DTLS-SRTP (DTLS Extension to Establish Keys for SRTP)

Also known as: RFC 5764

DTLS-SRTP (RFC 5764) is a keying mechanism that runs a DTLS handshake over the media path to derive SRTP master keys, binding the media session to certificate fingerprints exchanged in SDP over signalling. It is the standard media-plane key agreement for WebRTC and is increasingly adopted in modern IMS deployments as a stronger alternative to SDES, whose keys travel in the clear inside SIP.

Categories: Security ControlsProtocols and StandardsEncryption and Cryptography

DTLS-SRTP in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom security is written into standards from 3GPP, GSMA, ETSI, IETF and ITU-T. Understanding which body owns which specification, and how they interlock, is essential for both design and audit work.

To place DTLS-SRTP in the wider telecom-security picture, review XMPP, SRTP, NAF, HKDF, 3G and 6G — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.