← All Blackline products

Controlled exchange over untrusted networks

Magnesium Secure messaging & file-transfer gateway

A distributed secure messaging architecture for exchanging messages and files between pre-authorized parties without extending a trusted security envelope to every user device.

Distributed enforcementCentral policyMessage traceability

Controlled exchange over untrusted networks

Secure exchange without a traditional high-security WAN

Magnesium combines centralized management with geographically distributed remote units, reducing administrative overhead while maintaining policy, logging and traceability.

Magnesium secure message gateway hardware
Magnesium project hardware / concept imagery.

Core characteristics

  • Centralized and automated management and policy generation
  • Distributed policy enforcement
  • Scalable regional or group structures
  • Low administrative overhead
  • Strong chain of evidence, logging and traceability
  • High-reliability system design
  • Flexible deployment model
  • Security architecture designed around protected cryptographic services

Controlled exchange over untrusted networks

Remote units connected to one or more gateways

An Mg deployment consists of multiple geographically distributed Mg-RU remote units reporting to one or more Mg-GW gateway devices.

Magnesium deployment architecture
Magnesium deployment architecture.

Mg-Fe

  • Subscriber access over an untrusted IP network
  • Gigabit Ethernet or USB 3.0 mass-storage access from user equipment
  • Access control, security policy, queuing and reliable message transfer
  • Generates and receives messages and files within the authorized Mg community

Mg-Fe-PC

  • Adds an internally secured PC running captive applications in kiosk mode
  • Reduces reliance on externally managed subscriber computers
  • Supports controlled logon, message creation, attachment upload, message inventory and logout

Controlled exchange over untrusted networks

A hard boundary around the secure messaging zone

Users can employ native COTS tools on their own systems while submitted files cross a controlled boundary into the Mg secure zone.

Controlled file handling

  • Files can be submitted from PCs, cameras, DVRs, smartphones and other attached devices
  • Submitted files are tagged and retained in native format with filename and extension
  • The approach avoids treating user endpoint devices as part of the protected security envelope
  • Designed to be simpler to administer than conventional PC-and-VPN arrangements

Discuss Magnesium with Blackline.

Discuss Magnesium secure messaging, distributed remote units, gateway architecture and deployment requirements with Blackline.

Contact Blackline Systems