Close-up of fiber optic strands carrying light

Architecture patterns

The designs that keep recurring

The same handful of designs solve most of the problems in this field. Each pattern states the product choice, the environments it serves and what breaks when it is built wrong.

Architecture patterns
26
Environments
49
Products used
82

Data diodes and one-way transfer

Pattern DD-A · Backup over a data diodeSizing against the backup window, the role of the middleware, and why restoring is the hard direction.

The backup server stays in production and hands the result to the diode. No path runs back.Production domainBackup domainBackup serverDDMW senderDDMW receiverBackup store, WORMOffline copyjob → filesdata diodehash verifiedno acknowledgement,no restore
The backup server stays in production and hands the result to the diode. No path runs back.Production domainBackup domainBackup serverDDMW senderDDMW receiverBackup store, WORMOffline copyjob → filesdata diodehash verifiednoacknowledgement,no restore
  • One-way path
  • Data path
  • Path that does not exist
The backup server stays in production and hands the result to the diode. No path runs back.
  1. DD-ABackup over a data diodeSizing against the backup window, the role of the middleware, and why restoring is the hard direction.
  2. DD-BLog export and evidence retentionSyslog passes natively without middleware, and the chain of custody gets stronger as a side effect.
  3. DD-COT export out, control or updates inTwo links in opposite directions, each with its own approval and its own decision owner.
  4. DD-DCross-domain publishing with a release decisionThe diode controls direction; the release decision controls content — and they are different mechanisms.
  5. DD-EFile lock between domainsFrom a USB stick to a one-way transfer, with the human decision made explicit rather than assumed.
  6. DD-FRugged one-way link from field sensorsVibration, temperature range and DC supply, with no maintenance while the unit is deployed.
  7. DD-GPresentation surface across a domain boundaryThe display is a shared, writable node between every domain connected to it.

TEMPEST/RÖS and the secure workplace

Pattern TE-A · The single workstation in a Level A zoneThe indivisible zone: every device in the chain carries the level, and the weakest one sets it.

The zone is indivisible. Every device inside carries the level, and the weakest one sets it.Level A zoneOutside the zoneClientPeripheralsPrintingNetworkMains supplyfiber across theboundaryrequires afilter
The zone is indivisible. Every device inside carries the level, and the weakest one sets it.Level A zoneOutside the zoneClientPeripheralsPrintingNetworkMains supplyfiber acrossthe boundaryrequires afilter
The zone is indivisible. Every device inside carries the level, and the weakest one sets it.
  1. TE-AThe single workstation in a Level A zoneThe indivisible zone: every device in the chain carries the level, and the weakest one sets it.
  2. TE-BRemote computer: KVM over fiberThe zone shrinks to the presentation surface, and the desk becomes an extension of the computer.
  3. TE-CThe red/black workstationTwo networks on one desk, with the separation physical rather than logical.
  4. TE-DThe briefing room with a shared displayThe bridge for an external client is a deliberate compromise, decided in advance and written down.
  5. TE-EFlow out of the zone: a diode in and outTwo diodes in opposite directions are not a bidirectional link, as long as they stay physically separate.
  6. TE-FThe print and registry nodePaper is a zone exit that no network diagram shows.
  7. TE-GFrom zero to an approved workstationOrder of operations, decision authority per step, and the two thresholds where mistakes get expensive.

Fiber communication, teleprotection and OT

Pattern FO-A · Teleprotection between two substationsThe optical budget and the delay budget are calculated together, because the link is part of the protection.

The link is part of the protection, not a service to it. Delay and symmetry decide.Substation ASubstation BProtection relayC37.94 converterC37.94 converterProtection relaydark fiber,symmetrical pathasymmetry becomesphase error, not analarm
The link is part of the protection, not a service to it. Delay and symmetry decide.Substation ASubstation BProtection relayC37.94 converterC37.94 converterProtection relaydark fiber, symmetricalpathasymmetrybecomes phaseerror, not analarm
  • Data path
  • Path that does not exist
The link is part of the protection, not a service to it. Delay and symmetry decide.
  1. FO-ATeleprotection between two substationsThe optical budget and the delay budget are calculated together, because the link is part of the protection.
  2. FO-BA C37.94 island inside an E1 or SDH networkWhere the clock master sits, and what happens to the protection when it disappears.
  3. FO-CGalvanic barrier and cross-connect inside the siteWhere the isolation boundary sits is a design decision, not an installation detail.
  4. FO-DA/B path with an optical switchTwo fibers in one cable is one path, and duplicated equipment on a shared breaker is not redundancy.
  5. FO-EOne-way release from OT, with a controlled returnOut is the default. Anything coming back is a separate link with its own approval.
  6. FO-FLink between security domains with a signature requirementThe diode removes the logical return path, the fiber removes the electrical one — the two reinforce each other.

KVM, HDBaseT and secure video conferencing

Pattern KV-A · Shared workstation with physical KVM switchingFour properties separate a secure KVM from an ordinary one: EDID emulation, one-way HID, no shared buffer, tamper indication.

The peripherals are shared. That is why they are the channel, and why the switch has to be physical.Operator positionDomainsKeyboard, mouse, headsetSecure USB DisconnectSecure KVM switchDisplay without an OSDomain 1Domain 2HID onlyactive domainno buffersurvives theswitch
The peripherals are shared. That is why they are the channel, and why the switch has to be physical.Operator positionDomainsKeyboard, mouse,headsetSecure USB DisconnectSecure KVM switchDisplay without an OSDomain 1Domain 2HID onlyactive domainno buffersurvives theswitch
  • Data path
  • Path that does not exist
The peripherals are shared. That is why they are the channel, and why the switch has to be physical.
  1. KV-AShared workstation with physical KVM switchingFour properties separate a secure KVM from an ordinary one: EDID emulation, one-way HID, no shared buffer, tamper indication.
  2. KV-BRemote compute over HDBaseT fiberThe link carries USB and two-way audio, which moves the security boundary away from where people assume it is.
  3. KV-CThe display as a pure receiverHDMI is not one-way: DDC runs in both directions, and EDID is a shared, writable object.
  4. KV-DCodec switch: several networks, one set of peripheralsThe control path sits outside every network, and the switch is sealed for exactly that reason.
  5. KV-EThe dual-use meeting roomWhat is disconnected, what is sealed, and what has to be physical when the same room is used at two levels the same day.
  6. KV-FOne-way outlet from a protected environmentThe image path can be one-way while the touch path is not.
Hands soldering a circuit board under a work lamp

Next step

Designing something that is not here?

Send us the constraints. We build from idea to certified end product, and most of what is in the catalogue started that way.