Take Action
End-to-End Encrypted Voice & Messaging

Your call stays private from key to carrier.

Native VoLTE voice and SMS end-to-end encryption for 5G smartphones — built on standards-based identity cryptography (RFC 6508 SAKKE / ECCSI) and an AES-256 session cipher that runs inside the device's trusted execution environment.

<30 msEncrypted voice latency
AES-256CTR session cipher
10,000Encrypted terminals / KMS
IP67 / IP68KMS & rugged handset

Encryption that lives inside the native dialer

No third-party app, no overlay, no voice gateway. The cryptographic engine sits between the modem and the codec, so a call is encrypted the moment it is placed — and decrypted only on the callee's handset.

STEP 01

KMS Initialization

Administrators start the KMS and authenticate with the U-key. The root key never leaves the device, and all IP transport channels are disabled at the system level.

STEP 02

QR Key Injection

Select the department and mobile number, then let the KMS generate a one-time QR code. The handset scans it and stores the private key through the TEE interface.

STEP 03

Encrypted Call

The caller's SDK exchanges a fresh PCK session key over the SIP user plane. Voice is encrypted at the SOC/modem boundary and decrypted on arrival — transparent to the user.

U-key authentication, KMS initialization, QR private key injection and encrypted call flow
U-key authentication → KMS key generation → QR key injection → encrypted voice call and SMS
Encrypted VoLTE flow between User-A and User-B through the IMS core
Media flow encryption on the caller side, decryption on the callee side — the carrier only ever carries ciphertext
Security Model

The operator carries ciphertext, not your voice

Each communication domain owns its own root key. Every subscriber receives an identity-based private key bound to their phone number, so no certificate authority, key directory, or online key server is ever exposed to interception.

  • Identity-based keys — SAKKE for encryption and ECCSI for signatures, both defined by RFC 6508 / RFC 6507.
  • TEE-backed storage — the private key is sealed inside the trusted execution environment, unreachable from the rich OS.
  • Hardware root of trust — the KMS root key is encrypted with a key held on the physical U-key, required at every boot.
  • Air-gapped by design — cellular and Wi-Fi interfaces on the KMS are shut down at the system level.
  • Per-call session keys — one 128-bit PCK per session, generated by the caller's KMC.
Conversations about pricing, litigation or a new design should not be audible to anyone else.

From the boardroom to the beach, the same handset, the same dialer, the same encrypted channel.

KMS private key generator with U-key
Key Management

The KMS — Private Key Generator

Manage the root key for your communication domain and issue a user private key for every VoLTE device in it, derived from the subscriber's communication number.

  • Device purpose — root key authority and private key issuer for the whole domain.
  • Offline design — all IP transmission channels (cellular / Wi-Fi) are shut down at the system level.
  • SAKKE key length — 1024-bit KMS root key and 2048-bit user private key, per RFC 6508.
  • Root key secure storage — the root key is encrypted with a key held on the U-key, and U-key insertion is mandatory for KMS startup and operation.
Unit price$22,000
Key Specifications
SpecificationDetails
Dimensions10.59 in. L × 6.65 in. W × 0.49 in. H (269 mm × 169 mm × 12.5 mm)
Weight26.1 oz. / 740 g with battery
Display10.95" HD (1920×1200) industrial-grade IPS, Corning Gorilla Glass, 500 nits LED backlight
ProcessorOcta-core: 2× Arm Cortex-A76 @ 2.2 GHz + 6× Arm Cortex-A55 @ 2.0 GHz
Operating SystemAndroid 15.0
MemoryRAM 6 GB (optional 8 GB); Flash 128 GB (optional 256 GB / 512 GB); microSD up to 512 GB
BatteryRechargeable Li-ion 3.85 V 10000 mAh, supports 12 V/3 A 30 W PE2.0 / PD3.0 fast charging
DurabilityIP67 rated; withstands 1.2 m drops to concrete; 500 tumbles
Touch PanelCapacitive touch panel, supports water & gloves touch mode
Max Encrypted Terminals10,000
Operating Temperature-4°F to 122°F / -20°C to +50°C; Storage: -40°F to 158°F / -40°C to +70°C
F70 5G VoLTE encryption large-screen smartphone
Smartphone

The F70 — 5G VoLTE Encryption Large-Screen Smartphone

A full-size daily driver that supports native VoLTE voice and SMS end-to-end encryption without changing the way anyone makes a call.

  • Symmetric cipher — AES256_CTR with a 256-bit key length on the mobile terminal.
  • Private key secure storage — the key fetched by the on-device KMC over QR code is encrypted and stored through the TEE interface; the wrapping key lives inside the TEE and is inaccessible to the rich OS space.
  • One tap to encrypt — the native dialer offers both a normal call and an encrypted call.
Unit price$760
Key Specifications
SpecificationDetails
Dimensions6.72 in. L × 3.11 in. W × 0.35 in. H (170.8 mm × 79.1 mm × 9.0 mm)
Weight7.3 oz. / 207.7 g
Display6.81" FHD+ (2400×1080) punch-hole display
ProcessorOcta-core 2.2 GHz (domestic chipset)
Operating SystemAndroid 15
MemoryRAM 8 GB; ROM 128 GB (optional 6 GB + 128 GB / 8 GB + 256 GB)
CameraRear: 48 MP + 8 MP (wide-angle) + 2 MP (bokeh); Front: 8 MP
Battery5000 mAh (typical), 9 V/2 A 18 W fast charging
DurabilityIP54 rated
End-to-End Encryption Voice Latency<30 ms
Frequency Bands4G LTE-FDD: B1/B3/B5/B7/B8; 4G LTE-TDD: B34/B38/B39/B40/B41 (2515–2675 MHz); 5G NR: N1/N41/N78/N28A
D51 5G VoLTE encryption rugged smartphone
Rugged & Explosion-Proof

The D51 — 5G VoLTE Encryption Rugged Smartphone

The same end-to-end encrypted voice and SMS, packaged for field operations that demand rugged and intrinsically safe hardware.

