ONVIF, the global industry standard-setting forum for interoperability, recently announced ONVIF Profile V as a release candidate, taking into focus the relation between video security devices and cloud VMS clients of different brands.
In an exclusive interview with asmag, ONVIF Ambassador Roberto Licari pointed out that the relation between a camera on the one hand, and an on-prem client or a cloud client on the other is fundamentally different when it comes to enabling interoperability.
“The key word is perimeter,” Licari explained. “In an on-prem scenario, the perimeter is clearly identified and limited. The client, for example an NVR, can ping addresses on the local network and find all suitable devices. In the cloud scenario, this perimeter doesn't exist—edge devices are connected to the Internet, where the number of potential connections is virtually limitless.”
“Under Profile V, the device initiates the connection—not the client, like in other profiles," Licari said.
Previously released ONVIF profiles standardize the relationships within on-prem systems, such as Profile S, Profile T or Profile G. Here, the relationship is initiated by the client. The NVR, for example, discovers devices within the network and establishes a relationship based on the shared standard. When the relationship centers on a cloud service, however, the premise collapses as there is no local network underlying the whole system.
Establishing connections in the direction of endpoint-to-client is not only a matter of technical implementation if cloud clients are involved, but also a matter of cybersecurity.
"Once you go outside the perimeter, the typical IT security logic goes like this: No one can come in, everyone can get out," Licari stated. "By establishing the connection starting at the device under Profile V, VPNs or port forwarding are no longer needed, and firewalls no longer need to be modified to let the initial signal in.”
Interoperability for video and AI metadata transmission
Aside from system setup, Profile V also standardizes the transmission of video and audio data, as well as event metadata and notifications, for example for AI inference. Each of the three channels relies on established cybersecure protocols: WSS for the initial handshake, WebRTC for live video and audio, and MQTTS or WSS for metadata and event notifications, all running over TLS-secured connections.
The aim is enabling interoperability with regard to all data that is being sent from the camera to the cloud, regardless of what cloud analytics are being added.
Why interoperability?
Proponents of interoperability argue that no single manufacturer excels at every layer of a system. A standardized cloud connection means integrators can pair the most suitable camera with the most suitable VMS or cloud analytics service, enabling integrated “best-of-breed solutions.”
However, interoperability can be challenging from an operational point of view. Critics of full interoperability therefore argue that keeping a system proprietary and tightly controlled “guarantees” that every element performs to its best and helps facilitate end-to-end support.
While its standards underpin open ecosystems, ONVIF doesn’t take a stand against selective interoperability or proprietary ecosystems. Some brands known for “vendor lock-in” approaches are ONVIF members and have implemented select profiles for some of device series.
“With ONVIF Profile V, we give companies an additional standard for communication between device and cloud,” Licari said. “It doesn’t exclude devices that support multiple standards. For example, if your customers are happy with a proprietary connection that relies on your own standard, you can cut off the ONVIF channel and go back to a proprietary link. That is fine, too.”
“However, we believe interoperability also opens new opportunities to vendors focused on a proprietary ecosystem,” Licari explained. “If they believe their devices and services are the best in the market, interoperability enables them to get a foot in the door in mixed-vendor systems. Then the customer can decide whether their devices and services are really the best and potentially switch to an ecosystem solution.”
Add-on flexibility to increase cybersecurity
Profile V comes with the companion Profile V Security Add-on, which covers authentication (built on the OAuth 2.0 framework and mutual TLS) and the encryption of video and audio. Splitting security out ensures the standards set in the core profile do not need to be changed after Profile V is finalized, while the Add-on can accommodate updates to address cyberthreats.
“Cybersecurity is constantly evolving,” Licari said. “ONVIF will modify the Add-on as threats evolve, while the core profile will stay the same to ensure that Profile V-conformant devices remain interoperable with each other based on a reliable standard.”
What data can be transmitted?
Profile V requires that devices can transmit and clients can receive video encoded in H.264 over WebRTC, but ONVIF is otherwise agnostic as to what data is being exchanged, as long as the standardized relation is between a device and cloud location.
“Profile V has nothing to do with cloud-to-cloud communications,” Licari stated. “If data is being transmitted from your cloud VMS to an external analytics client or AI agent, ONVIF does not set any standards for this. Our focus is on video security devices and their connections.”
Profile V is similarly agnostic about what happens upstream of the camera. "How you manage your IT infrastructure, your archive, your internal security policy—all that has nothing to do with Profile V," Licari added. "You can have cameras connecting to an on-prem video encoder, and that encoder transmits to a cloud repository using Profile V. The communication Profile V establishes is between the encoder and the client.”
Profile V rollout and conformance testing
ONVIF has made the draft specifications of Profile V available to its members for review until the end of the year, when the final version will be published and vendors and cloud service providers can apply for conformance testing.
This rigorous process is important to ensure “ONVIF” is more than a label vendors can use in spec sheets and marketing materials. ONVIF membership means companies are eligible to apply for testing, and they may take part in the process of drafting the standards depending on membership level—it does not mean all their devices are built for interoperability.
Before products are declared conformant, they go through ONVIF's independent conformance testing process for the relevant standard. During a twice-a-year “ONVIF Plugfest,” it brings members together to connect and test their devices in a controlled environment.
“Once Profile V is finalized, manufacturers can submit specific products and firmware versions they want to have confirmed for conformance,” Licari stated. “Some companies have already started building against the release candidate in their labs.”