Axis Products With AXIS OS 11 Now Support IEEE 802.1AE MACsec

Axis Communications announces the support for the IEEE 802.1AE MACsec security standard in the latest release of the Axis operating system, AXIS OS 11.8, for more than 200 network devices, including cameras, intercoms, and audio speakers. The development enables such devices to automatically encrypt data at a foundational level to enhance zero-trust networking. Axis becomes the first manufacturer of physical security products to support MACsec (Media Access Control Security), underscoring the company’s ongoing commitment to both device and data security.

With AXIS OS 11.8, MACsec is enabled by default (through EAP-TLS/Dynamic CAK mode). Data is encrypted at the Ethernet Layer 2 (data link) network level, safeguarding the integrity of data being transferred between Axis devices and MACsec-enabled Ethernet switches. Because it operates at layer 2, MACsec can encrypt and protect data that could not previously be encrypted such as NTP, DHCP for general device operation, and RTP/RTSP for video streaming. Even if a user is already implementing HTTPS or a different form of encryption at another layer, adding MACsec at layer 2 effectively double encrypts the data, ensuring that an attacker would need to intercept and decrypt both layers in order to see or steal critical information. This makes the attacker’s job considerably more difficult, significantly increasing protection against attacks including denial of service, intrusion, man-in-the-middle data insertion and eavesdropping.

“Customers benefit from security features that are enabled by default and that do not require any pre-configuration,” says Andre Bastert, Global Product Manager of AXIS OS. “They lower installation complexity, and thereby, literally save time and money. These security features are great examples of zero-trust security that do not require more time from customers. With the increase in the convergence of OT (operational technology) and IT (information technology), these standard security mechanisms are what IT professionals expect of smart IoT products, and we are meeting their needs as part of Axis’ long-term strategy to enable secure, zero-touch integration of Axis network products into zero-trust networks.”

The adoption of IEEE 802.1AE MACsec builds on Axis’ implementation of the IEEE 802.1AR Secure Device Identity (DevID) standard, together with IEEE 802.1X EAP-TLS network access control. Default support for the three IEEE standards on Axis devices enables automated device onboarding, authentication, and end-to-end encryption, providing IT professionals with standard mechanisms to efficiently and securely integrate Axis devices into a corporate network.

MACsec allows for an exchange and verification of encryption keys between a MACsec-enabled device and switch. Data within each Ethernet frame is then encrypted and decrypted in real time using AES-GCM 128-bit, enabling fast and secure transfer of data. AXIS OS 11.8 supports the two standard IEEE 802.1AE security modes: dynamic CAK (EAP-TLS), which is automatic and enabled by default, and static CAK (pre-shared key) for manual configuration.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3

  • Hanwha QNO-7012R

    Hanwha QNO-7012R

    The Q Series cameras are equipped with an Open Platform chipset for easy and seamless integration with third-party systems and solutions, and analog video output (CVBS) support for easy camera positioning during installation. A suite of on-board intelligent video analytics covers tampering, directional/virtual line detection, defocus detection, enter/exit, and motion detection. 3