Search
19 result(s) for OPC UA
-
OPC-10000-1 – OPC Unified Architecture - Part 1: Overview and ConceptsOverview and Concepts Part 1 (this part) presents the concepts and overview of OPC UA. Part 2 ( OPC 10000-2 ) - Security Model Part 2 describes the model for securing interactions ... between OPC UA Applications . Part 3 ( OPC 10000-3 ) - Address Space Model Part 3 describes the contents and structure of the Server's AddressSpace . Part 4 ( OPC 10000-4 ) - Services
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security ModelOPC UA security environment OPC UA is a protocol used between components in the operation of an industrial facility at multiple levels: from high-level enterprise management to low-level ... direct process control of a device. The use of OPC UA for enterprise management involves dealings with customers and suppliers. It could be an attractive target for industrial espionage
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Model4.3.2.2 Message floodingMessage that contains a large number of requests, with the goal of overwhelming the OPC UA Server or dependent components such as CPU, TCP/IP stack, operating system, or the file ... system. Flooding attacks can be conducted at multiple layers including OPC UA, HTTP or TCP. Message flooding attacks can also target a Client , although this is less of a risk
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security ModelOPC UA relationship to site security OPC UA security works within the overall Cyber Security Management System ( CSMS ) of a site. Sites often have a CSMS that addresses security policy ... referenced in Clause 2 . The security requirements of a site CSMS apply to its OPC UA interfaces. That is, the security requirements of the OPC UA interfaces that are deployed
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Model4.6 SecurityPolicieschoice of allowed SecurityPolicies is normally made by the administrator typically when the OPC UA Applications are installed. The available security policies are specified in OPC 10000-7 . The Administrator ... future, therefore, it makes sense to support different security policies in an OPC UA Application and to be able to adopt more as they become available. NIST or other agencies
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security ModelSecurity Profiles OPC UA Client and Server products are certified against Profiles that are described in OPC 10000-7 . Some of the Profiles specify security functions and others specify other ... different Profiles specify different details such as which encryption algorithms are required for which OPC UA functions. If a problem is found in one encryption algorithm then the OPC Foundation
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Model4.11 User AuthorizationUser Authorization OPC UA provides user authorization based on the authenticated user (see 4.9 ). OPC UA Applications can determine in their own way what data is accessible and what operations
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Model5.1.2.4 Application CrashesApplication Crashes OPC UA provides certification of OPC UA Applications . The lab testing and certification includes testing by injecting error and junk commands which could discover common faults. OPC Foundation ... also fuzz tested to ensure they are resilient to errors. Although a certified OPC UA Application does not guarantee fault free operation, the certified OPC UA Application is more likely
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Model5.1.7 Malformed MessagesMalformed Messages See 4.3.7 for a description of this threat. Implementations of OPC UA Applications counter threats of malformed Message s by checking that Message s have the proper form ... within their legal range. Invalid Message s are discarded. This is specified in OPC 10000-4 , OPC 10000-6 and OPC
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Modelspecified as a set, i.e., 2048, 3072, 4096 bits. It is important that an OPC UA Application supports the entire set of values for its ApplicationInstanceCertificate . This allows
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security ModelAdditional Security considerations If an OPC UA Application becomes aware of compromised credentials, which could be application level or user level credentials, the application should terminate any connection using
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security ModelMulticast Discovery OPC UA can be configured to support discovery in multiple manners. One of the options is a multi-cast discovery. In this type of Discovery, Servers announce themselves ... impersonate another host or Server . Risks from Rogue Servers can be minimized if OPC UA security is enabled and all applications use certificate TrustLists to control access. Also, Clients should
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Model9.1 OverviewOverview OPC UA Applications typically have ApplicationInstanceCertificates to provide application-level security. They are used for establishing a secure connection using Asymmetric Cryptography. These ApplicationInstanceCertificates are Certificates which are X.509 ... Cryptography makes use of two keys - a Private Key and a Public Key . An OPC UA Application will have a list of trusted Public Keys that represent the applications
-
OPC-10000-2 – OPC Unified Architecture - Part 2: Security Modeldevelopers From a developer point of view, it is a best practice for your OPC UA Application to automatically provide a self-signed ApplicationInstanceCertificate on installation. In addition, the OPC ... ApplicationInstances are kept in a separate list than those of a CA. Also, an OPC UA Application has to be able to handle Certificate Revocation Lists (CRL). These are lists
-
OPC-10000-4 – OPC Unified Architecture - Part 4: Services5.6.1 OverviewConfidentiality and Integrity of all Messages exchanged with the Server . The base concepts for OPC UA security are defined in OPC 10000-2 . The SecureChannel Services are unlike other Services ... because they are not implemented directly by the OPC UA Application . Instead, they are provided by the Communication Stack on which the OPC UA Application is built. For example
-
OPC-10000-4 – OPC Unified Architecture - Part 4: Services6.1.1 OverviewOverview The OPC UA Services define a number of mechanisms to meet the security requirements outlined in OPC 10000-2 . This clause describes a number of important security-related procedures ... that OPC UA Applications shall follow
-
OPC-10000-12 – OPC Unified Architecture - Part 12: Discovery and Global Services3.1.6 DiscoveryServerDiscoveryServer an application that maintains a list of OPC UA Applications that are available on the network and provides mechanisms for other OPC UA Applications to obtain this list
-
OPC-10000-26 – Part 26: LogObject - Part 26: LogObject Model5.6.1 Overviewdistributed system. Such a trace may produce multiple log messages in one OPC UA Application and/or multiple log messages across multiple OPC UA Applications . The TraceId is a unique identifier ... operation. Spans are the building blocks of traces. A span is local to an OPC UA Application . The SpanId is a unique identifier assigned by an OPC UA Application
-
OPC-10030 – OPC Unified Architecture - Common Object Model: ISA-95work centre types (within an area and contains work units). Its representation in the OPC UA AddressSpace is defined in a below table. Table 37 - ISA95EquipmentElementLevelEnum Definition Attributes Value BrowseName