← All use cases

Secure OT-to-IT Historian Transfer

Transfer selected OPC UA and OPC XML data from Level 2 to an IT database through a hardware-enforced one-way optical path.

A physically one-way path from OT to IT.

The complete Diodos transfer system is shown as one protected boundary: South PC, one-way fiber-optic converter and North PC.

OPC UA & OPC XMLLevel 2 · OT sources
DIODOS ONE-WAY TRANSFER SYSTEM
Diodos South PCLevel 3 · collects and sends
One-way fiber-optic converterHardware-enforced direction
Diodos North PCLevel 4 · receives and reconstructs
DatabaseIT historian / approved SQL destination
HISTORIAN REPLICATION

Incremental OT history, delivered one way

OTDataMule reads only records newer than the committed checkpoint, preserves source identity and buffers the resulting batches before hardware-enforced transfer to the IT historian.

IT HISTORIANEnterprise history and analytics
6
Replay-safe writeDeduplicate · preserve source time · commit destination range
DashboardsFresh replicated history
AnalyticsGoverned time-series access
ReportingIT-side consumers
Validated batches and deterministic record IDs
IT DELIVERYIndependent destination session
5
Reconstruct and reconcileDetect duplicates · verify time range · expose gaps
LEVEL 3.5 / ONE-WAY BOUNDARYHistorian records move toward IT only
Diodos Data DiodeHardware-enforced OT-to-IT transfer
No IT query reaches the production historian
OT BUFFERStore-and-forward resilience
4
Persistent batch queueRetention · integrity · capacity alarms · ordered replay
Incremental records after checkpoint
OT EXTRACTIONRead-only local access
2
Query approved tagsHistorian API · OPC UA · SQL view · vendor connector
3
Advance checkpointLast source time + record identity committed after local persistence
New history only
PRODUCTION OTAuthoritative source history
1
Production historianTags · timestamps · quality · annotations · batch context
Gap detectedExpected and delivered time ranges do not align.
Local backfill requestOT-side extractor reads the missing approved range.
One-way replayBackfill follows the same diode path with duplicate protection.
Reference replication pattern. Checkpoint semantics and backfill behaviour depend on the source historian API and destination write model.
FreshnessNewest replicated source timestamp
CheckpointLast committed source position
Queue capacityRemaining outage retention
IntegrityGaps, duplicates and rejects

No return network path.

South-side collection

The Level 3 South PC reads approved OPC UA and OPC XML data from Level 2 sources.

Optical enforcement

The fiber-optic converter physically permits transmission only from South to North.

North-side delivery

The Level 4 North PC reconstructs the transfer and writes it to the approved database.

Designed for high-assurance segmentation.

Protocol-aware input

Collect from OPC UA and OPC XML sources without exposing the OT endpoints to IT.

Hardware-enforced direction

The security property does not depend on a software firewall rule or routing configuration.

Controlled database output

Only the selected, reconstructed historian data reaches the Level 4 destination.

Validate one secure historian flow.

Define the OT sources, one-way boundary and target database.

Discuss a one-way historian transfer