Analog encrypted telephone terminal and method based on public switched telephone network transmission
By controlling the NMOS transistor and signal coupling transformer with physical encryption buttons, the hardware switching control and physical key destruction of the analog encrypted phone are realized, which solves the problems of analog encrypted phones being easily shut down by software and key residue, and improves the reliability and security of the device.
Patent Information
- Application Number
- CN202611046302.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-14
- Publication Date
- 2026-08-25
AI Technical Summary
Existing analog encrypted phone solutions are easily shut down by software, mechanical relay switching has poor reliability, and the key cannot be completely physically destroyed after the encrypted call ends, posing risks and security vulnerabilities.
The security encryption chip uses physical encryption buttons to directly control the on/off state of the NMOS transistor, along with the power supply and enable pin. Combined with an external independent power supply and a signal coupling transformer to isolate DC, it achieves pure hardware switching control and physical key destruction, avoiding software intervention.
To ensure the continuous operation of encryption functions, improve device reliability, prevent key residue, eliminate the risk of unauthorized shutdown, and guarantee call security.
Smart Images

Figure CN122640499A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of analog communication technology, and in particular to an analog encrypted telephone terminal and method based on transmission over a public switched telephone network. Background Technology
[0002] The Public Switched Telephone Network (PSTN), as a widely deployed basic communication infrastructure, is still extensively used in government, military, enterprise, and emergency communication scenarios. Traditional analog telephone lines themselves lack encryption capabilities; voice signals are transmitted transparently over twisted-pair cables in the form of baseband analog current, making them highly vulnerable to eavesdropping and information leakage. Therefore, the industry has long researched solutions for overlaying encryption processing onto analog telephone lines to give them anti-eavesdropping capabilities.
[0003] However, existing analog encrypted telephone solutions typically achieve encryption by adding a security encryption chip and control circuitry inside the telephone. Chinese invention patent CN112671981A discloses a method and device for preventing telephone eavesdropping. This method involves detecting key presses on the telephone keypad after establishing a regular call with the calling device; determining the mode conversion command corresponding to the key presses; synchronizing with the calling device and verifying its identity; and, upon confirming the identity, randomly selecting frequency interleaving parameters and amplitude transformation parameters from a parameter set and sending these parameters to the calling device. Based on these parameters, the call content is simulated and encrypted to establish a secure call. This invention patent solves the problems of high computational load, high cost, complex supporting devices, and poor voice fidelity in digital encrypted eavesdropping prevention devices, thereby improving the security strength of analog encrypted eavesdropping prevention devices. However, the encryption function of the above-mentioned scheme is controlled by the terminal main control program through software instructions. The encryption function may be illegally turned off without the user's knowledge, causing subsequent calls to be transmitted in plain language, which poses a certain risk. Furthermore, if the power supply to the security encryption chip is not physically cut off after the encrypted call ends, the temporary session key in the chip's internal memory may still remain, and the complete destruction of the key cannot be guaranteed, posing a risk of being extracted or recovered afterward.
[0004] Therefore, there is an urgent need to propose an analog encrypted telephone terminal and method based on public switched telephone network transmission. Summary of the Invention
[0005] This invention provides an analog encrypted telephone terminal and method based on public switched telephone network transmission. It solves the technical problems of existing analog encrypted telephones, such as relying on software control which is easily bypassed, poor reliability of mechanical relay switching, and the inability to completely destroy the key physically after hanging up.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: This invention provides an analog encrypted telephone terminal based on public switched telephone network transmission, comprising: Analog line interface module: includes an RJ11 interface and polarity protection circuit, used to connect twisted-pair cables to the public switched telephone network; Analog voice module: Connects the microphone and handset of the handset, and directly couples the analog voice signal to the telephone line in an unencrypted state to enable normal calls.
