<?xml version="1.0"?>
<?xml-stylesheet href="docbook.xsl" type="text/xsl" ?>
<book xmlns="http://docbook.org/ns/docbook" version="5.0">
  <info>
    <title>Security Baseline Specification</title>
    <titleabbrev>SecurityBaseline</titleabbrev>
    <releaseinfo>25.12</releaseinfo>
    <author>
      <orgname>ONVIF™</orgname>
      <uri>www.onvif.org</uri>
    </author>
    <pubdate>December, 2025</pubdate>
    <mediaobject>
      <imageobject>
        <imagedata fileref="media/logo.png" contentwidth="60mm"/>
      </imageobject>
    </mediaobject>
    <copyright>
      <year>2008-2025</year>
      <holder>ONVIF™ All rights reserved.</holder>
    </copyright>
    <legalnotice>
      <para>Recipients of this document may copy, distribute, publish, or display this document so
        long as this copyright notice, license and disclaimer are retained with all copies of the
        document. No license is granted to modify this document.</para>
      <para>THIS DOCUMENT IS PROVIDED "AS IS," AND THE CORPORATION AND ITS MEMBERS AND THEIR
        AFFILIATES, MAKE NO REPRESENTATIONS OR WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT
        LIMITED TO, WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE,
        NON-INFRINGEMENT, OR TITLE; THAT THE CONTENTS OF THIS DOCUMENT ARE SUITABLE FOR ANY PURPOSE;
        OR THAT THE IMPLEMENTATION OF SUCH CONTENTS WILL NOT INFRINGE ANY PATENTS, COPYRIGHTS,
        TRADEMARKS OR OTHER RIGHTS.</para>
      <para>IN NO EVENT WILL THE CORPORATION OR ITS MEMBERS OR THEIR AFFILIATES BE LIABLE FOR ANY
        DIRECT, INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE OR CONSEQUENTIAL DAMAGES, ARISING OUT OF OR
        RELATING TO ANY USE OR DISTRIBUTION OF THIS DOCUMENT, WHETHER OR NOT (1) THE CORPORATION,
        MEMBERS OR THEIR AFFILIATES HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, OR (2)
        SUCH DAMAGES WERE REASONABLY FORESEEABLE, AND ARISING OUT OF OR RELATING TO ANY USE OR
        DISTRIBUTION OF THIS DOCUMENT.  THE FOREGOING DISCLAIMER AND LIMITATION ON LIABILITY DO NOT
        APPLY TO, INVALIDATE, OR LIMIT REPRESENTATIONS AND WARRANTIES MADE BY THE MEMBERS AND THEIR
        RESPECTIVE AFFILIATES TO THE CORPORATION AND OTHER MEMBERS IN CERTAIN WRITTEN POLICIES OF
        THE CORPORATION.</para>
    </legalnotice>
    <revhistory>
      <revision>
        <revnumber>25.12</revnumber>
        <date>Dec-2025</date>
        <author>
          <personname>Hans Busch</personname>
        </author>
        <revremark>First release</revremark>
      </revision>
    </revhistory>
  </info>
  <chapter>
    <title>Scope</title>
    <para>This document defines the security baseline for ONVIF specifications. Its content is based on state-of-the-art technology as published by NIST or BSI.</para>
    <para>Note that any updates to this specification require a review of implications on technical, profile, and addon specifications.
