Method for encrypting voice calls in mobile communication network, and system, terminal, and network side thereof
Abstract
Disclosed is a method for encrypting voice calls in a mobile communication network, which includes: a sender establishes a call with a receiver, and after encrypting voice frames using its own Cipher Key (CK), the sender sends the voice frames to a network side; after receiving the voice frames sent from the sender, the network side decrypts the voice frames using the sender CK, encrypts the decrypted voice frames using the receiver CK and sends them to the receiver; the receiver receives the voice frames from the network side and decrypts the voice frames using its own CK. Also disclosed is a system for encrypting voice calls in a mobile communication network. The present invention effectively improves the security and confidentiality in voice communications.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 4 independent, 6 dependent
- 1权 利 要 求 书 1、 一种移动通讯网中加密语音通话的方法, 其包括: 发送方与接收方建立呼叫, 发送方使用自身的加密密钥(CK )对语音帧 进行加密后, 发送给网络侧; 网络侧接收到发送方发送的该语音帧后, 使用发送方的 CK对所述语音 帧进行解密, 使用接收方的 CK对解密后的语音帧进行加密, 发送给接收方; 以及 所述接收方从所述网络侧接收所述语音帧, 使用接收方自身的 CK对所 述语音帧进行解密。
- 22、 如权利要求 1所述的方法, 其中, 所述接收方或发送方通过如下方式获取其自身的 CK:所述接收方或发送方在呼叫建立过程中, 与所述网络侧进行交互, 获取 随机数, 结合自身安全密钥 Ki, 生成自身的 CK。
- 33、 如权利要求 1所述的方法, 其中, 所述网络侧通过如下方式获取发送 方或接收方的 CK:所述网络侧在呼叫建立过程中,归属位置寄存器或鉴权中心产生随机数, 根据所述发送方或接收方的根密钥, 结合产生的随机数, 生成发送方或接收 方的 CK, 并将所述随机数发送给发送方或接收方。
- 44、 如权利要求 1、 2或 3所述的方法, 其中, 所述发送方、 接收方和网 络侧使用硬件加密模块实现所述加密和解密。
- 55、 如权利要求 4所述的方法, 其中, 所述硬件加密模块由终端设备商和 运营商外的第三方提供。
- 66、 一种终端, 所述终端包括加密模块、 发送模块和接收模块, 其中: 所述加密模块设置为: 使用加密密钥(CK )对语音帧进行加密后, 发送 给所述发送模块; 所述发送模块设置为: 将所述语音帧发送给网络侧; 和 /或, 所述接收模块设置为: 从网络侧接收语音帧, 发送给所述加密模块; 所述加密模块设置为: 使用其 CK对所述语音帧进行解密。
- 77、 如权利要求 6所述的终端, 其中, 所述加密模块为硬件加密模块。
- 88、一种网络侧, 所述网络侧包括接收模块、发送模块和加密模块,其中: 所述接收模块设置为: 接收发送方发送的语音帧, 发送给加密模块; 所述加密模块设置为: 使用发送方的 CK对所述语音帧进行解密, 使用 接收方的 CK对解密后的语音帧进行加密, 发送给发送模块; 发送模块设置为: 将所述语音帧发送给接收方。
- 99、 如权利要求 8所述的网络侧, 其中, 所述加密模块为硬件加密模块。
- 1010、 一种移动通讯网中加密语音通话的系统, 其包括发送方、 接收方和 网络侧, 其中: 所述发送方设置为: 与所述接收方建立呼叫, 使用发送方自身的加密密 钥 (CK )对语音帧进行加密后, 发送给网络侧; 所述网络侧设置为: 接收到所述发送方发送的语音帧后, 使用发送方的 CK对所述语音帧进行解密, 使用接收方的 CK对解密后的语音帧进行加密, 发送给接收方; 所述接收方设置为: 从所述网络侧接收所述语音帧, 使用接收方自身的 CK对所述语音帧进行解密。
Independent claims10
85 paragraphs in 3 sections, as filed
Method and system for mobile communication network encrypted voice call, the terminal and the network side
TECHNICAL FIELD
The present invention belongs to the field of mobile communication, relates to a method and system for a mobile communication network in encrypted voice calls, as well as terminal and network side.
Background technique
Voice calls are mobile communication network of the most fundamental and important business, and most users and operators concerned, so its confidentiality and security of an important part of network technology is moving.
This article first voice data generation, transmission, exchange, presentation of the reception to make a few. Now the general mobile communication network speech data generated by the receiver of the mobile terminal receives the sound wave, a pulse code modulation (Pulse Code Modulation, PCM) encoded data, and then converted to the transmission network for encoding, such as wideband code division multiple access (WCDMA AMR coding) under the global mobile communications system (GSM) network was after EFR / FR, HR encoded for transmission to the network lateral switch sides exchanged AMR voice data transmission, while the other side to the network came the voice data downlink, and then after AMR decoded PCM voice data, put it into vocoder sound. As shown in Figure 1.
Mobile communication network itself has its own encryption method, in the third generation Universal Mobile Telecommunications System (3G UMTS, including WCDMA and TD-SCDMA TD-SCMDMA) system, the user's global subscriber identity module (USIM) card and the home network home location register / authentication center (HLR / AuC) share a security key Ki (128bit), based on the security key, the network can authenticate the user, the user can authenticate network between the base station and the terminal may also use Ki radio link encryption and integrity protection. But this method of encryption is to encrypt the wireless environment, the technical basis when voice data is passed to the network side, non-encrypted data, which is network monitoring. So that data security is threatened.
SUMMARY
Technical problem to be solved by the present invention is to provide a mobile communication network in encrypted voice call method And systems, terminal and network side, in order to achieve full encryption, enhanced voice communications security and confidentiality.
To solve the above problems, the present invention provides a mobile communication network in the encrypted voice calls, comprising:
The sender and receiver to enter into a call, the sender uses its own encryption key (CK) after the speech frame is encrypted and sent to the network side;
After the network side receives the voice frame sent by the sender using the sender of the speech frame CK decrypt CK using the recipient's decrypted speech frame is encrypted and sent to the recipient; the recipient from the network side receives the speech frames using the recipient's own CK for decrypting said speech frame.
The above method may have the following characteristics:
The recipient or the sender gets its own CK by:
The recipient or sender of the call setup process, interacting with the network side, to obtain a random number, with its own security key Ki, generate their own CK.
The above method may have the following characteristics:
The network side obtaining CK sender or recipient of the following ways:
The network side in the call setup process, the home location register or the authentication center generates a random number, according to the sender or recipient root key combination random number generator to generate the sender or recipient CK, and the random number will be sent to the sender or recipient.
The above method may have the following characteristics: the sender, the receiver and the network side uses the hardware encryption module for encryption and decryption.
The above method may have the following characteristics: the hardware encryption module is provided by a third-party terminal equipment manufacturers and operators outside.
The present invention also provides a terminal, the terminal includes an encryption module, transmitting and receiving means, wherein:
The encryption module is configured to: use the encryption key (CK) encrypted after speech frame, of the transmitting module; The transmission module is configured to: the voice frame is sent to the network side;
and / or,
The receiver module is configured to: receive voice frames from the network side transmits to the encryption module; the encryption module is configured to: use their CK of the speech frame decrypting.
The terminal may also have the following features, the hardware encryption module encryption module.
The present invention also provides a network side, the network side comprises a receiving module, sending module and the encryption module, wherein:
The receiver module is configured to: receiving voice frame sent by the sender, is sent to the encryption module; the encryption module is configured to: Use CK sender to decrypt the speech frames using the recipient's voice CK decrypted frame is encrypted, to the transmission module;
Sending module configured to: the voice frame is sent to the recipient.
Said network side may also have the following characteristics, the encryption module is a hardware encryption module. The present invention also provides a mobile communication network in encrypted voice systems, including the sender, recipient and the network side, wherein:
The sender is set to: the entering into receiving calls, using its own encryption key (CK) after the speech frame is encrypted and sent to the network side;
The network side is set to: after receiving the voice frame sent by the sender using the sender of the speech frame CK decrypt CK using the recipient's decrypted speech frame is encrypted and sent to the recipient ;
The receiver is configured to: receive the speech frames from the network side, using its own CK to decrypt the speech frame.
