In an end-to-end encrypted (E2EE) call, participants' devices encrypt each video/audio frame with a shared group media key before it ever leaves the device. The SFU (Selective Forwarding Unit) in the middle only routes ciphertext between participants โ it never holds the key, so it cannot decode a frame even though it controls all the traffic.
The group key is not static. Every time membership changes โ someone joins or leaves โ or a rotation timer fires, the key ratchets forward through a one-way key-derivation function:
K(n+1) = KDF( K(n), epoch = n+1 ) // one-way, e.g. HKDF-SHA256 in real systems
- Leave โ forward secrecy. Because the KDF cannot run backward, a participant who leaves โ even a compromised device โ cannot derive K(n+1) and loses access to every frame sent after they left.
- Join โ post-compromise security. A new key epoch also means a newly joined device only gets K(n) onward, never the keys used for frames sent before it arrived.
- Timed rotation. Production systems (e.g. MLS-based group calls) also ratchet on a periodic timer regardless of membership churn, to bound how long any single leaked key stays useful โ the interval slider controls that cadence here.
- Intercept attempt. Because the SFU never receives the key, any attempt by the relay (or an attacker who compromises it) to read a packet fails โ it only ever holds ciphertext bytes, shown as the red "denied" flash.
This is the same core model used by production E2EE video products (e.g. Signal, Zoom's E2EE mode, Google Meet client-side encryption): a symmetric ratcheting group key, a semi-trusted relay that only forwards ciphertext, and a rotation on every membership change (plus, here, an optional timer) so leaked keys have the shortest possible useful life.