IEC TR 62541-2:2020 PDF
OPC Unified Architecture - Part 2: Security Model
OPC Unified Architecture - Part 2: Security Model
- Статус документа:
- D
- Формат:
- Электронный (PDF)
- Количество страниц:
- 48
- Дата публикации:
- 17 ноября 2020 г.
- Издание:
- IEC TR 62541 edition 3 version 1
- ICS:
- 25.040.40
IEC 62541-2:2020 describes the OPC Unified Architecture (OPC UA) security model. It describes the security threats of the physical, hardware, and software environments in which OPC UA is expected to run. It describes how OPC UA relies upon other standards for security. It provides definition of common security terms that are used in this and other parts of the OPC UA specification. It gives an overview of the security features that are specified in other parts of the OPC UA specification. It references services, mappings, and Profiles that are specified normatively in other parts of the OPC UA Specification. It provides suggestions or best practice guidelines on implementing security. Any seeming ambiguity between this part and one of the other normative parts does not remove or reduce the requirement specified in the other normative part.
Abstract
Overview
IEC TR 62541-2:2020 - OPC Unified Architecture: Part 2: Security Model defines the security model for OPC UA, the vendor-neutral framework for industrial interoperability. This technical report describes the security environment, objectives, and threats relevant to OPC UA deployments and explains how OPC UA leverages other security standards. It provides definitions of common security terms, an overview of security features specified in other OPC UA parts, and best-practice guidance for implementation and deployment.
Key Topics and Requirements
- Security objectives: Authentication, authorization, confidentiality, integrity, non-repudiation, auditability, and availability are clearly identified as core goals for OPC UA systems.
- Threat analysis: Detailed threat categories (e.g., denial of service, eavesdropping, message spoofing/replay/alteration, session hijacking, rogue servers/publishers, credential compromise) and reconciliation of these threats with OPC UA mechanisms.
- OPC UA architectures: Security considerations for both Client/Server and Publisher/Subscriber models, including SecurityPolicies, Security Profiles, and Security Mode Settings.
- Authentication & authorization: Guidance on application and user authentication, user roles, and authorization mapping.
- Certificate management: Best practices for self-signed and CA-signed certificates, Global Discovery Server (GDS) interactions, and certificate handling workflows.
- Implementation guidance: Deployment advice on timeouts, strict message processing, random number generation, rate limiting, administrative access, cryptographic key handling, audit event management, and secure transport (HTTPS/TLS/WebSockets).
- Unsecured services: Identification of services that remain unsecured (e.g., multicast discovery) and mitigations for Global Discovery Server threats.
- Standards reliance: Explains how OPC UA relies on established standards (TLS, PKI, OAuth2, JWT where relevant) for secure transport and identity handling.
Practical Applications and Who Uses It
IEC TR 62541-2:2020 is essential for:
- Industrial automation architects and control system integrators designing secure OPC UA deployments
- IIoT and SCADA security engineers implementing secure data exchange
- Device and software vendors developing OPC UA-compliant products
- Security officers and compliance teams assessing risk, certificate management, and auditability in manufacturing, energy, building management, and smart infrastructure
Practical benefits include secure interoperable communications, reduced risk of unauthorized access or data tampering, and guidance for secure system lifecycle management.
Related Standards
- Other parts of the IEC 62541 (OPC UA) family (normative services, mappings, and profiles)
- Transport and identity standards used by OPC UA such as TLS/HTTPS, PKI, and token-based schemes (OAuth2 / JWT) referenced for user and application authentication.
This report serves as the authoritative guide for understanding OPC UA security posture, threat mitigation, and best practices for secure industrial communications.
Технические детали
- Технический комитет
- SC 65E - Devices and integration in enterprise systems
- SKU
- IEC TR 62541-2:2020
Похожие стандарты
Упомянутые в описании и другие стандарты IEC
BS EN IEC 62541-23:2026
ДействующийOPC unified architecture - Common Reference Types
IEC 60050-161:1990/AMD2:1998
ДействующийAmendment 2 - International Electrotechnical Vocabulary (IEV) - Part 161: Electromagnetic compatibility
IEC 60050-161:1990/AMD2:1998 – Electromagnetic Compatibility Vocabulary Amendment ### Overview The IEC 60050-161:1990/AMD2:1998 is the second amendment to the International Electrotechnical Vocabular…