End to End Authentication of Caller ID in Heterogeneous Telephony Systems

异构电话系统中呼叫者 ID 的端到端身份验证

基本信息

  • 批准号:
    EP/T014784/1
  • 负责人:
  • 金额:
    $ 114.81万
  • 依托单位:
  • 依托单位国家:
    英国
  • 项目类别:
    Research Grant
  • 财政年份:
    2021
  • 资助国家:
    英国
  • 起止时间:
    2021 至 无数据
  • 项目状态:
    未结题

项目摘要

Caller ID spoofing is a global unsolved problem in the telecommunication industry. This problem has affected billions of telephone users worldwide as an enabler for widespread fraud and social engineering attacks. It has also seriously disrupted public services that require reliable authentication of the caller (e.g., police or medical emergency calls). According to Ofcom, UK consumers receive 5 billion nuisance calls per annum across all networks in the UK. Caller ID spoofing is a common technique used by fraudsters and scammers to hide the identity and to avoid tracing. The Internet Engineering Task Force (IETF) has formed a special working group to tackle this problem with a proposed solution called STIR/SHAKEN. The STIR/SHAKEN proposal is inspired by the HTTPS web communication and attempts to apply the same approach from web browsers to telephones. However, this proposal has two major drawbacks. First of all, it requires a Public Key infrastructure (PKI), which is expensive to set up and to maintain. Besides the cost and operational issues associated with a PKI, it remains unclear who should act as globally trusted certificate authorities (CAs). Second, STIR/SHAKEN is designed to only work with the SIP system (VoIP), leaving SS7 systems (landline and mobile phones) out of scope. This significantly limits the effectiveness of the proposed solution. We propose to investigate alternative ways to achieve end-to-end authentication of caller IDs for both SIP and SS7 systems without requiring any PKI. Our main idea is to leverage the DTMF signalling in a call-back session as a trusted channel to send a short code to the purported caller, in conjunction with a password authenticated key exchange (PAKE) protocol to perform key exchange over a data channel to establish a shared high-entropy session key which is then used to authenticate the caller ID end-to-end. This proposed solution has been positively reviewed by our industrial partners. However, the feasibility of this proposal still needs to be further confirmed through research, prototyping, and a comprehensive evaluation of performance, security and usability in real-world telecommunication settings, which will be done in close collaboration with our industrial partners.We divide the work into three main stages. The first stage (month 1-18) will focus on designing a caller ID authentication framework without a PKI. This includes the architectural designs (Work Package 1) based on PKI-free key exchange protocols, a one-round PAKE (WP 2) which can fit in the proposed framework with the minimised communication latency, and a user interface (WP 3) which can effectively communicate the caller ID authentication status to the end user. The second stage (month 19-36) will focus on building prototypes, which will cover both the SIP (WP 4.1) and SS7 (WP 4.2) systems. The final stage (months 37-48) will focus on the evaluation of the developed prototypes in terms of security, performance and usability.
主叫号码欺骗是电信行业中一个全球性的未解决的问题。这个问题已经影响到全球数十亿电话用户,成为广泛的欺诈和社会工程攻击的推动者。它还严重扰乱了需要对呼叫者进行可靠认证的公共服务(例如,警察或医疗急救电话)。根据Ofcom的数据,英国消费者每年在英国的所有网络上收到50亿个骚扰电话。呼叫者ID欺骗是欺诈者和诈骗者用来隐藏身份和避免追踪的常见技术。互联网工程任务组(IETF)已经成立了一个特别工作组来解决这个问题,提出了一个名为STIR/SHAKEN的解决方案。STIR/SHAKEN提案受到HTTPS网络通信的启发,并试图将相同的方法从网络浏览器应用到电话。然而,这一提议有两个主要缺点。首先,它需要一个公钥基础设施(PKI),这是昂贵的建立和维护。除了与PKI相关的成本和操作问题之外,还不清楚谁应该充当全球可信的证书颁发机构(CA)。其次,STIR/SHAKEN设计为仅与SIP系统(VoIP)一起工作,而将SS 7系统(固定电话和移动的电话)排除在范围之外。这大大限制了所提出的解决方案的有效性。我们建议调查的替代方法来实现端到端的SIP和SS 7系统的来电显示身份验证,而不需要任何PKI。我们的主要思想是利用Docking信令在回叫会话作为一个可信的通道发送一个短代码的声称的调用者,结合密码认证密钥交换(PAKE)协议,以执行密钥交换的数据通道,以建立一个共享的高熵会话密钥,然后用于验证呼叫者ID端到端。这一解决方案得到了我们的工业合作伙伴的积极评价。然而,这一方案的可行性还需要通过研究、原型开发以及在实际电信环境中对性能、安全性和可用性的全面评估来进一步确认,这将与我们的行业合作伙伴密切合作。我们将工作分为三个主要阶段。第一阶段(1-18个月)将侧重于设计一个没有公钥基础设施的来电显示认证框架。这包括基于无PKI密钥交换协议的体系结构设计(工作包1),一个单轮PAKE(WP 2),它可以适应所提出的框架,具有最小的通信延迟,以及一个用户界面(WP 3),它可以有效地将呼叫者ID认证状态传达给最终用户。第二阶段(19-36个月)将专注于构建原型,这将涵盖SIP(WP 4.1)和SS 7(WP 4.2)系统。最后阶段(37-48个月)将侧重于在安全性,性能和可用性方面对开发的原型进行评估。

项目成果

期刊论文数量(9)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Spoofing Against Spoofing: Toward Caller ID Verification in Heterogeneous Telecommunication Systems
反欺骗:异构电信系统中的来电显示验证
Prudent Practices in Security Standardization
安全标准化的审慎实践
VERICONDOR
维康多
  • DOI:
    10.1145/3488932.3497758
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Harrison L
  • 通讯作者:
    Harrison L
A Publicly Verifiable Optimistic Fair Exchange Protocol Using Decentralized CP-ABE
  • DOI:
    10.1093/comjnl/bxad039
  • 发表时间:
    2023-04
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Liangao Zhang;Haibin Kan;Feiyang Qiu;F. Hao
  • 通讯作者:
    Liangao Zhang;Haibin Kan;Feiyang Qiu;F. Hao
Spoofing Against Spoofing: Towards Caller ID Verification In Heterogeneous Telecommunication Systems
欺骗对抗欺骗:异构电信系统中的主叫方 ID 验证
  • DOI:
    10.48550/arxiv.2306.06198
  • 发表时间:
    2023
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Wang S
  • 通讯作者:
    Wang S
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Feng Hao其他文献

Effect of Solidification Pressure on Phase Transformation and Precipitated Phases of 30Cr15Mo1N Ingot
凝固压力对30Cr15Mo1N铸锭相变和析出相的影响
Aqueous solvent-regulated crystallization and interfacial modification in perovskite solar cells with enhanced stability and performance
钙钛矿太阳能电池中水性溶剂调节的结晶和界面改性提高了稳定性和性能
  • DOI:
    10.1016/j.jpowsour.2020.228447
  • 发表时间:
    2020-09
  • 期刊:
  • 影响因子:
    9.2
  • 作者:
    Kejun Liao;Lisha Xie;Yuying Cui;Shurong Wang;Chengbo Li;Aili Wang;Xiaoyu Deng;Yong Xiang;Liming Ding;Feng Hao
  • 通讯作者:
    Feng Hao
Using seismic surveys to investigate sediment distribution and to estimate burial fluxes of OC, N, and P in a canyon reservoir
利用地震勘测调查沉积物分布并估算峡谷水库中 OC、N 和 P 的埋藏通量
  • DOI:
    10.1007/s11631-019-00353-x
  • 发表时间:
    2019-12
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Ningxiao Yu;Yong Qin;Feng Hao;Yunchao Lang;Fushun Wang
  • 通讯作者:
    Fushun Wang
Circumferential Material Flow in the Hydroforming of Overlapping Blanks
重叠毛坯液压成形中的周向材料流动
  • DOI:
    10.3390/met10070864
  • 发表时间:
    2020-06
  • 期刊:
  • 影响因子:
    2.9
  • 作者:
    Han Cong;Feng Hao
  • 通讯作者:
    Feng Hao
High-efficiency couplers for graphene surface plasmon polaritons in mid-infrared region
中红外区石墨烯表面等离子体激元的高效耦合器
  • DOI:
  • 发表时间:
    2020
  • 期刊:
  • 影响因子:
    3.6
  • 作者:
    Ye Longfang;Sui Kehan;Feng Hao
  • 通讯作者:
    Feng Hao

Feng Hao的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Feng Hao', 18)}}的其他基金

Bridging Theory and Practice in Key Exchange Protocols
密钥交换协议的理论与实践的桥梁
  • 批准号:
    EP/J011541/1
  • 财政年份:
    2012
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Research Grant

相似国自然基金

基于ARM Pointer Authentication的操作系统内核数据保护研究
  • 批准号:
    62002317
  • 批准年份:
    2020
  • 资助金额:
    24.0 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

New Frontiers for Anonymous Authentication
匿名身份验证的新领域
  • 批准号:
    DE240100282
  • 财政年份:
    2024
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Discovery Early Career Researcher Award
Physical layer authentication of IoT devices in the 6G era
6G时代物联网设备物理层认证
  • 批准号:
    24K07482
  • 财政年份:
    2024
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Authentication and Authorisation for Research Collaboration Technical Revision to Enhance Effectiveness
研究合作的认证和授权技术修订以提高效率
  • 批准号:
    10095554
  • 财政年份:
    2024
  • 资助金额:
    $ 114.81万
  • 项目类别:
    EU-Funded
ExpandQISE: Track 1: A Quantum Good Network Protocol (QGP) and Implementation for Security-Enhanced Network Authentication
ExpandQISE:轨道 1:量子良好网络协议 (QGP) 和安全增强型网络身份验证的实现
  • 批准号:
    2329053
  • 财政年份:
    2023
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Standard Grant
I-Corps: Liveness detection and integrity authentication of digital audio
I-Corps:数字音频的活性检测和完整性认证
  • 批准号:
    2309443
  • 财政年份:
    2023
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Standard Grant
Multipoint Caller Authentication - An AI based voice biometrics solution for real-time fraud detection and prevention in the call centre
多点呼叫者身份验证 - 基于人工智能的语音生物识别解决方案,用于呼叫中心的实时欺诈检测和预防
  • 批准号:
    10074067
  • 财政年份:
    2023
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Grant for R&D
A study of contactless vein authentication system using 3D images
基于3D图像的非接触式静脉认证系统的研究
  • 批准号:
    23H01644
  • 财政年份:
    2023
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
Nanobody technology: feeding target authentication and mitigation strategies in crop protection.
纳米抗体技术:作物保护中的饲喂目标验证和缓解策略。
  • 批准号:
    2881464
  • 财政年份:
    2023
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Studentship
Tri-fair Biometrics: Realizing a fair biometric authentication system that satisfies the three requirements of biometrics
Tri-fair Biometrics:实现公平的生物识别认证系统,满足生物识别的三个要求
  • 批准号:
    23H03395
  • 财政年份:
    2023
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
FMitF: Track II: Bringing Verification-Aware Languages and Federated Authentication to Enable Secure Computing for Scientific Communities
FMITF:轨道 II:引入验证感知语言和联合身份验证,为科学界提供安全计算
  • 批准号:
    2319190
  • 财政年份:
    2023
  • 资助金额:
    $ 114.81万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了