OPC UA Interoperability For Industrie4 and IoT en v5
OPC UA Interoperability For Industrie4 and IoT en v5
OPC UA Interoperability For Industrie4 and IoT en v5
IoT
4.0
Industrie
M2M
2
Thomas J. Burke
President und Executive Director
OPC Foundation
OPC Unified Architecture (OPC-UA) is the data ex- OPC-UA is an IEC standard and therefore ideally
change standard for safe, reliable, manufacturer- suited for cooperation with other organizations.
and platform-independent industrial communication. As a global non-profit organization, the OPC Foun-
It enables data exchange between products from dation coordinates the further development of the
different manufacturers and across operating sys- OPC standard in collaboration with users, manufac-
tems. The OPC-UA standard is based on specifica- turers and researchers. Activities include:
tions that were developed in close cooperation be-
tween manufacturers, users, research institutes and ➞ Development and maintenance of specifications
consortia, in order to enable safe information ex- ➞ Certification and compliance tests of
change in heterogeneous systems. implementations
➞ Cooperation with other standards organizations
OPC has been very popular in the industry and also
becoming more popular in other markets like the This brochure provides an overview of IoT, M2M
Internet of Things (IoT). With the introduction of Ser- (Machine to Machine) and Industrie 4.0 requirements
vice-Oriented-Architecture (SOA) in industrial auto- and illustrates solutions, technical details and imple-
mation systems in 2007, OPC-UA started to offer a mentations based on OPC-UA.
scalable, platform-independent solution which com- The broad approval among representatives from re-
bines the benefits of web services and integrated search, industry and associations indicates OPC-UA
security with a consistent data model. to be a key ingredient of data and information ex-
change standards.
Regards,
Thomas J. Burke
President and Executive Director
OPC Foundation
[email protected]
www.opcfoundation.org
3
Contents
QUOTES 37 SCALABILITY:
8 IT and Industry OPC-UA AT CHIP LEVEL
10 Industrial Suppliers and Users Prof. Jasperneite, Fraunhofer-Anwendungs-
12 Organizations – Research zentrum Industrial Automation (IOSB-INA),
Lemgo
14 OPC-UA AT A GLANCE
38 SMART METERING:
16 OPC-UA TECHNOLOGY IN DETAIL CONSUMPTION INFORMATION FROM
Karl-Heinz Deiretsbacher, Siemens AG and THE METER RIGHT UP TO IT ACCOUNTING
Dr. Wolfgang Mahnke, ABB SYSTEMS
Carsten Lorenz, Honeywell
23 SECURITY CHECK BY GERMAN FEDERAL
OFFICE FOR INFORMATION SECURITY 39 HORIZONTAL:
OPC-UA ENABLES M2M AND IOT
OPC FOUNDATION Silvio Merz, Joint Water and Wastewater
25 Organization Authority, Vogtland
26 Specifications, Information and Events
28 Laboratory – Certification 40 RENEWABLE ENERGY:
29 OPC-UA: Integration into products OPC-UA FOR MONITORING OFFSHORE
WIND FARMS
COLLABORATIONS Eike Grünhagen, Adwen GmbH
31 AutomationML
32 MDIS – Offshore Oil & Gas 41 VERTICAL:
33 AIM-D – RFID and other AutoID systems OPC-UA FROM PRODUCTION
34 PLCopen – Client and server in controller RIGHT INTO SAP
35 MES-DACH – MES data profiles Roland Essmann, Elster GmbH
42 CLOUD:
OPC-UA FOR IOT UP INTO THE CLOUD
Clemens Vasters, Microsoft Corporation
IoT 4.0
Industrie
M2M
Remote Device Access (with OPC-UA) as the common intersection of M2M, IoT and Industrie 4.0
6
Independence of the communication The OPC Foundation is a vendor-independent non-profit organization. Membership is not required
technology from manufacturer, for using the OPC-UA technology or for developing OPC-UA products. OPC is widely used in auto-
sector, operating system, program- mation but is technologically sector-neutral. OPC-UA runs on all operating systems – there are even
ming language chip layer implementations without an operating system. OPC-UA can be implemented in all lan-
guages – currently stacks in Ansi C/C++, .NET and Java are available.
Scalability for integrated networking OPC-UA scales from 15 kB footprint (Fraunhofer Lemgo) through to single- and multi-core hardware
including the smallest sensors, with a wide range of CPU architectures (Intel, ARM, PPC, etc.) OPC-UA is used in embedded field
embedded devices and PLC devices such as RFID readers, protocol converters etc. and in virtually all controllers and SCADA/
controllers, PCs, smartphones, HMI products as well as MES/ERP systems. Projects have already been successfully realized in
mainframes and cloud applications. Amazon and Microsoft Azure Cloud.
Horizontal and vertical communica-
tion across all layers.
Secure transfer and authentication at OPC-UA uses X.509 certificates, Kerberos or user/password for authentication of the application.
user and application level Signed and encrypted transfer, as well as a rights concept at data point level with audit functionality
is available in the stack.
SOA, transport via established OPC-UA is independent of the transport method. Currently two protocol bindings are available:
standards such as TCP/IP for optimized TCP-based binary protocol for high-performance applications and HTTP/HTTPS web
exchanging live and historic data, service with binary or XML coded messages. Additionally Publish/Subscribe communication model
commands and events (event/ can be integrated. The stacks guarantee consistent transport of all data. Besides live and real time
callback) data also historical data and their mathematical aggregation are standardized in OPC-UA. Further-
more method calls with complex arguments are possible, but also alarm and eventing via token
based mechanism (late polling).
Mapping of information content with OPC-UA provides a fully networked concept for an object oriented address space (not only hierar-
any degree of complexity for chical but full-meshed network), including metadata and object description. Object structures can
modeling of virtual objects to be generated via referencing of the instances among each other and their types and a type model
represent the actual products and that can be extended through inheritance. Since servers carry their instance and type system, clients
their production steps. can navigate through this network and obtain all the information they need, even for types that were
unknown to them before. This is a base requirement for Plug-and-Produce functionality without
prior configuration of the devices.
