Skip to content

Technical Knowledge

OPC UA in Factory Digitalization: Bridging OT and IT with Semantic Interoperability

OPC UA provides platform-independent semantic interoperability for Industry 4.0. Learn how OPC UA bridges multi-vendor PLCs with enterprise IT and Cloud systems.

  • Thiết kế hệ thống & thiết bị
OPC UA in Factory Digitalization: Bridging OT and IT with Semantic Interoperability

OPC UA (Open Platform Communications Unified Architecture, IEC 62541) is the global, platform-independent, service-oriented interoperability standard engineered to serve as the communication backbone for Industry 4.0 and Smart Manufacturing. While legacy protocols such as Modbus RTU/TCP transmit raw, opaque 16-bit integers that require tedious manual address mapping, OPC UA introduces rich, object-oriented Semantic Information Modeling. This allows enterprise IT systems, MES software, and cloud analytics platforms to instantly ingest and understand factory machine telemetry without consulting manual register spreadsheets.

In brownfield manufacturing plants, automation fragmentation is a constant headache: labeling machines run on Siemens S7, injection molders use Mitsubishi MELSEC, robotic arms run Omron Sysmac, and water treatment utilities use Schneider Modicon. Bridging this multi-vendor landscape into a unified enterprise data lake requires a standardized semantic layer.

This technical guide provides a deep exploration of OPC UA: its object-oriented architecture, multi-tiered X.509 security framework, head-to-head comparison against Modbus and MQTT, and deployment strategies for embedding OPC UA servers onto industrial IoT gateways.

---

1. What is OPC UA and Why Did Classic OPC Evolve?

Industrial Ethernet managed switch routing high speed OPC UA factory telemetry
Industrial Ethernet switches routing secure OPC UA traffic across dedicated OT VLANs.

Classic OPC (OPC DA, HDA, AE) was developed in the 1990s as a Windows-only standard tied strictly to Microsoft's proprietary DCOM (Distributed Component Object Model). Classic OPC was incapable of traversing firewalls, could not run on Linux or embedded microcontrollers, and contained zero native cryptographic security.

Classic OPC (1996):  Windows-Only -> Tied to Microsoft DCOM -> Zero Security -> No Firewalls
                                      VS
OPC UA (IEC 62541):  Platform-Independent (Linux, RTOS, Windows) -> Built-In X.509 TLS Security -> Semantic Information Models

OPC Unified Architecture (OPC UA) completely rebuilt the standard from the ground up:

  • Platform Independence: Implemented in ANSI C, C++, Java, Rust, and Python, executing seamlessly on bare-metal RTOS, embedded Linux gateways, and cloud Kubernetes clusters.
  • Firewall-Friendly Transport: Consolidates all communications onto a single binary TCP port or standard HTTPS WebSockets.
  • Built-In Security by Design: Every message can be digitally signed and encrypted using X.509 certificates and AES-256 ciphers.
  • Semantic Information Modeling: Organizes data into object nodes containing attributes, data types, physical engineering units, and functional relationships.

---

2. The Power of Semantic Information Modeling

SCADA central control screen visualizing real-time OPC UA semantic machine nodes
OPC UA Information Models allow supervisory SCADA/MES systems to self-discover machine parameters.

In Modbus, reading temperature yields raw register 40001 = 253. An external system cannot know if this represents 25.3°C, 253°F, or an error code without human documentation.

In OPC UA, data is organized into a navigable Node Graph (Address Space):

Objects (Root)
   └── Boiler_System_4 (ObjectNode)
          ├── Manufacturer = "DeviceLab Industrial" (Property)
          ├── SerialNumber = "DL-BLR-2026-09" (Property)
          └── Steam_Temperature (VariableNode)
                 ├── Value = 184.6
                 ├── DataType = Double
                 ├── EngineeringUnits = "°C"
                 ├── MinLimit = 0.0
                 ├── MaxLimit = 300.0
                 └── Timestamp = 2026-10-02T14:30:00Z [Good]

When an MES or cloud platform connects to an OPC UA server, it executes Address Space Browsing, self-discovering the complete machine topology, variable names, and engineering ranges automatically.

