Fuze for personal computers... 7 Fuze for mobile devices... 7 ios... 7 Android... 7



Similar documents
Live Guide System Architecture and Security TECHNICAL ARTICLE

VIDEOCONFERENCE. 1 Introduction. Service Description Videoconferece

District of Columbia Courts Attachment 1 Video Conference Bridge Infrastructure Equipment Performance Specification

Dropbox for Business. Secure file sharing, collaboration and cloud storage. G-Cloud Service Description

GTS VIDEOCONFERENCE. Powered by: Valid from: 1 June 2014

Top. Reasons Federal Government Agencies Select kiteworks by Accellion

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

CONNECTING THE WORLD Mobility. Compatibility. Simplicity.

Ensuring Enterprise Data Security with Secure Mobile File Sharing.

Cloud Video. Data Sheet

Smartphone Enterprise Application Integration

Flexible Identity Federation

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: Security Note

Security Overview Enterprise-Class Secure Mobile File Sharing

Casper Suite. Security Overview

Cloud Video Conferencing. A comprehensive guide

E-commerce: Competing the Advantages of a Mobile Enterprise

Zeenov Agora High Level Architecture

Blue Jeans Network Security Features

Fuze Meeting Video Conferencing. Boardroom quality HD video conferencing to any internet connected device.

Cloud Video Conferencing. A Comprehensive Guide

The All-in-One Support Solution. Easy & Secure. Secure Advisor

The Acano Solution. acano.com

OmniJoin Security (July 2015)

The Conference Room of Today. Easy & Secure. Instant Meeting

PRIVACY, SECURITY AND THE VOLLY SERVICE

Lifesize. Cloud. Now you re talking with incredible video conferencing

What it can do. Further scaling and resilience provided by native clustering. Automatic failover with no single point of failure.

Configuration Guide BES12. Version 12.2

ipecs UCS Unified Communications Solution Easy to access and activate Highlights Single server solution

FRAFOS GmbH Windscheidstr. 18 Ahoi Berlin Germany

FileCloud Security FAQ

THE LINK OFFLINE DATA ARCHITECTURE

The Vidyo Conferencing Portfolio. Everything you need for HD video conferencing with incredible quality, reach and savings

RCS - Overview. Rich Communication Suite

Deployment Guide July-2014 rev. a. Deploying Array Networks APV Series Application Delivery Controllers for Microsoft Lync Server 2013

Mitel MiCloud Telepo for Service Providers 4.0 SP3

Service Overview v1.1

Configuration Guide BES12. Version 12.1

Dell World Software User Forum 2013

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference

Bridgit Conferencing Software: Security, Firewalls, Bandwidth and Scalability

Top. Enterprise Reasons to Select kiteworks by Accellion

Mitel MiCloud Telepo for service providers 4.2

BlackBerry Enterprise Service 10. Version: Configuration Guide

CBIO Security White Paper

Security Features 01/01/2014

FRAFOS GmbH Windscheidstr. 18 Ahoi Berlin Germany

Communication ports used by Citrix Technologies. July 2011 Version 1.5

Cisco WebEx Meetings Server

IBM Cognos TM1 on Cloud Solution scalability with rapid time to value

CONNECTING TO LYNC/SKYPE FOR BUSINESS OVER THE INTERNET NETWORK PREP GUIDE

IOCOM Whitepaper: Connecting to Third Party Organizations

Cloud Managed Printing

Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0

Interwise Connect. Working with Reverse Proxy Version 7.x

Troubleshooting BlackBerry Enterprise Service 10 version Instructor Manual

Security Overview Introduction Application Firewall Compatibility

Conference Bridge setup

Ensuring the security of your mobile business intelligence

Migrating, Installing, and Configuring ADOBE CONNECT 9

CTX OVERVIEW. Ucentrik CTX

With Eversync s cloud data tiering, the customer can tier data protection as follows:

Williamson County Technology Services Technology Project Questionnaire for Vendor (To be filled out withprospective solution provider)

Live Communications Server 2005 SP1 Office Communications Server Matt Newton Network Engineer MicroMenders, Inc

WHITEPAPER. SECUREAUTH 2-FACTOR AS A SERVICE 2FaaS

RTMP Channel Server I6NET Solutions and Technologies

Skynax. Mobility Management System. System Manual

Migrating, Installing, and Configuring ADOBE CONNECT 8

Biba Datasheet. Biba is a mobile collaboration tool that provides:

Cisco WebEx Meeting Center

BeBanjo Infrastructure and Security Overview

Advanced Configuration Administration Guide

What We Do: Simplify Enterprise Mobility

Media Exchange. Enterprise-class Software Lets Users Anywhere Move Large Media Files Fast and Securely. Powerfully Simple File Movement

Rich Communication Suite Enabler. plus integration with your existing VoIP services

Windstream Integrated Services Group Avaya Inc. All rights reserved. 1

Web Conferencing: Unleash the Power of Secure, Real-Time Collaboration

Polycom Solutions For Microsoft Unified Communications ETK networks Technical Workshop 2011 Michael Ott, Distribution Manager DACH

WebEx Security Overview Security Documentation

WebRTC: Why You Should Care and How Avaya Can Help You. Joel Ezell Lead Architect, Collaboration Environment R&D

Configuration Guide BES12. Version 12.3

Enterprise SM VOLUME 1, SECTION 4.5: WEB CONFERENCING SERVICES (WCS)

Famly ApS: Overview of Security Processes

Cisco Unified Videoconferencing Manager Version 5.5

Proof of Concept Guide

Middleware- Driven Mobile Applications

Founded in employees Guinness World Record for the largest online training Provides videoconferencing with 4K Ultra HD SaaS and On-Premise

IP Ports and Protocols used by H.323 Devices

Application Note. Onsight Connect Network Requirements V6.1

Spontania User Setup Guide

Copyright 2013, 3CX Ltd.

ezuce Uniteme TM Unified Communications for the Enterprise ezuce Inc. 2015

Secure VidyoConferencing SM TECHNICAL NOTE. Protecting your communications VIDYO

Microsoft Office Communications Server 2007 & Coyote Point Equalizer Deployment Guide DEPLOYMENT GUIDE


1. What are the System Requirements for using the MaaS360 for Exchange ActiveSync solution?

Global Network. Whitepaper. September Page 1 of 9

PostFiles. The file sharing and synchronization solution dedicated to professionals.

Transcription:

Fuze technology.

Table of contents. Fuze architecture. 4 6 UCAPI services... 5 Audio conference bridge... 5 Audio conference service... 5 Transport services... 5 Screen sharing hubs... 6 Video conference hubs... 6 Telepresence connect gateways... 6 Transcoding services... 6 Authentication services... 6 Clients. 7 Fuze for personal computers... 7 Fuze for mobile devices... 7 ios... 7 Android... 7 Security. 9 General application and session connectivity. TLS session encryption for all web and mobile clients... Password protection... Single Sign On (SSO) with LDAP or SAML based Authentication... Billing and commerce transactions... Signed code... Content and infrastructure security. Enterprise content policies... Certified FIPS 140-2 compliance... Audio and Video Media Security. 9 Audio encryption... 9 Communication through secure ports and firewall traversal... 9 File security/protection... 9 File upload and download... 9 Data at rest provider... 9 Fuze technology 2

Table of contents. (Cont.) Fuze Ignite Partner APIS. 10 Fuze support. 11 Contacting support... 11 Fuze support tiers... 11 Support ticket workflow... 11 Fuze service reliability. 12 Global infrastructure... 12 Automated service quality monitoring... 12 24x7 Engineering and operations teams... 12 Load balancing, failover, scalability & security are implemented in order to guarantee service performance... 12 Private Cloud infrastructure... 12 Dedicated communication lines... 12 Fuze technology 3

Fuze architecture. Fuze is an intuitive and powerful visual communication solution - built in the cloud with a modular, horizontally-scalable architecture - designed to provide reliable up-time, secure data transmission, and quick deployment of improvements and innovations to all Fuze users. By leveraging standard protocols, Fuze delivers a vendor-agnostic user experience that can be exteded across all leading device endpoints. As a result, users can host or join a Fuze meeting from any device including smartphones, tablets, laptops, desktops and in-room conferencing systems. Major components of the Fuze platform are described below. Architecture Fuze clients directly connect to Fuze cloud over WAN (optional video hub for video meetins can be on LAN) Site 1 Site 2 Fuze Client Fuze Client Fuze Client Fuze Client Transport Services Remote Sites Traansport Services: Events sync between participants & meetings allowing clients to join/ reconnect, provide mobile devices with access Voice Conference Service Voice Attendee Fuze Cloud Services Fuze Database Server Fuze Client Video gateway supports H.323 and SIP video devices to connect into Fuze Telepresence Video Gateway Fuze Service Web Servers Web servers manage meetings data, metadata about media files Transcoding Services Transcoders convert video, documents and images to formats, uploaded to secure servers, in a viewable format for the clients Required Firewall Ports, Outbound: 0/443 TCP: HTTP/HTTPS from client to Fuze web services 43 TCP: Flash policy for Flash clients 347 UDP/TCP: STUN/NAT Traversal for VoIP 5060 UDP: SIP signaling for video and VoIP 50,000-60,000 UDP: RTP for VoIP and video conferencing Fuze technology 4

Fuze architecture (Cont.) UCAPI services UCAPI (Unified Communication API) is a HTTP service accessible via HTTPS. This is the Fuze Meeting application layer. It is responsible for managing persistent account and meeting data, as well as metadata about media files. UCAPI exposes several APIs for communication with both internal and external parties: Internal SOAP API, used by our clients Internal JSON API, used by the Fuze Meeting website Partner API used by partners via the FuzeBox Ignite platform program UCAPI is implemented in Python using the Pylons framework. The service itself runs as a paster application that binds to the loopback interface of the server. Apache is used to add a secure layer, proxying requests to the paster service. All communication to UCAPI instances passes through HTTPS. All SOAP methods and other request handlers require authentication in the form of a valid session previously obtained from the service. Internal methods require a service session, and these are issued to internal components only (such as WMP) via a special service account. Audio conference bridge Our conference bridge infrastructure mixes PSTN, cellular and VoIP participants in a conference call for each meeting. Toll free and international numbers are provided through partnerships with leading domestic and international providers. Our VoIP implementation uses industry standard SIP and RTP transport protocols for PC, MAC, iphone, ipad and Android. Audio conference service All client actions in the audio conferencing room (mute, fetch participant, audio recording) go through UCAPI to the audio conference service, which sends the respective requests to our conference bridge using a XML based control protocol. It also sends updates to clients for any room changes via the transport services and manages audio recording. Transport services Our Transport Service layer provides media for exchanging synchronization events between meeting participants and the server side control logic. It holds the meeting dynamic state, allowing clients to join/reconnect to a meeting while it is in progress. It provides the mobile devices with access to the rest of the services. It also enables presence and instant messaging services. Fuze technology 5

Fuze architecture (Cont.) Screen sharing hubs We provide screen sharing, application sharing and remote control to meeting participants. Desktop and mobile clients connect directly to our screen sharing hubs. Video conference hubs HD video conferencing is a standard Fuze Meeting feature. Desktop and mobile clients connect directly to the Fuze service at their closest Fuze data center, passing video data over the secure Fuze network and minimizing any performance impact from local connections. Telepresence connect gateways The Telepresence Connect Gateway lets you connect Polycom, Tandberg or other MCU-based systems to any Fuze Meeting video session. The gateway supports H.3232 and SIP. H.264 and H.263 are supported for video and wide band audio. Transcoding services Transcoding Services consist of Transcoding Manager and Transcoding Engines. Transcoding Manager dispatches transcoding jobs between the transcoding engines based on the media file extension and the load of the running transcoding engines. When the client uploads media it is saved to Amazon S3 storage. Transcoding Engines communicate with the Transcoding Manager via XML RPC to receive jobs and to report progress and results of the transcoding. Authentication services The Authentication Service supports Microsoft Active Directory, OpenLDAP and SAML directory servers. Corporate users will get authenticated against their corporate directory service. Access to Fuze Meeting services is controlled by participation in selected directory groups. Fuze technology 6

Clients. Fuze runs on all major personal computer and mobile device platforms, either through native client apps or via Flash-enabled Web browsers. All clients share common user interface elements to let users connect with confidence regardless of the device they use. Fuze for personal computers Fuze runs natively on the leading personal computer operating systems, with native apps for both Windows and MacOS. Meeting guests can join a Fuze meeting by clicking on a URL link within their meeting invite. If Fuze is installed, the link will launch the Fuze app with the appropriate Fuze meeting number. If Fuze is not installed, the link will redirect the user to a guided app installation flow, with an option to join the meeting via browser-only. The Flash plug-in provides basic browser-only confrencing services for meeting guests. Installation of the Fuze client app is required to access complete service capabilities, including video conferencing, internet audio and screen sharing Fuze for mobile devices Fuze led the industry with the introduction of the first native-featured video conferencing app for ios in 2010. We continue to drive innovation on leading tablet and smartphone platforms. ios Fuze provides two native ios applications approved in the Apple App Store: Fuze for ipad provides full capabilities to initiate, control or record Fuze meetings with up to 12 HD video conferencing streams. It permits content sharing from the screen, both built-in ipad cameras, or the cloud. Fuze for iphone offers the ability to join Fuze meetings. Android Fuze for Android tablets provides full meeting host capabilities on par with Fuze for ipad. This Android app is Java based using the Android SDK for most of the components with only the VoIP library compiled in C++ using the Android NDK. Fuze for Android phones is also available for download on all major Android application stores. Similar to Fuze for iphone, this build enables Android phone users to join Fuze Meetings. Fuze technology 7

Security. Our customers trust Fuze to present and protect confidential documents and assets. We earned that trust with technology that keeps meeting information and content secure and confidential. The Fuze platform provides: General application and session connectivity. TLS session encryption for all web and mobile clients Fuze sessions utilize TLS to ensure encryption between participants and the Fuze service. Password protection When using Fuze s native user authentication, passwords are never stored in our systems. We only keep a salted, one-way MD5 hash value. The channel between the client and the server utilizes basic TLS authentication. Single Sign On (SSO) with LDAP or SAML based authentication For enterprise deployments, our system can leverage either LDAP or SAML for authentication. In this mode, customer passwords are not stored in our database. Authentication is delegated to the Customer s directory servers. Billing and commerce transactions All our billing and commerce transactions use a secure system with the following compliance: PCI DSS Level 1 Service Provider SSAE16 SOC1 Type 2 audited US-EU Safe Harbor Signed code FuzeBox components use signed code and a third-party certificate provided by VeriSign. Content and infrastructure security. Enterprise content policies Enterprises with compliance regulations can set a policy that ensures all content is deleted at the end of the meeting. Certified FIPS 140-2 compliance Our at-rest storage provider uses FIPS 140-2 compliant cryptography to secure confidential content. Fuze technology

Security (Cont.) Audio and video media security Audio encryption We encrypt all audio between the client and the server using the SRTP standard. (coming in Q1 2014) Communication through secure ports and firewall traversal Fuze is designed to work seamlessly in your highly secured environment, complete with proxy traversal capabilities and the ability to send all traffic over TCP 443. Your data stays secure in the cloud. File security/protection All content uploaded by the host of the meeting is securely stored on our backend. We encrypt all content at rest with AES 256 encryption. During a meeting, content pushed to the meeting participants is handled in a way so a local copy can never be obtained. File upload and download All files transferred between the server and the client is done over a secure HTTPS connection. Data at rest provider Storage infrastructure has been designed and managed in alignment with regulations, standards, and best-practices including: HIPAA SOC 1/SSAE 16/ISAE 3402 (formerly SAS70) SOC 2 SOC 3 PCI DSS Level 1 ISO 27001 FedRAMP(SM) DIACAP and FISMA ITAR FIPS 140-2 CSA MPAA Media and webservices layer hosting providers ISO 27001 PCI DSS Fuze technology 9

Fuze Ignite Partner APIS. The FuzeBox Ignite (Fuze Meeting) Partner API is a service allowing integration of third party systems with Fuze Meeting. The API is built on HTTP and made available over secure (HTTPS) connections. It is is built on welldefined standards and technologies HTTP and JSON, making usage straightforward. Calling a method is as simple as sending a HTTP POST request to the method's URL, passing the request parameters as formurlencoded request payload. Requests must also include a partner-identifying header and an authorization token. The response is a JSON object that always contains a code and message members. Here is a list of modules and corresponding APIs available with each module: Api module & method User Module signup signin getpackages Account Module subscribe cancel getinfo Meeting Module schedule start list getlaunchtoken get status update Media Uploading addmediatomeeting Description Creates new account on behalf of a partner Gets a session for partner s account Returns packages provided to a partner for its users subscriptions Subscribes an existing user for specific payment package/add-on Cancel all subscriptions of a customer Get account information Creates /schedules a Fuze meeting Creates a Fuze meeting and generates launch token immediately List meetings hosted or scheduled by the current user Returns token to be used to compose launch meeting URL Get meeting information Get meeting status information Update the details of an existing meeting Adds a previously uploaded media to a meeting Fuze technology 10

Fuze support. Contacting Support Within Fuze, go to Help > Report a Problem On the Web, www.fuze.com/about/contact, Select Support On our Support site, support.fuzemeeting.com/home Email, support@fuze.com Phone, (00) 44-411 or (415) 692-400 Fuze support tiers Fuze has 3 support tiers to address any technical issues users may experience. Tickets are further grouped within each support tier by type and priority. Tier 1 Live support for calls and tickets 24 hours a day, 5 days a week Tier 2 Escalations of difficult tickets from Tier 1 that require deeper technical understanding Tier 3 Fuze Product Development and Operations Support ticket workflow. New Email Open & Assigned Pending Email Solved Email Survey Email Customer creates support ticket Support agent working on ticket Support requests additonal Support notifies customer After 24 business hours, customer info/response satisfaction survey Closed After 5 days SOLVED Fuze technology 11

Fuze service reliability. Video Voice Screenshare San Jose Jersey Amsterdam WWW Telepresence WWW WWW Website Singapore Sydney Global infrastructure Fuze operates out of data centers located in San Jose CA, New Bergen NJ, Singapore, Sydney and Amsterdam. This global distribution of the modular, horizontally-scalable Fuze architecture enables Fuze to deliver high quality service to customers around the world, as well as maintain service to all customers even in the event of catastrophic failure in one or more data center locations. Automated service quality monitoring Automated monitoring alerts the Operations team when service parameters approach pre-defined thresholds. 24x7 engineering and operations teams Our offices in the US and Europe are staffed so that there is always a team available to take action where intelligent decision-making is necessary. State-of-the-art software engineering practices are in place to guarantee that performance targets are met. Load balancing, failover, scalability & security are implemented in order to guarantee service performance Our private cloud infrastructure is capable of growing automatically when necessary, and shrinking when service load goes down. Private Cloud infrastructure Fuze Meeting service is utilizing distributed computing and cloud storage for highly redundant and scalable infrastructure. Our geo-redundant data centers run private cloud infrastructure built on world-class compute, network and storage technologies. The service expands automatically to accommodate additional load at peak hours. Dedicated communication lines High definition video conferencing is dependent on a low latency network. Dedicated connections to our data centers can be accommodated in order to avoid public Internet weather. Fuze technology 12