
- Architecture patterns
- File lock between domains
Pattern DD-E
File lock between domains
From a USB stick to a one-way transfer, with the human decision made explicit rather than assumed.
- Area
- Data diodes
- Environments
- 2
- Products used
- 2
How it is built
- One-way path
- Data path
- Path that does not exist
Used in these environments
How it works
Media is carried in, read in a staging zone, validated, and only then released onward. The staging zone is the pattern: without it, the file lock is a USB port with a procedure attached.
A staging zone is not a DMZ
A DMZ is reachable from both sides. A staging zone is not reachable from the protected domain at all — validation results move outward, never inward on request.
This is where the protection gets worked around
A file lock that takes fifteen minutes when someone needs a file now is a file lock that gets bypassed by a USB stick and a friendly colleague. The countermeasure is not training. It is making the sanctioned path faster than the unsanctioned one, and designing for the case where it is not.
In the catalogue
Equipment from the catalogue



Next step
Designing something that is not here?
Send us the constraints. We build from idea to certified end product, and most of what is in the catalogue started that way.
Verified credentials
All certifications- Swedish Armed ForcesM-numbered equipmentMain supplier, Total Defence

- Government of SwedenSupplier to Swedish authoritiesPolice · FMV · FOI

- NATOCertified TEMPEST supplierSDIP-27 · Level A & B

- ISO 9001 14001ISO certifiedQuality & environmentDownload certificate (JPG)
- SOFFDefence industry memberExport control frameworks

- Made in SwedenDesigned & built in StockholmSecure supply chain
