Dedicated Micros' Closed IPTV solution is a key focus for the company at IP Expo
Dedicated Micros' Closed IPTV solution is a key focus for the company at IP Expo
Mike Newton, founder of CCTV specialist Dedicated Micros - part of AD Group - takes a closer look at the company's award-winning Closed IPTV solution which is a key focus for Dedicated Micros at IP EXPO, the UK's largest end-to-end IT infrastructure event, being held from 20-21 October at Earls Court 2 in London.

In essence Closed IPTV, which I was instrumental in creating, has been brought to market to deliver all of the simplicity and security of a traditional CCTV installation to the IP environment. From a security perspective the fact that, with Closed IPTV, each connected IP camera is locked down within a private network and, crucially, that trusted IP end points can be created, closes the door to those looking to use this as a route to hack into the corporate network. Also, from a practical perspective, there is no longer the frustration of having to manually assign individual IP addresses where mistakes can unwittingly introduce vulnerabilities.

Looking in more detail at how our patent-pending, Closed IPTV, is configured in practice, it uses a completely deterministic set-up which automatically maps each, standard or HD resolution, IP camera to a specific port on Dedicated Micros' Layer 3 Enhanced CCTV Switch and, in turn, to the corresponding camera input number on a hybrid DVR/NVR (Digital Video Recorder/Network Video Recorder). This approach, combined with DM's unique implementation of secure modes means that, when it comes to IP video, complete security of the IP endpoints can be achieved by users with a single click so preventing potentially damaging hacking attacks.

At Dedicated Micros we are currently rolling out Closed IPTV in a number of product lines with one of the first being a version of the hybrid SD Advanced DVR/NVR which is on display at IP EXPO.

Closed IPTV offers ease of installation and key benefits to far more than the user or installer who may be afraid of ‘setting a few IP addresses'

Turning to some typical questions regarding Closed IPTV:

Q1 - Does Dedicated Micros' Closed IPTV technology only have a short term appeal to those afraid of IP Video?

Dedicated Micros believes this is not the case. Closed IPTV offers ease of installation and key benefits to far more than the user or installer who may be afraid of ‘setting a few IP addresses'. While simple segregated IPTV solutions have been implemented, they are often open to attack compromising the video being delivered, and many of the benefits are lost from the segregation as soon as access is shared with the general network.

The Closed IPTV solution we are bringing to market is far more than just a simple discovery scheme as proposed by others in the marketplace which offer little more than a custom DHCP (Dynamic Host Configuration) server, which updates system parameters when the IP address is dynamically re-allocated, and no other system protection. In particular, Closed IPTV addresses segregation of the IP system while still allowing access as required direct to the cameras, for Multicast as an example.

If IP Camera systems are going to offer genuine benefits over IP Video enabled analog solutions this will only be achieved if the IP connectivity of the cameras themselves can be leveraged to improve Return On Investment (ROI) otherwise the IP technology is just an alternative, and more complex, transport medium. It is short sighted for people to claim a limited appeal for Closed IPTV until the full sophistication and advantages are fully understood.

Q2 - Does Closed IPTV lock you in to proprietary protocols?

No, Closed IPTV provides increased ease of installation and security depending on the equipment used. The Layer 3 Enhanced CCTV Switch functionality, combined with the Dedicated Micros' NVR provides basic deterministic solutions which operate with any IP products, and in the majority of cases will give enhanced security capabilities at either VLAN (Virtual Local Area Network) or MAC (Media Access Control) access control list level, with little user intervention.

Closed IPTV provides increased ease of installation and security

However when used with Dedicated Micros' products significant extra advantages are enabled, with fully automated IP discovery and allocation with transparent default  configurations and setup options. Further enhancements such as ‘Trusted Endpoint' technology are only realised with Dedicated Micros' products.

Q3 - Are the security techniques of Closed IPTV proprietary, and hence unfamiliar or unwelcome to many users?

The proprietary systems utilised are firstly targeted at the physical layer, through the Layer 3 Enhanced CCTV Switch employed. This removes much of the burden of achieving in a single user operation, MAC ACL and VLAN restrictions which would otherwise have to be implemented by a specialist installer with significant additional effort.

The IP scheme is unique in that it allows a general Private Network Address range, as operated in the client's existing installation, to potentially operate concurrently with an auto configured address scheme. Once configured, it is the user's choice to rely upon the DHCP/Static generated addresses, or the automatic configuration addresses, or in fact both. This is implemented using dual MAC / VLAN techniques, transparently supported by the Layer 3 Enhanced CCTV Switch.

The further implementations of ‘Trusted Endpoint' in Closed IPTV are specifically designed to meet the unusual needs of CCTV, in that the key benefit of TCP/IP on the World Wide Web is specifically non-deterministic, and when secure connections are required, it is typical that the client is in an insecure location, and the server protected in a secure location.

For CCTV we specifically demand that the connection to the camera is unequivocal as a physical device, with deterministic knowledge of its location, and that the ‘servers', i.e. the cameras, are typically located outside the protected area, and the user is typically inside the protected area. This requires bespoke and focused solutions, rather than the general case of the World Wide Web.

Q4 - Is the Layer 3 Enhanced CCTV Switch used in Closed IPTV custom to Dedicated Micros and does it support PoE (Power over Ethernet)?

Yes, the switch is a custom device, heavily integrated into the NVR user interface to allow the specific and key goals to be achieved in the required environment for CCTV. It supports dual address ranges and VLANS, as well as the various additional security protocols. While the maximum benefit is achieved with NetVu Connected devices from Dedicated Micros, it will also provide basic benefits for any IP camera, to much the same level as can typically be achieved by a number of hours of custom configuration of an ‘off the shelf' layer 2 or 3 switch.

The further implementations of ‘Trusted Endpoint' in Closed IPTV are specifically designed to meet the unusual needs of CCTV

All the NetVu Connected parts are available in PoE (Power over Ethernet) versions, and the only unconfirmed date is the exact production scheduled build of the PoE versions of the Layer 3 Enhanced CCTV Switch. First production quantities of the non PoE version are now available, with full approval and availability of the PoE version anticipated before the end of the calendar year. All NetVu Connected PoE capable cameras will additionally be shipped with a passive PoE injector.

Q5 - With Closed IPTV does the proprietary nature of the discovery 'lock you in', and why not just spend a few days writing scripts to achieve the same thing?

Again the base layer of Closed IPTV utilizes zeroconf as one of the more universal discovery schemes, supported by many devices, and likely to be the most popular solution under PSIA and ONVIF. It is the further deterministic solution of Closed IPTV that easily delivers the security advantages as well, which it is likely that while such scripts may enhance discovery, they do little for enhancing security. The basis of all open standards is that the fundamental lower layers should be non-proprietary to achieve common ground and interoperability. It is however the enhancements at the higher layers that deliver the unique benefits and strengths of a solution, otherwise no one would be able to deliver an enhanced, bespoke solution. Closed IPTV completely fulfills those goals and delivers them with a few key strokes, rather than days or weeks of writing custom scripts, assuming this knowledge is held. 

Q6 - Is 'closing' IP cameras an inefficient approach to gain simplicity?

Most certainly not. It is important not to confuse ‘Closed IPTV' with restrictive proprietary protocols. The usage of Closed IPTV is highly efficient, as with little installer overhead the following is achieved:

  • Deterministic allocation and configuration, combined or independent of the client's wider DHCP or other addressing scheme.
  • VLAN level security protocols without the user even having to be aware that multiple and sophisticated VLANS have been implemented.
  • MAC level security ACL's, again without the user even being aware of the MAC addresses of the devices used.
  • Endpoint to Endpoint segregation, blocking access of any other IP camera from an unprotected endpoint.
  • Full monitoring and protection against 'Man in the Middle' attacks, such as ARP (Address Resolution Protocol) storms, without any user configuration and intervention.
  • Interoperability with other IP vendors, to the extent of the capabilities of that camera.
  • "Trusted Endpoint" technology ensuring in an absolutely deterministic manner that the device connected physically to the port, and configured as a device to a specific channel is the device unaltered with no intermediate device.
  • Both secure signature and optional encryption of the streams to a unique key generated when the system solution is secured, to both protect data from eavesdropping or interception and ensure that the validity and integrity of the data received can be assured.

This is all achieved by utilising the Layer 3 Enhanced CCTV Switch, and selecting two or three options with the ‘Closed IPTV - Lock Down' menu. This is certainly not inefficient, and achieves much improved secure scenarios than many alternative environments.