---

3. Engineering Comparison: OPC UA vs. Modbus TCP vs. MQTT

Architectural AttributeModbus TCPMQTT over TLSOPC UA (Client/Server & Pub/Sub)
Primary Architectural RoleField device serial bridgingLightweight telemetry uplinkComprehensive OT/IT semantic integration
Data Payload StructureRaw 16-bit binary registersUnstructured payload (JSON, String, Binary)Rich Object-Oriented Information Models
Communication ParadigmClient / Server (Request/Response)Publish / Subscribe (Event-Driven)Both: Client/Server and Pub/Sub (TSN)
Transport OverheadMinimal (7-byte MBAP Header)Ultra-lightweight (2-byte Header)Moderate to High (Complex protocol frames)
Native Security FrameworkNone (Cleartext)TLS 1.3 Transport SecurityBuilt-in X.509 Certificates, Sign & Encrypt
Resource FootprintExtremely low (<10KB RAM)Low (<50KB RAM)Moderate to High (2MB–64MB RAM)
Primary Industrial Use CaseLegacy PLC / Meter pollingCloud streaming over cellular/LPWANSCADA/MES integration, machine-to-machine

---

4. Multi-Layered OPC UA Cybersecurity Architecture

Automation engineer configuring X.509 digital security certificates on OPC UA server
Two-way digital certificate authentication completely eliminates eavesdropping and rogue commands.

OPC UA enforces three sequential security verification layers:

[ Transport Layer Security ] ──► [ User Authentication ] ──► [ Role-Based Access Control ]
 ├── Endpoint Security: None / Sign / SignAndEncrypt
 ├── Cipher Suites: Basic256Sha256, Aes128_Sha256_RsaOaep
 └── X.509 Certificates: Mutual client & server certificate trust validation
  1. Endpoint Negotiation & Certificate Exchange: The client and server exchange public X.509 certificates. Both parties verify trust lists and certificate revocation lists (CRL).
  2. Channel Encryption (SignAndEncrypt): Symmetric session keys (AES-256) encrypt all packet payloads, while HMAC-SHA256 signatures guarantee zero packet modification.
  3. User Authentication & Authorization: Users authenticate via Anonymous (read-only monitoring), Username/Password, or X.509 User Certificates. Access Control Lists (ACLs) restrict write permissions to certified operators.

---

DeviceLab OPC UA Integration & Gateway Solutions

DeviceLab embeds OPC UA servers and clients directly into industrial IoT hardware:

  • Embedded OPC UA Gateways: High-performance Linux edge computing gateways running open62541 and Eclipse Milo stacks, polling heterogeneous field PLCs (Siemens, Mitsubishi, Modbus) and exposing normalized OPC UA Address Spaces.
  • Semantic Modeling & Companion Standards: Implementation of standard industrial companion specifications (OPC UA for Machinery, PackML, Euromap).
  • Turn-Key OT/IT Integration: Secure bridging of factory OPC UA servers to enterprise MES, Microsoft Azure IoT Operations, and AWS IoT SiteWise.

Related technical resources:

About the author

Written by

Đinh Mạnh Thảo

Head of Hardware R&D, DeviceLab

Technical Review

Engineering Team

Senior Embedded & Systems Engineers

Last updated: 12/09/2026

Specialization OPC UA · Industrial Automation · PLC Communication · OT/IT Convergence · SCADA/MES

View DeviceLab engineered projects →

Need custom Industrial IoT gateways or telemetry hardware?

Describe your field machinery, PLC signals, and required data streams. DeviceLab will determine the right path: COTS, Hybrid, or custom gateway development.

Submit Project Requirements

Start from PoC scope and architecture — no need to lock gateway models beforehand.