WO2016180180A1 - 一种语音通话的加密方法及装置 - Google Patents

一种语音通话的加密方法及装置 Download PDF

Info

Publication number
WO2016180180A1
WO2016180180A1 PCT/CN2016/079600 CN2016079600W WO2016180180A1 WO 2016180180 A1 WO2016180180 A1 WO 2016180180A1 CN 2016079600 W CN2016079600 W CN 2016079600W WO 2016180180 A1 WO2016180180 A1 WO 2016180180A1
Authority
WO
WIPO (PCT)
Prior art keywords
key information
call
calling
called
voice call
Prior art date
Application number
PCT/CN2016/079600
Other languages
English (en)
French (fr)
Inventor
高扬
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016180180A1 publication Critical patent/WO2016180180A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/02Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]

Definitions

  • the calling user equipment UE sends a call request message, where the session description protocol SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE;
  • the calling UE transmits the unencrypted first voice call data and receives the unencrypted second voice call data.
  • the calling UE receives the second encrypted second voice call data sent by the SBC on the calling UE side, and applies the first key information to decrypt the second encrypted second voice call data once.
  • the selected second set of key information is used to perform secondary decryption on the decrypted second voice call data.
  • the called UE sends unencrypted second voice call data; and receives unencrypted first voice call data.
  • the called UE After receiving the second encrypted first voice call data sent by the SBC on the called UE side, the called UE applies the second key information to perform the second encrypted first voice call data. Decrypting once, and then applying the selected set of key information to perform secondary decryption on the decrypted first voice call data.
  • the SDP proposal signaling of the call request message further carries the first key information
  • the SBC of the calling UE side forwarding the call request message includes:
  • the forwarding the call response message to the calling UE includes:
  • the method After forwarding the call response message to the calling UE, the method further includes:
  • the SBC on the calling UE side receives the second encrypted first voice call data, and applies the first key information to decrypt the second encrypted first voice call data once, and then forwards the decrypted first a voice call data;
  • An embodiment of the present invention further provides an encryption method for a voice call, including:
  • the session border controller SBC of the called user equipment UE side receives the call request message, and forwards the call request message to the called UE, where the session description protocol SDP proposal signaling of the call request message carries the At least one set of key information supported by the calling UE;
  • the SBC on the called UE side receives a call response message carrying the second key information in the SDP response signaling, and forwards the call response message after deleting the second key information;
  • the method further includes:
  • the SBC on the called UE side receives the decrypted first voice call data, and applies the second key information to perform secondary encryption on the first decrypted first voice call data, and then sends the first voice call data to the called UE;
  • the SBC on the called UE side receives the second encrypted voice call data, and applies the second key information to decrypt the second encrypted second voice call data once, and then forwards the decrypted first Two voice call data.
  • the embodiment of the present invention further provides a calling user equipment UE, where the calling UE includes:
  • a first receiving unit configured to receive a call response message; where the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information, Receiving the encrypted second voice call data, and applying the selected set of key information to decrypt the encrypted second voice call data.
  • the first sending unit is further configured to: when the SDP response signaling of the call response message received by the first receiving unit does not carry the key information, send the unencrypted first voice.
  • Call data is further configured to: when the SDP response signaling of the call response message received by the first receiving unit does not carry the key information, send the unencrypted first voice.
  • the first receiving unit is further configured to receive the unencrypted second voice call data if the key information is not carried in the SDP response signaling of the call response message.
  • the first receiving unit is further configured to receive the unencrypted second voice call data if the received call response message carries the call encryption indication information.
  • the SDP proposal signaling of the call request message further carries the first key information
  • the SDP response signaling of the call response message further carries the first key information
  • the first sending unit is further configured to apply the selected set of key information to encrypt the first voice call data once, and then apply the first key information to perform the first encrypted voice call data. After secondary encryption, the SBC is sent to the calling UE side;
  • the first receiving unit is further configured to receive the second encrypted second voice call data sent by the SBC on the calling UE side, and apply the first key information to perform the second encrypted second voice call data. Decrypting once, and then applying the selected set of key information to perform secondary decryption on the decrypted second voice call data.
  • the embodiment of the present invention further provides a called user equipment UE, where the called UE includes:
  • a second sending unit configured to: when the encrypted call is supported, select a set of key information from the at least one set of key information received by the second receiving unit, and send a call response message;
  • the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information; and sends a second voice encrypted by applying the selected set of key information.
  • the second sending unit is further configured to send the unencrypted second voice call data
  • the second sending unit is further configured to send a call response message if the encrypted call is not supported, where the call response message carries the call encryption indication information.
  • the second sending unit is further configured to send the unencrypted second voice call data
  • the second receiving unit is further configured to receive the unencrypted first voice call data.
  • the second sending unit is further configured to apply the selected set of key information to encrypt the second voice call data once, and then apply the second key information to perform the second encrypted voice call data.
  • the SBC is sent to the called UE side;
  • the second receiving unit is further configured to receive the second encrypted first voice call data sent by the SBC on the called UE side, and apply the second key information to perform the second encrypted first voice call data. Decrypting once, and then applying the selected set of key information to perform secondary decryption on the decrypted first voice call data.
  • the embodiment of the present invention further provides a session border controller SBC on the UE side of the calling user equipment, and the SBC on the calling UE side includes:
  • a third receiving unit configured to receive a call request message, where the session description protocol SDP offer signaling of the call request message carries at least one set of key information supported by the calling UE; and receives a call response message, where the call The SDP response signaling of the response message carries a set of key information selected by the called UE from the at least one set of key information;
  • a third sending unit configured to forward the call request message received by the third receiving unit, and forward the call response message received by the third receiving unit to the calling UE.
  • the SDP proposal signaling of the call request message further carries first key information
  • the third sending unit is configured to forward the call request message after deleting the first key information, and carry the first in the SDP response signaling of the call response message received by the third receiving unit Key information is forwarded to the calling UE;
  • the third receiving unit is further configured to receive the second encrypted call data after the second encryption
  • the third sending unit is further configured to: after applying the first key information, decrypting the second encrypted first voice call data received by the third receiving unit, and then forwarding the decrypted first Voice call data;
  • the third receiving unit is further configured to receive the decrypted second voice call data once;
  • the third sending unit is further configured to apply the first key information to perform secondary encryption on the second decrypted second voice call data, and then send the data to the calling UE.
  • An embodiment of the present invention further provides an SBC on the called UE side, including:
  • a fourth receiving unit configured to receive a call request message, where the SDP offer signaling of the call request message carries at least one set of key information supported by the calling UE; and receive a call response message, where the call response The SDP response signaling of the message carries a set of key information selected by the called UE from the at least one set of key information;
  • the fourth sending unit is configured to carry the second key information in the SDP proposal signaling of the call request message received by the fourth receiving unit, and then forward the information to the called UE;
  • the fourth sending unit is configured to forward and delete the call response message after deleting the second key information
  • the fourth sending unit is further configured to apply the second key information to perform secondary encryption on the first decrypted first voice call data received by the fourth receiving unit, and then send the data to the called UE;
  • the embodiment of the invention provides a method and device for encrypting a voice call, the calling UE and the called party
  • the UE applies the SDP signaling to negotiate the key information used when transmitting the voice call data between the calling UE and the called UE, that is, the selected set of key information, and then uses the selected set of key information, the calling UE and the Any one of the called UEs encrypts the voice call data that needs to be transmitted, and then transmits the encrypted voice call data to the other party through multiple devices in the transmission link, and the other party receives the encrypted voice call data.
  • the selected one of the selected key information is used for decryption, so that the voice call data is obtained.
  • the embodiment of the present invention implements end-to-end encryption of the voice call, so that the voice call data is encrypted during the entire transmission process. Status improves the security of voice calls.
  • the transmission voice call data between the UE and the SBC on the UE side can implement secondary encryption, which further improves the security of the call; and the solution provided by the embodiment of the present invention is also compatible with the case where the called UE does not support the encrypted call.
  • the method of calling to achieve a variety of possible situations that occur during the call.
  • FIG. 1 is a schematic flowchart of a method for encrypting a voice call according to Embodiment 1 of the present invention
  • FIG. 2 is a schematic flowchart of an encryption method applied to a voice call of a calling UE side according to Embodiment 1 of the present invention
  • FIG. 3 is a schematic flowchart of an encryption method applied to a voice call of a called UE according to Embodiment 1 of the present invention
  • FIG. 4 is a schematic flowchart of an encryption method applied to a voice call on an SBC side of a calling UE side according to Embodiment 1 of the present invention
  • FIG. 5 is a schematic flowchart of a method for encrypting a voice call applied to an SBC side of a called UE according to Embodiment 1 of the present invention
  • FIG. 6 is a schematic flowchart of a method for encrypting a voice call according to Embodiment 2 of the present invention.
  • FIG. 8 is a schematic flowchart of another encryption method for a voice call according to Embodiment 2 of the present invention.
  • FIG. 9 is a structural block diagram of a calling UE according to Embodiment 3 of the present invention.
  • FIG. 10 is a structural block diagram of a called UE according to Embodiment 3 of the present invention.
  • FIG. 11 is a structural block diagram of an SBC on a calling UE side according to Embodiment 3 of the present invention.
  • FIG. 12 is a structural block diagram of an SBC on the called UE side according to Embodiment 3 of the present invention.
  • the embodiment of the present invention is applied to a VoLTE call scenario.
  • the call scenario is based on the communication system shown in FIG. 1.
  • the communication system includes a calling user equipment (UE, User Equipment) and a calling UE side SBC (in FIG. 1). SBC1), IMS, SBC on the called UE side (SBC2 shown in FIG. 1), called UE.
  • UE User Equipment
  • SBC1 SBC1
  • IMS SBC on the called UE side
  • SBC2 shown in FIG. 1
  • the calling UE needs to send a call request message, and the call request message is sent to the called UE through the SBC, IMS, and the SBC of the called UE side.
  • the called UE may send a call response message, which is sent to the calling UE through the SBC, the IMS, and the SBC of the calling UE side.
  • the calling UE and the called UE can perform a voice call, and the voice call data between the calling UE and the called UE is also transmitted through the SBC of the called UE side, the IMS, and the SBC of the calling UE side.
  • data transmission between the UE and the SBC on the UE side is encrypted.
  • the calling UE encrypts the voice call data and sends the data to the calling UE.
  • the voice call data is sent to the SBC of the called UE side through the IMS; the SBC of the called UE side encrypts the voice call data and sends it to the called UE, called After the UE decrypts, the voice call data can be played, so that the user on the called UE side can hear the voice sent by the calling UE.
  • the process in which the called UE sends the voice call data to the calling UE is the same as the process in which the calling UE sends the voice call data to the called UE. For details, refer to the above description.
  • the voice call data when the voice call data is transmitted between the called UE and the calling UE, the voice call data is between the SBC of the called UE side, the IMS of the called UE, and the SBC of the calling UE side.
  • the transmission is not encrypted, so it is easy to be maliciously monitored and the security performance is not good.
  • the voice call data when the voice call data is transmitted between the calling UE and the called UE, the voice call data is transmitted between the SBC, the IMS on the called UE side, and the SBC on the calling UE side. It is encrypted so that the security of the call can be improved.
  • An embodiment of the present invention provides a method for encrypting a voice call. As shown in FIG. 1 , the process of the method in this embodiment includes the following steps:
  • Step 101 The calling UE sends a call request message, and the SBC on the calling UE side receives the call request message.
  • the session description protocol (SDP) of the call request message carries at least one set of key information supported by the calling UE.
  • the calling UE needs to send a call request message to the called UE first.
  • the calling UE needs to send the call request message to the network side device first, and then the network side device forwards the message to the called party.
  • Called UE In the method of this embodiment, the calling UE sends the call request message to the SBC of the calling UE side.
  • the SDP of the call request message includes SDP offer signaling, and the key information can be used as a specific media stream in the SDP (corresponding to a specific m line)
  • the attribute description exists, specifically labeled a line.
  • Crypto-suite (encryption combination) - includes Secure Real-time Transport Protocol (SRTP) encryption algorithm and message authentication algorithm;
  • SRTP Secure Real-time Transport Protocol
  • Key-params (key parameter) - contains the master key, the main salt (Salt) value and its survival time;
  • Session-params (session parameters) - contains session key derivation rate, SRTP payload encryption flag, SRTP authentication protection flag, SRTP replay list length and other information.
  • Step 102 The SBC on the calling UE side forwards the call request message, and the SBC on the called UE side receives the call request message.
  • the SBC on the calling UE side forwards the call request to the IMS.
  • the IMS forwards the call request to the SBC of the called UE side, and the SBC of the called UE side receives the call request message.
  • Step 103 The SBC on the called UE side forwards the call request message to the called UE.
  • the called UE receives the call request message.
  • Step 104 In the case of supporting an encrypted call, the called UE selects a set of key information from the at least one set of key information, and sends a call response message, and the SBC on the called UE side receives the call response message.
  • the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information.
  • the call response message may be a 200 OK message or a 183 message, depending on the specific application scenario.
  • Step 105 The SBC on the called UE side forwards the call response message, and the SBC on the calling UE side receives the call response message.
  • the SBC on the called UE side After receiving the call response message, the SBC on the called UE side forwards the call response message to the IMS, and the IMS forwards the call response message to the SBC on the calling UE side, and the SBC on the calling UE side receives the call. Reply message.
  • Step 106 The SBC on the calling UE side forwards the call response message to the calling UE, and the calling UE receives a call response message.
  • the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information.
  • the key information used when transmitting the voice call data is negotiated between the calling UE and the called UE, that is, the selected set of key information.
  • the Offer/Answer model in the SDP is used, and the Off party, that is, the calling UE, carries the SDP proposal signaling in the sent call request message.
  • the SDP proposal signaling defines a plurality of crypto attribute items, and indicates at least one set of key information that the calling UE can support (a set of key information is one composed of information such as an encryption combination, a key parameter, and a session parameter). Group information);
  • the called party selects a crypto combination crypto attribute item that it can support, that is, a set of key information, and attaches it to the SDP Answer signaling to the Offer side, that is, the calling UE, and the negotiation is completed.
  • Step 107 The calling UE and the called UE use the selected set of key information to encrypt the voice call data during the transmission.
  • the calling UE sends a request to apply the selected one.
  • the first voice call data after the group key information is encrypted; the encrypted first voice call data is sequentially transmitted through the SBC of the calling UE side, the IMS of the called UE, and the SBC of the called UE side, and then sent to the called party.
  • the called UE decrypts the encrypted first voice call data by using the selected set of key information.
  • the called UE sends the second voice call data encrypted by applying the selected set of key information; the encrypted second voice call data sequentially passes through the SBC, IMS of the called UE side, After the transparent transmission of the SBC on the side of the calling UE is sent to the calling UE; after receiving the encrypted second voice call data, the calling UE applies the selected set of key information to the encrypted The second voice call data is decrypted.
  • the calling UE and the called UE apply SDP signaling to negotiate the key information used when transmitting the voice call data between the calling UE and the called UE, that is, the selected set of key information, and then adopt the selection.
  • a set of key information the calling UE and the called UE encrypt the voice call data that needs to be transmitted, and then transmit the encrypted voice call data to the other party through multiple devices in the transmission link.
  • the other party uses the selected set of key information to perform decryption, so that the voice call data is obtained, and the method in this embodiment implements end-to-end encryption of the voice call, so that The voice call data is encrypted during the entire transmission process, which improves the security of the voice call.
  • the method in FIG. 1 is described in the following description from the calling UE, the called UE, the SBC on the calling UE side, and the SBC on the called UE side.
  • the specific process refer to the foregoing description.
  • the embodiment of the present invention further provides an encryption method for a voice call, which is applied to the calling UE side.
  • the processing procedure of the method in this embodiment includes the following steps:
  • Step 201 The calling UE sends a call request message, where the session description protocol SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE.
  • Step 202 The calling UE receives a call response message.
  • Step 203 In a case where the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information, the calling UE sends the application. Selecting a set of key information encrypted first voice call data; and, after receiving the encrypted second voice call data, the calling UE applies the selected set of key information to the encryption The second voice call data is then decrypted.
  • the embodiment of the present invention further provides a method for encrypting a voice call, which is applied to the called UE side.
  • the processing procedure of the method in this embodiment includes the following steps:
  • Step 301 The called UE receives a call request message, where the session description protocol SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE.
  • Step 302 In the case of supporting an encrypted call, the called UE selects a set of key information from the at least one set of key information, and sends a call response message.
  • the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information.
  • Step 303 The called UE sends the second voice call data encrypted by applying the selected set of key information; and after the received UE receives the encrypted first voice call data, the application UE The selected set of key information decrypts the encrypted first voice call data.
  • the embodiment of the present invention further provides an encryption method for a voice call, which is applied to the SBC of the calling UE.
  • the processing procedure of the method in this embodiment includes the following steps:
  • Step 401 The SBC of the calling UE receives the call request message, and the session description protocol SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE.
  • Step 402 The SBC on the calling UE side forwards the call request message.
  • Step 403 The SBC of the calling UE receives the call response message, and forwards the call response message to the calling UE.
  • the SDP response signaling of the call response message carries the called UE from the A set of key information selected from at least one set of key information.
  • the embodiment of the present invention further provides an encryption method for a voice call, which is applied to the SBC of the called UE.
  • the processing procedure of the method in this embodiment includes the following steps:
  • Step 501 The SBC on the called UE side receives a call request message, and cancels the call request.
  • the session description protocol SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE.
  • Step 502 The SBC on the called UE side receives and forwards the call response message, where the SDP response signaling of the call response message carries a set of keys selected by the called UE from the at least one set of key information. information.
  • each device side described in FIG. 2 to FIG. 5 may be specifically referred to the description in the method flow described in FIG. 1 and will not be described in detail.
  • SBC1 shown in FIG. 6 to FIG. 8 is the SBC on the UE side
  • SBC2 is the SBC on the called UE side.
  • the embodiment of the present invention further provides an encryption method for a voice call.
  • the processing procedure of the method in this embodiment includes the following steps:
  • Step 601 The calling UE sends a call request message, and the SBC on the calling UE side receives the call request message.
  • the SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE.
  • the calling UE needs to send a call request message to the called UE first.
  • the calling UE needs to send the call request message to the network side device first, and then the network side device forwards the message to the called party.
  • the UE is called, and in this embodiment, the calling UE sends a call request message to the SBC of the calling UE side; the SBC of the calling UE side receives the call request message.
  • Step 602 The SBC on the calling UE side forwards the call request message, and the SBC on the called UE side receives the call request message.
  • the SBC on the calling UE side forwards the call request to the IMS.
  • the IMS forwards the call request to the SBC of the called UE side, and the SBC of the called UE side receives the call request message.
  • Step 603 The SBC on the called UE side forwards the call request message to the called UE.
  • the called UE receives the call request message.
  • Step 604 The called UE sends a call response message if the encrypted call is not supported or the at least one set of key information supported by the calling UE carried in the SDP proposal signaling is not recognized;
  • the SBC receives the call answer message.
  • the SDP response signaling of the call response message does not carry key information.
  • Step 605 The SBC on the called UE side forwards the call response message, and the SBC on the calling UE side receives the call response message.
  • the SBC on the called UE side After receiving the call response message, the SBC on the called UE side forwards the call response message to the IMS, and the IMS forwards the call response message to the SBC on the calling UE side, and the SBC on the calling UE side receives the call. Reply message.
  • Step 606 The SBC on the calling UE side forwards the call response message to the calling UE, and the calling UE receives a call response message.
  • the SDP response signaling of the call response message does not carry the key information, that is, the key information used by the calling UE and the called UE to negotiate the transmission of the voice call data fails.
  • the called UE and the called UE are to make an unencrypted call, that is, a clear message.
  • Step 607 The calling UE and the called UE perform an unencrypted voice call.
  • the non-encrypted voice call is performed by the calling UE and the called UE.
  • the calling UE sends unencrypted first voice call data, and the unencrypted first voice call data sequentially passes through the SBC and IMS of the calling UE side. After the transparent transmission of the SBC on the called UE side, it is sent to the called UE; the called UE receives the unencrypted first voice call data.
  • the called UE sends the unencrypted second voice call data, and the unencrypted second voice call data is sequentially transmitted through the SBC of the called UE side, the IMS of the calling UE side, and the SBC of the calling UE side, and then sent to the main Called UE; the calling UE receives unencrypted second voice call data.
  • the method described in FIG. 6 cannot distinguish whether the called UE does not perform the encrypted call, does not support the encrypted call, or cannot identify at least one set of key information supported by the calling UE carried in the SDP offer signaling, so the present invention implements
  • the example also provides an encryption method for a voice call.
  • the processing procedure of the method in this embodiment includes the following steps:
  • Step 701 The calling UE sends a call request message, and the calling party on the side of the UE receives the call. Ask for news.
  • the SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE, and the call request message further carries call encryption indication information.
  • the call request message may be a SIP message
  • the call encryption indication information may be carried in a header of the SIP message.
  • the calling UE needs to send a call request message to the called UE first.
  • the calling UE needs to send the call request message to the network side device first, and then the network side device forwards the message to the called party.
  • the calling UE sends a call request message to the SBC on the calling UE side, and the SBC on the calling UE side receives the call request message.
  • Step 702 The SBC on the calling UE side forwards the call request message, and the SBC on the called UE side receives the call request message.
  • the SBC on the calling UE side forwards the call request to the IMS.
  • the IMS forwards the call request to the SBC of the called UE side, and the SBC of the called UE side receives the call request message.
  • Step 703 The SBC on the called UE side forwards the call request message to the called UE, and the called UE receives the call request message.
  • Step 704 The called UE sends a call response message without supporting the encrypted call, and the SBC of the called UE side receives the call response message.
  • the call response message carries information that does not use call encryption indication.
  • the called UE After the called UE receives the call request message, if the encrypted call is not supported, the called UE carries the call encryption indication information in the call response message to inform the calling UE that it does not support the use of the encrypted call.
  • the called UE sends the call response message to the SBC on the called UE side, and the SBC on the called UE side receives the call response message.
  • Step 705 The SBC on the called UE side forwards the call response message, and the SBC on the calling UE side receives the call response message.
  • the SBC on the called UE side After receiving the call response message, the SBC on the called UE side forwards the call response message to the IMS, and the IMS forwards the call response message to the SBC on the calling UE side, and the SBC on the calling UE side receives the call. Reply message.
  • Step 706 The SBC on the calling UE side forwards the call response message to the calling UE, and the calling UE receives a call response message.
  • the SDP response signaling of the call response message does not carry the key information, that is, the key information used by the calling UE and the called UE to negotiate the transmission of the voice call data fails.
  • the called UE and the called UE are to make an unencrypted call, that is, a clear message.
  • Step 707 The calling UE and the called UE perform an unencrypted voice call.
  • the non-encrypted voice call between the calling UE and the called UE includes:
  • the calling UE sends the unencrypted first voice call data, and the unencrypted first voice call data is transparently transmitted through the SBC of the calling UE side, the IMS, and the SBC of the called UE side, and then sent to the Called UE; the called UE receives unencrypted first voice call data.
  • the called UE sends the unencrypted second voice call data, and the unencrypted second voice call data is sequentially transmitted through the SBC of the called UE side, the IMS of the calling UE side, and the SBC of the calling UE side, and then sent to the main Called UE; the calling UE receives unencrypted second voice call data.
  • the processing procedure of the method in this embodiment includes the following steps:
  • Step 801 The calling UE sends a call request message, and the SBC on the calling UE side receives the call request message.
  • the SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE, and the SDP proposal signaling of the call request message further carries the first key information.
  • the first key information is used for communication encryption between the calling UE and the SBC on the calling UE side.
  • the two types of key information are required on the calling UE side, the two types of key information: at least one set of key information supported by the calling UE and the first key information in the SDP offer signaling. It needs to be two separate parts, for example as two separate attributes in the same media stream (m line) in the SDP offer signaling.
  • the calling UE When making a VoLTE call, the calling UE needs to send a call request message to the called UE first. In this process, the calling UE needs to send the call request message to the SBC of the calling UE side, and then forward and send it to the called UE through multiple network side devices.
  • Step 802 The SBC on the calling UE side forwards the call request message after deleting the first key information, and the SBC on the called UE side receives the call request message.
  • the SBC of the calling UE After receiving the call request message, the SBC of the calling UE needs to store the first key information in the call request message, and then delete the first key information in the SDP offer signaling of the call request message. Forwarding the call request message after deleting the first key information to the IMS, and after receiving the call request message after deleting the first key information, the IMS forwards the call request message to the called party.
  • the SBC on the UE side receives the call request message from the SBC on the called UE side.
  • Step 803 The SBC on the called UE side carries the second key information in the SDP proposal signaling of the call request message, and then forwards the message to the called UE.
  • the called UE receives the call request message.
  • the SDP proposal signaling of the call request message received by the SBC of the called UE carries at least one set of key information supported by the calling UE; the SBC of the called UE side may propose signaling at the SDP
  • the second key information is added to the called UE, and the call request message received by the called UE carries the at least one set of key information and the second key information.
  • Step 804 In the case of supporting an encrypted call, the called UE selects a set of key information from the at least one set of key information, and sends a call response message, and the SBC of the called UE side receives the SDP response signaling. A call answer message carrying the second key information.
  • the called UE selects a set of key information from the at least one set of key information, and the called UE sends an SDP response to the call response message of the SBC on the called UE side.
  • the signaling carries a set of key information and second key information selected by the called UE from the at least one set of key information, and the SBC of the called UE side receives the second key in the SDP response signaling. Call reply message for information.
  • the SBC on the called UE side negotiates with the called UE the second key information for secondary encryption when transmitting between the two.
  • the two types of key information are required on the called UE side, the two types of key information: the selected set of key information and the second key information need to be two in the SDP offer signaling.
  • the independent part for example, exists as two separate sets of attributes in the same media stream (m line) in the SDP offer signaling.
  • the call response message may be a 200 OK message or a 183 message, depending on the specific application scenario.
  • Step 805 The SBC on the called UE side forwards the call response message after deleting the second key information; the SBC on the calling UE side receives the call response message.
  • the SBC of the called UE side After receiving the call response message, the SBC of the called UE side deletes the second key information in the SDP response signaling of the call response message. At this time, the SDP response signaling of the call response message is carried in the SDP response signaling. There is a set of key information selected by the called UE from the at least one set of key information.
  • the SBC on the called UE side forwards the call response message after deleting the second key information to the IMS, and the IMS forwards the call response message after deleting the second key information to the calling UE.
  • the SBC on the calling UE side receives the call response message.
  • Step 806 The SBC on the calling UE side carries the first key information in the SDP response signaling of the call response message, and then forwards the call to the calling UE.
  • the calling UE receives the call response message.
  • the IMS forwards the call response message after deleting the second key information to the SBC of the calling UE side.
  • the SDP response signaling of the call response message carries the called UE from the a set of key information selected from at least one set of key information; the SBC on the calling UE side adds the first key information to the caller message, and then forwards the first key information to the calling UE, so that the calling UE side
  • the SBC negotiates with the calling UE the first key information for secondary encryption when transmitting between the two.
  • the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information.
  • the key information used when transmitting the voice call data is negotiated between the calling UE and the called UE, that is, the selected set of key information.
  • the key information used when transmitting the voice call data is negotiated between the calling UE and the called UE, that is, the selected set of key information, the calling UE and the master.
  • the SBC called the UE side also negotiates the first key information for secondary encryption between the two; the called UE and the SBC of the called UE side also negotiate the second secret for secondary encryption between the two. Key information.
  • Step 807 The calling UE and the called UE use the selected set of key information to perform end-to-end encryption on the voice call data during transmission, and simultaneously transmit the first key information and the second key information.
  • the voice call data in the process is subjected to secondary encryption on the access side.
  • the calling UE sends the first voice call to the called UE.
  • the flow of data is as follows:
  • the calling UE applies the selected set of key information to encrypt the first voice call data once, and then applies the first key information to perform secondary encryption on the first encrypted first voice call data.
  • the decrypted first voice call data is forwarded; the SBC on the calling UE side forwards the decrypted first voice call data to the IMS, and the IMS will decrypt the first voice call.
  • the data is transparently transmitted to the SBC on the called UE side, and the SBC on the called UE side receives the decrypted first voice call data, and applies the second key information to perform the first decrypted first voice call data.
  • the second UE is applied to the called UE.
  • the called UE After receiving the second encrypted first voice call data sent by the SBC on the called UE side, the called UE applies the second key information to the secondary encryption.
  • the first voice call data into Once decrypted then apply a selected first set of the key information is a voice call data after decrypting the decrypted secondary; the so called UE may obtain the calling UE sends a voice call over a first data.
  • the called UE applies the selected set of key information to encrypt the second voice call data once, and then applies the second key information to perform secondary encryption on the second encrypted voice call data.
  • the decrypted second voice call data is forwarded once.
  • the SBC on the called UE side sends the decrypted second voice call data to the IMS, and the IMS transparently transmits the decrypted second voice call data to the SBC on the calling UE side.
  • the SBC on the UE side receives the decrypted second voice call data, and applies the first key information to perform secondary encryption on the decrypted second voice call data, and then sends the second voice call data to the calling UE.
  • the calling UE receives the second encrypted second voice call data sent by the SBC on the calling UE side, and applies the first key information to decrypt the second encrypted second voice call data once, and then applies The selected set of key information performs secondary decryption on the decrypted second voice call data.
  • the transmission of the voice call data between the calling UE and the called UE is encrypted, that is, end-to-end encryption is realized, and at the same time, the UE and the UE
  • the transmission voice call data between the SBCs on the UE side is twice encrypted, which further improves the security of the call.
  • Embodiments of the present invention also provide a computer readable storage medium storing computer executable instructions for performing any of the methods described above.
  • An embodiment of the present invention provides a calling UE.
  • the calling UE includes: a first sending unit 901 and a first receiving unit 902, where
  • the first sending unit 901 is configured to send a call request message, where the session description protocol SDP offer signaling of the call request message carries at least one set of key information supported by the calling UE;
  • the first receiving unit 902 is configured to receive a call response message
  • the first sending unit 901 is further configured to carry, in the SDP response signaling of the call response message received by the first receiving unit 902, a group selected by the called UE from the at least one set of key information.
  • a group selected by the called UE from the at least one set of key information.
  • the first receiving unit 902 is further configured to receive, when the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information, The encrypted second voice call data is decrypted by applying the selected set of key information to the encrypted second voice call data.
  • the first sending unit 901 is further configured to: when the SDP response signaling of the call response message received by the first receiving unit 902 does not carry the key information, send the unencrypted first a voice call data; the first receiving unit 902 is further configured to receive the unencrypted second voice call data if the key information is not carried in the SDP response signaling of the call response message.
  • the call request message further carries the call encryption indication information
  • the first sending unit 901 is further configured to: carry the call reply message in the call response message received by the first receiving unit 902 In the case of indicating information, transmitting unencrypted first voice call data
  • the first receiving unit 902 is further configured to receive the unencrypted second voice call data if the received call response message carries the call encryption indication information.
  • the SDP proposal signaling of the call request message further carries the first key information
  • the SDP response signaling of the call response message further carries the first key information
  • the first sending unit 901. The first voice call data is encrypted once by applying the selected set of key information, and then the first key information is used to perform secondary encryption on the first encrypted voice call data.
  • SBC sent to the calling UE side; the first receiving unit 902 is further configured to receive the second encrypted second voice call data sent by the SBC on the calling UE side, and apply the first key information to the second
  • the second encrypted voice call data is decrypted once, and then the selected second set of key information is used to perform secondary decryption on the decrypted second voice call data.
  • the embodiment of the present invention further provides a called user equipment UE.
  • the called UE includes: a second receiving unit 1001 and a second sending unit 1002, where
  • the second receiving unit 1001 is configured to receive a call request message, where the session description protocol SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE;
  • the second sending unit 1002 is configured to: when the encrypted call is supported, select a set of key information from the at least one set of key information received by the second receiving unit 1001, and send a call response message;
  • the SDP response signaling of the call response message carries a set of key information selected by the called UE from the at least one set of key information;
  • the second receiving unit 1001 is further configured to receive the encrypted first voice call data, and apply the selected set of key information to decrypt the encrypted first voice call data;
  • the second sending unit 1002 is further configured to send the second voice call data encrypted by applying the selected set of key information.
  • the second sending unit 1002 is further configured to send, if the encrypted call is not supported or the at least one set of key information supported by the calling UE carried in the SDP proposal signaling is not recognized. a call response message, wherein the SDP response signaling of the call response message does not carry key information; the second sending unit 1002 is further configured to send unencrypted second voice call data; the second receiving The unit 1001 is further configured to receive the unencrypted first voice call data.
  • the call request message further carries call encryption indication information
  • the sending unit 1002 is further configured to send a call response message if the encrypted call is not supported, wherein the call response message carries the call encryption indication information, and the second sending unit 1002 is further configured to send The second voice call data is unencrypted; the second receiving unit 1001 is further configured to receive the first voice call data that is not encrypted.
  • the SDP proposal signaling of the call request message further carries the second key information
  • the SDP response signaling of the call response message further carries the second key information
  • the second sending unit 1002 further configured to apply the selected one set of key information to encrypt the second voice call data once, and then apply the second key information to perform secondary encryption on the second encrypted second voice call data.
  • Sending to the SBC of the called UE side; the second receiving unit 1001 is further configured to receive the second encrypted first voice call data sent by the SBC on the called UE side, and apply the second key information to the second
  • the first encrypted voice call data is decrypted once, and then the selected first set of key information is used to perform secondary decryption on the first decrypted first voice call data.
  • the embodiment of the present invention further provides an SBC on the calling UE side.
  • the SBC on the calling UE side includes: a third receiving unit 1101 and a third sending unit 1102, where
  • the third receiving unit 1101 is configured to receive a call request message, where the session description protocol SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE;
  • the third sending unit 1102 is configured to forward the call request message received by the third receiving unit 1101;
  • the third receiving unit 1101 is further configured to receive a call response message, where the SDP response signaling of the call response message carries a set of keys selected by the called UE from the at least one set of key information.
  • the third sending unit 1102 further forwards the call response message received by the third receiving unit to the calling UE.
  • the SDP proposal signaling of the call request message further carries the first key information
  • the third sending unit 1102 is configured to forward the call request message after deleting the first key information; And carrying the first key information in the SDP response signaling of the call response message received by the third receiving unit 1101, and forwarding the first key information to the calling UE;
  • the third receiving unit 1101 is further configured to receive the second encrypted first voice call data; the third sending unit 1102 is further configured to apply the first key information to the third receiving unit. After the first encrypted voice data received by the second encryption is decrypted once, the decrypted first voice call data is forwarded once;
  • the third receiving unit 1101 is further configured to receive the decrypted second voice call data; the third sending unit 1102 is further configured to apply the first key information to the third receiving unit 1101 after receiving the decryption. After the second voice call data is secondarily encrypted, it is sent to the calling UE.
  • the embodiment of the present invention further provides an SBC on the called UE side.
  • the SBC on the called UE side includes: a fourth receiving unit 1201 and a fourth sending unit 1202, where
  • the fourth receiving unit 1201 is configured to receive a call request message, where the SDP proposal signaling of the call request message carries at least one set of key information supported by the calling UE;
  • the fourth sending unit 1202 is configured to forward the call request message received by the fourth receiving unit 1201 to the called UE;
  • the fourth receiving unit 1201 is further configured to receive a call response message, where the SDP response signaling of the call response message carries a set of keys selected by the called UE from the at least one set of key information. Information; the fourth sending unit 1202 is further configured to forward a call response message.
  • the fourth sending unit 1202 is configured to carry the second key information in the SDP proposal signaling of the call request message received by the fourth receiving unit 1201, and then forward the information to the called UE;
  • the fourth receiving unit 1201 is further configured to receive a call response message carrying the second key information in the SDP response signaling; the fourth sending unit 1202 is configured to forward and delete the second key information. Call answer message;
  • the fourth receiving unit 1201 is further configured to receive the decrypted first voice call data once;
  • the fourth sending unit 1202 is further configured to apply the second key information to perform secondary encryption on the first decrypted first voice call data received by the fourth receiving unit 1201, and then send the data to the called UE;
  • the fourth receiving unit 1201 is further configured to receive the second encrypted voice call data after the second encryption
  • the fourth sending unit 1202 is further configured to apply the second key information to decrypt the second encrypted second voice call data received by the fourth receiving unit 1202 once, and then forward the decrypted first Two voice call data.
  • the first sending unit 901 and the first receiving unit 902 described in this embodiment are used. It can be a central processing unit (CPU), a microprocessor (MPU, a Micro Processing Unit), a digital signal processor (DSP), or a field programmable gate array (FPGA, Field) on the calling UE. -Programmable Gate Array) and other device implementations.
  • the second receiving unit 1001 and the second transmitting unit 1002 described in this embodiment may be centrally programmable (CPU), microprocessor (MPU), digital signal processor (DSP) or field programmable on the called UE. Device implementation such as gate array (FPGA).
  • the third receiving unit 1101 and the third transmitting unit 1102 described in this embodiment may be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP) or the like on the SCB of the calling UE side.
  • Device implementation such as field programmable gate array (FPGA).
  • the fourth receiving unit 1201 and the fourth transmitting unit 1202 described in this embodiment may be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP) or the like on the SCB of the called UE side.
  • Device implementation such as field programmable gate array (FPGA).
  • embodiments of the present invention can be provided as a method, system, or computer program product. Accordingly, the present invention can take the form of a hardware embodiment, a software embodiment, or a combination of software and hardware. Moreover, the invention can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) including computer usable program code.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the apparatus implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
  • These computer program instructions can also be loaded onto a computer or other programmable data processing device. Having a series of operational steps performed on a computer or other programmable device to produce computer-implemented processing such that instructions executed on a computer or other programmable device are provided for implementing one or more processes and/or block diagrams in the flowchart. The steps of a function specified in a box or multiple boxes.
  • each module/unit in the foregoing embodiment may be implemented in the form of hardware, for example, by implementing an integrated circuit to implement its corresponding function, or may be implemented in the form of a software function module, for example, executing a program in a storage and a memory by a processor. / instruction to achieve its corresponding function.
  • the invention is not limited to any specific form of combination of hardware and software.

Abstract

一种语音通话的加密方法,所述方法包括:主叫UE发送呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;接收呼叫应答消息;在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,发送应用所述选择的一组密钥信息加密后的第一语音通话数据;并且,在接收到加密后的第二语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。本发明实施例公开了一种语音通话的加密装置。

Description

一种语音通话的加密方法及装置 技术领域
本文涉及但不限于长期演进(LTE,Long Term Evolution)网络上的语音(VoLTE,Voice over LTE)技术,尤其涉及一种语音通话的加密方法及装置。
背景技术
VoLTE技术是基于互联网协议(IP,Internet Protocol)多媒体子系统(IMS,IP Multimedia Subsystem)实现的,虽然IMS本身提供了一套复杂和较为安全的认证、鉴权机制,但是随着恶意监听越来越普遍,VoLTE相关的安全机制并不能满足需求。
目前IMS的媒体面加密技术,一般是在终端与IMS接入侧设备即会话边界控制器(SBC,Session Border Controller)之间建立加密,而在网络侧之间是不加密的,这样很容易被恶意监听。尤其是考虑后续VoLTE技术作为语音的主流技术推广,而VoLTE本身又基于IP技术这样一个事实,VoLTE语音被敌对国家恶意监听的问题甚至会上升到国家安全的层面。
发明内容
以下是对本文详细描述的主题的概述。本概述并非是为了限制权利要求的保护范围。
本发明实施例提供一种语音通话的加密方法及装置,可以提高通话的安全性。
本发明实施例提出一种语音通话的加密方法,包括:
主叫用户设备UE发送呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
所述主叫UE接收呼叫应答消息;
在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,所述主叫UE发送应用所述选择的一组密钥信息加密后的第一语音通话数据;并且,所述主叫UE在接收到 加密后的第二语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。
可选的,还包括:
在所述呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,所述主叫UE发送未加密的第一语音通话数据,并接收未加密的第二语音通话数据。
可选的,所述呼叫请求消息中还携带有通话加密指示信息;
该方法还包括:
在所述呼叫应答消息中携带有不使用通话加密指示信息的情况下,所述主叫UE发送未加密的第一语音通话数据,并接收未加密的第二语音通话数据。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述呼叫应答消息的SDP应答信令中还携带有第一密钥信息;
所述主叫UE应用所述选择的一组密钥信息对第一语音通话数据进行一次加密,再应用所述第一密钥信息对一次加密后的第一语音通话数据进行二次加密后,发送给主叫UE侧的SBC;
并且,所述主叫UE接收主叫UE侧的SBC发送的二次加密后的第二语音通话数据,应用所述第一密钥信息对二次加密后的第二语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第二语音通话数据进行二次解密。
本发明实施例还提出了一种语音通话的加密方法,包括:
被叫用户设备UE接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
在支持加密通话的情况下,被叫UE从所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
所述被叫UE发送应用所述选择的一组密钥信息加密后的第二语音通话数据;并且,所述被叫UE在接收到加密后的第一语音通话数据后,应用所 述选择的一组密钥信息对所述加密后的第一语音通话数据进行解密。
可选的,所述方法还包括:
在被叫UE不支持加密通话或无法识别所述SDP提议信令中携带的所述主叫UE支持的至少一组密钥信息的情况下,被叫UE发送呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中未携带有密钥信息;
所述被叫UE发送未加密的第二语音通话数据;并接收未加密的第一语音通话数据。
可选的,所述呼叫请求消息中还携带有通话加密指示信息;
该方法还包括:
在不支持加密通话的情况下,发送呼叫应答消息,其中,所述呼叫应答消息中携带有不使用通话加密指示信息;
所述被叫UE发送未加密的第二语音通话数据;并接收未加密的第一语音通话数据。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第二密钥信息,所述呼叫应答消息的SDP应答信令中还携带有第二密钥信息;
所述被叫UE应用所述选择的一组密钥信息对第二语音通话数据进行一次加密,再应用所述第二密钥信息对一次加密后的第二语音通话数据进行二次加密后,发送给被叫UE侧的SBC;
并且,所述被叫UE在接收到被叫UE侧的SBC发送的二次加密后的第一语音通话数据后,应用所述第二密钥信息对二次加密后的第一语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第一语音通话数据进行二次解密。
本发明实施例还提出了一种语音通话的加密方法,包括:
主叫用户设备UE侧的会话边界控制器SBC接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有主叫UE支持的至少一组密钥信息;
主叫UE侧的SBC转发所述呼叫请求消息;
主叫UE侧的SBC接收呼叫应答消息,并将所述呼叫应答消息转发给所述主叫UE;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述主叫UE侧的SBC转发所述呼叫请求消息包括:
所述主叫UE侧的SBC转发删除所述第一密钥信息后的呼叫请求消息;
所述将所述呼叫应答消息转发给所述主叫UE包括:
在所述呼叫应答消息的SDP应答信令中携带所述第一密钥信息后转发给所述主叫UE;
在将所述呼叫应答消息转发给所述主叫UE之后,所述方法还包括:
所述主叫UE侧的SBC接收二次加密后的第一语音通话数据,应用所述第一密钥信息对二次加密后的第一语音通话数据进行一次解密后,转发一次解密后的第一语音通话数据;
所述主叫UE侧的SBC接收一次解密后的第二语音通话数据,应用所述第一密钥信息对一次解密后的第二语音通话数据进行二次加密后,发送给主叫UE。
本发明实施例还提出了一种语音通话的加密方法,包括:
被叫用户设备UE侧的会话边界控制器SBC接收呼叫请求消息,并将所述呼叫请求消息转发给所述被叫UE,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
被叫UE侧的SBC接收并转发呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。
可选的,被叫UE侧的SBC将所述呼叫请求消息转发给所述被叫UE包括:
被叫UE侧的SBC在所述呼叫请求消息的SDP提议信令中携带第二密钥信息后,转发给所述被叫UE;
所述被叫UE侧的SBC接收并转发呼叫应答消息包括:
所述被叫UE侧的SBC接收在SDP应答信令中携带第二密钥信息的呼叫应答消息,并转发删除所述第二密钥信息后的呼叫应答消息;
在被叫UE侧的SBC转发呼叫应答消息之后,所述方法还包括:
所述被叫UE侧的SBC接收一次解密后的第一语音通话数据,应用所述第二密钥信息对一次解密后的第一语音通话数据进行二次加密后,发送给被叫UE;
所述被叫UE侧的SBC接收二次加密后的第二语音通话数据,应用所述第二密钥信息对二次加密后的第二语音通话数据进行一次解密后,转发一次解密后的第二语音通话数据。
本发明实施例还提出了一种主叫用户设备UE,所述主叫UE包括:
第一发送单元,设置为发送呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;在所述第一接收单元接收到的呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,发送应用所述选择的一组密钥信息加密后的第一语音通话数据;
第一接收单元,设置为接收呼叫应答消息;在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,接收加密后的第二语音通话数据,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。
可选的,所述第一发送单元,还设置为在所述第一接收单元接收到的呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,发送未加密的第一语音通话数据;
所述第一接收单元,还设置为在呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,接收未加密的第二语音通话数据。
可选的,所述呼叫请求消息中还携带有通话加密指示信息;
所述第一发送单元,还设置为在所述第一接收单元接收到的呼叫应答消息中携带有不使用通话加密指示信息的情况下,发送未加密的第一语音通话 数据;
所述第一接收单元,还设置为在接收到的呼叫应答消息中携带有不使用通话加密指示信息的情况下,接收未加密的第二语音通话数据。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述呼叫应答消息的SDP应答信令中还携带有第一密钥信息;
所述第一发送单元,还设置为应用所述选择的一组密钥信息对第一语音通话数据进行一次加密,再应用所述第一密钥信息对一次加密后的第一语音通话数据进行二次加密后,发送给主叫UE侧的SBC;
所述第一接收单元,还设置为接收主叫UE侧的SBC发送的二次加密后的第二语音通话数据,应用所述第一密钥信息对二次加密后的第二语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第二语音通话数据进行二次解密。
本发明实施例还提出了一种被叫用户设备UE,所述被叫UE包括:
第二接收单元,设置为接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;接收加密后的第一语音通话数据,应用所述选择的一组密钥信息对所述加密后的第一语音通话数据进行解密;
第二发送单元,设置为在支持加密通话的情况下,从所述第二接收单元接收到的所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;发送应用所述选择的一组密钥信息加密后的第二语音通话数据。
可选的,所述第二发送单元,还设置为在不支持加密通话或无法识别所述SDP提议信令中携带的所述主叫UE支持的至少一组密钥信息的情况下,发送呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中未携带有密钥信息;
所述第二发送单元,还设置为发送未加密的第二语音通话数据;
所述第二接收单元,还设置为接收未加密的第一语音通话数据。
可选的,所述呼叫请求消息中还携带有通话加密指示信息;
所述第二发送单元,还设置为在不支持加密通话的情况下,发送呼叫应答消息,其中,所述呼叫应答消息中携带有不使用通话加密指示信息;
所述第二发送单元,还设置为发送未加密的第二语音通话数据;
所述第二接收单元,还设置为接收未加密的第一语音通话数据。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第二密钥信息;所述呼叫应答消息的SDP应答信令中还携带有第二密钥信息;
所述第二发送单元,还设置为应用所述选择的一组密钥信息对第二语音通话数据进行一次加密,再应用所述第二密钥信息对一次加密后的第二语音通话数据进行二次加密后,发送给被叫UE侧的SBC;
所述第二接收单元,还设置为接收被叫UE侧的SBC发送的二次加密后的第一语音通话数据,应用所述第二密钥信息对二次加密后的第一语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第一语音通话数据进行二次解密。
本发明实施例还提出了一种主叫用户设备UE侧的会话边界控制器SBC,所述主叫UE侧的SBC包括:
第三接收单元,设置为接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有主叫UE支持的至少一组密钥信息;接收呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
第三发送单元,设置为转发所述第三接收单元接收的呼叫请求消息;将所述第三接收单元接收的所述呼叫应答消息转发给所述主叫UE。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息;
所述第三发送单元,是设置为转发删除所述第一密钥信息后的呼叫请求消息;并在所述第三接收单元接收到的呼叫应答消息的SDP应答信令中携带所述第一密钥信息后转发给所述主叫UE;
第三接收单元,还设置为接收二次加密后的第一语音通话数据;
所述第三发送单元,还设置为应用所述第一密钥信息对所述第三接收单元接收到的二次加密后的第一语音通话数据进行一次解密后,转发一次解密后的第一语音通话数据;
第三接收单元,还设置为接收一次解密后的第二语音通话数据;
所述第三发送单元,还设置为应用所述第一密钥信息对一次解密后的第二语音通话数据进行二次加密后,发送给主叫UE。
本发明实施例还提出了一种所述被叫UE侧的SBC,包括:
第四接收单元,设置为接收呼叫请求消息,所述呼叫请求消息的SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;接收呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
第四发送单元,设置为将所述第四接收单元接收的呼叫请求消息转发给所述被叫UE;转发呼叫应答消息。
可选的,所述第四发送单元,是设置为将所述第四接收单元接收的呼叫请求消息的SDP提议信令中携带第二密钥信息后,转发给所述被叫UE;
所述第四接收单元,还设置为接收在SDP应答信令中携带第二密钥信息的呼叫应答消息;
所述第四发送单元,是设置为转发删除所述第二密钥信息后的呼叫应答消息;
第四接收单元,还设置为接收一次解密后的第一语音通话数据;
所述第四发送单元,还设置为应用所述第二密钥信息对第四接收单元接收的一次解密后的第一语音通话数据进行二次加密后,发送给被叫UE;
第四接收单元,还设置为接收二次加密后的第二语音通话数据;
所述第四发送单元,还设置为应用所述第二密钥信息对所述第四接收单元接收的二次加密后的第二语音通话数据进行一次解密后,转发一次解密后的第二语音通话数据。
本发明实施例提供了一种语音通话的加密方法及装置,主叫UE和被叫 UE应用SDP信令协商出主叫UE和被叫UE之间传输语音通话数据时采用的密钥信息即选择的一组密钥信息,然后采用该选择的一组密钥信息,主叫UE和被叫UE中的任一方对需要传输的语音通话数据进行加密,然后将加密后的语音通话数据通过传输链路中的多个设备传输至另一方,另一方收到加密后的语音通话数据后,应用协商好的所述选择的一组密钥信息进行解密,这样即获得语音通话数据,本发明实施例实现了语音通话的端到端加密,使语音通话数据在整个传输过程中都处于加密状态,提高了语音通话的安全性。另外,UE以及UE侧的SBC之间的传输语音通话数据可以实现二次加密,这样就更加提高通话的安全性;且本发明实施例提供的方案还兼容了被叫UE不支持加密通话时的通话方法,实现通话过程中出现的多种可能情况。
在阅读并理解了附图和详细描述后,可以明白其他方面。
附图概述
图1为本发明实施例1提供的一种语音通话的加密方法流程示意图;
图2为本发明实施例1提供的一种应用于主叫UE侧的语音通话的加密方法流程示意图;
图3为本发明实施例1提供的一种应用于被叫UE侧的语音通话的加密方法流程示意图;
图4为本发明实施例1提供的一种应用于主叫UE侧的SBC侧的语音通话的加密方法流程示意图;
图5为本发明实施例1提供的一种应用于被叫UE侧的SBC侧的语音通话的加密方法流程示意图;
图6为本发明实施例2提供的一种语音通话的加密方法流程示意图;
图7为本发明实施例2提供的另一种语音通话的加密方法流程示意图;
图8为本发明实施例2提供的另一种语音通话的加密方法流程示意图;
图9为本发明实施例3提供的一种主叫UE的结构框图;
图10为本发明实施例3提供的一种被叫UE的结构框图;
图11为本发明实施例3提供的一种主叫UE侧的SBC的结构框图;
图12为本发明实施例3提供的一种被叫UE侧的SBC的结构框图。
本发明的实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述。
本发明实施例应用于VoLTE通话场景,该通话场景基于图1所示的通信系统,所述通信系统中包括主叫用户设备(UE,User Equipment)、主叫UE侧的SBC(图1中所示的SBC1)、IMS、被叫UE侧的SBC(图1中所示的SBC2)、被叫UE。主叫UE与被叫UE进行通话时,主叫UE需要先发送呼叫请求消息,所述呼叫请求消息依次通过主叫UE侧的SBC、IMS、被叫UE侧的SBC后发送给被叫UE;被叫UE接收到该呼叫请求消息后可以发送呼叫应答消息,所述呼叫应答消息依次通过被叫UE侧的SBC、IMS、主叫UE侧的SBC后发送给主叫UE。这样主叫UE和被叫UE就可以进行语音通话,所述主叫UE和被叫UE之间的语音通话数据也是经过被叫UE侧的SBC、IMS、主叫UE侧的SBC进行传输的。
在相关技术中,为了保证安全,UE与该UE侧的SBC之间的数据传输是建立加密的;示例的,在语音通话过程中,主叫UE会将语音通话数据加密后发送给主叫UE侧的SBC,主叫UE侧的SBC解密后,再将语音通话数据通过IMS发送给被叫UE侧的SBC;被叫UE侧的SBC会将语音通话数据加密后发送给被叫UE,被叫UE解密后,可以播放语音通话数据,这样被叫UE侧的用户就可以听到主叫UE发送过来的语音。被叫UE向主叫UE发送语音通话数据的过程与主叫UE向被叫UE发送语音通话数据的过程相同,具体可参考以上的描述。
由上可知,在相关技术中,被叫UE和主叫UE之间传输语音通话数据时,语音通话数据在被叫UE侧的SBC、IMS、主叫UE侧的SBC这些网络侧设备之间的传输是没有经过加密的,这样很容易被恶意监听,安全性能不好。
在本发明实施例中,主叫UE和被叫UE之间传输语音通话数据时,语音通话数据在被叫UE侧的SBC、IMS、主叫UE侧的SBC这些网络侧设备之间的传输都是经过加密,这样就可以提高通话的安全性。
本发明实施例提供了一种语音通话的加密方法,如图1所示,本实施例方法的处理流程包括以下步骤:
步骤101、主叫UE发送呼叫请求消息,主叫UE侧的SBC接收呼叫请求消息。
其中,所述呼叫请求消息的会话描述协议(SDP,Session Description Protocol)提议信令中携带有所述主叫UE支持的至少一组密钥信息。
在进行VoLTE通话时,主叫UE需要先发送呼叫请求消息给被叫UE,在这个过程中,主叫UE需要先将呼叫请求消息发送给网络侧的设备,再由网络侧的设备转发给被叫UE。本实施例方法中主叫UE将所述呼叫请求消息发送给主叫UE侧的SBC。
在这里对SDP提议信令中密钥信息携带的格式进行说明:所述呼叫请求消息的SDP包括SDP提议(offer)信令,密钥信息可以作为SDP中具体媒体流(对应一个具体的m行)的属性描述存在,具体标示为a行。如:a行的原型定义a=crypto:<tag><crypto-suite><key-params>[<session-params>];a行中每一个字段的含义如下:
Tag(标签)——用于m行中唯一确定一个crypto;
crypto-suite(加密组合)——包含安全实时传输协议(SRTP,Secure Real-time Transport Protocol)加密算法和消息认证算法;
key-params(密钥参数)——包含主密钥、主加盐(Salt)值及其存活时间;
session-params(会话参数)——包含会话密钥推导率,SRTP载荷加密标志,SRTP认证保护标志,SRTP重放列表长度等信息。
步骤102、主叫UE侧的SBC转发所述呼叫请求消息,被叫UE侧的SBC接收所述呼叫请求消息。
主叫UE侧的SBC接收到所述呼叫请求消息后,转发所述呼叫请求到IMS。所述IMS接收到所述呼叫请求消息后,转发所述呼叫请求到被叫UE侧的SBC,被叫UE侧的SBC接收所述呼叫请求消息。
步骤103、被叫UE侧的SBC将所述呼叫请求消息转发给所述被叫UE, 被叫UE接收呼叫请求消息。
步骤104、在支持加密通话的情况下,被叫UE从所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息,被叫UE侧的SBC接收呼叫应答消息。
其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。
在这里需要说明的是,所述呼叫应答消息可以是200OK消息,也可以是183消息,视具体应用场景而定。
步骤105、被叫UE侧的SBC转发所述呼叫应答消息,主叫UE侧的SBC接收呼叫应答消息。
被叫UE侧的SBC接收到所述呼叫应答消息后转发所述呼叫应答消息到IMS,所述IMS再将所述呼叫应答消息转发到主叫UE侧的SBC,主叫UE侧的SBC接收呼叫应答消息。
步骤106、主叫UE侧的SBC将所述呼叫应答消息转发给所述主叫UE,所述主叫UE接收呼叫应答消息。
此时,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。这样所述主叫UE和所述被叫UE之间就协商好了传输语音通话数据时所采用的密钥信息即所述选择的一组密钥信息。
本实施例方法中,主叫UE和被叫UE之间协商密钥信息时采用的是SDP中的Offer/Answer模型,Offer方即主叫UE在发送的呼叫请求消息中携带SDP提议信令,所述SDP提议信令中定义若干个crypto属性项,说明主叫UE所能支持的至少一组密钥信息(一组密钥信息为由加密组合、密钥参数、会话参数等信息组成的一组信息);Answer方即被叫UE选择一个自己能支持的加密组合crypto属性项即一组密钥信息,将其附在SDP Answer信令中发给Offer方即主叫UE,协商完成。
步骤107、主叫UE和被叫UE采用所述选择的一组密钥信息,对传输过程中的语音通话数据进行加密。
在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,所述主叫UE发送应用所述选择的一组密钥信息加密后的第一语音通话数据;所述经过加密后的第一语音通话数据依次经过主叫UE侧的SBC、IMS、被叫UE侧的SBC的透传后,发送至被叫UE;所述被叫UE在接收到加密后的第一语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第一语音通话数据进行解密。
同理,所述被叫UE发送应用所述选择的一组密钥信息加密后的第二语音通话数据;所述经过加密后的第二语音通话数据依次经过被叫UE侧的SBC、IMS、主叫UE侧的SBC的透传后,发送至主叫UE;所述主叫UE在接收到加密后的第二语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。
这样,主叫UE和被叫UE双方在进行语音通话时,语音通话数据在主叫UE与被叫UE之间的传输都是经过加密,即实现了端到端的加密,这样就可以提高通话的安全性。
本实施例方法,主叫UE和被叫UE应用SDP信令协商出主叫UE和被叫UE之间传输语音通话数据时采用的密钥信息即选择的一组密钥信息,然后采用该选择的一组密钥信息,主叫UE和被叫UE中的任一方对需要传输的语音通话数据进行加密,然后将加密后的语音通话数据通过传输链路中的多个设备传输至另一方,另一方收到加密后的语音通话数据后,应用协商好的所述选择的一组密钥信息进行解密,这样即获得语音通话数据,本实施例方法实现了语音通话的端到端加密,使语音通话数据在整个传输过程中都处于加密状态,提高了语音通话的安全性。
以下分别从主叫UE、被叫UE、主叫UE侧的SBC、被叫UE侧的SBC对上述图1中的方法进行描述,具体过程可参考上述的描述。
本发明实施例还提供了一种语音通话的加密方法,应用于主叫UE一侧,如图2所示,本实施例方法的处理流程包括以下步骤:
步骤201、主叫UE发送呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息。
步骤202、所述主叫UE接收呼叫应答消息。
步骤203、在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,所述主叫UE发送应用所述选择的一组密钥信息加密后的第一语音通话数据;并且,所述主叫UE在接收到加密后的第二语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。
本发明实施例还提供了一种语音通话的加密方法,应用于被叫UE侧,如图3所示,本实施例方法的处理流程包括以下步骤:
步骤301、被叫UE接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息。
步骤302、在支持加密通话的情况下,被叫UE从所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息。
其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
步骤303、所述被叫UE发送应用所述选择的一组密钥信息加密后的第二语音通话数据;并且,所述被叫UE在接收到加密后的第一语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第一语音通话数据进行解密。
本发明实施例还提供了一种语音通话的加密方法,应用于主叫UE侧的SBC,如图4所示,本实施例方法的处理流程包括以下步骤:
步骤401、主叫UE侧的SBC接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有主叫UE支持的至少一组密钥信息。
步骤402、主叫UE侧的SBC转发所述呼叫请求消息。
步骤403、主叫UE侧的SBC接收呼叫应答消息,并将所述呼叫应答消息转发给所述主叫UE;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。
本发明实施例还提供了一种语音通话的加密方法,应用于被叫UE侧的SBC,如图5所示,本实施例方法的处理流程包括以下步骤:
步骤501、被叫UE侧的SBC接收呼叫请求消息,并将所述呼叫请求消 息转发给所述被叫UE,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息。
步骤502、被叫UE侧的SBC接收并转发呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。
本实施例中,图2-图5所述的每一个设备一侧的方法步骤具体可以参考图1所述的方法流程中的描述,不再一一详述。
实施例2
本实施例图6-图8中所示的SBC1为主叫UE侧的SBC,SBC2为被叫UE侧的SBC。
实施例1所述的方法中,被叫UE支持加密通话,这样主叫UE和被叫UE之间的语音通话就可以加密进行;然而,被叫UE还可能不支持加密通话,此种情况下,本发明实施例还提供了一种语音通话的加密方法,如图6所示,本实施例方法的处理流程包括以下步骤:
步骤601、主叫UE发送呼叫请求消息,主叫UE侧的SBC接收呼叫请求消息。
其中,所述呼叫请求消息的SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息。
在进行VoLTE通话时,主叫UE需要先发送呼叫请求消息给被叫UE,在这个过程中,主叫UE需要先将呼叫请求消息发送给网络侧的设备,再由网络侧的设备转发给被叫UE,在本实施例中所述主叫UE会先将呼叫请求消息发送给所述主叫UE侧的SBC;主叫UE侧的SBC接收呼叫请求消息。
步骤602、主叫UE侧的SBC转发所述呼叫请求消息,被叫UE侧的SBC接收所述呼叫请求消息。
主叫UE侧的SBC接收到所述呼叫请求消息后,转发所述呼叫请求到IMS。所述IMS接收到所述呼叫请求消息后,转发所述呼叫请求到被叫UE侧的SBC,被叫UE侧的SBC接收所述呼叫请求消息。
步骤603、被叫UE侧的SBC将所述呼叫请求消息转发给所述被叫UE, 被叫UE接收呼叫请求消息。
步骤604、被叫UE在不支持加密通话或无法识别所述SDP提议信令中携带的所述主叫UE支持的至少一组密钥信息的情况下,发送呼叫应答消息;被叫UE侧的SBC接收呼叫应答消息。
其中,所述呼叫应答消息的SDP应答信令中未携带有密钥信息。
步骤605、被叫UE侧的SBC转发呼叫应答消息,主叫UE侧的SBC接收呼叫应答消息。
被叫UE侧的SBC接收到所述呼叫应答消息后转发所述呼叫应答消息到IMS,所述IMS再将所述呼叫应答消息转发到主叫UE侧的SBC,主叫UE侧的SBC接收呼叫应答消息。
步骤606、主叫UE侧的SBC将所述呼叫应答消息转发给所述主叫UE,所述主叫UE接收呼叫应答消息。
此时,所述呼叫应答消息的SDP应答信令中未携带有密钥信息,即所述主叫UE和所述被叫UE协商传输语音通话数据时所采用的密钥信息失败,所述主叫UE和所述被叫UE要进行非加密的通话即明话。
步骤607、主叫UE和被叫UE进行非加密语音通话。
主叫UE和被叫UE进行非加密语音通话包括:所述主叫UE发送未加密的第一语音通话数据,所述未加密的第一语音通话数据依次经过主叫UE侧的SBC、IMS、被叫UE侧的SBC的透传后,发送至被叫UE;所述被叫UE接收未加密的第一语音通话数据。所述被叫UE发送未加密的第二语音通话数据,所述未加密的第二语音通话数据依次经过被叫UE侧的SBC、IMS、主叫UE侧的SBC的透传后,发送至主叫UE;所述主叫UE接收未加密的第二语音通话数据。
图6所述的方法无法区分被叫UE不进行加密通话是不支持加密通话还是无法识别所述SDP提议信令中携带的所述主叫UE支持的至少一组密钥信息,故本发明实施例还提供了一种语音通话的加密方法,如图7所示,本实施例方法的处理流程包括以下步骤:
步骤701、主叫UE发送呼叫请求消息,主叫UE侧的SBC接收呼叫请 求消息。
其中,所述呼叫请求消息的SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息,所述呼叫请求消息中还携带有通话加密指示信息。
示例的,所述呼叫请求消息可以是SIP消息,所述通话加密指示信息可以携带在SIP消息的头部。
在进行VoLTE通话时,主叫UE需要先发送呼叫请求消息给被叫UE,在这个过程中,主叫UE需要先将呼叫请求消息发送给网络侧的设备,再由网络侧的设备转发给被叫UE,在本实施例中所述主叫UE会先将呼叫请求消息发送给所述主叫UE侧的SBC,主叫UE侧的SBC接收呼叫请求消息。
步骤702、主叫UE侧的SBC转发所述呼叫请求消息,被叫UE侧的SBC接收所述呼叫请求消息。
主叫UE侧的SBC接收到所述呼叫请求消息后,转发所述呼叫请求到IMS。所述IMS接收到所述呼叫请求消息后,转发所述呼叫请求到被叫UE侧的SBC,被叫UE侧的SBC接收所述呼叫请求消息。
步骤703、被叫UE侧的SBC将所述呼叫请求消息转发给所述被叫UE,被叫UE接收呼叫请求消息。
步骤704、被叫UE在不支持加密通话的情况下,发送呼叫应答消息,被叫UE侧的SBC接收呼叫应答消息。
其中,所述呼叫应答消息中携带有不使用通话加密指示信息。
被叫UE接收呼叫请求消息后,如果不支持使用加密通话,则被叫UE会在呼叫应答消息中携带有不使用通话加密指示信息,以告知主叫UE自己不支持使用加密通话。被叫UE将所述叫应答消息发送给被叫UE侧的SBC,被叫UE侧的SBC接收呼叫应答消息。
步骤705、被叫UE侧的SBC转发呼叫应答消息,主叫UE侧的SBC接收呼叫应答消息。
被叫UE侧的SBC接收到所述呼叫应答消息后转发所述呼叫应答消息到IMS,所述IMS再将所述呼叫应答消息转发到主叫UE侧的SBC,主叫UE侧的SBC接收呼叫应答消息。
步骤706、主叫UE侧的SBC将所述呼叫应答消息转发给所述主叫UE,所述主叫UE接收呼叫应答消息。
此时,所述呼叫应答消息的SDP应答信令中未携带有密钥信息,即所述主叫UE和所述被叫UE协商传输语音通话数据时所采用的密钥信息失败,所述主叫UE和所述被叫UE要进行非加密的通话即明话。
步骤707、主叫UE和被叫UE进行非加密语音通话。
主叫UE和被叫UE进行非加密语音通话包括:
所述主叫UE发送未加密的第一语音通话数据,所述未加密的第一语音通话数据依次经过主叫UE侧的SBC、IMS、被叫UE侧的SBC的透传后,发送至被叫UE;所述被叫UE接收未加密的第一语音通话数据。所述被叫UE发送未加密的第二语音通话数据,所述未加密的第二语音通话数据依次经过被叫UE侧的SBC、IMS、主叫UE侧的SBC的透传后,发送至主叫UE;所述主叫UE接收未加密的第二语音通话数据。
在IMS的实际部署中,UE与其一侧的SBC之间一般存在接入侧的加密,将其加入到图1所述的端到端加密,此时就存在二次加密,故本发明实施例还提供了一种语音通话的加密方法,如图8所示,本实施例方法的处理流程包括以下步骤:
步骤801、主叫UE发送呼叫请求消息,主叫UE侧的SBC接收呼叫请求消息。
其中,所述呼叫请求消息的SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述第一密钥信息用于所述主叫UE与主叫UE侧的SBC之间的通信加密。
因为涉及二次加密,在主叫UE侧需要两种密钥信息,这两种密钥信息:主叫UE支持的至少一组密钥信息以及所述第一密钥信息在SDP提议信令中需要作为两个独立部分,比如作为SDP提议信令中同一个媒体流(m行)中的两组独立的属性存在。
在进行VoLTE通话时,主叫UE需要先发送呼叫请求消息给被叫UE, 在这个过程中,主叫UE需要先将呼叫请求消息发送给主叫UE侧的SBC,再通过多个网络侧设备转发发送给被叫UE。
步骤802、所述主叫UE侧的SBC转发删除所述第一密钥信息后的呼叫请求消息,被叫UE侧的SBC接收该呼叫请求消息。
主叫UE侧的SBC接收到所述呼叫请求消息后,需要先存储所述呼叫请求消息中的第一密钥信息,然后删除所述呼叫请求消息的SDP提议信令中的第一密钥信息,并转发删除所述第一密钥信息后的呼叫请求消息到IMS,所述IMS接收到所述删除所述第一密钥信息后的呼叫请求消息后,转发所述呼叫请求消息到被叫UE侧的SBC,被叫UE侧的SBC接收该呼叫请求消息。
步骤803、被叫UE侧的SBC在所述呼叫请求消息的SDP提议信令中携带第二密钥信息后,转发给所述被叫UE;被叫UE接收呼叫请求消息。
所述被叫UE侧的SBC接收到的呼叫请求消息的SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;所述被叫UE侧的SBC会在SDP提议信令中添加第二密钥信息,然后将转发给所述被叫UE,所述被叫UE接收的呼叫请求消息中携带有所述至少一组密钥信息以及第二密钥信息。
步骤804、在支持加密通话的情况下,被叫UE从所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息,被叫UE侧的SBC接收在SDP应答信令中携带第二密钥信息的呼叫应答消息。
在支持加密通话的情况下,被叫UE会从所述至少一组密钥信息中选择出一组密钥信息,所述被叫UE发送给被叫UE侧的SBC的呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息以及第二密钥信息,被叫UE侧的SBC接收在SDP应答信令中携带第二密钥信息的呼叫应答消息。这样,被叫UE侧的SBC与被叫UE就协商好了两者之间传输时二次加密用的第二密钥信息。
因为涉及二次加密,在被叫UE侧需要两种密钥信息,则两种密钥信息:选择的一组密钥信息以及所述第二密钥信息在SDP提议信令中需要作为两个独立部分,比如作为SDP提议信令中同一个媒体流(m行)中的两组独立的属性存在。
在这里需要说明的是,所述呼叫应答消息可以是200OK消息,也可以是183消息,视具体应用场景而定。
步骤805、被叫UE侧的SBC转发删除所述第二密钥信息后的呼叫应答消息;主叫UE侧的SBC接收呼叫应答消息。
被叫UE侧的SBC接收到所述呼叫应答消息后,会删除所述呼叫应答消息的SDP应答信令中的第二密钥信息,此时,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。所述被叫UE侧的SBC转发删除所述第二密钥信息后的呼叫应答消息到IMS,所述IMS再将所述删除所述第二密钥信息后的呼叫应答消息转发到主叫UE侧的SBC,主叫UE侧的SBC接收该呼叫应答消息。
步骤806、主叫UE侧的SBC在所述呼叫应答消息的SDP应答信令中携带所述第一密钥信息后转发给所述主叫UE,所述主叫UE接收呼叫应答消息。
所述IMS将所述删除所述第二密钥信息后的呼叫应答消息转发到主叫UE侧的SBC,此时,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;主叫UE侧的SBC在该呼叫应答消息中添加所述第一密钥信息后转发给所述主叫UE,这样,主叫UE侧的SBC与主叫UE就协商好了两者之间传输时二次加密用的第一密钥信息。
同时,该呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。这样所述主叫UE和所述被叫UE之间就协商好了传输语音通话数据时所采用的密钥信息即所述选择的一组密钥信息。
这样通过上述的步骤,所述主叫UE和所述被叫UE之间就协商好了传输语音通话数据时所采用的密钥信息即所述选择的一组密钥信息,主叫UE和主叫UE侧的SBC也协商好了两者之间二次加密用的第一密钥信息;被叫UE和被叫UE侧的SBC也协商好了两者之间二次加密用的第二密钥信息。
步骤807、主叫UE和被叫UE采用所述选择的一组密钥信息,对传输过程中的语音通话数据进行端到端加密,同时采用第一密钥信息和第二密钥信息对传输过程中的语音通话数据进行接入侧的二次加密。
在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,主叫UE向被叫UE发送第一语音通话数据的流程如下:
所述主叫UE应用所述选择的一组密钥信息对第一语音通话数据进行一次加密,再应用所述第一密钥信息对一次加密后的第一语音通话数据进行二次加密后,发送给主叫UE侧的SBC;所述主叫UE侧的SBC接收二次加密后的第一语音通话数据,应用所述第一密钥信息对二次加密后的第一语音通话数据进行一次解密后,转发一次解密后的第一语音通话数据;所述主叫UE侧的SBC会将一次解密后的第一语音通话数据转发给IMS,所述IMS会将一次解密后的第一语音通话数据透传给被叫UE侧的SBC,所述被叫UE侧的SBC接收一次解密后的第一语音通话数据,应用所述第二密钥信息对一次解密后的第一语音通话数据进行二次加密后,发送给被叫UE;所述被叫UE在接收到被叫UE侧的SBC发送的二次加密后的第一语音通话数据后,应用所述第二密钥信息对二次加密后的第一语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第一语音通话数据进行二次解密;这样所述被叫UE就可以获得所述主叫UE发送过来的第一语音通话数据。
同理,被叫UE向主叫UE发送第二语音通话数据的流程如下:
所述被叫UE应用所述选择的一组密钥信息对第二语音通话数据进行一次加密,再应用所述第二密钥信息对一次加密后的第二语音通话数据进行二次加密后,发送给被叫UE侧的SBC;所述被叫UE侧的SBC接收二次加密后的第二语音通话数据,应用所述第二密钥信息对二次加密后的第二语音通话数据进行一次解密后,转发一次解密后的第二语音通话数据。所述被叫UE侧的SBC会将一次解密后的第二语音通话数据发送给IMS,所述IMS会将一次解密后的第二语音通话数据透传给主叫UE侧的SBC,所述主叫UE侧的SBC接收一次解密后的第二语音通话数据,应用所述第一密钥信息对一次解密后的第二语音通话数据进行二次加密后,发送给主叫UE。所述主叫UE接收主叫UE侧的SBC发送的二次加密后的第二语音通话数据,应用所述第一密钥信息对二次加密后的第二语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第二语音通话数据进行二次解密。
这样,主叫UE和被叫UE双方在进行语音通话时,语音通话数据在主叫UE与被叫UE之间的传输都是经过加密,即实现了端到端的加密,同时,所述UE以及UE侧的SBC之间的传输语音通话数据是二次加密的,这样就更加提高通话的安全性。
本发明实施例还提出了一种计算机可读存储介质,存储有计算机可执行指令,计算机可执行指令用于执行上述描述的任意一个方法。
实施例3
本发明实施例提供了一种主叫UE,如图9所示,所述主叫UE包括:第一发送单元901和第一接收单元902,其中,
第一发送单元901,设置为发送呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
第一接收单元902,设置为接收呼叫应答消息;
所述第一发送单元901,还设置为在所述第一接收单元902接收到的呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,发送应用所述选择的一组密钥信息加密后的第一语音通话数据;
所述第一接收单元902,还设置为在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,接收加密后的第二语音通话数据,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。
可选的,所述第一发送单元901,还设置为在所述第一接收单元902接收到的呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,发送未加密的第一语音通话数据;所述第一接收单元902,还设置为在呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,接收未加密的第二语音通话数据。
可选的,所述呼叫请求消息中还携带有通话加密指示信息;所述第一发送单元901,还设置为在所述第一接收单元902接收到的呼叫应答消息中携带有不使用通话加密指示信息的情况下,发送未加密的第一语音通话数据; 所述第一接收单元902,还设置为在接收到的呼叫应答消息中携带有不使用通话加密指示信息的情况下,接收未加密的第二语音通话数据。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述呼叫应答消息的SDP应答信令中还携带有第一密钥信息;所述第一发送单元901,还设置为应用所述选择的一组密钥信息对第一语音通话数据进行一次加密,再应用所述第一密钥信息对一次加密后的第一语音通话数据进行二次加密后,发送给主叫UE侧的SBC;所述第一接收单元902,还设置为接收主叫UE侧的SBC发送的二次加密后的第二语音通话数据,应用所述第一密钥信息对二次加密后的第二语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第二语音通话数据进行二次解密。
本发明实施例还提供了一种被叫用户设备UE,如图10所示,所述被叫UE包括:第二接收单元1001和第二发送单元1002,其中,
第二接收单元1001,设置为接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
第二发送单元1002,设置为在支持加密通话的情况下,从所述第二接收单元1001接收到的所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
所述第二接收单元1001,还设置为接收加密后的第一语音通话数据,应用所述选择的一组密钥信息对所述加密后的第一语音通话数据进行解密;
所述第二发送单元1002,还设置为发送应用所述选择的一组密钥信息加密后的第二语音通话数据。
可选的,所述第二发送单元1002,还设置为在不支持加密通话或无法识别所述SDP提议信令中携带的所述主叫UE支持的至少一组密钥信息的情况下,发送呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中未携带有密钥信息;所述第二发送单元1002,还设置为发送未加密的第二语音通话数据;所述第二接收单元1001,还设置为接收未加密的第一语音通话数据。
可选的,所述呼叫请求消息中还携带有通话加密指示信息;所述第二发 送单元1002,还设置为在不支持加密通话的情况下,发送呼叫应答消息,其中,所述呼叫应答消息中携带有不使用通话加密指示信息;所述第二发送单元1002,还设置为发送未加密的第二语音通话数据;所述第二接收单元1001,还设置为接收未加密的第一语音通话数据。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第二密钥信息;所述呼叫应答消息的SDP应答信令中还携带有第二密钥信息;所述第二发送单元1002,还设置为应用所述选择的一组密钥信息对第二语音通话数据进行一次加密,再应用所述第二密钥信息对一次加密后的第二语音通话数据进行二次加密后,发送给被叫UE侧的SBC;所述第二接收单元1001,还设置为接收被叫UE侧的SBC发送的二次加密后的第一语音通话数据,应用所述第二密钥信息对二次加密后的第一语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第一语音通话数据进行二次解密。
本发明实施例还提供了一种主叫UE侧的SBC,如图11所示,所述主叫UE侧的SBC包括:第三接收单元1101和第三发送单元1102,其中,
第三接收单元1101,设置为接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有主叫UE支持的至少一组密钥信息;
第三发送单元1102,设置为转发所述第三接收单元1101接收的呼叫请求消息;
所述第三接收单元1101,还设置为接收呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;所述第三发送单元1102,还用将所述第三接收单元接收的所述呼叫应答消息转发给所述主叫UE。
可选的,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息;所述第三发送单元1102,是设置为转发删除所述第一密钥信息后的呼叫请求消息;并在所述第三接收单元1101接收到的呼叫应答消息的SDP应答信令中携带所述第一密钥信息后转发给所述主叫UE;
第三接收单元1101,还设置为接收二次加密后的第一语音通话数据;所述第三发送单元1102,还设置为应用所述第一密钥信息对所述第三接收单元 1101接收到的二次加密后的第一语音通话数据进行一次解密后,转发一次解密后的第一语音通话数据;
第三接收单元1101,还设置为接收一次解密后的第二语音通话数据;所述第三发送单元1102,还设置为应用所述第一密钥信息对第三接收单元1101接收的一次解密后的第二语音通话数据进行二次加密后,发送给主叫UE。
本发明实施例还提供了一种被叫UE侧的SBC,如图12所示,所述被叫UE侧的SBC包括:第四接收单元1201和第四发送单元1202,其中,
第四接收单元1201,设置为接收呼叫请求消息,所述呼叫请求消息的SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
第四发送单元1202,设置为将所述第四接收单元1201接收的呼叫请求消息转发给所述被叫UE;
所述第四接收单元1201,还设置为接收呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;所述第四发送单元1202,还设置为转发呼叫应答消息。
可选的,所述第四发送单元1202,是设置为将所述第四接收单元1201接收的呼叫请求消息的SDP提议信令中携带第二密钥信息后,转发给所述被叫UE;所述第四接收单元1201,还设置为接收在SDP应答信令中携带第二密钥信息的呼叫应答消息;所述第四发送单元1202,是设置为转发删除所述第二密钥信息后的呼叫应答消息;
第四接收单元1201,还设置为接收一次解密后的第一语音通话数据;
所述第四发送单元1202,还设置为应用所述第二密钥信息对第四接收单元1201接收的一次解密后的第一语音通话数据进行二次加密后,发送给被叫UE;
第四接收单元1201,还设置为接收二次加密后的第二语音通话数据;
所述第四发送单元1202,还设置为应用所述第二密钥信息对所述第四接收单元1202接收的二次加密后的第二语音通话数据进行一次解密后,转发一次解密后的第二语音通话数据。
在实际应用中,本实施例中所述的第一发送单元901和第一接收单元902 可以由主叫UE上的中央处理器(CPU,Central Processing Unit)、微处理器(MPU,Micro Processing Unit)、数字信号处理器(DSP,Digital Signal Processor)或现场可编程门阵列(FPGA,Field-Programmable Gate Array)等器件实现。本实施例中所述的第二接收单元1001和第二发送单元1002可以由被叫UE上的中央处理器(CPU)、微处理器(MPU)、数字信号处理器(DSP)或现场可编程门阵列(FPGA)等器件实现。本实施例中所述的第三接收单元1101和第三发送单元1102可以由主叫UE侧的SCB上的中央处理器(CPU)、微处理器(MPU)、数字信号处理器(DSP)或现场可编程门阵列(FPGA)等器件实现。本实施例中所述的第四接收单元1201和第四发送单元1202可以由被叫UE侧的SCB上的中央处理器(CPU)、微处理器(MPU)、数字信号处理器(DSP)或现场可编程门阵列(FPGA)等器件实现。
本领域内的技术人员应明白,本发明的实施例可提供为方法、系统、或计算机程序产品。因此,本发明可采用硬件实施例、软件实施例、或结合软件和硬件方面的实施例的形式。而且,本发明可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本发明是参照根据本发明实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上, 使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序来指令相关硬件(例如处理器)完成,所述程序可以存储于计算机可读存储介质中,如只读存储器、磁盘或光盘等。可选地,上述实施例的全部或部分步骤也可以使用一个或多个集成电路来实现。相应地,上述实施例中的各模块/单元可以采用硬件的形式实现,例如通过集成电路来实现其相应功能,也可以采用软件功能模块的形式实现,例如通过处理器执行存储与存储器中的程序/指令来实现其相应功能。本发明不限于任何特定形式的硬件和软件的结合。
以上所述,仅为本发明的较佳实施例而已,并非用于限定本发明的保护范围。
工业实用性
上述技术方案提高了语音通话的安全性。

Claims (24)

  1. 一种语音通话的加密方法,所述方法包括:
    主叫用户设备UE发送呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
    所述主叫UE接收呼叫应答消息;
    在所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,所述主叫UE发送应用所述选择的一组密钥信息加密后的第一语音通话数据;并且,所述主叫UE在接收到加密后的第二语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。
  2. 根据权利要求1所述的方法,还包括:
    在所述呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,所述主叫UE发送未加密的第一语音通话数据,并接收未加密的第二语音通话数据。
  3. 根据权利要求1所述的方法,所述呼叫请求消息中还携带有通话加密指示信息;所述方法还包括:
    在所述呼叫应答消息中携带有不使用通话加密指示信息的情况下,所述主叫UE发送未加密的第一语音通话数据,并接收未加密的第二语音通话数据。
  4. 根据权利要求1所述的方法,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述呼叫应答消息的SDP应答信令中还携带有第一密钥信息;
    所述主叫UE应用所述选择的一组密钥信息对第一语音通话数据进行一次加密,再应用所述第一密钥信息对一次加密后的第一语音通话数据进行二次加密后,发送给主叫UE侧的SBC;
    并且,所述主叫UE接收主叫UE侧的SBC发送的二次加密后的第二语音通话数据,应用所述第一密钥信息对二次加密后的第二语音通话数据进行 一次解密,再应用选择的一组密钥信息对一次解密后的第二语音通话数据进行二次解密。
  5. 一种语音通话的加密方法,所述方法包括:
    被叫用户设备UE接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
    在支持加密通话的情况下,被叫UE从所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
    所述被叫UE发送应用所述选择的一组密钥信息加密后的第二语音通话数据;并且,所述被叫UE在接收到加密后的第一语音通话数据后,应用所述选择的一组密钥信息对所述加密后的第一语音通话数据进行解密。
  6. 根据权利要求5所述的方法,所述方法还包括:
    在所述被叫UE不支持加密通话或无法识别所述SDP提议信令中携带的所述主叫UE支持的至少一组密钥信息的情况下,所述被叫UE发送呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中未携带有密钥信息;
    所述被叫UE发送未加密的第二语音通话数据;并接收未加密的第一语音通话数据。
  7. 根据权利要求5所述的方法,所述呼叫请求消息中还携带有通话加密指示信息;所述方法还包括:
    在不支持加密通话的情况下,发送呼叫应答消息,其中,所述呼叫应答消息中携带有不使用通话加密指示信息;
    所述被叫UE发送未加密的第二语音通话数据;并接收未加密的第一语音通话数据。
  8. 根据权利要求5所述的方法,所述呼叫请求消息的SDP提议信令中还携带有第二密钥信息,所述呼叫应答消息的SDP应答信令中还携带有第二密钥信息;
    所述被叫UE应用所述选择的一组密钥信息对第二语音通话数据进行一次加密,再应用所述第二密钥信息对一次加密后的第二语音通话数据进行二 次加密后,发送给被叫UE侧的SBC;
    并且,所述被叫UE在接收到被叫UE侧的SBC发送的二次加密后的第一语音通话数据后,应用所述第二密钥信息对二次加密后的第一语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第一语音通话数据进行二次解密。
  9. 一种语音通话的加密方法,所述方法包括:
    主叫用户设备UE侧的会话边界控制器SBC接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有主叫UE支持的至少一组密钥信息;
    主叫UE侧的SBC转发所述呼叫请求消息;
    主叫UE侧的SBC接收呼叫应答消息,并将所述呼叫应答消息转发给所述主叫UE;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。
  10. 根据权利要求9所述的方法,其中,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述主叫UE侧的SBC转发所述呼叫请求消息包括:
    所述主叫UE侧的SBC转发删除所述第一密钥信息后的呼叫请求消息;
    所述将所述呼叫应答消息转发给所述主叫UE包括:
    在所述呼叫应答消息的SDP应答信令中携带所述第一密钥信息后转发给所述主叫UE;
    在将所述呼叫应答消息转发给所述主叫UE之后,所述方法还包括:
    所述主叫UE侧的SBC接收二次加密后的第一语音通话数据,应用所述第一密钥信息对二次加密后的第一语音通话数据进行一次解密后,转发一次解密后的第一语音通话数据;
    所述主叫UE侧的SBC接收一次解密后的第二语音通话数据,应用所述第一密钥信息对一次解密后的第二语音通话数据进行二次加密后,发送给主叫UE。
  11. 一种语音通话的加密方法,所述方法包括:
    被叫用户设备UE侧的会话边界控制器SBC接收呼叫请求消息,并将所述呼叫请求消息转发给所述被叫UE,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;
    被叫UE侧的SBC接收并转发呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息。
  12. 根据权利要求11所述的方法,其中,被叫UE侧的SBC将所述呼叫请求消息转发给所述被叫UE包括:
    被叫UE侧的SBC在所述呼叫请求消息的SDP提议信令中携带第二密钥信息后,转发给所述被叫UE;
    所述被叫UE侧的SBC接收并转发呼叫应答消息包括:
    所述被叫UE侧的SBC接收在SDP应答信令中携带第二密钥信息的呼叫应答消息,并转发删除所述第二密钥信息后的呼叫应答消息;
    在被叫UE侧的SBC转发呼叫应答消息之后,所述方法还包括:
    所述被叫UE侧的SBC接收一次解密后的第一语音通话数据,应用所述第二密钥信息对一次解密后的第一语音通话数据进行二次加密后,发送给被叫UE;
    所述被叫UE侧的SBC接收二次加密后的第二语音通话数据,应用所述第二密钥信息对二次加密后的第二语音通话数据进行一次解密后,转发一次解密后的第二语音通话数据。
  13. 一种主叫用户设备UE,所述主叫UE包括:
    第一发送单元,设置为发送呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;在所述第一接收单元接收到的呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,发送应用所述选择的一组密钥信息加密后的第一语音通话数据;
    第一接收单元,设置为接收呼叫应答消息;在所述呼叫应答消息的SDP 应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息的情况下,接收加密后的第二语音通话数据,应用所述选择的一组密钥信息对所述加密后的第二语音通话数据进行解密。
  14. 根据权利要求13所述的主叫UE,
    所述第一发送单元,还设置为在所述第一接收单元接收到的呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,发送未加密的第一语音通话数据;
    所述第一接收单元,还设置为在呼叫应答消息的SDP应答信令中未携带有密钥信息的情况下,接收未加密的第二语音通话数据。
  15. 根据权利要求13所述的主叫UE,所述呼叫请求消息中还携带有通话加密指示信息;
    所述第一发送单元,还设置为在所述第一接收单元接收到的呼叫应答消息中携带有不使用通话加密指示信息的情况下,发送未加密的第一语音通话数据;
    所述第一接收单元,还设置为在接收到的呼叫应答消息中携带有不使用通话加密指示信息的情况下,接收未加密的第二语音通话数据。
  16. 根据权利要求13所述的主叫UE,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息,所述呼叫应答消息的SDP应答信令中还携带有第一密钥信息;
    所述第一发送单元,还设置为应用所述选择的一组密钥信息对第一语音通话数据进行一次加密,再应用所述第一密钥信息对一次加密后的第一语音通话数据进行二次加密后,发送给主叫UE侧的SBC;
    所述第一接收单元,还设置为接收主叫UE侧的SBC发送的二次加密后的第二语音通话数据,应用所述第一密钥信息对二次加密后的第二语音通话数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第二语音通话数据进行二次解密。
  17. 一种被叫用户设备UE,所述被叫UE包括:
    第二接收单元,设置为接收呼叫请求消息,所述呼叫请求消息的会话描 述协议SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;接收加密后的第一语音通话数据,应用所述选择的一组密钥信息对所述加密后的第一语音通话数据进行解密;
    第二发送单元,设置为在支持加密通话的情况下,从所述第二接收单元接收到的所述至少一组密钥信息中选择出一组密钥信息,发送呼叫应答消息;其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;发送应用所述选择的一组密钥信息加密后的第二语音通话数据。
  18. 根据权利要求17所述的被叫UE,
    所述第二发送单元,还设置为在不支持加密通话或无法识别所述SDP提议信令中携带的所述主叫UE支持的至少一组密钥信息的情况下,发送呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中未携带有密钥信息;
    所述第二发送单元,还设置为发送未加密的第二语音通话数据;
    所述第二接收单元,还设置为接收未加密的第一语音通话数据。
  19. 根据权利要求17所述的被叫UE,所述呼叫请求消息中还携带有通话加密指示信息;
    所述第二发送单元,还设置为在不支持加密通话的情况下,发送呼叫应答消息,其中,所述呼叫应答消息中携带有不使用通话加密指示信息;
    所述第二发送单元,还设置为发送未加密的第二语音通话数据;
    所述第二接收单元,还设置为接收未加密的第一语音通话数据。
  20. 根据权利要求17所述的被叫UE,所述呼叫请求消息的SDP提议信令中还携带有第二密钥信息;所述呼叫应答消息的SDP应答信令中还携带有第二密钥信息;
    所述第二发送单元,还设置为应用所述选择的一组密钥信息对第二语音通话数据进行一次加密,再应用所述第二密钥信息对一次加密后的第二语音通话数据进行二次加密后,发送给被叫UE侧的SBC;
    所述第二接收单元,还设置为接收被叫UE侧的SBC发送的二次加密后的第一语音通话数据,应用所述第二密钥信息对二次加密后的第一语音通话 数据进行一次解密,再应用选择的一组密钥信息对一次解密后的第一语音通话数据进行二次解密。
  21. 一种主叫用户设备UE侧的会话边界控制器SBC,所述主叫UE侧的SBC包括:
    第三接收单元,设置为接收呼叫请求消息,所述呼叫请求消息的会话描述协议SDP提议信令中携带有主叫UE支持的至少一组密钥信息;接收呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
    第三发送单元,设置为转发所述第三接收单元接收的呼叫请求消息;将所述第三接收单元接收的所述呼叫应答消息转发给所述主叫UE。
  22. 根据权利要求21所述的主叫UE侧的SBC,其中,所述呼叫请求消息的SDP提议信令中还携带有第一密钥信息;
    所述第三发送单元,是设置为转发删除所述第一密钥信息后的呼叫请求消息;并在所述第三接收单元接收到的呼叫应答消息的SDP应答信令中携带所述第一密钥信息后转发给所述主叫UE;
    第三接收单元,还设置为接收二次加密后的第一语音通话数据;
    所述第三发送单元,还设置为应用所述第一密钥信息对所述第三接收单元接收到的二次加密后的第一语音通话数据进行一次解密后,转发一次解密后的第一语音通话数据;
    第三接收单元,还设置为接收一次解密后的第二语音通话数据;
    所述第三发送单元,还设置为应用所述第一密钥信息对一次解密后的第二语音通话数据进行二次加密后,发送给主叫UE。
  23. 一种被叫用户设备UE侧的会话边界控制器SBC,其中,所述被叫UE侧的SBC包括:
    第四接收单元,设置为接收呼叫请求消息,所述呼叫请求消息的SDP提议信令中携带有所述主叫UE支持的至少一组密钥信息;接收呼叫应答消息,其中,所述呼叫应答消息的SDP应答信令中携带有被叫UE从所述至少一组密钥信息中选择的一组密钥信息;
    第四发送单元,设置为将所述第四接收单元接收的呼叫请求消息转发给所述被叫UE;转发呼叫应答消息。
  24. 根据权利要求23所述的被叫UE侧的SBC,其中,
    所述第四发送单元,是设置为将所述第四接收单元接收的呼叫请求消息的SDP提议信令中携带第二密钥信息后,转发给所述被叫UE;
    所述第四接收单元,还设置为接收在SDP应答信令中携带第二密钥信息的呼叫应答消息;
    所述第四发送单元,是设置为转发删除所述第二密钥信息后的呼叫应答消息;
    第四接收单元,还设置为接收一次解密后的第一语音通话数据;
    所述第四发送单元,还设置为应用所述第二密钥信息对第四接收单元接收的一次解密后的第一语音通话数据进行二次加密后,发送给被叫UE;
    第四接收单元,还设置为接收二次加密后的第二语音通话数据;
    所述第四发送单元,还设置为应用所述第二密钥信息对所述第四接收单元接收的二次加密后的第二语音通话数据进行一次解密后,转发一次解密后的第二语音通话数据。
PCT/CN2016/079600 2015-09-09 2016-04-18 一种语音通话的加密方法及装置 WO2016180180A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510572139.8 2015-09-09
CN201510572139.8A CN106534044A (zh) 2015-09-09 2015-09-09 一种语音通话的加密方法及装置

Publications (1)

Publication Number Publication Date
WO2016180180A1 true WO2016180180A1 (zh) 2016-11-17

Family

ID=57247771

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/079600 WO2016180180A1 (zh) 2015-09-09 2016-04-18 一种语音通话的加密方法及装置

Country Status (2)

Country Link
CN (1) CN106534044A (zh)
WO (1) WO2016180180A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110621016A (zh) * 2019-10-18 2019-12-27 中国联合网络通信集团有限公司 一种用户身份保护方法、用户终端和基站
CN112953964A (zh) * 2021-03-15 2021-06-11 北京中联环信科技有限公司 一种语音信令加密处理系统及加密处理方法

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108833943B (zh) * 2018-04-24 2020-12-08 苏州科达科技股份有限公司 码流的加密协商方法、装置及会议终端

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130031365A1 (en) * 2011-07-28 2013-01-31 Electronics And Telecommunications Research Institute Information protection system and method
CN103795966A (zh) * 2014-01-15 2014-05-14 北京明朝万达科技有限公司 一种基于数字证书的安全视频通话实现方法及系统
CN204145683U (zh) * 2014-10-24 2015-02-04 厦门蓝斯通信股份有限公司 一种数字对讲机加密的装置
CN104468634A (zh) * 2014-12-31 2015-03-25 大唐移动通信设备有限公司 一种呼叫建立方法、终端和安全as

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101222320B (zh) * 2007-01-11 2011-02-16 华为技术有限公司 一种媒体流安全上下文协商的方法、系统和装置
US9544334B2 (en) * 2011-05-11 2017-01-10 Alcatel Lucent Policy routing-based lawful interception in communication system with end-to-end encryption
CN104683098B (zh) * 2013-11-29 2019-09-10 中国移动通信集团公司 一种保密通信业务的实现方法、设备及系统
CN104683304B (zh) * 2013-11-29 2019-01-01 中国移动通信集团公司 一种保密通信业务的处理方法、设备和系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20130031365A1 (en) * 2011-07-28 2013-01-31 Electronics And Telecommunications Research Institute Information protection system and method
CN103795966A (zh) * 2014-01-15 2014-05-14 北京明朝万达科技有限公司 一种基于数字证书的安全视频通话实现方法及系统
CN204145683U (zh) * 2014-10-24 2015-02-04 厦门蓝斯通信股份有限公司 一种数字对讲机加密的装置
CN104468634A (zh) * 2014-12-31 2015-03-25 大唐移动通信设备有限公司 一种呼叫建立方法、终端和安全as

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110621016A (zh) * 2019-10-18 2019-12-27 中国联合网络通信集团有限公司 一种用户身份保护方法、用户终端和基站
CN110621016B (zh) * 2019-10-18 2022-08-12 中国联合网络通信集团有限公司 一种用户身份保护方法、用户终端和基站
CN112953964A (zh) * 2021-03-15 2021-06-11 北京中联环信科技有限公司 一种语音信令加密处理系统及加密处理方法
CN112953964B (zh) * 2021-03-15 2024-03-08 北京中联环信科技有限公司 一种语音信令加密处理系统及加密处理方法

Also Published As

Publication number Publication date
CN106534044A (zh) 2017-03-22

Similar Documents

Publication Publication Date Title
US11025414B2 (en) Key exchange method and apparatus
JP6903006B2 (ja) 次世代セルラーネットワークのためのユーザプレーンセキュリティ
JP4710267B2 (ja) ネットワークシステム、データ中継装置、セッションモニタシステム、およびパケットモニタ中継装置
WO2015180654A1 (zh) 一种保密通信实现方法及装置
WO2017114123A1 (zh) 一种密钥配置方法及密钥管理中心、网元
CN103428221B (zh) 对移动应用的安全登录方法、系统和装置
JP6764753B2 (ja) 制限帯域幅を有するチャネルにおける効率的かつ強秘匿性の対称暗号化のためのシステムおよび方法
JP5785346B1 (ja) リンク層セキュリティー伝送をサポートする交換設備およびデータ処理方法
CN102036230B (zh) 本地路由业务的实现方法、基站及系统
JP2010505284A (ja) 入れ子状のインターネットプロトコルセキュリティトンネルを処理するための方法およびネットワーク装置
US20160006707A1 (en) Data transmission method, apparatus, and system
WO2018076742A1 (zh) 一种数据传输方法、相关设备及系统
CN108833943B (zh) 码流的加密协商方法、装置及会议终端
WO2015180604A1 (zh) 一种保密通信控制、保密通信方法及装置
WO2015131609A1 (zh) 一种实现L2TP over IPsec接入的方法
WO2016180180A1 (zh) 一种语音通话的加密方法及装置
CN100527875C (zh) 实现媒体流安全的方法及通信系统
WO2017215443A1 (zh) 报文传输方法、装置及系统
CN107294968A (zh) 一种音视频数据的监控方法和系统
US10826688B2 (en) Key distribution and receiving method, key management center, first network element, and second network element
WO2017197968A1 (zh) 一种数据传输方法及装置
WO2016070685A1 (zh) 一种实现sip会话传输的方法及系统
JP6456451B1 (ja) 通信装置、通信方法、及びプログラム
CN103986640A (zh) 一种可保障用户通讯内容安全的即时通讯方法及其系统
CN105704681A (zh) 一种对端到端加密呼叫的缜密监听方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16792030

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16792030

Country of ref document: EP

Kind code of ref document: A1