Lightweight voice encryption method and device for digital interphone

By using lightweight hybrid encryption modules and software to implement encryption functions in the walkie-talkie, the problem of low performance and needing an external encryption chip in the prior art is solved, and high security and real-time voice data transmission is achieved, reducing costs.

CN119993171AActive Publication Date: 2025-05-13TAIYUAN UNIVERSITY OF TECHNOLOGY
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510117890.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-05-13
Estimated Expiration
2045-01-24

AI Technical Summary

Technical Problem

Existing intercoms have low performance when dealing with complex encryption algorithms and real-time voice intercom tasks, and require an external encryption chip to improve hardware encryption performance, but this increases costs.

Method used

The lightweight hybrid encryption module is adopted, combined with the AES encryption algorithm, the chacha20 stream encryption algorithm and the double-layer RSAq encryption algorithm, to encrypt the voice data and double-layer encryption of the encryption key. The encryption function is realized through software, avoiding excessive dependence on chip performance.

Benefits of technology

It improves the security and real-time nature of voice data transmission, reduces dependence on high-performance chips, and effectively reduces cost and overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119993171A_ABST
    Figure CN119993171A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of communication encryption, and aims to solve the problems that a low-performance development board can only realize simple software encryption, the safety coefficient is low, and an encryption chip needs to be additionally arranged to meet the encryption requirement. The invention provides a lightweight voice encryption method and device for a digital interphone. The lightweight voice encryption method comprises the following steps: acquiring to-be-encrypted voice data; the to-be-encrypted voice data is obtained by a microphone module and is obtained through digital-to-analog conversion and PCM format switching; encrypting the voice data to be encrypted based on an AES encryption algorithm and a chach20 stream encryption algorithm of the lightweight hybrid encryption module, and encrypting an AES encryption key based on a double-layer RSAq encryption algorithm of the lightweight hybrid encryption module; and the encrypted data and the encrypted key are used for triggering the lightweight hybrid decryption module to perform decryption and performing voice playing through the power amplifier module. According to the invention, the security and real-time performance of voice data transmission can be greatly improved, and the cost is effectively reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of communication encryption, and in particular relates to a lightweight voice encryption method and device for a digital walkie-talkie. Background Art

[0002] Walkie-talkie technology as a whole collects voice data, transmits it to the encryption module for encryption, and then sends it out by the RF module. The overall information transmission method is similar, and the information cannot be processed during transmission. The information can only be encrypted and decrypted end-to-end before transmission and after receipt.

[0003] At present, the main control MCUs related to walkie-talkies and encryption all use chips with good performance, such as STM32's high-performance voice and signal processing: STM32F7, STM32H7 series, STM32L4, STM32WB series, and STM32F4 series for low power consumption.

[0004] Compared with the above chips, the price of STM32F103C6T6 is much lower; STM32F103C6T6 is a microcontroller based on the ARMCortex-M3 core. It has certain computing power, storage capacity and multiple peripheral interfaces, but its performance is relatively low, especially when dealing with complex encryption algorithms (such as AES) and real-time voice intercom tasks.

[0005] AES (Advanced Encryption Standard) is a widely used symmetric encryption algorithm with different key lengths (128, 192, 256 bits), and each encryption round in the AES encryption process involves a lot of calculations. Although STM32F103C6T6 supports software acceleration of the AES algorithm, its software acceleration function is not comprehensive, and an external encryption chip is required to improve the overall hardware encryption performance, but this will increase costs. Summary of the invention

[0006] In order to solve at least one of the above technical problems existing in the prior art, the present invention provides a lightweight voice encryption method and device for a digital walkie-talkie.

[0007] The present invention is implemented by the following technical solution: a lightweight voice encryption method for a digital intercom, comprising the following steps:

[0008] Acquire the voice data to be encrypted; the voice data to be encrypted is acquired by the microphone module and is obtained through digital-to-analog conversion and PCM format switching;

[0009] Encrypting the voice data to be encrypted based on the AES encryption algorithm and the chacha20 stream encryption algorithm of the lightweight hybrid encryption module, and encrypting the AES encryption key based on the double-layer RSAq encryption algorithm of the lightweight hybrid encryption module;

[0010] The encrypted data and key are used to trigger the lightweight hybrid decryption module for decryption and voice playback through the power amplifier module.

[0011] Preferably, the lightweight hybrid encryption module includes two layers, the inner layer adopts a combination of block encryption and byte order encryption, that is, the voice data to be encrypted is encrypted by the AES encryption algorithm and the chacha20 stream encryption algorithm, and the outer layer uses a double-layer RSAq encryption algorithm to encrypt the inner layer key.

[0012] Preferably, the inner layer of the magnitude hybrid encryption module is used to achieve the purpose of data screening, and a counter is built in. When 10 packets are transmitted as chacha20 stream encryption, AES encrypted packets are transmitted, and one round of chahca20 stream encryption and AES encryption is used as an overall inner layer encryption;

[0013] The obtained ciphertext formula is as follows:

[0014]

[0015] c i =E k m i

[0016] Where: c i is the ciphertext, m i is the packet plaintext, which refers to the voice data to be encrypted, x i is the chacha20 stream key seed, E k It is the AES encryption function.

[0017] Preferably, a chacha20 key seed is generated based on a random number, and each key seed update is adjusted to 10 chacha20 encryption packages per update, and two buffer areas are set up, one for updating the chacha20 key seed value and the other for recording the current chacha20 key seed value to encrypt data;

[0018] In the process of sending 10 chacha20 data packets, the key seed value in the seed cache is updated for later updating of the actual key seed value; when the count value indicates that 10 chacha20 stream encryption packets have been sent, the value in the updated seed cache overwrites the current value in the key seed cache.

[0019] Preferably, before the double - layer RSAq encryption algorithm encrypts the AES encryption algorithm key, the key is subjected to truncated permutation using the default permutation numbers of both parties;

[0020] When initially generating the key, the prime factor p is built - in, and the large prime factor q is detected and generated using the Miller - Rabin primality test algorithm. Subsequently, the generated large prime factor q is stored in a file for use as the prime factor p next time. On this basis, it is named the RSAq encryption algorithm and placed in the inner layer. Combining the structural idea of the symmetric encryption algorithm in the middle, the public key and modulus length are hidden; another layer of optimized RSAq is used for protection in the outer layer.

[0021] Preferably, the modulus length n calculation and encryption formula are as follows:

[0022] n1 = p1×q1

[0023] φ(n1)=(p1 - 1)×(q1 - 1)

[0024]

[0025] (e i ,n i ) -> (e' i ,n' i )

[0026] n2 = p2×q2

[0027] φ(n2)=(p2 - 1)×(q2 - 1)

[0028]

[0029] Where: n is the modulus length value, p is the built - in prime factor, q is the large prime factor generated by the Miller - Rabin primality test algorithm, c i is the ciphertext, m is the plaintext, e is the public key, 1 < e < φ(n), and e and φ(n) are relatively prime. When i = 1, all symbols represent the characteristic numbers of the inner - layer encryption algorithm. When i = 2, all symbols represent the characteristic numbers of the outer - layer encryption algorithm. c1 serves as both the ciphertext obtained by inner - layer encryption and the plaintext for outer - layer encryption. The key is that the outer - layer RSAq encryption algorithm selects the first 250 bits of the ciphertext obtained by the inner - layer RSAq encryption algorithm as the plaintext for encryption. In subsequent use, different lengths of outer - layer plaintext can be randomly selected. In this article's examples, the outer - layer plaintext with a length of 250 bits is used in all cases. mod represents the modulo operation.

[0030] A lightweight voice encryption device for a digital walkie - talkie includes a microphone module, an A / D analog - to - digital conversion module, a PCM encoding / decoding module I, a lightweight hybrid encryption module, a Bluetooth module, a PCM encoding / decoding module II, a D / A digital - to - analog conversion module, a lightweight hybrid decryption module, and a power amplifier module;

[0031] The microphone module is used to obtain the voice information sent by the user, the A / D analog-to-digital conversion module PC is used to convert the digital signal into an analog signal, the PCM codec module I is used to switch the analog signal into a PCM format, and the lightweight hybrid encryption module is used to encrypt the voice data to be encrypted;

[0032] The lightweight hybrid encryption module is connected to the PCM codec module II via the Bluetooth module. The PCM codec module II is used to switch the PCM format data into analog signals. The D / A digital-to-analog conversion module is used to convert the analog signals into digital signals. The lightweight hybrid decryption module is used to decrypt the encrypted voice data. The power amplifier module is used to play the decrypted voice.

[0033] Preferably, a preprocessing module is provided before the lightweight hybrid encryption module, and the preprocessing module sets a high threshold value of 4000 and a low threshold value of 100 according to the range of sampling accuracy and the digital sampling value of the entire speaker to form a speech data group to be encrypted.

[0034] Compared with the prior art, the present invention has the following beneficial effects:

[0035] The present invention adopts a pre-processing threshold method to reduce the data volume and encrypts valid data. Combined with a lightweight hybrid encryption method, it can greatly improve the security and real-time performance of voice data transmission, solve the problem that low-performance development boards require external encryption chips to meet encryption requirements, and effectively reduce cost expenses. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0037] Figure 1 It is the overall structure diagram of the present invention;

[0038] Figure 2 It is a structural diagram of the lightweight hybrid encryption method of the present invention;

[0039] Figure 3 This is a processor structure diagram of the Cortex-M-based digital intercom encryption system and device of the present invention;

[0040] Figure 4 It is a structural diagram of the double-layer RSAq encryption algorithm involved in the lightweight hybrid encryption method of the present invention;

[0041] Figure 5 The scoring diagram is used for the Cortex-M-based digital intercom encryption system of the present invention;

[0042] Figure 6 It is a structural block diagram of the double-layer encryption algorithm of the present invention;

[0043] Figure 7 Schematic diagram of actual packet encryption processing DETAILED DESCRIPTION

[0044] In conjunction with the drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention are clearly and completely described. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other implementation methods obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0045] It should be noted that the structures, proportions, sizes, etc. illustrated in the drawings of this specification are only used to match the contents disclosed in the specification so that people familiar with this technology can understand and read them. They are not used to limit the conditions under which the present invention can be implemented, and therefore have no substantive technical significance. Any structural modification, change in proportional relationship or adjustment of size should fall within the scope of the technical contents disclosed in the present invention without affecting the effects and purposes that can be achieved by the present invention. It should be noted that in this specification, relational terms such as first and second are only used to distinguish one entity from several other entities, and do not necessarily require or imply any actual relationship or order between these entities.

[0046] The present invention provides an embodiment:

[0047] like Figure 1 As shown, a lightweight voice encryption device for a digital walkie-talkie includes a microphone module, an A / D analog-to-digital conversion module, a PCM codec module I, a lightweight hybrid encryption module, a Bluetooth module, a PCM codec module II, a D / A digital-to-analog conversion module, a lightweight hybrid decryption module and a power amplifier module; wherein the microphone module is used to obtain voice information sent by a user, the A / D analog-to-digital conversion module is used to convert a digital signal into an analog signal, the PCM codec module I is used to switch the analog signal into a PCM format, and the lightweight hybrid encryption module is used to encrypt voice data to be encrypted; the lightweight hybrid encryption module is connected to the PCM codec module II via the Bluetooth module, the PCM codec module II is connected to switch data in PCM format into an analog signal, the D / A digital-to-analog conversion module is used to convert the analog signal into a digital signal, the lightweight hybrid decryption module is used to decrypt the encrypted voice data, and the power amplifier module is used to play the decrypted voice.

[0048] A preprocessing module is also provided before the lightweight hybrid encryption module. The preprocessing module sets a high threshold of 4000 and a low threshold of 100 according to the range of sampling accuracy and the digital sampling value of the entire speaker to form a speech data group to be encrypted.

[0049] This embodiment also includes a digital walkie-talkie lightweight voice encryption method, comprising the following steps:

[0050] Acquire the voice data to be encrypted; the voice data to be encrypted is acquired by the microphone module and obtained through digital-to-analog conversion and PCM format switching; the voice data to be encrypted is encrypted based on the AES encryption algorithm and the chacha20 stream encryption algorithm of the lightweight hybrid encryption module, and the AES encryption key is encrypted based on the double-layer RSAq encryption algorithm of the lightweight hybrid encryption module; the encrypted data and key are used to trigger the lightweight hybrid decryption module for decryption and perform voice playback through the power amplifier module.

[0051] When the two parties establish communication in the double-layer encryption algorithm, they first send their public keys to each other. Both parties have a default substitution number. After receiving the public key, the public key is restored according to the default substitution number, and then the internal and external public keys are stored in the temporary storage area for encrypting the AES key. When sending data packets, both parties mark the AES key encrypted by the double-layer encryption algorithm, and set the header and tail of the packet to numbers that do not often overlap based on the length of the packet, such as 0xffff and 0xfffe, so as to facilitate different identification and processing of different packets. The AES encryption algorithm and the chacha20 stream encryption algorithm encrypt the plaintext, and then the AES key is scrambled by the double-layer RSAq encryption algorithm and transmitted to the receiver. After receiving the data packet, the receiver calls its own private key to decrypt the AES key package, and decrypts the data packet after obtaining the AES key.

[0052] Preferably, when the AES key is {1234567890abcdef}, the plain text is: "Hello, this is the sample data to be encrypted", the double-layer RSAq encryption encrypts the key to:

[0053] {d iLg6id I60jmCSH / v15eWQI J3hx5U65XVCSOaPmQQ0hg9vYuSHMq+N4LvQsQgYRF9HYzv0QQ6yE1 zGnBFnPOfStxoBNXGPueYVj+332CxPQn6ZrcoH8tO / B / aoifJQJEdr371S0kIey7ZBuMsQiv20v+qUHXmsH l5bPsOr3Vt4vLHcK8+H7C6TxMragS8LFZJha92MM7qdpZAkb+adppE / WRox5f5HCN5wI B / 0bYzjA1 B+1X1mhxHS4vUr7pT2wmmzDI l i92O93vBt+8eZZRAaB+P41 IdW7THgPquuPk0Fpsv4u+9+wcxsTIs07fKAZD382no / TdjyhF7x415xZfgA==$FQyTW+ZPy0YXFv6hbuwurBSck lAM1FwD877jFrLtqRTkmEPjP+DcsuH88I Fwc2au99CKc2bCCzw2NeuHj / M8TXqnX3UWQjAX6ET5vOJARPWGX7z+i8x9 l PfRU4ZI uucohukD6aMbO4L+SFajYjlCJGCcihtP5Ve / Oqs i IOyCWjnEF6s l uMk / ddBR1 i jzQF ZDzcf l T+erSvQ0eLpQURP6Yx33iD16Yo3BeFJ8K5ipT8J l+ / 9tx5GA4dL2MiUu1GD5tpnWZr62Hw9VMvVxq7pJYs7Gm9akgYa9ka0MLtz3bkOB16Xs / Lt / faKQSghbvx7iClWEcnbHCNwLmv2za+kMzw==4u iVJ0mNINKjW8LWK42tSjgjS9jTS3XquL9Qs+ctdSDff76I lZwK+A3eRy6vTL6cI uJe4sXWF / / 6e7sEiYXCLk5HwRiA===},

[0054] The plaintext is encrypted as:

[0055] {bda160ed15e89201 b08be57ff20bebfa3c9352aef6666f87a58b862f985d49fddc772bd82c3750d2a2b5d15ba9085a4f}, the private key and public key of the double-layer encryption algorithm are too long and are not shown.

[0056] like Figure 2 As shown, the lightweight hybrid encryption module includes two layers, the inner and outer layers, wherein the inner layer adopts a combination of block encryption and byte order encryption, that is, the voice data to be encrypted is encrypted by the AES encryption algorithm and the chacha20 stream encryption algorithm, and the outer layer uses a double-layer RSAq encryption algorithm to encrypt the inner key.

[0057] The principle of RSA encryption algorithm is based on the mathematical fact that "it is easy to multiply two large prime numbers, but it is very difficult to decompose the product into the original prime factors." This fact is used to generate public and private keys, improve the security factor of the key, and thus the overall security of RSA encryption algorithm is also quite high in the field of encryption. AES encryption algorithm includes five important parts: key expansion, round key addition, byte replacement, row shift, and column confusion. The encryption processing of plaintext includes both nonlinear transformation and linear transformation relationship, which is inherently highly secure. Since each step includes the participation of the key, the correlation between the key and the plaintext is relatively strong. When the cracker obtains the key or a part of the subkey, the difficulty of cracking the AES encryption algorithm is greatly reduced. Therefore, it is considered to choose to protect the key of the AES encryption algorithm in a targeted manner. As an encryption method with lower complexity than the AES encryption algorithm, chacha20 stream encryption has a fast data encryption speed and has a positive effect on the real-time processing of data.

[0058] The main connection between the outer layer and the inner layer lies in the encryption key of the inner layer. The inner key is encrypted using the high security of the double-layer RSAq encryption algorithm, and then the encrypted key is transmitted. Both parties improve the security of the key during the AES encryption process by transmitting the key encrypted by the outer double-layer RSAq encryption algorithm, so as to achieve the purpose of the outer layer protecting the inner layer. The inner layer implements a data screening part to control the encryption type of the transmission package. A counter is built in. When 10 packets are transmitted for chacha20 stream encryption, AES encrypted packets are transmitted. One round of chahca20 stream encryption and AES encryption is used as an overall inner layer encryption.

[0059] The double-layer RSAq encryption algorithm encrypts the AES encryption key, and the resulting ciphertext formula is as follows:

[0060]

[0061] c i =E k m i

[0062] Where: c i is the ciphertext, m i is the packet plaintext, which refers to the voice data to be encrypted, xi is the chacha20 stream key seed, E k It is the AES encryption function.

[0063] The chacha20 seed itself is generated and updated. When a new chacha20 stream encryption package is received, it means that the counter generated by the chacha20 seed will be updated, and the chacha20 key seed will be updated. When it is the turn of the chacha20 encryption package to be encrypted, the chacha20 key seed can be used to encrypt it directly.

[0064] It is worth noting that before the double-layer RSAq encryption algorithm encrypts the AES encryption algorithm key, it first uses the default permutation number of both parties to truncate the key, using almost zero execution time to increase the difficulty of cracking by crackers. The double-layer RSAq encryption algorithm uses space resources to save time resources based on the shortcoming that RSA prime number generation consumes more time resources;

[0065] When the key is generated for the first time, the prime factor p is built in, and the large prime factor q is generated using the Miller-Rabin primality test algorithm. The generated large prime factor q is subsequently stored in a file and used as the next prime factor p. On this basis, it is named the RSAq encryption algorithm and placed in the inner layer. The structural idea of ​​the symmetric encryption algorithm is combined in the middle to hide the public key and modulus length. The outer layer is protected by an optimized RSAq layer to improve security.

[0066] The calculation and encryption formula of the modulus length n is as follows:

[0067] n1=p1×q1

[0068] φ(n1)=(p1-1)×(q1-1)

[0069]

[0070] (e i ,n i )->(e' i ,n' i )

[0071] n2=p2×q2

[0072] φ(n2)=(p2-1)×(q2-1)

[0073]

[0074] Where: n is the modulus length, p is the built-in prime factor, q is the large prime factor generated by the Miller-Rabin primality test algorithm, c iLet c be the ciphertext, m be the plaintext, and e be the public key, where 1 < e < φ(n) and e and φ(n) are relatively prime. When i = 1, all symbols represent the characteristic numbers of the inner encryption algorithm; when i = 2, all symbols represent the characteristic numbers of the outer encryption algorithm. c1 serves as both the ciphertext obtained by inner-layer encryption and the plaintext for outer-layer encryption. The key lies in that the outer-layer RSAq encryption algorithm selects the first 250 bits of the ciphertext obtained by the inner-layer RSAq encryption algorithm as the plaintext for encryption. In subsequent use, different lengths of outer-layer plaintext can be randomly selected. In this example, the outer-layer plaintext is 250 bits long, and mod represents the modulo operation. And as Figure 6 shown, a permutation operation on the original modulus length n and the public key e is added between the inner and outer layers to confuse the attacker and increase the complexity.

[0075] See Figure 3 , the preferred embodiment is implemented in an actual scenario. With a cortex processor as the control kernel, a microphone is used to collect the analog signal of communication voice. The ADC is used for A / D analog-to-digital conversion to convert the collected audio analog signal into a PCM digital signal. Software is used to implement the data packing of the digital signal. After packing, it is handed over to the lightweight hybrid encryption module for processing. In this example, the lightweight hybrid module is completely implemented by software without the need to add an additional encryption software chip to implement the software function. The lightweight hybrid encryption method is implemented by improving the AES encryption algorithm in the software encryption library Crypto.lib and combining it with the double-layer RSAq encryption algorithm implemented by software. According to the actual design scenario of the chip's main frequency and real-time encryption, the AES encryption algorithm with a 128-bit key length is adopted. Among them, 4 collected encoding data packets are encrypted into one AES encryption packet by the AES encryption algorithm, and 8 are encrypted into one chacha20 encryption packet by the chacha20 encryption algorithm. That is, the AES encryption algorithm encrypts data in groups of 128 bits, and the chacha20 stream encryption encrypts audio data in groups of 256 bits. When the audio sampling frequency is 40Mhz, the encryption is performed in the way of 10 groups of chacha20 stream encryption packets followed by one AES encryption packet. Using the flash storage space of the chip, 4 temporary storage areas are manually set to store default prime numbers, cyclic prime numbers, and the keys of both parties at the initial stage of communication for information interaction.

[0076] During the data transmission process, after each sentence is sampled, the number of analog signals converted into digital signals is set according to the sampling frequency. Therefore, the digital signal data corresponding to each sentence is processed, and the digital signal is divided into AES encryption and stream encryption packets to propose an encryption model with a high security factor. The speed of the AES encryption algorithm is "compensated" by the fast chacha20 stream encryption, and the real-time voice encryption is realized on the STM32F103. Compared with ordinary XOR encryption, the key seed of chacha20 is obtained based on 20 rounds of mathematical operation cycles, which has high randomness and unpredictability. It uses a 256-bit key (32 bytes) and a 64-bit counter (8 bytes). The counter ensures that the key is updated in time and the key seed value will not be repeated. The key seed can be generated using a hardware random number generator. Figure 7 As shown, the present invention saves resources and uses software to generate chacha20 key seeds with random numbers, and ensures that each key seed update will not cause data delay, and each key seed update is adjusted to 10 chacha20 encryption packages per update, and two buffers are set up, one for updating the chacha20 key seed value, and the other for recording the current chacha20 key seed value to encrypt data; in the process of sending 10 chacha20 data packets, the key seed value of the update seed buffer is updated, which is used to update the actual key seed value later; when the count value indicates that 10 chacha20 stream encryption packages have been sent, the value of the update seed buffer covers the value of the current key seed buffer.

[0077] like Figure 4 As shown in the figure, it is a single-layer encryption algorithm structure diagram. In the figure, p1 is one of the prime factors p for subsequent key generation. When the key is generated for the first time, the prime factors in the temporary storage area are used as p for key generation, reducing the consumption of time resources for generating large prime factors. q is detected and generated using the Miller-Rabin algorithm, and the generated q is subsequently stored in a file for use as the next prime factor p, maintaining the variability of the overall encryption key.

[0078] After setting the timer working frequency to 40Mhz, that is, sending a packet of data every 25ms, the packaged digital signal is encrypted and the corresponding header and tail are added after 4 packets are full. After confirmation, the large packet is sent to the Bluetooth transmitter. After confirmation, the Bluetooth module sends the data. In practice, the processor core can be an ARM series core of Cortex-M3 and above, or the processor main frequency is like the benchmark, model STM32F103C6T6 and above, and can have TIMER timer peripherals. The most basic requirement is to be able to realize A / D analog-to-digital conversion function and D / A digital-to-analog conversion function. At present, chips basically have this condition.

[0079] like Figure 5In the preferred embodiment, 100 people are randomly selected to conduct subjective MOS quality evaluation on the communication decryption voice quality.

[0080] The participants were divided into five groups, with 20 people in each group using intercom communication in a relatively peaceful environment. After the cumulative use time reached 12 hours, their feelings about the intercom communication tool processed by this method were collected, and the evaluation scores were averaged. Figure 4 As shown by Figure 4 It can be seen that after using it for a period of time, the five groups of people were relatively satisfied with the use of the communication tools processed by the inventive method.

[0081] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be based on the protection scope of the claims.

Claims

1. A lightweight voice encryption method for a digital intercom, characterized in that: The following steps are involved: Acquire the voice data to be encrypted; the voice data to be encrypted is acquired by the microphone module and is obtained through digital-to-analog conversion and PCM format switching; Encrypting the voice data to be encrypted based on the AES encryption algorithm and the chacha20 stream encryption algorithm of the lightweight hybrid encryption module, and encrypting the AES encryption key based on the double-layer RSAq encryption algorithm of the lightweight hybrid encryption module; The encrypted data and key are used to trigger the lightweight hybrid decryption module for decryption and voice playback through the power amplifier module.

2. A lightweight voice encryption method for a digital intercom according to claim 1, characterized in that: The lightweight hybrid encryption module includes two layers, an inner layer and an outer layer, wherein the inner layer adopts a combination of block encryption and byte order encryption, that is, the voice data to be encrypted is encrypted by the AES encryption algorithm and the chacha20 stream encryption algorithm, and the outer layer uses a double-layer RSAq encryption algorithm to encrypt the inner layer key.

3. A lightweight voice encryption method for a digital intercom according to claim 2, characterized in that: The inner layer of the magnitude hybrid encryption module is used to achieve the purpose of data screening. A counter is built in. When 10 packets are transmitted as chacha20 stream encryption, AES encrypted packets are transmitted. One round of chahca20 stream encryption and AES encryption is used as an overall inner layer encryption. The obtained ciphertext formula is as follows: c i =E k m i Where: c i is the ciphertext, m i is the packet plaintext, which refers to the voice data to be encrypted, x i is the chacha20 stream key seed, E k It is the AES encryption function.

4. A lightweight voice encryption method for a digital intercom according to claim 3, characterized in that: Generate the chacha20 key seed based on random numbers, adjust each key seed update to 10 chacha20 encryption packages at a time, set up two cache areas, one for chacha20 key seed value update, and one for recording the current chacha20 key seed value to encrypt data; In the process of sending 10 chacha20 data packets, the key seed value in the seed cache is updated for later updating of the actual key seed value; when the count value indicates that 10 chacha20 stream encryption packets have been sent, the value in the updated seed cache overwrites the current value in the key seed cache.

5. A lightweight voice encryption method for a digital intercom according to claim 4, characterized in that: Before the double-layer RSAq encryption algorithm encrypts the AES encryption algorithm key, it first uses the default permutation number of both parties to truncate the key; When the key is generated for the first time, the prime factor p is built in, and the large prime factor q is generated using the Miller-Rabin primality test algorithm. The generated large prime factor q is subsequently stored in a file and used as the next prime factor p. On this basis, it is named the RSAq encryption algorithm and placed in the inner layer. The structural idea of ​​the symmetric encryption algorithm is combined in the middle to hide the public key and modulus length. The outer layer is protected by an optimized RSAq layer.

6. A lightweight voice encryption method for a digital intercom according to claim 5, characterized in that: The calculation and encryption formula of the modulus length n is as follows: n1=p1×q1 φ(n1)=(p1-1)×(q1-1) (e i ,n i )->(e' i ,n' i ) n2=p2×q2 φ(n2)=(p2-1)×(q2-1) Where: n is the modulus value, p is the built-in prime factor, q is the large prime factor generated by the Miller-Rabin primality test algorithm, c i is the ciphertext, m is the plaintext, e is the public key, 1 < e < φ(n), and e and φ(n) are relatively prime. When i is 1, all symbols represent the characteristic numbers of the inner encryption algorithm. When i equals 2, all symbols represent the characteristic numbers of the outer encryption algorithm. c1 serves as both the ciphertext obtained by inner encryption and the plaintext for outer encryption. The key lies in that the outer RSAq encryption algorithm selects the first 250 bits of the ciphertext obtained by the inner RSAq encryption algorithm as the plaintext for encryption. In subsequent use, different lengths of outer plaintext can be randomly selected. In this paper's examples, the outer plaintext with a length of 250 bits is used. mod represents the modulo operation.

7. A digital intercom lightweight voice encryption device, used to implement a digital intercom lightweight voice encryption method as claimed in any one of claims 1 to 6, characterized in that: It includes microphone module, A / D analog-to-digital conversion module, PCM codec module I, lightweight hybrid encryption module, Bluetooth module, PCM codec module II, D / A digital-to-analog conversion module, lightweight hybrid decryption module and power amplifier module; The microphone module is used to obtain the voice information sent by the user, the A / D analog-to-digital conversion module is used to convert the digital signal into an analog signal, the PCM codec module I is used to switch the analog signal into a PCM format, and the lightweight hybrid encryption module is used to encrypt the voice data to be encrypted; The lightweight hybrid encryption module is connected to the PCM codec module II via the Bluetooth module. The PCM codec module II is used to switch the PCM format data into analog signals. The D / A digital-to-analog conversion module is used to convert the analog signals into digital signals. The lightweight hybrid decryption module is used to decrypt the encrypted voice data. The power amplifier module is used to play the decrypted voice.

8. A lightweight voice encryption device for a digital intercom, characterized in that: A preprocessing module is also provided before the lightweight hybrid encryption module. The preprocessing module sets a high threshold of 4000 and a low threshold of 100 according to the range of sampling accuracy and the digital sampling value of the entire speaker to form a speech data group to be encrypted.

Citation Information

Patent Citations

  • Realizing method of voice communication identity authentication based on smart phone

    CN106060808A

  • End-to-end encrypted voice communication Bluetooth earphone and voice encryption method thereof

    CN115426648A

  • Audio anti-counterfeiting method, equipment and medium

    CN117979051A

  • Portable device with voice encryption and decryption functions

    TWM258513U

  • Improved authentication system

    WO2008030184A1