Data diode

PLASMA DD: purpose, specifications, compliance

A one-way security gateway for guaranteed unidirectional data transfer between networks of different access levels.

State Service of Special Communications expert conclusion No. [TBC]

The One-Way Security Gateway (OSG) PLASMA DD, or Data Diode, is a hardware and software complex developed and manufactured by NVP «Plasmotekhnika». It is designed to organise one-way communication between two networks with different security levels, in which information is physically transferred in one direction only. One-way operation is guaranteed at the hardware level: the return channel is physically absent from the product, so it cannot be opened by a configuration error, by malicious software, or by the actions of an intruder.

The PLASMA DD OSG holds a State Service of Special Communications expert conclusion (No. [TBC]) and is supplied directly by the manufacturer — with design of the connection scheme, implementation and subsequent support.

PLASMA DD hardware and software complex: transmitter and receiver units
PLASMA DD one-way security gateway

Purpose and application scenarios

As soon as an isolated network gains any connection to the external environment, a risk of information leakage and intrusion from outside arises. Software segmentation tools — firewalls, gateways, VPNs — are bidirectional by nature: their security rests on the correctness of settings and the absence of vulnerabilities. The PLASMA DD OSG solves the problem differently: data can physically move in only one direction, and this is a property of the hardware architecture, not a rule in the configuration that can be changed or bypassed.

The direction of transfer is determined by the task: from a closed segment to an open one (controlled export of data with no risk of intrusion inward) or from an open segment to a closed one (delivery of data inward with no possibility of leakage outward).

PLASMA DD OSG application examples

  • Transferring telemetry, event logs and monitoring data from a protected network to external collection and analysis systems (SIEM, monitoring centres) — with no possibility of affecting the data source.
  • Delivery of software updates, antivirus databases and signatures to isolated segments that have no internet access.
  • One-way export of documents or reporting from a closed perimeter to an open one for further processing.
  • Segmentation of operational and corporate networks: transferring fault and alarm logs from industrial OT networks to the IT/management segment — with no risk of interference in operational control.
  • Secure monitoring of dispatch data for urban infrastructure (water utilities, district heating networks).
  • Protection of internal banking systems: transaction accounting, customer databases, internal registers, payment gateways.
  • Transferring data from medical information systems with no risk of external interference in internal processes; segmentation of «clean» and external networks when working with intellectual property.

In each of these scenarios, the PLASMA DD OSG acts as a controlled exchange point: the protected segment remains isolated while the required data flow is not interrupted. For the head of the institution this is a legitimate way to combine isolation with business processes; for the IT unit, a predictable connection scheme without rebuilding the network; for the information-protection unit, a guarantee confirmed by documents rather than settings alone.

Advantages of the PLASMA DD OSG

  • A modern and reliable information-protection solution that provides the highest possible level of assurance.
  • A Ukrainian product that has passed examination at the State Service of Special Communications and Information Protection of Ukraine.
  • Continuous development of new functionality to address end users’ tasks, and support from qualified specialists.
  • The PLASMA DD OSG already protects state information resources of Ukraine.

How a data diode differs from a firewall

A firewall filters bidirectional traffic according to rules: an error in the rules, a vulnerability in the program code or the compromise of an administrator account opens a return channel. In a data diode there is no return channel at the physical level, so the guarantee of one-way operation does not depend on settings, updates or the qualifications of personnel. For the most critical connections this is a fundamentally different class of guarantee that cannot be reproduced by software.

Application schemes

The typical schemes for connecting the PLASMA DD OSG into the customer’s network are shown below.

  • Protection against leakage of restricted information (confidential, secret) from a highly protected network.
  • Schemes for transferring data into a highly protected network.
  • A scheme for transferring data from a highly protected system to external consumers.
  • Enabling the use of qualified electronic signatures (QES) in highly protected networks.

Technical specifications

The PLASMA DD OSG consists of a PLASMA DD transmitter unit (1 Gbps or 10 Gbps), a PLASMA DD receiver unit (1 Gbps or 10 Gbps) and dedicated software; if required, dedicated cryptographic information-protection software is added to the complex. The main product specifications are given in the table. A full technical description with details of protocols and configuration options is provided on request via the form at the bottom of the page.

ParameterValue
Operating principleHardware-guaranteed one-way data transfer
Throughput1 Gbps or 10 Gbps (configuration options)
Complex compositionPLASMA DD transmitter unit, PLASMA DD receiver unit, dedicated software
Cryptographic protectionIf required — dedicated cryptographic information-protection software
Supported protocols and transfer scenarios[TBC]
Configuration / form factor[TBC]
Power supply[TBC]
Operating conditions[TBC]
Dimensions and weight[TBC]

Documents and compliance

The PLASMA DD OSG holds a State Service of Special Communications expert conclusion (No. [TBC]) confirming the product’s compliance with the requirements of the regulatory documents of the technical information security system. This makes it possible to use the data diode as part of comprehensive information protection systems (CIPS) and in information and communication systems undergoing security assessment.

  • State Service of Special Communications expert conclusion: No. [TBC].
  • NVP «Plasmotekhnika» TPI licences and permits: details [TBC].
  • Manufacturer details for verification by a security service: LLC «Research and Production Enterprise «Plasmotekhnika», EDRPOU code 30023446, 03056, Kyiv, vul. Politekhnichna 16, office 021.

If your institution is transitioning from a CIPS to ICS security authorization under Resolution No. 712 of the Cabinet of Ministers of Ukraine, using tools with valid expert conclusions simplifies justifying the system architecture and passing the assessment. We support such a transition as a separate service — see authorization under Resolution No. 712.

Integration and support

We not only manufacture the data diode but also implement it ourselves. This removes the typical «manufacturer separate, integrator separate» problem, where no one is responsible for the solution actually working in the customer’s real network. The developer and the engineering team work in Kyiv, so matters of service, consultation and refinements are resolved directly with the manufacturer, without intermediaries.

  • Survey and design: we determine the segmentation point, the direction of transfer, the types and volumes of data, and prepare the scheme for connecting the product into the network.
  • Implementation: installation, configuration of applied transfer scenarios, and testing together with the customer’s IT and information-security units.
  • Certification: if required, we carry out the full scope of technical information security work — from CIPS design to certification and instrumental control.
  • Manufacturer support: warranty and post-warranty servicing, consultations from the design engineers; terms and timelines — [TBC].

The PLASMA DD OSG is complemented by the enterprise’s other in-house products: the secure workstations PLASMA-ZV-ARM/MONO (passive protection against leakage via technical channels) and PLASMA-ZARM/AZ (active protection). Together they cover the typical pairing of «a secure workstation + controlled data exchange between perimeters».

Obtain a technical description and consultation

Send a request via the form at the bottom of the page — we will provide the PLASMA DD OSG technical description, a copy of the expert conclusion and a commercial proposal. For a substantive response, please indicate: which networks you plan to segment, the desired direction of transfer, the types of data and the approximate volumes.

You can also ask questions by phone: +38 (044) 204-83-62. NVP «Plasmotekhnika», 03056, Kyiv, vul. Politekhnichna 16, office 021.

State Service expert conclusion

PLASMA-ZV-ARM/MONO

Passive protection

A secure workstation for processing restricted information, with passive protection against leakage via technical channels.

View product
State Service expert conclusion

PLASMA-ZARM/AZ

Active protection

A secure workstation with active protection against information leakage via technical channels.

View product

Technical information security

Need documents or a technical brief?

Send a request — we will prepare a conclusion, a specification or a response to your brief.

By submitting the request, you agree to the privacy policy.