Secure Real-time Transport Protocol (SRTP)

A profile of RTP (RFC 3711) that encrypts and authenticates voice and video media streams and protects them against replay, with keys supplied by a separate exchange.

The Secure Real-time Transport Protocol (SRTP) is defined in RFC 3711 as a security profile of RTP, the protocol that carries the audio and video in voice over IP calls and conferences. SRTP adds confidentiality by encrypting the media payload, message authentication so that altered packets are detected, and protection against replay attacks. A companion, SRTCP, protects the control messages that report on the stream. The design keeps packet overhead small, because real-time media is sensitive to delay and jitter.

SRTP does not negotiate its own keys. They come from a separate key management exchange, commonly DTLS-SRTP (RFC 5764), keys carried inside the call signalling, or a dedicated protocol such as MIKEY. That dependency is the point candidates tend to miss. Call setup is handled by the Session Initiation Protocol, and if the signalling carries the media keys without its own protection, such as TLS, anyone who reads the signalling can decrypt the media. A protected call therefore needs both halves: protected signalling and SRTP for the media.

Exam relevance: a scenario about preventing eavesdropping on the content of VoIP calls is likely to point to SRTP, while one about protecting call setup points to SIP over TLS. Candidates are expected to know that SRTP protects the media only, and relies on another exchange for its keys.