Product
Technology
What is the threat
Existing solutions
⁠CyberRidge technology explained
Use cases
Resources
NewsWhite papers
Product UpdatesBlogNews
Company
Contact
Home
Product
Technology
Use cases
Company
Resources
News
White papers
Product updates
Blog
Get in touch

How to Implement Unrecordable High-Speed Optical Transmission for Data in Transit

What unrecordable optical transmission requires for data in transit across WANs, how it is rolled out link by link, and where its limits sit.

Making a high-speed optical transmission unrecordable happens at Layer 1, by reshaping the light carrying the data, referred to as Photonic Layer Security (PLS). An attacker who taps the fiber captures ciphertext rather than a clear-text copy of the traffic. It differs from conventional optical encryption, which scrambles the payload but still involves placing a distinct, recordable waveform on the fiber. PLS is implemented one link at a time, using a matched pair of transmission units at each end of a span running over existing DWDM infrastructure. It does not replace post-quantum cryptography, because it blocks the recording step in an attack chain sequence, rather than the decoding of an encrypted key. CyberRidge's Carmel platform implements this on 100 Gb/s links over standard single-mode fiber.

‍

What is an unrecordable optical transmission?

Unrecordable means there is no intelligible signal on the fiber for an attacker to capture and store. Conventional Layer 1 encryption, such as the AES-256 in-flight encryption on transponders from Ciena, Nokia, and Adtran, protects the contents of the transmission but leaves a well-formed optical signal that a tap can exfiltrate in full. This exfiltrated data still needs to be protected even though the payload is encrypted. An attacker can record the ciphertext now, along with the key exchange, and potentially decrypt both if the encryption key is lost or stollen, if either is implemented incorrectly or cryptoanalytic capabilities advance. This is the Harvest-Now-Decrypt-Later threat, and it is why encryption on its own does not close the exposure window for data that must stay confidential for years or decades.Β 

‍

Photonic Layer Security targets the earlier harvest step and removes the artifact that would be archived. This matters because fiber taps are cheap and quiet. Physical access to a fiber generally takes one of a few forms: installing hardware at entry and exit points such as street cabinets and manholes, inserting an inline splitter that diverts a portion of the light to a recording device, or bending the fiber itself. Among these, macrobending is the most common stealth technique: bending a fiber past roughly a 6.5–7.5 cm radius causes light to leak from the core through the cladding into a clip-on coupler, without cutting the cable or producing a detectable loss in signal strength.

‍

What Is Harvest Now, Decrypt Later, and How Can Organizations Protect Against It? This article breaks down the threat model this technology is built against.

‍

How the signal is made unrecordable

Before the signal reaches the fiber, Carmel reshapes it in three stages. It spreads the signal across roughly 1.5 THz of the spectral band rather than concentrating it on one narrow wavelength. An optical key then modifies that spread signal, changing every fraction of a second; the key is generated inside the unit by an air-gapped generator and carried within the light itself, so there is nothing stored for an attacker to reach. The signal is then attenuated and buried beneath added spontaneous optical noise, driving down the optical signal-to-noise ratio. A measure of how far a signal stands above the background noise on the fiber, to a level theoretically unrecoverable.

‍

Reconstruction happens through coherent optical detection: the incoming light is mixed with the receiver's synchronized mode-locked laser, and the coherent addition that recovers the data, as opposed to noise, occurs as the signal is down-converted at the photodetector. That recovery only succeeds if the receiver's laser is synchronized to the sender's at the precision coherent detection requires, and if it holds the matching photonic key for that instant. Both requirements, laser synchronization and key matching, exist only inside a paired unit, and not just a software key."Β 

‍

How to roll it out on a live network

Start by scoping the links, not the network. Inventory which fiber paths carry data with a confidentiality requirement measured in years or decades: classified government records, defense communications, financial records, intellectual property. Federal timelines set the pace. Executive Order 14412, signed June 22, 2026, requires federal high-value assets and high-impact systems to move to post-quantum key establishment by December 31, 2030, and digital signatures by December 31, 2031, with a FAR rule putting contractors on the same 2030 deadline.

‍

Next, confirm the physical path supports it. Carmel runs up to 100 km unamplified and works with EDFA and Raman amplification for even longer spans. No changes are needed to existing DWDM equipment; it works with any vendor's optical transport, and supports up to five alien wavelengths alongside conventional traffic. Then check the client side and the facility: a 100 GbE interface across up to four QSFP-28 ports (OTU4 also supported), 3U of rack space per unit, and dual redundant AC or DC power at each site.

‍

CyberRidge deploys in weeks rather than the multi-year timelines typical of a cryptographic migration. This is because implementation is an overlay: the new hardware goes in alongside the existing infrastructure rather than replacing it. Bring the first pair of Carmel transmission units online by simply replacing the line cards, move non-critical traffic across to validate performance and error rates, then shift to critical traffic once the link has proven itself trustworthy.Β  Decide how the link is operated: the Trekker network management system adds multi-link visibility and SIEM integration for ease of management.

‍

For more on the cryptographic half of the rollout, see How Do You Implement Post-Quantum Encryption for Data-in-Transit?

‍

What this approach does not do

Photonic Layer Security does not replace post-quantum cryptography. Quantum computers threaten the RSA and elliptic-curve key exchange that protects the asymmetric session key, not the AES-256 encryption itself. Instead, PLS sits underneath and closes a different gap.

‍

The encryption itself is not the weak point. AES-256, the algorithm protecting the data, is expected to hold up against quantum computers, and standards bodies do not require replacing it. The problem is what protects the key that establishes the channel between two destinations. Keys are exchanged using older encryption methods that quantum computers are expected to break, which is what the post-quantum migration is designed to fix. But an attacker who copies your encrypted traffic off the fiber today, can keeps that ciphertext, along with the key exchange that came with it, and wait. When the capability to break that exchange arrives, the stored traffic gets decrypted retroactively, exposing everything.Β 

‍

Once the attacker already has your data, there is no way to reach back and retrieve it. That is why the recording itself matters more than the strength of the encryption. Photonic Layer Security removes the copy: if there is no intelligible signal to capture off the fiber, there is nothing for an attacker to store and wait on.

‍

Carmel at a glance

Attribute Specification Why it matters for implementation
Uplink rate 100-400 Gb/s with Photonic Encryption; Sets the per-link capacity you can protect today
Client traffic port 100 GbE over QSFP-28 Standard client optics, no bespoke edge equipment
Link distance Up to 100 km unamplified; EDFA and Raman compatible Extends to long-haul spans, unlike QKD's ~100 km ceiling
Spectrum C-band spread across 1.5 THz Coexists with conventional DWDM channels
Infrastructure change No modification to existing DWDM. Works on any vendor's transport Avoids a network redesign to add the link
Coexistence Up to 5 alien wavelengths supported Protected and unprotected services share the same fiber
Key handling Continuous optical key rotation, air-gapped generator, keys embedded in the light No key stored for an attacker or insider to target
Form factor and power 3U, 19-inch rack unit; dual-redundant AC or DC inlets Determines rack, power, and site planning per endpoint
Compliance Designed to meet compliance with FIPS 140-3 Treat as a design target, not a completed certification

‍

What This Means for Network Teams

Carmel is deployed on specific links you choose, not across the whole network at once. Identify the links whose traffic must stay confidential well past 2030, confirm you control both endpoints, and protect those first. Run the post-quantum migration on its own track in parallel, since the two address different failure modes.

‍

Have links carrying data that must stay confidential for decades? Learn more to see how CyberRidge implements unrecordable transmission across existing fiber.

‍

FAQs

Q: Does CyberRidge's Carmel need new fiber to be installed?

‍

A: No. Carmel runs over existing single-mode fiber and requires no modification to installed DWDM equipment, working alongside any vendor's optical transport. This is a key operational difference from quantum key distribution, which typically requires dedicated fiber or a dedicated wavelength.

‍

Q: How fast can Carmel actually run today?

‍

A: Carmel supports 100 Gb/s uplinks with Photonic Encryption today, using a 100 GbE client interface over QSFP-28.Β 

‍

Q: Do I need Carmel units at both ends of the link?

‍

A: Yes. Reconstruction is optical and happens only at a receiver holding the matching key at the exact moment the signal arrives, so a matched pair is required, one unit at each end of the protected span.

‍

Q: Does Carmel replace a post-quantum cryptography rollout?

‍

A: No. CyberRidge positions Carmel as complementary to post-quantum cryptography, which secures the key exchange that quantum computers actually threaten. Carmel addresses a separate problem: preventing the payload from being recorded off the fiber in the first place.

‍

Q: How long does a Carmel deployment take?

‍

A: Deployment can be completed in a matter of weeks, with the first link typically brought up in parallel with existing infrastructure so no downtime is required during the initial phase. Thistimeline can vary depending on site access, power, and how many links are in scope.

‍

Q: How far can a Carmel-protected link reach?

‍

A: The Carmel data sheet gives up to 100 km unamplified, with full compatibility with EDFA and Raman amplification for longer spans. Thishas been validated over multi-ROADM, multi-vendor carrier infrastructure.

‍

Q: Is Carmel FIPS 140-3 certified?

‍

A: Carmel has been designed to support compliance with FIPS 140-3 and the referenced ETSI and Telcordia standards. The Air-gapped crypto-engine, PQC/ML-KEM algorithm support continuous optical key rolling. These are intentional design choices that make FIPS 140-3 attainable with a Carmel deployment.Β 

Be post quantum ready before its too late

Get in touch
Post-Quantum Optical Security for Data-in-Transit
General
HomeProductTechnologyUse casesCompany
Resources
White papersBlogNewsInsights
Contact
Get in touchinfo@cyber-ridge.comLinkedin
Legal
PrivacyTOCAccessibility statement
CyberRidge 2026. All rights reservd
Site by Streetlight