Skip to Main Content (Press Enter)

Logo UNIRC
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Attività
  • Competenze

UNI-FIND
Logo UNIRC

|

UNI-FIND

unirc.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Attività
  • Competenze
  1. Pubblicazioni

CallTrust: A federated system for call authentication in telephony networks

Articolo
Data di Pubblicazione:
2026
Citazione:
CallTrust: A federated system for call authentication in telephony networks / Buccafurri, F., De Angelis, V., Lazzaro, S., Licciardi, C.. - In: JOURNAL OF INFORMATION SECURITY AND APPLICATIONS. - ISSN 2214-2134. - 97:(2026). [10.1016/j.jisa.2025.104365]
Abstract:
Voice phishing (vishing) remains a critical security threat in telephone communications, where users cannot reliably authenticate calling parties. Despite technical efforts like STIR/SHAKEN, traditional telephony still lacks application-layer mechanisms to detect spoofed or hijacked calls. In this paper, we present CallTrust, a novel, deployable, and infrastructure-agnostic solution that enables real-time verification of incoming and outgoing calls between users and Certified Services, i.e., trusted entities publicly certified to own specific phone numbers. Our protocol operates entirely at the application layer and leverages time-slotted, privacy-preserving credentials published by Certified Services to detect spoofed or hijacked calls. We detail the protocol design and show that it satisfies the intended security properties. To demonstrate the practical relevance of our approach, we propose a federated design that enables cross-realm (i.e., cross-border) adoption. As a concrete example, we apply it to the European eIDAS framework by extending Qualified Website Authentication Certificates (QWACs) to support the binding of telephone numbers to legally recognized entities. Through a mobile-based proof-of-concept implementation, we show that call authentication can be completed in under two seconds, thus providing users with timely warnings before engaging with potentially phone scammers. Experimental results confirm the practicality of our approach, offering a viable path toward securing telephony communication against impersonation-based threats.
Tipologia CRIS:
1.1 Articolo in rivista
Keywords:
Authentication; eIDAS; Spoofing; Telephone scams; Vishing
Elenco autori:
Buccafurri, F.; De Angelis, V.; Lazzaro, S.; Licciardi, C.
Autori di Ateneo:
BUCCAFURRI Francesco
LICCIARDI CARMEN
Link alla scheda completa:
https://iris.unirc.it/handle/20.500.12318/169346
Pubblicato in:
JOURNAL OF INFORMATION SECURITY AND APPLICATIONS
Journal
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.7.0.0