      Publication of updates to this document shall be synchronized with ONVIF Technical and Technical Service Committees.</para>
  </chapter>
  <chapter>
    <title>Normative References</title>
    <para>NIST FIPS 180-4 Secure Hash Standard (SHS)</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf"/>&gt; </para>
    <para>NIST FIPS 186-5 Digital Signature Standard (DSS) - February 3, 2023</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf"/>&gt;</para>
    <para>BSI – Technical Guideline, Cryptographic Mechanisms: Recommendations and Key Length- January 31, 2025</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TG02102/BSI-TR-02102-1.pdf?__blob=publicationFile&amp;v=9"/>&gt;</para>
    <para>RFC 4055 - Additional Algorithms and Identifiers for RSA Cryptography for use in the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc4055"/>&gt;</para>
    <para>RFC 4868 -  Using HMAC-SHA-256, HMAC-SHA-384, and HMAC-SHA-512 with IPsec</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc4868"/>&gt;</para>
    <para>RFC 5116 -  An Interface and Algorithms for Authenticated Encryption</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc5116"/>&gt;</para>
    <para>RFC 5280 Internet X.509 Public Key Infrastructure Certificate and Certificate
      Revocation List (CRL) Profile</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink"
      xlink:href="http://www.ietf.org/rfc/rfc5280.txt"
      >http://www.ietf.org/rfc/rfc5280.txt</link>&gt;</para>
    <para>RFC 5480 - Elliptic Curve Cryptography Subject Public Key Information</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc5480"/>&gt;</para>
    <para>RFC 5758 - Internet X.509 Public Key Infrastructure: Additional Algorithms and Identifiers for DSA and ECDSA</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc5758"/>&gt;</para>
    <para>RFC 5869 - HMAC-based Extract-and-Expand Key Derivation Function (HKDF)</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc5869"/>&gt;</para>
    <para>RFC 7292 - PKCS #12: Personal Information Exchange Syntax v1.1</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc7292"/>&gt;</para>
    <para>RFC 7714 - AES-GCM Authenticated Encryption in the Secure Real-time Transport Protocol (SRTP)</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc7714"/>&gt;</para>
    <para>RFC 7518 - JSON Web Algorithms (JWA)</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc7518"/>&gt;</para>
    <para>RFC 7519 - JSON Web Token (JWT)</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc7519"/>&gt;</para>
    <para>RFC 8017 - PKCS #1: RSA Cryptography Specifications Version 2.2</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc8017"/>&gt;</para>
    <para>RFC 8018 - PKCS #5: Password-Based Cryptography Specification Version 2.1</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc8018"/>&gt;</para>
    <para>RFC 8439 - ChaCha20 and Poly1305 for IETF Protocols</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc8439"/>&gt;</para>
    <para>RFC 9579 - Use of Password-Based Message Authentication Code 1 (PBMAC1) in PKCS #12 Syntax</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://datatracker.ietf.org/doc/html/rfc9579"/>&gt;</para>
    <para>ANSI X9.62 - Public Key Cryptography for the Financial Services Industry: The Elliptic Curve Digital Signature Algorithm (ECDSA)</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://webstore.ansi.org/standards/ascx9/ansix9622005"/>&gt;</para>
    <para>NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation: Methods and Techniques</para>
    <para>&lt;<link xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf"/>&gt;</para>
  </chapter>
  <chapter>
    <title>Terms and Definitions</title>
    <informaltable>
      <tgroup cols="2">
        <colspec colname="c1" colwidth="27*"/>
        <colspec colname="c2" colwidth="73*"/>
        <tbody valign="top">
          <row>
            <entry>
              <para>Asymmetric Encryption</para>
            </entry>
            <entry>
              <para>Encryption using a public and private key pair.</para>
            </entry>
          </row>
          <row>
            <entry>
              <para>Hash</para>
            </entry>
            <entry>
              <para>A method of creating a unique fingerprint of a large data set.</para>
            </entry>
          </row>
          <row>
            <entry>
              <para>Signature</para>
            </entry>
            <entry>
              <para>A hash signed with a private key that can be verified using the corresponding public key.</para>
            </entry>
          </row>
          <row>
            <entry>
              <para>Public Key Cryptography</para>
            </entry>
            <entry>
              <para>Cryptographic operations using a key pair (public and private key), including encryption, key agreement, and digital signatures.</para>
            </entry>
          </row>
        </tbody>
      </tgroup>
    </informaltable>
  </chapter>
  <chapter>
    <title>Overview</title>
    <para>The content of this document is based on state-of-the-art technology as published by the American institute NIST and the German department BSI.
      Note that any updates to this specification require a review of implications on technical, profile, and addon specifications.
      Publication of updates shall be synchronized with ONVIF Technical and Technical Service Committee.</para>
    <para>The tables in this document define cryptographic algorithms and identifiers used by ONVIF specifications.
      In all cases, the applicable profile or add-on specification is the authoritative source of conformance obligations.</para>
  </chapter>
  <chapter>
    <title>Hash Functions</title>
    <para>This chapter defines the hash functions and their corresponding algorithm OIDs that
      devices shall support when implementing hash-based operations.</para>
    <table xml:id="hashTable">
      <title>Hash Functions and Algorithm OIDs</title>
      <tgroup cols="5">
        <colspec colname="c1" colwidth="14*"/>
        <colspec colname="c2" colwidth="18*"/>
        <colspec colname="c3" colwidth="10*"/>
        <colspec colname="c4" colwidth="24*"/>
        <colspec colname="c5" colwidth="16*"/>
        <thead>
          <row>
            <entry><para>Scheme Category</para></entry>
            <entry><para>Algorithm</para></entry>
            <entry><para>Size</para></entry>
            <entry><para>OID</para></entry>
            <entry><para>Reference</para></entry>
          </row>
        </thead>
        <tbody valign="top">
          <row>
            <entry morerows="2"><para>SHA-2</para></entry>
            <entry><para>SHA-256</para></entry>
            <entry><para>256 Bit</para></entry>
            <entry><para>2.16.840.1.101.3.4.2.1</para></entry>
            <entry><para>FIPS 180-4</para></entry>
          </row>
          <row>
            <entry><para>SHA-384</para></entry>
            <entry><para>384 Bit</para></entry>
            <entry><para>2.16.840.1.101.3.4.2.2</para></entry>
            <entry><para>FIPS 180-4</para></entry>
          </row>
          <row>
            <entry><para>SHA-512</para></entry>
            <entry><para>512 Bit</para></entry>
            <entry><para>2.16.840.1.101.3.4.2.3</para></entry>
            <entry><para>FIPS 180-4</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
  </chapter>
  <chapter>
    <title>Symmetric Encryption</title>
    <para>The following table specifies the symmetric encryption algorithms that a device shall
      support when implementing symmetric encryption operations.</para>
    <table xml:id="symTable">
      <title>Symmetric Encryption Schemes</title>
      <tgroup cols="5">
        <colspec colname="c1" colwidth="16*"/>
        <colspec colname="c2" colwidth="10*"/>
        <colspec colname="c3" colwidth="24*"/>
        <colspec colname="c4" colwidth="12*"/>
        <colspec colname="c5" colwidth="26*"/>
        <thead>
          <row>
            <entry><para>Algorithm</para></entry>
            <entry><para>Key Length</para></entry>
            <entry><para>OID</para></entry>
            <entry><para>Reference</para></entry>
            <entry><para>Usage</para></entry>
          </row>
        </thead>
        <tbody valign="top">
          <row>
            <entry><para>AES-GCM</para></entry>
            <entry><para>128 Bit</para></entry>
            <entry><para>2.16.840.1.101.3.4.1.6</para></entry>
            <entry><para>RFC 5116</para></entry>
            <entry><para>General symmetric encryption</para></entry>
          </row>
          <row>
            <entry><para>AES-CTR</para></entry>
            <entry><para>128 Bit</para></entry>
            <entry><para>—</para></entry>
            <entry><para>NIST SP 800-38A</para></entry>
            <entry><para>Recording content encryption</para></entry>
          </row>
          <row>
            <entry><para>AES-CBC</para></entry>
            <entry><para>128 Bit</para></entry>
            <entry><para>2.16.840.1.101.3.4.1.2</para></entry>
            <entry><para>RFC 7292</para></entry>
            <entry><para>Private key wrapping (PKCS#12)</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
  </chapter>
  <chapter>
    <title>Public Key Cryptography</title>
    <section>
      <title>Asymmetric Key Schemes</title>
      <para>The following table specifies the requirements for public key encryption and key
        agreement schemes that a product shall support when implementing public key cryptography.</para>
      <table xml:id="_Ref395173040">
        <title>Asymmetric Key Schemes</title>
        <tgroup cols="4">
          <colspec colname="c1" colwidth="52*"/>
          <colspec colname="c2" colwidth="12*"/>
          <colspec colname="c3" colwidth="12*"/>
          <colspec colname="c4" colwidth="12*"/>
          <thead>
            <row>
              <entry><para>Algorithm</para></entry>
              <entry><para>Key Length</para></entry>
              <entry><para>OID</para></entry>
              <entry><para>Reference</para></entry>
            </row>
          </thead>
          <tbody valign="top">
            <row>
