Safeguarding the Core: How Data Diodes Fortify Nuclear Power Plants Against Cyber Threats
Explore how data diodes provide hardware-enforced security for nuclear power plants, enabling safe data sharing while preventing cyber threats from reaching critical control systems. Learn about real-world deployments, regulatory guidance from DoE and NRC, and practical applications in OT/IT convergence.
Safeguarding the Core: How Data Diodes Fortify Nuclear Power Plants Against Cyber Threats
In an era where cyberattacks can cripple critical infrastructure, nuclear power plants stand as prime targets. Enter data diodes: hardware devices that enforce one-way data flow, acting like digital check valves. These one-way transfer devices ensure information travels outward from sensitive systems but has no physical ability to transmit in the reverse direction, thwarting hackers at the gate. Today, U.S. nuclear facilities rely on them to maintain strict isolation, guided by recommendations from the Department of Energy (DoE) and bodies like the Nuclear Regulatory Commission (NRC). Here is how they work, where they are deployed, and why data diodes show up repeatedly in NRC guidance.
The Simple Design Behind Data Diodes
Data diodes are intentionally simple devices, both in physical design and in implementation. Our Expanse Data Diode (EDD) line takes that a step further.
In the world of engineering, complexity is the architect of catastrophe. With each additional layer of complexity in a system, a new vulnerability emerges.
Where competitors may use custom Ethernet-based hardware solutions and FPGAs, we use the ubiquitous and commoditized Standard Form-factor Pluggable (SFP) purely optical approach. This limits our threat surface to an easily auditable and incredibly small footprint while also eliminating entire classes of side-channel attacks that competing products are susceptible to. Use of the SFP form-factor also allows our clients to utilize their existing network infrastructure and equipment (i.e. switches, routers, media converters, etc.) without needing to plan for additional power, storage, or cooling requirements to accommodate the hardware.
Our approach is simple:
One data diode transmit module sits on the boundary of your secure, low-threat network (OT control & monitoring / plant side) and one data diode receive module sits on the boundary of your less secure, high-threat network (IT LAN). Systems monitoring and historian information is then forwarded between networks while maintaining an air-gap and meeting NRC 10 CFR 73.54 requirements. This network link is made immutable and deterministic through physical hardware, whereas a firewall may be compromised.
Real-World Deployment in U.S. Nuclear Facilities
Nuclear power plants across the U.S. integrate data diodes to create airtight network segments. The DoE's Office of Nuclear Energy has poured resources into this tech, funding studies that position data diodes as essential for communication designs.
Below is a diagram from Idaho National Laboratory, illustrating a defensive architecture with implementation of data diodes at layers 2 and 3 of the architecture.[1]
Simple, notional secure defensive architecture.
"Communicating between levels, intralevel communication, is much simpler in that only one-way communication is only permitted using deterministic, hardware-based network segmentation (i.e. data diodes)." —Sandia National Laboratory[2]
NRC Regulations & Compliance
The Nuclear Regulatory Commission (NRC) is the U.S. regulatory authority with independent oversight of nuclear power plants, fuel cycle facilities, radioactive material uses, and waste management.
As one might imagine, nuclear is a heavily regulated industry for environmental, health, and national security purposes. The regulatory structure applicable to the cybersecurity of nuclear facilities can be seen above. The authority structure flows from top to bottom:
Federal Law (Authority Level)
Atomic Energy Act of 1954 & Energy Reorganization Act
-
Gives the Nuclear Regulatory Commission (NRC) legal authority over nuclear facility safety, security, and cyber systems.
-
Establishes the requirement that nuclear facilities must protect against sabotage, espionage, and cyber-attack.
This is the root of all nuclear cyber requirements.
Code of Federal Regulations (Binding Rule)
10 CFR 73.54 – Protection of digital computer and communication systems and networks[3]
-
The core mandatory rule governing cybersecurity for U.S. commercial nuclear plants.
-
Requires licensees to provide "high assurance" that digital systems important to safety, security, and emergency preparedness (SSEP) are protected from cyber-attack.
-
Performance-based (it does not tell plants how to design networks).
Requires a Cyber Security Program, CDAs, defensive architecture, access controls, monitoring, incident response, etc.
The rule requires protection and isolation of critical digital systems. A diode is one method used downstream to implement this.
NRC Regulatory Guidance (How to Meet the Rule)
NRC Regulatory Guide 5.71 – Cyber Security Programs for Nuclear Facilities[4]
This is NRC's official interpretation of how to comply with 10 CFR 73.54.[4] It defines a defensive architecture divided into security levels comprised of Network segmentation, Isolation boundaries, and One-way data transfer mechanisms (data diodes).[4]
RG 5.71 recommends hardware-enforced unidirectional communication from higher-security networks to lower-security networks.[4] It also endorses NEI 08-09 – Cyber Security Plan for Nuclear Power Reactors[5] which outlines many specifications for when / where / how to implement data diodes in your architecture. A plant's Cyber Security Program is typically based on NEI 08-09.[5] It also has various technical implementation checklists that no longer apply when using data diodes due to their simplicity and elimination of a need for complex configuration. This document is created by the Nuclear Energy Institute (NEI) and has been reviewed and endorsed by NRC as an acceptable way to implement 10 CFR 73.54.[5]
RG 5.71 borrows heavily from NIST security controls 'AC-4 Information Flow Enforcement', more specifically: 'AC-4(7) Hardware-based unidirectional flow mechanisms'.[6]
Conclusion
-
DoE & NRC funded research highly recommends data diode usage, outlines how and where to implement, and it is templated into NEI-08-09 while also significantly reducing security checklist items.
-
DoE, NRC, NEI and NIST all outline the importance of unidirectional gateway appliance / data diode usage to safeguarding critical systems.
Domain Systems provides turnkey solutions, such as our Industrial Line Expanse Data Diodes, which pair hardware with optional software for high-throughput performance. We back all of our products with decades of experience in defending and attacking sophisticated networks while operating under the National Security Agency, U.S. Cyber Command, and adjacent intelligence community partners.
Domain Systems is ready to secure your network from beginning to end. We manufacture, QA test, and perform hands-on installation of your data diodes to ensure your security and success.
Learn More: For information on how we can help secure your nuclear infrastructure, or if you're just in need of advice on meeting 10 CFR 73.54, please email us at: [email protected].
References
- Cyber Risk Considerations for Nuclear Digital I&C Systems - Idaho National Laboratory
- Cyber-Physical Risks for Advanced Reactors - Sandia National Laboratories
- 10 CFR 73.54 - Protection of digital computer and communication systems and networks - U.S. Nuclear Regulatory Commission
- NRC Regulatory Guide 5.71 - Cyber Security Programs for Nuclear Facilities - U.S. Nuclear Regulatory Commission
- NEI 08-09 - Cyber Security Plan for Nuclear Power Reactors - Nuclear Energy Institute
- NIST SP 800-53 - Security and Privacy Controls for Information Systems and Organizations - National Institute of Standards and Technology