A method, system and device for preventing eavesdropping applied to a hotel telephone
By monitoring key updates and current noise data in real time, and dynamically calculating link risk and security threat indices, the problem of incomplete encryption coverage in hotel telephone systems is solved, achieving precise and real-time anti-eavesdropping protection for hotel telephone communications.
Patent Information
- Application Number
- CN202511350489.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-09-22
AI Technical Summary
Traditional hotel telephone systems suffer from incomplete encryption coverage, protecting only the connection between the telephone and the hotel's internal server. The connection between the hotel's internal server and the external PSTN gateway remains unencrypted, reducing the system's ability to prevent eavesdropping.
By acquiring key update timestamps, current data, and environmental noise data during hotel telephone calls in real time, the irregularity of key updates and the correlation between current noise are analyzed. The link risk index and security threat index are calculated, and anti-eavesdropping protection strategies are dynamically adjusted, including quantum key encryption and physically cutting off microphone power, as well as switching to backup fiber optic channels and virtual secure tunnel technology.
It enables accurate and real-time security assessment of hotel telephone communications, timely identification of sudden man-in-the-middle attacks, improves overall anti-eavesdropping protection capabilities, and makes up for the shortcomings of traditional encryption that only covers the first hop.
Smart Images

Figure CN120856825B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of anti-eavesdropping protection technology for hotel telephones, specifically to anti-eavesdropping protection methods, systems, and devices applied to hotel telephones. Background Technology
[0002] Hotels, as places with frequent personnel flow and highly sensitive information, often involve telephone communications involving personal identity, financial information, business secrets, and even private conversations. Traditional analog telephone systems and early digital systems have inherent vulnerabilities, making calls susceptible to unauthorized eavesdropping. Therefore, anti-eavesdropping technologies have emerged. In hotel telephone systems, the core of network attacks and man-in-the-middle threats lies in attackers' intrusion into the hotel's telephone network. They can use ARP spoofing, DNS hijacking, or deploy unauthorized gateways to insert themselves as "man-in-the-middles," intercepting VoIP packets and attempting to decrypt or eavesdrop on call content.
[0003] The current mainstream solution is to enforce TLS / SRTP encryption and certificate authentication. This involves using TLS to encrypt the SIP signaling channel to ensure the security of the call setup process, combining this with SRTP protocol to encrypt the voice stream with a dynamic key, and employing two-way certificate authentication to verify the authenticity of the communication parties and prevent spoofing attacks. However, this current mainstream solution has the problem of incomplete encryption coverage. The solution only protects the hop from the telephone to the hotel's internal server, while the connection between the hotel's internal server and the external PSTN gateway is usually not encrypted, reducing the anti-eavesdropping protection capability of the hotel telephone calls. Summary of the Invention
[0004] In a first aspect, embodiments of this application provide an anti-eavesdropping protection method for hotel telephones, the method comprising the following steps:
[0005] Real-time acquisition of key update timestamps, current data, and environmental noise data during hotel telephone calls;
[0006] By analyzing the degree of disorder of all key update timestamps within a preset time period before each time, the key update irregularity at each time is determined; by analyzing the correlation between current data and environmental noise data at all times within a preset time period before each time, the current noise correlation at each time is determined; and combined with the key update irregularity, the link risk index of hotel telephone communication at each time is determined.
[0007] Based on the smoothness of all link risk indices within a preset time period before each time, the link risk benchmark value at each time is determined; by analyzing the abnormal situation of the deviation between all link risk indices and the link risk benchmark value within a preset time period before each time, the security anomaly degree at each time is determined, and combined with the link risk benchmark value, the security threat index of hotel telephone communication at each time is determined.
[0008] Based on the current security threat index of hotel telephone communication, anti-eavesdropping protection is implemented for hotel telephone communication at the current moment.
[0009] Preferably, the key update irregularity at each time point is the information entropy of all key update timestamps within a preset time period prior to each time point.
[0010] Preferably, the current noise correlation at each time point is the correlation coefficient between the current data and the environmental noise data at all times within a preset time period prior to each time point.
[0011] Preferably, the expression for the link risk index of hotel telephone communication at each time point is: In the formula, This represents the link risk index of hotel communication at time i. Indicates the irregularity of key updates at time i; This indicates the correlation between current and noise at time i; represents the preset threshold; exp() represents the exponential function with the natural constant as the base; max() represents the maximum value function.
[0012] Preferably, the link risk benchmark value at each time point is a smoothed value obtained by applying a smoothing algorithm to all link risk indices within a preset time period prior to each time point.
[0013] Preferably, the security anomaly degree at each time point is an anomaly score obtained by using an anomaly detection algorithm to measure the deviation between all link risk indices and link risk benchmark values within a preset time period prior to each time point.
[0014] Preferably, the expression for the security threat index of hotel telephone communication at each time point is: In the formula, This represents the security threat index at time i; Indicates the safety anomaly degree at time i; represents the baseline value of link risk at time i; norm() represents the normalization function.
[0015] Preferably, the method of protecting hotel telephone communications from eavesdropping at the current moment includes:
[0016] If the security threat index of the hotel telephone communication at the current moment is less than or equal to the preset first value, then the TLS / SRTP encryption between the hotel telephone and the hotel's SIP proxy server will be maintained.
[0017] If the security threat index of the hotel telephone communication at the current moment is between the preset first value and the preset second value, then quantum key encryption will be automatically enabled and the power supply to the telephone microphone will be physically cut off. The preset first value is less than the preset second value.
[0018] If the security threat index at the current moment is greater than the preset second value, the hotel telephone will be switched to the backup fiber optic channel, and the PSTN analog signal will be encapsulated into an SM4 encrypted IP packet using virtual secure tunnel technology.
[0019] Secondly, embodiments of this application provide an anti-eavesdropping protection system for hotel telephones, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements any of the above-described anti-eavesdropping protection methods for hotel telephones.
[0020] Thirdly, embodiments of this application also provide an anti-eavesdropping protection device for hotel telephones, wherein the device stores a computer program, and when the computer program is executed by a processor, it implements any of the aforementioned anti-eavesdropping protection methods for hotel telephones.
[0021] As can be seen from the above embodiments, the anti-eavesdropping protection method for hotel telephones provided in this application has at least the following beneficial effects:
[0022] This application generates a link risk index by real-time calculation of the risks of insufficient randomness in key updates and microphone acoustic wave resonance activation. This dynamically quantifies the security status of hotel telephone communications, providing a basis for tiered protection and effectively addressing the two core vulnerabilities of fixed key updates and illegal eavesdropping, thereby improving overall anti-eavesdropping protection capabilities. Furthermore, this application calculates a security threat index by dynamically analyzing the smoothing trend and abnormal deviations of the link risk index, promptly identifying sudden man-in-the-middle attacks. This achieves accurate and real-time assessment of the security of hotel telephone communications, enabling timely triggering of corresponding protection strategies and improving anti-eavesdropping capabilities. Finally, this application dynamically calculates link risk and security threat indices by real-time monitoring of key updates, current, and environmental noise data, promptly identifying sudden man-in-the-middle attacks. This achieves accurate assessment of the security of hotel telephone communications and triggers tiered protection strategies, compensating for the shortcomings of traditional encryption that only covers the first hop and improving overall anti-eavesdropping capabilities. Attached Figure Description
[0023] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 A flowchart illustrating the steps of an anti-eavesdropping protection method for hotel telephones provided in one embodiment of this application;
[0025] Figure 2 This is a schematic diagram illustrating the security threat index extraction process provided in one embodiment of this application. Detailed Implementation
[0026] To further illustrate the technical means and effects adopted by this application to achieve the intended purpose of the invention, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation methods, structures, features, and effects of the anti-eavesdropping protection method, system, and device for hotel telephones proposed according to this application. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.
[0028] The following description, in conjunction with the accompanying drawings, details the specific solutions provided in this application for the anti-eavesdropping protection method, system, and device for hotel telephones.
[0029] Please see Figure 1 The diagram illustrates a flowchart of an anti-eavesdropping protection method for hotel telephones according to an embodiment of this application. The method includes the following steps:
[0030] S1: Real-time acquisition of key update timestamps, current data, and environmental noise data during hotel telephone calls.
[0031] The anti-eavesdropping protection system for hotel telephones consists of three parts:
[0032] Hotel telephone terminal: built-in encryption chip, physical anti-tamper sensor, and microphone shielding circuit.
[0033] Distributed security gateway: Deployed at the hotel network boundary, it contains three modules: a. Encryption module: supports the national cryptographic SM4 / SM9 algorithm and quantum key distribution interface; b. Protocol conversion module: realizes seamless conversion of PSTN-VoIP-SIP protocol; c. Audit module: records the encryption status log of the entire link.
[0034] Central control platform: Visually monitors the security status of each node and supports dynamic policy distribution.
[0035] A lightweight eavesdropping agent is deployed on the SIP proxy server of the hotel network to accurately capture the timestamp of key update time; a high-precision microampere-level current sensor is installed in the microphone circuit inside the phone to collect current data in real time during the call; at the same time, a wideband digital microphone is configured in the same sound field environment as the earpiece to record the ambient noise signal synchronously.
[0036] To achieve cross-domain data fusion, a PTP-based protocol is adopted. A high-precision time synchronizer locks the sampling phase of the current and noise sensors through a hardware clock synchronization line and marks key events with a unified time stamp. Specifically, all sensors sample at a frequency of f, SIP signaling monitoring has its own timestamp, and microampere-level current sensors and ambient noise microphones acquire continuous waveforms by locking the phase through a hardware synchronization line. The high-precision time synchronizer is used to achieve cross-domain timestamp alignment of the three data streams.
[0037] It should be noted that the sampling frequency f is set manually. In this embodiment, the sampling frequency f is 100Hz. In actual applications, as other implementation methods, implementers can also set it according to specific circumstances. This embodiment does not impose any special restrictions.
[0038] Thus, through the above real-time data collection, the key update timestamp, current data, and environmental noise data during the hotel telephone call were obtained.
[0039] Furthermore, in order to eliminate the influence of data dimensions, the current data and environmental noise data are normalized separately. In this embodiment, the z-score normalization method is used to normalize the data. In practical applications, as other implementation methods, implementers may also use the maximum-minimum value normalization method to normalize the data according to specific circumstances. This embodiment does not impose any special restrictions on the selection of normalization methods.
[0040] Among them, z-score normalization is a well-known technique, and the specific process of using it to normalize data will not be elaborated here.
[0041] S2: By analyzing the degree of disorder of all key update timestamps within a preset time period before each time, the key update irregularity at each time period is determined; by analyzing the correlation between current data and environmental noise data at all times within a preset time period before each time, the current noise correlation at each time period is determined; and combined with the key update irregularity, the link risk index of hotel telephone communication at each time period is determined.
[0042] Because the hotel telephone system has two core vulnerabilities in VoIP communication—fixed key update mode and unauthorized microphone activation—attackers can crack the encryption link by analyzing key change patterns or remotely activate the microphone to eavesdrop by using the principle of sound wave resonance, causing end-to-end encryption protection to fail. Therefore, to ensure that hotel telephone calls are not eavesdropped on, these two core vulnerabilities must be addressed simultaneously.
[0043] Therefore, addressing the two core vulnerabilities of fixed key update patterns and unauthorized microphone activation, this embodiment analyzes the degree of disorder in all key update timestamps within a preset time period prior to each moment to determine the key update irregularity at each moment; it also analyzes the correlation between current data and environmental noise data within a preset time period prior to each moment to determine the current noise correlation at each moment. Combined with the key update irregularity, the link risk index of hotel telephone communication at each moment is determined to quantify the overall security posture of the hotel telephone anti-eavesdropping protection mechanism. Specifically:
[0044] In this embodiment, the following calculation and analysis are performed to address the issue of fixed key update patterns:
[0045] In this embodiment, the information entropy of all key update timestamps within a preset time period before each moment is used as the key update irregularity at each moment. The smaller the information entropy, the smaller the corresponding key update irregularity, indicating that the key replacement interval is regular, that is, the key update pattern is fixed, and the attacker is more likely to predict malicious key data packets.
[0046] It should be noted that the preset duration is set manually. In this embodiment, the preset duration is 10 seconds. In actual applications, as other implementation methods, implementers can also set it according to specific circumstances. This embodiment does not impose any special restrictions.
[0047] Specifically, for moments less than 10 seconds prior, the arithmetic mean of the data from the existing moments is used to fill the gaps.
[0048] The method for calculating information entropy is a well-known technique. In this embodiment, the probability of key update timestamps at each time within a preset time period before each time is statistically analyzed. Based on the probability and its corresponding value, the information entropy of key update timestamps at all times within a preset time period before each time is obtained using the formula for calculating information entropy. The specific calculation process will not be described in detail.
[0049] Furthermore, in this embodiment, the following calculation and analysis are performed to address the issue of illegal microphone activation:
[0050] In this embodiment, the correlation coefficient between the current data and the environmental noise data at all times within a preset time period before each time moment is used as the current-noise correlation at each time moment. This is used to measure the synchronicity between environmental sound waves and current fluctuations. The greater the correlation between current and environmental noise, the lower the synchronicity between environmental noise and current fluctuations, and there is a risk that the microphone may be illegally activated by acoustic resonance technology.
[0051] It should be noted that there are many commonly used methods for measuring correlation coefficients. In this embodiment, the Pearson correlation coefficient between microphone current data and ambient noise data at all times within a preset time period before each time period is used as the correlation coefficient between microphone current data and ambient noise data at all times within a preset time period before each time period. In practical applications, as other implementation methods, implementers may also use other correlation coefficient calculation methods such as Spearman correlation coefficient according to specific circumstances. This embodiment does not impose any special restrictions on the calculation of correlation coefficients.
[0052] The calculation method for the Pearson correlation coefficient is a well-known technique, and its specific calculation process will not be elaborated here.
[0053] Based on the above analysis, hotel telephone anti-eavesdropping protection faces two major risks: "fixed key update mode" and "illegal microphone activation." Although these two risks are independent, they can lead to the same or related consequences such as encryption failure or information leakage. Furthermore, if the key is easily predictable, the risk posed by illegal microphone activation is greater. Therefore, this embodiment uses the current noise correlation and key update irregularity calculated above to determine the link risk index of hotel telephone communication at each time point, in order to quantify the overall security posture of the hotel telephone anti-eavesdropping protection mechanism. Specifically:
[0054] As one implementation method, in this embodiment, the link risk index of hotel telephone communication at time i is... The expression is: In the formula, Indicates the irregularity of key updates at time i; This indicates the correlation between current and noise at time i; represents the preset threshold; exp() represents the exponential function with the natural constant as the base; max() represents the maximum value function.
[0055] It should be noted that the preset threshold value is set manually. In this embodiment, the preset threshold value is 0.7. In actual application, the implementer can also set it according to the specific situation. This embodiment does not impose any special restrictions.
[0056] Based on the link risk index of hotel telephone communication at various times, it can be understood that the link risk index is used to measure the security level of hotel telephone communication. It combines the risk of insufficient randomness in key updates and the risk of illegal activation of the hotel telephone microphone by acoustic resonance. If the irregularity of key updates at the current time is smaller, it means that the randomness of key updates is worse and the key change interval is more regular. Attackers are more likely to predict the key or inject malicious data packets to crack the encrypted link, which makes the encrypted link itself vulnerable. The overall link risk index will also increase, and the risk of encryption protection failure will increase. At the same time, if the difference between the current noise correlation at the current time and the preset threshold is greater than 0, and the larger the difference is, the stronger the synchronization of current and environmental noise data fluctuations is, the higher the possibility of physical eavesdropping, and the corresponding link risk index will also be greater.
[0057] Conversely, the greater the irregularity of key updates at the current moment, the better the randomness of key updates and the more irregular the key change interval. This makes it more difficult for attackers to predict the key or inject malicious data packets to crack the encrypted link, making the encrypted link itself more robust. The overall link risk index will decrease, and the risk of encryption protection failure will also decrease. At the same time, if the difference between the current noise correlation at the current moment and the preset threshold is less than or equal to 0, or the smaller the difference, the weaker the synchronization between current and environmental noise data fluctuations, the lower the possibility of physical eavesdropping, and the smaller the corresponding link risk index will be.
[0058] Thus, this embodiment generates a link risk index by calculating the risks of insufficient randomness in key updates and microphone acoustic wave resonance activation in real time, dynamically quantifies the security status of hotel telephone communication, provides a basis for graded protection, effectively addresses the two core vulnerabilities of fixed key updates and illegal eavesdropping, and improves the overall anti-eavesdropping protection capability.
[0059] S3: Based on the smoothness of all link risk indices within a preset time period before each time, determine the link risk benchmark value at each time; by analyzing the abnormal situation of the deviation between all link risk indices and the link risk benchmark value within a preset time period before each time, determine the security anomaly degree at each time, and in combination with the link risk benchmark value, determine the security threat index of hotel telephone communication at each time.
[0060] During hotel phone calls, man-in-the-middle attacks can exploit two vulnerabilities identified in step S2 to threaten call security: either by exploiting key update patterns to crack encryption or by sending specific sound waves to activate the microphone. Therefore, based on the link risk index obtained in step S2, it is necessary to determine whether the hotel phone call has been affected by a sudden man-in-the-middle attack. However, due to the instantaneous and stealthy nature of man-in-the-middle attacks, it is difficult to distinguish between long-term security degradation and sudden man-in-the-middle attacks when identifying them using traditional static threshold detection based on the link risk index, leading to delayed or false triggers in the protection response.
[0061] Specifically, long-term security degradation is usually a slow and gradual process. For example, the key updates of hotel telephones may initially be relatively random, but over time, system aging or misconfiguration can lead to a gradual increase in the regularity of key updates. During this slow degradation process, the link risk index may approach or even occasionally and briefly exceed the static threshold. Sudden man-in-the-middle attacks, on the other hand, are rapid and drastic. For example, an attacker may suddenly use specific methods to make the telephone key updates extremely regular, or remotely activate the microphone through sound waves. Such sudden attacks can cause the link risk index to rise sharply in a short period of time, potentially exceeding the static threshold rapidly and significantly. Since both long-term security degradation and sudden man-in-the-middle attacks can cause the link risk index to exceed the static threshold, and the static threshold is a value that only considers the "value" and not the "process," it is difficult for the static threshold to identify the risk of sudden man-in-the-middle attacks in a timely manner from long-term security degradation and sudden man-in-the-middle attacks, resulting in a delay in early warning.
[0062] Therefore, based on the above analysis, this embodiment determines the link risk benchmark value at each time point based on the smoothness of all link risk indices within a preset time period prior to each time point; by analyzing the abnormal situations of the deviation between all link risk indices and the link risk benchmark value within a preset time period prior to each time point, the security anomaly degree at each time point is determined; and combined with the link risk benchmark value, the security threat index of hotel telephone communication at each time point is determined, so as to timely judge the security level of the hotel telephone communication process, specifically as follows:
[0063] (1) In order to determine whether the hotel telephone communication process is threatened by a sudden man-in-the-middle attack, this embodiment determines the link risk benchmark value at each time point based on the smoothness of all link risk indices within a preset time period before each time point, so as to obtain the judgment benchmark for sudden man-in-the-middle attacks. This breaks the traditional static threshold setting and uses dynamic analysis of the link risk benchmark value to replace the static threshold judgment. Specifically:
[0064] As one implementation method, in this embodiment, all link risk indices within a preset time period before each moment are used as inputs to variables in the Exponential Moving Average (EMA) algorithm. The smoothing factor in the EMA algorithm is set to 0.2 to balance recent mutations and long-term trends, avoid short-term noise interference, and the output smoothed value is used as the link risk benchmark value at each moment to reflect the security level of the hotel telephone call environment and eliminate normal fluctuations such as equipment restarts.
[0065] It should be noted that the exponentially weighted moving average algorithm is used in this embodiment to smooth the prediction of the link risk index at each time point. In actual application, as another implementation method, the implementer may also use other smoothing algorithms according to the specific situation. This embodiment does not impose any special restrictions on the selection of smoothing algorithms.
[0066] The exponentially weighted moving average algorithm is a well-known technique, and its specific principles will not be elaborated here.
[0067] (2) Further, in this embodiment, by analyzing the abnormal situations of the deviation between all link risk indices and link risk benchmark values within a preset time period before each time point, the security anomaly degree at each time point is determined, so as to promptly determine whether the hotel telephone communication has been subjected to a sudden man-in-the-middle attack, thereby quickly making early warning and prevention measures, specifically:
[0068] In this embodiment, the absolute value of the difference between the link risk index and the link risk benchmark value at each time point is calculated as the deviation between the link risk index and the link risk benchmark value at each time point. The deviation between the link risk index and the link risk benchmark value at all times within a preset time period before each time point is used as the input of the anomaly detection algorithm, and anomaly score is output. The output anomaly score is used as the security anomaly degree at each time point. If the security anomaly degree at the current time point is larger, it indicates that the current link risk index deviates more from the link risk benchmark value, and that the hotel telephone communication security is more likely to be subjected to a sudden man-in-the-middle attack. At this time, a higher level of protection strategy needs to be triggered. Conversely, if the security anomaly degree at the current time point is smaller, it indicates that the current link risk index deviates less from the link risk benchmark value, and that the hotel telephone communication security is higher.
[0069] It should be noted that there are many commonly used anomaly detection algorithms. This implementation uses the Isolation Forest anomaly detection algorithm to obtain the anomaly score at each time point. Specifically, the deviation between the link risk index and the link risk benchmark value at all times within a preset time period before each time point is used as the input of the Isolation Forest algorithm. The number of trees is set to 200 to ensure statistical significance of small samples, and the subsampling quantity is set to 100 to cover the call window. The average path length of each node in the 200 trees is calculated. In this embodiment, the average path length of the deviation at each time point within the preset time period in the 200 trees is calculated. Finally, the Isolation Forest algorithm converts the average path length into anomaly score. In practical applications, as other implementation methods, implementers can also use other methods such as the LOF anomaly detection algorithm according to specific circumstances. This embodiment does not impose special restrictions on the selection of anomaly detection algorithms.
[0070] The isolated forest anomaly detection algorithm is a well-known technique, and the specific process of using it to estimate anomaly scores will not be elaborated here.
[0071] (3) Furthermore, in order to more comprehensively and accurately assess the security of hotel telephone communication, this embodiment determines the security threat index of hotel telephone communication at each time point based on the security anomaly degree and link risk benchmark value at each time point, so as to judge the security level of hotel telephone communication in real time, specifically as follows:
[0072] As one implementation method, in this embodiment, the security threat index of hotel telephone communication at time i is... The expression is: In the formula, Indicates the safety anomaly degree at time i; represents the baseline value of link risk at time i; norm() represents the normalization function.
[0073] Preferably, the schematic diagram of the security threat index extraction process provided in this embodiment is as follows: Figure 2 As shown.
[0074] Based on the security threat index of hotel telephone communication at the current moment, it can be understood that the security threat index reflects the security level of hotel telephone communication. If the security anomaly level is higher at the current moment, it indicates that the attacker's suddenness is very strong, and the corresponding security threat index is correspondingly higher. At the same time, the lower the link risk benchmark value, the lower the inherent security level of the call process, that is, the greater the risk of the call being eavesdropped on, and therefore the corresponding security threat index is higher. Conversely, if the security anomaly level is lower at the current moment, it indicates that no sudden attack has been detected, and the corresponding security threat index is correspondingly lower. At the same time, the higher the link risk benchmark value, the higher the inherent security level of the call process, that is, the lower the risk of the call being eavesdropped on, and therefore the corresponding security threat index is also lower.
