Product / Detail

TwinPath

Bidirectional access with directions fixed in hardware

Dual-Unidirectional Service Access Gateway

TwinPath uses two independent one-way systems in opposing directions to create a controlled round-trip service channel. Return data is present, while each physical path across the boundary retains its designed direction.

Logical topology / Dual-unidirectional paths

TwinPath logical topology with two opposing one-way systems

Two independent one-way systems / four logical endpoint roles

One-way system A

Request-path one-way system

Protected side → Designated service
Protected sideRequest-sending endpoint
Service sideRequest-receiving endpoint

One-way system B

Return-path one-way system

Designated service → Protected side
Service sideReturn-sending endpoint
Protected sideReturn-receiving endpoint
The two cross-boundary paths remain separate, and each transfers only in its marked direction. The four logical endpoint roles describe the fixed topology; they do not imply four physical appliances.

Access boundary / Constraints

TwinPath access boundary

  • Session initiation

    New sessions originate only from the protected side toward designated services

    The request direction carries service sessions established by the protected side and does not permit the service side to establish arbitrary sessions in reverse.

  • Service-side boundary

    The service side cannot initiate new sessions through TwinPath

    The return direction carries response data required by existing controlled service access; it does not become a new-session entry point for the service side.

  • Reachability

    Reachability is limited to configured services

    Service access is provided only for configured destinations and service scope; it does not turn the networks on both sides into a generally interconnected environment.

  • Hardware direction

    Software cannot reverse either one-way core

    Each physical cross-boundary path transfers only in its hardware-designed direction, and the two systems remain separate.

The complete TwinPath service channel includes a controlled return data path. This explicitly distinguishes it from the Falcon-1000 one-way data-release model.

Layered control / Comparison boundary

Boundary comparison with a software-only bidirectional firewall

Two physical paths with directions fixed in hardware reduce the cross-boundary attack surface relative to a software-only bidirectional firewall. This comparison addresses direction control and does not mean that every risk has been removed.

Firewalls and other layered controls retain their own protective roles. TwinPath does not replace existing service-side, network, or content-layer controls.

Physical deployment / Concept boundaries

Logical topology and physical packaging

Logical endpoint
Each one-way system has two logical endpoints; the two systems have four fixed endpoint roles in total.
One-way path
Each one-way system establishes one hardware path in a designated direction. The two paths are separate and run in opposing directions.
Physical appliance
Depending on the qualified supplier design, the two endpoints may be integrated into one 1U appliance or split across two 1U appliances.
Rack unit
1U describes the rack height of one physical appliance. It does not represent one logical endpoint, one one-way path, or the complete TwinPath system.

The physical appliance count is determined by the two selected qualified configurations; it cannot be inferred as a fixed count from the four logical endpoint roles.

Compatibility boundary / Qualified scope

Qualified One-Way Hardware Configuration boundary

Published compatibility is limited to the listed model, firmware, topology, and TwinPath version. Changing any element requires the resulting configuration to be qualified again.

The two directions may use one-way systems from different suppliers, but support applies only when that exact combination has been qualified.

A similar appearance, a component-level test, or another supplier combination does not inherit support automatically. Evaluation must use the complete configuration currently listed.