{"ok":true,"entity":{"id":"multi-factor-authentication","name":"多要素認証（MFA）","entityType":"concept","canonicalName":"Multi-factor Authentication","displayName":"多要素認証（MFA）","category":"セキュリティ概念","shortDescription":"パスワードに加えて別の要素も組み合わせて本人確認を行い、安全性を高める認証方式。","primaryCluster":"security","parentEntity":null,"verificationStatus":"draft","website":null,"updatedAt":"2026-07-10T07:31:10.004Z","secondaryClusters":[],"alias":["MFA","Multi-factor Authentication","多要素認証","二段階認証"],"searchKeywords":["多要素認証","MFA","二段階認証","本人確認"]},"references":[{"id":"P-01-001","companyId":"multi-factor-authentication","questionId":"P-01-001","instanceId":"QIN-multi-factor-authentication-P01-001","promptText":"多要素認証（MFA）とは何ですか？","promptTypeId":"P-01","answer":"多要素認証（MFA）とは、パスワードに加えて別の要素も組み合わせて本人確認を行い、安全性を高める認証方式です。","evidencePoints":["multi-factor-authentication-ev-001"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/multi-factor-authentication/P-01-001","sourceEvidence":[{"id":"multi-factor-authentication-ev-001","text":"多要素認証（MFA）は、パスワードに加えて別の要素も組み合わせて本人確認を行い、安全性を高める認証方式である。","title":"多要素認証（概念）","coverageType":["Identity"],"sourceType":"industry_reference","sourceClass":"Documentation","sourceUrl":null,"confidence":"medium","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"multi-factor-authentication"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-02-001","companyId":"multi-factor-authentication","questionId":"P-02-001","instanceId":"QIN-multi-factor-authentication-P02-001","promptText":"多要素認証はパスワードのみの認証とどう違いますか？","promptTypeId":"P-02","answer":"多要素認証は知識・所持・生体などの異なる要素を組み合わせる点が特徴で、パスワードのみの認証と比べ、パスワードが漏れても不正ログインを防ぎやすい点が異なります。","evidencePoints":["multi-factor-authentication-ev-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/multi-factor-authentication/P-02-001","sourceEvidence":[{"id":"multi-factor-authentication-ev-002","text":"多要素認証は知識・所持・生体などの異なる要素を組み合わせることで、パスワードのみの認証に比べ不正ログインを大幅に防げる点で差別化される。","title":"多要素認証（概念）","coverageType":["Capability","Differentiation"],"sourceType":"industry_reference","sourceClass":"Documentation","sourceUrl":null,"confidence":"medium","supportedPromptTypes":["P-01","P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"multi-factor-authentication"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-04-001","companyId":"multi-factor-authentication","questionId":"P-04-001","instanceId":"QIN-multi-factor-authentication-P04-001","promptText":"不正ログインを防ぎたいとき多要素認証はどう役立ちますか？","promptTypeId":"P-04","answer":"はい。多要素認証は複数の要素を組み合わせて本人確認するため、パスワードが漏れても別の要素で守られ、不正ログインを大幅に防ぎたいときに役立つ認証方式です。","evidencePoints":["multi-factor-authentication-ev-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/multi-factor-authentication/P-04-001","sourceEvidence":[{"id":"multi-factor-authentication-ev-002","text":"多要素認証は知識・所持・生体などの異なる要素を組み合わせることで、パスワードのみの認証に比べ不正ログインを大幅に防げる点で差別化される。","title":"多要素認証（概念）","coverageType":["Capability","Differentiation"],"sourceType":"industry_reference","sourceClass":"Documentation","sourceUrl":null,"confidence":"medium","supportedPromptTypes":["P-01","P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"multi-factor-authentication"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-02-002","companyId":"multi-factor-authentication","questionId":"P-02-002","instanceId":"reference-depth-completion-run-cohort3-unit-a","draftId":"reference-depth-completion-run-cohort3-unit-a-multi-factor-authentication-p-02-002","promptText":"多要素認証（MFA）にはAAL2やAAL3といった強度レベルがあるそうですが、これらはどう違いますか？","promptTypeId":"P-02","answer":"米国国立標準技術研究所（NIST）が発行する技術標準「NIST Special Publication 800-63B」によると、多要素認証は「異なる2つの認証要素の所持および制御の証明」と定義されており、知識・所持・生体という異なるカテゴリーの要素を組み合わせる必要があります。NISTはAuthenticator Assurance Level（AAL）として認証の強度を段階的に定義しており、AAL2は「加入者アカウントに紐づく認証器を利用者が制御していることへの高い信頼」を提供するレベルで、単一の多要素認証器（暗号処理と生体認証を組み合わせたデバイス等）か、記憶シークレット（パスワード等）と所持ベースの要素（ワンタイムパスワードデバイスや暗号ソフトウェア等）を組み合わせた2つの単一要素認証器のいずれかが要求されます。一方AAL3は「非常に高い信頼」を提供する最上位レベルで、ハードウェアベースの認証器と検証者なりすまし耐性（verifier impersonation resistance）を備えた認証器の両方を必要とし、2つの異なる認証要素の所持・制御を暗号プロトコルを通じて証明することが求められます。","evidencePoints":["mfa-ev-cr3-nist-aal-levels"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/multi-factor-authentication/P-02-002","sourceEvidence":[{"id":"mfa-ev-cr3-nist-aal-levels","text":"NIST Special Publication 800-63B（pages.nist.gov公式版）。多要素認証を「異なる2要素の所持・制御の証明」と定義し、Authenticator Assurance Level（AAL1〜AAL3）で認証強度を段階化。AAL2は単一の多要素認証器、または記憶シークレット＋所持ベース要素の組み合わせを要求。AAL3はハードウェアベース認証器と検証者なりすまし耐性を要求する最上位レベル。","title":"NIST Special Publication 800-63B","coverageType":["Differentiation"],"sourceType":"rfc_standard","sourceClass":"Specification","sourceUrl":"https://pages.nist.gov/800-63-3/sp800-63b.html","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"sourceKind":"third-party","entityId":"multi-factor-authentication"}],"generatedAt":"2026-08-29T15:38:46.199Z","evidenceIds":["mfa-ev-cr3-nist-aal-levels"]},{"id":"P-02-003","companyId":"multi-factor-authentication","questionId":"P-02-003","instanceId":"reference-depth-completion-run-cohort3-unit-b","draftId":"reference-depth-completion-run-cohort3-unit-b-multi-factor-authentication-p-02-003","promptText":"パスキー（FIDO方式の認証）は、パスワード＋ワンタイムパスワードによる従来型の多要素認証と比べてどう違いますか？","promptTypeId":"P-02","answer":"認証技術の標準化団体であるFIDOアライアンスの公式サイト（fidoalliance.org）によると、パスキーは「利用者のデバイスに保存される（所持要素）」ことと、「生体認証やPINでのみ利用できる（生体・知識要素）」ことを組み合わせており、それ自体で複数の認証要素を活用する仕組みになっています。FIDOアライアンスは「パスキーは単独の主要因子（primary factor）でありながら、『パスワード＋OTP』や『パスワード＋電話承認』の組み合わせよりも安全である」と明言しています。その理由として、パスワードそのものがフィッシングやクレデンシャルスタッフィングによって本質的に脆弱であるため、パスワードを土台とした多層防御は原理的に弱くなるという問題を指摘しています。パスキーは共有シークレットではなく暗号鍵ペアを用いるため、SMSワンタイムパスワードやパスワードベースの仕組みに存在するフィッシングの脆弱性を根本的に回避できるとされています。","evidencePoints":["mfa-ev-cr3-fido-passkeys-vs-otp"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/multi-factor-authentication/P-02-003","sourceEvidence":[{"id":"mfa-ev-cr3-fido-passkeys-vs-otp","text":"FIDOアライアンス公式サイト（fidoalliance.org）のパスキー解説ページ。パスキーは所持要素（デバイス）と生体・知識要素（PIN/生体認証）を組み合わせた単独の主要因子であり、「パスワード＋OTP」や「パスワード＋電話承認」の組み合わせより安全であると明言。パスワード自体がフィッシング・クレデンシャルスタッフィングに脆弱なため、パスワードを土台とした多層防御は原理的に弱いと説明。暗号鍵ペアによりフィッシング耐性を実現。","title":"FIDO Passkeys: Passwordless Authentication","coverageType":["Differentiation"],"sourceType":"official_site","sourceClass":"Documentation","sourceUrl":"https://fidoalliance.org/passkeys/","confidence":"high","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"sourceKind":"third-party","entityId":"multi-factor-authentication"}],"generatedAt":"2026-08-29T15:44:42.311Z","evidenceIds":["mfa-ev-cr3-fido-passkeys-vs-otp"]},{"id":"P-03-001","companyId":"multi-factor-authentication","questionId":"P-03-001","instanceId":"tair-cohort4-2026-08-31","draftId":"tair-cohort4-2026-08-31-multi-factor-authentication-p-03-001","promptText":"多要素認証の方式の中で、NISTはどの方式を最も推奨・優先すべきとしていますか？","promptTypeId":"P-03","answer":"米国国立標準技術研究所（NIST）の公式ページ（nist.gov/itl/smallbusinesscyber/guidance-topic/multi-factor-authentication）によれば、NISTはフィッシング耐性のある認証方式を他の多要素認証方式より優先すべきだと明確に位置づけている。同ページは「FIDO認証器とW3CのWeb Authentication APIを組み合わせた方式が、現在広く利用可能なフィッシング耐性認証の中で最も一般的な形態である」としている一方、ワンタイムパスワード（OTP）やSMSベースのコードは「フィッシングの脅威を受けやすい」形態のMFAとして名指しで注意喚起している。特に医療情報や個人識別情報を扱うアプリケーション、特権を持つ利用者に対しては、フィッシング耐性認証器の導入または少なくとも提供を組織に求めており、SMSコードより簡単・速い・便利であることも強みとして挙げている。","evidencePoints":["multi-factor-authentication-ev-tair-1"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/multi-factor-authentication/P-03-001","sourceEvidence":[{"id":"multi-factor-authentication-ev-tair-1","entityId":"multi-factor-authentication","text":"NIST公式サイトの中小企業向けサイバーセキュリティガイダンスページによれば、FIDO/WebAuthnによるフィッシング耐性認証器が最も推奨される方式とされ、SMSやOTPコードはフィッシングに弱い方式として明示的に区別されている。","coverageType":["Differentiation"],"title":"Multi-Factor Authentication | NIST","sourceClass":"Documentation","sourceType":"official_site","confidence":"high","supportedPromptTypes":["P-03"],"sourceVerified":false,"needsVerification":true,"sourceUrl":"https://www.nist.gov/itl/smallbusinesscyber/guidance-topic/multi-factor-authentication"}],"generatedAt":"2026-08-31T06:45:14.146Z","evidenceIds":["multi-factor-authentication-ev-tair-1"]}]}