This invention provides a method and system for secure messaging on a mobile network, leveraging public/private key encryption. The method includes steps for deploying a trusted application by a mobile carrier on a device with a Trusted Execution Environment (TEE). A wireless Software Development Kit (SDK) on the subscriber device interacts with the trusted application and a wireless original equipment manufacturer (OEM) cloud service for mutual attestation, confirming the identity and trustworthiness of the device. A pair of public and private keys are generated, with the private key secured on the device. Messages are encrypted with the public key at a cloud messaging application, and decrypted with the private key at the device, enabling secure, viewable messages. The system can support secure transmission of one-time-passwords (OTPs) from an enterprise application, as well as encrypted chat functionality for device responses to the enterprise application.