Unplanned, ad hoc communication OPC-UA defines different “discovery” mechanisms for identification and notification of OPC-UA-
for plug-and-produce function with capable devices and their functions within a network. OPC-UA participants can be located local
description of the access data and (on the same host), in a subnet or global (within enterprise). Aggregation across subnets and intelli-
the offered function (services) for gent, configuration-less procedure (e.g. Zeroconf) are used to identify and address network partici-
self-organized (also autonomous) pants.
participation in “smart” networked
orchestration/combination of
components
Integration into engineering and The OPC Foundation already collaborates successfully with other organizations (PLCopen, BACnet,
semantic extension FDI, AIM, etc.) and is currently expanding its cooperation activities, e.g. MES-DACH, ISA95, MDIS
(oil and gas industry), etc. A new cooperation initiative is with AutomationML, with the aim of optimiz-
ing interoperability between engineering tools.
Verification of conformity with the OPC-UA is already an IEC standard (IEC 62541), and tools and test laboratories for testing and
defined standard certifying conformity are available. Additional test events (e.g. Plugfest) enhance the quality and en-
sure compatibility. Expanded tests are required for extensions/amendments (companion standards,
semantics). Additionally various validations regarding data security and functional safety are per-
formed by external test and certification bodies.
8 QUOTES – MARKET LEADERS FROM IT AND INDUSTRY
»OPC-UA is an essential component of the connect- »Manufacturing in the digital world requires a highly
ed products that manufacturing customers need to- connected and intelligent approach to provide high
day, and it is increasingly seen as an important part responsiveness to individualized customer demands,
of enterprise IoT scenarios and business models. In to enable flexible manufacturing processes and to
keeping with our commitment to openness and col- fully empower production workers. In order to
laboration, Microsoft is fully committed to supporting achieve this SAP is using and supporting standards
OPC-UA and its evolution. like OPC-UA to ensure simple, scalable and safe in-
formation exchange with the shop floor.«
Matt Vasey, Director of IoT Business Development, Microsoft,
OPC board member
Veronika Schmid-Lutz, Chief Product Owner Manufacturing, SAP AG,
OPC board member
Scott Armour, VP Global Java Business Unit, Oracle Johannes Diemer, Manager Industrie 4.0, Hewlett-Packard GmbH
9
»One of the principal ideas of the Industrial Internet of »ABB is offering a classic OPC interface for most of
Things (IIoT) is to connect industrial systems that its products or uses classic OPC to integrate data.
communicate data analytics and actions to improve As OPC-UA does not only allow data exchange but
performance and efficiency. The implementation of provides information modeling capabilities and com-
IIoT will require a paradigm change in the way organ munication in a secure, platform-independent way
izations design and expand industrial systems. we see a high potential and are fully committed to it.
Therefore, the integration with existing or third-party Our customers will benefit from reduced integration
automation devices through standard, secure com- efforts and new application scenarios by utilizing the
munication protocols is paramount. OPC-UA stands possibilities of OPC-UA.«
up to this challenge by providing a widely adopted
Thoralf Schulz, Global Technology Manager for Control Technologies, ABB
and secure industry standard for interoperability be-
tween dissimilar processing elements and IT devices
on the factory floor. NI has adopted OPC-UA in its
portfolio of embedded devices to help drive the inter-
connectivity of Cyber Physical Systems (CPS) in the
evolutionary process of IIoT.«
James Smith, Director for Embedded Systems Product Marketing,
National Instruments
»OPC DA is the most popular and successful stan- »OPC-UA will provide a common layer of technical
dard interface on the automation systems. Yokoga- and semantic inoperability for M2M and M2H
wa joins OPC Foundation from the beginning and (Machine to Human) communications that is critical
has much contributed to the development of OPC for enabling the Industrial Internet. By establishing
interface. Now Yokogawa is fully committed itself to interoperability standards together as an industry, we
new promising OPC-UA and will contribute to the will provide a scalable, reliable platform for GE and
development as ever.« others to build out the Industrial Internet and expand
the value and capabilities we can provide for our
Nobuaki Konishi, Yokogawa, President OPC Council Japan,
OPC board member
customers.«
»With OPC-UA a future proven and manufacturer-in- »OPC-UA has the potential for an immediate cross-
dependent communication standard is offered to the vendor implementation of Industrie 4.0 and the nec-
industry. Its scalability allows horizontal and vertical essary internet based services.
networking of systems, machines and processes. The adoption of this open standard is an opportunity
Bosch Rexroth consistently uses this internationally for vendors and users. Proprietary solutions will not
accepted open standard as a key technology and generate an adequate value.«
offers extensive services and semantic information Dr.-Ing. Reinhold Achatz, Head of Corporate Function Technology,
models for its products. We develop the functiona- Innovation & Sustainability, ThyssenKrupp AG
Pioneers in automation
»Schneider Electric sees the advent of the Industrial »In the production of the future, standardized inter-
Internet of Things as an “evolution”, not a “revoluti- faces like OPC-UA will be essential for the communi-
on”. In a world where our smart connected products cation and connection of intelligent components
and systems operate as part of larger systems of which are ready for Plug and Produce. Thereby we
systems, consistency when moving data is impor- will be able to connect modular and scalable produc-
tant. Even more important is putting data into con- tion facilities much easier to superordinate systems
text. With OPC-UA we can efficiently and effectively like MES or ERP. At the OPC Day Europe in 2014 we
deliver systems and applications that do just that – already showed an OPC-UA test implementation in
and thus help our customers fully realize the potenti- our production. Also the innovative transport system
al of Industrie 4.0.« Multi-Carrier-System and the automation platform
CPX both have an OPC-UA interface for integration
John Conway, VP Strategy & Partnerships, Schneider Electric
into Industrie 4.0 HOST environments.«
Prof. Dr. Peter Post, Leiter Corporate Research and Technology, FESTO
»OPC-UA proves to be ideal for implementing the »One main challenge of Digital Factory is the horizon-
functionality required for Industrie 4.0, in terms of tal and vertical communication among with all sys-
communication within automation systems, and in- tems and devices. For example, a MES system
teroperability between Industrie 4.0 components via needs to fetch data from each PLC in a production
defined objects and semantics. Due to the interna- line, which means huge costs. Fortunately, OPC UA
tional support of different automation solution provid- connects but also reduces costs for this effort. It pro-
ers, the protocol already finds a use in numerous vides a secured standardized interface for device
devices, from the sensor level to Manufacturing Ex- data and their meaning. Therefore, we developed
ecution Systems (MES) to Enterprise Resource Plan- Industry Real-time DB product suite, AicVision, com-
ning systems (ERP). Acceptance and a future-orient- pletely based on OPC UA, and provide comprehen-
ed technological basis will result in the development sive data integration solutions for Digital Factory.«
of an international and evolving standard – OPC-UA
Peizhe Wang, CEO AIC
provides this basis.«
»OPC-UA represents an essential step forward in »Communication is not about data. Communication
truly open communications standards, without which is about information and access to that in an
there can be no Industrie 4.0 or industrial Internet of easy and secure way. This is what the cooperation
Things. OPC-UA is consistent with OMAC’s most PLCopen and OPC Foundation is all about. OPC-UA
important initiatives, combining standards with func- technology creates the possibility for a transparent
tionality to bridge the persistent gap between machi- communication independent of the network, which
nes, control platforms, and management systems.« is the foundation for a new communication age in
industrial control.«
John Kowal, Board member OMAC & PMMI
(B&R Industrial Automation Corp)
Eelco van der Wal, Managing Director PLCopen
»BACnet and OPC-UA are already cooperating in „OPC-UA offers a secure, reliable, interoperable and
the exploration of new opportunities for integration platform-independent basis for the MDIS information
between industrial and building automation: Energy model. The simplified communication connections
data are semantically defined through BACnet and and increasing data quality offer the oil & gas opera-
can conveniently and interoperably be made avail- tors a real value-add.“
able to enterprise systems via OPC-UA: An ideal
Paul Hunkar, DS Interoperability, OPC Consultant of the MDIS Network
standardization from sensor right up to IT billing sys-
tems.«
Prof. Dr. Dr. Detlef Zühlke, Scientific Director Prof. Dr.-Ing. Birgit Vogel-Heuser, Head of Institute of Automation and
Innovative Factory Systems (IFS), DFKI Kaiserslautern Information Systems, Munich University of Technology (TUM)
14 OPC-UA AT A GLANCE
OPC-UA at a glance –
secure, reliable and platform-independent
exchange of information
SECURE, RELIABLE AND PLATFORM- HTTP are also optionally supported. Additional pro-
INDEPENDENT EXCHANGE OF INFORMATION tocol bindings like Multicast or Message-Queuing
OPC-UA is the latest technology generation from can be integrated easily without breaking exsiting
the OPC Foundation for the secure, reliable and communication concepts. The integrated encryption
vendor-independent transport of raw data and mechanisms ensure secure communication over the
pre-processed information from sensor and field Internet.
level up to the control system and into production
planning systems. SERVICE-ORIENTED ARCHITECTURE
With OPC-UA every type of information is available OPC-UA defines generic services and in doing so
anytime and anywhere for every authorized use and follows the design paradigm of service-oriented ar-
to every authorized person. chitecture (SOA), with which a service provider
receives requests, processes them and sends the
PLATFORM AND VENDOR-INDEPENDENT results back with the response.
OPC-UA is independent of the vendor or system In contrast to classic Web services that describe
supplier that produces or supplies the respective ap- their services over a WSDL and can thus be different
plication. The communication is independent of the with each service provider, generic services are al-
programming language in which the respective soft- ready defined with OPC-UA.
ware was programmed and it is independent of the A WSDL is thus not required, because the services
operating system on which the application runs. It is are standardized. As a result they are compatible
an open standard without any dependence on, and interoperable, without the caller needing to have
or bind to proprietary technologies or individual any special knowledge about the structure or behav-
vendors. ior of a special service. OPC-UA defines various
groups of services for different functions (read-
STANDARDIZED COMMUNICATION VIA ing/writing/signaling/execution, navigation/search-
INTERNET & FIREWALLS ing, connection/session/security). The flexibility re-
OPC-UA extends the preceding OPC industry stan- sults from the OPC-UA information model. Building
dard by several important functions such as platform on a basic model, any desired complex, object-ori-
independence, scalability, high availability and Inter- ented extensions can be made without impairing the
net capability. OPC-UA is no longer based on Micro- interoperability in the process.
soft’s DCOM technology; it has been reconceived on
the basis of service-oriented architecture (SOA). PROTECTION AGAINST
OPC-UA is thus very simple to adapt. Today OPC- UNAUTHORIZED ACCESS
UA already connects the enterprise level right down OPC-UA technology uses proven security concepts
to the embedded systems of the automation com- that offer protection against unauthorized access,
ponents – independent of Microsoft, UNIX or any against sabotage, the modification of process data
other operating system. OPC-UA uses a TCP based, and against careless operation. The OPC-UA secu-
optimized, binary protocol for data exchange over a rity concepts contain user and application
port 4840 registered with IANA. Web service and authentication, the signing of messages and the
15
OPC-UA
Object Method
Variables Methods Service Set
Attribute (Programs)
_____ _____( )
Service Set
_____ _____( )
(Data Access,
_____ _____( )
Historical
Data Access)
Events
N
N Subscription
N Service Set
(Alarms &
Conditions)
encryption of the transmitted data itself. OPC-UA procedures and systems in uniform object-
security is based on recognized standards that are oriented components. Information consumers that
also used for secure communication in the Internet, only support the basic rules can process the data
such as SSL, TLS and AES. The safety mechanisms even without knowledge of the interrelationships of
are part of the standard and are obligatory for ven- the complex structures of a server.
dors. The user may combine the various security
functions according to his case of use; thus scalable AREAS OF APPLICATION
security results in relation to the specific application. The universal applicability of OPC-UA technology en-
ables the implementation of entirely new vertical inte-
ACCESSIBILITY AND RELIABILITY gration concepts. The information is transported se-
OPC-UA defines a robust architecture with reliable curely and reliably from the production level into the
communication mechanisms, configurable timeouts ERP system by cascading OPC-UA components.
and automatic error detection. Embedded OPC-UA servers at field device level and
The error elimination mechanisms automatically re- integrated OPC-UA clients in ERP systems at enter-
store the communication connection between the prise level are directly connected with one another.
OPC-UA client and the OPC-UA server without loss The respective OPC-UA components can be geo-
of data. OPC-UA offers redundancy functions that graphically distributed and separated from one an-
are integrable in both client and server applications other by firewalls. OPC-UA enables other standard-
and thus enable the implementation of high-availa- ization organizations to use the OPC-UA services as
bility systems with maximum reliability. a transport mechanism for their own information
models. The OPC Foundation already cooperates
SIMPLIFICATION BY UNIFICATION today with many different groups from different in-
OPC-UA defines an integrated address space and dustries, including PLCopen, AIM, BACnet, ISA and
an information model in which process data, alarms FDI. Additional specifications are compiled that con-
and historical data can be represented together with tain common, semantic definitions of information
function calls. OPC-UA combines all classic OPC models.
functionalities and allows the description of complex
16 OPC-UA TECHNOLOGY IN DETAIL
UA Binary UA XML
Collaboration Models
UA Secure WS Secure
Conversation Conversation
DA AC HA Prg
UA TCP SOAP
Base Services
HTTPS HTTP
INTEGRATED ADDRESS SPACE MODEL The OPC-UA address space is structured hierarchi-
The object model enables production data, alarms, cally, to foster the interoperability of clients and serv-
events and historic data to be integrated in a single ers. The top levels are standardized for all servers. All
OPC-UA server. This allows, for example to repre- nodes in the address space can be reached via the
sent a temperature measuring device as an object hierarchy. They can have additional references
with its temperature value, alarm parameters and among each other, so that the address space forms
corresponding alarm limits. a cohesive network of nodes.
OPC-UA integrates and standardizes the different The OPC-UA address space not only contains in-
address spaces and the services, so that OPC-UA stances (instance space), but also the instance types
applications only require a single interface for naviga- (type space).
tion.
Root
“Located In“
reference
Area 2
Current Value Hi Limit Lo Limit
Area 3
Hi Alarm Lo Alarm
PLATFORM-INDEPENDENCE PERFORMANCE
Unlike “Classic OPC”, which is based on DCOM The OPC-UA services can be mapped to different
technology and is therefore inevitably linked to the technologies. Currently there are essentially two
Windows platform and the languages supported mappings: UA-TCP and HTTPS. The use of UA-TCP
there, OPC-UA was designed for application on arbi- on top of advanced Ethernet technologies ensures
trary platforms using arbitrary program languages. high performance.
The services themselves are also designed for high
data throughput. An individual read call can access
Tool or API thousands of values, for example. Subscriptions ser-
Language
Dependent
vices enable notification when values are changed
Proxy /
(e.g. .NET) Stubs and exceed configured thresholds
Services
Binding
INFORMATION MODELS WITH OPC-UA
Abstract UA Model
Specification THE OPC-UA META MODEL
➞ The next level (Services Binding) is used to The OPC-UA object model defines a set of standard-
specify how the services are to be mapped to cer- ized node types, which can be used to represent
tain protocols. Currently mappings for TCP (UA- objects in the address space. This model represents
TCP) and for HTTP (OPC-UA WebServices) are objects with their variables (data/properties), meth-
available. In the future – once new technologies ods, events and their relationships with other ob-
become established – further mappings can be jects.
specified without having to change the OPC-UA The node properties are described through attributes
model and the services. The mappings are en- defined by OPC-UA. Attributes are the only elements
tirely based on standardized basic protocols, of a server that have data values. The data types of
which already exist on all known platforms. the attributes can be simple or complex.
OPC-UA enables modeling of any object and vari-
➞ The following levels are realizations for dedi- able types and the relationships between them. The
cated platforms and languages. The OPC Foun- semantics is indicated by the server in the address
dation itself offers three such realizations, namely space and can be picked up by clients (during navi-
for Java, .NET and AnsiC/C++. gation). Type definitions can be standardized or ven-
The last option contains a platform adaptation dor-specific. Each type is identified by the organiza-
layer. tion that is responsible for its definition.
20 OPC-UA TECHNOLOGY IN DETAIL
Boiler 1
Pipe1001 FC1001
FT1001 Measurement
Signal
DataItem
ControlOut
Valve1001 Signal
FlowTo
DataItem Setpoint
Drum1001 LC1001
Input1
Signal
Executes
Signal
Input2
Input3
ControlOut ControlModule
TECHNOLOGY-SPECIFIC
INFORMATION MODELS The following companion standards
Standardization committees dealing with the control/ currently exist or are in preparation:
automation technology prepare technology-specific
information models. Examples are IEC61804 (EDDL), ➞ OPC-UA for Devices
ISA SP 103 (field device tool), ISA-S88, ISA-S95 and (IEC 62541-100)
IEC-TC57-CIM. These specifications are important,
since they standardize the descriptions of units, rela- ➞ OPC-UA for Analyser Devices
tions and workflows in certain fields of knowledge.
The OPC Foundation was keen to collaborate with ➞ OPC-UA for Field Device Integration
other organizations in the development of the new
standard right from the start. Rules for mapping the ➞ OPC-UA for Programmable Controllers
information models of these organizations to OPC- based on IEC61131-3
UA (companion standards) are specified in joint
working groups. ➞ OPC-UA for Enterprise and Control
Systems based on ISA 95
OPC-UA is a mature standard, which meets the Although various important information models
requirements of Industrie 4.0 regarding semantic already exist, there is still a need for action:
interoperability. OPC-UA provides the protocol ➞H ow for example, does a temperature sensor
and services (the “How”) for publishing compre- or a value control unit identify itself?
hensive information models (the “What”) and ex- ➞W hich objects, methods, variables and events
changing complex data between applications define the interface for configuration, initializa-
that were developed independently. tion, diagnostics and runtime?
22 OPC-UA TECHNOLOGY IN DETAIL
App Authentication of
Security OPC-UA Comms OPC-UA Comms
client, server, messages
OPC-UA is one of the most important modern stan- An extensive analysis of the security functions in the
dards for industrial facilities and many further sce- specification of OPC UA confirmed that OPC UA
narios in an intelligent and connected world. OPC- was designed with a focus on security and does not
UA is considered a central building block on the way contain systematic security vulnerabilities. Addition-
towards Industrie 4.0. It enables integration between ally a selected reference stack (ANSI C, Linux, Intel-
various layers of the automation pyramid from sensor 32bit, single thread) was assessed regarding the
up to the ERP system. It is the first time a unified, implementation of the security functionality. No crash
worldwide recognized industrial protocol can be em- could be generated during many tests of the com-
ployed that allocates necessary cryptographic munication stack. A list of security enhancements of
mechanisms for a secure smart factory. In order to the reference implementation was submitted to the
assess the quality of the security mechanisms of OPC Foundation. At all time the OPC Foundation
OPC-UA BSI has conducted a comprehensive and supported BSI in their security check effort.
independent security check.
»The only communication technology in the factory, with implicit security features and the potential for
the challenges posed by Industrie 4.0, that I am aware of today, is OPC-UA.«
Holger Junker, Head of Division C12, BSI
24 OPC-UA TECHNOLOGY IN DETAIL
The OPC-UA working group is currently integrating ➞ 2. Publisher/Subscriber for message
additional communication methods into the OPC-UA exchange in global networks (Cloud)
standard. They will extend the Client-Server architec- This model supports connectivity between OPC-
ture with the well-known Publish/Subscriber model UA applications that reside in different networks,
where the Server (Publisher) can publish its data to or where data shall be published to Clients that
an arbitrary number of Clients (Subscribers). This will reside “in the Cloud”, as well as network topolo-
improve the usability of OPC-UA in application fields gies where relays, brokers, or event hubs enable
like M2M (Machine to Machine) and IoT (Internet of the data transmission. It can connect any number
Things). of Servers with any number of Clients.
Both additions integrate seamlessly into the multi-
TWO DIFFEREN METHODS WILL BE AVAIL- layer architecture of OPC-UA where extensibility is
ABLE TO SUPPORT DIFFERENT SCENARIOS: part of the design. Just like the already existing Cli-
ent-Server communication methods, the new Pub-
➞ 1. Publisher/Subscriber over fast, lish-Subscribe methods for OPC-UA will utilize well-
local communication media established protocols. For Secure Multicast, for
This method is targeted to local networks. The example, the focus is on the User Datagram Protocol
data will be sent once (published) and received by (UDP) and Time Sensitive Networking (TSN). For
any number of Clients (Subscribers) using UDP Publish/Subscribe in global networks, the working
Secure Multicast. It allows extremely efficient data group focusses on the Advanced Message Queuing
distribution without brokerage. Protocol (AMQP). Both additions also only apply to
the transport of data, not the information model of
the application. I.e., the application and the informa-
tion that it exposes does not need to be changed.
Subscriber Publisher/Sender
(Client) (Server)
Relay
Subscriber Broker Publisher/Sender
(Client) (Server)
Subscriber
(Client)
Subscriber Publisher
(Client) (Server)
OPC FOUNDATION 25
OPC
48 % EUROPE
Organization
Members
6 % JAPAN
5 % CHINA
8 % OTHER
With more than 450 members, the OPC Foundation MEMBER DISTRIBUTION
is the world‘s leading organization for interoperability Although the head office is in Phoenix, Arizona, most
solutions based on the OPC specifications. members (almost 50 %) are based in Europe. Around
All members, including corporate members, end us- one third of the members are based in North Ameri-
ers and non-voting members, are committed to inte- ca. All main German manufacturers of automation
grated, compatible communication between soft- technology are members of the OPC Foundation
ware-driven devices, including CPS, in industrial and already offer OPC technologies in their products.
automation environments.
The OPC Foundation offers a marketing program in- MEMBERSHIP BENEFITS
cluding a newsletter, website and various training Members of the OPC Foundation have full access to
and information events aimed at manufacturers of the latest OPC specifications and preliminary ver-
automation solutions and providers of OPC technol- sions. They can take part in all working groups and
ogy. Member companies offer events and training contribute requirements and solution proposals.
programs for end users of the OPC technology. The Members have free access to core implementations
cooperation of developers and users in working and sample code. In addition, script-based test and
groups is crucial to ensure that practical require- analysis tools are provided.
ments and user feedback are taken into account in Manufacturers of OPC-capable products can have
the specifications. these certified in accredited test laboratories. The
developer and user community meets at events for
INDEPENDENCE exchange of information and networking. Three
The OPC Foundation is a non-profit organization that times each year, a week-long interoperability work-
is independent of individual manufacturers or special shop (IOP) is held, at which the latest products and
technologies. The members of the working groups their interaction are tested.
are provided by the member companies on a volun-
tary basis. The organization is financed entirely from
membership fees and receives no government
grants. The organization operates worldwide and
has regional contacts on all continents. All members
have identical voting rights, irrespective of their size.
26 OPC FOUNDATION – RESOURCES
OPC-UA SPECIFICATIONS AND IEC 62541 ➞ 2. Access models. These contain extensions of
The main source of information are the specifica- the information model for typical access to data,
tions. They are publicly accessible and also available alarms, messages, historic data and programs.
as an IEC standard series (IEC 62541). Currently 13
OPC-UA specifications are available, subdivided into ➞ 3. Extensions. These contain additional solutions
three groups. for finding of OPC-UA-capable components and
their access points in a network, plus the descrip-
tion of aggregate functions and calculations for
processing historic information.
Part 7 – Profiles
Part 13 – Aggregates
Laboratory – Certification
End users and integrators are encouraged to only TEST TOOLS AND QA
use certified OPC products in productive environ- There are different test tools available to validate the
ment. OPC server and client products which were correct function of an OPC-UA server or client prod-
tested in one of the independent certification labora- uct. OPC Members have access to all the tools and
tories, are recognizable by the „Certified“ logo. These thus can easily build up a comprehensive test envi-
test labs are accredited by the OPC Foundation and ronment. Especially the OPC Compliance Test Tool
follow the defined test scenarios to guarantee that (CTT) implements several hundred test cases and
your product complies with the following: provides a functional test with enormous test cover-
age. The script based tool is permanently enhanced
➞ Compliance to the OPC Specifications with new test cases and hence also covers enhance-
➞ Interoperability with other vendors’ products ments specification in a timely fashion. Additionally it
➞ Robustness and recovery from error conditions can be extended with your own product specific test
➞ Efficiency of CPU, RAM, and bandwidth etc. cases. The CTT is a test platform which perfectly can
➞ Usability ensures a good user-experience be integrated into your company‘s automated sys-
tem and regression test.
