Tech

The cloud and voice encryption

Published on:

February 7, 2014

When the first version of pbxnsip introduced RTP encryption, it was a pioneering feature, but it didn’t generate the expected marketing success. Back then, customers were just happy if they could hear each other over VoIP. Over time, we refined our SRTP implementation to address challenges like the rollover counter, optimized transcoding, and avoided one-way audio issues. With growing awareness of security, encryption is now a critical focus, yet many providers still don’t encrypt voice traffic. To bridge this gap, we’ve added the ability to write decrypted PCAP files, making troubleshooting encrypted voice easier, and this feature is available in version 5.1.3.

The first version of pbxnsip had already RTP encryption. It was actually one of the reason to start a new PBX because at that time there was nothing on the market that was affordable. I remember we made a full-page advertisement in a telephony magazine about this important feature. However, instead of having the phone ringing all the time about this new feature, it was a marketing flop. Almost nobody cared. At that time VoIP was just in a different stage, customers were happy if they could hear each other at all. One-way audio had just been invented.

Over time we learned how to deal with the rollover counter. Instead of coming up with SSRTP, which is not backward compatible, we found a pragmatic way that works in practically all situations. We optimized the SRTP implementation, so that SRTP transcoding was not stressing the CPU too much. Also transfers did not cause any SRTP hiccups. Also we found ways to read misleading answers during the negotiation so that we did not end up with one-way audio because of SRTP.

After the latest revelations about the various agencies in the world, people today are a lot more aware about the importance of voice encryption and the cloud. However there is still a huge gap between what could be done and what is the reality. Many hosted PBX providers are still not encrypting their voice traffic between the PBX and the handset. And even worse, the competition in the SIP trunk space is all about price. Things like encryption don’t play a role, and so most of the RTP traffic in the internet backbone is completely unencrypted. With least cost routing that makes up most of the routing decisions today, it would be easy to set up a trunk provider that bids for the routes that you are interested in and then you’ll get the voice traffic delivered to your front door.

I have not given up the hope that SRTP will be used on a trunk one day. We are still preparing for this. Apart from offering the encryption mechanisms, we also need to work on the tools to trouble shoot encrypted voice.

Therefore, the latest security feature that we have added is the writing of decrypted PCAP files. Having the raw packets as they go in and out of the PBX if great to analyze problems. However if they are encrypted they have only limited value. Because the PBX knows the security context, it can first decrypt the packets and then write them into a PCAP file with the timestamps when they were received. Other devices like SIP-aware firewalls and ALG are typically not able to see this traffic. This is something that is very useful in cases when installations have quality problems and the customers demand encryption of their voice traffic.The feature is available since 5.1.3 and does not need a separate license.

Latest Articles

View All

Vodia Visits IT Expo 2025

Vodia was excited to attend IT Expo 2025 in Ft. Lauderdale, where Sales Engineer Eric Altman connected with industry leaders such as Tommy Lee from Fanvil, Gary Harbeck from Dinstar, Spencer Lee from Telin, Sebastian Balan from Fidelity, Todd Weikle from Soar Communications, Steve Scott from Borderless.com, and Mitch Kahl from BCM One. The discussions highlighted the role of AI in business communications, Vodia’s Microsoft Teams-certified PBX, and our integration with Realtime AI via APIs. This event followed a strategic planning session with key partners to outline Vodia’s goals for 2025. We look forward to connecting with you at future events!

February 19, 2025

AI-Powered Hotel Phone System: OpenAI for Guest Services

Vodia has integrated OpenAI’s Realtime API with its PBX, enabling real-time AI-powered hotel phone systems that enhance guest services. By leveraging natural speech processing, guests can make reservations, request services, and access hotel amenities in multiple languages - all through voice commands. This integration streamlines hotel operations, reduces staff workload, and improves guest satisfaction. Whether booking a room, ordering room service, or arranging transportation, AI-powered phone systems provide seamless communication and efficiency. Hotels can now offer personalized, automated experiences while maintaining reliable, high-quality service.

February 18, 2025

Vodia and Microsoft Teams: Your Call Center Solution

ConnectPlus, a fictional call center with 150 agents and 20 support team members, faced several challenges in managing its phone systems and customer interactions. The company struggled with inefficient call routing, long wait times, and inadequate reporting, especially as it relied on Microsoft Teams for internal communication. To improve operational efficiency and enhance the customer experience, ConnectPlus sought a solution that could streamline its processes across multiple devices and platforms. Integrating Vodia’s PBX with Teams provided the ideal solution, optimizing their call handling and overall communication capabilities.

February 12, 2025