Spec clauses
Requirement language you can paste into a wireless specification, each clause tied to the page that explains it. Fill the blanks from your own values, or carry them over from the requirements translator.
- Timing and outage budget (5)
- Roaming (6)
- Coverage and signal (5)
- Spectrum and channels (6)
- QoS and airtime (6)
- Security (5)
- Loss of comms (6)
- Monitoring and logs (5)
- Change control (5)
- Acceptance testing (6)
Your values
Type your values, or work them out in the requirements translator. Blanks you leave empty stay marked in the text.
1. Timing and outage budget
1.1 Design to the outage budget shall
The wireless system shall be designed so that no gap in valid packets it causes, whether from a roam, a scan, a rekey, a channel change, or retries, exceeds [Outage budget] ms on any connection carried by [Vehicle or machine]. This outage budget is the tightest connection timeout on the link, [Tightest connection timeout] ms, as configured by the machine builder, less [Allowance for the wired path and endpoints] ms allowed for the wired path and the endpoints.
1.2 Timeouts are fixed inputs from the project shall
The outage budget shall be derived from the timeouts configured in the controller, vehicle, and fleet manager projects, such as CIP Safety connection reaction time limits, EtherNet/IP connection timeouts, PROFINET watchdog times, PROFIsafe F-monitoring times, and fleet heartbeats, and not from protocol defaults. The wireless design shall take these timeouts as fixed inputs; any proposal to raise one goes to the machine builder and is outside the wireless scope.
1.3 Measure the wired allowance shall
The share of the timeout spent outside the radio, [Allowance for the wired path and endpoints] ms, shall be measured on the installed system, for example from the maximum observed network delay a CIP Safety controller reports, and shall not be assumed.
1.4 Report the worst case, not the average shall
Every timing figure the wireless vendor submits, including roam time, latency, and gap duration, shall be stated as the maximum observed over the test, with the number of samples, and not as a mean or median alone.
1.5 State the distance traveled during the budget should
For each vehicle, the design report should state the distance [Vehicle or machine] travels at [Vehicle speed] [Speed unit] during the outage budget, as a planning figure for the machine builder's risk assessment, without judging whether that distance is acceptable.
2. Roaming
2.1 A worst-case roam limit inside the budget shall
The longest roam on any production route shall not exceed [Worst-case roam limit] ms, measured from the last data frame on the old access point to the first data frame on the new one. That limit shall sit inside the [Outage budget] ms outage budget with room left for retries.
2.2 Measured on the production client shall
Roam performance shall be demonstrated on the production radio, driver, and firmware of [Vehicle or machine], under the production security configuration. Figures measured on laptops, test clients, or a different security mode shall not be accepted.1
2.3 Fast roaming that both sides support shall
Every SSID that carries control traffic shall use a fast roaming method that each client model on it supports for the key management in use, 802.11r fast transition where available, otherwise OKC or PMK caching, so that no roam repeats a full 802.1X exchange. The vendor shall list, per client model and key type, the methods each one supports.2
2.4 One mobility domain along each route shall
Every access point a vehicle route crosses shall advertise the same mobility domain, with key holder configuration that lets each one reach the others, and roaming shall be tested across every boundary between access point groups, controllers, or sites that a route crosses.
2.5 Neighbor reports on, access point scanning controlled shall
SSIDs that carry control traffic shall send 802.11k neighbor reports where the clients support them. Off-channel scanning by access points that serve time-sensitive clients shall be disabled, or deferred while prioritized traffic is present, and any scanning that remains shall be counted against the outage budget.2
2.6 No steering on control SSIDs shall
Band steering, load balancing, and network-initiated low-signal disconnects shall be disabled on SSIDs that carry control traffic, unless a feature has been tested with every client model on the SSID and accepted in writing by the owner.
3. Coverage and signal
3.1 Coverage on every vehicle path shall
The wireless system shall provide at least [Minimum signal at the client] dBm signal and [Minimum SNR at the client] dB SNR, as received by the client, along every path [Vehicle or machine] uses, including aisles, lifts, doors, and enclosed structures, and not only in open aisles.3
3.2 Survey from the client's side shall
The survey shall be taken with the vehicle's own radio, or one with the same antenna, at the vehicle's real antenna height and mounting, with the vehicle carrying its tallest load, and not with a laptop on a cart.
3.3 Design for the worst condition shall
Coverage in the [Site or area] shall be designed and validated with racks at full and at empty fill level, finished product staged where it is staged in production, and cranes, doors, and vehicles in their working positions and moving. The signal and SNR targets shall be met at the worse of those conditions.
3.4 Raw measurements, not a heat map alone shall
Survey deliverables shall include the raw measurements for each location, with signal, SNR, data rate, and retries, and shall not rely on a predicted or measured heat map alone. The owner shall keep them as the baseline for later surveys.
3.5 A second path where metal moves should
Where large metal moves through a coverage area, each control client should hear at least two access points from different directions above the signal target, so a single object cannot block every path.
