Featured Developer Sponsor • Zero-Token Protection
0.18 ms
Frame Encryption Latency (Hardware AES-NI)
15 Bytes
SFrame Per-Frame Header + Tag Overhead
Zero (Opaque)
SFU Media Payload Visibility
128 Bits
Tamper-Proof Authentication Tag
1. SFrame Cipher & SFU Topologies
2. SFrame Wire Format & SFU Packet Inspection
Transmitted Media Frame Structure (Total Size: ~12,450 Bytes)
SFrame Header (3B)
Encrypted Media Payload (12,431B - AES-GCM Ciphertext)
Auth Tag (16B)
[SFU PACKET INSPECTION] What the Mediasoup / LiveKit Server Sees:
• RTP Sequence Number: 24,910 (Used for packet loss detection & retransmission)
• RTP Timestamp: 1,482,049 (Used for jitter buffer synchronization)
• RTP SSRC: 0x4a91bc2e (Used for routing stream to subscribed peers)
• Payload Data: 0x3f9a2e81...b4e1 (Unreadable / Encrypted Ciphertext)
• Result: Zero Trust Maintained. Server possesses no decryption keys.
• RTP Sequence Number: 24,910 (Used for packet loss detection & retransmission)
• RTP Timestamp: 1,482,049 (Used for jitter buffer synchronization)
• RTP SSRC: 0x4a91bc2e (Used for routing stream to subscribed peers)
• Payload Data: 0x3f9a2e81...b4e1 (Unreadable / Encrypted Ciphertext)
• Result: Zero Trust Maintained. Server possesses no decryption keys.
// Generated SFrame Worker code
Frequently Asked Technical Questions
Why does standard WebRTC DTLS-SRTP fail to provide End-to-End Encryption in multi-party SFU conferences?+
In point-to-point 1-on-1 WebRTC calls, DTLS-SRTP encrypts the media directly between the two endpoints. However, in group video conferences with 3 or more participants, point-to-point mesh requires O(N^2) bandwidth and CPU encoding, which quickly overwhelms mobile devices. Group calls rely on Selective Forwarding Units (SFUs) to route streams. Because DTLS-SRTP terminates at the media server, the SFU possesses the decryption keys and can inspect, record, or modify all unencrypted audio and video payloads. True E2EE requires frame-level encryption before RTP packetization, ensuring the SFU acts as a blind relay.
How does RFC 9605 SFrame (Secure Frame) solve the SFU E2EE challenge?+
SFrame (RFC 9605) is a lightweight, frame-level encryption format designed specifically for real-time media. Instead of encrypting at the RTP packet layer, SFrame encrypts each complete encoded video or audio frame (using AES-GCM or AES-CTR with HMAC) immediately after the codec outputs it. SFrame prepends a tiny header (containing a Key ID and frame counter) and appends an authentication tag (typically 80 or 128 bits). The encrypted frame is then passed to the browser's standard WebRTC packetizer. The SFU receives standard RTP packets, inspects unencrypted RTP sequence numbers and timestamps to route packets to subscribers, but has zero ability to decrypt the underlying video/audio data.
How do WebRTC Insertable Streams and RTCRtpScriptTransform enable in-browser SFrame encryption?+
WebRTC Insertable Streams (via the RTCRtpScriptTransform API) expose encoded audio and video chunks as standard WHATWG Streams inside a dedicated Web Worker thread. On the sending peer, an TransformStream intercepts each RTCEncodedVideoFrame before packetization, reads frame.data into an ArrayBuffer, applies SFrame encryption, and writes the ciphertext back. On the receiving peer, another worker stream intercepts the incoming encoded frames, verifies the SFrame authentication tag, decrypts the payload, and passes the plaintext frame to the browser's video decoder.
What is the byte overhead and performance latency of SFrame encryption per video frame?+
SFrame was engineered for minimal bandwidth impact. A typical SFrame header occupies only 3 to 5 bytes (using variable-length integer encoding for Key ID and Frame Counter), and the authentication tag adds 8 to 16 bytes. Total overhead is only ~11 to 21 bytes per frame. At 30 frames per second, SFrame adds less than 0.5 KB/s of network overhead—virtually undetectable. Using hardware-accelerated WebCrypto AES-GCM, frame encryption takes less than 0.2 milliseconds, adding imperceptible latency to real-time communication.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement