{"id":4910,"date":"2026-06-24T00:03:11","date_gmt":"2026-06-23T15:03:11","guid":{"rendered":"https:\/\/blog.id774.net\/entry\/?p=4910"},"modified":"2026-06-23T10:48:23","modified_gmt":"2026-06-23T01:48:23","slug":"cryptsetup-%e3%81%ae-tcrypt-%e4%ba%92%e6%8f%9b%e3%82%b3%e3%83%bc%e3%83%89%e3%82%92%e8%aa%ad%e3%82%80","status":"publish","type":"post","link":"https:\/\/blog.id774.net\/entry\/2026\/06\/24\/4910\/","title":{"rendered":"cryptsetup \u306e TCRYPT \u4e92\u63db\u30b3\u30fc\u30c9\u3092\u8aad\u3080"},"content":{"rendered":"<p>\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u306f\u3001\u5358\u306b\u30c7\u30fc\u30bf\u3092\u8aad\u3081\u306a\u304f\u3059\u308b\u305f\u3081\u306e\u4ed5\u7d44\u307f\u3067\u306f\u306a\u3044\u3002\u6b63\u3057\u3044\u9375\u3001\u6b63\u3057\u3044\u30d8\u30c3\u30c0\u30fc\u3001\u6b63\u3057\u3044\u5f62\u5f0f\u7406\u89e3\u3001\u6b63\u3057\u3044\u5b9f\u88c5\u304c\u305d\u308d\u3063\u305f\u3068\u304d\u306b\u3060\u3051\u3001\u9589\u3058\u305f\u30c7\u30fc\u30bf\u3092\u518d\u3073\u958b\u3051\u308b\u4ed5\u7d44\u307f\u3067\u3042\u308b\u3002\u3053\u306e\u6027\u8cea\u306f\u3001\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u3092\u5b89\u5168\u306b\u3059\u308b\u4e00\u65b9\u3067\u3001\u9577\u671f\u904b\u7528\u3067\u306f\u5225\u306e\u554f\u984c\u3092\u751f\u3080\u3002\u53e4\u3044\u5a92\u4f53\u304c\u624b\u5143\u306b\u6b8b\u3063\u3066\u3044\u3066\u3082\u3001\u305d\u308c\u3092\u958b\u304f\u305f\u3081\u306e\u5f62\u5f0f\u4e92\u63db\u6027\u304c\u5931\u308f\u308c\u308c\u3070\u3001\u5a92\u4f53\u306f\u6b8b\u3063\u3066\u3044\u308b\u306e\u306b\u4e2d\u8eab\u3078\u5230\u9054\u3067\u304d\u306a\u3044\u3002<\/p>\n<p>\u65e2\u7a3f\u3067\u306f\u3001TrueCrypt \u65e7\u8cc7\u7523\u3092 GNU\/Linux \u3067\u4fdd\u5168\u3059\u308b\u3053\u3068\u3001LUKS \u6697\u53f7\u5316\u5a92\u4f53\u3092\u4f5c\u6210\u624b\u9806\u3060\u3051\u3067\u306a\u304f\u904b\u7528\u624b\u9806\u3068\u3057\u3066\u6271\u3046\u3053\u3068\u3001\u4fdd\u5b58\u3092\u672a\u6765\u306e\u6642\u70b9\u3067\u610f\u5473\u3092\u53d6\u308a\u51fa\u305b\u308b\u69cb\u9020\u3068\u3057\u3066\u6349\u3048\u308b\u3053\u3068\u3001\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u3092\u9577\u671f\u904b\u7528\u3068\u9000\u5f79\u306e\u554f\u984c\u3068\u3057\u3066\u6271\u3046\u3053\u3068\u3092\u6574\u7406\u3057\u3066\u304d\u305f<a href=\"#ref1\">[1]<\/a><a href=\"#ref2\">[2]<\/a><a href=\"#ref3\">[3]<\/a><a href=\"#ref4\">[4]<\/a>\u3002\u3055\u3089\u306b\u3001\u5177\u4f53\u7684\u306a\u904b\u7528\u624b\u9806\u3001\u81ea\u7531\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3060\u3051\u3067\u6271\u3048\u308b\u6697\u53f7\u5316\u5a92\u4f53\u306e\u7bc4\u56f2\u3001LUKS \u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u306e lifecycle \u3082\u6574\u7406\u3057\u305f<a href=\"#ref5\">[5]<\/a><a href=\"#ref6\">[6]<\/a><a href=\"#ref7\">[7]<\/a>\u3002\u672c\u7a3f\u306f\u3001\u305d\u306e\u7cfb\u5217\u306e\u4e2d\u3067\u3001cryptsetup \u306b\u542b\u307e\u308c\u308b TCRYPT \/ VeraCrypt \u4e92\u63db\u30b3\u30fc\u30c9\u3092\u8aad\u3080\u3002<\/p>\n<p>\u4e2d\u5fc3\u547d\u984c\u306f\u5358\u7d14\u3067\u3042\u308b\u3002cryptsetup \u306e TCRYPT \u4e92\u63db\u30b3\u30fc\u30c9\u306f\u3001TrueCrypt \u3092\u5fa9\u6d3b\u3055\u305b\u308b\u305f\u3081\u306e\u30b3\u30fc\u30c9\u3067\u306f\u306a\u3044\u3002\u904e\u53bb\u306b\u4f5c\u3089\u308c\u305f\u6697\u53f7\u5316\u8cc7\u7523\u3078\u5230\u9054\u3059\u308b\u305f\u3081\u306e\u4e92\u63db\u30ec\u30a4\u30e4\u30fc\u3067\u3042\u308b\u3002\u53e4\u3044\u5f62\u5f0f\u3092\u4e3b\u7cfb\u306b\u623b\u3055\u305a\u3001\u3057\u304b\u3057\u5fc5\u8981\u306a\u3068\u304d\u306b\u958b\u3051\u308b\u7d4c\u8def\u306f\u6b8b\u3059\u3002\u3053\u306e\u8a2d\u8a08\u306f\u3001\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u306e\u9577\u671f\u904b\u7528\u306b\u304a\u3044\u3066\u91cd\u8981\u306a\u30ec\u30b8\u30ea\u30a8\u30f3\u30b9\u3067\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u89b3\u70b9<\/th>\n<th>\u672c\u7a3f\u3067\u6271\u3046\u3053\u3068<\/th>\n<th>\u672c\u7a3f\u3067\u6271\u308f\u306a\u3044\u3053\u3068<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u5bfe\u8c61\u30b3\u30fc\u30c9<\/td>\n<td>cryptsetup \/ libcryptsetup \u306b\u542b\u307e\u308c\u308b lib\/tcrypt\/tcrypt.c \u306e\u8cac\u52d9\u3068\u51e6\u7406\u69cb\u9020\u3092\u6271\u3046\u3002<\/td>\n<td>TrueCrypt \/ VeraCrypt \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u5168\u4f53\u306e\u518d\u5b9f\u88c5\u3084 GUI \u6a5f\u80fd\u306f\u6271\u308f\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u904b\u7528\u4e0a\u306e\u4f4d\u7f6e\u3065\u3051<\/td>\n<td>\u65e2\u5b58 TCRYPT \/ VeraCrypt \u8cc7\u7523\u3078\u5230\u9054\u3059\u308b\u305f\u3081\u306e\u4e92\u63db\u7d4c\u8def\u3068\u3057\u3066\u4f4d\u7f6e\u3065\u3051\u308b\u3002<\/td>\n<td>TrueCrypt \/ VeraCrypt \u3092\u65b0\u898f\u4e3b\u7cfb\u3068\u3057\u3066\u63a8\u5968\u3059\u308b\u8b70\u8ad6\u306f\u6271\u308f\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u6280\u8853\u8aac\u660e<\/td>\n<td>\u30d8\u30c3\u30c0\u30fc\u8aad\u89e3\u3001KDF \u5019\u88dc\u3001cipher \u5019\u88dc\u3001hidden volume\u3001system encryption\u3001dm-crypt mapping \u3078\u306e\u63a5\u7d9a\u3092\u6271\u3046\u3002<\/td>\n<td>\u6697\u53f7\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u306e\u6570\u5b66\u7684\u8a3c\u660e\u3084\u653b\u6483\u8a55\u4fa1\u306e\u8a73\u7d30\u306b\u306f\u8e0f\u307f\u8fbc\u307e\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u4e00\u822c\u5316<\/td>\n<td>\u6697\u53f7\u5316\u5a92\u4f53\u306b\u304a\u3051\u308b\u5f62\u5f0f\u4e92\u63db\u6027\u3092\u3001\u5fa9\u5143\u53ef\u80fd\u6027\u3068\u9577\u671f\u904b\u7528\u306e\u554f\u984c\u3068\u3057\u3066\u6271\u3046\u3002<\/td>\n<td>\u4fdd\u5b58\u5a92\u4f53\u4e00\u822c\u306e\u5168\u5206\u91ce\u3084\u3001\u6587\u66f8\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u4e00\u822c\u306e\u4fdd\u5b58\u8ad6\u307e\u3067\u306f\u5e83\u3052\u306a\u3044\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u306a\u304a\u3001\u672c\u7a3f\u3067\u6271\u3046 cryptsetup upstream \u306e\u5b9f\u88c5\u3001\u4fdd\u5b88\u4e3b\u4f53\u3001\u30e9\u30a4\u30bb\u30f3\u30b9\u8868\u8a18\u3001KDF \u5019\u88dc\u3001cipher \u5019\u88dc\u306f\u30012026 \u5e74 6 \u6708\u6642\u70b9\u3067\u53c2\u7167\u3057\u305f\u60c5\u5831\u306b\u57fa\u3065\u304f\u3002cryptsetup \u306f\u7d99\u7d9a\u7684\u306b\u66f4\u65b0\u3055\u308c\u308b\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u3067\u3042\u308a\u3001\u5c06\u6765\u306e main \u30d6\u30e9\u30f3\u30c1\u3067\u306f\u5b9f\u88c5\u3084\u8868\u8a18\u304c\u5909\u308f\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u3002\u305d\u306e\u305f\u3081\u3001\u8a73\u7d30\u8a2d\u8a08\u306e\u65ad\u9762\u3092\u53b3\u5bc6\u306b\u78ba\u8a8d\u3059\u308b\u5834\u5408\u306f\u3001\u672c\u7a3f\u306e\u516c\u958b\u65e5\u3060\u3051\u3067\u306a\u304f\u3001\u53c2\u7167\u3057\u305f release tag \u307e\u305f\u306f commit \u3082\u78ba\u8a8d\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002<\/p>\n<hr>\n<h2>1. \u53e4\u3044\u6697\u53f7\u5316\u8cc7\u7523\u306f\u3001\u53e4\u304f\u306a\u3063\u3066\u3082\u6d88\u3048\u306a\u3044<\/h2>\n<p>TrueCrypt \u306f\u3001\u304b\u3064\u3066\u6697\u53f7\u5316\u30d5\u30a1\u30a4\u30eb\u30b3\u30f3\u30c6\u30ca\u30fc\u3084\u6697\u53f7\u5316\u30c7\u30d0\u30a4\u30b9\u3092\u6271\u3046\u305f\u3081\u306e\u5b9f\u7528\u7684\u306a\u9078\u629e\u80a2\u3060\u3063\u305f\u3002\u73fe\u5728\u306e TrueCrypt \u516c\u5f0f\u30b5\u30a4\u30c8\u306f\u3001TrueCrypt \u306e\u5229\u7528\u3092\u5b89\u5168\u3067\u306a\u3044\u3082\u306e\u3068\u3057\u3066\u8b66\u544a\u3057\u3001BitLocker \u3078\u306e\u79fb\u884c\u624b\u9806\u3092\u793a\u3059\u72b6\u614b\u306b\u306a\u3063\u3066\u3044\u308b<a href=\"#ref8\">[8]<\/a>\u30022014 \u5e74\u306e\u7d42\u4e86\u544a\u77e5\u306f\u5f53\u6642\u5927\u304d\u304f\u5831\u3058\u3089\u308c\u3001TrueCrypt \u306f\u4fdd\u5b88\u7d42\u4e86\u3057\u305f\u6697\u53f7\u5316\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3068\u3057\u3066\u6271\u308f\u308c\u308b\u3088\u3046\u306b\u306a\u3063\u305f<a href=\"#ref9\">[9]<\/a>\u3002<\/p>\n<p>\u3057\u304b\u3057\u3001\u4fdd\u5b88\u7d42\u4e86\u3057\u305f\u3053\u3068\u3068\u3001\u904e\u53bb\u306b\u4f5c\u3089\u308c\u305f\u6697\u53f7\u5316\u8cc7\u7523\u304c\u6d88\u3048\u308b\u3053\u3068\u306f\u540c\u3058\u3067\u306f\u306a\u3044\u3002\u904e\u53bb\u306b TrueCrypt 7.1a \u3067\u4f5c\u3063\u305f\u30d5\u30a1\u30a4\u30eb\u30b3\u30f3\u30c6\u30ca\u30fc\u3001\u5916\u4ed8\u3051 HDD\u3001\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u5a92\u4f53\u3001\u9000\u5f79\u30c7\u30a3\u30b9\u30af\u306f\u3001\u4e16\u754c\u4e2d\u306b\u6b8b\u3063\u3066\u3044\u308b\u3002\u500b\u4eba\u306e\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3060\u3051\u3067\u306a\u304f\u3001\u7814\u7a76\u6a5f\u95a2\u306e\u53e4\u3044\u5a92\u4f53\u3001\u4f01\u696d\u306e\u4fdd\u7ba1\u30c7\u30a3\u30b9\u30af\u3001\u6cd5\u52d9\u30fb\u76e3\u67fb\u30fb\u30d5\u30a9\u30ec\u30f3\u30b8\u30c3\u30af\u7528\u9014\u306e\u53d6\u5f97\u30a4\u30e1\u30fc\u30b8\u306b\u3082\u3001\u53e4\u3044\u6697\u53f7\u5316\u5f62\u5f0f\u306f\u6b8b\u308a\u5f97\u308b\u3002<\/p>\n<p>\u6697\u53f7\u5316\u3057\u3066\u3044\u306a\u3044\u30d5\u30a1\u30a4\u30eb\u3067\u3042\u308c\u3070\u3001\u53e4\u3044\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u306a\u304f\u3066\u3082\u3001\u30d5\u30a1\u30a4\u30eb\u5f62\u5f0f\u3092\u89e3\u6790\u3057\u305f\u308a\u3001\u90e8\u5206\u7684\u306b\u5fa9\u65e7\u3057\u305f\u308a\u3067\u304d\u308b\u5834\u5408\u304c\u3042\u308b\u3002\u6697\u53f7\u5316\u30d6\u30ed\u30c3\u30af\u30c7\u30d0\u30a4\u30b9\u3067\u306f\u4e8b\u60c5\u304c\u9055\u3046\u3002\u30d8\u30c3\u30c0\u30fc\u5f62\u5f0f\u3001\u9375\u5c0e\u51fa\u65b9\u5f0f\u3001\u6697\u53f7\u65b9\u5f0f\u3001\u30c7\u30fc\u30bf offset\u3001sector size \u304c\u5206\u304b\u3089\u306a\u3051\u308c\u3070\u3001\u30c7\u30a3\u30b9\u30af\u4e0a\u306e byte \u5217\u306f\u9589\u3058\u305f\u307e\u307e\u3067\u3042\u308b\u3002\u5a92\u4f53\u304c\u751f\u304d\u3066\u3044\u3066\u3082\u3001\u5f62\u5f0f\u3092\u958b\u304f\u5b9f\u88c5\u304c\u5931\u308f\u308c\u308c\u3070\u3001\u30c7\u30fc\u30bf\u306f\u5b9f\u8cea\u7684\u306b\u5931\u308f\u308c\u308b\u3002<\/p>\n<p>\u3057\u305f\u304c\u3063\u3066\u3001\u53e4\u3044\u6697\u53f7\u5316\u5f62\u5f0f\u306b\u5bfe\u3059\u308b\u4e92\u63db\u30b3\u30fc\u30c9\u306f\u3001\u5358\u306a\u308b\u61d0\u53e4\u3067\u306f\u306a\u3044\u3002\u65b0\u898f\u5229\u7528\u3092\u63a8\u5968\u3057\u306a\u3044\u5f62\u5f0f\u3067\u3042\u3063\u3066\u3082\u3001\u904e\u53bb\u8cc7\u7523\u3078\u5230\u9054\u3059\u308b\u305f\u3081\u306e\u51fa\u53e3\u3068\u3057\u3066\u610f\u5473\u3092\u6301\u3064\u3002\u3053\u3053\u3067\u91cd\u8981\u306a\u306e\u306f\u3001\u53e4\u3044\u5f62\u5f0f\u3092\u4e3b\u7cfb\u306b\u623b\u3059\u3053\u3068\u3067\u306f\u306a\u3044\u3002\u53e4\u3044\u5f62\u5f0f\u3092\u8aad\u307f\u53d6\u308a\u4e2d\u5fc3\u306e\u4e92\u63db\u7d4c\u8def\u3078\u79fb\u3057\u3001\u5fc5\u8981\u306a\u671f\u9593\u3060\u3051\u7ba1\u7406\u3057\u3001\u79fb\u884c\u304c\u7d42\u308f\u3063\u305f\u6642\u70b9\u3067\u9000\u5f79\u3055\u305b\u308b\u3053\u3068\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>2. TCRYPT \u4e92\u63db\u306f LUKS \u306e\u4e00\u90e8\u3067\u306f\u306a\u304f\u3001cryptsetup \u306e\u5f62\u5f0f\u30cf\u30f3\u30c9\u30e9\u3067\u3042\u308b<\/h2>\n<p>TCRYPT \u4e92\u63db\u306b\u3064\u3044\u3066\u8a9e\u308b\u3068\u304d\u3001\u307e\u305a\u7528\u8a9e\u3092\u88dc\u6b63\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002\u3053\u308c\u306f LUKS \u306b\u30de\u30fc\u30b8\u3055\u308c\u305f\u6a5f\u80fd\u3067\u306f\u306a\u3044\u3002cryptsetup \/ libcryptsetup \u306b\u542b\u307e\u308c\u308b TCRYPT \/ VeraCrypt \u5f62\u5f0f\u5bfe\u5fdc\u30b3\u30fc\u30c9\u3067\u3042\u308b\u3002LUKS1 \/ LUKS2 \u306f cryptsetup \u304c\u6271\u3046\u4e2d\u5fc3\u7684\u306a\u6697\u53f7\u5316\u30e1\u30bf\u30c7\u30fc\u30bf\u5f62\u5f0f\u3060\u304c\u3001cryptsetup \u304c\u6271\u3046\u5f62\u5f0f\u306f LUKS \u3060\u3051\u3067\u306f\u306a\u3044\u3002<\/p>\n<p>cryptsetup \u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306f\u3001dm-crypt kernel module \u306b\u57fa\u3065\u304f\u30c7\u30a3\u30b9\u30af\u6697\u53f7\u5316\u3092\u6271\u3046\u305f\u3081\u306e open-source utility \u3067\u3042\u308a\u3001plain volumes\u3001LUKS volumes\u3001loop-AES\u3001TrueCrypt including VeraCrypt extension\u3001BitLocker\u3001FileVault2 \u3092 supported formats \u3068\u3057\u3066\u6319\u3052\u3066\u3044\u308b<a href=\"#ref10\">[10]<\/a>\u3002\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u69cb\u6210\u8aac\u660e\u3067\u3082\u3001lib\/tcrypt \u306f TrueCrypt \/ VeraCrypt format \u306e\u5b9f\u88c5\u3068\u3057\u3066\u4f4d\u7f6e\u3065\u3051\u3089\u308c\u308b<a href=\"#ref11\">[11]<\/a>\u3002<\/p>\n<p>\u898b\u304b\u3051\u4e0a\u306f\u3001\u540c\u3058 cryptsetup \u30b3\u30de\u30f3\u30c9\u3067 LUKS \u3082 TCRYPT \u3082\u6271\u3048\u308b\u305f\u3081\u3001TCRYPT \u304c LUKS \u306e\u5185\u90e8\u6a5f\u80fd\u3067\u3042\u308b\u3088\u3046\u306b\u898b\u3048\u3084\u3059\u3044\u3002\u3057\u304b\u3057\u5185\u90e8\u69cb\u9020\u3068\u3057\u3066\u306f\u3001LUKS \u30e1\u30bf\u30c7\u30fc\u30bf\u51e6\u7406\u3068 TCRYPT \u30e1\u30bf\u30c7\u30fc\u30bf\u51e6\u7406\u306f\u5225\u306e\u5f62\u5f0f\u30cf\u30f3\u30c9\u30e9\u3067\u3042\u308b\u3002cryptsetup \u306f\u3001Linux \u306e\u6697\u53f7\u5316\u30d6\u30ed\u30c3\u30af\u30c7\u30d0\u30a4\u30b9\u3092\u6271\u3046\u5165\u53e3\u3068\u3057\u3066\u8907\u6570\u5f62\u5f0f\u3092\u675f\u306d\u3066\u3044\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u5bfe\u8c61<\/th>\n<th>\u4f4d\u7f6e\u3065\u3051<\/th>\n<th>\u672c\u7a3f\u3067\u306e\u6271\u3044<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>LUKS1 \/ LUKS2<\/td>\n<td>Linux \u3067\u5e83\u304f\u4f7f\u308f\u308c\u308b\u6697\u53f7\u5316\u30e1\u30bf\u30c7\u30fc\u30bf\u5f62\u5f0f\u3067\u3042\u308a\u3001cryptsetup \u306e\u4e2d\u5fc3\u7684\u5bfe\u8c61\u3067\u3042\u308b\u3002<\/td>\n<td>\u672c\u7a3f\u3067\u306f\u4e3b\u7cfb\u904b\u7528\u306e\u6bd4\u8f03\u5bfe\u8c61\u3068\u3057\u3066\u6271\u3046\u3002<\/td>\n<\/tr>\n<tr>\n<td>TCRYPT \/ VeraCrypt<\/td>\n<td>TrueCrypt \/ VeraCrypt \u7531\u6765\u306e\u6697\u53f7\u5316\u5f62\u5f0f\u3067\u3042\u308a\u3001cryptsetup \u3067\u306f\u5225\u5f62\u5f0f\u3068\u3057\u3066\u6271\u308f\u308c\u308b\u3002<\/td>\n<td>\u672c\u7a3f\u306e\u4e3b\u5bfe\u8c61\u3067\u3042\u308a\u3001\u4e92\u63db\u30b3\u30fc\u30c9\u306e\u8a2d\u8a08\u3092\u8aad\u3080\u3002<\/td>\n<\/tr>\n<tr>\n<td>dm-crypt<\/td>\n<td>Linux kernel \u5074\u3067 block device \u306e\u6697\u53f7\u5316 mapping \u3092\u63d0\u4f9b\u3059\u308b\u57fa\u76e4\u3067\u3042\u308b\u3002<\/td>\n<td>TCRYPT \u5f62\u5f0f\u304b\u3089\u53d6\u308a\u51fa\u3057\u305f\u60c5\u5831\u306e\u63a5\u7d9a\u5148\u3068\u3057\u3066\u6271\u3046\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u306e\u533a\u5225\u306f\u3001\u904b\u7528\u5224\u65ad\u3067\u3082\u91cd\u8981\u3067\u3042\u308b\u3002LUKS \u3092\u4e3b\u7cfb\u306b\u3059\u308b\u3053\u3068\u3068\u3001TCRYPT \u65e2\u5b58\u8cc7\u7523\u3092 cryptsetup \u304b\u3089\u8aad\u3081\u308b\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u306f\u77db\u76fe\u3057\u306a\u3044\u3002\u524d\u8005\u306f\u73fe\u5728\u4ee5\u964d\u306e\u6a19\u6e96\u5f62\u5f0f\u3092\u6c7a\u3081\u308b\u8a71\u3067\u3042\u308a\u3001\u5f8c\u8005\u306f\u904e\u53bb\u8cc7\u7523\u3078\u306e\u5230\u9054\u53ef\u80fd\u6027\u3092\u7dad\u6301\u3059\u308b\u8a71\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>3. \u306a\u305c\u3001\u3053\u306e\u3088\u3046\u306a\u30cb\u30c3\u30c1\u306a\u4e92\u63db\u30b3\u30fc\u30c9\u304c\u4fdd\u5b88\u3055\u308c\u3066\u3044\u308b\u306e\u304b<\/h2>\n<p>cryptsetup \u306e man page \u306f\u3001TCRYPT \u306b\u3064\u3044\u3066\u91cd\u8981\u306a\u5883\u754c\u3092\u793a\u3057\u3066\u3044\u308b\u3002cryptsetup \u306f TrueCrypt\u3001tcplay\u3001VeraCrypt \u6697\u53f7\u5316\u30d1\u30fc\u30c6\u30a3\u30b7\u30e7\u30f3\u3092 Linux kernel API \u3067 mapping \u3067\u304d\u308b\u4e00\u65b9\u3067\u3001TCRYPT \u30d8\u30c3\u30c0\u30fc\u306e\u751f\u6210\u3084\u5909\u66f4\u3092\u30b5\u30dd\u30fc\u30c8\u305b\u305a\u3001device \u4e0a\u306e TCRYPT \u30d8\u30c3\u30c0\u30fc\u3092\u66f8\u304d\u63db\u3048\u306a\u3044<a href=\"#ref12\">[12]<\/a>\u3002\u3053\u308c\u306f\u3001TCRYPT \u5bfe\u5fdc\u304c\u65b0\u898f\u4f5c\u6210\u6a5f\u80fd\u3067\u306f\u306a\u304f\u3001\u65e2\u5b58\u30dc\u30ea\u30e5\u30fc\u30e0\u3092\u958b\u304f\u305f\u3081\u306e\u4e92\u63db\u6a5f\u80fd\u3068\u3057\u3066\u8a2d\u8a08\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u308b\u3002<\/p>\n<p>\u3053\u306e\u3088\u3046\u306a\u4e92\u63db\u30b3\u30fc\u30c9\u304c\u4fdd\u5b88\u3055\u308c\u308b\u7406\u7531\u306f\u3001\u6697\u53f7\u5316\u8cc7\u7523\u306e\u6027\u8cea\u306b\u3042\u308b\u3002\u6697\u53f7\u5316\u30b9\u30c8\u30ec\u30fc\u30b8\u3067\u306f\u3001\u30c7\u30fc\u30bf\u3001\u9375\u3001\u5f62\u5f0f\u3001\u5b9f\u88c5\u304c\u305d\u308d\u3063\u3066\u521d\u3081\u3066\u5fa9\u5143\u3067\u304d\u308b\u3002TrueCrypt \u304c\u4fdd\u5b88\u7d42\u4e86\u3057\u3066\u3082\u3001\u904e\u53bb\u306b\u4f5c\u3089\u308c\u305f\u6697\u53f7\u5316\u5a92\u4f53\u306f\u6b8b\u308b\u3002\u305d\u306e\u5a92\u4f53\u304c\u5fc5\u8981\u306b\u306a\u308b\u5834\u9762\u306f\u3001\u65e5\u5e38\u7684\u3067\u306f\u306a\u3044\u304b\u3082\u3057\u308c\u306a\u3044\u3002\u3057\u304b\u3057\u3001\u5fc5\u8981\u306b\u306a\u3063\u305f\u3068\u304d\u306b\u4ee3\u66ff\u304c\u52b9\u304d\u306b\u304f\u3044\u3002<\/p>\n<p>\u3053\u3053\u3067\u306e\u30cb\u30c3\u30c1\u3055\u306f\u3001\u8da3\u5473\u7684\u306a\u5e0c\u5c11\u6027\u3067\u306f\u306a\u3044\u3002\u9000\u5f79\u5a92\u4f53\u3001\u9577\u671f\u4fdd\u7ba1\u5a92\u4f53\u3001\u53e4\u3044\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3001\u8abf\u67fb\u5bfe\u8c61\u30c7\u30a3\u30b9\u30af\u3001\u7814\u7a76\u30c7\u30fc\u30bf\u306e\u3088\u3046\u306b\u3001\u666e\u6bb5\u306f\u76ee\u7acb\u305f\u306a\u3044\u304c\u5931\u308f\u308c\u308b\u3068\u56f0\u308b\u9818\u57df\u306e\u30cb\u30c3\u30c1\u3067\u3042\u308b\u3002\u6697\u53f7\u5316\u5a92\u4f53\u3067\u306f\u3001\u5f62\u5f0f\u3092\u8aad\u3081\u306a\u3044\u3053\u3068\u304c\u3001\u30c7\u30fc\u30bf\u6d88\u5931\u3068\u307b\u307c\u540c\u3058\u610f\u5473\u3092\u6301\u3064\u3002\u3057\u305f\u304c\u3063\u3066\u3001\u4e92\u63db\u30b3\u30fc\u30c9\u306f\u904e\u53bb\u8cc7\u7523\u306e\u6551\u6e08\u7d4c\u8def\u306b\u306a\u308b\u3002<\/p>\n<p>\u305f\u3060\u3057\u3001\u4e92\u63db\u30b3\u30fc\u30c9\u304c\u5b58\u5728\u3059\u308b\u3053\u3068\u306f\u3001\u305d\u306e\u5f62\u5f0f\u3092\u65b0\u898f\u4e3b\u7cfb\u3068\u3057\u3066\u4f7f\u3044\u7d9a\u3051\u308b\u7406\u7531\u306b\u306f\u306a\u3089\u306a\u3044\u3002cryptsetup \u304c TCRYPT \u3092 open \u3067\u304d\u308b\u3053\u3068\u3068\u3001TrueCrypt \/ VeraCrypt \u3092\u6a19\u6e96\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b\u5165\u308c\u7d9a\u3051\u308b\u3053\u3068\u306f\u5225\u3067\u3042\u308b\u3002\u4e92\u63db\u6027\u306f\u3001\u63a8\u5968\u3067\u306f\u306a\u3044\u3002\u3053\u306e\u5207\u308a\u5206\u3051\u304c\u3001\u672c\u7a3f\u5168\u4f53\u306e\u57fa\u790e\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>4. tcrypt.c \u306f\u77ed\u304f\u898b\u3048\u308b\u304c\u3001\u6697\u53f7\u5316\u51e6\u7406\u3092\u5168\u90e8\u66f8\u3044\u3066\u3044\u308b\u308f\u3051\u3067\u306f\u306a\u3044<\/h2>\n<p>lib\/tcrypt\/tcrypt.c \u3092\u898b\u308b\u3068\u3001\u4e3b\u8981\u6a5f\u80fd\u304c\u610f\u5916\u306b\u77ed\u3044\u7bc4\u56f2\u306b\u53ce\u307e\u3063\u3066\u3044\u308b\u3088\u3046\u306b\u898b\u3048\u308b\u3002\u3057\u304b\u3057\u3001\u305d\u3053\u3067\u6697\u53f7\u5316\u30b9\u30c8\u30ec\u30fc\u30b8\u306e\u5168\u6a5f\u80fd\u3092\u81ea\u524d\u5b9f\u88c5\u3057\u3066\u3044\u308b\u308f\u3051\u3067\u306f\u306a\u3044\u3002tcrypt.c \u304c\u62c5\u3063\u3066\u3044\u308b\u306e\u306f\u3001TCRYPT \/ VeraCrypt \u5f62\u5f0f\u306e\u30d8\u30c3\u30c0\u30fc\u3092\u8aad\u307f\u3001KDF \u3068 cipher \u306e\u5019\u88dc\u3092\u8a66\u3057\u3001\u5fa9\u53f7\u6e08\u307f\u30d8\u30c3\u30c0\u30fc\u304b\u3089\u5fc5\u8981\u306a\u30d1\u30e9\u30e1\u30fc\u30bf\u3092\u53d6\u308a\u51fa\u3057\u3001cryptsetup \u306e\u5171\u901a\u5c64\u3068 dm-crypt \u3078\u6e21\u3059\u3053\u3068\u3067\u3042\u308b\u3002<\/p>\n<p>VeraCrypt \u306e\u6280\u8853\u8aac\u660e\u3067\u306f\u3001\u6a19\u6e96 volume header \u306e\u5fa9\u53f7\u6642\u306b\u3001KDF \u3068\u95a2\u9023\u30d1\u30e9\u30e1\u30fc\u30bf\u3001\u6697\u53f7\u65b9\u5f0f\u3001mode \u306a\u3069\u304c\u672a\u77e5\u3067\u3042\u308a\u3001\u53ef\u80fd\u306a\u7d44\u307f\u5408\u308f\u305b\u3092\u8a66\u3059\u5fc5\u8981\u304c\u3042\u308b\u3068\u8aac\u660e\u3055\u308c\u3066\u3044\u308b<a href=\"#ref13\">[13]<\/a>\u3002cryptsetup \u306e tcrypt.c \u3082\u540c\u3058\u554f\u984c\u3092\u5b9f\u88c5\u4e0a\u306e\u69cb\u9020\u3068\u3057\u3066\u6301\u3064\u3002\u3064\u307e\u308a\u3001\u30d8\u30c3\u30c0\u30fc\u304c\u5fa9\u53f7\u3055\u308c\u308b\u307e\u3067\u3001\u3069\u306e\u65b9\u5f0f\u3067\u4f5c\u3089\u308c\u305f volume \u306a\u306e\u304b\u306f\u78ba\u5b9a\u3057\u306a\u3044\u3002<\/p>\n<p>\u3053\u306e\u305f\u3081\u3001tcrypt.c \u306f KDF \u5019\u88dc\u30c6\u30fc\u30d6\u30eb\u3068 cipher \u5019\u88dc\u30c6\u30fc\u30d6\u30eb\u3092\u6301\u3064\u3002\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3068 keyfile \u304b\u3089\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u3092\u5c0e\u51fa\u3057\u3001\u5019\u88dc\u3068\u306a\u308b cipher chain \u3068 mode \u3067\u30d8\u30c3\u30c0\u30fc\u3092\u5fa9\u53f7\u3057\u3001magic \u3068 CRC \u304c\u6b63\u3057\u3044\u304b\u3092\u78ba\u8a8d\u3059\u308b\u3002\u6b63\u3057\u3044\u7d44\u307f\u5408\u308f\u305b\u304c\u898b\u3064\u304b\u308b\u3068\u3001master key\u3001data offset\u3001volume size\u3001sector size \u306a\u3069\u3092\u53d6\u308a\u51fa\u3057\u3001dm-crypt mapping \u306b\u5fc5\u8981\u306a\u60c5\u5831\u3078\u5909\u63db\u3059\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u51e6\u7406<\/th>\n<th>tcrypt.c \u306e\u8cac\u52d9<\/th>\n<th>\u59d4\u8b72\u5148<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u89e3\u91c8<\/td>\n<td>TCRYPT \/ VeraCrypt \u56fa\u6709\u306e\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u3001backup header\u3001hidden volume\u3001system encryption \u3092\u6271\u3046\u3002<\/td>\n<td>\u5f62\u5f0f\u56fa\u6709\u51e6\u7406\u306a\u306e\u3067 tcrypt.c \u304c\u4e2d\u5fc3\u3068\u306a\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u9375\u5c0e\u51fa\u5019\u88dc<\/td>\n<td>PBKDF\u3001hash\u3001iteration count\u3001VeraCrypt PIM \u306e\u5019\u88dc\u3092\u9078\u3073\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u3092\u5c0e\u304f\u3002<\/td>\n<td>\u5b9f\u969b\u306e crypto backend \u306f cryptsetup \u5171\u901a\u5c64\u306b\u59d4\u8b72\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u6697\u53f7\u65b9\u5f0f\u5019\u88dc<\/td>\n<td>AES\u3001Serpent\u3001Twofish \u306a\u3069\u306e cipher chain \u3068 mode \u5019\u88dc\u3092\u8a66\u3059\u3002<\/td>\n<td>\u6697\u53f7\u30d7\u30ea\u30df\u30c6\u30a3\u30d6\u305d\u306e\u3082\u306e\u306f backend \u3068 kernel \u5074\u306b\u59d4\u8b72\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>block device \u5316<\/td>\n<td>\u30d8\u30c3\u30c0\u30fc\u304b\u3089\u53d6\u308a\u51fa\u3057\u305f\u60c5\u5831\u3092 dm-crypt \u7528\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u3078\u5909\u63db\u3059\u308b\u3002<\/td>\n<td>device-mapper table \u3068\u5b9f\u969b\u306e I\/O \u306f dm-crypt \u304c\u62c5\u3046\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u306e\u8cac\u52d9\u5206\u96e2\u306b\u3088\u308a\u3001\u898b\u305f\u76ee\u3088\u308a\u5c11\u306a\u3044\u30b3\u30fc\u30c9\u3067\u5e83\u3044\u4e92\u63db\u6027\u304c\u5b9f\u73fe\u3055\u308c\u308b\u3002tcrypt.c \u306f TrueCrypt \/ VeraCrypt \u5168\u4f53\u3092\u518d\u5b9f\u88c5\u3057\u3066\u3044\u308b\u306e\u3067\u306f\u306a\u304f\u3001\u5f62\u5f0f\u56fa\u6709\u306e\u77e5\u8b58\u3092 cryptsetup \u306e\u65e2\u5b58\u57fa\u76e4\u3078\u63a5\u7d9a\u3059\u308b adapter \u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>5. \u4fdd\u5b88\u4e3b\u4f53\u3068\u30e9\u30a4\u30bb\u30f3\u30b9\u3092\u898b\u308b<\/h2>\n<p>\u4e92\u63db\u30b3\u30fc\u30c9\u3092\u9577\u671f\u904b\u7528\u4e0a\u306e\u6839\u62e0\u3068\u3057\u3066\u898b\u308b\u306a\u3089\u3001\u6a5f\u80fd\u3060\u3051\u3067\u306a\u304f\u3001\u4fdd\u5b88\u4e3b\u4f53\u3068\u30e9\u30a4\u30bb\u30f3\u30b9\u3082\u78ba\u8a8d\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002cryptsetup \u306e SECURITY.md \u3067\u306f current maintainer \u304c Milan Broz \u3067\u3042\u308b\u3068\u793a\u3055\u308c\u3066\u3044\u308b<a href=\"#ref14\">[14]<\/a>\u3002Milan Bro\u017e \u306f Red Hat Research \u306e profile \u3067\u3082 full disk encryption \u3084 cryptsetup \/ LUKS \u306a\u3069\u306b\u95a2\u308f\u308b\u4eba\u7269\u3068\u3057\u3066\u7d39\u4ecb\u3055\u308c\u3066\u3044\u308b<a href=\"#ref15\">[15]<\/a>\u3002<\/p>\n<p>tcrypt.c \u306e\u30d5\u30a1\u30a4\u30eb\u5192\u982d\u306b\u306f\u3001SPDX-License-Identifier: LGPL-2.1-or-later \u3068\u3001TCRYPT TrueCrypt-compatible and VeraCrypt volume handling \u3068\u3044\u3046\u8aac\u660e\u304c\u3042\u308b\u3002\u8457\u4f5c\u6a29\u8868\u8a18\u306f 2012-2026 Red Hat, Inc. \u3068 2012-2026 Milan Broz \u3067\u3042\u308b<a href=\"#ref16\">[16]<\/a>\u3002\u3064\u307e\u308a\u3001\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u5358\u4f4d\u3067\u306f LGPL-2.1-or-later \u306e\u30b3\u30fc\u30c9\u3068\u3057\u3066\u7f6e\u304b\u308c\u3066\u3044\u308b\u3002<\/p>\n<p>\u4e00\u65b9\u3067\u3001cryptsetup \u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u5168\u4f53\u306f\u5358\u4e00\u30e9\u30a4\u30bb\u30f3\u30b9\u3067\u306f\u306a\u3044\u3002README.licensing \u306f\u3001\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u5185\u306b GPL-2.0-or-later\u3001LGPL-2.1-or-later\u3001OpenSSL exception \u4ed8\u304d LGPL\u3001Apache-2.0\u3001CC-BY-SA-4.0\u3001Public Domain \u306a\u3069\u304c\u6df7\u5728\u3059\u308b\u3053\u3068\u3092\u793a\u3059<a href=\"#ref17\">[17]<\/a>\u3002SPDX \u306e LGPL-2.1-or-later \u306f\u3001GNU Lesser General Public License version 2.1 or later \u3092\u8868\u3059\u8b58\u5225\u5b50\u3067\u3042\u308b<a href=\"#ref18\">[18]<\/a>\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u89b3\u70b9<\/th>\n<th>\u78ba\u8a8d\u3067\u304d\u308b\u5185\u5bb9<\/th>\n<th>\u672c\u7a3f\u3067\u306e\u610f\u5473<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u4fdd\u5b88\u4e3b\u4f53<\/td>\n<td>cryptsetup upstream \u306e current maintainer \u3068\u3057\u3066 Milan Broz \u304c\u793a\u3055\u308c\u3066\u3044\u308b\u3002<\/td>\n<td>\u30cb\u30c3\u30c1\u306a\u4e92\u63db\u6a5f\u80fd\u3067\u3042\u3063\u3066\u3082\u3001upstream \u306e\u7ba1\u7406\u4e0b\u306b\u3042\u308b\u5b9f\u88c5\u3068\u3057\u3066\u6271\u3048\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d5\u30a1\u30a4\u30eb\u5358\u4f4d\u30e9\u30a4\u30bb\u30f3\u30b9<\/td>\n<td>tcrypt.c \u306b\u306f LGPL-2.1-or-later \u306e SPDX \u8868\u8a18\u304c\u3042\u308b\u3002<\/td>\n<td>\u5f53\u8a72\u30d5\u30a1\u30a4\u30eb\u306f libcryptsetup \u5074\u306e\u30e9\u30a4\u30d6\u30e9\u30ea\u5b9f\u88c5\u3068\u3057\u3066\u898b\u308b\u306e\u304c\u81ea\u7136\u3067\u3042\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u5168\u4f53<\/td>\n<td>cryptsetup \u5168\u4f53\u306f\u30d5\u30a1\u30a4\u30eb\u3054\u3068\u306e\u6df7\u5728\u30e9\u30a4\u30bb\u30f3\u30b9\u3067\u69cb\u6210\u3055\u308c\u308b\u3002<\/td>\n<td>\u5168\u4f53\u3092\u5358\u4e00\u30e9\u30a4\u30bb\u30f3\u30b9\u3060\u3051\u3067\u5358\u7d14\u5316\u305b\u305a\u3001\u30d5\u30a1\u30a4\u30eb\u5358\u4f4d\u306e\u8868\u8a18\u3092\u898b\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u3053\u304b\u3089\u5206\u304b\u308b\u306e\u306f\u3001tcrypt.c \u304c\u5358\u306a\u308b\u91ce\u826f\u4e92\u63db\u30b3\u30fc\u30c9\u3067\u306f\u306a\u3044\u3068\u3044\u3046\u3053\u3068\u3067\u3042\u308b\u3002\u53e4\u3044\u6697\u53f7\u5316\u5f62\u5f0f\u306e\u5230\u9054\u53ef\u80fd\u6027\u3092\u652f\u3048\u308b\u30b3\u30fc\u30c9\u304c\u3001cryptsetup upstream \u306e\u4e2d\u3067\u3001\u660e\u793a\u7684\u306a\u30e9\u30a4\u30bb\u30f3\u30b9\u8868\u793a\u3092\u6301\u3063\u3066\u4fdd\u5b88\u3055\u308c\u3066\u3044\u308b\u3002\u3053\u306e\u4e8b\u5b9f\u306f\u3001\u9577\u671f\u904b\u7528\u3067\u305d\u306e\u4e92\u63db\u7d4c\u8def\u3092\u3069\u3046\u6271\u3046\u304b\u3092\u8003\u3048\u308b\u3046\u3048\u3067\u91cd\u8981\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>6. tcrypt.c \u306e\u5168\u4f53\u50cf<\/h2>\n<p>tcrypt.c \u306e\u51e6\u7406\u306f\u3001\u30d8\u30c3\u30c0\u30fc\u3092\u8aad\u3080\u3001\u5019\u88dc\u3092\u8a66\u3059\u3001\u6b63\u3057\u3044\u7d44\u307f\u5408\u308f\u305b\u3092\u898b\u3064\u3051\u308b\u3001dm-crypt \u306b\u6e21\u3059\u3001\u3068\u3044\u3046\u6d41\u308c\u3067\u7406\u89e3\u3067\u304d\u308b\u3002cryptsetup \u306e lib\/setup.c \u3067\u306f\u3001TCRYPT \u306f LUKS\u3001plain\u3001loop-AES\u3001BitLocker\u3001FileVault2 \u306a\u3069\u3068\u4e26\u3076\u5f62\u5f0f\u306e\u4e00\u3064\u3068\u3057\u3066\u6271\u308f\u308c\u308b<a href=\"#ref19\">[19]<\/a>\u3002\u3057\u305f\u304c\u3063\u3066\u3001tcrypt.c \u306f cryptsetup \u306e\u4e2d\u3067 TCRYPT \/ VeraCrypt \u5f62\u5f0f\u3092\u62c5\u5f53\u3059\u308b\u90e8\u54c1\u3067\u3042\u308b\u3002<\/p>\n<p>\u51e6\u7406\u306e\u5165\u53e3\u3067\u306f\u3001\u901a\u5e38\u30d8\u30c3\u30c0\u30fc\u3001backup header\u3001hidden volume header\u3001system encryption header \u306e\u3044\u305a\u308c\u3092\u8aad\u3080\u304b\u304c\u6c7a\u307e\u308b\u3002\u6b21\u306b\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3068 keyfile \u304b\u3089 key pool \u3092\u4f5c\u308a\u3001KDF \u5019\u88dc\u3092\u9806\u306b\u8a66\u3059\u3002KDF \u5019\u88dc\u306b\u3088\u308a\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u304c\u5c0e\u51fa\u3055\u308c\u308b\u3068\u3001cipher \u5019\u88dc\u3092\u9806\u306b\u8a66\u3057\u3001\u5fa9\u53f7\u7d50\u679c\u306b\u6b63\u3057\u3044 magic \u304c\u3042\u308b\u304b\u3092\u8abf\u3079\u308b\u3002\u3055\u3089\u306b CRC \u306b\u3088\u308a\u3001\u5fa9\u53f7\u7d50\u679c\u304c\u5076\u7136\u305d\u308c\u3089\u3057\u304f\u898b\u3048\u305f\u3060\u3051\u3067\u306f\u306a\u3044\u3053\u3068\u3092\u691c\u8a3c\u3059\u308b\u3002<\/p>\n<p>\u3053\u306e\u51e6\u7406\u306f\u3001\u6697\u53f7\u5316\u30d8\u30c3\u30c0\u30fc\u304c\u6301\u3064\u6839\u672c\u7684\u306a\u5faa\u74b0\u3092\u89e3\u304f\u305f\u3081\u306e\u3082\u306e\u3067\u3042\u308b\u3002\u5f62\u5f0f\u60c5\u5831\u3092\u77e5\u308b\u306b\u306f\u30d8\u30c3\u30c0\u30fc\u3092\u8aad\u3080\u5fc5\u8981\u304c\u3042\u308b\u3002\u3057\u304b\u3057\u30d8\u30c3\u30c0\u30fc\u3092\u8aad\u3080\u306b\u306f\u3001\u5f62\u5f0f\u60c5\u5831\u306e\u5019\u88dc\u3092\u5148\u306b\u8a66\u3059\u5fc5\u8981\u304c\u3042\u308b\u3002tcrypt.c \u306f\u3001\u3053\u306e\u5faa\u74b0\u3092\u5019\u88dc\u63a2\u7d22\u306b\u3088\u3063\u3066\u89e3\u6c7a\u3059\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u6bb5\u968e<\/th>\n<th>\u4ee3\u8868\u7684\u306a\u51e6\u7406<\/th>\n<th>\u610f\u5473<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u8aad\u307f\u53d6\u308a<\/td>\n<td>TCRYPT_read_phdr \u304c flags \u306b\u5fdc\u3058\u3066\u901a\u5e38\u3001hidden\u3001backup\u3001system \u306e\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u3092\u9078\u3076\u3002<\/td>\n<td>\u3069\u306e\u5834\u6240\u306b\u3042\u308b\u30e1\u30bf\u30c7\u30fc\u30bf\u3092\u8aad\u3080\u304b\u3092\u6c7a\u3081\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u521d\u671f\u5316\u3068 KDF \u63a2\u7d22<\/td>\n<td>TCRYPT_init_hdr \u304c\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3001keyfile\u3001PIM\u3001KDF \u5019\u88dc\u3092\u6271\u3046\u3002<\/td>\n<td>\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306b\u5fc5\u8981\u306a\u9375\u306e\u5019\u88dc\u3092\u4f5c\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>cipher \u63a2\u7d22<\/td>\n<td>TCRYPT_decrypt_hdr \u304c cipher chain \u3068 mode \u306e\u5019\u88dc\u3092\u8a66\u3059\u3002<\/td>\n<td>\u6b63\u3057\u3044\u6697\u53f7\u65b9\u5f0f\u3067\u30d8\u30c3\u30c0\u30fc\u304c\u5fa9\u53f7\u3067\u304d\u308b\u304b\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u691c\u8a3c<\/td>\n<td>TCRYPT_hdr_from_disk \u304c magic\u3001CRC\u3001size\u3001offset\u3001sector size \u3092\u78ba\u8a8d\u3059\u308b\u3002<\/td>\n<td>\u5fa9\u53f7\u7d50\u679c\u304c\u59a5\u5f53\u306a TCRYPT \/ VeraCrypt \u30d8\u30c3\u30c0\u30fc\u304b\u3092\u5224\u65ad\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u6709\u52b9\u5316<\/td>\n<td>TCRYPT_activate \u304c dm-crypt mapping \u306b\u5fc5\u8981\u306a\u60c5\u5831\u3092\u69cb\u6210\u3059\u308b\u3002<\/td>\n<td>\u5fa9\u53f7\u6e08\u307f block device \u3068\u3057\u3066\u6271\u3048\u308b\u3088\u3046\u306b\u3059\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u306e\u69cb\u9020\u3092\u62bc\u3055\u3048\u308b\u3068\u3001tcrypt.c \u306e\u8aad\u307f\u65b9\u304c\u5909\u308f\u308b\u3002\u500b\u3005\u306e\u95a2\u6570\u540d\u3092\u8ffd\u3046\u524d\u306b\u3001\u3069\u306e\u95a2\u6570\u304c\u5f62\u5f0f\u60c5\u5831\u3092\u8aad\u3080\u306e\u304b\u3001\u3069\u306e\u95a2\u6570\u304c\u5019\u88dc\u3092\u8a66\u3059\u306e\u304b\u3001\u3069\u306e\u95a2\u6570\u304c\u691c\u8a3c\u3059\u308b\u306e\u304b\u3001\u3069\u306e\u95a2\u6570\u304c Linux kernel \u5074\u3078\u6e21\u3059\u306e\u304b\u3092\u898b\u308b\u3079\u304d\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>7. KDF \u5019\u88dc\u3068 cipher \u5019\u88dc\u306f\u3001\u5f62\u5f0f\u4e92\u63db\u6027\u306e\u4e2d\u5fc3\u3067\u3042\u308b<\/h2>\n<p>TCRYPT \/ VeraCrypt \u4e92\u63db\u306e\u96e3\u3057\u3055\u306f\u3001\u5358\u4e00\u306e\u6697\u53f7\u65b9\u5f0f\u306b\u5bfe\u5fdc\u3059\u308c\u3070\u7d42\u308f\u308b\u70b9\u306b\u306f\u306a\u3044\u3002TrueCrypt \u3068 VeraCrypt \u3067\u306f\u3001\u6642\u4ee3\u3001\u8a2d\u5b9a\u3001system encryption \u304b\u901a\u5e38 volume \u304b\u3001PIM \u304c\u3042\u308b\u304b\u3069\u3046\u304b\u306b\u3088\u3063\u3066\u3001KDF\u3001hash\u3001iteration count\u3001cipher chain\u3001mode \u304c\u5909\u308f\u308b\u3002VeraCrypt \u306e header key derivation \u8aac\u660e\u3067\u306f\u3001header key \u304c encrypted volume header \u306e\u6697\u53f7\u5316\u9818\u57df\u3092\u5fa9\u53f7\u3059\u308b\u305f\u3081\u306b\u4f7f\u308f\u308c\u3001\u305d\u306e\u9818\u57df\u306b master key \u306a\u3069\u304c\u542b\u307e\u308c\u308b\u3068\u8aac\u660e\u3055\u308c\u3066\u3044\u308b<a href=\"#ref20\">[20]<\/a>\u3002<\/p>\n<p>VeraCrypt \u3067\u306f PIM\u3001\u3059\u306a\u308f\u3061 Personal Iterations Multiplier \u306b\u3088\u308a\u3001password\u3001PIM\u3001Key Derivation Function \u306e\u7d44\u307f\u5408\u308f\u305b\u3067 iteration count \u3092\u8abf\u6574\u3067\u304d\u308b<a href=\"#ref21\">[21]<\/a>\u3002\u3053\u308c\u306f\u5b89\u5168\u6027\u3068 open \/ boot \u6642\u9593\u306e\u8abf\u6574\u306b\u95a2\u4fc2\u3059\u308b\u3002tcrypt.c \u304c VeraCrypt mode \u3068 PIM \u306e\u6271\u3044\u3092\u6301\u3064\u306e\u306f\u3001VeraCrypt \u7531\u6765\u306e volume \u3092\u958b\u304f\u305f\u3081\u306b\u3001\u3053\u306e\u5206\u5c90\u3092\u7121\u8996\u3067\u304d\u306a\u3044\u304b\u3089\u3067\u3042\u308b\u3002<\/p>\n<p>cipher \u5074\u3082\u540c\u3058\u3067\u3042\u308b\u3002VeraCrypt \u306e\u6280\u8853\u60c5\u5831\u306f\u3001Encryption Scheme\u3001Modes of Operation\u3001Header Key Derivation\u3001Keyfiles\u3001PIM\u3001Volume Format Specification \u3092\u4f53\u7cfb\u7684\u306b\u8aac\u660e\u3057\u3066\u3044\u308b<a href=\"#ref22\">[22]<\/a>\u3002tcrypt.c \u306e cipher \u5019\u88dc\u30c6\u30fc\u30d6\u30eb\u306b\u306f\u3001AES\u3001Serpent\u3001Twofish\u3001Camellia\u3001Kuznyechik \u3068\u3001\u305d\u308c\u3089\u306e chained cipher\u3001XTS\u3001LRW\u3001CBC \u7cfb legacy mode \u304c\u4e26\u3076\u3002\u4e92\u63db\u30b3\u30fc\u30c9\u306f\u3001\u73fe\u5728\u3088\u304f\u4f7f\u3046\u65b9\u5f0f\u3060\u3051\u3067\u306a\u304f\u3001\u904e\u53bb\u306b\u4f5c\u3089\u308c\u305f volume \u306e\u5206\u5c90\u3092\u8a18\u61b6\u3059\u308b\u5834\u6240\u3067\u3082\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u5206\u985e<\/th>\n<th>\u4f8b<\/th>\n<th>\u4e92\u63db\u30b3\u30fc\u30c9\u3067\u5fc5\u8981\u306b\u306a\u308b\u7406\u7531<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>KDF \/ hash<\/td>\n<td>PBKDF2 \u3068 RIPEMD160\u3001SHA512\u3001Whirlpool\u3001SHA256\u3001BLAKE2s-256\u3001Streebog512 \u306a\u3069\u306e\u7d44\u307f\u5408\u308f\u305b\u304c\u3042\u308b\u3002<\/td>\n<td>\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u3092\u4f5c\u308b\u65b9\u5f0f\u304c volume \u3054\u3068\u306b\u7570\u306a\u308b\u305f\u3081\u3001\u5019\u88dc\u3068\u3057\u3066\u8a66\u3059\u5fc5\u8981\u304c\u3042\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>iteration count<\/td>\n<td>TrueCrypt \u7cfb\u306e\u56fa\u5b9a\u56de\u6570\u3001VeraCrypt \u7cfb\u306e\u5927\u304d\u306a\u56de\u6570\u3001PIM \u306b\u3088\u308b\u8abf\u6574\u304c\u3042\u308b\u3002<\/td>\n<td>\u540c\u3058\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3067\u3082 iteration count \u304c\u9055\u3048\u3070\u3001\u5c0e\u51fa\u3055\u308c\u308b\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u306f\u4e00\u81f4\u3057\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>cipher chain<\/td>\n<td>AES \u5358\u4f53\u3001Serpent\u3001Twofish\u3001Serpent-Twofish-AES \u306a\u3069\u306e chained cipher \u304c\u3042\u308b\u3002<\/td>\n<td>\u30c7\u30fc\u30bf\u6697\u53f7\u5316\u65b9\u5f0f\u3068 master key layout \u304c\u7570\u306a\u308b\u305f\u3081\u3001dm-crypt \u306b\u6e21\u3059\u5f62\u5f0f\u3082\u5909\u308f\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>mode<\/td>\n<td>XTS\u3001LRW\u3001CBC \u7cfb legacy mode \u304c\u3042\u308b\u3002<\/td>\n<td>\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3068\u3057\u3066\u8a8d\u8b58\u3067\u304d\u3066\u3082\u3001kernel \u5074\u304c mapping \u3068\u3057\u3066\u6271\u3048\u308b\u304b\u306f\u5225\u554f\u984c\u306b\u306a\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u3053\u3067\u91cd\u8981\u306a\u306e\u306f\u3001\u4e92\u63db\u30b3\u30fc\u30c9\u304c\u904e\u53bb\u306e\u4ed5\u69d8\u5206\u5c90\u3092\u80cc\u8ca0\u3046\u3068\u3044\u3046\u3053\u3068\u3067\u3042\u308b\u3002\u5f62\u5f0f\u306e\u5bff\u547d\u304c\u9577\u304f\u306a\u308b\u307b\u3069\u3001\u904e\u53bb\u306b\u8a31\u5bb9\u3055\u308c\u305f\u65b9\u5f0f\u304c\u5897\u3048\u308b\u3002\u73fe\u5728\u306e\u6a19\u6e96\u3060\u3051\u3092\u6b8b\u305b\u3070\u5b9f\u88c5\u306f\u7c21\u5358\u306b\u306a\u308b\u304c\u3001\u904e\u53bb\u306e volume \u306f\u958b\u3051\u306a\u304f\u306a\u308b\u3002\u4e92\u63db\u6027\u3068\u306f\u3001\u904e\u53bb\u306e\u5206\u5c90\u3092\u3069\u3053\u307e\u3067\u8a18\u61b6\u3059\u308b\u304b\u3068\u3044\u3046\u8a2d\u8a08\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>8. \u901a\u5e38\u30d8\u30c3\u30c0\u30fc\u3001hidden volume\u3001system encryption\u3001backup header \u306e\u9055\u3044<\/h2>\n<p>TCRYPT \/ VeraCrypt \u4e92\u63db\u3067\u306f\u3001\u30d8\u30c3\u30c0\u30fc\u3092\u8aad\u3080\u3068\u3044\u3046\u51e6\u7406\u3082\u5358\u7d14\u3067\u306f\u306a\u3044\u3002VeraCrypt Volume Format Specification \u306f\u3001\u6a19\u6e96 volume header\u3001hidden volume header\u3001embedded backup header\u3001system encryption \u306b\u304a\u3051\u308b layout \u306e\u9055\u3044\u3092\u8aac\u660e\u3057\u3066\u3044\u308b<a href=\"#ref23\">[23]<\/a>\u3002\u3053\u306e\u9055\u3044\u306f\u3001tcrypt.c \u306e\u30d8\u30c3\u30c0\u30fc\u8aad\u307f\u53d6\u308a\u4f4d\u7f6e\u9078\u629e\u306b\u76f4\u63a5\u53cd\u6620\u3055\u308c\u308b\u3002<\/p>\n<p>\u901a\u5e38 volume \u3067\u306f\u3001\u5148\u982d\u4ed8\u8fd1\u306e\u6a19\u6e96\u30d8\u30c3\u30c0\u30fc\u3092\u8aad\u3080\u3002hidden volume \u3067\u306f\u3001\u5916\u5074 volume \u306e\u4e2d\u306b\u96a0\u3055\u308c\u305f\u5225\u306e header \u304c\u3042\u308a\u3001\u305d\u306e\u4f4d\u7f6e\u3092\u8aad\u3080\u5fc5\u8981\u304c\u3042\u308b\u3002backup header \u306f volume \u672b\u5c3e\u5074\u306b\u3042\u308a\u3001\u901a\u5e38\u30d8\u30c3\u30c0\u30fc\u304c\u5931\u308f\u308c\u305f\u3068\u304d\u306e\u5fa9\u65e7\u7d4c\u8def\u306b\u306a\u308b\u3002system encryption \u3067\u306f\u3001\u5bfe\u8c61\u304c partition \u3067\u3042\u3063\u3066\u3082\u3001\u30d8\u30c3\u30c0\u30fc\u304c base device \u5074\u306b\u3042\u308b\u5834\u5408\u304c\u3042\u308b\u3002<\/p>\n<p>\u3053\u306e\u8907\u96d1\u3055\u306f\u3001TCRYPT \/ VeraCrypt \u304c\u5358\u306a\u308b\u30d5\u30a1\u30a4\u30eb\u30b3\u30f3\u30c6\u30ca\u30fc\u5f62\u5f0f\u3067\u306f\u306a\u3044\u3053\u3068\u306b\u7531\u6765\u3059\u308b\u3002hidden volume\u3001system encryption\u3001backup header \u3068\u3044\u3063\u305f\u6a5f\u80fd\u306f\u3001\u6697\u53f7\u5316\u30c7\u30fc\u30bf\u306e\u4f7f\u3044\u65b9\u3068\u4fdd\u5168\u65b9\u6cd5\u306b\u95a2\u308f\u308b\u3002\u305d\u306e\u305f\u3081\u3001\u4e92\u63db\u30b3\u30fc\u30c9\u306f\u6697\u53f7\u65b9\u5f0f\u3060\u3051\u3067\u306a\u304f\u3001\u30e1\u30bf\u30c7\u30fc\u30bf\u914d\u7f6e\u306e\u4e92\u63db\u6027\u3082\u6301\u305f\u306a\u3051\u308c\u3070\u306a\u3089\u306a\u3044\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u30d8\u30c3\u30c0\u30fc\u7a2e\u5225<\/th>\n<th>\u5f79\u5272<\/th>\n<th>\u5b9f\u88c5\u4e0a\u306e\u610f\u5473<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u901a\u5e38\u30d8\u30c3\u30c0\u30fc<\/td>\n<td>\u6a19\u6e96 volume \u3092\u958b\u304f\u305f\u3081\u306e\u4e3b\u30d8\u30c3\u30c0\u30fc\u3067\u3042\u308b\u3002<\/td>\n<td>\u901a\u5e38 open \u306e\u6700\u521d\u306e\u8aad\u307f\u53d6\u308a\u4f4d\u7f6e\u306b\u306a\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>hidden volume header<\/td>\n<td>\u5916\u5074 volume \u306e\u4e2d\u306b\u7f6e\u304b\u308c\u305f\u96a0\u3057 volume \u3092\u958b\u304f\u305f\u3081\u306e\u30d8\u30c3\u30c0\u30fc\u3067\u3042\u308b\u3002<\/td>\n<td>hidden \u6307\u5b9a\u6642\u306b\u5225 offset \u3092\u8aad\u3080\u5fc5\u8981\u304c\u3042\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>backup header<\/td>\n<td>\u4e3b\u30d8\u30c3\u30c0\u30fc\u7834\u640d\u6642\u306b\u5fa9\u65e7\u7d4c\u8def\u3068\u306a\u308b\u57cb\u3081\u8fbc\u307f backup header \u3067\u3042\u308b\u3002<\/td>\n<td>backup \u6307\u5b9a\u6642\u306b\u306f\u901a\u5e38\u3068\u306f\u7570\u306a\u308b\u4f4d\u7f6e\u3092\u8aad\u3080\u3002<\/td>\n<\/tr>\n<tr>\n<td>system encryption header<\/td>\n<td>system partition encryption \u306b\u95a2\u4fc2\u3059\u308b\u30d8\u30c3\u30c0\u30fc\u3067\u3042\u308b\u3002<\/td>\n<td>partition \u3067\u306f\u306a\u304f base device \u5074\u3092\u898b\u308b\u5fc5\u8981\u304c\u3042\u308b\u5834\u5408\u304c\u3042\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u306e\u7ae0\u304b\u3089\u4e00\u822c\u5316\u3067\u304d\u308b\u306e\u306f\u3001\u4e92\u63db\u6027\u3068\u306f\u6697\u53f7\u65b9\u5f0f\u3060\u3051\u3067\u306f\u306a\u3044\u3068\u3044\u3046\u3053\u3068\u3060\u3002\u6697\u53f7\u5316\u30b9\u30c8\u30ec\u30fc\u30b8\u306e\u4e92\u63db\u6027\u306b\u306f\u3001\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u3001backup \u306e\u6271\u3044\u3001\u96a0\u3057\u9818\u57df\u3001system encryption \u306e layout \u307e\u3067\u542b\u307e\u308c\u308b\u3002\u5f62\u5f0f\u4e92\u63db\u6027\u3068\u306f\u3001\u6697\u53f7\u30d1\u30e9\u30e1\u30fc\u30bf\u4e92\u63db\u3067\u3042\u308b\u3068\u540c\u6642\u306b\u3001\u30ec\u30a4\u30a2\u30a6\u30c8\u4e92\u63db\u3067\u3082\u3042\u308b\u3002<\/p>\n<hr>\n<h2>9. \u8a73\u7d30\u8a2d\u8a08\u66f8\uff1aTCRYPT \/ VeraCrypt \u4e92\u63db\u51e6\u7406<\/h2>\n<p>\u3053\u3053\u304b\u3089\u306f\u3001tcrypt.c \u306e\u51e6\u7406\u3092\u8a73\u7d30\u8a2d\u8a08\u66f8\u3068\u3057\u3066\u6574\u7406\u3059\u308b\u3002\u76ee\u7684\u306f\u3001\u30b3\u30fc\u30c9\u306e\u9010\u8a9e\u89e3\u8aac\u3067\u306f\u306a\u304f\u3001\u8cac\u52d9\u3001\u30c7\u30fc\u30bf\u69cb\u9020\u3001\u51e6\u7406\u30d5\u30ed\u30fc\u3001\u5883\u754c\u6761\u4ef6\u3001\u4f9d\u5b58\u95a2\u4fc2\u3092\u8aad\u3081\u308b\u5f62\u306b\u3059\u308b\u3053\u3068\u3067\u3042\u308b\u3002\u5bfe\u8c61\u30b3\u30fc\u30c9\u306f lib\/tcrypt\/tcrypt.c \u3092\u4e2d\u5fc3\u3068\u3057\u3001cryptsetup \/ libcryptsetup \u306e TCRYPT \/ VeraCrypt \u5f62\u5f0f\u30cf\u30f3\u30c9\u30e9\u3068\u3057\u3066\u8aad\u3080\u3002<\/p>\n<h3>9.1 \u76ee\u7684<\/h3>\n<p>\u672c\u8a2d\u8a08\u306f\u3001cryptsetup \u306b\u304a\u3051\u308b TCRYPT \/ VeraCrypt \u4e92\u63db\u51e6\u7406\u306e\u69cb\u9020\u3092\u6574\u7406\u3059\u308b\u3082\u306e\u3067\u3042\u308b\u3002<\/p>\n<p>\u5bfe\u8c61\u30b3\u30fc\u30c9\u306f lib\/tcrypt\/tcrypt.c \u3092\u4e2d\u5fc3\u3068\u3059\u308b\u3002\u3053\u3053\u3067\u3044\u3046 TCRYPT \u4e92\u63db\u51e6\u7406\u3068\u306f\u3001TrueCrypt \/ VeraCrypt \u5f62\u5f0f\u306e\u65e2\u5b58\u30dc\u30ea\u30e5\u30fc\u30e0\u3092\u8aad\u307f\u53d6\u308a\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u304a\u3088\u3073 keyfile \u304b\u3089\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306b\u5fc5\u8981\u306a\u9375\u3092\u5c0e\u51fa\u3057\u3001\u30d8\u30c3\u30c0\u30fc\u5185\u306e\u60c5\u5831\u3092\u691c\u8a3c\u3057\u305f\u3046\u3048\u3067\u3001Linux \u306e dm-crypt mapping \u3068\u3057\u3066\u6709\u52b9\u5316\u3059\u308b\u51e6\u7406\u3092\u6307\u3059\u3002<\/p>\n<p>\u672c\u5b9f\u88c5\u306e\u76ee\u7684\u306f\u3001TrueCrypt \/ VeraCrypt \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u518d\u5b9f\u88c5\u3059\u308b\u3053\u3068\u3067\u306f\u306a\u3044\u3002\u65e2\u5b58\u306e TCRYPT \/ VeraCrypt \u30dc\u30ea\u30e5\u30fc\u30e0\u304b\u3089\u5fc5\u8981\u306a\u6697\u53f7\u30d1\u30e9\u30e1\u30fc\u30bf\u3068 master key \u3092\u53d6\u308a\u51fa\u3057\u3001cryptsetup \/ libcryptsetup \u306e\u65e2\u5b58\u57fa\u76e4\u306b\u63a5\u7d9a\u3059\u308b\u3053\u3068\u3067\u3042\u308b\u3002<\/p>\n<h3>9.2 \u9069\u7528\u7bc4\u56f2<\/h3>\n<p>\u672c\u8a2d\u8a08\u306e\u5bfe\u8c61\u7bc4\u56f2\u306f\u6b21\u306e\u901a\u308a\u3067\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u5bfe\u8c61\u7bc4\u56f2<\/th>\n<th>\u5185\u5bb9<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>TCRYPT \/ VeraCrypt \u30d8\u30c3\u30c0\u30fc\u306e\u8aad\u307f\u53d6\u308a<\/td>\n<td>\u901a\u5e38\u30d8\u30c3\u30c0\u30fc\u3001backup header\u3001hidden volume header\u3001system encryption header \u3092\u8aad\u307f\u53d6\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u9078\u629e<\/td>\n<td>\u901a\u5e38\u30d8\u30c3\u30c0\u30fc\u3001backup header\u3001hidden volume header\u3001system encryption header \u306e\u4f4d\u7f6e\u3092 flags \u306b\u5fdc\u3058\u3066\u9078\u3076\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u9375\u5c0e\u51fa<\/td>\n<td>\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u304a\u3088\u3073 keyfile \u304b\u3089\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u3092\u5c0e\u51fa\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>KDF \/ hash \/ iteration count \u5019\u88dc\u7ba1\u7406<\/td>\n<td>TrueCrypt \u7cfb\u3068 VeraCrypt \u7cfb\u306e\u5019\u88dc\u3092\u7ba1\u7406\u3057\u3001\u5fc5\u8981\u306b\u5fdc\u3058\u3066 PIM \u3092\u53cd\u6620\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>cipher chain \/ mode \u5019\u88dc\u7ba1\u7406<\/td>\n<td>\u5358\u4e00 cipher \u3068 chained cipher\u3001XTS\u3001LRW\u3001CBC \u7cfb legacy mode \u3092\u5019\u88dc\u3068\u3057\u3066\u6271\u3046\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u8a66\u884c<\/td>\n<td>KDF \u5019\u88dc\u3068 cipher \u5019\u88dc\u3092\u7d44\u307f\u5408\u308f\u305b\u3001\u5fa9\u53f7\u7d50\u679c\u3092\u691c\u8a3c\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u5024\u691c\u8a3c<\/td>\n<td>magic\u3001CRC\u3001version\u3001volume size\u3001offset\u3001sector size \u306a\u3069\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>cryptsetup \u30d1\u30e9\u30e1\u30fc\u30bf\u8a2d\u5b9a<\/td>\n<td>\u5fa9\u53f7\u6e08\u307f\u30d8\u30c3\u30c0\u30fc\u60c5\u5831\u304b\u3089 cipher spec\u3001mode\u3001key size \u306a\u3069\u3092\u8a2d\u5b9a\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>dm-crypt mapping \u69cb\u6210<\/td>\n<td>master key\u3001offset\u3001size\u3001cipher spec \u3092\u4f7f\u3063\u3066 dm-crypt mapping \u306b\u63a5\u7d9a\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u88dc\u52a9\u64cd\u4f5c<\/td>\n<td>TCRYPT volume \u306e activate\u3001deactivate\u3001dump\u3001offset \u53d6\u5f97\u51e6\u7406\u3092\u6271\u3046\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u5bfe\u8c61\u5916\u306f\u6b21\u306e\u901a\u308a\u3067\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u5bfe\u8c61\u5916<\/th>\n<th>\u7406\u7531<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>TrueCrypt \/ VeraCrypt \u5f62\u5f0f\u306e\u65b0\u898f\u4f5c\u6210<\/td>\n<td>\u672c\u5b9f\u88c5\u306f\u65e2\u5b58 volume \u3092\u958b\u304f\u305f\u3081\u306e\u4e92\u63db\u51e6\u7406\u3067\u3042\u308a\u3001\u5f62\u5f0f\u4f5c\u6210\u3092\u76ee\u7684\u306b\u3057\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>TCRYPT \u30d8\u30c3\u30c0\u30fc\u306e\u66f4\u65b0\u30fb\u66f8\u304d\u63db\u3048<\/td>\n<td>cryptsetup \u306e TCRYPT \u5bfe\u5fdc\u306f on-device header \u306e\u5909\u66f4\u3092\u5bfe\u8c61\u306b\u3057\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u5909\u66f4<\/td>\n<td>\u30d8\u30c3\u30c0\u30fc\u518d\u6697\u53f7\u5316\u3084 key material \u306e\u66f4\u65b0\u3092\u6271\u308f\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u518d\u6697\u53f7\u5316<\/td>\n<td>\u65e2\u5b58\u30d8\u30c3\u30c0\u30fc\u3092\u5fa9\u53f7\u3057\u3066\u8aad\u3080\u3053\u3068\u306b\u96c6\u4e2d\u3057\u3001\u66f8\u304d\u623b\u3057\u306f\u884c\u308f\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>VeraCrypt GUI \u4e92\u63db\u6a5f\u80fd<\/td>\n<td>GUI \u3084\u30e6\u30fc\u30b6\u30fc\u64cd\u4f5c\u306e\u518d\u73fe\u3067\u306f\u306a\u304f\u3001block device \u3068\u3057\u3066\u306e activation \u3092\u76ee\u7684\u306b\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u51e6\u7406<\/td>\n<td>\u958b\u3044\u305f block device \u4e0a\u306e ext4\u3001FAT\u3001NTFS \u306a\u3069\u306f\u5225\u5c64\u306e\u8cac\u52d9\u3067\u3042\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u5b9f\u969b\u306e block I\/O \u5fa9\u53f7\u51e6\u7406\u305d\u306e\u3082\u306e<\/td>\n<td>\u5b9f\u30c7\u30fc\u30bf\u306e\u900f\u904e\u7684\u5fa9\u53f7\u306f dm-crypt \u3068 kernel \u5074\u306b\u59d4\u8b72\u3055\u308c\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u5b9f\u969b\u306e\u6697\u53f7\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u51e6\u7406\u3001device-mapper \u64cd\u4f5c\u3001\u30e1\u30e2\u30ea\u5b89\u5168\u51e6\u7406\u3001\u30ed\u30b0\u51fa\u529b\u3001device \u62bd\u8c61\u5316\u306f cryptsetup \u306e\u5171\u901a\u57fa\u76e4\u304a\u3088\u3073 Linux kernel \u5074\u306e dm-crypt \u306b\u59d4\u8b72\u3059\u308b\u3002<\/p>\n<h3>9.3 \u5168\u4f53\u69cb\u6210<\/h3>\n<p>TCRYPT \u4e92\u63db\u51e6\u7406\u306f\u3001\u6982\u5ff5\u7684\u306b\u306f\u4e09\u5c64\u3067\u69cb\u6210\u3055\u308c\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u5c64<\/th>\n<th>\u62c5\u5f53<\/th>\n<th>\u8aac\u660e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>TCRYPT \u5f62\u5f0f\u89e3\u91c8\u5c64<\/td>\n<td>tcrypt.c<\/td>\n<td>TCRYPT \/ VeraCrypt \u56fa\u6709\u306e\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u3001KDF \u5019\u88dc\u3001cipher chain\u3001legacy mode\u3001hidden volume\u3001system encryption \u306a\u3069\u3092\u89e3\u91c8\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>libcryptsetup \u5171\u901a\u5c64<\/td>\n<td>cryptsetup \u5185\u90e8 API<\/td>\n<td>device \u62bd\u8c61\u5316\u3001volume key \u7ba1\u7406\u3001\u30ed\u30b0\u3001\u30a8\u30e9\u30fc\u51e6\u7406\u3001\u5b89\u5168\u306a\u30e1\u30e2\u30ea\u64cd\u4f5c\u3001activation API \u306a\u3069\u3092\u63d0\u4f9b\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>crypto backend \/ Linux kernel dm-crypt \u5c64<\/td>\n<td>crypto backend \u3068 kernel<\/td>\n<td>\u5b9f\u969b\u306e\u6697\u53f7\u30d7\u30ea\u30df\u30c6\u30a3\u30d6\u3001cipher mode\u3001device-mapper table\u3001block device \u3068\u3057\u3066\u306e I\/O \u3092\u62c5\u5f53\u3059\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3057\u305f\u304c\u3063\u3066\u3001tcrypt.c \u306e\u4e2d\u5fc3\u8cac\u52d9\u306f\u3001TCRYPT \u5f62\u5f0f\u3092 dm-crypt \u3067\u6271\u3048\u308b\u30d1\u30e9\u30e1\u30fc\u30bf\u3078\u5909\u63db\u3059\u308b\u3053\u3068\u3067\u3042\u308b\u3002<\/p>\n<h3>9.4 \u4e3b\u8981\u30c7\u30fc\u30bf\u69cb\u9020<\/h3>\n<p>KDF \u5019\u88dc\u30c6\u30fc\u30d6\u30eb\u306f\u3001TCRYPT \/ VeraCrypt \u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306b\u4f7f\u7528\u3059\u308b KDF \u5019\u88dc\u3092\u5b9a\u7fa9\u3059\u308b\u9759\u7684\u30c6\u30fc\u30d6\u30eb\u3067\u3042\u308b\u3002\u5404\u8981\u7d20\u306f\u3001legacy mode \u304b\u3069\u3046\u304b\u3001VeraCrypt mode \u304b\u3069\u3046\u304b\u3001KDF \u540d\u3001hash \u540d\u3001\u6a19\u6e96 iteration count\u3001VeraCrypt PIM \u7528\u306e\u5b9a\u6570\u3001VeraCrypt PIM \u7528\u306e\u4e57\u6570\u3092\u6301\u3064\u3002\u3053\u306e\u30c6\u30fc\u30d6\u30eb\u306b\u3088\u308a\u3001\u5b9f\u88c5\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u660e\u793a\u3057\u305f\u65b9\u5f0f\u3060\u3051\u3092\u4f7f\u3046\u306e\u3067\u306f\u306a\u304f\u3001\u5019\u88dc\u3092\u9806\u306b\u8a66\u3057\u3001\u6b63\u3057\u3044\u30d8\u30c3\u30c0\u30fc magic \u3068 CRC \u304c\u5f97\u3089\u308c\u308b\u7d44\u307f\u5408\u308f\u305b\u3092\u63a2\u3059\u52d5\u4f5c\u3092\u5b9f\u73fe\u3059\u308b\u3002<\/p>\n<p>TrueCrypt \u7cfb\u3067\u306f PBKDF2 \u3068 RIPEMD160 \/ SHA512 \/ Whirlpool \/ SHA1 \u306a\u3069\u304c\u5019\u88dc\u306b\u306a\u308b\u3002VeraCrypt \u7cfb\u3067\u306f\u3001\u3088\u308a\u5927\u304d\u306a iteration count \u3084 PIM \u306b\u3088\u308b\u8abf\u6574\u3001SHA256\u3001BLAKE2s\u3001Streebog \u306a\u3069\u306e\u5019\u88dc\u304c\u542b\u307e\u308c\u308b\u3002<\/p>\n<p>\u5358\u4e00 cipher \u5b9a\u7fa9\u306f\u3001cipher chain \u5185\u306e\u4e00\u3064\u306e\u6697\u53f7\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u3092\u8868\u3059\u3002\u4e3b\u306a\u8981\u7d20\u306f\u3001cipher \u540d\u3001key size\u3001IV size\u3001key offset\u3001IV offset \u307e\u305f\u306f tweak key offset\u3001\u8ffd\u52a0 key \u9818\u57df\u30b5\u30a4\u30ba\u3067\u3042\u308b\u3002TCRYPT \u3067\u306f\u3001\u30d8\u30c3\u30c0\u30fc\u5185\u306e key material \u304b\u3089\u5404 cipher \u306b\u5fc5\u8981\u306a\u9375\u9818\u57df\u3092\u5207\u308a\u51fa\u3059\u5fc5\u8981\u304c\u3042\u308b\u3002key offset\u3001IV offset\u3001\u8ffd\u52a0 key \u9818\u57df\u30b5\u30a4\u30ba\u306f\u3001\u305d\u306e\u5207\u308a\u51fa\u3057\u4f4d\u7f6e\u3092\u5b9a\u7fa9\u3059\u308b\u3002<\/p>\n<p>cipher chain \u5b9a\u7fa9\u306f\u3001TCRYPT \/ VeraCrypt \u3067\u4f7f\u7528\u3055\u308c\u308b cipher chain \u3068 mode \u306e\u7d44\u307f\u5408\u308f\u305b\u3092\u8868\u3059\u3002\u4e3b\u306a\u8981\u7d20\u306f\u3001legacy mode \u304b\u3069\u3046\u304b\u3001chain count\u3001chain \u5168\u4f53\u306e key size\u3001cryptsetup \u4e0a\u306e cipher \u540d\u3001mode \u540d\u3001\u6700\u5927 3 \u8981\u7d20\u306e cipher \u914d\u5217\u3067\u3042\u308b\u3002\u3053\u306e\u69cb\u9020\u306b\u3088\u308a\u3001\u5358\u4e00 AES-XTS \u3060\u3051\u3067\u306a\u304f\u3001Twofish-AES\u3001Serpent-Twofish-AES\u3001AES-Twofish-Serpent \u306a\u3069\u306e chained cipher \u3092\u8868\u73fe\u3059\u308b\u3002<\/p>\n<p>mode \u3068\u3057\u3066\u306f\u3001\u4e3b\u306b XTS\u3001LRW\u3001CBC \u7cfb legacy mode \u304c\u6271\u308f\u308c\u308b\u3002\u305f\u3060\u3057\u3001\u3059\u3079\u3066\u306e mode \u304c activation \u53ef\u80fd\u3068\u306f\u9650\u3089\u306a\u3044\u3002\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306b\u306f\u5fc5\u8981\u3067\u3082\u3001kernel dm-crypt \u304c\u5bfe\u5fdc\u3057\u306a\u3044 legacy mode \u306f activation \u6642\u306b\u62d2\u5426\u3055\u308c\u308b\u3002<\/p>\n<h3>9.5 \u4e3b\u8981\u95a2\u6570\u8a2d\u8a08<\/h3>\n<p>TCRYPT_read_phdr \u306f\u3001TCRYPT \u7269\u7406\u30d8\u30c3\u30c0\u30fc\u3092 device \u304b\u3089\u8aad\u307f\u53d6\u308a\u3001\u5fa9\u53f7\u521d\u671f\u5316\u51e6\u7406\u3078\u6e21\u3059\u5165\u53e3\u3067\u3042\u308b\u3002\u3053\u306e\u95a2\u6570\u306f\u3001\u6307\u5b9a\u3055\u308c\u305f flags \u306b\u5fdc\u3058\u3066\u30d8\u30c3\u30c0\u30fc\u8aad\u307f\u53d6\u308a\u4f4d\u7f6e\u3092\u5207\u308a\u66ff\u3048\u308b\u3002\u4e3b\u306a\u5206\u5c90\u306f\u3001system encryption header\u3001hidden volume header\u3001hidden volume backup header\u3001hidden volume old offset\u3001normal backup header\u3001normal header \u3067\u3042\u308b\u3002<\/p>\n<p>system encryption \u306e\u5834\u5408\u3001\u5bfe\u8c61 device \u304c partition \u3067\u3042\u308c\u3070 base device \u3092\u53d6\u5f97\u3057\u3001partition \u306e\u5916\u5074\u306b\u3042\u308b system header \u3092\u8aad\u3080\u3002\u3053\u308c\u306f TCRYPT system encryption \u3067\u306f\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u304c\u901a\u5e38\u306e partition \u5185\u90e8\u3068\u306f\u7570\u306a\u308b\u305f\u3081\u3067\u3042\u308b\u3002\u8aad\u307f\u53d6\u308a\u306b\u6210\u529f\u3057\u305f\u5834\u5408\u3001TCRYPT_init_hdr \u3092\u547c\u3073\u51fa\u3057\u3066\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3068\u691c\u8a3c\u3092\u884c\u3046\u3002\u5931\u6557\u3057\u305f\u5834\u5408\u306f\u30d8\u30c3\u30c0\u30fc\u9818\u57df\u3092\u30bc\u30ed\u30af\u30ea\u30a2\u3057\u3001\u30a8\u30e9\u30fc\u3092\u8fd4\u3059\u3002<\/p>\n<p>TCRYPT_init_hdr \u306f\u3001\u6697\u53f7\u5316\u3055\u308c\u305f TCRYPT \u30d8\u30c3\u30c0\u30fc\u3092\u5fa9\u53f7\u3057\u3001\u6b63\u3057\u3044 KDF \/ cipher \/ mode \u306e\u7d44\u307f\u5408\u308f\u305b\u3092\u63a2\u7d22\u3059\u308b\u4e2d\u5fc3\u51e6\u7406\u3067\u3042\u308b\u3002\u3053\u306e\u95a2\u6570\u306e\u5165\u529b\u306f\u3001\u8aad\u307f\u53d6\u3089\u308c\u305f\u6697\u53f7\u5316\u30d8\u30c3\u30c0\u30fc\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3001keyfile\u3001flags\u3001PIM \u306a\u3069\u3067\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u9806\u5e8f<\/th>\n<th>TCRYPT_init_hdr \u306e\u51e6\u7406<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1<\/td>\n<td>\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u9818\u57df\u3068\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u9818\u57df\u3092\u5b89\u5168\u30e1\u30e2\u30ea\u3068\u3057\u3066\u78ba\u4fdd\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3092\u521d\u671f key pool \u3078\u914d\u7f6e\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>keyfile \u304c\u6307\u5b9a\u3055\u308c\u3066\u3044\u308b\u5834\u5408\u3001keyfile pool \u51e6\u7406\u3092\u884c\u3046\u3002<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>KDF \u5019\u88dc\u30c6\u30fc\u30d6\u30eb\u3092\u9806\u306b\u8d70\u67fb\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>flags \u306b\u5408\u308f\u306a\u3044 legacy \/ VeraCrypt \u5019\u88dc\u3092\u9664\u5916\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>PIM \u304c\u6307\u5b9a\u3055\u308c\u3066\u3044\u308b\u5834\u5408\u306f VeraCrypt \u306e\u898f\u5247\u306b\u57fa\u3065\u3044\u3066 iteration count \u3092\u8abf\u6574\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>7<\/td>\n<td>PBKDF \u306b\u3088\u308a\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u3092\u5c0e\u51fa\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>8<\/td>\n<td>TCRYPT_decrypt_hdr \u306b\u3088\u308a cipher \u5019\u88dc\u3092\u8a66\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>9<\/td>\n<td>magic \u3068 CRC \u304c\u6b63\u3057\u3044\u7d44\u307f\u5408\u308f\u305b\u3092\u898b\u3064\u3051\u305f\u5834\u5408\u3001TCRYPT_hdr_from_disk \u306b\u3088\u308a\u30d8\u30c3\u30c0\u30fc\u5024\u3092 CPU endian \u3078\u5909\u63db\u3057\u3001params \u3092\u8a2d\u5b9a\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>10<\/td>\n<td>\u4e00\u6642\u9375\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3001key material \u3092\u5b89\u5168\u306b\u6d88\u53bb\u3057\u3066\u7d42\u4e86\u3059\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u306e\u95a2\u6570\u306f\u3001TCRYPT \u5f62\u5f0f\u306e\u3001\u3069\u306e KDF \/ cipher \u3067\u4f5c\u3089\u308c\u305f\u304b\u304c\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u524d\u306b\u306f\u5206\u304b\u3089\u306a\u3044\u3068\u3044\u3046\u6027\u8cea\u3092\u3001\u5019\u88dc\u63a2\u7d22\u306b\u3088\u308a\u5438\u53ce\u3059\u308b\u3002<\/p>\n<p>TCRYPT_pool_keyfile \u306f\u3001TCRYPT \/ VeraCrypt keyfile \u3092 key pool \u306b\u6df7\u5408\u3059\u308b\u51e6\u7406\u3067\u3042\u308b\u3002keyfile \u3092\u6700\u5927\u9577\u307e\u3067\u8aad\u307f\u53d6\u308a\u3001\u8aad\u307f\u53d6\u3063\u305f byte stream \u306b\u5bfe\u3057\u3066 CRC32 \u3092\u66f4\u65b0\u3057\u306a\u304c\u3089 key pool \u3078\u52a0\u7b97\u3059\u308b\u3002\u8907\u6570 keyfile \u304c\u3042\u308b\u5834\u5408\u3082\u3001\u540c\u3058 pool \u306b\u9806\u6b21\u6df7\u5408\u3055\u308c\u308b\u3002\u3053\u306e\u51e6\u7406\u306e\u76ee\u7684\u306f\u3001keyfile \u306e\u5185\u5bb9\u3092\u76f4\u63a5\u6697\u53f7\u9375\u3068\u3057\u3066\u4f7f\u3046\u306e\u3067\u306f\u306a\u304f\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3068\u540c\u3058 key derivation \u5165\u529b\u9818\u57df\u306b\u6df7\u305c\u8fbc\u3080\u3053\u3068\u3067\u3042\u308b\u3002\u8aad\u307f\u53d6\u308a\u5f8c\u306e keyfile buffer \u3068 CRC \u5024\u306f\u5b89\u5168\u306b\u6d88\u53bb\u3055\u308c\u308b\u3002<\/p>\n<p>TCRYPT_decrypt_hdr \u306f\u3001\u5c0e\u51fa\u6e08\u307f\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u3092\u4f7f\u3063\u3066\u3001cipher \u5019\u88dc\u3092\u9806\u306b\u8a66\u3059\u51e6\u7406\u3067\u3042\u308b\u3002\u3053\u306e\u95a2\u6570\u306f cipher \u5019\u88dc\u3092\u8d70\u67fb\u3059\u308b\u3002\u30e6\u30fc\u30b6\u30fc\u304c cipher \u3092\u6307\u5b9a\u3057\u3066\u3044\u308b\u5834\u5408\u306f\u3001\u305d\u306e cipher \u540d\u306b\u5408\u308f\u306a\u3044\u5019\u88dc\u3092\u9664\u5916\u3059\u308b\u3002legacy mode \u304c\u8a31\u53ef\u3055\u308c\u3066\u3044\u306a\u3044\u5834\u5408\u306f legacy \u5019\u88dc\u3092\u9664\u5916\u3059\u308b\u3002<\/p>\n<p>\u5404 cipher \u5019\u88dc\u306b\u3064\u3044\u3066\u3001\u6697\u53f7\u5316\u30d8\u30c3\u30c0\u30fc\u3092\u4f5c\u696d\u7528\u9818\u57df\u306b\u30b3\u30d4\u30fc\u3057\u3001mode \u306b\u5fdc\u3058\u3066\u5fa9\u53f7\u51e6\u7406\u3092\u884c\u3046\u3002cbci \u7cfb mode \u306e\u5834\u5408\u306f TCRYPT_decrypt_cbci \u3092\u4f7f\u3046\u3002\u305d\u308c\u4ee5\u5916\u306e\u5834\u5408\u306f\u3001chain \u306e\u5f8c\u308d\u304b\u3089\u524d\u3078 TCRYPT_decrypt_hdr_one \u3092\u9069\u7528\u3059\u308b\u3002\u5fa9\u53f7\u5f8c\u3001\u30d8\u30c3\u30c0\u30fc\u5185\u306e magic \u3092\u78ba\u8a8d\u3059\u308b\u3002TrueCrypt \u5f62\u5f0f\u306e magic \u304c\u691c\u51fa\u3055\u308c\u308c\u3070\u6210\u529f\u3068\u3059\u308b\u3002VeraCrypt mode \u304c\u6709\u52b9\u306a\u5834\u5408\u306f\u3001VeraCrypt \u5f62\u5f0f\u306e magic \u3082\u6210\u529f\u6761\u4ef6\u3068\u3059\u308b\u3002\u5fa9\u53f7\u306b\u5931\u6557\u3057\u305f\u5019\u88dc\u306f\u7834\u68c4\u3055\u308c\u3001\u6b21\u306e\u5019\u88dc\u3078\u9032\u3080\u3002<\/p>\n<p>TCRYPT_decrypt_hdr_one \u306f\u3001\u5358\u4e00 cipher \u306b\u3088\u308b\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3092\u62c5\u5f53\u3059\u308b\u3002mode \u540d\u304b\u3089 backend \u306b\u6e21\u3059 mode \u90e8\u5206\u3092\u5207\u308a\u51fa\u3057\u3001\u5fc5\u8981\u306b\u5fdc\u3058\u3066 IV \u3092\u69cb\u6210\u3059\u308b\u3002CBC \u7cfb\u3067\u306f whitening \u3092\u9664\u53bb\u3057\u3001LRW \u7cfb\u3067\u306f IV \u3092\u8abf\u6574\u3059\u308b\u3002\u305d\u306e\u5f8c\u3001backend \u7528\u306e key \u3092\u69cb\u6210\u3057\u3001cryptsetup \u306e cipher backend \u3092\u4f7f\u3063\u3066\u30d8\u30c3\u30c0\u30fc\u9818\u57df\u3092\u5fa9\u53f7\u3059\u308b\u3002XTS\u3001LRW\u3001CBC \u3067\u306f key material \u306e\u914d\u7f6e\u304c\u7570\u306a\u308b\u305f\u3081\u3001key copy \u51e6\u7406\u304c mode \u3054\u3068\u306e\u5dee\u7570\u3092\u5438\u53ce\u3059\u308b\u3002<\/p>\n<p>TCRYPT_decrypt_cbci \u306f\u3001CBC \u7cfb\u306e chained cipher \u5fa9\u53f7\u3092\u62c5\u5f53\u3059\u308b\u3002backend \u304c TCRYPT \u56fa\u6709\u306e outer CBC \u51e6\u7406\u3092\u76f4\u63a5\u63d0\u4f9b\u3057\u306a\u3044\u305f\u3081\u3001\u3053\u306e\u95a2\u6570\u306f ECB cipher \u3092\u8907\u6570\u521d\u671f\u5316\u3057\u3001block \u3054\u3068\u306b chain \u306e\u9006\u9806\u3067\u5fa9\u53f7\u3057\u3001IV \u3068 XOR \u3059\u308b\u3053\u3068\u3067 CBC \u5fa9\u53f7\u3092\u5b9f\u88c5\u3059\u308b\u3002\u3053\u306e\u51e6\u7406\u306f\u3001TCRYPT legacy mode \u4e92\u63db\u306e\u305f\u3081\u306b\u5fc5\u8981\u3067\u3042\u308b\u3002\u901a\u5e38\u306e XTS \u7cfb activation \u3068\u306f\u7570\u306a\u308a\u3001TCRYPT \u56fa\u6709\u306e\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u51e6\u7406\u306b\u8fd1\u3044\u4f4d\u7f6e\u3065\u3051\u3067\u3042\u308b\u3002<\/p>\n<p>TCRYPT_hdr_from_disk \u306f\u3001\u5fa9\u53f7\u6e08\u307f\u30d8\u30c3\u30c0\u30fc\u3092\u691c\u8a3c\u3057\u3001disk endian \u304b\u3089 CPU endian \u3078\u5909\u63db\u3057\u3001cryptsetup \u7528 params \u3092\u8a2d\u5b9a\u3059\u308b\u51e6\u7406\u3067\u3042\u308b\u3002\u4e3b\u306a\u691c\u8a3c\u306f\u3001\u30d8\u30c3\u30c0\u30fc\u672c\u4f53 CRC32\u3001key \u9818\u57df CRC32\u3001version\u3001sector size\u3001volume size\u3001hidden volume size\u3001master key offset\u3001master key size \u3067\u3042\u308b\u3002CRC \u304c\u4e0d\u4e00\u81f4\u306e\u5834\u5408\u306f\u4e0d\u6b63\u30d8\u30c3\u30c0\u30fc\u3068\u3057\u3066\u6271\u3046\u3002\u5909\u63db\u5f8c\u3001crypt_params_tcrypt \u306b hash \u540d\u3001key size\u3001cipher \u540d\u3001mode \u540d\u3092\u8a2d\u5b9a\u3059\u308b\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u5f8c\u7d9a\u306e activation \u51e6\u7406\u304c\u30d8\u30c3\u30c0\u30fc\u304b\u3089\u5f97\u3089\u308c\u305f\u6697\u53f7\u65b9\u5f0f\u3092\u5229\u7528\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308b\u3002<\/p>\n<p>TCRYPT_activate \u306f\u3001\u5fa9\u53f7\u6e08\u307f TCRYPT \u30d8\u30c3\u30c0\u30fc\u3092\u3082\u3068\u306b dm-crypt mapping \u3092\u4f5c\u6210\u3059\u308b\u51e6\u7406\u3067\u3042\u308b\u3002\u3053\u306e\u95a2\u6570\u306f\u3001\u307e\u305a\u30d8\u30c3\u30c0\u30fc\u304c\u5fa9\u53f7\u6e08\u307f\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u3002\u30d8\u30c3\u30c0\u30fc\u304c\u8aad\u307f\u8fbc\u307e\u308c\u3066\u3044\u306a\u3044\u72b6\u614b\u3067\u306f activation \u3092\u62d2\u5426\u3059\u308b\u3002\u6b21\u306b sector size \u3092\u691c\u8a3c\u3059\u308b\u3002sector size \u304c cryptsetup \u306e\u60f3\u5b9a sector \u5358\u4f4d\u3068\u6574\u5408\u3057\u306a\u3044\u5834\u5408\u306f activation \u4e0d\u53ef\u3068\u3059\u308b\u3002\u3055\u3089\u306b\u3001kernel \u304c\u5bfe\u5fdc\u3057\u306a\u3044 legacy mode \u306f\u62d2\u5426\u3059\u308b\u3002\u7279\u306b tcrypt \u7cfb legacy mode \u306f\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3068\u3057\u3066\u6271\u3048\u3066\u3082\u3001kernel mapping \u3068\u3057\u3066\u306f\u6709\u52b9\u5316\u3067\u304d\u306a\u3044\u5834\u5408\u304c\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>volume \u7a2e\u5225<\/th>\n<th>TCRYPT_activate \u3067\u306e size \u6c7a\u5b9a<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>system encryption<\/td>\n<td>\u5bfe\u8c61 device \u5168\u4f53\u3092\u6271\u3046\u3002<\/td>\n<\/tr>\n<tr>\n<td>hidden volume<\/td>\n<td>hidden volume size \u3092\u4f7f\u3046\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u901a\u5e38 volume<\/td>\n<td>volume size \u3092\u4f7f\u3046\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u305d\u306e\u5f8c\u3001data offset\u3001IV offset\u3001cipher spec\u3001volume key \u3092\u69cb\u6210\u3057\u3001device-mapper \u7528\u306e active device \u60c5\u5831\u3092\u7d44\u307f\u7acb\u3066\u308b\u3002\u6700\u7d42\u7684\u306b\u306f\u3001libcryptsetup \u306e activation \u7d4c\u8def\u3092\u901a\u3058\u3066 dm-crypt mapping \u3092\u4f5c\u6210\u3059\u308b\u3002\u3053\u308c\u306b\u3088\u308a\u3001TCRYPT \/ VeraCrypt volume \u306f Linux \u4e0a\u3067\u901a\u5e38\u306e block device \u3068\u3057\u3066\u6271\u3048\u308b\u3088\u3046\u306b\u306a\u308b\u3002<\/p>\n<p>TCRYPT_deactivate \u306f\u3001\u4f5c\u6210\u6e08\u307f mapping \u3092\u89e3\u9664\u3059\u308b\u51e6\u7406\u3067\u3042\u308b\u3002\u3053\u306e\u51e6\u7406\u81ea\u4f53\u306f TCRYPT \u56fa\u6709\u306e\u8907\u96d1\u306a\u30ed\u30b8\u30c3\u30af\u3092\u6301\u305f\u305a\u3001cryptsetup \u306e\u5171\u901a deactivate \u51e6\u7406\u306b\u59d4\u8b72\u3059\u308b\u3002<\/p>\n<p>TCRYPT \u30e2\u30b8\u30e5\u30fc\u30eb\u306f\u3001\u5fa9\u53f7\u6e08\u307f\u30d8\u30c3\u30c0\u30fc\u304b\u3089 data offset\u3001IV offset\u3001volume key\u3001volume key size\u3001header dump \u60c5\u5831\u3092\u53d6\u5f97\u3059\u308b\u88dc\u52a9\u95a2\u6570\u3092\u6301\u3064\u3002\u3053\u308c\u3089\u306f\u3001tcryptDump \u76f8\u5f53\u306e\u60c5\u5831\u8868\u793a\u3084\u3001activation \u6642\u306e device-mapper table \u69cb\u6210\u306b\u5229\u7528\u3055\u308c\u308b\u3002<\/p>\n<h3>9.6 \u51e6\u7406\u30d5\u30ed\u30fc<\/h3>\n<p>\u901a\u5e38\u306e TCRYPT open \u51e6\u7406\u306f\u3001\u6b21\u306e\u9806\u5e8f\u3067\u9032\u3080\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u9806\u5e8f<\/th>\n<th>\u901a\u5e38 open \u51e6\u7406<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1<\/td>\n<td>\u547c\u3073\u51fa\u3057\u5143\u304c CRYPT_TCRYPT \u5f62\u5f0f\u3068\u3057\u3066 cryptsetup \u3092\u521d\u671f\u5316\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>\u30e6\u30fc\u30b6\u30fc\u304c\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3001keyfile\u3001flags\u3001PIM \u306a\u3069\u3092\u6307\u5b9a\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>TCRYPT_read_phdr \u304c device \u304b\u3089\u8a72\u5f53\u30d8\u30c3\u30c0\u30fc\u3092\u8aad\u3080\u3002<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>TCRYPT_init_hdr \u304c KDF \u5019\u88dc\u3092\u8a66\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>\u5404 KDF \u5019\u88dc\u306b\u3064\u3044\u3066\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u9375\u3092\u5c0e\u51fa\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>TCRYPT_decrypt_hdr \u304c cipher \u5019\u88dc\u3092\u8a66\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>7<\/td>\n<td>magic \u3068 CRC \u304c\u6b63\u3057\u3044\u5019\u88dc\u3092\u63a1\u7528\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>8<\/td>\n<td>TCRYPT_hdr_from_disk \u304c params \u3092\u78ba\u5b9a\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>9<\/td>\n<td>TCRYPT_activate \u304c dm-crypt mapping \u3092\u69cb\u6210\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>10<\/td>\n<td>mapping \u6210\u529f\u5f8c\u3001\u5229\u7528\u8005\u306f\u5fa9\u53f7\u6e08\u307f block device \u3068\u3057\u3066\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>hidden volume \u306e\u5834\u5408\u3001\u30d8\u30c3\u30c0\u30fc\u8aad\u307f\u53d6\u308a\u4f4d\u7f6e\u304c\u901a\u5e38 volume \u3068\u7570\u306a\u308b\u3002CRYPT_TCRYPT_HIDDEN_HEADER \u304c\u6307\u5b9a\u3055\u308c\u308b\u3068\u3001TCRYPT_read_phdr \u306f hidden volume header offset \u3092\u8aad\u3080\u3002\u901a\u5e38\u306e hidden header \u3067\u5931\u6557\u3057\u305f\u5834\u5408\u3001\u65e7 offset \u3082\u8a66\u3059\u3002backup header \u304c\u6307\u5b9a\u3055\u308c\u3066\u3044\u308b\u5834\u5408\u306f hidden backup header offset \u3092\u8aad\u3080\u3002\u5fa9\u53f7\u5f8c\u306e activation \u3067\u306f\u3001device size \u3068\u3057\u3066 hidden volume size \u3092\u4f7f\u3046\u3002<\/p>\n<p>system encryption \u306e\u5834\u5408\u3001\u30d8\u30c3\u30c0\u30fc\u306f partition \u5185\u3067\u306f\u306a\u304f\u3001base device \u5074\u306e\u56fa\u5b9a\u4f4d\u7f6e\u306b\u5b58\u5728\u3057\u3046\u308b\u3002\u305d\u306e\u305f\u3081\u3001\u5bfe\u8c61\u304c partition \u3067\u3042\u308c\u3070 base device path \u3092\u53d6\u5f97\u3057\u3001base device \u304b\u3089 system header offset \u3092\u8aad\u3080\u3002activation \u6642\u306b\u306f\u3001system encryption \u7279\u6709\u306e offset \u51e6\u7406\u304c\u5fc5\u8981\u306b\u306a\u308b\u3002\u30d8\u30c3\u30c0\u30fc\u304c partition \u5916\u306b\u3042\u308b\u305f\u3081\u3001data device \u3068 metadata device \u306e\u95a2\u4fc2\u3092\u901a\u5e38 volume \u3068\u540c\u3058\u3088\u3046\u306b\u306f\u6271\u3048\u306a\u3044\u3002<\/p>\n<p>backup header \u304c\u6307\u5b9a\u3055\u308c\u305f\u5834\u5408\u3001\u901a\u5e38\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u3067\u306f\u306a\u304f backup header offset \u3092\u8aad\u3080\u3002\u3053\u308c\u306f\u901a\u5e38 volume \u3068 hidden volume \u306e\u4e21\u65b9\u306b\u5b58\u5728\u3059\u308b\u3002\u901a\u5e38 backup header \u3068 hidden backup header \u306f flags \u306b\u3088\u3063\u3066\u533a\u5225\u3055\u308c\u308b\u3002<\/p>\n<h3>9.7 \u30a8\u30e9\u30fc\u51e6\u7406\u8a2d\u8a08<\/h3>\n<p>\u672c\u5b9f\u88c5\u3067\u306f\u3001device open \u5931\u6557\u3001header read \u5931\u6557\u3001KDF \u4e0d\u4e00\u81f4\u3001cipher \u4e0d\u4e00\u81f4\u3001magic \u4e0d\u4e00\u81f4\u3001CRC \u4e0d\u4e00\u81f4\u3001unsupported sector size\u3001unsupported legacy mode\u3001kernel feature \u4e0d\u8db3\u3001memory allocation \u5931\u6557\u3001keyfile open \/ read \u5931\u6557\u3092\u533a\u5225\u3059\u308b\u3002<\/p>\n<p>\u5fa9\u53f7\u5019\u88dc\u63a2\u7d22\u4e2d\u306e\u5931\u6557\u306f\u3001\u305f\u3060\u3061\u306b\u6700\u7d42\u5931\u6557\u3068\u306f\u3057\u306a\u3044\u3002KDF \/ cipher \u5019\u88dc\u304c\u8907\u6570\u3042\u308b\u305f\u3081\u3001\u4e00\u3064\u306e\u5019\u88dc\u3067\u5931\u6557\u3057\u3066\u3082\u6b21\u306e\u5019\u88dc\u3078\u9032\u3080\u3002\u4e00\u65b9\u3001device open\u3001memory allocation\u3001keyfile read\u3001activation \u4e0d\u53ef\u6761\u4ef6\u306a\u3069\u306f\u3001\u51e6\u7406\u7d99\u7d9a\u304c\u610f\u5473\u3092\u6301\u305f\u306a\u3044\u305f\u3081\u3001\u30a8\u30e9\u30fc\u3068\u3057\u3066\u8fd4\u3059\u3002\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306b\u5931\u6557\u3057\u305f\u5834\u5408\u3001\u8aad\u307f\u53d6\u3063\u305f\u30d8\u30c3\u30c0\u30fc\u9818\u57df\u306f\u30bc\u30ed\u30af\u30ea\u30a2\u3055\u308c\u308b\u3002<\/p>\n<h3>9.8 \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8a2d\u8a08<\/h3>\n<p>\u672c\u5b9f\u88c5\u306f\u3001\u6b21\u306e\u89b3\u70b9\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u914d\u616e\u3092\u6301\u3064\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u89b3\u70b9<\/th>\n<th>\u8a2d\u8a08\u4e0a\u306e\u914d\u616e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u4e00\u6642\u60c5\u5831\u306e\u6d88\u53bb<\/td>\n<td>\u4e00\u6642\u9375\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3001keyfile buffer\u3001IV\u3001backend key \u306a\u3069\u306f\u3001\u51e6\u7406\u5f8c\u306b\u5b89\u5168\u6d88\u53bb\u3055\u308c\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u5fa9\u53f7\u6210\u529f\u5224\u5b9a<\/td>\n<td>\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306e\u6210\u529f\u5224\u5b9a\u306f magic \u3060\u3051\u306b\u4f9d\u5b58\u305b\u305a\u3001CRC \u691c\u8a3c\u306b\u3088\u308a\u5fa9\u53f7\u7d50\u679c\u306e\u6574\u5408\u6027\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u5019\u88dc\u5236\u9650<\/td>\n<td>TCRYPT \/ VeraCrypt \u306e\u4ed5\u69d8\u4e0a\u5fc5\u8981\u306a KDF \/ cipher \u5019\u88dc\u3092\u8a66\u3059\u304c\u3001flags \u306b\u3088\u3063\u3066 legacy mode \u3084 VeraCrypt mode \u3092\u5236\u9650\u3067\u304d\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>activation \u5236\u9650<\/td>\n<td>kernel \u304c\u5bfe\u5fdc\u3057\u306a\u3044 mode \u306f activation \u6642\u306b\u62d2\u5426\u3057\u3001\u5b89\u5168\u306b block device \u3068\u3057\u3066\u516c\u958b\u3067\u304d\u306a\u3044\u69cb\u6210\u3092\u6392\u9664\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>mapping \u524d\u691c\u8a3c<\/td>\n<td>device-mapper mapping \u3092\u4f5c\u6210\u3059\u308b\u524d\u306b sector size\u3001volume size\u3001offset\u3001cipher spec \u3092\u78ba\u8a8d\u3059\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u305f\u3060\u3057\u3001\u672c\u5b9f\u88c5\u306f TCRYPT \/ VeraCrypt \u5f62\u5f0f\u305d\u306e\u3082\u306e\u306e\u5b89\u5168\u6027\u3092\u6539\u5584\u3059\u308b\u3082\u306e\u3067\u306f\u306a\u3044\u3002\u65e2\u5b58\u5f62\u5f0f\u3092\u8aad\u307f\u53d6\u308b\u4e92\u63db\u5b9f\u88c5\u3067\u3042\u308a\u3001\u6697\u53f7\u8a2d\u8a08\u4e0a\u306e\u8a55\u4fa1\u306f\u5143\u5f62\u5f0f\u306b\u4f9d\u5b58\u3059\u308b\u3002<\/p>\n<h3>9.9 \u4e92\u63db\u6027\u8a2d\u8a08<\/h3>\n<p>\u672c\u5b9f\u88c5\u306f\u3001TrueCrypt \u3068 VeraCrypt \u306e\u5dee\u7570\u3092\u3001magic \u306e\u9055\u3044\u3001KDF \/ hash \/ iteration count \u306e\u9055\u3044\u3001VeraCrypt PIM \u306e\u6271\u3044\u3001keyfile pool length \u306e\u9055\u3044\u3001cipher \/ mode \u5019\u88dc\u306e\u9055\u3044\u3001legacy mode \u306e\u6271\u3044\u3001hidden volume header offset \u306e\u9055\u3044\u3001system encryption header offset \u306e\u9055\u3044\u3067\u5438\u53ce\u3059\u308b\u3002<\/p>\n<p>TrueCrypt \u7531\u6765\u306e legacy mode \u306b\u3064\u3044\u3066\u306f\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306e\u305f\u3081\u306b\u5b9f\u88c5\u3055\u308c\u3066\u3044\u308b\u3082\u306e\u304c\u3042\u308b\u3002\u4e00\u65b9\u3067\u3001kernel dm-crypt \u304c\u5bfe\u5fdc\u3067\u304d\u306a\u3044 mode \u306b\u3064\u3044\u3066\u306f activation \u3067\u304d\u306a\u3044\u3002\u3057\u305f\u304c\u3063\u3066\u3001\u672c\u5b9f\u88c5\u306e\u4e92\u63db\u6027\u306f\u3001\u30d8\u30c3\u30c0\u30fc\u3092\u8a8d\u8b58\u3067\u304d\u308b\u3053\u3068\u3068\u3001\u5b9f\u969b\u306b mapping \u3068\u3057\u3066\u6709\u52b9\u5316\u3067\u304d\u308b\u3053\u3068\u3092\u5206\u3051\u3066\u8003\u3048\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002<\/p>\n<h3>9.10 \u8cac\u52d9\u5206\u96e2<\/h3>\n<p>tcrypt.c \u304c\u6301\u3064\u3079\u304d\u8cac\u52d9\u306f\u3001TCRYPT \/ VeraCrypt \u56fa\u6709\u4ed5\u69d8\u306e\u5438\u53ce\u3001\u30d8\u30c3\u30c0\u30fc\u4f4d\u7f6e\u6c7a\u5b9a\u3001KDF \u5019\u88dc\u9078\u629e\u3001keyfile pool \u51e6\u7406\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3001\u30d8\u30c3\u30c0\u30fc\u691c\u8a3c\u3001params \u69cb\u7bc9\u3001activation \u306b\u5fc5\u8981\u306a TCRYPT \u56fa\u6709\u30d1\u30e9\u30e1\u30fc\u30bf\u306e\u7b97\u51fa\u3067\u3042\u308b\u3002<\/p>\n<p>tcrypt.c \u304c\u6301\u3064\u3079\u304d\u3067\u306a\u3044\u8cac\u52d9\u306f\u3001\u6c4e\u7528 device \u64cd\u4f5c\u306e\u518d\u5b9f\u88c5\u3001\u6c4e\u7528\u6697\u53f7\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u306e\u518d\u5b9f\u88c5\u3001dm-crypt table \u64cd\u4f5c\u306e\u76f4\u63a5\u5b9f\u88c5\u3001LUKS \u30e1\u30bf\u30c7\u30fc\u30bf\u51e6\u7406\u3001\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u51e6\u7406\u3001TCRYPT \u5f62\u5f0f\u306e\u4f5c\u6210\u30fb\u66f4\u65b0\u51e6\u7406\u3067\u3042\u308b\u3002\u3053\u306e\u5206\u96e2\u306b\u3088\u308a\u3001TCRYPT \u56fa\u6709\u306e\u4e92\u63db\u51e6\u7406\u3092\u5c0f\u3055\u306a\u7bc4\u56f2\u306b\u9589\u3058\u8fbc\u3081\u3064\u3064\u3001\u5b9f\u969b\u306e\u6697\u53f7\u51e6\u7406\u3068 device \u7ba1\u7406\u306f\u65e2\u5b58\u57fa\u76e4\u3078\u59d4\u8b72\u3067\u304d\u308b\u3002<\/p>\n<h3>9.11 \u5236\u7d04\u4e8b\u9805<\/h3>\n<p>\u672c\u5b9f\u88c5\u306b\u306f\u5236\u7d04\u304c\u3042\u308b\u3002TCRYPT \/ VeraCrypt volume \u306e\u65b0\u898f\u4f5c\u6210\u306f\u6271\u308f\u306a\u3044\u3002\u30d8\u30c3\u30c0\u30fc\u66f4\u65b0\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u5909\u66f4\u3001keyfile \u5909\u66f4\u306f\u6271\u308f\u306a\u3044\u3002\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3067\u304d\u3066\u3082\u3001kernel \u304c mode \u3092\u30b5\u30dd\u30fc\u30c8\u3057\u306a\u3051\u308c\u3070 activation \u3067\u304d\u306a\u3044\u3002legacy mode \u306f flags \u306b\u3088\u308a\u660e\u793a\u7684\u306b\u8a31\u53ef\u3055\u308c\u306a\u3044\u9650\u308a\u5019\u88dc\u304b\u3089\u9664\u5916\u3055\u308c\u308b\u3002VeraCrypt mode \u3082 flags \u306b\u3088\u308a\u660e\u793a\u7684\u306b\u6271\u308f\u308c\u308b\u3002hidden volume \u306f\u901a\u5e38 volume \u3068\u7570\u306a\u308b header offset \u3068 volume size \u3092\u6301\u3064\u305f\u3081\u3001\u901a\u5e38 volume \u3068\u540c\u4e00\u8996\u3067\u304d\u306a\u3044\u3002system encryption \u306f metadata device \u3068 data device \u306e\u95a2\u4fc2\u304c\u901a\u5e38 volume \u3068\u7570\u306a\u308b\u3002<\/p>\n<h3>9.12 \u4fdd\u5b88\u4e0a\u306e\u6ce8\u610f\u70b9<\/h3>\n<p>KDF \u5019\u88dc\u3084 cipher \u5019\u88dc\u3092\u8ffd\u52a0\u30fb\u5909\u66f4\u3059\u308b\u5834\u5408\u306f\u3001\u5bfe\u5fdc\u3059\u308b cryptographic backend \u304c\u5b58\u5728\u3059\u308b\u3053\u3068\u3001kernel dm-crypt \u304c activation \u306b\u5fc5\u8981\u306a mode \u3092\u30b5\u30dd\u30fc\u30c8\u3059\u308b\u3053\u3068\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3060\u3051\u3067\u5fc5\u8981\u306a\u51e6\u7406\u304b activation \u307e\u3067\u5fc5\u8981\u306a\u51e6\u7406\u304b\u3092\u533a\u5225\u3059\u308b\u3053\u3068\u3001legacy mode \u3092\u901a\u5e38\u5019\u88dc\u306b\u6df7\u305c\u306a\u3044\u3053\u3068\u3001VeraCrypt PIM \u306e iteration count \u8a08\u7b97\u3092\u58ca\u3055\u306a\u3044\u3053\u3068\u3001key offset \/ IV offset \/ chain key size \u306e\u6574\u5408\u6027\u3092\u5d29\u3055\u306a\u3044\u3053\u3068\u3001CRC \u691c\u8a3c\u3092\u8fc2\u56de\u3057\u306a\u3044\u3053\u3068\u3001\u4e00\u6642\u9375\u3068 buffer \u306e\u5b89\u5168\u6d88\u53bb\u3092\u7dad\u6301\u3059\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002<\/p>\n<p>\u7279\u306b chained cipher \u306e key layout \u306f\u3001\u5358\u7d14\u306a key size \u306e\u5408\u7b97\u3067\u306f\u306a\u304f\u3001mode \u3054\u3068\u306e offset \u3068 extra key \u9818\u57df\u3092\u542b\u3080\u3002\u3053\u3053\u3092\u8aa4\u308b\u3068\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306b\u5931\u6557\u3059\u308b\u3060\u3051\u3067\u306a\u304f\u3001\u8aa4\u3063\u305f mapping \u3092\u4f5c\u308b\u5371\u967a\u304c\u3042\u308b\u3002<\/p>\n<h3>9.13 \u8a2d\u8a08\u4e0a\u306e\u8981\u70b9<\/h3>\n<p>\u672c\u5b9f\u88c5\u306e\u672c\u8cea\u306f\u3001TCRYPT \/ VeraCrypt \u3092 Linux \u4e0a\u3067\u65b0\u3057\u3044\u4e3b\u5f62\u5f0f\u3068\u3057\u3066\u6271\u3046\u3053\u3068\u3067\u306f\u306a\u3044\u3002\u672c\u8cea\u306f\u3001\u65e2\u5b58\u306e TCRYPT \/ VeraCrypt volume \u304b\u3089\u3001dm-crypt \u306b\u5fc5\u8981\u306a\u60c5\u5831\u3092\u5fa9\u5143\u3059\u308b\u3053\u3068\u3067\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u8981\u70b9<\/th>\n<th>\u8aac\u660e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u5f62\u5f0f\u56fa\u6709\u306e\u77e5\u8b58<\/td>\n<td>TCRYPT \/ VeraCrypt \u56fa\u6709\u306e\u77e5\u8b58\u306f tcrypt.c \u306b\u96c6\u7d04\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u6697\u53f7\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0<\/td>\n<td>\u6697\u53f7\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u81ea\u4f53\u306f backend \u306b\u59d4\u8b72\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>block device \u5316<\/td>\n<td>block device \u5316\u306f dm-crypt \u306b\u59d4\u8b72\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u5019\u88dc\u5236\u9650<\/td>\n<td>\u30e6\u30fc\u30b6\u30fc\u304c\u6307\u5b9a\u3057\u306a\u3044\u9650\u308a\u3001legacy mode \u3084 VeraCrypt mode \u3092\u4e0d\u7528\u610f\u306b\u5e83\u3052\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u8aad\u307f\u53d6\u308a\u4e92\u63db<\/td>\n<td>\u8aad\u307f\u53d6\u308a\u4e92\u63db\u3092\u4e2d\u5fc3\u306b\u7f6e\u304d\u3001\u5f62\u5f0f\u4f5c\u6210\u3084\u30d8\u30c3\u30c0\u30fc\u66f4\u65b0\u306b\u306f\u8e0f\u307f\u8fbc\u307e\u306a\u3044\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u3053\u306e\u8a2d\u8a08\u306b\u3088\u308a\u3001\u6bd4\u8f03\u7684\u5c11\u306a\u3044\u30b3\u30fc\u30c9\u91cf\u3067\u3001TCRYPT \/ VeraCrypt \u65e2\u5b58\u8cc7\u7523\u3092 cryptsetup \u306e\u6a19\u6e96\u64cd\u4f5c\u4f53\u7cfb\u306b\u63a5\u7d9a\u3057\u3066\u3044\u308b\u3002<\/p>\n<hr>\n<h2>10. dm-crypt \u3078\u6e21\u3059\u3068\u3044\u3046\u3053\u3068<\/h2>\n<p>tcrypt.c \u306e\u8a2d\u8a08\u3092\u7406\u89e3\u3059\u308b\u306b\u306f\u3001dm-crypt \u306e\u4f4d\u7f6e\u3065\u3051\u3082\u78ba\u8a8d\u3059\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002Linux kernel documentation \u306f\u3001dm-crypt \u3092 device-mapper target \u3068\u3057\u3066\u8aac\u660e\u3057\u3001kernel crypto API \u3092\u4f7f\u3063\u3066 block device \u306e\u900f\u904e\u7684\u306a\u6697\u53f7\u5316\u3092\u63d0\u4f9b\u3059\u308b\u3082\u306e\u3068\u3057\u3066\u3044\u308b<a href=\"#ref24\">[24]<\/a>\u3002device-mapper \u306f\u3001kernel \u5185\u3067 block device \u3092 mapping \u3059\u308b\u4ed5\u7d44\u307f\u3067\u3042\u308a\u3001dm-crypt \u306f\u305d\u306e\u6697\u53f7\u5316 target \u3067\u3042\u308b<a href=\"#ref25\">[25]<\/a>\u3002<\/p>\n<p>\u3064\u307e\u308a\u3001tcrypt.c \u304c\u6700\u7d42\u7684\u306b\u3084\u308b\u3053\u3068\u306f\u3001TCRYPT \/ VeraCrypt volume \u3092\u30e6\u30fc\u30b6\u30fc\u30e9\u30f3\u30c9\u3060\u3051\u3067\u5fa9\u53f7\u3059\u308b\u3053\u3068\u3067\u306f\u306a\u3044\u3002\u30d8\u30c3\u30c0\u30fc\u304b\u3089\u53d6\u308a\u51fa\u3057\u305f master key\u3001cipher spec\u3001offset\u3001size \u3092\u4f7f\u3063\u3066\u3001dm-crypt \u304c\u6271\u3048\u308b mapping \u3092\u4f5c\u308b\u3053\u3068\u3067\u3042\u308b\u3002mapping \u304c\u4f5c\u3089\u308c\u308b\u3068\u3001\u5229\u7528\u8005\u306b\u306f\u5fa9\u53f7\u6e08\u307f block device \u306e\u3088\u3046\u306b\u898b\u3048\u308b\u3002<\/p>\n<p>\u3053\u3053\u3067\u3001\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u3068\u30c7\u30fc\u30bf\u5fa9\u53f7\u306f\u5206\u3051\u3066\u8003\u3048\u308b\u5fc5\u8981\u304c\u3042\u308b\u3002\u30d8\u30c3\u30c0\u30fc\u5fa9\u53f7\u306f\u3001\u3069\u306e\u9375\u3068\u65b9\u5f0f\u3067 volume \u3092\u958b\u304f\u304b\u3092\u77e5\u308b\u305f\u3081\u306e\u51e6\u7406\u3067\u3042\u308b\u3002\u30c7\u30fc\u30bf\u5fa9\u53f7\u306f\u3001\u958b\u304b\u308c\u305f mapping \u306b\u5bfe\u3057\u3066 block I\/O \u304c\u884c\u308f\u308c\u308b\u305f\u3073\u306b kernel \u5074\u3067\u51e6\u7406\u3055\u308c\u308b\u3002tcrypt.c \u306f\u524d\u8005\u3092\u4e2d\u5fc3\u306b\u62c5\u5f53\u3057\u3001\u5f8c\u8005\u306f dm-crypt \u306b\u59d4\u8b72\u3059\u308b\u3002<\/p>\n<p>dm-integrity \u306e\u3088\u3046\u306a device-mapper target \u306f\u3001block device \u306e\u5b8c\u5168\u6027\u4fdd\u8b77\u3092\u6271\u3046\u5225\u306e\u5c64\u3067\u3042\u308b<a href=\"#ref26\">[26]<\/a>\u3002\u672c\u7a3f\u306e\u4e3b\u984c\u306f TCRYPT \u4e92\u63db\u3067\u3042\u308a\u3001\u5b8c\u5168\u6027\u4fdd\u8b77\u305d\u306e\u3082\u306e\u3067\u306f\u306a\u3044\u3002\u3057\u304b\u3057\u3001\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u904b\u7528\u304c\u6a5f\u5bc6\u6027\u3060\u3051\u3067\u306a\u304f\u3001\u5f62\u5f0f\u4e92\u63db\u6027\u3001\u5b8c\u5168\u6027\u3001\u5fa9\u5143\u78ba\u8a8d\u3001\u9000\u5f79\u5224\u65ad\u307e\u3067\u542b\u3080\u5e83\u3044\u554f\u984c\u3078\u63a5\u7d9a\u3059\u308b\u3053\u3068\u306f\u3001\u3053\u3053\u304b\u3089\u3082\u5206\u304b\u308b\u3002<\/p>\n<hr>\n<h2>11. \u3053\u306e\u30b3\u30fc\u30c9\u304c\u3084\u3089\u306a\u3044\u3053\u3068<\/h2>\n<p>tcrypt.c \u306f TCRYPT \/ VeraCrypt \u306e\u3059\u3079\u3066\u3092\u6271\u3046\u30b3\u30fc\u30c9\u3067\u306f\u306a\u3044\u3002\u3053\u308c\u306f\u3001\u6a5f\u80fd\u4e0d\u8db3\u3068\u3044\u3046\u3088\u308a\u3001\u8cac\u52d9\u3092\u7d5e\u3063\u305f\u4e92\u63db\u30b3\u30fc\u30c9\u3067\u3042\u308b\u3002cryptsetup \u306e man page \u306f\u3001TCRYPT header \u306f\u6697\u53f7\u5316\u3055\u308c\u3066\u3044\u308b\u305f\u3081\u6709\u52b9\u306a passphrase \u3068 keyfiles \u304c\u5fc5\u8981\u3067\u3042\u308a\u3001cryptsetup \u306f\u30d8\u30c3\u30c0\u30fc variant \u3092\u8a8d\u8b58\u3059\u308b\u4e00\u65b9\u3067\u3001\u3044\u304f\u3064\u304b\u306e legacy cipher chain \u306b\u306f\u5236\u9650\u304c\u3042\u308b\u3068\u8aac\u660e\u3057\u3066\u3044\u308b<a href=\"#ref12\">[12]<\/a>\u3002\u307e\u305f\u3001tcryptDump \u306f\u8a8d\u8b58\u53ef\u80fd\u306a TCRYPT device \u306e header \u60c5\u5831\u3092 dump \u3059\u308b\u305f\u3081\u306e\u6a5f\u80fd\u3068\u3057\u3066\u8aac\u660e\u3055\u308c\u308b<a href=\"#ref27\">[27]<\/a>\u3002<\/p>\n<p>\u3053\u3053\u3067\u91cd\u8981\u306a\u306e\u306f\u3001\u8a8d\u8b58\u3067\u304d\u308b\u3053\u3068\u3001dump \u3067\u304d\u308b\u3053\u3068\u3001mapping \u3068\u3057\u3066\u6709\u52b9\u5316\u3067\u304d\u308b\u3053\u3068\u3001\u5f62\u5f0f\u3092\u4f5c\u6210\u30fb\u66f4\u65b0\u3067\u304d\u308b\u3053\u3068\u304c\u3001\u305d\u308c\u305e\u308c\u5225\u3067\u3042\u308b\u70b9\u3067\u3042\u308b\u3002tcrypt.c \u306f\u4e3b\u306b\u65e2\u5b58 volume \u3092\u958b\u304f\u65b9\u5411\u306b\u8a2d\u8a08\u3055\u308c\u3066\u3044\u308b\u3002TCRYPT volume \u306e\u65b0\u898f\u4f5c\u6210\u3001\u30d8\u30c3\u30c0\u30fc\u66f4\u65b0\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u5909\u66f4\u3001keyfile \u5909\u66f4\u3001\u30d8\u30c3\u30c0\u30fc\u518d\u6697\u53f7\u5316\u3001GUI \u6a5f\u80fd\u3001\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u51e6\u7406\u306f\u5bfe\u8c61\u5916\u3067\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u6a5f\u80fd<\/th>\n<th>tcrypt.c \u306e\u4f4d\u7f6e\u3065\u3051<\/th>\n<th>\u904b\u7528\u4e0a\u306e\u610f\u5473<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u65e2\u5b58 volume \u3092\u958b\u304f<\/td>\n<td>\u4e2d\u5fc3\u7684\u306a\u5bfe\u8c61\u3067\u3042\u308b\u3002<\/td>\n<td>\u904e\u53bb\u8cc7\u7523\u3078\u5230\u9054\u3059\u308b\u305f\u3081\u306e\u4e92\u63db\u7d4c\u8def\u306b\u306a\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u60c5\u5831\u3092\u8868\u793a\u3059\u308b<\/td>\n<td>dump \u7cfb\u306e\u88dc\u52a9\u6a5f\u80fd\u3068\u3057\u3066\u6271\u308f\u308c\u308b\u3002<\/td>\n<td>\u5a92\u4f53\u8abf\u67fb\u3084\u79fb\u884c\u524d\u78ba\u8a8d\u306b\u5f79\u7acb\u3064\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u65b0\u898f volume \u3092\u4f5c\u308b<\/td>\n<td>\u5bfe\u8c61\u5916\u3067\u3042\u308b\u3002<\/td>\n<td>\u65b0\u898f\u4e3b\u7cfb\u3068\u3057\u3066 TCRYPT \u3092\u5897\u3084\u3059\u8a2d\u8a08\u3067\u306f\u306a\u3044\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d8\u30c3\u30c0\u30fc\u3092\u66f8\u304d\u63db\u3048\u308b<\/td>\n<td>\u5bfe\u8c61\u5916\u3067\u3042\u308b\u3002<\/td>\n<td>\u65e2\u5b58\u30d8\u30c3\u30c0\u30fc\u3092\u5909\u66f4\u305b\u305a\u3001\u8aad\u307f\u53d6\u308a\u4e92\u63db\u3078\u5bc4\u305b\u3066\u3044\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u53e4\u3044\u5f62\u5f0f\u3078\u306e\u5bfe\u5fdc\u306f\u3001\u5168\u6a5f\u80fd\u518d\u5b9f\u88c5\u3067\u3042\u308b\u5fc5\u8981\u306f\u306a\u3044\u3002\u9577\u671f\u904b\u7528\u3067\u5fc5\u8981\u306a\u306e\u306f\u3001\u8aad\u3080\u3053\u3068\u3001\u78ba\u8a8d\u3059\u308b\u3053\u3068\u3001\u79fb\u884c\u3059\u308b\u3053\u3068\u3001\u5fc5\u8981\u306a\u3089\u9000\u5f79\u3059\u308b\u3053\u3068\u3067\u3042\u308b\u3002tcrypt.c \u306f\u3001\u305d\u306e\u305f\u3081\u306e\u6700\u5c0f\u3060\u304c\u91cd\u8981\u306a\u7d4c\u8def\u3092\u63d0\u4f9b\u3057\u3066\u3044\u308b\u3002<\/p>\n<hr>\n<h2>12. \u8aad\u3081\u308b\u3053\u3068\u3068\u3001\u4e3b\u7cfb\u3068\u3057\u3066\u4f7f\u3046\u3053\u3068\u306f\u9055\u3046<\/h2>\n<p>TCRYPT \/ VeraCrypt \u4e92\u63db\u304c\u5b58\u5728\u3059\u308b\u3053\u3068\u306f\u3001TrueCrypt \/ VeraCrypt \u3092\u65b0\u898f\u4e3b\u7cfb\u3068\u3057\u3066\u4f7f\u3044\u7d9a\u3051\u308b\u7406\u7531\u306b\u306f\u306a\u3089\u306a\u3044\u3002Debian \u306e\u53e4\u3044 man page \u3067\u306f\u3001cryptsetup \u304c historical loopaes \u3068 TrueCrypt compatible volumes \u3092\u30b5\u30dd\u30fc\u30c8\u3059\u308b\u3068\u8aac\u660e\u3055\u308c\u3066\u3044\u308b<a href=\"#ref28\">[28]<\/a>\u3002\u305d\u306e\u5f8c\u306e Debian man page \u3067\u306f\u3001loop-AES\u3001TrueCrypt\u3001VeraCrypt\u3001BitLocker compatible volumes \u306b limited support \u304c\u3042\u308b\u3068\u8aac\u660e\u3055\u308c\u3066\u3044\u308b<a href=\"#ref29\">[29]<\/a>\u3002\u3053\u3053\u304b\u3089\u3082\u3001cryptsetup \u306f LUKS \u3060\u3051\u3067\u306a\u304f\u4e92\u63db\u5f62\u5f0f\u3092\u6271\u3063\u3066\u304d\u305f\u304c\u3001\u305d\u308c\u306f\u4e3b\u7cfb\u5f62\u5f0f\u3068\u3057\u3066\u63a8\u5968\u3059\u308b\u3053\u3068\u3068\u306f\u5225\u3067\u3042\u308b\u3002<\/p>\n<p>\u6a19\u6e96\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b TrueCrypt \/ VeraCrypt \u306e\u81ea\u52d5\u5c0e\u5165\u3092\u6b8b\u3057\u7d9a\u3051\u308b\u3068\u3001\u65b0\u898f\u74b0\u5883\u306e\u6a19\u6e96\u69cb\u6210\u304c\u66d6\u6627\u306b\u306a\u308b\u3002LUKS2 \u3092\u4e3b\u7cfb\u306b\u3059\u308b\u306e\u3067\u3042\u308c\u3070\u3001\u901a\u5e38\u306e Debian setup \u3067\u306f LUKS \u95a2\u9023\u306e\u73fe\u884c\u904b\u7528\u306b\u5bc4\u305b\u308b\u65b9\u304c\u3088\u3044\u3002\u4e00\u65b9\u3067\u3001TrueCrypt \/ VeraCrypt \u306e\u500b\u5225\u30a4\u30f3\u30b9\u30c8\u30fc\u30e9\u30fc\u3084 cryptsetup \u306e TCRYPT \u4e92\u63db\u6a5f\u80fd\u307e\u3067\u6d88\u3057\u3066\u3057\u307e\u3046\u3068\u3001\u904e\u53bb\u8cc7\u7523\u3078\u306e\u5230\u9054\u7d4c\u8def\u304c\u5f31\u304f\u306a\u308b\u3002<\/p>\n<p>\u3057\u305f\u304c\u3063\u3066\u3001\u5408\u7406\u7684\u306a\u5206\u96e2\u306f\u3001\u6a19\u6e96\u69cb\u6210\u304b\u3089\u306f\u5916\u3057\u3001\u5fc5\u8981\u6642\u306e\u4e92\u63db\u7d4c\u8def\u3068\u3057\u3066\u6b8b\u3059\u3053\u3068\u3067\u3042\u308b\u3002\u3053\u308c\u306f\u3001\u53e4\u3044\u5f62\u5f0f\u3092\u7121\u6761\u4ef6\u306b\u6b8b\u3059\u3053\u3068\u3067\u3082\u3001\u5373\u5ea7\u306b\u6368\u3066\u308b\u3053\u3068\u3067\u3082\u306a\u3044\u3002\u65b0\u898f\u4e3b\u7cfb\u3001\u4e92\u63db\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3001\u8aad\u307f\u53d6\u308a\u4e2d\u5fc3\u30a2\u30fc\u30ab\u30a4\u30d6\u3001\u79fb\u884c\u5bfe\u8c61\u3001\u9000\u5f79\u5019\u88dc\u3092\u5206\u3051\u3066\u6271\u3046\u8a2d\u8a08\u3067\u3042\u308b\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u5206\u985e<\/th>\n<th>\u610f\u5473<\/th>\n<th>TrueCrypt \/ TCRYPT \u65e7\u8cc7\u7523\u306e\u6271\u3044<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u65b0\u898f\u4e3b\u7cfb<\/td>\n<td>\u4eca\u5f8c\u3082\u6a19\u6e96\u3068\u3057\u3066\u5897\u3084\u3059\u69cb\u6210\u3067\u3042\u308b\u3002<\/td>\n<td>\u8a72\u5f53\u3057\u306a\u3044\u3002LUKS2 \u306a\u3069\u73fe\u884c\u4e3b\u7cfb\u3078\u5bc4\u305b\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u4e92\u63db\u30d0\u30c3\u30af\u30a2\u30c3\u30d7<\/td>\n<td>\u904e\u53bb\u8cc7\u7523\u3078\u5230\u9054\u3059\u308b\u305f\u3081\u306b\u6b8b\u3059\u7d4c\u8def\u3067\u3042\u308b\u3002<\/td>\n<td>\u8a72\u5f53\u3059\u308b\u3002\u5fc5\u8981\u6642\u306b cryptsetup \u306e TCRYPT \u4e92\u63db\u3067\u78ba\u8a8d\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u8aad\u307f\u53d6\u308a\u4e2d\u5fc3\u30a2\u30fc\u30ab\u30a4\u30d6<\/td>\n<td>\u5185\u5bb9\u78ba\u8a8d\u3084\u79fb\u884c\u306e\u305f\u3081\u306b\u4fdd\u6301\u3059\u308b\u304c\u3001\u7a4d\u6975\u7684\u306b\u306f\u66f4\u65b0\u3057\u306a\u3044\u69cb\u6210\u3067\u3042\u308b\u3002<\/td>\n<td>\u8a72\u5f53\u3057\u5f97\u308b\u3002\u66f8\u304d\u8fbc\u307f\u904b\u7528\u306f\u614e\u91cd\u306b\u5206\u96e2\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u79fb\u884c\u5bfe\u8c61<\/td>\n<td>\u73fe\u884c\u5f62\u5f0f\u3078\u5185\u5bb9\u3092\u79fb\u3059\u5bfe\u8c61\u3067\u3042\u308b\u3002<\/td>\n<td>\u8a72\u5f53\u3059\u308b\u3002LUKS + ext4 \u306a\u3069\u3078\u6bb5\u968e\u79fb\u884c\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u9000\u5f79\u5019\u88dc<\/td>\n<td>\u79fb\u884c\u3068\u78ba\u8a8d\u304c\u7d42\u308f\u308c\u3070\u5ec3\u6b62\u3067\u304d\u308b\u69cb\u6210\u3067\u3042\u308b\u3002<\/td>\n<td>\u8a72\u5f53\u3059\u308b\u3002\u8aad\u3081\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u305f\u3046\u3048\u3067\u9000\u5f79\u6761\u4ef6\u3092\u6c7a\u3081\u308b\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u8aad\u3081\u308b\u3053\u3068\u306f\u3001\u4f7f\u3044\u7d9a\u3051\u308b\u3053\u3068\u3067\u306f\u306a\u3044\u3002\u4e92\u63db\u30b3\u30fc\u30c9\u304c\u3042\u308b\u304b\u3089\u65b0\u898f\u5229\u7528\u3057\u3066\u3088\u3044\u306e\u3067\u306f\u306a\u304f\u3001\u4e92\u63db\u30b3\u30fc\u30c9\u304c\u3042\u308b\u304b\u3089\u904e\u53bb\u8cc7\u7523\u3092\u6551\u6e08\u3067\u304d\u308b\u3002\u3053\u306e\u533a\u5225\u304c\u3001\u53e4\u3044\u6697\u53f7\u5316\u5f62\u5f0f\u3092\u5b89\u5168\u306b\u6271\u3046\u305f\u3081\u306e\u57fa\u790e\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>13. \u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u306e\u9577\u671f\u904b\u7528\u3067\u306f\u3001\u5f62\u5f0f\u4e92\u63db\u6027\u3082\u30ec\u30b8\u30ea\u30a8\u30f3\u30b9\u3067\u3042\u308b<\/h2>\n<p>\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u3084\u9577\u671f\u4fdd\u5b58\u3067\u306f\u3001\u30c7\u30fc\u30bf\u3092\u8907\u88fd\u3059\u308b\u3060\u3051\u3067\u306f\u4e0d\u5341\u5206\u3067\u3042\u308b\u3002\u7269\u7406\u5a92\u4f53\u7ba1\u7406\u306e\u65e2\u7a3f\u3067\u306f\u3001\u5b88\u308b\u3079\u304d\u3082\u306e\u306f\u5a92\u4f53\u305d\u306e\u3082\u306e\u3067\u306f\u306a\u304f\u3001\u5fc5\u8981\u306a\u6642\u70b9\u3067\u610f\u5473\u3042\u308b\u30c7\u30fc\u30bf\u69cb\u9020\u3092\u518d\u69cb\u6210\u3067\u304d\u308b\u53ef\u80fd\u6027\u3067\u3042\u308b\u3068\u6574\u7406\u3057\u305f<a href=\"#ref30\">[30]<\/a>\u3002\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u3067\u306f\u3001\u3053\u306e\u5fa9\u5143\u53ef\u80fd\u6027\u306b\u5f62\u5f0f\u4e92\u63db\u6027\u304c\u5f37\u304f\u95a2\u308f\u308b\u3002<\/p>\n<p>\u6697\u53f7\u5316\u5a92\u4f53\u306e\u5fa9\u5143\u53ef\u80fd\u6027\u306f\u3001\u5a92\u4f53\u3001\u63a5\u7d9a\u7d4c\u8def\u3001\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba\u3001keyfile\u3001\u30d8\u30c3\u30c0\u30fc\u3001\u5bfe\u5fdc\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3001kernel \u6a5f\u80fd\u3001\u30d5\u30a1\u30a4\u30eb\u30b7\u30b9\u30c6\u30e0\u3001\u624b\u9806\u66f8\u3001\u53f0\u5e33\u306e\u7d44\u307f\u5408\u308f\u305b\u3067\u6c7a\u307e\u308b\u3002\u3069\u308c\u304b\u4e00\u3064\u304c\u6b20\u3051\u3066\u3082\u3001\u5fa9\u5143\u4f5c\u696d\u306f\u6b62\u307e\u308b\u3002\u7279\u306b\u30d8\u30c3\u30c0\u30fc\u3068\u5f62\u5f0f\u5b9f\u88c5\u306f\u3001\u6697\u53f7\u5316 block device \u306e\u5165\u53e3\u305d\u306e\u3082\u306e\u3067\u3042\u308b\u3002<\/p>\n<p>cryptsetup \/ dm-crypt \u7cfb\u306e\u4fdd\u5b88\u306f\u3001\u5358\u306b\u6a5f\u5bc6\u6027\u3060\u3051\u3092\u6271\u3046\u3082\u306e\u3067\u306f\u306a\u3044\u3002full disk encryption \u306b\u304a\u3051\u308b data integrity protection \u306e\u8b70\u8ad6\u3082\u3001\u6697\u53f7\u5316\u30b9\u30c8\u30ec\u30fc\u30b8\u304c\u9577\u671f\u904b\u7528\u3001\u5b8c\u5168\u6027\u3001\u5fa9\u5143\u53ef\u80fd\u6027\u306e\u554f\u984c\u3078\u63a5\u7d9a\u3059\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u308b<a href=\"#ref31\">[31]<\/a>\u3002\u672c\u7a3f\u306e\u4e3b\u984c\u306f TCRYPT \u4e92\u63db\u3067\u3042\u308a\u3001\u5b8c\u5168\u6027\u4fdd\u8b77\u305d\u306e\u3082\u306e\u3067\u306f\u306a\u3044\u3002\u3057\u304b\u3057\u3001\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u3092\u4e00\u56de\u4f5c\u3063\u3066\u7d42\u308f\u308a\u306e\u8a2d\u5b9a\u3067\u306f\u306a\u304f\u3001\u7d99\u7d9a\u7684\u306a\u904b\u7528\u8cc7\u7523\u3068\u3057\u3066\u6271\u3046\u3068\u3044\u3046\u70b9\u3067\u306f\u540c\u3058\u554f\u984c\u570f\u306b\u3042\u308b\u3002<\/p>\n<p>\u5f62\u5f0f\u4e92\u63db\u6027\u306f\u3001\u30ec\u30b8\u30ea\u30a8\u30f3\u30b9\u3067\u3042\u308b\u3002\u969c\u5bb3\u6642\u3001\u79fb\u884c\u6642\u3001\u9000\u5f79\u6642\u3001\u76e3\u67fb\u6642\u306b\u3001\u904e\u53bb\u8cc7\u7523\u3078\u5230\u9054\u3067\u304d\u308b\u304b\u3069\u3046\u304b\u306f\u3001\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u904b\u7528\u306e\u7d99\u7d9a\u6027\u3092\u5de6\u53f3\u3059\u308b\u3002\u5f37\u3044\u6697\u53f7\u3067\u9589\u3058\u308b\u3053\u3068\u3060\u3051\u3067\u306f\u5341\u5206\u3067\u306f\u306a\u3044\u3002\u5fc5\u8981\u306a\u3068\u304d\u306b\u3001\u6b63\u3057\u3044\u624b\u9806\u3067\u3001\u6b63\u3057\u304f\u958b\u3051\u308b\u3053\u3068\u304c\u5fc5\u8981\u3067\u3042\u308b\u3002<\/p>\n<hr>\n<h2>14. \u53e4\u3044\u5f62\u5f0f\u3092\u4e3b\u7cfb\u306b\u623b\u3055\u305a\u3001\u5230\u9054\u53ef\u80fd\u6027\u3060\u3051\u3092\u6b8b\u3059<\/h2>\n<p>tcrypt.c \u306e\u5b58\u5728\u306f\u3001\u53e4\u3044\u6697\u53f7\u5316\u5f62\u5f0f\u3092\u5ef6\u547d\u3059\u308b\u8a71\u3067\u306f\u306a\u3044\u3002\u904e\u53bb\u8cc7\u7523\u3078\u306e\u5230\u9054\u53ef\u80fd\u6027\u3092\u4fdd\u3064\u8a2d\u8a08\u306e\u8a71\u3067\u3042\u308b\u3002TrueCrypt \/ VeraCrypt \u3092\u65b0\u898f\u6a19\u6e96\u3068\u3057\u3066\u5897\u3084\u3059\u306e\u3067\u306f\u306a\u304f\u3001\u65e2\u306b\u5b58\u5728\u3059\u308b TCRYPT \/ VeraCrypt volume \u3092\u3001\u5fc5\u8981\u306a\u3068\u304d\u306b cryptsetup \u304b\u3089\u958b\u3051\u308b\u53ef\u80fd\u6027\u3092\u6b8b\u3059\u3002\u3053\u306e\u4f4d\u7f6e\u3065\u3051\u304c\u6700\u3082\u91cd\u8981\u3067\u3042\u308b\u3002<\/p>\n<p>\u6280\u8853\u306e\u9000\u5f79\u306f\u3001\u6d88\u3059\u3053\u3068\u3060\u3051\u3067\u306f\u306a\u3044\u3002\u4e3b\u7cfb\u304b\u3089\u5916\u3057\u3001\u4e92\u63db\u7d4c\u8def\u3078\u79fb\u3057\u3001\u8aad\u307f\u53d6\u308a\u4e2d\u5fc3\u306b\u3057\u3001\u5fc5\u8981\u306a\u3089\u73fe\u884c\u5f62\u5f0f\u3078\u79fb\u884c\u3057\u3001\u79fb\u884c\u6e08\u307f\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304b\u3089\u9000\u5f79\u3059\u308b\u3002\u3053\u306e\u6bb5\u968e\u3092\u8e0f\u3080\u3053\u3068\u3067\u3001\u53e4\u3044\u5f62\u5f0f\u3078\u306e\u904e\u5270\u4f9d\u5b58\u3092\u907f\u3051\u306a\u304c\u3089\u3001\u904e\u53bb\u8cc7\u7523\u306e\u55aa\u5931\u3082\u907f\u3051\u3089\u308c\u308b\u3002<\/p>\n<p>tcrypt.c \u306f\u3001\u305d\u306e\u3088\u3046\u306a\u904b\u7528\u5224\u65ad\u3092\u652f\u3048\u308b\u5c0f\u3055\u306a\u5b9f\u88c5\u3067\u3042\u308b\u3002\u30b3\u30fc\u30c9\u306e\u4e2d\u306b\u306f\u3001KDF \u5019\u88dc\u3001cipher \u5019\u88dc\u3001hidden volume\u3001backup header\u3001system encryption\u3001legacy mode\u3001VeraCrypt PIM\u3001CRC \u691c\u8a3c\u3001dm-crypt mapping \u3078\u306e\u63a5\u7d9a\u304c\u8a70\u3081\u8fbc\u307e\u308c\u3066\u3044\u308b\u3002\u3057\u304b\u3057\u3001\u305d\u306e\u76ee\u7684\u306f\u8907\u96d1\u306a\u3082\u306e\u3092\u5897\u3084\u3059\u3053\u3068\u3067\u306f\u306a\u3044\u3002\u53e4\u3044\u5f62\u5f0f\u3092\u3001\u5fc5\u8981\u306a\u7bc4\u56f2\u3067\u3001\u73fe\u5728\u306e Linux \u74b0\u5883\u3078\u63a5\u7d9a\u3059\u308b\u3053\u3068\u3067\u3042\u308b\u3002<\/p>\n<p>\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u306e\u9577\u671f\u904b\u7528\u306b\u304a\u3051\u308b\u6210\u719f\u3057\u305f\u5224\u65ad\u3068\u306f\u3001\u53e4\u3044\u3082\u306e\u3092\u7121\u6761\u4ef6\u306b\u6b8b\u3059\u3053\u3068\u3067\u3082\u3001\u5373\u5ea7\u306b\u6368\u3066\u308b\u3053\u3068\u3067\u3082\u306a\u3044\u3002\u5f79\u5272\u3092\u5909\u3048\u3066\u7ba1\u7406\u3059\u308b\u3053\u3068\u3067\u3042\u308b\u3002TrueCrypt \/ TCRYPT \u306f\u65b0\u898f\u4e3b\u7cfb\u3067\u306f\u306a\u3044\u3002\u3057\u304b\u3057\u3001\u65e2\u5b58\u8cc7\u7523\u3078\u5230\u9054\u3059\u308b\u305f\u3081\u306e\u4e92\u63db\u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u7d4c\u8def\u3068\u3057\u3066\u306f\u610f\u5473\u304c\u3042\u308b\u3002cryptsetup \u306e tcrypt.c \u306f\u3001\u305d\u306e\u5730\u5473\u3060\u304c\u91cd\u8981\u306a\u7d4c\u8def\u3092\u5b9f\u88c5\u3057\u3066\u3044\u308b\u3002<\/p>\n<hr>\n<h2>\u53c2\u8003\u6587\u732e<\/h2>\n<ol>\n<li id=\"ref1\">id774, TrueCrypt \u8cc7\u7523\u3092 GNU\/Linux \u3067\u4fdd\u5168\u3059\u308b\uff082026-05-16\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/05\/16\/4773\/\">https:\/\/blog.id774.net\/entry\/2026\/05\/16\/4773\/<\/a><\/li>\n<li id=\"ref2\">id774, LUKS \u6697\u53f7\u5316\u306e\u624b\u9806\u3068\u904b\u7528\uff082026-05-11\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/05\/11\/4746\/\">https:\/\/blog.id774.net\/entry\/2026\/05\/11\/4746\/<\/a><\/li>\n<li id=\"ref3\">id774, \u672a\u6765\u306e\u81ea\u5206\u306b\u610f\u5473\u3092\u6b8b\u3059\uff082026-05-12\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/05\/12\/4750\/\">https:\/\/blog.id774.net\/entry\/2026\/05\/12\/4750\/<\/a><\/li>\n<li id=\"ref4\">id774, \u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u3092\u9577\u671f\u904b\u7528\u3059\u308b\u305f\u3081\u306e\u8a2d\u8a08\uff082026-05-30\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/05\/30\/4818\/\">https:\/\/blog.id774.net\/entry\/2026\/05\/30\/4818\/<\/a><\/li>\n<li id=\"ref5\">id774, \u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u904b\u7528\u624b\u9806\u3092\u6574\u7406\u3059\u308b\uff082026-05-31\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/05\/31\/4829\/\">https:\/\/blog.id774.net\/entry\/2026\/05\/31\/4829\/<\/a><\/li>\n<li id=\"ref6\">id774, \u81ea\u7531\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u3060\u3051\u3067\u6697\u53f7\u5316\u5a92\u4f53\u3092\u3069\u3053\u307e\u3067\u6271\u3048\u308b\u304b\uff082026-06-03\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/06\/03\/4849\/\">https:\/\/blog.id774.net\/entry\/2026\/06\/03\/4849\/<\/a><\/li>\n<li id=\"ref7\">id774, A Practical Lifecycle Guide to Operating LUKS Encrypted Disks\uff082026-06-07\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/06\/07\/4864\/\">https:\/\/blog.id774.net\/entry\/2026\/06\/07\/4864\/<\/a><\/li>\n<li id=\"ref8\">TrueCrypt, TrueCrypt. <a href=\"https:\/\/truecrypt.sourceforge.net\/\">https:\/\/truecrypt.sourceforge.net\/<\/a><\/li>\n<li id=\"ref9\">Brian Krebs, True Goodbye: \u2018Using TrueCrypt Is Not Secure\u2019\uff082014-05-29\uff09. <a href=\"https:\/\/krebsonsecurity.com\/2014\/05\/true-goodbye-using-truecrypt-is-not-secure\/\">https:\/\/krebsonsecurity.com\/2014\/05\/true-goodbye-using-truecrypt-is-not-secure\/<\/a><\/li>\n<li id=\"ref10\">cryptsetup project, README.md. <a href=\"https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/README.md\">https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/README.md<\/a><\/li>\n<li id=\"ref11\">cryptsetup project, CONTRIBUTING.md. <a href=\"https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/CONTRIBUTING.md\">https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/CONTRIBUTING.md<\/a><\/li>\n<li id=\"ref12\">cryptsetup project, cryptsetup(8). <a href=\"https:\/\/man7.org\/linux\/man-pages\/man8\/cryptsetup.8.html\">https:\/\/man7.org\/linux\/man-pages\/man8\/cryptsetup.8.html<\/a><\/li>\n<li id=\"ref13\">VeraCrypt, Encryption Scheme. <a href=\"https:\/\/veracrypt.io\/en\/Encryption%20Scheme.html\">https:\/\/veracrypt.io\/en\/Encryption%20Scheme.html<\/a><\/li>\n<li id=\"ref14\">cryptsetup project, SECURITY.md. <a href=\"https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/SECURITY.md\">https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/SECURITY.md<\/a><\/li>\n<li id=\"ref15\">Red Hat Research, Milan Bro\u017e. <a href=\"https:\/\/research.redhat.com\/blog\/project_member\/milan\/\">https:\/\/research.redhat.com\/blog\/project_member\/milan\/<\/a><\/li>\n<li id=\"ref16\">cryptsetup project, lib\/tcrypt\/tcrypt.c. <a href=\"https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/lib\/tcrypt\/tcrypt.c\">https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/lib\/tcrypt\/tcrypt.c<\/a><\/li>\n<li id=\"ref17\">cryptsetup project, README.licensing. <a href=\"https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/README.licensing\">https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/README.licensing<\/a><\/li>\n<li id=\"ref18\">SPDX, GNU Lesser General Public License v2.1 or later. <a href=\"https:\/\/spdx.org\/licenses\/LGPL-2.1-or-later.html\">https:\/\/spdx.org\/licenses\/LGPL-2.1-or-later.html<\/a><\/li>\n<li id=\"ref19\">cryptsetup project, lib\/setup.c. <a href=\"https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/lib\/setup.c\">https:\/\/gitlab.com\/cryptsetup\/cryptsetup\/-\/raw\/v2.8.6\/lib\/setup.c<\/a><\/li>\n<li id=\"ref20\">VeraCrypt, Header Key Derivation, Salt, and Iteration Count. <a href=\"https:\/\/veracrypt.io\/en\/Header%20Key%20Derivation.html\">https:\/\/veracrypt.io\/en\/Header%20Key%20Derivation.html<\/a><\/li>\n<li id=\"ref21\">VeraCrypt, Personal Iterations Multiplier (PIM). <a href=\"https:\/\/veracrypt.io\/en\/Personal%20Iterations%20Multiplier%20%28PIM%29.html\">https:\/\/veracrypt.io\/en\/Personal%20Iterations%20Multiplier%20%28PIM%29.html<\/a><\/li>\n<li id=\"ref22\">VeraCrypt, Technical Details. <a href=\"https:\/\/veracrypt.io\/en\/Technical%20Details.html\">https:\/\/veracrypt.io\/en\/Technical%20Details.html<\/a><\/li>\n<li id=\"ref23\">VeraCrypt, VeraCrypt Volume Format Specification. <a href=\"https:\/\/veracrypt.io\/en\/VeraCrypt%20Volume%20Format%20Specification.html\">https:\/\/veracrypt.io\/en\/VeraCrypt%20Volume%20Format%20Specification.html<\/a><\/li>\n<li id=\"ref24\">The Linux Kernel documentation, dm-crypt. <a href=\"https:\/\/docs.kernel.org\/admin-guide\/device-mapper\/dm-crypt.html\">https:\/\/docs.kernel.org\/admin-guide\/device-mapper\/dm-crypt.html<\/a><\/li>\n<li id=\"ref25\">The Linux Kernel documentation, Device Mapper. <a href=\"https:\/\/docs.kernel.org\/admin-guide\/device-mapper\/index.html\">https:\/\/docs.kernel.org\/admin-guide\/device-mapper\/index.html<\/a><\/li>\n<li id=\"ref26\">The Linux Kernel documentation, dm-integrity. <a href=\"https:\/\/docs.kernel.org\/admin-guide\/device-mapper\/dm-integrity.html\">https:\/\/docs.kernel.org\/admin-guide\/device-mapper\/dm-integrity.html<\/a><\/li>\n<li id=\"ref27\">cryptsetup project, cryptsetup-tcryptDump(8). <a href=\"https:\/\/man7.org\/linux\/man-pages\/man8\/cryptsetup-tcryptDump.8.html\">https:\/\/man7.org\/linux\/man-pages\/man8\/cryptsetup-tcryptDump.8.html<\/a><\/li>\n<li id=\"ref28\">Debian manpages, cryptsetup(8), stretch. <a href=\"https:\/\/manpages.debian.org\/stretch\/cryptsetup-bin\/cryptsetup.8.en.html\">https:\/\/manpages.debian.org\/stretch\/cryptsetup-bin\/cryptsetup.8.en.html<\/a><\/li>\n<li id=\"ref29\">Debian manpages, cryptsetup(8), bullseye. <a href=\"https:\/\/manpages.debian.org\/bullseye\/cryptsetup-bin\/cryptsetup.8.en.html\">https:\/\/manpages.debian.org\/bullseye\/cryptsetup-bin\/cryptsetup.8.en.html<\/a><\/li>\n<li id=\"ref30\">id774, \u30d0\u30c3\u30af\u30a2\u30c3\u30d7\u30fb\u30ea\u30ab\u30d0\u30ea\u30fc\u6226\u7565\u306b\u304a\u3051\u308b\u7269\u7406\u5a92\u4f53\u7ba1\u7406\uff082026-05-10\uff09. <a href=\"https:\/\/blog.id774.net\/entry\/2026\/05\/10\/4743\/\">https:\/\/blog.id774.net\/entry\/2026\/05\/10\/4743\/<\/a><\/li>\n<li id=\"ref31\">Milan Broz, Mikulas Patocka, Vashek Matyas, Practical Cryptographic Data Integrity Protection with Full Disk Encryption Extended Version\uff082018\uff09. <a href=\"https:\/\/arxiv.org\/abs\/1807.00309\">https:\/\/arxiv.org\/abs\/1807.00309<\/a><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u306f\u3001\u5358\u306b\u30c7\u30fc\u30bf\u3092\u8aad\u3081\u306a\u304f\u3059\u308b\u305f\u3081\u306e\u4ed5\u7d44\u307f\u3067\u306f\u306a\u3044\u3002\u6b63\u3057\u3044\u9375\u3001\u6b63\u3057\u3044\u30d8\u30c3\u30c0\u30fc\u3001\u6b63\u3057\u3044\u5f62\u5f0f\u7406\u89e3\u3001\u6b63\u3057\u3044\u5b9f\u88c5\u304c\u305d\u308d\u3063\u305f\u3068\u304d\u306b\u3060\u3051\u3001\u9589\u3058\u305f\u30c7\u30fc\u30bf\u3092\u518d\u3073\u958b\u3051\u308b\u4ed5\u7d44\u307f\u3067\u3042\u308b\u3002\u3053\u306e\u6027\u8cea\u306f\u3001\u6697\u53f7\u5316\u30c7\u30a3\u30b9\u30af\u3092\u5b89\u5168\u306b\u3059\u308b\u4e00\u65b9\u3067 &#8230; <a title=\"cryptsetup \u306e TCRYPT \u4e92\u63db\u30b3\u30fc\u30c9\u3092\u8aad\u3080\" class=\"read-more\" href=\"https:\/\/blog.id774.net\/entry\/2026\/06\/24\/4910\/\" aria-label=\"cryptsetup \u306e TCRYPT \u4e92\u63db\u30b3\u30fc\u30c9\u3092\u8aad\u3080 \u306b\u3064\u3044\u3066\u3055\u3089\u306b\u8aad\u3080\">\u7d9a\u304d\u3092\u8aad\u3080<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33,31,14],"tags":[],"class_list":["post-4910","post","type-post","status-publish","format-standard","hentry","category-cryptography","category-resilience","category-tech"],"_links":{"self":[{"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/posts\/4910","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/comments?post=4910"}],"version-history":[{"count":1,"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/posts\/4910\/revisions"}],"predecessor-version":[{"id":4911,"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/posts\/4910\/revisions\/4911"}],"wp:attachment":[{"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/media?parent=4910"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/categories?post=4910"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.id774.net\/entry\/wp-json\/wp\/v2\/tags?post=4910"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}