Kaigi on Rails 2024 ã§ã®çºè¡¨è³æã§ã #kaigionrails https://kaigionrails.org/2024/talks/moro/
ã¦ã¼ã¶ã¼èªè¨¼ã管çãè¡ãã¢ããªã±ã¼ã·ã§ã³ãæ¢ãã¦ããã¨ãã Authelia ã¨ããè¯ããã㪠OSS ãè¦ã¤ãã¾ããããã ç¾æç¹ã§ã¯æ¥æ¬èªã®æ å ±ãæ®ã©ãªãã£ãã®ã§ãå®éã«ç°å¢ãæ§ç¯ãã¦æ©è½ããããã試ãã¦ã¿ã¾ãã Authelia ã«ã¤ã㦠ããã¥ã¡ã³ã Github ããã¥ã¡ã³ãããå¼ç¨ Authelia is an open-source authentication and authorization server and portal fulfilling the identity and access management (IAM) role of information security in providing multi-factor authentication and single sign-on (SSO) for your applications via a
æ¬è¨äºã¯ Digital Identityæè¡åå¼·ä¼ #iddance Advent Calendar 2023 ã®11æ¥ç®ã®è¨äºã§ãã æè¿ããã¹ãã¼ã®ãã¨ã°ããèãã¦ãã¾ãããããã®ä¸ã ã£ãããå¥ã®æèã ã£ããã§ããèªè¨¼ã®å¼·åº¦ã身å 確èªã¬ãã«ã¨å©ç¨å¯è½ãªæ©è½ã®é¢ä¿ããèããæ©ä¼ããã¡ããã¡ããããã¾ããã ä¾ãã°ããã¹ãã¼ã§ã¢ã«ã¦ã³ãç»é²ãããå®æ½ããã®ãçæ³çã ãããã¨ããæè¦ãèãã¾ãããã®ä¸æ¹ã§ãããã¹ãã¼ã§phishingã®å¯¾çã¯ã§ãããããããªããã©ã誰ã§ãç°¡åã«ã¢ã«ã¦ã³ãä½ãããã ãã ãããé»è©±çªå·ã®ç»é²ã¯ã©ã®ã¿ã¡å¿ è¦ãiCloud keychain/ç»é¢ããã¯æå¹ã«ãã¦ãªã人ãããããããã¾ã§ãã¹ãã¼ãå ¨é¢ã«ã ãã®ã¯å¾®å¦ãããªãï¼ãã¨ããæè¦ãèãã¾ãã ãããªè©±ãèãã¦ããããã¢ã«ã¦ã³ããèªè¨¼å¼·åº¦ã身å 確èªå¼·åº¦ã®è¦³ç¹ãããã©ãããç¶æ ããã£ã¦ãåç¶æ ã«ã©ããããªã¹ã¯ãã
æè¿ ID çéã§è©±é¡ã«ãªã£ã¦ãããããã¯ã¨ãã¦ããã¸ã¿ã«IDã¦ã©ã¬ãã(DIW) ã¨ããã³ã³ã»ãããããã¾ããããã¯ã身å証ãé転å 許証ããéè¡ã®ãã£ãã·ã¥ã«ã¼ããããã«ã¯ãåºã®ãã¤ã³ãã«ã¼ãã¾ã§ãããããæ¬äººã®ã¢ã¤ãã³ãã£ãã£ã«é¢ãããã¼ã¿ããã¹ããã¢ããªã«ä¿åããå¿ è¦ã«å¿ãã¦ãå¿ è¦ãªæ å ±ã ããå¿ è¦ããã°è¤æ°ãã¾ã¨ãã¦ä¸åº¦ã«ãæ示ã§ããã¨ããã³ã³ã»ããã§ãã 