A data diode is a security device that allows data to travel in one direction only – physically. Where a firewall is software that decides what may pass, a data diode is hardware that makes reverse traffic impossible: the sending side has only a transmitter, the receiving side only a receiver. There is nothing to misconfigure, no rule set to get wrong, and no software path for an attacker to exploit.
The principle is old and unglamorous. It is also the reason data diodes are trusted in places where nothing else is.
How it works
The mechanism is easier to grasp physically than logically. Inside the unit, the link between the two sides is optical, and it is deliberately incomplete: on the send side there is a light source but no detector; on the receive side a detector but no light source. Light travels one way across the gap because there is no component on the far side capable of sending it back.
That has an immediate consequence for protocols. TCP – the basis of most network traffic – requires acknowledgements travelling back to the sender. Across a true diode, those acknowledgements cannot exist. So one-way transfer works with protocols that do not need a return path:
- UDP in all its forms – unicast, broadcast, multicast, manycast
- Syslog, for exporting security and system logs
- NTP broadcast, for time distribution into an isolated network
- SNMP traps, for alerting outward from protected equipment
For file transfer and other applications that assume a two-way conversation, middleware on both sides terminates the protocol, moves the payload across the diode, and reconstructs it on the far side. The application believes it had a normal exchange. The wire never carried one.
The one-way protocols are covered in detail here.
Why one-way transfer matters
Any connection that can carry data in can carry an attack in. That is not a statement about a particular vulnerability; it is a property of bidirectional links.
Critical networks frequently need to export information without ever accepting anything back. A power grid control system needs to send process data to the operations office. A classified network needs to publish reports to a lower domain. A hospital’s medical device network needs to deliver measurements to an analysis system. In each case the outward flow is required and the inward flow is pure risk.
A firewall reduces that risk by filtering. A data diode removes the return path altogether. The comparison with firewalls is worth reading in full, because the difference is not one of degree.
What it does not do
A data diode is not a general-purpose security product, and overselling it does customers no favours.
It does not inspect content. Anything the sending side transmits reaches the receiving side, including malformed or malicious data. If the sending network is compromised, a diode faithfully exports the compromise. Content inspection, if needed, is a separate function on one side or the other.
It does not solve authentication or confidentiality. Data crossing a diode is not thereby encrypted or verified.
And it enforces one direction, which means the direction has to be the right one. A diode installed to protect a control network exports data outward; if someone later needs to send configuration in, the diode is not the obstacle to work around – the requirement has changed and the design needs revisiting. Bidirectional variants exist for cases that genuinely need a controlled return channel, using two independent one-way paths rather than a relaxed single one.
Where they are deployed
Process and telemetry data flows out to office and analysis systems while the control network stays unreachable from them. This is the largest single use, and the regulatory pressure behind it keeps increasing.
One-way transfer between classification domains – typically from a lower domain into a higher one, or exporting sanctioned reports downward – where a cross-domain solution must be demonstrable rather than merely configured.
Tamper-proof export of security logs to a monitoring centre. Because the diode makes the return path physically absent, an attacker who compromises the monitoring side cannot reach back into the systems being monitored.
Measurement and imaging data leaving isolated device networks without exposing those networks to the hospital’s general IT environment.
What to consider when choosing one
Diodes are specified in data rate, from 100 Mbit to multi-gigabit. Size for the actual peak, not the average – there is no back-pressure mechanism to slow a sender down.
Stand-alone units for a single link, rack card modules where several links share a chassis, and rugged units for field and vehicle installations where temperature, vibration and shock matter.
Multimode over short distances within a building, singlemode where the link is long. The difference is explained here.
If the diode sits in a TEMPEST-protected environment, the diode itself has to meet the level. A certified workplace with an uncertified network device in it is not certified.
Ask what makes the one-way property verifiable: sealed enclosures, tamper evidence, and a hardware design where the absence of a return path can be inspected rather than taken on trust.
Built in Sweden
Fibersystem builds data diodes as stand-alone units, 19-inch rack modules, rugged field units and HDMI variants, at speeds from 100 Mbit upward, in multimode and singlemode – with TEMPEST Level A and RÖS U1 certified versions where the environment requires it. Design, development, certification and production happen in one building in Stockholm.





