A wired telephone protection method and system based on analog isolation

Through the wired telephone protection method and system based on analog isolation, the shortcomings of wired telephone security isolation protection in the existing technology are solved, and the full life cycle security protection of analog, digital and IP relays is achieved, the risk of attack is reduced, and the purity and security of communication content are ensured.

CN120321334BActive Publication Date: 2025-09-05ZHONGTIE XINAN BEIJING INFORMATION SECURITY TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510782468.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-09-05
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

Existing wired telephone security isolation and protection solutions are difficult to effectively protect telephone communications, especially analog relays, digital relays and IP relays.

Method used

A wired telephone protection method based on analog isolation is adopted to convert call requests into analog signals. Through the "one link, one isolation" physical barrier architecture, combined with multi-layer dynamic authentication and blocking mechanisms, physical isolation channels are scanned and managed in real time, analog link resources are dynamically allocated, and security data processing, dynamic noise injection and spectrum masking are performed to form hardware-level security protection.

Benefits of technology

It achieves full life cycle security protection for analog, digital and IP relays, reduces the risk of external network attacks and signaling attacks, ensures the purity and security of communication content, and improves protection efficiency and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321334B_ABST
    Figure CN120321334B_ABST
Patent Text Reader

Abstract

The present application provides a wired telephone protection method and system based on analog isolation, which belongs to the field of telephone communication technology. The method includes: if the call request is a valid call request, unifying the signal in the valid call request into a first analog signal, and allocating an analog link to the first analog signal as the first analog link; turning on the physical isolation channel of the first analog link, while the physical isolation channels of other analog links remain disconnected; performing security data processing on the first analog signal to obtain a second analog signal after security data processing; converting the second analog signal into an output signal, and transmitting the output signal to the called party. The present application converts the call request accessed by the digital relay and IP relay into an analog signal first, and cooperates with the "one link and one isolation" physical barrier architecture to fundamentally defend against external network attacks and signaling attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of telephone communication technology, and in particular to a wired telephone protection method and system based on analog isolation. Background Art

[0002] Wired telephone lines, as a traditional communication method, have long been widely used in various office environments. Since wired telephones require fixed access through physical lines and usually maintain a continuous connection to the user's location, there is a possibility of information leakage in the user environment when there is no communication. On the other hand, it may also lead to security risks of external attacks using physical lines.

[0003] There are three main access methods for wired telephones: analog relay access, digital relay access, and IP relay access. Currently, there are very few security isolation and protection products for analog relays, and traditional network isolation-based products cannot effectively protect digital relay lines. Traditional network protection cannot completely provide security protection for IP relays.

[0004] In summary, existing wired telephone security isolation protection solutions are difficult to effectively protect telephone communications. Summary of the Invention

[0005] The present application provides a wired telephone protection method and system based on analog isolation, aiming to solve the problem that existing wired telephone security isolation protection solutions are difficult to effectively protect telephone communications.

[0006] In a first aspect, the present application provides a wired telephone protection method based on analog isolation, comprising:

[0007] If the call request is a valid call request, unifying the signal in the valid call request into a first analog signal, and allocating an analog link to the first analog signal as the first analog link;

[0008] The physical isolation channel of the first analog link is turned on, while the physical isolation channels of other analog links remain disconnected; wherein each analog link includes one physical isolation channel;

[0009] Performing security data processing on the first analog signal to obtain a second analog signal after the security data processing;

[0010] The second analog signal after the security data processing is converted into an output signal, and the output signal is transmitted to the called party; wherein the output signal is obtained by conversion according to the protocol used for the valid call request.

[0011] As an embodiment, the physical isolation channel includes two mutually isolated physical layers and a physical switch arranged between the two physical layers.

[0012] As an embodiment, when the valid call request is a first digital signal, converting the first digital signal into a first analog signal specifically includes:

[0013] Decomposing the first digital signal by time slots to obtain a plurality of decoupled second digital signals;

[0014] converting each second digital signal into a third analog signal as a first analog signal;

[0015] Furthermore, one first analog link is allocated to each third analog signal.

[0016] As an embodiment, when the valid call request is a broadband telephone signal, converting the broadband telephone signal into a first analog signal specifically includes:

[0017] Analyze the protocol stack consisting of Session Initiation Protocol and Real-time Transport Protocol in the Internet;

[0018] converting a first voice stream in a broadband telephone signal into an analog baseband signal according to a protocol stack;

[0019] The analog baseband signal is converted into a first analog signal.

[0020] As an embodiment, the wired telephone protection method further includes:

[0021] Automatically scan the status of the physical isolation channels of all analog links in real time to obtain idle physical isolation channels;

[0022] In response to a valid call request, binding at least one idle first analog link corresponding to the physically isolated channel to the valid call request;

[0023] If the call ends or the call duration reaches the threshold, the valid call request will be untied from all first analog links, the status of the physical isolation channels corresponding to all first analog links will be restored to idle, and all temporary data of the first analog links will be erased.

[0024] As an embodiment, if there is an abnormality in the physical isolation channel, the valid call request is untied from all the first analog links, the status of the physical isolation channels corresponding to all the first analog links is restored to idle, and an alarm log is triggered.

[0025] As an embodiment, the wired telephone protection method further includes:

[0026] A security protection policy is configured for each physically isolated channel. The encoding parameters and isolation level within the security protection policy are dynamically adjusted based on the call scenario at the time of binding.

[0027] As an embodiment, the wired telephone protection method further includes:

[0028] The signal strength, coding integrity and physical switch status of the first analog link are collected in real time, and combined with dynamic permission allocation and authentication mechanisms, abnormal access behavior of the first analog link is cut off at the millisecond level.

[0029] As an embodiment, the wired telephone protection method further includes:

[0030] Generate a log chain for channel operations and permission changes of physically isolated channels.

[0031] As an embodiment, if there is no idle physically isolated channel, the waiting queue management strategy is entered, and the elastic expansion mechanism is triggered at the same time to dynamically expand the capacity of the physically isolated channel.

[0032] As an embodiment, if a fault occurs in the physically isolated channel, the physically isolated channel is marked as a fault and is placed in an isolation area.

[0033] As an embodiment, determining whether the call request is a valid call request specifically includes:

[0034] Verify the legitimacy of the number coding rules for call requests;

[0035] If the number coding rules are legal, two-way identity authentication is performed on the calling and called parties;

[0036] If the two-way identity authentication is passed, the call request is a valid call request.

[0037] As an embodiment, security data processing is performed on a valid call request, specifically including:

[0038] Dynamic noise is injected into a first analog signal, and the first analog signal is lossily re-encoded in real time.

[0039] As an embodiment, performing security data processing on a valid call request further includes:

[0040] analyzing the time-frequency distribution characteristics of the first analog signal in real time to determine abnormal energy distortion in the first analog signal;

[0041] In response to abnormal energy distortion, a dynamic spectrum masking mechanism is adopted to irreversibly erase the illegal data embedded in the covert channel corresponding to the abnormal energy distortion.

[0042] As an embodiment, performing security data processing on a valid call request further includes:

[0043] If it is detected that the first analog signal has an abnormal data structure, the first analog link is immediately cut off and dynamic noise injection is triggered to achieve physical layer hard isolation of the attack surface.

[0044] In a second aspect, the present application further provides a wired telephone protection system based on analog isolation, comprising a first proxy module, a first channel management module, a second channel management module, a second proxy module, and a plurality of mutually isolated analog links;

[0045] The first agent module is used to determine whether the call request is a valid call request;

[0046] The first channel management module is configured to, when the call request is a valid call request, allocate the analog link of the calling end to the first analog signal as the first analog link; and connect the physical isolation channel of the first analog link, while keeping the physical isolation channels of the analog links of other calling ends disconnected;

[0047] Each analog link includes a physical isolation channel, the physical isolation channel being used to perform security data processing on a first analog signal corresponding to a valid call request to obtain a second analog signal after the security data processing;

[0048] The second channel management module is used to allocate an analog link of the called end to the second analog signal;

[0049] The second proxy module is used to convert the second analog signal into an output signal and transmit the output signal to the called party; wherein the output signal is obtained by converting according to the protocol used for the valid call request.

[0050] As an embodiment, the first agent module is further configured to convert the digital signal into a first analog signal when the valid call request is a digital signal.

[0051] As an embodiment, the physically isolated channel includes a hardware decoding module and a hardware-based lossy encoding module;

[0052] The hardware decoding module decodes the signal;

[0053] The hardware-based lossy encoding module is used to perform time-varying distortion processing on the signal to obtain a second analog signal after security data processing.

[0054] As an embodiment, the hardware decoding module is configured to convert a first voice stream in the broadband telephone signal into an analog baseband signal according to a protocol stack of the broadband telephone signal when the valid call request is a broadband telephone signal;

[0055] The hardware-based lossy encoding module is used to convert the analog baseband signal into a first analog signal. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions in the present application or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0057] Figure 1 This is one of the flow charts of the wired telephone protection method based on analog isolation provided by this application;

[0058] Figure 2 This is the second flow chart of the wired telephone protection method based on analog isolation provided by this application;

[0059] Figure 3 This is a flowchart of determining whether a call request is a valid call request provided by this application;

[0060] Figure 4 This is a flow chart of the dynamic allocation mechanism of the analog link provided by this application;

[0061] Figure 5 This is one of the structural diagrams of the wired telephone protection system based on analog isolation provided by this application;

[0062] Figure 6 This is a schematic diagram of the structure of the first agent module provided by this application;

[0063] Figure 7 This is the second structural diagram of the wired telephone protection system based on analog isolation provided by this application;

[0064] Figure 8 This is a schematic diagram of the structure of the physical isolation module provided by this application;

[0065] Figure 9 It is a structural diagram of the first channel management module provided in this application. DETAILED DESCRIPTION

[0066] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.

[0067] It should be noted that, in the description of the present invention, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0068] The terms "first," "second," and so forth, used herein are used to distinguish similar objects, not to describe a specific order or precedence. It should be understood that such terms are interchangeable where appropriate, allowing embodiments of the present invention to be implemented in an order other than that illustrated or described herein. Furthermore, the terms "first," "second," and so forth generally distinguish objects of a single type, and do not limit the number of objects. For example, the first object may be one or more. Furthermore, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the connected objects.

[0069] The following combination Figures 1 to 9 The present application describes a wired telephone protection method and system based on analog isolation.

[0070] It should be noted that the wired telephone protection method based on analog isolation provided in the embodiment of the present application is implemented based on the wired telephone protection system based on analog isolation. The wired telephone protection method based on analog isolation first converts the call requests accessed by digital relays and IP relays into analog signals, and cooperates with the "one chain and one isolation" physical barrier architecture to fundamentally defend against external network attacks and signaling attacks.

[0071] The embodiment of the present application describes the wired telephone protection method based on analog isolation by taking the wired telephone protection system based on analog isolation as an example of the execution body.

[0072] Figure 1 This is one of the flow charts of the wired telephone protection method based on analog isolation provided by this application. Figure 2 This is the second flow chart of the wired telephone protection method based on analog isolation provided by this application.

[0073] like Figure 1 As shown, the wired telephone protection method based on analog isolation provided by this application includes:

[0074] S110: If the call request is a valid call request, unify the signals in the valid call request into a first analog signal, and allocate an analog link to the first analog signal as the first analog link.

[0075] Specifically, if the valid call request is received via a digital relay or IP (Internet Protocol) relay, the signal within the valid call request is converted into a first analog signal, and then the first analog signal is subjected to security data processing. If the valid call request is received via an analog relay, the analog signal is used as the first analog signal.

[0076] There are multiple analog links in the wired telephone protection system, and the analog links are based on analog signals for telephone communications.

[0077] S120: The physical isolation channel of the first analog link is turned on, while the physical isolation channels of other analog links remain disconnected.

[0078] Each analog link includes an independent physically isolated channel. This means that the physically isolated channels of different analog links are isolated from each other, forming a "one-link, one-isolation" barrier architecture. Each physically isolated channel is disconnected by default and is only connected when communication is required. When the physically isolated channel of the first analog link is connected, the physically isolated channels of the other analog links remain disconnected.

[0079] S130: Perform security data processing on the first analog signal to obtain a second analog signal after security data processing.

[0080] When performing security data processing on a valid call request, unsafe data in the valid call request can be processed to eliminate potential safety hazards and obtain a safe second analog signal.

[0081] S140: Convert the second analog signal after the security data processing into an output signal, and transmit the output signal to the called party.

[0082] The output signal is converted based on the protocol used by the active call request. Specifically, if the active call request is received via a digital trunk or IP trunk, the output signal is a digital signal or IP signal. If the active call request is received via an analog trunk, the output signal is an analog signal.

[0083] Please combine Figure 2The caller initiates a call request. After the call request is connected to the wired telephone protection system, it is first determined whether the call request is a valid call request. If so, the signal in the valid call request is unified into a first analog signal, and a first analog link is allocated to each first analog signal and the physical isolation channel of the first analog link is connected. Subsequently, security data processing is performed on the first analog signal to obtain a second analog signal, and then the second analog signal is converted into an output signal adapted to the protocol used in the call request, and the output signal is output to the called party.

[0084] Both digital and IP signals involve data transmission with signaling formats, representing purely digital communication methods. Therefore, these transmissions are subject to numerous unpredictable attack risks, such as signaling attacks. Analog links, on the other hand, do not transmit any signaling data, allowing only voice signals to pass through, effectively ensuring the purity of telephone communications. Furthermore, because the physical lines of traditional analog phones are always connected, they still pose a security risk even when not in use. Attackers can exploit these lines for real-time passive eavesdropping. This "always-on" physical nature creates a persistent blind spot in security protection.

[0085] Based on the above, after identifying a valid call request, the embodiment of the present application first converts the call request accessed by the digital relay and IP relay into an analog signal. On this basis, each analog link is provided with a physical isolation channel, forming a "one link one isolation" physical barrier architecture, ensuring the intrinsic safety of the hardware level, cutting off the possibility of covert channels, side attacks and malicious code implantation from the root; and, according to the required number of analog links, the other analog links remain disconnected, and the call is physically disconnected upon completion, compressing the high-risk communication window to seconds. The embodiment of the present application has formed differentiated advantages over the existing technology in the three dimensions of security, reliability and compliance, thereby fundamentally reducing the risk of external network attacks, signaling attacks, etc.

[0086] Existing wired telephone protection systems employ two-way authentication mechanisms, which are unable to verify the identity of callers or the legitimacy of called parties. This one-way authentication model allows attackers to exploit protocol vulnerabilities and eavesdrop on lines. When external attackers initiate malicious harassing calls, the protection system lacks dynamic control over blacklists and whitelists, leaving communication channels exposed to the risk of long-term unauthorized access.

[0087] Based on the above considerations, in one possible embodiment, a multi-layer dynamic authentication and blocking mechanism is used to achieve end-to-end security management and control. Figure 3 As shown, determining whether the call request is a valid call request specifically includes:

[0088] P1: Verify the number coding rules of the call request and verify the legality of the number format (such as international coding standards, valid digits, etc.). If the number is illegal, it will be blocked immediately.

[0089] P2: If the number coding rules are legal, two-way identity authentication is performed on the calling and called parties.

[0090] like Figure 3 As shown, in a possible embodiment, the two-way identity authentication includes, in sequence, caller identity authentication, adaptive blacklist and whitelist check of the calling end, and legitimacy verification of the called end.

[0091] Specifically, during caller identity authentication, the authenticity of the caller's identity is verified using a digital certificate or hardware token. If authentication fails (e.g., due to permission issues), the process is terminated and a security alert is generated.

[0092] After the caller identity is passed, the communication policy control is started and the adaptive blacklist and whitelist check module is called:

[0093] If the caller is on the whitelist, the call is directly allowed to proceed to the called party's legitimacy verification process.

[0094] If the caller is on the blacklist, it is immediately blocked and marked as a high-risk source, and the adaptive strategy is updated synchronously.

[0095] If the caller is unknown, the system analyzes the caller's call behavior characteristics (such as call frequency, call history, etc.) If there is any abnormal behavior (such as high-frequency calls, requests during non-working hours, sudden nighttime traffic, and other suspicious behavior), the call will be immediately blocked.

[0096] In the legitimacy verification process of the called party, the device fingerprint, authorization status, etc. are verified. After the verification is passed, P3 is executed.

[0097] P3: If the two-way identity authentication is passed, the call request is a valid call request.

[0098] In any of the above authentication links, after the blocking alarm unit is activated as needed, the physical layer cuts off the analog link and generates an anti-tampering log. At the same time, the adaptive strategy is dynamically updated (such as adding blacklist entries, adjusting risk thresholds, etc.), forming a closed-loop protection system of "attack discovery → strategy optimization → active defense". The embodiment of the present application realizes the identification of effective call requests through the four-level linkage of "rule filtering → identity authentication → policy control → dynamic blocking", realizes millisecond-level interception of unfamiliar calls, ensures millisecond-level real-time blocking of channels and trustworthy identities of the entire link; through the full-process closed-loop protection of "trusted identity → controllable strategy → traceable communication", the "passive answering" of the traditional telephone network is upgraded to "active defense communication", achieving the protection goal of "legitimate users are unaware and illegal attacks cannot enter".

[0099] In a possible embodiment, in step S110, when the valid call request is a first digital signal (E1 or T1 digital signal), converting the first digital signal into a first analog signal specifically includes:

[0100] R1: Decompose the first digital signal by time slots to obtain multiple decoupled second digital signals.

[0101] R2: converts each second digital signal into a third analog signal as the first analog signal.

[0102] Specifically, each second digital signal is converted into a third analog signal through existing digital-to-analog conversion technology, which is not limited in this application.

[0103] Furthermore, based on the above, when the valid call request is a first digital signal, in step S110 , a first analog link is allocated to each third analog signal.

[0104] In a possible embodiment, each decoupled second digital signal is converted into an independent third analog signal through analog signal reconstruction technology, and then independently injected into the corresponding analog link.

[0105] In the embodiment of the present application, the time slot dynamic decoupling technology decomposes the E1 or T1 digital signal into time slots, breaking the continuity feature of the traditional time division multiplexing architecture; in the process of analog signal reconstruction, only the voice baseband signal is retained, the out-of-band signaling and metadata of the digital relay are stripped, and the covert data transmission that exploits protocol vulnerabilities is eliminated from the physical layer; on this basis, the corresponding number of analog link resources are dynamically allocated in real time according to communication needs, and the coordinated work of dynamic allocation and channel management ensures that each analog link is only temporarily activated during the authorized period and only dynamically generates temporary links during the authorized time slot, converting the permanent attack surface of the digital relay into a dynamically reconfigurable temporary communication window, making it impossible for attackers to reside for a long time or pre-place malicious payloads, and effectively defending against various attack methods against digital relays. Furthermore, through the technical path of "digital decoupling → analog reconstruction → physical isolation → dynamic allocation", while being compatible with the existing digital relay network, the persistent attack surface of digital communication is completely isolated, which is particularly suitable for threats such as covert channels and supply chain attacks, and can achieve full life cycle security protection of digital relay signals.