CODE AND ADVICE The developer frameworks e.g. toolkits are available
The OPC Foundation manages three OPC-UA com- at attractive prices as binary “black box” compo-
munication stacks (C, .NET and Java) in order to en- nents or includingcomplete source code. In addition
sure interoperability at protocol level. Although mem- to the source code for the OPC-UA stacks of the
bers have access to the source code of the stacks, OPC Foundation, commercial toolkits offer simplifi-
many decide to use a commercial toolkit in view of cations and convenience functions. The general
the fact that, in addition to the actual communication OPC-UA functionality is encapsulated behind an API.
layer for OPC-UA applications, – especially for an For this reason application developers do not need
OPC-UA server – further specific administrative func- detailed OPC-UA expertise. A stable, tested library
tions have to be implemented. enables them to focus on their own core compe-
This is where the toolkits come in by consolidating tence.
generic functions such as connection management,
certificate management and security features. Using QUALITY AND FUNCTION
toolkits e.g. developer frameworks offers advantag- OPC-UA toolkits are used for a wide range of appli-
es for implementation and time to market. cation scenarios in industrial environments. For that
reason they are robust, certified, are being main-
EXPERT KNOWLEDGE tained and continuously enhanced. Toolkit providers
A number of companies around the world offer com- offer specialized and optimized developer frame-
mercial support for the integration of OPC-UA com- works for various programming languages. Toolkits
munication technology in existing products and the differ in their OPC-UA-specific functionality and in
implementation of new products, ranging from ad- terms of their application, use-case and operational
vice and developer training to selling software librar- environment. All toolkits are offered with professional
ies and development support right up to long-term support and development service. Further informa-
support and maintenance contracts. tion is available from toolkit manufacturers.
Collaborations
The OPC Foundation closely cooperates with orga- through its secure and effective transport and offers
nizations and associations from various branches. access priviliges and generic interoperability. Thus
Specific information models of other standardization communication across branches and domains is
organizations are mapped onto OPC-UA and thus made possible without sacrificing particular, seman-
become portable. The organizations define „what“ tic, branch-specific objects and types.
shall be communicated. OPC-UA delivers „how“
TM
COLLABORATIONS
Page 31: AutomationML
Page 32: MDIS – Offshore Oil & Gas
Page 33: AIM-D – Auto-ID
Page 34: PLCopen
Page 35: MES-DACH
OPC-UA SOLUTIONS
31
The factory of the future shall be capable of produc- AUTOMATION MLTM AND OPC-UA
ing customer-specific products in ever new variants. FOR INDUSTRIE 4.0
Those involved in engineering and production shall Self-configuration can be achieved by using Auto-
react on short notice to changed customer wishes, mation ML to describe the capabilities of compo-
even after order intake. Uncertainties in markets lead nents and machines and OPC-UA to enable them to
to versatile factories and manufacturing equipment. communicate with each other. The companion stan-
Industrie 4.0 is the strategic framework program for dard that was mutually developed between OPC
the German industry entrenching growing digitaliza- Foundation and AutomationML e. V. aims at combin-
tion in its construction bureaus and production halls. ing the two technologies such that in case of modifi-
A wide range of individual industrial-suited standards cations in the factory data is communicated current-
is available, which now have to be purposefully con- ly, consistently and reliably. To this end, features and
solidated. capabilities are stored as AutomationML objects
Also the Industrie 4.0 ICT architecture needs the within the very components. Consequently, they are
ability to adapt to changes – either by adding new readily available to the control system as OPC-UA
equipment or production processes into the system information model at the time of physical integration.
or by changing existing production systems e.g. be- Component suppliers identify the information re-
cause a new, additional product variant has to be quired for this purpose in advance and include it in
manufactured. If in the future work pieces, machines the components themselves. Machine builders or
or material flow systems communicate with each system integrators thereby save approximately 20 %
other, they need a common language and a universal time in the case of initial start-ups or changes in ma-
transmission channel. Only both components collec- chines and production systems for the physical and
tively lead to inter-operable solutions. informal integration of components on the basis of
A central idea of Industrie 4.0 is that objects in- the “plug & play” principle. Configuration mistakes
volved in production comprehensibly will be reduced because the data flow is automated.
describe their unique identity and Even greater potential can be opened up if data re-
their capabilities. If then new quired for the configuration of an HMI or superim-
components, machines or posed MES are taken from the engineering systems
equipment are brought into the on which they are based and stored directly in OPC-
production system or changes UA information models as AutomationML objects.
appear in production, the ap-
propriate software modules can
quickly and efficiently ad-
just the configuration
of ICT systems.
32 OPC-UA SOLUTIONS
The trend towards increased automation is demand- HARTING already initiated such cross-vendor stan-
ing systems that are more heterogeneous. New chal- dardization for the AutoID industry back in 2013. Mo-
lenges and tasks can only be dealt with properly tivated by the knowledge that an accepted, stan-
when communication nodes are able to exchange all dardized communication interface for AutoID devices
relevant information directly in a flexible manner. would make the work of system integrators signifi-
UHF RFID and other AutoID technologies are clearly cantly more efficient, HARTING and Siemens raised
the key technologies for implementing the concept the OPC-UA issue in an AIM Germany (Association
of „Integrated Industry“. That is why it is so critical for Automatic Identification and Mobility) working
that these technologies are integrated into complete group at the beginning of 2014. Together with other
solutions as simply as possible. industry leaders, this association decided to define a
Thanks to its advantages and broad, cross-vendor companion specification for AutoID devices in coop-
acceptance, OPC-UA has emerged as a viable com- eration with the OPC Foundation.
munication standard in the automation industry. One Now, thanks to a year of dedicated work by all those
of the many benefits that OPC-UA offers is the ability involved, this goal has become a reality. The final
to pre-define data models of device groups in so- released new unified communication interface for
called companion specifications. These specifica- AutoID devices has been presented at 2016 Hanover
tions contain the essential functionality, including the Fair.
data type description of the individual variables, The advantage of such a companion specification is
transfer parameters and return parameters. quite evident. As more manufacturers follow this re
AutoID-Topologie mit OPC UA commendation and implement their communication
interfaces accordingly, it will be possible to integrate
various devices, even from different manufacturers,
more quickly into new applications. This saves time
HMI PLC PC Applications IT Systems Mobile Apps
and provides improved protection for our customers‘
investments.