話é¡ã«ãªã£ã¦ããèæ¯ãå¿ è¦ã¨ãªãæè¡ã欧米ã®åããªã©ãï¼ï¼ï¼ï¼å¹´ï¼ï¼ææç¹ã§ã®ç§ã®ç解ãã¾ã¨ãã¾ããã æ確ãªã½ã¼ã¹ãããæ å ±ã¯ã極åã½ã¼ã¹ã¨ãªãURLãæ·»ä»ãã¦ãã¾ãã ã¾ããä¸è¬è«ã¨ãã¦ããã«è¨è¼ããæ å ±ã«ã¤ãã¦ã¯ãå½å å¤ã®å¤ãã®èè ã®æ¹ã®ã話ããç´æ¥çãéæ¥çã«ä¼ºãä¸ã§ãç§ã®ä¸ã§åå¼ãæ¶åããå 容ã¨ãªã£ã¦ããã¾ããããã®çæ§ã®ãååã¯ç¥ããã¦é ãã¾ããã御礼ç³ãä¸ãã¾ããããã§ããæ¬ããã°ã®å 容ã«èª¤ããããã°ããã¹ã¦ç§ã®è²¬ä»»
çç¶æ¤ç´¢ã¨ã³ã¸ã³ãã¦ãã¼ã ã§ã¯ããã¼ã³ãå½åãã Firebase Auth (GCP Identity Platform) ã使ã£ã¦ãã¾ããããOIDCã«æºæ ããå 製ã®èªè¨¼èªå¯åºç¤ã«ç§»è¡ãã¾ããã èªè¨¼èªå¯åºç¤ãã®ãã®ã¯ m_mizutani 㨠nerocrux 㨠toshi0607(éè·æ¸) ãä½ã£ã¦ããããããåã¯ç§»è¡ã®ã¿ãæ å½ãã¾ããã çµæã¨ãã¦ãå¼·å¶ãã°ã¢ã¦ããªãã»ç¡åæ¢ã§ãã¸ãã¹å½±é¿ãåºããã«ãå¹´é1000ä¸å以ä¸ã®ã³ã¹ãåæ¸ã«æåãã¾ãã[1]ããã®ç§»è¡ããã»ã¹ã«ã¤ãã¦ç´¹ä»ãã¾ããèªè¨¼èªå¯åºç¤ãã®ãã®ã®ç´¹ä»ã¯ãã¾ããã¾ããã 移è¡ããçç± å¤§éã®å¿åã¢ã«ã¦ã³ã ã¦ãã¼ã§ã¯ãã¢ã¯ã»ã¹ããå ¨ã¦ã¼ã¶ã¼ã«å¯¾ãã¦èªåçã«å¿åã¢ã«ã¦ã³ããçºè¡ãã¦ãã¾ããããã«ãããã¦ã¼ã¶ã¼ãã¢ã«ã¦ã³ãç»é²ãã¦ãããã©ããã«é¢ããããåãIDä½ç³»ã§ééçã«å±¥æ´æ å ±çãæ±ããã¨ãã§ãã¾ããã¢ã«ã¦ã³ã
ãã¹ãã¼ã®ç»å ´ä»¥æ¥ãIDé£æºãç¹ã«ã½ã¼ã·ã£ã«ãã°ã¤ã³ã¯èªè¨¼æ¹æ³ã¨ãã¦æ¯ã¹ããããã¨ãå¤ããªãã¾ããããã®è¨äºã§ã¯ããã®2ã¤ãæ¯è¼ããããã®é¢ä¿ãèå¯ããéã«æèãã¦ããã¹ã観ç¹ãæ´çãã¦ããã¾ãã ããããã®ç¹å¾´ä¸¡è ã¯ç°ãªãç¹å¾´ãæã£ã¦ãã¾ãã ãã¹ãã¼ ç¨é: èªè¨¼ ãã¹ãã¼ã®ç®¡ç: ãã©ãããã©ã¼ã ãæä¾ãããã¹ã¯ã¼ãããã¼ã¸ã£ã¼ããµã¼ããã¼ãã£ã¼ã®ãã¹ã¯ã¼ãããã¼ã¸ã£ã¼ãã»ãã¥ãªãã£ãã¼ããã©ã¦ã¶ å±æ§æ å ±: ä¸ç·ã«ä¿æã§ãã¦å¼ãåãããã¼ã¿ã¯ User Handle ããã IDé£æº ç¨é: æ°è¦ç»é²ãèªè¨¼ãå±æ§æ å ±ã®åå¾/åæ ã¢ã«ã¦ã³ãæ å ±ã®ç®¡ç: Identity Provider å±æ§æ å ±: ãããã£ã¼ã«æ å ±ã確èªæ¸ã¿ã¡ã¼ã«ã¢ãã¬ã¹ãªã©ãåå¾å¯è½ãªã®ãä¸è¬ç ç¹å¾´ãç°ãªãããã«ãå°å ¥ç®æãæå³åããç°ãªãã¾ãã ãã£ã¨æãã¤ãã®ã æ°è¦ç»é² ãã°ã¤ã³ åèªè¨¼ ãããã§ããã
Azure AD B2C ã®è¡æ¹ã¨æ°ãã«ç»å ´ãã Microsoft Entra ID for customers ã®ã©ã£ã¡ãããã®ï¼MicrosoftSecurityAzureADidentityEntra ããã«ã¡ã¯ã@daimat ã¨ç³ãã¾ãã Microsoft Security Advent Calendar 2023 1 æ¥ç®ãæ å½ããã¦ããã ãã¾ãããããããé¡ããããã¾ãã Microsoft ã® CIAM ã½ãªã¥ã¼ã·ã§ã³ã¯ 2 ã¤åå¨ CIAM ã¨ã¯ Customer Identity and Access Management ã®é æåããæãç«ã¡ãèªãã§ãã ãã£ã¦ããçããããè¦ãã客æ§ã® ID ã管çãããã¨ãæãã¦ãã¾ããã¡ãªã¿ã«ãµã¤ã¢ã ã¨èªãããã§ãã ãã® CIAM ã½ãªã¥ã¼ã·ã§ã³ã¯ã以åãããã Azure AD B2C ã«å ãã¦ç¾å¨ãããªãã¯ãã¬ãã¥ã¼ã¨ã
ã¿ãªãã¾ãèªå¯ã®è¨è¨ã«è¦ããã§ããã§ããããï¼ç§ã¯è¦ããã§ãã¾ããè¦ãã¾ãªãã£ãç¬éãªã©ããã¾ãããæãã¢ããªã±ã¼ã·ã§ã³ã«ããã権éè¨è¨ã®èª²é¡ããå·çãã¾ãããããããã3年以ä¸ãçµã¡ã¾ãã å½æã¯èªå¯ã®è¨è¨ã«é¢ããæ å ±ããã¾ãã¾ã¨ã¾ã£ã¦ããè¨äºãªã©ã»ã¨ãã©ç¡ãã調ã¹ã«èª¿ã¹ã¦å¾ããã¬ãã¸ãæ¸ãè¨ããã®ãä¸è¨ã®è¨äºã§ãã3年以ä¸çµã¡ã¾ãããè¦æ©ãä»ãç¹ã«å¤ãã£ã¦ããªããã¨ãé©ãã§ãã ãã ããä¸ã®ä¸çã«ã¯èªå¯ã®ã©ã¤ãã©ãªã§ãã£ãããµã¼ãã¹ã¨ããã®ã¯å°ããã¤å¢ãã¦ãã¦ããå°è±¡ãããã¾ã(Auth0ã® OpenFGA ã§ãã£ããOsoã® Oso Cloud ãAsertoã® Topaz )ã èªå¯ã®è¨è¨ã«é¢ããè¨äºãå°ããã¤å¢ãã¦ããå°è±¡ãããããã®ä¸ã§ãæ¬è¨äºã§ç´¹ä»ãããã®ãAuthorization Academyã§ãã ããã¯èªå¯ãµã¼ãã¹ã§ãã Oso Cloud ãOSSã®ã©ã¤ãã©ãª o
ããããªã¢ã¤ãã³ãã£ãã£ç®¡ç系製åããµã¼ãã¹ã®å®é¨ã®è¨é²ããã¦ããã¾ãã å¾ã¯ãé¢é£ãããã¥ã¼ã¹ãªã©ãå¾ç¶ã¨ã ããã«ã¡ã¯ãå¯å£«æ¦®ã§ãã ãªãã ããã ã§uPortã触ã£ããç¾Azure Active Directory Verifiable Credentialsã®å身ã触ã£ãããæè¿ã ã¨æ°ã«æã§å®è¨¼å®é¨ããã¸ã§ã¯ããç«ã¡ä¸ããããMS主å¬ã®Decentralized Identity Hackathonã§å ¥è³ãã¦ã¿ãããã¨åæ£åIDã«é¢ããå§ãã¦5å¹´ãããçµã£ã¦ããããã¾ãã®ã§ãç¾æç¹ã§åãã£ããã¨ãã¡ã¢ãã¦ããããã¨æãã¾ããï¼å¾ã ã«ãã¦æ°å¹´å¾ã«è¦è¿ãã¨ããããã¨ãªããã¤ã ãã©æ°ã«ããªããã¨ã«ããï¼ â»ããããæå³ã§ã¯2019å¹´ã®#didconã§ãã®æç¹ã§ããã£ã¦ãããã¨ãããç¨åº¦ã¾ã¨ãã¦çºè¡¨ãã¦ããããã3å¹´ãçµã¤ãã§ããã»ã»ã» ã¾ãæ©ä¼ãããã°didconã§ãéå¬ãã¦ãã£ããã話ã
ããã«ã¡ã¯ãå¯å£«æ¦®ã§ãã 20æ¥ã«ãã¸ã¿ã«åºããªãªã¼ã¹ããã¯ã¯ãã³æ¥ç¨®è¨¼æã¢ããªã話é¡ã§ãããå 容çã«ã¯SMART Health Cardã®ä»æ§ã«æ²¿ã£ã証æãã¼ã¿ãåºã¦ãã¦ããã¨ãã話ã ã£ãã®ã§ä¸èº«ãç´è§£ãã¦ã¿ãããã¨æãã¾ããä½ããSMART Health Cardã®ä¸èº«ã¯W3Cã®Verifiable Credentialsï¼VCï¼ãªã®ã§ã åèï¼ï¼ https://www.digital.go.jp/policies/vaccinecert/faq_06 ãã åèï¼ï¼ This document describes how clinical information, modeled in FHIR, can be presented in a form based on W3C Verifiable Credentials (VC). https://spec.smarthealth
æ¬è¨äºã¯ Digital Identityæè¡åå¼·ä¼ #iddance Advent Calendar 2020 ã®11æ¥ç®ã®è¨äºã§ãã èªåãã¡ã§ç®¡çãã¦ãããµã¼ãã¹(以ä¸ã1st party client)åã³ãã®ã¢ã«ã¦ã³ãã«å¯¾ãã¦ãOAuthåã³OpenID Connectã®ããã»ã¹ãå°å ¥ãããã¨ã«ã¤ãã¦è©±ãã¾ãã æ£ç´ãèªåã®ä¸ã§å®å ¨ã«çããã¾ã¨ã¾ã£ã¦ããç¶æ ã§ã¯ããã¾ããããã¤ãã¤ãIDå¨ã®çæ§æ¹ã®æè¦ãèãããã®ã§ãç¾ç¶ã®èããã¾ã¨ãã¦ããããã¨æãã¾ãï¼ èæ¯ â» ãã®èæ¯ã¯ãã£ã¯ã·ã§ã³ã§ããå®å¨ã®äººç©ãå£ä½ãªã©ã¨ã¯ä¸åé¢ä¿ããã¾ããã æã ãããã¨ããã«ãAã¨ãããµã¼ãã¹ãããã¾ããããã®ãµã¼ãã¹ã¯ãï¼ã¤ã®ããã¯ã¨ã³ãã¨ãiOS/Androidãªã©ã®è¤æ°ã®ããã³ãã¨ã³ãããæ§æããã¦ããã¾ãããã¢ã«ã¦ã³ãã®ç»é²ããã°ã¤ã³ããã°ã¢ã¦ããéä¼ããã¹ã¯ã¼ãå¤æ´çã®æ©è½ã¯ãã¹ã¦ãä»
