ä»æ¥ãŸã§ããããã¯ãã§ãŒã³ãã¯ãããžãŒãæå·é貚ããããŠãããã©ãã»ã©åªããŠãããã«ã€ããŠæžããŠããªãã®ã¯æ ãè ã ãã§ãã ãã ãããã®èšäºã§ã¯ãã®ãã¯ãããžãŒãè³è³ããããšã¯ãããŸããããã ããã®æ¬ ç¹ãšãããåãé€ãæ¹æ³ã«ã€ããŠã®ã¿èª¬æããŸãã
Altirix Systems ã§ãããžã§ã¯ãã® XNUMX ã€ã«åãçµãã§ãããšãããããã¯ãã§ãŒã³å€éšã®ãœãŒã¹ããã®ããŒã¿ãå®å šãã€æ€é²ã«èããŠç¢ºèªãããšãã課é¡ãçããŸããã XNUMX çªç®ã®ã·ã¹ãã ã®ã¬ã³ãŒãã®å€æŽã確èªãããããã®å€æŽã«åºã¥ããŠã¹ããŒã ã³ã³ãã©ã¯ã ããžãã¯ã® XNUMX ã€ãŸãã¯å¥ã®åå²ãå®è¡ããå¿ èŠããããŸããã äžèŠãããšããããã®ã¿ã¹ã¯ã¯éåžžã«ç°¡åã§ãããããã»ã¹ã«åå ããŠããäžæ¹ã®åœäºè ã®è²¡æ¿ç¶æ ããã®å®è£ ã®çµæã«äŸåããå Žåãè¿œå ã®èŠä»¶ã衚瀺ãããŸãã ãŸã第äžã«ãããã¯ãã®ãããªæ€èšŒã¡ã«ããºã ã«å¯Ÿããå æ¬çãªä¿¡é Œã§ãã ãããããŸãæåã«ã
åé¡ã¯ããããã¯ãã§ãŒã³èªäœãèªåŸçã§ééçãªãšã³ãã£ãã£ã§ããããããããã¯ãã§ãŒã³å ã®ã¹ããŒã ã³ã³ãã©ã¯ãã¯å€ã®äžçã«ã€ããŠäœãç¥ããªãããšã§ãã åæã«ãã¹ããŒã ã³ã³ãã©ã¯ãã®æ¡ä»¶ã¯ãå€ãã®å ŽåãçŸå®ã®ãã®ã«é¢ããæ å ± (ãã©ã€ãã®é 延ãçºæ¿ã¬ãŒããªã©) ã«é¢é£ä»ããããŠããŸãã ã¹ããŒã ã³ã³ãã©ã¯ããé©åã«æ©èœããã«ã¯ããããã¯ãã§ãŒã³ã®å€éšããååŸããæ å ±ãä¿¡é Œã§ããæ€èšŒãããŠããå¿ èŠããããŸãã ãã®åé¡ã¯ãTown Crier ã DECO ãªã©ã®ãªã©ã¯ã«ã䜿çšããããšã§è§£æ±ºãããŸãã ãããã®ãªã©ã¯ã«ã«ããããããã¯ãã§ãŒã³ ãããã¯ãŒã¯å ã®ã¹ããŒã ã³ã³ãã©ã¯ããä¿¡é Œã§ãã Web ãµãŒããŒããã®æ å ±ãä¿¡é Œã§ããããã«ãªãããããã¯ä¿¡é Œã§ããæ å ±ãããã€ããŒã§ãããšèšããŸãã
ãªã©ã¯ã«
ãæ°ã«å ¥ãã®ãµãã«ãŒ ã¯ã©ãããã·ã¢ ã«ããã§åªåããå Žåãã¹ããŒã ã³ã³ãã©ã¯ãã«ãã£ãŠ 0.001 btc ããããã³ã€ã³ ãŠã©ã¬ããã«ééããããšæ³åããŠãã ããã å®éã«åå©ããå Žåãã¹ããŒã ã³ã³ãã©ã¯ãã¯ã©ã®ã¯ã©ããåã£ããã«é¢ããæ å ±ã転éããå¿ èŠããããŸããããã§å€ãã®åé¡ãçºçããŸãããã®æ å ±ãã©ãã§ååŸããããã¹ããŒã ã³ã³ãã©ã¯ãã«å®å šã«è»¢éããæ¹æ³ãããã³ã¹ããŒãã³ã³ãã©ã¯ãã§åãåã£ãæ å ±ã¯æ¬åœã«çŸå®ãšäžèŽããŸãã?
æ å ±æºã®åé¡ã§ã¯ã2 ã€ã®ã·ããªãªãèããããŸããXNUMX ã€ã¯è©Šåã®çµæã«é¢ããæ å ±ãäžå çã«ä¿åããä¿¡é Œã§ãã Web ãµã€ãã«ã¹ããŒã ã³ã³ãã©ã¯ããæ¥ç¶ããæ¹æ³ããã XNUMX ã€ã¯è€æ°ã®ãµã€ãã«äžåºŠã«æ¥ç¶ããã»ãšãã©ã®ãµã€ãããæ å ±ãéžæããæ¹æ³ã§ããåãããŒã¿ãæäŸãããœãŒã¹ã æ å ±ãæ£ããããšã確èªããããã«ãTLSNotary (ããŒã¿ã®ä¿¡é Œæ§ã蚌æããããã® TLS å€æŽ) ã䜿çšãã Oraclize ãªã©ã®ãªã©ã¯ã«ã䜿çšãããŸãã ããããGoogle ã«ã¯ Oraclize ã«é¢ããååãªæ å ±ããããHabré ã«é¢ããèšäºãããã€ããããŸãããä»æ¥ã¯æ å ±äŒéã«å°ãç°ãªãã¢ãããŒãã䜿çšãã Oracle ã§ãã Town Crier ãš DECO ã«ã€ããŠèª¬æããŸãã ãã®èšäºã§ã¯ãäž¡æ¹ã®ãªã©ã¯ã«ã®åäœåçãšè©³çŽ°ãªæ¯èŒã«ã€ããŠèª¬æããŸãã
ã¿ãŠã³ã¯ã©ã€ã€ãŒ
Town Crier (TC) ã¯ã3 幎㮠CCS'2016 㧠IC16 (The Initiative for CryptoCurrency and Contracts) ã«ãã£ãŠå°å
¥ãããŸããã TC ã®èåŸã«ããäž»ãªã¢ã€ãã¢ã¯ãWeb ãµã€ãããã¹ããŒã ã³ã³ãã©ã¯ãã«æ
å ±ãæž¡ããTC ã«ãã£ãŠé
ä¿¡ãããæ
å ±ã Web ãµã€ãäžã®æ
å ±ãšåãã§ããããšã確èªããããšã§ãã TC 㯠TEE (ä¿¡é Œãããå®è¡ç°å¢) ã䜿çšããŠããŒã¿ã®æææš©ãèªèšŒããŸãã TC ã®ãªãªãžãã« ããŒãžã§ã³ã§ã¯ãIntel SGX ãšé£æºããæ¹æ³ã説æãããŠããŸãã
Town Crier ã¯ããããã¯ãã§ãŒã³å
ã®éšåãšãOS èªäœå
ã®éšå (TC Server) ã§æ§æãããŸãã
TC ã³ã³ãã©ã¯ãã¯ãããã¯ãã§ãŒã³äžã«ãããTC ã®ããã³ããšã³ããšããŠæ©èœããŸãã CUïŒãŠãŒã¶ãŒã¹ããŒãã³ã³ãã©ã¯ãïŒããã®ãªã¯ãšã¹ããåãä»ããTCãµãŒããŒããã¬ã¹ãã³ã¹ãè¿ããŸãã TC ãµãŒããŒã®å
éšã«ã¯ããšã³ã¯ã¬ãŒããã€ã³ã¿ãŒããã (åæ¹åãã©ãã£ãã¯) ã«æ¥ç¶ãããšã³ã¯ã¬ãŒãããããã¯ãã§ãŒã³ã«æ¥ç¶ãããªã¬ãŒããããŸãã Enclave ã«ã¯ããããã¯ãã§ãŒã³ãããªã¯ãšã¹ããäœæããããžã¿ã«çœ²åããããããã¯ãã§ãŒã³ã«ã¡ãã»ãŒãžãè¿ãã³ãŒãã§ãã progencl ãå«ãŸããŠããŸããprogencl ã«ã¯ã¹ããŒã ã³ã³ãã©ã¯ã ã³ãŒãã®äžéšãå«ãŸããŠãããå®éã«ãã®æ©èœã®äžéšãå®è¡ããŸãã
Intel SGX ãšã³ã¯ã¬ãŒãã¯ãecall ãéããŠå®è¡ããã API ãåããå
±æã©ã€ãã©ãªãšèããããšãã§ããŸãã Ecall ã¯å¶åŸ¡ããšã³ã¯ã¬ãŒãã«è»¢éããŸãã ãšã³ã¯ã¬ãŒãã¯ãçµäºãããäŸå€ãçºçãããŸã§ã³ãŒããå®è¡ããŸãã ãšã³ã¯ã¬ãŒãã®å€åŽã§å®çŸ©ãããé¢æ°ãåŒã³åºãã«ã¯ãocall ã䜿çšããŸãã Ocall ã¯ãšã³ã¯ã¬ãŒãã®å€ã§å®è¡ããããšã³ã¯ã¬ãŒãã«ãã£ãŠä¿¡é Œã§ããªãåŒã³åºããšããŠæ±ãããŸãã ocall ãå®è¡ãããåŸãå¶åŸ¡ã¯ãšã³ã¯ã¬ãŒãã«æ»ããŸãã
ãšã³ã¯ã¬ãŒãéšåã§ã¯ãWeb ãµãŒããŒã§å®å
šãªãã£ãã«ãæ§æããããšã³ã¯ã¬ãŒãèªäœãã¿ãŒã²ãã ãµãŒããŒãš TLS ãã³ãã·ã§ã€ã¯ãå®è¡ãããã¹ãŠã®æå·åæäœããã®å
éšã§å®è¡ããŸãã TLS ã©ã€ãã©ãª (mbedTLS) ãš HTTP ã³ãŒãã®çž®å°ããŒãžã§ã³ã SGX ç°å¢ã«ãšã¯ã¹ããŒããããŸããã ãŸããEnclave ã«ã¯ããªã¢ãŒã ãµãŒããŒã®èšŒææžã確èªããããã®ã«ãŒã CA 蚌ææž (蚌ææžã®ã³ã¬ã¯ã·ã§ã³) ãå«ãŸããŠããŸãã ãªã¯ãšã¹ã ãã³ãã©ãŒã¯ãã€ãŒãµãªã¢ã ãæäŸãã圢åŒã§ããŒã¿ã°ã©ã ãªã¯ãšã¹ããåãåããããã埩å·åããŠè§£æããŸãã 次ã«ãèŠæ±ãããããŒã¿ã°ã©ã ãå«ãã€ãŒãµãªã¢ã ãã©ã³ã¶ã¯ã·ã§ã³ãçæããskTC ã§çœ²åã㊠Relay ã«éä¿¡ããŸãã
ãªã¬ãŒéšåã«ã¯ãã¯ã©ã€ã¢ã³ã ã€ã³ã¿ãŒãã§ã€ã¹ãTCPããããã¯ãã§ãŒã³ ã€ã³ã¿ãŒãã§ã€ã¹ãå«ãŸããŸãã ã¯ã©ã€ã¢ã³ã ã€ã³ã¿ãŒãã§ã€ã¹ã¯ããšã³ã¯ã¬ãŒã ã³ãŒããæ€èšŒããã¯ã©ã€ã¢ã³ããšéä¿¡ããããã«å¿ èŠã§ãã ã¯ã©ã€ã¢ã³ãã¯ãecall ã䜿çšããŠæ§æ蚌æãªã¯ãšã¹ããéä¿¡ããatt (æ§æ蚌æ眲å) ãšãšãã« skTC ã«ãã£ãŠçœ²åãããã¿ã€ã ã¹ã¿ã³ããåä¿¡ããŸãã次ã«ãatt 㯠Intel Attestation Service (IAS) ã䜿çšããŠæ€èšŒãããã¿ã€ã ã¹ã¿ã³ãã¯ä¿¡é Œã§ããã¿ã€ã ãµãŒãã¹ã«ãã£ãŠæ€èšŒãããŸãã ãããã¯ãã§ãŒã³ ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãåä¿¡ãªã¯ãšã¹ããæ€èšŒãããã©ã³ã¶ã¯ã·ã§ã³ããããã¯ãã§ãŒã³äžã«é 眮ããŠããŒã¿ã°ã©ã ãé ä¿¡ããŸãã Geth ã¯å ¬åŒã® Ethereum ã¯ã©ã€ã¢ã³ãã§ãããRelay ã RPC åŒã³åºããä»ããŠãããã¯ãã§ãŒã³ãšå¯Ÿè©±ã§ããããã«ããŸãã
