Windows Embedded Security and Surveillance Solutions Windows Embedded 2010 Page 1
Copyright The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as of the date of publication. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information presented after the date of publication. This White Paper is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation. Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Microsoft, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows and the Windows logo are either registered trademarks or trademarks of the Microsoft group of companies. The names of actual companies and products mentioned herein may be the trademarks of their respective owners. Windows Embedded 2010 Page 2
Windows Embedded for Security and Suerveillance Solutions One Platform, Endless Possibilities Introduction Security and surveillance device manufacturers exist in a rapidly transitioning industry characterized by a shift from analog technologies to digital IP based technologies. This shift is driving a convergence between traditional security and surveillance products and IT products and technologies. The results of which have changed the security customer s perception of the importance of hardware compared to the importance of software. These innovations and resulting shifts within customer demand are making the choice of operating systems increasingly important. The Windows Embedded line of operating systems and development tools provides a platform that security and surveillance manufacturers can leverage to greatly enhance the performance and perception of their solutions. Relying on a proven Windows Embedded platform gives manufacturers the ability to lower production and operation costs, and increases the functionality of their devices. While embedded device manufacturers are the primary beneficiaries, the entire security and surveillance industry gains from the adoption of the Windows Embedded platform. Integrators and distributors are supplied with higher performance solutions that are easier to install and manage, and end users are rewarded with a more reliable solution and a higher quality of security Challenges Faced by Security and Surveillance OEMs Device and system manufacturers in the security and surveillance industry who are successful maintain their success by responding astutely to the changing threat environment as it presents itself in various forms. By mixing technological advancements from both the optics, information technology, access control and sensor industries and best practices in security systems design and risk mitigation these manufacturers manage to skillfully stay ahead of the curve of security threats and offer effective solutions that defend against, deter, delay and apprehend threats. Innovation, support, and performance are the three hallmarks of successful systems and device manufacturers in the security and surveillance industry. Innovation is required to keep pace with new developments from competition, to respond to customer demands for new features and functionality, and to do so within diminishing development cycles. Well developed support allows manufacturers to continue the lifecycle of currently deployed product lines, to easily increase integration possibilities with 3 rd party systems, and to easily distribute upgrades across their entire range of product lines and installations. Windows Embedded 2010 Page 3
High performance allows manufacturers to increase the breadth and depth of their distribution channel by adding high-end technologies and features and keeping pace with industry trends while reducing the complexity of installation and integration processes with proven and respected technologies and partners. Windows Embedded can help manufacturers increase all three of their key characteristics and go to market with embedded devices that improve the quality and effectiveness of security and surveillance installations. Windows Embedded 2010 Page 4
Why Windows Embedded for Security and Surveillance? The Windows Embedded security and surveillance portfolio consists of four product lines: Windows Embedded CE, Windows Embedded Standard, Windows Embedded Enterprise and Windows Embedded Server. These products share several common attributes which can provide great benefits for security and surveillance manufacturers: As a whole the security and surveillance industry can depend on Windows Embedded to provide a common platform for the user experience with devices and systems, and a common.net framework and Visual Studio development environment to efficiently expedite innovation. Application and software vendors who choose to build systems with Windows Embedded gain a platform that simplifies installation and integration with a wide range of third party applications and systems. This allows the integrators and distributors who work with these products to be more efficient and effective, ultimately driving additional demand and loyalty. Device and systems manufacturers gain a solid partner in Windows Embedded which extends the lifecycle of their solutions providing 15 years of product availability. Embedded device manufacturers in the security and surveillance industry can also turn to the Windows Embedded platform to upgrade their ability to connect with business intelligence systems and applications providing increased value to enterprise class installations. The licensing process can be simplified, and revenue channels protected, using OEM Activation with Windows Embedded Enterprise and Windows Server 2008 R2 for Embedded Systems. Along with these revenue enhancing benefits integrators and end users also gain the benefit of knowing their systems Windows Embedded 2010 Page 5
and devices will be dedicated to the protection of people and assets and hardened against any malicious uses. In addition Windows Embedded CE allows OEMs to modify source code without the need to report these changes back to Microsoft or the community and IP indemnification protects the OEM from software infringements on the Windows Embedded CE operating system. Windows Embedded CE for Edge Devices Windows Embedded CE is a componentized, real time operating system for a wide range of small footprint or rugged edge devices such as video surveillance cameras, video encoders, and access control card or biometric readers. It runs on multiple architectures such as MIPS, X86, ARM and SH4. Support for Silverlight makes Windows Embedded CE the perfect choice for devices requiring web accessible GUIs with a rich user experience. Security and surveillance edge devices using Windows Embedded CE enhance their ability to connect to and communicate with PC IT infrastructure. This includes managed and automated distribution of firmware and configuration changes, and automated device discovery. Users who access the edge devices will also benefit from a consistently intuitive interface across PC, web and edge device. A global ecosystem of partners, including trained and experienced designers and developers, can be leveraged by edge device manufacturers in the security and surveillance industry to help bring innovative and powerful devices to market faster. Documented and supported tools and training are Windows Embedded 2010 Page 6
