
Line-Rate Encryption and Traffic Confidentiality on Shared Cable Systems
Encryption inside the transport frame, spectrum-level isolation of a virtual fibre pair, key management, and monitoring for physical interference.
Write the interface contract before the equipment arrives.
What You Will Learn
- Define line-rate encryption from the frame anatomy of Figure 1 and state which FlexO fields are encrypted, which are authenticated, and which are neither.
- Quantify payload expansion with the efficiency relation, and reproduce the 97.91% and 96.53% figures for 32-byte and 54-byte expansion on a 1500-byte client.
- Place the trust boundaries of Figure 2 between spectrum user, spectrum provider and wet plant, and say which party holds which key.
- Compute a cryptoperiod from the 232 invocation bound: about 10 s for 64-byte frames at 400 Gb/s against about 7.6 h for a 100G FlexO instance.
- Convert a contracted power spectral density into a total input power, using −15.0 dBm/12.5 GHz over a 1200 GHz allocation as the worked case.
- Separate spectrum isolation from confidentiality, and state what the ingress and egress blocking of a spectrum management block does and does not protect.
- Select monitoring observables for physical interference, from state-of-polarization and phase records to the coherent OTDR trace, with their reporting latencies.
- Build the migration path to hybrid post-quantum key establishment without touching the symmetric cipher already running on the line.
1. Introduction
A transoceanic fibre pair that once carried one owner's traffic now routinely carries two to four parties, each lighting its own block of spectrum from its own submarine line terminal equipment (SLTE). The SubOptic Spectrum Sharing Working Group records this as the normal shape of the service: splitting a full fibre pair between two and four users is what the industry does, and allocations below roughly 20–25% of the fibre pair spectrum are discouraged because they waste capacity and complicate operation (industry working-group guidance). Each party operates its own transponders, chooses its own margin, and turns channels up without asking anyone. The physical medium underneath all of them is one glass strand crossing an ocean floor that no party controls.
Confidentiality on that shared strand rests on two mechanisms with different jobs. Encryption applied at the line rate protects the content of the traffic against anyone who obtains the optical signal, whether by tapping the fibre, by mis-provisioning inside a shared terminal, or by compelling access at a landing point. Spectrum-level isolation protects the operational independence of each party, so that one user's frequency slot cannot be inserted into, read from, or disturbed by another. Neither substitutes for the other. Isolation without encryption leaves plaintext on the glass; encryption without isolation leaves a user exposed to a neighbour who over-drives the line and collapses everyone's margin.
The reason line-rate encryption became the deployed answer rather than a layered overlay is arithmetic. Every earlier scheme paid for confidentiality in bandwidth: an IPsec Encapsulating Security Payload adds tens of bytes per packet, a Media Access Control Security (MACsec) frame adds 32 bytes, and on a submarine route where a decibel of margin is bought once and spent for twenty-five years, that expansion converts directly into lost capacity. Encryption placed inside the transport frame writes ciphertext into the payload area the frame already carries, so the client rate, the line rate and the optical spectrum are unchanged. The cost moves from bandwidth to key state and silicon area.
This article covers the mechanism, the arithmetic and the operational practice: how a frame is protected and what it costs, where the trust boundaries fall between spectrum user, spectrum provider and cable owner, how keys are established and how often they must change, what spectrum isolation adds on top, and which optical observables report physical interference on a cable no one can inspect. Regulatory and policy context appears only where it changes an engineering requirement.
Three terms name the same commercial construct with different emphasis. Spectrum sharing is the service in which a provider opens a frequency window that the user fills from its own SLTE. Dark spectrum and unmanaged spectrum are alternative names for it. A virtual fibre pair is what the user holds as a result: an allocation the user lights, loads and operates independently, on a fibre pair it does not own.
2. Line-Rate Encryption Definition and Frame Anatomy
Line-rate encryption is the encryption of transport frames at the full serial rate of the interface, performed inside the frame structure the interface already sends. Ciphertext replaces plaintext in the payload area, overhead fields carry the security state, and no byte is added, so the client rate and the line rate stay exactly as they were.
The mechanism sits in the transmit chain between client mapping and forward error correction. A client signal is mapped into the transport frame in the usual way; the payload area of that frame is then passed through an Advanced Encryption Standard cipher in Galois/Counter Mode with a 256-bit key (AES-GCM-256), which produces ciphertext of exactly the same length plus an authentication tag; the tag and the security state are written into overhead positions that the frame already reserves; and the frame goes on to the encoder unchanged in size. Figure 1 shows which regions of the frame each operation touches.
Read the Full Analysis with Premium
The remaining 87% of this article — the design numbers, trade-offs and field guidance — is part of MapYourTech Premium, along with the full premium library, courses and professional tools.
You May Also Like
-
Free
-
August 22, 2026
-
Premium
-
August 22, 2026
-
Premium
-
August 22, 2026