Design Methods
Chapter 2 · Unattended Surveillance Site Design Guide
2.1 Design Principles and Basis
Effective unattended surveillance design requires a set of actionable engineering principles that go beyond camera selection. These twelve principles are derived from field failure statistics, O&M cost analysis, resilience engineering practice, and security hardening standards. Each principle has a verifiable basis and a corresponding acceptance check.
1. Engineer the Station, Not the Camera
Allocate budget first to power, backhaul, enclosure, and grounding. Field data shows that most unattended site failures originate in infrastructure, not camera quality. Basis: O&M cost breakdown analysis.
2. Local-First Continuity
"Record locally, transmit selectively." Cellular links are unreliable in remote areas; local NVR ensures evidence is never lost due to backhaul outages. Basis: link availability statistics for remote cellular.
3. Graceful Degradation
Define which functions must survive worst-case conditions (e.g., at least one camera + alarms at minimum battery). Design load-shedding priority lists accordingly. Basis: resilience engineering principles.
4. Eliminate Single Points of Failure
For the core path: dual SIM, dual power paths, watchdog relays. Single-point failures on remote sites mean extended outages due to long dispatch times. Basis: availability target calculations.
5. Environmental Class Drives Materials
IP66/67 enclosures, anti-condensation measures, corrosion protection, and UV-resistant cables must be specified based on the site's environmental class, not a generic standard. Basis: IEC enclosure and cable standards.
6. Lightning is a System Problem
Effective protection requires bonding + SPD coordination + cable routing — not just adding an SPD. Every metallic element must be part of the equipotential bonding network. Basis: IEC 62305 and surge protection standards.
7. Security by Default
Deny-by-default firewall rules, certificate-based VPN, least-privilege access, and unique credentials per device. Remote sites are high-value targets for lateral movement attacks. Basis: OT/IoT hardening guides.
8. Maintainability is a Requirement
Modular connectors, labeled wiring, documented configurations, and remote reset capability reduce MTTR from days to hours. Design for "swap in 15 minutes" for core components. Basis: MTTR reduction economics.
9. Measure Everything
Monitor power (V/I/SoC), link (latency/loss/RSSI), storage (SMART), temperature/humidity, and reboot counts. Unmonitored parameters become surprise failures. Basis: observability engineering practice.
10. Test Like the Field
Simulate link loss, low battery, surge events (safe), and remote recovery drills during acceptance. Acceptance tests that don't simulate real failure modes provide false confidence. Basis: acceptance test integrity principles.
11. Policy-Driven Alarm Design
Map alarm priority to response resources and evidence packaging requirements. Alarm fatigue from false positives is a leading cause of security posture degradation at unattended sites. Basis: alarm management standards.
12. Lifecycle Cost Over Capex
Industrial-grade components cost more upfront but reduce truck rolls, replacement frequency, and energy consumption. For unattended points, OPEX typically exceeds CAPEX within 3–5 years. Basis: total cost of ownership analysis.
2.2 Failure Causes → Recommendations
The table below maps the most commonly observed field failures to their root mechanisms, avoidance recommendations, and verification methods. This failure-mode analysis forms the basis for the design checklist and acceptance test plan in Chapter 10.
| Observed Failure | Root Mechanism | Avoidance Recommendation | Verification Method |
|---|---|---|---|
| Reboots at night | Battery undervoltage under combined IR illuminator + PTZ heater load; undersized battery for worst-case winter night | Size battery for worst-case load including all IR and heater loads; implement staged load shedding with SoC thresholds | Overnight soak test with full load; record DC voltage and SoC trend; verify no reboot events in NVR log |
| Blurry or unusable evidence | Wrong FoV for identification distance; focus drift from thermal cycling; vibration from wind or machinery | FoV design using target pixel density calculation (PPM); rigid mount with anti-vibration pads; focus lock after commissioning | Target chart test at specified distance; photograph result and calculate pixel count; document with screenshot evidence |
| False alarms in rain / wind | Analytics not tuned for weather conditions; single-sensor video motion detection triggered by rain streaks or swaying vegetation | Multi-sensor correlation (video + radar/beam); weather filters; zone masking for vegetation; confidence scoring thresholds | Replay recorded rain/wind events through analytics; measure false alarm rate against acceptance threshold |
| Link flapping / intermittent | Marginal RF signal with insufficient antenna gain; poor antenna placement near metallic structures; single SIM with no failover | Site RF survey before installation; high-gain directional antenna; antenna diversity; dual-SIM failover from different carriers | Continuous ping + RSSI/RSRP logging over 7 days; review packet loss and failover event counts |
| Water ingress in cabinet | Improperly sized or untightened cable glands; condensation from temperature cycling without desiccant or breather valve | IP-rated glands sized to cable OD; desiccant packs with replacement schedule; breather valve; cabinet heater for cold climates | Humidity trend monitoring; quarterly visual inspection; spray test on cabinet seals during acceptance |
| Lightning damage | Inadequate equipotential bonding; long unprotected copper runs between pole and cabinet; SPD installed without proper grounding | Equipotential bonding of all metallic elements; SPDs at every cable entry point; prefer fiber for long runs to isolate surge paths | Ground resistance test report; bonding continuity check; SPD status indicator inspection after storm events |
| Storage silently fails | No SMART attribute monitoring; SD card or consumer HDD used in write-heavy 24/7 recording environment | Enterprise-grade SSD or surveillance-rated HDD; SMART monitoring with alerting; spare storage device in kit; proactive replacement schedule | SMART wear-level report at commissioning and quarterly; forced disk fault simulation test during acceptance |
| Unauthorized access | Default passwords left unchanged; management ports exposed on WAN; no VPN requirement enforced | Unique credentials per device; disable UPnP and unused services; VPN-only management access; MFA for platform accounts | Security audit checklist; port scan report showing only VPN port exposed; credential uniqueness verification |
2.3 Core Design / Selection Logic
The design process follows a structured decision sequence that converts site inputs into a solution blueprint. The flowchart below illustrates the key decision points and their branching logic. Each decision gate has defined inputs (from site survey), outputs (design requirements), and verification methods (acceptance tests).
Figure 2.1: Decision tree for unattended surveillance point design — from site assessment through power, backhaul, threat, evidence, environment, recording strategy, redundancy, and sensor decisions to final BoQ output
Key Decision Rules
The following conditional rules summarize the most impactful design decisions. Each rule is derived from the failure mode analysis in Section 2.2 and the scenario requirements in Chapter 3.
| Condition | Design Rule | Rationale |
|---|---|---|
| Cellular only; coverage uncertain | Enforce local NVR storage + event uplink; dual SIM from different carriers; high-gain antenna | Single cellular link has typical availability of 95–99%; insufficient for evidence-grade recording continuity |
| No AC mains power | Solar + battery sized for worst month (lowest irradiance + highest load); load shedding mandatory | Solar yield varies 3–5× between summer and winter; worst-month sizing prevents winter outages |
| High lightning density area | Upgrade grounding to low resistance target; add SPDs at every cable boundary; isolate long copper runs with fiber | Lightning damage is the leading cause of multi-device simultaneous failure at remote sites |
| Legal evidence required | Minimum pixel density per identification standard; retention policy enforced; watermarking/hash on evidence clips; audit log completeness | Evidence that cannot meet identification standards or has broken chain of custody is inadmissible |
| High false alarm risk (wildlife / weather) | Multi-sensor fusion (video + radar/beam); weather-adaptive thresholds; zone masking; confidence scoring | Alarm fatigue from false positives leads to ignored alarms; multi-sensor correlation reduces false positive rate by 60–90% |
| Long MTTR (remote location) | Dual WAN + dual power path; OOB management channel; pre-configured spare kit; remote reboot capability | Dispatch time to remote sites may be 4–48 hours; every remotely resolvable fault avoids a truck roll |
2.4 Key Design Dimensions
Every unattended surveillance design must be evaluated across seven key dimensions. These dimensions are not independent — trade-offs between them define the final solution architecture. The table below provides the evaluation framework used in Chapter 5 for product selection and in Chapter 10 for acceptance criteria definition.
Performance / Experience
Clarity at distance, night performance, PTZ responsiveness, event latency
Stability / Reliability
MTBF, surge tolerance, watchdog recovery, redundancy depth
Maintainability
Modular parts, standard connectors, remote reset, quick swap time
Compatibility / Expansion
ONVIF profiles, open API, VLAN/QoS support, storage scalability
Lifecycle Cost (LCC)
Power cost, truck roll frequency, spare strategy, warranty coverage
Energy & Sustainability
Solar sizing, sleep modes, low-power camera options, battery longevity
| Dimension | Key Metrics | Trade-off with Other Dimensions | Acceptance Check |
|---|---|---|---|
| Performance | Pixel density at target distance (PPM), SNR at minimum lux, PTZ preset accuracy | Higher resolution → higher bitrate → more storage and bandwidth cost | Target chart test; night field test; PTZ preset accuracy measurement |
| Stability | MTBF (hours), surge withstand level (kV), watchdog recovery time (s) | Higher redundancy → higher CAPEX; industrial-grade components → higher unit cost | WAN failover test; power cut test; surge inspection log |
| Maintainability | MTTR (hours), remote reboot success rate (%), swap time in drill (min) | Modular design → higher initial cost; labeled harness → installation time investment | Remote reboot drill; swap time measurement; config restore test |
| Compatibility | ONVIF profile compliance, API response time, VLAN tag support | Open standards → easier integration but may limit advanced features | ONVIF conformance test; API integration test; VLAN policy verification |
| LCC | 5-year TCO (CAPEX + OPEX), truck rolls per year, energy cost per site per year | Lower CAPEX often means higher OPEX; industrial grade pays back in 2–4 years | TCO model review; first-year O&M cost tracking |
| Energy | Solar autonomy days, battery cycle life, site power consumption (W) | More cameras → more power → larger solar array → higher cost and wind load | Power autonomy test; solar yield calculation vs actual; battery SoC trend |
| Compliance | IP rating, EMC class, safety certification, privacy zone coverage | Higher certification requirements → longer procurement lead times | Certification document review; privacy mask verification; EMC test report |
Design Checklist Reminder: Before finalizing any site design, verify that all twelve design principles have been addressed, the failure mode analysis has been reviewed for site-specific risks, the decision tree has been followed for all key choices, and all seven dimensions have been evaluated with explicit trade-off decisions documented. This documentation forms the basis of the design review and acceptance test plan.