2.1 Executable Principles & Basis

Effective IK10 surveillance design is grounded in twelve executable principles derived from threat modeling, structural mechanics, cybersecurity practice, and field incident analysis. These principles are not aspirational guidelines but engineering requirements with verifiable acceptance criteria. Each principle is paired with a design basis that explains why it matters in adversarial environments.

1. Design for Adversary Time-Cost

Raise the effort needed to blind or destroy cameras. Every second an attacker spends increases exposure. Basis: threat modeling + field incidents.

2. IK10 is Necessary, Not Sufficient

Include anti-pry mounts, anti-pull cabling, and anti-occlusion detection. IK10 alone cannot stop dismantling or cable cut. Basis: failure analysis.

3. No Exposed Weak Points

Hide pigtails, screws, and connectors. Every exposed component is a potential attack vector. Basis: common attack vector analysis.

4. Cross-Coverage by Default

Every critical view has a witness view. If one camera is destroyed, another records the act and suspect trajectory. Basis: resilience design.

5. Tamper-to-Alarm Within 3–10 Seconds

Define and enforce alarm latency targets. Fast alarms enable fast response. Basis: operational response SLA requirements.

6. Two-Stage Evidence Preservation

Local buffer (SD card) + central recording for critical zones. Protects against link-cut scenarios. Basis: link-cut failure analysis.

7. Install Strength > Device Strength

Mount to structural substrate, not decorative panels. The weakest point determines the system's physical resilience. Basis: structural mechanics.

8. Minimize Maintenance Friction

Use standard fasteners, camera templates, and spare pools. Fast repair reduces blind time. Basis: maintainability engineering.

9. Security by Segmentation

Isolate camera VLAN, enforce least privilege, use certificates. Cyber attacks can disable recording as effectively as physical attacks. Basis: cybersecurity practice.

10. Measure What Matters

Track pixel density, retention completeness, alarm SLA, and MTTR. What is not measured cannot be improved. Basis: acceptance testing.

11. Environmental Hardening

Apply IP rating, corrosion resistance, vibration tolerance, and thermal margin. Environmental stress compounds adversarial damage. Basis: environmental engineering.

12. LCC Optimization

A cheaper camera with frequent replacement costs more over 5 years. Total cost of ownership includes truck rolls, downtime, and evidence gaps. Basis: lifecycle cost logic.

2.2 Failure Causes → Recommendations

Field deployments consistently reveal the same failure patterns. The table below maps each root cause to its failure mechanism, the recommended engineering countermeasure, and the verification method that confirms the fix has been properly implemented. These pairs represent the most impactful improvements available to designers and installers.

Failure CauseFailure MechanismRecommendationVerification
"IK10 camera, normal screws"Screws removed quickly with common toolsSecurity screws (Torx pin / tri-wing) + hidden fastenersAttempt removal with standard tools; should fail
Cable exposed under cameraPull/cut in seconds; no tools neededConduit to locked junction box; strain relief clampVisual inspection + tug test on cable
Camera mounted too lowReachable by hand; easy to grab and twistMount height policy (≥3.5 m) + protective cage where low ceilingMeasure height; simulate reach test
Over-sensitive tamper detectionFalse alarms cause operator fatigue; alarms ignoredProfile-based thresholds + debounce timers; day/night profilesOne-week alarm statistics; false alarm rate within threshold
No lighting considerationFace not identifiable at night; evidence unusableAdd supplemental lighting, WDR tuning, IR planningPixel density measurement at night; face ID test
Single uplink edge switchOne cut = entire zone blindDual uplink or ring topology; RSTP/ERPS protocolPull one uplink; verify reroute within seconds
Storage sized only for average loadBurst traffic drops frames at critical momentsIO headroom ≥30% + write cache; size for peak not averageStress test sustained write; verify no frame drops
No spare/repair SOPLong outage; extended blind zoneSpare camera pool + toolkits + documented SLADrill MTTR exercises; measure against P1/P2/P3 targets

2.3 Core Design / Selection Logic

The design decision process follows a structured sequence that begins with risk zoning and ends with acceptance test planning. The decision tree below provides a visual guide for selecting the appropriate camera type, mounting method, cabling approach, recording mode, and linkage level based on the specific characteristics of each zone.

IK10 Design Decision Tree
Figure 2.1: IK10 Surveillance Design Decision Tree — Zone Risk Assessment to Solution Selection

Step-by-Step Design Sequence

  1. Risk Zoning: Classify each area by threat level (adversarial / semi-adversarial / standard) and reachability (height, access control)
  2. Coverage & Pixel Density Targets: Define PPF requirements for identification (150–250 PPF) vs. overview (30–80 PPF) at each choke point
  3. Reachable vs. Non-reachable Mounting: Determine mounting height; add cages or recessed housings for reachable zones
  4. Anti-pull Cabling Route: Plan conduit paths; identify junction box locations; specify strain relief and sealing requirements
  5. Tamper Detection Profile: Configure occlusion, scene-change, and defocus sensitivity per zone; set debounce timers
  6. Redundancy Design: Assign witness cameras; define cross-coverage pairs; plan panoramic placement for overview
  7. Network/Power Resilience: Size PoE budget; plan dual uplinks or ring; size UPS for peak load × runtime target
  8. Storage Retention & Integrity: Calculate TB requirement with overhead factor; define RAID level; plan hot spares
  9. Acceptance Tests & O&M: Define test cases for each function; document SLAs; plan spare inventory and inspection schedule

Response Timeline Reference: T0 attack begins → T0+3s occlusion alarm → T0+5s strobe/siren linkage → T0+15s operator confirms via witness camera → T0+3min on-site response → T0+30min repair and restore → T+24h post-mortem and rule tuning.

IK10 Tamper Attack Response Timeline
Figure 2.2: IK10 Tamper Attack Response Timeline and Exception Chain Analysis

2.4 Key Dimensions

Effective design requires balancing seven key dimensions simultaneously. Each dimension has a primary optimization target, a typical metric, and a trade-off control mechanism. The table below provides a structured framework for making design decisions that account for all relevant dimensions rather than optimizing for a single factor.

DimensionWhat to OptimizeTypical MetricTrade-off Control
Performance / UXIdentification quality and search speedPPF at choke points, search latency, time-to-findIndexing, presets, UI optimization
ReliabilityContinuous recording without gapsUptime %, failover time, recording gap rateHA architecture, ring topology, UPS
MaintainabilityFast replacement and repairMTTR, standard parts availabilityCamera templates, spare pool, SOP
CompatibilityMulti-vendor interoperabilityONVIF profiles verified, API coverageLab test matrix before deployment
LCC (Lifecycle Cost)5-year total cost of ownership5-year TCO including truck rolls and downtimeReduce replacements; invest in quality mounts
Energy EfficiencyPoE and server power consumptionW/camera, kWh/year, PoE budget utilizationH.265 codecs, efficient IR, smart scheduling
CompliancePrivacy and audit requirementsAccess log completeness, masking coveragePolicy enforcement; regular privacy audits