What Is a Data Diode? How Unidirectional Gateways Protect OT Networks
A data diode is a hardware device that allows network traffic to travel in one direction only, with the return path made physically impossible rather than simply blocked by a rule. In operational technology environments, that difference matters enormously. A firewall decides what to allow based on configuration that a person wrote and a person can change. A data diode decides based on the physical construction of the device itself, so no configuration error, stolen credential, or software exploit can reverse the direction of flow.
This guide explains what a data diode is, how one way enforcement works at the hardware level, where unidirectional gateways fit into an industrial network, and why they have become a standard control for protecting industrial control systems.
What Is a Data Diode?
A data diode is a network security device that enforces one way data transfer using hardware rather than software. It is also referred to as a unidirectional gateway or a unidirectional security gateway. Data can pass from the protected network out to a less trusted network, but nothing can travel back in the opposite direction.
The name comes from the electronic component it behaves like. An electrical diode permits current to flow in one direction and blocks it in the other. A data diode applies the same principle to network traffic. Engineers who work with process equipment often find a mechanical comparison easier: a data diode behaves like a check valve in a pipe. Flow is permitted one way, and the physical construction of the valve prevents flow the other way regardless of pressure.
The practical result is that a data diode removes the inbound attack surface entirely at the boundary where it is deployed. An attacker on the receiving network has no route back into the protected network, because no route exists to exploit.
How a Data Diode Works
Most high assurance data diodes are built around an optical core. The transmit side of the device contains an optical transmitter but no optical receiver. The receive side contains a photodetector but no transmitter. Because neither side has the component required to send signal back toward the source, the return path does not exist in hardware. This is what people mean when they describe one way flow as being enforced by physics rather than by software.
The TCP problem and the protocol break
This design creates an immediate technical challenge. Most network communication relies on TCP, and TCP requires acknowledgements travelling back to the sender to confirm that packets arrived. Across a true data diode, those acknowledgements can never return.
Data diodes solve this with proxies on each side of the device. The proxy on the send side terminates the original TCP session from the source system and converts the payload into a one way stream. The diode passes that stream across the optical gap. The proxy on the receive side rebuilds a fresh TCP session and delivers the data to the destination system.
This is known as a protocol break, and it is a significant security benefit in its own right. Because no session ever passes end to end, protocol level attacks that depend on manipulating a live connection cannot cross the boundary. The source and destination systems never speak to each other directly at any point.
Reliability without acknowledgements
Since the receiving side cannot request a retransmission, data diodes use forward error correction and controlled redundancy to protect against packet loss. Well engineered appliances also provide monitoring on the receive side so operators can confirm that expected data is arriving, along with alerting when a stream stops.
|
Key point A data diode is not a firewall with a strict rule set. It is a device where the reverse path has been removed from the hardware. There is no configuration in which it can be made to pass traffic backwards. |
Data Diode vs Airgap
Many industrial sites still describe their control networks as air gapped, meaning there is no network connection at all between the OT environment and the outside world. In practice, true air gaps are rare and getting rarer. Business teams need production data, vendors need remote support access, and maintenance staff need to move files and updates in and out.
When there is no network path, data still moves. It moves on USB drives, contractor laptops, and portable hard disks, which is one of the most reliable ways malware has historically entered isolated industrial environments. The air gap becomes a manual process with no logging and no control.
A data diode addresses this directly. It gives an operator the inbound protection of an air gap while allowing outbound data to flow automatically, continuously, and with full logging. In many environments a unidirectional gateway is stronger in practice than the air gap it replaces, because it removes the need for removable media.
Why OT and ICS Networks Need Unidirectional Gateways
The pressure on industrial networks has changed considerably over the past decade. Operators are expected to deliver production data to enterprise systems, feed telemetry to cloud analytics platforms, forward security events to a SOC, and support predictive maintenance programmes. Every one of those requirements creates a reason to connect the OT network to something else.
The risk is not theoretical. Ransomware incidents at major industrial operators have repeatedly followed the same pattern, where the initial compromise lands on the corporate IT network and operations are then halted because the operator cannot confirm that the control environment is unaffected. A boundary that eliminates the inbound path removes that uncertainty.
Several characteristics make OT environments particularly suited to unidirectional protection:
-
Consequences are physical. A compromise in an industrial network can lead to equipment damage, environmental release, or harm to personnel, not simply data loss.
-
Legacy systems cannot be patched quickly. Controllers and field devices often run for decades and cannot be updated on a normal cycle, so reducing exposure matters more than remediating vulnerabilities.
-
Data flow is genuinely one directional. In most OT to IT use cases, the business only needs to read operational data. Nothing legitimate needs to travel back into the control network.
-
Availability is the priority. A device that cannot be misconfigured into allowing inbound traffic protects uptime as well as security.
What Data Diodes Actually Transfer
A common misconception is that unidirectional gateways only handle simple file copies. Modern appliances support a wide range of industrial and IT data flows through application aware proxies:
-
Historian replication, including plant historian data sent to an enterprise or cloud historian
-
Syslog, security events, and alerts forwarded to a SIEM or a security operations centre
-
File and folder transfer, including scheduled batch exports
-
OPC UA and OPC DA process data
-
Modbus and other industrial protocol data
-
Database replication for reporting and analytics
-
Video surveillance streams from plant cameras
-
Print and reporting streams from operational systems
Protocol support is one of the most important practical differences between products. An appliance with native connectors for the systems already installed at your site will deploy in days. One without them will require custom engineering work.
Where Data Diodes Fit in IEC 62443
The IEC 62443 standard organises industrial networks into zones, which are groups of assets sharing a trust level, and conduits, which are the communication channels between zones. Every conduit must be secured to the higher of the two Security Levels it connects. Our IEC 62443 Compliance Playbook explains this zone and conduit model in more detail.
A data diode is one of the strongest conduit controls available. Where a firewall demonstrates compliance through rule sets that must be reviewed, documented, and audited over time, a unidirectional gateway demonstrates it through the physical properties of the device. This makes the compliance argument considerably simpler, and it is a common reason operators targeting Security Level 3 or Security Level 4 choose a diode for their most critical boundaries.
The same logic applies where safety systems are involved. A safety instrumented system that an attacker can reach is no longer a dependable safety system, which is why functional safety and cybersecurity need to be considered together when protecting these zones.
Common Data Diode Use Cases
OT to SOC monitoring
Security teams need visibility into the control network, but giving a SOC platform a two way connection into OT creates a new path inward. A data diode allows logs, alerts, and network telemetry to flow out to the SOC while keeping the monitoring platform itself outside the trust boundary.
Historian and analytics data export
Production data is replicated from the plant historian out to enterprise reporting systems or a cloud analytics platform. This is the single most common deployment, and it maps naturally to one way flow because the business only ever needs to read the data.
Remote and unmanned site monitoring
Upstream oil and gas sites, substations, water treatment facilities, and other remote assets often send telemetry back to a central operations centre. A diode ensures that the central platform cannot become a route into the remote site.
Safety system data egress
Where operators need visibility into safety instrumented system performance without exposing the SIS to any inbound traffic, a unidirectional gateway is often the only acceptable solution.
What a Data Diode Does Not Do
Being clear about the limitations matters as much as understanding the benefits.
-
It does not replace every firewall. Boundaries that legitimately require two way communication still need a firewall. A data diode protects the boundaries where inbound traffic should never be possible.
-
It does not inspect content on its own. A diode controls direction, not payload. Where files cross the boundary, pair the diode with content disarm and reconstruction or antivirus scanning on the appropriate side.
-
It does not remove the need for the fundamentals. Asset inventory, network segmentation, access control, and monitoring all remain necessary. A diode strengthens the boundary; it does not secure the zone behind it.
-
It cannot be made bidirectional. If a use case genuinely requires two way traffic, a diode is the wrong tool for that boundary. Some operators deploy diode pairs in opposing directions for separate, strictly controlled flows, but each device remains one way.
Frequently Asked Questions
Can data get back through a data diode?
No. In a hardware enforced optical data diode, the components required to transmit signal in the reverse direction are not present. There is no configuration setting, firmware change, or exploit that can create a return path, because the path does not exist physically.
Is a data diode the same as a unidirectional gateway?
The terms are used interchangeably in most contexts. Some vendors use unidirectional gateway to describe the complete product including the proxy and application software, and data diode to describe the hardware enforcement core specifically. Functionally they refer to the same category of one way transfer device.
Do data diodes slow down data transfer?
Modern appliances handle throughput from around one gigabit per second up to twenty five gigabits per second and beyond, which is sufficient for the large majority of industrial data flows including video. The proxy layer introduces a small amount of latency, which is rarely material for the monitoring and reporting use cases diodes are deployed to serve.
Can you send files through a data diode?
Yes. File transfer is one of the most common applications. The send side proxy accepts the file, the diode passes it across the optical gap, and the receive side proxy writes it to the destination with integrity checking to confirm the transfer completed correctly.
Do data diodes work with industrial protocols like Modbus and OPC?
Yes, through application aware proxies. This is why native protocol support is such an important evaluation criterion. A diode that already understands your historian, control system, and industrial protocols will integrate far more easily than one requiring custom development.
Choosing the Right Approach
If you are weighing a unidirectional gateway against your existing perimeter controls, our comparison of data diodes and firewalls sets out where each technology is the right choice and why many operators deploy both.
If you have already decided that a diode is the right control and are now evaluating suppliers, our guide to choosing a data diode vendor covers certification levels, protocol coverage, throughput, and the questions worth asking before you commit.
Arista Cyber delivers, deploys, and supports the OWA data diode appliance range across North America, with certified optical diode cores and native connectors for the industrial systems already running in your plant.
|
Protect your OT boundary with hardware enforced one way flow Speak with an Arista Cyber specialist about where a data diode fits in your environment. |