Protocol infrastructure
Addressing, identity, time, power and administration support the main application. Use these references when checking the services and interfaces underneath an integration.
On this page
Overview#
These pages cover the foundations reused by cameras, controllers, intercoms, alarms, building systems, and gateways. “Uses IP,” “uses TLS,” or “has an RS485 port” is only a layer statement; the application protocol and operational contract still have to be identified.
| Concern | Reference |
|---|---|
| Ethernet, IPv4/IPv6, TCP/UDP, multicast, VLANs, NAT, segmentation | IP transport and segmentation |
| DHCP, DNS, mDNS/DNS SD, WS Discovery, LLDP | Discovery and addressing |
| NTP/NTS, PTP, monotonic and event time | Time synchronisation |
| SNMP, syslog, SSH/SFTP, secure management | Monitoring and secure administration |
| 802.1X/EAP/RADIUS, LDAP, Active Directory, Kerberos | AAA and network access |
| SAML 2.0, OpenID Connect, OAuth security, enterprise SSO | Enterprise federation with SAML and OIDC |
| SCIM provisioning, joiner/mover/leaver, reconciliation, asynchronous signals | SCIM identity provisioning |
| WebAuthn, FIDO2, CTAP, passkeys, cross device authentication | WebAuthn, FIDO, and passkeys |
| TLS, mutual TLS, X.509 and certificate operations | TLS, PKI, and secure transport |
| UART, TIA 232/422/485 and serial gateways | Serial transports |
| WiFi, Bluetooth, Zigbee, Thread, Z Wave, LoRaWAN, NFC | Wireless and low power links |
| PoE, USB, GPIO, relay and supervised circuits | Power, USB, and GPIO |
Shared rule#
For each dependency record protocol/version, endpoint and authenticated identity, addresses, ports/media, direction, expected rates, timeout/retry, maximum sizes, trust roots or keys, authorisation, clock dependency, monitoring, owner, safe failure, and recovery. Discovery output and source addresses populate candidates; they don't establish identity or authorisation.
Safety boundary#
Network scans, multicast discovery, time changes, AAA changes, serial attachment, radio commissioning, PoE cycling, USB insertion, GPIO drive, and relay operation can interrupt or actuate physical security systems. These references grant no authority for those actions. Use offline configuration review for research and the asset owner's approved commissioning process for environment acceptance.