TEE ãšé£æºãããšãTC ã¯è€æ°ã®ãšã³ã¯ã¬ãŒãã䞊è¡ããŠå®è¡ã§ãããããæ å ±åŠçã®é床ã 3 ååäžããŸãã 15 ã€ã®åäœãšã³ã¯ã¬ãŒãã®é床ã 20 tx/ç§ã ã£ãå Žåã65 ã®äžŠåå®è¡ãšã³ã¯ã¬ãŒãã§ã¯é床㯠26 tx/ç§ã«å¢å ããŸããæ¯èŒã®ããã«ããããã³ã€ã³ ãããã¯ãã§ãŒã³ã®æ倧é床㯠XNUMX tx/ç§ã§ãã
DECO
DECO (Decentralized Oracles for TLS) 㯠CCS'20 ã§å°å
¥ãããTLS æ¥ç¶ããµããŒããããµã€ãã§åäœããŸãã ããŒã¿ã®æ©å¯æ§ãšå®å
šæ§ãä¿èšŒããŸãã
TLS ã䜿çšãã DECO ã¯å¯Ÿç§°æå·åã䜿çšãããããã¯ã©ã€ã¢ã³ããš Web ãµãŒããŒã¯æå·åããŒãæã¡ãã¯ã©ã€ã¢ã³ãã¯å¿
èŠã«å¿ã㊠TLS ã»ãã·ã§ã³ ããŒã¿ãåœè£
ã§ããŸãã ãã®åé¡ã解決ããããã«ãDECO ã¯èšŒæè
(ã¹ããŒã ã³ã³ãã©ã¯ã)ãæ€èšŒè
(ãªã©ã¯ã«)ãWeb ãµãŒã㌠(ããŒã¿ ãœãŒã¹) ã®é㧠XNUMX ãŠã§ã€ ãã³ãã·ã§ã€ã¯ ãããã³ã«ã䜿çšããŸãã
DECO ã®ä»çµã¿ã¯ã蚌æè ãããŒã¿ D ãåãåããD ã TLS ãµãŒã㌠S ããæ¥ããã®ã§ããããšãæ€èšŒè ã«ç¢ºèªãããšãããã®ã§ãããã XNUMX ã€ã®åé¡ã¯ãTLS ãããŒã¿ã«çœ²åããªããããTLS ã¯ã©ã€ã¢ã³ããããŒã¿ D ã蚌æããããšãé£ããããšã§ããããŒã¿ã¯ãã®ãµãŒããŒããåä¿¡ãããŸãã (æ¥æŽã®å°é£ã)ã
DECO ãããã³ã«ã¯ãKEnc ããã³ KMac æå·åããŒã䜿çšããŸãã ã¯ã©ã€ã¢ã³ã㯠Q ãªã¯ãšã¹ãã Web ãµãŒããŒã«éä¿¡ããR ãµãŒããŒããã®å¿çã¯æå·åãããŸãããã¯ã©ã€ã¢ã³ããšãµãŒããŒã¯åã KMac ãææããŠãããããã¯ã©ã€ã¢ã³ã㯠TLS ã¡ãã»ãŒãžãåœé ã§ããŸãã DECO ã®è§£æ±ºçã¯ãèŠæ±ã«å¿çãããŸã§ã¯ã©ã€ã¢ã³ã (蚌æè ) ãã KMac ããé ããããšã§ãã çŸåšãKMac ã¯èšŒæè ãšæ€èšŒè (KpMac ãš KvMac) ã«åãããŠããŸãã ãµãŒããŒã¯ KMac ãåä¿¡ããããŒã®äžéšã«å¯Ÿã㊠KpMac â KvMac = KMac æŒç®ã䜿çšããŠå¿çãæå·åããŸãã
XNUMX ãŠã§ã€ ãã³ãã·ã§ã€ã¯ãèšå®ããããšã«ãããã¯ã©ã€ã¢ã³ããšãµãŒããŒéã®ããŒã¿äº€æã¯ã»ãã¥ãªãã£ãä¿èšŒãããç¶æ