also available to help security and surveillance manufacturers increase their own ability to develop products on the Windows Embedded CE operating system. Windows Embedded Standard and Enterprise for Recording and Workstation Devices Windows Embedded Standard delivers the power, familiarity and reliability of the Windows operating system in a componentized form. Windows Embedded Standard 7 is a componentized version of Windows 7 allowing developers to choose only the feature components that are needed, reducing the OS footprint, and fits any X86 hardware platform. It includes Enterprise connectivity for management, configuration and deployment plus hardening features such as Enhanced Write Filters which prevent any changes to the OS image while diverting important recordings to an alternate partition or disk. Windows Embedded Enterprise portfolio includes a fully functional version of Microsoft s Windows 7 desktop operating system intended for use in an embedded solution. Features included in Windows Embedded Enterprise that can create competitive separation for the security and surveillance manufacturers that choose to utilize it are: Touch and multi-point touch APIs used to build an intuitive control interface for clients and management applications running on Windows Embedded Enterprise. Virtual XP Mode (available with Windows Embedded Enterprise) enables legacy applications to run on modern hardware platforms; further extending the lifecycle of existing products. BitLocker and AppLocker features on Windows Embedded Enterprise prevent malicious programs or users from reading exported information on other computers or executing viruses or malware. Windows Embedded Enterprise provides Media Foundation and the DXVA video processing API enable client devices that are optimized to decode and display H.264 video streams, and video in true HD formats. Windows Server 2008 R2 for Embedded Systems Windows Embedded Server is a family of operating systems offering the same technologies and features in the Windows Server operating systems. These are scalable, dedicated smart server appliances that run on a 64 bit architecture. Windows Server 2008 R2 for Embedded Systems is the newest version of Windows Embedded Server and provides the security and surveillance industry with a platform that enables an entirely new class of high value embedded integrated solutions. Hyper-V virtualization in Windows Server 2008 R2 for Emedded Systems allows manufacturers to build devices which host multiple security functions within the same hardware platform lowering the cost of Windows Embedded 2010 Page 7
complex integrated systems, lowering the physical hardware footprint of deployed solutions and increasing the value of security and surveillance systems. Virtualization also provides scalable CPU utilization for recording and display devices which can dynamically allocate additional resources to specific workload processes such as video decoding and display or video motion detection and recording. VMS Recording Application SQL Database Windows Server 2008 R2 for Embedded Systems using the Hyper-V feature as Host OS This image displays a single embedded device hosting two virtual machines. Each virtual machine is running an application that is optimally isolated in its own hardware and software environment. Hyper-V virtualization enabled by Windows Server 2008 R2 for Embedded Systems provides security and surveillance manucfacturers the ability to include both of these software components on one high value embedded device. Windows Server 2008 R2 for Embedded Systems using the Hyper-V feature as Host OS NVR/VMS Recording Application with 32 cameras 32 Cameras Here we show again a single embedded device utilizing Hyper-V virtualization to effectively double the recording capacity of one hardware device by hosting two virtual machines, each of which are running an independent VMS or NVR application. With additional CPU and memory resources for each virtual machine the number of edge devices recorded and managed by security and surveillance devices can be increased when they are running Windows Server 2008 R2 for Embedded Systems. The Unix SDK can be utilized to extend the lifecycle of applications developed for legacy embedded devices into modern, high performance and enterprise connected platforms. Windows Server 2008 R2 for Embedded Systems also includes increased logical processor support so that it can be used on Windows Embedded 2010 Page 8
hardware platforms demanding the highest levels of performance, which are commonly found in mission critical security and surveillance systems. Network Load Balancing and Agile VPN features provide a high availability resilient connection used to bind remote systems to centralized command and control rooms, client displays to recording platforms, and even edge devices to management or recording systems. Multipath I/O technology can be used on storage systems operating within a Windows Server 2008 R2 for Embedded Systems platform to increase throughput and eliminate chokepoints between recording platforms and network storage locations. Security and Surveillance Industry Benefits from Windows Embedded Windows Embedded solutions for security and surveillance enable device manufacturers to accomplish resource efficiency, increase features and functionality and enhance connections to their ecosystem. Product development resources, legacy devices and applications and channel resources can all benefit from the efficiency of the Windows Embedded family of products. Performance from a recording and display standpoint and also device availability can be increased with Windows Embedded. Ecosystem connectivity, or the ability of devices to easily interoperate