  • Encryption — AES256_CTR with a 256-bit key length, private key sealed via the TEE interface (identical to the F70).
  • PTT button — a dedicated push-to-talk key supporting group call, temporary group and two-way intercom over the public network.
  • Special environment adaptability — rugged and explosion-proof construction for demanding scenarios.
  • Independent positioning — GPS / GLONASS / AGPS / WLAN / Bluetooth plus an independent BeiDou (BDS) receiver.
Unit price$1,060
Key Specifications
SpecificationDetails
Dimensions6.75 in. L × 3.20 in. W × 0.45 in. H (171.6 mm × 81.2 mm × 11.55 mm)
Display6.67" FHD+ (2400×1080), auto-brightness, glove & wet-hand touch mode
ProcessorOcta-core 2.2 GHz, 6 nm EUV (domestic 5G chipset)
Operating SystemAndroid 15
MemoryRAM 8 GB; ROM 128 GB / 256 GB, microSD expansion
CameraRear: 48 MP (AI) + 13 MP (wide-angle); Front: 8 MP (AI)
Battery4300 mAh, fast charging with overload protection
DurabilityIP68 rated; 2.0 m drop to concrete (12 drops); 1 m underwater for 2 hours
Explosion-Proof RatingEx ib IIC T4 Gb (intrinsically safe)
PTT & Public Network IntercomDedicated PTT button; group call, temporary group, two-way intercom
PositioningGPS / GLONASS / AGPS / WLAN / Bluetooth; independent BeiDou (BDS)
End-to-End Encryption Voice Latency<30 ms
Frequency Bands4G LTE-FDD: B1/B3/B5/B7/B8; 4G LTE-TDD: B34/B38/B39/B40/B41 (2515–2675 MHz); 5G NR: N1/N41/N78/N28A

Every key, and where it lives

Domain Key Symbol Key Length Generated by Store Where Definitions
SAKKE Keys ZT (S) 1024-bit KMS KMS Master key of KMS, for encryption
ZT (P) 2048-bit KMS KMS, KMC Global public encryption key of KMS, well-known
RSK 1024-bit KMS KMC User private encryption key for encryption
ECCSI Keys KSAK 256-bit KMS KMS Master key of KMS, for signature
KPAK 512-bit KMS KMS, KMC Global public signature key of KMS, well-known
SSK 256-bit KMS KMC User private encryption key for signature
Symmetric Key PCK 128-bit KMC (Caller) — For P2P call (one session, one key)
SAKKE — Identity-Based Encryption ECCSI — Identity-Based Signature Symmetric — Session Key
Sequence diagram of encrypted call establishment between caller and callee
Call start → IMessage key exchange → call answered → encrypted call established → encrypted voice transmission
Native dialer with Normal Call and Encrypt Call buttons

Dial with one extra tap

The native dialer adds an Encrypt Call button beside the standard call key — no separate app to launch.

Encryption call setup screen

Encryption call setup

The SDK negotiates the session key over the SIP user plane while the phone shows a normal call setup screen.

Encryption call going screen

Encryption call going

Both parties see the encrypted state in the call UI; recording, mute, keypad and speaker behave as usual.

Unit Price

One KMS builds the domain; every handset added afterwards simply scans a QR code.

KMS unit price

KMS

Unit price$22,000
  • Root key authority for one domain
  • Up to 10,000 encrypted terminals
  • U-key required at every startup
  • Air-gapped, IP transport disabled
View Pricing
D51 unit price

D51

Unit price$1,060
  • Rugged, IP68, 2 m drop rated
  • Ex ib IIC T4 Gb intrinsically safe
  • Dedicated PTT / group intercom key
  • Independent BeiDou positioning
View Pricing

All prices quoted are EXW (Ex Works) price, excluding domestic logistics, ocean freight, customs declaration, duties and all other transportation and tax expenses.

Bulk Discount

Bulk discount packages for different scales — from a two-device trial to a full field rollout.

Trial package

Trial Package

Package price$1,520

For test only. Temporary QR codes are provided remotely so you can evaluate the encryption end to end.

95% Discount
Small package

Small Package

Package price$35,340

A pilot squad: one KMS domain plus a group of encrypted handsets, ready for day-to-day use.

90% Discount
Medium package

Medium Package

Package price$88,200

Department-wide coverage with mixed F70 and D51 handsets and full key lifecycle management.

85% Discount
Advanced package

Advanced Package

Package price$341,700

Large-scale deployment for enterprise and government communication domains.