Technology
The Fox DataDiode works by enforcing the use of a single strand of a fibre optic connection. This lack of full duplex communication breaks the use of TCP/IP. This problem is addressed by using dropbox proxies which transmit data in a connectionless way.
A typical Data Diode setup consists of two proxies. One of the proxies is placed in the Black network (which can be directly connected to the Internet). The other proxy is placed in the Red network. A one-way physical connection is made between the two proxies to prevent data leakage and guarantee the security of the red network. Each proxy has an easy-to-use web interface that allows authorized users to configure what is to be transferred from where (Black side) to where (Red side). A transfer can contain files, streaming video, or incoming email. This greatly increases the possibilities of people working on the red network.
The Solution
The Fox DataDiode offers security and data integrity, enhanced through the use of event logging, and error detection and correction. It also boasts an easy transfer procedure and user-friendly interface. Furthermore, users of the receiving network are able to receive e-mail from outside their network, print locally or access frequently used websites or databases, all without exposing their high-security network to outside risks or threats.
Read moreCertifications
The Fox DataDiode, or more precisely the hardware data diode, has a Common Criteria EAL 7+ certificate. It has also been indepently evaluated and approved by two EU member states (Netherlands and Germany) for use up to and including Secret national classification levels, i.e. Stg Geheim and Geheim. Finally, the hardware diode of the Fox DataDiode is listed in the NATO Information Assurance Product Catalogue (NIAPC) and is approved for use up to and including Nato Secret (NS).
Read moreDiode Hardware
The hardware Data Diode of the Fox DataDiode solution provides the security of the system. Based on the laws of physics it guarantees that information flows from one side to another but not the other way. In principle it is a guaranteed one-way wire.
Read moreDiode Software
The Fox DataDiode software is available in two versions. The government version running on OpenBSD and the business version running as a Windows Service. Both versions provide the option to flexibly transfer information from one network to another over an one-way connection such as a Data Diode.
Read moreDiode Servers
The Fox DataDiode proxy servers are a standard part of the Fox DataDiode solution. We always use high-performance Industrial Grade rack servers to provide a high-reliable network appliance.
Read moreAdditional Options
The Fox DataDiode solution can be augmented with various specific customer requirements. We support for example ruggedized casings for easy transport to remote locations, TEMPEST of the Hardware Diode and the servers based on NATO SDIP-27, fiber to serial convertors, provide Mil-Spec or industrial grade proxy servers, etc.
Read moreDiode Explained
The Fox DataDiode explained by the guy who works with secret information. Short stop-motion animation on the what, why and how of the Fox DataDiode product.
Read more