Mobile communication system and voice call encryption method thereof
Abstract
Disclosed are a mobile communication system and a voice call encryption method in the mobile communication system, belonging to the technical field of mobile communications. In the mobile communication system, a calling terminal generates a voice key for voice encryption/decryption, and after encrypting the voice key by using a shared key factor of the calling terminal, sends the encrypted voice key to a network side; the network side decrypts the encrypted voice key according to the shared key factor shared by the calling terminal, and after encrypting the voice key by using the shared key factor shared by a called terminal, sends the encrypted voice key to the called terminal; the called terminal decrypts the encrypted voice key by using the shared key factor of the called terminal to obtain the voice key. The calling terminal and the called terminal utilize the voice key to perform the encrypted voice call. The present invention enables the encrypted transmission of the voice key used by the voice communication, and thereby the calling and called parties can utilize the shared voice key to perform safer voice calls.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 3 independent, 7 dependent
- 1权 利 要 求 书 1、 一种移动通信系统中语音通话加密的方法, 包括: 主叫终端生成用于语音加密和解密的语音密钥, 利用所述主叫终端的共 享密钥因子对该语音密钥进行加密后发送给网络侧; 所述网络侧根据共享的所述主叫终端的共享密钥因子对加密后的语音密 钥进行解密, 再利用共享的被叫终端的共享密钥因子对所述语音密钥进行加 密后发送给所述被叫终端; 所述被叫终端利用所述被叫终端的共享密钥因子对加密后的语音密钥进 行解密, 获取所述语音密钥; 所述主叫终端和所述被叫终端在语音通话时, 利用语音密钥对发送的语 音数据进行加密, 对接收的语音数据进行解密, 所述主叫终端和所述被叫终 端实现加密语音通话。
- 22、 如权利要求 1所述的方法, 其还包括: 主叫终端和网络侧在呼叫验证阶段根据 A3 算法由随机数和主叫终端用 户的才艮密钥 Ki计算得到所述主叫终端的共享密钥因子; 被叫终端和网络侧在呼叫验证阶段根据 A3 算法由随机数和被动终端用 户的才艮密钥 Ki计算得到所述被叫终端的共享密钥因子。
- 33、 如权利要求 1所述的方法, 其还包括: 主叫终端在每次通话时按照一定算法随机生成所述用于语音加密 /解密 的语音密钥。
- 44、 如权利要求 1所述的方法, 其中, 所述语音密钥在经共享密钥因子加密后是通过主叫终端与网络侧之间的 呼叫建立消息以及网络侧与被叫终端之间的呼叫建立消息进行传输的。
- 55、 一种移动通信系统, 包括: 移动终端, 核心网交换单元, 其中, 所述 移动终端包括加解密模块, 所述核心网交换单元包括网络加解密模块, 其中: 所述加解密模块, 设置成在所述移动终端作为主叫移动终端时生成用于 语音数据加密 /解密的语音密钥, 利用所述移动终端的共享密钥因子对所述语 音密钥加密后发送给所述核心网交换单元; 还设置成在移动终端作为被叫移 动终端时, 从所述核心网交换单元获取利用所述移动终端的共享密钥因子加 密的语音密钥, 并利用所述共享密钥因子解密获取主叫生成的语音密钥; 所述网络加解密模块, 设置成利用所述主叫移动终端的共享密钥因子对 所述主叫移动终端加密后的语音密钥进行解密, 再利用所述被叫移动终端的 共享密钥因子对所述语音密钥进行加密后发送至所述被叫移动终端。
- 66、 如权利要求 5所述的移动通信系统, 其中, 所述移动终端的所述加解密模块和所述核心网交换单元的所述网络加解 密模块还设置成在呼叫验证阶段根据 A3 算法由随机数和移动终端用户的根 密钥 Ki计算得到所述移动终端的共享密钥因子。
- 77、 如权利要求 5所述的移动通信系统, 其中, 所述移动终端的加解密模块还设置成在所述移动终端作为主叫移动终端 的每次通话时按照一定算法随机生成所述用于语音加密 /解密的语音密钥。
- 88、 如权利要求 5所述的移动通信系统, 其中, 所述移动终端是设置成在与核心网交换单元之间的呼叫建立消息中携带 加密后的语音密钥。
- 99、 一种移动终端, 包括加解密模块, 所述加解密模块, 设置成在移动终端作为主叫移动终端时生成用于语音 数据加密 /解密的语音密钥, 利用所述移动终端的共享密钥因子对所述语音密 钥加密后发送给核心网交换单元; 还设置成在所述移动终端作为被叫移动终 端时, 从所述核心网交换单元获取共享密钥因子加密后的语音密钥, 利用所 述共享密钥因子获取所述语音密钥。
- 1010、 如权利要求 9所述的移动终端, 其中, 所述加解密模块还设置成按照与网络侧相同的方式, 根据 A3 算法由随 机数和移动终端用户的根密钥 Ki计算得到所述移动终端的共享密钥因子; 所述移动终端的加解密模块还设置成在所述移动终端作为主叫移动终端 的每次通话时按照一定算法随机生成所述用于语音加密 /解密的语音密钥。
Independent claims10
58 paragraphs in 2 sections, as filed
A mobile communication system and method for voice encryption
TECHNICAL FIELD
The present invention relates to the technical field of mobile communications, particularly to a system and method for a mobile communication system, a mobile communication port force encrypted voice call.
