Reference About 4 min read

Protocol layer and role matrix

Look up a technology's layer and role before comparing interfaces. Use the linked pages for the relevant protocol, codec, profile or system details.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Architectural mapping only; editions, options, security modes, transports, and product roles require exact verification.

Verification and testing

Overview#

A single solution typically uses several rows. “Over IP” isn't a complete protocol description, and technologies at different layers aren't alternatives.

Family Primary layer/model Typical roles Direction/model Common companions Canonical page
ONVIF Application profiles and web services Device, client, media service, recording/search, access roles Request/response plus events/media HTTP(S), SOAP/XML, WS Discovery, RTSP/RTP, MQTT conditionally ONVIF
GB/T 28181 Video surveillance application/domain protocol SIP domain, device, platform, catalogue/event/media roles Registration, catalogue/events, SIP session control, RTP media SIP, SDP, RTP/RTCP, XML, GB 35114 security GB/T 28181
RTSP Media session control Client and media server Stateful request/response SDP, RTP/RTCP, authentication, TLS in supported profiles RTSP/RTP/SDP
RTP/RTCP Real time media/data transport and control Sender, receiver, mixer/translator Usually datagram flows plus reports SDP, RTSP/SIP/WebRTC, SRTP RTSP/RTP/SDP
WebRTC Secure real time communications suite Browser/native peers and signaling/relay services Peer media/data with application defined signaling ICE, STUN, TURN, DTLS SRTP, SDP WebRTC
SIP Session signaling User agents, proxies, registrars, B2BUAs Request/response and dialogs SDP, RTP/SRTP, TLS, digest or deployment identity SIP and SRTP
SRT / RIST Media contribution transport families Sender/caller/listener or RIST sender/receiver roles Long lived contribution media flow with retransmission/recovery profile Encoded media, encryption/profile, network QoS, application authorisation SRT and RIST
OSDP Access peripheral application protocol Control panel and peripheral device Addressed bidirectional bus; poll/reply model Commonly RS485; Secure Channel OSDP
Wiegand interface Legacy electrical/data interface Reader to controller Primarily one way pulses Credential formats and vendor wiring Legacy reader interfaces
SIA DC09 Alarm transport/application framing Premises transmitter and central station receiver Supervised event delivery and acknowledgement IP transport; underlying SIA/contact formats as applicable DC09
SIA DC03 / DC05 Alarm message formats Alarm panel/transmitter and receiver Event records DC09, dial/receiver product transport Alarm protocols
IEC 60839-5 Alarm transmission system/equipment/network family Supervised premises, transmission network, receiving centre roles Requirements split across independently versioned parts National adoption, product profile, monitoring procedure IEC 60839 alarm transmission
HTTP/REST style APIs Web transport/application convention Client and server/resource service Request/response TLS, OAuth/OIDC, mTLS, JSON/XML, webhook HTTP and REST
SOAP/XML Contracted web services/serialisation Service client and server Request/response and extension frameworks HTTP(S), WSDL, WS-* SOAP and XML
MQTT Brokered application messaging Publisher, subscriber, broker Publish/subscribe with session/QoS semantics TCP, TLS, client identity, topic ACL, payload schema MQTT
AMQP 1.0 Message oriented application protocol Container, connection/session/link endpoints; sender and receiver Credit based links and settlement TCP, TLS, SASL, broker/router policy, application schema AMQP 1.0
CoAP / OSCORE / LwM2M Constrained REST like exchange, object security, and management profile Client/server; origin/proxy; LwM2M client/server/bootstrap roles Request/response, observe, block wise, managed objects UDP/TCP/WebSocket, DTLS/TLS, OSCORE, object model CoAP, OSCORE, and LwM2M
CAP / EDXL DE Emergency message and distribution envelope formats Alert issuer, aggregator, distributor, consumer Alert/update/cancel lifecycle and routed XML messages HTTPS/message transport, regional profile, XML signatures under explicit profile CAP and EDXL
WebSocket Full duplex application channel Client and server Long lived bidirectional messages HTTP upgrade, TLS, application authentication/schema WebSocket/SSE/webhook
Modbus RTU Industrial application protocol over serial framing Client/master and server/slave devices Request/reply Serial line, vendor register map Modbus RTU
Modbus/TCP Industrial application protocol over TCP Client and server Request/reply with transaction identifiers TCP/IP, segmentation; Modbus Security where supported Modbus/TCP
BACnet Building automation objects/services BACnet devices and clients; routers; management systems Request/reply, notifications, discovery BACnet/IP, MS/TP, or BACnet/SC data links BACnet family
BACnet/SC Secure BACnet data link Nodes and hubs TLS protected WebSocket connections BACnet application/network layers, PKI BACnet/SC
KNX Building control application/system family Sensors, actuators, controllers, management tools Group communication and configuration TP/RF/IP/IPv6 media; Data/IP Secure where applicable KNX
OPC UA Information modeling and service framework Clients, servers, publishers/subscribers Services and PubSub models UA Secure Conversation, application certs, user identity OPC UA
IEC 60870-5-101/-104 Telecontrol application companion profiles Controlling station, controlled station, gateway ASDUs over serial or TCP profile IEC 62351 security, time/quality/address model IEC 60870-5-101 and -104
IEC 61850 Utility information model and communication mappings IEDs, clients/servers, publishers/subscribers, engineering tools MMS services plus GOOSE/SV multicast and SCL engineering Ethernet, time, IEC 62351, conformance/profile IEC 61850
Matter Fabric based IP application protocol Commissioner, controller, administrator, node, bridge Commissioning, cluster commands/attributes/events IPv6, Thread/WiFi/Ethernet, certificates, attestation, ACLs Matter
SAML / OIDC Enterprise federation protocols Identity provider/openid provider, service/relying party, client Assertions or authorisation code/token/user info flows HTTPS, metadata/JWKs, OAuth security profile, local role mapping Enterprise federation
SCIM Identity provisioning protocol/schema Provisioning client and service provider Resource CRUD, bulk/filter, cursor and event assisted reconciliation HTTPS, OAuth/mTLS profile, authoritative identity lifecycle SCIM
WebAuthn / CTAP Web authentication and authenticator protocol Relying party, client/browser, authenticator Challenge/response registration and authentication ceremonies HTTPS origin, FIDO credentials, CTAP transports, recovery policy WebAuthn and FIDO
SNMP Network/device management Manager and agent Polling plus notifications UDP/TCP profiles; SNMPv3 security Monitoring/admin
Syslog Event/log transport and message format family Originator, relay, collector Push/event stream UDP/TCP/TLS profiles, time and integrity pipeline Monitoring/admin
NTP/NTS/PTP Time distribution Clients/servers or clock hierarchy Request/response or precision time messages DNS, PKI/keys, network timing design Time
TLS Secure transport/session Client and server peers Authenticated protected channel TCP/application protocol, X.509/PKI, sometimes PSK TLS

Questions the matrix can't answer#

  • Which product role and optional features are actually supported?
  • Is the secure mode enabled with an acceptable key lifecycle?
  • What semantics and safety consequence does a field or command carry?
  • Can an event be replayed, duplicated, reordered, or lost?
  • Which component remains authoritative during partitions?
  • Is a product licensed and conformant for the exact firmware version?

Resolve those questions in the linked family page, applicable system page, product documentation, and an approved environment validation record.

Section overview · Wiki home