Download PDF version Download PDF version

In case you missed it

Access The Right Areas - Making A Smart Home Genius With Biometrics
Access The Right Areas - Making A Smart Home Genius With Biometrics

Household adoption of smart home systems currently sits at 12.1% and is set to grow to 21.4% by 2025, expanding the market from US$ 78.3 billion to US$ 135 billion, in the same period. Although closely linked to the growth of connectivity technologies, including 5G, tech-savvy consumers are also recognizing the benefits of next-generation security systems, to protect and secure their domestic lives. Biometric technologies are already commonplace in our smartphones, PCs and payment cards, enhancing security without compromising convenience. Consequently, manufacturers and developers are taking note of biometric solutions, as a way of leveling-up their smart home solutions. Biometrics offer enhanced security As with any home, security starts at the front door and the first opportunity for biometrics to make a smart home genius lies within the smart lock. Why? Relying on inconvenient unsecure PINs and codes takes the ‘smart’ out of smart locks. As the number of connected systems in our homes increase, we cannot expect consumers to create, remember and use an ever-expanding list of unique passwords and PINs. Indeed, 60% of consumers feel they have too many to remember and the number can be as high as 85 for all personal and private accounts. Biometric solutions strengthen home access control Biometric solutions have a real opportunity to strengthen the security and convenience of home access control Doing this risks consumers becoming apathetic with security, as 41% of consumers admit to re-using the same password or introducing simple minor variations, increasing the risk of hacks and breaches from weak or stolen passwords. Furthermore, continually updating and refreshing passwords, and PINs is unappealing and inconvenient. Consequently, biometric solutions have a real opportunity to strengthen the security and convenience of home access control. Positives of on-device biometric storage Biometric authentication, such as fingerprint recognition uses personally identifiable information, which is stored securely on-device. By using on-device biometric storage, manufacturers are supporting the 38% of consumers, who are worried about privacy and biometrics, and potentially winning over the 17% of people, who don’t use smart home devices for this very reason. Compared to conventional security, such as passwords, PINs or even keys, which can be spoofed, stolen, forgotten or lost, biometrics is difficult to hack and near impossible to spoof. Consequently, homes secured with biometric smart locks are made safer in a significantly more seamless and convenient way for the user. Biometric smart locks Physical access in our domestic lives doesn’t end at the front door with smart locks. Biometrics has endless opportunities to ease our daily lives, replacing passwords and PINs in all devices. Biometric smart locks provide personalized access control to sensitive and hazardous areas, such as medicine cabinets, kitchen drawers, safes, kitchen appliances and bike locks. They offer effective security with a touch or glance. Multi-tenanted sites, such as apartment blocks and student halls, can also become smarter and more secure. With hundreds of people occupying the same building, maintaining high levels of security is the responsibility for every individual occupant. Biometric smart locks limit entry to authorized tenants and eliminate the impact of lost or stolen keys, and passcodes. Furthermore, there’s no need for costly lock replacements and when people leave the building permanently, their data is easily removed from the device. Authorized building access Like biometric smart locks in general, the benefits extend beyond the front door Like biometric smart locks in general, the benefits extend beyond the front door, but also throughout the entire building, such as washing rooms, mail rooms, bike rooms and community spaces, such as gyms. Different people might have different levels of access to these areas, depending on their contracts, creating an access control headache. But, by having biometric smart locks, security teams can ensure that only authorized people have access to the right combination of rooms and areas. Convenience of biometric access cards Additionally, if building owners have options, the biometric sensors can be integrated into the doors themselves, thereby allowing users to touch the sensor, to unlock the door and enter. Furthermore, the latest technology allows biometric access cards to be used. This embeds the sensor into a contactless keycard, allowing the user to place their thumb on the sensor and tap the card to unlock the door. This may be preferable in circumstances where contactless keycards are already in use and can be upgraded. Smarter and seamless security In tandem with the growth of the smart home ecosystem, biometrics has real potential to enhance our daily lives, by delivering smarter, seamless and more convenient security. Significant innovation has made biometrics access control faster, more accurate and secure. Furthermore, today’s sensors are durable and energy efficient. With the capacity for over 10 million touches and ultra-low power consumption, smart home system developers no longer have to worry about added power demands. As consumers continue to invest in their homes and explore new ways to secure and access them, biometrics offers a golden opportunity for market players, to differentiate and make smart homes even smarter.

