Glossary · OT security engineering
Unidirectional gateway
Also known as: Unidirectional security gateway, One-way gateway
German: Unidirektionales Gateway
In OT network security, a unidirectional gateway is a combination of data diode hardware, which physically permits data flow in one direction only, and software on both sides that replicates servers or emulates protocols, so that industrial data such as historian values or alarms can be sent out of a protected network without any path back in.
- Security engineering
- OT security
In one sentence
A unidirectional gateway combines one-way data diode hardware with replication software to send industrial data out of a protected network with no path back.
Example
A unidirectional gateway replicates the plant historian to a copy in the enterprise network; business users query the replica, while nothing can be sent into the control network.
How it applies
- Engineering: The software on the protected side collects data, for example from a historian, OPC server or syslog, and sends it through the diode; the software on the other side rebuilds it as a replica server or forwards it. Each protocol or application to be replicated needs support in the gateway software.
- Operation: Use cases that need a return path, such as remote control, remote updates or acknowledgements from enterprise systems, cannot run through the gateway and need a separate, controlled solution.
- Maintenance: Replication must be monitored: a stalled transfer means business users see outdated data without noticing.
- Documentation: Architecture and operating documents should list the replicated data sources, update rates and the limits of the replica (for example no write access). Tell users in the enterprise network that they see a copy, not the live system.
Unidirectional gateway vs. data diode
A Data diode is the hardware that enforces one-way flow. A unidirectional gateway adds the software needed to make industrial applications work across it.