ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Axis Products With AXIS OS 11 Now Support IEEE 802.1AE MACsec, Significantly Enhancing Security in Zero-Trust Networks

Added layer of security and encryption—long recognized and required by IT departments— now incorporated into Axis devices

Axis Communications, a leader in network video, announces the support for the IEEE 802.1AE MACsec security standard in the latest release of the Axis operating system, AXIS OS 11.8, for more than 200 network devices, including cameras, intercoms, and audio speakers. The development enables such devices to automatically encrypt data at a foundational level to enhance zero-trust networking. Axis becomes the first manufacturer of physical security products to support MACsec (Media Access Control Security), underscoring the company’s ongoing commitment to both device and data security.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240131637783/en/

The securely stored Axis device ID [1], an IEEE 802.1AR-compliant secure device identity, is used to authenticate into MACsec-enabled networks [4,5] through the IEEE 802.1X EAP-TLS port-based network access control (2). Through the EAP-TLS session, MACsec keys are exchanged automatically to setup a secure link [3], protecting all network traffic from the Axis device to a MACsec-enabled switch. (Graphic: Business Wire)

The securely stored Axis device ID [1], an IEEE 802.1AR-compliant secure device identity, is used to authenticate into MACsec-enabled networks [4,5] through the IEEE 802.1X EAP-TLS port-based network access control (2). Through the EAP-TLS session, MACsec keys are exchanged automatically to setup a secure link [3], protecting all network traffic from the Axis device to a MACsec-enabled switch. (Graphic: Business Wire)

With AXIS OS 11.8, MACsec is enabled by default (through EAP-TLS/Dynamic CAK mode). Data is encrypted at the Ethernet Layer 2 (data link) network level, safeguarding the integrity of data being transferred between Axis devices and MACsec-enabled Ethernet switches. Because it operates at layer 2, MACsec can encrypt and protect data that could not previously be encrypted such as NTP, DHCP for general device operation, and RTP/RTSP for video streaming. Even if a user is already implementing HTTPS or a different form of encryption at another layer, adding MACsec at layer 2 effectively double encrypts the data, ensuring that an attacker would need to intercept and decrypt both layers in order to see or steal critical information. This makes the attacker’s job considerably more difficult, significantly increasing protection against attacks including denial of service, intrusion, man-in-the-middle data insertion and eavesdropping.

“Customers benefit from security features that are enabled by default and that do not require any pre-configuration,” says Andre Bastert, Global Product Manager of AXIS OS. “They lower installation complexity, and thereby, literally save time and money. These security features are great examples of zero-trust security that do not require more time from customers. With the increase in the convergence of OT (operational technology) and IT (information technology), these standard security mechanisms are what IT professionals expect of smart IoT products, and we are meeting their needs as part of Axis’ long-term strategy to enable secure, zero-touch integration of Axis network products into zero-trust networks.”

The adoption of IEEE 802.1AE MACsec builds on Axis’ implementation of the IEEE 802.1AR Secure Device Identity (DevID) standard, together with IEEE 802.1X EAP-TLS network access control. Default support for the three IEEE standards on Axis devices enables automated device onboarding, authentication, and end-to-end encryption, providing IT professionals with standard mechanisms to efficiently and securely integrate Axis devices into a corporate network.

MACsec allows for an exchange and verification of encryption keys between a MACsec-enabled device and switch. Data within each Ethernet frame is then encrypted and decrypted in real time using AES-GCM 128-bit, enabling fast and secure transfer of data. AXIS OS 11.8 supports the two standard IEEE 802.1AE security modes: dynamic CAK (EAP-TLS), which is automatic and enabled by default, and static CAK (pre-shared key) for manual configuration.

Secure onboarding of an Axis device can be done through IEEE 802.1X EAP-TLS port-based network access control, in combination with an Axis device’s support for IEEE 802.1AR. IEEE 802.1AR is part of the Axis Edge Vault cybersecurity platform and enables automatic authentication in an IEEE 802.1X network. Axis loads unique, IEEE 802.1AR-compliant Initial Device Identifiers (IDevIDs) into a tamper-protected hardware cryptographic computing module that is embedded in Axis IoT products at the time of manufacture, protecting the IDevIDs against probing.

Seamless onboarding can be achieved with any network access control solution that supports the IEEE standards; for instance, with HPE Aruba Networking ClearPass Policy Manager, for which an integration guide is available.

For more information on IEEE 802.1AE MACsec, please visit the Axis solutions page for enterprise IT or the AXIS OS knowledge base.

Contacts

Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the following
Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.