A method and apparatus for heterogeneous security hardening of a pulse code modulation voice data stream
By employing channel partitioning and nonlinear permutation methods in voice switches, combined with various packet data hardening algorithms, the relationship between voice data channels is obfuscated, thus solving the problem of insufficient data security in traditional voice switches and achieving highly secure voice data transmission.
Patent Information
- Application Number
- CN202310382867.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-12
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2043-04-12
AI Technical Summary
In traditional voice switches, voice data lacks effective security protection when transmitted in E1 trunk channels, making it easy to intercept and crack. Existing hardening algorithms are not complex enough, have low diffusion, and the impact of local changes in the original data on the hardened ciphertext is limited.
Multiple mainstream packet data hardening algorithms are employed. By dividing the channel, nonlinear permutation and XOR operation, the channel relationship of consecutive frames is confused. S-boxes of different algorithms are used for nonlinear permutation, and the extended key is reused for the hardening operation of the second voice data channel area to be hardened, so as to realize the data shifting and cross-fusion.
It effectively defends against attacks and cracking of single-group data algorithms, improves the security of voice data, and enhances the spreadability and uncrackability of data hardening.
Smart Images

Figure CN118802095B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application generally relate to the technical field of voice switch, and particularly relate to a heterogeneous security reinforcement method and device for pulse code modulation voice data stream. BACKGROUND
[0002] In a voice switching network, the traditional practice is that in the remote interconnection E1 trunk channel between voice switches, according to the specification of ITU-T, the G.711 original plaintext of voice is carried, which can be intercepted, downloaded and saved, played, listened to and easily understood, and has no security protection function for important information, and the security is poor for some applications. In the traditional network, the voice data carried in the E1 trunk channel between voice switches has the following problems:
[0003] 1. The G.711 original plaintext of voice is directly transmitted in the trunk channel, the data stream content can be played, listened to and understood after being intercepted and downloaded, and has no security protection ability. The traditional practice is to focus on the supervision and restraint of the personnel management system in the communication room where the voice switch is located, but there is no solution in technical prevention;
[0004] 2. Some methods enable security reinforcement based on stream data reinforcement (sequence data reinforcement), and perform exclusive or operation on the data original text with a specific key on both sides of the switch. After the voice code stream data is downloaded, the playing effect presents white noise, and the data cannot be normally played and listened to. However, because the stream data reinforcement design originally excessively focuses on the data reinforcement implementation efficiency based on time evaluation of data stream, the algorithm complexity is insufficient, the diffusion of the data security reinforcement is low, the influence range of the local change of the data original text on the reinforced ciphertext is limited, which leads to that the data can still be cracked by analyzing the distribution rule of the ciphertext data after being intercepted and downloaded.
[0005] As the patent: "A VoLTE voice encryption optimization implementation method, terminal and system (application number: CN202210992026.3)": the method includes that first terminal is split to voice data frame of data length greater than encrypted packet byte, obtains second voice data and at least one group first voice data;Adopting CBC encryption mode, using key K and IV encrypting first voice data, obtaining first ciphertext;For second voice data, adopt ECB encryption mode, use key K to encrypt the adjacent first voice data encryption ciphertext, obtain Kiv_1;According to the length of second voice data, intercept the Kiv_1, the intercepted ciphertext is XOR processed with second voice data, and second ciphertext is obtained;The first ciphertext and the second ciphertext are spliced to obtain the call ciphertext, and are sent to the second terminal, and the encrypted call is realized.The scheme realizes the encryption conversion from ECB to CBC, improves the security of VoLTE voice call, but belongs to a kind of based on stream data reinforcement, the complexity of algorithm is insufficient, the diffusion of data security reinforcement is lower, and the influence range of local change of data original text on reinforced ciphertext is limited. SUMMARY
[0006] To solve the above problems, the present application adopts a plurality of mainstream packet data reinforcement algorithms and makes joint expansion, including using S-boxes of different algorithms to realize nonlinear permutation, reusing the expansion key in the algorithm for the first to be reinforced voice data channel area for reinforcement operation of the second to be reinforced voice data channel area, further shifting cross fusion of the two voice channel areas reinforced by two algorithms, etc., and the original fixed channel relationship of continuous frames is more blurred, which can effectively prevent attacks and cracking against single packet data algorithm.
[0007] According to the embodiments of the present application, a method and device for heterogeneous security reinforcement of pulse code modulation voice data stream are provided.
[0008] In the first aspect of the present application, a method for heterogeneous security reinforcement of pulse code modulation voice data stream is provided. The method comprises:
[0009] S01: divide the relay code stream data in each frame E1 into four functional areas in units of channels: synchronization functional channel area, reinforcement control functional channel area, first to be reinforced voice data channel area and second to be reinforced voice data channel area;
[0010] S02: pre-process the data of the first to be reinforced voice data channel area to become a 16-byte row matrix, and then perform 128-bit mode packet algorithm for data reinforcement;
[0011] S03: Pre-process the data in the second to be secured voice data channel region into a 14-byte row matrix, and then perform the S-box of a grouping algorithm different from that in S02 to complete the nonlinear permutation;
[0012] S04: Perform XOR calculation on the data in the second to be secured voice data channel region using the dynamic round key of the first to be secured voice data channel region, and then perform mixing operation on the data in the first to be secured voice data channel region and the data in the second to be secured voice data channel region to complete the data securing process;
[0013] S05: Push the secured data into the E1 relay code stream sending buffer, and when the next 125-microsecond frame synchronization arrives, sequentially send the data through the relay interface LIU chip, and the switch at the receiving end receives the data and performs the unsecuring process.
[0014] Further, the securing control function channel region in S01 is specified by an algorithm.
[0015] Further, the algorithm is specified by an engineer when generating data.
[0016] Further, the algorithm is dynamically configured by a user at the start.
[0017] Further, the mixing operation in S04 is specified by an engineer when generating data or dynamically configured by a user at the start.
[0018] Further, if the S-box used in S03 is the same as the grouping algorithm in S02, then the round key of the first to be secured voice data channel region is used to perform XOR operation on the data in the second to be secured voice data channel region in a self-defined manner.
[0019] Further, the unsecuring steps in S05 are opposite to the process of the securing process.
[0020] In a second aspect of the present application, a device for heterogeneous secure reinforcement of a pulse code modulation voice data stream is provided. The device comprises:
[0021] a channel division module for dividing the data of each frame of E1 relay code stream into four function regions in units of channels, i.e., a synchronization function channel region, a securing control function channel region, a first to be secured voice data channel region, and a second to be secured voice data channel region;
[0022] a first preprocessing module for pre-processing the data in the first to be secured voice data channel region into a 16-byte row matrix, and then performing 128-bit grouping algorithm to secure the data;
[0023] The second preprocessing module is used for pre-processing the data in the second data channel area to be secured, and performing the S-box of a grouping algorithm different from the first preprocessing module to complete the nonlinear permutation.
[0024] The mixing operation module is used for performing the XOR operation of the second data channel area to be secured with the dynamic round key of the first data channel area to be secured, and then performing the mixing operation of the first data channel area to be secured and the second data channel area to be secured to complete the data securing process.
[0025] The sending module is used for pushing the data after the securing process into the E1 relay code stream sending buffer, and then sending the data through the relay interface LIU chip when the next 125 microseconds frame synchronization arrives.
[0026] Further, the securing control function channel area in the channel division module is specified by an algorithm.
[0027] Further, the algorithm is specified by an engineer when generating the data.
[0028] Further, the algorithm is dynamically configured by a user at the beginning.
[0029] Further, the mixing operation in the mixing operation module is specified by an engineer when generating the data or is dynamically configured by a user at the beginning.
[0030] Further, if the S-box used by the second preprocessing module is the same as the grouping algorithm of the first preprocessing module, the mixing operation module uses the round key of the first data channel area to be secured to perform the XOR operation of the data in the second data channel area to be secured in a self-defined manner.
[0031] Further, the step of the desecuring in the sending module is opposite to the process of the securing process.
[0032] The above-mentioned English abbreviations are explained as follows:
[0033] E1: digital circuit relay, 2.048 Mbit / s rate, 32 channel pulse modulation
[0034] S-box: data table for byte nonlinear permutation of symmetric algorithm for data securing
[0035] LIU: Line Interface Unit, line interface unit realized in the form of integrated circuit or FPGA
[0036] ITU-T: International Telecommunication Union Tech, International Telecommunication Union Technical Standard
[0037] G.711: ITU-T specification describing a standard for speech sampling and compression based on pulse code modulation
[0038] FPGA: Field Programmable Gate Array, Field Programmable Gate Array
[0039] G.703: ITU-T specification describing the physical and electrical characteristics of digital interfaces in digital systems
[0040] TDM: Time-Division Multiplexing, Time-Division Multiplexing
[0041] PCM: Pulse Code Modulation, Pulse Code Modulation
[0042] SM4: Domestic Data Reinforcement Algorithm 4, Block Cipher Algorithm
[0043] AES-128: Advanced Encryption Standard, Advanced Encryption Standard with a key length of 128 bits
[0044] MK: Master Key-MK, Master Key
[0045] ID: Identity document, Identity document
[0046] The application adopts a plurality of mainstream block data reinforcement algorithms and makes joint expansion, including using S-boxes of different algorithms to respectively implement nonlinear permutation, reusing the expansion key in the algorithm for the first to be reinforced voice data channel area for reinforcement operation of the second to be reinforced voice data channel area, and further shifting and cross-fusing the data of the two voice channel areas reinforced by the two algorithms, etc., so that the original fixed channel relationship of the continuous frame is confused more obscurely, which can effectively prevent attacks and cracking against a single block data algorithm.
[0047] It should be understood that the content described in the summary section is not intended to limit the key or important features of the embodiments of the application, nor to limit the scope of the application. Other features of the application will become apparent through the following description. BRIEF DESCRIPTION OF DRAWINGS
[0048] The above and other features, advantages, and aspects of the embodiments of the present application will become more apparent by describing in detail the following detailed description in conjunction with the accompanying drawings, in which:
[0049] Figure 1 A method flow chart of heterogeneous security reinforcement of pulse code modulation voice data stream is shown according to the embodiment of the present application;
[0050] Figure 2 A code stream data characteristic diagram of E1 relay channel between switches is shown according to the embodiment of the present application;
[0051] Figure 3 A relay code stream data frame structure definition diagram is shown according to the embodiment of the present application;
[0052] Figure 4 A primary data reinforcement diagram of a first voice data channel area to be reinforced is shown according to the embodiment of the present application;
[0053] Figure 5 A nonlinear substitution S-box diagram is shown according to the embodiment of the present application;
[0054] Figure 6 A logic / obfuscated channel ID corresponding definition diagram of voice channel is shown according to the embodiment of the present application;
[0055] Figure 7 A bit definition diagram of control channel byte is shown according to the embodiment of the present application;
[0056] Figure 8 A device block diagram of heterogeneous security reinforcement of pulse code modulation voice data stream is shown according to the embodiment of the present application. DETAILED DESCRIPTION
[0057] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0058] According to the embodiments of the present application, a method and device of heterogeneous security reinforcement of pulse code modulation voice data stream are provided, a plurality of mainstream packet data reinforcement algorithms are adopted and are jointly extended, including that S-boxes using different algorithms respectively implement nonlinear substitution, an extended key in the algorithm for a first voice data channel area to be reinforced is reused for reinforcement operation of a second voice data channel area to be reinforced, and data of two voice channel areas reinforced by two algorithms are further shifted and cross-fused, and so on. The original fixed channel relationship of continuous frames is confused more obscurely, and attacks and cracking against single packet data algorithm can be effectively prevented.
[0059] The principles and spirits of the present application will be explained in detail below with reference to several representative embodiments of the present application.
[0060] Figure 1 Figure 1 is a schematic diagram of a method for heterogeneous security reinforcement of a pulse code modulation voice data stream according to an embodiment of the present application. The method comprises:
[0061] S01: dividing the E1 relay code stream data in each frame into four functional areas in channel units, i.e. a synchronization functional channel area, a reinforcement control functional channel area, a first to be reinforced voice data channel area, and a second to be reinforced voice data channel area;
[0062] S02: pre-arranging the data in the first to be reinforced voice data channel area into a 16-byte row matrix and then performing a 128-bit mode grouping algorithm to reinforce the data;
[0063] S03: pre-arranging the data in the second to be reinforced voice data channel area into a 14-byte row matrix and then performing an S-box different from the grouping algorithm in S02 to complete a nonlinear permutation;
[0064] S04: performing an XOR calculation on the data in the second to be reinforced voice data channel area using a dynamic round key of the first to be reinforced voice data channel area, and then performing a mixing operation on the data in the first to be reinforced voice data channel area and the data in the second to be reinforced voice data channel area to complete the data reinforcement processing;
[0065] S05: pushing the data after the reinforcement processing into an E1 relay code stream sending buffer, and when the next 125-microsecond frame synchronization arrives, sequentially sending the data through a relay interface LIU chip, and receiving the data by a switch at the receiving end and then performing a demineralization processing.
[0066] It should be noted that although the operations of the method of the present application are described in a specific order in the above embodiments and the accompanying drawings, this does not require or imply that the operations must be performed in this specific order or that all of the shown operations must be performed to achieve the desired results. Additionally or alternatively, certain steps can be omitted, a plurality of steps can be combined into one step, and / or one step can be divided into a plurality of steps.
[0067] In order to more clearly explain the above-mentioned method for heterogeneous security reinforcement of a pulse code modulation voice data stream, a specific embodiment will be described below, however, it should be noted that this embodiment is only used to better illustrate the present application and does not constitute an improper limitation on the present application.
[0068] The method for heterogeneous security reinforcement of a pulse code modulation voice data stream will be further described in more detail below with a specific example:
[0069] According to the specification of ITU-T, the E1 relay channel between the remote interconnection of voice switch carries the E1 relay stream data in G.703 format, provides TDM time division multiplexing service, and the specific data format is continuous pulse code modulation PCM stream, the rate is 2.048 MHz, and one binary code data is transmitted per clock. One complete E1 relay channel is divided into 32 channels, except that channel 0 is used for synchronization of devices at both ends, the remaining channels can be used for transmission of voice data; the information amount of each channel is fixed at 1 byte. The 32 channels are a data frame, and 8,000 data frames are transmitted in 1 second, with an average time of 125 microseconds per frame and an average time of 3.90 microseconds per channel. A plurality of frames of the same channel, which constitute a voice channel, are used for voice transmission of the listening party of the telephone user. That is, one complete E1 relay channel can carry voice call data transmission of multiple calls. The stream data characteristics of the E1 relay channel between the switches are shown in Table 1. Figure 2
[0070] Each frame of E1 relay stream data is divided into four functional areas in units of channels:
[0071] (1) Synchronization functional channel area: channel 0 is conducive to the operation of the bottom layer relay interface LIU chip;
[0072] (2) Reinforcement control functional channel area: any channel can be specified by an algorithm engineer according to different sites when generating data, or can be dynamically configured by an operator user when starting. In the following expression, it is temporarily defined as channel 1;
[0073] (3) First to-be-reinforced voice data channel area: it is a combination of any 16 channels specified by the algorithm except channel 0 and the reinforcement control channel. In the following expression, it is temporarily defined as the section of channel 2 to channel 17;
[0074] (4) Second to-be-reinforced voice data channel area: it is a combination of the remaining 14 channels. In the following expression, it is temporarily defined as the section of channel 18 to channel 31.
[0075] The E1 relay stream data frame structure definition of the algorithm in the implementation process is a non-regular channel specification, which increases the confusion characteristics in the planning period of the data model, as shown in Table 2. Figure 3
[0076] The data of the first to-be-strengthened voice data channel area is pre-processed and becomes a 16-byte row matrix. A certain grouping algorithm data strengthening of 128-bit mode is performed on the grouped data of the first to-be-strengthened voice data channel area. The algorithm can include but is not limited to SM4 and AES-128. In this example, SM4 data strengthening is taken as an example. The 16-byte to-be-strengthened voice data channel area 1 is divided into four parts, each part being a 4-byte (32-bit) row matrix. The original plaintext can be represented as X0, X1, X2 and X3. In the SM4 algorithm, the key MK of the algorithm is also 128 bits, which can be extended to calculate 32 round keys, represented as rk0, rk1, rk2… to rk31, each round key being 4 bytes long. The original plaintext X0, X1, X2 and X3 are subjected to the first round of round function calculation with the first round key rk0, to generate a new row matrix X4, completing the first step. Then, the X0 part in the original plaintext is discarded, and the remaining X1, X2 and X3 are combined with the new row matrix X4 generated by the round function to perform the second round of round function calculation with the second round key rk0, to generate a second new row matrix X5, completing the second step. In this way, when the 32 rounds of round function calculation are completed, a completely new row matrix is obtained from X4, X5… to X35. Finally, the last four 16-byte row matrices X32, X33, X34 and X35 are combined to perform reverse sequence conversion to generate 16-byte temporary intermediate ciphertext Y0, Y1, Y2 and Y3. The initial data strengthening of the first to-be-strengthened voice data channel area is completed, as shown in Figure 4 In each round of round function calculation, according to the round, a total of four row matrix data including the original plaintext and the intermediate text participate in the operation. The last three input data matrices are subjected to exclusive OR operation with the round key, and then subjected to nonlinear substitution through the S-box of SM4 and linear operation of row and column shift, to finally generate 4-byte intermediate text and perform exclusive OR operation with the first input data matrix to finally generate a new 4-byte row matrix.
[0077] The data of the second to-be-strengthened voice data channel area is pre-processed and becomes a 14-byte row matrix. First, the S-box is executed to complete nonlinear substitution, which is different from the previous step. In this example, the S-box of AES-128 is taken as an example, as shown in Figure 5 In the second to-be-strengthened voice data channel area, the algorithm queries the data corresponding to the two-dimensional coordinates composed of the corresponding row and column in the S-box according to the high 4 bits and the low 4 bits in each to-be-strengthened byte, to complete nonlinear substitution. This step can fully confuse the continuity rule of the original voice plaintext.
[0078] After the 14-byte nonlinear permutation of the second to be reinforced voice data channel area is completed, the data of the second to be reinforced voice data channel area is calculated by XOR using the dynamic round key of the first to be reinforced voice data channel area. This step fuses different algorithms and reduces the possibility of implementing S-box inverse operation attack on a single algorithm. After that, the data of the second to be reinforced voice data channel area not only breaks the continuity of the original plaintext, but also changes the characteristics of the fixed output after the nonlinear permutation of the S-box, further confusing the data of the second to be reinforced voice data channel area. This example is only for illustrative purposes, and does not exclude the algorithm performing multiple rounds of nonlinear permutation, shifting and XOR calculation processing on the second to be reinforced voice data channel area.
[0079] After that, the mixing operation of the data of the first to be reinforced voice data channel area and the second to be reinforced voice data channel area is performed, further expanding the data reinforcement effect through controlled random reordering. There are two designated channels in the second to be reinforced voice data channel area, which are first replaced with the two random dynamic channels of the first to be reinforced voice data channel area. The algorithm has a built-in confusion correspondence table of the 16 channels of the first to be reinforced voice data channel area, as shown in Figure 6 .
[0080] The confusion channel ID will be filled in the reinforcement control channel. In each code stream data frame of the E1 relay, the algorithm will randomly generate two random integers A and B between 0 and 15, and write them to the buffer bytes of the reinforcement control channel to be sent. The bit definition of the control channel byte is as shown in Figure 7 .
[0081] When the random numbers A and B are completed, the algorithm will replace the corresponding two random channels in the first to be reinforced voice data channel area with the corresponding two designated channels in the second to be reinforced voice data channel area according to the logical / confusion channel ID corresponding definition. After this step is completed, Figure 3 , the bit sequence of the channels of the first to be reinforced voice data channel area and the second to be reinforced voice data channel area that have been interwoven as shown in the figure is confused; since the confusion channel ID is randomly generated every frame, it can be ensured that the bit sequence of the channels of the first to be reinforced voice data channel area and the second to be reinforced voice data channel area in two consecutive frames is different with high probability. At this time, the 16-byte data of the first to be reinforced voice data channel area and the channel 16-byte data of the second to be reinforced voice data channel area have been fused together to become a 30-byte data block to be sent. Finally, the IDs of the two random logical channels are summed. After this processing, the continuity of the original voice channel is also broken down, further increasing the difficulty of cracking attack analysis.
[0082] After the data reinforcement processing is completed, the E1 relay code stream sending buffer is pushed into, and when the next 125 microsecond frame synchronization arrives, it is sent out in turn through the relay interface LIU chip. Among the data of 32 channels, in addition to the synchronization channel byte without information value and a constantly changing reinforcement control channel byte, the remaining all 30 speech channel contents are based on the high-security packet data reinforcement algorithm, and sufficient confusion and diffusion are performed, so that even if intercepted and downloaded, the cracking difficulty is very high.
[0083] For the switch at the receiving end, the target is to reliably and stably restore the content in each channel to the original plaintext, and to ensure that no mismatch occurs. In contrast to the reinforcement process of the sending switch, the receiving switch sequentially performs:
[0084] 1. Analyzing the confusion channel ID in the reinforcement control channel and summing;
[0085] 2. Performing inverse cyclic right shift of the remaining 30-byte data blocks;
[0086] 3. Deriving the channel of the first to be reinforced speech data channel area and the second to be reinforced speech data channel area according to the logical / confusion channel ID correspondence, and arranging accurate homing;
[0087] 4. Performing the desolidification operation on the 16-byte data block of the first to be reinforced speech data channel area;
[0088] 5. Perform desolidification operation on the 14-byte data block of the second to be reinforced speech data channel area (reuse the round key of the first to be reinforced speech data channel area);
[0089] 6. Pushing the 30-way speech plaintext after desolidification into the inside of the switch for further processing.
[0090] Based on the same inventive concept, the present application also proposes a device for heterogeneous security reinforcement of pulse code modulation speech data stream. The implementation of the device can be referred to the implementation of the above-mentioned method, and the repeated parts will not be described again. As shown in Figure 2 The device 100 comprises:
[0091] The channel division module 101 is used to divide the E1 relay code stream data of each frame into four functional areas: a synchronization functional channel area, a reinforcement control functional channel area, a first to be reinforced speech data channel area, and a second to be reinforced speech data channel area;
[0092] The first preprocessing module 102 is used to pre-arrange the data of the first to be reinforced speech data channel area to become a 16-byte row matrix, and then perform a 128-bit mode packet algorithm for data reinforcement;
[0093] The second preprocessing module 103 is used for pre-processing the data of the second data channel area to be data-protected to a 14-byte row matrix, and then performing the S-box of a grouping algorithm different from the one described in the first preprocessing module to complete the nonlinear permutation;
[0094] The mixing operation module 104 is used for performing the XOR operation of the data of the second data channel area to be data-protected with the dynamic round key of the first data channel area to be data-protected, and then performing the mixing operation of the data of the first data channel area to be data-protected and the data of the second data channel area to be data-protected to complete the data protection processing;
[0095] The sending module 105 is used for pushing the data processed by the protection into the E1 relay code stream sending buffer, and then sending the data through the relay interface LIU chip when the next 125-microsecond frame synchronization arrives, and the switch of the receiving end receives the data and then performs the desolidification processing.
[0096] The device for the heterogeneous security protection of the pulse code modulation voice data stream provided by the application adopts a plurality of mainstream grouping data protection algorithms, and makes joint expansion, including using the S-boxes of different algorithms to respectively implement the nonlinear permutation, reusing the expansion key in the algorithm for the first data channel area to be data-protected in the protection operation of the second data channel area to be data-protected, and further performing the shift cross fusion of the data of the two voice channel areas protected by the two algorithms, so that the original fixed channel relationship of the continuous frames is more confused, and the attacks and cracking against the single grouping data algorithm can be effectively prevented.
[0097] Although the spirit and principles of the application have been described with reference to several specific embodiments, it should be understood that the application is not limited to the disclosed specific embodiments, and the division of aspects does not mean that the features in these aspects cannot be combined for the benefit, and the division is only for the convenience of expression. The application is intended to cover various modifications and equivalent arrangements included in the spirit and scope of the appended claims.
[0098] The scope of protection of the application should be understood by those skilled in the art that various modifications or changes made on the basis of the technical solutions of the application without creative labor are still within the scope of protection of the application.
Claims
1. A method of heterogeneous security hardening of a pulse code modulated voice data stream, characterized by, The method comprises: S01: dividing relay code stream data in each frame E1 into four functional areas in channel units: a synchronization functional channel area, a reinforcement control functional channel area, a first to-be-reinforced voice data channel area, and a second to-be-reinforced voice data channel area; S02: pre-processing data in the first to-be-reinforced voice data channel area to form a 16-byte row matrix, and then performing a 128-bit grouping algorithm to reinforce data; S03: pre-processing data in the second to-be-reinforced voice data channel area to form a 14-byte row matrix, and then performing an S-box different from the grouping algorithm in S02 to complete nonlinear permutation; S04: performing XOR calculation on data in the second to-be-reinforced voice data channel area using a dynamic round key of the first to-be-reinforced voice data channel area, and then performing mixing operation on data in the first to-be-reinforced voice data channel area and data in the second to-be-reinforced voice data channel area to complete data reinforcement processing; S05: pushing the data after reinforcement processing into an E1 relay code stream sending buffer, and when the next 125-microsecond frame synchronization arrives, sequentially sending out through a relay interface LIU chip, and after receiving the data, a switch at a receiving end performs desolidification processing.
2. A method of heterogeneous security hardening of a pulse code modulated voice data stream as claimed in claim 1, wherein, The reinforcement control functional channel area in the channel division module is specified by an algorithm.
3. A method of heterogeneous security hardening of a pulse code modulated voice data stream as claimed in claim 2, wherein, The algorithm is specified by an engineer when generating data.
4. A method of heterogeneous security hardening of a pulse code modulated voice data stream as claimed in claim 2, wherein, The algorithm is dynamically configured by a user at the beginning.
5. A method of heterogeneous security hardening of a pulse code modulated voice data stream as claimed in claim 1, wherein, The mixing operation in S04 is specified by an engineer when generating data or is dynamically configured by a user at the beginning.
6. A method of heterogeneous security hardening of a pulse code modulated voice data stream as claimed in claim 1, wherein, The desolidification steps in S05 are opposite to the reinforcement processing process.
7. An apparatus for heterogeneous security hardening of a pulse code modulated voice data stream, characterized by, The device comprises: a channel division module: for dividing relay code stream data in each frame E1 into four functional areas in channel units: a synchronization functional channel area, a reinforcement control functional channel area, a first to-be-reinforced voice data channel area, and a second to-be-reinforced voice data channel area; a first preprocessing module: for pre-processing data in the first to-be-reinforced voice data channel area to form a 16-byte row matrix, and then performing a 128-bit grouping algorithm to reinforce data; a second preprocessing module: for pre-processing data in the second to-be-reinforced voice data channel area to form a 14-byte row matrix, and then performing an S-box different from the grouping algorithm in the first preprocessing module to complete nonlinear permutation; a mixing operation module: for performing XOR calculation on data in the second to-be-reinforced voice data channel area using a dynamic round key of the first to-be-reinforced voice data channel area, and then performing mixing operation on data in the first to-be-reinforced voice data channel area and data in the second to-be-reinforced voice data channel area to complete data reinforcement processing; a sending module: for pushing the data after reinforcement processing into an E1 relay code stream sending buffer, and when the next 125-microsecond frame synchronization arrives, sequentially sending out through a relay interface LIU chip, and after receiving the data, a switch at a receiving end performs desolidification processing.
8. A device for heterogeneous security hardening of a pulse code modulated voice data stream according to claim 7, characterized in that, The reinforcement control functional channel area in the channel division module is specified by an algorithm.
9. A device for heterogeneous security hardening of a pulse code modulated voice data stream according to claim 8, characterized in that, The algorithm is specified by an engineer when generating data.
10. A device for heterogeneous security hardening of a pulse code modulated voice data stream as defined in claim 8, wherein, The algorithm is dynamically configured by a user at the beginning.
11. A device for heterogeneous security hardening of a pulse code modulated voice data stream as defined in claim 7, wherein, The mixed operation in the mixed operation module is specified by an engineer when generating data or dynamically configured by a user at the beginning.
12. A device for heterogeneous security hardening of a pulse code modulated voice data stream as defined in claim 7, characterized by The step of the de-hardening in the sending module is opposite to the process of the hardening.
Citation Information
Patent Citations
VoLTE voice encryption optimization implementation method, terminal and system
CN115361678A
Round calculation unit and corresponding encryption and decryption algorithm system
CN115037443A
Method and device for performing substitution table operations
EP3531612A1