Reference About 8 min read

Diagram index

Find diagrams of system components, responsibilities and data flows. These support the explanations in the wiki and require site specific engineering before installation use.

Overview#

The knowledge base uses fenced plain text figures so architecture remains readable in ordinary Markdown without a site generator. Figures explain roles and boundaries; they don't prescribe a product topology, pinout, electrical design, firewall rule, safety circuit, or command procedure.

Reading conventions#

Mark Meaning unless the page says otherwise
→ or ──> Direction of request, data, event, trust promotion, or intended flow, not necessarily a persistent connection
↔ Bidirectional exchange; does not imply equal authority or symmetric security
↓ Encapsulation, processing stage, dependency, or transition
[component] / named box Logical role, not necessarily a separate host/product
Dashed/logical boundary Trust, responsibility, or processing boundary; consult surrounding prose
Branch/state arrow Possible transition, not proof that every product supports it

Always read the text immediately before and after a figure. The canonical standard, product evidence, configuration, and environment validation record outrank a teaching diagram.

Orientation and foundations#

Page Figure focus Use it for
Physical security protocol landscape Layered integration path and cross domain map Locating protocols between physical interfaces, transport, application, system, and operations
Scope and boundaries Physical effect boundary Distinguishing research/observation from a real world control path
Architecture and layering Layer stack, encapsulation, profile/product chain Classifying a claim at the correct layer
Physical security system architecture Reference topology and shared services Identifying edge devices, controllers, management, integrations, and trust boundaries
Networking fundamentals End to end layered network path Separating link, IP, transport, TLS, and application failures
Trust boundaries and segmentation Zones and conduits Recording where identity, authority, and consequence cross a boundary
Architecture and layering Encapsulation versus semantic equivalence Avoiding the assumption that a gateway preserves every property
Credentials and identity media Subject to credential to reader to controller chain Finding where proof can be reduced to an identifier
Identity, authentication, and authorisation Identity decision and physical access chains Separating identity, authentication, policy, command, and observed result
Events, state, commands, and time State reconstruction and command lifecycle Preserving distinct occurrence, delivery, acceptance, and physical milestones
Encoding and serialisation Bytes to validated domain object pipeline Placing bounds, decoding, schema, and semantic validation
Interoperability, conformance, and profiles Capability record and conformance chain Turning broad support claims into testable product/role evidence
Media streaming fundamentals Capture, encode, signal, transport, decode path Locating media/control/security/capacity responsibilities
Multicast, discovery, and NAT Secure enrollment path Keeping discovery separate from trusted inventory and authorisation
Observability and evidence Layered health model Diagnosing service without collapsing link, protocol, data, and physical health
Ethernet, PoE, and power budgets End to end power chain Accounting for PSE, channel loss, PD, accessories, and degraded supply
Serial and field interfaces Multidrop bus record Separating electrical, wiring, UART, framing, and application layers
Dry contacts and supervised circuits Relay command versus physical feedback Avoiding “relay energized equals physical result”
TLS, PKI, and certificates Certificate/trust lifecycle Planning enrollment, validation, rotation, revocation, and recovery

Protocol figures, access control and credentials#

Page Figure focus Boundary highlighted
Access control protocol map Credential, reader, controller, PACS, and opening Medium, proof, link, decision, and physical effect are separate
OSDP Bus topology, frame/exchange, Secure Channel provisioning, ACU state RS485, protocol state, cryptographic state, and high impact output
Legacy reader interfaces Wiegand 26 bit layout and offline decode shape Bit format does not add link authentication or supervision
Contactless and smart card standards ISO layer map and APDU command/response shapes RF/contact transport is separate from credential application security
NFC, BLE, and UWB Multi radio layers and conceptual access state machine Discovery/range is not identity; reader/controller proof remains required
Credential formats and mobile credentials Assurance chain and static bit layout anatomy Namespace and cryptographic proof can be lost by output conversion

Protocol figures, video, media, web, and messaging#

Page Figure focus Boundary highlighted
Protocol families Protocol reference reading stack Physical/electrical, framing, transport, application, profile, product
ONVIF ONVIF service/discovery/media stack WS Discovery, SOAP services, media control, stream, and product profile
GB/T 28181 SIP domain registration, catalogue, signalling, events, and media path National application profile, platform/device role, media, and security requirements remain separate
RTSP, RTP, RTCP, and SDP On demand session sequence Control negotiation, SDP description, RTP media, RTCP telemetry
WebRTC Signaling, ICE/STUN/TURN, DTLS SRTP path Application signaling authority versus protected peer/relay media
SIP and SRTP Intercom call flow SIP signaling, SDP offer/answer, RTP/SRTP, and separately authorised door control
SRT and RIST Contribution sender/network/receiver boundary Recovery and transport security do not add entitlement, application authorisation, or evidential provenance
MQTT Broker architecture and topic hierarchy Producer/broker/consumer identities, sessions, retained state, and ACLs
AMQP 1.0 Container/session/link flow and settlement boundary Credit and delivery settlement remain distinct from downstream workflow and physical outcome
CoAP, OSCORE, and LwM2M Constrained exchange, proxy, object security, and management roles Transport ACK, object security, device management, and physical result are separate
CAP and EDXL emergency messaging Alert/update/cancel chain and EDXL distribution envelope Issuer, profile, geography, delivery, presentation, and activation remain separate evidence
SOAP and XML Envelope anatomy Transport, XML namespace/schema, SOAP headers/body, action and fault processing
WebSocket, SSE, and webhooks SSE event stream wire shape Long lived stream framing and event contract; not delivery durability

Protocol figures, alarm monitoring#

Page Figure focus Boundary highlighted
Alarm monitoring protocols Premises to receiver to automation path Transport/report acceptance, automation ingest, operator response, and dispatch
Contact ID / SIA DC05 DTMF communicator/receiver sequence Handshake/message/kissoff versus automation/operator handling
SIA AV01 Operator audio verification path Voice/DTMF, premises session, privacy, relay actuation
SIA DC03 Communicator to receiver framing path Message blocks, parser, acknowledgement, and security wrapper
SIA DC07 Receiver to automation feed Durable acceptance/backpressure and downstream routing
SIA DC09 IP alarm reporting path Sender/account identity, receiver ACK, encryption, retry, and dispatch boundary
IEC 60839 alarm transmission Premises, transmission network, receiving centre, and response boundaries Independently versioned IEC parts and national/product profiles must not be collapsed

Protocol figures, building, industrial, and legacy interoperability#

Page Figure focus Boundary highlighted
BACnet Secure Connect Node/hub/failover topology TLS/PKI secure link versus BACnet object/write semantics and legacy segments
Modbus family Application PDU mapped to serial/TCP/security carriers Shared function/register semantics do not equal identical transport/security
Modbus RTU RTU frame and receive state Inter character timing, address/function/data/CRC, bus/gateway behaviour
Modbus TCP MBAP/PDU over TCP stream TCP chunks are not message boundaries; transaction and unit IDs remain distinct
Matter Commissioner, fabric, controller, bridge, and node trust model Attestation, operational identity, ACL authorisation, application state, and physical outcome differ
IEC 60870-5-101 and -104 Telecontrol station/ASDU/gateway paths Serial/TCP carriers, addresses, cause, quality, time, security, and command authority remain explicit
IEC 61850 Logical model, SCL engineering, MMS, GOOSE, and SV paths Engineering configuration, client/server, multicast, security, and protection/control coupling differ
Enterprise federation with SAML and OIDC Identity provider, application, claims, and local role boundary Federation authentication never substitutes for local high impact authorisation
SCIM identity provisioning Authoritative identity, provisioning client/service, PACS adapter, and reconciliation API acceptance, source lifecycle, downstream state, and physical access rights differ
WebAuthn, FIDO, and passkeys Relying party, browser/client, authenticator, and recovery boundary Web authentication is distinct from PACS credential presentation and physical authorisation
Pelco D and Pelco P Legacy serial PTZ path Non normative legacy orientation and physical movement consequence
PSIA PLAI Logical area synchronisation path Identity/access semantics, synchronisation authority, and extension mapping

System figures, access control#

Page Figure focus
Access control systems End to end access decision chain
PACS architecture PACS services, controllers, readers, identity sources, operations
Panels, readers, and door I/O Controller/reader/input/output/lock feedback chain
Credential lifecycle Proofing, issuance, activation, use, suspension/revocation, retirement
Mobile access Issuer/cloud/mobile/reader/controller path
Pedestrian portals, turnstiles, and interlocked doors Access grant, actuator, barrier/door state, occupancy, and passage chain
Offline operation and antipassback Online/offline authority, cache, reconciliation, antipassback state
Biometrics Capture/template/matcher/decision and privacy boundary
Locks, egress, and life safety Access command versus egress/fire/local hardware authority
Visitor, identity, and elevator integration Identity/visitor/PACS/lift integration and authority boundaries

System figures, integration platforms#

Page Figure focus
Integration platforms Cross domain adapter/broker/platform boundary
PSIM and command platforms Event correlation, operator workflow, commands, and system of record boundary
SIEM, SOAR, and case management Security event/case/automation path and actuation separation
BMS and SCADA integration Physical security to building/OT gateway and write authority
HR, identity, and visitor integration Joiner/mover/leaver and identity synchronisation boundaries
Cloud, mobile, and multi tenant platforms Tenant, regional cloud, mobile, edge, and dependency boundaries

System figures, intercom, intrusion, and perimeter#

Page Figure focus
Intercom system architecture Endpoint/call server/media/door/recording topology
Call routing, media, and door control Signaling/media route and separate physical control authorisation
Emergency phones, mass notification, and PA Emergency call/message sources, distribution, acknowledgement, and certified boundaries
Intrusion monitoring systems Sensor to panel to receiver to operator event lifecycle
Panels, zones, and sensors Detection/electrical zone/panel/event semantics
Communicators, receivers, and monitoring Supervised reporting, ACK, automation, and operator path
Duress, panic, and fire boundaries High impact alarm categories and dispatch/life safety separation
Perimeter security architecture Sensors/zones/analytics/command center/response boundary
ANPR/LPR systems Capture/OCR/match/event/retention pipeline
Gates, barriers, and vehicle access Credential/detection/controller/safety device/movement/feedback chain

System figures, video surveillance#

Page Figure focus
Video surveillance systems Capture, recording, viewing, event, and management paths
Cameras and encoders Optical capture through encoder, stream, metadata, and device services
Recording, storage, and retention Recording lifecycle and capacity relationship
Analytics and metadata Frames to model to metadata/event pipeline
PTZ and device I/O Command arbitration, motor/output actuation, and feedback
Health and service monitoring Layered health and service response workflow
Evidence export and integrity Export manifest, custody, validation, and release boundary

Data layouts, formulas, and record fixtures#

These fenced figures are useful references but aren't architecture diagrams.

Page Fixture
Legacy reader interfaces Synthetic 26 bit Wiegand layout and offline decoder shape
Contactless and smart card standards ISO 7816 APDU command/response field shapes and synthetic fixture
Credential formats and mobile credentials Static credential bit layout and safe record shape
SOAP and XML SOAP envelope fixture
MQTT event contract example Synthetic topic and event payload
Modbus read response example Synthetic byte sequence and field interpretation
Video bandwidth/storage lab Capacity formula and synthetic scenario worksheet
Media bandwidth and storage reference Unit safe formulas and synthetic calculation
Cabling, power, and distance caveats Voltage drop formulas and PoE budget chain
Integration readiness checklist Readiness evidence record template
Safety impact checklist High impact review record template

Code/protocol fixtures are also indexed by code example index.

What is intentionally not indexed as a diagram#

  • YAML front matter examples in the metadata policy;
  • citation format examples;
  • ordinary JSON/XML/SDP/HTTP/SIP message examples unless they materially illustrate a layout;
  • source code listings, which belong in the code example index;
  • tables that already serve as the clearer comparison form.

Maintenance checklist#

  • Add a page here only when a figure materially explains architecture, sequence, state, boundary, or data layout
  • Use a page level link so heading renames don't create fragile anchors
  • Describe the decision or boundary shown in the diagram
  • Keep figures text native and legible without rendering or color
  • Add a legend locally when arrows/boxes differ from the conventions above
  • Mark conceptual, synthetic, non normative, or release candidate content in surrounding prose
  • Never use a diagram as product support, conformance, electrical, safety, or deployment evidence
  • Reconcile this index during repository review after adding or removing a figure

Section overview · Wiki home