with 3 rd party systems and devices, is optimized with all Window Embedded products. Innovation Benefits Simplifying the installation and complexity of integration to extend high quality security and surveillance solutions to all levels of installations is another benefit Windows Embedded can provide. Windows Embedded solutions include device drivers and built in connectivity to any peripheral an end user or integrator wants to use and also connects the system to management and monitoring applications used for enterprise infrastructure or business intelligence. This simplifies the process of integration between previously stand alone security and surveillance devices and IT managed enterprise applications lowering the complexity of installation for integrators. Providing integrators with products that are easier to install and integrate allows them to sell and deploy larger and more sophisticated projects. Windows Embedded platform also provides significant upgrades in operational efficiency. By providing a method for automating the distribution of configurations and firmware or software updates Windows Embedded also provides a valuable time savings to system administrators by monitoring their deployed devices and communicating configuration and status changes. In addition intuitive GUIs for management and client applications will enable operators to be trained more rapidly and effectively. Connectivity to third party systems is also simplified with a system built upon a standards based platform such as Windows Embedded. This enables manufacturers and integrators to leverage their creativity and innovation to provide unique and customized solutions to their customers. Windows Embedded 2010 Page 9
Support Benefits The Windows Embedded platform enables a much more efficient use of product support and development resources by security and surveillance manufacturers and allows integrators and end users to benefit from cost effective solutions. By using intuitive development tools, platforms and technologies and relying upon an active developer and partner community manufacturers can dramatically shorten development cycles and lower the total cost of producing embedded devices. Lower total cost will directly impact manufacturers bottom line earnings, while also increasing the competitive position of their products. Extended availability for 15 years on Windows Embedded products allows manufacturers to extend the lifecycle of their products and to provide significant value to end users with a longer lasting system. Security and surveillance manufacturers with solutions that are currently running on 32bit operating systems must eventually make the transition to 64bit operating systems for the performance upgrades enabled on these next generation platforms. The XP Mode and Unix SDK features within Windows Embedded Enterprise and Windows Server 2008 R2 for Embedded Systems allow legacy applications to extend their life on modern 64bit embedded devices and support veteran security personnel with a familiar look and feel. By extending the lifecycle of applications developed initially for 32Bit operating systems, Windows Embedded can increase the ROI from manufacturers already developed and supported products. Available on Windows Embedded Server and Windows Embedded Enterprise, OEM Activation allows manufacturers to control and support the end user licensing process and prevents piracy which protects investments in developing the distribution channel and guarantees quality installations. All of these benefits lower costs for either end users, integrators or security and surveillance manufacturers which makes devices that run with Windows Embedded solutions considerably more attractive and competitive options. Performance Benefits Increasing the performance of devices to industry leading levels is also a benefit of choosing to use the Windows Embedded family of products. Security and surveillance manufacturers and integrators face challenges trying to accurately calculate the CPU requirements for display and recording hardware given the customer s camera count. Manufacturers base device CPU and Memory resource allotment on testing and experience. Windows Server 2008 R2 for Embedded Systems and Hyper-V virtualization can provide increased flexibility with dynamically scalable CPU and memory resources. More efficient use of computing resources when decoding H.264 and displaying HD video allow client and recording devices to increase the number of video streams they can handle simultaneously which enables systems to lower the number of devices performing recording, logging, processing, management and display operations, while maintaining or even increasing the number of actively recorded cameras which in turn increases the quality of security. By offering recording, management, and storage devices with the capacity to handle increased numbers Windows Embedded 2010 Page 10
of cameras and edge devices, security and surveillance manufacturers will see the value of their products increase, and will also gain the option of deployment in larger installations and more challenging verticals. Mission critical security installations must have high performance from a recording perspective and a reliability perspective. Windows Embedded can provide network redundancy and resilience to enable efficient display of information and video to increase situational awareness and promote better decision making. Hardened devices also prevent malicious threats, either internal or external, from disrupting the continuity of the security system. Providing highly available and high performance devices increases the value of manufacturer s solution. Summary The security and surveillance industry is currently positioned to take advantage of Windows Embedded solutions due to the emergence of processor based technologies and the shift from analog based systems to IP based installations. Windows Embedded platform can provide a proven high performance platform for the range of devices within security and surveillance: edge devices, recording and video management servers, and client and workstation devices. The Windows Embedded family of highly reliable tools and operating systems provides physical security manufacturers with innovative and stable solutions that improve the quality and functionality of physical security solutions by simplifying advanced systems integration with a new class of security hardware. Windows Embedded 2010 Page 11