Background technique
Voice services as a basic business mobile communications network, its security and confidentiality has always been of concern, how to improve the security of a call and privacy protection is one of the important research of mobile network technology. Mobile networks generally have their own communication encryption method, for example,
UMTS (Universal Mobile Communication System, Universal Mobile Telecommunications System) system, the user's USIM (Universal Subscriber Identity Module, the global subscriber identification card) HLR cards and home network / AuC (home position memory / Authentication Center) share a secret root key Ki (128bit), based on the root key Ki, the mobile terminal and the network can be a two-way authentication between the base station and the mobile terminal may also utilize radio link root key Ki encrypted and integrity protected. But this method of encryption is to encrypt the wireless environment, voice data is transmitted in clear text across the network.
There are already a lot of technologies and solutions for based on CS (Circuit Switch, circuit switched) domain voice calls were force. Secret protection. For example, to pass through a DTMF (Dual Tone Multi Frequency, Dual Tone Multi-Frequency) key index, stored on the mobile terminal by a fixed key to encrypt data; use SMS to achieve key negotiation and delivery, and then using the generated keys for secure communication and so on. From the technical features, the use of a fixed key security is relatively poor; using SMS key negotiation, less efficient. To sum up, the existing encryption schemes, there are some shortcomings and deficiencies.
SUMMARY
The technical problem to be solved is to provide a mobile communication system and a mobile communication system for voice encryption method, and the mobile communication system a mobile terminal, for solving the existing voice encryption security presence poor, low efficiency problem, reliable encrypted voice calls. To solve the above problems, the present invention proposes a mobile communication system voice encryption method, comprising:
The calling terminal for generating speech voice encryption and decryption keys, is sent to the network side after the use of the calling terminal shared key encrypting key factor of the voice;
Sent to the called shared key factor after the network side based on the shared key factor of the calling terminal shared for encrypted voice key for decryption, re-use of the called terminal to share the voice key for encryption terminal;
Called terminal utilizing called terminal shared key factor for encrypted voice key for decryption, obtains the voice key;
The calling terminal and the called terminal during a voice call using the voice key for voice data transmission is encrypted, the received voice data to decrypt the calling terminal and the called terminal for encryption of voice calls.
The calling terminal and the network side call verification stage to obtain a shared key factor of the calling terminal A3 algorithm based on the random number and the calling end users only Gen key Ki;
Called terminal and the network side call validation phase A3 algorithm based on the random number and the passive end-users to get key Ki Gen shared key factor of the called terminal.
The calling terminal at each call according to a certain algorithm for generating the random voice encryption / decryption key voice.
Voice key factor shared key encryption after establishing the call message and the network side and the called terminal via the call between the calling between the terminal and the network side establishing message transmission.
The present invention also provides a mobile communication system, comprising: a mobile terminal, the core network switching unit, characterized in that said mobile terminal comprises encryption and decryption modules, the network includes a core network switching element encryption and decryption modules, wherein:
The encryption and decryption module, the speech key is provided in the mobile terminal as a calling mobile terminal for generating speech data encryption / decryption using the shared key factor for the mobile terminal after the voice encryption key is sent to the core network switching unit; when arranged in the mobile terminal as a called mobile terminal, switching from the core network using a mobile terminal unit acquires shared key factor voice encryption key, and use of shared Get decryption key factor generated voice calling keys;
The network encryption and decryption module arranged to use the calling mobile terminal shared key factor for the calling mobile terminal encrypted voice key to decrypt, re-use shared key factor called mobile terminal of the voice key sent encrypted to the called mobile terminal.
The mobile network encryption and decryption encryption and decryption module and the terminal module core network switching unit is in the call validation phase obtained shared key factor of the mobile terminal calculated by the root key Ki and random number algorithm mobile terminal user according to A3 .
The encryption and decryption modules of mobile terminals, as the calling mobile terminal is a mobile terminal during a call algorithmically generated randomly for each of the voice encryption / decryption key voice.
The mobile terminal and the core network using switched call is established between the unit encrypted message carries the voice key.
The present invention also provides a mobile terminal, including encryption and decryption modules, the encryption and decryption module, the speech key is provided in the mobile terminal as a calling mobile terminal for generating speech data encryption / decryption using the shared key of the mobile terminal factors that are sent to the core network switching unit after the speech encryption key; when arranged in the mobile terminal as a called mobile terminal unit acquires shared key factor encrypted key from the core network to exchange voice, using the shared secret Get key factor voice key.
The encryption and decryption module is further arranged according to the same manner as the network side, according to the shared key factor A3 algorithm of the mobile terminal calculated by the root key Ki and random number of the mobile terminal user; the encryption and decryption of the mobile terminal modules, arranged in a mobile terminal as a calling mobile terminal is generated randomly each time the encryption for the voice call algorithmically / decryption key voice.
In summary, the present invention in a mobile terminal and network add the appropriate hardware and software, mobile terminal and the network share CK (Cipher Key encryption key) to complete the final voice when voice communication using the key Kr encrypted transmission, so that the user can take advantage of both sides shared between voice key Kr a more secure voice calls. BRIEF DESCRIPTION Figure 1 is a schematic flow diagram of the mobile communication system transmitting an embodiment of the present invention, there is provided a speech key Kr; and
Figure 2 is a schematic view of the network structure of the present embodiment of the invention, there is provided a mobile communication system.
Preferred embodiments of the present invention
For the purpose, technical solutions, and advantages of the present invention will become apparent below in conjunction with the accompanying drawings of the present invention will be further described in detail.
Mobile communication system, voice calls are encrypted to protect the security aspect of the existence of poor, low efficiency, the mobile communication system according to the present invention there is provided a communication system and a mobile voice call encryption method by voice calling terminal generates the encryption / decryption key voice Kr, by the network side and the mobile terminal using a shared key factors CK (cipher key encryption key) for establishing a call between a voice transmitted ciphertext message Kr key for encryption and decryption, are obtained in order to achieve between the calling terminal and the called terminal for voice calls shared encryption / decryption key voice Kr, both using the speech encryption key Kr voice calls.
The key factor CK shared by the mobile communication network can root key Ki and random number RAND according to some key algorithm to obtain, since the root key Ki has a very high confidentiality and security, making use of the shared key factor CK encrypted transfer key Kr also has speech ^ high safety and confidentiality, can participate in the network using shared key factor CK complete voice key Kr transfer work.
The shared key factor CK may be a mobile terminal and the network side call validation phase according to A3 algorithm calculated by the random number RAND and the mobile end user root key Ki. Each mobile terminal and the network side are shared have shared key factor CK.
In the voice data transfer phase, since the calling and called mobile terminals have been given the voice key Kr, can be accomplished by adding an encryption and decryption module of the mobile terminal sending a voice call reception and decryption, the process is completely independent of the network, That voice communication process, simply send and receive double voice encryption and decryption operations without further network-side encryption and decryption process.
The mobile communication system according to the present invention there is provided a voice call encryption method, comprising: generating set to the calling terminal voice encryption / decryption key Kr, with call validation phase generated Shared key factor CK<sub>A</sub>Encrypts the key Kr, the voice key Kr encrypted write call setup message sent to the network side;
The network side according to the shared key factor CK call validation phase<sub>A</sub>Kr voice key to decrypt the encrypted using a shared key factor called terminal CK<sub>B</sub>After the speech written for encryption key Kr call setup message sent to the called terminal;
Called terminal, with call validation phase generated shared key factor CK<sub>B</sub>Kr voice key to decrypt the encrypted obtaining the voice key Kr;
Between the calling terminal and the called terminal by the voice key Kr for encryption / decryption operations on voice data, voice data transmission is encrypted, the received speech data to decrypt the encrypted voice calls.
