æ¬æ€èšŒãããžã§ã¯ãïŒSorane: 空é³ïŒã¯ãé«ç²ŸåºŠãªã¿ã€ãã°ã©ãã£ãšãã¹ãéåæå·ïŒPQCïŒãçµã¿åãããããŒã¿åºç€ã«ã€ããŠãå®è£ ã¬ãã«ã®èª²é¡ãæŽçããããã®è©Šè¡çãªåãçµã¿ã§ãããæ¬çš¿ã¯ãå ¬çãªèšŒææžçãVCãšããŠçºè¡ããéã®å®åçãªè«ç¹ããå®éã®ã³ãŒãïŒæ¬PoCïŒãéããŠæŽãåºããã¡ã¢ã§ãããä»åŸã®å ·äœçãªã·ã¹ãã èŠä»¶ãæ€èšããäžã§ã®ãæè¡çãªå©ãå°ããšããŠäœæãããã®ã§ããã
ææ°ã®ã¹ããŒã¿ã¹ (2025-12-31): Red Team ã«ããã»ãã¥ãªãã£ã»ã¢ã»ã¹ã¡ã³ãïŒv1ïœv7ïŒãçµãŠããã€ãããéçšã«åããã¬ãŒãã¬ãŒã«ïŒv2.4.0ïŒã®å®è£ ãå®äºããã詳现㯠Web/A Security Audit Index ããã³ Red Team Evaluation v8 (PoC Approval) ãåç §ã®ããšã
Purpose and Scope of this PoC
æ¬ãããžã§ã¯ãã¯ãç¹å®ã®å®æããã補åãç®æããã®ã§ã¯ãªããããžã¿ã«èšŒææžã®å®è£ ã«ãããŠãã©ãã«æè¡çãªå£ããããããææ¡ããããã®ãå®è£ ã¬ãã«ã®ãµã³ãããã¯ã¹ïŒå®éšå ŽïŒã§ããã
- æ³å®ããæŽ»çšã·ãŒã³:
- å ¬éæ å ±ã®ãã¹ã: å ¬å ±æ©é¢ã®ãã¬ã¹ãªãªãŒã¹ããªãŒãã³ããŒã¿ãæ¹ç«äžå¯èœãªåœ¢ã§ãã¹ãããOSSãšããŠã®æå°æ§æã®è©Šè¡ã
- æ©åŸ®ãªèšŒææžã®æè¡æ€èš: äœæ°ç¥šã課çšèšŒææžãå°±æ¥èšŒææžãåŠç蚌ãªã©ã察人ïŒãã©ã€ãã·ãŒãå«ãïŒã®èšŒææžãããžã¿ã«åããéã®ãæè¡çãªReferenceïŒåç §ã³ãŒãïŒãšããŠã®æç€ºã
- æ¬ãããžã§ã¯ãã®ç«ã¡äœçœ®:
- çºè¡ã·ã¹ãã ãã®ãã®ãæ§ç¯ããã®ã§ã¯ãªããIVSç°äœåã®æ±ããPQC眲åãªã©ãå ±éçã«çŽé¢ãããå®è£ äžã®é£æããã©ãã¯ãªã¢ãããã«ã€ããŠã®ããããå°ãšãªãå®è£ äŸã®æç€ºã
- åçè ã«ããæªçšé²æ¢ããããžã¿ã«äžã§ã®æåã®çæ£æ§ãªã©ãå®åè ãæè¡çãªè°è«ãè¡ãããã®ããŒã¹ã©ã€ã³ãæäŸãããã®ã§ããã
Institutional Governance and Root of Trust
å ¬å ±æ©é¢ãçºè¡äœãšãªãå Žåããã®ã身å ããšãæš©éããããžã¿ã«äžã§ããã«èšŒæããç¶ç¶çã«ç®¡çããããæå€§ã®è«ç¹ãšãªãã
å ¬èªããã¥ã¡ã³ãã«ããã眲åã®å®çŸ©
- è«ç¹: å ¬èªããã¥ã¡ã³ãã«ä»äžãã眲åã¯ãæ¥æ¬ã®ãé»åçœ²åæ³ãã«ãããé»å眲åãšã©ãæŽçãã¹ããã
- æ¬PoCã®èŠç¹: æ¬ãããžã§ã¯ãã«ãããVCã®çœ²åã¯ãèªç¶äººã®ãææè¡šç€ºããæ ä¿ããåŸæ¥åã®é»å眲åãšã¯æ§è³ªãç°ãªããããããçµç¹ã®çæ£æ§ã蚌æãã e-Seals (EU) ããWebãµã€ãã®ä¿¡é Œæ§ã確ä¿ãã SSL/TLSèšŒææžããœãããŠã§ã¢ã®åºæãä¿èšŒãã ã³ãŒã眲åèšŒææž ã«è¿ããã·ã¹ãã ã®èªååŠçã«ãã ãçµç¹ã®èšŒè·¡ïŒæ©é¢æ€èšŒïŒã ãšæããã¹ãã§ã¯ãªããã
- ãã©ã¹ãåºç€ã®èŠªåæ§:
did:webçãéããŠãæ¢åã®Webãã©ã¹ããã§ãŒã³ïŒWebTrustçïŒãšèŠªåæ§ã®é«ãæè¡ã¹ã¿ãã¯ãæ¡çšããããšã§ãæ±çšçãªãã©ãŠã¶ãããŒã«ã§ã®æ€èšŒå¯èœæ§ãå€å±€çã«æ ä¿ããã
ä¿¡é Œã®åºç¹ (did:web)
- è«ç¹: çºè¡äœã®èå¥åïŒIDïŒãã©ãã«çœ®ããã
- æ¬PoCã§ã®ã¢ãããŒã: æ¢åã®ã€ã³ã¿ãŒãããåºç€ïŒDNS/TLSïŒãšé£åãã
did:webãæ¡çšãããçºè¡äœã®å ¬åŒãã¡ã€ã³çŽäžïŒ/.well-known/did.jsonïŒã«å ¬é鵿 å ±ãé åããããšã§ãWebPKIã®ä¿¡é Œæ§ãVCã®ä¿¡é Œæ§ã«çŽçµãããææ³ãæ€èšŒããã - å ¬å ±æ©é¢åŽã®æ€èšäºé : ãã¡ã€ã³ç®¡çéšéãšæ å ±ã·ã¹ãã éšéã®é£æºãããã³éµã®ã©ã€ããµã€ã¯ã«ç®¡çã«ãŒã«ã®çå®ãå¿ èŠã§ããã
眲åäž»äœã®éå±€æ§é
- è«ç¹: åçºè¡äœãåå¥ã«éµãéçšããããäžå€®æ©é¢ã眲åã代è¡ãããã
- æ¬PoCã§ã®æ§æ: æè¡çã«ã¯ã©ã¡ãã察å¿å¯èœã§ãããçŸå®çã«ã¯ãäºååž°å±ã¯åå¥ã®æ©é¢ãšãã€ã€ã眲ååºç€ã¯ã¯ã©ãŠãçã®æ€èšŒæžã¿ç°å¢ã«éçŽããçºè¡äœã¯ã眲åæç€ºãã®ã¿ãè¡ã ãå§èšçœ²åã¢ãã«ã ããéçšã³ã¹ãã»ã»ãã¥ãªãã£ã®èгç¹ããäžã€ã®æåãªéžæè¢ãšãªãã
- å ¬å ±æ©é¢åŽã®æ€èšäºé : åäž»äœã®æš©éæ ä¿ïŒçœ²åæç€ºã®çæ£æ§ïŒãšãå ±åéçšã«ããã³ã¹ãåæžã®ãã©ã³ã¹ãéèŠãšãªãã
èšŒææžãšçœ²åã®æå¹æéã»é·ææ€èšŒ
- è«ç¹: VCãã®ãã®ã®æå¹æéãšããããä¿èšŒããããã®ããžã¿ã«çœ²åã®æå¹æéïŒããã³ã¢ã«ãŽãªãºã ã®å±æ®åïŒãããã«åãåãããã
- å
¬ç€ºææžãžã®é·æçœ²åïŒLTVïŒã®é©çšå¯èœæ§:
- èªæ²»äœã®å瀺ããã¬ã¹ãªãªãŒã¹çãæ°å幎åäœã§ã®çæ£æ§æ ä¿ãå¿ èŠãªãå ¬ç€ºæ å ±ãã«ã€ããŠã¯ã眲åããéã®éµã倱å¹ããåŸããæå·ã¢ã«ãŽãªãºã ïŒRSA/ECDSAçïŒãè匱åããåŸã§ãæ€èšŒå¯èœã§ããå¿ èŠãããã
- æè¡ç課é¡ãšæšæºåç¶æ³:
- VCãã€ãã£ããªLTVæšæºã®æ¬ åŠ: PDFã«ãããPAdESã®ãããªãé·ææ€èšŒçšã®èšŒè·¡ãããã¥ã¡ã³ãå ã«å å«ããæšæºçãªä»çµã¿ããçŸæç¹ã®W3C VCã³ã¢ä»æ§ã«ã¯æç€ºçã«ååšããªãã
- æ¢åèŠæ Œã®è»¢çš: IETFã§æšæºåãããŠãã Evidence Record Syntax (ERS) çã®èšŒè·¡ãã©ãŒãããããVCã®ã¡ã¿ããŒã¿ãšããŠã©ãçµ±åãããã課é¡ã§ããã
- C2PAçã®ä»èŠæ Œãšã®é£æº: ã³ã³ãã³ãã®æ¥æŽã管çããC2PAçãããåºçŸ©ã®ããã¥ã¡ã³ãçæ£æ§èŠæ ŒãšVCãçµã¿åãããã¢ãããŒããææã§ããã
- æ¬PoCã®èšèšæ¹é:
- å¯ŸäººèšŒææž: æå¹æéãçãèšå®ãããªã³ã©ã€ã³ã§ã®å³ææ€èšŒïŒStatus ListïŒã«é Œãããšã§ã眲åã®é·æç¶æã³ã¹ããæå¶ããã
- å ¬ç€ºææž: 眲åäœææã«ä¿¡é Œã§ããã¿ã€ã ã¹ã¿ã³ããä»äžãããšãšãã«ãæ¬PoCã§æ¡çšãã ãã¹ãéåæå·ïŒPQCïŒ ã¢ã«ãŽãªãºã ãé©çšããããšã§ãå°æ¥çãªéåèšç®æ©ã«ããè§£èªãªã¹ã¯ã«å¯Ÿæããå®è³ªçãªæ€èšŒå¯èœæéã®å»¶äŒžãå³ã£ãŠããã
å ¬ç€ºææžã«ãããæ°žç¶çèå¥åïŒPID/DOIïŒã®æŽ»çš
- è«ç¹: èªæ²»äœã®å瀺ãçµ±èšããŒã¿çã®å ¬éæ å ±ã«ã€ããŠãURLã®å€æŽçã«å·Šå³ãããªãæ°žç¶çãªèå¥ïŒPIDïŒãå°å ¥ãã¹ããã
- DOIïŒDigital Object IdentifierïŒã®æ€èš:
- ã¡ãªãã: ãªã³ã¯åãã®é²æ¢ãåŒçšã»åç §ã®ç¢ºå®æ§åäžãåŠè¡åéã§æšæºçãªDOIãå ¬ææžã«ä»äžããããšã§ãå€éšã®ã¢ãŒã«ã€ãã·ã¹ãã ãšã®èŠªåæ§ãé«ãŸãã
- å®è£
é£æåºŠ:
- å¶åºŠé¢: ãžã£ãã³ãªã³ã¯ã»ã³ã¿ãŒïŒJaLCïŒçã®ç»é²æ©é¢ãžã®å çãšã驿£ãªã¡ã¿ããŒã¿ç®¡çäœå¶ã®æ§ç¯ãå¿ èŠãšãªãïŒã³ã¹ããšäºåæç¶ãäž»ïŒã
- æè¡é¢: æ¬SSGã®ãããªä»çµã¿ã«ãããŠãããã³ããã¿ãŒã«DOIãä¿æãããã«ãæã«ç»é²æ©é¢ã®APIãšé£æºããŠã¡ã¿ããŒã¿ãèªåéä¿¡ããä»çµã¿ãæ§ç¯ããããšã¯æè¡çã«å®¹æã§ããã
- ææ¡: ããŒã¿ã®çæ£æ§ãæ ä¿ããVCãšãããŒã¿ã®çºèŠæ§ã»æ°žç¶æ§ã確ä¿ããPIDïŒDOIïŒãçµã¿åãããããšã§ãå ¬çã«ãäºæ¬¡å©çšããããããŒã¿ã®ä¿¡é Œæ§ãé£èºçã«åäžããã
æ³ççšèªãšæç€ºåœ¢æ ã®å®çŸ©
- è«ç¹: ããžã¿ã«ããŒã¿ãã忬ããšåŒã¹ããããŸãå°å·ç©ã®å¹åãã©ãå®çŸ©ãããã
- æ¬PoCã«ãããæ«å®å®çŸ©: æ³ä»€äžãçŸæç¹ã§ãããžã¿ã«åæ¬ããšããæŠå¿µã¯æªç¢ºå®ã§ããããã衚瀺äžã®æèšã ãé»å亀ä»ãããå 容ã®ç¢ºèªç»é¢ã ãšå®çŸ©ãã誀解ãæããªã衚çŸãæ€èšããã
- éçšèŠä»¶:
- VPïŒVerifiable PresentationïŒæç€ºã®åå: ã¹ããŒããã©ã³çã§ã®ãç»é¢æç€ºãããã³ãã®ãããžã¿ã«æ€èšŒãã®ã¿ãæ³çå¹åã®ããã蚌æããšäœçœ®ã¥ããã
- å°å·ç©ç¡å¹ã®åŸ¹åº: å°å·æã«ã¯ãè€åç¡å¹ãçã®ãŠã©ãŒã¿ãŒããŒã¯ã匷å¶ããå°çŽçã®ã¢ããã°åœé 鲿¢æè¡ã«é Œããªãããžã¿ã«å®çµåã®éçšãåæãšããã
Data Authenticity and Machine Readability
ããŒã¿ã®æ¹ç«é²æ¢ïŒæ°åŠççæ£æ§ïŒã ãã§ãªãããã®ãæå³ããæ£ããè§£éãããïŒã»ãã³ãã£ãã¯ãªçæ£æ§ïŒå¿ èŠãããã
åœéæšæº (W3C VC 2.0) ãšã®æŽå
- è«ç¹: ç¬èªã®ããŒã¿æ§é ã«éãããããã«ã°ããŒãã«ãªæ€èšŒããŒã«ããŠã©ã¬ãããšäºææ§ãæã€ãã
- æ€èšæ¹é: W3C VC Data Model v2.0 ã«æºæ ããJSON-LDïŒæå³å®çŸ©ïŒãš CBOR/COSEïŒå¹çæ§ïŒã®ãã€ããªããæ§æãæ¡çšããã
- å ¬å ±æ©é¢åŽã®æ€èšäºé : ããžã¿ã«åºãæšé²ãããããŒã¹ã¬ãžã¹ããªãããèªæ²»äœã·ã¹ãã æšæºåãåãã¡ã€ã³ïŒå»çãæè²çïŒã®æšæºèŠæ Œãšã®ãããã³ã°ãå¿ èŠãã
衚èšççæ£æ§ vs æå³ççæ£æ§
- 課é¡: å¹Žææ¥ã®ãå å·è¡šèšãããå šè§æ°åãçã®åœå æ £ç¿ãšãåœéçãªæ©æ¢°å¯èªæ§ïŒISO 8601çïŒã®ã³ã³ããªã¯ãã
- æ¬PoCã®å¯Ÿå¿: å
éšããŒã¿ã¯æ©æ¢°å¯èªãªåœ¢åŒïŒäŸïŒ
2024-01-01ïŒã§ä¿æãã€ã€ãã眲å察象ã®VCããŒã¿ãããæ³ä»€ãæ§åŒã«åºã¥ãã衚èšãåçã«çæããã¬ã³ããªã³ã°ãšã³ãžã³ã ãæ§ç¯ãããããã«ããã衚瀺å 容ãšããžã¿ã«çœ²åã1察1ã§å¯Ÿå¿ããæ§é ã確ç«ããã
Authority and Typography in Presentation
å ¬çææžã«ã¯ãäžç®ã§ãããæ£åœãªãã®ã§ãããšèªèããããä¿¡é Œã®ãã¶ã€ã³ããæ±ããããã
æ£ç¢ºãªå圢衚瀺 (IVS)
- è«ç¹: åºæåè©çã«å«ãŸããç°äœåãããã«æ£ãã衚瀺ããæ å ±ã®çæ£æ§ïŒè¡šèšã®æ£ç¢ºæ§ïŒãæ ä¿ãããã
- æ¬PoCã®å®è£ æè¡: Unicode Variation Sequences (IVS) ããã³ OpenType Cmap Format 14 ããã€ãã£ãã«åŠçãããå€åïŒãã©ã³ã眮æïŒã«é Œãããã»ãã³ãã£ãã¯ãªæ å ±ãä¿æãããŸãŸã§å ¬èªæå®ãã©ã³ãçãçšããé«ç²ŸåºŠã¬ã³ããªã³ã°ãå®çŸããæååããå圢ã®äžäžèŽãé²ãææ³ãæ€èšŒããã
æšæºåæªæžæåïŒè¿œå æåïŒã®ç¬Šå·åæ¹é
- è«ç¹: ãè¡æ¿äºåæšæºæåãã®ãã¡ãUnicodeã«æªæ¡é²ã®ãè¿œå æåããããžã¿ã«ããŒã¿ïŒVCïŒå ã§ããã«æ±ããã
