Electronic device for preventing deepfake phishing call and storage medium thereof

The electronic device and storage medium enhance call security by verifying caller authenticity and protecting detection algorithms, effectively identifying and preventing deepfake phishing calls through confidential computing.

WO2026084231A1PCT designated stage Publication Date: 2026-04-23SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2025-08-21
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively distinguish between real and deepfake voices in phishing calls, particularly due to the advancements in deepfake technology, leading to increased instances of unethical and malicious activities.

Method used

An electronic device and storage medium that verify the authenticity of a call by using caller attestation information, including sensing data and modulation application status, and employ confidential computing to protect detection algorithms from manipulation.

Benefits of technology

Effectively identifies deepfake phishing calls by ensuring the integrity of caller verification and preventing unauthorized modulation applications, thereby enhancing call security and reducing false positives.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025012737_23042026_PF_FP_ABST
    Figure KR2025012737_23042026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed is an electronic device comprising: a communication circuit; at least one processor; and a memory storing instructions. The instructions may instruct the electronic device to: identify that a call has come in; while the call is maintained, receive, from an external electronic device, caller proof information including first information related to whether the call is originated by a user of the external electronic device, and second information indicating whether a modulation application related to voice and / or video is being executed; identify whether the call is a deepfake phishing call on the basis of the caller proof information; and output a notification on the basis of identifying that the call is a deepfake phishing call.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device for preventing deepfake phishing calls and storage medium thereof

[0001] The present disclosure relates to an electronic device and a storage medium thereof that prevent deepfake phishing calls.

[0002] Various services and additional functions provided through user terminals, such as electronic devices like smartphones, are gradually increasing. To enhance the utility value of these electronic devices and satisfy the needs of diverse users, telecommunications service providers and electronic device manufacturers are competitively developing electronic devices that offer a wide range of functions. Consequently, the various functions provided through these electronic devices are also becoming increasingly sophisticated.

[0003] Phishing is a compound word meaning "fishing for private data," referring to a fraudulent method of illegally obtaining personal information by impersonating financial institutions or other entities. Depending on the method, phishing includes messenger phishing and voice phishing. Voice phishing refers to a financial fraud method in which a victim is deceived or their personal information is illegally obtained through voice calls, and then used for criminal purposes.

[0004] Due to the advancement of deepfake technology, it has become nearly impossible to distinguish between a mechanized voice and a real human voice. Consequently, phishing calls based on deepfake technology are becoming a major social problem as they are used for unethical and malicious purposes. For example, deepfake technology allows malicious users to reproduce a target's voice and impersonate their identity. Through this, malicious users can commit defamation, threats, provide false information, or launch socio-ethical attacks against the target or the recipient. With the recent proliferation of AI smartphones equipped with on-device AI capabilities, the likelihood of an increase in deepfake phishing problems utilizing smartphone AI functions has risen.

[0005] The information described above may be provided as related art for the purpose of aiding understanding of the present disclosure. No claim or determination is made as to whether any of the foregoing may be applied as prior art related to the present disclosure.

[0006] Embodiments of the present disclosure may provide an electronic device and a storage medium thereof that prevent deepfake phishing calls.

[0007] Embodiments of the present disclosure may provide an electronic device and a storage medium thereof for verifying whether a transmission by a sending user is authentic.

[0008] Embodiments of the present disclosure may provide an electronic device and a storage medium thereof that prevent deepfake phishing by verifying a transmission by a sending user and verifying whether a modification program is running.

[0009] The technical problems to be solved in this disclosure are not limited to those mentioned above, and other unmentioned technical problems will be clearly understood by those skilled in the art to which this disclosure belongs from the description below.

[0010] An electronic device according to one embodiment of the present disclosure may include at least one processor comprising a communication circuit and a processing circuit, and a memory for storing instructions. When the instructions are executed individually or collectively by the at least one processor, the electronic device may identify that a call has been received. When the instructions are executed individually or collectively by the at least one processor, the electronic device may receive caller attestation information from the external electronic device through the communication circuit, the caller attestation information comprising first information relating to whether the call was initiated by a user of the external electronic device and second information indicating whether a voice and / or video modulation application is running on the external electronic device while the call is being maintained. When the instructions are executed individually or collectively by the at least one processor, the electronic device may identify whether the call is a deepfake phishing call based on the caller attestation information. When the above instructions are executed individually or collectively by the at least one processor, the electronic device may output a notification indicating that the call is a deepfake phishing call based on confirming that the call is a deepfake phishing call.

[0011] An electronic device according to one embodiment of the present disclosure may include at least one processor comprising a communication circuit and a processing circuit, and a memory for storing instructions. When the instructions are executed individually or collectively by the at least one processor, the electronic device may be able to confirm that a call is being made to an external electronic device. When the instructions are executed individually or collectively by the at least one processor, the electronic device may be able to generate first information regarding whether the call was made by a user of the electronic device based on at least one of sensing data collected by a proximity sensor, data collected by a camera, data collected by a microphone, or data collected by a Bluetooth (BT) chip while the call is being maintained. When the instructions are executed individually or collectively by the at least one processor, the electronic device may be able to generate second information indicating whether a modulation application related to voice and / or video is running on the electronic device while the call is being maintained. When the above instructions are executed individually or collectively by the at least one processor, the electronic device may transmit caller attestation information, including the first information and the second information, to the external electronic device through the communication circuit.

[0012] According to one embodiment of the present disclosure, in a non-transient computer-readable storage medium storing one or more programs, the one or more programs may include instructions that, when executed individually or collectively by at least one processor of an electronic device, cause the electronic device to confirm that a call has been received, and while the call is maintained, receive caller attestation information from the external electronic device, the information including first information relating to whether the call was made by a user of the external electronic device and second information indicating whether a modulation application related to voice and / or video is running on the external electronic device, determine whether the call is a deepfake phishing call based on the caller attestation information, and output a notification indicating that the call is a deepfake phishing call based on the confirmation that the call is a deepfake phishing call.

[0013] According to one embodiment of the present disclosure, in a non-transient computer-readable storage medium storing one or more programs, the one or more programs may include instructions that, when executed individually or collectively by at least one processor of an electronic device, cause the electronic device to confirm that a call is being made to an external electronic device, and while the call is being maintained, generate first information relating to whether the call was made by a user of the electronic device based on at least one of sensing data collected by a proximity sensor, data collected by a camera, data collected by a microphone, or data collected by a Bluetooth (BT) chip, and while the call is being maintained, generate second information indicating whether a modulation application related to voice and / or video is being executed on the electronic device, and transmit caller identification information including the first information and the second information to the external electronic device.

[0014] FIG. 1 is a block diagram of an electronic device in a network environment according to various embodiments.

[0015] FIG. 2 is a drawing for explaining an example of a deepfake phishing call according to one embodiment of the present disclosure.

[0016] FIG. 3 illustrates a system structure for detecting deepfake phishing according to one embodiment of the present disclosure.

[0017] FIG. 4 illustrates a sequence diagram for explaining a sender authenticity verification procedure according to one embodiment of the present disclosure.

[0018] FIG. 5a is a diagram illustrating the configuration of a transmitting electronic device for performing sender authenticity verification according to one embodiment of the present disclosure.

[0019] FIG. 5b is a drawing illustrating the configuration of a receiving electronic device for detecting deepfake phishing calls according to one embodiment of the present disclosure.

[0020] FIG. 6 is a diagram showing a software structure for preventing deepfake phishing according to one embodiment of the present disclosure.

[0021] FIG. 7 is a flowchart illustrating a procedure for detecting deepfake phishing calls according to one embodiment of the present disclosure.

[0022] FIG. 8 is a flowchart illustrating a procedure for determining a call made by a calling user according to one embodiment of the present disclosure.

[0023] Embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. In describing the embodiments of the present disclosure, specific descriptions of related known functions or configurations are omitted if it is determined that such detailed descriptions would unnecessarily obscure the essence of the present disclosure. Furthermore, terms used below are defined considering their functions in the embodiments of the present disclosure, and these may vary depending on the intentions or practices of the user or operator. Therefore, such definitions should be based on the content throughout the present disclosure.

[0024] It should be noted that technical terms used in this disclosure are used merely to describe one embodiment and are not intended to limit this disclosure. Alternatively, unless specifically defined otherwise in this disclosure, technical terms used in this disclosure shall be interpreted in the sense generally understood by those skilled in the art to which this disclosure pertains, and shall not be interpreted in an overly broad or overly narrow sense. Alternatively, technical terms used in this disclosure may be understood as being replaced by other technical terms understood by those skilled in the art. General terms used in the embodiments of this disclosure shall be interpreted according to their prior definitions or according to the context, and shall not be interpreted in an overly narrow sense.

[0025] Singular expressions used in this disclosure may include plural expressions unless the context clearly indicates otherwise. In this disclosure, terms such as “composed” or “comprising” should not be interpreted as necessarily including all of the various components or operations described in the specification, and should be interpreted as meaning that some of the components or operations may not be included, or that additional components or operations may be included.

[0026] Terms including ordinal numbers, such as first, second, etc., used in this disclosure may be used to describe various components, but said components should not be limited by said terms. Such terms may be used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of this disclosure, the first component may be named the second component, and similarly, the second component may be named the first component.

[0027] When it is stated that one component is "connected" or "connected" to another component, it may be directly connected or connected to that other component, or there may be other components in between. On the other hand, when it is stated that one component is "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between.

[0028] Hereinafter, embodiments according to the present disclosure will be described with reference to the attached drawings. Identical or similar components regardless of drawing symbols are given the same reference numeral, and redundant descriptions thereof will be omitted. In describing the embodiments of the present disclosure, detailed descriptions of related prior art are omitted if it is determined that such detailed descriptions may obscure the essence of the present disclosure. It should be noted that the attached drawings are intended only to facilitate understanding of the embodiments of the present disclosure and should not be interpreted as limiting the present disclosure. The present disclosure should be interpreted as extending to all modifications, equivalents, and substitutions in addition to the attached drawings.

[0029] In this disclosure, embodiments will be described using an electronic device as an example, but the electronic device may be referred to as a terminal, mobile station, mobile equipment (ME), user equipment (UE), user terminal (UT), subscriber station (SS), wireless device, handheld device, or access terminal (AT). In the embodiments of this disclosure, the electronic device may be a device equipped with communication functions, such as a mobile phone, personal digital assistant (PDA), smartphone, wireless modem, or laptop.

[0030] FIG. 1 is a block diagram of an electronic device (101) in a network environment (100) according to various embodiments.

[0031] Referring to FIG. 1, in a network environment (100), an electronic device (101) may communicate with an electronic device (102) through a first network (198) (e.g., a short-range wireless communication network) or with an electronic device (104) or a server (108) through a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) through a server (108). According to one embodiment, the electronic device (101) may include a processor (120), memory (130), input module (150), sound output module (155), display module (160), audio module (170), sensor module (176), interface (177), connection terminal (178), haptic module (179), camera module (180), power management module (188), battery (189), communication module (190), subscriber identification module (196), or antenna module (197). In some embodiments, at least one of these components (e.g., connection terminal (178)) may be omitted from the electronic device (101), or one or more other components may be added. In some embodiments, some of these components (e.g., sensor module (176), camera module (180), or antenna module (197)) may be integrated into a single component (e.g., display module (160)).

[0032] The processor (120) can control at least one other component (e.g., hardware or software component) of the electronic device (101) connected to the processor (120) by executing software (e.g., program (140)), and can perform various data processing or operations. According to one embodiment, as at least part of the data processing or operations, the processor (120) can store commands or data received from other components (e.g., sensor module (176) or communication module (190)) in volatile memory (132), process the commands or data stored in volatile memory (132), and store the resulting data in non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., central processing unit or application processor) or an auxiliary processor (123) that can operate independently or together with it (e.g., graphics processing unit, neural processing unit (NPU), image signal processor, sensor hub processor, or communication processor). For example, if the electronic device (101) includes a main processor (121) and an auxiliary processor (123), the auxiliary processor (123) may be configured to use lower power than the main processor (121) or to be specialized for a designated function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as part thereof.

[0033] The auxiliary processor (123) may control at least some of the functions or states associated with at least one component of the electronic device (101) (e.g., display module (160), sensor module (176), or communication module (190)) on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. According to one embodiment, the auxiliary processor (123) (e.g., image signal processor or communication processor) may be implemented as part of another functionally related component (e.g., camera module (180) or communication module (190)). According to one embodiment, the auxiliary processor (123) (e.g., neural network processing unit) may include a hardware structure specialized for processing an artificial intelligence model. The artificial intelligence model may be generated through machine learning. Such learning may be performed, for example, on the electronic device (101) itself where the artificial intelligence is performed, or through a separate server (e.g., server (108)). The learning algorithm may include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model may include a plurality of artificial neural network layers.An artificial neural network may be a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to the hardware structure, the artificial intelligence model may include a software structure, either additionally or substantially.

[0034] The memory (130) can store various data used by at least one component of the electronic device (101) (e.g., processor (120) or sensor module (176)). The data may include, for example, input data or output data for software (e.g., program (140)) and related commands. The memory (130) may include volatile memory (132) or non-volatile memory (134).

[0035] The program (140) may be stored as software in memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0036] The input module (150) can receive commands or data to be used for a component of the electronic device (101) (e.g., processor (120)) from outside the electronic device (101) (e.g., user). The input module (150) may include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0037] The sound output module (155) can output a sound signal to the outside of the electronic device (101). The sound output module (155) may include, for example, a speaker or a receiver. The speaker may be used for general purposes, such as multimedia playback or recording playback. The receiver may be used to receive incoming calls. According to one embodiment, the receiver may be implemented separately from the speaker or as part thereof.

[0038] The display module (160) can visually provide information to an external (e.g., user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling said device. According to one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of the force generated by said touch.

[0039] The audio module (170) can convert sound into an electrical signal or, conversely, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150) or output sound through the sound output module (155) or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphones) connected directly or wirelessly to the electronic device (101).

[0040] The sensor module (176) can detect the operating state of the electronic device (101) (e.g., power or temperature) or the external environmental state (e.g., user state) and generate an electrical signal or data value corresponding to the detected state. According to one embodiment, the sensor module (176) may include, for example, a gesture sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an accelerometer sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biosensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0041] The interface (177) may support one or more specified protocols that can be used for the electronic device (101) to be connected directly or wirelessly to an external electronic device (e.g., electronic device (102)). According to one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0042] The connection terminal (178) may include a connector through which the electronic device (101) can be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0043] The haptic module (179) can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that the user can perceive through tactile or kinesthetic senses. According to one embodiment, the haptic module (179) may include, for example, a motor, a piezoelectric element, or an electric stimulation device.

[0044] The camera module (180) can capture still images and video. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0045] The power management module (188) can manage the power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least part of a power management integrated circuit (PMIC).

[0046] The battery (189) can supply power to at least one component of the electronic device (101). According to one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0047] The communication module (190) can support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between an electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may include one or more communication processors that operate independently of the processor (120) (e.g., application processor) and support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., cellular communication module, short-range wireless communication module, or GNSS (global navigation satellite system) communication module) or a wired communication module (194) (e.g., LAN (local area network) communication module, or power line communication module). The corresponding communication module among these communication modules can communicate with an external electronic device (104) through a first network (198) (e.g., a short-range communication network such as Bluetooth, WiFi (wireless fidelity) direct, or IrDA (infrared data association)) or a second network (199) (e.g., a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can identify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) using subscriber information (e.g., International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module (196).

[0048] The wireless communication module (192) can support 5G networks and next-generation communication technologies following 4G networks, for example, new radio access technology. NR access technology can support high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and connection of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low-latency communications (URLLC)). The wireless communication module (192) can support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The wireless communication module (192) can support various technologies for securing performance in the high-frequency band, such as beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large-scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), external electronic device (e.g., electronic device (104)), or network system (e.g., second network (199)). According to one embodiment, the wireless communication module (192) can support a Peak data rate (e.g., 20 Gbps or more) for realizing eMBB, loss coverage (e.g., 164 dB or less) for realizing mMTC, or U-plane latency (e.g., downlink (DL) and uplink (UL) each 0.5 ms or less, or round trip 1 ms or less) for realizing URLLC.

[0049] An antenna module (197) can transmit a signal or power to or from an external source (e.g., an external electronic device). According to one embodiment, the antenna module (197) may include an antenna comprising a radiator made of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). According to one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as a first network (198) or a second network (199), may be selected from the plurality of antennas, for example, by a communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. According to some embodiments, in addition to the radiator, other components (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as part of the antenna module (197).

[0050] According to various embodiments, the antenna module (197) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent to a first surface (e.g., bottom surface) of the printed circuit board and capable of supporting a specified high frequency band (e.g., mmWave band), and a plurality of antennas (e.g., array antennas) disposed on or adjacent to a second surface (e.g., top surface or side surface) of the printed circuit board and capable of transmitting or receiving a signal of the specified high frequency band.

[0051] At least some of the above components can be connected to each other via a communication method between peripheral devices (e.g., bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)) and exchange signals (e.g., commands or data) with each other.

[0052] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) through a server (108) connected to a second network (199). Each of the external electronic devices (102, or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations performed on the electronic device (101) may be performed on one or more of the external electronic devices (102, 104, or 108). For example, if the electronic device (101) needs to perform a function or service automatically or in response to a request from a user or another device, the electronic device (101) may request one or more external electronic devices to perform at least part of the function or service instead of performing the function or service itself or additionally. One or more external electronic devices that receive the above request may execute at least part of the requested function or service, or additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may provide the result as is or additionally processed as at least part of the response to the request. For this purpose, for example, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used. The electronic device (101) may provide ultra-low latency services using, for example, distributed computing or mobile edge computing. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server using machine learning and / or neural networks. According to one embodiment, the external electronic device (104) or the server (108) may be included within a second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0053] FIG. 2 is a drawing for explaining an example of a deepfake phishing call according to one embodiment of the present disclosure.

[0054] Referring to FIG. 2, a malicious user (212) may attempt to make an outgoing call using a first electronic device (210) (e.g., electronic device (101)) that has on-device artificial intelligence (AI) embedded. The first electronic device (210) may establish a call (e.g., a voice call or a video call) with a second electronic device (220) (e.g., electronic device (101)) through a network (200) (e.g., a cellular network, and / or a second network (199)). The first electronic device (210) may use deepfake technology to transform (e.g., modulate) the voice, machine-generated voice, or machine-generated image of the malicious user (212) into the voice or image of a person whom the user of the second electronic device (220) (e.g., the receiving user (220)) considers intimate.

[0055] To defend against crimes based on deepfake phishing, blacklist-based phishing detection technology or machine learning (ML)-based deepfake phishing detection technology may be used.

[0056] Blacklist-based phishing detection technology databases the phone numbers of malicious callers and uses said databased numbers as a blacklist to detect phishing calls, and can be effective in preventing voice call-based fraud such as voice phishing. Blacklist-based phishing detection technology can operate in the following sequence.

[0057] Creating a blacklist may mean building a database (e.g., a blacklist) by collecting phone numbers suspected of or confirmed to be involved in fraudulent activity. The blacklist may be updated periodically to include newly identified malicious caller numbers.

[0058] Whenever an outgoing call is detected, the system (e.g., a network entity) compares the caller number against the blacklist, and if the caller number is registered in the blacklist, it may consider the outgoing call as a phishing attempt and warn the caller or automatically block (e.g., terminate) the outgoing call.

[0059] The receiving user can recognize that the incoming call is being received from a malicious caller through a warning message delivered from the system, and can be provided with an option to accept or reject the incoming call through a user interface (UI).

[0060] Receiving users can directly report caller ID numbers suspected of being malicious to the system, and the system can contribute to the protection of other receiving users by adding said caller ID numbers to a database (e.g., a blacklist). Blacklist-based technology can be a highly effective means of preventing phone fraud. However, maintaining the efficiency of blacklist-based technology may require continuous management (e.g., updates) of the database and active participation from receiving users.

[0061] Since malicious users' phone numbers are constantly changing, the system may fail to detect new threats if the blacklist is not updated in real time. Furthermore, if an attacker uses spoofing techniques to manipulate or alter caller ID, their outgoing calls can bypass blacklist-based detection systems. In addition, innocent users may suffer harm due to false positives, where legitimate phone numbers are mistakenly added to the blacklist, or omissions, where actual malicious phone numbers are not listed.

[0062] While a highly dynamic response system is necessary to counter rapidly changing fraudulent call patterns, existing static blacklist-based phishing detection technologies have limitations in that they cannot respond to new fraudulent call patterns. Furthermore, since users must manually report suspicious numbers, it can be difficult to identify new threats without active user participation.

[0063] Machine learning-based deepfake phishing detection technology can be used to overcome the limitations of blacklist-based voice phishing detection technology. Machine learning-based deepfake phishing detection technology is a solution that uses artificial intelligence (AI) to identify deepfake content (e.g., voice or video). By learning patterns in calls or emails, machine learning-based deepfake phishing detection technology can detect new threats and effectively detect threats that might be missed by blacklists alone. Furthermore, machine learning-based technology can be advantageous in terms of maintenance because it automatically repeats the learning process. Machine learning-based deepfake phishing detection technology can operate in the following sequence.

[0064] Data collection and preprocessing can collect large datasets of real and fake content. The collected datasets are used for model training and can be processed into a form suitable for training through preprocessing.

[0065] The system can train a machine learning model (e.g., a deep learning model) using the collected dataset. The trained model can distinguish between real content and fake content by learning the technical characteristics and patterns used to generate deepfakes.

[0066] The above-mentioned trained model can identify subtle features in video or audio content. For example, these subtle features may include unnatural facial movements, unnaturalness of eye blinking, and subtle modulation of voice.

[0067] The above-mentioned trained model can analyze patterns of content (e.g., audio or video) and determine whether the content is a deepfake based on the analyzed patterns. The accuracy of the determination may depend on the complexity of the above-mentioned trained model and the quality of the training data.

[0068] After going through the detection process, the system can provide the user with a result regarding whether the content is a deepfake or not. Through this, the user can determine the reliability of the content.

[0069] As deepfake generation technology continues to advance, machine learning models can be regularly updated to learn new patterns and techniques. Machine learning-based deepfake detection technology can be usefully employed to determine the authenticity of video and audio content. To maintain the effectiveness of such deepfake detection technology, continuous data collection, model training, and updates to keep pace with technological advancements are essential. However, machine learning-based deepfake detection technology relies heavily on training data and may struggle to respond to new types of deepfake attacks.

[0070] As deepfake generation technology advances, new manipulation techniques that bypass machine learning models may continuously emerge, potentially affecting the detection accuracy of machine learning models. Furthermore, if the training data for machine learning models is biased, the models may be overly sensitive or insensitive to certain types of deepfake phishing calls. Models specialized for specific types of deepfakes may be less effective for others, while general-purpose detection models may lack the ability to detect details in specific situations. Additionally, since analyzing and determining authenticity in real-time for high-definition video or audio requires significant computing resources, it may be difficult to determine authenticity in real-time using machine learning-based deepfake phishing detection technology.

[0071] Embodiments of the present disclosure enable a recipient to distinguish deepfake phishing calls by verifying the authenticity of a call made by a caller (e.g., a real human) when a call is made, and by providing information on whether a voice and / or video-related modulation application is running on the caller's electronic device (e.g., a smartphone). Embodiments of the present disclosure utilize confidential computing (CC) to protect algorithms for detecting deepfake phishing (e.g., a caller authenticity verification module (604) and / or a modulation application scan module (616))) from being manipulated by other malicious programs, and through hardware attestation, ensure an environment in which said algorithms operate normally and voice or video-related modulation applications cannot operate.

[0072] Confidential computing refers to a security method designed to protect sensitive information during processing. Confidential computing can operate by encrypting data at the hardware level and restricting access rights to prevent external access to the data. It can proactively prevent data leakage or misuse. Confidential computing can be utilized to process critical information in a cloud environment.

[0073] Hardware attestation, one of the mechanisms supporting the implementation of confidential computing, can refer to the action of proving that hardware or software is running in a safe and reliable state as expected. Hardware attestation can refer to the process of ensuring the integrity and reliability of hardware components in a computing system. Hardware attestation may include actions that verify the identity and expected behavior of hardware components.

[0074] FIG. 3 illustrates a system structure for detecting deepfake phishing according to one embodiment of the present disclosure.

[0075] Referring to FIG. 3, a first electronic device (210) (e.g., a sending electronic device) may be used by a malicious user (e.g., an attacker) to send a call (e.g., a deepfake phishing call (302)). In one embodiment, the first electronic device (210) may run a voice modulation application and generate a mechanical voice that mimics a target through the voice modulation application and transmit said generated voice through the deepfake phishing call (302). The deepfake phishing call (302) sent by the first electronic device (210) may be connected to a second electronic device (220) through a network (e.g., a network (200)). The second electronic device (220) (e.g., a receiving electronic device) may receive said voice through said deepfake phishing call (302).

[0076] In one embodiment, the first electronic device (210) may be configured to execute a caller authentic verification algorithm (e.g., a caller authentic verification module (604)) to determine whether the call is authentic and was made by an actual caller (e.g., a real human) while the call (e.g., a deepfake phishing call (302)) is being made. By executing the caller authentic verification algorithm, the first electronic device (210) may generate a caller attestation report (304) indicating whether the call was made by an actual caller. In one embodiment, while the call is being made, the first electronic device (210) may transmit the caller attestation report (304) related to the deepfake phishing call (302) to the second electronic device (220).

[0077] In one embodiment, the caller authentication report (304) may include at least one of: first information indicating the result of performing the caller authenticity verification algorithm; second information indicating the result of scanning whether a modulation application related to voice and / or video is running in the first electronic device (210); third information indicating whether the caller phone number has been modulated; or fourth information indicating whether the algorithm scanning the execution of the caller authenticity verification algorithm and the modulation application (e.g., the modulation application scan module (616)) is operating normally.

[0078] In one embodiment, the first electronic device (210) may periodically transmit the caller ID report (304) related to the deepfake phishing call (302) to the second electronic device (220) in response to a request from the second electronic device (220) or without a request from the second electronic device (220) while performing the deepfake phishing call (302).

