Glossary · OT security engineering
Data diode
Also known as: One-way data link
German: Datendiode
In network security, a data diode is a hardware device that physically allows data to flow in only one direction between two networks, typically from a more trusted network such as a control network to a less trusted one, so that no data or commands can be sent back.
- Security engineering
- OT security
In one sentence
A data diode is a hardware device that physically permits data flow in only one direction between two networks, so nothing can be sent back.
Example
A power plant sends process values from its control network through a data diode to the corporate network, where they feed dashboards; no connection from the corporate side can reach the control network.
How it applies
- Engineering: One-way transmission is enforced by the hardware, for example by an optical link with a transmitter on one side and only a receiver on the other. Because standard protocols such as TCP need acknowledgements, software on both sides is needed to transfer data; see Unidirectional gateway.
- Operation: Data diodes suit monitoring use cases: historians, dashboards, log export. They prevent remote control, remote updates and bidirectional protocols through the same path, which must be planned separately.
- Maintenance: The diode itself needs little configuration, but the proxy software and the data flows it replicates must be maintained and monitored for gaps.
- Documentation: Architecture documents should state which data crosses the diode, in which direction and in which format, and how updates or remote service reach the protected network instead.
Data diode vs. firewall
A Firewall enforces rules in software and allows bidirectional traffic; a misconfiguration can open a path. A data diode physically cannot pass traffic back, which gives stronger assurance at the cost of flexibility.