GDPR and Product Security
Introduction to GDPR
01
02
UNV solution for GDPR
03
What the GDPR means for video surveillance?
What is the GDPR?
Introduction to GDPR
Data subject
Data controller
Data processor
Introduction to GDPR
Any information that could identify an individual (”data subject”), such as a name, an identification number, location data, photo, bank details, medical information and an online identifier etc.
Personal
Data
Introduction to GDPR
Right to consent
Right to access
Right to correction
Right to data portability
Right to data erasure
Introduction to GDPR
Data subject’s personal rights under GDPR regulations
Introduction to GDPR
Data controllers
Data processors
Data controller V.S. Data processor
Introduction to GDPR
01
02
UNV solution for GDPR
03
What the GDPR means for video surveillance?
What the GDPR means for video surveillance?
Corporate Accountabilities under GDPR Regulations
Data processing principles: lawfulness, fairness and transparency
legitimate interest, public security, competent authority or data subject’s consent
72
Hours
awareness of data breach
notify to DPAs (Data Protection Authority) within 72 hours
What the GDPR means for video surveillance?
Data breach notification
notification to data subject in clear and plain language, and delivered by means that maximize the chances of communicating the information to all affected data subjects
Case Level | Definition | Feedback Time | Time for Resuming | Deadline |
Level 1 (Urgent) | System breakdown/suspended during operation Basic function unusable | Immediately at Chinese working time | <=2h | <=15days |
Level 2 (High) | Potential system breakdown/ suspended risk during operation Some function unusable | Chinese work time<=2h | <=24h | <=30days |
Level 3 (Medium) | Partly function unusable during operation | Chinese work time<=24h | <=48h | <=60days |
What the GDPR means for video surveillance?
Support for Product Response Timeline
Introduction to GDPR
01
02
UNV solution for GDPR
03
What the GDPR means for video surveillance?
Cyber Issues
Hack in to see private home camera
Cyber security is now incredible serious as hacker may hack to your camera and make your surveillance camera monitoring yourself.
It is Uniview’s priority to protect customers privacy in safe.
Cyber Issues
System error to see other video stream
What do Uniview do to ensure your privacy and data secure in public and private network environment
Network
Security
Network environment surveillance to resist illegal attack
High level of safety design requirement and process specification
System Design Security
Give consideration to both usability and security
Intelligent Access Control
Private Network Solution
Environment Security Surveillance
01
Strong Password
Hint of strong and weak
Access block due to wrong password
Forcing strong PW for Non-direct network
02
03
IP Filtration
whitelist
blacklist
Identify Verification
Before all kinds of access
RTSP Verification
IAC
Strong Password
Identity Verification
RTSP
Network
Verification required
Wrong and denied
X
RTSP
Verification?
IP Filtration
to allow the access from specific IP addresses
to reject the access from specific IP addresses
Same as mobile payment
HTTPS
Keep reliable during ARP attack
ARP Protection
Verification of switch ports
802.1x
Anti-modification of recordings
Water Mark
ESS
HTTPS
HTTPS is security version of HTTP, based on SSL protocol. And it can provide authentication and encrypted communication, which make communication over Internet secure.
ARP Protection
Network can be bound to confirmed Gateway(by its MAC address)
Devices will reject any ARP connection without this Gateway MAC address.
802.1x
The devices supports to work under the network using IEEE802.1X which means the RADIUS server will do verification for all devices in the network and ensure devices communication
Using stream watermark to prove the stream unmodified. The watermark only works with EZPlayer and has no influence to both live view and playback.
Digital Watermark
Database protection
Individual notadmin user for database operation
Operation limitation and monitoring
Patch upgrade annually
Key info encryption
Encryption during storage
Encryption of file with verification info
AES/DH/DSA/RSA/HASH encryption algorithm
Portal safety
Open to use under monitoring
Both hardware port and network port
Communication management
Replay attack protection
Multiple communication limitation
SDS
Turn off service like SNMP V1/V2 in default
Turn off telnet in defalut
Service and module safety
Public Network Solution
Cloud Security
Reliable
Independent Cloud Server
Dynamic encryption
Device unicity
Directly connection
Easy configuration
Flexible access
Usability
Independent Cloud Server
①Device Info.
②STUN Info about Device
③Login Account : Username、Password
④ Device Info、STUN Info about Client
Include:
EZCloud Server、STUN Server、TURN Server
⑥ STUN Info about Client
⑤P2P Request
⑥ STUN Info about Device
⑦Set up P2P tunnel
⑧Login Device:Username,Password
The Cloud Server will only help to set the network tunnel and keep separated with business such as live view and alarm management which means the very user is the only one who have the authentication to get access to his/her devices.
Device Share
Share the device according to user rights
Dynamic Encryption
Dynamic Password
Automatically Login
Dynamic Random Value
Dynamic Random Value
DC647EB65E************18212B3964
Device Unicity