Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

Axis implements MACsec standard in zero trust network solutions

Axis implements MACsec

International. Axis Communications announced the support of the latest version of its AXIS OS 11.8 operating system for the IEEE 802.1AE Media Access Control Security standard on more than 200 network devices, including cameras, intercoms and speakers.

This advancement allows such devices to automatically encrypt data at the second layer (data link) of Ethernet to strengthen communication in zero trust networks. In this way, Axis becomes the first manufacturer of physical security products to incorporate Media Access Control Security (MACsec).

With AXIS OS 11.8, MACsec is enabled by default (via EAP-TLS/Dynamic CAK mode) to protect the integrity of data transferred between Axis devices and MACsec-enabled Ethernet switches.

Additionally, MACsec protects data communications and network protocols at the elementary level, providing increased protection against low-level attacks such as denial of service, intrusion, man-in-the-middle data insertion, and interception.

- Publicidad -

The adoption of IEEE 802.1AE MACsec adds to Axis' implementation of the IEEE 802.1AR secure device identity (DevID) standard, along with the IEEE 802.1X EAP-TLS network access control standard.

The out-of-the-box support of these three IEEE standards on Axis devices opens the door to automating device onboarding, authentication and end-to-end encryption, giving IT professionals standard mechanisms to integrate Axis devices on corporate networks.

“Customers have security features that are enabled by default and nothing needs to be configured,” said Andre Bastert, Global Product Manager, AXIS OS. “They reduce installation complexity and therefore save time and money. These security features are a great example of zero trust security that doesn't force customers to invest more time. With an increasing convergence of OT (Operational Technology) and IT (Information Technology), these standard security mechanisms are what IT professionals expect from intelligent IoT products, and at Axis we are responding to their needs with a consolidated strategy to facilitate the secure and zero-intervention integration of Axis networking products into zero trust networks.”

Features and compatibility
MACsec allows encryption keys to be exchanged and verified between a device and a switch with MACsec. The data in each Ethernet frame is then encrypted and decrypted in real time using 128-bit AES-GCM, opening the door to fast and secure data transfer.

AXIS OS 11.8 supports two standard IEEE 802.1AE security modes: Dynamic CAK (EAP-TLS), which is automatic and enabled by default, and Static CAK (Pre-Shared Key) for manual configuration.

The securely stored Axis device ID [1], a secure device identity compliant with IEEE 802.1AR, is used for authentication on networks with MACsec [4,5] through IEEE port-based network access control 802.1X EAP-TLS (2). In the EAP-TLS session, MACsec keys are automatically exchanged to create a secure link [3] that protects all network traffic from the Axis device to a MACsec-enabled switch.

- Publicidad -

Secure onboarding of an Axis device can be accomplished through IEEE 802.1X EAP-TLS port-based network access control, combined with the IEEE 802.1AR standard supported on the Axis device. IEEE 802.1AR is part of the Axis Edge Vault cybersecurity platform and enables automatic authentication on an IEEE 802.1X network.

Axis loads unique IEEE 802.1AR compliant Initial Device Identifiers (IDevIDs) into a tamper-proof hardware cryptographic computing module built into Axis IoT products at the time of manufacture, to protect IDevIDs from possible spies.

Easy onboarding is possible on any IEEE standards-compliant network, for example with HPE Aruba Networking's ClearPass Policy Manager when an integration guide is available. For more technical information on MACsec IEEE 802.1AE on AXIS OS, see the AXIS OS knowledge base.

 
Author: lpi-english

No thoughts on “Axis implements MACsec standard in zero trust network solutions”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Suscribase Gratis
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS

Webinar: NxWitness el VMS rápido fácil y ultra ligero

Webinar: Por qué elegir productos con certificaciones de calidad

Por: Eduardo Cortés Coronado, Representante Comercial - SECO-LARM USA INC La importancia de utilizar productos certificados por varias normas internacionales como UL , Ul294, CE , Rosh , Noms, hacen a tus instalciones mas seguras y confiables además de ser un herramienta más de venta que garantice nuestro trabajo, conociendo qué es lo que certifica cada norma para así dormir tranquilos sabiendo que van a durar muchos años con muy bajo mantenimiento. https://www.ventasdeseguridad.com/2...

Webinar: Anviz ONE - Solución integral para pymes

Por: Rogelio Stelzer, Gerente comercial LATAM - Anviz Presentación de la nueva plataforma Anviz ONE, en donde se integran todas nuestras soluciones de control de acceso y asistencia, video seguridad, cerraduras inteligentes y otros sensores. En Anviz ONE el usuario podrá personalizar las opciones según su necesidad, de forma sencilla y desde cualquier sitio que tenga internet. https://www.ventasdeseguridad.com/2...

Webinar: Aplicaciones del IoT y digitalización en la industria logística

Se presentarán los siguientes temas: • Aplicaciones del IoT y digitalización en la industria logística. • Claves para decidir el socio en telecomunicaciones. • La última milla. • Nuevas estrategias de logística y seguimiento de activos sostenibles https://www.ventasdeseguridad.com/2...

Sesión 5: Milestone, Plataforma Abierta que Potencializa sus Instalaciones Manteniéndolas Protegidas

Genaro Sanchez, Channel Business Manager - MILESTONE https://www.ventasdeseguridad.com/2...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter