securitylinkindia

NIST Releases Version 1.0 of Privacy Framework

Today’s data-driven society has a tricky balancing act to perform – building innovative products and services that use personal data while still protecting people’s privacy. To help organizations keep this balance, the National Institute of Standards and Technology (NIST) is offering a new tool for managing privacy risk. The agency has just released Version 1.0 of the NIST Privacy Framework – a tool for improving privacy through enterprise risk management. Developed from a draft version in collaboration with a range of stakeholders, the framework provides a useful set of privacy protection strategies for organizations that wish to improve their approach to using and protecting personal data. The publication also provides clarification about privacy risk management concepts and the relationship between the Privacy Framework and NIST’s Cybersecurity Framework. “Privacy is more important than ever in today’s digital age,” said Under Secretary of Commerce for Standards and Technology and NIST Director Walter G. Copan, “The strong support the Privacy Framework’s development has already received demonstrates the critical need for tools to help organizations build products and services providing real value, while protecting people’s privacy.” Personal data includes information about specific individuals such as their addresses or social security numbers that a company might gather and use in the normal course of business. Because this data can be used to identify the people who provide it, an organization must frequently take action to ensure it is not misused in a way that could embarrass, endanger or compromise the customers. The NIST Privacy Framework is not a law or regulation, rather a voluntary tool that can help organizations manage privacy risk arising from their products and services, as well as demonstrate compliance with laws that may affect them such as the California Consumer Privacy Act and the European Union’s General Data Protection Regulation. It helps organizations identify the privacy outcomes they want to achieve and then prioritize the actions needed to do so. “What you’ll find in the framework are building blocks that can help you achieve your privacy goals, which may include laws your organization needs to follow,” said Naomi Lefkovitz, a Senior Privacy Policy Adviser at NIST and Leader of the framework effort, “If you want to consider how to increase customer trust through more privacy-protective products or services, the framework can help you do that. But we designed it to be agnostic to any law, so it can assist you no matter what your goals are.” Privacy as a basic right in the USA has roots in the U.S. Constitution, but its application in the digital age is still evolving, in part because technology itself is changing at a rapidly accelerating pace. New uses for data pop up regularly, especially in the context of the internet of things and artificial intelligence, which together promise to gather and analyze patterns in the real world that previously have gone unrecognized. With these opportunities come new risks. “A class of personal data that we consider to be of low value today may have a whole new use in a couple of years,” Lefkovitz said, “Or you might have two classes of data that are not sensitive on their own, but if you put them together they suddenly may become sensitive as a unit. That’s why you need a framework for privacy risk management, not just a checklist of tasks. You need an approach that allows you to continually re-evaluate and adjust to new risks.” The Privacy Framework 1.0 has an overarching structure modeled on that of the widely used NIST Cybersecurity Framework, and the two frameworks are designed to be complementary and also updated over time. “Privacy and security are related but distinct concepts, and merely adopting a good security posture does not necessarily mean that an organization is addressing all its privacy needs” said Lefkovitz. As with its draft version, the Privacy Framework centers on three sections – the Core, which offers a set of privacy protection activities; the Profiles, which help determine which of the activities in the Core an organization should pursue to reach its goals most effectively, and the Implementation Tiers, which help optimize the resources dedicated to managing privacy risk. The NIST authors plan to continue building on their work to benefit the framework’s users. Digital privacy risk management is a comparatively new concept, and Lefkovitz said they received many requests for clarification about the nature of privacy risk, as well as for additional supporting resources. “People continue to yearn for more guidance on how to do privacy risk management,” she said, “We have released a companion roadmap for the framework to point the way toward more research to address current privacy challenges, and we are building a repository of guidance resources to support implementation of the framework. We hope the community of users will contribute to it to advance privacy for the good of all.”  

Read More

Hikvision Wins Twin Accolades

Prestigious Innovative Achievement Award at the 2019 Detektor International Awards Hikvision has been awarded the Innovative Achievement Award for its thermal and optical network Turret camera at the 2019 Detektor International Awards in Sweden. The award was given in the category of Alarm and Detection. About the Hikvision camera, the jury said, “Through a combination of smart analytics, and thermal and optical technologies, Hikvision succeeds in offering an impressive solution for early detection and optimum performance.”   Marcel Wiechmann, Thermal Products Manager at Hikvision Europe was present at the ceremony to receive the award. He said, “Hikvision is excited to receive this accolade. Our innovative thermal and optical network Turret camera was launched in July to empower security teams to stop a fire before it’s truly started. It’s also very cost-effective with such advanced fire detection. We’re delighted that this product has been so well recognized by the security industry.” The award winning Hikvision camera DS-2TD1217-2/ V1 enables rapid indoor fire detection through bi-spectrum technology, which captures images using both thermal radiation and visible light. By displaying optical and thermal images together through image fusion or picture-in-picture, the camera helps safety personnel to quickly pinpoint the source of a fire. Importantly, the camera also triggers an alarm once the temperature goes higher than a user-set limit – potentially allowing personnel to prevent ignition or combustion. In addition, the camera contains a built-in GPU for running the Hikvision deep learning algorithm in order to support indoor monitoring and advanced intrusion detection. Equipped for double duty – both fire detection and intrusion detection – this camera is highly recommended for indoor solutions, especially in application scenarios such as warehouses, museums, data centers, and offices. Explosive Performance of Hikvision Smart Thermal Camera at GIT Security Awards 2020 Hikvision also won the GIT Security Award for its thermal explosion proof camera (DS-2TD2466T-25X). In a vote by GIT’s security professional readers, the product was hailed as the winner in the ‘Fire and Explosion Protection’ category of the popular annual awards. One focus of the awards is innovation in products – and the Hikvision camera does not disappoint. It uses a vanadium oxide uncooled focal plane sensor to deliver enhanced thermal image quality. It also uses a smart fire detection algorithm to identify potential fire risks by monitoring irregular temperature rises in a sensitive area. The camera adopts 316L stainless steel material to meet the requirements of environments that have a risk of explosion, like chemical plants, oil depots and gas stations. Allen Xue, Hikvision DACH Area Manager said, “We are honoured to receive this award from GIT Security. The fact that this is the result of voting from GIT readers – representing our customers – makes it even more poignant. It’s also interesting that video surveillance cameras do not usually win in the fire prevention category, and we believe this reflects the innovative nature of our products. We pride ourselves on using our innovation to solve customer problems, and this award is testimony to that goal.”  

Read More

Socionext Collaborates with Foxconn and Network Optix

New, compact, powerful edge computing platforms for ‘smart’ applications Socionext Inc., a world leading system-on-chip (SoC) solutions provider, has introduced new, intelligent, scalable edge-AI solutions developed in partnership with Foxconn Technology Group and Network Optix Inc. The newly launched solutions are powered by a scalable, 24-core Arm Cortex-A53 SoC offering exceptional CPU performance, which provides excellent processing speed and power-savings. The new system is designed to support the most demanding edge computing, smart energy, Internet of Things (IoT), and real-time data processing applications. Socionext and Foxconn have collaborated on the development of Foxconn’s BOXiedge, a high-density, fan-less, and highly efficient edge server that measures a compact 200mmx200mm (1U) and typically consumes only 30W of power. The BOXiedge is ideal for industrial internet AI applications as it provides over 20 TOPS in total with AI accelerating card that offers excellent performance in object classification. It also supports the mainstream Caffe and TensorFlow AI development frameworks, so no additional learning time is required. In order to support additional computational off-loading of real-time applications, Foxconn will be pre-installing the Network Optix’s Witness VMS to the BOXiedge server for better optimization. Additionally, it provides immediate support for a broad range of IP cameras on the market. “Socionext has been a reliable and trusted technology partner in ASSP for many years and share the same vision with us at Foxconn of innovating the next-generation AI solutions,” said Gene Liu, VP of Foxconn Technology Group, “We are pleased to partner with Socionext again to integrate the ‘Nx Witness VMS’ into Foxconn’s BOXiedge in or der to deliver even greater value to HWSW integrated ARM solutions, bringing a more powerful and cost-effective solution to the retail and manufacturing industry.” BOXiedge Plus Nx Witness VMS The new edge computing system developed with Network Optix combines the ultra-fast processing capabilities of arm-based CPU with Network Optix’s Nx Witness VMS that integrates seamlessly with other products ‘Powered-by-Nx’ built on the Nx Meta video development platform for analyzing and enriching video data. It enables multiple video input processing in real-time and provides a powerful and intuitive user interface to view and manage multiple incoming IP video streams. The lightweight VMS can run on most hardware and leading server platforms. This compact and efficient Edge AI server is ideal for real-time edge inference applications such as being able to recognize and filter video input using metadata to identify objects, people, commodities, human faces and even pathways. Potential applications include smart retail, smart manufacturing, surveillance, medical AI, and more. “Socionext is taking a unique approach to solving the challenges of creating lightweight but powerful AI-enabled hardware with their advanced SoC solutions. The collaboration between Nx, Socionext and Foxconn strengthens the ability of all companies involved to bring to market exceptional intelligent video hardware that can be used for a variety of applications – from cloudbased IoT solutions to on-premise edge processing” said Tony Luce, Director of Marketing & Business Development, Network Optix. “Socionext, as a provider of SoCbased solutions, looks to create a solid synergy by working with leading hightech companies such as Foxconn and Network Optix,” said Kotaro Goto, Vice Head of the Automotive & Industrial Business Group at Socionext, “Moving business processes to the edge with simple and scalable hardware solutions offer service providers the ability to streamline workflow and support a wide range of business needs, resulting in faster response times and data transfer speed.”  

Read More

MOBOTIX Receives ‘Secure by Default’ Certification

MOBOTIX has been awarded ‘Secure by Default’ certification in the UK. The certification for the new MOBOTIX 7 platform includes the new IP video system M73, launched at the MOBOTIX Global Partner Conference in October 2019, as well as the Mx6 product line. This highlights MOBOTIX’ ongoing focus on cyber security and privacy protection. MOBOTIX has been approved based on the 12 guiding principles of the surveillance camera commissioner. The company is now globally enabled to use the official ‘Secure by Default’ logo. Proactive approach to cyber security Self-certification allows manufacturers of surveillance camera devices and components to clearly demonstrate that their products meet requirements that ensure they are secure by default. The requirements are an important step forward in providing the best possible assurance for stakeholders that products aren’t vulnerable to cyberattacks. “Many congratulations to MOBOTIX AG in self-certifying their products as Secure by Default,” highlighted Tony Porter, Surveillance Camera Commissioner, “The certification mark demonstrates to customers and stakeholders alike that the products listed on my website meet the new minimum requirements I expect in terms of cyber-secure surveillance camera products. It’s great that we have a number of proactive manufacturers like MOBOTIX AG leading the way toward a common goal to develop products which are to mitigate potential cyber-threats.” Secure by Default Several high profile and well publicised compromises of systems were left in an unacceptable security configuration. Some of these compromises also showed the root cause of cyberattacks was down to poor design and manufacturing. Driven by the need to ensure the UK’s resilience against this and other forms of cyber security vulnerability, as well as to provide the best possible assurance to stakeholders, the requirements are an important step forward for manufacturers, installers and users alike. Secure by Default highlights the conformity to the 12 guiding principles as part of the surveillance camera Code of Practice as well as the development and use of surveillance camera systems, of which MOBOTIX applies conform. Phillip Antoniou, Vice President Sales Europe South/ West & MEAPAC of MOBOTIX underlined “We’re very proud to achieve the ‘Secure by Default’ certification, this demonstrates the commitment that we as MOBOTIX have towards cyber security. We recognise the existing and increasing concerns and as such will be further developing our solutions and strategy to address this.” MOBOTIX continues cyber security focus Recently, MOBOTIX has launched a free of charge Cactus Patch with latest firmware updates. With this continuous support, a stable and secure video system is sustained.  

Read More

Facial Recognition Hardware to Feature on Over 800M Mobiles by 2024, but Software Will Win Out

A new report from Juniper Research found that facial recognition hardware such as Face ID on recent iPhones, will be the fastest growing form of smartphone biometric hardware. This means it will reach over 800 million in 2024, compared to an estimated 96 million in 2019. The new research, Mobile Payment Authentication – Biometrics, Regulation & Forecasts 2019-2024, however, notes that the majority of smartphone facial recognition will be software-based, with over 1.3 billion devices having that capability by 2024. This is made possible by advances in AI, with companies like iProov and Mastercard offering facial recognition authentication that is strong enough to be used for payment and other highend authentication tasks. Juniper Research recommends that all vendors embrace AI to drive further developments of capabilities and therefore increase customer acquisition. Fingerprints to lead remote commerce authentication The research also found that despite the ubiquitous nature of selfie cameras, fingerprint hardware will remain a dominant element in biometric payments, as sensors expand to emerging markets. Juniper Research anticipates over 4.6 billion smartphones worldwide will have fingerprint sensors installed by 2024, although their usage for payment will be significantly lower than this. This expansion of biometric capabilities will bring the technology to more e-commerce platforms, as retailers seek to meet enhanced security requirements. Originally envisioned for contactless payment use, the report expects over 60% of biometrically authenticated payments in 2024 will be for authorising remote payments. As the longest running biometric modality, fingerprint payments will take the lead in this market as standards coalesce around the technology more easily than for facial recognition payments. “Many consumers are now used to making fingerprint-based biometric payments, both for contactless and remote payments,” remarked Research Author James Moar, “That familiarity and continued inclusion in smartphones will make it hard to displace in many markets.”  

Read More

Thales Leverages New Technologies to Boost Biometric Matching Performance Whilst Halving Environmental Impact

Thales applies innovative Field-Programmable Gate Array (FPGA) technology, designed for massive parallel data processing, to power its biometric matching system. With Gemalto’s commercial off-the-shelf FPGA solution, Thales allows the number of servers to be cut in half and dramatically limits the overall carbon footprint. Border agencies introducing entry/ exit systems, and other government agencies requiring real-time response can now benefit from low latency biometric data processing and greater scalability, while saving costs. Thalesis using innovative assets from the aerospace industry to boost its Biometric Matching System (BMS) performance while reducing the environmental impact. The BMS is the heart of government digital identification systems. Introducing interoperability with its border management system requires multiple processing of hundreds of millions of biometric database records within 1 to 2 seconds. To perform data comparison at this scale Gemalto, a Thales company, is applying commercial off the-shelf Field-Programmable Gate Array (FPGA) technology, originally designed for ultra-low latency applications in high performance computing (HPC) environments in financial and scientific industry, which is compatible with any server and cloud. “Our FPGA based solution can cut data centre investment and space overall by more than a half, whilst reducing CO2 emissions by around 50%. Gemalto technology brings new options for governments wishing to prioritise environmental sustainability, without in any way impacting national security. The alternative of a pure central processing unit based approach for biometric data matching requires massive computing capacity – even, in some cases, up to four times more servers than Gemalto’s approach – to perform the same transaction” – Youzec Kurp SVP Identity & Biometric Solutions, Thales Specifically, Gemalto uses these FPGA boards for matching hundreds of millions of biometric fingerprint templates which are digital signatures, created from fingerprint images. This proven solution also allows for much Leverages New Technologies to Boost Biometric Matching Performance Whilst Halving Environmental Impact faster data processing and greater matching accuracy, while at the same time limiting infrastructure costs and cutting carbon emissions. Depending on server and system specification, it can require up to 75% less servers and energy overall. Gemalto’s automated fingerprint identification system (AFIS) and automated biometric identification system (ABIS) are scalable and customizable solutions, providing a range of functionalities for processing, editing, searching, retrieving, and storing fingerprint, palm print, face and iris images and biographic subject records. With FPGA, ABIS makes it easier for government agencies to run very large and complex multi-biometric solutions with remarkable matching accuracy and speed, enabling states to better protect and serve their citizens.