4. Spectrum and channels
4.1 No DFS channels for control traffic shall
Radios that carry control traffic shall not use channels subject to dynamic frequency selection (DFS), which under US rules are those in 5.25 to 5.35 GHz and 5.47 to 5.725 GHz, or the equivalent channels under the rules for [Country or regulatory domain].4
4.2 A written channel and power plan shall
The wireless system shall follow a written channel and power plan that assigns each radio its channel, width, and transmit power, and names the channels reserved for control traffic. Reserved channels shall carry no other application, and control radios shall use [Channel width for control radios] MHz channels unless a measured need justifies wider.
4.3 Automatic channel and power changes under control shall
Automatic channel and power changes shall be disabled on radios that serve control traffic, or limited to scheduled windows outside production that the owner approves. Every channel and power change shall be logged with time, radio, old and new value, and reason.
4.4 6 GHz device class confirmed for each location shall
Before control traffic is planned on 6 GHz, the vendor shall state the 6 GHz device class each access point and client is certified for, low power indoor, standard power, or very low power, and confirm that the class is permitted where the device will operate, whether indoors, outdoors, or on a vehicle, under the rules for [Country or regulatory domain]. Each standard power access point shall have a monitored path to its AFC system.5
4.5 6 GHz client support in writing shall
Control traffic shall be planned on 6 GHz only for vehicles whose maker confirms in writing that the vehicle's radio supports 6 GHz in the country of use, and which fast transition method it uses there, FT with SAE or FT with 802.1X. Access points in 6 GHz shall use preferred scanning channels and send neighbor reports.6
4.6 A spectrum management plan shall
The wireless system shall be operated under a spectrum management plan that lists every wireless network and emitter on site, including cameras, instrument networks, vehicle head units, Bluetooth devices, and personal hotspots, with owner, band, and channels, and that forbids unapproved access points in production areas.
5. QoS and airtime
5.1 Separate control from bulk traffic shall
Control traffic for [Vehicle or machine] shall ride a channel, band, or radio that carries no video, map downloads, firmware updates, or log uploads during production. Where a vehicle carries two radios, one shall carry control traffic and nothing else.
5.2 Bulk transfers in scheduled windows shall
Firmware downloads, map pushes, and log uploads to vehicles shall run in scheduled windows outside production, or shall be rate-limited and staged so that no more than [Share of the fleet transferring at once] percent of the fleet transfers at once.
5.3 Marking preserved end to end shall
Control traffic shall carry DSCP marking from the end device. The access point shall map DSCP to WMM user priority by an explicit table rather than the default three-bit copy, the marking shall survive every switch, tunnel, and controller on the path in both directions, and bulk traffic shall be marked below control traffic.
5.4 Uplink marking on the vehicle shall
The maker of [Vehicle or machine] shall document the DSCP and WMM marking its radio applies to each uplink traffic class, and control traffic sent by the vehicle shall leave it marked above best effort.
5.5 Few SSIDs and no low basic rates shall
Radios that carry control traffic shall advertise no more than [Maximum SSIDs per control radio] SSIDs, and their lowest basic rate shall be [Lowest basic rate] Mbps or higher once every device on the SSID is confirmed to join at that rate.3
5.6 An airtime budget per channel shall
Channel utilization on every channel that carries control traffic shall stay below [Channel utilization ceiling] percent at peak with the full fleet running, and the design shall be sized for the fleet the owner plans to run, [Planned fleet size] vehicles, not the fleet on survey day.7
6. Security
6.1 Wireless in its own segment shall
Wireless devices shall sit in their own network segment, and access points shall connect through a boundary protection device that enforces the owner's security policy between the wireless segment and the rest of the control network.
6.2 Authentication inside the plant shall
Authentication of plant floor clients shall not depend on any link outside the plant. The authentication server, or a local proxy or replica of it, shall sit inside the plant's network zone, and its round trip multiplied by the number of exchanges in one full authentication shall be counted in the outage budget for every join and reauthentication.
6.3 Security chosen together with roaming shall
The security configuration of each SSID that carries control traffic shall be one under which every client model on it completes a fast transition, and roam time under that configuration shall be measured on the production client before the configuration is approved.6
6.4 Key and session timers recorded and tested shall
The design shall record every key and session timer on control SSIDs and the authentication server: group key rekey, pairwise rekey, 802.1X reauthentication period, RADIUS Session-Timeout and Termination-Action, and idle timeout. Where a session timeout is sent, the Termination-Action shall request reauthentication rather than end the session. Each client model shall pass several cycles of every timer before rollout.8
6.5 Unapproved access points detected, never jammed shall
The wireless system shall detect access points and networks it does not own in production areas, alert a named person to any heard on a control channel or connected to the wired network, and shall not deauthenticate, contain, or jam networks the owner does not own.
7. Loss of comms
7.1 Behavior in writing for each vehicle shall
The maker of [Vehicle or machine] shall state in writing, for the software version supplied, what the vehicle does when it loses its link to the fleet manager: continue on the route it already holds, stop at the next decision point, stop, or power down. The answer shall say whether that changes while the vehicle carries a load, docks, waits at a door or lift, or works inside a guarded or enclosed area.