At present, the relevant patent or program-end voice encryption and decryption are not required to participate in the network, you can not take advantage of network security key or other key Ki Ki generated as the cipher key (CK) and other encryption and decryption operation and the need to pass both the communication key. The present invention is implemented in a mobile terminal and the core network switching unit configured encryption module encryption and decryption methods uplink and downlink voice data. The present invention utilizes CK voice in real-time hardware encryption does not need to pass both a key communication, such Encryption can not monitor voice calls on the network side, and the transmission in a wireless environment is equivalent to double encryption, more privacy and security. Even if the party won the eavesdropping party may be eavesdropping security key Ki, can not eavesdrop on the wireless transmission environment. The present invention the encryption factor CK is different each time, only valid in this call, more big crack difficulty from the wireless transmission environment. The present invention is applicable to sensitive government departments, intelligence agencies, and so attaches great importance to the security and confidentiality of organizations and individuals.
BRIEF DESCRIPTION
Figure 1 is a schematic view of the transmission of voice data communications network;
Figure 2 is a schematic diagram of the present invention to encrypt voice communications network for data transmission;
Figure 3 is a voice data transmitting terminal of the present invention, the encryption process inside interaction diagrams to show the implementation process; Figure 4 is a network of the present invention, the encrypted voice processing flow diagram to show the implementation process; Fig. 5 is a voice data receiving terminal of the present invention, the decryption process internal interaction diagrams to show the implementation process.
Preferred embodiments of the present invention
Implementation and mobile network of the present invention itself has nothing to do encryption, is superimposed on the network itself is encrypted, another layer of encryption, the core idea is: through the mobile terminal and the core network switching unit configured encryption module, to achieve a voice call encryption, among them, the CK-based encryption module as a factor on the mobile communication network operator voice data encryption.
In the present invention, for convenience of description, the following standard WCDMA AMR voice data frame encryption and decryption process is exemplified description. But the method of the present invention should be in other formats GSM, CDMA, also apply.
Encryption factors preclude the use of CK (Cipher Key encryption key) using RAND (random number) and the user's root key Ki is calculated based on the A3 algorithm, CK = A3 (RAND, Ki). The RAND voice during a call will be different each time, it means that the call set-up encryption factor will change each voice call. For each user, we have a Ki, while the network reserved for this user Ki, Ki is due to the network (in fact, the network element HLR / AUC) and the terminal share, RAND is a network-side transmitting terminal each time a voice call, Therefore CK is a particular terminal and network shared. As root key Ki mobile communications networks, with a very high privacy and security. Since Ki privacy Randomness and RAND parameters, CK having a cryptographic operation factor advantages.
Encryption scheme of the present invention as illustrated in Figure 2, the encryption module is added in the terminal, it can be a digital signal processor, or other similar function devices may also be based on software, both encryption and decryption functions, for convenience, same network side and terminal encryption module operation rules, which preclude the use of a specific encryption algorithm is not part of the present invention, for convenience of description, we may be called X algorithm. Which preclude the use of hardware encryption module, then voice data is only true in the short-lived encryption module, the communication networks of other network elements, only the encrypted data, better security effect, as shown in FIG. The encryption module may be provided by a third-party embedded terminal and network equipment, is responsible for voice and data encryption and decryption operations. Even though the network, terminal equipment manufacturers and operators are unable to eavesdrop on encrypted voice calls.
The present invention provides a mobile communication network in encrypted voice calls, comprising:
The sender and receiver to enter into a call, the sender uses its own encryption key (CK) after the speech frame is encrypted and sent to the network side;
After the network side receives the voice frame sent by the sender using the sender of the speech frame CK decrypt CK using the recipient's decrypted speech frame is encrypted and sent to the recipient; the recipient from the network side receives the speech frame, for the use of their CK decrypted speech frame.
The present invention is in the production end of the speech data by adding the following links, as shown in Figure 2:
Before transmission to the network, AMR voice packets into the sender's encryption operation cryptographic modules do X, operational factors preclude the use of encryption to send side CK, whereby encryption AMR speech frame and upload network encryption AMR speech frame.
This encrypted voice network side frame, the sender CK, CK recipient encryption module into the network side, the network side encryption module uses X algorithm to the sender CK factor for the operation of the voice decrypt the data, then use X Algorithm to the recipient CK factor for the operation of the voice data is encrypted, and returns the operation result to the network device, network device then this encrypted voice frame sent to the receiver terminal.
