Knowledge base

What is a data diode?

A data diode is hardware that physically enforces one-way data transfer between networks. How it works, why it beats a firewall for critical systems, and where it is used.

Reading time: 4 minUpdated:

A data diode is a security device that allows data to travel in one direction only – physically. Where a firewall is software that decides what may pass, a data diode is hardware that makes reverse traffic impossible: the sending side has only a transmitter, the receiving side only a receiver. There is nothing to misconfigure, no rule set to get wrong, and no software path for an attacker to exploit.

The principle is old and unglamorous. It is also the reason data diodes are trusted in places where nothing else is.

How it works

The mechanism is easier to grasp physically than logically. Inside the unit, the link between the two sides is optical, and it is deliberately incomplete: on the send side there is a light source but no detector; on the receive side a detector but no light source. Light travels one way across the gap because there is no component on the far side capable of sending it back.

That has an immediate consequence for protocols. TCP – the basis of most network traffic – requires acknowledgements travelling back to the sender. Across a true diode, those acknowledgements cannot exist. So one-way transfer works with protocols that do not need a return path:

  • UDP in all its forms – unicast, broadcast, multicast, manycast
  • Syslog, for exporting security and system logs
  • NTP broadcast, for time distribution into an isolated network
  • SNMP traps, for alerting outward from protected equipment

For file transfer and other applications that assume a two-way conversation, middleware on both sides terminates the protocol, moves the payload across the diode, and reconstructs it on the far side. The application believes it had a normal exchange. The wire never carried one.

The one-way protocols are covered in detail here.

Why one-way transfer matters

Any connection that can carry data in can carry an attack in. That is not a statement about a particular vulnerability; it is a property of bidirectional links.

Critical networks frequently need to export information without ever accepting anything back. A power grid control system needs to send process data to the operations office. A classified network needs to publish reports to a lower domain. A hospital’s medical device network needs to deliver measurements to an analysis system. In each case the outward flow is required and the inward flow is pure risk.

A firewall reduces that risk by filtering. A data diode removes the return path altogether. The comparison with firewalls is worth reading in full, because the difference is not one of degree.

What it does not do

A data diode is not a general-purpose security product, and overselling it does customers no favours.

It does not inspect content. Anything the sending side transmits reaches the receiving side, including malformed or malicious data. If the sending network is compromised, a diode faithfully exports the compromise. Content inspection, if needed, is a separate function on one side or the other.

It does not solve authentication or confidentiality. Data crossing a diode is not thereby encrypted or verified.

And it enforces one direction, which means the direction has to be the right one. A diode installed to protect a control network exports data outward; if someone later needs to send configuration in, the diode is not the obstacle to work around – the requirement has changed and the design needs revisiting. Bidirectional variants exist for cases that genuinely need a controlled return channel, using two independent one-way paths rather than a relaxed single one.

Where they are deployed

Power and industrial control

Process and telemetry data flows out to office and analysis systems while the control network stays unreachable from them. This is the largest single use, and the regulatory pressure behind it keeps increasing.

Defence and government

One-way transfer between classification domains – typically from a lower domain into a higher one, or exporting sanctioned reports downward – where a cross-domain solution must be demonstrable rather than merely configured.

Log and event collection

Tamper-proof export of security logs to a monitoring centre. Because the diode makes the return path physically absent, an attacker who compromises the monitoring side cannot reach back into the systems being monitored.

Healthcare and research

Measurement and imaging data leaving isolated device networks without exposing those networks to the hospital’s general IT environment.

What to consider when choosing one

Throughput

Diodes are specified in data rate, from 100 Mbit to multi-gigabit. Size for the actual peak, not the average – there is no back-pressure mechanism to slow a sender down.

Form factor

Stand-alone units for a single link, rack card modules where several links share a chassis, and rugged units for field and vehicle installations where temperature, vibration and shock matter.

Fiber type

Multimode over short distances within a building, singlemode where the link is long. The difference is explained here.

Certification

If the diode sits in a TEMPEST-protected environment, the diode itself has to meet the level. A certified workplace with an uncertified network device in it is not certified.

Assurance evidence

Ask what makes the one-way property verifiable: sealed enclosures, tamper evidence, and a hardware design where the absence of a return path can be inspected rather than taken on trust.

Built in Sweden

Fibersystem builds data diodes as stand-alone units, 19-inch rack modules, rugged field units and HDMI variants, at speeds from 100 Mbit upward, in multimode and singlemode – with TEMPEST Level A and RÖS U1 certified versions where the environment requires it. Design, development, certification and production happen in one building in Stockholm.

Environments this article explains

15 real installations, filterable by area

Showing all 15 environments

In the catalogue

Products related to this topic

Standard

Data Diode Secure 100 Mbit MM

Data rate
100 Mbps
Wavelength
Multimode 1310 nm

Product no 60-00-7304

Standard

Data Diode Secure 1 Gbit SM

Data rate
1 Gbps
Wavelength
Singlemode 1310 nm
Input, LC
1000 BaseLX

Product no 60-00-8362

TEMPEST Level A · RÖS U1

Data Diode Secure 1 Gbit MM TEMPEST

Data rate
1 Gbps
Wavelength
Multimode 850 nm
Input, LC
1000 BaseSX

Product no 60-00-7303

TEMPEST Level A · RÖS U1

Data Diode Rugged 1 Gbit MM TEMPEST

Secure one-way (simplex) hardware-based connection between two networks, ensuring that no data can ever flow…

Product no 60-00-7131

Standard

Data Diode Middleware (DDMW)

Software solution for transferring data over data diodes in such a controlled manner. It consists of a sender…

Product no 60-00-7367

Standard

Data Diode Bidirectional 1 Gbit Dual AC

Secure two-way communication using a fully hardware-based design that removes any risk of data flowing in the…

Product no 60-00-7563

Next step

A question the guides don't answer?

Ask the people who build the hardware – our engineers in Stockholm answer directly, no sales script.