7.2 Every timer listed shall
The maker of [Vehicle or machine] shall list every timer that starts a loss-of-comms response, with its default, its range, and who can change it, and shall state the longest gap the vehicle tolerates without starting any response. The shortest of these timers shall be an input to the outage budget.
7.3 Stops carried over the network declared shall
The maker of [Vehicle or machine] shall declare whether any stop command, interlock, or safety data reaches the vehicle over the wireless link, and the timeout of each such connection. A vehicle that needs a message over the network in order to stop shall be referred to the machine builder's risk assessment before the wireless design proceeds.
7.4 Fleet detection time stated shall
The fleet manager supplier shall state how the fleet detects a lost vehicle and how long detection takes, including any heartbeat or keep alive period, and what happens to the vehicle's reserved path and zones until it does.9
7.5 Vehicle Wi-Fi watchdogs declared shall
The maker of [Vehicle or machine] shall declare any Wi-Fi watchdog or forced reconnect the vehicle runs, what triggers it, and what it monitors, and shall show that a fault elsewhere on the network cannot trigger it.
7.6 Recovery path stated shall
The maker of [Vehicle or machine] shall state whether the vehicle resumes on its own when the link returns or needs a reset, a restart, or a person, where that person has to be, and what the vehicle logs about the drop, with timestamps on which clock.
8. Monitoring and logs
8.1 One clock for every log shall
Access points, controllers, switches, vehicles, and the fleet manager shall synchronize to a common time source, and the timestamps in their logs shall agree to within [Timestamp agreement between systems] ms.10
8.2 Events the network keeps shall
The wireless system shall log, per client, every association, roam, deauthentication and disassociation with its reason code, every authentication failure, every radar event, and every channel or power change, each with time, access point, and channel, and shall keep the logs for at least [Log retention] days.
8.3 Client-side logs from the vehicle shall
The maker of [Vehicle or machine] shall make the vehicle radio's own logs available, including roam attempts, roam failures, and the sender and reason code of each deauthentication, with millisecond timestamps.
8.4 Alerts on drift shall
The wireless system shall alert a named person, during production, to any radar event, any channel or power change on a control radio, any new foreign network on a control channel, channel utilization above [Channel utilization ceiling] percent, and signal or SNR on a monitored route falling below the design targets.
8.5 Trends kept per route shall
The wireless system shall keep trends of signal, SNR, retries, channel utilization, roam count, and roam duration per area and per vehicle route, so slow drift can be compared with the acceptance baseline.
9. Change control
9.1 No automatic upgrades shall
Automatic and vendor-scheduled firmware upgrades shall be disabled. Every infrastructure upgrade shall be tested first with the production clients, deployed under an approved plan in a maintenance window agreed with production, and have a tested roll-back.
9.2 Configuration changes only in windows shall
Configuration changes that restart radios or require the wireless network to be shut down shall be made only in maintenance windows, and no setting shall reach the floor outside a window, including from a cloud management portal.
9.3 Client firmware pinned and piloted shall
Vehicle and client radio firmware shall be pinned per model, recorded in the asset inventory, and tested on a pilot vehicle and route, with a way back, before fleet rollout.11
9.4 Physical changes reviewed for wireless shall
Physical changes on the floor, including new racking, lines, walls, mezzanines, machines, enclosures, and changes to the stock profile, shall go through change management that includes their impact on the wireless network, and shall trigger revalidation of the affected routes.
9.5 New traffic and new radios reviewed shall
Any new traffic flow, SSID, vehicle model, or radio in a production area shall be reviewed against the traffic inventory and the spectrum management plan before it goes live, and its supplier shall state its data volume, frequency, band, and marking.
10. Acceptance testing
10.1 Test in production conditions shall
Acceptance tests shall use production vehicles at their top operating speed, [Top operating speed] [Speed unit] for [Vehicle or machine], on their real routes, with the full fleet and normal plant traffic running, while the plant is in operation.
10.2 Long enough to catch the rare roam shall
The acceptance test shall run for at least [Test duration] hours of production, cover every route, and capture every roam and every gap in cyclic traffic rather than a sample.
10.3 Pass or fail on the worst gap shall
The test shall pass only if the longest gap in valid packets on every connection, across every vehicle and route, stays inside the outage budget of [Outage budget] ms. A single gap longer than the budget fails the test.
10.4 Count events per vehicle and shift shall
The test report shall state, per vehicle and per shift, the number of gaps longer than [Gap length to count as an event] ms and the number of disconnects with their reason codes, as well as their durations.
10.5 Failure paths tested and timed shall
Acceptance shall include, in a planned window, pulling an access point uplink, bouncing a switch port, making the primary authentication server unreachable, and restarting every wireless device at once, with each recovery timed against the outage budget and the time to the last device back recorded.
10.6 Retest after change shall
The route test shall be repeated after any change to infrastructure firmware, client firmware, security settings, the channel plan, the physical layout along a route, or the fleet size, and for every new vehicle model.
Free to copy, change, and use in any specification, with no credit needed (CC0). The clauses are a starting point for your own wording: they do not certify a design, and they never set a safety timing value.