
Unrecordable optical transmission works by reshaping the light itself at Layer 1, so an attacker who taps the fiber captures noise rather than a usable copy of the traffic, and it is rolled out one link at a time as an overlay on existing optical infrastructure rather than a network-wide redesign. The sections below break down why encryption alone doesn’t achieve this, what the underlying mechanism requires, how a rollout actually sequences, and how the leading approach compares to the optical-layer encryption most enterprises already have in place.
What Makes Transmission Unrecordable (And Why Encryption Alone Doesn’t)
Conventional optical encryption, the AES-256 in-flight encryption built into transponders from established transport vendors, protects the contents of a transmission while leaving a clean, well-formed optical signal on the fiber. That signal is exactly what a tap needs to exfiltrate usable data. An attacker doesn’t need to break the encryption in real time to benefit; they can record the ciphertext, along with the key exchange that accompanied it, and wait for the encryption to fail later through a compromised key, an implementation flaw, or cryptanalytic advances. This is the harvest-now-decrypt-later problem, and it means encryption strength alone cannot close the exposure window for data that must stay confidential for years or decades, including classified records, financial data, defense communications, and intellectual property.
Unrecordable transmission targets the step before that: the recording itself. Instead of protecting what the data means, it removes the intelligible signal from the fiber entirely, so there is nothing coherent for an attacker to archive in the first place, regardless of future decryption capability.
How Fiber Taps Actually Work
Physical access to a fiber link doesn’t require cutting the cable. Three methods account for most real-world taps: hardware installed at accessible points such as street cabinets or manholes, an inline splitter that diverts a portion of the light to a recording device, and macrobending, which involves bending the fiber past roughly a 6.5 to 7.5 centimeter radius until light leaks through the cladding into a clip-on coupler. Macrobending is the stealthiest of the three: it produces no cut and no detectable loss in signal strength, which is why it routinely evades standard fiber monitoring.
Do you know The Fiber Link Nobody Could Tap, Even When We Let Them Try? Learn what happened when a team deliberately tried to intercept a protected link using these exact methods.
The Three-Stage Mechanism Behind an Unrecordable Signal
Making a signal physically unrecordable happens before it ever reaches the fiber, through three coordinated changes at Layer 1. First, the signal is spread across a wide slice of spectrum, on the order of 1.5 terahertz, rather than concentrated on one identifiable wavelength. Second, an optical key modifies that spread signal continuously, changing multiple times per second, generated inside an air-gapped unit so the key is never stored anywhere reachable by an attacker or insider. Third, the signal is attenuated and buried under added optical noise, driving the signal-to-noise ratio down to a level that is theoretically unrecoverable without the matching setup.
Reconstruction happens only through coherent optical detection: the receiver mixes the incoming light with its own laser, synchronized to the senders with the precision coherent detection requires, while simultaneously holding the matching photonic key for that exact instant. Both conditions, laser synchronization and key matching, exist only inside a paired hardware unit, not in a software key that could be copied or leaked.
Deployment Requirements and Rollout Sequence
Rollout starts with scoping the specific links that need it, not the network as a whole. Teams inventory which fiber paths carry data with a confidentiality requirement measured in years or decades and prioritize those first. Regulatory timelines are compressing that prioritization window: Executive Order 14412, signed June 22, 2026, requires federal high-value assets and high-impact systems to move to post-quantum key establishment by December 31, 2030, and digital signatures by December 31, 2031, with a companion FAR rule holding contractors to the 2030 deadline.
On the infrastructure side, systems in this category are generally built to run up to roughly 100 kilometers unamplified, extending further with standard EDFA or Raman amplification, without requiring modification to whatever DWDM equipment is already installed, and typically supporting a handful of alien wavelengths alongside conventional traffic on the same fiber. Client-side requirements usually include a 100 GbE interface, several rack units of space per endpoint, and dual-redundant power at each site. Deployment then proceeds link by link: the first pair of units goes in by swapping line cards, non-critical traffic shifts over first to validate error rates and performance, and critical traffic follows once the link has proven itself.
For more on how this fits into a broader quantum-readiness timeline, see Making an Optical Link Physically Unrecordable.
What This Does Not Solve: The Post-Quantum Gap
Unrecordable transmission is not a substitute for a post-quantum cryptography migration. Quantum computers threaten the RSA and elliptic-curve key exchange that establishes a session, not AES-256 itself, which is expected to remain secure. The two approaches address different points in the same chain: unrecordable transmission prevents the ciphertext and its key exchange from being captured off the fiber at all, while post-quantum cryptography protects that key exchange once it has already been transmitted. An organization pursuing only one of the two still has an open exposure at the other point, which is why the two migrations are typically run on parallel, independent tracks.
CyberRidge, Ciena, and Nokia Compared
The table below compares the three names that most frequently come up in optical-layer security evaluations. Ciena and Nokia both apply strong payload encryption at the transponder; the distinction is architectural, in whether the transmitted signal itself remains recordable.
| Evaluation dimension | CyberRidge (Carmel) | Ciena (WaveLogic Encryption) | Nokia (1830 PSS) |
|---|---|---|---|
| Core approach | Layer 1 photonic reshaping; removes the recordable signal itself | AES-256 payload encryption on the transponder | AES-256 payload encryption integrated into the optical transport platform |
| Signal remains recordable off the fiber? | No, by design | Yes, a well-formed encrypted waveform is transmitted | Yes, a well-formed encrypted waveform is transmitted |
| Infrastructure model | Overlay; no modification to existing DWDM equipment | Built into the transport platform’s transponders | Built into the transport platform’s line systems |
| Typical deployment timeline | Weeks, deployed link by link | Tied to the transponder refresh or transport platform lifecycle | Tied to the transport platform lifecycle |
| FIPS 140-3 status | Designed to support compliance; not yet certified | Varies by product line and generation | Varies by product line and generation |
Bottom Line
Signal recordability and encryption strength are separate properties of a fiber link, and a complete review of data-in-transit protection has to evaluate both. For links carrying data that must stay confidential well past the next decade, confirm who controls both endpoints, scope those links first, and run the post-quantum migration on its own parallel track.
FAQ
Q: What does unrecordable mean for an optical signal?
A: It means there is no intelligible waveform on the fiber for an attacker to capture and store, as distinct from conventional encryption, which scrambles the content but still transmits a recordable signal.
Q: Can a fiber optic cable be tapped without cutting it?
A: Yes. Inline splitters and macrobending, bending the fiber past roughly a 6.5 to 7.5 centimeter radius, both extract usable light without a cut or a signal-strength drop that standard monitoring would typically flag.
Q: How far can an unrecordable optical link run?
A: Systems in this category generally run up to roughly 100 kilometers unamplified and extend further with standard EDFA or Raman amplification, comparable to conventional optical transport.
Q: How is CyberRidge’s Carmel different from Ciena’s or Nokia’s optical encryption?
A: WaveLogic Encryption and the 1830 PSS platform encrypt the payload but still transmit a recordable waveform. Carmel is built specifically to remove that recordable signal at Layer 1, deployed as an overlay rather than a transponder or transport-platform replacement.
Q: Does CyberRidge’s Carmel replace a post-quantum cryptography migration?
A: No. It is complementary, addressing signal recordability rather than the key-exchange vulnerability that post-quantum cryptography is designed to fix.
Q: Is CyberRidge’s Carmel platform FIPS 140-3 certified?
A: Not currently. It is designed to support compliance with FIPS 140-3, which CyberRidge treats as a design target rather than a completed certification.