Bosch/Genetec Video Cybersecurity Partnership Examined (CHAVE)

Author: Brian Karas, Published on Feb 15, 2017

Surveillance products have been relatively weak when it comes to cyber security. Default passwords, open ports, and weak authentication mechanisms led to a wave of exploits.

Now, Bosch and Genetec are working together to deliver a system that is "resilient against unauthorized access, malware, brute force cracking and other exploit techniques."

The two companies described the solution, which Bosch is marketing as CHAVE (Credentialed High Assurance Video Encryption), in a conversation with IPVM.

In this report we describe how CHAVE differs from other security mechanisms, what it adds in terms of costs, and how installation and day to day use vary from other systems.

************ ******** **** **** ********** **** **** ** ***** ** cyber ********. ******* *********, **** *****, *** **** ************** ********** led ** * **** ** ********.

***, ***** *** ******* *** ******* ******** ** ******* * system **** ** "********* ******* ************ ******, *******, ***** ***** ******** *** ***** exploit **********."

*** *** ********* ********* *** ********, ***** ***** ** ********* as ***** (************ **** ********* ***** **********), ** * ************ **** ****.

** **** ****** ** ******** *** ***** ******* **** ***** security **********, **** ** **** ** ***** ** *****, *** how ************ *** *** ** *** *** **** **** ***** systems.

[***************]

CHAVE ****** ********

***** ** ** ***-**-*** ******** *********** *** ***** *******. ** utilizes ******* **** ********** ******** / ******** *** ******** **** encryption, ***** **** ***-****** ******** ************ *** * *** **** can ********* **** *** ** ***** **********.

*** **** ** ***** ** ** ****** *** ********* ** video, **** *** ******* **** *** **** ***********, *** ** better ****** *** *** **** ****** ** **** *** ****** video. ***** ***** *.*. ************** ***-****** * ************, ***** ***** ****** ** ***** ************ ** able ** **.

*********, ***** ** ********* *****-******* *******, *** ******* ** ****** CHAVE ******* ** ** ******** ******** ****** *******.

User **************

***** ** * ***** ****** *** ****** ***** *****, **** commonly**********-****** ****-** *****, ***** **** **** ** ********** ****. ***** ** *** VMS ******** ********* ***** ***** **** ** * ****** ******** to *** ****** ** *** ******** * ***.

Target *********

*******/**********, ** ******* ********* **** **** ********** ** ********** ************ around ************* *** *** ****** ******. ** ** ******** **** even * ***** ********** *******-****** ******** ***** ********* ***** ******* outside ************.

CHAVE ********** ********

********* ** *****, *** ********** ********** ** ***** *** *** based ** *********-********* ********, **** ***.*** ****************** (********* ***** ********). ***** ** *****'* ********* **** *** ******* ***** ********* together **** ** ** ******, *** ************ *** ******** *** accessing *** *******.

******* ******* *** ******** ** **** ******** ******** ********** ** support *****, ** ** *** * ******* **** *** ** added ** ******** ******* *** ******** ******** ** ***** *******.

Username/Password ** ****

***** *************** ***** **************, ***** ********** ********/******** ****** ** *******, *** *** **** of ****** ** ******* *********. *** ****** ** ******** ** have ****** ** *** ********, ** **** *** ******* *** routinely ******* *** *********** ********* ** ****** *** ***** *** still *****. ********* ** *****, *** ******** ****** *********** ** not ** *****, **** *** ********-****** ********** *************, ** *** systems ********* ******* **** ******** ****** *** ****** ******/************** ********.

Supported *******

***** ***** *** ********* ******* ** ********* ********** *****:

  • ********* ** **** ** ***** **** ******
  • ********* ** ********* **** ** ***** **** ******
  • ****** ** ********* **** ** ***** *** ******
  • ********* ** **** ** ********* ******
  • ******** ** ******* **** ** ***
  • *** ** ********* **** ** ********** ***
  • ****** ** ****** **** ** ******

Genetec *******

******* **** **** *** ****** ** **** **** ******* *** CHAVE ** *** **** ******* ** ******** ******, ***** ****** be *.*.

********* ***** ******* ** ********* ** *******, ****** ******* ***** nor ******* ***** ******* *** **** *** ********* *********** ** intended ** ****.

Additional ******** *** ************ ************

******* **** ** **** *** ******** ************ ***-********* ****** ********, this **** ** ******* **************. *** *********** ******* ******* **** ******** ****-**** ********, ********* to *****, *** ****** *** *** **** **** * *** extra ****.

**** ********, ************* ************ **** ** ** ******** **** ******** Center ****** *** ******* *** ** ***** ** *** *** and **********. ***** ******** ** ****** *****, **** ** ******** bitrate ******** ** ******** ******** *** *** **** ** ***-***** cameras.

*******, *** ********** **** ******** ** ******* *** ********* *****-******* cameras ****** ** *******, *** **** ******* ***** ** ** through * ********/************* *******.

Training ************

***** **** **** *********** **** **** ** ******* ********** ******** before **** *** ********* ** **** *** ******* ***** ********. The ******** ** ******** ** ** ********* *****, *** **** likely ** * **** *** ******.

Cost ** *****

***** *** ********** ******* ***** ** ********* ***** ** * non-CHAVE ******. ***** *** ********* ******* ** *** **** ***** and ***-***** ********, ******* **** * ******** **** *** *** more *** ***** *******, *** ******* ***** *** * ***** camera *** ** ****** **** * *********** *******.

*** ******** ******** ************ **** $**-$***, ********* ** *** ***** level ** *** *********** ***** ******, *** **** **** ** be ******* ***** * *****.

******* **** **** **** *** ********* ******* *** ******** ****** with *****, *** *** *** ** ***** ****** ** * different ******* *******, **** ** ********** ****.

***** **** **** **** ** ** ****** ***** *****, *** have ****** *** ******** **** ***** **** *******. *******, ** is ****** **** ********* ************ ***** **** ******* ** ***** smart *****, ** **** **** *** *** ** ********, ** may **** ******* * *** *** ** **** ***** **** readers *****.

Compared ** ***** ******** *******

*****'* ******* *************** *** *** **** ***-* ***** * **********, and ***********-***** ****** **** *** *********** ** ********/******** *****. **** *** **** ******** ** *** ***** ** **** ************ claims *** **** **********, ***** ***** ** ******** ** ********* that **** ** **** ***** ************, ** ** ***** ********* the **** ** ****** ** *********** ******** *** *******/********. *********** the ******* ** ***** **** * ****/**** ***** ***** ** valuable ** ********-****** *********, **** ** **** *** *** **** to **** *** ******** ********** ************.

*******, * ***** ****** ***** ****** ** ************ **** ********* than *********** *******, **** ** ***** * *** *** ******* that ******* ***** ************** *** ***** *********, ** ** ******** specific ****** ********, ************ **** **** ** ** ****** ********* and **** ******* ***** * *****, **** ********** *****/************ ****.

Outlook *** *****

***** **** ** ****** ******** ** ********** ************, ** **** help *** * ********* *** **** *** ** **** **** a ************* *********** ** **** ******* **** **********. ****/** ***** VMSes ******* *****, ** *** ****** **** ** ***** ******** methods ** *******-**** ** ******** *******, ****** ****** **** ******* requirements (*.*., ** *********** *** ***** *****). *****, **** ** unlikely ** ****** ** ****, ****** ***** * ********** ***** concept **** **** ** *** ********** ******.

Comments (19)

**** ** * ********* *** ******** ******** **** ***** **** come ** ****. * ** *******.

****, * *** *** * ** **** ******* *** *** cost ** ****** **** *** *********** ** *****, ** *** may ***** **** **** ********** ;)

*****'* ******* *************** *** *** **** ***-* ***** * **********, and ***********-***** ****** **** *** *********** ** ********/******** *****. ** is *** **** ******** ** *** ***** ** **** ************ claims *** **** **********, ***** ***** ** ******** ** ********* that **** ** **** ***** ************, ** ** ***** ********* the **** ** ****** ** *********** ******** *** *******/********. *********** the ******* ** ***** **** * ****/**** ***** ***** ** valuable ** ********-****** *********, **** ** **** *** *** **** to **** *** ******** ********** ************

********* *** ********* ******* ** **** **** ***** **** *****-* or ********* ** *** *** ******* ******* ****** *** ***** with *** *** **-*****.

******* *** ***** ***** ** *** *** ******** ******** **** the **** ****** *** *** ***** *** * ***** ****** really *** **** *** ****** ** *** **** ************* ** my **** *** ****** ** *'** **** **** ******** **** i *** *****.

**** ***-* *** * ****** ** **********, * ***** *** most *****, * ***** *** **** ******.

********* ***** **** ***-* ***** * ** ***** ******* ****** release.** ******* **** **** ******* ** *** ***** ******* *******, *** ******* * ****.

*** ********* ******* **** **** ***** **** *** ***** ***** options, *** ***** ******* **** ******* *** * ***** ***, 5MP *** ******, *** **** *********.

**** ** *** **** **********, *'* **** ** *** *** camera ************* ******* ************ (***** ** ***** **** *** ***) when *** ****** ** ****** ***-** ******** ******* * ************ number. **** ***** ******* *** ****** ************* ********** ** *** often * ***** ** *** ***. ** ********** ** ****** to *** *******.

* ***** **** **** *********. * ********** **** *****, ******, and ********* **** ***** **** ******* ****, *** * ******* only ********* ****** ****** ** ** **** ** ****** **** to *** ****** (*** * ******* ****'* **** ********** **** iVMS, *** * *****'* *******). ******* *** ******* ** ****, but ******* ************, *** **** ****** **** ** ***** **.

**** ***** ** ********* ******* ** ****:

*** ****** ***** ** *** *** ************* ******* ****** ***** detection ** ***. ** ***** ***** ** *** ****** ******* tries ** ***** **** * ***** ********, *** ******* *** VMSes, ******** ** *********** ********, ** ***?

*'* **** ** *** *** ****** ************* ******* ************ (***** or ***** **** *** ***) **** *** ****** ** ****** log-in ******** ******* * ************ ******.

*******:****: **% ** ***** *** *** *** ************'* ************** *** **** **** *** ******* ****.

**** ********* *******, ****** **** *** ******* ******* ** **** lock ** ******* ***** ******* *** *** **** *** ***** you ** *** ****** ***** *******. ****** ** **** **** any ****** ***.

******* ** ******* ** * ********* ****** *****'* **** *** stream ***********, **** *** *** *********. * **** ****** **** with ***** *** *'** **** *** **** ** ***** *****. It ***** **** ********* ** *** ***, ******.

******, **** ** ** *** ******** **** **** *** ****** offline, **** ************ **** **** **** *** **'* *******. **** you're **** ************* *** **'* ******* **********. ******** ******* * discrete ***** ***** ** **********.

* ** ****** **** ****** ************* *** ******* ****... ** an *** **** *** ****** ********* ** * ********** ***** video ************ ****** - * **** ** ****** ********** ********* based **** *** ******'* *****-******** ********.. *** ***** ***** **** be ******* **** *** ****** ** ****** ** ***** ** SDK **** **** * *** **** ****** ***** ******** ***** as * ***** ************** ** **** ****** ************* *** ** a ****** *** **** ***, ******* ******* ***. * ***'* think * ** ***** ** ****....

*******, ***** *** ***** *****-******** ******** *** ***** ************? **-***** analytics, ****** ***********, ****** ***********, ******** ***?

*****, *** **, *** ******** **** *** ****** *** **** to ***** *** *** ******** ** *** ********* ******* ************. That ***** ****, * ** * *** *** ** *** Smart ****** *** ******** **** ******* *** ****** ********** ***.

** ** *******, **** * ********* ******* ********** - ****** features **** ******* ************ ** ****** ** *** ******** ** your ***** ************ ****** ** * ****** ******** (***** ****** which *** ******* *********** ***) .

******* **** *** ******** - * ** ******* *** * 4K **** **** ***** ** ** , ** ********* **** dynamic *****, **** *** ***** ***********, ******** * ***** ***** and ******** ***-** ******* ************ - ** * ****** *** too **** :) ??

* ***'* ***** *** *** ****** *** *** **** ** the ***** ** ******* * ******* ********** **** ** ***********. I ***** *** ********* *** ************* ** **** ** ** often * ****-*** **** **** *********** *********. ************ **** *****-******** features ***** ********* **** **** *** ** *******. ***** **** delay ** **** * *******, ***** ** ** * ****, hard ** ***.

* ***** **** ********* **** ** **** ** ***** *** cyber ******** ************ ***** ** **** ********* **** "****** *****" like ********* ** *****(**) ****** (******** ** ****** **** *** other ****** ******** *** ** *** **** ******** *********, * company **** ** *** *.*** ***** ***** ** ****** *** working ** **** *****).

* ***** **** **** *** *** ****** - *** ****** being ***** ** **** **** ******* ********* **** **** ****** security ********. ** **** ***** * **** **** ************ ***** add **** ***** **** *** ** *** ******** ******** ** using *********** ***** ************** ***.

"*** ****** ** ******** ** **** ****** ** *** ********, so **** *** ******* *** ********* ******* *** *********** ********* to ****** *** ***** *** ***** *****. ********* ** *****, the ******** ****** *********** ** *** ** *****, **** *** security-minded ********** *************, ** *** ******* ********* ******* **** ******** access *** ****** ******/************** ********."

**** ** ***** * ******* *******. ** ******* ** ** security ******* ****** ** **** ********* ** *** ********. ********** not *** ****** ************** ********.

******* ***** * **** **** **** ****** **** *** **** one **** *** * *****/******** ***** *** *** *** ***** to *** ******. ***** *** ** ****** ** ******, ** your ****** ** ********** *****.

** *** **** ** ******* ** *** ********, *** ***'* the **** *** ***** ********** *** **** *** ******** *********** reader, ****** ************* ****** *** ** ********* *** *** ** Android, * **** *** ****** **** **** *******.

** ** *** **** *** ** ******? ** *** ********* a ****** ** * ****** **** *** *** ***** ** touch ** **** **** ******* *****!

**** ********* *** ** *** ********* ** **.****** ** *** does *** ******* *** *****, ****** ***** ***** ****.

** *** ** **** * ****** *** *** * *********** cost **** ******* ******?

*. ****** *** * ********* ******, *** ******** ** **** is * ** **** *****. *********.

*. ******* ****** ***** ** ******, ******** ***** *** ** direct.

*. ****** ** ***** ***** ** **** ** **** ************* / ******** ********** ****.

*. ********* *** *** *********** ***** ***, ***** **** **** after * **** **** ***** * ******* **** *** ******, for **** ****** **** ** **** ************* ******** ** **** from ***** (******* ** **** **** * ****** ****** ** a ****** **********) ****** *** *** ****** *** ****** **** the ****** ** ** **** * **** ** *** *********** generation. (*** ***** ******** ***** ** **** *** ** *** the *****)

*. **** ******** *** ****** **** *** ****** ******** *************, close *** *********.

*. ***** *** *** *** * ****** ****** / ******* codes ******, **** **** *** ** ****** ** *** ********, this ***** ** ***** *****.

*. ****** ********* **'* *** ********, ** **** ******* *********** of *** *** ** ******** * ********.

*.****/**** *** ** *** **** ***** ** ****** ** ******** at ***** **** ***** **** **** **** *******.

*. ****: ** ************ ******** *** *** ** ****** ***** software ****, ** **** *** **** *** *********. ******** *** certificate *** **** ********* ** *** ******** ****, ** **** as **** ** ********.

*. **** *********** **** ******** ******** ** ** ********, *** allow ***** - ****** (*** ** ** ********) ** **** a *** ***-***** ** *** *********** ***** *** ****** ** added.

* ******** ******** *** ** ******** ** ***** *** ** we ***'* **** **** ********.

**. ************ ******* ***** **** ****** ** ****** ****, *** even ******* *** **** ********.

**. ****** **** **** *** ******* ** ************* **** *** generated ***********.

***** ** **** ** **** *** ******* *** *** ******** certificate **********, *** ******** ********** ********* ***. * ******'openssl **** -****** **' gives you a lovely password nobody would be able to guess.

**, * ***** ******* ** ** *** *** ******:

***** ** *** *** ******** ********* ***** ***** **** ** a ****** ******** ** *** ****** ** *** ******** * PIN.

******* ***** * **** **** **** ****** **** *** **** one **** *** * *****/******** ***** *** *** *** ***** to *** ******. ***** *** ** ****** ** ******, ** your ****** ** ********** *****.

** *** *****!

***** *** ******* **** **** *********** *******, ** ** *** have *** ***********, **** ***** *** ****** **** ******* ** well

=>*****://**.*************.***/**/********/********************/***************/****************/**********************

***** ** ** ************ ** ********** **** ***** ** ******* and ***** ** * ***** **** ******* ******* ********* ****** hardening. ** ** **** ******** ** ***** **** ************** ** been ******** ** ********* ***** ******* ** ** **** ********.

* **** ** ******* **** *** **** **** ** *** installers *** *********** ** ******* *** ******* ***** *** ************ to **** ********.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports on VMS

4MP Camera Shootout - Axis, Dahua, DW, Hanwha, Hikvision, Uniview, Vivotek on Sep 24, 2018
4MP usage continues to climb, especially for lowe cost fixed lens models. To see who was best, we bought and tested seven 4MP models from Axis,...
VMS Export Shootout - Avigilon, Dahua, Exacq, Genetec, Hikvision, Milestone on Sep 13, 2018
When crimes, accidents or problems occur, exporting video from one's video surveillance system is critical to proving incidents. But who does it...
Dahua Low-Cost 4MP Camera Tested (N44CL52) on Sep 10, 2018
4MP use continues to increase, especially in low-cost models, according to integrators in our 2018 Resolution Usage Statistics. We bought Dahua's...
Directory Of 110+ Video Management Software (VMS) Suppliers on Aug 30, 2018
This directory provides a list of Video Management Software providers to help you see and research what options are available. Listing...
Inputs/Outputs For Video Surveillance Guide on Aug 24, 2018
While many cameras have Input/Output (I/O) ports, few are actually used and most designers do not even consider them. However, a good understanding...
Luxriot VMS Profile on Aug 23, 2018
Luxriot is more popular than Hikvision and Milestone products according to ASMAG which was probably even surprising to Luxriot. The company has...
Synology Surveillance Station VMS Tested on Aug 22, 2018
With so many low-cost NVRs and enterprise VMSes, is there any place in the market for NAS-based VMSes? Recently, IPVM bought a Synology NAS for...
SNMP / Network Monitoring For Surveillance 2018 on Aug 21, 2018
Surveillance systems typically rely on the the VMS to report issues, but this most often just means knowing a camera is "down" with no warning or...
Video Analytics Integration Guide on Aug 16, 2018
Video analytics is hot again (at least conceptually) but integrating video analytics with VMSes can be challenging. This is especially significant...
ISS VMS / Video Analytics Company Profile on Aug 16, 2018
Who is ISS? In the past few months, they had one of the craziest ISC West promo items in years. Then, they hired industry veteran and ex-Dahua...

Most Recent Industry Reports

Genetec Takes Aim At 'Untrustworthy' 'Foreign Government-Owned Vendors' on Sep 24, 2018
Genetec is taking aim at 'untrustworthy' 'foreign government-owned vendors'. This is not a new theme for Genetec as nearly 2 years ago, Genetec...
4MP Camera Shootout - Axis, Dahua, DW, Hanwha, Hikvision, Uniview, Vivotek on Sep 24, 2018
4MP usage continues to climb, especially for low cost fixed lens models. To see who was best, we bought and tested seven 4MP models from Axis,...
Alexa Guard Expands Amazon's Security Offerings, Boosts ADT's Stock on Sep 21, 2018
Amazon is expanding their security offerings yet again, this time with Alexa Guard that delivers security audio analytics and a virtual "Fake...
UTC, Owner of Lenel, Acquires S2 on Sep 20, 2018
UTC now owns two of the biggest access control providers, one of integrator's most hated access control platforms, Lenel, and one of their...
BluePoint Aims To Bring Life-Safety Mind-Set To Police Pull Stations on Sep 20, 2018
Fire alarm pull stations are commonplace but police ones are not. A self-funded startup, BluePoint Alert Solutions is aiming to make police pull...
SIA Plays Dumb On OEMs And Hikua Ban on Sep 20, 2018
OEMs widely pretend to be 'manufacturers', deceiving their customers and putting them at risk for cybersecurity attacks and, soon, violation of US...
Axis Vs. Hikvision IR PTZ Shootout on Sep 20, 2018
Hikvision has their high-end dual-sensor DarkfighterX. Axis has their high-end concealed IR Q6125-LE. Which is better? We bought both and tested...
Avigilon Announces AI-Powered H5 Camera Development on Sep 19, 2018
Avigilon will be showcasing "next-generation AI" at next week's ASIS GSX. In an atypical move, the company is not actually releasing these...
Favorite Request-to-Exit (RTE) Manufacturers 2018 on Sep 19, 2018
Request To Exit devices like motion sensors and lock releasing push-buttons are a part of almost every access install, but who makes the equipment...
25% China Tariffs Finalized For 2019, 10% Start Now, Includes Select Video Surveillance on Sep 18, 2018
A surprise move: In July, when the most recent tariff round was first announced, the tariffs were only scheduled for 10%. However, now, the US...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact