> For the complete documentation index, see [llms.txt](https://zoom.gitbook.io/zoom/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://zoom.gitbook.io/zoom/contents.md).

# Contents

### **1. Introduction**

\
*1.1 Outline* \
*1.1.1 E2E Encryption for Zoom Meetings*

### 2. Background and Security Goals&#x20;

\
*2.1 Limitations*

### 3. User Identity and Key Management&#x20;

\
*3.1 Non-Cryptographic Identity at Zoom*&#x20;

*3.2 Cryptographic User Identity*&#x20;

*3.3 Displaying Identity*&#x20;

*3.3.1 Identifying Accounts*&#x20;

*3.3.2 Identifying Users*&#x20;

*3.4 Multi-Device Support*&#x20;

*3.4.1 Per-User Keys*&#x20;

*3.4.2 Backup Keys*&#x20;

*3.4.3 Escrow Keys*&#x20;

*3.4.1 Lockdown Mode*&#x20;

*3.5 Consistent Identities With Sighchains*&#x20;

*3.5.1 Sighchains*&#x20;

*3.5.2 Overview of Sighchain Types*&#x20;

*3.5.3 User Sighchains*&#x20;

*3.5.4 Email Sighchains*&#x20;

*3.5.5 Account Sighchains*&#x20;

*3.5.6 ADN Sighchains*&#x20;

*3.5.7 Membership Sighchains*&#x20;

*3.6 Sighchain Fingerprints*&#x20;

*3.7 Client Key Management*&#x20;

*3.7.1 Storing Secret Keys on Device*&#x20;

*3.7.2 Device Management Interface*&#x20;

*3.8 Account Escrow*&#x20;

*3.8.1 Escrow Administrators and the EA Sighchain*&#x20;

*3.8.2 Users’ Escrow Device Management*&#x20;

*3.8.3 EA Permissions*&#x20;

*3.8.4 User Recovery*&#x20;

*3.8.5 Legal Discovery*&#x20;

*3.9 Highlighting Untrusted Devices with Contact Sync*&#x20;

*3.10 Compromise Prevention for Device Provisioning*&#x20;

*3.11 Security Properties*&#x20;

*3.11.1 MitM Between a User’s Devices*&#x20;

*3.11.2 MitM Between Different Users*&#x20;

*3.11.3 Integrity*&#x20;

*3.11.4 Security Limitations*&#x20;

*3.11.5 Privacy Limitations*

### 4. Transparency Tree&#x20;

*4.1 Zoom Transparency Tree*&#x20;

*4.2 Integration Details*&#x20;

*4.2.1 ZTT Auditing*&#x20;

*4.2.2 Provisioning*&#x20;

*4.2.3 Self-Audit and Refresh*&#x20;

*4.2.4 Validating User Identity*&#x20;

*4.2.5 Contact List Updates*&#x20;

*4.3 Security Properties*

*5 Identity Provider Attestations*&#x20;

*5.1 Associating Accounts with Identity Providers*&#x20;

*5.2 IDP Attestations 5.3 Updating Snapshots*&#x20;

*5.4 Validating IDP Attestations*&#x20;

*5.5 Zoom Identity Snapshots*&#x20;

*5.6 Security Properties*

### *6. Encryption for Zoom Mail Service*&#x20;

*6.1 Encrypted Email Protocol*&#x20;

*6.2 Emails to Users without Devices*&#x20;

*6.3 Emails to and from External Users*&#x20;

*6.4 Mailing Lists 6.5 Calendar Email Integration*&#x20;

*6.6 Encrypting Non-Email Data*&#x20;

*6.7 Security Properties*&#x20;

*6.7.1 Spam Detection and Contact Monitoring*

### 7. Encryption for Zoom Meetings&#x20;

*7.1 Zoom Meetings*&#x20;

*7.2 Enhanced Encryption*&#x20;

*7.3 End-to-End Encryption*

*7.3.1 Security Goals*&#x20;

*7.4 System Components*&#x20;

*7.5 Cryptographic Algorithms*&#x20;

*7.5.1 Signing*&#x20;

*7.5.2 Authenticated Public-Key Encryption*&#x20;

*7.6 Join/Leave Protocol flow*

*7.6.1 Server Key Certificate Chains*&#x20;

*7.6.2 Participant Key Generation*

*7.6.3 Leader Join*&#x20;

*7.6.4 Participant Join (Leader)*&#x20;

*7.6.5 Participant Join (Non-Leader)*&#x20;

*7.6.6 Key Rotation*&#x20;

*7.6.7 Leader Participant List*&#x20;

*7.6.8 Liveness*&#x20;

*7.6.9 Locked Meetings*&#x20;

*7.6.10 Meeting Teardown*

*7.7 Meeting Leader Security Code*&#x20;

*7.8 E2E Encryption for Breakout Rooms*&#x20;

*7.9 Abuse Management and Reporting*&#x20;

*7.10 IDP Attestations for E2EE Meetings*&#x20;

*7.11 E2EE Meetings with Cryptographic Identity*&#x20;

*7.12 Security Properties for E2EE Meetings*&#x20;

*7.12.1 Areas to Improve*

### 8. Encryption for Zoom Phone&#x20;

*8.1 E2EE Zoom Phone Calls*&#x20;

*8.1.1 Join/Leave Protocol*

*8.1.2 Phone Security Code*&#x20;

*8.2 Advanced Encryption for Voicemail*&#x20;

*8.2.1 Security Properties*

### A. Release Schedule

B Understanding Multiple Devices&#x20;

B.1 A Claim about Device Equivalence Classes

### C. Cake-AES&#x20;

C.1 Encryption&#x20;

C.2 Decryption&#x20;

C.3 Random-Access Decryption