[0075] Thus, this embodiment calculates the security threat index by dynamically analyzing the smoothing trend and abnormal deviation of the link risk index, and promptly identifies sudden man-in-the-middle attacks, achieving accurate and real-time assessment of the security of hotel telephone communications. This enables the timely triggering of corresponding protection strategies and enhances the ability to prevent eavesdropping.
[0076] S4: Based on the security threat index of hotel telephone communication at the current moment, implement anti-eavesdropping protection for hotel telephone communication at the current moment.
[0077] The goal of a man-in-the-middle attack is to intercept and decrypt call content. Traditional encryption schemes only cover the first hop in a hotel telephone system—the connection between the hotel room telephone and the hotel's internal VoIP gateway server. The second hop—the connection between the hotel's internal VoIP gateway server and the external PTSN gateway—is unencrypted. In this case, the attacker doesn't need to directly compromise the hotel's internal network; by setting up listening points on the second hop and intercepting the unencrypted second hop, they can eavesdrop. Therefore, the security threat index obtained in step S3 indirectly reflects the risk posed by the unencrypted second hop. Thus, based on the security threat index obtained in step S3, the overall security threat level of the hotel telephone system is assessed, and timely protection against eavesdropping on hotel telephone calls is implemented. Specifically:
[0078] Based on the current security threat index B, a graded protection mechanism is set up to achieve adaptive closed-loop protection, as detailed below:
[0079] 1. Basic Protection Layer: If the security threat index of the hotel telephone communication at the current moment is less than or equal to the preset first value, it means that the security coefficient of the hotel telephone process is relatively high at this time. TLS / SRTP encryption is maintained to ensure the security of normal calls. It is suitable for scenarios without abnormal network fluctuations.
[0080] 2. Active blocking layer: If the security threat index at the current moment is greater than the preset second value, quantum key encryption will be automatically enabled and the power supply to the phone microphone will be physically cut off to prevent eavesdropping by fake base stations;
[0081] 3. Emergency Circuit Breaker Layer: If the security threat index at the current moment is greater than the preset second value, for high-risk ARP spoofing or unencrypted link attacks, the hotel telephone call will be switched to the backup fiber optic channel. At the same time, the PSTN analog signal will be encapsulated into SM4 encrypted IP packets through Virtual Secure Tunnel (VST) technology to completely eliminate the last-mile vulnerability.
[0082] It should be noted that the values of the first preset value and the second preset value are both set manually. In this embodiment, the first preset value is 0.3 and the second preset value is 0.6. In actual application, as other implementation methods, implementers can also set them according to specific circumstances. This embodiment does not impose any special restrictions.
[0083] Quantum key encryption and Virtual Secure Tunnel (VST) technology are both well-known technologies. The specific process of quantum key encryption and the process of encapsulating PSTN analog signals into SM4 encrypted IP packets using Virtual Secure Tunnel (VST) technology will not be described in detail here.
[0084] Thus, this embodiment, by monitoring key updates, current and environmental noise data in real time, dynamically calculates link risk and security threat indices, promptly identifies sudden man-in-the-middle attacks, achieves accurate assessment of the security of hotel telephone communications, and triggers a tiered protection strategy. This compensates for the shortcomings of traditional encryption that only covers the first hop, and improves the overall anti-eavesdropping capability.
[0085] Based on the same inventive concept as the above methods, this application also provides an anti-eavesdropping protection system for hotel telephones, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any one of the above-described anti-eavesdropping protection methods for hotel telephones.
[0086] Based on the same inventive concept as the above method, this application also provides an anti-eavesdropping protection device for hotel telephones. The device stores a computer program, which, when executed by a processor, implements any of the above-described anti-eavesdropping protection methods for hotel telephones.
[0087] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments of this specification have been described above. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.
[0088] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
[0089] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.
Claims
1. A method for preventing eavesdropping in hotel telephones, characterized in that, The method includes the following steps: Real-time acquisition of key update timestamps, current data, and environmental noise data during hotel telephone calls; By analyzing the degree of disorder of all key update timestamps within a preset time period before each time, the key update irregularity at each time is determined; by analyzing the correlation between current data and environmental noise data at all times within a preset time period before each time, the current noise correlation at each time is determined; and combined with the key update irregularity, the link risk index of hotel telephone communication at each time is determined. Based on the smoothness of all link risk indices within a preset time period before each time, the link risk benchmark value at each time is determined; by analyzing the abnormal situation of the deviation between all link risk indices and the link risk benchmark value within a preset time period before each time, the security anomaly degree at each time is determined, and combined with the link risk benchmark value, the security threat index of hotel telephone communication at each time is determined. Based on the current security threat index of hotel telephone communication, anti-eavesdropping protection is implemented for hotel telephone communication at the current moment.
2. The anti-eavesdropping protection method for hotel telephones as described in claim 1, characterized in that, The key update irregularity at each time point is the information entropy of all key update timestamps within a preset time period prior to each time point.
3. The anti-eavesdropping protection method for hotel telephones as described in claim 1, characterized in that, The current noise correlation at each time point is the correlation coefficient between the current data and the environmental noise data at all times within a preset time period prior to each time point.
4. The anti-eavesdropping protection method for hotel telephones as described in claim 1, characterized in that, The expression for the link risk index of hotel telephone communication at each time point is as follows: In the formula, This represents the link risk index of hotel communication at time i. Indicates the irregularity of key updates at time i; This indicates the correlation between current and noise at time i; represents the preset threshold; exp() represents the exponential function with the natural constant as the base; max() represents the maximum value function.
5. The anti-eavesdropping protection method for hotel telephones as described in claim 1, characterized in that, The reference value for link risk at each time point is a smoothed value obtained by applying a smoothing algorithm to all link risk indices within a preset time period prior to each time point.
6. The anti-eavesdropping protection method for hotel telephones as described in claim 1, characterized in that, The security anomaly degree at each time point is the anomaly score obtained by using an anomaly detection algorithm to measure the deviation between the link risk index and the link risk benchmark value within a preset time period prior to each time point.
7. The anti-eavesdropping protection method for hotel telephones as described in claim 1, characterized in that, The expression for the security threat index of hotel telephone communication at each time point is: In the formula, This represents the security threat index at time i; Indicates the safety anomaly degree at time i; represents the baseline value of link risk at time i; norm() represents the normalization function.
8. The anti-eavesdropping protection method for hotel telephones as described in claim 1, characterized in that, The protection against eavesdropping on hotel telephone communications at the current moment includes: If the security threat index of the hotel telephone communication at the current moment is less than or equal to the preset first value, then the TLS / SRTP encryption between the hotel telephone and the hotel's SIP proxy server will be maintained. If the security threat index of the hotel telephone communication at the current moment is between the preset first value and the preset second value, then quantum key encryption will be automatically enabled and the power supply to the telephone microphone will be physically cut off. The preset first value is less than the preset second value. If the security threat index at the current moment is greater than the preset second value, the hotel telephone will be switched to the backup fiber optic channel, and the PSTN analog signal will be encapsulated into an SM4 encrypted IP packet using virtual secure tunnel technology.
9. An anti-eavesdropping protection system for hotel telephones, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the anti-eavesdropping protection method for hotel telephones as described in any one of claims 1-8.
10. An anti-eavesdropping protection device for hotel telephones, wherein the device stores a computer program, characterized in that, When the computer program is executed by the processor, it implements the anti-eavesdropping protection method for hotel telephones as described in any one of claims 1-8.
Citation Information
Patent Citations
Information security management method based on data processing
CN120128361A
Malware response system and method based on artificial intelligence
CN120162785A