ã§å®è¡ãããŸãã
åæ£åãªã©ã¯ã« ã·ã¹ãã ãšèšãã°ãChainlink ã«ã€ããŠè§Šããã«ã¯ããããŸãããChainlink ã¯ãã¢ãžã¥ãŒã«æ§ã念é ã«çœ®ããã€ãŒãµãªã¢ã ããããã³ã€ã³ããã€ããŒã¬ãžã£ãŒãšäºææ§ã®ãããªã©ã¯ã« ããŒãã®åæ£åãããã¯ãŒã¯ãæ§ç¯ããããšãç®æããŠããŸããã·ã¹ãã ã®ãã¹ãŠã®éšåã¯ã¢ããã°ã¬ãŒãå¯èœã§ãã åæã«ãã»ãã¥ãªãã£ã確ä¿ããããã«ãChainlink ã¯ã¿ã¹ã¯ã«åå ããåãªã©ã¯ã«ã«ã㌠(å
¬éããŒãšç§å¯ããŒ) ã®çµã¿åãããçºè¡ããããææ¡ããŸãã ç§å¯ããŒã¯ãããŒã¿ãèŠæ±ãã決å®ãå«ãéšå眲åãçæããããã«äœ¿çšãããŸãã çããåŸãã«ã¯ããããã¯ãŒã¯ã®ãªã©ã¯ã«ã®éšå眲åããã¹ãŠçµã¿åãããå¿
èŠããããŸãã
Chainlink ã¯ãMixicles ã®ãããªåæ£åéèã¢ããªã±ãŒã·ã§ã³ã«çŠç¹ãåœãŠãæåã® PoC DECO ãèšç»ããŠããŸãã ãããæžããŠããæç¹ã§ãChainlink ãã³ãŒãã«å€§åŠãã DECO ãè²·åãããšãããã¥ãŒã¹ã Forbes ã«æ²èŒãããŠããŸããã
ãªã©ã¯ã«ãžã®æ»æ
æ å ±ã»ãã¥ãªãã£ã®èŠ³ç¹ãããTown Crier ã«å¯Ÿãã次ã®æ»æãæ€èšãããŠããŸãã
-
TEE ããŒãã§ã®äžæ£ãªã¹ããŒã ã³ã³ã¿ã¯ã ã³ãŒã ã€ã³ãžã§ã¯ã·ã§ã³ã
æ»æã®æ¬è³ªã¯ãæå³çã«ééã£ãŠããã¹ããŒã ã³ã³ãã©ã¯ã ã³ãŒãã TEE ã«éä¿¡ããããšã§ãããŒãã«ã¢ã¯ã»ã¹ããæ»æè ã埩å·åãããããŒã¿ã«å¯ŸããŠç¬èªã® (äžæ£ãª) ã¹ããŒã ã³ã³ãã©ã¯ããå®è¡ã§ããããã«ããããšã§ãã ãã ããè¿ãããå€ã¯ç§å¯ããŒã§æå·åããããã®ãããªããŒã¿ã«ã¢ã¯ã»ã¹ããå¯äžã®æ¹æ³ã¯ãæ»ã/åºåæã«æå·æãæŒæŽ©ããããšã§ãã
ãã®æ»æã«å¯Ÿããä¿è·ã¯ããšã³ã¯ã¬ãŒãã«ããçŸåšã®ã¢ãã¬ã¹ã«ããã³ãŒãã®æ£ç¢ºæ§ã®ãã§ãã¯ã§æ§æãããŸãã ããã¯ãã³ã³ãã©ã¯ã ã³ãŒããããã·ã¥ããããšã«ãã£ãŠã³ã³ãã©ã¯ãã®ã¢ãã¬ã¹ã決å®ãããã¢ãã¬ã¹æå®ã¹ããŒã ã䜿çšããŠå®çŸã§ããŸãã -
å¥çŽç¶æ ã®æå·æã®å€æŽãæŒæŽ©ããŸãã
