Diodes are Diodes and Guards are Guards

Author: Colin Robbins

15 Sep 2014

Diodes are Diodes, Guards are Guards

Over the last 3-5 years, Data Diodes have grown in popularity as a solution for moving data between isolated networks. With this has come creative marketing to leverage the term 'Diode' for solutions that are anything but.

Let's just take a few moments to revise some of the fundamental modes of secure information exchange.

Modes of secure information exchange

Protecting secrets

If you want to share information with a network, but that network has secrets to protect, the highest level of assurance you can obtain is to use a data diode to ensure information can only flow left to right, as demonstrated in the diagram below, and not right to left.

The Nexor white paper Protecting confidential information using Data Diodes describes how this works in detail. It also describes how content filtering works to ensure only a restricted subset of data is allowed over the connection.

This is a common scenario in high-security government and defence network.

Data Diode Solution - Diodes are Diodes, Guards are Guards

Protecting assets

Data Diode Solution - Diodes are Diodes, Guards are Guards

This is the reverse of the Protecting Secrets scenario, here there is data produced by the Assets that needs to be shared, but the network you are sharing with cannot be allowed to influence the assets in any way.

This is a common scenario in high-integrity industrial control systems, such as power generation and transport infrastructures. Here too, if you want a high level of assurance, Data Diodes are used.

One-way data, with protocol handshake

One of the difficulties with the diode approaches above is that the underlying communication protocol is often two-way. However, in lower assurance environments, the feedback is useful as it provides a mechanism for saying something has gone wrong. A good example is an email exchange – you want to know it has been delivered. The compromise is that by providing a feedback loop, you are reducing the assurance – you have fundamentally implemented two-way communication. In this case, you need a two-way data exchange solution, not a data diode.

Two-way data exchange (synchronous communications)

When you absolutely need two-way communications, then diodes do not have a role. This is where Data Guards come in – special-purpose appliances designed to allow the data flow, while providing high-assurance network separation and filtering. Note also the difference between a guard and a gateway.

Two-way, asynchronous communications

In this mode of communication, you fundamentally need data to flow both ways, but the information flows are not linked. A good example of this is described in the blog Secure Remote Camera Control, where streaming video flows one way, and pan-tilt-zoom controls the other.

Here, using diodes makes sense, as they are two independent data streams – it is hard (but not impossible) to create a two-way information flow.

What is the difference between a data guard and a data diode?

Both data duards and data diodes enhance network security, but they operate differently:

  • Data Diode: A hardware-based device that enforces physical one-way data flow. It guarantees no return path, offering the highest assurance for data isolation by relying on physics rather than software inspection.

  • Data Guard: Often a software-based solution (or combined with hardware) that inspects and filters data content as it moves between networks. It actively validates data against security policies and can facilitate more complex, yet controlled, information exchange.

In essence, a Data Diode is about guaranteed physical isolation, while a Data Guard focuses on intelligent content inspection and policy enforcement. They are frequently deployed together for a robust, multi-layered security approach.

Read more about what data diodes are and how they work.

How Nexor can help

This may seem complex, because it is complex; that is why we see so many security breach reports, security is hard. The critical element is to ensure you know what problem you are trying to solve, understand the threats, design a solution that mitigates the threats to an agreed level of assurance and is then implemented using best-of-breed products.

That's what we do at Nexor.

We don't try to dress a data guard up as a data diode, because that represents misinformation - integrity ought to extend beyond the data transmission!

Read more posts on

About the author

Colin Robbins is a Principal Security Consultant, leading customer-funded research activities in secure interoperability and information exchange. He has specific technical interests in the Single Information Environment and Data Centric Security, as well as the processes of security, such as Secure by Design and Information Security Management Systems (ISMS). He is a Fellow of CIISec, and a former NCSC certified Security and Information Risk Adviser (Lead CCP).

Colin Robbins on Linkedin

Read more posts by Colin Robbins