Reference About 4 min read
Protocol layer and role matrix
Look up a technology's layer and role before comparing interfaces. Use the linked pages for the relevant protocol, codec, profile or system details.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Architectural mapping only; editions, options, security modes, transports, and product roles require exact verification.
On this page
Overview#
A single solution typically uses several rows. “Over IP” isn't a complete protocol description, and technologies at different layers aren't alternatives.
| Family | Primary layer/model | Typical roles | Direction/model | Common companions | Canonical page |
|---|---|---|---|---|---|
| ONVIF | Application profiles and web services | Device, client, media service, recording/search, access roles | Request/response plus events/media | HTTP(S), SOAP/XML, WS Discovery, RTSP/RTP, MQTT conditionally | ONVIF |
| GB/T 28181 | Video surveillance application/domain protocol | SIP domain, device, platform, catalogue/event/media roles | Registration, catalogue/events, SIP session control, RTP media | SIP, SDP, RTP/RTCP, XML, GB 35114 security | GB/T 28181 |
| RTSP | Media session control | Client and media server | Stateful request/response | SDP, RTP/RTCP, authentication, TLS in supported profiles | RTSP/RTP/SDP |
| RTP/RTCP | Real time media/data transport and control | Sender, receiver, mixer/translator | Usually datagram flows plus reports | SDP, RTSP/SIP/WebRTC, SRTP | RTSP/RTP/SDP |
| WebRTC | Secure real time communications suite | Browser/native peers and signaling/relay services | Peer media/data with application defined signaling | ICE, STUN, TURN, DTLS SRTP, SDP | WebRTC |
| SIP | Session signaling | User agents, proxies, registrars, B2BUAs | Request/response and dialogs | SDP, RTP/SRTP, TLS, digest or deployment identity | SIP and SRTP |
| SRT / RIST | Media contribution transport families | Sender/caller/listener or RIST sender/receiver roles | Long lived contribution media flow with retransmission/recovery profile | Encoded media, encryption/profile, network QoS, application authorisation | SRT and RIST |
| OSDP | Access peripheral application protocol | Control panel and peripheral device | Addressed bidirectional bus; poll/reply model | Commonly RS485; Secure Channel | OSDP |
| Wiegand interface | Legacy electrical/data interface | Reader to controller | Primarily one way pulses | Credential formats and vendor wiring | Legacy reader interfaces |
| SIA DC09 | Alarm transport/application framing | Premises transmitter and central station receiver | Supervised event delivery and acknowledgement | IP transport; underlying SIA/contact formats as applicable | DC09 |
| SIA DC03 / DC05 | Alarm message formats | Alarm panel/transmitter and receiver | Event records | DC09, dial/receiver product transport | Alarm protocols |
| IEC 60839-5 | Alarm transmission system/equipment/network family | Supervised premises, transmission network, receiving centre roles | Requirements split across independently versioned parts | National adoption, product profile, monitoring procedure | IEC 60839 alarm transmission |
| HTTP/REST style APIs | Web transport/application convention | Client and server/resource service | Request/response | TLS, OAuth/OIDC, mTLS, JSON/XML, webhook | HTTP and REST |
| SOAP/XML | Contracted web services/serialisation | Service client and server | Request/response and extension frameworks | HTTP(S), WSDL, WS-* | SOAP and XML |
| MQTT | Brokered application messaging | Publisher, subscriber, broker | Publish/subscribe with session/QoS semantics | TCP, TLS, client identity, topic ACL, payload schema | MQTT |
| AMQP 1.0 | Message oriented application protocol | Container, connection/session/link endpoints; sender and receiver | Credit based links and settlement | TCP, TLS, SASL, broker/router policy, application schema | AMQP 1.0 |
| CoAP / OSCORE / LwM2M | Constrained REST like exchange, object security, and management profile | Client/server; origin/proxy; LwM2M client/server/bootstrap roles | Request/response, observe, block wise, managed objects | UDP/TCP/WebSocket, DTLS/TLS, OSCORE, object model | CoAP, OSCORE, and LwM2M |