ãã®è¨äºã¯Digital Identityæè¡åå¼·ä¼ #iddance Advent Calendar 2020 20æ¥ç®ã®è¨äºã§ãã ãã®è¨äºã®ç®ç ã¯ããã¾ãã¦ãæè¿ä¸èº«ä¸ã®é½åã«ããDIDã«å ¥éããkazuhideYSã§ããæ社ã§IDæè¡ããã£ã¦ã¾ãã ãã¦ãæè¿è©±é¡ã®DIDã§ãããåå¼·ãã¦ãã¦æåã«èºããã®ã¯ã©ã®ä»æ§æ¸ããèªãã°ãããããããªãã¨ãããã¨ã§ããã DIDé¢é£ã®ä»æ§ãçå®ãã¦ããçµç¹ã¯ W3C DID Working Group Decentralized Identity Foundation (DIF) ã®2ã¤ãã¡ã¤ã³ã§ããããããã®ãµã¤ãã«ã¯ä»æ§æ¸(ã®Githubãªãã¸ããª)ã®ä¸è¦§ã¯ããã®ã§ããããã©ãããèªãã§ããã°ããã®ããã¨ããã¬ã¤ãã¯ããã¾ãããç§ã¯çµå±æå½ãã次第ã«èªãã§ããã¾ããããèªãã ãã¨ã§ããããããªã«éè¦ãããªããªâ¦â¦ãã¨æã£ãããããã£ã¡ã
製å 製åã°ã«ã¼ã Microsoft Defender Microsoft Entra Microsoft Intune Microsoft Priva Microsoft Purview Microsoft Sentinel ã»ãã¥ãªã㣠AI Microsoft Copilot for Security ID (ã¢ã¤ãã³ãã£ãã£) ã¨ã¢ã¯ã»ã¹ Microsoft Entra ID (Azure Active Directory) Microsoft Entra å¤é¨ ID Microsoft Entra ID ã¬ããã³ã¹ Microsoft Entra ID ä¿è· Microsoft Entra Internet Access Microsoft Entra Private Access Microsoft Entra Permissions Management Microsoft
ãã®è¨äºã®å 容 èªå·±ä¸»æ¨©åã¢ã¤ãã³ãã£ãã£ï¼Self-Sovereign Identityï¼ã«é¢ããååããã®å®è£ æè¡ã«ã¤ãã¦ãåå¼·ããå 容ãæ´çãã¦ããã¾ãã ç®æ¬¡ ã¯ããã« SSIã«ã¤ã㦠SSIã®ãã¼ãã¡ã¯ã¿ã¼ ã¾ã¨ã ã¯ããã« æè¿ãã¸ã¿ã«ã¢ã¤ãã³ãã£ãã£ã®ä¸çã§ãèªå·±ä¸»æ¨©åã¢ã¤ãã³ãã£ãã£ï¼Self-Sovereign Identityï¼ãã¨ããèãæ¹ã注ç®ããå§ãã¦ãã¾ããEUãåç±³ã§ã¯ä»¥åãããã®å®ç¨åã«åããåãçµã¿ãè°è«ãããã¦ãããå½å ã§ããããã¯ãã§ã¼ã³çéãä¸å¿ã«å¾ã ã«è©±é¡ã«ä¸ããããã«ãªã£ã¦ãã¦ãã¾ãããªããããã¯ãã§ã¼ã³çéãªã®ãã¨ããã¨ããããã¯ãã§ã¼ã³æè¡ã¨ç¸æ§ã®è¯ãã¦ã¼ã¹ã±ã¼ã¹ã ããã§ãããªãç¸æ§ãè¯ãã®ãã¨ãã話ã¯å¾è¿°ããã¨ãã¦ãä»åã¯Self-Sovereign Identityï¼é·ãã®ã§ä»¥å¾"SSI"ã«çç¥ï¼ã®æ¦è¦ã¨åºæ¬çãªã¢ã¼ããã¯ãã£ã«ã¤ãã¦å¦ã