Quantum Focuses On Unstructured Data, Embraces Pivot3 Acquisition
Quantum Focuses On Unstructured Data, Embraces Pivot3 Acquisition

Video is an enormous wellspring of unstructured data in the enterprise environment. Finding new ways to use video data requires easy access for analysis. Gone are the days when video was recorded just to be played back later. New computer capabilities can analyze video to provide business intelligence and trends, all of which requires that a lot of unstructured data be captured, stored and kept immediately accessible. It's a driving force for companies specializing in video storage such as Quantum, which is focused on storing and managing unstructured data, including video, photos, music and sound. Managing various analytics “Unstructured data is driving the massive growth in storage today, and video surveillance fits right in there,” says Jamie Lerner, CEO and President, Quantum. As data multiplies in business, matters of storing and accessing the data take on a larger profile. Especially challenging is meeting the need to store and access expanding amounts of unstructured data, such as video. Video is also part of a changing end-to-end architecture in the enterpriseWhereas 10 years ago, video surveillance was all about recording and playback, now the emphasis is much more on an end-to-end approach. In addition to capturing and playing back video, systems have to manage various analytics, archival and data retention aspects as well as recording. Video is also part of a changing end-to-end architecture in the enterprise, including hybrid, cloud and on-premise storage. Video surveillance industry Historically, structured data, such as financial information, was stored to allow future analytics. The same trend extends to unstructured data, such as video analytics. Quantum has expanded its video storage capabilities with acquisition this year of the video surveillance business of Pivot3, provider of a hyperconverged system that provides recording, analysis and seamlessly archives data on a converged platform that is less expensive and easier to manage. In acquiring Pivot3, Quantum is refocusing the smaller company on the video surveillance industry. “We are now focused 100% on surveillance and having the highest quality while being very cost-effective,” says Lerner. “The industry is ready for an IT-forward solution that is totally focused on surveillance. You can’t make a platform all things to all people.” Traditional security customers There is overlap in large stadiums and theme parks, where Lerner sees even more opportunity to expand Pivot3 will also help to expand Quantum’s customer base. The larger company has a history of serving customers in entertainment, movies, television and sports production. The addition of Pivot3’s 500 new customers in large surveillance, transportation and critical infrastructure markets will expand the mix. There is overlap in large stadiums and theme parks, where Lerner sees even more opportunity to expand. Pivot3 also helps to bridge the gap between traditional security customers and the information technology (IT) department. “Pivot3 has a reputation as simple to use,” says Lerner. “My belief is that physical security can run separately [from IT] until you reach a certain size, then IT has to be involved. Pivot3 gives IT people in the security space a product that is well formed and fits into an IT strategy. They are not undertaking a piece of equipment that will be a burden.” Physical security presence Customers expect their infrastructure vendors to provide systems that allow them to “Set it and forget it,” says Lerner. It’s one of the big advantages of cloud computing and also central to Quantum’s approach with their traditional products. “At the end of the day, you want to run a hospital, for example, so you want your systems to be easy to use,” says Lerner. The Pivot3 acquisition will also allow Quantum to expand their physical security presence more broadly and globally. Previously, the geographic reach of Pivot3 was limited by the high cost of placing personnel in diverse locations. Under Quantum, which has been serving global companies for 40 years, the problem disappears. “Quantum has global support on all continents and in more countries,” says Lerner. “It’s a higher level of support, given size and legacy of our organization.”

Data Explosion: Futureproofing Your Video Surveillance Infrastructure
Data Explosion: Futureproofing Your Video Surveillance Infrastructure

Video surveillance systems are producing more unstructured data than ever before. A dramatic decrease in camera costs in recent years has led many businesses to invest in comprehensive surveillance coverage, with more cameras generating more data. Plus, advances in technology mean that the newest (8K) cameras are generating approximately 800% more data than their predecessors (standard definition). Traditional entry-level solutions like network video recorders (NVRs) simply aren’t built to handle massive amounts of data in an efficient, resilient and cost-effective manner. This has left many security pioneers grappling with a data storage conundrum. Should they continue adding more NVR boxes? Or is there another, better, route? Retaining video data In short, yes. To future proof their video surveillance infrastructure, an increasing number of businesses are adopting an end-to-end surveillance architecture with well-integrated, purpose-built platforms for handling video data through its lifecycle. This presents significant advantages in terms of security, compliance and scalability, as well as unlocking new possibilities for data enrichment. All of this with a lower total cost of ownership than traditional solutions. Security teams would typically delete recorded surveillance footage after a few days or weeks Previously, security teams would typically delete recorded surveillance footage after a few days or weeks. However, thanks to increasingly stringent legal and compliance demands, many are now required to retain video data for months or even years. There’s no doubt that this can potentially benefit investigations and increase prosecutions, but it also puts significant pressure on businesses’ storage infrastructure. Data lifecycle management This necessitates a more intelligent approach to data lifecycle management. Rather than simply storing video data in a single location until it’s wiped, an end-to-end video surveillance solution can intelligently migrate data to different storage platforms and media as it ages. So, how does this work? Video is recorded and analyzed on a combination of NVR, hyperconverged infrastructure (HCI) and application servers. Then, it’s moved to resilient file storage for a pre-determined period, where it can be immediately retrieved and accessed for review. Finally, based on policies set by heads of security, data is moved from file storage to highly secure, low-cost archive storage such as an object, tape or cloud. Data is moved from file storage to highly secure, low-cost archive storage Long-Term storage This process is known as tiering. It allows businesses to use reliable, inexpensive long-term storage for most of their data, whilst still enabling security pioneers to retrieve video data when the need arises, such as during a compliance audit, or to review footage following a security breach. In a nutshell, it offers them the best of both worlds. Scaling your video surveillance infrastructure can be a headache. Businesses that rely on NVRs – even high-end units with 64 or even 96 hard drives – are finding themselves running out of capacity increasingly quickly. In order to scale, security pioneers then have to procure new boxes. With NVRs, this inevitably involves a degree of guesswork. Should they go for the largest possible option, and risk over provisioning? Or perhaps a smaller option, and risk running out of capacity again? Common management console Security pioneers can easily add or remove storage capacity or compute resources – separately or together As businesses add new cameras or replace existing ones, many end up with inadequate surveillance infrastructure made up of multiple NVR boxes along with several application servers for running other surveillance functions such as access control, security photo databases, analytics, etc. This patchwork approach leaves security pioneers scrambling for capacity, maintaining various hardware footprints, repeating updates and checks across multiple systems, and taking up valuable time that could be better spent elsewhere. By contrast, flexible HCI surveillance platforms aggregate the storage and ecosystem applications to run on the same infrastructure and combine viewing under a common management console, avoiding ‘swivel chair’ management workflows. Plus, they offer seamless scalability. Security pioneers can easily add or remove storage capacity or compute resources – separately or together. Data storage solutions Over time, this ensures a lower total cost of ownership. First and foremost, it removes the risk of over provisioning and helps to control hardware sprawl. This in turn leads to hardware maintenance savings and lower power use. Many security pioneers are now looking beyond simple data storage solutions for their video surveillance footage. Meta tags can provide context around data, making it easier to find and access when needed Instead, they’re asking themselves how analyzing this data can enable their teams to work faster, more efficiently and productively. Implementing an end-to-end video surveillance architecture enables users to take advantage of AI and machine learning applications which can tag and enrich video surveillance data. These have several key benefits. Firstly, meta tags can provide context around data, making it easier to find and access when needed. Object storage platform For instance, if security teams are notified of a suspicious red truck, they can quickly find data with this tag, rather than manually searching through hours of data, which can feel like looking for a needle in a haystack. Plus, meta tags can be used to mark data for future analysis. This means that as algorithms are run over time, policies can be set to automatically store data in the right location. For example, if a video is determined to contain cars driving in and out of your premises, it would be moved to long-term archiving such as an object storage platform for compliance purposes. If, on the other hand, it contained 24 hours of an empty parking lot, it could be wiped. These same meta tags may be used to eventually expire the compliance data in the archive after it is no longer needed based on policy. Video surveillance architecture Continuing to rely on traditional systems like NVRs will fast become unsustainable for businesses Even if your organization isn’t using machine learning or artificial intelligence-powered applications to enhance your data today, it probably will be one, three, or even five years down the line. Implementing a flexible end-to-end video surveillance solution prepares you for this possibility. With new advances in technology, the quantity of data captured by video surveillance systems will continue rising throughout the coming decade. As such, continuing to rely on traditional systems like NVRs will fast become unsustainable for businesses. Looking forward, when moving to an end-to-end video surveillance architecture, security pioneers should make sure to evaluate options from different vendors. For true futureproofing, it’s a good idea to opt for a flexible, modular solution, which allow different elements to be upgraded to more advanced technologies when they become available.