื” ื‘ื•ืฆืขื• ื”ื—ื™ืฉื•ื‘ื™ื. ื‘ืขื™ืงืจื• ืฉืœ ื“ื‘ืจ, HTTPA ืžืจื—ื™ื‘ ืืช HTTPS ืขื ื”ื™ื›ื•ืœืช ืœืืฉืจ ืžื•ื‘ืœืขืช ืžืจื—ื•ืง ื•ืœืืคืฉืจ ืœืš ืœื•ื•ื“ื ืฉื”ื™ื ืคื•ืขืœืช ื‘ืกื‘ื™ื‘ืช Intel SGX ืžืงื•ืจื™ืช ื•ืฉื ื™ืชืŸ ืœืกืžื•ืš ืขืœ ืฉื™ืจื•ืช ื”ืื™ื ื˜ืจื ื˜. ื”ืคืจื•ื˜ื•ืงื•ืœ ืžืคื•ืชื— ื‘ืชื—ื™ืœื” ื›ืคืจื•ื˜ื•ืงื•ืœ ืื•ื ื™ื‘ืจืกืœื™, ื•ื‘ื ื•ืกืฃ ืœืื™ื ื˜ืœ SGX, ื ื™ืชืŸ ืœื™ื™ืฉื ืื•ืชื• ืขื‘ื•ืจ ืžืขืจื›ื•ืช TEE ืื—ืจื•ืช.

ืื™ื ื˜ืœ ืžืคืชื—ืช ืืช ืคืจื•ื˜ื•ืงื•ืœ HTTPA ื›ื“ื™ ืœื”ืฉืœื™ื ืืช HTTPS

ื‘ื ื•ืกืฃ ืœืชื”ืœื™ืš ื”ืจื’ื™ืœ ืฉืœ ื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ ืžืื•ื‘ื˜ื— ืขื‘ื•ืจ HTTPS, HTTPA ื“ื•ืจืฉ ื‘ื ื•ืกืฃ ืžืฉื ื•ืžืชืŸ ืขืœ ืžืคืชื— ื”ืคืขืœื” ืžื”ื™ืžืŸ. ื”ืคืจื•ื˜ื•ืงื•ืœ ืžืฆื™ื’ ืฉื™ื˜ืช HTTP ื—ื“ืฉื” "ATTEST", ื”ืžืืคืฉืจืช ืœืš ืœืขื‘ื“ ืฉืœื•ืฉื” ืกื•ื’ื™ื ืฉืœ ื‘ืงืฉื•ืช ื•ืชื’ื•ื‘ื•ืช:

  • "ื˜ื™ืกื” ืžื•ืงื“ืžืช" ื›ื“ื™ ืœื‘ื“ื•ืง ืื ื”ืฆื“ ื”ืžืจื•ื—ืง ืชื•ืžืš ื‘ืื™ืฉื•ืจ ืžื•ื‘ืœืขืช;
  • "ืื™ืฉื•ืจ" ืœื”ืกื›ืžื” ืขืœ ืคืจืžื˜ืจื™ ืื™ืฉื•ืจ (ื‘ื—ื™ืจืช ืืœื’ื•ืจื™ืชื ืงืจื™ืคื˜ื•ื’ืจืคื™, ื”ื—ืœืคืช ืจืฆืคื™ื ืืงืจืื™ื™ื ื™ื™ื—ื•ื“ื™ื™ื ืœืกืฉืŸ, ื™ืฆื™ืจืช ืžื–ื”ื” ืกืฉืŸ ื•ื”ืขื‘ืจืช ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ ืฉืœ ื”ืžื•ื‘ืœืขืช ืœืœืงื•ื—);
  • "ื”ืคืขืœื” ืžื”ื™ืžื ื”" - ื™ืฆื™ืจืช ืžืคืชื— ื”ืคืขืœื” ืœื—ื™ืœื•ืคื™ ืžื™ื“ืข ืžื”ื™ืžืŸ. ืžืคืชื— ื”ืคื’ื™ืฉื” ื ื•ืฆืจ ื‘ื”ืชื‘ืกืก ืขืœ ืกื•ื“ ืžื•ืกื›ื ืœืคื ื™ ื”ืคื’ื™ืฉื” ืฉื ื•ืฆืจ ืขืœ ื™ื“ื™ ื”ืœืงื•ื— ื‘ืืžืฆืขื•ืช ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ TEE ืฉื”ืชืงื‘ืœ ืžื”ืฉืจืช, ื•ืจืฆืคื™ื ืืงืจืื™ื™ื ืฉื ื•ืฆืจื• ืขืœ ื™ื“ื™ ื›ืœ ืฆื“.

