← All Blackline products

Cross Domain Security

Blackline-CDS Cadmium

Cadmium / Blackline-CDS is Blackline Systems Corporation's Canadian Cross Domain Solution (CDS) platform for controlled movement of files and streaming IP data between security domains. It combines a hardware-enforced unidirectional security boundary (data diode), protocol filtering, hardware-assisted protocol policing and optional content inspection.

CSE certified to TS EAL 4+ RTB 5.1 compliant NSA approved OWT list Designed & built in Canada
Blackline-CDS Cadmium 1U cross domain security appliance
Blackline-CDS 1U secure one-way transfer platform

One-way transfer, with more control

A highly integrated cross domain platform

Cadmium is Blackline Systems' high-assurance Cross Domain Solution platform. Blackline-CDS provides controlled transfer between networks with different security classifications or trust levels, supporting both streaming and file-based flows. Its architecture separates source and destination security domains and uses a hardware-enforced one-way boundary so the transfer path cannot become an ordinary bidirectional network connection.

Diagram showing source network, Blackline CDS, destination network and separate administrative access
One-way transfer architecture with independent administrative access on source and destination sides.

Streaming data

TCP, UDP and SYSLOG flows with hardware-assisted protocol enforcement and very low latency.

File transfer

Direct cut-through or Store & Forward movement using supported secure and standard file protocols.

Content inspection

Optional native and third-party inspection can be configured as a pipelined, flow-specific policy.

TCPUDPSYSLOGFTPFTPSSFTPHTTPSMQTTSMTPSYSLOG/TLS

Independent assurance

Common Criteria EAL4+ evaluated unidirectional subsystem

The Blackline Systems Corporation BSC-CDS Unidirectional Subsystem PN 710-0185-00 is the evaluated one-way security subsystem used within the Blackline cross domain architecture. The Canadian Common Criteria certification report records an EAL4+ evaluation completed under the Canadian Common Criteria Program.

What the evaluation covers

The Security Target describes the BSC-CDS Unidirectional Subsystem as part of a cross-domain solution (data diode) providing reliable unidirectional throughput while preventing establishment of a reverse communication channel.

Independent references

Review the official certification information directly from the Canadian Centre for Cyber Security and the international Common Criteria portal.

Canadian Common Criteria certified products
BSC-CDS Security Target (Common Criteria Portal)

Security architecture

Separate sides. Hardware-enforced boundaries.

The platform uses independent source and destination cards joined by a unidirectional fibre link. Hardware-assisted packet filtering and protocol policing are performed by NXP T2080 network processors, with secure key storage and cryptographic functions.

Protocol security

Cadmium extends its RTB 5.1 architecture into the internal one-way transfer boundary. Its hardware-assisted protocol policing is designed to address the RTB 5.1 OWT-17 requirement family, including OWT-17, OWT-17.1, OWT-17.2 and OWT-17.3, by enforcing the proprietary internal transport in processor hardware rather than relying only on software inspection.

  • Hard context-sensitive firewalling on interfaces
  • Hardware-assisted protocol air gap, with protocol policing implemented by NXP T2080 DPAA filtration-management hardware
  • Proprietary unidirectional protocol across the internal fibre boundary; permitted frame structure and transport characteristics are validated by hardware pattern matching before normal software processing
  • Non-conforming internal transport frames are identified and directed away from the normal transfer path, while a hardware-specific integrity value provides an additional validation check

Physical security

  • Tamper-evident and tamper-resistant packaging
  • Live and shelf tamper detection
  • Configurable tamper actions
  • Monitoring for enclosure, temperature, voltage and probing events

Data protection

  • Secure key storage and encrypted keys
  • CNSA 2.0 cryptographic algorithms used for certificates and keys on protected transport interfaces
  • Encrypted SSD storage
  • Integrated wipe facility
  • Separate source and destination security domains

Hardware protocol policing: Cadmium uses processor DPAA hardware pattern matching to validate protocol characteristics, direct violations to controlled queues and check Blackline-specific frame integrity information in hardware.

Content inspection

Native filtering and third-party Sentry integration

Inspection operates above the transport layer and is configured per flow. Native and off-board inspection can be mixed in a pipelined chain designed around RAIN principles: redundant, always-invoked, independent and non-bypassable.

Blackline CDS diagram illustrating native on-board filtering between source and destination networks
Native on-board filtering can be applied on the source and destination sides and combined with off-board inspection.

Native inspection

For Store & Forward file flows, native inspection capabilities include file metadata checks, XML normalization and schema validation, XML signature validation using uploaded certificates, and JSON format/schema checks.

Sentry off-board inspection

Dedicated Sentry interfaces allow application-agnostic third-party inspection for secondary XML vetting, content removal, malware detection, proprietary inspection and other specialized functions. Up to eight named processes can be chained on a flow.

HTTPS deliveryICAP supportFlow-specific chainsOptional file return

Measured performance

Low latency with near-gigabit streaming throughput

Current 1Gbps SFP interfaces combine hardware crypto, filtering and queue handling with an eight-core network processor architecture.

FlowMeasured throughput
UDP881 Mbps
TCP822 Mbps
FTP765 Mbps
FTPS451 Mbps
SFTP239 Mbps
HTTPS241 Mbps
7 µsMinimum looped UDP latency (Theoretic)
312 µsAverage looped UDP latency (Measured)

Latency figures in the source presentation are for a minimal 64-byte UDP datagram in a looped test and include approximately 3 µs of serialization delay. 10Gbps/SFP+ is identified as roadmap capability.

Administration, audit & monitoring

Operational control without a universal super-user

A browser-based HTTPS console exposes role-specific capabilities for administration, operation and monitoring. The design separates responsibilities across five enforced roles.

Blackline CDS web administration console showing configured flows
Flow administration in the Blackline-CDS web console.

User Admin

Manages user names, passwords and privileges.

Systems Admin

Manages flows, communications, protocols and addresses.

Security Admin

Manages certificates, keys, security policy and tamper actions.

Operator / Monitor

Audit operations and read-only system status functions are separated from administration.

Audit and forensic support

On-platform logging covers audit, system, security and quarantine events along with content-inspection reports. Logging can be file based and/or delivered through SYSLOG, with support for UDP or TCP/TLS.

Off-platform SYSLOG can also be configured as a protected data flow from the source WAN interface to the destination WAN interface.

Blackline CDS monitoring view showing three systems tiled side by side
Read-only monitoring view can be tiled to show multiple Blackline-CDS platforms.

Deployment patterns

One-way, two-way and resilient architectures

The same platform can support several deployment models, from a single secure transfer path to paired systems for inspected request/response workflows.

Bulk one-way transfer

Move file or streaming traffic between networks with different security ratings using a single Blackline-CDS platform.

Secure request / response

Deploy two one-way systems back-to-back to build an inspected CDS path where requests and responses are independently validated.

Streaming redundancy

Use source and destination application signalling to switch to a secondary protected path if delivery fails or a destination response is not received.

Blackline CDS secure stream redundancy architecture with primary, secondary and feedback units
Reference architecture for protected streaming redundancy.

Flexible test and integration environments

The presentation also documents a three-unit demonstration setup combining high- and low-side servers, a Sentry server, native XML validation and third-party malware checking. It demonstrates that native and external inspection can be composed into different paths without changing the underlying one-way security model.

Blackline CDS demonstration rack with three Cadmium units and associated servers
Blackline test environment with three Blackline-CDS units.

Platform hardware

Purpose-built 1U appliance

Cadmium packages the source and destination sides into one rack-mount platform while maintaining separate interfaces, storage and security functions for each side.

Form factor

1U rack mount, front mount / rear exhaust and deck-to-deck stacking.

Interfaces

Factory-configurable fibre or copper 1Gbps SFP connectivity, with independent Admin and Sentry interfaces.

Storage

Dedicated encrypted SSDs on each side, with the presentation identifying 1TB standard storage and up to 8TB per side.

OEM

The platform is identified as available for OEM integration.

Rear view of Blackline CDS showing source, destination, admin, Sentry and power interfaces
Rear view showing independent source/destination connections, administrative interfaces, Sentry interfaces and power.

Cross domain basics

Cadmium / Blackline-CDS frequently asked questions

What is Cadmium / Blackline-CDS?

Cadmium is Blackline Systems' Cross Domain Solution (CDS) platform for controlled movement of files and streaming IP data between networks with different security classifications or trust levels.

Is Cadmium a data diode?

Cadmium incorporates a hardware-enforced unidirectional subsystem as its one-way security boundary. The complete CDS platform adds protocol filtering, transfer services, administration, auditing and optional content inspection around that boundary.

What is BSC-CDS?

BSC-CDS Unidirectional Subsystem is the Blackline Systems unidirectional security subsystem evaluated under the Canadian Common Criteria program at EAL4+. It is a component of the broader Blackline cross domain architecture.

Can Blackline-CDS transfer files and streaming data?

Yes. The platform supports file-oriented transfer as well as streaming TCP, UDP and SYSLOG flows, with policy and protocol enforcement applied to configured flows.

Bring controlled data movement into your cross domain architecture.

Talk to Blackline about Blackline-CDS / Cadmium, supported flows, inspection options, integration requirements and deployment architectures.

Contact Blackline Systems