one-way information flow
An architectural security property of an information path between two systems or domains in which data is permitted to travel in only one direction — from source to destination — with no return channel possible. It distinguishes itself from general access control by regulating *where* data can travel rather than *who* may access it, making bidirectional communication structurally or physically impossible rather than merely policy-prohibited. Standards bodies such as NIST (SP 800-53 AC-4 and SP 800-171 3.1.3) cite it as an enforcement mechanism alongside write-permission verification and regrading, specifically "employing hardware mechanisms to enforce one-way information flows" — typically realized as a data diode or unidirectional security gateway — applied wherever networks of differing confidentiality or integrity must be separated, such as preventing back-channel exfiltration into classified networks or blocking malware ingress into high-integrity industrial control systems.
Senses
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- one-way information flows
- possessive
- one-way information flow's
- pluralpossessive
- one-way information flows'