Domain Systems

Expanse Network Stack

Modular command-line utilities for network communication across unidirectional data diode links. TCP bridging, reliable file transfer, and custom pipelines for Expanse deployments.

sender: file transfer pipeline

Sender side

cat filelist.txt | ens-file-reader | ens-pitcher --udp-target-address 10.10.1.2

Receiver side

ens-catcher --udp-listen-port 8080 | ens-reorderer | ens-file-writer
→ Stream ID 0x4a2f91c8 · 1,247 packets · complete

Protocol bridging for one-way links

Traditional protocols like TCP require bidirectional communication: the three-way handshake, acknowledgments, and flow control all depend on a return path. Data diodes physically prevent that. Without specialized software, their use is severely limited.

ENS bridges that gap. A collection of modular, interoperable utilities you chain together with standard Unix pipes, building custom data flow pipelines tailored to your deployment, from simple syslog forwarding to complex TCP session bridging.

Three categories, one pipeline

Every ENS tool fits into Sources, Sinks, or Manipulators. Compose them into pipelines for any unidirectional data flow.

Sources

Convert raw data into ENS packets

  • ens-stdin
  • ens-file-reader
  • ens-tcp-server
  • ens-http-server

Sinks

Reconstruct ENS packets into usable data

  • ens-stdout
  • ens-file-writer
  • ens-tcp-client
  • ens-http-client

Manipulators

Optimize and process packet streams

  • ens-buffer
  • ens-reorderer
  • ens-rate-limiter
  • ens-error-on-dropped-packets

Network I/O

UDP transmission across the diode

  • ens-pitcher (send)
  • ens-catcher (receive)

Everything you need across the diode

TCP Bridging

Bridge TCP applications across unidirectional links. ens-tcp-server and ens-tcp-client maintain session traffic without requiring bidirectional handshakes on the diode.

Modular Pipelines

Chain tools with Unix pipes to build exactly the data flow your application needs. Born from GNURadio-style modularity with SDR-world terminology.

Packet Reordering

Automatic out-of-order packet handling via ens-reorderer. Essential when using UDP across diode links where packets may arrive out of sequence.

Reliable File Transfer

Drop-box file transfer with ens-file-reader and ens-file-writer. Forward error correction and retransmission reduce or eliminate packet loss.

Rate Limiting & Buffering

Control transmission rates and buffer data for performance. Prevent overwhelming receivers that cannot communicate back across the diode.

For Expanse Deployments

The complete toolkit for protocol bridging, file transfer, and custom pipelines across Expanse diode links — with no metered restrictions.

Typical deployment patterns

Compose sender and receiver pipelines independently. Each side mirrors the other's architecture.

Basic stream

Sender

ens-stdin | ens-pitcher

Receiver

ens-catcher | ens-stdout

File transfer

Sender

ens-file-reader | ens-pitcher

Receiver

ens-catcher | ens-reorderer | ens-file-writer

TCP bridge

Sender

ens-tcp-server | ens-pitcher

Receiver

ens-catcher | ens-reorderer | ens-tcp-client

Advanced

Sender

ens-tcp-server | ens-buffer | ens-rate-limiter | ens-pitcher

Receiver

ens-catcher | ens-reorderer | ens-error-on-dropped-packets | ens-tcp-client

Custom ENS protocol

A purpose-built packet format with stream IDs, sequence numbers, and control flags, supporting multiple concurrent streams over a single diode link.

FieldSizeDescription
Magic3 bytesAlways "ENS"
Size2 bytesPayload size
Flags2 bytesEndOfStream, Error
Sequence4 bytesPacket sequence within stream
Stream ID4 bytesUnique stream identifier

Common questions

Is ENS included with Expanse hardware?

ENS is the software layer for Expanse deployments. Expanse Data Diode hardware enforces physical one-way flow; ENS adds TCP bridging, reliable file transfer, and composable pipelines across the link.

Do I need ENS for simple UDP protocols?

Not necessarily. Stateless UDP protocols like syslog, SNMP traps, and NetFlow can often be forwarded with standard Linux tools. ENS is designed for protocols requiring session management, reliable file transfer, or TCP bridging.

How does ENS differ from Lattice?

ENS is the modular toolkit of command-line utilities for building data flow pipelines. Lattice is the enterprise platform that orchestrates ENS tools, adds ticket-based file transfer with JWT authorization, and provides a web operations dashboard.

Where can I find documentation?

Licensed customers receive access to ENS documentation at docs.domainsystems.us, including quick-start guides, architecture patterns, performance tuning, and industry-specific deployment examples.

Expanse Data Diode

Physical SFP+ modules that enforce one-way data flow. Pair with ENS for protocol bridging across the link.

Learn about Expanse

Lattice

Enterprise CDS software that orchestrates ENS pipelines, manages file transfers, and provides operator dashboards.

Learn about Lattice

Ready to build your first pipeline?

Contact our team for deployment guidance, architecture templates, and access to the full ENS documentation suite.