æ»æã®æ¬è³ª: ã¹ããŒã ã³ã³ãã©ã¯ããå®è¡ãããããŒãã®ææè ã¯ããšã³ã¯ã¬ãŒãå€ã§æå·åããã圢åŒã§ã³ã³ãã©ã¯ãç¶æ ã«ã¢ã¯ã»ã¹ã§ããŸãã ããŒãã®å¶åŸ¡ãç²åŸããæ»æè ã¯ãã¹ããŒã ã³ã³ãã©ã¯ã ã³ãŒãèªäœãšãã®æè¡ä»æ§ãå ¬éãããŠããããããã©ã³ã¶ã¯ã·ã§ã³ã®ååŸã§ã³ã³ã¿ã¯ãã®ç¶æ ãæ¯èŒããã©ã®åŒæ°ãå ¥åãããã©ã®ã¹ããŒã ã³ã³ãã©ã¯ã ã¡ãœããã䜿çšãããããå€æã§ããŸãã
ããŒãèªäœã®ä¿¡é Œæ§ã確ä¿ããããã®ä¿è·ã -
ãµã€ããã£ãã«æ»æã
ããŸããŸãªã·ããªãªã§ãšã³ã¯ã¬ãŒã ã¡ã¢ãªãšãã£ãã·ã¥ ã¢ã¯ã»ã¹ã®ç£èŠã䜿çšããç¹å¥ãªã¿ã€ãã®æ»æã ãã®ãããªæ»æã®äŸãšããŠã¯ãPrime ããã³ Probe ããããŸãã
æ»æé åº:- t0: æ»æè ã¯è¢«å®³è ã®ããã»ã¹ã®ããŒã¿ ãã£ãã·ã¥å šäœãåããŸãã
- t1: 被害è ã¯ã被害è ã®æ©å¯ããŒã¿ (æå·åããŒ) ã«äŸåããã¡ã¢ãª ã¢ã¯ã»ã¹ã§ã³ãŒããå®è¡ããŸãã ãã£ãã·ã¥ã©ã€ã³ã¯ããŒãããå€ã«ãã£ãŠéžæãããŸãã å³ã®äŸã§ã¯ãkeybit = 0 ã§ããã£ãã·ã¥ ã©ã€ã³ 2 ã®ã¢ãã¬ã¹ X ãèªã¿åããŸããX ã«æ ŒçŽãããŠããããŒã¿ããã£ãã·ã¥ã«ããŒãããã以åã«ååšããŠããããŒã¿ã眮ãæããããŸãã
- t2: æ»æè ã¯ãèªåã®ãã£ãã·ã¥ ã©ã€ã³ã®ãã¡ã被害è ã䜿çšãããã£ãã·ã¥ ã©ã€ã³ãåé€ãããããšã確èªããŸãã ããã¯ãã¢ã¯ã»ã¹æéã枬å®ããããšã«ãã£ãŠè¡ãããŸãã ãã®æäœãããŒãããããšã«ç¹°ãè¿ãããšã§ãæ»æè ã¯ããŒå šäœãååŸããŸãã
æ»æä¿è·: Intel SGX ã«ã¯ããã£ãã·ã¥é¢é£ã€ãã³ãã®ç£èŠãç¡å¹ã«ãããµã€ããã£ãã«æ»æã«å¯Ÿããä¿è·æ©èœããããŸãããæ»æè
ã¯èªåã®ããã»ã¹ã®ãã£ãã·ã¥ ã€ãã³ããç£èŠãã被害è
ãšãã£ãã·ã¥ãå
±æããããããã©ã€ã ã¢ã³ã ãããŒãæ»æã¯äŸç¶ãšããŠééããŸãã
ãããã£ãŠãçŸæç¹ã§ã¯ããã®æ»æã«å¯Ÿããä¿¡é Œã§ããä¿è·ã¯ãããŸããã
Prime ããã³ Probe ã«äŒŒã Spectre and Foreshadow (L1TF) æ»æãç¥ãããŠããŸãã ããã«ããããµãŒãããŒãã£ã®ãã£ãã«ãéããŠãã£ãã·ã¥ããããŒã¿ãèªã¿åãããšãã§ããŸãã Spectre-v2 è匱æ§ã«å¯Ÿããä¿è·ãæäŸãããŠãããããã XNUMX ã€ã®æ»æã«å¯ŸããŠæ©èœããŸãã
DECO ã«é¢é£ããŠãXNUMX ãŠã§ã€ ãã³ãã·ã§ã€ã¯ã«ããã»ãã¥ãªãã£ãä¿èšŒãããŸãã
