本文へ移動
新規テクノロジー報道日時 2026-10-07 00:00

Meta が検証可能なタイムサービス用 NTS を発表

Metaは、公開タイムサービスにNetwork Time Security(NTS)を実装し、時間の検証と認証を可能にしました。これにより、証明書の検証、トークンの有効期限、ログの相関におけるセキュリティ上の懸念が解決されます。

//

注目点

  • If the USD/JPY rate rises above 160 within the next 30 days, it would reflect a notable shift after Meta's NTS launch.

    未確定

    2026-11-07 まで · シグナルからモデルが提案。データで判定されるまでは仮説

  • If the EUR/USD rate climbs above 1.13 within the next 30 days, it would indicate a broader market reaction to the new time‑security service.

    未確定

    2026-11-07 まで · シグナルからモデルが提案。データで判定されるまでは仮説

なぜ重要か. MetaのNTS実装は、時間ベースのプロトコルのセキュリティを強化し、インターネット全体における証明書の検証、トークン管理、ログの相関に影響を与えます。

01

誰に影響するか

  1. 1Meta Platforms
  2. を生み出す →事実
    2Muse製品
  3. に投資 →事実
  4. の一部 →事実
  5. を使用 →事実
    5chrony技術
  6. を可能にする →事実
02

根拠

  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Each server derives the sealing key from a shared master secret and the current day: key = HKDF-SHA256(master, salt = BE32(day), info = “fbnts-cookie-seal-v1”)
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    NTS support exists where you would expect it in the server world – chrony and ntpsec implement it.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Server-side, the public NTS list today runs to a few dozen entries, mostly national metrology institutes and internet infrastructure operators such as PTB, Netnod, and time.nl.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Each row’s session keys came out of its own TLS handshake and work only for that association.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Precision without authenticity only gets you a very accurate number from an unknown source. Now it can be both.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Cloudflare had launched time.cloudflare.com with NTS 15 months earlier, in June 2019, against the then-current draft, and showed it works at scale.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    every one of them is trusting an unauthenticated UDP packet.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    CLen 68 is the cookie: 36 bytes of envelope around the two 16-byte keys inside.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    That indirection is why we use pool rather than server. A single server line gives you one association and one responder, which is a single point of failure – and NTP is a protocol that wants several sources so it can outvote a bad one. pool asks for maxsources independent assoc…
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    One line of chrony config: pool nts.meta.com nts iburst maxsources 5
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Type 30 is the negotiated AEAD, AES-128-GCM-SIV, with KLen 128 bits of session key — chrony lists it first and client preference wins.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    RFC 8915, Network Time Security for the Network Time Protocol, was published on the IETF Standards Track as a Proposed Standard in September 2020.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Phase 2 – Authenticated NTP: Standard NTPv4 over UDP/123 to the advertised server, with NTS extension fields.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Android’s platform time sync is plain SNTP over UDP/123 – a fixed 48-byte packet with no extension-field handling, alongside NITZ and GNSS – so there is no NTS path in it.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    NTS works in phases, and separating them is what makes it deployable. Phase 1 – Key Establishment (NTS-KE): TLS 1.3 over TCP/4460, negotiated with ALPN ntske/1.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    chrony runs perfectly well on Android
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    We’ve open sourced everything, including the protocol, server, client through Meta’s Time library on GitHub.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    The key that seals them into a cookie is the shared one – the epoch day number from the derivation above, identical on every responder we run, stamped inside each cookie and never visible to the client.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    Meta’s public time service now speaks NTS (Network Time Security, RFC 8915) at nts.meta.com.
    出典を見る
  • MMeta Engineering Blog企業開示2026-10-07 00:00
    We’ve previously written about building a more accurate time service at Meta scale – migrating from ntpd to chrony, going from 10 milliseconds to 100 microseconds, and opening time.meta.com to everyone.
    出典を見る