Segmented decentralised connectivity in a care facility
An anonymised project profile covering separated network access for residents, visitors, staff and operational services.
Anonymised project profile · client confidential
Context
A larger care facility needed straightforward, stable and clearly separated connectivity for residents, visitors, staff and selected operational services. The location, operator and specific building information remain confidential.
Initial situation and objective
Separate connections for individual residents would have required recurring technician visits, individual provisioning, some building work and considerable administration. New residents, guests and personal devices needed access without complex per-device approvals, while operational systems had to remain separate.
The objective was a maintainable solution without a separate connection for each resident and without unnecessarily opening the internal infrastructure.
Role and approach
IT-NERDS assessed the building and network situation, reviewed available connection options and designed a decentralised architecture. A Freifunk-inspired approach provided logically separated access areas. Multiple gateways or connection points distributed the available connectivity to the intended user groups.
Private and operational use were separated through segmentation, clear network boundaries and Zero Trust principles. Here, “Zero Trust” describes a design principle rather than a complete formal implementation.
Technologies and principles
- decentralised network architecture
- Freifunk-inspired approach
- multiple gateways and connection points
- logical network segmentation
- Zero Trust principles
- open protocols and maintainable components
Outcome and deliverables
Residents, visitors and staff gained more flexible access while operational systems remained separate. Administrative effort for individual connections and device approvals was reduced without claiming quantified savings.
Deliverables included the technical design, network and segmentation logic, operational documentation and guidance for fault handling. The profile makes no formal classification of the facility or solution.