课题基金 / 基金详情

End to End Authentication of Caller ID in Heterogeneous Telephony Systems

End to End Authentication of Caller ID in Heterogeneous Telephony Systems
异构电话系统中呼叫者 ID 的端到端身份验证
批准号:
EP/T014784/1
负责人:
Feng Hao
金额:
$114.81万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2021
资助国家:
英国
项目状态:
未结题
起止时间:
2021 至 --

项目摘要

项目成果

Feng Hao的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Caller ID spoofing is a global unsolved problem in the telecommunication industry. This problem has affected billions of telephone users worldwide as an enabler for widespread fraud and social engineering attacks. It has also seriously disrupted public services that require reliable authentication of the caller (e.g., police or medical emergency calls). According to Ofcom, UK consumers receive 5 billion nuisance calls per annum across all networks in the UK. Caller ID spoofing is a common technique used by fraudsters and scammers to hide the identity and to avoid tracing. The Internet Engineering Task Force (IETF) has formed a special working group to tackle this problem with a proposed solution called STIR/SHAKEN. The STIR/SHAKEN proposal is inspired by the HTTPS web communication and attempts to apply the same approach from web browsers to telephones. However, this proposal has two major drawbacks. First of all, it requires a Public Key infrastructure (PKI), which is expensive to set up and to maintain. Besides the cost and operational issues associated with a PKI, it remains unclear who should act as globally trusted certificate authorities (CAs). Second, STIR/SHAKEN is designed to only work with the SIP system (VoIP), leaving SS7 systems (landline and mobile phones) out of scope. This significantly limits the effectiveness of the proposed solution. We propose to investigate alternative ways to achieve end-to-end authentication of caller IDs for both SIP and SS7 systems without requiring any PKI. Our main idea is to leverage the DTMF signalling in a call-back session as a trusted channel to send a short code to the purported caller, in conjunction with a password authenticated key exchange (PAKE) protocol to perform key exchange over a data channel to establish a shared high-entropy session key which is then used to authenticate the caller ID end-to-end. This proposed solution has been positively reviewed by our industrial partners. However, the feasibility of this proposal still needs to be further confirmed through research, prototyping, and a comprehensive evaluation of performance, security and usability in real-world telecommunication settings, which will be done in close collaboration with our industrial partners.We divide the work into three main stages. The first stage (month 1-18) will focus on designing a caller ID authentication framework without a PKI. This includes the architectural designs (Work Package 1) based on PKI-free key exchange protocols, a one-round PAKE (WP 2) which can fit in the proposed framework with the minimised communication latency, and a user interface (WP 3) which can effectively communicate the caller ID authentication status to the end user. The second stage (month 19-36) will focus on building prototypes, which will cover both the SIP (WP 4.1) and SS7 (WP 4.2) systems. The final stage (months 37-48) will focus on the evaluation of the developed prototypes in terms of security, performance and usability.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3625546
发表时间: 2023
期刊: ACM Transactions on Privacy and Security
影响因子: 2.3
作者: [Wang S]
通讯作者: Wang S
Prudent Practices in Security Standardization
安全标准化的审慎实践
DOI: 10.1109/mcomstd.121.2100005
发表时间: 2021
期刊: IEEE Communications Standards Magazine
影响因子: --
作者: [Hao F]
通讯作者: Hao F
VERICONDOR
维康多
DOI: 10.1145/3488932.3497758
发表时间: 2022
期刊:
影响因子: --
作者: [Harrison L]
通讯作者: Harrison L
DOI: 10.1093/comjnl/bxad039
发表时间: 2023-04
期刊: Comput. J.
影响因子: --
作者: [Liangao Zhang;Haibin Kan;Feiyang Qiu;F. Hao]
通讯作者: Liangao Zhang;Haibin Kan;Feiyang Qiu;F. Hao
8
    Bridging Theory and Practice in Key Exchange Protocols
    • 批准号:
      EP/J011541/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $12.73万
    • 财政年份:
      2012
    • 负责人:
      Feng Hao
    • 依托单位:
    国内基金
    海外基金
    基于ARM Pointer Authentication的操作系统内核数据保护研究
    • 批准号:
      62002317
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      24.0万元
    • 批准年份:
      2020
    • 负责人:
      申文博
    • 依托单位: