ãã®ã³ã³ãã³ãã®æçµæŽæ°æ¥ã¯ 2024 幎 6 æã§ãäœææç¹ã®ç¶æ³ã衚ããŠããŸããã客æ§ã®ä¿è·ã®ç¶ç¶çãªæ¹åã®ããã«ãGoogle ã®ã»ãã¥ãªã㣠ããªã·ãŒãšã·ã¹ãã ã¯å€æŽãããå ŽåããããŸãã
ã¯ããã«
ãã®ããã¥ã¡ã³ãã§ã¯ãGoogle ã®æè¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£èšèšã®æŠèŠã«ã€ããŠèª¬æããŸãããã®ããã¥ã¡ã³ãã¯ãã»ãã¥ãªãã£ç®¡çè ãã»ãã¥ãªã㣠ã¢ãŒããã¯ããç£æ»è ã察象ãšããŠããŸãã
ãã®ããã¥ã¡ã³ãã®å å®¹ã¯æ¬¡ã®ãšããã§ãã
- Google ã®ã°ããŒãã«æè¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãGoogle ã®æ
å ±åŠçã©ã€ããµã€ã¯ã«å
šåã§ã»ãã¥ãªãã£ã確ä¿ããããã«èšèšãããŠããŸãããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãããæ¬¡ã®ããšãå¯èœã«ãªããŸãã
- ãµãŒãã¹ã®å®å šãªãããã€
- ãšã³ããŠãŒã¶ãŒã®ãã©ã€ãã·ãŒä¿è·ã«ããããŒã¿ã®å®å šãªä¿ç®¡
- ãµãŒãã¹éã®å®å šãªéä¿¡
- ã€ã³ã¿ãŒãããçµç±ã§ã®ãŠãŒã¶ãŒãšã®å®å šã§ãã©ã€ããŒããªéä¿¡
- Google ãšã³ãžãã¢ã«ããå®å šãªéçš
- ãã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããŠãã€ã³ã¿ãŒããã ãµãŒãã¹ïŒGoogle æ€çŽ¢ãGmailãGoogle ãã©ããªã©ã®äžè¬ãŠãŒã¶ãŒåããµãŒãã¹ãGoogle Workspace ãGoogle Cloudãªã©ã®äŒæ¥åããµãŒãã¹ïŒãæ§ç¯ããæ¹æ³ã
- ã»ãã¥ãªãã£èŠä»¶ãæºããããã« Google å éšã«å®è£ ããã€ãããŒã·ã§ã³ããçãŸããã»ãã¥ãªã㣠ãããã¯ããšãµãŒãã¹ãããšãã°ãBeyondCorp ã¯ããŒããã©ã¹ã ã»ãã¥ãªã㣠ã¢ãã«ã®å éšå®è£ ããçŽæ¥çãŸãããããã¯ãã§ãã
ããã°ã¬ãã·ã ã¬ã€ã€ã§ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£ãã©ã®ããã«èšèšãããããããã®ã¬ã€ã€ã«ã¯æ¬¡ã®ãã®ããããŸãã
以éã®ã»ã¯ã·ã§ã³ã§ã¯ãã»ãã¥ãªã㣠ã¬ã€ã€ã«ã€ããŠèª¬æããŸãã
äžäœã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä¿è·
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãGoogle ã®ããŒã¿ã»ã³ã¿ãŒã®ç©çæœèšãããŒã¿ã»ã³ã¿ãŒã®ããŒããŠã§ã¢ãããŒããŠã§ã¢äžã§çšŒåãããœãããŠã§ã¢ ã¹ã¿ãã¯ãä¿è·ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ç©çæœèšã®ã»ãã¥ãªãã£
Google ã§ã¯ãè€æ°ã®ç©çå±€ã»ãã¥ãªãã£ãçµã¿èŸŒãã ç¬èªã®ããŒã¿ã»ã³ã¿ãŒãèšèšããæ§ç¯ããŠããŸãããããã®ããŒã¿ã»ã³ã¿ãŒãžã®ã¢ã¯ã»ã¹ã¯å³éã«ç®¡çãããŠããŸããè€æ°ã®ç©çã»ãã¥ãªã㣠ã¬ã€ã€ã䜿çšããŠãããŒã¿ã»ã³ã¿ãŒã®ããã¢ãä¿è·ããŠããŸããGoogle ã§ã¯ãçäœèªèšŒãé屿€ç¥ãã«ã¡ã©ãè»äž¡é害ç©ãã¬ãŒã¶ãŒã«ããäŸµå ¥æ€ç¥ã·ã¹ãã ãªã©ãå°å ¥ããŠããŸãã詳现ã«ã€ããŠã¯ãããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ãã芧ãã ããã
ããŒã¿ã»ã³ã¿ãŒå ã§ã¯ããµãŒããŒã®ç©ççãªã¢ã¯ã»ã¹ãä¿è·ãããã¢ãã¿ãªã³ã°ãããããã«è¿œå ã®å¶åŸ¡ãå®è£ ããŠããŸãã詳现ã«ã€ããŠã¯ãGoogle ãããŒã¿ã»ã³ã¿ãŒã®ç©çè«ç空éãä¿è·ããä»çµã¿ãã芧ãã ããã
ãŸããäžéšã®ãµãŒããŒã¯ãµãŒãããŒãã£ã®ããŒã¿ã»ã³ã¿ãŒã«ãã¹ããããŠããŸãããããã®ããŒã¿ã»ã³ã¿ãŒã«ã¯ãGoogle ç¬èªã®ããŒã¿ã»ã³ã¿ãŒãšåãèŠå¶åºæºãé©çšãããŸããGoogle ã¯ãããŒã¿ã»ã³ã¿ãŒ ãªãã¬ãŒã¿ãŒãæäŸããã»ãã¥ãªã㣠ã¬ã€ã€ã«å ããŠãGoogle ã管çããç©ççãªã»ãã¥ãªãã£å¯Ÿçãš Google ã管çããæ¥ç¶ã確å®ã«å®æœããŠããŸããããšãã°ãããŒã¿ã»ã³ã¿ãŒã®ãªãã¬ãŒã¿ãŒãæäŸããã»ãã¥ãªã㣠ã¬ã€ã€ãšã¯å¥ã«ãçäœèªèšŒèå¥ã·ã¹ãã ãã«ã¡ã©ãé屿¢ç¥æ©ãèšçœ®ããŠããŸãã
ç¹ã«æèšãããŠããªãéãããã®ããã¥ã¡ã³ãã®ã»ãã¥ãªãã£ç®¡çã¯ãGoogle ææã®ããŒã¿ã»ã³ã¿ãŒãšãµãŒãããŒãã£ã®ããŒã¿ã»ã³ã¿ãŒã®äž¡æ¹ã«é©çšãããŸãã
ããŒããŠã§ã¢ã®èšèšãšäŸçµŠå
Google ããŒã¿ã»ã³ã¿ãŒã¯ãããŒã«ã« ãããã¯ãŒã¯ã«æ¥ç¶ãããäœåå°ãã®ãµãŒããŒã§æ§æãããŠããŸããGoogle ã§ã¯ããµãŒããŒããŒãããããã¯ãŒã¯æ©åšã®èšèšãè¡ã£ãŠããŸããGoogle ã¯ãææºããã³ã³ããŒãã³ã ãã³ããŒãå ¥å¿µã«èª¿æ»ããã³ã³ããŒãã³ããæ éã«éžæããŠããŸããGoogle ã§ã¯ãã³ã³ããŒãã³ãã«ãã£ãŠæäŸãããã»ãã¥ãªãã£ç¹æ§ããã³ããŒãšååããŠç£æ»ããã³æ€èšŒããŠããŸãããŸãããµãŒããŒãããã€ã¹ãåšèŸºæ©åšã«ãããã€ããããŒããŠã§ã¢ ã»ãã¥ãªã㣠ãããïŒTitan ãšåŒã°ããïŒãªã©ã®ã«ã¹ã¿ã ããããèšèšããŠããŸãããããã®ãããã¯ãæ£èŠã® Google ããã€ã¹ãããŒããŠã§ã¢ ã¬ãã«ã§èå¥ããŠèªèšŒããããŒããŠã§ã¢ã®ã«ãŒã ãªã ãã©ã¹ããšããŠæ©èœããŸãã
ããŒãã¹ã¿ãã¯ãšãã·ã³ ID ã®ã»ãã¥ãªãã£
