Diagram index
Find diagrams of system components, responsibilities and data flows. These support the explanations in the wiki and require site specific engineering before installation use.
On this page
Overview#
The knowledge base uses fenced plain text figures so architecture remains readable in ordinary Markdown without a site generator. Figures explain roles and boundaries; they don't prescribe a product topology, pinout, electrical design, firewall rule, safety circuit, or command procedure.
Reading conventions#
| Mark | Meaning unless the page says otherwise |
|---|---|
→ or ──> |
Direction of request, data, event, trust promotion, or intended flow, not necessarily a persistent connection |
↔ |
Bidirectional exchange; does not imply equal authority or symmetric security |
↓ |
Encapsulation, processing stage, dependency, or transition |
[component] / named box |
Logical role, not necessarily a separate host/product |
| Dashed/logical boundary | Trust, responsibility, or processing boundary; consult surrounding prose |
| Branch/state arrow | Possible transition, not proof that every product supports it |
Always read the text immediately before and after a figure. The canonical standard, product evidence, configuration, and environment validation record outrank a teaching diagram.
Orientation and foundations#
| Page | Figure focus | Use it for |
|---|---|---|
| Physical security protocol landscape | Layered integration path and cross domain map | Locating protocols between physical interfaces, transport, application, system, and operations |
| Scope and boundaries | Physical effect boundary | Distinguishing research/observation from a real world control path |
| Architecture and layering | Layer stack, encapsulation, profile/product chain | Classifying a claim at the correct layer |
| Physical security system architecture | Reference topology and shared services | Identifying edge devices, controllers, management, integrations, and trust boundaries |
| Networking fundamentals | End to end layered network path | Separating link, IP, transport, TLS, and application failures |
| Trust boundaries and segmentation | Zones and conduits | Recording where identity, authority, and consequence cross a boundary |
| Architecture and layering | Encapsulation versus semantic equivalence | Avoiding the assumption that a gateway preserves every property |
| Credentials and identity media | Subject to credential to reader to controller chain | Finding where proof can be reduced to an identifier |
| Identity, authentication, and authorisation | Identity decision and physical access chains | Separating identity, authentication, policy, command, and observed result |
| Events, state, commands, and time | State reconstruction and command lifecycle | Preserving distinct occurrence, delivery, acceptance, and physical milestones |
| Encoding and serialisation | Bytes to validated domain object pipeline | Placing bounds, decoding, schema, and semantic validation |
| Interoperability, conformance, and profiles | Capability record and conformance chain | Turning broad support claims into testable product/role evidence |
| Media streaming fundamentals | Capture, encode, signal, transport, decode path | Locating media/control/security/capacity responsibilities |
| Multicast, discovery, and NAT | Secure enrollment path | Keeping discovery separate from trusted inventory and authorisation |
| Observability and evidence | Layered health model | Diagnosing service without collapsing link, protocol, data, and physical health |
| Ethernet, PoE, and power budgets | End to end power chain | Accounting for PSE, channel loss, PD, accessories, and degraded supply |
| Serial and field interfaces | Multidrop bus record | Separating electrical, wiring, UART, framing, and application layers |
| Dry contacts and supervised circuits | Relay command versus physical feedback | Avoiding “relay energized equals physical result” |
| TLS, PKI, and certificates | Certificate/trust lifecycle | Planning enrollment, validation, rotation, revocation, and recovery |
Protocol figures, access control and credentials#
| Page | Figure focus | Boundary highlighted |
|---|---|---|
| Access control protocol map | Credential, reader, controller, PACS, and opening | Medium, proof, link, decision, and physical effect are separate |
| OSDP | Bus topology, frame/exchange, Secure Channel provisioning, ACU state | RS485, protocol state, cryptographic state, and high impact output |
| Legacy reader interfaces | Wiegand 26 bit layout and offline decode shape | Bit format does not add link authentication or supervision |
| Contactless and smart card standards | ISO layer map and APDU command/response shapes | RF/contact transport is separate from credential application security |
| NFC, BLE, and UWB | Multi radio layers and conceptual access state machine | Discovery/range is not identity; reader/controller proof remains required |
| Credential formats and mobile credentials | Assurance chain and static bit layout anatomy | Namespace and cryptographic proof can be lost by output conversion |
Protocol figures, video, media, web, and messaging#
| Page | Figure focus | Boundary highlighted |
|---|---|---|
| Protocol families | Protocol reference reading stack | Physical/electrical, framing, transport, application, profile, product |
| ONVIF | ONVIF service/discovery/media stack | WS Discovery, SOAP services, media control, stream, and product profile |
| GB/T 28181 | SIP domain registration, catalogue, signalling, events, and media path | National application profile, platform/device role, media, and security requirements remain separate |
| RTSP, RTP, RTCP, and SDP | On demand session sequence | Control negotiation, SDP description, RTP media, RTCP telemetry |
| WebRTC | Signaling, ICE/STUN/TURN, DTLS SRTP path | Application signaling authority versus protected peer/relay media |
| SIP and SRTP | Intercom call flow | SIP signaling, SDP offer/answer, RTP/SRTP, and separately authorised door control |
| SRT and RIST | Contribution sender/network/receiver boundary | Recovery and transport security do not add entitlement, application authorisation, or evidential provenance |
| MQTT | Broker architecture and topic hierarchy | Producer/broker/consumer identities, sessions, retained state, and ACLs |
| AMQP 1.0 | Container/session/link flow and settlement boundary | Credit and delivery settlement remain distinct from downstream workflow and physical outcome |
| CoAP, OSCORE, and LwM2M | Constrained exchange, proxy, object security, and management roles | Transport ACK, object security, device management, and physical result are separate |
| CAP and EDXL emergency messaging | Alert/update/cancel chain and EDXL distribution envelope | Issuer, profile, geography, delivery, presentation, and activation remain separate evidence |
| SOAP and XML | Envelope anatomy | Transport, XML namespace/schema, SOAP headers/body, action and fault processing |
| WebSocket, SSE, and webhooks | SSE event stream wire shape | Long lived stream framing and event contract; not delivery durability |
Protocol figures, alarm monitoring#
| Page | Figure focus | Boundary highlighted |
|---|---|---|
| Alarm monitoring protocols | Premises to receiver to automation path | Transport/report acceptance, automation ingest, operator response, and dispatch |
| Contact ID / SIA DC05 | DTMF communicator/receiver sequence | Handshake/message/kissoff versus automation/operator handling |
| SIA AV01 | Operator audio verification path | Voice/DTMF, premises session, privacy, relay actuation |
| SIA DC03 | Communicator to receiver framing path | Message blocks, parser, acknowledgement, and security wrapper |
| SIA DC07 | Receiver to automation feed | Durable acceptance/backpressure and downstream routing |
| SIA DC09 | IP alarm reporting path | Sender/account identity, receiver ACK, encryption, retry, and dispatch boundary |
| IEC 60839 alarm transmission | Premises, transmission network, receiving centre, and response boundaries | Independently versioned IEC parts and national/product profiles must not be collapsed |
Protocol figures, building, industrial, and legacy interoperability#
| Page | Figure focus | Boundary highlighted |
|---|---|---|
| BACnet Secure Connect | Node/hub/failover topology | TLS/PKI secure link versus BACnet object/write semantics and legacy segments |
| Modbus family | Application PDU mapped to serial/TCP/security carriers | Shared function/register semantics do not equal identical transport/security |
| Modbus RTU | RTU frame and receive state | Inter character timing, address/function/data/CRC, bus/gateway behaviour |
| Modbus TCP | MBAP/PDU over TCP stream | TCP chunks are not message boundaries; transaction and unit IDs remain distinct |
| Matter | Commissioner, fabric, controller, bridge, and node trust model | Attestation, operational identity, ACL authorisation, application state, and physical outcome differ |
| IEC 60870-5-101 and -104 | Telecontrol station/ASDU/gateway paths | Serial/TCP carriers, addresses, cause, quality, time, security, and command authority remain explicit |
| IEC 61850 | Logical model, SCL engineering, MMS, GOOSE, and SV paths | Engineering configuration, client/server, multicast, security, and protection/control coupling differ |
| Enterprise federation with SAML and OIDC | Identity provider, application, claims, and local role boundary | Federation authentication never substitutes for local high impact authorisation |
| SCIM identity provisioning | Authoritative identity, provisioning client/service, PACS adapter, and reconciliation | API acceptance, source lifecycle, downstream state, and physical access rights differ |
| WebAuthn, FIDO, and passkeys | Relying party, browser/client, authenticator, and recovery boundary | Web authentication is distinct from PACS credential presentation and physical authorisation |
| Pelco D and Pelco P | Legacy serial PTZ path | Non normative legacy orientation and physical movement consequence |
| PSIA PLAI | Logical area synchronisation path | Identity/access semantics, synchronisation authority, and extension mapping |
System figures, access control#
| Page | Figure focus |
|---|---|
| Access control systems | End to end access decision chain |
| PACS architecture | PACS services, controllers, readers, identity sources, operations |
| Panels, readers, and door I/O | Controller/reader/input/output/lock feedback chain |
| Credential lifecycle | Proofing, issuance, activation, use, suspension/revocation, retirement |
| Mobile access | Issuer/cloud/mobile/reader/controller path |
| Pedestrian portals, turnstiles, and interlocked doors | Access grant, actuator, barrier/door state, occupancy, and passage chain |
| Offline operation and antipassback | Online/offline authority, cache, reconciliation, antipassback state |
| Biometrics | Capture/template/matcher/decision and privacy boundary |
| Locks, egress, and life safety | Access command versus egress/fire/local hardware authority |
| Visitor, identity, and elevator integration | Identity/visitor/PACS/lift integration and authority boundaries |
System figures, integration platforms#
| Page | Figure focus |
|---|---|
| Integration platforms | Cross domain adapter/broker/platform boundary |
| PSIM and command platforms | Event correlation, operator workflow, commands, and system of record boundary |
| SIEM, SOAR, and case management | Security event/case/automation path and actuation separation |
| BMS and SCADA integration | Physical security to building/OT gateway and write authority |
| HR, identity, and visitor integration | Joiner/mover/leaver and identity synchronisation boundaries |
| Cloud, mobile, and multi tenant platforms | Tenant, regional cloud, mobile, edge, and dependency boundaries |
System figures, intercom, intrusion, and perimeter#
| Page | Figure focus |
|---|---|
| Intercom system architecture | Endpoint/call server/media/door/recording topology |
| Call routing, media, and door control | Signaling/media route and separate physical control authorisation |
| Emergency phones, mass notification, and PA | Emergency call/message sources, distribution, acknowledgement, and certified boundaries |
| Intrusion monitoring systems | Sensor to panel to receiver to operator event lifecycle |
| Panels, zones, and sensors | Detection/electrical zone/panel/event semantics |
| Communicators, receivers, and monitoring | Supervised reporting, ACK, automation, and operator path |
| Duress, panic, and fire boundaries | High impact alarm categories and dispatch/life safety separation |
| Perimeter security architecture | Sensors/zones/analytics/command center/response boundary |
| ANPR/LPR systems | Capture/OCR/match/event/retention pipeline |
| Gates, barriers, and vehicle access | Credential/detection/controller/safety device/movement/feedback chain |
System figures, video surveillance#
| Page | Figure focus |
|---|---|
| Video surveillance systems | Capture, recording, viewing, event, and management paths |
| Cameras and encoders | Optical capture through encoder, stream, metadata, and device services |
| Recording, storage, and retention | Recording lifecycle and capacity relationship |
| Analytics and metadata | Frames to model to metadata/event pipeline |
| PTZ and device I/O | Command arbitration, motor/output actuation, and feedback |
| Health and service monitoring | Layered health and service response workflow |
| Evidence export and integrity | Export manifest, custody, validation, and release boundary |
Data layouts, formulas, and record fixtures#
These fenced figures are useful references but aren't architecture diagrams.
| Page | Fixture |
|---|---|
| Legacy reader interfaces | Synthetic 26 bit Wiegand layout and offline decoder shape |
| Contactless and smart card standards | ISO 7816 APDU command/response field shapes and synthetic fixture |
| Credential formats and mobile credentials | Static credential bit layout and safe record shape |
| SOAP and XML | SOAP envelope fixture |
| MQTT event contract example | Synthetic topic and event payload |
| Modbus read response example | Synthetic byte sequence and field interpretation |
| Video bandwidth/storage lab | Capacity formula and synthetic scenario worksheet |
| Media bandwidth and storage reference | Unit safe formulas and synthetic calculation |
| Cabling, power, and distance caveats | Voltage drop formulas and PoE budget chain |
| Integration readiness checklist | Readiness evidence record template |
| Safety impact checklist | High impact review record template |
Code/protocol fixtures are also indexed by code example index.
What is intentionally not indexed as a diagram#
- YAML front matter examples in the metadata policy;
- citation format examples;
- ordinary JSON/XML/SDP/HTTP/SIP message examples unless they materially illustrate a layout;
- source code listings, which belong in the code example index;
- tables that already serve as the clearer comparison form.
Maintenance checklist#
- Add a page here only when a figure materially explains architecture, sequence, state, boundary, or data layout
- Use a page level link so heading renames don't create fragile anchors
- Describe the decision or boundary shown in the diagram
- Keep figures text native and legible without rendering or color
- Add a legend locally when arrows/boxes differ from the conventions above
- Mark conceptual, synthetic, non normative, or release candidate content in surrounding prose
- Never use a diagram as product support, conformance, electrical, safety, or deployment evidence
- Reconcile this index during repository review after adding or removing a figure