Integration & Gateways · Study deck
Choosing an IoT Protocol Stack
Choose a complete message path by testing requirements, comparing evidence, and recording responsibility at every boundary.
Gateway Gus is your guide for this deck.

After studying this chapter
Learning objectives
A protocol recommendation needs requirements, field evidence, and a plan for changed assumptions.
- Hard requirements remove unsuitable candidates.Coverage, timing, power, mobility, and ownership constraints must become gates before attractive features influence the selection.
- A recommendation must cover the complete operated stack.Application, transport, network, link, security, gateway, and monitoring assumptions belong in the same comparison.
- Gateway duties need explicit evidence and ownership.Translation, buffering, credentials, freshness, and failure behavior can change the meaning of a successful message transfer.
- The selection record must include reasons to reopen the choice.Changed coverage, battery behavior, traffic, or ownership can invalidate the assumptions that supported the original recommendation.
Major section
Start With One Message That Has to Survive the Field
The asset tag needs a working message path across the warehouse and yard.
- The message family determines what the path must carry.The asset tag needs position reports and a departure alarm, with different consequences if delivery fails.
- The route must satisfy concrete deployment requirements.Payload size, arrival deadline, travel area, mobility, and battery goal are recorded as hard constraints.
- A failed hard gate removes a candidate.Missing yard coverage or excessive power consumption can prevent a path from supporting the required service.
- The installed path needs an operating owner.Fixed equipment and continuing service costs must have named responsibility before the team accepts the selection.
Major section
Field Trials Along the Shipment Route
A field trial must exercise the failures that could defeat the message.
- The final enclosure and antenna belong in the route test.Installed performance needs evidence from the configuration that will travel between the warehouse and yard.
- Failure trials must exercise weak and missing coverage.The selected path must be checked when a weak area or lost connection threatens the departure alarm.
- Receiver evidence must confirm the alarm’s arrival.A transmitting device alone cannot establish that the required warning reached the far end of the path.
- Recovery and recurring costs belong in the selection record.The field trial records who fixes failures and what continuing costs remain after installation.
Major section
Overview: Protocol Selection Starts With Gates, Not Favorites
This gate diagram checks traffic and responsibility before selection; follow the checks into the decision and recheck loop.
- The traffic-fit gate connects candidates to message requirements.The selection starts with payload, timing, coverage, and power evidence for the actual message family.
- The coexistence gate needs evidence of shared operation.The communication path must work alongside other traffic before the candidate reaches the selection decision.
- Boundary and lifecycle checks assign operating responsibilities.Gateway duties and continuing ownership must be visible before the team accepts the complete stack.
- Recheck triggers return changed assumptions to review.Coverage failure, battery misses, or ownership changes can require another selection pass after rollout.
Activity 1 · Draw it
✎ Build the selection gates

I want you to remove impossible paths before comparing attractive features.
Draw a selection path for the moving asset tag. Put hard requirements before candidate comparison. Add the field evidence needed at the decision and a return arrow for a changed assumption.
3 minutes · Pen and paper · Answer: Activity 1
Major section
Each Radio Choice Changes the Constraints
Each radio option shifts the constraints that the deployment must satisfy.
- BLE can satisfy power needs while depending on reader coverage.The warehouse and yard still need enough phones, readers, or gateways to make the location evidence useful.
- Wi-Fi capacity does not establish battery or roaming fit.Richer payload support can coexist with a failure to meet the moving tag’s power and mobility requirements.
- LoRaWAN requires gateway and server decisions.Yard coverage must be reviewed alongside gateway placement, network-server ownership, downlink limits, and alarm latency.
- Cellular introduces continuing service assumptions.Carrier coverage, subscriptions, credentials, and replacement plans become part of the complete operated path.
Major section
Gateway Duties and Message Consequences
Evaluate the complete stack and the team that will operate its boundaries.
- A gateway can simplify the path while adding responsibilities.Translation also brings buffering, credentials, and monitoring duties that need an owner and supporting evidence.
- Telemetry and commands need different failure reviews.A battery sensor’s rare report and a door-lock command have different timing needs and consequences of loss.
- Familiar protocols can fail deployment-specific gates.Firewall traversal, range, offline behavior, or operations support can disqualify a path that works in tutorials.
- Surviving stacks need comparable operating evidence.Device, gateway, security, and operations records make the comparison about deployed behavior rather than protocol labels.
Major section
The Decision Brief Preserves the Reasoning
A short decision record preserves the reasoning needed for the next review.
- Rejected candidates need an explicit reason.The brief names the hard requirement each removed option could not satisfy, such as coverage or battery life.
- Each finalist needs supporting field evidence.The pilot or route trace must show why the complete stack remains plausible under actual deployment conditions.
- The primary choice needs assumptions and a review trigger.The recommendation states what was selected and which changed condition would reopen the decision.
- The record must remain useful after rollout.Firmware, coverage, traffic, provider, firewall, or ownership changes can require the team to revisit the same evidence.
Major section
Practitioner: Build the Protocol Selection Record
The campus leak-sensor example turns the selection workflow into a reviewable recommendation.
- The message family must distinguish telemetry from alarms.The campus sensors send rare reports but also need an urgent warning path when a leak occurs.
- Deployment gates must precede candidate comparison.Battery operation, closet coverage, alarm delivery, gateway ownership, and stale-data behavior constrain the shortlist.
- A complete stack must show where responsibility changes hands.The review records device, gateway, network, security, and operations duties rather than one application protocol name.
- The decision brief must make acceptance reviewable.The selected stack, rejected alternatives, pilot check, risk limit, and recheck trigger belong in the final record.
Major section
Campus Coverage Shapes the Shortlist
The leak-sensor shortlist remains conditional until the actual closets have been tested.
- Uneven closet coverage makes gateway placement a selection issue.The team needs coverage evidence before protocol preferences can decide the campus deployment path.
- Several low-power paths can remain plausible.Low-power wide-area and local mesh candidates with gateways survive as complete deployment stacks for further comparison.
- Operating effort helps distinguish the surviving paths.Device power, installation work, gateway monitoring, and support ownership must be compared using evidence from the deployment.
- High-throughput choices can fail the battery workload gate.Continuously connected stacks may leave the shortlist when they cannot support the campus sensors’ required service.
Major section
The Campus Gateway Owns Evidence
Gateway behavior becomes part of the evidence supporting the leak-alarm service.
- The gateway must authenticate upstream and handle interruptions.The campus example gives the gateway responsibility for briefly buffering alarms as part of the trusted message path.
- Timestamps and stale-state reports expose missing freshness.Received-event times help distinguish a current reading from a delayed event or a device that has stopped reporting.
- Credentials and alerts require named owners.Credential management, alarm responsibility, and retry visibility must be assigned before the boundary record is complete.
- Pilot evidence can reopen the stack decision.Changed closet coverage, battery behavior, ownership, or alarm timing requires another review of the selection assumptions.
Activity 2 · Predict
✎ Move the pilot into the plant

I want you to find the evidence gap when a working pilot changes networks.
A gateway publishes successfully in the lab. Production requires segmentation approval and a different credential owner. Write which result remains useful, what remains unproven, and what the decision record must add.
3 minutes · Pen and paper · Answer: Activity 2
Major section
Under the Hood: Boundaries, Tradeoffs, and Recheck Triggers
Boundary records expose assumptions that a protocol label cannot settle.
- The device-to-link boundary must fit the workload.Radio power, packet size, sleep behavior, airtime, and retry policy determine whether the field device can sustain the path.
- Gateways and brokers need explicit operating duties.Translation, buffering, authentication, naming, and monitoring require a runbook, policy, and responsible owner.
- Network and security boundaries must permit real operation.Firewalls, NAT, roaming, segmentation, and credential rotation can prevent a laboratory stack from operating in production.
- The application must explain the received message’s status.Freshness, duplicates, missed messages, alarm escalation, and support ownership need receiver-side evidence.
Major section
Laboratory Success Has a Limited Scope
A successful laboratory message establishes only the conditions actually tested.
- A working demonstration can still miss the field power budget.Retries may drain the battery or drop alarms when the actual radio path differs from the laboratory setup.
- Hidden gateway failures can damage downstream evidence.Buffering or monitoring failures may leave readings stale or incomplete even when the dashboard continues to display data.
- Production policy can reject a laboratory communication path.Plant segmentation and credential ownership need evidence beyond the successful laboratory reachability test.
- The record must separate observations from assumptions.Operating limits and missing approvals must remain visible beside the pilot result until the deployment boundaries are checked.
Major section
Delivery, Support, and Recheck Triggers
Delivery behavior must support the application decision and survive changes in deployment conditions.
- Delivered bytes do not establish a trustworthy application result.Freshness, authorization, and command meaning need evidence beyond the delivery behavior of the selected protocol.
- The stack needs an operations team with defined duties.Monitoring, patching, and credential management must be supported before the system is considered production-ready.
- Changed deployment facts should reopen selection.Coverage failure, missed battery goals, new security constraints, and ownership changes can invalidate the original choice.
- New evidence can challenge an accepted recommendation.The recheck trigger lets the team review a failing assumption before recurring failures become normal operating behavior.
Deck summary
Key takeaways
The selected stack remains defensible when its requirements, evidence, owners, and recheck conditions remain visible.
- Hard deployment gates must come before feature comparisons.Coverage, timing, power, and ownership requirements remove candidates that cannot support the required message path.
- The recommendation must include every stack layer and operating duty.Application, transport, network, link, gateway, security, and operations assumptions remain attached to the selected path.
- Gateway and security boundaries are design responsibilities.Translation, buffering, credentials, monitoring, and stale-data behavior need explicit ownership and supporting evidence.
- The decision needs proof and a condition for review.Rejected options, pilot evidence, rollout limits, and recheck triggers make the selection useful when deployment facts change.
Retrieval practice
Recall check 1 of 3

Gateway Gus says: answer from memory, then check your reasoning.
Q1A team starts protocol selection by saying, "Use MQTT," before recording message timing, payload size, power source, gateway ownership, or failure impact. What should happen first?
Show answer
Answer: C A protocol recommendation should follow requirement gates and evidence comparison.
Retrieval practice
Recall check 2 of 3

Gateway Gus says: answer from memory, then check your reasoning.
Q2A protocol-selection record compares MQTT, CoAP, LoRaWAN, and cellular by name only, without gateway ownership, credential handling, stale-data behavior, or operations support. What is the main weakness?
Show answer
Answer: B Protocol selection must preserve stack, gateway, security, and operations evidence.
Retrieval practice
Recall check 3 of 3

Gateway Gus says: answer from memory, then check your reasoning.
Q3A pilot proves a sensor can publish through a gateway in the lab, but the production plant network requires segmentation approval and a different credential owner. What should the selection record do?
Show answer
Answer: D Lab success is useful evidence, but production network and credential boundaries must be gated explicitly.
Print reference
Answers
Answer key.
- C · A protocol recommendation should follow requirement gates and evidence comparison.
- B · Protocol selection must preserve stack, gateway, security, and operations evidence.
- D · Lab success is useful evidence, but production network and credential boundaries must be gated explicitly.
Print reference
Activity 1 answer
Model answer.
Draw it: The sketch gates coverage, timing, payload, power, mobility, and ownership before comparing complete stacks. The decision includes final-enclosure route and failure evidence. Coverage, battery, alarm timing, or ownership changes return the choice to review.
Print reference
Activity 2 answer
Model answer.
Predict: Keep the lab delivery result as bounded evidence. It does not prove production segmentation, allowed flows, credential lifecycle, monitoring, or support. Add those boundary records and owners before approving the production path.