Google ãµãŒããŒã¯ããŸããŸãªæè¡ã䜿çšããŠãç®çã®ãœãããŠã§ã¢ ã¹ã¿ãã¯ãèµ·åããŠããŸããGoogle ã§ã¯ãèµ·åããã»ã¹ã®åã¹ãããã§æåŸ ãããèµ·åç¶æ ãé©çšãã顧客ããŒã¿ãå®å šã«ä¿ã€ããã«ãæ¥çãããã¯ã©ã¹ã®å¶åŸ¡æ©æ§ãå®è£ ããŠããŸãã
Google ã¯ãããŒããŠã§ã¢ã®äžä»£ããšã«ãµãŒããŒãç¶ç¶çã«æ¹åããTrusted Computing Group ã DMTF ãšã®æšæºããã»ã¹ãžã®åå ãéããŠãæ¥çå šäœã«ãããã®æ¹åãããããããšãç®æããŠããŸãã
ããŒã¿ã»ã³ã¿ãŒå ã®åãµãŒããŒã«ã¯ç¬èªã® ID ãèšå®ãããŠããŸãããã® ID ã¯ãããŒããŠã§ã¢ã®ã«ãŒã ãªã ãã©ã¹ããšããã·ã³ãèµ·åãããœãããŠã§ã¢ã«é¢é£ä»ããããšãã§ããŸãããã® ID ã¯ããã·ã³äžã®äžäœç®¡çãµãŒãã¹ãšã®éã§ããåãããã API åŒã³åºãã®èªèšŒã«äœ¿çšãããŸãããã® ID ã¯ãçžäºãµãŒããŒèªèšŒãšè»¢éæå·åã«ã䜿çšãããŸããGoogle ã§ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ãªã¢ãŒã ããã·ãŒãžã£ ã³ãŒã«ïŒRPCïŒéä¿¡ãä¿è·ããããã«ãApplication Layer Transport SecurityïŒALTSïŒã·ã¹ãã ãéçºããŸããããããã®ãã·ã³ ID ã¯ãã»ãã¥ãªã㣠ã€ã³ã·ãã³ãã«å¯Ÿå¿ããããã«äžå çã«åãæ¶ãããšãã§ããŸãããŸããèšŒææžãšéµã¯å®æçã«ããŒããŒã·ã§ã³ãããå€ããã®ã¯åãæ¶ãããŸãã
Google ã§ã¯ã次ã®ããšãè¡ãããã«èªåã·ã¹ãã ãéçºããŸããã
- ãµãŒããŒã§åžžã«ãœãããŠã§ã¢ ã¹ã¿ãã¯ã®ææ°ããŒãžã§ã³ïŒã»ãã¥ãªã㣠ããããå«ãïŒãå®è¡ãããããšãä¿èšŒããã
- ããŒããŠã§ã¢ãŸãã¯ãœãããŠã§ã¢ã®åé¡ãæ€åºããŠèšºæããã
- ç¢ºèªæžã¿ã®èµ·åèšŒææžãšèšŒææžã䜿çšããŠãã·ã³ãšåšèŸºæ©åšã®æŽåæ§ãç¶æããã
- ç®çã®ãœãããŠã§ã¢ãšãã¡ãŒã ãŠã§ã¢ãå®è¡ããŠãããã·ã³ã®ã¿ããæ¬çªç°å¢ãããã¯ãŒã¯äžã§éä¿¡ã§ããèªèšŒæ å ±ã«ã¢ã¯ã»ã¹ã§ããããšãä¿èšŒããã
- å®å šæ§ãã§ãã¯ã«åæ Œããªãã£ããã·ã³ããäžèŠã«ãªã£ããã·ã³ã¯åé€ãããä¿®çããã
ããŒãã¹ã¿ãã¯ãšãã·ã³ã®æŽåæ§ãä¿è·ããæ¹æ³ã®è©³çްã«ã€ããŠã¯ãGoogle ãæ¬çªç°å¢ãã·ã³ã«èµ·åææŽåæ§ãé©çšããæ¹æ³ãšåæ£ãã·ã³ã®ãªã¢ãŒãæ§æèšŒæãã芧ãã ããã
ãµãŒãã¹ã®å®å šãªãããã€
Google ãµãŒãã¹ã¯ãããããããŒã Google ã®ã€ã³ãã©ã¹ãã©ã¯ãã£äžã§äœæããŠå®è¡ããã¢ããªã±ãŒã·ã§ã³ ãã€ããªã§ããGoogle ãµãŒãã¹ã®äŸãšããŠã¯ãGmail ãµãŒããŒãSpanner ããŒã¿ããŒã¹ãCloud Storage ãµãŒããŒãYouTube åç»ãã©ã³ã¹ã³ãŒããã«ã¹ã¿ã ã¢ããªã±ãŒã·ã§ã³ãå®è¡ãã Compute Engine VM ãªã©ããããŸããå¿ èŠãªèŠæš¡ã®ã¯ãŒã¯ããŒããåŠçããããã«ãäœåãã®ãã·ã³ãåããµãŒãã¹ã®ãã€ããªãå®è¡ããŠããå ŽåããããŸããBorg ãšããã¯ã©ã¹ã¿ ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ ãµãŒãã¹ãã€ã³ãã©ã¹ãã©ã¯ãã£äžã§çŽæ¥å®è¡ããããµãŒãã¹ãå¶åŸ¡ããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã§å®è¡ãããŠãããµãŒãã¹éã®ä¿¡é ŒãåæãšããŸããããã®ä¿¡é Œã¢ãã«ã¯ããŒããã©ã¹ã ã»ãã¥ãªã㣠ã¢ãã«ãšåŒã°ããŸãããŒããã©ã¹ã ã»ãã¥ãªã㣠ã¢ãã«ã®ããã©ã«ãã§ã¯ããããã¯ãŒã¯å å€ã«ããããããããã€ã¹ããŠãŒã¶ãŒã¯ä¿¡é ŒãããŸããã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãã«ãããã³ããšããŠèšèšãããŠããããããŠãŒã¶ãŒïŒæ¶è²»è ãäŒæ¥ãGoogle ç¬èªã®ããŒã¿ïŒã®ããŒã¿ã¯å ±æã€ã³ãã©ã¹ãã©ã¯ãã£å šäœã«åæ£ãããŸãããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãæ°äžå°ã®åçš®ã®ãã·ã³ã§æ§æãããŠããŸããã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ã顧客ããŒã¿ãåäžãã·ã³ãŸãã¯ãã·ã³ã®ã»ããã«åé¢ããããšã¯ãããŸããããã ãã Google Cloud ã䜿çšã㊠Compute Engine ã®åäžããã³ãããŒãã« VM ãããããžã§ãã³ã°ããå Žåãªã©ãç¹å®ã®ç¶æ³ãé€ããŸãã
Google Cloud ãš Google Workspace ã¯ãããŒã¿æåšå°ã«é¢ããèŠå¶èŠä»¶ã«å¯Ÿå¿ããŠããŸããããŒã¿æåšå°ãšGoogle Cloudã®è©³çްã«ã€ããŠã¯ããªãœãŒã¹ ãã±ãŒã·ã§ã³ã®å¶éãã芧ãã ãããããŒã¿æåšå°ãš Google Workspace ã®è©³çްã«ã€ããŠã¯ãããŒã¿ ãªãŒãžã§ã³: ããŒã¿ã®å°ççãªä¿ç®¡å Žæãéžæãããã芧ãã ããã
ãµãŒãã¹ IDãæŽåæ§ãåé¢
ãµãŒãã¹éã®éä¿¡ãå¯èœã«ãããããã¢ããªã±ãŒã·ã§ã³ã¯æå·èªèšŒãšèªå¯ã䜿çšããŸããèªèšŒãšèªå¯ã«ããã管çè ãšãµãŒãã¹ãèªèã§ããæœè±¡åã¬ãã«ãšç²åºŠã§åŒ·åãªã¢ã¯ã»ã¹å¶åŸ¡ãæäŸãããŸãã
