PCI PIN Security æºæ ã·ã¹ãã ã§ã®ã¯ã©ã¦ãHSMãµã¼ãã¹å©ç¨ã«ã¤ã㦠â Part.1: FIPS140-2 ã¬ãã«3ã®HSM
ã¯ããã«
2020å¹´1æãPCI SSCã®PTS PIN Security Requirementsã®ãã¯ãã«ã«FAQã«ãã¯ã©ã¦ãä¸ã®HSMã«é¢ãã以ä¸ã®FAQ*1ã追å ããã¾ããããã®èæ¯ã«ã¯ãPCI PIN Security æºæ ã·ã¹ãã ã«ãããHSMã®ã¯ã©ã¦ãåã«é¢ããåãåãããå¢å ãã¦ããããã§ããã¨èãããã¾ãã
è±æï¼
Q 5 January 2020: Can an acquirer use third party hosted HSM services i.e. HSM in the cloud?
A Yes, however the acquirer is responsible for ensuring that all applicable requirements regarding the management of the HSMs are met by the HSM cloud Provider.
å訳ï¼
ã¢ã¯ã¯ã¤ã¢ã©ã¯ããµã¼ããã¼ãã£ããã¹ãããHSMãµã¼ãã¹(ä¾ï¼ã¯ã©ã¦ãä¸ã®HSM) ã使ç¨ã§ãã¾ããï¼
ã¯ãããã ããã¢ã¯ã¯ã¤ã¢ã©ã¯ãHSMã®ç®¡çã«é¢ããé©ç¨å¯è½ãªãã¹ã¦ã®è¦ä»¶ãHSMã¯ã©ã¦ããããã¤ãã¼ã«ãã£ã¦æºãããã¦ãããã¨ã確èªãã責任ãããã¾ãã
ã¯ã©ã¦ãä¸ã§æ±ºæ¸ã·ã¹ãã ãæ§ç¯ããããã¨ãå¢å ãã¦ãããã¯ã©ã¦ãä¸ã®HSMãµã¼ãã¹ã¯ä»å¾ã®å©ç¨æ¡å¤§ãæå¾ ããã¦ãã¾ããæ¬ç¨¿ã§ã¯ãã¯ã©ã¦ããµã¼ãã¹ã®HSMãå©ç¨ããPCI PIN Security æºæ ã·ã¹ãã ãã¯ã©ã¦ãä¸ã§å®ç¾ããããã«å¿ è¦ãªPIN Securityã®éè¦ãªæè¡çè¦ä»¶(ä¾ï¼FIPS140-2ãKey BlockãDual Controlãªã©)ã«ã¤ãã¦ãä½åãã«åãã¦è§£èª¬ãããã¨æãã¾ããã¾ããå®ç¾æ¹æ³ã«é¢ãã¦ã¯ãAWSããã³Azureãä¾ã¨ãã¦èª¬æãã¾ãã
1. FIPS140-2 ã¬ãã«3ã®HSM
ä»å確èªããPIN Security è¦ä»¶*2ã¯ä»¥ä¸ã®è¦ä»¶1-3ã§ãã
è±æï¼
1-3 All hardware security modules (HSMs) shall be either:
- FIPS140-2 Level 3 or higher certified, or
- PCI approved.
å訳ï¼
1-3 ãã¹ã¦ã®ãã¼ãã¦ã§ã¢ã»ãã¥ãªãã£ã¢ã¸ã¥ã¼ã«(HSM) ã次ã®ããããã§ãªãã¦ã¯ãªããªãï¼
- FIPS140-2 ã¬ãã« 3 以ä¸ã§ã®èªå®ãã¾ãã¯
- PCI èªå®
ã¯ã©ã¦ããµã¼ãã¹ä¸ã«æ§ç¯ãããPCI PIN Securityæºæ ã·ã¹ãã ã«ããã¦HSMãå©ç¨ããå ´åãã¯ã©ã¦ããµã¼ãã¹ãããã¤ãããä¸è¨ã®æ¡ä»¶ãæºããHSMãµã¼ãã¹ãæä¾ãã¦ãããã¨ã確èªããå¿ è¦ãããã¾ãã
ä¾ãã°ãAWSãæä¾ããAWS CloudHSMãAzureãæä¾ããAzure Dedicated HSMã¯ãæ¬ç¨¿å·çæç¹ï¼2020å¹´4æï¼æç¹ã§ã FIPS 140-2 ã¬ãã« 3ã«æºæ ãã¦ãã¾ãã
2. æä¾ããããµã¼ãã¹ã®FIPS 140-2ã¬ãã«ã®éãã«æ³¨æ
ã¯ã©ã¦ããµã¼ãã¹ã«ãã£ã¦ã¯ãè¤æ°ç¨®é¡ã®HSMãµã¼ãã¹ãæä¾ãã¦ããå ´åãããã¾ãããã®å ´åãæä¾ããããµã¼ãã¹ã®FIPS140-2ã®ã¬ãã«ã«éããããå ´åãããã¾ãã®ã§ãã¯ã©ã¦ãä¸ã«PCI PIN Securityæºæ ã®ç°å¢ãæ§ç¯ããæã¯ã FIPS140-2ã¬ãã«3ãæºãããµã¼ãã¹ã使ç¨ãã¦ãã ããã
ä¾ãã°ãAWSã§ã®ããä¸ã¤ã®HSMãµã¼ãã¹ã§ããAWS KMS(Key Management Service)ãAzureã§ã®ããä¸ã¤ã®HSMãµã¼ãã¹ã§ããAzure Key Vaultã¯ãæ¬ç¨¿å·çæç¹ï¼2020å¹´4æï¼æç¹ã§ã FIPS 140-2 ã¬ãã« 2ã«æºæ ãã¦ãã¾ãã
ãªããFIPS 140-2 ã¬ãã« 3ã¨ã¬ãã« 2ã®éãã«é¢ãã¦èå³ããæ¹ã¯ã以ä¸ã®ææ¸ã®P12辺ãã®ãTable 1 summarizes the security requirementsãããåç
§ãã ããã
https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf
ä»åã¯ã¯ã©ã¦ããµã¼ãã¹ã§æä¾ãããHSMã®FIPS140-2 ã¬ãã«3ã«é¢ãã¦èª¬æãã¾ããã
次åã¯æè¡çè¦ä»¶Key Blockã«é¢ãã¦ç¢ºèªãã¦ããã¾ãã
å¼ç¨å :
- â»1: PCI PTS PIN Security Requirements Technical FAQs for use with Version 3
https://www.pcisecuritystandards.org/documents/PTS_PIN_Technical_FAQs_v3_Feb%202020.pdf - â»2: PCI PIN Security Requirements and Testing Procedures Version 3.0
ãããããã¦ã³ãªã¹ããããV3.0-AUG2018ããé¸æãã¦ãã ããã
https://www.pcisecuritystandards.org/document_library?category=pci_pin&document=pcipinpin__sec_req_pdf
Writer Profile
ã»ãã¥ãªãã£äºæ¥æ¬é¨ ã»ãã¥ãªãã£ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨
ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹æ
å½ ãã¼ãã³ã³ãµã«ã¿ã³ã
å´ ç³å Cui Bingnan
ï¼CISSPãCISAãQSAãQSA (P2PE)ãQPAï¼
主ã«PCI DSSãP2PEãPIN Securityã®æºæ æ¯æ´ãªã©ã«å¾äºãæ¥ã»ä¸ã»éã»è± è¨èªã§ã³ãã¥ãã±ã¼ã·ã§ã³å¯è½ã
Tweet