CN100388659C - Device, system and method for realizing encrypted communication between heterogeneous networks - Google Patents
Device, system and method for realizing encrypted communication between heterogeneous networks Download PDFInfo
- Publication number
- CN100388659C CN100388659C CNB031468233A CN03146823A CN100388659C CN 100388659 C CN100388659 C CN 100388659C CN B031468233 A CNB031468233 A CN B031468233A CN 03146823 A CN03146823 A CN 03146823A CN 100388659 C CN100388659 C CN 100388659C
- Authority
- CN
- China
- Prior art keywords
- module
- communication
- encrypted
- data
- link
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Lifetime
Links
- 238000004891 communication Methods 0.000 title claims abstract description 156
- 238000000034 method Methods 0.000 title claims abstract description 37
- 230000005540 biological transmission Effects 0.000 claims abstract description 50
- 238000005538 encapsulation Methods 0.000 claims abstract description 9
- 230000011664 signaling Effects 0.000 claims description 53
- 238000010295 mobile communication Methods 0.000 claims description 34
- 238000006243 chemical reaction Methods 0.000 claims description 3
- 230000000977 initiatory effect Effects 0.000 claims 2
- 230000006978 adaptation Effects 0.000 description 1
- 239000000969 carrier Substances 0.000 description 1
- 230000001413 cellular effect Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 230000002452 interceptive effect Effects 0.000 description 1
- 238000011084 recovery Methods 0.000 description 1
Images
Landscapes
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
本发明公开了实现加密通信的方法,包括移动终端向固定终端的通信方法,其特征在于:加密移动终端发起加密业务呼叫时,采用业务选项通知基站系统需要使用加密业务,基站通信系统分配相应的资源建立加密通信,在增加了加密业务传输协议的封装后,使用加密业务传输协议处理模块进行业务数据的接收,数据恢复,最后通过调制解调模块发送到加密固定终端。提高了资源的利用率,降低了成本;架构灵活,可以根据相关原理扩展应用到其它类型的异种网络,支持较多类型的业务,可以支持加密业务和非加密业务。
The invention discloses a method for realizing encrypted communication, including a communication method from a mobile terminal to a fixed terminal, and is characterized in that: when an encrypted mobile terminal initiates an encrypted service call, the service option is used to notify the base station system that the encrypted service needs to be used, and the base station communication system allocates the corresponding The resource establishes encrypted communication. After adding the encapsulation of the encrypted service transmission protocol, the encrypted service transmission protocol processing module is used to receive the service data, recover the data, and finally send it to the encrypted fixed terminal through the modem module. The resource utilization rate is improved and the cost is reduced; the structure is flexible, and it can be extended and applied to other types of heterogeneous networks according to relevant principles, and supports more types of services, including encrypted services and non-encrypted services.
Description
技术领域 technical field
本发明涉及通信系统,尤其涉及在移动通信网络和固定通信网络之间实现加密通信装置、系统及方法。The present invention relates to a communication system, in particular to a device, system and method for realizing encrypted communication between a mobile communication network and a fixed communication network.
背景技术 Background technique
加密通信提供一种保证通信内容安全的机制,防止通信内容被非授权用户获知。加密通信日益重要,应用的范围也越来越宽,从特殊用户延伸到普通用户。加密的技术和方法有很多种,在固定通信网的终端之间可以直接通过终端加密、解密实现加密通信。而在移动通信网的终端之间,必须要求网络支持,以建立加密通信链路,通过终端加密实现加密通信,例如在中国专利99802508“加密数据传输方法和应用此方法的一种蜂窝无线电系统”中,提供一种移动通信系统和一种在移动通信系统中对数据传输进行加密的方法。该系统包括在包含一个或者多个无线电载波或者逻辑信道的无线电链路上与其他发送接收机通信的至少一个发送接收机,加密是利用所选的加密方法在载波或者逻辑信道上实现的。Encrypted communication provides a mechanism to ensure the security of communication content and prevent communication content from being known by unauthorized users. Encrypted communication is becoming more and more important, and the scope of application is wider and wider, extending from special users to ordinary users. There are many encryption technologies and methods, and encrypted communication can be realized directly through terminal encryption and decryption between terminals in a fixed communication network. Between the terminals of the mobile communication network, network support must be required to establish an encrypted communication link and realize encrypted communication through terminal encryption, such as in Chinese patent 99802508 "encrypted data transmission method and a cellular radio system using this method" In the present invention, a mobile communication system and a method for encrypting data transmission in the mobile communication system are provided. The system comprises at least one transceiver communicating with other transceivers over a radio link comprising one or more radio carriers or logical channels on which encryption is performed using a selected encryption method.
现有的方法只能够提供同种网络内部的对称的加密业务,不能够灵活的应用于各种网络;对于不同网络(例如固定网络与移动网络之间)的终端,则不能够提供加密通信业务,只能采用非加密业务,加密业务应用的范围比较窄。Existing methods can only provide symmetric encrypted services within the same network, and cannot be flexibly applied to various networks; for terminals on different networks (such as between fixed networks and mobile networks), encrypted communication services cannot be provided , only non-encrypted services can be used, and the application range of encrypted services is relatively narrow.
发明内容 Contents of the invention
本发明要解决的技术任务之一是提供一种加密装置,支持异种网络终端之间的加密通信业务。本发明要解决的另一技术任务是提供一种系统,实现异种网络之间的加密通信业务。本发明还要解决的是提供一种异种网络间的加密通讯方法。One of the technical tasks to be solved by the present invention is to provide an encryption device that supports encrypted communication services between heterogeneous network terminals. Another technical task to be solved by the present invention is to provide a system to realize encrypted communication services between heterogeneous networks. Another object of the present invention is to provide an encrypted communication method between heterogeneous networks.
本发明所述的一种实现异种网络间加密通信的装置,包括信令处理/控制模块、数字调制解调模块、加密业务传输协议处理模块和链路接口模块;所述信令处理/控制模块通过控制接口分别和其它的功能模块连接,提供通信有关信令处理和内部资源管理、分配和控制,通过信令链路接收和发送信令;所述数字调制解调模块,用于建立点到点通信,通过数据总线和加密业务传输协议处理功能模块连接,发送和接收加密的业务数据;所述加密业务传输协议处理模块通过数据总线与所述数字调制解调模块连接,发送和接收加密的业务数据,用于加密业务时处理加密业务传输协议,与移动通信网建立连接;所述链路接口模块提供物理链路接口,对外提供中继链路和信令链路。A device for realizing encrypted communication between heterogeneous networks according to the present invention includes a signaling processing/control module, a digital modulation and demodulation module, an encrypted service transmission protocol processing module, and a link interface module; the signaling processing/control module Connect with other functional modules through the control interface, provide communication-related signaling processing and internal resource management, allocation and control, and receive and send signaling through the signaling link; the digital modulation and demodulation module is used to establish point-to-point point communication, through the data bus and encrypted business transmission protocol processing function module connection, send and receive encrypted business data; the encrypted business transmission protocol processing module is connected with the digital modem module through the data bus, send and receive encrypted The service data is used to process the encrypted service transmission protocol for the encrypted service, and establish a connection with the mobile communication network; the link interface module provides a physical link interface, and provides a relay link and a signaling link to the outside.
本发明提供一种实现异种网络间加密通信的系统,包括移动通信系统和固定通信系统,所述的移动通信系统至少包括基站、支持加密业务的移动台、移动交换中心和基站控制器,所述的固定通信系统至少包括固定交换机和固定终端,其特征在于:所述的系统进一步包括实现异种网络间加密通信的装置;所述的移动通信系统通过陆地移动通信网与所述实现异种网络间加密通信的装置相连接,所述的固定通信系统通过交换电话网与所述实现异种网络间加密通信的装置相连接;所述实现异种网络间加密通信的装置通过在所述移动通信系统与所述固定通信系统之间建立的通信链路,完成所述移动台与所述固定终端之间加密业务数据的透明传递。The present invention provides a system for realizing encrypted communication between heterogeneous networks, including a mobile communication system and a fixed communication system. The mobile communication system at least includes a base station, a mobile station supporting encrypted services, a mobile switching center, and a base station controller. The fixed communication system includes at least a fixed exchange and a fixed terminal, and is characterized in that: the system further includes a device for realizing encrypted communication between heterogeneous networks; The device for communication is connected, and the fixed communication system is connected with the device for realizing encrypted communication between heterogeneous networks through the switched telephone network; the device for realizing encrypted communication between heterogeneous networks is connected by the mobile communication system with the The communication link established between the fixed communication systems completes the transparent transfer of encrypted service data between the mobile station and the fixed terminal.
本发明提供的一种实现加密通信的方法,包括移动终端向固定终端的通信方法,其特征在于:加密移动终端发起加密业务呼叫时,采用业务选项通知基站系统需要使用加密业务,基站通信系统分配相应的资源建立加密通信,在增加了加密业务传输协议的封装后,使用加密业务传输协议处理模块进行业务数据的接收,数据恢复,最后通过调制解调模块发送到加密固定终端。A method for implementing encrypted communication provided by the present invention includes a communication method from a mobile terminal to a fixed terminal, and is characterized in that: when an encrypted mobile terminal initiates an encrypted service call, the service option is used to notify the base station system that the encrypted service needs to be used, and the base station communication system allocates Corresponding resources establish encrypted communication. After adding the encapsulation of the encrypted service transmission protocol, the encrypted service transmission protocol processing module is used to receive the service data, restore the data, and finally send it to the encrypted fixed terminal through the modem module.
本发明还提供一种实现异种网络间数据业务半程加密的装置,其特征在于包括信令处理/控制模块、加密业务传输协议处理模块,链路接口模块以及数字调制解调模块和加密/解密模块;所述信令处理/控制模块通过控制接口分别和其它的功能模块连接,提供通信有关信令处理和内部资源管理、分配和控制,通过信令链路接收和发送信令;所述数字调制解调模块,用于建立点到点通信,通过数据总线与所述加密业务传输协议处理功能模块连接,发送和接收加密的业务数据;所述加密业务传输协议处理模块通过数据总线与所述数字调制解调模块连接,发送和接收加密的业务数据,用于加密业务时处理加密业务传输协议,与移动通信网建立连接;所述加密/解密模块,提供加密通信中的加密和解密功能,与所述加密业务传输协议处理功能模块连接,接收和发送加密的数据;所述链路接口模块提供物理链路接口,对外提供中继链路和信令链路。The present invention also provides a device for realizing half-process encryption of data services between heterogeneous networks, which is characterized in that it includes a signaling processing/control module, an encrypted service transmission protocol processing module, a link interface module, a digital modulation and demodulation module and encryption/decryption module; the signaling processing/control module is respectively connected to other functional modules through the control interface, provides communication-related signaling processing and internal resource management, allocation and control, and receives and sends signaling through the signaling link; the digital The modulation and demodulation module is used to establish point-to-point communication, and is connected to the encrypted service transmission protocol processing function module through a data bus to send and receive encrypted service data; the encrypted service transmission protocol processing module is connected to the said encrypted service transmission protocol processing module through a data bus The digital modem module connects, sends and receives encrypted service data, processes the encrypted service transmission protocol when used for encrypted services, and establishes a connection with the mobile communication network; the encryption/decryption module provides encryption and decryption functions in encrypted communication, It is connected with the encrypted service transmission protocol processing function module to receive and send encrypted data; the link interface module provides a physical link interface and provides a relay link and a signaling link to the outside.
本发明还提供一种实现异种网络间数据业务半程加密通信的系统,包括移动通信系统和固定通信系统,所述的移动通信系统至少包括基站、支持加密业务的移动台、移动交换中心和基站控制器,所述的固定通信系统至少包括固定交换机和固定终端,其特征在于:所述的系统进一步包括实现异种网络间数据业务半程加密通信的装置;所述的移动通信系统通过陆地移动通信网与所述实现异种网络间数据业务半程加密通信的装置相连接,所述的固定通信系统通过交换电话网与所述实现异种网络间数据业务半程加密通信的装置相连接;所述实现异种网络间数据业务半程加密通信的装置通过在所述移动通信系统与所述固定通信系统之间建立的通信链路,完成所述移动台与所述固定终端之间数据业务半程加密的传递。The present invention also provides a system for realizing half-way encrypted communication of data services between heterogeneous networks, including a mobile communication system and a fixed communication system. The mobile communication system at least includes a base station, a mobile station supporting encrypted services, a mobile switching center, and a base station The controller, the fixed communication system includes at least a fixed exchange and a fixed terminal, characterized in that: the system further includes a device for realizing half-pass encrypted communication of data services between heterogeneous networks; the mobile communication system communicates via land mobile The network is connected with the device for realizing half-time encrypted communication of data services between heterogeneous networks, and the described fixed communication system is connected with the device for realizing half-process encrypted communication of data services between heterogeneous networks through the switched telephone network; The device for half-pass encrypted communication of data services between heterogeneous networks completes half-pass encryption of data services between the mobile station and the fixed terminal through the communication link established between the mobile communication system and the fixed communication system transfer.
本发明还提供一种实现异种网络间数据业务半程加密通信的方法,其特征在于:首先从所述加密移动终端传来的业务数据经过基站的传输,增加了加密业务传输协议的封装,使用加密业务传输协议处理模块进行业务数据的接收,然后到加密/解密模块进行解密,最后通过调制解调器模块发送到普通终端。The present invention also provides a method for realizing half-way encrypted communication of data services between heterogeneous networks. The encrypted service transmission protocol processing module receives the service data, and then goes to the encryption/decryption module for decryption, and finally sends it to the common terminal through the modem module.
本发明还提供一种实现异种网络间话音业务半程加密的装置,其特征在于包括信令处理/控制模块、加密业务传输协议处理模块,链路接口模块以及数字调制解调模块加密/解密模块以及声码器模块; 所述信令处理/控制模块通过控制接口分别和其它的功能模块连接,提供通信有关信令处理和内部资源管理、分配和控制,通过信令链路接收和发送信令;所述数字调制解调模块,用于建立点到点通信,通过数据总线与所述加密业务传输协议处理功能模块连接,发送和接收加密的业务数据;所述加密业务传输协议处理模块通过数据总线与所述数字调制解调模块连接,发送和接收加密的业务数据,用于加密业务时处理加密业务传输协议,与移动通信网建立连接;所述加密/解密模块,提供加密通信中的加密和解密功能,与所述加密业务传输协议处理功能模块连接,接收和发送加密的数据;所述声码器模块,提供固定通信网与移动通信网之间语音编码的转换,与所述加密/解密模块通过通信接口进行加密/解密语音包的交互传送;所述链路接口模块提供物理链路接口,对外提供中继链路和信令链路。The present invention also provides a device for realizing half-time encryption of voice services between heterogeneous networks, which is characterized in that it includes a signaling processing/control module, an encrypted service transmission protocol processing module, a link interface module, and a digital modulation and demodulation module encryption/decryption module and a vocoder module; the signaling processing/control module is respectively connected to other functional modules through a control interface, provides communication-related signaling processing and internal resource management, allocation and control, and receives and sends signaling through a signaling link The digital modulation and demodulation module is used to establish point-to-point communication, and is connected to the encrypted service transmission protocol processing function module through a data bus to send and receive encrypted service data; the encrypted service transmission protocol processing module passes the data The bus is connected to the digital modulation and demodulation module to send and receive encrypted service data, and to process the encrypted service transmission protocol when used for encrypted services, and to establish a connection with the mobile communication network; the encryption/decryption module provides encryption in encrypted communication. and decryption function, connected with the encryption service transmission protocol processing function module, receiving and sending encrypted data; the vocoder module, providing voice coding conversion between the fixed communication network and the mobile communication network, and the encryption/ The decryption module performs interactive transmission of encrypted/decrypted voice packets through the communication interface; the link interface module provides a physical link interface, and provides a relay link and a signaling link to the outside.
本发明还提供一种实现异种网络间话音业务半程加密通信的方法,其特征在于:加密移动终端发起加密业务呼叫时,采用业务选项通知基站系统需要使用加密业务,基站通信系统分配相应的资源建立加密通信,在增加了加密业务传输协议的封装后,通过所述加密业务传输协议处理模块进行业务数据的接收,然后由所述加密/解密模块进行解密,之后所述声码器模块进行语音信号的解码,最后通过所述交换机发送到所述固定终端。The present invention also provides a method for realizing half-time encrypted communication of voice services between heterogeneous networks, which is characterized in that: when an encrypted mobile terminal initiates an encrypted service call, the service option is used to notify the base station system that the encrypted service needs to be used, and the base station communication system allocates corresponding resources Establish encrypted communication, after adding the encapsulation of the encrypted service transmission protocol, the service data is received by the encrypted service transmission protocol processing module, and then decrypted by the encryption/decryption module, and then the vocoder module performs voice The decoding of the signal is finally sent to the fixed terminal through the switch.
与现有技术相比,本发明的装置、系统和方法,提高了资源的利用率,降低了成本;架构灵活,可以根据相关原理扩展应用到其它类型的异种网络,支持较多类型的业务,可以支持加密业务和非加密业务。Compared with the prior art, the device, system and method of the present invention improve resource utilization and reduce costs; the structure is flexible, and can be extended and applied to other types of heterogeneous networks according to relevant principles, supporting more types of services, It can support encrypted business and non-encrypted business.
附图说明 Description of drawings
图1是本发明提出的实现异种网络间加密通信的装置的一个实施例。Fig. 1 is an embodiment of the device for implementing encrypted communication between heterogeneous networks proposed by the present invention.
图2是本发明提出实现异种网络间加密通信的系统的一个实施例。Fig. 2 is an embodiment of the system proposed by the present invention to realize encrypted communication between heterogeneous networks.
图3是图2所述系统中的移动通信系统实现加密业务时的协议结构。Fig. 3 is a protocol structure when the mobile communication system in the system shown in Fig. 2 implements encryption services.
图4是支持加密业务的移动终端呼叫支持加密业务的固定终端建立全程加密通信的流程;Fig. 4 is the flow that the mobile terminal supporting encryption service calls the fixed terminal supporting encryption service to establish whole-process encryption communication;
图5是支持加密业务的固定终端呼叫支持加密业务的移动终端建立全程加密通信的流程;Fig. 5 is the flow that the fixed terminal that supports encrypted service calls the mobile terminal that supports encrypted service and establishes whole-process encrypted communication;
具体实施方式 Detailed ways
下面结合附图对技术方案的实施作进一步的详细描述:Below in conjunction with accompanying drawing, the implementation of technical scheme is described in further detail:
如图1所示,是实现异种网络间加密通信的装置的一个实施例,该实施例可用于完成异种网络间的话音业务加密,该装置具体包括:信令处理和控制功能模块,提供通信有关信令处理和内部资源管理、分配和控制,采用控制接口分别和其它的功能模块连接,对其它模块进行管理、控制;同时,提供时分复用(TDM)接口和电路交换功能模块连接,通过信令链路接收和发送信令。加密功能模块,提供加密通信中的加密和解密功能;和声码器功能模块存在通信接口,把解密的语音包发送给声码器,并接收声码器的语音包进行加密;另外,和加密业务传输协议处理功能模块连接,接收和发送加密的数据。声码器功能模块,提供固定通信网与移动通信网之间语音编码的转换;同时,通过时分复用(TDM)接口和电路交换功能模块连接,接收和发送固定通信网的语音数据。数字调制解调功能模块,用于与加密固定终端建立点到点通信;通过时分复用(TDM)接口和电路交换功能模块连接,接收和发送与加密固定终端之间的业务数据;通过数据总线和加密业务传输协议处理功能模块连接,发送和接收加密的业务数据。加密业务传输协议处理功能模块,用于加密业务时处理加密业务传输协议,与移动通信网建立连接;并通过时分复用(TDM)接口和电路交换功能模块连接,向移动通信网发送和接收业务数据;通过数据总线和数字调制解调功能模块连接,发送和接收加密的业务数据。链路接口模块提供物理链路接口,对外提供中继链路和信令链路,并通过时分复用(TDM)接口和电路交换功能模块连接,使内部的功能单元与外部链路连接。As shown in Figure 1, it is an embodiment of a device for implementing encrypted communication between heterogeneous networks. This embodiment can be used to complete encryption of voice services between heterogeneous networks. The device specifically includes: signaling processing and control function modules, providing communication-related Signaling processing and internal resource management, distribution and control, use the control interface to connect with other functional modules to manage and control other modules; at the same time, provide time division multiplexing (TDM) Make the link receive and send signaling. The encryption function module provides encryption and decryption functions in encrypted communication; there is a communication interface with the vocoder function module, and the decrypted voice packet is sent to the vocoder, and the voice packet received by the vocoder is encrypted; The service transmission protocol processing function module connects, receives and sends encrypted data. The vocoder function module provides voice coding conversion between the fixed communication network and the mobile communication network; at the same time, it connects with the circuit switching function module through a time division multiplexing (TDM) interface to receive and send voice data of the fixed communication network. The digital modulation and demodulation function module is used to establish point-to-point communication with the encrypted fixed terminal; it is connected with the circuit switching function module through a time division multiplexing (TDM) interface, and receives and sends business data between the encrypted fixed terminal; through the data bus It is connected with the encrypted service transmission protocol processing function module to send and receive encrypted service data. The encryption service transmission protocol processing function module is used to process the encryption service transmission protocol when encrypting services, and establish a connection with the mobile communication network; and connect with the circuit switching function module through a time division multiplexing (TDM) interface, and send and receive services to the mobile communication network Data: through the data bus and digital modem function module connection, send and receive encrypted business data. The link interface module provides a physical link interface, provides a relay link and a signaling link externally, and is connected to a circuit switching function module through a time division multiplexing (TDM) interface, so that internal functional units are connected to external links.
实现加密通信的装置可以采用移动关口局增加部分功能单元软件升级而实现,其中移动关口局包括信令处理和控制功能模块、交换功能模块和链路接口模块,外部可以独立地提供声码器功能模块、数字调制解调功能模块、加密业务传输协议处理功能模块和加密解密功能模块。移动关口局通过控制接口来控制、管理这些功能模块,这些功能模块通过和移动关口局之间的数据接口(可以是时分复用接口或者其它类型的串行或/和并行接口)进行业务数据通信。The device for realizing encrypted communication can be implemented by adding some functional unit software upgrades in the mobile gateway office, in which the mobile gateway office includes signaling processing and control function modules, switching function modules and link interface modules, and the external can independently provide the vocoder function Module, digital modulation and demodulation function module, encrypted service transmission protocol processing function module and encryption and decryption function module. The mobile gateway office controls and manages these functional modules through the control interface, and these functional modules communicate with the data interface (which can be a time division multiplexing interface or other types of serial or/and parallel interfaces) with the mobile gateway office. .
能够支持移动通信网络和固定通信网络之间加密通信业务的系统见图2。包括支持加密业务的移动终端(简称加密移动终端);移动通信系统,包括基站、基站控制器和移动交换中心;实现加密通信的装置;固定通信网中的固定终端,包括不支持加密业务的普通终端和支持加密业务的固定终端(简称加密固定终端)。如果支持对私有数据网的加密访问,可以增加加密接入服务器或者普通接入服务器。A system capable of supporting encrypted communication services between a mobile communication network and a fixed communication network is shown in Figure 2. Including mobile terminals that support encrypted services (referred to as encrypted mobile terminals); mobile communication systems, including base stations, base station controllers, and mobile switching centers; devices that implement encrypted communications; fixed terminals in fixed communication networks, including ordinary Terminals and fixed terminals supporting encrypted services (referred to as encrypted fixed terminals). If encrypted access to the private data network is supported, an encrypted access server or a common access server may be added.
加密接入服务器可以支持与加密移动终端之间点对点的加密,是增加了加密/解密模块的普通接入服务器,可以实现加密移动终端到加密接入服务器全程的加密通信。使用普通接入服务器只可以实现半程加密通信,也就是在在加密移动终端到实现加密通信的装置之间建立加密通信,普通接入服务器和实现加密通信的装置之间建立非加密的通信。The encryption access server can support point-to-point encryption with the encryption mobile terminal. It is a common access server with an encryption/decryption module added, which can realize the encrypted communication from the encryption mobile terminal to the encryption access server. Using the common access server can only realize half-pass encrypted communication, that is, establish encrypted communication between the encrypted mobile terminal and the device for realizing encrypted communication, and establish non-encrypted communication between the common access server and the device for realizing encrypted communication.
移动通信系统中加密语音和数据业务采用的协议结构如图3。基站系统要支持相应的协议。加密业务采用无线链路协议(IS-707A中定义,Radio LinkProtocol)传输经过加密的语音和数据,加密语音业务和加密数据业务分别采用了透明无线链路协议和非透明无线链路协议;空中接口采用标准的无线协议;基站系统采用加密业务传输协议,例如互联系统链路协议(IS-728中定义,Intersystem Link Protocol),实现空中业务速率数据与64kbps速率的地面链路之间的速率适配,并采用64kbps速率的地面链路作为传输的物理链路与其他系统建立连接。这样,上层的业务可以实现透明的传输。The protocol structure adopted by the encrypted voice and data services in the mobile communication system is shown in Figure 3. The base station system must support corresponding protocols. The encrypted service adopts the radio link protocol (defined in IS-707A, Radio Link Protocol) to transmit encrypted voice and data, and the encrypted voice service and encrypted data service respectively adopt the transparent wireless link protocol and the non-transparent wireless link protocol; the air interface Standard wireless protocols are adopted; the base station system adopts encrypted service transmission protocols, such as Intersystem Link Protocol (defined in IS-728, Intersystem Link Protocol), to realize rate adaptation between air service rate data and 64kbps ground link , and use the 64kbps ground link as the physical link for transmission to establish connections with other systems. In this way, services on the upper layer can be transmitted transparently.
另外,加密业务采用特定的业务选项,加密移动终端发起加密业务呼叫时,采用业务选项通知基站系统需要使用加密业务,基站通信系统分配相应的资源建立加密通信。基站系统并且可以把业务选项等相关信息传递给移动交换中心,使交换中心清楚需要建立加密通信,交换中心负责建立通信的链路,透明传递加密业务的数据。In addition, the encrypted service adopts a specific service option. When an encrypted mobile terminal initiates an encrypted service call, it uses the service option to notify the base station system that the encrypted service needs to be used, and the base station communication system allocates corresponding resources to establish encrypted communication. The base station system can also transmit relevant information such as service options to the mobile switching center, so that the switching center knows that encrypted communication needs to be established, and the switching center is responsible for establishing a communication link and transparently transmitting encrypted service data.
普通终端(接入服务器)和实现加密通信的装置建立的半程加密通信需要根据业务类型选择参与通信的模块。语音业务需要声码器模块、加密业务传输协议处理模块和加密/解密模块;首先从加密移动终端来的语音经过基站的传输,增加了加密业务传输协议的封装,使用加密业务传输协议处理模块进行业务数据的接收,然后到加密/解密模块进行解密,之后声码器模块进行语音的解码,最后通过交换机发送到普通终端。对于普通终端语音的处理过程是一个逆过程,声码器接收后进行语音的编码,之后到加密/解密模块进行加密,最后使用加密业务传输协议处理模块进行封装,发送到基站系统。数据业务需要调制解调器部分和普通终端(接入服务器)的调制解调器之间建立相应的通信,例如传真、异步数据等。数据业务需要加密业务传输协议处理模块、调制解调器模块和加密/解密模块。首先从加密移动终端来的业务数据经过基站的传输,增加了加密业务传输协议的封装,使用加密业务传输协议处理模块进行业务数据的接收,然后到加密/解密模块进行解密,最后通过调制解调器模块发送到普通终端(接入服务器)。对于普通终端(接入服务器)发送到加密移动终端的数据处理过程是一个逆过程,调制解调器模块接收数据,然后加密/解密模块进行加密,最后使用加密业务传输协议处理模块进行封装,发送到基站系统。The half-pass encrypted communication established between the ordinary terminal (access server) and the device for implementing encrypted communication needs to select the modules involved in the communication according to the business type. Voice services require a vocoder module, an encrypted service transmission protocol processing module, and an encryption/decryption module; firstly, the voice from the encrypted mobile terminal is transmitted through the base station, and the encapsulation of the encrypted service transmission protocol is added, and the encrypted service transmission protocol processing module is used for processing. The service data is received, and then goes to the encryption/decryption module for decryption, and then the voice coder module decodes the voice, and finally sends it to the ordinary terminal through the switch. The voice processing process for ordinary terminals is a reverse process. The vocoder encodes the voice after receiving it, then encrypts it in the encryption/decryption module, and finally uses the encryption service transmission protocol processing module to encapsulate it and send it to the base station system. The data service needs to establish corresponding communication between the modem part and the modem of the common terminal (access server), such as facsimile, asynchronous data and so on. The data service requires an encryption service transmission protocol processing module, a modem module and an encryption/decryption module. First, the business data from the encrypted mobile terminal is transmitted through the base station, the encapsulation of the encrypted business transmission protocol is added, the business data is received by the encrypted business transmission protocol processing module, and then decrypted by the encryption/decryption module, and finally sent through the modem module to a common terminal (access server). For the data processing process sent by the ordinary terminal (access server) to the encrypted mobile terminal is a reverse process, the modem module receives the data, then the encryption/decryption module encrypts, and finally uses the encrypted service transmission protocol processing module to encapsulate and send to the base station system .
同样,普通终端和非加密移动终端之间可以建立不加密的普通通信。Likewise, unencrypted ordinary communication can be established between ordinary terminals and non-encrypted mobile terminals.
加密固定终端(加密接入服务器)和加密移动终端可以建立全程加密通信。建立的全程加密通信需要加密业务传输协议处理模块和调制解调模块;首先从加密移动终端来的业务经过基站的传输,增加了加密业务传输协议的封装,使用加密业务传输协议处理模块进行业务数据的接收,数据恢复,最后通过调制解调模块发送到加密固定终端(加密接入服务器)。对于加密固定终端(加密接入服务器)业务数据的处理过程是一个逆过程,调制解调模块进行接收,最后使用加密业务传输协议处理模块进行封装,发送到基站系统。数据业务需要调制解调器部分和加密固定终端(加密接入服务器)的调制解调器之间建立相应的通信,例如传真、异步数据等。An encrypted fixed terminal (encrypted access server) and an encrypted mobile terminal can establish whole-process encrypted communication. The established whole-process encrypted communication requires an encrypted service transmission protocol processing module and a modem module; firstly, the business from the encrypted mobile terminal is transmitted through the base station, and the encapsulation of the encrypted service transmission protocol is added, and the encrypted service transmission protocol processing module is used to process the business data. The data is received, recovered, and finally sent to the encrypted fixed terminal (encrypted access server) through the modem module. The processing process for encrypted fixed terminal (encrypted access server) service data is a reverse process, the modem module receives it, and finally uses the encrypted service transmission protocol processing module to package it and send it to the base station system. The data service needs to establish corresponding communication between the modem part and the modem of the encrypted fixed terminal (encrypted access server), such as fax, asynchronous data, etc.
如果是加密语音通信,在加密固定终端内,将接收到加密语音数据进行解密,然后进行语音解码,恢复为语音回放。如果是加密传真,加密固定终端内,将接收到加密数据进行解密,恢复出原始数据。如果是加密异步数据业务,将接收到加密数据进行解密,然后交上层协议处理。If it is an encrypted voice communication, in the encrypted fixed terminal, the received encrypted voice data will be decrypted, and then the voice will be decoded to resume voice playback. If it is an encrypted fax, the encrypted fixed terminal will decrypt the received encrypted data to restore the original data. If it is an encrypted asynchronous data service, the encrypted data will be received for decryption, and then handed over to the upper layer protocol for processing.
在加密接入服务器内部,情况与加密固定终端的加密异步数据业务类似,将接收到加密数据进行解密,然后交上层协议处理,进行数据包的恢复、路由等。Inside the encrypted access server, the situation is similar to the encrypted asynchronous data service of encrypted fixed terminals. The received encrypted data is decrypted, and then handed over to the upper layer protocol for processing, data packet recovery, routing, etc.
图4是支持加密业务的移动终端呼叫支持加密业务的固定终端建立全程加密通信的流程。首先,二类终端设备向移动终端发送AT命令,申请建立通信。移动终端向移动基站系统发送业务申请,其中的业务选项参数指示了业务类型。此时,移动通信系统可以进行有关的接入鉴权,确定终端是否合法加密业务用户,确定是否接入。移动终端接入成功,移动基站系统为此次呼叫分配资源,包括无线资源、无线协议处理资源、无线链路协议处理资源和加密业务传输协议处理资源。基站系统将业务类型、被呼号码等参数送给移动交换中心和实现加密通信的装置。实现加密通信的装置根据业务类型和被呼号码等参数确定是加密业务,与固定终端建立连接。如果业务与终端类型不匹配,例如业务为加密语音业务,而终端为数据终端;或者为加密数据业务,而终端为语音终端,则呼叫无法建立,释放呼叫。并根据业务类型分配相应的资源。实现加密通信的装置的调制解调单元与终端的调制解调单元建立连接,呼叫建立。释放时,如果移动终端发起释放,释放所有的链路资源。同时,固定终端也可以发起释放。FIG. 4 is a flowchart of a mobile terminal supporting encryption services calling a fixed terminal supporting encryption services to establish full encrypted communication. First, the second-class terminal device sends an AT command to the mobile terminal to apply for establishing communication. The mobile terminal sends a service application to the mobile base station system, in which the service option parameter indicates the service type. At this time, the mobile communication system can perform related access authentication to determine whether the terminal is a legal encryption service user and whether to access. After the mobile terminal accesses successfully, the mobile base station system allocates resources for this call, including radio resources, radio protocol processing resources, radio link protocol processing resources, and encrypted service transmission protocol processing resources. The base station system sends parameters such as service type and called number to the mobile switching center and the device for implementing encrypted communication. The device for implementing encrypted communication determines the encrypted service according to parameters such as the service type and the called number, and establishes a connection with the fixed terminal. If the service does not match the type of the terminal, for example, the service is an encrypted voice service and the terminal is a data terminal; or the service is encrypted data and the terminal is a voice terminal, the call cannot be established and the call is released. And allocate corresponding resources according to the business type. The modem unit of the device for implementing encrypted communication establishes a connection with the modem unit of the terminal, and the call is established. When releasing, if the mobile terminal initiates the release, all link resources are released. At the same time, the fixed terminal can also initiate release.
图5是支持加密业务的固定终端呼叫支持加密业务的移动终端建立全程加密通信的流程。首先,固定终端发起呼叫,固定交换机建立相应的连接,并把主叫号码、被叫号码等参数携带给实现加密通信的装置。实现加密通信的装置根据主叫号码、被叫号码等参数判断业务类型,分配相应的资源,和固定终端建立连接;同时把有关参数送给移动交换中心与移动基站系统。如果业务与终端类型不匹配,例如业务为加密业务,而终端为普通终端,释放呼叫。移动交换中心与移动基站系统根据业务类型建立与移动终端的连接,此时,移动通信系统可以进行有关的接入鉴权,确定终端是否合法加密业务用户,确定是否接入。移动终端接入成功,移动基站系统为此次呼叫分配资源,包括无线资源、无线协议处理资源、无线链路协议处理资源和加密业务传输协议处理资源。呼叫建立。释放时,如果固定终端发起释放,释放所有的链路资源。同时,移动终端也可以发起释放。对于普通固定终端,建立通信的步骤与上述类似,只是与实现加密通信的装置之间的通信类型不同,需要根据业务类型建立不同的通信;并且实现加密通信的装置分配的处理资源不同。FIG. 5 is a flowchart of a fixed terminal supporting encrypted services calling a mobile terminal supporting encrypted services to establish full encrypted communication. First, the fixed terminal initiates a call, and the fixed exchange establishes a corresponding connection, and carries parameters such as calling number and called number to the device for implementing encrypted communication. The device for realizing encrypted communication judges the service type according to parameters such as calling number and called number, allocates corresponding resources, and establishes a connection with a fixed terminal; at the same time, it sends relevant parameters to the mobile switching center and mobile base station system. If the service does not match the terminal type, for example, the service is an encrypted service and the terminal is a common terminal, release the call. The mobile switching center and the mobile base station system establish a connection with the mobile terminal according to the type of service. At this time, the mobile communication system can perform relevant access authentication to determine whether the terminal is a legal encryption service user and whether to access. After the mobile terminal accesses successfully, the mobile base station system allocates resources for this call, including radio resources, radio protocol processing resources, radio link protocol processing resources, and encrypted service transmission protocol processing resources. The call is established. When releasing, if the fixed terminal initiates the release, all link resources are released. At the same time, the mobile terminal can also initiate release. For ordinary fixed terminals, the steps for establishing communication are similar to the above, except that the communication type between devices implementing encrypted communication is different, and different communication needs to be established according to the business type; and the processing resources allocated by devices implementing encrypted communication are different.
Claims (10)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CNB031468233A CN100388659C (en) | 2003-09-10 | 2003-09-10 | Device, system and method for realizing encrypted communication between heterogeneous networks |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CNB031468233A CN100388659C (en) | 2003-09-10 | 2003-09-10 | Device, system and method for realizing encrypted communication between heterogeneous networks |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN1523805A CN1523805A (en) | 2004-08-25 |
| CN100388659C true CN100388659C (en) | 2008-05-14 |
Family
ID=34286638
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CNB031468233A Expired - Lifetime CN100388659C (en) | 2003-09-10 | 2003-09-10 | Device, system and method for realizing encrypted communication between heterogeneous networks |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN100388659C (en) |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN100442881C (en) * | 2005-03-31 | 2008-12-10 | 华为技术有限公司 | Method for Realizing Information Encrypted Transmission in Wireless Communication System |
| CN100352302C (en) * | 2005-06-28 | 2007-11-28 | 熊猫电子集团有限公司 | Mobile terminal having double call functions of public call and privacy call |
| US7912009B2 (en) * | 2006-02-03 | 2011-03-22 | Motorola Mobility, Inc. | Method and apparatus for supporting mobility in inter-technology networks |
| US7873988B1 (en) * | 2006-09-06 | 2011-01-18 | Qurio Holdings, Inc. | System and method for rights propagation and license management in conjunction with distribution of digital content in a social network |
| CN101626540B (en) * | 2008-07-11 | 2012-04-04 | 深圳市沃其丰科技股份有限公司 | Heterogeneous mobile terminal multi-point access system |
| CN105025475B (en) * | 2015-07-28 | 2019-02-26 | 东南大学常州研究院 | Mobile secrecy terminal realizing method towards android system |
| CN105792193B (en) * | 2016-02-26 | 2019-02-26 | 东南大学常州研究院 | End-to-end encryption method for mobile terminal voice based on iOS operating system |
Citations (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1142307A (en) * | 1994-03-03 | 1997-02-05 | 艾利森公司 | Secure radio personal communications system and method |
| CN1198278A (en) * | 1995-09-27 | 1998-11-04 | 艾利森电话股份有限公司 | method of encrypting information |
| CN1236517A (en) * | 1996-09-09 | 1999-11-24 | 艾利森电话股份有限公司 | Method and arrangement for encrypting radio traffic in a telecommunications network |
| WO2000059149A1 (en) * | 1999-03-26 | 2000-10-05 | Motorola Inc. | Secure wireless electronic-commerce system with digital product certificates and digital license certificates |
| CN1282498A (en) * | 1997-12-18 | 2001-01-31 | 西门子公司 | Method and communications system for ciphering information for radio transmission and for authenticating subscribers |
| WO2001024436A2 (en) * | 1999-09-30 | 2001-04-05 | Qualcomm Incorporated | Method and apparatus for encrypting transmissions in a communication system |
| CN1291396A (en) * | 1998-12-21 | 2001-04-11 | 松下电器产业株式会社 | Communication system and communication method |
| CN1073330C (en) * | 1994-11-24 | 2001-10-17 | 日本电气株式会社 | mobile communication system |
| CN1112082C (en) * | 1998-01-30 | 2003-06-18 | 艾利森电话股份有限公司 | How to establish an encrypted connection |
-
2003
- 2003-09-10 CN CNB031468233A patent/CN100388659C/en not_active Expired - Lifetime
Patent Citations (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1142307A (en) * | 1994-03-03 | 1997-02-05 | 艾利森公司 | Secure radio personal communications system and method |
| CN1073330C (en) * | 1994-11-24 | 2001-10-17 | 日本电气株式会社 | mobile communication system |
| CN1198278A (en) * | 1995-09-27 | 1998-11-04 | 艾利森电话股份有限公司 | method of encrypting information |
| CN1236517A (en) * | 1996-09-09 | 1999-11-24 | 艾利森电话股份有限公司 | Method and arrangement for encrypting radio traffic in a telecommunications network |
| CN1282498A (en) * | 1997-12-18 | 2001-01-31 | 西门子公司 | Method and communications system for ciphering information for radio transmission and for authenticating subscribers |
| CN1112082C (en) * | 1998-01-30 | 2003-06-18 | 艾利森电话股份有限公司 | How to establish an encrypted connection |
| CN1291396A (en) * | 1998-12-21 | 2001-04-11 | 松下电器产业株式会社 | Communication system and communication method |
| WO2000059149A1 (en) * | 1999-03-26 | 2000-10-05 | Motorola Inc. | Secure wireless electronic-commerce system with digital product certificates and digital license certificates |
| WO2001024436A2 (en) * | 1999-09-30 | 2001-04-05 | Qualcomm Incorporated | Method and apparatus for encrypting transmissions in a communication system |
Also Published As
| Publication number | Publication date |
|---|---|
| CN1523805A (en) | 2004-08-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| AU750597B2 (en) | Method of ciphering data transmission and a cellular radio system employing the method | |
| RU2172077C2 (en) | Radio communication system using radio frequency signal modulated under condition of multiple access with code division of channels jointly with network communication protocol a-interface , standard gsm | |
| CA2044435C (en) | Mobile communications | |
| RU98113934A (en) | A RADIO COMMUNICATION SYSTEM USING A RADIO FREQUENCY SIGNAL MODULATED IN MULTIPLE ACCESS MODE WITH CODE DIVISION OF CHANNELS, IN TOGETHER WITH THE A-INTERFACE GSM COMMUNICATION PROTOCOL OF A-INTERFACE | |
| US7821990B2 (en) | Method of transmitting service information, and radio system | |
| JP2009508416A (en) | Wireless access method, apparatus and system | |
| CN100466805C (en) | A method of end-to-end encrypted voice communication | |
| CN100388659C (en) | Device, system and method for realizing encrypted communication between heterogeneous networks | |
| CN100442881C (en) | Method for Realizing Information Encrypted Transmission in Wireless Communication System | |
| CN100454798C (en) | CDMA system and method for implementing dynamic distribution of cipher key | |
| CN101175299B (en) | Apparatus and method for controlling mobile terminal access in UMA access network | |
| HK1143018B (en) | Method of ciphering data transmission and a cellular radio system employing the method | |
| HK1070527B (en) | Wireless telecommunications system utilizing cdma radio frequency signal modulation in conjunction with the gsm a-interface telecommunications network protocol | |
| HK1070528B (en) | Wireless telecommunications system utilizing cdma radio frequency signal modulation in conjunction with the gsm a-interface telecommunications network protocol | |
| CA2475870A1 (en) | Method and apparatus for providing a private communication system in a public switched telephone network | |
| HK1070529B (en) | Wireless telecommunications system utilizing cdma radio frequency signal modulation in conjunction with the gsm a-interface telecommunications network protocol |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| C14 | Grant of patent or utility model | ||
| GR01 | Patent grant | ||
| CX01 | Expiry of patent term |
Granted publication date: 20080514 |
|
| CX01 | Expiry of patent term |