Client Server ClientHello + use_srtp + supported_ekt_ciphers --------> ServerHello {EncryptedExtensions} + use_srtp + supported_ekt_ciphers {... Finished} <-------- {... Finished} --------> [ACK] <-------- [EKTKey] [ACK] --------> |SRTP packets| <-------> |SRTP packets| + + {} Messages protected using DTLS handshake keys [] Messages protected using DTLS application traffic keys <> Messages protected using the EKTKey and EKT Cipher || Messages protected using the SRTP master key sent in a Full EKT Tag