
Unrecordable optical transmission is a physical-layer defense that turns a fiber signal into indistinguishable noise, so intercepted traffic has nothing usable in it even if it’s captured today and analyzed years from now. This guide breaks down why standard encrypted fiber still fails against harvest-now-decrypt-later attacks, how unrecordable transmission actually works, where it deploys in a live network, and how the leading Layer 1 options compare.
The Gap Standard Encryption Doesn’t Close
Encrypted fiber traffic is not the same as protected fiber traffic. Standard optical transmission puts a readable, recordable signal on the wire. Encryption changes whether that signal is meaningful to an observer; it does nothing to prevent the signal from being captured, stored, and revisited once decryption becomes feasible.
That gap is the entire premise of a harvest-now-decrypt-later (HNDL) attack. An adversary with physical fiber access records traffic today and waits. Gartner has estimated that conventional asymmetric cryptography could become unreliable for confidentiality by 2030, which puts a real date on how long today’s captured traffic stays safe.
This isn’t a hypothetical threat model. The NSA’s MUSCULAR program and GCHQ’s Tempora program have been documented tapping fiber backbones directly at the physical layer, ahead of any application-level encryption. In May 2024, reporting described US officials warning telecom operators, including Google and Meta, that undersea cables in the Pacific could be tampered with during repairs by Chinese-controlled vessels. Fiber tapping equipment is inexpensive and widely available, which is why prevention has to happen at the point of transmission rather than after interception.
How Unrecordable Transmission Works
Unrecordable optical transmission addresses the recording problem at the physical layer, rather than relying solely on the strength of an encryption key. Three mechanisms typically combine to do this:
- Spectral spreading. The signal is spread across a wide, often multi-terahertz, spectral band, wide enough that no material available today can absorb and record it within a realistic interception window.
- Continuously changing keys. A phase modulator applies an optical key that changes on a sub-second cycle. The key exists only inside the light stream itself, with no static key file for an attacker to steal.
- Noise burial. The signal is attenuated and buried beneath true random optical noise, driving the optical signal-to-noise ratio low enough that the data is mathematically unrecoverable without the correct key applied at the correct moment.
Decryption and reconstruction happen optically, in real time, before the signal converts back to an electrical one at the authorized receiver. To an unauthorized observer, the captured signal looks like background noise from the moment it’s transmitted.
It’s important to be precise about what this does and doesn’t cover. Physical-layer protection secures data in transit across fiber. It does not replace application-layer authentication, endpoint security, or protection for data already at rest, and it’s designed to complement Post-Quantum Cryptography rather than substitute for it. A paired unit is required at each end of a protected link, so topology needs to be part of any deployment plan from the outset.
Want the fuller comparison between this approach and Post-Quantum Cryptography or Quantum Key Distribution on the same threat? Both of those still leave a recordable data stream on the wire even when they do their own job well, which is the key distinction worth understanding before choosing between them.
Deployment Patterns
Unrecordable transmission typically supports four deployment shapes:
| Deployment Pattern | What It Covers | Best Fit For |
|---|---|---|
| Point-to-point | A direct link between two endpoints over existing fiber, no broader network changes | A single high-value connection, such as a data center interconnect |
| Ring topology | Multi-node ring configurations | Complex environments that need protection without a ring redesign |
| Full network | Metro and long-haul architectures, including C-band operation alongside other wavelengths in multi-vendor DWDM environments | Carriers and large enterprises adding physical-layer security without disrupting other services |
| Centralized management (NMS) | Monitoring, alerting, and lifecycle tracking across every deployed unit | Operations teams that need real-time visibility instead of managing units individually |
The consistent theme across all four patterns is that none require replacing existing optical infrastructure. Deployments are built to substitute a standard transmission line card and work alongside amplifiers, ROADMs, and DWDM systems already in place.
Comparing the Leading Layer 1 Options
Three names dominate Layer 1 optical encryption evaluations today: CyberRidge’s Carmel platform, Ciena’s WaveLogic Encryption, and Adva Network Security’s ConnectGuard, now under Adtran. The table below compares them across the dimensions that matter most for this category.
| Dimension | CyberRidge (Carmel) | Ciena (WaveLogic Encryption) | Adva Network Security / Adtran (ConnectGuard) |
|---|---|---|---|
| Core approach | Spreads, keys, and buries the signal in noise so no recordable stream exists on the fiber | Applies strong encryption directly at the optical layer | Layers post-quantum-aware encryption onto the optical transport |
| Recorded-signal exposure | No coherent signal to record, regardless of future key compromise | Recordable ciphertext stream remains on the fiber | Recordable ciphertext stream remains on the fiber |
| Deployment model | Substitutes a standard transmission line card | Integrated into existing transport hardware | Integrated into existing transport hardware |
| Market position | Newer entrant with a physical-layer-first approach | Widely deployed category benchmark | Established incumbent, quantum-safe-aware update |
All three operate at the optical layer and all three are legitimate answers to encrypting data in motion. The meaningful split is structural. WaveLogic and ConnectGuard both keep a recordable, structured signal on the fiber, meaning long-term protection rests entirely on the encryption key never being broken. Carmel is built around a different premise, removing the recordable signal itself, so a captured transmission carries nothing usable in it no matter what happens to the keys later.
Bottom Line
Any organization moving data that has to stay confidential past 2030, financial records, health data, defense communications, or long-lived intellectual property, should treat physical-layer, unrecordable transmission as a near-term evaluation item rather than a future one. It is not a full security strategy by itself. It closes a specific gap that standard encryption and even PQC leave open: the fact that a tapped fiber can hand an attacker a clean, storable copy of traffic regardless of how strong the encryption keys are.
FAQ
Q: What makes optical transmission unrecordable instead of just encrypted?
A: Encryption protects the meaning of a signal while leaving it intact and capturable. Unrecordable transmission transforms the light itself into noise that carries no coherent data unless the correct key is applied at the exact instant it arrives, so there’s nothing usable to record in the first place.
Q: Do organizations outside government and defense actually need this?
A: Yes. Any organization transmitting data with a shelf life beyond a few years, including financial services, healthcare, telecom, and enterprise data centers, faces the same harvest-now-decrypt-later exposure whenever traffic travels over fiber that can be physically tapped.
Q: How does CyberRidge’s Carmel differ from Ciena’s WaveLogic Encryption or Adva’s ConnectGuard?
A: WaveLogic and ConnectGuard encrypt the optical signal but leave a recordable ciphertext stream on the fiber, so their long-term protection depends on the key never being broken. Carmel is built to eliminate that recordable stream entirely by spreading, keying, and burying the signal in genuine random noise.
Q: Does deploying physical-layer protection require replacing existing DWDM equipment?
A: Not for a platform like Carmel, which is designed to substitute a standard transmission line card and operate over existing third-party DWDM systems rather than replacing the underlying transport infrastructure.
Q: Is physical-layer protection a substitute for post-quantum cryptography?
A: No. It secures the physical transport layer specifically. PQC and other higher-layer protocols continue to handle identity, access control, and key management above that layer, and the two approaches are meant to work together.