Read More

Upstream & Fujitsu Security Partner for Vehicle Security

Fujitsu Limited and Upstream Security Ltd., cutting-edge security solution provider for connected vehicles, recently announced a partnership for vehicle cybersecurity. The companies will collaborate in the development of security operations solutions for connected vehicles. As more vehicles are connected to the network, they are increasingly prone to the growing risk of cyber-attacks. International and domestic committees such as UNECE/ WP.29 have already started discussing regulation and standardization of cybersecurity for connected vehicles. Car manufacturers and fleet operators need to address and protect against vehicle data loss and unlawful vehicle application control while developing solutions for security operations. Upstream C4 is a cloud-based automotive cybersecurity solution that leverages auto threat intelligence, the industry’s first automotive threat feed. Driven by data, the solution protects connected vehicles and smart mobility services against cybersecurity threats. By integrating such a solution with Fujitsu’s ICT-SOC (ICT-Security Operation Center) solution and big data processing technology, the two companies will develop a comprehensive connected vehicle security solution that can detect the threats not only in vehicle side but also in the center side. The solution will be gradually rolled out during 2020 for car manufacturers and other mobility companies in Japan, North America and Europe. “Fujitsu will strengthen partnership with Upstream to realize safety and security for the mobility business,” said Junichi Azuma, Corporate Executive Officer, and EVP, Head of Private Enterprise Business in the Technology Solutions Business at Fujitsu Limited, “Fujitsu has positioned cybersecurity as one of the focus areas which bolster our customer’s digital transformation. Together with Upstream, we will contribute to the realization of a trusted mobility society in which everyone can rest assured by leveraging our security technologies and experience in the ICT field.” “The partnership with Fujitsu is strategic for Upstream to increase our footprint in the Japanese market,” said Yoav Levy, CEO and Co-Founder of Upstream Security, “Our mission is to protect every connected vehicle on the planet by detecting security incidents and remediate them before they become a real threat to the safety and security of drivers and passengers alike.”  

Read More

Onvif Hosts 21st Developers’ Plugfest in Rome

ONVIF®, the leading global standardization initiative for IP-based physical security products, hosted its 21st Developers’ Plugfest late last year in Rome, an event that highlighted the continued demand for interoperable solutions. More than 30 developers and engineers from 18 ONVIF member companies gathered for this multi-day event, which featured 164 hours of testing. Attendees tested their implementations of ONVIF profiles along with other ONVIF profile-conformant products. Developers could also test products independently for profile conformance, as well as assess interoperability between their devices and those from other manufacturers. “The collaboration and exchange of ideas necessary for interoperability does not happen in a vacuum and as such, these events provide valuable face to face time for our members,” said Per Björkdahl, Chair of the ONVIF Steering Committee, “We are grateful for the continued support from our member companies and developers to help us continue to maintain profiles.” Profiles tested at this event included Profile S for basic video streaming, Profile T for advanced video streaming, Profile G for edge storage and retrieval and Profile Q for quick installation. Additionally, developers were able to perform testing of the Media2 service methods for media configuration and streaming and conformance testing for discovery. ONVIF Developers’ Plugfests are held twice a year around the world, allowing the global membership of ONVIF to gather and test their implementations.  

Read More

Advances in Key and Equipment Management unlocked by Maxxess eFusion Integration with Traka

Powerful tools for managing keys and high value assets can now be used seamlessly within centralized management platforms, following the integration of Maxxess eFusion with Traka from ASSA ABLOY Global Solutions. “There are huge benefits to be gained from integrating Traka’s capability with wider functions and operations in- cluding building management systems, security, fire and the many application-specific systems used by our customers in different sectors.” Allowing organizations to operate with unprecedented efficiency, eFusion with Traka now makes it simple for au- thorized staff to gain access to a wide range of controlled assets, from keys and premises to high value equipment, vehicles and machinery. The new integration enables full traceability and audit reports that can include video and audio recordings as well as transactional data from systems such as access control, intruder and fire. “With Traka solutions globally deployed in many market sectors such as critical infrastructure, retail, logistics, hospitality and corporate environments – and increasingly integrated with access control systems – the new integration with eFusion opens the way for more powerful integrated opportunities to be developed.” -Lee Copland  Managing Director, Maxxess EMEA As with all Traka solutions, audit capability across key cabinets and lockers enables instant traceability and report- ing. Some of the more widely used important features include fault logging, curfews and multiple authorizations that provide tangible returns on investment by improving operational efficiency, increasing productivity and minimizing costly downtime. With this latest integration between eFusion and Traka, users can manage all their keys and high-value equipment from their centralized security management platform, reducing the risk of security breaches and streamlining their day- to-day operations. “The power of this integration brings together Traka’s intelligent key and equipment management systems and eFusion’s flexible cloud architecture,developing a solution that will deliver exciting advances in security and opera- tional efficiency. Our new integrated capability will not only benefit major new build projects, but also open significant potential for existing users of eFusion and Traka technol- ogy. We look forward to building on this exciting partner- ship with Maxxess which we jointly believe continues to deliver tangible benefits to our valued customers.” -Martin Woodhouse  Head of Traka APACMEA The integration with Traka is just the latest example of how the eFusion platform gives users the freedom to inte- grate, customize and adapt their security systems to meet both current needs and emerging risks. eFusion’s open technology software supports more than 60 off-the-shelf integrations from leading vendors, providing complete freedom to customize solutions combining surveillance, access control, fire and intruder systems with back-office processes.  

Read More

Securiton Celebrates 50th Birthday of Aspirating Smoke Detectors

Securiton’s famous aspirating smoke detectors are celebrating a major birthday – the brand’s iconic product is turning 50 in 2020. Since the first ASD product launch in 1970, decades of research and development knowledge and the experience gained from thousands of installed systems led to this impressive success story. Aspirating smoke detectors from Securiton are among the most precise and reliable early warning systems against fires. Developed in Switzerland and manufactured in Germany, they meet the highest quality standards and set the benchmark for the entire industry. Customers from around the world rely on the cutting-edge technology offered by Securiton. The ASD aspirating smoke detectors respond instantly and with unique levels of precision to the presence of smoke in a wide variety of environments including IT racks, warehouses, manufacturing facilities and cold stores. All the models are equipped with state-of-the-art high dynamic smoke sensors with highest sensitivity. To extend the service life of the smoke sensors, airflow sensors and fans in applications subject to dust or dirt, a DFU 911 dust filter can be installed in the sampling pipe tube network. This significantly results in enhanced resistance to false alarms. The right device for any application The SecuriSmoke ASD 535 aspirating smoke detector is capable of monitoring areas up to 5,760 square metres in size. His sibling, the ASD 533 is a scaleddown version of the ASD 535 with restricted system limits. The compact and highly sensitive SecuriSmoke ASD 531 and ASD 532 aspirating smoke detectors offer superb, cost-effective fire protection for small and medium-sized environments. Due to the wide range of accessories, the devices can be used in almost every environment. In 2020 Securiton is launching the ASD 535 HD (Heavy Duty) model, which is specifically developed for applications in industrial and harsh environments. Networking and visualisation FidesNet makes it possible to connect multiple SecuriSmoke aspirating smoke detectors in a network. It is typically used wherever remote visualisation and operation are required. The NetSoft software tool visualises live data from the aspirating smoke detectors directly on the computer. From one central point, one has a complete overview of the entire ASD network – all aspirating smoke detectors deployed in the system are visualised on a building plan including their current states. The devices can also be configured directly from the graphical interface.                                                                          

Read More