[0106] In a possible embodiment, in step S110, when the valid call request is a broadband telephone signal (IP signal), converting the broadband telephone signal into a first analog signal specifically includes:

[0107] S1: Analyzes the protocol stack consisting of Session Initiation Protocol and Real-time Transport Protocol in the Internet. Specifically, it deeply analyzes the SIP (Session Initiation Protocol) / RTP (Real-Time Transport Protocol) protocol stack in Voice over Internet Protocol (VoIP) networks.

[0108] S2: Converting the first voice stream in the broadband telephone signal into an analog baseband signal according to the protocol stack.

[0109] Specifically, physical layer signal reconstruction is performed on the first voice stream to convert it into an analog baseband signal.

[0110] S3: Convert the analog baseband signal into a first analog signal.

[0111] Specifically, the analog baseband signal is converted into the first analog signal using existing technology, which is not limited in this application.

[0112] In this embodiment, IP signals are converted into analog signals, creating a "network-to-voice security barrier." This completely eliminates attack paths based on protocol vulnerabilities, such as SIP flooding attacks, RTP injection, and signaling hijacking. Even attackers with zero-day vulnerabilities cannot penetrate the physically isolated channel. Furthermore, the voice signal is reconstructed through physical layer analog reconstruction, preventing attackers from analyzing the target network topology through traffic analysis or conducting side-channel attacks. Furthermore, combined with on / off control of the physically isolated analog link, this embodiment establishes a physical layer security boundary for the IP phone system through a "digital protocol decoupling → analog signal reconstruction" protection architecture. This completely separates the high-risk digital domain of the VoIP network from the intrinsically safe analog domain, effectively defending against VoIP protocol stack attacks and penetration attacks exploiting PBX (Private Branch Exchange) vulnerabilities. Through the three-tiered protection of "digital protocol decoupling → analog signal reconstruction → dynamic link isolation," the VoIP network's permanent digital attack surface is converted into a temporary analog communication window, creating an impenetrable "digital → analog" security boundary and thoroughly defending against threats such as protocol stack malformed packet attacks and lateral penetration through PBX vulnerabilities.

[0113] In a possible embodiment, the physical isolation channel includes two mutually isolated physical layers and a physical switch arranged between the two physical layers.

[0114] In the embodiment of the present application, the physical isolation module realizes complete isolation of the physical layer of each analog link through the linkage control of the hardware isolation layer and the physical switch, forming a "one chain one isolation" barrier architecture.

[0115] Existing wired telephone protection systems lack an effective detection mechanism for least significant bit (LSB) steganography attacks, which allow attackers to transmit data through the channel. Therefore, existing protection systems cannot effectively prevent attacks such as abnormal data inclusion and data steganography during voice calls.

[0116] Based on the above considerations, in one possible embodiment, in step S130, security data processing is performed on the valid call request, specifically including at least one of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation:

[0117] Q1: Dynamic quantization noise injection: Dynamic noise is injected into the first analog signal to perform real-time lossy re-encoding on the first analog signal.

[0118] Specifically, a nonlinear quantization algorithm dynamically adjusts the quantization step size, performing real-time lossy re-encoding on the first analog signal (a Pulse Code Modulation (PCM) voice stream). This selectively discards high-frequency details above 8kHz (such as the high-frequency band commonly used by steganographic carriers) and precisely removes low-energy signal components (such as microdata fragments lurking in background noise). This directly destroys data carriers such as LSB steganography and frequency-domain watermarking, while preserving the core voice frequency band of 300-3400Hz.

[0119] The embodiments of the present application use hardware-level dynamic noise injection to completely eliminate the physical basis of high-frequency steganographic attacks while retaining the fidelity of the core voice and audio frequency band of 300-3400Hz. This greatly improves the bit error rate of steganography and builds a secure communication defense line that is "hearable but not stealable." Without reducing call quality, it fundamentally eliminates the high-risk behavior of using voice channels for data theft.

[0120] Q2: Adaptive Spectrum Shaping: Real-time analysis of the time-frequency distribution characteristics of the first analog signal to identify abnormal energy distortion in the first analog signal. A dynamic spectrum masking mechanism is used to irreversibly erase illegal data embedded in the covert channel corresponding to the abnormal energy distortion.

[0121] Specifically, wavelet-domain threshold filtering technology is used to analyze the time-frequency distribution characteristics of the first analog signal in real time. A dynamic spectrum masking mechanism is activated to address abnormal energy distortion during silent periods or high-frequency bands (such as the non-voice bands exploited by Asymmetric Digital Subscriber Line (ADSL) attacks). Through adaptive energy threshold adjustment and frequency-selective attenuation, the system irreversibly erases illegal data embedded in covert channels.

[0122] The embodiments of the present application combine hardware-level spectrum shaping logic to ensure that only the energy distribution of frequency bands that meet the voice characteristics is retained, fundamentally blocking data entrainment transmission during voice silence periods or spectrum gaps.

[0123] Q3: Hardware-level security isolation: If it is detected that the first analog signal has an abnormal data structure, the first analog link is immediately cut off and dynamic noise injection is triggered to achieve physical layer hard isolation of the attack surface.

[0124] Specifically, in one possible embodiment, signal processing logic is hardened within a Field Programmable Gate Array (FPGA) to prevent software-layer side-channel attacks from tampering with the encoding and decoding process. Upon detecting an abnormal data structure (such as a malformed packet or residual steganographic traces), the current analog link is immediately disconnected and dynamic noise injection is triggered, achieving physical-layer hard isolation of the attack surface.

[0125] The embodiment of the present application combines a hardware protection layer with a dynamic randomization strategy to form a three-dimensional defense system of "logic cannot be tampered + parameters cannot be predicted + links can be cut off".

[0126] Based on the above, while using the three strategies of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation at the same time, through the three-level collaboration of "dynamic quantization interference → spectrum intelligent purification → hardware logic isolation", the stealth carrier destruction, spectrum anomaly cleaning and physical link disconnection are completed within millisecond delays, ensuring the fidelity of voice signals in the core frequency band, and achieving real-time blocking and erasure of data entrainment attacks.

[0127] Based on the above, a plurality of analog links are provided in the wired telephone protection system. On this basis, the wired telephone protection method also includes a dynamic allocation mechanism of analog links. Figure 4 As shown in FIG, the dynamic allocation mechanism of the analog link specifically includes:

[0128] S410: Automatically scan the status of the physical isolation channels of all analog links in real time to obtain idle physical isolation channels.

[0129] During the physical isolation channel creation and initialization phase, a unique channel ID is automatically generated for each physical isolation channel of the analog link to complete the physical mapping of hardware resource binding and analog links.

[0130] S420: If there are enough idle physical isolation channels, in response to a valid call request, bind at least one first analog link corresponding to the idle physical isolation channel to the valid call request to complete the call establishment.

[0131] S430: If the call ends or the call duration reaches a threshold, the valid call request is unbound from all first analog links, the status of the physical isolation channels corresponding to all first analog links is restored to idle, and all temporary data of the first analog links are erased.

[0132] The embodiment of the present application adopts a dynamic channel management mechanism to automatically scan and obtain idle channels, complete the binding of channels with valid call requests, and automatically unbind the channels after the call ends or the call duration reaches a threshold, erase temporary data and recycle resources for reuse by subsequent requests. Thus, through the full life cycle management of "dynamic allocation → physical isolation → status monitoring → resource recovery", the secure processing of large-scale high-concurrency call requests is achieved (the channel reuse rate is increased by more than 60%, and the hardware resource consumption is reduced by 30%), and the "one chain and one isolation" hardware structure is used to ensure that the physical layers of multiple communications do not interfere with each other, thereby achieving high-density communication, millisecond-level response and isolated transmission; and in this process, the physically isolated channel is activated on demand, the exposure time window is controllable, and latent attacks can be blocked.

[0133] Based on the above, in a possible embodiment, the dynamic allocation mechanism of the analog link further includes:

[0134] If there is an abnormality in the physical isolation channel, the valid call request will be untied from all the first analog links, the status of the physical isolation channels corresponding to all the first analog links will be restored to idle, and an alarm log will be triggered.

[0135] The embodiment of the present application adopts an abnormal cut-off mechanism to ensure the security of the physically isolated channel, and records abnormal information through alarm logs to facilitate subsequent tracing.

[0136] Furthermore, the dynamic allocation mechanism of the analog link also includes:

[0137] If there is no idle physical isolation channel, the new request will be rejected and the resource occupation will be prompted, and the waiting queue management strategy will be implemented to avoid the risk of overload; at the same time, the elastic expansion mechanism will be triggered to dynamically expand the capacity of the physical isolation channel.

[0138] In the embodiment of the present application, a rejection occupancy strategy is adopted to avoid overload when there are no idle channels, thereby ensuring communication quality, while dynamically expanding channel capacity and improving processing efficiency.

[0139] Furthermore, the dynamic allocation mechanism of the analog link also includes:

[0140] If there is a fault in the physical isolation channel, the physical isolation channel will be marked as a fault and placed in the isolation area.

[0141] The embodiment of the present application isolates the faulty channel to prevent it from being connected again, thereby ensuring call safety.

[0142] Based on the above, the wired telephone protection method provided by this application also includes the management of physically isolated channels, specifically including:

[0143] A security protection policy is configured for each physically isolated channel. The encoding parameters and isolation level within the security protection policy are dynamically adjusted based on the call scenario at the time of binding.

[0144] In an embodiment of the present application, during the channel creation and initialization phase, a preset security protection policy is loaded for each physically isolated channel. During use, the security protection policy of each physically isolated channel is independently and dynamically adjusted based on the call scenario at the time of binding, so that each physically isolated channel has an independent security protection policy, ensuring that calls with different security levels have differentiated protection strategies.

[0145] Furthermore, the management of physically isolated channels also includes:

[0146] The signal strength, coding integrity and physical switch status of the first analog link are collected in real time. Combined with the dynamic permission allocation and authentication mechanism of the physical isolation channel, abnormal access behavior of the first analog link is cut off at the millisecond level.

[0147] The embodiment of the present application improves the efficiency of security protection by real-time monitoring of the channel status and performs millisecond-level cutoff in the event of abnormal access, thereby greatly reducing the probability of the wired telephone protection system being attacked.

[0148] Furthermore, the management of physically isolated channels also includes:

[0149] Generate a log chain for channel operations, permission changes, and device status of physically isolated channels.

[0150] The embodiment of the present application generates a log chain to form a tamper-proof audit trail, which is conducive to tracing and later updating and correcting the management strategy of the physical isolation channel.

[0151] It is understandable that in the embodiment of the present application, the operation permissions for the physical management channel (such as on / off permissions, configuration modification permissions) can be dynamically granted and revoked through a visual interface.

[0152] Based on the above, the present application further provides a wired telephone protection system based on analog isolation. The wired telephone protection system based on analog isolation and the above-mentioned wired telephone protection method based on analog isolation can refer to each other.

[0153] As an example, Figure 5 As shown, the wired telephone protection system includes a first agent module, a first channel management module, a second channel management module, a second agent module and a plurality of mutually isolated analog links.

[0154] The first agent module is used to determine whether the call request is a valid call request.

[0155] The first channel management module is configured to allocate the analog link of the calling end to the first analog signal as the first analog link when the call request is a valid call request, and connect the physical isolation channel of the first analog link while keeping the physical isolation channels of the analog links of other calling ends disconnected.

[0156] Each analog link includes a physical isolation channel, which is used to perform security data processing on a first analog signal corresponding to a valid call request to obtain a second analog signal after security data processing.

[0157] The second channel management module is used to allocate an analog link of the called end to the second analog signal.

[0158] The second proxy module is used to convert the second analog signal after the security data processing into an output signal and transmit the output signal to the called party, wherein the output signal is obtained by converting according to the protocol used for the valid call request.

[0159] This embodiment of the present application converts call requests from digital and IP trunks into analog signals. On this basis, each analog link is equipped with a physical isolation channel, forming a "one-link, one-isolation" physical barrier architecture. The required number of analog links is connected as needed, while the other analog links remain disconnected, thereby fundamentally reducing the risk of external network attacks, signaling attacks, and the like. Furthermore, this embodiment of the present application separates the proxy modules for the calling and called parties, decoupling signal processing from protocol conversion, improving their efficiency and reducing their mutual impact.

[0160] Specifically, if Figure 6 As shown, the first proxy module includes a first protocol identification module, a first analog proxy module, a first digital proxy module, and a first IP proxy module. The first protocol identification module is used to identify whether the call request is an analog relay access method, a digital relay access method, or an IP relay access method. The first analog proxy module is used to authenticate call requests for analog relay access and determine whether the call request is a valid call request. The first digital proxy module is used to authenticate call requests for digital relay access and determine whether the call request is a valid call request. The first IP proxy module is used to authenticate call requests for IP relay access and determine whether the call request is a valid call request.

[0161] The embodiments of the present application support cross-standard signal mixing processing, thereby improving the versatility of the wired telephone protection system.

[0162] If a valid call request is received via a digital relay, the first proxy module (specifically, the first digital proxy module) converts the first digital signal in the valid call request into a first analog signal. The first analog signal is then subjected to security data processing via the physically isolated channel. This includes: decomposing the first digital signal by time slots to obtain multiple decoupled second digital signals; and converting each second digital signal into a third analog signal, which serves as the first analog signal.

[0163] If the valid call request is accessed through the analog relay, the first analog proxy module uses the analog signal as the first analog signal.

[0164] Please combine Figure 7 The first channel management module is used to allocate an analog link of the calling end to each first analog signal, and the second channel management module is used to allocate a called module link to the second analog signal after security data processing output by the physical management channel, and is used to output the output signal to the called party, and establish an end-to-end communication link through the analog link of the calling end and the analog link of the called end.

[0165] In one possible embodiment, Figure 9 As shown, the first channel management module includes a channel creation and initialization unit, a status monitoring and on-off expansion unit, a channel release and resource recovery unit, a binding configuration and policy loading unit, a dynamic permission allocation and authentication unit, and a full-link logging unit.

[0166] The channel creation and initialization unit is used to automatically generate a unique channel ID for each physically isolated channel and load preset security policies during the channel creation and initialization phase, completing the physical mapping of hardware resource binding and analog links.

[0167] The status monitoring and on-off expansion unit is used to collect the signal strength, coding integrity and physical switch status of each analog link in real time. Combined with dynamic permission allocation and authentication mechanism, it can implement millisecond-level cutoff of abnormal access behavior.

[0168] The channel release and resource recovery unit is used to automatically unbind the physical isolation channel, reset the physical switch status, and erase the temporary cache data when the call ends.

[0169] The binding configuration and policy loading unit is used to dynamically adjust encoding parameters and isolation levels according to the call scenario, ensuring that sessions with different security levels match differentiated protection strategies.

[0170] The dynamic permission allocation and authentication unit is used to dynamically grant and revoke operation permissions for physically isolated channels (such as on / off permissions, configuration modification permissions, etc.) through a visual interface.

[0171] The full-link logging unit is used to record channel operations, permission changes, and device status, forming a tamper-proof audit trail.

[0172] As can be understood, the second channel management module has the same functions and structure as the first channel management module. After the first channel management module connects the physically isolated channels of the analog link on the calling end, if the call request signal is successfully transmitted to the second channel management module, the second channel management module will connect the corresponding number of physically isolated channels of the analog link on the called end. If the call ends, times out, or an abnormality occurs, and a disconnection is required, both the first and second channel management modules will unbind the current call request from the corresponding physically isolated channels.

[0173] In the embodiment of the present application, the channel management module implements intelligent management of the entire call process. By dynamically allocating call channels, dynamically binding channel IDs to physical port mappings, time slots, and other features, it ensures that channel resources cannot be maliciously hijacked or counterfeited. Furthermore, by dynamically allocating channel bandwidth and priority on demand, it improves line utilization by over 30%. It also has a channel self-destruct mechanism that immediately clears information such as channel IDs and cached data after a call is terminated, ensuring that attackers cannot recover sensitive information. Through the full-cycle management and control of "create-run-destroy," the channel management module transforms communication channels from "static resources" to "dynamic security assets," realizing an active defense system where "risks are visible, resources can be mobilized, and attacks can be prevented."

[0174] like Figure 5 and Figure 7 As shown, multiple physical isolation modules are provided between the first channel management module and the second channel management module, and the structure thereof can be multiple independent physical isolation modules (such as Figure 5 The upper physical isolation module and Figure 7 All physically isolated modules are shown), and can also form a physically isolated array (such as Figure 5 physically isolated array shown in the lower part).

[0175] In one possible embodiment, the physically isolated channel includes two isolated physical layers and a physical switch between them. Under normal system conditions (when no call is required), the physically isolated channel maintains a disconnected physical layer. A call link is dynamically established only during active call periods, creating an "air gap" protection mechanism.

[0176] Specifically, physical switches can use industrial-grade electromagnetic relays to build a double-breakpoint isolation barrier, keeping the physical layers of the lines on both sides completely separated when there is no effective communication demand.

[0177] like Figure 8As shown in the figure, when there is no communication, the physical switch keeps the lines on both sides completely disconnected, ensuring the dual-channel full isolation state of the analog isolation module, as shown in the figure. Figure 8 The physical switch of the analog link 2 to N. When there is a call in a certain time slot, the physical switch is closed, such as Figure 8 The physical switch of the top analog link 1 establishes a temporary communication link at this time to transmit analog signals, thereby achieving safe and controllable analog signal transmission.

[0178] In the embodiment of the present application, active security control of the analog link is achieved through a dual-channel full isolation architecture, eliminating the risk of unauthorized data transmission at the hardware level.

[0179] like Figure 5 、 Figure 7 and Figure 8 As shown, the physical isolation module includes a hardware decoding module and a hardware-based lossy encoding module. The hardware decoding module decodes the signal. The hardware-based lossy encoding module performs time-varying distortion processing on the signal, further enhancing anti-interference and anti-eavesdropping capabilities, and obtaining a second analog signal after security data processing.

[0180] The embodiment of the present application uses a dedicated decoding module and encoding module for data processing, which reduces processing delay (actual measurement <5ms).

[0181] In a possible embodiment, the hardware decoding module is provided on a physical layer close to the first proxy module, and the lossy encoding module is provided on a physical layer close to the second proxy module, with a physical switch provided between the two.

[0182] If the valid call request is accessed through a digital relay or an IP relay, the physical isolation channel converts the signal in the valid call request into a first analog signal, and then the physical isolation channel performs security data processing on the first analog signal.

[0183] Specifically, the first IP proxy module deeply parses the protocol stack consisting of the Session Initiation Protocol and the Real-Time Transport Protocol on the Internet. Specifically, it deeply parses the SIP (Session Initiation Protocol) / RTP (Real-Time Transport Protocol) protocol stack in Voice over Internet Protocol (VoIP) networks. The hardware decoding module then converts the first voice stream in the broadband phone signal into an analog baseband signal based on the protocol stack. The lossy encoding module then converts the analog baseband signal into the first analog signal.

[0184] In a possible embodiment, the time-varying distortion processing of the hardware-based lossy coding module includes at least one of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation.

[0185] Dynamic quantization noise injection: dynamic noise is injected into the first analog signal to perform real-time lossy re-encoding on the first analog signal.

[0186] Specifically, a nonlinear quantization algorithm dynamically adjusts the quantization step size, performing real-time lossy re-encoding on the first analog signal (a Pulse Code Modulation (PCM) voice stream). This selectively discards high-frequency details above 8kHz (such as the high-frequency band commonly used by steganographic carriers) and precisely removes low-energy signal components (such as microdata fragments lurking in background noise). This directly destroys data carriers such as LSB steganography and frequency-domain watermarking, while preserving the core voice frequency band of 300-3400Hz.

[0187] The embodiments of the present application use hardware-level dynamic noise interference and coding strategy switching to completely destroy the physical basis of high-frequency steganographic attacks while preserving the fidelity of the core voice frequency band of 300-3400Hz, effectively defending against signal eavesdropping and injection attacks.

[0188] Adaptive Spectrum Shaping: This technology analyzes the time-frequency distribution of the first analog signal in real time to identify abnormal energy distortion within the first analog signal. It then employs a dynamic spectrum masking mechanism to irreversibly erase illegal data embedded in the covert channel corresponding to the abnormal energy distortion.

[0189] Specifically, wavelet-domain threshold filtering technology is used to analyze the time-frequency distribution characteristics of the first analog signal in real time. A dynamic spectrum masking mechanism is activated to address abnormal energy distortion during silent periods or in high-frequency bands (such as the non-voice bands exploited by ADSL attacks). Through adaptive energy threshold adjustment and frequency-band selective attenuation, illegal data embedded in covert channels is irreversibly erased.

[0190] The embodiments of the present application combine hardware-level spectrum shaping logic to ensure that only the energy distribution of frequency bands that meet the voice characteristics is retained, fundamentally blocking data entrainment transmission during voice silence periods or spectrum gaps.

[0191] Hardware-level security isolation: If the first analog signal is detected to have an abnormal data structure, the first analog link is immediately disconnected and dynamic noise injection is triggered to achieve physical layer hard isolation of the attack surface.

[0192] Specifically, in one possible embodiment, signal processing logic is hardened within a Field Programmable Gate Array (FPGA) to prevent software-layer side-channel attacks from tampering with the encoding and decoding process. Upon detecting an abnormal data structure (such as a malformed packet, residual stegoscopy, or a zero-day exploit in a Private Branch Exchange (PBX) device), the current analog link is immediately disconnected and dynamic noise injection is triggered, achieving physical-layer hard isolation of the attack surface.

[0193] The embodiment of the present application combines a hardware protection layer with a dynamic randomization strategy to form a three-dimensional defense system of "logic cannot be tampered + parameters cannot be predicted + links can be cut off".

[0194] Based on the above, while using the three strategies of dynamic quantization noise injection, adaptive spectrum shaping, and hardware-level security isolation at the same time, through the three-order collaboration of "dynamic quantization interference → spectrum intelligent purification → hardware logic isolation", the stealth carrier destruction, spectrum anomaly cleaning and physical link disconnection are completed within millisecond delays, ensuring the fidelity of voice signals in the core frequency band, and achieving real-time blocking and trace erasure of data entrainment attacks, thereby destroying the integrity of attack payloads lurking in digital protocols.

[0195] The second proxy module includes a second protocol identification module, a second analog proxy module, a second digital proxy module, and a second IP proxy module. The second protocol identification module is used to determine whether the call request from the caller is an analog relay access method, a digital relay access method, or an IP relay access method. The second analog proxy module is used to perform protocol adaptation on the second analog signal corresponding to the call request for analog relay access, and form output data in the form of an analog signal. The second digital proxy module is used to perform protocol adaptation on the second analog signal corresponding to the call request for analog relay access, and form output data in the form of a digital signal. The second IP proxy module is used to perform protocol adaptation on the second analog signal corresponding to the call request for analog relay access, and form output data in the form of an IP signal.

[0196] The working principle of the wired telephone protection system of this application is as follows:

[0197] The first and second proxy modules continuously monitor communication status. When an incoming or outgoing call is detected, the first or second proxy module immediately intervenes, extracting key information such as the calling or called number and the signaling protocol, and initiating bidirectional identity authentication. If authentication fails (e.g., due to permission issues), communication is terminated to mitigate risks. Once authentication is successful, the channel management module dynamically allocates a physically isolated channel, closes the physical switch, and loads security policies (such as dynamic noise injection and spectrum shaping parameters) to establish an end-to-end encrypted link.

[0198] The physical isolation module performs real-time protection processing on voice signals through this physically isolated channel (including high-frequency steganographic carrier destruction and abnormal spectrum erasure) and initiates a call request to the other end. If the called party does not respond, a timeout is triggered and the call is disconnected, reclaiming resources. If the call is established, the channel management module continuously monitors the link status (signal integrity and attack signatures), dynamically adjusts the isolation level, and maintains a full link log of operational behavior and abnormal events. When the call ends, the channel management module immediately disconnects the physical switch, releases analog link resources, and erases temporary data, returning the system to its initial monitoring state, completing the fully closed-loop process of "trigger → authentication → communication → release." This process, through a "normal isolation, dynamic connection" mechanism, achieves on-demand allocation of communication resources and minimizes the attack surface, ensuring physical layer security and controllability, and millisecond-level abnormality disconnection.

[0199] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A wired telephone protection method based on analog isolation, characterized in that: include: If the call request is a valid call request, unifying the signal in the valid call request into a first analog signal, and allocating an analog link to the first analog signal as the first analog link; Conducting the physical isolation channel of the first analog link while keeping the physical isolation channels of other analog links disconnected; wherein each analog link includes one physical isolation channel; performing safety data processing on the first analog signal to obtain a second analog signal after the safety data processing; converting the second analog signal after the security data processing into an output signal, and transmitting the output signal to the called party; wherein the output signal is obtained by converting according to the protocol used by the valid call request; The wired telephone protection method further comprises: Automatically scan the status of the physical isolation channels of all analog links in real time to obtain idle physical isolation channels; In response to a valid call request, binding at least one idle first analog link corresponding to the physically isolated channel to the valid call request; If the call ends or the call duration reaches a threshold, the valid call request is untied from all first analog links, the status of the physical isolation channels corresponding to all first analog links is restored to idle, and all temporary data of the first analog links are erased.

2. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: The physical isolation channel includes two mutually isolated physical layers and a physical switch arranged between the two physical layers.

3. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: When the valid call request is a first digital signal, converting the first digital signal into a first analog signal specifically includes: Decomposing the first digital signal by time slots to obtain a plurality of decoupled second digital signals; converting each second digital signal into a third analog signal as the first analog signal; Furthermore, a first analog link is allocated to each third analog signal.

4. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: In a case where the valid call request is a broadband telephone signal, converting the broadband telephone signal into a first analog signal specifically includes: Analyze the protocol stack consisting of Session Initiation Protocol and Real-time Transport Protocol in the Internet; converting a first voice stream in the broadband telephone signal into an analog baseband signal according to the protocol stack; The analog baseband signal is converted into the first analog signal.

5. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: If there is an abnormality in the physical isolation channel, the valid call request will be untied from all the first analog links, the status of the physical isolation channels corresponding to all the first analog links will be restored to idle, and an alarm log will be triggered.

6. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: The wired telephone protection method further comprises: A security protection policy is configured for each physically isolated channel, and the encoding parameters and isolation level in the security protection policy are dynamically adjusted according to the call scenario at the time of binding.

7. The wired telephone protection method based on analog isolation according to claim 6, characterized in that: The wired telephone protection method further comprises: The signal strength, coding integrity and physical switch status of the first analog link are collected in real time, and combined with dynamic permission allocation and authentication mechanism, abnormal access behavior of the first analog link is cut off at the millisecond level.

8. The wired telephone protection method based on analog isolation according to claim 7, characterized in that: The wired telephone protection method further comprises: Generate a log chain for channel operations and permission changes of the physically isolated channel.

9. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: If there is no idle physical isolation channel, the waiting queue management strategy is entered, and the elastic expansion mechanism is triggered at the same time to dynamically expand the capacity of the physical isolation channel.

10. The wired telephone protection method based on analog isolation according to claim 9, characterized in that: If a fault occurs in the physical isolation channel, the physical isolation channel is marked as a fault and is placed in an isolation area.

11. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: Determining whether the call request is a valid call request specifically includes: Performing legal verification on the number coding rules of the call request; If the number coding rule is legal, two-way identity authentication is performed on the calling party and the called party; If the two-way identity authentication is passed, the call request is a valid call request.

12. The wired telephone protection method based on analog isolation according to claim 1, characterized in that: Performing security data processing on the valid call request, specifically including: Dynamic noise is injected into the first analog signal, and real-time lossy re-encoding is performed on the first analog signal.

13. The wired telephone protection method based on analog isolation according to claim 12, characterized in that: Performing security data processing on the valid call request further includes: analyzing the time-frequency distribution characteristics of the first analog signal in real time to determine abnormal energy distortion in the first analog signal; In response to the abnormal energy distortion, a dynamic spectrum masking mechanism is adopted to irreversibly erase illegal data embedded in the covert channel corresponding to the abnormal energy distortion.

14. The wired telephone protection method based on analog isolation according to claim 13, characterized in that: Performing security data processing on the valid call request further includes: If it is detected that the first analog signal has an abnormal data structure, the first analog link is immediately cut off and dynamic noise injection is triggered to achieve physical layer hard isolation of the attack surface.

15. A wired telephone protection system based on analog isolation, characterized in that: It includes a first agent module, a first channel management module, a second channel management module, a second agent module and a plurality of mutually isolated analog links; The first proxy module is used to determine whether the call request is a valid call request; The first channel management module is configured to allocate an analog link of the calling end as the first analog link to the first analog signal corresponding to the valid call request when the call request is a valid call request; and conducting the physical isolation channel of the first analog link, while the physical isolation channels of the analog links of other calling ends remain disconnected; Each analog link includes a physical isolation channel, wherein the physical isolation channel is used to perform security data processing on the first analog signal corresponding to the valid call request to obtain a second analog signal after the security data processing; The second channel management module is used to allocate an analog link of the called end to the second analog signal; The second proxy module is used to convert the second analog signal into an output signal and transmit the output signal to the called party; wherein the output signal is obtained by converting the signal according to the protocol used by the valid call request; The wired telephone protection system is also used for: Automatically scan the status of the physical isolation channels of all analog links in real time to obtain idle physical isolation channels; In response to a valid call request, binding at least one idle first analog link corresponding to the physically isolated channel to the valid call request; If the call ends or the call duration reaches a threshold, the valid call request is untied from all first analog links, the status of the physical isolation channels corresponding to all first analog links is restored to idle, and all temporary data of the first analog links are erased.

16. The wired telephone protection system based on analog isolation according to claim 15, characterized in that: The first agent module is further configured to convert the digital signal into a first analog signal when the valid call request is a digital signal.

17. The wired telephone protection system based on analog isolation according to claim 15, characterized in that: The physically isolated channel includes a hardware decoding module and a hardware-based lossy encoding module; The hardware decoding module decodes the signal; The hardware-based lossy encoding module is used to perform time-varying distortion processing on the signal to obtain a second analog signal after security data processing.

18. The wired telephone protection system based on analog isolation according to claim 17, characterized in that: The hardware decoding module is configured to convert a first voice stream in the broadband telephone signal into an analog baseband signal according to a protocol stack of the broadband telephone signal when the valid call request is a broadband telephone signal; The hardware-based lossy encoding module is used to convert the analog baseband signal into the first analog signal.

Citation Information

Patent Citations

  • Leakage prevention device for mobile phone

    CN101127985A

  • Anti-monitoring method and device for telephone set

    CN112671981A

  • Telephone system capable of automatically switching SIP and analog telephone

    CN117411857A