Key takeaways
- An OPC UA server publishes data as nodes in an address space; the meaning of a value comes with the node’s attributes and references.
- Using subscriptions instead of constantly polling values is one of the main design decisions that determine network and server load.
- Security mode, security policy and certificate trust are configured separately; the “None” mode is not recommended for production networks.
- The namespace index in a NodeId can differ between servers; use the namespace URI in persistent configuration.
OPC UA is less a data format than an information model together with the services to access it. Most surprises in integration projects (nodes that cannot be found, unexpected load, rejected certificates) come from misunderstanding three parts of this architecture: the address space, subscriptions and security.
Address space: nodes and references
An OPC UA server presents its information in an address space. The address space is a graph made of nodes and the references that connect them. The main node classes are Object, Variable and Method; their type definitions use the ObjectType, VariableType, ReferenceType and DataType classes. There is also a View class.
Every node has a unique NodeId. A NodeId consists of a namespace index and an identifier; the identifier can be a number, a string, a GUID or a byte string. A Variable node has attributes such as DataType and AccessLevel besides its Value. Every value that is read comes with a status code (StatusCode) and timestamps, so the “value” and the “trustworthiness of the value” can be interpreted separately.
A client browses the address space, follows references and discovers nodes. A machine object might, for example, expose its components through HasComponent references. Unlike a flat tag list, this also carries the structure of the equipment.
Services: read, write, call and subscribe
A client reaches the server through service calls: Read and Write to read and write attributes, Browse to move around the address space, Call to invoke a method. Servers that support history also offer historical access services.
For values that are watched continuously, the most suitable method is the subscription. The client creates a subscription and adds monitored items to it. The server evaluates each item at its sampling interval; if there is a change it places it in a queue and delivers it to the client in a single notification at the subscription’s publishing interval. A filter decides what counts as a “change”: a change of status, value or timestamp; for numeric values a deadband can be defined.
These parameters directly determine load. Sampling thousands of tags every 100 milliseconds strains both server and network unless it is really needed. Sampling interval, queue size and deadband should be chosen according to the decision the data will serve, and measured under real load during the pilot.
Transport and security: mode, policy, certificate
An OPC UA connection is usually made with the binary protocol on an opc.tcp:// address; an HTTPS-based transport is also defined. Security is configured by three independent decisions:
- Security mode: None (no protection), Sign (signed) or SignAndEncrypt (signed and encrypted).
- Security policy: The set of algorithms used, for example Basic256Sha256 or Aes128_Sha256_RsaOaep. Older policies such as Basic128Rsa15 and Basic256 are marked deprecated.
- User identity: Anonymous, user name and password, an X.509 certificate or an issued token.
Application certificates make client and server trust each other. A Sign or SignAndEncrypt connection cannot be established until each side has placed the other’s certificate in its trusted list. A certificate’s expiry date is also a cause of outages, so a renewal plan is needed. See the OPC UA certificate guide for a detailed checklist.
Information models and companion specifications
A server can build any structure it likes in its own namespace; for devices of the same kind to speak the same structure there are industry companion specifications. For example, separate specifications have been published for machinery (OPC UA for Machinery), robots, packaging machines (PackML) and plastics injection moulding machines (Euromap 77). Which of them a server supports is stated in the manufacturer’s documentation; do not assume.
Basic types also carry information: for example, the types defined for analog measurements can expose engineering unit and scale range through standard attributes. If unit and range can be read from the server, use that information instead of guessing a conversion.
Practical consequences for integration
- Use the namespace URI. The namespace index in a NodeId can change when a server restarts or on a different server. Basing persistent configuration on the namespace URI rather than the index prevents “node not found” errors.
- Carry the quality. Pass the status code to the destination along with the value. Silently storing a bad-quality value causes problems in reports.
- Keep the source timestamp. Server timestamp and source timestamp can differ; analysis usually needs the time the event happened at the source.
- Size the subscription to the need. Measure sampling interval and deadband under real load.
- Try with a standalone client first. Browsing the address space with an independent OPC UA client before adding the connection to the project shows address-space, security and permission problems early.
PLC or machine data is read into OPC Router through this architecture; certificate trust, security mode and subscription parameters are confirmed together in the project.
Frequently asked questions
What is the difference between an OPC UA client and server?
The server publishes information in its address space and answers requests; the client connects to the server and reads, writes, subscribes or calls methods. The same software can be both client and server. In OPC Router the OPC UA Client is used to read sources and the OPC UA Server to expose processed data.
Should I use polling or subscriptions?
For values that are watched continuously subscriptions are usually more efficient; the server only reports changes. Polling suits infrequent, scheduled reads. The decision depends on how often the data changes and how much delay is acceptable.
Can I leave the security mode at None?
Technically yes, but the connection is neither signed nor encrypted, so it is not recommended on production networks. Configure certificate trust together with Sign or SignAndEncrypt.