ãµãŒãã¹ã¯ãäž»èŠãªã»ãã¥ãªã㣠ã¡ã«ããºã ãšããŠãå éšãããã¯ãŒã¯ã®ã»ã°ã¡ã³ããŒã·ã§ã³ããã¡ã€ã¢ãŠã©ãŒã«ã«äŸåããŠããŸãããIP ã¹ããŒãã£ã³ã°ãé²ãããããããã¯ãŒã¯å ã®ããŸããŸãªãã€ã³ãã§äžãïŒå åãïŒãšäžãïŒå€åãïŒã®ãã£ã«ã¿ãªã³ã°ãè¡ã£ãŠããŸãããã®ã¢ãããŒãã¯ããããã¯ãŒã¯ã®ããã©ãŒãã³ã¹ãšå¯çšæ§ã®æå€§åã«ã圹ç«ã¡ãŸãã Google Cloudã®å ŽåãVPC Service Controls ã Cloud Interconnect ãªã©ã®ã»ãã¥ãªã㣠ã¡ã«ããºã ã远å ã§ããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£äžã§åäœããåãµãŒãã¹ã«ã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ID ãé¢é£ä»ããããŸãããµãŒãã¹ã«ã¯ãRPC ãäœæãŸãã¯åä¿¡ãããšãã«ãä»ã®ãµãŒãã¹ã«å¯Ÿãã ID ã®èšŒæã«äœ¿çšã§ããæå·èªèšŒæ å ±ãä»äžãããŸãããããã® ID ã¯ã»ãã¥ãªã㣠ããªã·ãŒã§äœ¿çšãããŸããã»ãã¥ãªã㣠ããªã·ãŒã¯ãã¯ã©ã€ã¢ã³ããæå³ãããµãŒããŒãšéä¿¡ããŠããããšãšãç¹å®ã®ã¯ã©ã€ã¢ã³ããã¢ã¯ã»ã¹ã§ããã¡ãœãããšããŒã¿ããµãŒããŒãå¶éããããšãä¿èšŒããŸãã
Google ã§ã¯ãåããã·ã³äžã§åäœããŠããä»ã®ãµãŒãã¹ãããµãŒãã¹ãä¿è·ããããã«ãããŸããŸãªå颿æ³ãšãµã³ãããã¯ã¹åææ³ã䜿çšããŠããŸãããããã®ææ³ã«ã¯ãLinux ãŠãŒã¶ãŒã®åé¢ãèšèªããŒã¹ïŒSandboxed API ãªã©ïŒãšã«ãŒãã«ããŒã¹ã®ãµã³ãããã¯ã¹ãã³ã³ããçšã¢ããªã±ãŒã·ã§ã³ ã«ãŒãã«ïŒgVisorïŒãããŒããŠã§ã¢ããŒã¹ã®ä»®æ³åãªã©ããããŸããäžè¬ã«ããããªã¹ã¯ã®é«ãã¯ãŒã¯ããŒãã«ã¯ãããå€ãã®åé¢ã¬ã€ã€ã䜿çšããŸãããªã¹ã¯ã®é«ãã¯ãŒã¯ããŒãã«ã¯ãã€ã³ã¿ãŒãããããã®ãµãã¿ã€ãºãããŠããªãå ¥åãåŠçããã¯ãŒã¯ããŒããå«ãŸããŸããããšãã°ããªã¹ã¯ã®é«ãã¯ãŒã¯ããŒããšããŠã¯ãä¿¡é Œã§ããªãå ¥åã«å¯Ÿããè€éãªãã¡ã€ã« ã³ã³ããŒã¿ã®å®è¡ããCompute Engine ãªã©ã®ãããã¯ãã®ãµãŒãã¹ãšããŠä»»æã®ã³ãŒããå®è¡ãããªã©ããããŸãã
ã»ãã¥ãªãã£ã匷åãããããã¯ã©ã¹ã¿ ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ ãµãŒãã¹ãäžéšã®éµç®¡çãµãŒãã¹ãªã©ã®æ©å¯æ§ã®é«ããµãŒãã¹ã¯å°çšã®ãã·ã³ã§ã®ã¿åäœããŸãã
Google Cloudã§ã¯ãã¯ãŒã¯ããŒãã«å¯ŸããŠãã匷åãªæå·åé¢ãæäŸãã䜿çšäžã®ããŒã¿ãä¿è·ããããã«ãCompute Engine ä»®æ³ãã·ã³ïŒVMïŒã€ã³ã¹ã¿ã³ã¹ãš Google Kubernetes EngineïŒGKEïŒããŒãã«å¯Ÿã㊠Confidential Computing ãµãŒãã¹ããµããŒãããŠããŸãã
ãµãŒãã¹éã¢ã¯ã»ã¹ã®ç®¡ç
ãµãŒãã¹ã®ææè ã¯ããµãŒãã¹ãšéä¿¡ã§ããä»ã®ãµãŒãã¹ã®ãªã¹ããäœæããããšã§ãã¢ã¯ã»ã¹ã管çã§ããŸãããã®ã¢ã¯ã»ã¹ç®¡çæ©èœã¯ Google ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãã£ãŠæäŸãããŸããããšãã°ããããµãŒãã¹ã§ãçä¿¡ RPC ãä»ã®ãµãŒãã¹ã®èš±å¯ãªã¹ãã®ã¿ã«å¶éã§ããŸããææè ã¯ããµãŒãã¹ ID ã®èš±å¯ãªã¹ãã䜿çšããŠãµãŒãã¹ãæ§æããããšãã§ããŸãããã®ãªã¹ãã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãã£ãŠèªåçã«é©çšãããŸããé©çšã«ã¯ãç£æ»ãã®ã³ã°ãçç±ãäžæ¹çãªã¢ã¯ã»ã¹å¶éïŒãšã³ãžã㢠ãªã¯ãšã¹ããªã©ïŒãå«ãŸããŸãã
ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããå¿ èŠããã Google ãšã³ãžãã¢ã«ãåå¥ã® ID ãçºè¡ãããŸãããµãŒãã¹ã¯ãID ã«åºã¥ããŠã¢ã¯ã»ã¹ãèš±å¯ãŸãã¯æåŠããããã«æ§æã§ããŸãããããã® IDïŒãã·ã³ããµãŒãã¹ã瀟å¡ïŒã¯ãã¹ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãç¶æããã°ããŒãã«ãªåå空éå ã«ãããŸãã
ãããã® ID ã管çãããããã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯æ¿èªãã§ãŒã³ããã®ã³ã°ãéç¥ãå«ãã¯ãŒã¯ãã㌠ã·ã¹ãã ãçšæãããŠããŸããããšãã°ãã»ãã¥ãªã㣠ããªã·ãŒã«ãã£ãŠãã«ãããŒãã£ã®æ¿èªãé©çšã§ããŸãããã®ã·ã¹ãã ã«ã¯ 2 人ã«ãŒã«ãæ¡çšãããŠãããåç¬ã§è¡åãããšã³ãžãã¢ã¯ãæš©éãæã€ä»ã®ãšã³ãžãã¢ã®æ¿èªããªããã°ãæ©å¯æ§ã®é«ãæäœãè¡ãããšãã§ããŸããããã®ã·ã¹ãã ã䜿çšããã°ãå®å šãªã¢ã¯ã»ã¹ç®¡çããã»ã¹ãã€ã³ãã©ã¹ãã©ã¯ãã£äžã§åäœããäœåãã®ãµãŒãã¹ã«æ¡åŒµã§ããŸãã
ãŸãããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ããŠãŒã¶ãŒãã°ã«ãŒããã¡ã³ããŒã·ããã管çããããã®æ£èŠãµãŒãã¹ãæäŸããããã«ãå¿ èŠã«å¿ããŠãã«ã¹ã¿ã ã§ãã现ããã¢ã¯ã»ã¹å¶åŸ¡ãå®è£ ã§ããŸãã
Google Workspace ã§ã®ãšã³ããŠãŒã¶ãŒ ããŒã¿ã®ã¢ã¯ã»ã¹ç®¡çã§èª¬æãããŠããããã«ããšã³ããŠãŒã¶ãŒ ID ã¯åå¥ã«ç®¡çãããŸãã
ã¯ãŒã¯ããŒãééä¿¡ã®æå·å
ãã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ããããã¯ãŒã¯äžã® RPC ããŒã¿ã®æ©å¯æ§ãšæŽåæ§ãæäŸããŸãããã¹ãŠã® Google Cloud ä»®æ³ãããã¯ãŒã¯ ãã©ãã£ãã¯ã¯æå·åãããŸãã Google Cloud ã€ã³ãã©ã¹ãã©ã¯ã㣠ã¯ãŒã¯ããŒãéã®éä¿¡ã¯æå·åãããŸããäŸå€ã¯ãGoogle ããŒã¿ã»ã³ã¿ãŒã®ãšããžã§ãã©ãã£ãã¯ãè€æ°ã®ã¬ã€ã€ã®ç©çã»ãã¥ãªãã£ãè¶ããªãé«ããã©ãŒãã³ã¹ ã¯ãŒã¯ããŒãã«ã®ã¿é©çšãããŸãã Google Cloud ã€ã³ãã©ã¹ãã©ã¯ã㣠ãµãŒãã¹éã®éä¿¡ã«ã¯ãæå·ã®å®å šæ§ä¿è·ãé©çšãããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãããŒã¿ã»ã³ã¿ãŒéã®ãããã¯ãŒã¯ãçµç±ããã€ã³ãã©ã¹ãã©ã¯ã㣠RPC ãã©ãã£ãã¯ã«ãšã³ãããŒãšã³ãã®æå·åããïŒããŒããŠã§ã¢ ãªãããŒãã䜿çšããŠïŒèªåçãã€å¹ççã«æäŸããŸãã
Google Workspace ã§ã®ãšã³ããŠãŒã¶ãŒ ããŒã¿ã®ã¢ã¯ã»ã¹ç®¡ç
æšæºç㪠Google Workspace ãµãŒãã¹ã¯ããšã³ããŠãŒã¶ãŒã®ããã«äœããããããã«äœãããŠããŸããããšãã°ããšã³ããŠãŒã¶ãŒã¯ãGmail äžã«èªåã®ã¡ãŒã«ãä¿åããŠããããšãã§ããŸããGmail ãªã©ã®ã¢ããªã±ãŒã·ã§ã³ãšãšã³ããŠãŒã¶ãŒãšã®ããåãã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ä»ã®ãµãŒãã¹ã«ãåã¶å¯èœæ§ããããŸããããšãã°ãGmail ã¯ãšã³ããŠãŒã¶ãŒã®ã¢ãã¬ã¹åž³ã«ã¢ã¯ã»ã¹ããããã« People API ãåŒã³åºãå ŽåããããŸãã
ãµãŒãã¹ééä¿¡ã®æå·åã§ã¯ãå¥ã®ãµãŒãã¹ïŒGmail ãªã©ïŒããã® RPC ãªã¯ãšã¹ããä¿è·ããããã«ãµãŒãã¹ïŒGoogle ã³ã³ã¿ã¯ããªã©ïŒãèšèšããæ¹æ³ã«ã€ããŠèª¬æããŸãããã ããGmail ã¯ä»»æã®ãŠãŒã¶ãŒã®é£çµ¡å ããã€ã§ããªã¯ãšã¹ãã§ããããããã®ã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ã«ã¯åŒãç¶ãåºç¯ãªæš©éã䜿çšãããŠããŸãã
Gmail ããšã³ããŠãŒã¶ãŒã«ä»£ãã£ãŠ Google ã³ã³ã¿ã¯ãã« RPC ãªã¯ãšã¹ããè¡ããšãã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãã£ãŠ Gmail 㯠RPC ãªã¯ãšã¹ãã«ãšã³ããŠãŒã¶ãŒæš©éãã±ãããæç€ºã§ããŸãããã®ãã±ããã¯ãGmail ãç¹å®ã®ãšã³ããŠãŒã¶ãŒã®ä»£ããã« RPC ãªã¯ãšã¹ããäœæããŠããããšã蚌æãããã®ã§ãããããããGoogle ã³ã³ã¿ã¯ãããã±ããã§æå®ããããšã³ããŠãŒã¶ãŒã®ããŒã¿ã®ã¿ãè¿ãããã«å®å šä¿è·å¯Ÿçãå®è£ ã§ããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯ããããã®ãšã³ããŠãŒã¶ãŒ ã³ã³ããã¹ã ãã±ãããçºè¡ããäžå€®ã®ãŠãŒã¶ãŒ ID ãµãŒãã¹ããããŸããID ãµãŒãã¹ããšã³ããŠãŒã¶ãŒã®ãã°ã€ã³ã確èªããCookie ã OAuth ããŒã¯ã³ãªã©ã®ãŠãŒã¶ãŒèªèšŒæ å ±ããŠãŒã¶ãŒã®ããã€ã¹ã«çºè¡ããŸããããã€ã¹ããã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®åŸç¶ã®ãªã¯ãšã¹ãã§ã¯ããã®ãšã³ããŠãŒã¶ãŒèªèšŒæ å ±ãæç€ºããå¿ èŠããããŸãã
ãµãŒãã¹ã¯ãšã³ããŠãŒã¶ãŒèªèšŒæ å ±ãåãåããšãæ€èšŒã®ããã«ãã®èªèšŒæ å ±ã ID ãµãŒãã¹ã«æž¡ããŸãããšã³ããŠãŒã¶ãŒèªèšŒæ å ±ãæ€èšŒããããšãID ãµãŒãã¹ã¯æå¹æéãçããšã³ããŠãŒã¶ãŒ ã³ã³ããã¹ã ãã±ãããè¿ããŸãããã®ãã±ããã¯ããŠãŒã¶ãŒã®ãªã¯ãšã¹ãã«é¢é£ãã RPC ã«äœ¿çšã§ããŸãããã®äŸã§ã¯ããšã³ããŠãŒã¶ãŒ ã³ã³ããã¹ã ãã±ãããååŸãããµãŒãã¹ã¯ Gmail ã§ããããã±ãã㯠Google ã³ã³ã¿ã¯ãã«æž¡ãããŸãããã以éã¯ãã©ã®ãããªã«ã¹ã±ãŒãåŒã³åºãã«å¯ŸããŠããåŒã³åºãåŽã®ãµãŒãã¹ã¯ãRPC ã®äžéšãšããŠãšã³ããŠãŒã¶ãŒ ã³ã³ããã¹ã ãã±ãããåŒã³åºãåŽã«éä¿¡ã§ããŸãã
次ã®å³ã¯ããµãŒãã¹ A ãšãµãŒãã¹ B ã®éä¿¡ã瀺ããŠããŸãããã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ããµãŒãã¹ IDãèªåçžäºèªèšŒãæå·åããããµãŒãã¹ééä¿¡ããµãŒãã¹ ãªãŒããŒã«ãã£ãŠå®çŸ©ãããã¢ã¯ã»ã¹ ããªã·ãŒã®é©çšãå¯èœã«ããŸããåãµãŒãã¹ã«ã¯ããµãŒãã¹ ãªãŒããŒãäœæãããµãŒãã¹æ§æããããŸããæå·åããããµãŒãã¹ééä¿¡ã®å ŽåãèªåçžäºèªèšŒã¯åŒã³åºãå ãšåŒã³åºãå ã® ID ã䜿çšããŸããéä¿¡ã¯ãã¢ã¯ã»ã¹ã«ãŒã«ã®æ§æã§èš±å¯ãããŠããå Žåã«ã®ã¿å¯èœã§ãã
Google Cloudã®ã¢ã¯ã»ã¹ç®¡çã«ã€ããŠã¯ãIAM ã®æŠèŠãã芧ãã ããã
Google Cloudã§ã®ãšã³ããŠãŒã¶ãŒ ããŒã¿ã®ã¢ã¯ã»ã¹ç®¡ç
Google Workspace ã§ã®ãšã³ããŠãŒã¶ãŒ ããŒã¿ã®ã¢ã¯ã»ã¹ç®¡çãšåæ§ã«ãã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãµãŒãã¹ ã¢ã«ãŠã³ããèªèšŒããããã®äžå€®ã®ãŠãŒã¶ãŒ ID ãµãŒãã¹ãæäŸãããµãŒãã¹ ã¢ã«ãŠã³ããèªèšŒãããåŸã«ããšã³ããŠãŒã¶ãŒ ã³ã³ããã¹ã ãã±ãããçºè¡ããŸããéåžžã Google Cloud ãµãŒãã¹éã®ã¢ã¯ã»ã¹ç®¡çã¯ããšã³ããŠãŒã¶ãŒ ã³ã³ããã¹ã ãã±ããã§ã¯ãªãããµãŒãã¹ ãšãŒãžã§ã³ãã䜿çšããŠè¡ããŸãã
Google Cloud ã¯ãIdentity and Access ManagementïŒIAMïŒãš Identity-Aware Proxy ãªã©ã®ã³ã³ããã¹ãã¢ãŠã§ã¢ ãããã¯ãã䜿çšããŠãGoogle Cloud çµç¹å ã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã管çããŸãã Google Cloud ãµãŒãã¹ãžã®ãªã¯ãšã¹ãã§ã¯ãIAM ãéããŠæš©éã確èªãããŸãã
ã¢ã¯ã»ã¹ç®¡çããã»ã¹ã¯æ¬¡ã®ãšããã§ãã
- Google Front End ãµãŒãã¹ããŸãã¯ã客æ§ã® VM ã® Cloud Front End ãµãŒãã¹ãéããŠããªã¯ãšã¹ããå°çããŸãã
- ãªã¯ãšã¹ããäžå€®ã®ãŠãŒã¶ãŒ ID ãµãŒãã¹ã«è»¢éãããŸããäžå€®ã®ãŠãŒã¶ãŒ ID ãµãŒãã¹ã§èªèšŒãã§ãã¯ãè¡ããããšã³ããŠãŒã¶ãŒ ã³ã³ããã¹ã ãã±ãããçºè¡ãããŸãã
- ãŸãããªã¯ãšã¹ãã¯æ¬¡ã®é
ç®ããã§ãã¯ããããã«ãã«ãŒãã£ã³ã°ãããŸãã
- IAM ã¢ã¯ã»ã¹æš©éïŒããªã·ãŒãã°ã«ãŒã ã¡ã³ããŒã·ãããªã©ïŒ
- ã¢ã¯ã»ã¹ã®éææ§ã䜿çšããã¢ã¯ã»ã¹ã®éææ§
- Cloud Audit Logs
- å²ãåœãŠ
- ãæ¯æã
- 屿§èšç®ããŒã«
- VPC Service Controls ã®ã»ãã¥ãªãã£å¢ç
- ãããã®ãã§ãã¯ãã¹ãŠã«åæ Œãããšã Google Cloud ããã¯ãšã³ã ãµãŒãã¹ãåŒã³åºãããŸãã
Google Cloudã®ã¢ã¯ã»ã¹ç®¡çã«ã€ããŠã¯ãIAM ã®æŠèŠãã芧ãã ããã
ããŒã¿ã®å®å šãªä¿å
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ã«ä¿åãããŠããããŒã¿ã®ã»ãã¥ãªãã£ãå®è£ ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ä¿åæã®æå·å
Google ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãããŸããŸãªã¹ãã¬ãŒãž ãµãŒãã¹ãšåæ£ãã¡ã€ã« ã·ã¹ãã ïŒSpanner ã Colossus ãªã©ïŒãšäžå€®ã®éµç®¡çãµãŒãã¹ãæäŸããŸããGoogle äžã®ã¢ããªã±ãŒã·ã§ã³ã¯ãã¹ãã¬ãŒãž ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããŠç©çã¹ãã¬ãŒãžã«ã¢ã¯ã»ã¹ããŸããä¿åãããŠããããŒã¿ãä¿è·ããããã«ãè€æ°ã®æå·åã¬ã€ã€ã䜿çšãããŠããŸããããã©ã«ãã§ã¯ããŠãŒã¶ãŒããŒã¿ãç©çã¹ãã¬ãŒãžã«æžã蟌ãŸããåã«ãã¹ãã¬ãŒãž ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãŠãŒã¶ãŒããŒã¿ãæå·åããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãã¢ããªã±ãŒã·ã§ã³ãŸãã¯ã¹ãã¬ãŒãž ã€ã³ãã©ã¹ãã©ã¯ã㣠ã¬ã€ã€ã§æå·åãå®è¡ããŸãããã®æå·åã®éµã¯ Google ã«ãã£ãŠç®¡çãããææãããŸããæå·åã«ãããã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãã¹ãã¬ãŒãžã®äžäœã¬ãã«ã§ã®æœåšçãªè åšïŒæªæã®ãããã£ã¹ã¯ ãã¡ãŒã ãŠã§ã¢ãªã©ïŒããã€ã³ãã©ã¹ãã©ã¯ãã£èªäœãåé¢ã§ããŸãã該åœããå ŽåãGoogle ã§ã¯ããŒããã©ã€ããš SSD å ã®ããŒããŠã§ã¢æå·åãµããŒããæå¹ã«ãããã¹ãŠã®ãã©ã€ãããã®ã©ã€ããµã€ã¯ã«ãéããŠçްãã远跡ããŠããŸãã廿£äºå®ã®æå·åãããã¹ãã¬ãŒãž ããã€ã¹ã¯ãç©ççã«ç®¡ç察象å€ã«ãªãåã«ã2 åã®ç¬ç«ããæ€èšŒãå«ã倿®µéããã»ã¹ã䜿çšããŠã¯ãªãŒãã³ã°ãããŸãããã®ã¯ãªãŒãã³ã° ããã»ã¹ã«åæ ŒããŠããªãããã€ã¹ã¯ããªã³ãã¬ãã¹ã§ç©ççã«ç Žå£ïŒçްæïŒãããŸãã
Google ãææããã³ç®¡çããæå·éµã䜿çšããŠã€ã³ãã©ã¹ãã©ã¯ãã£ã§å®è¡ãããæå·åã«å ããŠã Google Cloud ãš Google Workspace ã«ã¯ããŠãŒã¶ãŒãææããŠç®¡çã§ããéµã®éµç®¡çãµãŒãã¹ãçšæãããŠããŸããGoogle Cloudã®å ŽåãCloud KMS ã¯ãããŒããŠã§ã¢ ããŒã¹ã® FIPS 140-3 L3 èªå®éµãªã©ãç¬èªã®æå·éµãäœæã§ããã¯ã©ãŠã ãµãŒãã¹ã§ãããããã®éµã¯ Google Cloud ãµãŒãã¹ã§ã¯ãªããŠãŒã¶ãŒã«åºæã®ãã®ã§ãããããªã·ãŒãšæé ã«æ²¿ã£ãŠéµã管çã§ããŸããGoogle Workspace ã®å Žåã¯ãã¯ã©ã€ã¢ã³ããµã€ãæå·åã䜿çšã§ããŸãã詳ããã¯ãGoogle Workspace ã§ã®ã¯ã©ã€ã¢ã³ããµã€ãæå·åãšã³ã©ãã¬ãŒã·ã§ã³åŒ·åãã芧ãã ããã
ããŒã¿ã®åé€
æå·ãããªã¢ã«ãŸãã¯ããŒã¿ã®åé€ã¯ãéåžžãç¹å®ã®éµãŸãã¯ããŒã¿ãåé€å¯Ÿè±¡ãšããŠããŒã¯ããããšããå§ãŸããŸããããŒã¿ã«åé€ããŒã¯ãä»ããããã»ã¹ã§ã¯ããµãŒãã¹åºæã®ããªã·ãŒãšã客æ§åºæã®ããªã·ãŒãèæ ®ãããŸãã
ããŒã¿ãåé€ããã¹ã±ãžã¥ãŒã«ãèšå®ãããããŸãéµãç¡å¹ã«ããããšã§ãã客æ§ãéå§ããã®ãããã°ãåå ãªã®ãããŸãã¯å éšããã»ã¹ãšã©ãŒãåå ãªã®ãã«é¢ä¿ãªããæå³ããªãåé€ããå埩ã§ããŸãã
ãšã³ããŠãŒã¶ãŒãã¢ã«ãŠã³ããåé€ãããšãã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ã¢ã«ãŠã³ããåé€ãããããšããšã³ããŠãŒã¶ãŒ ããŒã¿ãåŠçãããµãŒãã¹ã«éç¥ããŸãããã®åŸãåé€ããããšã³ããŠãŒã¶ãŒ ã¢ã«ãŠã³ãã«é¢é£ä»ããããããŒã¿ãåé€ããããã«ã¹ã±ãžã¥ãŒãªã³ã°ã§ããŸãããã®æ©èœã«ããããšã³ããŠãŒã¶ãŒã¯èªåã®ããŒã¿ãå¶åŸ¡ã§ããŸãã
詳现ã«ã€ããŠã¯ãGoogle Cloudäžã®ããŒã¿ã®åé€ãã芧ãã ãããCloud Key Management Service ã䜿çšããŠç¬èªã®éµãç¡å¹ã«ããæ¹æ³ã«ã€ããŠã¯ãéµããŒãžã§ã³ã®ç Žæ£ãšåŸ©å ãã芧ãã ããã
å®å šãªã€ã³ã¿ãŒãããéä¿¡
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãã€ã³ã¿ãŒããããš Google ã€ã³ãã©ã¹ãã©ã¯ãã£äžã§å®è¡ããããµãŒãã¹ã®éã®éä¿¡ãä¿è·ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ããŒããŠã§ã¢ã®èšèšãšäŸçµŠå ã§èª¬æããããã«ãã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãLAN ãš WAN ã§çžäºæ¥ç¶ããã倿°ã®ç©çãã·ã³ã§æ§æãããŠããŸãããµãŒãã¹ééä¿¡ã®ã»ãã¥ãªãã£ã¯ããããã¯ãŒã¯ã®ã»ãã¥ãªãã£ã«äŸåããŸããããã ããã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ã€ã³ã¿ãŒããããããã©ã€ããŒã IP ã¢ãã¬ã¹ç©ºéã«åé¢ãããŠããŸãããµãŒãã¹æåŠæ»æïŒDoSïŒã«å¯Ÿããé²åŸ¡ãªã©ã®è¿œå ã®ä¿è·ãå®è£ ã§ããããã«ããã·ã³ã®ãµãã»ãããçŽæ¥å€éšã®ã€ã³ã¿ãŒããã ãã©ãã£ãã¯ã«å ¬éããŠããŸãã
Google Front End ãµãŒãã¹
ãµãŒãã¹ãã€ã³ã¿ãŒãããäžã§å©çšå¯èœã«ããå¿ èŠãããå Žåãããã Google Front EndïŒGFEïŒãšåŒã°ããã€ã³ãã©ã¹ãã©ã¯ã㣠ãµãŒãã¹ã«ç»é²ããå¿ èŠããããŸããGFE ã¯ããã¹ãŠã® TLS æ¥ç¶ãæ£ããèšŒææžã䜿çšããå®å šãªåæ¹ç§å¿æ§ã®ãµããŒããªã©ã®ãã¹ã ãã©ã¯ãã£ã¹ã«æ²¿ã£ãŠçµç«¯ãããããšãä¿èšŒããŸããGFE ã¯ãDoS æ»æã«å¯Ÿããä¿è·ãé©çšããŸãããã®åŸãGFE 㯠Google Workspace ã§ã®ãšã³ããŠãŒã¶ãŒ ããŒã¿ã®ã¢ã¯ã»ã¹ç®¡çã§èª¬æãããŠãã RPC ã»ãã¥ãªã㣠ãããã³ã«ã䜿çšããŠããµãŒãã¹ã®ãªã¯ãšã¹ãã転éããŸãã
å®éã«ã¯ãå€éšã«å ¬éããå éšãµãŒãã¹ã§ã¯ãGFE ãã¹ããŒããªãªããŒã¹ ãããã· ããã³ããšã³ããšããŠäœ¿çšãããŸããGFE ã¯ããããªã㯠DNS åãDoS ä¿è·ãTLS çµç«¯ã®ãããªã㯠IP ã¢ãã¬ã¹ ãã¹ãã£ã³ã°ãæäŸããŸããGFE ã¯ãä»ã®ãµãŒãã¹ãšåæ§ã®ã€ã³ãã©ã¹ãã©ã¯ãã£äžã§åäœããçä¿¡ãªã¯ãšã¹ãã®éã«åãããŠã¹ã±ãŒãªã³ã°ã§ããŸãã
Google Cloud VPC ãããã¯ãŒã¯å ã®ã客æ§ã® VM ã Borg ã§çŽæ¥ãã¹ããããŠãã Google API ãšãµãŒãã¹ã«ã¢ã¯ã»ã¹ãããšãã客æ§ã® VM 㯠Cloud Front End ãšåŒã°ããç¹å®ã® GFE ãšéä¿¡ããŸããã¬ã€ãã³ã·ãæå°éã«æããããã«ãCloud Front End ã¯ã客æ§ã® VM ãšåãã¯ã©ãŠã ãªãŒãžã§ã³å ã«é 眮ãããŸããã客æ§ã® VM ãš Cloud Front End éã®ãããã¯ãŒã¯ ã«ãŒãã£ã³ã°ã§ã¯ãã客æ§ã® VM ã«å€éš IP ã¢ãã¬ã¹ããªããŠãããŸããŸãããéå®å ¬éã® Google ã¢ã¯ã»ã¹ãæå¹ã«ãªã£ãŠããå Žåãå éš IP ã¢ãã¬ã¹ã®ã¿ãæã€ã客æ§ã® VM ã¯ãCloud Front End ã䜿çšã㊠Google API ãšãµãŒãã¹ã®å€éš IP ã¢ãã¬ã¹ãšéä¿¡ã§ããŸããã客æ§ã® VMãGoogle APIããµãŒãã¹éã®ãã¹ãŠã®ãããã¯ãŒã¯ ã«ãŒãã£ã³ã°ã¯ãå€éš IP ã¢ãã¬ã¹ãæã€ã客æ§ã® VM ã®å Žåã§ããGoogle ã®æ¬çªç°å¢ãããã¯ãŒã¯å ã®ãã¯ã¹ããããã«äŸåããŸãã
DoS é²åŸ¡
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®èŠæš¡ã倧ããããã倿°ã® DoS æ»æãåžåã§ããŸãããµãŒãã¹ã«å¯Ÿãã DoS ã®åœ±é¿ã®ãªã¹ã¯ã軜æžãããããGoogle ã§ã¯å€å±€åã® DoS é²åŸ¡ãæäŸããŠããŸãã
å ãã¡ã€ã㌠ããã¯ããŒã³ã Google ã®ããŒã¿ã»ã³ã¿ãŒã®ããããã«å€éšæ¥ç¶ãæäŸãããšãæ¥ç¶ã¯ããŒããŠã§ã¢ãšãœãããŠã§ã¢ã®ããŒããã©ã³ãµã®è€æ°ã®ã¬ã€ã€ãééããŸãããããã®ããŒããã©ã³ãµã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£äžã§åäœããŠããäžå€®ã® DoS ãµãŒãã¹ãžã®åä¿¡ãã©ãã£ãã¯ã«é¢ããæ å ±ãå ±åããŸããäžå€®ã® DoS ãµãŒãã¹ã DoS æ»æãæ€åºãããšãæ»æã«é¢é£ä»ãããããã©ãã£ãã¯ãç Žæ£ãŸãã¯æå¶ããããã«ããŒããã©ã³ãµãæ§æã§ããŸãã
GFE ã€ã³ã¹ã¿ã³ã¹ã¯ãäžå€®ã® DoS ãµãŒãã¹ã«åä¿¡ãããªã¯ãšã¹ãã«é¢ããæ å ±ãå ±åããŸãããã®æ å ±ã«ã¯ãããŒããã©ã³ãµãã¢ã¯ã»ã¹ã§ããªãã¢ããªã±ãŒã·ã§ã³ ã¬ã€ã€ã®æ å ±ãå«ãŸããŸãããã®åŸã§ãäžå€®ã® DoS ãµãŒãã¹ããæ»æãã©ãã£ãã¯ãç Žæ£ãŸãã¯æå¶ããããã« GFE ã€ã³ã¹ã¿ã³ã¹ãæ§æã§ããŸãã
ãŠãŒã¶ãŒèªèšŒ
DoS é²åŸ¡ã®åŸãå®å šãªéä¿¡ãå®çŸãããããäžå€®ã® ID ãµãŒãã¹ã«ãã£ãŠæ¬¡ã®é²åŸ¡ã¬ã€ã€ã远å ãããŸãããšã³ããŠãŒã¶ãŒã¯ãGoogle ãã°ã€ã³ããŒãžã§ãã®ãµãŒãã¹ãæäœããŸãããã®ãµãŒãã¹ã§ã¯ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããæ±ããããŸãããŸãããªã¹ã¯èŠå ã«åºã¥ããŠè¿œå æ å ±ããŠãŒã¶ãŒã«æ±ããããšãã§ããŸãããªã¹ã¯èŠå ã®äŸãšããŠã¯ããŠãŒã¶ãŒãåãããã€ã¹ãããã°ã€ã³ãããã©ãããåæ§ã®å Žæãããã°ã€ã³ããããšããããã©ããããªã©ããããŸãããŠãŒã¶ãŒã®èªèšŒåŸã¯ãID ãµãŒãã¹ãã以éã®åŒã³åºãã«äœ¿çšå¯èœãª Cookie ã OAuth ããŒã¯ã³ãªã©ã®èªèšŒæ å ±ãçºè¡ããŸãã
ãŠãŒã¶ãŒããã°ã€ã³ãããšãã«ãOTP ãªã©ã®ç¬¬ 2 èŠçŽ ããTitan ã»ãã¥ãªã㣠ããŒãªã©ã®ãã£ãã·ã³ã°èæ§ã®ããã»ãã¥ãªã㣠ããŒã䜿çšã§ããŸããTitan ã»ãã¥ãªã㣠ããŒã¯ãFIDO Universal 2nd FactorïŒU2FïŒããµããŒãããç©çããŒã¯ã³ã§ããGoogle 㯠FIDO Alliance ã§ U2F ã®ãªãŒãã³èŠæ Œã®çå®ãæ¯æŽããŸãããã»ãšãã©ã®ãŠã§ã ãã©ãããã©ãŒã ãšãã©ãŠã¶ã§ããã®ãªãŒãã³èªèšŒæšæºãæ¡çšãããŠããŸãã
ãªãã¬ãŒã·ã§ã³ ã»ãã¥ãªãã£
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãGoogle ãã€ã³ãã©ã¹ãã©ã¯ã㣠ãœãããŠã§ã¢ãéçºããŠã瀟å¡ã®ãã·ã³ãšèªèšŒæ å ±ãä¿è·ããå éšãšå€éšã®äž¡æ¹ã®è åšããã€ã³ãã©ã¹ãã©ã¯ãã£ãé²åŸ¡ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
å®å šãªãœãããŠã§ã¢ã®éçº
Google ã§ã¯ãåè¿°ã®ãœãŒã¹ç®¡çã®ä¿è·ãšäºè ã¬ãã¥ãŒ ããã»ã¹ã«å ããŠãããããããŒãç¹å®ã®ã¯ã©ã¹ã®ã»ãã¥ãªã㣠ãã°ãçºçãããªãããã«ã©ã€ãã©ãªã䜿çšããŠããŸããããšãã°ããŠã§ãã¢ããªã® XSS è匱æ§ãæé€ããã®ã«åœ¹ã«ç«ã€ã©ã€ãã©ãªãšãã¬ãŒã ã¯ãŒã¯ãçšæãããŠããŸãããŸãããã¡ã¶ãŒãªã©ã®èªåããŒã«ãéçè§£æããŒã«ããŠã§ã ã»ãã¥ãªã㣠ã¹ãã£ãã䜿çšããŠãã»ãã¥ãªã㣠ãã°ãèªåçã«æ€åºããŸãã
æçµãã§ãã¯ãšããŠããªã¹ã¯ã®äœãæ©èœã«å¯Ÿããè¿ éãªéžå¥ãããæããªã¹ã¯ã®é«ãæ©èœã«å¯Ÿããç¶¿å¯ãªèšèšã»å®è£ ã¬ãã¥ãŒãŸã§ãæäœæ¥ã«ããã»ãã¥ãªã㣠ã¬ãã¥ãŒã宿œããŠããŸãããããã®ã¬ãã¥ãŒãè¡ãããŒã ã«ã¯ããŠã§ã ã»ãã¥ãªãã£ãæå·ããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã»ãã¥ãªãã£ã®å°éå®¶ãå«ãŸããŠããŸãããã®ã¬ãã¥ãŒã¯ãæ°ããã»ãã¥ãªã㣠ã©ã€ãã©ãªæ©èœã®éçºããä»åŸã®ãããã¯ãã«äœ¿çšã§ããæ°ãããã¡ã¶ãŒã®éçºã«ã€ãªããå¯èœæ§ããããŸãã
ããã«ãã€ã³ãã©ã¹ãã©ã¯ãã£ãã¢ããªã±ãŒã·ã§ã³ã®ãã°ãçºèŠããŠå ±åãã人ã«å ±å¥šéãåºãè匱æ§å ±å¥šéããã°ã©ã ã宿œããŠããŸããGoogle ãæäŸããŠããç¹å žãªã©ããã®ããã°ã©ã ã®è©³çްã«ã€ããŠã¯ãBug Hunters ã®äž»èŠãªçµ±èšæ å ±ãã芧ãã ããã
ãŸããGoogle ã䜿çšãããªãŒãã³ãœãŒã¹ ãœãããŠã§ã¢ã«å¯ŸãããŒãã〠ãšã¯ã¹ããã€ããªã©ã®ã»ãã¥ãªãã£åé¡ã®çºèŠã«ãåãçµãã§ããŸããGoogle ã§ã¯ãSpectre ãš Meltdown ãªã©ããŒããã€è匱æ§ã®ç ç©¶ã«åãçµã Google ã®ç ç©¶è ããŒã Project Zero ãéå¶ããŠããŸãããŸããGoogle 㯠Linux KVM ãã€ããŒãã€ã¶ã® CVE ãšã»ãã¥ãªã㣠ãã°ã®ä¿®æ£ã®æå€§ã®æåºè ã§ããããŸãã
ãœãŒã¹ã³ãŒãã®ä¿è·
Google ã®ãœãŒã¹ã³ãŒãã¯ãæŽåæ§ãšã¬ããã³ã¹ãåãããªããžããªã«æ ŒçŽãããŠããŸãããã®ãªããžããªã§ã¯ããµãŒãã¹ã®ææ°ããŒãžã§ã³ãšå€ãããŒãžã§ã³ã®äž¡æ¹ãç£æ»ã§ããŸããã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ããµãŒãã¹ã®ãã€ããªãã¬ãã¥ãŒããã§ãã¯ã€ã³ããã¹ãããåŸã«ç¹å®ã®ãœãŒã¹ã³ãŒããããã«ãããå¿ èŠããããŸããBinary Authorization for BorgïŒBABïŒã¯ããµãŒãã¹ããããã€ããããšãã«å®è¡ãããå éšé©çšãã§ãã¯ã§ããBAB ã§ã¯æ¬¡ã®åŠçãè¡ãããŸãã
- Google ã«ãããã€ãããæ¬çªç°å¢ã®ãœãããŠã§ã¢ãšæ§æãïŒç¹ã«ãã®ã³ãŒãããŠãŒã¶ãŒããŒã¿ã«ã¢ã¯ã»ã¹ã§ããå Žåã«ïŒç¢ºèªãããæ¿èªãããŠããããšã確èªããŸãã
- ã³ãŒããšæ§æã®ãããã€ãç¹å®ã®æå°åºæºãæºãããŠããããšã確èªããŸãã
- ã€ã³ãµã€ããŒãæ»æè ããœãŒã¹ã³ãŒãã«æªæã®ãã倿Žãå ããªãããå¶éããŠããµãŒãã¹ãããã®ãœãŒã¹ãŸã§ã®ç£æ»èšŒè·¡ãæäŸããŸãã
瀟å¡ã®ããã€ã¹ãšèªèšŒæ å ±ã®ä¿è·
Google ã§ã¯ã瀟å¡ã®ããã€ã¹ãšèªèšŒæ å ±ã䟵害ããä¿è·ããããã«å®å šå¯Ÿçãå®è£ ããŠããŸãã瀟å¡ãé«åºŠãªãã£ãã·ã³ã°è©æ¬ºããä¿è·ãããããOTP ã® 2 èŠçŽ èªèšŒã«ä»£ãããU2F äºæã®ã»ãã¥ãªã㣠ããŒã®äœ¿çšãå¿ é ã«ããŸããã
Google ã§ã¯ã瀟å¡ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®éçšã«äœ¿çšããã¯ã©ã€ã¢ã³ã ããã€ã¹ãã¢ãã¿ãªã³ã°ããŠããŸãããããã®ããã€ã¹ã®ãªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã€ã¡ãŒãžãã»ãã¥ãªã㣠ããããå«ãææ°çã§ããããšãä¿èšŒãã瀟å¡ãããã€ã¹ã«ã€ã³ã¹ããŒã«ã§ããã¢ããªã±ãŒã·ã§ã³ã管çããŠããŸãããŸãããŠãŒã¶ãŒãã€ã³ã¹ããŒã«ããã¢ããªã±ãŒã·ã§ã³ãããŠã³ããŒãããã©ãŠã¶ã®æ¡åŒµæ©èœããŠã§ããã©ãŠã¶ã®ã³ã³ãã³ããã¹ãã£ã³ããŠãããã€ã¹ãäŒæ¥ããã€ã¹ã«é©ããŠãããã©ããã倿ããŠããŸãã
瀟å LAN ã«æ¥ç¶ãããŠããããšã¯ãã¢ã¯ã»ã¹æš©ãä»äžããããã®äž»èŠãªä»çµã¿ã§ã¯ãããŸããã代ããã«ããªãœãŒã¹ãžã®ç€Ÿå¡ã®ã¢ã¯ã»ã¹ãä¿è·ããããã«ãŒããã©ã¹ã ã»ãã¥ãªãã£ã䜿çšããŠããŸããã¢ããªã±ãŒã·ã§ã³ ã¬ãã«ã§ã®ã¢ã¯ã»ã¹ç®¡çã«ããã瀟å¡ã管ç察象ããã€ã¹ã䜿çšããŠãäºæããããããã¯ãŒã¯ãšå°ççãªå Žæããæ¥ç¶ããŠããå Žåã«ã®ã¿ãå éšã¢ããªã±ãŒã·ã§ã³ã瀟å¡ã«å ¬éã§ããŸããã¯ã©ã€ã¢ã³ã ããã€ã¹ã¯ãåã ã®ãã·ã³ã«å¯ŸããŠçºè¡ãããèšŒææžãšããã®æ§æïŒææ°ã®ãœãããŠã§ã¢ãªã©ïŒã«é¢ããã¢ãµãŒã·ã§ã³ã«åºã¥ããŠä¿¡é ŒãããŸãã詳现ã«ã€ããŠã¯ãBeyondCorp ãã芧ãã ããã
ã€ã³ãµã€ã㌠ãªã¹ã¯ã®äœæž
ã€ã³ãµã€ã㌠ãªã¹ã¯ãšã¯ãGoogle ã®ãããã¯ãŒã¯ãã·ã¹ãã ãããŒã¿ãžã®ã¢ã¯ã»ã¹æš©ãçŸåšæã£ãŠãããéå»ã«æã£ãŠããåŸæ¥å¡ãå åŸæ¥å¡ãè«è² æ¥è ããã®ä»ã®ããžãã¹ ããŒãããŒãããã®ã¢ã¯ã»ã¹ãæªçšã㊠Google ã®æ å ±ã·ã¹ãã ããŸãã¯æ å ±ã·ã¹ãã ã®æ©å¯æ§ãå®å šæ§ãå¯çšæ§ã䟵害ããå¯èœæ§ã®ããšã§ãã
ã€ã³ãµã€ã㌠ãªã¹ã¯ã軜æžãããããGoogle ã§ã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®ç®¡çè æš©éãä»äžãããåŸæ¥å¡ã®ã¢ã¯ãã£ããã£ãå¶éããç©æ¥µçã«ã¢ãã¿ãªã³ã°ããŠããŸããGoogle ã§ã¯ãåãã¿ã¹ã¯ãå®å šã§ç®¡çãããæ¹æ³ã§èªåçã«å®è¡ããåŠçãè¡ãããšã§ãç¹å®ã®ã¿ã¹ã¯ã«å¯Ÿããç¹æš©ã¢ã¯ã»ã¹ã®å¿ èŠæ§ãæé€ããåªåãç¶ããŠããŸããGoogle ã¯ãæ©å¯ããŒã¿ãå ¬éããã«ãããã°ã§ããå¶éä»ã API ãå ¬éããŠããŸãããŸãã人éã®ãªãã¬ãŒã¿ãè¡ãç¹å®ã®æ©å¯æ§ã®é«ãã¢ã¯ã·ã§ã³ã«ã¯ãäºè ã®æ¿èªãå¿ èŠã§ãã
ãšã³ããŠãŒã¶ãŒæ å ±ãžã® Google 瀟å¡ã®ã¢ã¯ã»ã¹ã¯ãäžäœã€ã³ãã©ã¹ãã©ã¯ã㣠ããã¯ãä»ããŠèšé²ãããŸããGoogle ã®ã»ãã¥ãªã㣠ããŒã ãã¢ã¯ã»ã¹ ãã¿ãŒã³ãç£èŠããç°åžžãªã€ãã³ãã調æ»ããŠããŸãã詳现ã«ã€ããŠã¯ã Google Cloudã®ç¹æš©ã¢ã¯ã»ã¹ãã芧ãã ããã
Google ã¯ãã€ã³ãµã€ã㌠ãªã¹ã¯ãããµãã©ã€ ãã§ãŒã³ãä¿è·ããããã« Binary Authorization for Borg ã䜿çšããŠããŸãããŸããBeyondProd ãžã®æè³ã¯ãGoogle ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãŠãŒã¶ãŒããŒã¿ã®ä¿è·ãš Google ãµãŒãã¹ã«å¯Ÿããä¿¡é Œã®ç¢ºç«ã«åœ¹ç«ã£ãŠããŸãã
Google Cloudã§ã¯ãã¢ã¯ã»ã¹ã®éææ§ã䜿çšããŠããŒã¿ãžã®ã¢ã¯ã»ã¹ãã¢ãã¿ãªã³ã°ã§ããŸããã¢ã¯ã»ã¹ã®éææ§ã®ãã°ã䜿çšããããšã«ãããGoogle ã®æ åœè ã«ããã客æ§ããŒã¿ãžã®ã¢ã¯ã»ã¹ã¯ããµãŒãã¹åæ¢ã®ä¿®åŸ©ããµããŒã ãªã¯ãšã¹ããžã®å¯Ÿå¿ãªã©ãããžãã¹äžã®æ£åœãªçç±ãããå Žåã«éãããŠããããšã確èªã§ããŸãããŸããAccess Approval ã«ãããCloud ã«ã¹ã¿ããŒã±ã¢ããšã³ãžãã¢ãªã³ã°ãã客æ§ã®ããŒã¿ã«ã¢ã¯ã»ã¹ããå¿ èŠãããå Žåã«æç€ºçãªæ¿èªãæ±ããããããã«ãªããŸãããã®æ¿èªã¯ãã¢ã¯ã»ã¹æ¿èªã®æŽåæ§ã確ä¿ããããã«æå·çã«æ€èšŒãããŸãã
æ¬çªç°å¢ãµãŒãã¹ã®ä¿è·ã®è©³çްã«ã€ããŠã¯ãGoogle ãæ¬çªç°å¢ã®ãµãŒãã¹ãä¿è·ããæ¹æ³ãã芧ãã ããã
è åšã®ã¢ãã¿ãªã³ã°
Google ã® Threat Analysis Group ã¯è åšã¢ã¯ã¿ãŒãšããã®æŠè¡ãšæè¡ã®é²åãã¢ãã¿ãªã³ã°ããŸãããã®ã°ã«ãŒãã®ç®çã¯ãGoogle ãããã¯ãã®å®å šæ§ãšã»ãã¥ãªãã£ãæ¹åãããªã³ã©ã€ã³ ã³ãã¥ããã£ã®ã¡ãªãããåŸãããã«ãã®æ å ±ãå ±æããããšã§ãã
Google Cloudã®å Žåã¯ãGoogle Cloud Threat Intelligence for Google Security Operations ãš VirusTotal ã䜿çšããŠãããŸããŸãªçš®é¡ã®ãã«ãŠã§ã¢ãã¢ãã¿ãªã³ã°ãã察åŠã§ããŸãã Google Cloud Threat Intelligence for Google Security Operations ã¯ãGoogle Security Operations ã§äœ¿çšããè åšã€ã³ããªãžã§ã³ã¹ãéçºããè åšç ç©¶è ã®ããŒã ã§ããVirusTotal ã¯ãäŒæ¥å ã§ã®ãã«ãŠã§ã¢ã®åäœãè©³çŽ°ã«ææ¡ã§ãããã«ãŠã§ã¢ ããŒã¿ããŒã¹ãšå¯èŠåãœãªã¥ãŒã·ã§ã³ã§ãã
è åšã¢ãã¿ãªã³ã°æŽ»åã®è©³çްã«ã€ããŠã¯ãThreat Horizons ã¬ããŒããã芧ãã ããã
äŸµå ¥æ€ç¥
Google ã§ã¯ãé«åºŠãªããŒã¿åŠçãã€ãã©ã€ã³ã䜿çšããŠãåã ã®ããã€ã¹ã§ã®ãã¹ãããŒã¹ã®ä¿¡å·ãã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ããŸããŸãªã¢ãã¿ãªã³ã° ãã€ã³ãããã®ãããã¯ãŒã¯ ããŒã¹ã®ä¿¡å·ãã€ã³ãã©ã¹ãã©ã¯ã㣠ãµãŒãã¹ããã®ä¿¡å·ãçµ±åããŠããŸãããããã®ãã€ãã©ã€ã³äžã«æ§ç¯ãããã«ãŒã«ãšãã·ã³ ã€ã³ããªãžã§ã³ã¹ã«ãããã»ãã¥ãªã㣠ãšã³ãžãã¢ã¯æœåšçãªã€ã³ã·ãã³ãã®èŠåã確èªã§ããŸããGoogle ã®èª¿æ»ããã³ã€ã³ã·ãã³ã察å¿ããŒã ã¯ããããã®æœåšçãªã€ã³ã·ãã³ãã幎äžç¡äŒã§éžå¥ã調æ»ã察å¿ããŠããŸããGoogle ã§ã¯ãæ€åºã¡ã«ããºã ãšå¯Ÿå¿ã¡ã«ããºã ã®æå¹æ§ãè©äŸ¡ããŠæ¹åããããã® Red Team èšç·Žã宿œããŠããŸãã
次ã®ã¹ããã
- Building secure and reliable systemïŒO'Reilly ã®æžç±ïŒã§ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä¿è·ã®è©³çްã確èªããã
- ããŒã¿ã»ã³ã¿ãŒã®ã»ãã¥ãªãã£ã®è©³çްã確èªããã
DDoS æ»æããã®ä¿è·æ¹æ³ã確èªããã
Google ã®ãŒããã©ã¹ã ãœãªã¥ãŒã·ã§ã³ã§ãã BeyondCorp ã®è©³çްã確èªããã