- 蚌æè ã®æŽåæ§: 䟵害ããã蚌æè ã¯ããµãŒããŒã®çºä¿¡å æ å ±ãåœé ã§ããããµãŒããŒãç¡å¹ãªãªã¯ãšã¹ããåãå ¥ããããæå¹ãªãªã¯ãšã¹ãã«èª€ã£ãŠå¿çãããããããšã¯ã§ããŸããã ããã¯ããµãŒããŒãšèšŒæè éã®ãªã¯ãšã¹ã ãã¿ãŒã³ãéããŠè¡ãããŸãã
- æ€èšŒè ã®å®å šæ§: ãããã³ã°ãããæ€èšŒè ã蚌æè ã«ééã£ãçããäžããããšã¯ã§ããŸããã
- ãã©ã€ãã·ãŒ: ãããã³ã°ãããæ€èšŒããŒã«ã¯ãå ¬éãããŠããæ å ± (ãªã¯ãšã¹ãããµãŒããŒå) ã®ã¿ãæ€æ»ããŸãã
DECO ã§ã¯ããã©ãã£ã㯠ã€ã³ãžã§ã¯ã·ã§ã³ã®è匱æ§ã®ã¿ãçºçããå¯èœæ§ããããŸãã ãŸããXNUMX ãŠã§ã€ ãã³ãã·ã§ã€ã¯ã«ãããæ€èšŒè ã¯æ°ãã nonce ã䜿çšããŠãµãŒããŒã® ID ã確ç«ã§ããŸãã ãã ãããã³ãã·ã§ã€ã¯ã®åŸãæ€èšŒè ã¯ãããã¯ãŒã¯å±€ã€ã³ãžã±ãŒã¿ãŒ (IP ã¢ãã¬ã¹) ã«äŸåããå¿ èŠããããŸãã ãããã£ãŠãæ€èšŒè ãšãµãŒããŒéã®éä¿¡ã¯ãã©ãã£ã㯠ã€ã³ãžã§ã¯ã·ã§ã³ããä¿è·ããå¿ èŠããããŸãã ããã¯ãããã·ã䜿çšããããšã§å®çŸãããŸãã
ãªã©ã¯ã«ã®æ¯èŒ
Town Crier ã¯ããã¯ãšã³ãã§ã®ãšã³ã¯ã¬ãŒãã®æäœã«åºã¥ããŠããŸãããDECO ã§ã¯ XNUMX ãŠã§ã€ ãã³ãã·ã§ã€ã¯ã䜿çšããŠããŒã¿ã®çºä¿¡å ãèªèšŒããæå·ããŒã䜿çšããŠããŒã¿ãæå·åã§ããŸãã ãããã®ãªã©ã¯ã«ã®æ¯èŒã¯ãé床ãã»ãã¥ãªãã£ãã³ã¹ããå®çšæ§ã®åºæºã«åŸã£ãŠå®è¡ãããŸããã
ã¿ãŠã³ã¯ã©ã€ã€ãŒ
DECO
ããã©ãŒãã³ã¹
é«éå (çµäºãŸã§ 0.6 ç§)
é
ã (ãããã³ã«ãå®äºãããŸã§ã« 10.50 ç§)
ã»ãã¥ãªãã£
å®å
šæ§ãäœã
ããå®å
šãª
ã³ã¹ã
ãã£ãšé«ã
å®ã
å®çšæ§
ç¹å¥ãªããŒããŠã§ã¢ãå¿
èŠ
TLSããµããŒããããããããµãŒããŒã§åäœããŸã
ã¹ããŒãããã©ãŒãã³ã¹A: DECO 㯠0.37 ãŠã§ã€ ãã³ãã·ã§ã€ã¯ã®ã»ããã¢ãããå¿ èŠã§ãLAN çµç±ã§ã»ããã¢ããããå Žå㯠2 ç§ããããŸããæ¥ç¶ç¢ºç«åŸã®éä¿¡ã«ã¯ 0,13PC-HMAC (æžã蟌ã¿ããã 3 ç§) ãæå¹ã§ãã DECO ã®ããã©ãŒãã³ã¹ã¯ãå©çšå¯èœãª TLS æå·ã¹ã€ãŒãããã©ã€ããŒã ããŒã¿ã®ãµã€ãºãããã³ç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ã®èšŒæã®è€éãã«äŸåããŸãã IC10,50 ã®ãã€ããªãŒ ãªãã·ã§ã³ ã¢ããªã±ãŒã·ã§ã³ãäŸãšããŠäœ¿çšãããšãLAN çµç±ã§ãããã³ã«ãå®äºãããŸã§ã«çŽ 0,6 ç§ããããŸãã æ¯èŒãããšãTown Crier ã¯åæ§ã®ã¢ããªã±ãŒã·ã§ã³ãå®äºããã®ã«çŽ 20 ç§ããããDECO ãããçŽ XNUMX åé«éã§ãã åçã®æ¡ä»¶äžã§ã¯ãTC ã®æ¹ãéããªããŸãã
ã»ãã¥ãªãã£: Intel SGX ãšã³ã¯ã¬ãŒãã«å¯Ÿããæ»æ (ãµã€ããã£ãã«æ»æ) ã¯æ©èœããã¹ããŒã ã³ã³ãã©ã¯ãã®åå è ã«å®éã®æ害ãäžããå¯èœæ§ããããŸãã DECO ã«é¢ããŠã¯ãã©ãã£ãã¯ã€ã³ãžã§ã¯ã·ã§ã³æ»æãå¯èœã§ããããããã·ã䜿çšããããšã§ãã®ãããªæ»æã¯ç¡å¹åãããŸãã ãããã£ãŠãDECO ã¯ããå®å šã§ãã
ã®ã³ã¹ã: Intel SGX ã§ã®åäœããµããŒãããããŒããŠã§ã¢ã®ã³ã¹ãã¯ãDECO ã§ãããã³ã«ãæ§æããã³ã¹ããããé«ããªããŸãã ãããã£ãŠãTCã¯ããé«äŸ¡ã«ãªããŸãã
å®çšæ§ïŒã¿ãŠã³ã¯ã©ã€ã¢ãšé£æºããã«ã¯ãTEEã«å¯Ÿå¿ããå°çšæ©åšãå¿ èŠã§ãã ããšãã°ãIntel SGX ã¯ã第 6 äžä»£ Intel Core ããã»ããµ ãã¡ããªä»¥éã§ãµããŒããããŠããŸãã DECO ã§ã¯ããããæ©åšã䜿çšã§ããŸãããTEE ã䜿çšãã DECO èšå®ããããŸãã ã»ããã¢ããããã»ã¹ã«ãããšãDECO ã® XNUMX ãŠã§ã€ ãã³ãã·ã§ã€ã¯ã«ã¯æéããããå ŽåããããŸãããTC ã®ããŒããŠã§ã¢å¶éã«æ¯ã¹ãã°å€§ããããšã§ã¯ãªããããDECO ã®æ¹ãå®çšçã§ãã
ãŸãšã
2020 ã€ã®ãªã©ã¯ã«ãåå¥ã«èŠãŠã4 ã€ã®åºæºã§æ¯èŒãããšãTown Crier ã XNUMX ç¹äž XNUMX ç¹ã§ DECO ããå£ã£ãŠããããšã¯æããã§ãã DECO ã¯ãæ å ±ã»ãã¥ãªãã£ã®ç¹ã§ä¿¡é Œæ§ãé«ããå®äŸ¡ã§å®çšçã§ãããXNUMX æ¹åãããã³ã«ã®èšå®ã«ã¯æéããããå Žåããããæå·åããŒã䜿çšããè¿œå æäœãªã©ã®æ¬ ç¹ããããŸãã TC 㯠DECO ãããé«éã§ããããµã€ããã£ãã«æ»æã®è匱æ§ã«ãããã©ã€ãã·ãŒã倱ãããå±éºããããŸãã DECO 㯠XNUMX 幎 XNUMX æã«å°å ¥ãããŸãããããŸã å®å šã§ãããšèããã«ã¯ååãªæéãçµéããŠããªãããšã«æ³šæããŠãã ããã Town Crier 㯠XNUMX 幎éã«ããã£ãŠæ»æãåããŠãããå€ãã®ãã¹ããçµãŠãããããå€ãã®ãããžã§ã¯ãã§ã®äœ¿çšã¯æ£åœåãããŠããŸãã
åºæïŒ habr.com