This specification can also be extended with device-
specific or vendor-specific customizations, because
Industrial Ethernet
of OPC-UA‘s object-oriented design. Manufacturers
can thus retain their unique features while still relying
on a common, widely accepted communication plat-
form.
And more…
HF-RFID UHF-RFID
Mobile RTLS
1D/2D Codes
Computing
The interaction between IT and the world of automa- PLC CONTROLLER INITIATES HORIZONTAL
tion is certainly not revolutionary, but is based on the AND VERTICAL COMMUNICATION
long-established model of the automation pyramid: In collaboration with the OPC Foundation, the PLC
The upper level initiates a data communication (as a open (association of IEC6-1131-3-based controller
client) with the level below, which responds (as serv- manufacturers) has defined corresponding OPC-UA
er) cyclically or event-driven: A visualization, for ex- client function blocks. In this way the controller can
ample, can request status data from the PLC or play the active, leading role, in addition or as an alter-
transfer new production recipes to the PLC. native to the usual distribution of roles. The PLC can
With Industrie 4.0 this strict separation of the levels thus horizontally exchange complex data structures
and the top-down approach of the information flow with other controllers or vertically call up methods in
will start to soften and mix: In an intelligent network an OPC-UA server in an MES/ERP system, e.g. to
each device or service can autonomously initiate a retrieve new production orders or write data to the
communication with other services. cloud. This enables the production line to become
active autonomously – in combination with integrat-
ed OPC-UA security a key step towards Industrie
4.0.
PLCs
Factory Floor
OPC-UA SOLUTIONS 35
Vertical: OPC-UA plus UMCM – The “USB plug” in between SPS and MES
In an industrial environment, it is crucial that the sym- fied, secure across different security layers and nev-
bols, language and meaning of content is standard- ertheless extendable architecture. Optimal bidirec-
ized and the same for all systems. In the MES D.A.CH tional communication is thus assured, also for the
association with UMCM (Universal Machine Connec- future.
tivity for MES) an integrated communication model Based on OPC-UA, the MES D.A.CH association to-
for machine data towards higher-level systems that gether with the OPC Foundation offers function
is optimized for the lowest common denominator, blocks on the basis of IEC 61131-3 for various PLC
was implemented. 73 member companies promote suppliers and also in the format of high-level lan-
and optimize this model since 2012 and many sug- guages that enable convenient and fast implementa-
gestions and improvements from members have tions.
been incorporated and implemented in the current This is an efficient and simple method for raising sys-
version 1.7. tems to the next level of industrialization and making
Furthermore it is necessary to follow a secure, fast them fit for IoT and Industrie 4.0 applications.
standardized, easily recognizable and if necessary
extendable route. OPC-UA offers an unrivalled uni-
»The merger of automation technology and information technologies requires two key elements. Firstly –
an intelligent, networked system that can make rule-based decisions and save data, i.e. a Manufacturing
Execution System (MES) – and, perhaps even more important, secondly – a communication layer that is fast,
platform-independent, scalable and secure and can be integrated horizontally and vertically, from the device
level right into ERP systems, i.e. OPC-UA. We then have an Industrie 4.0-capable system or a so-called cyber-
physical system (CPS) that is independent of the location of the stored data.« Angelo Bindi
36 OPC-UA SOLUTIONS
»OPC-UA being a highly scalable technology enables a seamless exchange of information between sensor,
controller and ERP-Systems. In the next steps, OPC-UA is envisioned to be used to describe the semantics
of various services for a Smart Factory.« Jürgen Jasperneite
38 OPC-UA SOLUTIONS
Smart Metering: Consumption information from the meter right up to IT accounting systems
“A safe and reliable communication protocol plays Communication protocols are transferred in encrypt-
an important role in smart metering”, says Carsten ed form with respect to gas meters. This means:
Lorenz, AMR (Automatic Meter Reading) Manager at Personal data and critical commands, such as clos-
Honeywell, a leading supplier of smart meter prod- ing and opening of a valve integrated in the meter,
ucts for gas, water and electricity. Our UMI (Universal are not visible for third parties and cannot be inter-
Metering Interface) protocol ensures optimum ener- cepted or simulated.
gy efficiency and long battery life in networks. The communication protocols support both asym-
At Honeywell, we offer a software with OPC-UA in- metric and symmetric state-of-the-art encryption
terface for our own systems as well as other head- methods, such as the Advanced Encryption Stan-
end systems, since many systems used by supply dard (AES). AES encryption is approved in the United
companies already support this established stan- States for government documents with maximum
dard. Integrated encryption of sensitive meter data is security classification.
an important argument for OPC-UA“. Smart Metering is the precursor for the energy in-
Security and encryption of personal data is a MUST frastructure of the future. Transparent online display
when Smart Metering is introduced. This means: of consumption data offers customers the option to
Corresponding security concepts have to be intro- optimize their energy consumption and utilize flexible
duced together with Smart Metering in existing and tariffs based on their device and energy mix.
new systems. They have to take account of new pro-
cesses such as exchange of encryption mechanisms
between manufacturers and energy suppliers.
SSL
Remote API
Meter Data
Elster Open Meter Data Management
Collection Engine
Internet
Billing
Management
OPC-UA API
Asset
Management
APN etc.
