As I understand iMessage, when you attempt to text a number a background thread fires and checks with Apple's iMessage servers to see whether or not the number is associated with an iMessage account, then returns the end-user account details to your device so it may send a digital message addressed to that user to Apple's iMessage servers.
Replace that digital ID with a public key. Private keys are generated and kept only on your iDevice. iMessage servers are your CA. Each iDevice has a unique public key.
At this point you have a very secure, end-to-end encryption scheme. No warrantless snooping is possible, and even Apple is unaware of your message contents.
Now depending on whether you want your design to be CALEA-compatible or not, Apple can issue a new private key to the government and add it to "your" list of public keys on their CA to allow the government to intercept future messages after they have obtained a warrant. If you think you can go toe-to-toe with the FBI and exempt yourself from CALEA by claiming the design of your infrastructure does not permit for message interception, you can tweak the CA around a bit. Only one public key per user, pass private key symmetrically encrypted with a password only the user knows from one device to the other via a "secure" side channel when adding new iDevice to user's iMessage account or other workaround.
I'm absolutely not a security person, and none of what I say should be taken except as some ramblings that might have some hint of an idea beneath them. I already can think of a dozen weaknesses in this system, this kinda works only if you assume you can trust Apple to play within the rules of the framework they're making, i.e. not to try to intercept your private key, log your keystrokes, automatically add a second public key recipient to your messages, etc. Fact of the matter is, you are at their mercy. tptacek, please be gentle in gutting me.
Edit: Thanks for that link, daniel. It is comforting to know that there is indeed some base level of security. If CALEA-compliance is achieved by adding the fed's public key to a list of destination public keys for a message, that implies you should actually be able to find out whether or not you're being monitored by simply checking for new/unknown/unexpected additions to your list of public keys. Of course, there are other methods of doing this that wouldn't be as easy to detect, e.g. maybe there is an out-of-band request for additional public keys to send to, maybe the fed's public key is already embedded in the device and is being used invisibly every time, etc. etc. etc.
Edit2: For people wondering if syncing of old iMessages between devices means iMessage doesn't work like this, I don't think that's the case. I believe that's done via iCloud (i.e. backup of previously decrypted messages), as when you add a new Apple ID to iMessages on OS X, you don't get the old messages for that account, only new ones. So it's another attack vector, but not inherent weakness in the iMessage design.