[0007] Power supply filtering module: In conjunction with the π-type filter circuit, it provides low-noise power to the security encryption chip and filters out high-frequency noise generated when the encryption chip is working; Power supply control module: It adopts NMOS transistors, with its drain connected to the external power interface, its source connected to the power pin of the security encryption chip, and its gate connected to the physical encryption button, without going through any software logic; Encryption processing module: Built-in quantum-resistant encryption core and quantum random source circuit, capable of modulating / demodulating analog voice signals; Signal coupling and isolation module: Used to isolate the DC component introduced by the external power supply, allowing only encrypted and modulated AC voice signals to pass through, protecting the switch ports from being burned out by DC.
[0008] Ring detection module: Connected across both ends of the telephone line interface, once an AC ringing signal of about 25Hz / 90V is detected, the enable pin level of the security encryption chip is forcibly pulled low, so that it remains in a power-off or sleep state during standby, ringing and unencrypted calls, to avoid accidental triggering.
[0009] The beneficial effects of the technical solution provided by this invention include at least the following: The encryption function of this invention relies entirely on the physical button to directly control the power supply and enable pins of the security encryption chip, without involving any microprocessor instructions or software code. Even if the terminal's main control program crashes, malfunctions, or is remotely hijacked, as long as the physical button remains pressed, encryption continues to work and cannot be illegally disabled or bypassed by software.
[0010] This invention eliminates the mechanical relays in traditional solutions and uses electronic switching elements such as NMOS transistors to control the establishment and disconnection of encrypted paths. The electronic switches have no moving contacts and no mechanical lifespan limitations. They will not experience contact oxidation, poor soldering, or adhesion failures in harsh environments such as high temperature, high humidity, and vibration, thus significantly improving the long-term reliability of the equipment.
[0011] This invention provides independent power to the security encryption chip through an external power interface, completely eliminating the dependence on the weak power supply of analog telephone lines. It can fully support the high-performance security encryption chip with built-in anti-quantum encryption core and quantum random source to work at full speed, while avoiding voltage drops and audio distortion caused by drawing power from the line.
[0012] The temporary session key of the secure encryption chip of this invention is stored only in the internal volatile storage unit. When the call ends and the call is hung up, the physical button pops up, the power supply control switch element is cut off, the chip power supply is instantly cut off, and the temporary key is physically dissipated immediately due to power loss, without relying on software erase commands, thus eliminating the risk of key residue and subsequent retrieval.
[0013] The present invention uses a signal coupling transformer connected in series between the security encryption chip and the telephone line to effectively block the DC component of the external power supply from entering the public switched telephone network, allowing only AC encrypted voice signals to pass through, thus ensuring that the port circuits of the analog program-controlled exchange will not be burned out due to the introduction of external power. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 This is a system architecture flowchart of an analog encrypted telephone terminal based on public switched telephone network transmission provided in an embodiment of the present invention; Figure 2 A flowchart illustrating an analog encrypted telephone method based on a public switched telephone network provided in an embodiment of the present invention. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0017] Example An analog encrypted telephone terminal based on public switched telephone network transmission Please refer to Figure 1-2This is a system flowchart of an analog encrypted telephone terminal and method based on public switched telephone network transmission provided in an embodiment of the present invention.
[0018] I. Analog Line Interface Module The terminal has an RJ11 telephone line interface on the back, and a polarity protection circuit consisting of four diodes is connected to the rear of the interface. No matter whether the two wires of the twisted pair are connected correctly or incorrectly, the polarity protection circuit can automatically correct to a fixed polarity output, ensuring the correct power supply polarity of the terminal's internal circuitry and preventing damage to subsequent circuitry due to reversed wiring.
[0019] II. Analog Voice Module In unencrypted mode, the voice signal picked up by the handset microphone is amplified and then directly connected to the twisted pair cable through the coupling circuit to form a transparent analog voice transmission path; at the same time, the voice signal received from the other party through the twisted pair cable is also sent to the handset earpiece through the circuit to realize the normal call function.
[0020] III. Power Filtering Module It includes a π-type filter circuit, consisting of two parallel filter capacitors and one series filter inductor, positioned between the external power interface and the power pins of the security encryption chip. High-frequency switching noise generated when the security encryption chip operates at high speed is effectively filtered out by the dual filtering of the inductor and capacitor in the π-type filter circuit, ensuring a clean and stable DC voltage supplied to the chip, while preventing noise from back-intruding into the analog voice module and causing call interference.
[0021] IV. Power Supply Control Module The gate of the NMOS transistor serves as the control terminal, connected to one end of the physical encryption button via a current-limiting resistor. The drain of the NMOS transistor is connected to the positive terminal of the external power supply interface, and the source is connected to the power supply pin of the security encryption chip. The other end of the physical encryption button is also connected to the positive terminal of the external power supply interface. When the button is not pressed, the gate voltage of the NMOS transistor is zero, the drain-source connection is cut off, and the security encryption chip receives no power. When the button is pressed, the external power supply voltage is applied to the gate through the button and the current-limiting resistor. The gate-source voltage exceeds the turn-on threshold voltage of the NMOS transistor, causing it to saturate and conduct. The external power supply voltage is then applied to the security encryption chip through the drain-source path. The entire process is completed solely by a hardware circuit consisting of the physical button and electronic components, without any microprocessor or software instructions.
[0022] V. Encryption Processing Module The quantum random source circuit generates a true random number sequence based on quantum noise, and the quantum-resistant encryption core embeds a lattice-based cryptographic algorithm. After the chip is powered on and activated, the quantum-resistant encryption core reads the quantum random number as a seed and uses the lattice-based cryptographic algorithm to generate a temporary session key. Subsequently, this key is used to modulate the input analog voice current in real time by changing the instantaneous amplitude and phase parameters of the analog signal, outputting an encrypted analog signal. At the same time, the received encrypted analog signal is demodulated to recover the plaintext voice current and sent to the earpiece.
[0023] VI. Signal Coupling and Isolation Module A 1:1 audio signal coupling transformer is used. The two ends of the transformer's primary winding are connected to the encrypted signal output terminal of the security encryption chip and ground, respectively. The two ends of the secondary winding are connected to one line and the other line of the polarity protection circuit output terminal, respectively. The transformer transmits the AC encrypted voice signal from the primary side to the secondary side through electromagnetic induction. At the same time, the physical insulation between the primary and secondary sides completely blocks the DC component that may leak from the external power supply to the telephone line through the security encryption chip, ensuring that the switch port will not be damaged by DC voltage.
[0024] VII. Ringing Detection Module It consists of a DC blocking capacitor, a rectifier bridge, and an optocoupler, connected across the two wires of the RJ11 interface. When the analog PBX sends a 25Hz / 90V AC ringing signal to this terminal, the signal is coupled by the DC blocking capacitor, rectified by the rectifier bridge, and then drives the optocoupler to conduct. The output of the optocoupler pulls the enable pin of the security encryption chip low. Because the chip's enable pin is forcibly pulled low, even if the physical encryption button is accidentally pressed, the chip cannot be activated, thus preventing accidental entry into encryption mode during standby ringing.
[0025] VIII. Human-Computer Interaction Module It includes a standard telephone keypad, a handset, and a physical encryption button located in the keypad area. The physical encryption button is a self-locking or momentary mechanical button; when pressed, the contact closes, and when released, it automatically pops back open. In addition, the terminal casing has a display screen connected to the operating status output pin of the security encryption chip. The screen illuminates when the chip is in encryption mode, indicating to the user that the current call is in encrypted call mode.
[0026] A method for simulating encrypted telephone calls based on public switched telephone networks includes the following steps: After the calling user picks up the handset, the hook switch inside the terminal handset closes, and the analog voice coupling circuit connects the handset microphone circuit to the telephone line interface. The user dials via the keypad, and the dual-tone multi-frequency (DTMF) signal generated by the keypad circuit is output to the twisted-pair cable via the analog voice coupling circuit and sent to the analog PBX.
[0027] The analog PBX receives and parses the dual-tone multi-frequency dialing signal, determines the called number, and then sends a 25Hz / 90V AC ringing signal to the user line connected to the called terminal.
[0028] When the called user hears the ringing, they pick up the phone. The hook switch inside the called terminal closes, and its analog voice coupling circuit connects the handset microphone and handset circuit to the telephone line interface. Upon detecting the DC loop formed by the called party picking up the phone, the exchange stops sending the ringing signal and connects the calling and called lines through its internal switching matrix, forming an end-to-end bidirectional analog voice transmission path. During this process, neither terminal's physical encryption button is pressed, the NMOS transistor is in the off state, and the security encryption chip has no power input, remaining completely powered off and in sleep mode.
[0029] One of the parties in the call (taking the caller as an example) decides to enter encrypted mode by pressing the physical encryption button on the terminal. The button contacts close, and the positive voltage of the external 9V DC power supply is applied directly to the gate of the NMOS transistor through the closed button contacts and the 10kΩ current-limiting resistor in series.
[0030] The gate voltage of the NMOS transistor instantly rises to 9V, far exceeding the gate-source threshold voltage specified in the NMOS transistor datasheet (typically 1.5V-2.5V). The NMOS transistor immediately switches from the off state to the saturated conduction state, forming a low-impedance path between its drain and source, establishing a current path from the external power interface through the NMOS transistor to the power pin of the security encryption chip.
[0031] The established current path will transmit the external 9V DC voltage directly to the power supply pin of the security encryption chip through the saturated NMOS transistor, providing a stable operating voltage for the various circuit modules inside the chip.
[0032] At the same time, when the NMOS transistor is turned on, its gate high-level signal (about 9V) is applied to the enable pin of the security encryption chip through a branch line to provide a high-level enable signal.
[0033] When the security encryption chip receives both the power supply voltage and a high-level enable signal, its internal power management circuit and clock circuit are activated, and the encryption logic circuit is physically activated. The entire power-on and activation process is directly controlled by the mechanical pressing action of the physical encryption button through the hardware circuitry, without any program judgment or software instructions from the microprocessor within the terminal. Even if the main control software completely crashes, the chip will continue to work as long as the button remains pressed.
[0034] Once the security encryption chip is powered on and activated, its internal quantum random source circuit begins to operate. This circuit utilizes the physical random process of quantum shot noise in semiconductor junctions to continuously generate a nondeterministic, truly random number sequence as the entropy source for key generation.
[0035] The chip's internal quantum-resistant encryption core reads a random number sequence generated by a quantum random source as an algorithm seed, calls a lattice-based cryptographic algorithm (CRYSTALS-Kyber) pre-embedded in the chip's ROM, and uses this seed to generate a temporary session key that is only used for this call. Because the seed originates from a quantum physical process, the key is theoretically unpredictable.
[0036] The security encryption chip uses the temporary session key generated in step S402 to perform real-time encryption modulation on the analog voice current signal input from the handset microphone. The modulation process alters the instantaneous amplitude and phase parameters of the analog signal, transforming the original voice waveform into a noise-like encrypted analog waveform, making the original voice content indistinguishable from the waveform. The modulated encrypted analog signal is then output from the chip's output terminal.
[0037] The encrypted analog signal output by the security encryption chip is first fed into the primary winding of a 1:1 signal coupling transformer. Driven by the encrypted voice current, the primary winding of the transformer generates an alternating magnetic field, which induces a corresponding AC voltage signal across the secondary winding via electromagnetic induction. Because the primary and secondary windings of the transformer are physically insulated, any DC component introduced by the external power supply system is effectively blocked and will not be transmitted to the telephone line side.
[0038] The two ends of the secondary winding of the signal coupling transformer are soldered to the two lines of the terminal RJ11 interface. The induced AC encrypted analog signal is directly injected into the twisted pair.
[0039] The AC encrypted analog signal injected into the twisted pair is transmitted along the user line to the analog program-controlled exchange, and then transparently transmitted to the user line connected to the called terminal through the circuit switching path already established inside the exchange, finally reaching the RJ11 interface of the called terminal to complete the transmission of the encrypted signal.
[0040] When the physical encryption button on the called terminal is not pressed, the security encryption chip is in a sleep standby state, but a low-power signal detection circuit inside it is always connected across the telephone line interface to continuously monitor the signal characteristics on the line.
[0041] When the encrypted analog signal sent by the calling terminal arrives at the called terminal, the signal detection circuit identifies the encrypted pilot signal containing a specific frequency and pattern (such as a specific dual-tone combination lasting 100ms), determines it to be an encrypted call request, and then outputs a wake-up trigger signal.
[0042] The wake-up trigger signal directly drives an auxiliary NMOS transistor inside the called terminal to conduct, applying an external 9V power supply voltage to the power and enable pins of the local security encryption chip. The security encryption chip of the called terminal is then physically activated. The entire process requires no operation from the called user or involvement from the called terminal's main control software.
[0043] After the called terminal's security encryption chip is activated, it receives and parses the encrypted synchronization frame sent by the calling terminal from the line. The synchronization frame contains the public parameters required for key negotiation. Using its local quantum random source and the same lattice-based cryptographic algorithm, the called terminal's chip completes key negotiation with the calling terminal to generate a temporary session key for this call.
[0044] After key synchronization is complete, the called terminal's security encryption chip enters full-duplex encryption mode: on one hand, it performs real-time encryption modulation on the voice signal collected by the local handset microphone and sends it; on the other hand, it demodulates the encrypted signal received from the line in real time, restoring it to plaintext voice and sending it to the handset. At this point, both the calling and called ends are in encryption mode, establishing a full-duplex encrypted voice link. The encryption status is displayed on both terminals.
[0045] When either party hangs up at the end of the call, the user who hung up releases the physical encryption button, and the button contacts automatically pop up and disconnect. The gate voltage of the NMOS transistor is rapidly discharged to zero through the pull-down resistor, and the NMOS transistor changes from a saturated conduction state to a cutoff state. The voltages on the power supply pin and enable pin of the security encryption chip are simultaneously cut off, and the chip instantly loses all power. The volatile static random access memory (SRAM) cells inside the chip, used to store temporary session keys, lose power, and the stored key data is immediately and irrecoverably physically destroyed, leaving no trace. The terminal reverts to a normal analog telephone state.
[0046] Furthermore, it should be noted that the present invention can be provided as a method, apparatus, or computer program product. Therefore, embodiments of the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code.
[0047] The embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0048] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The functions specified in one or more boxes. These computer program instructions may also be loaded onto a computer or other programmable data processing terminal equipment to cause a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0049] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0050] Finally, it should be noted that the above description represents a preferred embodiment of the present invention. It should be pointed out that although preferred embodiments have been described, those skilled in the art, once they understand the basic inventive concept of the present invention, can make various improvements and modifications without departing from the principles described herein. These improvements and modifications should also be considered within the scope of protection of the present invention. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.
Claims
1. An analog encrypted telephone terminal based on public switched telephone network transmission, characterized in that, include: Analog line interface module: includes an RJ11 interface and polarity protection circuit, used to connect twisted-pair cables to the public switched telephone network; Analog voice module: Connects the microphone and earpiece of the handset, and directly couples the analog voice signal to the telephone line in an unencrypted state to enable ordinary calls; Power supply filtering module: In conjunction with the π-type filter circuit, it provides low-noise power to the security encryption chip and filters out high-frequency noise generated when the encryption chip is working; Power supply control module: It adopts NMOS transistors, with its drain connected to the external power interface, its source connected to the power pin of the security encryption chip, and its gate connected to the physical encryption button, realizing pure hardware-level power switching and enable control without any software logic. Encryption processing module: Built-in quantum-resistant encryption core and quantum random source circuit, capable of modulating / demodulating analog voice signals; Signal coupling and isolation module: Used to isolate the DC component introduced by the external power supply, allowing only encrypted and modulated AC voice signals to pass through, protecting the switch ports from being burned out by DC; Ring detection module: Connected across both ends of the telephone line interface, once an AC ringing signal of about 25Hz / 90V is detected, the enable pin level of the security encryption chip is forcibly pulled low, so that it remains in a power-off or sleep state during standby, ringing and unencrypted calls to avoid false triggering; Human-computer interaction module: used for daily dialing, call operations and encryption status indication.
