Pattern DD-A

Backup over a data diode

Sizing against the backup window, the role of the middleware, and why restoring is the hard direction.

Area
Data diodes
Environments
1
Products used
6

How it is built

The backup server stays in production and hands the result to the diode. No path runs back.Production domainBackup domainBackup serverDDMW senderDDMW receiverBackup store, WORMOffline copyjob → filesdata diodehash verifiedno acknowledgement,no restore
The backup server stays in production and hands the result to the diode. No path runs back.Production domainBackup domainBackup serverDDMW senderDDMW receiverBackup store, WORMOffline copyjob → filesdata diodehash verifiednoacknowledgement,no restore
  • One-way path
  • Data path
  • Path that does not exist
The backup server stays in production and hands the result to the diode. No path runs back.

How it works

The backup server stays where it is and keeps doing its job. What changes is the destination: instead of writing to storage it can read back from, it hands the result to the middleware’s sender node. The sender terminates the protocol, sends the payload as a one-way stream across the diode, and the receiver rebuilds the files and verifies the hash before writing them to the store.

The hard part is sizing

The receiving side cannot ask the sender to slow down. Send more than the link carries and the excess is lost — and the sender does not notice. For telemetry a lost sample is noise; for backup a lost file is a broken restore that surfaces when it is needed.

Size for the peak, not the average. The largest single job, divided by the actual window in seconds, plus the middleware’s redundancy, plus margin for interleaved jobs — then compare against 1 Gbit, which is the ceiling in this catalogue. A production network with several terabytes of nightly change does not fit across a 1 Gbit link however well the flow is built. Write that into the study rather than discovering it at commissioning.

Verification without an acknowledgement

Nothing comes back, so verification has to be built as an independent flow out of the backup domain to a third place — not as a return path. Three mechanisms, in the order they should be introduced: a manifest per job listing what was sent, a heartbeat that alarms when it stops, and a periodic test restore. A pattern without the third is not verified. It is monitored.

In the catalogue

Equipment from the catalogue

Standard

Data Diode Middleware (DDMW)

Software solution for transferring data over data diodes in such a controlled manner. It consists of a sender…

Product no 60-00-7367

TEMPEST Level A · RÖS U1

Data Diode Secure 1 Gbit MM TEMPEST

Data rate
1 Gbps
Wavelength
Multimode 850 nm
Input, LC
1000 BaseSX

Product no 60-00-7303

Standard

Data Diode Secure 1 Gbit SM

Data rate
1 Gbps
Wavelength
Singlemode 1310 nm
Input, LC
1000 BaseLX

Product no 60-00-8362

Standard

Rack 19" 3 HU 16 Slots SNMP

Fibersystem’s new enterprise-class 50-502 Rack System is designed to provide a flexible manageable system for…

Product no 60-00-6918

Standard

Data Diode Bidirectional 1 Gbit Dual AC

Secure two-way communication using a fully hardware-based design that removes any risk of data flowing in the…

Product no 60-00-7563

Standard

Data Diode Bidirectional 1 Gbit Dual DC

Secure two-way communication using a fully hardware-based design that removes any risk of data flowing in the…

Product no 60-00-7564

Hands soldering a circuit board under a work lamp

Next step

Designing something that is not here?

Send us the constraints. We build from idea to certified end product, and most of what is in the catalogue started that way.

Verified credentials

All certifications