The calling terminal and the called terminal may be a mobile terminal, a mobile station, or may be a fixed station, or other fixed communication terminals.
The shared key factor of the calling terminal CK<sub>A</sub>Is the calling terminal and the network side call validation phase according to A3 algorithm calculated by the random number RAND and the calling end-user root key Ki. The shared key factor of the called terminal CK<sub>B</sub>It is called terminal and the network side call validation phase according to A3 algorithm calculated by the random number RAND and passive end-user root key Ki.
The voice key for voice Kr encryption / decryption is made as the calling terminal according to a certain algorithm randomly generated at each call. The call setup message for carrying the encrypted key Kr fields are the Third Generation Partnership Project 3GPP specifications call setup message (SETUP) of the User-user field.
A mobile communication system of the present invention, comprising: a mobile terminal, the core network switching unit, the encryption module comprises a mobile terminal, the network includes a core network switching element encryption and decryption modules, wherein: the encryption and decryption modules arranged when the speech key Kr is generated as the calling mobile terminal for voice data encryption / decryption using the shared key factor of the mobile terminal CK<sub>A</sub>Said voice encryption key Kr written after the call setup message sent to the core network switching unit; arranged in the mobile terminal as a called terminal unit obtains the call set-up message from the core network switching, the mobile terminal using a shared key factor CK<sub>B</sub>Key Kr voice call setup message encrypted decrypt Get voice key Kr; After the network encryption and decryption module arranged to receive the call setup message from the calling mobile terminal, using a shared key factor calling mobile terminal CK<sub>A</sub>Wherein the speech encryption key Kr decrypts, shared key reuse factor called mobile terminal CK<sub>B</sub>After the voice key Kr is encrypted, the core voice network switching unit writes the encrypted key Kr call setup message transmitted to the called mobile terminal.
1, showing an embodiment of the present invention, the voice key Kr transfer process, comprising the steps of:
S101: A mobile terminal call mode selection, you can choose to encrypt a call or ordinary call;
S102: If you choose a general call, the call press for ordinary normal processes;
S103: If you choose to encrypt the call, the mobile terminal A initiates the call is encrypted mobile terminal B, the mobile terminal A is used to generate the encryption key Kr voice data through their own voice encryption and decryption modules, UUS add a field (SETUP) message in the call set-up a mobile terminal using a shared key factor CK<sub>A</sub> Encrypt voice key Kr; the shared key factor CK<sub>A</sub>In the validation phase is to generate a call, the mobile terminal A is shared with the network side key.
S104: After receiving the SETUP message network side, according to the UUS field to determine whether the call is encrypted, and if you turn S105, and if not, press the normal flow of the call will be ordinary;
S105: For encrypted calls, the network side using a shared key factor calling terminal CK<sub>A</sub>Decrypt the voice key Kr, and then using a shared key factor mobile terminal B CK<sub>B</sub>Again voice key Kr is encrypted by voice UUS field of the SETUP message encrypted key Kr is transmitted to the mobile terminal B;
S106: The mobile terminal B determines whether to encrypt a call, if not, the normal flow of the call was an ordinary press;
S107: If the judgment is encrypted call, the mobile terminal B ciphertext removed from the SETUP message; encryption and decryption modules using a shared key factor mobile terminal B CK<sub>B</sub>From the ciphertext to decrypt the voice key Kr, and as a follow-up voice data encryption and decryption of voice key; the shared key factor called terminal CK<sub>B</sub>In the validation phase is to generate a call, the mobile terminal B is shared with the network side key.
Between the mobile terminal A and mobile terminal B via voice key Kr, the encryption and decryption modules for voice data encryption and decryption operations to realize the voice data transmission is encrypted, the received data into voice Decrypt, encrypt voice calls, no network involved in the follow-up process.
