æéããŒã¹ã®ã¯ã³ã¿ã€ã ãã¹ã¯ãŒã (TOTP) ã¯ãæ€èšŒå¯èœãªã¯ã³ã¿ã€ã ãã¹ã¯ãŒããçæããããã®å ç¢ãªã»ãã¥ãªã㣠ã¢ã«ãŽãªãºã ã§ããããŠãŒã¶ãŒèªèšŒã®åéã§äžè¬çã«äœ¿çšãããŸããåºãæ¡çšãããŠããã»ãã¥ãªãã£å¯ŸçãšããŠãTOTP ã¯è¿œå ã®ä¿è·å±€ãæäŸãããæéã«ææãªäžæã®ãã¹ã¯ãŒããçæããããšã«ããããŠãŒã¶ãŒè³æ Œæ å ±ã®è匱æ§ãæå°éã«æããŸãããã®é«åºŠãªã¬ãã«ã®ã»ãã¥ãªãã£ã¯ããªã³ã©ã€ã³ ãã³ãã³ã°ãé»ååååŒãããã³å¢å€§ãããµã€ããŒè åšãå人æ å ±ã®çé£ãããã³äžæ£ã¢ã¯ã»ã¹ã®ã€ã³ã¹ã¿ã³ã¹ãé²åŸ¡ããããã«åŒ·åãªãŠãŒã¶ãŒèªèšŒãããã³ã«ãå¿ èŠãšãããã®ä»ã®ããŸããŸãªãã©ãããã©ãŒã ãªã©ã®æ©å¯æ§ã®é«ãã¢ããªã±ãŒã·ã§ã³ã§ç¹ã«éèŠã§ãã
ãŠãŒã¶ãŒèªèšŒæ¹æ³ãšããŠãTOTP 㯠HMAC ããŒã¹ã®ã¯ã³ã¿ã€ã ãã¹ã¯ãŒã (HOTP) ã¢ã«ãŽãªãºã ãšé£æºããŠåäœããŸãã HOTP ã¯ã«ãŠã³ã¿ãŒããŒã¹ã®ã·ã¹ãã ãå©çšããŠã¯ã³ã¿ã€ã ãã¹ã¯ãŒããçæããŸãããTOTP ã¯æéããŒã¹ã®åæãçµã¿èŸŒãã§ãäžæçã§å®å šãªäžæã®ãã¹ã¯ãŒããçæããŸããåºæ¬çã«ãTOTP ã¯ãã«ãŠã³ã¿ãŒ ã³ã³ããŒãã³ããçŸåšæå»ã«çœ®ãæããããšã«ãããHMAC ããŒã¹ã® OTP ã¢ã«ãŽãªãºã ã倿ŽããŸãããã®çµæã30 ç§ããšã«å€æŽãããåçã§æå¹æéã®çããã¹ã¯ãŒããåŸãããéçãªãã¹ã³ãŒããããé¡èãªå©ç¹ãåŸããããªãã¬ã€æ»æã®ãªã¹ã¯ã軜æžãããŸãã
å®éã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ãTOTP ã¯äž»ã« 2 èŠçŽ ãŸãã¯å€èŠçŽ èªèšŒããã»ã¹ãéããŠå°å ¥ãããŸãããã®ã¢ãããŒãã§ã¯ããŠãŒã¶ãŒã¯è€æ°ã®èº«å 蚌æãæäŸããå¿ èŠããããé垞㯠TOTP çæã³ãŒããšãšãã«äžæã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®çµã¿åãããå¿ èŠã«ãªããŸããå€ãã®å ŽåãTOTP ã³ãŒãã¯ããŠãŒã¶ãŒã®ã¢ãã€ã« ããã€ã¹ãŸãã¯å°çšã®ããŒããŠã§ã¢ ããŒã¯ã³ã«ã€ã³ã¹ããŒã«ããã TOTP æ€èšŒã¢ããªã±ãŒã·ã§ã³ãéããŠæäŸãããŸãããããã®ã¢ããªã±ãŒã·ã§ã³ã®æ³šç®ãã¹ãäŸã«ã¯ãGoogle AuthenticatorãAuthyãYubico Authenticator ãªã©ããããŸãããããã¯ãã¹ãŠãInternet Engineering Task Force (IETF) ã«ãã£ãŠ RFC 6238 ã§å®çŸ©ãããŠãã TOTP æšæºãšäºææ§ããããŸãã
TOTP çæããã»ã¹ã®éèŠãªèŠçŽ ã¯ããŠãŒã¶ãŒã®èªèšŒããã€ã¹ãšæ€èšŒãµãŒããŒéã§å ±æãããåºç€ãšãªãç§å¯ããŒã§ãããã®ããŒã¯ã¢ã«ãŽãªãºã ã®æ£åœæ§ãç¶æããã®ã«åœ¹ç«ã¡ãå®å šã«çæãä¿åãé åžããå¿ èŠããããŸãããã¹ã ãã©ã¯ãã£ã¹ã«åŸã£ãŠãæé©ãªãšã³ããã㌠ã¬ãã«ã確ä¿ããããã« SHA-256 ã SHA-512 ãªã©ã®æå·ã¢ã«ãŽãªãºã ã䜿çšããŠç§å¯ããŒãã©ã³ãã ã«çæãããã®åŸãQR ã³ãŒãã SSL/TLS æå·åæ¥ç¶ãªã©ã®å®å šãªéä¿¡ãã£ãã«ãä»ããŠãŠãŒã¶ãŒãšå ±æããå¿ èŠããããŸãã ã
TOTP çæããããã¹ã¯ãŒããå ¥åãããšãèªèšŒãµãŒããŒã¯ãçŸåšæå»ãå ±æç§å¯ããŒãäºåå®çŸ©ãããã¿ã€ã ã¹ãããééãèæ ®ããŠãæäŸãããã³ãŒãããµãŒããŒçæã® TOTP ãšæ¯èŒããŸããæå»åæã®äžäžèŽãé å»¶ã®åé¡ã«å¯ŸåŠããããã«ããµãŒããŒã§ã¯éåžžãäºåæ§æããã蚱容ç¯å²ãèš±å¯ãããŠããŸãã TOTP ã¯ã蚱容å¯èœãªæéç¯å²å ã§ãµãŒããŒã®æåŸ ãšäžèŽããå Žåã«æå¹ã§ãããšã¿ãªãããŸãã
AppMasterno-codeãã©ãããã©ãŒã ã®ã³ã³ããã¹ãã§ãŠãŒã¶ãŒèªèšŒã« TOTP ãå®è£ ãããšãããŸããŸãªã¡ãªãããåŸãããã¢ããªã±ãŒã·ã§ã³ ã»ãã¥ãªã㣠ãã¬ãŒã ã¯ãŒã¯ãããã«åŒ·åãããŸãã TOTP ã¯ããŠãŒã¶ãŒã®ã»ãã¥ãªãã£ã匷åããäžæ£ã¢ã¯ã»ã¹ã®ã€ã³ã¹ã¿ã³ã¹ãæžããã ãã§ãªãã峿 ŒãªããŒã¿ ã»ãã¥ãªã㣠ãããã³ã«ãå¿ èŠãšãã GDPRãHIPAAãPCI DSS ãªã©ã®æšæºãžã®èŠå¶éµå®ãä¿é²ããŸãã
AppMasterã§äœæãããèšå€§ãªæ°ã®ãŠãŒã¶ãŒ ã¢ããªã±ãŒã·ã§ã³ãèæ ®ãããšããã©ãããã©ãŒã ã®èªèšŒã¡ã«ããºã ã« TOTP ã¢ã«ãŽãªãºã ãçµã¿èŸŒãããšã§ãã¿ã€ã ãªãŒã§ä¿¡é Œæ§ã®é«ãã匷åãããã»ãã¥ãªã㣠ãœãªã¥ãŒã·ã§ã³ãæäŸãããŸããããã«ã AppMasteråºæã®no-codeæ©èœã«ãããTOTP ã¢ã«ãŽãªãºã ã®ã·ãŒã ã¬ã¹ãªçµ±åãå¯èœã«ãªããéçºè ã¯æå°éã®åŽåãšæå€§ã®å¹æã§ã»ãã¥ãªãã£æ©èœãã«ã¹ã¿ãã€ãºããã³ã¢ããã°ã¬ãŒãã§ããŸããé²åãç¶ããããžã¿ã«æä»£ã«ãããŠãæéããŒã¹ã®ã¯ã³ã¿ã€ã ãã¹ã¯ãŒã ã¢ã«ãŽãªãºã ã®ãããªå ç¢ãªã»ãã¥ãªãã£å¯Ÿçãæ¡çšããããšã¯ãè³¢æãªéžæã§ããã ãã§ãªããéèŠãªãŠãŒã¶ãŒæ å ±ãä¿è·ããã¢ããªã±ãŒã·ã§ã³ã®æŽåæ§ãç¶æããããã«äžå¯æ¬ ãªèŠä»¶ã§ããããŸãã