2. A method for simulating encrypted telephone transmission based on a public switched telephone network, applied to the terminal described in claim 1, characterized in that, include: S1, the calling terminal and the called terminal establish a normal analog voice channel through an analog program-controlled exchange. The analog voice coupling circuit of the two terminals transmits the handset voice signal directly, and the security encryption chip is in a power-off or sleep state. S2, when the user presses the physical encryption button on any terminal, the power supply control switch element in the hardware enable switch circuit is turned on through the hardware circuit. S3, the power supply control module directly applies the voltage from the external power interface to the power pins and enable pins of the security encryption chip, enabling the security encryption chip to be powered on and activated purely in hardware, without the need for software instructions from the terminal main control microprocessor. S4, once activated, the security encryption chip uses its internal quantum-resistant encryption core and quantum random source to generate a temporary session key, which modulates the analog voice signal from the handheld microphone in real time to generate an encrypted analog signal. S5, the encrypted analog signal is isolated from DC by the signal coupling transformer and then injected into the twisted pair of the public switched telephone network and transmitted to the other end terminal; S6: The security encryption chip of the peer terminal automatically detects the encryption pilot, completes encryption synchronization, and establishes a full-duplex encrypted voice link between the two ends. S7: When either end hangs up, the physical encryption button on that end pops up, the power supply control switch is turned off, the power supply and enable signal of the security encryption chip are cut off at the same time, the temporary session key inside the chip is destroyed immediately due to power failure, and the terminal returns to the normal analog telephone state.
3. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 2, characterized in that, The S1 calling terminal and the called terminal establish a normal analog voice channel through an analog program-controlled exchange. The analog voice coupling circuit of the two terminals transmits the handset voice signal directly. The security encryption chip is in a power-off or sleep state, wherein: S101, after the calling terminal goes off-hook, its analog voice coupling circuit connects the handset microphone circuit to the telephone line interface, and the dual-tone multi-frequency signal generated by keypad dialing is sent out to the twisted pair of the public switched telephone network through the analog voice coupling circuit. S102, the analog program-controlled exchange receives and parses the dialing signal, and sends an AC ringing signal to the user line corresponding to the called terminal; S103, after the called terminal goes off-hook, its analog voice coupling circuit connects the handset microphone and handset circuit to the telephone line interface, the exchange stops ringing and establishes a DC loop between the caller and the called party, forming a two-way analog voice transmission path.
4. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 2, characterized in that, When a user presses the physical encryption button on any terminal of S2, the power supply control switch element in the hardware enable switch circuit is turned on via the hardware circuitry, wherein: S201, when the physical encryption button is pressed, its contacts close, and the positive voltage of the external power interface is directly applied to the control terminal of the power supply control switch element through the closed physical encryption button and the series current limiting resistor. S202, the control terminal voltage exceeds the conduction threshold of the power supply control switch element, causing the switch element to switch from the off state to the saturated conduction state, thereby establishing a current path from the external power interface through the main path of the power supply control switch element to the power supply pin of the security encryption chip.
5. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 4, characterized in that, The control terminal voltage exceeds the conduction threshold of the power supply control switch element, wherein: The turn-on threshold is the gate and source turn-on threshold voltage of the NMOS transistor. When the voltage applied to the control terminal exceeds the corresponding threshold, the power supply control switch element enters the saturation conduction state.
6. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 2, characterized in that, The S3 power supply control module directly applies the voltage from the external power interface to the power pins and enable pins of the security encryption chip, enabling the security encryption chip to be powered on and activated purely in hardware, without requiring software instructions from the terminal's main control microprocessor. S301 establishes a current path to transmit the DC voltage from the external power interface to the power supply pin of the security encryption chip via a saturated power control switch element, thereby providing the chip with the operating voltage. S302, a high-level signal generated by the control terminal of the power supply control switch element when it is turned on is applied to the enable pin of the security encryption chip; The S303 security encryption chip is physically activated after simultaneously receiving power supply voltage and a high-level enable signal. The entire power-on and activation process is controlled by the mechanical action of the physical encryption button through hardware circuitry.
7. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 2, characterized in that, The S4-activated security encryption chip uses its internal quantum-resistant encryption core and quantum random source to generate a temporary session key, and modulates the analog voice signal from the handset microphone in real time to generate an encrypted analog signal, wherein: S401, after the security encryption chip is physically activated, its internal quantum random source circuit uses quantum physics processes to generate a nondeterministic random number sequence. S402, the quantum-resistant encryption kernel, is based on this random number sequence and uses a quantum-resistant cryptographic algorithm to generate a temporary session key that is only used for this call; S403, the security encryption chip uses the temporary session key to perform real-time encryption modulation on the analog voice current signal input from the handset microphone, changing the parameters in the instantaneous amplitude, frequency, and phase of the analog voice current, thereby outputting an encrypted analog voice signal.
8. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 7, characterized in that, The temporary session key generated using a quantum-resistant cryptographic algorithm is used exclusively for this call, wherein: The quantum-resistant encryption core inside the security encryption chip reads the nondeterministic random number sequence generated by the quantum random source circuit as the seed for the key generation algorithm; The quantum-resistant encryption kernel executes a pre-defined quantum-resistant cryptographic algorithm, which includes lattice-based cryptographic algorithms, multivariate-based cryptographic algorithms, hash-based signature algorithms, and encoding-based cryptographic algorithms. Using a seed and the quantum-resistant cryptographic algorithm, a temporary session key is generated that is only used for this call. The temporary session key is stored in a volatile storage unit inside the secure encryption chip. The volatile storage unit loses all data and leaves no trace of the key when the chip is powered off.
9. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 2, characterized in that, The S5 encrypted analog signal, after being isolated from DC by a signal coupling transformer, is injected into the twisted pair of the public switched telephone network and transmitted to the peer terminal. The encrypted analog signal output by the S501 security encryption chip is sent to the primary winding of the signal coupling transformer. The signal coupling transformer couples the AC encrypted voice signal on the primary winding to the secondary winding through electromagnetic induction. At the same time, it uses the physical insulation between the primary and secondary windings of the transformer to block the DC component introduced by the external power interface, allowing only the AC signal to pass through. S502, the two ends of the secondary winding are respectively connected to the two lines of the twisted pair, and the AC encrypted analog signal isolated by the signal coupling transformer is injected into the twisted pair; S503, the injected AC encrypted analog signal is transmitted along the twisted pair to the analog PBX, and then through the established circuit switching path of the analog PBX, it is transmitted to the user line connected to the peer terminal, thus completing the transmission of the encrypted analog signal to the peer terminal.
10. The analog encrypted telephone method based on public switched telephone network transmission as described in claim 2, characterized in that, The S6 peer terminal's security encryption chip automatically detects encryption pilots, completes encryption synchronization, and establishes a full-duplex encrypted voice link between the two ends, wherein: S601, when the security encryption chip of the peer terminal is in sleep mode, its internal signal detection circuit continuously monitors the signal received from the twisted pair. S602, when a specific encrypted pilot signal generated by encryption modulation sent by the calling terminal is detected on the line, the signal detection circuit outputs a wake-up signal; S603, the wake-up signal triggers the hardware enable switch circuit inside the peer terminal to turn on, and applies the external power supply voltage to the power pin and enable pin of the local security encryption chip, so that the local security encryption chip is physically activated. S604: After the security encryption chip of the peer terminal is activated, it parses the encrypted synchronization frame sent by the calling terminal, extracts the session establishment parameters, and uses the local quantum random source to generate the same temporary session key as the calling terminal or negotiates a common key. S605 After key synchronization is completed, the security encryption chip of the peer terminal performs real-time encryption modulation on the analog voice signal from the microphone of the local handheld device, and simultaneously demodulates and decrypts the encrypted analog signal received from the line. Both security encryption chips enter full-duplex encryption mode, realizing bidirectional simultaneous transmission of encrypted voice.
Citation Information
Patent Citations
Anti-monitoring method and device for telephone set
CN112671981A