Knowledge
An independent source of public knowledge
Maintain product identities, specifications and source evidence. Provide lookups and matching through an API, with separate candidate, verification and publication states.
X-NET-ATS / ARCHITECTURE & SECURITY
See what X-Net-ATS is made of, how its components connect, and which data and permissions need protection. Understand the links between product architecture, deployment topology and security mechanisms.
01 / SYSTEM ARCHITECTURE
Public knowledge and field evidence meet in Platform.
Verification and confirmation create your own asset and relationship records.
Product knowledge / source evidence / query and match
Public, reusable knowledgeAssets / actual topology / management records
Collect observations by network zone.
Submit standardized evidence.
Serial numbers, site IPs, asset locations, personnel information and actual topology stay in the customer environment.
Knowledge
Maintain product identities, specifications and source evidence. Provide lookups and matching through an API, with separate candidate, verification and publication states.
Platform
Manage assets, interfaces, connections, actual topology, responsibilities, permissions and audits. Turn external knowledge and field discoveries into candidates for verification.
Sensor
Run authorized tasks, recording collection methods, targets and times. Persist observations in a local queue before submitting them to Platform.
02 / CONNECTION TOPOLOGY
An example with one customer-side Platform and multiple sensors by network zone.
IT and OT connections are shown together.
Query and matching API
Persistent local queue
Clear after Platform acknowledgment
Browser and Sensor endpoints handle sessions and device identities separately. Permission checks run on the server.
Platform initiates knowledge queries. Sensor focuses on the field, while Platform connects knowledge with observations.
Platform queries Knowledge through an API. Customer and public knowledge databases are managed separately, preserving their data boundaries.
03 / SECURITY MECHANISMS
Security mechanisms map to specific components and connections.
They govern identity verification, authorized scope, fact confirmation and audit records.
Sensor identity derives from the device public key. Initial registration combines a one-time token with a signed device challenge. Communication certificates support renewal and revocation.
Browser access and knowledge queries use HTTPS. Regular Sensor control connections use mTLS after registration to verify Platform and Sensor identities.
Platform uses session authentication, role checks and granular asset permissions. Information access and management writes are controlled separately.
Knowledge queries submit only the minimum information needed for product identification. Asset IDs, personnel, precise locations and actual topology stay in the customer environment.
Field discoveries first create evidence and candidates. Operators verify them before adding them to the inventory. External knowledge is applied after reviewing differences and sources.
Sensor registration, renewal, revocation and asset changes are auditable. Observations retain sources, tasks, collection times and methods as verification evidence.
Retain what was observed, the supporting evidence and who confirmed it.
This page describes product architecture and implemented mechanisms. Collection protocols, adapters and extended capabilities evolve with product versions.
X-NET-ATS
Knowledge-driven / Distributed sensing / Intelligent management