Project revival: TwoSquares is preserving GNU Telephony's history and preparing an open-source revival. Contributors and collaborators are welcome.
GNU Telephony
Open-source telephony, preserved and being revived
Cryptographic Architecture

ZRTP & Media Encryption Architecture

How Phil Zimmermann, Werner Dittmann, and GNU Telephony engineered RFC 6189 to deliver authenticated SRTP media streams without central key servers.

Why ZRTP Succeeded Where PKI Failed

Before ZRTP, securing VoIP required either centralized SIP servers that decrypted all traffic or Public Key Infrastructure (PKI) certificates loaded onto every phone. Both models failed in practice: centralized PBXs were wiretapped, and PKI was too complex for ordinary end users and vulnerable to corrupted certificate authorities.

ZRTP took an entirely different route: in-band, ephemeral Diffie-Hellman key exchange directly over the RTP connection, authenticated by the human voice reading a two-word Short Authentication String (SAS).

The Four States of a ZRTP Connection

  1. Discovery: Endpoints exchange ZRTP Hello packets within the RTP stream to verify protocol support.
  2. Key Agreement: An ephemeral Diffie-Hellman exchange (DH-2048 or DH-3072) derives a master session key.
  3. SAS Verification: Both endpoints display a 4-character code or two PGP words. Callers verbally verify these words to eliminate active eavesdroppers.
  4. SRTP Streaming: The session switches to AES-CFB or AES-GCM encryption, protecting voice packets from passive wiretapping.