Classified information protection
BlackPiQCommercial Solutions
for Classified
BlackPiQ provides the inner IPsec encryption layer directly at the endpoint and physically secures its Ethernet connection.
Cryptographic authentication and physical enforcement at the Ethernet port—with optional hybrid ML-KEM key establishment.
CSfC Use Case
Encrypt at the endpoint.
Protect across the network.
The IPsec/IPsec deployment below follows the CSfC Multi-Site Connectivity architecture, using two independent encryption layers between Red networks operating at the same security level. BlackPiQ provides inner IPsec encryption at the video encoder.
BlackPiQ brings encrypted connectivity and physical port enforcement to the protected endpoint. The illustrated deployment also requires independent outer encryption components, supporting PKI, management services and the applicable network-security controls.
BlackPiQ at a glance
High-assurance protection at the endpoint interface.
BlackPiQ physically locks a standards-based encrypted IPsec connection to a mission-system endpoint, bringing authenticated connectivity, physical port control and powered security monitoring directly to the asset edge.
Authorized IPsec connectivity
Restricts protected endpoint traffic to the configured IPsec tunnel. In a layered architecture, PiQ provides the inner layer and a separate Outer VPN Gateway provides the outer layer.
Multi-vendor interoperability
Establishes standards-based IPsec with compatible third-party firewalls, VPN gateways and Ethernet encryptors. The remote peer does not need to be another BlackPiQ.
Transparent endpoint deployment
Adds inline protection at the Ethernet interface without modifying the attached system’s application logic.
Endpoint-side isolation
Helps prevent unauthorized local discovery and direct access by restricting network communication to the configured authenticated tunnel.
Zero-power lock retention
The bi-stable mechanical lock remains engaged if device power is lost. Electronic monitoring and encryption require power.
Powered monitoring and alerting
While powered, BlackPiQ can report authentication failures, link loss and tamper events to authorized network-management and security-monitoring systems.
Optional post-quantum protection
- Standard Mode: Hybrid ML-KEM-768 or ML-KEM-1024 key exchange combines classical and post-quantum cryptography.
- Compatible peers: Both endpoints must support and enable the selected hybrid key-exchange configuration.
- Layered protection: Hybrid key establishment strengthens an IPsec layer; it does not replace the independent outer encryption layer.
Physical port security
Secure the connection.
Control its removal.
BlackPiQ’s Ramp & Clamp mechanism physically locks the device to the endpoint’s RJ45 Ethernet port, adding physical enforcement to authenticated network connectivity.
The bi-stable locking mechanism retains its state without continuous power. Authorized lock and unlock control supports managed installation and service workflows.
Ramp & Clamp locking mechanism — cutaway view.
Conceptual layered protection. Separate gateways provide the outer IPsec layer.
Optional post-quantum protection
Extend post-quantum protection to the endpoint.
BlackPiQ combines physical port security with optional hybrid key establishment, bringing encrypted connectivity to the attached system without changing its application logic.
- Hybrid key establishment: ML-KEM-768 or ML-KEM-1024 combines with classical key exchange to establish IPsec session keys.
- Compatible peers: both endpoints must support and enable the selected configuration.
- Existing infrastructure: conventional IKEv2 IPsec remains available for compatible VPN gateways, firewalls and Ethernet encryptors.
- FIPS-mode upgrade path: future ML-KEM / ML-DSA support is subject to vendor firmware availability and applicable validation. No release date is published.
Device management and AAA
Control who can administer BlackPiQ.
BlackPiQ applies Authentication, Authorization, and Accounting to access to its device-management interface. These controls govern who can view device status, change configuration, and administer users; they are separate from the industrial traffic passing through the protected interface.
Authentication
Verify an authorized administrator before granting access to the BlackPiQ management interface.
Authorization
Map centralized privilege levels to BlackPiQ device-management roles.
Accounting
Associate management logins, administrative commands, and configuration activity with an authenticated identity.
BlackPiQ can use TACACS+ or RADIUS as the primary authentication service for login to its management interface. Optional local fallback can preserve administrative access if the remote service is unavailable, while centralized privilege information maps authenticated users to BlackPiQ device roles.
BlackPiQ management interface
Configure and monitor the protected interface from one console.
The browser-based management interface provides visibility into BlackPiQ device health, IPsec tunnel status, Ethernet interfaces, security state, active management sessions, and reported events.
TOTP authentication
One-time codes
Short-lived verification codes from an enrolled authenticator app.
Certificate authentication
Certificate-based identity
Client certificates establish identity through a configured trust chain.
CAC / PIV authentication
Smart-card identity
A workstation reader and middleware enable card-backed certificate authentication.
Authorization and roles
Permissions reflect administrative responsibility.
BlackPiQ provides two administrative roles: Admin for device administration and Super for device and user administration.
Monitoring and accountability
Turn device health, access and physical state into actionable events.
While powered, BlackPiQ can monitor its protected connection, record security-relevant activity and send configured notifications to authorized operations.
Device health
Monitor BlackPiQ availability, operating state and reported faults.
Link status
Detect changes affecting the secure uplink or protected endpoint connection.
Security events
Report authentication, configuration, lock-state and tamper conditions supported by the device’s configured monitoring profile.
SNMPv3 monitoring and traps
Send device and security events to authorized monitoring systems.
BlackPiQ can send SNMPv3 traps to configured network-management or security-monitoring systems. When authentication and privacy are enabled, SNMPv3 protects event reporting between BlackPiQ and the monitoring destination.
Administrators define SNMPv3 users, security settings and trap targets through the management interface. The on-device trap log shows notification history for operational review and troubleshooting.
BlackPiQ device
Configured device or security condition
SNMPv3 trap
Authentication + privacy when enabled
Monitoring platform
NMS · SIEM · SNMP manager
Trap targets are configured in the BlackPiQ management interface, while notification history remains available for operational review.
Live tamper response
Detect interference while it is happening.
While powered, BlackPiQ combines physical locking with electronic tamper sensing. A confirmed event can trigger key sanitization, live notification and a configured response.
Illustrative notification workflow. Electronic detection and response require power.
Hardware-rooted cryptographic security
Hardware-rooted protection for keys and secure sessions.
BlackPiQ uses a secure cryptographic coprocessor to provide hardware-backed protection for sensitive keys and supported cryptographic operations.
A dedicated hardware boundary helps isolate module-managed key material from general-purpose software, supporting authentication and secure sessions.
Cryptographic module assurance
FIPS 140-3
Validation applies to the cryptographic module in its approved configuration, not the complete BlackPiQ product.
Hardware root of trust
Protect keys within a dedicated hardware boundary.
Hardware-managed keys and supported cryptographic operations are isolated from general-purpose software.
This protection supports authentication and secure sessions while keeping the scope tied to the keys and operations managed by the module.
Technical specifications
Plan the endpoint connection.
Physical interfaces, power and management capabilities for BlackPiQ integration.
Protected interface
- 10/100 Base-T Ethernet
- Locking RJ45: Ramp & Clamp
Network uplink
- 10/100BASE-T Ethernet
- IX connector
Power
- 24 V DC: female power input or USB-C: bus power from the technician laptop.
- PoE: IEEE 802.3af Class 2
Cryptography
- IPsec: IKEv2; tunnel and transport modes.
- Standard Mode encryption: AES-256-GCM or ChaCha20-Poly1305.
- Standard Mode hash functions: SHA-256, SHA-384 and SHA-512.
- Standard Mode key exchange: Curve25519, Curve448, NIST P-384 and NIST P-521.
- FIPS Mode encryption and integrity: AES-256-CBC with HMAC-SHA-256, HMAC-SHA-384 or HMAC-SHA-512.
- FIPS Mode key exchange: NIST P-384 and NIST P-521.
- Authentication — both modes: ECDSA with NIST P-384 or P-521; RSA-3072 or RSA-4096.
- Optional post-quantum — Standard Mode: Hybrid ML-KEM-768 or ML-KEM-1024 key exchange, with PPK fallback. Requires compatible peer configuration.
- FIPS-mode post-quantum roadmap: ML-KEM / ML-DSA through a future firmware upgrade, subject to vendor availability and applicable validation. No release date is published.
Management
- HTTPS: hardened browser administration
- MFA: multi-factor authentication
- RBAC: role-based access control
- TACACS+ / RADIUS: centralized device authentication with supported local fallback
- SNMPv3: monitoring and notifications; electronic detection and notification require power
Operating range
- −40°C to +85°C
Dimensions
- 2.2 in × 1 in × 1.5 in
Physical lock
- Bi-stable mechanism: retains lock state without continuous power
Cryptographic hardware
- Secure cryptographic coprocessor: hardware-backed key protection
- FIPS 140-3 validated module: Overall Level 2; Physical Security Level 3
- Scope: validation applies to the module in its approved configuration, not the complete BlackPiQ product
Engage Black
Discuss your multi-site network architecture.
Discuss peer interoperability, the independent outer layer, management boundaries and product integration requirements.