Recipient after obtaining downlink voice data, this encryption of voice and data into the plus terminal CK Calculation module decrypts ciphertext X, thereby obtaining the ordinary speech frame, and the next on the same normal voice call processing, AMR voice data is decrypted into the DSP PCM data obtained, the PCM sound data into the vocoder.
Below with reference to the implementation of technical solutions described in further detail for. The proposed invention requires implementation of the terminal and the network are embedded in the encryption module, the encryption module is divided into a terminal, a network of two parts, but identical notation.
Implementation processes, voice encryption implementation process is divided into three parts:
The first stage: transmitting section
As shown in Figure 3, it occurs in the sender terminal.
1. In the voice call set-up phase, RAND predetermined by 3GPP, the sender will receive a terminal and network signaling interaction, with its own Ki, by A3 algorithm to produce currently valid CK, this is standard procedure. CK terminal needs to be passed to the encryption module, so the sender terminal encryption module gained the encryption factor CK.
2. After the call is established, the speech from the sender terminal into the receiver, the first digitized speech data sampling, quantization, encoded into PCM (Pulse Code Modulation, Pulse Code Modulation).
3. PCM input to the transmission side terminal voice DSP (digital signal processor) for processing to obtain suitable for network transmission of AMR encoding format.
4. The sender terminal will be encrypted AMR speech frame is sent to the encryption module, encryption module to use encryption factor CK speech frame X cryptographic operations, and returned to the sender terminal encrypted AMR speech frame.
5. sender terminal software part of the network protocol stack AMR speech frames transmitted encrypted to the network side.
6. encrypted voice call, repeat steps 2-5, will each AMR speech frame is encrypted and sent to the network side in turn, realize the whole process of voice call encryption.
The second stage: part exchange As Figure 4 shows, when the network side of the switching unit MSC.
1. Network side in setting up a call signaling process, AUC / HLR generates RAND, CK generated based on RAND and Ki. Interactions in the signaling network side also sends RAND to the terminal (including the caller and the called party). Specifically, the network side in the call setup process, the sender terminal or a receiver terminal, do the following: AUC / HLR generates random numbers based on the sender or recipient root key combination randomly generated number generated CK sender or receiver side and the random number is sent to the sender or recipient.
2. After the call is established, the network side from the upstream channel receives the encrypted AMR speech frame sender, the encrypted frames and AMR voice call both CK transmitted to the network side encryption module.
3. The network side encryption module uses the CK sender as the decryption factor, X-decryption operations to obtain non-encrypted AMR speech frame, then immediately use this speech frame CK recipient encryption factor X as encryption algorithms, and AMR speech frame encrypted back to the switching equipment MSC network side.
AMR voice encryption on 4. MSC will get one step frame is sent to the recipient via the downstream channel.
5. repeat 2-4, encrypted AMR speech frames sequentially transmitted to the receiving party.
The third stage: the receiving section
As shown in Fig. 5, it occurs in the receiver terminal. DSP receiver terminal in the AMR speech frame decoding to PCM, and then revert to PCM voice signals into the loudspeaker.
1. In the voice call set-up phase, RAND predetermined by 3GPP, the terminal will be obtained and the network signaling interaction, with its own Ki, by A3 algorithm to produce currently valid CK, this is standard procedure. It needs to be passed to the recipient terminal CK cryptographic module, so the receiving terminal to decrypt the encryption module obtains factor CK.
2. After the call is established, the receiving terminal to the network side in the downlink channel transmitted encrypted
AMR speech frame;
3. The recipient of this terminal encrypted AMR speech frame is sent to the encryption module, an encryption module for encrypting AMR speech frame X decryption operations, and returns to the receiver terminal. 4. A receiver terminal 4 bar unencrypted AMR speech frame input to the receiving party's voice terminal DSP (digital signal processor) for processing, to obtain PCM voice data.
5. the receiving terminal PCM voice data into the vocoder sound.
6. encrypted voice call, repeat steps 2-5, will each AMR speech frame decrypting, and in turn sent to the vocoder playback, realize the whole call voice decryption.
The present invention also provides a terminal, the terminal includes an encryption module, transmitting and receiving means, wherein:
The encryption module for using the encryption key (CK) after the speech frame is encrypted and sent to the sending module;
The means for transmitting the voice frame is sent to the network side;
and / or,
The receiving module for receiving voice frames from the network side, transmitted to the encryption module; the encryption module, for which the use of the CK decrypted speech frame.
