Cross Domain Security
Blackline-CDS Cadmium
Cadmium / Blackline-CDS is Blackline Systems Corporation's Canadian Cross Domain Solution (CDS) platform for controlled movement of files and streaming IP data between security domains. It combines a hardware-enforced unidirectional security boundary (data diode), protocol filtering, hardware-assisted protocol policing and optional content inspection.
One-way transfer, with more control
A highly integrated cross domain platform
Cadmium is Blackline Systems' high-assurance Cross Domain Solution platform. Blackline-CDS provides controlled transfer between networks with different security classifications or trust levels, supporting both streaming and file-based flows. Its architecture separates source and destination security domains and uses a hardware-enforced one-way boundary so the transfer path cannot become an ordinary bidirectional network connection.
Streaming data
TCP, UDP and SYSLOG flows with hardware-assisted protocol enforcement and very low latency.
File transfer
Direct cut-through or Store & Forward movement using supported secure and standard file protocols.
Content inspection
Optional native and third-party inspection can be configured as a pipelined, flow-specific policy.
Independent assurance
Common Criteria EAL4+ evaluated unidirectional subsystem
The Blackline Systems Corporation BSC-CDS Unidirectional Subsystem PN 710-0185-00 is the evaluated one-way security subsystem used within the Blackline cross domain architecture. The Canadian Common Criteria certification report records an EAL4+ evaluation completed under the Canadian Common Criteria Program.
What the evaluation covers
The Security Target describes the BSC-CDS Unidirectional Subsystem as part of a cross-domain solution (data diode) providing reliable unidirectional throughput while preventing establishment of a reverse communication channel.
Independent references
Review the official certification information directly from the Canadian Centre for Cyber Security and the international Common Criteria portal.
Canadian Common Criteria certified products
BSC-CDS Security Target (Common Criteria Portal)
Security architecture
Separate sides. Hardware-enforced boundaries.
The platform uses independent source and destination cards joined by a unidirectional fibre link. Hardware-assisted packet filtering and protocol policing are performed by NXP T2080 network processors, with secure key storage and cryptographic functions.
Protocol security
Cadmium extends its RTB 5.1 architecture into the internal one-way transfer boundary. Its hardware-assisted protocol policing is designed to address the RTB 5.1 OWT-17 requirement family, including OWT-17, OWT-17.1, OWT-17.2 and OWT-17.3, by enforcing the proprietary internal transport in processor hardware rather than relying only on software inspection.
- Hard context-sensitive firewalling on interfaces
- Hardware-assisted protocol air gap, with protocol policing implemented by NXP T2080 DPAA filtration-management hardware
- Proprietary unidirectional protocol across the internal fibre boundary; permitted frame structure and transport characteristics are validated by hardware pattern matching before normal software processing
- Non-conforming internal transport frames are identified and directed away from the normal transfer path, while a hardware-specific integrity value provides an additional validation check
Physical security
- Tamper-evident and tamper-resistant packaging
- Live and shelf tamper detection
- Configurable tamper actions
- Monitoring for enclosure, temperature, voltage and probing events
Data protection
- Secure key storage and encrypted keys
- CNSA 2.0 cryptographic algorithms used for certificates and keys on protected transport interfaces
- Encrypted SSD storage
- Integrated wipe facility
- Separate source and destination security domains
Hardware protocol policing: Cadmium uses processor DPAA hardware pattern matching to validate protocol characteristics, direct violations to controlled queues and check Blackline-specific frame integrity information in hardware.
Content inspection
Native filtering and third-party Sentry integration
Inspection operates above the transport layer and is configured per flow. Native and off-board inspection can be mixed in a pipelined chain designed around RAIN principles: redundant, always-invoked, independent and non-bypassable.
Native inspection
For Store & Forward file flows, native inspection capabilities include file metadata checks, XML normalization and schema validation, XML signature validation using uploaded certificates, and JSON format/schema checks.
Sentry off-board inspection
Dedicated Sentry interfaces allow application-agnostic third-party inspection for secondary XML vetting, content removal, malware detection, proprietary inspection and other specialized functions. Up to eight named processes can be chained on a flow.
Measured performance
Low latency with near-gigabit streaming throughput
Current 1Gbps SFP interfaces combine hardware crypto, filtering and queue handling with an eight-core network processor architecture.
| Flow | Measured throughput |
|---|---|
| UDP | 881 Mbps |
| TCP | 822 Mbps |
| FTP | 765 Mbps |
| FTPS | 451 Mbps |
| SFTP | 239 Mbps |
| HTTPS | 241 Mbps |
Latency figures in the source presentation are for a minimal 64-byte UDP datagram in a looped test and include approximately 3 µs of serialization delay. 10Gbps/SFP+ is identified as roadmap capability.
Administration, audit & monitoring
Operational control without a universal super-user
A browser-based HTTPS console exposes role-specific capabilities for administration, operation and monitoring. The design separates responsibilities across five enforced roles.
User Admin
Manages user names, passwords and privileges.
Systems Admin
Manages flows, communications, protocols and addresses.
Security Admin
Manages certificates, keys, security policy and tamper actions.
Operator / Monitor
Audit operations and read-only system status functions are separated from administration.
Audit and forensic support
On-platform logging covers audit, system, security and quarantine events along with content-inspection reports. Logging can be file based and/or delivered through SYSLOG, with support for UDP or TCP/TLS.
Off-platform SYSLOG can also be configured as a protected data flow from the source WAN interface to the destination WAN interface.
Deployment patterns
One-way, two-way and resilient architectures
The same platform can support several deployment models, from a single secure transfer path to paired systems for inspected request/response workflows.
Bulk one-way transfer
Move file or streaming traffic between networks with different security ratings using a single Blackline-CDS platform.
Secure request / response
Deploy two one-way systems back-to-back to build an inspected CDS path where requests and responses are independently validated.
Streaming redundancy
Use source and destination application signalling to switch to a secondary protected path if delivery fails or a destination response is not received.
Flexible test and integration environments
The presentation also documents a three-unit demonstration setup combining high- and low-side servers, a Sentry server, native XML validation and third-party malware checking. It demonstrates that native and external inspection can be composed into different paths without changing the underlying one-way security model.
Platform hardware
Purpose-built 1U appliance
Cadmium packages the source and destination sides into one rack-mount platform while maintaining separate interfaces, storage and security functions for each side.
Form factor
1U rack mount, front mount / rear exhaust and deck-to-deck stacking.
Interfaces
Factory-configurable fibre or copper 1Gbps SFP connectivity, with independent Admin and Sentry interfaces.
Storage
Dedicated encrypted SSDs on each side, with the presentation identifying 1TB standard storage and up to 8TB per side.
OEM
The platform is identified as available for OEM integration.
Cross domain basics
Cadmium / Blackline-CDS frequently asked questions
What is Cadmium / Blackline-CDS?
Cadmium is Blackline Systems' Cross Domain Solution (CDS) platform for controlled movement of files and streaming IP data between networks with different security classifications or trust levels.
Is Cadmium a data diode?
Cadmium incorporates a hardware-enforced unidirectional subsystem as its one-way security boundary. The complete CDS platform adds protocol filtering, transfer services, administration, auditing and optional content inspection around that boundary.
What is BSC-CDS?
BSC-CDS Unidirectional Subsystem is the Blackline Systems unidirectional security subsystem evaluated under the Canadian Common Criteria program at EAL4+. It is a component of the broader Blackline cross domain architecture.
Can Blackline-CDS transfer files and streaming data?
Yes. The platform supports file-oriented transfer as well as streaming TCP, UDP and SYSLOG flows, with policy and protocol enforcement applied to configured flows.
Bring controlled data movement into your cross domain architecture.
Talk to Blackline about Blackline-CDS / Cadmium, supported flows, inspection options, integration requirements and deployment architectures.
Contact Blackline Systems