| CAP / EDXL DE | Emergency message and distribution envelope formats | Alert issuer, aggregator, distributor, consumer | Alert/update/cancel lifecycle and routed XML messages | HTTPS/message transport, regional profile, XML signatures under explicit profile | CAP and EDXL |
| WebSocket | Full duplex application channel | Client and server | Long lived bidirectional messages | HTTP upgrade, TLS, application authentication/schema | WebSocket/SSE/webhook |
| Modbus RTU | Industrial application protocol over serial framing | Client/master and server/slave devices | Request/reply | Serial line, vendor register map | Modbus RTU |
| Modbus/TCP | Industrial application protocol over TCP | Client and server | Request/reply with transaction identifiers | TCP/IP, segmentation; Modbus Security where supported | Modbus/TCP |
| BACnet | Building automation objects/services | BACnet devices and clients; routers; management systems | Request/reply, notifications, discovery | BACnet/IP, MS/TP, or BACnet/SC data links | BACnet family |
| BACnet/SC | Secure BACnet data link | Nodes and hubs | TLS protected WebSocket connections | BACnet application/network layers, PKI | BACnet/SC |
| KNX | Building control application/system family | Sensors, actuators, controllers, management tools | Group communication and configuration | TP/RF/IP/IPv6 media; Data/IP Secure where applicable | KNX |
| OPC UA | Information modeling and service framework | Clients, servers, publishers/subscribers | Services and PubSub models | UA Secure Conversation, application certs, user identity | OPC UA |
| IEC 60870-5-101/-104 | Telecontrol application companion profiles | Controlling station, controlled station, gateway | ASDUs over serial or TCP profile | IEC 62351 security, time/quality/address model | IEC 60870-5-101 and -104 |
| IEC 61850 | Utility information model and communication mappings | IEDs, clients/servers, publishers/subscribers, engineering tools | MMS services plus GOOSE/SV multicast and SCL engineering | Ethernet, time, IEC 62351, conformance/profile | IEC 61850 |
| Matter | Fabric based IP application protocol | Commissioner, controller, administrator, node, bridge | Commissioning, cluster commands/attributes/events | IPv6, Thread/WiFi/Ethernet, certificates, attestation, ACLs | Matter |
| SAML / OIDC | Enterprise federation protocols | Identity provider/openid provider, service/relying party, client | Assertions or authorisation code/token/user info flows | HTTPS, metadata/JWKs, OAuth security profile, local role mapping | Enterprise federation |
| SCIM | Identity provisioning protocol/schema | Provisioning client and service provider | Resource CRUD, bulk/filter, cursor and event assisted reconciliation | HTTPS, OAuth/mTLS profile, authoritative identity lifecycle | SCIM |
| WebAuthn / CTAP | Web authentication and authenticator protocol | Relying party, client/browser, authenticator | Challenge/response registration and authentication ceremonies | HTTPS origin, FIDO credentials, CTAP transports, recovery policy | WebAuthn and FIDO |
| SNMP | Network/device management | Manager and agent | Polling plus notifications | UDP/TCP profiles; SNMPv3 security | Monitoring/admin |
| Syslog | Event/log transport and message format family | Originator, relay, collector | Push/event stream | UDP/TCP/TLS profiles, time and integrity pipeline | Monitoring/admin |
| NTP/NTS/PTP | Time distribution | Clients/servers or clock hierarchy | Request/response or precision time messages | DNS, PKI/keys, network timing design | Time |
| TLS | Secure transport/session | Client and server peers | Authenticated protected channel | TCP/application protocol, X.509/PKI, sometimes PSK | TLS |
Questions the matrix can't answer#
- Which product role and optional features are actually supported?
- Is the secure mode enabled with an acceptable key lifecycle?
- What semantics and safety consequence does a field or command carry?
- Can an event be replayed, duplicated, reordered, or lost?
- Which component remains authoritative during partitions?
- Is a product licensed and conformant for the exact firmware version?
Resolve those questions in the linked family page, applicable system page, product documentation, and an approved environment validation record.