2 ms·
I thought about a similar system but based on cryptography. The telecoms regulators for each country would act as a CA and have their root key capable of signi
by Rjevski 8y ago
I thought about a similar system but based on cryptography.
The telecoms regulators for each country would act as a CA and have their root key capable of signing anything for that particular country code, and phones would have all of them in their trust store (it could be all managed by the GSMA or something).
They would in turn issue certificates to any telecoms company that has number ranges allocated - those certs allow signing of calls for any of the number ranges the cert is for, as well as signing further certs. The telecoms company will in turn issue certificates for their customers for their assigned number only. It could be placed on the SIM card or distributed by email (perfect security isn’t needed here - “good enough” is all that’s required).
When a phone places a call it signs it with its certificate and the current date & time (to avoid replay attacks), and any equipment in the call path can verify the chain of trust all the way back to a trusted CA before relaying the call.
As the user still holds the end certificate, legitimate caller ID spoofing is still possible by them, but not anyone else.