AXISC1410MkIINetworkMiniSpeaker
Learnmore
cryptographiccomputingmodules(secureelementandTPM)andSoCsecurity(TEEandsecureboot),combinedwithexpertisein
edgedevicesecurity.
Signedrmware
Signedrmwareisimplementedbythesoftwarevendorsigningthermwareimagewithaprivatekey.Whenarmwarehasthis
signatureattachedtoit,adevicewillvalidatethermwarebeforeacceptingtoinstallit.Ifthedevicedetectsthatthermware
integrityiscompromised,thermwareupgradewillberejected.
Secureboot
Securebootisabootprocessthatconsistsofanunbrokenchainofcryptographicallyvalidatedsoftware,startinginimmutable
memory(bootROM).Beingbasedontheuseofsignedrmware,securebootensuresthatadevicecanbootonlywithauthorized
rmware.
Securekeystore
Atamper-protectedenvironmentfortheprotectionofprivatekeysandsecureexecutionofcryptographicoperations.Itprevents
unauthorizedaccessandmaliciousextractionintheeventofasecuritybreach.Dependingonsecurityrequirements,anAxisdevice
canhaveeitheroneormultiplehardware-basedcryptographiccomputingmodules,whichprovideahardware-protectedsecure
keystore.Dependingonsecurityrequirements,anAxisdevicecanhaveeitheroneormultiplehardware-basedcryptographic
computingmodules,likeaTPM2.0(TrustedPlatformModule)orasecureelement,and/oraTEE(TrustedExecutionEnvironment),
whichprovideahardware-protectedsecurekeystore.Furthermore,selectedAxisproductsfeatureaFIPS140-2Level2-certied
securekeystore.
AxisdeviceID
Beingabletoverifytheoriginofthedeviceiskeytoestablishingtrustinthedeviceidentity.Duringproduction,deviceswith
AxisEdgeVaultareassignedaunique,factory-provisioned,andIEEE802.1AR-compliantAxisdeviceIDcerticate.Thisworks
likeapassporttoprovetheoriginofthedevice.ThedeviceIDissecurelyandpermanentlystoredinthesecurekeystoreasa
certicatesignedbyAxisrootcerticate.ThedeviceIDcanbeleveragedbythecustomer’sITinfrastructureforautomatedsecure
deviceonboardingandsecuredeviceidentication
Encryptedlesystem
Thesecurekeystorepreventsthemaliciousexltrationofinformationandpreventscongurationtamperingbyenforcingstrong
encryptionuponthelesystem.Thisensuresnodatastoredinthelesystemcanbeextractedortamperedwithwhenthedeviceis
notinuse,unauthenticatedaccesstothedeviceisachievedand/ortheAxisdeviceisstolen.Duringthesecurebootprocess,the
read-writelesystemisdecryptedandcanbemountedandusedbytheAxisdevice.
TolearnmoreaboutthecybersecurityfeaturesinAxisdevices,gotoaxis.com/learning/white-papersandsearchforcybersecurity.
Axissecuritynoticationservice
AxisprovidesanoticationservicewithinformationaboutvulnerabilityandothersecurityrelatedmattersforAxisdevices.Toreceive
notications,youcansubscribeataxis.com/security-notication-service.
Vulnerabilitymanagement
Tominimizecustomers'riskofexposure,Axis,asaCommonVulnerabilityandExposures(CVE)numberingauthority(CNA),follows
industrystandardstomanageandrespondtodiscoveredvulnerabilitiesinourdevices,software,andservices.Formoreinformation
aboutAxisvulnerabilitymanagementpolicy,howtoreportvulnerabilities,alreadydisclosedvulnerabilities,andcorresponding
securityadvisories,seeaxis.com/vulnerability-management.
SecureoperationofAxisdevices
Axisdeviceswithfactorydefaultsettingsarepre-conguredwithsecuredefaultprotectionmechanisms.Werecommendusingmore
securitycongurationwheninstallingthedevice.TondoutmoreaboutAxishardeningguidesandothercybersecurityrelated
documentation,gotoaxis.com/support/cybersecurity/resources.
41