The present invention also provides a network side, the network side comprises a receiving module, sending module and the encryption module, wherein:
The receiving module for receiving speech frames sent by the sender, is sent to the encryption module; the encryption module, for use on the sender CK speech frame is decrypted using the recipient's voice CK decrypted frame is encrypted, to the transmission module;
Means for transmitting the voice frame is sent to the recipient.
The present invention also provides a mobile communication network in encrypted voice systems, including the sender, recipient and the network side, wherein:
The sender for: to enter into a call with the receiver, uses its own encryption key (CK) after the speech frame is encrypted and sent to the network side; The network side for: the received speech frame sent by the sender, the sender's use of the speech frame CK decrypted using CK recipient's decrypted speech frame is encrypted and sent to the recipient ;
The recipient for: receiving the speech frame from the network side, using its own CK of the speech frame decrypting.
Although for the illustrative purposes of the present invention have been disclosed preferred embodiments, those skilled in the art will appreciate that various modifications, additions and substitutions are possible, and therefore, the scope of the invention should not be limited to the embodiments described above.
Those of ordinary skill in the above-described method will be appreciated that all or part of the steps by a program instructing relevant hardware, the program may be stored in a computer-readable storage medium, such as read only memory, magnetic or optical disk. Alternatively, all or part of the steps of the above-described embodiments may have one or more integrated circuits. Accordingly, the above-described embodiment, each module / unit may preclude the use of hardware in the form of realization can also preclude the use of the form of software function module. The present invention is not limited to any particular form of combination of hardware and software.
Industrial Applicability
The present invention utilizes CK voice in real-time hardware encryption, and because the parties do not know each other's calls CK, so they need to participate in the network, and does not require the parties to pass key communications, more secure and reliable. Another Xi Bu, the present invention is encrypted factor CK is different each time, only valid in this call, more big crack difficulty from the wireless transmission environment. The present invention is applicable to sensitive government departments, intelligence agencies, and so attaches great importance to the security and confidentiality of organizations and individuals.
Contents3
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| US10649717B2 | Cited by | United States of America | – | Applicant |
| US10251055B2 | Cited by | United States of America | – | Applicant |
| US10715557B2 | Cited by | United States of America | – | Applicant |
| US10356059B2 | Cited by | United States of America | – | Applicant |
| CN113206737A | Cited by | China | – | Search report |
| US11606398B2 | Cited by | United States of America | – | Applicant |
| CN105722069A | Cited by | China | – | Search report |
| US9891882B2 | Cited by | United States of America | – | Applicant |
| US9900769B2 | Cited by | United States of America | – | Applicant |
| US10122767B2 | Cited by | United States of America | – | Applicant |
| CN101340433A | Cites | China | A | International search |
| CN1249636A | Cites | China | A | International search |
| CN1283063A | Cites | China | X | International search |
| US2008031275A1 | Cites | United States of America | X | International search |
2 members in 2 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 201010265260 | China | A | |
| 201010265260 | China | A | |
| 2010102652603 | – | – | – |
| CN20101265260 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| CN101951601A | China | A | |
| WO2012024903A1This record | World Intellectual Property Organization (WIPO) | A1 |
3 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Ep: pct application non-entry in european phase122 | 122 | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO |
Numbers
- Publication
- 2012/024903
- Publication, DOCDB
- 2012024903
- Publication, EPODOC
- WO2012024903
- Application
- 70232
- Application, DOCDB
- 2011070232
- Application, EPODOC
- WO2011CN70232
Titles2
- English
- METHOD FOR ENCRYPTING VOICE CALLS IN MOBILE COMMUNICATION NETWORK, AND SYSTEM, TERMINAL, AND NETWORK SIDE THEREOF
- French
- PROCÉDÉ DE CHIFFREMENT D'APPELS VOCAUX DANS UN RÉSEAU DE COMMUNICATION MOBILE, ET SYSTÈME, TERMINAL ET CÔTÉ RÉSEAU QUI LUI SONT ASSOCIÉS
Classification
- CPC, 2
- H04L63/0464
- H04W12/033
- IPC, 4
- H04W12 02
- H04W12 033
- H04W12 041
- H04W12 0431
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo