Solutions

VoLTE End-to-End Encryption Solution

Standards-based, carrier-transparent secure voice communication for the modern enterprise

Solution Overview

Cunmeng Tech’s VoLTE encryption solution provides end-to-end security for voice calls and SMS messages over standard 4G/5G VoLTE and VoNR networks, built on IETF and 3GPP standards.

Network Architecture

  • VoLTE/VoNR Network — Standard carrier or private network. No modifications required.
  • SIM Cards — Standard SIMs with VoLTE service enabled.
  • KMS — PAD-based offline server for private key generation. Supports 50,000 terminals per unit.
  • Encrypted Phones — 5G custom devices (4G fallback) with pre-loaded encryption module.

Key Innovation

Session keys are carried through the RTP Payload (user plane) rather than SIP signaling. Completely transparent to carrier core networks and IMS.

Core Value

Communication Security

End-to-end encryption for voice calls and SMS. One-call-one-key ensures each session is independently protected.

Broad Applicability

Keys transmitted via user plane — zero carrier infrastructure changes. Works with any standard VoLTE/VoNR network.

Lightweight Deployment

Offline KMS is ready out of the box. No cloud infrastructure, no complex integration required.

Native Experience

Built on native VoLTE with QoS. Standard dialer — no third-party apps, no voice quality loss.

Encryption Algorithms & Standards

StandardDescription
RFC 6507SAKKE — IBE-based encryption algorithm
RFC 6508ECCSI — IBE-based signature algorithm
RFC 6509MIKEY-SAKKE — Key exchange protocol
3GPP TS 33.180Mission Critical (MC) security framework
AlgorithmTypePurpose
SAKKEAsymmetric (IBE)Session key encryption
ECCSIAsymmetric (IBE)Digital signature
AES-256-CTRSymmetricVoice/SMS payload
PCK (128-bit)SymmetricPer-call session key

KMS Security

  • Ruggedized PAD — Three-proof design for field deployment
  • U-Key Protection — Hardware token stores encrypted root private key
  • MDM Kiosk Mode — Locked-down interface
  • All Ports Closed — No network services exposed
  • U-Key Backup — Redundant tokens for disaster recovery
  • Offline Operation — KMS does not participate in sessions

Key Hierarchy

KMS Root KeyUser Private Key (per VoLTE number) → Session Key PCK (128-bit random) → AES-256 Key (RFC 3830/3711)

Security Specifications

AttributeSpecification
Security Level128-bit (approximately equivalent to ECC 256-bit)
Post-QuantumNot currently supported
Multi-party ConferenceNot supported
Session Key ExpiryNot supported
Forward SecrecyIBE has no forward secrecy; periodic root key rotation recommended