OPC-UA Security Architecture
Implementing zero-trust security patterns in industrial protocols.
The Security Challenge in Industrial IoT
Traditional industrial protocols like Modbus and BACnet were designed for isolated networks with implicit trust. OPC-UA (Open Platform Communications Unified Architecture) was built from the ground up with security in mind, but proper implementation is critical.
OPC-UA Security Model
Three Pillars of Security
- Authentication: Verifying identity of clients and servers
- Authorization: Controlling access to nodes and methods
- Encryption: Protecting data in transit
Security Modes
┌─────────────────┬──────────────┬─────────────┬──────────────┐
│ Security Mode │ Signing │ Encryption │ Use Case │
├─────────────────┼──────────────┼─────────────┼──────────────┤
│ None │ No │ No │ Never │
│ Sign │ Yes │ No │ Monitoring │
│ SignAndEncrypt │ Yes │ Yes │ Production │
└─────────────────┴──────────────┴─────────────┴──────────────┘
Always use SignAndEncrypt in production environments.
Certificate Management
PKI Infrastructure
1from cryptography import x509 2from cryptography.x509.oid import NameOID 3from cryptography.hazmat.primitives import hashes 4from cryptography.hazmat.primitives.asymmetric import rsa 5 6def generate_opcua_certificate(common_name, uri): 7 key = rsa.generate_private_key( 8 public_exponent=65537, 9 key_size=2048, 10 ) 11 12 subject = issuer = x509.Name([ 13 x509.NameAttribute(NameOID.COUNTRY_NAME, "US"), 14 x509.NameAttribute(NameOID.ORGANIZATION_NAME, "Industrial Corp"), 15 x509.NameAttribute(NameOID.COMMON_NAME, common_name), 16 ]) 17 18 cert = ( 19 x509.CertificateBuilder() 20 .subject_name(subject) 21 .issuer_name(issuer) 22 .public_key(key.public_key()) 23 .serial_number(x509.random_serial_number()) 24 .not_valid_before(datetime.utcnow()) 25 .not_valid_after(datetime.utcnow() + timedelta(days=365)) 26 .add_extension( 27 x509.SubjectAlternativeName([ 28 x509.UniformResourceIdentifier(uri), 29 ]), 30 critical=False, 31 ) 32 .sign(key, hashes.SHA256()) 33 ) 34 35 return cert, key
Certificate Store Structure
/pki/
├── own/
│ ├── cert/ # This server's certificate
│ └── private/ # Private key (protected)
├── trusted/
│ └── certs/ # Trusted client certificates
├── rejected/
│ └── certs/ # Auto-rejected certificates
└── issuers/
└── certs/ # CA certificates
Zero-Trust Implementation
Principle of Least Privilege
1<!-- Role-based access control --> 2<RolePermissions> 3 <Role RoleId="Operator"> 4 <Permission NodeId="ns=2;s=Temperature" Read="true" Write="false"/> 5 <Permission NodeId="ns=2;s=Pressure" Read="true" Write="false"/> 6 </Role> 7 <Role RoleId="Engineer"> 8 <Permission NodeId="ns=2;s=*" Read="true" Write="true"/> 9 <Permission NodeId="ns=2;s=SafetyConfig" Write="false"/> 10 </Role> 11</RolePermissions>
Audit Logging
Every operation must be logged:
1class AuditLogger: 2 def log_event(self, event_type, client_id, node_id, action, result): 3 event = { 4 "timestamp": datetime.utcnow().isoformat(), 5 "event_type": event_type, 6 "client_id": client_id, 7 "client_certificate": self.get_cert_thumbprint(client_id), 8 "node_id": node_id, 9 "action": action, 10 "result": result, 11 "source_ip": self.get_client_ip(client_id) 12 } 13 self.audit_store.write(event)
Network Segmentation
┌─────────────────────────────────────────────────────────────┐
│ Enterprise Network │
├─────────────────────────────────────────────────────────────┤
│ Firewall (Port 4840 only, certificate validation) │
├─────────────────────────────────────────────────────────────┤
│ DMZ / OPC-UA Gateway │
├─────────────────────────────────────────────────────────────┤
│ Firewall (Strict IP allowlist) │
├─────────────────────────────────────────────────────────────┤
│ Industrial Network │
│ ┌─────────┐ ┌─────────┐ ┌─────────┐ ┌─────────┐ │
│ │ PLC 1 │ │ PLC 2 │ │ Robot │ │ Sensor │ │
│ └─────────┘ └─────────┘ └─────────┘ └─────────┘ │
└─────────────────────────────────────────────────────────────┘
Conclusion
OPC-UA provides robust security mechanisms, but they must be properly configured. Never deploy with SecurityMode=None, implement proper certificate management, and follow zero-trust principles throughout your architecture.
James Wilson
Contributing Writer
