Protocols About 2 min read

Video and media protocols

Video systems use separate paths for control, media, metadata and events. These references explain the protocols involved in each part.

Overview#

Use this section when implementing or reviewing camera, recorder, video management, intercom, or browser media integrations. It separates device/service control from session signalling, media transport, codec payloads, and application policy. Supporting one layer never implies support for the others.

Reading map#

Module Primary question Status covered
ONVIF How are conformant physical security devices discovered, configured, and controlled? Network Interface Specifications 26.06; active, release candidate, deprecated, and deprecating profiles as at 25 August 2026
GB/T 28181 How do Chinese public security video systems register, catalogue, signal, stream, and report events? GB/T 28181-2022 with related GB 35114-2017 security and GB/T 43026-2023 test context
RTSP, RTP, RTCP, and SDP How are stored/live sessions described, controlled, transported, and measured? RTSP 1.0 and 2.0; current RTP and SDP bases
WebRTC How is low latency encrypted browser/native real time media established? IETF WebRTC protocol suite and W3C WebRTC Recommendation
SIP and SRTP How do intercom and voice/video endpoints signal calls and protect media? SIP core, SRTP, and DTLS SRTP
Codecs and streaming How do codecs, packetisation, keyframes, bitrate, loss, latency, and adaptive delivery interact? H.264, H.265, AV1, JPEG, AAC, Opus, HLS, and MPEG DASH
SRT and RIST How do contribution links carry live media across impaired IP paths? SRT project protocol, the expired Internet Draft is not an IETF standard, and current VSF RIST profiles; neither is an ONVIF or evidence export replacement

Layer model#

  1. Discovery and management: ONVIF device/service APIs and product profiles.
  2. Session description and signalling: SDP, RTSP, SIP, or an application defined WebRTC signalling channel.
  3. Transport and feedback: RTP/RTCP, SRTP/SRTCP, WebRTC transports, or container/file transfer.
  4. Encoding: video and audio codecs plus their payload formats.
  5. Application policy: identity, authorisation, audit, retention, privacy, rate limits, and failure handling.

Treat every boundary as independently authenticated and authorised. A valid media URL, session identifier, ICE candidate, or SIP dialog identifier isn't an authorisation decision.

Integration defaults#

  • Prefer encrypted transports and authenticated discovery/control on managed networks.
  • Negotiate an explicit profile, codec, packetisation mode, clock rate, and transport; don't infer them from a file extension.
  • Bound parsers, jitter buffers, frame sizes, metadata, and session lifetime.
  • Keep credentials out of URLs, SDP, logs, packet captures, and example files.
  • Model reconnect, keyframe recovery, clock discontinuity, packet loss, duplicate control requests, and device restart.
  • Confirm claimed ONVIF conformance in ONVIF's registered product database; implementing a WSDL or endpoint alone isn't conformance.

Example and verification policy#

Examples in this section are documentation artefacts using synthetic addresses and identifiers. V1 on this index means its links and terminology were reviewed manually. Protocol pages use V2 where technical claims were checked against primary standards and a second official source. Environment specific compatibility or conformance requires its own evidence record.

Scope boundaries#

This section doesn't replace licensed standards, an ONVIF conformance test, codec patent/licensing advice, radio or privacy regulation, safety engineering, or vendor deployment guidance. General HTTP and messaging transports are in Web and messaging protocols.