ãã®è¨äºã¯Kyash Advent Calendar 2020ã®24æ¥ç®ã®è¨äºã§ãã ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾Kyashã®CTOã®æ¤éã¨ç³ãã¾ããä»å¹´ã¯ã³ããã¦ã£ã«ã¹ã®è延ããã£ããããã®ããæ±äº¬ãªãªã³ããã¯ã延æããããã¨ä½ãã¨å¤§å¤ãª1å¹´ã§ããããã®ãããªæä¸ããã£ã³ããã¯æ¥çããããããªåºæ¥äºãããã¾ãããå¤åºãè¦å¶ãããä¸ã§ãªã³ã©ã¤ã³æ±ºæ¸ã伸ã³ããã¨ã§ãã£ãã·ã¥ã¬ã¹æ±ºæ¸å¸å ´ãä¸ççã«ä¼¸é·ãã¾ãããããã®åé¢ä¸æ£ãå¢ããå¤ããã«éèæ¥çãæºãããéè¡-決æ¸äºæ¥è ã®é£æºé¨åãçã£ãä¸æ£å©ç¨ã¨ããäºè±¡ãçºçããããã¾ãããå©ä¾¿æ§ã¨å ç¢æ§ãå¦ä½ã«ä¸¡è¼ªã§é«ãã¦ããããã¯ITæ¥çå ¨ä½ã®ããã·ã§ã³ã§ãããã¾ããããéãæ±ãç§ãç¾å¨å±ãããã£ã³ããã¯æ¥çã«ã¨ã£ã¦é常ã«å¤§ããªé¢å¿äºã§ãããã¾ãã æ¹ãã¦æµ®ã彫ãã«ãªã£ãèª²é¡ ä»å¹´ã®å¤éãã«èµ·ãã£ãéè¡-決æ¸äºæ¥è éã®é£æºã«ãããä¸æ£ã®è©³ç´°ãå 容ã«é¢ãã¦ã¯ã
Merpay Advant Calendar 2020ã23æ¥ç®ã®è¨äºã¯ã趣å³ã§èªè¨¼èªå¯ããã£ã¦ãã @nerocrux ãéããããã¾ãã æè¿ GNAP ã¨ããèªå¯ãããã³ã«ã®ã¯ã¼ãã³ã°ã°ã«ã¼ããã©ãããåºã¦ãã¦é å¼µã£ã¦ç´°ããèªã¿ã¾ããã®ã§ãï¼æ¬¡åã¯ããå æ¸ã«ä»äºã§ãã£ã¦ããã¨ã«ã¤ãã¦ã話ãã¾ããï¼ä»åã¯ãã® GNAP ã«ã¤ãã¦ç´¹ä»ããã¦ãã ããã GNAP ã¨ã¯ãªã«ãï¼ GNAP 㯠Grant Negotiation and Authorization Protocol ã®ç¥ã§ãèªå¯ã®ãããã³ã«ã§ããJustin Richerããã¨ããæ¹ãä¸å¿ã«çå®ãã¦ãã¾ããä½è ã«ããã¨ãGNAP ã®çºé³ã¯ ããªã£ã· ã«ãªãã¾ãã èªå¯ï¼Authorizationï¼ãããã³ã«ã¨è¨ãã°ãOAuth 2.0 (RFC6749) ãåºãç¥ãããéç¨ããã¦ãã¾ããGNAP 㯠OAuth 2 ã®å¾ç¶ã¨ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}