VoLTE End-to-End Encryption Solution
Standards-based, carrier-transparent secure voice communication for the modern enterprise
Solution Overview
Cunmeng Tech’s VoLTE encryption solution provides end-to-end security for voice calls and SMS messages over standard 4G/5G VoLTE and VoNR networks, built on IETF and 3GPP standards.
Network Architecture
- VoLTE/VoNR Network — Standard carrier or private network. No modifications required.
- SIM Cards — Standard SIMs with VoLTE service enabled.
- KMS — PAD-based offline server for private key generation. Supports 50,000 terminals per unit.
- Encrypted Phones — 5G custom devices (4G fallback) with pre-loaded encryption module.
Key Innovation
Session keys are carried through the RTP Payload (user plane) rather than SIP signaling. Completely transparent to carrier core networks and IMS.
Core Value
Communication Security
End-to-end encryption for voice calls and SMS. One-call-one-key ensures each session is independently protected.
Broad Applicability
Keys transmitted via user plane — zero carrier infrastructure changes. Works with any standard VoLTE/VoNR network.
Lightweight Deployment
Offline KMS is ready out of the box. No cloud infrastructure, no complex integration required.
Native Experience
Built on native VoLTE with QoS. Standard dialer — no third-party apps, no voice quality loss.
Encryption Algorithms & Standards
| Standard | Description |
|---|---|
| RFC 6507 | SAKKE — IBE-based encryption algorithm |
| RFC 6508 | ECCSI — IBE-based signature algorithm |
| RFC 6509 | MIKEY-SAKKE — Key exchange protocol |
| 3GPP TS 33.180 | Mission Critical (MC) security framework |
| Algorithm | Type | Purpose |
|---|---|---|
| SAKKE | Asymmetric (IBE) | Session key encryption |
| ECCSI | Asymmetric (IBE) | Digital signature |
| AES-256-CTR | Symmetric | Voice/SMS payload |
| PCK (128-bit) | Symmetric | Per-call session key |
KMS Security
- Ruggedized PAD — Three-proof design for field deployment
- U-Key Protection — Hardware token stores encrypted root private key
- MDM Kiosk Mode — Locked-down interface
- All Ports Closed — No network services exposed
- U-Key Backup — Redundant tokens for disaster recovery
- Offline Operation — KMS does not participate in sessions
Key Hierarchy
KMS Root Key → User Private Key (per VoLTE number) → Session Key PCK (128-bit random) → AES-256 Key (RFC 3830/3711)
Security Specifications
| Attribute | Specification |
|---|---|
| Security Level | 128-bit (approximately equivalent to ECC 256-bit) |
| Post-Quantum | Not currently supported |
| Multi-party Conference | Not supported |
| Session Key Expiry | Not supported |
| Forward Secrecy | IBE has no forward secrecy; periodic root key rotation recommended |