              <entry><para>RSA</para></entry>
              <entry><para>3072 Bit</para></entry>
              <entry><para>1.2.840.113549.1.1.1</para></entry>
              <entry><para>RFC 8017</para></entry>
            </row>
            <row>
              <entry><para>RSA*</para></entry>
              <entry><para>4096 Bit</para></entry>
              <entry><para>1.2.840.113549.1.1.1</para></entry>
              <entry><para>RFC 8017</para></entry>
            </row>
            <row>
              <entry><para>secp256r1</para></entry>
              <entry><para>256 Bit</para></entry>
              <entry><para>1.2.840.10045.3.1.7</para></entry>
              <entry><para>RFC 5480</para></entry>
            </row>
            <row>
              <entry><para>secp384r1</para></entry>
              <entry><para>384 Bit</para></entry>
              <entry><para>1.3.132.0.34</para></entry>
              <entry><para>RFC 5480</para></entry>
            </row>
            <row>
              <entry><para>secp521r1*</para></entry>
              <entry><para>521 Bit</para></entry>
              <entry><para>1.3.132.0.35</para></entry>
              <entry><para>RFC 5480</para></entry>
            </row>
          </tbody>
        </tgroup>
      </table>
      <para>Items marked with asterisk relate to public key usage in order to e.g. support signature
        verification. </para>
    </section>
    <section>
      <title>Digital Signatures</title>
      <para>This section defines the signature schemes and their corresponding algorithm OIDs that
        devices shall support when implementing digital signatures. The listed algorithm OIDs are
        applicable to certificate signatures as well as other cryptographic operations such as media
        signing and general-purpose digital signatures. The applicable hash algorithms are defined
        in <xref linkend="hashTable"/>.</para>
      <table xml:id="sigTable">
        <title>Signature Schemes and Algorithm OIDs</title>
        <tgroup cols="4">
          <colspec colname="c1" colwidth="16*"/>
          <colspec colname="c2" colwidth="24*"/>
          <colspec colname="c3" colwidth="22*"/>
          <colspec colname="c4" colwidth="20*"/>
          <thead>
            <row>
              <entry><para>Scheme Category</para></entry>
              <entry><para>Algorithm</para></entry>
              <entry><para>OID</para></entry>
              <entry><para>Reference</para></entry>
            </row>
          </thead>
          <tbody valign="top">
            <row>
              <entry morerows="2"><para>RSA PKCS#1 v1.5*</para></entry>
              <entry><para>sha256WithRSAEncryption</para></entry>
              <entry><para>1.2.840.113549.1.1.11</para></entry>
              <entry><para>RFC 4055, RFC 8017</para></entry>
            </row>
            <row>
              <entry><para>sha384WithRSAEncryption</para></entry>
              <entry><para>1.2.840.113549.1.1.12</para></entry>
              <entry><para>RFC 4055, RFC 8017</para></entry>
            </row>
            <row>
              <entry><para>sha512WithRSAEncryption</para></entry>
              <entry><para>1.2.840.113549.1.1.13</para></entry>
              <entry><para>RFC 4055, RFC 8017</para></entry>
            </row>
            <row>
              <entry><para>RSASSA-PSS</para></entry>
              <entry><para>rsassa-pss</para></entry>
              <entry><para>1.2.840.113549.1.1.10</para></entry>
              <entry><para>RFC 8017</para></entry>
            </row>
            <row>
              <entry morerows="2"><para>ECDSA</para></entry>
              <entry><para>ecdsa-with-SHA256</para></entry>
              <entry><para>1.2.840.10045.4.3.2</para></entry>
              <entry><para>RFC 5758, X9.62</para></entry>
            </row>
            <row>
              <entry><para>ecdsa-with-SHA384</para></entry>
              <entry><para>1.2.840.10045.4.3.3</para></entry>
              <entry><para>RFC 5758, X9.62</para></entry>
            </row>
            <row>
              <entry><para>ecdsa-with-SHA512</para></entry>
              <entry><para>1.2.840.10045.4.3.4</para></entry>
              <entry><para>RFC 5758, X9.62</para></entry>
            </row>
          </tbody>
        </tgroup>
      </table>
      <para>*Note: RSA signatures using PKCS#1 v1.5 padding are marked as Required for baseline conformance due to their widespread use in existing ONVIF specifications and implementations, particularly for certificate signatures. However, implementers are encouraged to use other required alternatives from the table for new implementations and signatures, as it provides stronger security posture.</para>
