Why should ciphers and IT managers consider a distributed network solution?
by Warren Brown*
For end users, it is the only solution that addresses all four priorities. For system integrators, this strategy avoids the use of labor and the headaches caused by manually built interfaces between independent systems.
Enterprise definition and distributed network architecture
A "company" is a company or organization made up of two or more facilities, either in the same location or separated from each other. A company could be several facilities grouped in the same area, for example, a hospital complex, where the main building is surrounded by clinics, offices, etc. Or, it could be a large multinational company made up of many buildings that can be hundreds, even thousands, of miles from each other.
The main elements of a distributed network architecture are I) the distribution of decision-making and control to each headquarters, and at the same time II) the simultaneous networking and synchronization of the different headquarters, through a distribution center.
What end users and integrators want
The distribution of decision-making and control to each headquarters is essential for two reasons. First, headquarters managers need flexibility to manage the specific security needs of their headquarters. From adding staff to modifying access rights, you need to have the ability to manage your system on a day-to-day basis, without fear of losing network connectivity or bandwidth to an external central server.
Secondly, from the point of view of scalability, a well-designed architecture avoids unnecessary data transmission and excessive bandwidth consumption; for example, adding a new contractor and assigning it access privileges at a single site should not require communication with a central server.
While site control is critical, companies, as defined above, also need easy-to-configure synchronization of security data between sites. The fundamental factors for a network architecture are:
1. Instant and scheduled synchronization: Security managers need to receive real-time notifications about critical events and alarms and must have the ability to schedule the synchronization of non-critical activities to better manage maximum network utilization;
2. Network outage tolerance: Synchronization between multiple sites must be able to withstand short or prolonged network outages. When the headquarters or central server reconnects, synchronization should restart automatically;
3. "Scalability" from large to small: in most companies there is a combination of small headquarters – for example, four or five sales offices – and large office buildings. A true enterprise architecture must incorporate all headquarters, large and small, into the network.
A well-designed distributed network architecture also offers CIOs of enterprise and IT security powerful centralized management capabilities. Centralized personnel management – defining and modifying "global" access control privileges, editing staff details – is the most important starting point.
However, true centralized management goes beyond personnel. Security managers also need to have the ability to i) create an integrated event viewer across multiple venues; and (ii) centrally manage, monitor, and configure your dashboards and readers.
To meet IT needs, the different stand-alone servers at each site in a distributed network architecture must be able to communicate with the distribution center through either a local area network (LAN) or a wide area network (WAN).
Return on investment
The main benefits of a distributed network architecture include: scalability, efficiency, cost reduction, and reliability.
1. Scalability: Enterprise solutions that use a single server inevitably suffer performance problems as the company grows and the server becomes overloaded. In addition, solutions with a single server are very susceptible to network failures. A distributed architecture load balances on different servers at each site.
2. Efficiency: Security managers control data flow and decision making, minimizing network broadband usage and allowing them to focus on their business. At the same time, security personnel in a centralized location can easily generate reports, make changes, and view site status without needing to connect to separate separate systems.
3. Costs: The number of servers and the amount of software can be adapted according to each site to meet the specific needs of each site, without the need to install an expensive server even in the smallest locations.
4. Reliability: Distributed network architecture is much more resilient to network and hardware failures, compared to centralized single-server solutions.
To better illustrate these benefits, let's think about the case of a large organization that wants to integrate its access control system into its ERP (enterprise resource planning) system to eliminate duplication and redundancy of employee data. With a distributed, but not networked, architecture that employs separate and independent access control solutions, the organization has to pay for and maintain multiple ERP integrations to the access control software at each location.
With a networked, but not distributed architecture (the classic single-server solution) only one integration is required, but system performance is poor across sites and network bandwidth consumption is high. The distributed network architecture offers a single, cohesive solution that enables single ERP integration and optimized system and network bandwidth performance.
Summary
Early generations of enterprise security solutions focused on control functions and harmonizing those functions with an organization's personnel databases. Today, these solutions have evolved into complete control at each location and into the ability to manage access points, card readers, and alarm monitoring from a central location.
The range of functionalities of the access control system is expanding thanks to the distributed network architecture, as it solves the performance, scalability and load balancing problems inherent in the single server architecture. Finally, security managers can request an access control solution that meets all of their security priorities: a distributed network architecture.
* Warren Brown is the Vice President of Product Management for Tyco Security Products. Warren has coordinated product management teams for more than ten years in the security, retail and financial services industries. He earned his MBA from Harvard Business School and currently lives in Concord, Massachusetts.