- æ¬PoCã§ã®è©Šè¡: å€åé åïŒPUAïŒã«äžæçã«å²ãåœãŠãã¬ã³ããªã³ã°ã«å¿ èŠãªã°ãªãã®ã¿ããµãã»ããåããWebFontãšããŠããã¥ã¡ã³ãå ã«åçã«åã蟌ãããšã§ãèŠèŠçãªåçŸæ§ïŒèŠèªæ§ïŒã確ä¿ããã
- ä»åŸã®æ€èšããŒãïŒã¡ã¿ããŒã¿ã®æ©èªæ§ãšã®äž¡ç«:
- PUAç¶ææ¡: ããŒã¿ïŒVCã®ClaimsïŒäžãPUAã³ãŒãã§ä¿æãããèŠèŠçã«ã¯æ£ç¢ºã ãã第äžè ã®ã·ã¹ãã ã§ãã©ã³ããæ¬ èœããå Žåã«æå³ãæ¶å€±ãããªã¹ã¯ãããã
- JIS X 0213ä»£æ¿æ¡: æ€çŽ¢ãæ©æ¢°åŠçã®å©äŸ¿æ§ãåªå ããJIS X 0213ã®ç¯å²å ã«ãããè¿äŒŒããæšæºæåãã«æ£èŠåããŠä¿æããããã®å Žåã衚瀺äžã®çæ£æ§ïŒæ£ç¢ºãªå圢ïŒãšããŒã¿äžã®æ£èŠåãã©ã®ã¬ã€ã€ãŒã§åé¢ã»ç®¡çãããã課é¡ãšãªãã
- ãã€ããªããæ¡: 忬æ§ãšããŠPUAã³ãŒããä¿æãã€ã€ãæ€çŽ¢ã»é£æºçšã®ãæ£èŠåïŒä»£æ¿æåïŒãã£ãŒã«ãããã¡ã¿ããŒã¿ãšããŠäœµèšããæ§æã®æ€èšã
ããžã¿ã«ã»ããã¥ã¡ã³ããšããŠã®æç€ºå質
- è«ç¹: çŽã®ã·ãã¥ã¬ãŒã·ã§ã³ïŒã¹ãã¥ãŒã¢ãŒãã£ãºã ïŒã«åºå·ãã¹ãããããžã¿ã«æé©åãå³ãã¹ããã
- æ¬PoCã§ã®è©Šè¡:
- ç»é¢äž: Webã®å©ç¹ã掻ãããã¬ã¹ãã³ã·ãã§æ€èšŒç¶æ ãçŽæçã«ç¢ºèªã§ããããžã¿ã«ãã€ãã£ããªã¬ã€ã¢ãŠãã詊è¡ã
- å°å·æ: ãã©ãŠã¶ã®å°å·æ©èœãšé£åããèªåçã«ç¹å®ãµã€ãºïŒA4çïŒã®å³æ ŒãªäŒçµ±çã¬ã€ã¢ãŠãã«åãæ¿ããã·ã¹ãã ãæ€èšŒã
- éèŠæ§: æç»ã®ä¹±ããäžèªç¶ãªãã©ã³ãã¯ãæ€èšŒè ã«ãåœé ãããäžåãã®ç念ãæãããèŠå ãšãªããé«ç²Ÿçްãªã¹ã¿ã€ãªã³ã°ã¯ããžã¿ã«èšŒææžã®ä¿¡é Œæ§ãæ§æããéèŠãªèŠçŽ ã§ããã
垳祚æ§åŒã®ããžã¿ã«å®çŸ©ãšä¿å®ã®è¿ éå
- 課é¡: åŸæ¥ã®Excelé åžãå°çšã®åž³ç¥šèšèšãœããïŒSVFçïŒãçšããæ§åŒç®¡çã§ã¯ãå¶åºŠæ¹æ£æã®æ¹ä¿®ã³ã¹ããé«ãããã³ããŒäŸåïŒããã¯ã€ã³ïŒãçããããã
- Webæè¡ã«ãã垳祚åçŸã®å¯èœæ§:
- æ±çšæ§: ã¢ãã³ãªCSSïŒGrid/Flexbox/Print CSSïŒãçšããããšã§ãå°çšãœããã«äŸåãããšããåŸæ¥ã®çŽã®æ§åŒãããªåäœã®ç²ŸåºŠã§åçŸå¯èœã§ããã
- æ©åæ§: å¶åºŠæ¹æ£ã«ããé ç®ã远å ã»å€æŽãããéãå°çšãœããã®ããŒãžã§ã³ã¢ãããåé åžãåŸ ã€ããšãªããWebæšæºã®ã³ãŒãä¿®æ£ïŒãŸãã¯ã¹ã¿ã€ã«ã·ãŒãã®æŽæ°ïŒã®ã¿ã§å³åº§ã«å¯Ÿå¿ãå¯èœãšãªãã
- æ©æ¢°å¯èªãªæ§åŒå®çŸ©ã®å¿
èŠæ§:
- æ§åŒã®ã³ãŒãå: 垳祚ã®ã¬ã€ã¢ãŠãå®çŸ©ãã®ãã®ããYAMLãJSONã®ãããªæ©æ¢°å¯èªãªããŒã¿åœ¢åŒãšããŠèŠå®ããããšã§ã人éåãã®è¡šç€ºãšã·ã¹ãã åãã®åŠçããå ±éã®å®çŸ©äœãããçæããã¢ãŒããã¯ãã£ãžã®ç§»è¡ãæåŸ ãããã
- é»å亀ä»ãšã®å ±çš: VCã®ã¡ã¿ããŒã¿å ã«ããã®ããŒã¿ã¯ãã®æ§åŒå®çŸ©ãçšããŠè¡šç€ºãã¹ãããšããåç §ãå«ããããšã§ãçºè¡ã·ã¹ãã ãšæ€èšŒã¢ããªã®éã§å šãåäžã®è¡šç€ºå質ãä¿èšŒããããšãå¯èœãšãªãã
- ä»åŸã®æ€èšããŒã: åºå¹¹ã·ã¹ãã åŽã§ä¿æããŠããæ¢åã®èšèšããŒã¿ãããWebããŒã¹ã®æ§åŒå®çŸ©ãããã«èªå倿ã»çæãããããã®å€æããã»ã¹ã®ä¿¡é Œæ§ç¢ºä¿ãè«ç¹ãšãªãã
Environment and Multi-Device Coordination
å®åçãªäºåæç¶ãã¯PCã§è¡ãããèšŒææžã®æ ŒçŽããã€ãã³ããŒã«ãŒãã®èªã¿åãã¯ã¹ããŒããã©ã³ã§è¡ããããšãããããã€ã¹éã®ä¹é¢ãããã«åããããçŠç¹ãšãªãã
ãã©ãŠã¶å®çµãšç¬èªãœãããŠã§ã¢äŸåã®åé¿
- è«ç¹: è€éãªäºåæç¶ããè¡ãPCç°å¢ã«ãããŠãå°çšãœãããŠã§ã¢ïŒã€ã³ã¹ããŒã©ãŒåœ¢åŒã®ã¢ããªçïŒã®å°å ¥ãæå°éã«æããããã«ãã©ãŠã¶æšæºæ©èœã®ã¿ã§UXãå®çµããããã
- æ¬PoCã®èŠç¹: Webã§ã®ããã¥ã¡ã³ãæç€ºãåºæ¬ãšããOSããã©ãŠã¶ãæäŸããæšæºæ©èœïŒWebAuthnçïŒãæå€§é掻çšããããšã§ãç¹å®ã®å®è¡ç°å¢ãžã®äŸåãäœæžããã¢ãããŒããéèŠããŠããã
ç¹å®ãã©ãããã©ãŒã ã寡å ãœãããŠã§ã¢ãžã®äŸååé¿
- è«ç¹: ç¹å®ã®ãã³ããŒãæ¯é ãããœãããŠã§ã¢ããšã³ã·ã¹ãã ã«äŸåããããªãŒãã³ãªæšæºãããã«ç¶æãããã
- PDFïŒAATLïŒãšã®æ¯èŒ:
- PDF眲åïŒAATLæºæ ïŒã¯å®çžŸããããããã®å³å¯ãªæ€èšŒã«ã¯Adobe Acrobatçã®ç¹å®ã®å¯¡å çãœãããŠã§ã¢ãå¿ èŠãšãªãã±ãŒã¹ãå€ãã
- 察ããŠãWebTrustã¢ãã«ïŒTLS/DNSïŒã«åºã¥ãæè¡ã¹ã¿ãã¯ã¯ãè€æ°ã®äž»èŠãã©ãŠã¶ãå ±éã®ã»ãã¥ãªãã£ã¢ãã«ã§å®è£ ããŠãããç¹å®ã®ãã¥ãŒã¢ã«çžããã«ããã
- ãŠã©ã¬ããã®çžäºéçšæ§:
- ç¹å®ã®ãå°çšãŠã©ã¬ããã¢ããªãã§ããæ€èšŒã»ä¿åã§ããªãç¶æ³ã¯ãå°æ¥çãªãã³ããŒããã¯ã€ã³ãæãã
- W3C VCãOpenID4VCI/VPçã®åœéæšæºãæ¡çšããããšã§ããŠãŒã¶ãŒãèªèº«ã®å¥œããŠã©ã¬ãããèªç±ã«éžæã§ããããã«ããã³ããŒç°å¢ãã確ä¿ããããšãéèŠã§ããã
- çžäºéçšæ§ç¢ºä¿ãå°é£ãªçç±ãšèª²é¡:
- ãä¿¡é Œã®äžè§åœ¢ãã®äžå®å šæ§: æè¡çãªãããŒã¿åœ¢åŒãã®æšæºåïŒW3C VCçïŒã¯é²ãã§ããããã©ã®çºè¡äœããæ£åœãªæš©éãæã€ãããå®çŸ©ãã Trust RegistryïŒä¿¡é Œã¬ãžã¹ããªïŒ ã®ä»æ§ããªã¹ãã®éçšãåœããã¡ã€ã³ããšã«ä¹±ç«ããŠãããããããéçŽã»æšªæçã«åç §ããä»çµã¿ãäžè¶³ããŠããã
- å®è£ ãããã¡ã€ã«ã®ä¹é¢: åãOID4VPãæ¡çšããŠããŠããæ¬§å·ã®EUDIãããã¡ã€ã«ãšä»ã®å°åã®å®è£ ã§ã¯ãå¿ é é ç®ã®è§£éãæå·ã¹ã€ãŒãã®éžæã«çްããªå·®ç°ãçããçµæçã«ãã€ãªããã«ãããäºè±¡ãçºçããããã
- ããŒããŠã§ã¢äŸåã®å£: ãã€ãã³ããŒã«ãŒãçã®ICãããèªã¿åãããSecure EnclaveïŒå®å šãªé åïŒãžã®éµçæãªã©ãOSåºæã®ããŒããŠã§ã¢å¶åŸ¡APIãçµ±äžãããŠããªããããåã仿§ã®ãŠã©ã¬ããã§ãããã€ã¹ã«ãã£ãŠåäœãç°ãªãã
ã¹ããïŒãŠã©ã¬ããïŒãšPCã®é£æº
- è«ç¹: ã¹ããå ã®ãã€ãã³ããŒã«ãŒãèªã¿åãæ©èœããŠã©ã¬ããæ©èœãšãPCäžã®äºåãã©ãŠã¶ãã©ãã·ãŒã ã¬ã¹ã«é£æºããããã
- æ€èšããŒã:
- CTAP: PCãšã¹ãããBluetoothãUSBçã§æ¥ç¶ããã¹ãããå€éšèªèšŒåšãšããŠå©çšããæšæºèŠæ Œã®æŽ»çšã
- Passkeys / WebAuthn: åäžã®iCloud/Googleã¢ã«ãŠã³ãçã§åæãããPasskeyãæŽ»çšããããã€ã¹ãè·šãã èªèšŒã»çœ²åããã»ã¹ãç°¡ç¥åããææ³ã
- Cross-Device Flow: QRã³ãŒãçãä»ããOIDC4VPïŒOpenID for Verifiable PresentationsïŒçã®ãããã³ã«ã«ãããPCãã©ãŠã¶ããã¹ãããŠã©ã¬ãããžã®ã»ãŒããªãªã¯ãšã¹ããšã¬ã¹ãã³ã¹ã®åãæž¡ãã
ãµãŒããŒåãŠã©ã¬ããã®æäŸäž»äœãšãšã³ã·ã¹ãã
- è«ç¹: ãŠã©ã¬ããïŒç¹ã«ã¯ã©ãŠã/ãµãŒããŒåïŒã®æäŸäž»äœãããã«åæ£åããæ å ±ãç¹å®ã®äºæ¥è ã«éäžç®¡çãããªãç°å¢ãå®çŸãããã
- ãéŽã²ãåé¡ããšå
Œ
±ã®åœ¹å²:
- ãŠã©ã¬ããã®æ®åã¯ãçºè¡ãããèšŒææžã®æ°ïŒéèŠïŒãšããããåçããçªå£ïŒäŸçµŠïŒã®é¶ãšåµã®é¢ä¿ã«ãããæ°éäž»å°ã®ã¿ã§ã¯ãåæã®ã€ã³ã»ã³ãã£ãèšèšãé£ãããéŽã²ãïŒbootstrapïŒåé¡ããçããããã
- å ¬çæ©é¢ã ããªãŒãã³ãªæè¡ä»æ§ãããåç §å®è£ ïŒReference ImplementationïŒããããã³ ãé©åæ§ãã¹ãïŒConformance TestïŒã ãæäŸããåè³ªãæ ä¿ããä»çµã¿ãå¿ èŠã§ããã
- ãã«ããããã€ããŒç°å¢ã®å®çŸ:
- å ¬çæ©é¢ãã€ã³ãã©ã®å ±éåºæºãæŽåããäžã§ãè€æ°ã®äž»äœïŒå ¬çæ©é¢ã»æ°éäºæ¥è çïŒãçžäºéçšå¯èœãªãŠã©ã¬ãããæäŸã§ããç°å¢ãæãŸããã
- ããã«ããããŠãŒã¶ãŒãä¿¡é Œã§ããæäŸè ãéžæã§ããããã«ãªããåäžã®ãã©ãããã©ãŒã ã«ããããŒã¿ã®å æãç¬å ãé²ãããšãæåŸ ãããã
Compatibility with AI Agents and Autonomous Negotiation
- è«ç¹: 人éã®ä»åšãªãã«ãAIãšãŒãžã§ã³ããèªåŸçã«èšŒææžãæç€ºã»æ€èšŒã§ãããã
- AIãšãŒãžã§ã³ãã«ããèªåæç€º:
- å§ä»»: æ¬äººãAIãšãŒãžã§ã³ãã«å¯Ÿããç¹å®ã®æ¡ä»¶äžã§ç¹å®ã®VCãæç€ºããæš©éãå®å šã«å§ä»»ããä»çµã¿ïŒDelegation蚌跡ã®ä»äžçïŒãå¿ èŠã§ããã
- ä¿¡é Œã®ã°ã©ãè§£æ: ãšãŒãžã§ã³ãããæç€ºãããVCã®çºè¡äœãä¿¡é Œã§ãããã®ã§ãããããDIDããã¥ã¡ã³ããä¿¡é Œãªã¹ãã蟿ã£ãŠèªåŸçã«å€æãããä¿¡é Œã®ã°ã©ãè§£æãã®å®è£ ãéµãšãªãã
- 課é¡: ãšãŒãžã§ã³ãã誀ã£ãŠå¿ èŠä»¥äžã®æ å ±ãé瀺ããŠããŸããéå°é瀺ãã®ãªã¹ã¯ããæç€ºå ãæ£åœãªãšãŒãžã§ã³ãã§ããããå€å®ããããšãŒãžã§ã³ãéã®çžäºèªèšŒããæè¡çãªèª²é¡ãšããŠæ®ã£ãŠããã
ãã«ãèªèšŒæ å ±ã«ããæç€ºã®çæãšæšæºåç¶æ³
- è«ç¹: è€æ°ã®ç°ãªãçºè¡äœããåŸãè€æ°ã®VCãçµã¿åãããäžã€ã®èšŒæïŒVPïŒãšããŠæç€ºããéã®æšæºåã¯ã©ããŸã§é²ãã§ãããã
- æšæºåã®é²æç¶æ³ïŒ2025幎æç¹ïŒ:
- å®äºïŒå§åæžã¿ïŒ: W3C VCããŒã¿ã¢ãã« v2.0ãããã³OAuth 2.0ããŒã¹ã®æç€ºãããã³ã«ã§ãã OID4VP ã¯äž»èŠãªä»æ§ã確å®ããŠãããåçšç°å¢ã§ã®å®è£ ãå¯èœãšãªã£ãŠããã
- å®çšåãã§ãŒãº: è€æ°ã®VCããç¹å®ã®é ç®ã ããæœåºããŠæç€ºãã Presentation Exchange ããæ å ±ã®èŠæ±æ¹æ³ãå®ãã DCQLïŒããžã¿ã«è³æ Œæ å ±ç §äŒèšèªïŒã«ãããè€æ°ã®VCãè·šãã è€éãªèšŒæã®çæãæè¡çã«æšæºåãããã
- æ®ããã課é¡: ç°ãªãããŒã¿ãã©ãŒãããïŒJSON-LDãSD-JWTãmdocçïŒã®éã§ã®ãã¯ãã¹ãã©ãŒããããªæ€èšŒããžãã¯ãã®å ±éåããå€§èŠæš¡ãªå€±å¹ç¢ºèªïŒStatus ListïŒã®åçãªåæææ³ã«ã€ããŠã¯ãäŸç¶ãšããŠããã©ãŒãã³ã¹ãšãã©ã€ãã·ãŒã®ãã¬ãŒããªãã«é¢ããæ€èšãç¶ããŠããã
Security and Privacy
å¿ èŠæå°éã®ããŒã¿ã®ã¿ãæç€ºãããšãããããžã¿ã«ãªãã§ã¯ã®ãã©ã€ãã·ãŒä¿è·æ©èœã§ããã
ãã«ããŒãã€ã³ãã£ã³ã°ãšèå¥åã®èª²é¡
- è«ç¹: æ¬äººå®ã®éå ¬éèšŒææžïŒäœæ°ç¥šãçšèšŒæçïŒã«ãããŠãçºè¡ãããVCãšãæç€ºè ãæ¬äººã§ããããšïŒãã«ããŒãã€ã³ãã£ã³ã°ïŒããããã«æ€èšŒå¯èœã«ãããã
- èæ¯ãšèª²é¡:
- æ¢åææ³ã®éç: æ°åã³ããã¯ã¯ãã³æ¥çš®èšŒææžçã§ã¯åºæ¬4æ å ±ïŒæ°åã»äœæã»çå¹Žææ¥ã»æ§å¥ïŒãçšããããããéå ¬éãåæãšããèšŒææžã§ã¯ããããæ å ±ã®æç€ºãã®ãã®ããã©ã€ãã·ãŒã®æžå¿µãšãªãå Žåãããã
- èå¥åã®å¶çŽ: å ¬çå人èªèšŒïŒJPKIïŒã®ã·ãªã¢ã«çªå·çã¯ããã®äœ¿éãæ³åŸã§å³æ Œã«èŠå®ãããŠããã宿ã«VCã®èå¥åãšããŠåã蟌ãããšã¯å°é£ã§ããã
- æªçšé²æ¢ã®å¿ èŠæ§: åçãã第äžè ããåœè©²ãã€ã³ãã£ã³ã°æ å ±ãå¥ã®çšéã«æªçšïŒãªãã¬ã€æ»æçïŒããããšãé²ãä»çµã¿ãäžå¯æ¬ ã§ããã
- ä»åŸã®æ€èšæ¹å:
- PPID: æç€ºå ããšã«ç°ãªãäžæçãªèå¥åãçæããåå¯ããé²ãã€ã€æ¬äººæ§ãæ ä¿ããææ³ã®æ€èšã
- ZKP: èå¥åãã®ãã®ãé瀺ãããç¹å®ã®ç§å¯éµãä¿æããŠããããšã®ã¿ã蚌æãããŒãç¥è蚌æã®æŽ»çšã
- ã«ãŒã代æ¿é»ç£çèšé²ãšã®é£æº: ãã€ãã³ããŒã«ãŒãçã®ICãããå ã®æ å ±ïŒä»£æ¿é»ç£çèšé²ïŒãšãçºè¡ãããVCãããã«æ³ä»€ã«æµè§Šããããã€æ©å¯æ§ãä¿ã£ããŸãŸçŽä»ãããã«ã€ããŠã®ãå®è£ ã¬ãã«ã®è«ç¹æŽçãæ±ããããã
éžæçé瀺
- è«ç¹: è³æ ŒèšŒæã身å 確èªã®éãå¿ èŠãªé ç®ïŒäŸïŒå¹Žéœ¢ã®ã¿ïŒã«éå®ããŠæç€ºã§ãããã
- æè¡ã¹ã¿ãã¯: SD-JWT ãŸã㯠SD-CWT ã®æ¡çšãæ€èšã
- å¶åºŠç課é¡: æ¢åã®äºåèŠå®çã«åºã¥ãã蚌æäºé ãã®è§£éãšãããžã¿ã«äžã§ã®ãé ç®éžæããããã«æŽåãããããéèŠãªæ€èšããŒããšãªãã
VPã®æç€ºã»æ€èšŒæ¹æ³ãšæ€èšŒè ã€ã³ã¿ãŒãã§ãŒã¹ã®èŠä»¶
- è«ç¹: æ€èšŒè ãVPãåçããéã察é¢ã»é察é¢ã®åã·ãŒã³ã§ã©ã®ãããªã€ã³ã¿ãŒãã§ãŒã¹ïŒUI/UXããã³APIïŒãçšæãã¹ããã
- æç€ºææ³ã®åé¡:
- 察é¢ïŒã¢ãã€ã«éïŒ: QRã³ãŒãã®æç€ºããŸãã¯NFC/Bluetoothè¿æ¥éä¿¡ãçšãããªãã©ã€ã³æç€ºã
- é察é¢ïŒWebïŒ: ãã©ãŠã¶ã®ãªãã€ã¬ã¯ããçšãããåäžããã€ã¹å 飿ºãããPCç»é¢äžã®QRã³ãŒããã¹ããã§ã¹ãã£ã³ãããã¯ãã¹ããã€ã¹é£æºãã
- æ€èšŒè
åŽã«æ±ããããã€ã³ã¿ãŒãã§ãŒã¹èŠä»¶:
- èŠæ±å®çŸ©ã®æç€º: Presentation DefinitionçãçšããŠãå¿ èŠãªæ å ±ã®ãµãã»ããïŒäŸïŒæ°åãšçå¹Žææ¥ã®ã¿ïŒãåçã«ãªã¯ãšã¹ãããæ©èœã
- æ€èšŒãšã³ãžã³ã®å®è£ : æç€ºãããVPã®çœ²åïŒPQCå«ãïŒãçºè¡äœã®ä¿¡é Œæ§ïŒTrust Listç §åïŒã倱å¹ç¶æ ãããã³æç€ºè ãšèšŒææžã®çŽä»ãïŒãã«ããŒãã€ã³ãã£ã³ã°ïŒãèªåã§ããã¯ãšã³ãæ€èšŒããã
- UI/UX: æ€èšŒçµæããåæ Œ/äžåæ Œãã ãã§ãªããä¿¡é Œã®æ ¹æ ïŒã©ã®èªæ²»äœããã€çºè¡ãããçïŒã人éãçè§£å¯èœãªåœ¢ã§ã°ã©ãã£ã«ã«ã«è¡šç€ºãããã¥ãŒã¢ã
- å®åäžã®èª²é¡:
- ãªãã©ã€ã³æã®ä¿¡é Œæ ä¿: ãããã¯ãŒã¯ãäžå®å®ãªå¯Ÿé¢çŸå Žã«ãããŠãææ°ã®å€±å¹ãªã¹ããååŸã§ããªãå Žåã®ãä¿¡é Œã®é®®åºŠããã©ã蚱容ãããã
- æ€èšŒåŽã®ãªãããŸã鲿¢: æªæã®ããæ€èšŒè ãåœã®æ€èšŒãªã¯ãšã¹ãïŒVPRïŒãéããå人æ å ±ãäžæ£ã«ååŸãããªã¹ã¯ãæ€èšŒè èªèº«ã®DIDã«ãããæ€èšŒè èªèšŒãã®ä»çµã¿ãå¿ èŠãšãªãã
æå·ã¢ã«ãŽãªãºã ã®éžå®ãšçŸè¡ã¬ããã³ã¹ãšã®èŠªåæ§
- è«ç¹: JPKIïŒå ¬çå人èªèšŒïŒãGPKIïŒæ¿åºèªèšŒåºç€ïŒã§æšæºçãªã¢ã«ãŽãªãºã ãVCã«ãã®ãŸãŸå©çšã§ãããããŸã次äžä»£ã¢ã«ãŽãªãºã ãžã®ç§»è¡ã®åŠ¥åœæ§ã¯äœãã
- ã¢ã«ãŽãªãºã ç¹æ§ã®æ¯èŒ:
- RSA-2048 (çŸè¡åºæº): æ¢åã®æ¿åºã»å
Œ
±ã·ã¹ãã ã§åºãæ¡çšãããŠããã
- å®è£ å¯èœæ§: W3C VCæšæºïŒRsaSignature2018çïŒã§ãµããŒããããŠãããæè¡çãªå®è£ ã¯å¯èœã§ããã
- çžäºéçšæ§ã®èª²é¡: 眲åãµã€ãºã倧ããããïŒ256bytesïŒããªãã©ã€ã³æç€ºçšã®QRã³ãŒããé«å¯åºŠã«ãªããããå®äŸ¡ãªã«ã¡ã©çã§ã®èªã¿åã粟床ãäœäžããæžå¿µãããããŸããæ¬§å·ã®EUDI Walletçã®ææ°ã®åœéãã¬ãŒã ã¯ãŒã¯ã§ã¯ECDSAãåªå ãããŠãããã°ããŒãã«ãªçžäºéçšæ§ã«ãããŠãã¬ã¬ã·ãŒå¯Ÿå¿ããå¿ èŠã«ãªãå¯èœæ§ãããã
- ECDSA P-384 (é«ã»ãã¥ãªãã£èŠä»¶): RSAã«æ¯ã¹çœ²åãµã€ãºãåçã«å°ãããããé«ãã»ãã¥ãªãã£åŒ·åºŠã確ä¿ã§ãããGoogleãŠã©ã¬ãããAppleãŠã©ã¬ãããªã©ãäž»èŠãªã¢ãã€ã«ãã©ãããã©ãŒã ã§ã®èŠªåæ§ãæ¥µããŠé«ãã
- Ed25519 (æ¬PoCæ¡çš): é«éãã€å®è£ ãã·ã³ãã«ã§ããµã€ããã£ãã«æ»æãžã®èæ§ãé«ããVC/DIDã®ãšã³ã·ã¹ãã ã§äºå®äžã®ããã¡ã¯ããšããŠæšå¥šãããŠããã
- RSA-2048 (çŸè¡åºæº): æ¢åã®æ¿åºã»å
Œ
±ã·ã¹ãã ã§åºãæ¡çšãããŠããã
- æ¬PoCã®éžå®çç±ãšçŸè¡PKIãšã®é¢ä¿:
- äºææ§: çŸè¡ã®JPKI/GPKIã®ã¢ã«ãŽãªãºã ããã®ãŸãŸVCã«èŒããããšã¯å¯èœã ããã¢ãã€ã«ãã¡ãŒã¹ããªUXïŒQRã¹ãã£ã³ã®ããããããªãã©ã€ã³æ€èšŒçïŒã远æ±ããå ŽåãRSAãããECCïŒæ¥åæ²ç·æå·ïŒç³»ãé©ããŠããã
- åªäœæ§: ä»åæ¡çšãã Ed25519 + ML-DSA ã®ãã€ããªããæ§æã¯ãçŸåšã®è»œéã»é«éãªåŠçæ§èœãç¶æãã€ã€ãå°æ¥çãªéåèšç®æ©ãžã®èæ§ïŒPQCïŒãå åããããå°æ¥å¿åãã®èšèšãšãªã£ãŠãããçŸè¡åºæºãç¶æãã€ã€ããé·æéã®çæ£æ§æ ä¿ãå¿ èŠãªå ¬ææžã«ã€ããŠã¯ãPQCãžã®æ®µéçç§»è¡ãæ€èšãã¹ãã§ããã
ãã¹ãéåæå·
- 課é¡: éåã³ã³ãã¥ãŒã¿ã®å°é ã«ãããå°æ¥çãªçœ²åã®åœé ãªã¹ã¯ã
- æ¬PoCã®å®è£ : å ¬èªããã¥ã¡ã³ãã®é·æçãªçæ£æ§ãæ ä¿ãããããæ¢åã®æ¥åæ²ç·æå· (Ed25519) ãšæ¬¡äžä»£æ Œåæå· (ML-DSA-44) ãçµã¿åããã ãã€ããªãã眲å ãæ¡çšãããã®å®çšæ§ãæ€èšŒããã
Sorane (空é³) Project - Summary of Issues for Public Institutions - 2025-12-22 æ¬ããã¥ã¡ã³ãã¯ãæ¬PoCãéããŠåŸãããç¥èŠã«åºã¥ããå ¬å ±æ©é¢ã«ããããŒã¿é»å亀ä»ã®ç€ŸäŒå®è£ ã«åããæ€èšé ç®ãæŽçããã¡ã¢ã§ããã