• Download
  • Products
    • Product Highlights
      • DataHub Smart MQTT Broker
      • DataHub IoT Gateway
      • DataHub OPC Gateway
      • DataHub service for Azure
      • DataHub OPC Bridge
      • OPC DataHub
      • DataHub WebView
      • DataHub Modbus OPC Server
    • Tunnellers
      • DataHub UA Tunneller
      • DataHub DA Tunneller
      • DataHub Tunnel A&E
      • DataHub Modbus Tunneller
      • DataHub DDE Tunneller
      • Individual Features
        • Redundancy
        • Data Diode Mode
        • Monitoring
    • Historians
      • Connect to InfluxDB
      • Connect to Amazon Kinesis
      • Connect to AVEVA Historian
      • Connect to AVEVA Insight
      • Connect to AVEVA PI
      • Connect to RESTful Systems
      • Connect to Kafka
      • Connect to ODBC
      • Connect to Azure Event Hubs
      • Connect to OPC Classic HDA
    • Notifications
      • Alarm and Notification
      • Email / SMS
      • OPC A&E support
      • OPC UA A&C support
    • Excel and DDE
      • DataHub Add-In
        for Microsoft Excel
      • DDE / Excel
    • Loggers
      • DataHub OPC Logger
      • DataHub Modbus Logger
  • Purchasing
    • How to Purchase
    • Request a Quote
    • Feature Matrix
    • Software Subscription Plan
    • Maintenance Support Plan
    • Educational Program
  • Learning Hub
    • Industries & Use Cases
      • Wind & Solar
      • Conventional Energy
      • Oil & Gas
      • Minerals & Mining
      • Manufacturing
      • Food & Beverage
      • Pharma & Healthcare
      • System Integration
      • Machines & Tools
    • Knowledge Center
      • Videos
      • Webinars
      • How-To
      • Case Studies
      • White Papers
      • Essential Guides
        • MQTT & Sparkplug Essentials
        • DataHub Security Essentials
    • Connecting
      • Industrial AI
      • Industrial IoT
      • Secure OT to IT
      • OPC
      • Historian
      • MQTT
        • Sparkplug
      • Database
      • Modbus
      • Excel
      • Web
      • Embedded
      • Open APIs
      • DHTP
      • Architecture
  • Support
    • FAQ
    • Documentation
    • Release Notes
    • Technical Specifications
  • About
    • Partners
    • Customers
    • Testimonials
    • Privacy Policy
    • Terms of Use
    • Legal Notices
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Download
  • Products
    • DataHub Smart MQTT Broker
    • DataHub IoT Gateway
    • DataHub OPC Gateway
    • DataHub service for Azure
    • DataHub OPC Bridge
    • OPC DataHub
    • DataHub WebView
    • DataHub Modbus OPC Server
    • Tunnellers
      • DataHub UA Tunneller
      • DataHub DA Tunneller
      • Tunnel A&E
      • DataHub Modbus Tunneller
      • DataHub DDE Tunneller
    • Historians
      • Connect to InfluxDB
      • Connect to Amazon Kinesis
      • Connect to AVEVA Historian
      • Connect to AVEVA Insight
      • Connect to AVEVA PI
      • Connect to RESTful Systems
      • Connect to Kafka
      • Connect to Azure Event Hubs
      • Connect to ODBC
      • Connect to OPC Classic HDA
    • Notifications
      • Alarm and Notification
      • Email / SMS
      • OPC A&E support
      • OPC UA A&C support
    • Excel and DDE
      • DataHub Add-in for Microsoft Excel
      • DDE / Excel
    • Loggers
      • DataHub OPC Logger
      • DataHub Modbus Logger
      • Monitoring
    • Individual Features
      • Redundancy
      • Data Diode Mode
      • Monitoring
  • Purchasing
    • How to Purchase
    • Request a Quote
    • Feature Matrix
    • Software Subscription Plan
    • Maintenance Support Plan
    • Educational Program
  • Learning Hub
    • Industries & Use Cases
      • Wind and Solar
      • Conventional Energy
      • Oil & Gas
      • Minerals & Mining
      • Manufacturing
      • Food and Beverage
      • Pharma and Healthcare
      • System Integration
      • Machines and Tools
    • Knowledge Center
      • Videos
      • Webinars
      • How-to
      • Case Studies
      • White Papers
    • Essential Guides
      • MQTT and Sparkplug Essentials
      • DataHub Security Essentials
    • Connecting
      • Industrial AI
      • Industrial IoT
      • Secure OT to IT
      • OPC
      • Historian
      • MQTT
        • Sparkplug
      • Database
      • Modbus
      • Excel
      • Web
      • Embedded
      • Open APIs
      • DHTP
      • Architecture
  • Support
    • FAQ
    • Documentation
    • Release Notes
    • Technical Specifications
  • About
    • Partners
    • Customers
    • Testimonials
    • Privacy Policy
    • Terms of Use
    • Legal Notices
process-data-through-data-diode-white-paper

How to Access Process Data Through a Data Diode

Executive Summary

Industrial organizations face a growing challenge: how to access plant data for analytics, optimization, and compliance, while preventing inbound cyber-attacks. Data diodes offer the most robust defense available for operational technology (OT) networks, but because these devices strictly enforce one-way communication, they are not compatible with standard industrial protocols. This white paper explores how the tunnel/mirror architecture employed by Cogent DataHub software can overcome these challenges, and provide secure, consistent, and flexible remote data access.

Key Takeaways:

  1. Data diodes provide the strongest isolation for OT networks, blocking all inbound data flows.
  2. Standard industrial protocols like OPC and MQTT cannot function across a diode.
  3. A tunnel/mirroring approach such as employed by Cogent DataHub software can connect OPC, MQTT, or other protocols across a data diode, maintaining compatibility, security, and consistency of data.

Introduction

In many industries the appetite for real-time process data is accelerating. AI-driven analytics, predictive maintenance systems, and advanced operational dashboards require continuous, high-quality information from the plant floor. Unfortunately, the same connectivity that enables insight also creates exposure. Cyberattacks against industrial control systems are becoming both more sophisticated and more frequent. This dual pressure—an increasing need for data in the midst of growing security threats—has led many organizations to consider using data diodes.

A data diode enforces a one-way flow of information. Like its namesake in electronics which permits current to pass in only one direction, a data diode transmits data out from a secured network while completely blocking inbound traffic. There are no inbound packets to inspect or filter because none are ever delivered. This absolute barrier makes a data diode the most effective way to protect mission-critical OT systems from external threats.

DMZs and Firewalls

In industrial cybersecurity architectures, data diodes may replace or work with other well-known security layers such as firewalls and demilitarized zones (DMZs). Firewalls filter inbound and outbound traffic based on rules, but they still must allow certain packets through, which could be exploited. A DMZ creates a segmented network zone to mediate access, but it does not physically enforce one-way flow. A data diode, on the other hand, is a unidirectional gateway that physically or logically ensures data moves only one way.  For environments where even one inbound data packet is unacceptable, a data diode offers the highest level of protection.

Protocol Challenges with One-Way Links

While the security advantages of a data diode are clear, the one-way constraint disrupts virtually every industrial communication protocol. OPC UA and MQTT, for example, are built around two-way messaging. They require acknowledgments, subscriptions, or handshake exchanges that a true data diode blocks outright.

To work around this problem, OPC UA’s Pub/Sub model supports one-way transmission over UDP. However, UDP offers no guarantees of delivery, ordering, or completeness. Packets may be dropped or arrive out of sequence, which is unacceptable in critical process environments. Network congestion, MTU size limits, and lack of inherent error correction all contribute to reliability risks.

MQTT requires a different kind of work-around.  Although MQTT clients can connect outbound through a firewall to a broker, the protocol still requires bidirectional flows for session management and quality of service monitoring. To successfully traverse a data diode, MQTT messages must be encapsulated.

The Tunnel/Mirror Solution

A tunnel/mirror approach resolves protocol challenges for data diodes. In this architecture, the source protocol—OPC UA, MQTT, or other—is encapsulated within a unidirectional transport that can pass through the diode. On the receiving side, a mirrored instance reconstructs the original protocol’s semantics for the consuming applications.

Data Diode Mode Hardware Support diagram

This approach inevitably changes certain behaviors. For example, synchronous transactions become asynchronous, which may be inconvenient in some use cases. On the positive side, an implementation like DataHub tunnel/mirroring replaces MQTT’s quality-of-service feature with guaranteed data consistency, where the most recent value of each point is always accurate even if intermediate updates are lost. DataHub tunnel/mirroring can also translate between protocols. For example, source data in OPC UA can be served outward as MQTT without losing value, timestamp, or quality metadata.

Aggregating Data into a Universal Namespace

Industrial facilities often generate and use data from a diverse range of sources, including PLCs, sensors, SCADA systems, databases, and historians. Consolidating these feeds into a single diode-protected path reduces infrastructure complexity. A tunnel/mirror system capable of handling OPC UA, OPC Classic, MQTT, Modbus, ODBC and others on both source and client sides enables the creation of a universal namespace. This unified layer can then be consumed directly or fed to an existing enterprise namespace.

Ensuring Consistency

Ensuring consistency of data is critical for many industrial processes. Usually, the exact sequence of transient states is less important than the accuracy of the current state. If a sensor value changes rapidly, the consuming system primarily needs the most recent reading. For example, if a valve cycles open and closed multiple times, operators typically only require confirmation of its present position. A tunnel/mirror solution that guarantees data consistency ensures that these final states are delivered consistently and maintained reliably.

Store-and-Forward Considerations

Network interruptions can occur for many reasons, making store-and-forward functionality desirable. Across a data diode, however, forwarding historical data is inherently one-sided. Without acknowledgments flowing back, delivery cannot be confirmed. Some tunnel/mirror tools, including the DataHub implementation, allow a sender to ‘rewind’ to retransmit missed data. However, if the receiver is offline, that information may be lost.

Software Emulation

Where a physical data diode is impractical, software emulation can deliver similar benefits. Cogent DataHub data diode mode, for example, makes a secure tunnel connection behave like a hardware data diode by discarding all inbound application data and preventing any reverse communication. Unlike data diode hardware, such a solution can also support SSL connections. The trade-off is that if the receiver is compromised, the SSL stack on the sender might be targeted. One advantage to this approach is that a software data diode may be more affordable, and/or easier to install and maintain.

Data Diode Mode Software Emulation diagram

Considering All Options

While data diodes excel in high-assurance isolation, they are not universally applicable. You need to consider all options. Processes requiring bidirectional control commands, frequent acknowledgments, or transactional integrity across the link may be served better by a layered firewall/DMZ solution.

Here again, a secure tunnel/mirror implementation stands out. Even without running in data diode mode, DataHub tunnel/mirroring allows you to keep all inbound firewalls closed, and pass data through a DMZ with guaranteed consistency of data from source to user.

In any case, just because you need to access your process data, there’s no need to compromise on security. A tunnel/mirror approach such as implemented by Cogent DataHub software can meet the most stringent security requirements of a data diode, or provide secure bi-directional data flow through closed firewalls and DMZs. There are viable options for virtually any architecture.

Try it Now Request a Quote Download the White Paper (PDF)

Learning Hub Posts

  • Fractal Unified Namespace — Frequently Asked Questions
  • webinar-OT-network-segmentation
    OT Network Segmentation Webinar Hosted by MAC Solutions
  • webinar-iiot-world-energy-panel
    IIoT World Energy Day: Extending Grid Capacity with IIoT and AI: From Data to Capital Decisions
  • UNS-white-paper-featured-image
    Stop Unifying Everything
  • How to access process data through a Data Diode
    How to Access Process Data Through a Data Diode
  • Cogent DataHub Service for Azure
    Cogent DataHub Service for Microsoft Azure from Skkynet
  • Secure OPC networking: OT to IT and the Cloud webinar
    Webinar: Secure OPC networking – OT to IT and the Cloud
  • How to connect OPC UA to OPC DA featured image
    How to convert OPC UA to OPC DA
  • Network Security is not enough for OT Data
  • best-practices-OT-to-IT-series-featured-image
    Best Practices: OT to IT
  • how-to-video-redundancy-featured-image
    How to Configure Redundancy
  • for-mqtt-smarter-is-better banner
    White Paper: For MQTT Smarter is Better
  • Use Case: Wind Farm Access featured image
    Use Case: Wind Farm Access
  • DataHub Apache Kafka title card
    New Historian Connections for DataHub Version 11
  • DataHub WebView Pages and Solutions title card
    WebView Enhancements for DataHub version 11
  • DataHub Security Model title card
    New Security Model for
    DataHub version 11
Cogent DataHub footer logo white
  • Download
  • Products
  • Purchasing
  • Learning Hub
  • Support
  • About
  • Back to Top
  • LinkedIn iconTwitter iconYouTube icon

Skkynet
302-2233 Argentia Road
Mississauga, ON L5N 2X7

International: 1-905-702-7851
US toll free: 1-888-702-7851

[email protected]
[email protected]
[email protected]
[email protected]

© 2026 Skkynet | All rights reserved | Legal notices
Scroll to top Scroll to top Scroll to top

We are using cookies to give you the best experience on our website.

You can find out more about which cookies we are using or switch them off in .

Cogent DataHub Logo
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Cookie Policy

More information about our Cookie Policy