Security features
Built-in security features protect TCC M devices, data, and communications across network, firmware, access control, and privacy aspects.
Encryption and authentication
To meet the increasing demand for security in AV and IT projects, Sennheiser developed the secure Sennheiser Sound Control Protocol (SSCv2). Among other security features, this protocol defines a REST API that allows the user to control the device using an end-to-end encrypted connection via TLS1.2 / TLS1.3 (HTTPS). In addition to encryption, SSCv2 also provides an authentication scheme. By using HTTP basic authentication, a compatible and well-established mechanism of username and password is employed to ensure that no unauthorized changes are made to the device’s settings and that no data is read from it. The SSCv2 protocol is used for local on-premises connections to the TeamConnect Ceiling Medium to allow for secure configuration of the device.
The TeamConnect Ceiling Medium supports Dante Media Encryption, allowing to safeguard media from interception or unauthorized access. The feature is available since firmware version 1.1.1. and protects the content of media flows using AES-256 encryption. Visit the Dante® documentation for more on how to configure and use it.
Password protection
Sennheiser implements authentication methods on devices and software, to ensure that only authenticated users can access the devices on the network. The TeamConnect Ceiling Medium device is protected with a strong password and requires authentication in the form of claiming of the device in Control Cockpit before use. When the device is used for the first time with the Sennheiser Control Cockpit, the default password must be changed before allowing configuration or monitoring. The device is muted in the factory default state, to ensure it cannot be operated unsecure in the network.
- Sennheiser control software Control Cockpit user interface, which can be accessed on the network, is password protected by default.
- 3rd party integrations are disabled by default. They must be explicitly enabled and authorized by the user and require authentication using credentials defined within the respective 3rd party module.
IEEE 802.1x
Sennheiser TeamConnect Ceiling Medium supports IEEE 802.1X, a port-based network access control mechanism that ensures devices obtain network access only after successful authentication. This mitigates unauthorized network use during installation and daily operation. TeamConnect Ceiling Medium implements 802.1X as a supplicant and can be onboarded into secured networks that enforce identity-based access. IEEE 802.1X can be configured via SSH and supports two authentication methods: EAP-TLS and EPA-PEAPv0/EAP-MSCHAPv2. For further information on configuration of 802.1X, please refer to TCC 802.1X Config Guide.
Firmware updates
The TeamConnect Ceiling Medium can be updated, ensuring that future vulnerabilities are resolved by providing security patches. The devices implement a secure firmware update, ensuring that only authorized firmware is installed and protecting against malicious tampering.
Physical security
To reduce the risk of theft, tampering, or accidental damage to the TeamConnect Ceiling Medium, the device’s mounting kit comes with secure mechanical fixation points and a safety ceiling fastener, which can be screwed to a suitable anchor.
Protect personal data
The TeamConnect Ceiling Medium does not store any personal data, ensuring that your privacy is protected. The Sennheiser Control Cockpit software does not store any personal data.
