INDUSTRY
Smart City, EV charging, EnergyBACKGROUND
This document describes a reference architecture for municipal and commercial EV charging site operators running mixed-generation charging equipment across distributed locations. Protocol assignments, polling intervals, VPN topology, and power-management settings are configured for each deployment.CHALLENGES
A charging infrastructure operator needs a reliable way to connect geographically distributed EV charging sites to a central monitoring platform. Field equipment may span two generations: legacy controllers and energy meters that communicate over Modbus RTU on RS-485, and newer controllers that provide Modbus TCP over Ethernet. Building one communication architecture without replacing serviceable charging equipment is the core requirement.Dedicated communication lines are impractical across dispersed locations, which leaves the public mobile network as the realistic transport. That brings its own constraints:
- Public cellular services commonly use carrier-grade NAT (CGNAT) and dynamically assigned private addresses. Unless the service provides a public or static IP address or a private APN, inbound connections from the control center may not be available.
- Operational data travels over a network the operator does not control, so cybersecurity is a genuine concern.
- Gateways are installed in compact outdoor or semi-outdoor cabinets that are already warm, already crowded, and already exposed to electromagnetic interference from power-conversion equipment.
- Cellular links drop. The operator needs to know which site is offline, not just that data has stopped arriving.
SOLUTION PROVIDED
ATOP cellular gateways create a standardized LTE communication layer for mixed generations of charging equipment. In this example, ATOP PG5201B and SE5201B share the same platform, security model, and industrial envelope. The model is selected according to the field interface at each site.Reaching sites over a public mobile network
When inbound reachability is unavailable, a VPN tunnel gives the control center a managed path to the site. Both PG5201B and SE5201B support IPsec, OpenVPN, or L2TP tunnels, and the control center can poll each site through its tunnel. The tunnel therefore provides both encrypted transport and a consistent addressing path. Sessions are initiated by the control center, and data flows in both directions inside the tunnel.
Firewall rules, NAT, and port forwarding control what traffic is permitted once the tunnel is established.
Legacy sites: protocol conversion at the gateway
PG5201B connects to legacy charging controllers and energy meters through its serial port, which is software-selectable between RS-232 and 2-wire RS-485. On the bus, the gateway acts as the Modbus RTU master and polls the connected devices.
Configuration is done in eNode Designer, where protocol applications are assigned to ports, and field data points are mapped to the protocol the control center expects. A Full-License version allows more than one protocol to run simultaneously on the front-end and back-end sides.
Field changes and alarms are detected on the next configured PG5201B poll, with end-to-end alarm latency depending on northbound polling, device response and retry settings, cellular-network conditions, and monitoring-platform processing.
Ethernet-based sites: secure cellular access
Where controllers already provide Modbus TCP over Ethernet, no protocol conversion is required. SE5201B provides a secure cellular path and the control center polls the chargers through the tunnel. Fast Ethernet ports are available for LAN or WAN use.
Cabinet conditions and power
Both models accept 9 to 48 VDC, so they connect directly to the 12 V, 24 V, or 48 V auxiliary supply already present in a charging cabinet. Both use a metal housing with IP30 protection, carry industrial EMC protection, and operate from -30 °C to +75 °C. The high end is what matters in this application, since a sealed outdoor cabinet in direct sun can exceed 60 °C.
Both models consume less than 3 W in idle operation and less than 100 mW in hibernation at 12 VDC. In a charging cabinet, this low-power profile reduces the heat added to an enclosure that is already handling waste heat from the charging equipment, simplifying thermal design.
While a mains-powered charging site normally requires continuous monitoring, power-constrained deployments such as solar-battery-powered systems can utilize schedulable power management with sleep and hibernate modes.
Where a site provides backup power for the gateway and the monitoring platform is configured with communication-health checks, the gateway can stay reachable after the site loses mains power, which lets the platform distinguish a site power outage from a network fault.
Site I/O and fleet management
Each gateway provides one digital input and one digital output for cabinet-level signals, such as door or tamper status and connection to an external alarm or reset circuit, subject to the applicable I/O electrical ratings. SIM card slots and GNSS are also available depending on model or as an option.
Management can be centralized through ATOP management software. PG5201B additionally supports configuration backup and restore to and from a remote TFTP server, which helps standardize repeat deployments.
ARCHITECTURE BENEFITS
- Works over public mobile networks: IPsec, OpenVPN, or L2TP tunnels give the control center a reachable path to every site. Dedicated communication lines can be avoided.
- Legacy Modbus RTU and Ethernet-based Modbus TCP charging equipment can report into the same monitoring architecture, so serviceable field devices can be preserved.
- Firewall, NAT, and port forwarding control permitted. One security and addressing model covers every site, whether or not protocol conversion is needed there.
- Where per-site communication health is configured on the platform, an offline site can be identified rather than inferred from missing data.
- Adding a site means deploying one more gateway with the same VPN, firewall, addressing, and polling configuration, which keeps expansion a deployment task rather than a design task.
ADD-VALUES
- Idle power below 3 W and hibernation below 100 mW at 12 VDC on both models, which limits the thermal load added inside the cabinet.
- Industrial 9 to 48 VDC input, metal housing with IP30, EMC protection, and -30 °C to +75 °C operation.
- Digital input and output for cabinet-level signals.
- Remote management tools and configuration support available for consistent multi-site deployment.
- Made in Taiwan and carry a 5-year warranty. PG5201B is TAICS Level 2 certified.
PRODUCTS USED
| Product | Best fit | Role in this architecture |
|---|---|---|
| PG5201B | Legacy serial equipment on RS-232 or 2-wire RS-485 | Protocol conversion and secured LTE access |
| SE5201B | Ethernet-based Modbus TCP equipment | Secure LTE access and pass-through without protocol conversion |
SYSTEM TOPOLOGY

Reference architecture. The control center polls both sites through VPN tunnels; sessions are initiated by the control center and data flows in both directions inside each tunnel. PG5201B also converts Modbus RTU field data; SE5201B provides secure cellular access for Ethernet-based chargers.