GSM / GPRS
OPC-UA SOLUTIONS 39
If we regard some of the basic concepts of Industrie the PLC to other process devices as OPC-UA
4.0, such as platform and vendor-independent com- clients, whilst at the same time being able to respond
munication, data security, standardization, decen- to their requests or to requests from higher-level
tralized intelligence and engineering, then a technol- systems (SCADA, MES, ERP) as OPC-UA servers.
ogy for M2M (Machine-to-Machine) or IoT (Internet of The devices are connected by wireless router: a
Things) applications is already available in OPC-UA. physical interruption of the connection does not lead
OPC-UA is used for direct M2M communication be- to a loss of information, since information is auto-
tween plants for the intelligent networking of decen- matically buffered in the OPC-UA server for a time
tralized, independently acting, very small embedded and can be retrieved as soon as the connection has
controllers, i.e. around 300 potable water plants and been restored – a very important property in which a
300 wastewater plants (pumping plants, water great deal of proprietary engineering effort was in-
works, elevated reservoirs, etc.) distributed over vested beforehand. The authentication, signing and
about 1,400 km²: encryption safety mechanisms integrated in OPC-UA
Real objects (e.g. a pump) were modeled in the were used in addition to a closed mobile radio group
Filling Closed OK, I power IEC61131-3 PLC as complex objects with interactive to ensure the integrity of these partly sensitive data.
level reached! user group down!
possibilities; thanks to the OPC-UA server integrated The vendor-independent interoperability standard
in the controller these objects are automatically avail- OPC-UA opens up the possibility for us as end users
able to the outside world as complex data structures to subordinate the selection of a target platform for
for semantic interoperability. the demanded technology in order to avoid the use
The result is decentralized intelligence that makes of proprietary products or products that don‘t meet
decisions independently and transmits information to the requirements.
its neighbors or queries statuses and process values The replacement of a proprietary solution by a com-
for its own process in order to ensure a trouble-free bined OPC-UA client/server solution, for example,
Drinking Closed All OK!
process cycle. provided us with a saving on the initial licensing costs
water quality?
All OK!
user group With the standardized PLCopen function blocks the of more than 90 % per device.
devices independently initiate communication from
Closed
user group
40 OPC-UA SOLUTIONS
RENEWABLE ENERGY
»The integration of OPC-UA client functionality into our SCADA software was an important step towards se-
cure control and monitoring across remote networks, as required in the offshore wind sector. High availability
of system access is especially in offshore indispensable.« Eike Grünhagen
OPC-UA SOLUTIONS 41
The product itself determines the way it should be tures. The MES system receives the QM specifica-
produced. Ideally this enables flexible production tions via orders from the ERP and reports the fin-
without the need for manual setting up. Elster have ished products back to the ERP. Vertical integration
already implemented the vision of Industrie 4.0 in first is therefore not a one-way street, but a closed loop.
pilot lines. In future, intelligent products with their own data
A key factor is the seamless integration between storage will offer the prospect of exchanging much
shop floor, MES and ERP based on OPC-UA. At more than just a shopfloor control number with the
each step the product is identified through its unique plant. It is conceivable to load work schedules, pa-
shopfloor control number (SFC). OPC-UA enables rameters and quality limits onto the product, in order
the plant control system to be coupled directly with to enable autonomous production.
the MES system, so that flexible procedures and in- Before this can be implemented across the board, a
Rüdiger Fritz, SAP dividual quality checks can be realized in one-piece number of challenges relating to the semantics (ter-
flow mode. Without any additional effort, PLC vari- minology) have to be addressed. However, one im-
ables are published as OPC tags, and simply portant aspect in the Industrie 4.0 has already been
mapped to the MES interface. This enables fast and settled in practice: The communication between
consistent data transfer, even for complex struc- product and plant will take place via OPC-UA.
SAP ERP
SAP
Manufacturing
Execution
- PSN validieren: richtiger Schritt im Arbeitsplan,
Status nicht gesperrt oder Ausschuss
SAP Plant - Maschine validieren: Status nicht in Maintenance
oder gesperrt
Connectivity
(PCo) PSN und
Maschine
„StartResponse“
senden
validieren
- i.O.
- n.i.O./Fehler-info
-UA
OPC
- User
- Site weitere
- Resource-ID Prozessdaten
- Operation speichern
- PSN
Prozess
i.o.
durchführen
OK
PSN PSN and MES Response
erfassen anmelden auswerten
Webservice
NOK
„Start“ N.i.o. Fehler-
behandlung
42 OPC-UA SOLUTIONS
OPC-UA is an essential foundation for the conver chine learning capabilities for equipment that was
gence of OT and IT, providing a standardized not designed to have these capabilities built-in. The
communi cation, security and metadata/semantics cloud enables globally-available, industry-specific
abstraction for almost all industrial equipment. From Software as a Service (SaaS) solutions that are cost-
an IT perspective, OPC-UA is the programming inter- prohibitive to stand up for each industrial facility on
face of the “connected factory” and any other indus- its own.
trial facility and a critical enabler for Industrial Internet As customers and partners collaborate to modernize
of Things (IIoT) as well as the Reference Architecture their plants and facilities, OPC-UA is delivering digital
Model for Industry 4.0 (RAMI4.0) adoption. transformation simply and easily. Microsoft’s support
OPC-UA also serves as a critical gateway technolo- of OPC-UA offerings will reduce barriers to IoT adop-
gy to cloud-enable industrial equipment, enabling tion and help deliver immediate value.
data and device management, insights, and ma-
RTOS, Linux, Android, iOS, Windows
Cloud Gateway
Field Hot Path Business Logic
Dynamics, BizTalk Services,
Gateway IoT Hub Service Fabric & Actor Framework Notification Hubs
HEADQUARTERS / USA
OPC Foundation
16101 N. 82nd Street
Suite 3B
Scottsdale, AZ 85260-1868
Phone: (1) 480 483-6644
[email protected]
OPC EUROPE
Huelshorstweg 30
33415 Verl
Germany
[email protected]
OPC JAPAN
c/o Microsoft Japan Co., Ltd
2-16-3 Konan Minato-ku, Tokyo
1080075 Japan
[email protected]
OPC CHINA
B-8, Zizhuyuan Road 116,
Jiahao International Center, Haidian District,
Beijing, P.R.C
P.R.China
[email protected] www.opcfoundation.org
V5