Patent attributes
A hardware turnstile including a system-on-chip data security appliance (a diode). The diode includes a single-chip device defining a protected boundary co-incident with a boundary of the single-chip device, a first and a second communication interface, an electronic processor located within the protected boundary, a data transfer control component located within the protected boundary, and memory located within the protected boundary. The electronic processor is configured to selectively allow a designated one-way transfer of data appearing on the first communication interface to the second communication interface using the data transfer control component, based on data stored in the memory. The electronic processor is also configured to selectively modify fixed format data appearing on the second communication interface for transmission to the first communication interface using the data transfer control component based on data stored in the memory and discard all other data appearing on the first or second communication interfaces.