ืื™ื ื˜ืœ ืžืคืชื—ืช ืืช ืคืจื•ื˜ื•ืงื•ืœ HTTPA ื›ื“ื™ ืœื”ืฉืœื™ื ืืช HTTPS

HTTPA ืžืจืžื– ืฉื”ืœืงื•ื— ืืžื™ืŸ ื•ื”ืฉืจืช ืœื, ื›ืœื•ืžืจ. ื”ืœืงื•ื— ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ ื–ื” ื›ื“ื™ ืœืืžืช ื—ื™ืฉื•ื‘ื™ื ื‘ืกื‘ื™ื‘ืช TEE. ื™ื—ื“ ืขื ื–ืืช, HTTPA ืื™ื ื” ืžืชื—ื™ื™ื‘ืช ืฉื—ื™ืฉื•ื‘ื™ื ืื—ืจื™ื ืฉื‘ื•ืฆืขื• ื‘ืžื”ืœืš ืคืขื•ืœืช ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ืฉืื™ื ื ืžื‘ื•ืฆืขื™ื ื‘-TEE ืœื ื ืคื’ืขื•, ืžื” ืฉืžืฆืจื™ืš ืฉื™ืžื•ืฉ ื‘ื’ื™ืฉื” ื ืคืจื“ืช ืœืคื™ืชื•ื— ืฉื™ืจื•ืชื™ ืื™ื ื˜ืจื ื˜. ืœืคื™ื›ืš, HTTPA ืžื›ื•ื•ืŸ ื‘ืขื™ืงืจ ืœืฉื™ืžื•ืฉ ืขื ืฉื™ืจื•ืชื™ื ืžื™ื•ื—ื“ื™ื ืฉื”ื’ื‘ื™ืจื• ื“ืจื™ืฉื•ืช ืœืฉืœืžื•ืช ื”ืžื™ื“ืข, ื›ื’ื•ืŸ ืžืขืจื›ื•ืช ืคื™ื ื ืกื™ื•ืช ื•ืจืคื•ืื”.

ื‘ืžืฆื‘ื™ื ืฉื‘ื”ื ื™ืฉ ืœืืฉืจ ื—ื™ืฉื•ื‘ื™ื ื‘-TEE ื”ืŸ ืขื‘ื•ืจ ื”ืฉืจืช ื•ื”ืŸ ืขื‘ื•ืจ ื”ืœืงื•ื—, ืžืกื•ืคืงืช ื’ืจืกื” ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ mHTTPA (Mutual HTTPA), ืืฉืจ ืžื‘ืฆืขืช ืื™ืžื•ืช ื“ื•-ื›ื™ื•ื•ื ื™. ืืคืฉืจื•ืช ื–ื• ืžืกื•ื‘ื›ืช ื™ื•ืชืจ ื‘ืฉืœ ื”ืฆื•ืจืš ื‘ื™ื™ืฆื•ืจ ื“ื•-ื›ื™ื•ื•ื ื™ ืฉืœ ืžืคืชื—ื•ืช ื”ืคืขืœื” ืขื‘ื•ืจ ื”ืฉืจืช ื•ื”ืœืงื•ื—.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”