In the above method, the shared key factor CK (Cipher Key Encryption Key), which consists of a random number RAND and the user's key Ki is calculated based on the A3 algorithm (algorithm authentication), CK = A3 (RAND, Ki). When the random number RAND each voice call will be different, which means that the call to establish a shared key factor CK will change the course of each voice call. Because the root key Ki is a network (a network element actually HLR / AUC) and the terminal shared random number RAND is sent to the network terminal side of each voice call, so the terminal to generate a shared key factor is the network and terminal CK shared.
The key Kr voice call randomly generated each time according to a certain algorithm, which generates a specific algorithm and shared as an encryption algorithm key factor CK factor Kr encrypted, there are many related algorithms to choose from, not here do narrative.
As shown, a schematic view of an embodiment of the present invention there is provided a mobile communication system, the mobile terminal 2 adds encryption and decryption modules 201 and 202, the network side increases network encryption and decryption module 203, the mobile terminal A of encryption and decryption module 201 generates voice data used to complete the encryption / decryption key voice Kr; obtaining a shared key factor from the USIM card CK; fill factor through shared key CK encrypted voice key Kr UUS field in the SETUP message ; using voice key Kr complete voice and data encryption and decryption operations.
Mobile terminal B encryption and decryption module 202, configured to remove from the SETUP message UUS field after CK encrypted voice key Kr; use CK decrypted from the ciphertext voice key Kr; using voice key Kr complete voice and data encryption and decryption operating.
Increased network side network encryption and decryption module 203, configured to remove the voice encryption key Kr from an origin mobile terminal A SETUP message UUS field after; shared key factor using the initiator of CK decrypt; for the use of mobile receiving end shared key factor in the CK terminal B is encrypted; the voice key Kr encrypted on the SETUP message sent to the receiving end in the UUS field.
The encryption and decryption modules 203 to increase the network in the core network switching unit, the switching unit may be the core network a mobile switching center.
The mobile communication system and voice call encryption method of the present invention, by configuring the hardware encryption module on the mobile terminal and the core network switching unit for CK (Cipher Key key) The key is encrypted voice call, the caller end of the complete core network for voice calls by switching unit and a called terminal Voice key negotiation, the final completion of the voice data is encrypted transparently transmitted over the network.
Embodiments of the present invention described above is only only, not intended to limit the present invention, the skilled in the art, the present invention may have various changes and variations. Any modification within the spirit and principles of the present invention, made, equivalent replacement, or improvement should be included within the scope of the claims of the present invention requires.
Industrial Applicability The present invention provides a mobile communication system and a mobile communication system for voice encryption method, and the mobile communication system a mobile terminal to solve the poor security, the problem of low efficiency of conventional voice encryption exist , reliable encryption of voice calls.
The present invention is to add the appropriate hardware and software in the mobile terminal and the network through a mobile terminal and the network share CK (Cipher Key encryption key) to complete the transmission of voice encryption key Kr ultimate voice communications when used so that the user between the two sides can use a shared key Kr voice a more secure voice calls. Accordingly, the present invention has industrial applicability.
Contents2
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| CN114900500A | Cited by | China | – | Search report |
| KR20170077588A | Cited by | Republic of Korea | – | Search report |
| CN101309281A | Cites | China | A | International search |
| CN101790160A | Cites | China | X | International search |
| CN101917711A | Cites | China | XP | International search |
3 members in 2 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 201010265283 | China | A | |
| 201010265283 | China | A | |
| 2010102652834 | – | – | – |
| CN20101265283 | – | – | – |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| CN101917711A | China | A | |
| WO2012024906A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| CN101917711B | China | B |
3 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Ep: pct application non-entry in european phase122 | 122 | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO |
Numbers
- Publication
- 2012/024906
- Publication, DOCDB
- 2012024906
- Publication, EPODOC
- WO2012024906
- Application
- 70400
- Application, DOCDB
- 2011070400
- Application, EPODOC
- WO2011CN70400
Titles2
- English
- MOBILE COMMUNICATION SYSTEM AND VOICE CALL ENCRYPTION METHOD THEREOF
- French
- SYSTÈME DE COMMUNICATION MOBILE ET PROCÉDÉ DE CHIFFREMENT D'APPELS VOCAUX ASSOCIÉ
Classification
- CPC, 3
- H04W12/04
- H04L2463/062
- H04W12/033
- IPC, 3
- H04W12 02
- H04W12 033
- H04W12 0431
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo