Call encryption method, system and device and storage medium

By employing a dual encryption mechanism for cloud phone call data, using a second key and a first key to encrypt call data between the calling terminal and the cloud terminal server, and between the cloud terminal server and the called terminal, the problem of data leakage in traditional cloud phone calls is solved, achieving higher security.

CN120835293APending Publication Date: 2025-10-24CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510976439.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

Traditional cloud phone calling methods are prone to data leakage during data transmission. Especially with the diverse needs of cloud phone calling, existing encryption schemes are insufficient to guarantee call security.

Method used

A dual encryption mechanism is adopted. The calling terminal and the cloud terminal server use a second key to encrypt the call data, and then use the first key to encrypt it again. A similar process is used between the cloud terminal server and the called terminal to ensure the security of the data during transmission.

Benefits of technology

It improves the security of encrypted calls between the calling and called terminals, enhances the data transmission security of cloud phone calls, and prevents data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120835293A_ABST
    Figure CN120835293A_ABST
Patent Text Reader

Abstract

The invention provides a call encryption method, system and device and a storage medium, relates to the technical field of communication, and can improve the security of a call between a calling terminal and a called terminal. The method comprises the following steps: receiving a first key from a key management platform, wherein the first key is determined based on identity information of a called terminal and identity information of a cloud terminal server; receiving first call data from the calling terminal, the first call data being obtained by encrypting call data transmitted by the calling terminal to the called terminal based on a second key, and the second key being determined based on the identity information of the calling terminal and the identity information of the called terminal; and sending second call data to the called terminal, wherein the second call data is obtained by encrypting the first call data based on the first key.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a call encryption method, system, device and storage medium. BACKGROUND

[0002] With the rapid development of the communication technology field, the application of cloud phones is becoming more and more widespread. At present, the data transmission mode of the call through the cloud phone is plaintext transmission, that is, the call data in the call process is not encrypted and directly transmits the original call data.

[0003] As described above about the cloud phone call method, with the increasing demand for cloud phone calls, the traditional cloud phone call method has the problem of easily leaking call data when facing the demand for encrypted calls of the cloud phone. SUMMARY

[0004] The present application provides a call encryption method, system, device and storage medium, which can improve the security of the call between the calling terminal and the called terminal.

[0005] To achieve the above purpose, the present application adopts the following technical scheme:

[0006] In a first aspect, the present application provides a call encryption method, which comprises: receiving a first key from a key management platform, the first key being determined based on the identity information of the called terminal and the identity information of the cloud terminal server; receiving first call data from the calling terminal, the first call data being obtained by encrypting the call data transmitted by the calling terminal to the called terminal based on a second key, the second key being determined based on the identity information of the calling terminal and the identity information of the called terminal; and sending second call data to the called terminal, the second call data being obtained by encrypting the first call data based on the first key.

[0007] The call encryption method provided by the present application receives the call data encrypted based on the second key from the calling terminal, improves the security of the call between the calling terminal and the cloud terminal server, and then performs secondary encryption on the call data encrypted based on the second key from the calling terminal based on the first key, and sends the secondary encrypted call data to the called terminal, thereby improving the security of the call between the cloud terminal server and the called terminal, further improving the security of the encrypted call between the calling terminal and the called terminal, and further improving the security of the call between the calling terminal and the called terminal.

[0008] In a possible implementation manner, the first call data is obtained by encrypting the call data based on a lightweight encryption algorithm and the second key.

[0009] In a possible implementation, the second call data is obtained by encrypting the first call data based on an encryption algorithm and the first key.

[0010] In a possible implementation, the method further includes: receiving third call data from the called terminal, the third call data being obtained by re-encrypting call data transmitted by the called terminal to the calling terminal based on the first key and the second key; and sending fourth call data to the calling terminal, the fourth call data being obtained by decrypting the third call data based on the first key.

[0011] In a possible implementation, the method further includes: receiving encryption indication information from the calling terminal, the encryption indication information being used to indicate that the call between the calling terminal and the called terminal is encrypted.

[0012] In a second aspect, the present application provides a call encryption system, which includes: a calling terminal, a called terminal, a cloud terminal server, and a key management platform; the calling terminal sends a first message to the key management platform, the first message including a first key request message; the called terminal sends a second message to the key management platform, the second message including a second key request message; the cloud terminal server sends a third message to the key management platform, the third message including a third key request message; the key management platform determines a first key based on identity information of the calling terminal and identity information of the called terminal, and determines a second key based on identity information of the calling terminal and identity information of the cloud platform server; the key management platform sends the first key and the second key to the called terminal; the key management platform sends the first key to the cloud terminal server, the first key being determined based on identity information of the called terminal and identity information of the cloud terminal server; the key management platform adds a first status identifier to the first key; the status identifier is used to indicate that the first key is in a delivered state; in a case where the first key has the first status identifier, the key management platform sends the second key to the calling terminal; the key management platform adds a second status identifier to the second key; the second status identifier is used to indicate that the second key is in a delivered state; the calling terminal sends first call data to the cloud terminal server, the first call data being obtained by encrypting call data transmitted by the calling terminal to the called terminal based on the second key, the second key being determined based on identity information of the calling terminal and identity information of the called terminal; the cloud terminal server sends second call data to the called terminal, the second call data being obtained by encrypting the first call data based on the first key.

[0013] In a possible implementation, the call encryption method further includes: the calling terminal encrypts the first call data based on a lightweight encryption algorithm and the second key to obtain the second call data; and the cloud terminal server encrypts the call data based on an encryption algorithm and the first key to obtain the first call data.

[0014] In a possible implementation, the call encryption method further includes: the called terminal sending third call data to the cloud terminal server, the third call data being obtained by performing secondary encryption on the call data transmitted by the called terminal to the caller terminal based on the first key and the second key; and the cloud terminal server sending fourth call data to the caller terminal, the fourth call data being obtained by performing decryption on the third call data based on the first key.

[0015] In a possible implementation, the call encryption method further includes: the caller terminal sending encryption indication information to the cloud terminal server, the encryption indication information being used to indicate that the call between the caller terminal and the called terminal is encrypted; and sending the fourth call data to the caller terminal, the fourth call data being obtained by performing decryption on the third call data based on the first key.

[0016] In a third aspect, the present application provides a call encryption apparatus, which includes: a communication unit and a processing unit; the processing unit is configured to instruct the communication unit to receive a first key from a key management platform, the first key being determined based on identity information of a called terminal and identity information of a cloud terminal server; the communication unit is further configured to receive first call data from a caller terminal, the first call data being obtained by performing encryption on call data transmitted by the caller terminal to the called terminal based on a second key, the second key being determined based on identity information of the caller terminal and identity information of the called terminal; and the processing unit is further configured to instruct the communication unit to send second call data to the called terminal, the second call data being obtained by performing encryption on the first call data based on the first key.

[0017] In a possible implementation, the first call data is obtained by performing encryption on the call data based on a lightweight encryption algorithm and the second key.

[0018] In a possible implementation, the second call data is obtained by performing encryption on the first call data based on an encryption algorithm and the first key.

[0019] In a possible implementation, the processing unit is further configured to instruct the communication unit to receive third call data from the called terminal, the third call data being obtained by performing secondary encryption on the call data transmitted by the called terminal to the caller terminal based on the first key and the second key; and the processing unit is further configured to instruct the communication unit to send fourth call data to the caller terminal, the fourth call data being obtained by performing decryption on the third call data based on the first key.

[0020] In a possible implementation, the processing unit is further configured to instruct the communication unit to receive encryption indication information from the caller terminal, the encryption indication information being used to indicate that the call between the caller terminal and the called terminal is encrypted.

[0021] In a fourth aspect, the present application provides a call encryption device, comprising: a processor and a communication interface; the communication interface is coupled with the processor, and the processor is configured to run computer programs or instructions to implement the call encryption method as described in the first aspect and any possible implementation manner of the first aspect.

[0022] In a fifth aspect, the present application provides a computer readable storage medium, which stores instructions, when the instructions are run on a terminal, the terminal executes the call encryption method as described in the first aspect and any possible implementation manner of the first aspect.

[0023] In a sixth aspect, the present application provides a computer program product comprising instructions, when the computer program product is run on a call encryption device, the call encryption device executes the call encryption method as described in the first aspect and any possible implementation manner of the first aspect.

[0024] In a seventh aspect, the present application provides a chip, comprising a processor and a communication interface, the communication interface is coupled with the processor, and the processor is configured to run computer programs or instructions to implement the call encryption method as described in the first aspect and any possible implementation manner of the first aspect.

[0025] Specifically, the chip provided in the present application further comprises a memory for storing computer programs or instructions. BRIEF DESCRIPTION OF DRAWINGS

[0026] Figure 1 A structural diagram of a call encryption system provided by an embodiment of the present application is shown in the figure;

[0027] Figure 2 A structural diagram of a call encryption device provided by an embodiment of the present application is shown in the figure;

[0028] Figure 3 A flowchart of a call encryption method provided by an embodiment of the present application is shown in the figure;

[0029] Figure 4 A structural diagram of another call encryption device provided by an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0030] The call encryption method, device and storage medium provided by the embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0031] The term "and / or" in this paper is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone.

[0032] The terms "first" and "second" and the like in the description of the present application and in the claims of the present application are used for the purpose of distinguishing different objects, or different processing steps, and are not necessarily used to describe a particular sequential order, unless explicitly stated that sequence.

[0033] In addition, the terms "comprising" and "having" and any variations thereof in the description of the present application are intended to cover the non-exclusive inclusion of the steps or units listed. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but can optionally include other steps or units not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0034] It should be noted that in the embodiments of the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design presented as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Rather, the use of "exemplary" or "for example" is intended to present concepts in a concrete manner.

[0035] In the description of the present application, "a plurality of" means two or more, unless otherwise specified.

[0036] At present, cloud phones run mobile phone operating systems on cloud servers through virtualization technology, and user terminals only provide input and output interaction interfaces, screen rendering, and send touch instructions, and business logic and data processing are completed through cloud servers.

[0037] At present, the implementation method of the traditional encrypted call scheme is that the calling mobile phone carries an encrypted call identifier in the IP call request, which is used to indicate that the called mobile phone is an encrypted call this time, and the calling and called mobile phones realize key negotiation through interaction with the key cloud platform, thereby realizing encrypted call. In order to ensure encryption security, a one-call-one-key mechanism is generally used to encrypt call data. This encrypted call scheme is applied to calls between non-cloud mobile phones.

[0038] With the rapid development of the communication technology field, cloud phones are increasingly widely used. At present, the data transmission mode of the call through the cloud phone is plaintext transmission, that is, the call data in the call process is not encrypted and directly transmits the original call data.

[0039] As described above with respect to the cloud phone call method, as the demand for cloud phone calls becomes more and more diverse, when facing the demand for encrypted calls of cloud phones, the traditional cloud phone call method has the problem of easy leakage of call data.

[0040] Therefore, the application receives the call data encrypted based on the second key from the calling terminal, improves the security of the call between the calling terminal and the cloud terminal server, and then performs secondary encryption on the call data encrypted based on the second key from the calling terminal based on the first key, and sends the secondary encrypted call data to the called terminal, improves the security of the call between the cloud terminal server and the called terminal, further improves the security of the encrypted call between the calling terminal and the called terminal, and further improves the security of the call between the calling terminal and the called terminal.

[0041] The technical scheme provided by the embodiments of the application can be applied to various communication systems, for example, a new radio (NR) communication system using a 5th generation mobile communication technology (5G), a future evolution system, or a multi-communication fusion system.

[0042] Exemplarily, Figure 1 A structure diagram of a call encryption system provided by the embodiments of the application is shown in FIG. 1. The call encryption system can include at least one calling terminal 101, one called terminal 102, one key management platform 103, and one cloud terminal server 104. The calling terminal device 101, the called terminal 102, and the key management platform 103 can be in communication connection with the cloud terminal server 104. Figure 1 In the case shown in FIG. 1, only one calling terminal 101, one called terminal 102, one key management platform 103, and one cloud terminal server 104 are shown.

[0043] In a possible implementation, the calling terminal 101 is configured to send a second message including a second key request message to the key management platform 103, and send third call data to the cloud terminal server 104, the third call data being obtained by performing secondary encryption on the call data transmitted by the called terminal 102 to the calling terminal 101 based on the first key and the second key.

[0044] In a possible implementation, the called terminal 102 is configured to send a first message including a first key request message to the key management platform 103, and send first call data to the cloud terminal server 104, the first call data being obtained by performing encryption on the call data transmitted by the calling terminal 101 to the called terminal 102 based on the second key, the second key being determined based on the identity information of the calling terminal 101 and the identity information of the called terminal 102; and perform encryption on the first call data based on a lightweight encryption algorithm and the second key to obtain second call data.

[0045] In a possible implementation, the key management platform 103 is configured to determine the first key based on the identity information of the calling terminal 101 and the identity information of the called terminal 102, determine the second key based on the identity information of the calling terminal 101 and the identity information of the cloud terminal server 104, send the first key and the second key to the called terminal 102, send the first key to the cloud terminal server 104, the first key being determined based on the identity information of the called terminal 102 and the identity information of the cloud terminal server 104, add a first status identifier to the first key, and use the status identifier to indicate that the first key is in a delivered state, and send the second key to the calling terminal 101 in a case where the first key has the first status identifier.

[0046] In a possible implementation, the cloud terminal server 104 is configured to send a third message to the key management platform 103, the third message including a third key request message, and send second call data to the called terminal 102, the second call data being obtained by encrypting the first call data based on the first key.

[0047] Optionally, the calling terminal 101 and the called terminal 102 can be a large-capacity device (for example, a server integrated with a large number of boards) having a wireless communication function, and can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted. The calling terminal 101 and the called terminal 102 can also be deployed on water (for example, a ship) or in the air (for example, an airplane, a balloon, or a satellite).

[0048] The key management platform 103 can be a system for generating, storing, distributing, rotating, auditing, and destroying encryption keys. The key management platform 103 can be deployed in a local data center (for example, an enterprise data center). The key management platform 103 can also be deployed in the cloud (for example, a private cloud and a public cloud).

[0049] The cloud terminal server 104 can be a server based on cloud computing technology, which can virtualize terminal hardware resources and operating systems, and can be deployed on a cloud server to provide a virtual terminal environment and communication services for users through the Internet.

[0050] It should be noted that, Figure 1 The example framework diagram is only for illustration, Figure 1 The number of nodes included in the framework diagram and the names of various devices are not limited, and in addition to Figure 1 the function nodes shown in the framework diagram, the call encryption system can also include other nodes, such as core network devices, which are not limited in the present application.

[0051] The application scenarios of the embodiments of this application are not limited. The system architecture and business scenarios described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. It is known to those skilled in the art that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0052] When implementing it specifically, Figure 1 All devices in the Figure 2 The structure shown, or including Figure 2 Parts shown. Figure 2 This is a schematic diagram of the composition of a call encryption device 20 provided in an embodiment of the present application. The call encryption device 20 can be a calling terminal 101 or a chip or a system on a chip in the calling terminal 101. Alternatively, the call encryption device 20 can be a called terminal 102 or a chip or a system on a chip in the called terminal 102. Figure 2 As shown, the call encryption device 20 may include a processor 201 and a bus 202.

[0053] Furthermore, the call encryption device 20 may further include a communication interface 203 and a memory 204 . The processor 201 , the memory 204 and the communication interface 203 may be connected via a bus 202 .

[0054] The processor 201 is a CPU, a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 201 may also be other devices with processing functions, such as circuits, devices, or software modules, without limitation.

[0055] The bus 202 is used to transmit information between the components included in the call encryption device 20.

[0056] Communication interface 203 is used to communicate with other devices or other communication networks. Such other communication networks may be Ethernet, radio access networks (RAN), wireless local area networks (WLAN), etc. Communication interface 203 may be a module, circuit, communication interface, or any other device capable of implementing communication.

[0057] The memory 204 is used to store instructions, where the instructions may be computer programs.

[0058] The memory 204 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions, a random access memory (RAM), or other type of dynamic storage device that can store information and / or instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, etc., without limitation.

[0059] It should be noted that the memory 204 can exist independently of the processor 201 or can be integrated with the processor 201. The memory 204 can be used to store instructions or program codes or some data, etc. The memory 204 can be located in the call encryption device 20 or outside the call encryption device 20, without limitation.

[0060] In an example, the processor 201 can include one or more CPUs, such as the CPU0 and CPU1 (not shown in the figure) in the CPU 100. Figure 2

[0061] As an optional implementation, the call encryption device 20 includes multiple processors.

[0062] As an optional implementation, the call encryption device 20 can further include an output device 205 and an input device 206 (not shown in the figure). Exemplarily, the input device 206 is a keyboard, a mouse, a microphone, or a joystick, etc., and the output device 205 is a display screen, a speaker, etc.

[0063] It should be noted that the call encryption device 20 can be a desktop computer, a laptop computer, a network server, a mobile phone, a tablet computer, a wireless terminal, an embedded device, a chip system, or a device with a similar structure in the Figure 2 In addition, the constituent structures shown in the figures do not constitute a limitation on the call encryption device 20 and each device in the CPU 100. In addition to the components shown in the figures, each device in the CPU 100 can include more or fewer components, or combine some components, or different component arrangements. Figure 2 Figure 1 Figure 2 Figure 2 Figure 1 Figure 2 In the figures, each device in the CPU 100 can include more or fewer components than shown in the figures, or combine some components, or different component arrangements.​​​​​​

[0064] In the embodiment of the present application, the chip system can be composed of chips, or can include chips and other discrete devices.

[0065] In addition, the actions and terms involved in the various embodiments of this application can refer to each other without limitation. The message names or parameter names in the messages exchanged between the various devices in the embodiments of this application are only examples, and other names can also be used in specific implementations without limitation.

[0066] The following combination Figure 1 The call encryption system shown describes the call encryption method provided in the embodiment of the present application. Among them, the actions, terms, etc. involved in the various embodiments of the present application can refer to each other without limitation. The message names or parameter names in the messages exchanged between the various devices in the embodiment of the present application are only examples, and other names can also be used in the specific implementation without limitation. The actions involved in the various embodiments of the present application are only examples, and other names can also be used in the specific implementation, such as: "included in" in the embodiment of the present application can also be replaced by "carried on" or "carried in", etc.

[0067] like Figure 3 As shown, a call encryption method proposed in an embodiment of the present application includes:

[0068] S301: The cloud terminal server receives a first key from a key management platform.

[0069] The first key is determined based on the identity information of the called terminal and the identity information of the cloud terminal server.

[0070] Optionally, the cloud terminal server may receive the first key from the key management platform in the following manner: the key management platform extracts a first initial key that does not have a first status identifier from a pre-stored key repository; the key management platform binds the identity information of the called terminal and the identity of the cloud terminal server to the first initial key to generate the first key; the key management platform encrypts the first key using a public key to generate a data packet, and sends the data packet to the cloud terminal server. The cloud terminal server decrypts the data packet based on the public key to obtain the first key.

[0071] Furthermore, optionally, if the key management platform's pre-stored key repository does not contain a first initial key available for use by the cloud terminal server, the key management platform may generate a first key for the cloud terminal server. The key management platform may generate the first key for the cloud terminal server using a dynamic random number negotiation method, an asymmetric encryption-based key exchange method, or an identity-based encrypted call key method, which is not limited in this embodiment of the present application.

[0072] Optionally, the process of obtaining the call request information, the calling mobile phone identity, and the called mobile phone identity can be that the cloud terminal server receives a call request from the calling mobile phone, the call request including an encrypted identity, a calling mobile phone number, and a called mobile phone number. The cloud terminal server determines that the call is an encrypted call based on the encrypted identity, and establishes a call connection with the called mobile phone through the call platform based on the called mobile phone number.

[0073] S302, the cloud terminal server receives first call data from the calling terminal.

[0074] The first call data is encrypted based on a second key for call data transmitted by the calling terminal to the called terminal, and the second key is determined based on the identity information of the calling terminal and the identity information of the called terminal. The second key can be a lightweight encryption key, and the encryption algorithm based on the second key for encrypting the call data has a complexity less than a preset complexity threshold.

[0075] Optionally, the process of determining the second key by the key management platform based on the identity information of the calling terminal and the identity information of the called terminal can be that the key management platform extracts a second initial key that does not exist in the first state identifier in the pre-stored key library, the key management platform binds the identity information of the calling terminal and the identity of the called terminal with the second initial key to generate the second key, the key management platform encrypts the second key through a public key to generate a data packet, and sends the data packet to the cloud terminal server. The cloud terminal server decrypts the data packet based on the public key to obtain the second key.

[0076] Further, optionally, the pre-stored key library of the key management platform does not have a first initial key available for the calling terminal, and the key management platform can generate a second key for the cloud terminal server. The method of generating the second key for the cloud terminal server by the key management platform can be a lightweight key generation method based on real-time random numbers, a lightweight key derivation method based on a key agreement protocol, or a lightweight derivation method based on a pre-shared key, which is not limited in the embodiments of the application.

[0077] In a possible implementation, the first call data is encrypted based on a lightweight encryption algorithm and the second key for call data.

[0078] Illustratively, the lightweight encryption algorithm can include a lightweight real-time voice stream encryption algorithm, a lightweight hash function encryption algorithm, and other lightweight encryption algorithms (such as quantum-resistant key exchange encryption algorithms), which are not limited in the embodiments of the application.

[0079] S303, the cloud terminal server sends second call data to the called terminal.

[0080] The second call data is obtained by encrypting the first call data based on the first key.

[0081] In a possible implementation, the second call data is obtained by encrypting the first call data based on an encryption algorithm and the first key. Optionally, the called terminal receives the second call data from the cloud terminal server, and the called terminal can decrypt the second call data by using the first key and the second key to obtain the call data without encryption.

[0082] For example, the encryption algorithm can include a triple data encryption algorithm, an elliptic curve encryption algorithm, and other encryption algorithms (for example, an advanced encryption standard), and the embodiments of the present application do not limit this.

[0083] In a possible implementation, the cloud terminal server receives third call data from the called terminal, the third call data is obtained by encrypting the call data transmitted by the called terminal to the calling terminal based on the first key and the second key, and the cloud terminal server sends fourth call data to the calling terminal, the fourth call data is obtained by decrypting the third call data based on the first key.

[0084] Optionally, the calling terminal receives the fourth call data from the cloud terminal server, and the calling terminal decrypts the fourth call data based on the first key to obtain the call data without encryption.

[0085] It can be understood that, before the calling terminal and the called terminal communicate, a call connection between the calling terminal and the called terminal needs to be established, and the call connection establishment process is described below.

[0086] Optionally, before the cloud terminal server receives the call request information from the calling terminal, the following steps can also be included: the key management platform obtains a registration request message from the calling terminal, the cloud terminal server, and the called terminal, the registration request message includes identity information of the calling terminal, identity information of the cloud terminal server, and identity information of the called terminal, the key management platform stores the identity information in the registration request message, and completes authentication registration of the calling terminal, the cloud terminal server, and the called terminal.

[0087] Further, optionally, the cloud terminal server receives the registration request information from the calling terminal and stores the identity information of the calling terminal to complete authentication registration of the calling terminal in the cloud terminal server. The cloud terminal server sends the identity information of the cloud terminal server to the calling terminal, and the calling terminal stores the identity information of the cloud terminal server to complete authentication registration of the cloud terminal server in the calling terminal.

[0088] Optionally, the cloud terminal server receives call request information from the calling terminal, the call request information comprising calling terminal identity information, called terminal identity information, and encryption indication information, and the cloud terminal server establishes a call connection with the called terminal based on the called terminal identity information.

[0089] In a possible implementation, the cloud terminal server receives encryption indication information from the calling terminal, the encryption indication information being used to indicate that the call between the calling terminal and the called terminal is encrypted.

[0090] Optionally, the key management platform receives a first message from the calling terminal, the first message comprising a key pre-request message, and the key pre-request message comprising calling terminal identity information, called terminal identity information, and cloud terminal server identity information.

[0091] Further, optionally, the key management platform receives second information from the called terminal and third information from the cloud terminal server, the second information comprising called terminal key request information, the called terminal key request information comprising called terminal identity information and cloud terminal server identity information, and the third information comprising cloud terminal server key request information, the cloud terminal server key request information comprising calling terminal identity information, called terminal identity information, and cloud terminal server identity information. The key management platform determines a first key based on the called terminal identity information and the cloud terminal server identity information, and determines a second key based on the calling terminal identity information and the called terminal identity information. The key management platform sends the first key and the second key to the called terminal, sends the first key to the cloud terminal server, and sends the second key to the calling terminal.

[0092] Optionally, the cloud terminal server receives the first key from the key management platform, and sends a call connection establishment success message to the calling terminal.

[0093] In view of this, the embodiment of the present application proposes a call encryption method, receiving call data encrypted based on a second key from a calling terminal, ensuring encrypted call between the calling terminal and the cloud terminal server, and then performing secondary encryption on the call data encrypted based on the second key from the calling terminal based on a first key, and sending the secondary encrypted call data to a called terminal, ensuring encrypted call between the cloud terminal server and the called terminal, further improving the security of encrypted call between the calling terminal and the called terminal, and further ensuring encrypted call between the calling terminal and the called terminal.

[0094] It can be understood that the call encryption method described above can be implemented by a call encryption device. The call encryption device includes a hardware structure and / or a software module corresponding to each function in order to implement the above functions. Those skilled in the art should easily realize that, in combination with the modules and algorithm steps of each example described in the embodiments disclosed in the present application, the embodiments disclosed in the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in hardware or computer software driven hardware depends on the specific application of the technical solution and the design constraints. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments disclosed in the present application.

[0095] The embodiments disclosed in the present application can divide the function modules according to the call encryption device generated by the above method examples. For example, each function module can be divided according to each function, or two or more functions can be integrated into one processing module. The integrated module can be implemented in the form of hardware or software function module. It should be noted that the division of the modules in the embodiments disclosed in the present application is illustrative, and is only a logical function division. There can be another division method in actual implementation.

[0096] The embodiments disclosed in the present application can divide the function modules according to the call encryption device generated by the above method examples. For example, each function module can be divided according to each function, or two or more functions can be integrated into one processing module. The integrated module can be implemented in the form of hardware or software function module. It should be noted that the division of the modules in the embodiments disclosed in the present application is illustrative, and is only a logical function division. There can be another division method in actual implementation.

[0097] Figure 4 Another structural schematic diagram of a call encryption device provided by the embodiments of the present application is shown in FIG. 4. As shown in FIG. 4, the call encryption device 40 can be used to execute the call encryption method shown in FIG. 3. The call encryption device 40 includes a communication unit 401 and a processing unit 402. Figure 4 Figure 3

[0098] ​​Processing unit 402 is used to instruct the communication unit 401 to receive a first key from the key management platform, where the first key is determined based on the identity information of the called terminal and the identity information of the cloud terminal server; processing unit 402 is also used to instruct the communication unit 401 to receive first call data from the calling terminal, where the first call data is obtained by encrypting the call data transmitted from the calling terminal to the called terminal based on the second key, where the second key is determined based on the identity information of the calling terminal and the identity information of the called terminal; processing unit 402 is also used to instruct the communication unit 401 to send second call data to the called terminal, where the second call data is obtained by encrypting the first call data based on the first key.

[0099] In a possible implementation, the first call data is obtained by encrypting the call data based on a lightweight encryption algorithm and a second key.

[0100] In a possible implementation, the second call data is obtained by encrypting the first call data based on an encryption algorithm and a first key.

[0101] In one possible implementation, the processing unit 402 is also used to instruct the communication unit 401 to receive third call data from the called terminal, where the third call data is obtained by secondary encrypting the call data transmitted from the called terminal to the calling terminal based on the first key and the second key; the processing unit 402 is also used to instruct the communication unit 401 to send fourth call data to the calling terminal, where the fourth call data is obtained by decrypting the third call data based on the first key.

[0102] In a possible implementation, the processing unit 402 is further configured to instruct the communication unit 401 to receive encryption instruction information from the calling terminal, where the encryption instruction information is used to instruct encryption of the call between the calling terminal and the called terminal.

[0103] Through the description of the above embodiments, those skilled in the art will clearly understand that for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0104] The present disclosure also provides a computer-readable storage medium having instructions stored thereon. When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the call encryption method provided in the above-mentioned embodiment of the present disclosure.

[0105] The embodiment of the present disclosure further provides a computer program product containing instructions, which, when executed on an electronic device, causes the electronic device to perform the call encryption method provided by the embodiment of the present disclosure.

[0106] In some embodiments, a computer-readable storage medium can include a non- transitory computer-readable storage medium (e.g., any computer-readable medium that is not a carrier wave). In some embodiments, a computer-readable storage medium can include a RAM, a ROM, an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), a flash memory, or a floppy disk. In some embodiments, a computer-readable storage medium can include a tangible and non-transitory medium. In some embodiments, a computer-readable storage medium can include a storage medium that stores data that can be read by a computer system. In some embodiments, a computer- readable storage medium can not include a propagated signal. In some embodiments, a computer- readable storage medium can include a source or destination of computer-readable instructions encoded in an analog or digital form.

[0107] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method of call encryption, characterized by The method comprises: receiving a first key from a key management platform, the first key being determined based on identity information of a called terminal and identity information of a cloud terminal server; receiving first call data from a calling terminal, the first call data being encrypted based on a second key, the second key being determined based on identity information of the calling terminal and identity information of the called terminal; sending second call data to the called terminal, the second call data being encrypted based on the first key.

2. The method of claim 1, wherein, The first call data is encrypted based on a lightweight encryption algorithm and the second key.

3. The method according to claim 1 or 2, characterized in that, The second call data is encrypted based on an encryption algorithm and the first key.

4. The method of claim 1, wherein, The method further comprises: receiving third call data from the called terminal, the third call data being twice encrypted based on the first key and the second key, the third call data being call data transmitted by the called terminal to the calling terminal; sending fourth call data to the calling terminal, the fourth call data being decrypted based on the first key, the fourth call data being the third call data.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: receiving encryption indication information from the calling terminal, the encryption indication information being used to indicate encryption of a call between the calling terminal and the called terminal.

6. A method of call encryption, characterized by The call encryption method is applied to a call encryption system, the call encryption system comprising a calling terminal, a called terminal, a cloud terminal server, and a key management platform; the method comprises: the calling terminal sending a first message to the key management platform, the first message comprising identity information of the calling terminal; the called terminal sending a second message to the key management platform, the second message comprising identity information of the called terminal; the cloud terminal server sending a third message to the key management platform, the third message comprising identity information of the cloud platform server; the key management platform determining the first key based on the identity information of the calling terminal and the identity information of the called terminal, and determining the second key based on the identity information of the calling terminal and the identity information of the cloud platform server; the key management platform sending the first key and the second key to the called terminal; the key management platform sending a first key to the cloud terminal server, the first key being determined based on identity information of a called terminal and identity information of a cloud terminal server; the key management platform adding a first status identifier to the first key; the first status identifier is used to indicate that the first key is in a delivered state; in the case where the first key has the first status identifier, the key management platform sends the second key to the calling terminal; the key management platform adding a second status identifier to the second key; the second status identifier is used to indicate that the second key is in a delivered state; The calling terminal sends first call data to the cloud terminal server, the first call data being encrypted based on second key from call data transmitted by the calling terminal to the called terminal, the second key being determined based on identity information of the calling terminal and identity information of the called terminal; The cloud terminal server sends second call data to the called terminal, the second call data being encrypted based on the first key from the first call data.

7. The method of claim 6, wherein, The method further comprises: The calling terminal encrypts the first call data based on a lightweight encryption algorithm and the second key to obtain second call data; The cloud terminal server encrypts the call data based on a symmetric encryption algorithm and the first key to obtain first call data.

8. The method of claim 6, wherein, The method further comprises: The called terminal sends third call data to the cloud terminal server, the third call data being twice encrypted based on the first key and the second key from call data transmitted by the called terminal to the calling terminal; The cloud terminal server sends fourth call data to the calling terminal, the fourth call data being decrypted based on the first key from the third call data.

9. The method of claim 6, wherein, The method further comprises: The calling terminal sends encryption indication information to the cloud terminal server, the encryption indication information being used to indicate encryption of call between the calling terminal and the called terminal.

10. A cloud phone encrypted call implementation device, characterized in that, The unified acquisition device based on multiple object storages comprises a communication unit and a processing unit; The communication unit is used to receive a first key from a key management platform, the first key being determined based on identity information of a called terminal and identity information of a cloud terminal server; The communication unit is also used to receive first call data from a calling terminal, the first call data being encrypted based on a second key from call data transmitted by the calling terminal to the called terminal, the second key being determined based on identity information of the calling terminal and identity information of the called terminal; The processing unit is used to send second call data to the called terminal, the second call data being encrypted based on the first key from the first call data.

11. A cloud phone encrypted call implementation device, characterized in that, It comprises: A processor and a communication interface; the communication interface and the processor are coupled, and the processor is used to run computer programs or instructions to realize the call encryption implementation method according to any one of claims 1-5.

12. A computer-readable storage medium having stored therein instructions, the computer-readable storage medium comprising: When a computer executes the instructions, the computer executes the call encryption implementation method according to any one of claims 1-5.