    </section>
  </chapter>
  <chapter>
    <title>Key Management</title>
    <section>
      <title>Key Derivation Functions</title>
      <para>This section defines the key derivation functions that products shall support when
        implementing key derivation.</para>
      <table xml:id="keyTable">
        <title>Key Derivation Functions</title>
        <tgroup cols="4">
          <colspec colname="c1" colwidth="15*"/>
          <colspec colname="c2" colwidth="12*"/>
          <colspec colname="c3" colwidth="12*"/>
          <colspec colname="c4" colwidth="12*"/>
          <thead>
            <row>
              <entry><para>Algorithm</para></entry>
              <entry><para>OID</para></entry>
              <entry><para>Reference</para></entry>
              <entry><para>Usage</para></entry>
            </row>
          </thead>
          <tbody valign="top">
            <row>
              <entry><para>PBKDF2</para></entry>
              <entry><para>1.2.840.113549.1.5.12</para></entry>
              <entry><para>RFC 8018 &amp; RFC 9579</para></entry>
              <entry><para>For password-based key derivation</para></entry>
            </row>
            <row>
              <entry><para>HKDF</para></entry>
              <entry><para>1.2.840.113549.1.9.16.3.28</para></entry>
              <entry><para>RFC 5869</para></entry>
              <entry><para>For random key derivation</para></entry>
            </row>
          </tbody>
        </tgroup>
      </table>
    </section>
  </chapter>
    <chapter>
      
        <title>Private Key Protection</title>
        <para>This section defines the algorithms used to protect private keys during transit between key generation to key upload.
          PBKDF2 (defined in <xref linkend="keyTable"/>) is used to derive the encryption key from
          a password, and AES-CBC (defined in <xref linkend="symTable"/>) is used to wrap
          the private key material in PKCS#12 format (RFC 7292).</para>
        <table xml:id="certTable">
          <title>Private Key Protection Algorithms</title>
          <tgroup cols="3">
            <colspec colname="c1" colwidth="2*"/>
            <colspec colname="c2" colwidth="1*"/>
            <colspec colname="c3" colwidth="2*"/>
            <thead>
              <row>
                <entry><para>Algorithm</para></entry>
                <entry><para>Reference</para></entry>
                <entry><para>Capability</para></entry>
              </row>
            </thead>
            <tbody valign="top">
              <row>
                <entry><para>PBKDF2 + AES-CBC</para></entry>
                <entry><para>RFC 8018</para></entry>
                <entry><para>PasswordBasedEncryptionAlgorithms</para></entry>
              </row>
            </tbody>
          </tgroup>
        </table>
      <para>Note that this covers PKCS#12
          key transport; device-internal at-rest key storage may use stronger direct encryption
          as required by the applicable profile specification.</para>
  </chapter>
  <chapter>
    <title>Authentication and Authorization</title>
    <section>
      <title>JSON Web Token (JWT)</title>
      <para>This section specifies the requirements for JWT signature algorithms used in ONVIF
        client authorization flows. The signature algorithms listed below depend on the digital
        signature schemes defined in <xref linkend="sigTable"/> and the hash functions defined in
        <xref linkend="hashTable"/>.</para>
      <table xml:id="jwtTable">
        <title>JWT Signature Algorithm Baseline</title>
        <tgroup cols="2">
          <colspec colname="c1" colwidth="15*"/>
          <colspec colname="c2" colwidth="12*"/>
          <thead>
            <row>
              <entry><para>Algorithm</para></entry>
              <entry><para>Reference</para></entry>
            </row>
          </thead>
          <tbody valign="top">
            <row>
              <entry><para>RS256</para></entry>
              <entry><para>RFC 7518</para></entry>
            </row>
            <row>
              <entry><para>ES256</para></entry>
              <entry><para>RFC 7518</para></entry>
            </row>
          </tbody>
        </tgroup>
      </table>
    </section>
  </chapter>
  <appendix xml:id="b14_55m_51d">
    <title>TLS Cipher Reference (Informative)</title>
    
    <para>This annex presents an informative guide to a small subset of cipher suites selected as part of the ONVIF standard.</para>
    <para>The following small subset of ciphers covering TLS 1.2 / 1.3 are based on the baseline defined in this document and match common practice by Cloudflare, Mozilla, and ciphersuite.info.</para>
