ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR...

35
ITU Kaleidoscope 2016 ICTs for a Sustainable World TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION Huahong Tu , Adam Doupé, Ziming Zhao, and Gail-Joon Ahn Arizona State University [email protected] Bangkok, Thailand 14-16 November 2016

Transcript of ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR...

Page 1: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

ITU Kaleidoscope 2016ICTs for a Sustainable World

TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING

LINE IDENTIFICATION PRESENTATION

Huahong Tu, Adam Doupé, Ziming Zhao, and Gail-Joon Ahn

Arizona State [email protected]

Bangkok, Thailand14-16 November 2016

Page 2: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 3: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

0

100000

200000

300000

400000

500000

600000

2013 2014 2015

Fraud Complaints by Method of Contact 2013-2015

Phone Email

Data source: FTC Consumer Sentinel Data Book CY2015

Page 4: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

Fraud Complaints by Method of Communication in 2015

Phone Email Web Mail OtherData source: FTC Consumer Sentinel Data Book CY2015

Page 5: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 6: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 7: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 8: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 9: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 10: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 11: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 12: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 13: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

Spoof

Page 14: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

Why Security Indicators Matter

Page 15: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 16: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 17: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 18: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 19: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

Designing the Verification Scheme

Page 20: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 21: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

• Authentication

• Integrity

• Deployability

Design Principles

Page 22: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 23: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

1. Caller ID Verification

2. Authenticated Call Request

Scheme Overview

Page 24: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

• Provide proof of E.164 ownership to a CA

• Obtain a short-term Caller ID Certificate

• Use caller ID to generate Authenticated Call Requests

Caller ID Verification

Page 25: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 26: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

• Assert the originating identity

• Generate an extended IAM with a digital signature using the Caller ID Certificate

• Validate both the IAM signature as well as the signer

Authenticated Call Request

Page 27: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 28: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

• UTC Timestamp (UNIX time)

• X.509 certificate format

• International E.164 format

• Parameter Compatibility Information parameter (Q.764.2.9.5.3.2)

Other Details

Parameter Type Length (octets)

UTC Timestamp Optional Part 4-?

Signature Algorithm Optional Part 1-?

Signature Optional Part 16-?

Caller Identity Certificate Optional Part 32-?

Page 29: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

• Certificate Revocation to guard against stolen identity

– E.g. stolen certificate, cell phone theft, etc.

• Recommend using Certificate Revocation List (CRL) with short-term certificates

– No stalling, OCSP can cause stalling

– Risk containment

– Reduce list size

Security Considerations

Page 30: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

• Presenting the security indicator to the called party

• Use a flag indicator, only if

– local exchange network connection is secured

– identity of the local exchange carrier is authenticated

– the call request header is integrity protected

• Otherwise recommend using full conversion of the extended IAM parameters to allow the called party’s user equipment to perform verification

Local Deployment Considerations

Page 31: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 32: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 33: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION
Page 34: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

Acknowledgement

Page 35: ITU Kaleidoscope 2016 · 2020. 7. 17. · TOWARD AUTHENTICATED CALLER ID TRANSMISSION: THE NEED FOR A STANDARDIZED AUTHENTICATION SCHEME IN Q.731.3 CALLING LINE IDENTIFICATION PRESENTATION

ITU Kaleidoscope 2016ICTs for a Sustainable World

Thank YouHuahong Tu

Arizona State [email protected]

Download paper:

http://huahongtu.me/publications/itu-callerid.pdf

Bangkok, Thailand14-16 November 2016