Standards and Interfaces

Write the interface contract before the equipment arrives.

What You Will Learn

  • Define line-rate encryption from the frame anatomy of Figure 1 and state which FlexO fields are encrypted, which are authenticated, and which are neither.
  • Quantify payload expansion with the efficiency relation, and reproduce the 97.91% and 96.53% figures for 32-byte and 54-byte expansion on a 1500-byte client.
  • Place the trust boundaries of Figure 2 between spectrum user, spectrum provider and wet plant, and say which party holds which key.
  • Compute a cryptoperiod from the 232 invocation bound: about 10 s for 64-byte frames at 400 Gb/s against about 7.6 h for a 100G FlexO instance.
  • Convert a contracted power spectral density into a total input power, using −15.0 dBm/12.5 GHz over a 1200 GHz allocation as the worked case.
  • Separate spectrum isolation from confidentiality, and state what the ingress and egress blocking of a spectrum management block does and does not protect.
  • Select monitoring observables for physical interference, from state-of-polarization and phase records to the coherent OTDR trace, with their reporting latencies.
  • Build the migration path to hybrid post-quantum key establishment without touching the symmetric cipher already running on the line.

1. Introduction

A transoceanic fibre pair that once carried one owner's traffic now routinely carries two to four parties, each lighting its own block of spectrum from its own submarine line terminal equipment (SLTE). The SubOptic Spectrum Sharing Working Group records this as the normal shape of the service: splitting a full fibre pair between two and four users is what the industry does, and allocations below roughly 20–25% of the fibre pair spectrum are discouraged because they waste capacity and complicate operation (industry working-group guidance). Each party operates its own transponders, chooses its own margin, and turns channels up without asking anyone. The physical medium underneath all of them is one glass strand crossing an ocean floor that no party controls.

Confidentiality on that shared strand rests on two mechanisms with different jobs. Encryption applied at the line rate protects the content of the traffic against anyone who obtains the optical signal, whether by tapping the fibre, by mis-provisioning inside a shared terminal, or by compelling access at a landing point. Spectrum-level isolation protects the operational independence of each party, so that one user's frequency slot cannot be inserted into, read from, or disturbed by another. Neither substitutes for the other. Isolation without encryption leaves plaintext on the glass; encryption without isolation leaves a user exposed to a neighbour who over-drives the line and collapses everyone's margin.

The reason line-rate encryption became the deployed answer rather than a layered overlay is arithmetic. Every earlier scheme paid for confidentiality in bandwidth: an IPsec Encapsulating Security Payload adds tens of bytes per packet, a Media Access Control Security (MACsec) frame adds 32 bytes, and on a submarine route where a decibel of margin is bought once and spent for twenty-five years, that expansion converts directly into lost capacity. Encryption placed inside the transport frame writes ciphertext into the payload area the frame already carries, so the client rate, the line rate and the optical spectrum are unchanged. The cost moves from bandwidth to key state and silicon area.

This article covers the mechanism, the arithmetic and the operational practice: how a frame is protected and what it costs, where the trust boundaries fall between spectrum user, spectrum provider and cable owner, how keys are established and how often they must change, what spectrum isolation adds on top, and which optical observables report physical interference on a cable no one can inspect. Regulatory and policy context appears only where it changes an engineering requirement.

Terminology note

Three terms name the same commercial construct with different emphasis. Spectrum sharing is the service in which a provider opens a frequency window that the user fills from its own SLTE. Dark spectrum and unmanaged spectrum are alternative names for it. A virtual fibre pair is what the user holds as a result: an allocation the user lights, loads and operates independently, on a fibre pair it does not own.

2. Line-Rate Encryption Definition and Frame Anatomy

Line-rate encryption is the encryption of transport frames at the full serial rate of the interface, performed inside the frame structure the interface already sends. Ciphertext replaces plaintext in the payload area, overhead fields carry the security state, and no byte is added, so the client rate and the line rate stay exactly as they were.

The mechanism sits in the transmit chain between client mapping and forward error correction. A client signal is mapped into the transport frame in the usual way; the payload area of that frame is then passed through an Advanced Encryption Standard cipher in Galois/Counter Mode with a 256-bit key (AES-GCM-256), which produces ciphertext of exactly the same length plus an authentication tag; the tag and the security state are written into overhead positions that the frame already reserves; and the frame goes on to the encoder unchanged in size. Figure 1 shows which regions of the frame each operation touches.

FlexO frame anatomy with FlexOsec protection applied A map of the FlexO frame of 128 rows by 5140 bit columns. Row 1 holds the alignment mechanism in columns 1 to 480, extended overhead in columns 481 to 960 and basic overhead in columns 961 to 1280. The payload area occupies the remainder of row 1 and all of rows 2 to 128. The payload area is encrypted and authenticated, the basic overhead is authenticated but not encrypted, part of the extended overhead is authenticated, and the alignment mechanism is neither encrypted nor authenticated. Two panels state that payload expansion is zero bytes and that one frame is one cipher invocation. FlexO Frame Anatomy with FlexOsec Protection 128 rows of 5140 bit columns; row 1 carries the alignment mechanism and the overhead areas 1 480 960 1280 5140 Row 1 Rows 2 to 128 AM EOH BOH Payload area (row 1, columns 1281 to 5140) Payload area encrypted with AES-GCM-256 and authenticated ciphertext length equals plaintext length Protection Applied to Each Region Payload area: encrypted and authenticated Basic overhead: authenticated, not encrypted Extended overhead: part authenticated, not encrypted Alignment mechanism: neither encrypted nor authenticated Payload Expansion Client bytes in equal client bytes out. Ciphertext replaces plaintext in place and the tag occupies overhead positions the frame already reserves. Expansion = 0 bytes per frame Payload efficiency stays at 100%, against 97.91% for 32 bytes added to a 1500-byte client. Cipher Invocation Rate One frame is one authenticated-encryption invocation, so the frame size sets how quickly a key reaches its invocation bound. 128 × 5140 = 657,920 bits per frame At 103.125 Gb/s that is 156,744 frames per second and a cryptoperiod near 7.6 hours (computed). Field protection scope is standard-specified in ITU-T G.709.1; the frame is 128 rows of 5140 bit columns. Invocation and efficiency figures are computed from those field sizes.
Figure 1: FlexO frame anatomy with FlexOsec protection. The payload area is encrypted and authenticated, the basic overhead is authenticated without being encrypted, part of the extended overhead is authenticated, and the alignment mechanism is left untouched so that frame alignment still works on a receiver that cannot decrypt.
Premium Article — Free 13% Preview

Read the Full Analysis with Premium

The remaining 87% of this article — the design numbers, trade-offs and field guidance — is part of MapYourTech Premium, along with the full premium library, courses and professional tools.

1001+Technical Articles
66+Professional Courses
19+Engineering Tools
400K+Professionals
View Membership Plans Already a member? Sign In
Instant access Cancel anytime 48-hour trial available