BlackSER AES

BlackSER AES

Product Image
BlackSER AES Rear Product Image

Serial Data Encryptor

with FIPS 140-2 Level 3 certified cryptography and hardware
Includes: DB9 and DB25 adapters

BlackSER AES BD9 and DB25 Adapters

Overview

The Black•SER AES is an in-line Serial Data Encryptor with FIPS 140-2 Level 3 compliant cryptography and hardware. Serial data received on the DCE interface is encrypted using a 256 bit AES key and sent out the DTE interface. Serial data received on the DTE interface is decrypted using an 256 bit AES key and sent out the DCE interface.

BlackSER AES Diagram

Seamless Integration

blackser-aes-sytem-diagram

Retrofit existing serial communications systems easily with the BlackSER AES's simple bump-in-the-wire design protects: meters, protective relays, programmable logic controllers (PLCs), remote terminal units (RTUs), and computers from unauthorized access, control, eavesdropping, and malicious attack by authenticating and encrypting all serial data communications.

The BlackSER AES securely boots up as a protocol agnostic asynchronous Serial Data Encryptor executing inside of a tamper reactive cryptographic boundary. All cryptographic functions, including private and public key generation are performed inside FIPS Level 3 protected hardware. The cryptographic algorithms are FIPS certified. Internally generated keys use a NIST certified hardware seeded random number generator to ensure key entropy.

Military Grade Tamper Reactive

Master key is secured within CPU Die Shield's Cryptographic Boundary. Dynamic fault detection with real time environmental and active tamper detection circuitry.
• Achieves Active Level 3+ Tamper
• Transport Safe

Secure and Effective Management

Management interface is accessed by a web browser GUI. Connection is establish via HTTPS operating in the web browser.

blackser_aes_web-gui-example-picture

Key Management

The BlackSER AES core cryptography is based upon our FIPS approved Hardware Security Module. FIPs requires a sophisticated protection private key generation, exportation and importation.

Accessories Included:

Utility Application Example:

BlackSER AES Application with Utility diagram

Securing Serial Communication Between an Energy Management System and a Remote Telemetry Unit

Scenario Overview:

A utility company operates an Energy Management System (EMS) at its central operations center. The EMS communicates with various Remote Telemetry Units (RTUs) installed at substations, transformers, and other field equipment sites. These RTUs collect critical operational data—such as voltage, current, frequency, and status of breakers—and send control signals back to the EMS over RS232 serial links.

While functional, these legacy serial communications are inherently unencrypted, exposing the system to potential cybersecurity threats, including interception, tampering, and spoofing of control commands.


Solution: BlackSER AES RS232 Serial Encryptor

By deploying a pair of BlackSER AES encryptors—one at the EMS side and one at the RTU side—the utility company can:

1. Ensure Confidentiality:

All RS232 serial data between the EMS and RTU is encrypted using AES 256-bit encryption, making it unreadable to unauthorized entities.

2. Preserve Legacy Infrastructure:

The BlackSER units work transparently with existing serial devices, allowing the utility to enhance security without replacing or modifying the EMS or RTUs.

3. Prevent Unauthorized Commands:

Encrypted channels help protect against malicious actors sending unauthorized control commands to field devices, which could otherwise cause grid disruptions or equipment damage.


Example Deployment:

  • Location A – Control Center (EMS)

    • EMS communicates via RS232 to a BlackSER AES unit.

    • The BlackSER encrypts the serial data and sends it over a communication medium (e.g., leased line, serial radio modem).

  • Location B – Substation (RTU)

    • A second BlackSER AES decrypts the incoming serial data and passes it to the RTU.

    • Outbound data from the RTU is encrypted in reverse and sent securely back to the EMS.


Key Benefits:

  • Enhanced cybersecurity compliance (e.g., with NERC CIP, NIST 800-171).

  • No need for protocol conversion—transparent serial encryption.

  • Tamper-resistant hardware design.

  • Field-deployable with minimal setup.

Industrial / Public Safety Application Example:

Securing RS232-Based Alarm Circuits in Industrial Facilities

Scenario Overview: Many industrial facilities, utility substations, and remote infrastructure sites still rely on RS232-based alarm circuits to monitor critical systems like fire alarms, gas leak detectors, intrusion sensors, or environmental controls.

These alarm circuits transmit real-time status data from sensors and controllers to centralized monitoring stations over serial lines. When these circuits use leased lines, microwave links, or serial radio links, they are often unencrypted, exposing them to:

  • Data interception

  • False alarm injection

  • Tampering or spoofing of alarm statuses

Solution: Deploying BlackSER AES for Alarm Circuit Encryption By placing BlackSER AES encryptors at each end of the alarm circuit, organizations can securely encrypt all alarm data over RS232 without changing existing sensors or control systems.

Deployment Example:

Remote Facility Site

  • Alarm controller sends RS232 data to a BlackSER AES encryptor.

  • BlackSER encrypts the data and forwards it over a communication medium (e.g., serial radio or leased line).

Central Monitoring Station

  • Incoming encrypted data is received and passed to a second BlackSER AES.

  • The data is decrypted and forwarded to the alarm monitoring console or SCADA system.

Benefits:

  • Security for Legacy Infrastructure: Adds AES-256 encryption to unprotected RS232 alarm circuits.

  • Tamper Protection: Prevents spoofing or replay attacks on alarm signals.

  • Zero System Disruption: Transparent operation with existing alarm hardware and protocols.

  • Improved Compliance: Helps satisfy industrial cybersecurity standards such as ISA/IEC 62443 or NIST 800-82.

Conclusion: Using BlackSER AES units to protect RS232 alarm circuits enhances the integrity and confidentiality of alarm data—providing peace of mind and regulatory alignment for operators of industrial and critical infrastructure sites.

Specifications

RS232 Interfaces
  • 1 RS232 DCE (RJ50)
  • 1 RS232 DTE (RJ50)
  • Baud Rate: 1.2/2.4/4.8/9.6/19.2/38.4/57.6/115.2 Kilobits
Serial Protocols Supported
  • Asynchronous 8 bit: Modbus, DNP, IEC101, etc
LAN Network Interface
  • 1 Ethernet 10/100 BaseT Copper
  • TLS
Hardware
  • Hardware True Random Number Generator
  • NIST SP 800-90 compliant DRBG
  • Secure Boot Loader: PKI Authentication
  • Memory Encryption And Integrity Check
  • Real-Time Clock
  • Tamper: Mechanical, Die-Shield, Temp & Voltage
Physical Characteristics
  • Rack, Wall and Din Rail Mounting
  • Dimensions 102 x 153 x 26 mm (4 x 6 x 1in)
  • Weight: 454 grams; 1 pound
  • Temperature: operating -20 to 60°C,
  • Humidity: operating 10 to 90%, storage 0 to 95%
Certification
  • FIPS 140-2 Level 3
Cryptography
  • Symmetric algorithm: AES 256 bit
Management and Monitoring
  • Web GUI - run in Web Browser
  • Syslog diagnostics support
Safety & Environmental Compliance
  • UL, CE, FCC, RoHS
Power
  • DB9 Connector: Dual Hot Standby 5 to 30 VDC
  • Power consumption: 4W

So What’s Next?

WE’RE READY!

Engage logo 990000 rev 2.000
9565 Soquel Drive Dr,
Aptos, CA 95003
 
Telephone: +1-831-688-1021
Toll Free : +1-877-ENGAGE4
Designed, Fabricated, and Assembled
in America icon
Supported Worldwide

© 1989-2025 Engage Communication, Inc. All Rights Reserved.