OPC UA security basics: modes, policies and certificate trust
What Sign and SignAndEncrypt actually change, which security policies to avoid, how application certificates and trust lists work, and the connection errors you will meet first.
· 3 minHow to structure MQTT topics with an ISA-95-style hierarchy, what belongs in the topic versus the payload, how retained messages and last will fit, and which anti-patterns to avoid.
A unified namespace (UNS) is an agreed, hierarchical naming structure in which every system publishes the current state of what it knows about the business, and every consumer looks for that state in one predictable place. It is most often implemented on an MQTT broker. It is a design discipline, not a product: a broker with inconsistent topic names is not a unified namespace, however modern the tooling.
The most common structure follows the ISA-95 equipment hierarchy: enterprise, site, area, line (work center) and cell (work unit), followed by the asset and the thing being measured. A topic then reads like an address:
enterprise/site/area/line/cell/asset/metric
acme/istanbul/packaging/line1/filler/oee
The names above are placeholders. Use the vocabulary your organization already uses, and decide the number of levels once. Every level should answer a question a reader will actually ask: where is it, what is it, what is being measured.
The topic identifies what the message is about. The payload carries the data. Keep them apart:
Putting changing values or timestamps into topic names creates an unbounded number of topics and makes subscriptions impossible. Follow these naming rules:
/, which creates an empty first level.Line1 and line1 are different topics.$; brokers reserve them (for example $SYS).+ and #) are for subscribing only, never for publishing.A small, consistent JSON object serves most needs:
{
"value": 79.2,
"unit": "%",
"ts": "2026-10-03T09:15:00Z",
"quality": "good"
}
Use UTC timestamps in ISO 8601 form, one schema per metric type and a version you can evolve. If you need a standard that also specifies device birth and death messages and state management, look at Sparkplug B, which defines a topic namespace and a binary payload for that purpose.
Two MQTT features make a namespace feel like a live picture of the plant:
online message on a status topic when the client connects, and a retained offline will message, so consumers can tell a silent signal from a dead producer.Choose delivery guarantees deliberately: the trade-offs between QoS 0, 1 and 2 are explained in MQTT QoS levels for industrial messaging.
raw/…) apart from curated, contextualized data, so consumers know which they are reading.# in production is a load test of your own system.Let’s look at your machine, your data flow or your production goal together. Describe your situation in a few sentences and the ASP Dijital team will reply by email.