Wire telephone protection method and system based on analog isolation
The method and system convert digital and IP relay signals to analog for secure telephone communication, using physical isolation and dynamic security protocols to address the inadequacies of existing have-line telephone security, ensuring secure and efficient communication.
Patent Information
- Application Number
- CN202510782468.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-12
AI Technical Summary
The existing wired telephone security isolation protection solution is difficult to effectively protect telephone communication, especially the analog relay access method, which poses the risk of information leakage and external attacks.
The wired telephone protection method based on analog isolation is adopted to convert call requests from digital relay and IP relay access into analog signals, and through the "one chain, one isolation" physical barrier architecture, combined with multi-layer dynamic authentication and blocking mechanism, physical isolation channels are scanned and managed in real time, simulated link resources are dynamically allocated, and secure data processing is performed.
It realizes the full life cycle security protection of telephone communication, reduces the risks of external network attacks and signaling attacks, ensures the purity and security of communication content, and improves protection efficiency and reliability.
Smart Images

Figure CN120321334A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of telephone communication technologies, and in particular, to a wired telephone protection method and system based on analog isolation. Background Art
[0002] As a traditional communication method, wired telephone lines have long been widely used in various office environments. Since wired telephones need to be fixedly connected through physical lines and usually remain connected to the user's premises continuously, there may be information leakage in the user environment when there is no communication. On the other hand, there may also be a security risk of external attacks using physical lines.
[0003] There are mainly three general access methods for wired telephones: analog trunk access, digital trunk access, and IP trunk access. Currently, there are very few security isolation protection products for analog trunks, while traditional products based on network isolation cannot effectively protect digital trunk lines, and traditional network protection cannot completely achieve security protection for IP trunks.
[0004] In summary, the existing wired telephone security isolation protection solutions are difficult to effectively protect telephone communications. Summary of the Invention
[0005] This application provides a wired telephone protection method and system based on analog isolation, aiming to solve the problem that the existing wired telephone security isolation protection solutions are difficult to effectively protect telephone communications.
[0006] In a first aspect, this application provides a wired telephone protection method based on analog isolation, including: If the call request is a valid call request, unify the signals in the valid call request into a first analog signal, and allocate an analog link for the first analog signal as the first analog link; Turn on the physical isolation channel of the first analog link, while keeping the physical isolation channels of other analog links disconnected; where each analog link includes a physical isolation channel; Perform security data processing on the first analog signal to obtain a second analog signal after security data processing; Convert the second analog signal after security data processing into an output signal, and transmit the output signal to the called party; where the output signal is converted according to the protocol used in the valid call request.
[0007] As an embodiment, the physical isolation channel includes two isolated physical layers and a physical switch disposed between the two physical layers.
[0008] As an embodiment, in the case where the valid call request is a first digital signal, converting the first digital signal into a first analog signal specifically includes: Performing time slot decomposition on the first digital signal to obtain a plurality of decoupled second digital signals; Converting each second digital signal into a third analog signal as the first analog signal; And, allocating a first analog link for each third analog signal.
[0009] As an embodiment, in the case where the valid call request is a broadband telephone signal, converting the broadband telephone signal into a first analog signal specifically includes: Parsing the protocol stack composed of the Session Initiation Protocol and the Real-Time Transport Protocol in the Internet; Converting the first voice stream in the broadband telephone signal into an analog baseband signal according to the protocol stack; Converting the analog baseband signal into a first analog signal.
[0010] As an embodiment, the wired telephone protection method further includes: Real-time automatically scanning the status of the physical isolation channels of all analog links to obtain idle physical isolation channels; In response to the occurrence of a valid call request, binding at least one first analog link corresponding to an idle physical isolation channel to the valid call request; If the call ends or the call duration reaches the threshold, unbinding the valid call request from all first analog links, restoring the status of the physical isolation channels corresponding to all first analog links to idle, and erasing the temporary data of all first analog links.
[0011] As an embodiment, if there is an abnormality in the physical isolation channel, unbind the valid call request from all first analog links, restore the status of the physical isolation channels corresponding to all first analog links to idle, and trigger an alarm log.
[0012] As an embodiment, the wired telephone protection method further includes: Configuring a security protection policy for each physical isolation channel, and dynamically adjusting the encoding parameters and isolation levels in the security protection policy according to the call scenario at the time of binding.
[0013] As an embodiment, the wired telephone protection method further includes: Real-time collecting the signal strength, encoding integrity and status of the physical switch of the first analog link, and combining with the dynamic permission allocation and authentication mechanism to perform millisecond-level cut-off on the abnormal access behavior of the first analog link.
[0014] As an embodiment, the wired telephone protection method further includes: Generate a log chain for channel operations and permission changes of the physical isolation channel.
[0015] As an embodiment, if there is no idle physical isolation channel, enter the waiting queue management policy, and at the same time trigger the elastic expansion mechanism to dynamically expand the capacity of the physical isolation channel.
[0016] As an embodiment, if a physical isolation channel fails, mark the physical isolation channel as faulty and classify the physical isolation channel into the isolation area.
[0017] As an embodiment, determine whether a call request is a valid call request, specifically including: Perform legalization verification on the number coding rule of the call request; If the number coding rule is legal, perform two-way identity authentication on the caller and the callee; If the two-way identity authentication passes, the call request is a valid call request.
[0018] As an embodiment, perform security data processing on the valid call request, specifically including: Inject dynamic noise into the first analog signal and perform real-time lossy re-encoding on the first analog signal.
[0019] As an embodiment, performing security data processing on the valid call request further includes: Real-time analyze the time-frequency distribution characteristics of the first analog signal to determine the abnormal energy distortion in the first analog signal; For the abnormal energy distortion, adopt the dynamic spectrum masking mechanism to irreversibly erase the illegal data embedded in the covert channel corresponding to the abnormal energy distortion.
[0020] As an embodiment, performing security data processing on the valid call request further includes: If it is detected that the first analog signal has an abnormal data structure, immediately cut off the first analog link and trigger dynamic noise injection to achieve physical layer hard isolation of the attack surface.
[0021] In a second aspect, the present application further provides a wired telephone protection system based on analog isolation, including a first proxy module, a first channel management module, a second channel management module, a second proxy module, and a plurality of mutually isolated analog links; The first proxy module is used to determine whether a call request is a valid call request; The first channel management module is used to, when the call request is a valid call request, allocate the analog link of the calling end for the first analog signal as the first analog link; and conduct the physical isolation channel of the first analog link, while the physical isolation channels of the analog links of other calling ends remain disconnected; Each analog link includes a physically isolated channel, which is used to perform security data processing on a first analog signal corresponding to a valid call request to obtain a second analog signal after the security data processing; The second channel management module is used to allocate an analog link of the called end for the second analog signal; The second proxy module is used to convert the second analog signal into an output signal and transmit the output signal to the called party; wherein, the output signal is obtained by conversion according to the protocol used in the valid call request.
[0022] As an embodiment, the first proxy module is further used to convert a digital signal into a first analog signal when the valid call request is a digital signal.
[0023] As an embodiment, the physically isolated channel includes a hardware decoding module and a hardware-based lossy coding module; The hardware decoding module performs decoding processing on the signal; The hardware-based lossy coding module is used to perform time-varying distortion processing on the signal to obtain a second analog signal after the security data processing.
[0024] As an embodiment, the hardware decoding module is used to convert a first voice stream in a broadband telephone signal into an analog baseband signal according to the protocol stack of the broadband telephone signal when the valid call request is a broadband telephone signal; The hardware-based lossy coding module is used to convert the analog baseband signal into a first analog signal. Brief Description of the Drawings
[0025] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0026] Figure 1 is one of the flow schematic diagrams of the wired telephone protection method based on analog isolation provided by the present application; Figure 2 is another flow schematic diagram of the wired telephone protection method based on analog isolation provided by the present application; Figure 3 is the flow schematic diagram of judging whether a call request is a valid call request provided by the present application; Figure 4 is the flow schematic diagram of the dynamic allocation mechanism of the analog link provided by the present application; Figure 5 is one of the structural schematic diagrams of the wired telephone protection system based on analog isolation provided by the present application; Figure 6 It is a schematic structural diagram of the first proxy module provided by this application; Figure 7 It is the second schematic structural diagram of the wired telephone protection system based on analog isolation provided by this application; Figure 8 It is a schematic structural diagram of the physical isolation module provided by this application; Figure 9 It is a schematic structural diagram of the first channel management module provided by this application. Detailed implementation manners
[0027] To make the objectives, technical solutions and advantages of this application clearer, the technical solutions in this application will be clearly and completely described below with reference to the accompanying drawings in this application. Apparently, the described embodiments are some but not all of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0028] It should be noted that in the description of this invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitations, the element defined by the phrase "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0029] The terms "first", "second", etc. in this invention are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this invention can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of the same type, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.
[0030] Next, in combination with Figures 1 to 9 Describe the wired telephone protection method and system based on analog isolation provided by this application.
[0031] It should be noted that the wired telephone protection method based on analog isolation provided in the embodiments of the present application is implemented based on a wired telephone protection system based on analog isolation. The wired telephone protection method based on analog isolation first converts the call requests accessed by digital trunks and IP trunks into analog signals, and cooperates with the physical barrier architecture of "one link, one isolation" to fundamentally defend against external network attacks and signaling attack behaviors.
[0032] In the embodiments of the present application, the wired telephone protection method based on analog isolation is described by taking the wired telephone protection system based on analog isolation as the execution subject.
[0033] Figure 1 It is one of the flow diagrams of the wired telephone protection method based on analog isolation provided by the present application. Figure 2 It is the second flow diagram of the wired telephone protection method based on analog isolation provided by the present application.
[0034] As Figure 1 shown, the wired telephone protection method based on analog isolation provided by the present application includes: S110: If the call request is a valid call request, unify the signals in the valid call request into a first analog signal, and allocate an analog link for the first analog signal as the first analog link.
[0035] Specifically, if the valid call request is accessed through a digital trunk or an IP (Internet Protocol) trunk, convert the signals in the valid call request into a first analog signal, and then perform security data processing on the first analog signal. If the valid call request is accessed through an analog trunk, use the analog signal as the first analog signal.
[0036] There are multiple analog links in the wired telephone protection system, and the analog links perform telephone communication based on analog signals.
[0037] S120: Conduct the physical isolation channel of the first analog link, while keeping the physical isolation channels of other analog links in a disconnected state.
[0038] Each analog link includes an independent physical isolation channel. That is to say, the physical isolation channels of different analog links are isolated from each other, thus forming a "one link, one isolation" barrier architecture. The default state of each physical isolation channel is disconnected, and it is only conducted when there is a communication requirement. When the physical isolation channel of the first analog link is conducted, the physical isolation channels of other analog links remain disconnected.
[0039] S130: Perform security data processing on the first analog signal to obtain a second analog signal after security data processing.
[0040] When performing security data processing on a valid call request, insecure data in the valid call request can be processed to eliminate security hazards and obtain a secure second analog signal.
[0041] S140: Convert the second analog signal after security data processing into an output signal and transmit the output signal to the called party.
[0042] Among them, the output signal is obtained by conversion according to the protocol used in the valid call request. Specifically, if the valid call request is accessed through a digital trunk or an IP trunk, the output signal is a digital signal or an IP signal. If the valid call request is accessed through an analog trunk, the output signal is an analog signal.
[0043] Please combine Figure 2 When the calling party initiates a call request, after the call request accesses the wired telephone protection system, first determine whether the call request is a valid call request; if so, unify the signals in the valid call request into a first analog signal, and allocate a first analog link to each first analog signal and conduct the physical isolation channel of the first analog link; subsequently, perform security data processing on the first analog signal to obtain a second analog signal, and then convert the second analog signal into an output signal adapted to the protocol used in the call request, and output the output signal to the called party.
[0044] Both digital signals and IP signals involve data transmission with signaling formats and belong to pure digital communication methods. Therefore, in the data transmission process of digital signals and IP signals, there are many uncertain attack risks, such as signaling attacks. The analog link itself does not transmit any signaling data and only allows voice signals to pass through, which can effectively ensure the purity of telephone communication content. In addition, for traditional analog telephones, because the physical line is always in a conducting state, a security hazard still exists in the non-call state, and attackers can use the line for real-time passive eavesdropping. This "always-on and continuous" physical characteristic makes there always be a blind spot in security protection.
[0045] Based on the above, after the embodiments of the present application identify a valid call request, they first convert the call requests accessed through digital trunks and IP trunks into analog signals. On this basis, each analog link is provided with a physical isolation channel to form a physical barrier architecture of "one link, one isolation", ensuring hardware-level inherent security and cutting off the possibility of covert channels, side-channel attacks, and malicious code implantation from the root; and, according to the required conduction demand, the number of analog links is conducted, and other analog links remain disconnected, and the physical connection is disconnected immediately after the call ends, compressing the high-risk communication window to the second level. The embodiments of the present application form differentiated advantages from the prior art in three dimensions of security, reliability, and compliance, thereby fundamentally reducing the risks of being attacked by external networks, signaling attacks, etc.
[0046] In the existing wired telephone protection system, the two-way authentication mechanism can neither verify the identity of the calling party nor effectively authenticate the legality of the called party. This one-way authentication mode allows attackers to exploit protocol vulnerabilities to conduct line eavesdropping. When an external attacker initiates a malicious harassing call, the protection system lacks dynamic control over the black and white lists, resulting in the communication channel being exposed to the risk of illegal occupation for a long time.
[0047] Based on the above considerations, in a possible embodiment, a multi-layer dynamic authentication and blocking mechanism is adopted to achieve end-to-end security control. As Figure 3 shown, it is determined whether the call request is a valid call request, which specifically includes: P1: Legitimize the number coding rule of the call request to verify the legality of the number format (such as international coding specifications, number of valid digits, etc.). If the number is illegal, block it immediately.
[0048] P2: If the number coding rule is legal, perform two-way identity authentication on the calling party and the called party.
[0049] As Figure 3 shown, in a possible embodiment, the two-way identity authentication sequentially includes calling party identity authentication, adaptive black and white list check at the calling party end, and legality verification at the called party end.
[0050] Specifically, in the calling party identity authentication, the authenticity of the calling party identity is verified through a digital certificate or a hardware token. If the authentication fails (such as abnormal permissions), terminate the process and generate a security alert.
[0051] After the calling party identity is passed, start communication policy control and call the adaptive black and white list check module: If the calling party is in the white list, directly release it and enter the legality verification process of the called party.
[0052] If the calling party is in the black list, block it immediately and mark it as a high-risk source, and synchronously update the adaptive policy.
[0053] If the calling party is an unknown calling party, analyze the call behavior characteristics of the calling party (such as call frequency, historical records, etc.). If there are abnormal behaviors (such as high-frequency calls, requests during non-working hours, sudden traffic at night, etc.), trigger an immediate block.
[0054] In the legality verification process of the called party, verify the device fingerprint, authorization status, etc. After passing the verification, execute P3.
[0055] P3: If the two-way identity authentication passes, the call request is a valid call request.
[0056] In any of the above authentication processes, the tamper - blocking alarm unit can be activated as needed. Then, the physical layer cuts off the analog link and generates a tamper - proof log. At the same time, the adaptive policy is dynamically updated (such as adding blacklist entries, adjusting risk thresholds, etc.) to form a closed - loop protection system of "attack discovery → policy optimization → active defense". In the embodiment of the present application, the identification of valid call requests is realized through the four - level linkage of "rule filtering → identity authentication → policy control → dynamic blocking", achieving millisecond - level interception of strange calls, ensuring millisecond - level real - time blocking of the channel and full - link identity trustworthiness; through the full - process closed - loop protection of "identity trustworthiness → policy controllability → communication traceability", the "passive answering" of the traditional telephone network is upgraded to "active - defense communication", achieving the protection goal of "legitimate users are unaware, and illegal attacks cannot enter".
[0057] In a possible embodiment, in step S110, when the valid call request is a first digital signal (E1 or T1 digital signal), converting the first digital signal into a first analog signal specifically includes: R1: Decompose the first digital signal by time slots to obtain multiple decoupled second digital signals.
[0058] R2: Convert each second digital signal into a third analog signal as the first analog signal.
[0059] Specifically, each second digital signal is converted into a third analog signal through existing digital - to - analog conversion technology, and the present application does not limit this.
[0060] Moreover, based on the above, when the valid call request is a first digital signal, in step S110, allocate a first analog link to each third analog signal.
[0061] In a possible embodiment, each decoupled second digital signal is converted into an independent third analog signal through analog signal reconstruction technology and then independently injected into the corresponding analog link.
[0062] In the embodiments of the present application, the time-slot dynamic decoupling technology decomposes the time slots of E1 or T1 digital signals, breaking the continuity feature of the traditional time-division multiplexing architecture; during the analog signal reconstruction process, only the voice baseband signal is retained, stripping the out-of-band signaling and metadata of the digital relay, and preventing covert data transmission using protocol vulnerabilities from the physical layer; on this basis, the corresponding number of analog link resources is dynamically allocated in real time according to communication requirements. The coordinated work of dynamic allocation and channel management ensures that each analog link is only temporarily activated during the authorized period, and only a temporary link is dynamically generated during the authorized time slot, transforming the permanent attack surface of the digital relay into a dynamically reconfigurable temporary communication window, making it impossible for attackers to stay for a long time or preset malicious payloads, and effectively defending against various attack means against digital relays. Further, through the technical path of "digital decoupling → analog reconstruction → physical isolation → dynamic allocation", while being compatible with the existing digital relay network, the continuous attack surface of digital communication is completely isolated, especially suitable for threats such as covert channels and supply chain attacks, and the full-life-cycle security protection of digital relay signals can be achieved.
[0063] In a possible embodiment, in step S110, when the effective call request is a broadband telephone signal (IP signal), converting the broadband telephone signal into a first analog signal specifically includes: S1: Analyze the protocol stack composed of the Session Initiation Protocol and the Real-Time Transport Protocol in the Internet. Specifically, deeply analyze the SIP (Session Initiation Protocol) / RTP (Real-Time Transport Protocol) protocol stack in the Voice over Internet Protocol (VoIP) network of the Internet.
[0064] S2: Convert the first voice stream in the broadband telephone signal into an analog baseband signal according to the protocol stack.
[0065] Specifically, perform physical layer signal reconstruction on the first voice stream and convert it into an analog baseband signal.
[0066] S3: Convert the analog baseband signal into a first analog signal.
[0067] Specifically, use the existing technology to convert the analog baseband signal into a first analog signal, and the present application does not limit this.
[0068] In the embodiment of the present application, the IP signal is converted into an analog signal, and a "security barrier from network to voice" is constructed, which completely eliminates the attack paths based on protocol vulnerabilities such as SIP flooding attack, RTP injection, and signaling hijacking. Even if the attacker has mastered the 0-day vulnerability, he cannot penetrate the physical isolation channel; and after the voice signal is reconstructed by physical layer simulation, the attacker cannot locate the target network topology or implement side channel attacks through traffic analysis. Further, combined with the on-off control of the physical isolation channel of the analog link, the embodiment of the present application constructs the physical layer security boundary of the IP telephone system through the protection architecture of "digital protocol decoupling → analog signal reconstruction", completely cuts the high-risk digital domain of the VoIP network from the intrinsically safe analog domain, and can effectively defend against VoIP protocol stack attacks and penetration attacks that exploit PBX (Private Branch Exchange, user switch) vulnerabilities; through the three-level protection of "digital protocol decoupling → analog signal reconstruction → dynamic link isolation", the permanent digital attack surface of the VoIP network is converted into a temporary analog communication window, and a "digital → analog" security boundary that attackers cannot penetrate is constructed, which completely defends against threats such as protocol stack malformed packet attacks and PBX vulnerability lateral penetration.
[0069] In a possible embodiment, the physical isolation channel includes two mutually isolated physical layers and a physical switch arranged between the two physical layers.
[0070] In the embodiment of the present application, the physical isolation module realizes complete isolation of the physical layer of each analog link through the linkage control of the hardware isolation layer and the physical switch, forming a "one chain one isolation" barrier architecture.
[0071] The existing wired telephone protection system lacks an effective detection mechanism for the least significant bit (LSB) steganographic attack. Attackers can transmit data through the channel. Therefore, the existing protection system cannot effectively prevent attacks such as abnormal data inclusion and data steganography in voice calls.
[0072] Based on the above considerations, in a possible embodiment, in step S130, security data processing is performed on the valid call request, specifically including at least one of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation: Q1: Dynamic quantization noise injection: dynamic noise is injected into the first analog signal to perform real-time lossy re-encoding on the first analog signal.
[0073] Specifically, the quantization step size is dynamically adjusted through a non-linear quantization algorithm, and real-time lossy re-encoding is performed on the first analog signal (pulse code modulation (PCM) voice stream). High-frequency details above 8 kHz are selectively discarded (such as the high-frequency band commonly used for steganographic carriers), and low-energy signal components are accurately removed (such as micro data fragments lurking in background noise), directly destroying data embedding carriers such as LSB steganography and frequency-domain watermarking, and retaining the core voice frequency band of 300 - 3400 Hz.
[0074] In the embodiment of the present application, through hardware-level dynamic noise injection, while retaining the fidelity of the core voice frequency band of 300 - 3400 Hz, the physical basis of high-frequency steganographic attacks is completely disrupted, greatly increasing the bit error rate of steganography, building a secure communication defense line of "being able to hear clearly but unable to take away", and fundamentally disrupting the high-risk behavior of using the voice channel for data theft without reducing the call quality.
[0075] Q2: Adaptive spectrum shaping: Real-time analyze the time-frequency distribution characteristics of the first analog signal to determine abnormal energy distortion in the first analog signal; for the abnormal energy distortion, adopt a dynamic spectrum masking mechanism to irreversibly erase the illegal data embedded in the hidden channel corresponding to the abnormal energy distortion.
[0076] Specifically, the wavelet domain threshold filtering technology is adopted to real-time analyze the time-frequency distribution characteristics of the first analog signal. For abnormal energy distortion in the silent period or high-frequency band (such as the non-voice frequency band exploited by Asymmetric Digital Subscriber Line (ADSL) attacks), start the dynamic spectrum masking mechanism: through adaptive adjustment of the energy threshold and frequency band selective attenuation, irreversibly erase the illegal data embedded in the hidden channel.
[0077] The embodiment of the present application combines hardware-level spectrum shaping logic to ensure that only the energy distribution of the frequency band conforming to the voice characteristics is retained, fundamentally blocking data embedding transmission using the voice silent period or spectrum gap.
[0078] Q3: Hardware-level security isolation: If an abnormal data structure is detected in the first analog signal, immediately cut off the first analog link and trigger dynamic noise injection to achieve physical layer hard isolation of the attack surface.
[0079] Specifically, in a possible embodiment, the signal processing logic is solidified based on a Field Programmable Gate Array (FPGA) to prevent tampering with the encoding and decoding process by software layer bypass attacks. Once an abnormal data structure (such as a deformed packet or residual steganographic trace) is detected, immediately cut off the current analog link and trigger dynamic noise injection to achieve physical layer hard isolation of the attack surface.
[0080] The embodiment of the present application combines the hardware protection layer with the dynamic randomization strategy to form a three-dimensional defense system of "logic cannot be tampered + parameters cannot be predicted + links can be cut off".
[0081] Based on the above, while using the three strategies of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation at the same time, through the three-order collaboration of "dynamic quantization interference → spectrum intelligent purification → hardware logic isolation", the stealth carrier destruction, spectrum anomaly cleaning and physical link disconnection are completed within millisecond delays, ensuring the fidelity of voice signals in the core frequency band, and achieving real-time blocking and trace erasure of data entrainment attacks.
[0082] Based on the above, a plurality of analog links are provided in the wired telephone protection system. On this basis, the wired telephone protection method also includes a dynamic allocation mechanism of the analog links. Figure 4 As shown, the dynamic allocation mechanism of the analog link specifically includes: S410: Automatically scan the status of the physical isolation channels of all analog links in real time to obtain idle physical isolation channels.
[0083] During the physical isolation channel creation and initialization phase, a unique channel ID is automatically generated for each physical isolation channel of the analog link to complete the physical mapping of hardware resource binding and analog links.
[0084] S420: If there are enough idle physical isolation channels, in response to a valid call request, a first analog link corresponding to at least one idle physical isolation channel is bound to the valid call request to complete the call establishment.
[0085] S430: If the call ends or the call duration reaches a threshold, the valid call request is unbound from all first analog links, the status of the physical isolation channels corresponding to all first analog links is restored to idle, and the temporary data of all first analog links is erased.
[0086] The embodiment of the present application adopts a dynamic channel management mechanism to automatically scan and obtain idle channels, complete the binding of channels with valid call requests, and automatically unbind the channels after the call ends or the call duration reaches a threshold, erase temporary data and recycle resources for reuse by subsequent requests. Thus, through the full life cycle management of "dynamic allocation → physical isolation → status monitoring → resource recovery", the safe processing of large-scale high-concurrency call requests is achieved (the channel reuse rate is increased by more than 60%, and the hardware resource consumption is reduced by 30%), and the "one chain and one isolation" hardware structure is used to ensure that the physical layers of multi-channel communications do not interfere with each other, thereby achieving high-density communication, millisecond-level response and isolated transmission; and in this process, the physically isolated channel is activated on demand, and the exposure time window is controllable, which can block latent attacks.
[0087] Based on the above, in a possible embodiment, the dynamic allocation mechanism of the analog link further includes: If there is an abnormality in the physical isolation channel, the valid call request will be untied from all the first analog links, the status of the physical isolation channels corresponding to all the first analog links will be restored to idle, and an alarm log will be triggered.
[0088] The embodiment of the present application adopts an abnormal cut-off mechanism to ensure the security of the physically isolated channel, and records abnormal information through an alarm log to facilitate subsequent tracing.
[0089] Furthermore, the dynamic allocation mechanism of the analog link also includes: If there is no idle physical isolation channel, the new request will be rejected and the resource occupation will be prompted, and the waiting queue management strategy will be implemented to avoid the risk of overload. At the same time, the elastic expansion mechanism will be triggered to dynamically expand the capacity of the physical isolation channel.
[0090] In the embodiment of the present application, a rejection occupancy strategy is adopted to avoid overload when there are no idle channels, thereby ensuring communication quality, while dynamically expanding channel capacity and improving processing efficiency.
[0091] Furthermore, the dynamic allocation mechanism of the analog link also includes: If there is a fault in the physical isolation channel, the physical isolation channel will be marked as a fault and the physical isolation channel will be placed in the isolation area.
[0092] The embodiment of the present application isolates the faulty channel to prevent it from being turned on again, thereby ensuring call safety.
[0093] Based on the above, the wired telephone protection method provided by the present application also includes the management of the physical isolation channel, specifically including: A security protection strategy is configured for each physically isolated channel. The encoding parameters and isolation level in the security protection strategy are dynamically adjusted according to the call scenario during binding.
[0094] In an embodiment of the present application, during the channel creation and initialization stage, a preset security protection strategy is loaded for each physically isolated channel. During use, the security protection strategy of each physically isolated channel is independently and dynamically adjusted according to the call scenario during binding, so that each physically isolated channel has an independent security protection strategy, ensuring that calls with different security levels have differentiated protection strategies.
[0095] Furthermore, the management of physically isolated channels also includes: The signal strength, coding integrity and status of the physical switch of the first analog link are collected in real time, and combined with the dynamic permission allocation and authentication mechanism of the physical isolation channel, abnormal access behavior of the first analog link is cut off at the millisecond level.
[0096] In the embodiments of the present application, by monitoring the channel status in real time and cutting off in milliseconds during abnormal access, the efficiency of security protection is improved, and the probability of the wired telephone protection system being attacked is greatly reduced.
[0097] Furthermore, the management of the physical isolation channel further includes: Generating a log chain for the channel operations, permission changes, and device status of the physical isolation channel.
[0098] In the embodiments of the present application, by generating a log chain, a tamper-proof audit trail is formed, which is beneficial to tracing and later updating and correcting the management strategy of the physical isolation channel.
[0099] It can be understood that in the embodiments of the present application, the operation permissions for the physical management channel (such as on / off permission, configuration modification permission) can be dynamically granted and revoked through a visual interface.
[0100] Based on the above, the present application also provides a wired telephone protection system based on analog isolation. The wired telephone protection system based on analog isolation and the above-mentioned wired telephone protection method based on analog isolation can be correspondingly referred to each other.
[0101] As an embodiment, as Figure 5 shown, the wired telephone protection system includes a first proxy module, a first channel management module, a second channel management module, a second proxy module, and a plurality of mutually isolated analog links.
[0102] The first proxy module is used to determine whether a call request is a valid call request.
[0103] The first channel management module is used to, when the call request is a valid call request, allocate the analog link of the calling end for the first analog signal as the first analog link. And conduct the physical isolation channel of the first analog link, while the physical isolation channels of the analog links of other calling ends remain disconnected.
[0104] Each analog link includes a physical isolation channel, and the physical isolation channel is used to perform security data processing on the first analog signal corresponding to the valid call request to obtain a second analog signal after security data processing.
[0105] The second channel management module is used to allocate the analog link of the called end for the second analog signal.
[0106] The second proxy module is used to convert the second analog signal after security data processing into an output signal and transmit the output signal to the called party. Wherein, the output signal is obtained by conversion according to the protocol used in the valid call request.
[0107] In the embodiments of the present application, call requests accessed through digital trunks and IP trunks are first converted into analog signals. On this basis, each analog link is provided with a physically isolated channel, forming a physical barrier architecture of "one link, one isolation". According to the required number of conductive analog links, other analog links remain disconnected, thereby fundamentally reducing the risks of external network attacks, signaling attacks, etc. In addition, in the embodiments of the present application, the proxy modules of the calling party and the called party are separated and designed, realizing the decoupling of signal processing and protocol conversion, improving the processing efficiency of signal processing and protocol conversion, and reducing the mutual influence of signal processing and protocol conversion.
[0108] Specifically, as Figure 6 shown, the first proxy module includes a first protocol recognition module, a first analog proxy module, a first digital proxy module, and a first IP proxy module. The first protocol recognition module is used to identify whether the call request is in the analog trunk access mode, digital trunk access mode, or IP trunk access mode. The first analog proxy module is used to authenticate the call request accessed through the analog trunk and determine whether the call request is a valid call request. The first digital proxy module is used to authenticate the call request accessed through the digital trunk and determine whether the call request is a valid call request. The first IP proxy module is used to authenticate the call request accessed through the IP trunk and determine whether the call request is a valid call request.
[0109] The embodiments of the present application support cross-system signal hybrid processing, improving the versatility of the wired telephone protection system.
[0110] Among them, if the valid call request is accessed through the digital trunk, the first proxy module (specifically, the first digital proxy module) converts the first digital signal in the valid call request into a first analog signal, and then the physical isolation channel performs security data processing on the first analog signal. Specifically, it includes: decomposing the first digital signal into time slots to obtain multiple decoupled second digital signals; converting each second digital signal into a third analog signal as the first analog signal.
[0111] If the valid call request is accessed through the analog trunk, the first analog proxy module uses the analog signal as the first analog signal.
[0112] Please combine Figure 7 , the first channel management module is used to allocate a calling-end analog link for each first analog signal, and the second channel management module is used to allocate a called-module link for the second analog signal after security data processing output by the physical management channel, for outputting the output signal to the called party, and establishing an end-to-end communication link through the calling-end analog link and the called-end analog link.
[0113] In a possible embodiment, as Figure 9As shown in the figure, the first channel management module includes a channel creation and initialization unit, a status monitoring and on / off expansion unit, a channel release and resource recovery unit, a binding configuration and policy loading unit, a dynamic permission allocation and authentication unit, and a full-link logging unit.
[0114] The channel creation and initialization unit is used to automatically generate a unique channel ID for each physically isolated channel and load preset security policies during the channel creation and initialization phase, and complete the binding of hardware resources and the physical mapping of the simulation link.
[0115] The status monitoring and on / off expansion unit is used to collect the signal strength, coding integrity, and physical switch status of each simulation link in real time, and combine with the dynamic permission allocation and authentication mechanism to cut off abnormal access behaviors at the millisecond level.
[0116] The channel release and resource recovery unit is used to automatically unbind the physically isolated channel, reset the physical switch status, and erase the temporary cache data when the call ends.
[0117] The binding configuration and policy loading unit is used to dynamically adjust the coding parameters and isolation levels according to the call scenario to ensure that sessions with different security levels match differentiated protection policies.
[0118] The dynamic permission allocation and authentication unit is used to dynamically grant and revoke the operation permissions for the physically isolated channel (such as on / off permissions, configuration modification permissions, etc.) through a visual interface.
[0119] The full-link logging unit is used to record channel operations, permission changes, and device status to form an anti-tampering audit trail.
[0120] It can be understood that the second channel management module has the same functions and structure as the first channel management module. After the first channel management module conducts the physically isolated channel of the analog link at the calling end, if the signal of the call request is successfully transmitted to the second channel management module, the second channel management module will conduct the physically isolated channels of the corresponding number of analog links at the called end. If the call ends, the call times out, or the call is abnormal, etc., and disconnection is required, both the first channel management module and the second channel management module will unbind the current call request from the corresponding physically isolated channel.
[0121] In the embodiments of the present application, the channel management module realizes the intelligent management of the entire process of calls. By dynamically allocating call channels, dynamically binding features such as channel ID and physical port mapping, and time slots, it ensures that channel resources cannot be maliciously hijacked or counterfeited. And by dynamically allocating channel bandwidth and priority on demand, the line utilization rate is increased by more than 30%. At the same time, there is a channel self-destruction mechanism that immediately clears information such as channel ID and cached data after the call is terminated, ensuring that attackers cannot recover sensitive information. Through the full-cycle control of "creation - operation - destruction", the channel management module transforms communication channels from "static resources" into "dynamic security assets", realizing an active defense system of "visible risks, adjustable resources, and defendable attacks".
[0122] As Figure 5 and Figure 7 shown, there are multiple physical isolation modules between the first channel management module and the second channel management module. Its structural form can be multiple independent physical isolation modules (such as Figure 5 the physical isolation module in the upper part and Figure 7 all the physical isolation modules shown), or it can form a physical isolation array (such as Figure 5 the physical isolation array in the lower part shown).
[0123] In a possible embodiment, the physically isolated channel includes two physically isolated physical layers and a physical switch disposed between the two physical layers. Under normal system conditions (when there is no call requirement), the physically isolated channel maintains the open state of the physical layer, and only dynamically establishes a call link during the effective call period to form an "air gap" protection.
[0124] Specifically, the physical switch can be constructed with an industrial-grade electromagnetic relay to build a double-break isolation barrier, and keep the physical layers of both sides of the line completely separated when there is no effective communication requirement.
[0125] As Figure 8 shown, when there is no communication, the physical switch keeps both sides of the line completely open, ensuring the fully isolated state of the two channels of the analog isolation module, such as Figure 8 the physical switches of the analog links 2 to N inside. When there is a call in a certain time slot, the physical switch closes, such as Figure 8 the physical switch of the topmost analog link 1 in
[0126] In the embodiments of the present application, the active security control of the analog link is realized through a two-channel fully isolated architecture, eliminating the risk of unauthorized data transmission from the hardware level.
[0127] As Figure 5 , Figure 7 and Figure 8As shown in the figure, the physical isolation module includes a hardware decoding module and a hardware-based lossy encoding module. The hardware decoding module decodes the signal. The hardware-based lossy encoding module is used to perform time-varying distortion processing on the signal, further enhancing the anti-interference and anti-eavesdropping capabilities, and obtaining a second analog signal after secure data processing.
[0128] In the embodiment of the present application, a dedicated decoding module and an encoding module are used for data processing, reducing the processing delay (measured <5ms).
[0129] In a possible embodiment, the hardware decoding module is arranged on the physical layer close to the first proxy module, the lossy encoding module is arranged on the physical layer close to the second proxy module, and a physical switch is arranged between the two.
[0130] If the valid call request is accessed through a digital relay or an IP relay, the physical isolation channel converts the signal in the valid call request into a first analog signal, and then the physical isolation channel performs secure data processing on the first analog signal.
[0131] Specifically, the first IP proxy module deeply analyzes the protocol stack composed of the Session Initiation Protocol and the Real-Time Transport Protocol in the Internet. Specifically, it deeply analyzes the SIP (Session Initiation Protocol) / RTP (Real-Time Transport Protocol) protocol stack in the Voice over Internet Protocol (VoIP) network. Subsequently, the hardware decoding module converts the first voice stream in the broadband telephone signal into an analog baseband signal according to the protocol stack, and then the lossy encoding module converts the analog baseband signal into a first analog signal.
[0132] In a possible embodiment, the time-varying distortion processing of the hardware-based lossy encoding module includes at least one of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation: Dynamic quantization noise injection: Inject dynamic noise into the first analog signal and perform real-time lossy re-encoding on the first analog signal.
[0133] Specifically, the quantization step size is dynamically adjusted through a non-linear quantization algorithm, and real-time lossy re-encoding is performed on the first analog signal (Pulse Code Modulation (PCM) voice stream). Selectively discard high-frequency details above 8kHz (such as the high-frequency band commonly used for steganography carriers), and accurately eliminate low-energy signal components (such as micro data fragments lurking in background noise), directly destroying data embedding carriers such as LSB steganography and frequency-domain watermarks, and retaining the core voice frequency band of 300 - 3400Hz.
[0134] The embodiment of the present application uses hardware-level dynamic noise interference and coding strategy switching to completely destroy the physical basis of high-frequency steganographic attacks while retaining the fidelity of the core voice and audio band of 300-3400 Hz, and effectively resist signal eavesdropping and injection attacks.
[0135] Adaptive spectrum shaping: Real-time analysis of the time-frequency distribution characteristics of the first analog signal to determine the abnormal energy distortion in the first analog signal. In view of the abnormal energy distortion, a dynamic spectrum masking mechanism is used to irreversibly erase the illegal data embedded in the covert channel corresponding to the abnormal energy distortion.
[0136] Specifically, the wavelet domain threshold filtering technology is used to analyze the time-frequency distribution characteristics of the first analog signal in real time. For abnormal energy distortion in the silent period or high-frequency band (such as the non-voice band used in ADSL attacks), the dynamic spectrum masking mechanism is activated: through adaptive adjustment of energy thresholds and selective attenuation of frequency bands, the illegal data embedded in the covert channel is irreversibly erased.
[0137] The embodiment of the present application combines hardware-level spectrum shaping logic to ensure that only the frequency band energy distribution that meets the voice characteristics is retained, fundamentally blocking data entrainment transmission using voice silence periods or spectrum gaps.
[0138] Hardware-level security isolation: If it is detected that the first analog signal has an abnormal data structure, the first analog link is immediately cut off and dynamic noise injection is triggered to achieve physical layer hard isolation of the attack surface.
[0139] Specifically, in a possible embodiment, the signal processing logic is solidified based on the Field Programmable Gate Array (FPGA) to prevent the software layer from tampering with the encoding and decoding process. Once an abnormal data structure is detected (such as a malformed packet, residual steganographic traces, or a 0-day vulnerability exploit in a private branch exchange (PBX) device), the current analog link is immediately cut off and dynamic noise injection is triggered to achieve physical layer hard isolation of the attack surface.
[0140] The embodiment of the present application combines the hardware protection layer with the dynamic randomization strategy to form a three-dimensional defense system of "logic cannot be tampered + parameters cannot be predicted + links can be cut off".
[0141] Based on the above, while using the three strategies of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation at the same time, through the three-order collaboration of "dynamic quantization interference → spectrum intelligent purification → hardware logic isolation", the stealth carrier destruction, spectrum anomaly cleaning and physical link disconnection are completed within millisecond delays, ensuring the fidelity of voice signals in the core frequency band, and achieving real-time blocking and trace erasure of data entrainment attacks, thereby destroying the integrity of attack payloads lurking in digital protocols.
[0142] The second proxy module includes a second protocol identification module, a second analog proxy module, a second digital proxy module and a second IP proxy module. The second protocol identification module is used to determine whether the call request of the caller is an analog relay access mode, a digital relay access mode or an IP relay access mode. The second analog proxy module is used to perform protocol adaptation on the second analog signal corresponding to the call request of analog relay access, and form output data in the form of an analog signal. The second digital proxy module is used to perform protocol adaptation on the second analog signal corresponding to the call request of analog relay access, and form output data in the form of a digital signal. The second IP proxy module is used to perform protocol adaptation on the second analog signal corresponding to the call request of analog relay access, and form output data in the form of an IP signal.
[0143] The working principle of the wired telephone protection system of this application is as follows: The first proxy module and the second proxy module continuously monitor the communication status. When an incoming call or outgoing call request is detected, the first proxy module or the second proxy module immediately intervenes and extracts key information such as the calling number or called number, signaling protocol, and starts two-way identity authentication. If the authentication fails (such as permission abnormality), the communication is directly terminated to block the risk. After the authentication is passed, the channel management module dynamically allocates a physically isolated channel, closes the physical switch and loads the security policy (such as dynamic noise injection, spectrum shaping parameters, etc.) to establish an end-to-end encrypted link.
[0144] The physical isolation module performs real-time protection processing on the voice signal through the physical isolation channel (including high-frequency steganographic carrier destruction, abnormal spectrum erasure, etc.), and initiates a call request to the other end. If the called party does not respond, it triggers a timeout and hangs up to recycle resources. If the call is established, the channel management module continuously monitors the link status (signal integrity, attack characteristics), dynamically adjusts the isolation level, and records operation behaviors and abnormal events in the full link log. At the end of the call, the channel management module immediately disconnects the physical switch, releases the analog link resources, and erases temporary data, returning the system to the initial monitoring state, completing the full closed-loop process of "trigger → authentication → communication → release". This process uses the "normal isolation, dynamic conduction" mechanism to achieve on-demand allocation of communication resources and minimization of the attack surface, ensuring physical layer security and controllability and millisecond-level abnormal cutoff.
[0145] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present application.
Claims
1. A wired telephone protection method based on analog isolation, characterized in that, Including: If the call request is a valid call request, unify the signals in the valid call request into a first analog signal, and allocate an analog link for the first analog signal as the first analog link; Turn on the physical isolation channel of the first analog link, and keep the physical isolation channels of other analog links in a disconnected state; where each analog link includes a physical isolation channel; Perform security data processing on the first analog signal to obtain a second analog signal after security data processing; Convert the second analog signal after security data processing into an output signal, and transmit the output signal to the called party; where the output signal is obtained by conversion according to the protocol used in the valid call request.
2. The wired telephone protection method based on analog isolation according to claim 1, wherein The physical isolation channel includes two isolated physical layers and a physical switch arranged between the two physical layers.
3. The wired telephone protection method based on analog isolation according to claim 1, wherein In the case where the valid call request is a first digital signal, converting the first digital signal into a first analog signal specifically includes: Performing time slot decomposition on the first digital signal to obtain a plurality of decoupled second digital signals; Converting each second digital signal into a third analog signal as the first analog signal; And allocate a first analog link for each third analog signal.
4. The wired telephone protection method based on analog isolation according to claim 1, wherein In the case where the valid call request is a broadband telephone signal, converting the broadband telephone signal into a first analog signal specifically includes: Parsing the protocol stack composed of the Session Initiation Protocol and the Real-Time Transport Protocol in the Internet; Converting the first voice stream in the broadband telephone signal into an analog baseband signal according to the protocol stack; Converting the analog baseband signal into the first analog signal.
5. The method for protecting a wired telephone based on analog isolation according to claim 1, wherein, The wired telephone protection method further includes: Automatically and real-time scan the status of the physical isolation channels of all analog links to obtain idle physical isolation channels; In response to the appearance of a valid call request, bind at least one first analog link corresponding to an idle physical isolation channel to the valid call request; If the call ends or the call duration reaches the threshold, unbind the valid call request from all first analog links, restore the status of the physical isolation channels corresponding to all first analog links to idle, and erase the temporary data of all first analog links.
6. The wired telephone protection method based on analog isolation according to claim 5, characterized in that, If an abnormality exists in the physical isolation channel, unbind the valid call request from all first analog links, restore the status of the physical isolation channels corresponding to all first analog links to idle, and trigger an alarm log.
7. The wired telephone protection method based on analog isolation according to claim 1, wherein The wired telephone protection method further includes: Configure a security protection policy for each physical isolation channel, and the coding parameters and isolation levels in the security protection policy are dynamically adjusted according to the call scenario at the time of binding.
8. The wired telephone protection method based on analog isolation according to claim 7, wherein The wired telephone protection method further includes: Real-time collect the signal strength, coding integrity and the status of the physical switch of the first analog link, and combine the dynamic permission allocation and authentication mechanism to perform millisecond-level cut-off on the abnormal access behavior of the first analog link.
9. The wired telephone protection method based on analog isolation according to claim 8, wherein The wired telephone protection method further includes: Generate a log chain for the channel operation and permission change of the physical isolation channel.
10. The wired telephone protection method based on analog isolation according to claim 5, wherein If there is no idle physical isolation channel, enter the waiting queue management strategy and trigger the elastic expansion mechanism to dynamically expand the capacity of the physical isolation channel.
11. The wired telephone protection method based on analog isolation according to claim 10, wherein If a physical isolation channel fails, mark the physical isolation channel as faulty and place the physical isolation channel in the isolation area.
12. The wired telephone protection method based on analog isolation according to claim 1, wherein Determine whether the call request is a valid call request, specifically including: Verify the legality of the number coding rule of the call request; If the number coding rule is legal, perform two-way identity authentication on the caller and the callee; If the two-way identity authentication passes, the call request is a valid call request.
13. The wired telephone protection method based on analog isolation according to claim 1, characterized in that, Perform security data processing on the valid call request, specifically including: Inject dynamic noise into the first analog signal and perform real-time lossy re-encoding on the first analog signal.
14. The wired telephone protection method based on analog isolation according to claim 13, characterized in that, Performing security data processing on the valid call request further includes: Real-time analyze the time-frequency distribution characteristics of the first analog signal to determine abnormal energy distortion in the first analog signal; For the abnormal energy distortion, adopt a dynamic spectrum masking mechanism to irreversibly erase the illegal data embedded in the covert channel corresponding to the abnormal energy distortion.
15. The method for protecting a wired telephone based on analog isolation according to claim 14, wherein, Performing security data processing on the valid call request further includes: If it is detected that the first analog signal has an abnormal data structure, immediately cut off the first analog link and trigger dynamic noise injection to achieve physical layer hard isolation of the attack surface.
16. A wired telephone protection system based on analog isolation, characterized in that, Includes a first proxy module, a first channel management module, a second channel management module, a second proxy module, and multiple mutually isolated analog links; The first proxy module is used to determine whether a call request is a valid call request; The first channel management module is used to allocate the analog link of the calling end for the first analog signal corresponding to the valid call request as the first analog link when the call request is a valid call request; And conduct the physical isolation channel of the first analog link, while the physical isolation channels of the analog links of other calling ends remain disconnected; Each analog link includes a physical isolation channel, and the physical isolation channel is used to perform security data processing on the first analog signal corresponding to the valid call request to obtain a second analog signal after security data processing; The second channel management module is used to allocate the analog link of the called end for the second analog signal; The second proxy module is used to convert the second analog signal into an output signal and transmit the output signal to the callee; wherein, the output signal is converted according to the protocol used in the valid call request.
17. The wired telephone protection system based on analog isolation according to claim 16, characterized in that, The first proxy module is further used to convert the digital signal into a first analog signal when the valid call request is a digital signal.
18. The wired telephone protection system based on analog isolation according to claim 16, characterized in that, The physical isolation channel includes a hardware decoding module and a hardware-based lossy coding module; The hardware decoding module decodes the signal; The hardware-based lossy coding module is used to perform time-varying distortion processing on the signal to obtain a second analog signal after security data processing.
19. The wired telephone protection system based on analog isolation according to claim 18, characterized in that The hardware decoding module is used to convert the first voice stream in the broadband telephone signal into an analog baseband signal according to the protocol stack of the broadband telephone signal when the valid call request is a broadband telephone signal; The hardware-based lossy encoding module is used to convert the analog baseband signal into the first analog signal.
Citation Information
Patent Citations
Leakage prevention device for mobile phone
CN101127985A
Detection method of analog trunk line
CN101472011A
Anti-monitoring method and device for telephone set
CN112671981A
Telephone system capable of automatically switching SIP and analog telephone
CN117411857A
Analog line multiplexer
JP1997298782A