    <para>While TLS 1.2 and 1.3 are both currently viable, TLS 1.3 is recommended. Note that the table is not ordered by cipher strength.</para>
    
    <table>
      <title>TLS 1.3 / 1.2 Cipher list</title>
      <tgroup cols="2">
        <colspec colname="c1" colwidth="35*"/>
        <colspec colname="c2" colwidth="65*"/>
        <thead>
          <row>
            <entry><para>Minimum Protocol</para></entry><entry><para>IANA Name</para></entry>
          </row>
        </thead>
        
        <tbody valign="top">
          <row>
            <entry><para>TLS 1.3</para></entry><entry><para>TLS_AES_128_GCM_SHA256</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.3</para></entry><entry><para>TLS_AES_256_GCM_SHA384</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.3</para></entry><entry><para>TLS_CHACHA20_POLY1305_SHA256</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.2</para></entry><entry><para>TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.2</para></entry><entry><para>TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.2</para></entry><entry><para>TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.2</para></entry><entry><para>TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.2</para></entry><entry><para>TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384</para></entry>
          </row>
          <row>
            <entry><para>TLS 1.2</para></entry><entry><para>TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
  </appendix>
  <appendix>
    <title>Hybrid Public Key Encryption (Informative)</title>
    <para>This section lists the HPKE encryption baseline algorithms and provides references to the relevant IANA registry entries. The listed algorithms map to the definitions in the normative sections above.</para>
    <table frame="all">
      <title>HPKE KEM Identifiers</title>
      <tgroup cols="2">
        <colspec colname="c1" colnum="1" colwidth="1.0*"/>
        <colspec colname="c2" colnum="2" colwidth="1.0*"/>
        <thead>
          <row>
            <entry><para>IANA Identifier</para></entry>
            <entry><para>Algorithm</para></entry>
          </row>
        </thead>
        <tbody>
          <row>
            <entry><para>0x0010</para></entry>
            <entry><para>DHKEM(P-256, HKDF-SHA256)</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
    <table frame="all">
      <title>HPKE KDF Identifiers</title>
      <tgroup cols="2">
        <colspec colname="c1" colnum="1" colwidth="1.0*"/>
        <colspec colname="c2" colnum="2" colwidth="1.0*"/>
        <thead>
          <row>
            <entry><para>IANA Identifier</para></entry>
            <entry><para>Algorithm</para></entry>
          </row>
        </thead>
        <tbody>
          <row>
            <entry><para>1</para></entry>
            <entry><para>HKDF-SHA256</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
    <table frame="all">
      <title>HPKE AEAD Identifiers</title>
      <tgroup cols="2">
        <colspec colname="c1" colnum="1" colwidth="1.0*"/>
        <colspec colname="c2" colnum="2" colwidth="1.0*"/>
        <thead>
          <row>
            <entry><para>IANA Identifier</para></entry>
            <entry><para>Algorithm</para></entry>
          </row>
        </thead>
        <tbody>
          <row>
            <entry><para>2</para></entry>
            <entry><para>AES-256-GCM</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
  </appendix>
  <appendix>
    <title>Secure Streaming using SRTP (Informative)</title>
    <para>This section lists the security baseline algorithms for SRTP streaming and provides references to the relevant IANA registry entries. The listed algorithms map to the definitions in the normative sections above.</para>
    <table frame="all">
      <title>SRTP Identifiers</title>
      <tgroup cols="2">
        <colspec colname="c1" colnum="1" colwidth="1.0*"/>
        <colspec colname="c2" colnum="2" colwidth="1.0*"/>
        <thead>
          <row>
            <entry><para>Algorithm</para></entry>
            <entry><para>Reference</para></entry>
          </row>
        </thead>
        <tbody>
          <row>
            <entry><para>AEAD_AES_128_GCM</para></entry>
            <entry><para>RFC 7714</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
  </appendix>
  <appendix>
    <title>Baseline Usage by ONVIF Specifications</title>
    <para>The following table provides an informative mapping between ONVIF security use cases and
      the sections of this specification that define the required cryptographic primitives.
      Implementers should consult the referenced normative sections in conjunction with the
      corresponding ONVIF specification for each use case.</para>
    <table xml:id="usecaseTable">
    <title>Usecase to cryptographic baseline mapping</title>
      <tgroup cols="4">
        <colspec colname="c1" colwidth="22*"/>
        <colspec colname="c2" colwidth="20*"/>
        <colspec colname="c3" colwidth="36*"/>
        <colspec colname="c4" colwidth="22*"/>
        <thead>
          <row>
            <entry><para>ONVIF Use Case</para></entry>
            <entry><para>ONVIF Specification</para></entry>
            <entry><para>Required Sections</para></entry>
            <entry><para>Informative Annex</para></entry>
          </row>
        </thead>
        <tbody valign="top">
          <row>
            <entry><para>TLS mutual authentication</para></entry>
            <entry><para>Security Service</para></entry>
            <entry><para>Asymmetric Key Schemes, Digital Signatures, Hash Functions, Symmetric Encryption</para></entry>
            <entry><para>Annex A — TLS Cipher Reference</para></entry>
          </row>
          <row>
            <entry><para>X.509 certificate management and PKI</para></entry>
            <entry><para>Security Service</para></entry>
            <entry><para>Asymmetric Key Schemes, Digital Signatures, Hash Functions, Private Key Protection</para></entry>
            <entry><para>—</para></entry>
          </row>
          <row>
            <entry><para>JWT client authorization</para></entry>
            <entry><para>Security Service</para></entry>
            <entry><para>JSON Web Token (JWT), Digital Signatures, Hash Functions</para></entry>
            <entry><para>—</para></entry>
          </row>
          <row>
            <entry><para>Media signing</para></entry>
            <entry><para>Media Signing</para></entry>
            <entry><para>Digital Signatures, Hash Functions</para></entry>
            <entry><para>—</para></entry>
          </row>
          <row>
            <entry><para>Secure streaming (SRTP)</para></entry>
            <entry><para>Streaming</para></entry>
            <entry><para>Symmetric Encryption</para></entry>
            <entry><para>Annex C — Secure Streaming using SRTP</para></entry>
          </row>
          <row>
            <entry><para>Recording and data-at-rest encryption</para></entry>
            <entry><para>Recording Control</para></entry>
            <entry><para>Symmetric Encryption, Key Derivation Functions</para></entry>
            <entry><para>—</para></entry>
          </row>
          <row>
            <entry><para>Secure key encapsulation (HPKE)</para></entry>
            <entry><para>Various</para></entry>
            <entry><para>Asymmetric Key Schemes, Key Derivation Functions, Symmetric Encryption</para></entry>
            <entry><para>Annex B — Hybrid Public Key Encryption</para></entry>
          </row>
        </tbody>
      </tgroup>
    </table>
  </appendix>
  <appendix role="revhistory">
    <title>Revision History</title>
    <para/>
  </appendix>
</book>
