Tech

The cloud and voice encryption

Published on:

February 7, 2014

When the first version of pbxnsip introduced RTP encryption, it was a pioneering feature, but it didn’t generate the expected marketing success. Back then, customers were just happy if they could hear each other over VoIP. Over time, we refined our SRTP implementation to address challenges like the rollover counter, optimized transcoding, and avoided one-way audio issues. With growing awareness of security, encryption is now a critical focus, yet many providers still don’t encrypt voice traffic. To bridge this gap, we’ve added the ability to write decrypted PCAP files, making troubleshooting encrypted voice easier, and this feature is available in version 5.1.3.

The first version of pbxnsip had already RTP encryption. It was actually one of the reason to start a new PBX because at that time there was nothing on the market that was affordable. I remember we made a full-page advertisement in a telephony magazine about this important feature. However, instead of having the phone ringing all the time about this new feature, it was a marketing flop. Almost nobody cared. At that time VoIP was just in a different stage, customers were happy if they could hear each other at all. One-way audio had just been invented.

Over time we learned how to deal with the rollover counter. Instead of coming up with SSRTP, which is not backward compatible, we found a pragmatic way that works in practically all situations. We optimized the SRTP implementation, so that SRTP transcoding was not stressing the CPU too much. Also transfers did not cause any SRTP hiccups. Also we found ways to read misleading answers during the negotiation so that we did not end up with one-way audio because of SRTP.

After the latest revelations about the various agencies in the world, people today are a lot more aware about the importance of voice encryption and the cloud. However there is still a huge gap between what could be done and what is the reality. Many hosted PBX providers are still not encrypting their voice traffic between the PBX and the handset. And even worse, the competition in the SIP trunk space is all about price. Things like encryption don’t play a role, and so most of the RTP traffic in the internet backbone is completely unencrypted. With least cost routing that makes up most of the routing decisions today, it would be easy to set up a trunk provider that bids for the routes that you are interested in and then you’ll get the voice traffic delivered to your front door.

I have not given up the hope that SRTP will be used on a trunk one day. We are still preparing for this. Apart from offering the encryption mechanisms, we also need to work on the tools to trouble shoot encrypted voice.

Therefore, the latest security feature that we have added is the writing of decrypted PCAP files. Having the raw packets as they go in and out of the PBX if great to analyze problems. However if they are encrypted they have only limited value. Because the PBX knows the security context, it can first decrypt the packets and then write them into a PCAP file with the timestamps when they were received. Other devices like SIP-aware firewalls and ALG are typically not able to see this traffic. This is something that is very useful in cases when installations have quality problems and the customers demand encryption of their voice traffic.The feature is available since 5.1.3 and does not need a separate license.

Derniers articles

Voir tous

The Vodia PBX On-Premise Whisper AI Deployment​

Whisper, OpenAI’s Automatic Speech Recognition system, delivers multilingual, noise-tolerant, and technical-language-ready transcription through a streamlined encoder-decoder architecture. With Vodia PBX’s integration, organizations can choose between using OpenAI’s service or hosting Whisper AI locally for complete data sovereignty and control. This on-premise option ensures that sensitive call data stays within your infrastructure while still benefiting from powerful transcription capabilities. To explore deployment options, see our Whisper AI on-premise setup documentation, review a self-hosted integration example, or follow our cloud-based call transcription guide.

March 27, 2025

Vodia Will Attend Seatrade Cruise Global 2025

Vodia is excited to attend Seatrade Cruise Global 2025, marking the event’s 40th anniversary, taking place in Miami from April 7-10. In partnership with Lufthansa Industry Solutions, Vodia will showcase the Vodia Maritime Communication Server (Vodia MCS)—a next-generation solution designed to seamlessly integrate voice, video, and messaging within cruise ship communications. Engineered for both new vessels and retrofits, the Vodia MCS enhances onboard connectivity, passenger experience, and operational efficiency, while supporting essential maritime safety and security systems. Join us at booth #3608 to discover how Vodia MCS is reshaping onboard communication in the cruise industry.

March 24, 2025

The Vodia PBX Gives Hotels a Peerless Suite of Hospitality Features

Vodia PBX delivers a comprehensive hospitality communication system that enhances guest experience and streamlines hotel operations. With support for multiple device types, seamless PMS integration, in-house call center functionality, and Microsoft Teams connectivity, hotels can optimize efficiency while maintaining high-quality service. Guests can easily access hotel services, communicate with staff, and integrate their personal devices for a seamless and convenient stay. Advanced automation, multilingual support, AI-driven call management, and building automation features further enhance functionality, making Vodia PBX a powerful, scalable solution for modern hospitality environments.

March 20, 2025