[0079] In one embodiment, the second electronic device (220) may perform sender identity verification (306) with the server (310) to verify the sender identity report (304). The sender identity verification may include verifying whether the sender identity report was executed by a normal sender identity verification algorithm (e.g., a sender identity verification module (604)) and whether the sender identity verification algorithm is operating safely protected from the hardware or other software of the first electronic device (210). In one embodiment, to be used for sender identity verification (306), the sender identity report (304) may include hardware version, application version, and / or OS information related to the sender identity verification algorithm. The server performs a sender identity verification (306) based on the sender identity report (304) (e.g., hardware version, application version, and / or OS information) and can transmit the result of the sender identity verification (306) (e.g., verification success or verification failure) to the second electronic device (220).

[0080] In one embodiment, the second electronic device (220) may block or maintain the deepfake phishing call (302) based on the caller ID report (304) (e.g., verified caller ID report (304)). In one embodiment, the second electronic device (220) may output a user notification related to the deepfake phishing call (302) through the display module (160) or through the audio module (170) in the form of voice and / or sound based on the caller ID report (304) (e.g., verified caller ID report (304)). The second electronic device (220) can prevent damage caused by deepfake voice phishing by verifying the authenticity of a call made by a caller (e.g., a real human) based on the caller attestation report (304), verifying whether a modulation application related to voice and / or video is operating, and notifying the recipient that the detection function is operating normally through device attestation.

[0081] The embodiments of the present disclosure can solve the problem of number tampering and spoofing in blacklist-based phishing detection technology, and / or the problem of advanced tampering technology in machine learning-based deepfake phishing detection technology.

[0082] FIG. 4 illustrates a sequence diagram for explaining a sender authenticity verification procedure according to one embodiment of the present disclosure. Depending on the embodiments, at least one of the operations described below may be omitted, modified, or executed in a different order.

[0083] Referring to FIG. 4, in operation 402, the first electronic device (210) may make a call (e.g., a deepfake phishing call (302)) to the second electronic device (220). The call may be made between the first electronic device (210) and the second electronic device (220) via a network (e.g., a network (200)). The call may be, for example, a voice call or a video call.

[0084] In operation 404, the second electronic device (220) may transmit a request message to the first electronic device (210) to request a caller identity report (e.g., caller identity report (304)) while the call is being made. In one embodiment, the request message may be transmitted through a designated interface between the first electronic device (210) and the second electronic device (212) (e.g., an application interface). In operation 406, the first electronic device (210) may generate a caller identity report by executing a caller identity verification algorithm (e.g., a caller identity verification module (604)) associated with the voice call. The caller identity verification algorithm may determine whether the call was made by a real caller and provide information indicating whether the call is a deepfake phishing call (e.g., true or false) and / or information regarding the likelihood that the call is a deepfake phishing call (e.g., high likelihood or low likelihood).

[0085] In one embodiment, the caller authentication report (304) may include at least one of a first information indicating the result of performing the caller authenticity verification algorithm, a second information indicating the result of scanning whether a voice and / or video modulation application is running on the first electronic device (210), a third information indicating whether the caller phone number has been modulated, or a fourth information indicating whether the algorithm scanning the execution of the caller authenticity verification algorithm and the modulation application is operating normally. In one embodiment, the caller authentication report (304) may further include at least one of version information, hardware information, or OS information for verifying the caller authenticity verification algorithm and the algorithm scanning the execution of the modulation application.

[0086] In operation 408, the first electronic device (210) may transmit the caller ID report to the second electronic device (220). The caller ID report may be transmitted through a designated interface (e.g., between applications) between the first electronic device (210) and the second electronic device (212) during the call.

[0087] In operations 410 and 412, the second electronic device (220) may perform sender identity verification based on the sender identity report. In one embodiment, in operation 410, the second electronic device (220) may transmit a request message for sender identity verification, including the sender identity report, to the server (310). The server (310) may verify the sender identity report to verify whether the sender identity report was executed by a normal sender identity verification algorithm and whether the sender identity verification algorithm is operating safely protected from the hardware of the first electronic device (210). In operation 412, the server (310) may transmit a verification result response, including the result of the sender identity verification, to the second electronic device (220).

[0088] In one embodiment, the second electronic device (220) may perform operation 414, which verifies the sender identity report through a designated local algorithm, instead of or in addition to performing operations 410 and 412. The second electronic device (220) may verify the sender identity report to verify whether the sender identity report was executed by a normal sender identity verification algorithm, and whether the sender identity verification algorithm is operating safely protected from the hardware and / or software of the first electronic device (210). In one embodiment, the sender identity verification algorithm may execute a process to verify the legitimacy of the hardware and / or software. The sender identity verification algorithm may operate safely, separated from the hardware and / or software, to verify the legitimacy of the hardware and / or software.

[0089] As an optional embodiment, in operation 416, the first electronic device (210) may periodically transmit additional caller ID reports to the second electronic device (220) according to a specified period while the call is maintained, and / or in response to additional requests from the second electronic device (220). The second electronic device (220) may perform verification of the additional caller ID reports (e.g., operations 410 and 412, and / or operation 414).

[0090] In operation 418, the second electronic device (220) can identify whether the call is a deepfake phishing call based on the caller ID report (e.g., verified caller ID report and / or periodic caller ID report). In operation 420, the second electronic device (220) can block (e.g., terminate) the call based on identifying that the call is a deepfake phishing call, and / or provide (e.g., display) user notification information to the user indicating that the call is a deepfake phishing call (or is suspected of being a deepfake phishing call).

[0091] FIG. 5a is a diagram illustrating the configuration of a transmitting electronic device for performing sender authenticity verification according to one embodiment of the present disclosure.

[0092] Referring to FIG. 5a, a transmitting electronic device (e.g., a first electronic device (210)) may include a communication circuit (520) (e.g., a communication module (190)), a memory (530) for storing instructions (e.g., a memory (130)), and at least one processor (510) (e.g., a processor (120)) including a processing circuit. In one embodiment, the first electronic device (210) may be a smartphone or a computing device capable of making voice calls.

[0093] The first electronic device (210) can make a call (e.g., a voice call and / or a video call) with an external electronic device (e.g., a second electronic device (220)) through a communication circuit (520) configured to transmit and receive signals using one or more antennas (not shown). In one embodiment, one or more antennas may be implemented as part of the antenna module (197) of FIG. 1. The first electronic device (210) may support at least one of 3G (3rd generation), 4G (4th generation), long term evolution (LTE), or 5G / NR (new radio) through the communication circuit (520). The communication circuit (520) may include one or more communication circuits based on 3G, 4G, LTE, or 5G / NR.

[0094] The communication circuit (520) exchanges control signals to establish a call (e.g., voice call or video call) with a second electronic device (220) through an external electronic device (e.g., network (200)) under the control of the processor (510), and after the call is established, it can transmit voice / video packets to the second electronic device (220) or receive voice / video packets from the second electronic device (220).

[0095] The first electronic device (210) may include a processor (510) which may be implemented with one or more single-core processors or one or more multi-core processors, and a memory (530) which stores instructions, control information, and data for the operation of the first electronic device (210). The memory (530) may store one or more applications, user information, device information, software information, hardware information, or related data for executing a sender authenticity verification algorithm (e.g., a sender authenticity verification module (604)) according to embodiments of the present disclosure.

[0096] In one embodiment, the processor (510) executes a caller authenticity verification algorithm according to the embodiments of the present disclosure when a call is initiated or while a call is being performed, generates a caller authenticity report (e.g., a caller authenticity report (304)) based on the result of the execution of the caller authenticity verification algorithm, and can transmit the caller authenticity report to a second electronic device (220) directly by a communication circuit (520) or through an external electronic device (e.g., a network (200)) once or periodically.

[0097] FIG. 5b is a drawing illustrating the configuration of a receiving electronic device for detecting deepfake phishing calls according to one embodiment of the present disclosure.

[0098] Referring to FIG. 5b, the receiving electronic device (e.g., the second electronic device (220)) may include a communication circuit (560) (e.g., a communication module (190)), a memory (570) for storing instructions (e.g., a memory (130)), and at least one processor (550) (e.g., a processor (120)) including a processing circuit. In one embodiment, the second electronic device (220) may be a smartphone or a computing device capable of receiving voice calls.

[0099] The second electronic device (220) can make calls (e.g., voice calls and / or video calls) with an external electronic device (e.g., the first electronic device (210)) through a communication circuit (560) configured to transmit and receive signals using one or more antennas (not shown). In one embodiment, one or more antennas may be implemented as part of the antenna module (197) of FIG. 1. The second electronic device (220) may support at least one of 3G, 4G, LTE, or 5G / NR through the communication circuit (560). The communication circuit (560) may include one or more communication circuits based on 3G, 4G, LTE, or 5G / NR.

[0100] The communication circuit (560) exchanges control signals to establish a call (e.g., voice call or video call) with the first electronic device (210) through an external electronic device (e.g., network (200)) under the control of the processor (550), and after the voice call is established, it can transmit voice / video packets to the first electronic device (210) or receive voice / video packets from the first electronic device (210).

[0101] The second electronic device (220) may include a processor (550) which may be implemented with one or more single-core processors or one or more multi-core processors, and a memory (570) which stores instructions, control information, and data for the operation of the second electronic device (220). The memory (570) may store one or more applications, user information, device information, software information, hardware information, or related data for executing a sender authentication verification algorithm (e.g., a verification module (626)) according to embodiments of the present disclosure.

[0102] In one embodiment, the processor (550) transmits a request message for a caller ID report according to the embodiments of the present disclosure to the first electronic device (210) via the communication circuit (520) when a call is initiated or while a call is being performed, and may receive the caller ID report once or periodically from the first electronic device (210) via the communication circuit (520) directly or via an external electronic device (e.g., a network (200)).

[0103] In one embodiment, the processor (550) determines whether the voice call is a deepfake phishing call based on the caller ID report (e.g., a verified caller ID report) and, based on the result of the determination, may terminate the voice call, output a user notification, or maintain the voice call. In one embodiment, the second electronic device (220) includes a display (e.g., a display module (160)) or an audio output means (e.g., an audio module (170)) and may provide a user notification including a warning of a deepfake phishing call visually and / or audibly through the display or audio output means.

[0104] FIG. 6 is a diagram showing a software structure for preventing deepfake phishing according to one embodiment of the present disclosure.

[0105] Referring to FIG. 6, the first electronic device (210) may include at least one of a call application (602), a caller authentic verification module (604), a mobile platform (630), or a confidential computing platform (622). In one embodiment, at least one of the call application, the caller authentic verification module (604), the mobile platform (630), or the confidential computing platform (622) may be composed of software and / or instructions that are executable by the processor (210) and stored in memory (530).

[0106] In one embodiment, the caller authenticity verification module (604) may include at least one of an authenticity verification algorithm (606), a modulation application scan module (616), a user alarm module (618), or a phone number modulation detection module (620). The authenticity verification algorithm (606) can determine whether a voice call in progress on the first electronic device (210) is authentic and was made by an actual caller based on multiple factors (e.g., proximity sensor factor (608), camera factor (610), microphone factor (612), or Bluetooth (BT) scan factor (614)) collected through at least one of a sensor (e.g., sensor module (176)), a camera (e.g., camera module (180)), an audio input means (e.g., audio module (170)), or a wireless communication circuit (e.g., wireless communication module (192)).

[0107] In one embodiment, the authenticity verification algorithm (606) may determine whether the actual caller is speaking by utilizing at least one of the proximity sensor factor (608), camera factor (610), microphone factor (612), or BT scan factor (614). In one embodiment, the proximity sensor factor (608) may include sensing data collected by a proximity sensor (e.g., sensor module (176)) (e.g., information indicating whether the user's body is in close proximity to the first electronic device (210)). In one embodiment, the camera factor (610) may include data collected by a camera (e.g., camera module (180)) (e.g., information indicating whether the user's image has been captured by the camera). In one embodiment, the microphone factor (612) may include information indicating whether actual voice is being input through the microphone of the first electronic device (210) (e.g., built-in microphone or microphone of a paired Bluetooth headset). In one embodiment, the BT scan factor (614) is information collected by a BT chip (e.g., a wireless communication module (192)), and may include information indicating whether a BT device (e.g., a BT speaker) that is not paired with the first electronic device (210) is detected in the vicinity of the first electronic device (210).

[0108] In one embodiment, the authenticity verification algorithm (606) may determine whether the speech was made by an actual user by further considering additional factors, such as the human body detection result by an ultra-wide band (UWB) module. In one embodiment, the authenticity verification algorithm (606) may use a convolutional neural network (CNN) algorithm, a recurrent neural network (RNN) algorithm, and / or a support vector machine (SVM) algorithm to determine whether the speech was made by an actual user. In one embodiment, the authenticity verification algorithm (606) may further determine the liveness of the call and reflect it in the caller authentication report.

[0109] In one embodiment, the modulation application scan module (616) can determine whether at least one application capable of recording and modulating voice and / or video (e.g., a voice modulation application and / or a video modulation application) is running based on the permissions of applications running in the first electronic device (210).

[0110] In one embodiment, the phone number tampering detection module (620) can determine whether the caller's phone number associated with the call has been tampered with based on an API (application programmable interface) that identifies the caller's phone number and subscriber information obtained from the SIM (subscriber identification module) card of the first electronic device (210).

[0111] In one embodiment, the user alarm module (618) may be configured to notify the user whether a deepfake phishing call is in progress based on the operation results of the authenticity verification algorithm (606) and the voice modulation application scan module (616).

[0112] In one embodiment, the mobile platform (630) is software that controls wireless communication operations by the first electronic device (210), for example, Android TM It may include an operation system (OS). In one embodiment, the mobile platform (630) determines whether the caller's phone number has been altered based on subscriber information obtained from a SIM card, and transmits information indicating whether the caller's phone number has been altered to a proof report generation module (624).

[0113] In one embodiment, the confidential computing platform (622) may include at least one of an authenticity report generation module (624) or a verification module (626). The authenticity report generation module (624) may be configured to generate a caller identity report (e.g., a caller identity report (304)) based on the results of the operation of the authenticity verification algorithm (606), the tampering application scan module (616), and / or the phone number tampering detection module (620). In one embodiment, the caller identity report may include at least one of first information indicating the result of executing the authenticity verification algorithm (606), second information indicating the result of executing the tampering application scan module (616), or third information indicating the result of executing the phone number tampering detection module (620). In one embodiment, the authentication report generation module (624) may be configured to determine whether the authenticity verification algorithm (606) and the voice modulation application scan module (616) are operating normally, and to include fourth information indicating whether the authenticity verification algorithm (606) and the voice modulation application scan module (616) are operating normally in the sender authentication report.

[0114] In one embodiment, the sender authenticity verification module (604) may be included in a confidential computing platform (622), and all or part of the factors of the sender authenticity verification module (604) (e.g., at least one of a proximity sensor factor (608), a camera factor (610), a microphone factor (612), or a BT scan factor (614)) may be processed by the confidential computing platform (622).

[0115] In one embodiment, the verification module (626) may be configured to provide a service for verifying the sender identity report. The verification module (626) may verify the sender identity report through a mobile platform (630) or through collaboration with a server (e.g., server (310)).

[0116] In one embodiment, the authenticity verification algorithm (606) can determine whether a real user is speaking by utilizing a plurality of factors (e.g., at least one of a proximity sensor factor (608), a camera factor (610), a microphone factor (612), and / or a BT scan factor (614)). The result of performing the authenticity verification algorithm (606) may indicate at least one of the following: caller speech (e.g., no possibility of deepfake phishing), high possibility of caller speech (e.g., low possibility of deepfake phishing), low possibility of caller speech (e.g., high possibility of deepfake phishing), or not caller speech (e.g., deepfake phishing).

[0117] FIG. 7 is a flowchart illustrating a procedure for detecting deepfake phishing calls according to an embodiment of the present disclosure. According to embodiments, at least one of the operations described below may be omitted, modified, or executed in a different order. In one embodiment, at least one of the operations described below may be executed by a processor (550) of a second electronic device (220). In one embodiment, at least one of the operations described below may be implemented by one or more instructions stored in a memory (570) of the second electronic device (220).

[0118] Referring to FIG. 7, in operation 702, the second electronic device (220) (e.g., processor (550)) can identify that a call (e.g., voice call or video call) is received from the sending electronic device (e.g., first electronic device (220)) via the communication circuit (560). The call may be connected to the first electronic device (210) via a network (e.g., network (200)). In operation 704, the second electronic device (220) (e.g., processor (550)) can receive caller identity information (e.g., caller identity report (304)) associated with the call from the first electronic device (220) while the call is being performed.

[0119] In one embodiment, the caller authentication report may include at least one of: first information indicating whether the call was made by a real caller (e.g., a real human) (e.g., the result of performing an authenticity verification algorithm (606)); second information indicating whether a voice and / or video modulation application is running on the first electronic device (210) (e.g., the result of performing a modulation application scan module (616)); third information indicating whether the caller's phone number has been modulated (e.g., the result of performing a phone number modulation detection module (620)); or fourth information indicating whether the authenticity verification algorithm (606) and the modulation application scan module (616) are operating normally.

[0120] In one embodiment, a second electronic device (220) (e.g., a processor (550)) may receive the caller ID report from the first electronic device (210) based on transmitting a request message for the caller ID report to the first electronic device (210). In one embodiment, the second electronic device (220) (e.g., a processor (550)) may receive the caller ID report that is periodically transmitted from the first electronic device (210) while the call is maintained.

[0121] In operation 706, the second electronic device (220) (e.g., processor (550)) can determine whether the call is deepfake phishing based on the caller ID report. In one embodiment, if the call is determined not to be deepfake phishing, the second electronic device (220) (e.g., processor (550)) can proceed to operation 708. In operation 708, the second electronic device (220) (e.g., processor (550)) can maintain the call.

[0122] If it is determined that the above call is deepfake phishing, the second electronic device (220) (e.g., processor (550)) may proceed to operation 710. In operation 710, the second electronic device (220) (e.g., processor (550)) may output (e.g., display) a user notification indicating that the above call is deepfake phishing, or a user notification indicating that the above call is highly likely or has the potential to be deepfake phishing. In one embodiment, the second electronic device (220) (e.g., processor (550)) may terminate the above call based on identifying that the above call is deepfake phishing, or that the above call is highly likely to be deepfake phishing.

[0123] FIG. 8 is a flowchart illustrating a procedure for determining a call made by a caller according to an embodiment of the present disclosure. According to embodiments, at least one of the operations described below may be omitted, modified, or executed in a different order. In one embodiment, at least one of the operations described below may be executed by a processor (510) of a first electronic device (210). In one embodiment, at least one of the operations described below may be implemented by one or more instructions stored in a memory (530) of the first electronic device (210).

[0124] Referring to FIG. 8, in operation 800, the first electronic device (210) (e.g., the processor (510)) can identify that a call (e.g., a voice call or a video call) is being made to the receiving electronic device (e.g., the second electronic device (210)) through the communication circuit (520). The call may be connected to the second electronic device (220) through a network (e.g., the network (200)).

[0125] In operation 802, the first electronic device (210) (e.g., processor (510)) can determine whether voice is being input to the microphone (e.g., audio module (170)) of the first electronic device (210). The microphone may be a microphone built into the first electronic device (210) or an external microphone connected via wired or wireless connection. If voice is not being input to the microphone, the first electronic device (210) (e.g., processor (510)) can proceed to operation 804. If voice is being input to the microphone, the first electronic device (210) (e.g., processor (510)) can proceed to operation 808.

[0126] In operation 804, the first electronic device (210) (e.g., processor (510)) can determine whether there is a Bluetooth headset (e.g., Bluetooth earbuds) that is paired (or connected) with the first electronic device (210). If the paired Bluetooth headset exists, the first electronic device (210) (e.g., processor (510)) can proceed to operation 808. If the paired Bluetooth headset does not exist, the first electronic device (210) (e.g., processor (510)) can proceed to operation 806.

[0127] In operation 806, the first electronic device (210) (e.g., processor (510)) determines that the call is deepfake phishing and can proceed to operation 822. In operation 822, the first electronic device (210) (e.g., processor (510)) can generate caller identity information (e.g., caller identity report) to include information (e.g., first information) indicating that the call is deepfake phishing.

[0128] In operation 808, the first electronic device (210) (e.g., processor (510)) can determine whether an image of a user is being captured through the camera (e.g., camera module (180)) of the first electronic device (210). In one embodiment, the camera may be a camera embedded in the first electronic device (210) or an external camera connected via wired or wireless connection. In one embodiment, the first electronic device (210) (e.g., processor (510)) can identify that an image of a user is being captured through the camera and that the image contains the shape of a human body (e.g., a humanoid image having a biological response). If an image of a user is not being captured through the camera, the first electronic device (210) (e.g., processor (510)) can proceed to operation 820. If an image of a user is being captured through the camera, the first electronic device (210) (e.g., processor (510)) can proceed to operation 810. If it is not possible to determine whether the user's image is being captured through the camera above, the first electronic device (210) (e.g., processor (510)) can proceed to operation 814.

[0129] In operation 810, the first electronic device (210) (e.g., processor (510)) can determine whether there is a BT device (e.g., a BT headset or a BT speaker) that is not paired with the first electronic device (210) in the vicinity of the first electronic device (210) through a Bluetooth chip (e.g., a wireless communication module (192)) included in the first electronic device (210). If a BT speaker is detected through the Bluetooth chip, the first electronic device (210) (e.g., processor (510)) can proceed to operation 820. If a BT speaker is not detected through the Bluetooth chip, the first electronic device (210) (e.g., processor (510)) can proceed to operation 812.

[0130] In operation 812, the first electronic device (210) (e.g., processor (510)) determines that the outgoing call is a normal outgoing call made by an actual user and can proceed to operation 822. In operation 822, the first electronic device (210) (e.g., processor (510)) can generate caller identity information (e.g., caller identity report) to include information (e.g., first information) indicating that the call is not a deepfake phishing call (e.g., a normal call).

[0131] In operation 814, the first electronic device (210) (e.g., processor (510)) can determine whether an actual caller (e.g., an actual human) is detected through the proximity sensor of the first electronic device (210). If a caller is detected, the first electronic device (210) (e.g., processor (510)) can proceed to operation 810. If a caller is not detected, the first electronic device (210) (e.g., processor (510)) can proceed to operation 816. In operation 816, the first electronic device (210) (e.g., processor (510)) can determine whether a BT device (e.g., a BT headset or a BT speaker) that is not paired with the first electronic device (210) exists in the vicinity of the first electronic device (210) through a Bluetooth chip (e.g., wireless communication module (192)) included in the first electronic device (210). If a BT speaker is detected via the Bluetooth chip, the first electronic device (210) (e.g., processor (510)) can proceed to operation 820. If a BT speaker is not detected via the Bluetooth chip, the first electronic device (210) (e.g., processor (510)) can proceed to operation 818.

[0132] In operation 818, the first electronic device (210) (e.g., processor (510)) may determine that the outgoing call is likely a deepfake phishing call and proceed to operation 822. In operation 822, the first electronic device (210) (e.g., processor (510)) may generate caller identity information (e.g., caller identity report) to include information (e.g., first information) indicating that the call is likely a deepfake phishing call.

[0133] In operation 820, the first electronic device (210) (e.g., processor (510)) may determine that the outgoing call is likely to be a deepfake phishing call and proceed to operation 822. In operation 822, the first electronic device (210) (e.g., processor (510)) may generate caller identity information (e.g., caller identity report) to include information (e.g., first information) indicating that the call is likely to be a deepfake phishing call.

[0134] In operation 822, the first electronic device (210) (e.g., processor (510)) may generate caller identity information (e.g., caller identity report) containing first information determined by any one of operation 806, operation 812, operation 818, or operation 820. In one embodiment, the first electronic device (210) (e.g., processor (510)) may include second information in the caller identity information indicating whether a modulation application related to voice or video is running. In one embodiment, the first electronic device (210) (e.g., processor (510)) may include third information in the caller identity information indicating whether the caller phone number has been modulated. In one embodiment, the first electronic device (210) (e.g., processor (510)) may include fourth information indicating whether the sender authenticity verification algorithm (e.g., authenticity verification algorithm (606) and / or tampering application scan module (616)) is operating normally in the sender authentication information.

[0135] In operation 824, the first electronic device (210) (e.g., processor (510)) can transmit the generated caller ID information to the second electronic device (210) via the communication circuit (520). In one embodiment, the first electronic device (210) (e.g., processor (510)) can transmit the generated caller ID information in response to a request from the second electronic device (210). In one embodiment, the first electronic device (210) (e.g., processor (510)) can periodically transmit the generated caller ID information according to a specified period.

[0136] In one embodiment, the first electronic device (210) (e.g., processor (510)) may output (e.g., display) a user notification warning of deepfake phishing based on first information determined by any one of operation 806, operation 812, operation 818, or operation 820.

[0137] Embodiments of the present disclosure provide a deepfake phishing detection function based on sender authentication information provided by a sender (e.g., a first electronic device (210)), thereby enabling deepfake phishing in various cases to be blocked at the source.

[0138] An electronic device (220) according to one embodiment of the present disclosure may include a communication circuit (560), at least one processor (550) including a processing circuit, and a memory (570) for storing instructions. When the instructions are executed individually or collectively by the at least one processor, the electronic device may identify that a call has been received. When the instructions are executed individually or collectively by the at least one processor, the electronic device may receive caller attestation information from the external electronic device through the communication circuit, the information including first information regarding whether the call was initiated by a user of the external electronic device while the call is being maintained, and second information indicating whether a modulation application related to voice and / or video is running on the external electronic device. When the above instructions are executed individually or collectively by the at least one processor, the electronic device may determine whether the call is a deepfake phishing call based on the caller identity information. When the above instructions are executed individually or collectively by the at least one processor, the electronic device may output a notification indicating that the call is a deepfake phishing call based on the determination that the call is a deepfake phishing call.

[0139] In one embodiment, the caller authentication information may include at least one of a third piece of information indicating whether the caller phone number has been tampered with in the external electronic device, or a fourth piece of information indicating whether the caller authenticity verification algorithm generating the first piece of information is operating normally in the external electronic device, and / or whether the tampering application scan algorithm generating the second piece of information is operating normally in the external electronic device.

[0140] In one embodiment, the first information may be generated based on at least one of sensing data collected by a proximity sensor of the external electronic device, data collected by a camera of the external electronic device, data collected by a microphone of the external electronic device, or data collected by a Bluetooth (BT) chip of the external electronic device.

[0141] In one embodiment, the first information may be set to indicate that the call is likely to be the deepfake phishing call based on the fact that the microphone voice is being input and the user's image is not being captured by the camera, or may be set to indicate that the call is likely to be the deepfake phishing call based on the fact that the microphone voice is being input, the user's image is being captured by the camera, and the Bluetooth chip detects a BT speaker that is not paired with the external electronic device.

[0142] In one embodiment, the first information may be configured to indicate that the call is likely the deepfake phishing call based on the fact that the microphone voice is being input, it is not possible to determine whether the user's image is being captured by the camera, the presence of the user is not detected by the proximity sensor, and a BT speaker not paired with the external electronic device is not detected by the Bluetooth chip.

[0143] In one embodiment, the first information may be configured to indicate that the call is the deepfake phishing call based on the fact that the microphone voice is not being input and the BT headset paired with the external electronic device by the Bluetooth chip is not detected, or may be configured to indicate that the call is not the deepfake phishing call based on the fact that the microphone voice is being input, the user's image is being captured by the camera, and the BT headset not paired with the external electronic device by the Bluetooth chip is not detected.

[0144] In one embodiment, when the instructions are executed individually or collectively by the at least one processor, the electronic device may periodically receive caller ID information from the external electronic device while the call is maintained and terminate the call based on identifying that the call is a deepfake phishing call.

[0145] An electronic device (210) according to one embodiment of the present disclosure may include a communication circuit (520), at least one processor (510) including a processing circuit, and a memory (530) for storing instructions. When the instructions are executed individually or collectively by the at least one processor, the electronic device may be able to confirm that a call is being made to an external electronic device (220). When the instructions are executed individually or collectively by the at least one processor, the electronic device may be able to generate first information regarding whether the call was made by a user of the electronic device, based on at least one of sensing data collected by a proximity sensor, data collected by a camera, data collected by a microphone, or data collected by a Bluetooth (BT) chip, while the call is being maintained. When the above instructions are executed individually or collectively by the at least one processor, the electronic device may generate second information indicating whether a modulation application related to voice and / or video is running on the electronic device while the call is maintained. When the above instructions are executed individually or collectively by the at least one processor, the electronic device may transmit caller attestation information including the first information and the second information to the external electronic device through the communication circuit.

[0146] In one embodiment, the caller authentication information may include at least one of a third piece of information indicating whether the caller phone number has been tampered with in the external electronic device, or a fourth piece of information indicating whether the caller authenticity verification algorithm generating the first piece of information is operating normally in the external electronic device, and / or whether the tampering application scan algorithm generating the second piece of information is operating normally in the external electronic device.

[0147] In one embodiment, the first information is configured to indicate that the call is highly likely to be the deepfake phishing call based on the fact that the microphone voice is input and the user's image is not captured by the camera; or is configured to indicate that the call is highly likely to be the deepfake phishing call based on the fact that the microphone voice is input and the user's image is captured by the camera and a BT speaker not paired with the external electronic device is detected by the Bluetooth chip; or is configured to indicate that the call is likely to be the deepfake phishing call based on the fact that the microphone voice is input and it cannot be confirmed whether the user's image is captured by the camera, the presence of the user is not detected by the proximity sensor, and a BT speaker not paired with the external electronic device is not detected by the Bluetooth chip; or is configured to indicate that the call is the deepfake phishing call based on the fact that the microphone voice is not input and a BT headset paired with the external electronic device is not detected by the Bluetooth chip; or is configured to indicate that the call is the deepfake phishing call based on the fact that the microphone voice is input and the user's by the camera It can be configured to indicate that the call is not the deepfake phishing call based on the fact that an image is being captured and that a BT headset not paired with the external electronic device by the Bluetooth chip is not detected.

[0148] According to one embodiment of the present disclosure, in a non-transient computer-readable storage medium storing one or more programs, the one or more programs may include instructions that, when executed individually or collectively by at least one processor of an electronic device (220), cause the electronic device to identify that a call has been received from an external electronic device (210), and while the call is maintained, receive caller attestation information from the external electronic device, the information including first information relating to whether the call was made by a caller user and second information indicating whether a modulation application related to voice and / or video is running on the external electronic device, determine whether the call is a deepfake phishing call based on the caller attestation information, and output a notification indicating that the call is a deepfake phishing call based on the determination that the call is a deepfake phishing call.

[0149] In one embodiment, the caller authentication information may include at least one of a third piece of information indicating whether the caller phone number has been tampered with in the external electronic device, or a fourth piece of information indicating whether the caller authenticity verification algorithm generating the first piece of information is operating normally in the external electronic device, and / or whether the tampering application scan algorithm generating the second piece of information is operating normally in the external electronic device.

[0150] In one embodiment, the first information may be generated based on at least one of sensing data collected by a proximity sensor of the external electronic device, data collected by a camera of the external electronic device, data collected by a microphone of the external electronic device, or data collected by a Bluetooth (BT) chip of the external electronic device.

[0151] In one embodiment, the first information may be set to indicate that the call is likely to be the deepfake phishing call based on the fact that the microphone voice is being input and the user's image is not being captured by the camera, or may be set to indicate that the call is likely to be the deepfake phishing call based on the fact that the microphone voice is being input, the user's image is being captured by the camera, and the Bluetooth chip detects a BT speaker that is not paired with the external electronic device.

[0152] In one embodiment, the first information may be configured to indicate that the call is likely the deepfake phishing call based on the fact that the microphone voice is being input, it is not possible to determine whether the user's image is being captured by the camera, the presence of the user is not detected by the proximity sensor, and a BT speaker not paired with the external electronic device is not detected by the Bluetooth chip.

[0153] In one embodiment, the first information may be set to indicate that the call is the deepfake phishing call based on the fact that the microphone voice is not being input and the BT headset paired with the external electronic device by the Bluetooth chip is not detected, or the call may be set to indicate that the call is not the deepfake phishing call based on the fact that the microphone voice is being input, the user's image is being captured by the camera, and the BT headset not paired with the external electronic device by the Bluetooth chip is not detected.

[0154] In one embodiment, when the instructions are executed individually or collectively by the at least one processor, the electronic device may periodically receive caller ID information from the external electronic device while the call is maintained and terminate the call based on identifying that the call is a deepfake phishing call.

[0155] According to one embodiment of the present disclosure, in a non-transient computer-readable storage medium storing one or more programs, the one or more programs may include instructions that, when executed individually or collectively by at least one processor of an electronic device (210), cause the electronic device to confirm that a call is being made to an external electronic device (220), and while the call is being maintained, generate first information related to whether the call was made by a user of the electronic device based on at least one of sensing data collected by a proximity sensor, data collected by a camera, data collected by a microphone, or data collected by a Bluetooth (BT) chip, and while the call is being maintained, generate second information indicating whether a modulation application related to voice and / or video is being executed on the electronic device, and transmit caller attestation information including the first information and the second information to the external electronic device.

[0156] In one embodiment, the caller authentication information may include at least one of a third piece of information indicating whether the caller phone number has been tampered with in the external electronic device, or a fourth piece of information indicating whether the caller authenticity verification algorithm generating the first piece of information is operating normally in the external electronic device, and / or whether the tampering application scan algorithm generating the second piece of information is operating normally in the external electronic device.

[0157] In one embodiment, the first information is configured to indicate that the call is highly likely to be the deepfake phishing call based on the fact that the microphone voice is input and the user's image is not captured by the camera; or is configured to indicate that the call is highly likely to be the deepfake phishing call based on the fact that the microphone voice is input and the user's image is captured by the camera and a BT speaker not paired with the external electronic device is detected by the Bluetooth chip; or is configured to indicate that the call is likely to be the deepfake phishing call based on the fact that the microphone voice is input and it cannot be confirmed whether the user's image is captured by the camera, the presence of the user is not detected by the proximity sensor, and a BT speaker not paired with the external electronic device is not detected by the Bluetooth chip; or is configured to indicate that the call is the deepfake phishing call based on the fact that the microphone voice is not input and a BT headset paired with the external electronic device is not detected by the Bluetooth chip; or is configured to indicate that the call is the deepfake phishing call based on the fact that the microphone voice is input and the user's by the camera It can be configured to indicate that the call is not the deepfake phishing call based on the fact that an image is being captured and that a BT headset not paired with the external electronic device by the Bluetooth chip is not detected.

[0158] The electronic device according to the various embodiments disclosed in this document may be of various forms. The electronic device may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a consumer electronics device. The electronic device according to the embodiments of this document is not limited to the devices described above.

[0159] The various embodiments of this document and the terms used therein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various modifications, equivalents, or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of said items unless the relevant context clearly indicates otherwise. In this document, phrases such as "A or B," "at least one of A and B," "at least one of A or B," "A, B or C," "at least one of A, B and C," and "at least one of A, B, or C" may each include any one of the items listed together in the corresponding phrase, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used simply to distinguish said components from other said components and do not limit said components in any other aspect (e.g., importance or order). Where any (e.g., 1st) component is referred to as “coupled” or “connected” to another (e.g., 2nd) component, with or without the terms “functionally” or “communicationly,” it means that said any component may be connected to said other component directly (e.g., via a wire), wirelessly, or through a third component.

[0160] The term “module” as used in the various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit, for example. A module may be a component formed integrally, or a minimum unit of said component or a part thereof that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0161] Various embodiments of the present document may be implemented as software (e.g., program (240)) comprising one or more instructions stored in a storage medium (e.g., internal memory (236) or external memory (238)) readable by a machine (e.g., electronic device (201)). For example, a processor (e.g., processor (220)) of the machine (e.g., electronic device (201)) may call at least one of the one or more instructions stored from the storage medium and execute it. This enables the machine to be operated to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code that can be executed by an interpreter. The storage medium readable by the machine may be provided in the form of a non-transitory storage medium. Here, 'non-temporary' simply means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.

[0162] According to one embodiment, the method according to the various embodiments disclosed herein may be provided as included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or distributed online (e.g., download or upload) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0163] According to various embodiments, each component (e.g., module or program) of the components described above may include a singular or multiple entities, and some of the multiple entities may be separated and placed in other components. According to various embodiments, one or more of the components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Generally or additionally, multiple components (e.g., module or program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the multiple components in the same or similar manner as those performed by the corresponding component among the multiple components prior to integration. According to various embodiments, operations performed by the module, program, or other components may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

1. In an electronic device (220), Communication circuit (560); At least one processor (550) including a processing circuit; and The electronic device includes a memory (570) for storing instructions, and when the instructions are executed individually or collectively by the at least one processor, the electronic device, Identify that a call has been received, While the above call is maintained, caller attestation information is received from the external electronic device through the communication circuit, the information including first information relating to whether the above call was initiated by a user of the external electronic device (210) and second information indicating whether a modulation application related to voice and / or video is running on the external electronic device. Based on the above caller ID information, determine whether the above call is a deepfake phishing call, and An electronic device that outputs a notification indicating that the call is a deepfake phishing call based on confirming that the call is a deepfake phishing call.

2. In claim 1, the sender authentication information is, Third information indicating whether the caller's phone number has been altered in the above external electronic device, or An electronic device comprising at least one of fourth information indicating whether a sender authenticity verification algorithm generating the first information is operating normally in the external electronic device, and / or whether a modulation application scan algorithm generating the second information is operating normally in the external electronic device.

3. In claim 1 or 2, the first information is, An electronic device generated based on at least one of sensing data collected by a proximity sensor of the external electronic device, data collected by a camera of the external electronic device, data collected by a microphone of the external electronic device, or data collected by a Bluetooth (BT) chip of the external electronic device.

4. In Clause 3, the first information is, It is configured to indicate that the call is highly likely to be the deepfake phishing call based on the fact that the above microphone voice is being input and the user's image is not being captured by the above camera, or An electronic device configured to indicate that the call is highly likely to be the deepfake phishing call based on the fact that the above-mentioned microphone voice is input, the user's image is captured by the above-mentioned camera, and a BT speaker not paired with the above-mentioned external electronic device is detected by the above-mentioned Bluetooth chip.

5. In Paragraph 3 or 4, the first information is, An electronic device configured to indicate that the call is likely the deepfake phishing call based on the fact that the above-mentioned microphone voice is being input, it is not possible to determine whether the user's image is being captured by the above-mentioned camera, the presence of the user is not detected by the above-mentioned proximity sensor, and a BT speaker not paired with the above-mentioned external electronic device is not detected by the above-mentioned Bluetooth chip.

6. In any one of claims 3 to 5, the first information is, Based on the fact that the above-mentioned microphone voice is not being input and the BT headset paired with the external electronic device by the above-mentioned Bluetooth chip is not detected, the above-mentioned call is configured to indicate that the above-mentioned call is the deepfake phishing call, or An electronic device configured to indicate that the call is not the deepfake phishing call based on the fact that the above-mentioned microphone voice is input, the user's image is captured by the above-mentioned camera, and the above-mentioned Bluetooth chip does not detect a BT headset that is not paired with the above-mentioned external electronic device.

7. In any one of claims 1 to 6, when the instructions are executed individually or collectively by the at least one processor, the electronic device, While the above call is maintained, the caller ID information is periodically received from the external electronic device, and An electronic device that terminates a call based on identifying that the call is a deepfake phishing call.

8. In the electronic device (210), Communication circuit (520); At least one processor (510) including a processing circuit; and The electronic device includes a memory (530) for storing instructions, and when the instructions are executed individually or collectively by the at least one processor, the electronic device, Confirm that a call is being sent to an external electronic device (220), While the above call is maintained, first information related to whether the call was initiated by a user of the electronic device is generated based on at least one of sensing data collected by a proximity sensor, data collected by a camera, data collected by a microphone, or data collected by a Bluetooth (BT) chip, and While the above call is maintained, second information is generated indicating whether a modulation application related to voice and / or video is running on the electronic device, and An electronic device that transmits caller attestation information, including the first information and the second information, to the external electronic device through the communication circuit.

9. In Clause 8, the sender authentication information is, Third information indicating whether the caller's phone number has been altered in the above external electronic device, or An electronic device comprising at least one of fourth information indicating whether a sender authenticity verification algorithm generating the first information is operating normally in the external electronic device, and / or whether a modulation application scan algorithm generating the second information is operating normally in the external electronic device.

10. In claim 8 or 9, the first information is, It is configured to indicate that the call is highly likely to be the deepfake phishing call based on the fact that the above microphone voice is being input and the user's image is not being captured by the above camera, or Based on the fact that the above-mentioned microphone voice is input, the user's image is captured by the above-mentioned camera, and the above-mentioned Bluetooth chip detects a BT speaker that is not paired with the above-mentioned external electronic device, the system is configured to indicate that the above-mentioned call is highly likely to be the above-mentioned deepfake phishing call, or It is configured to indicate that the call is likely the deepfake phishing call based on the fact that it is not possible to verify whether the microphone voice is being input and whether the user's image is being captured by the camera, the presence of the user is not detected by the proximity sensor, and a BT speaker not paired with the external electronic device is not detected by the Bluetooth chip, or Based on the fact that the above-mentioned microphone voice is not being input and the BT headset paired with the external electronic device by the above-mentioned Bluetooth chip is not detected, the above-mentioned call is configured to indicate that the call is the deepfake phishing call, or An electronic device configured to indicate that the call is not the deepfake phishing call based on the fact that the above-mentioned microphone voice is input, the user's image is captured by the above-mentioned camera, and the above-mentioned Bluetooth chip does not detect a BT headset that is not paired with the above-mentioned external electronic device.

11. In a non-transient computer-readable storage medium storing one or more programs, the one or more programs are executed individually or collectively by at least one processor of an electronic device (220), thereby causing the electronic device, Identify that a call has been received, While the above call is maintained, caller attestation information is received from the external electronic device, including first information relating to whether the above call was initiated by a user of the external electronic device (210) and second information indicating whether a modulation application related to voice and / or video is running on the external electronic device. Based on the above caller ID information, determine whether the above call is a deepfake phishing call, and A storage medium comprising instructions that output a notification indicating that the call is a deepfake phishing call based on confirming that the call is a deepfake phishing call.

12. In claim 11, the sender authentication information is, Third information indicating whether the caller's phone number has been altered in the above external electronic device, or A storage medium comprising at least one of fourth information indicating whether the sender authenticity verification algorithm generating the first information is operating normally in the external electronic device, and / or whether the modulation application scan algorithm generating the second information is operating normally in the external electronic device.

13. In claim 11 or 12, the first information is, A storage medium generated based on at least one of sensing data collected by a proximity sensor of the external electronic device, data collected by a camera of the external electronic device, data collected by a microphone of the external electronic device, or data collected by a Bluetooth (BT) chip of the external electronic device.

14. In Clause 13, the first information is, Based on the fact that the above-mentioned microphone voice is being input and the user's image is not being captured by the above-mentioned camera, it indicates that the above-mentioned call is highly likely to be the above-mentioned deepfake phishing call, or Based on the fact that the above-mentioned microphone voice is being input, the user's image is being captured by the above-mentioned camera, and a BT speaker not paired with the above-mentioned external electronic device is detected by the above-mentioned Bluetooth chip, it indicates that the above-mentioned call is highly likely to be the above-mentioned deepfake phishing call, or Indicating that the call may be the deepfake phishing call based on the fact that it is not possible to verify whether the above-mentioned microphone voice is being input and whether the user's image is being captured by the above-mentioned camera, that the presence of the user is not detected by the above-mentioned proximity sensor, and that a BT speaker not paired with the above-mentioned external electronic device is not detected by the above-mentioned Bluetooth chip, or Based on the fact that the above-mentioned microphone voice is not being input and the BT headset paired with the external electronic device by the above-mentioned Bluetooth chip is not detected, the above-mentioned call indicates that the above-mentioned call is the deepfake phishing call, or A storage medium indicating that the call is not the deepfake phishing call based on the fact that the above-mentioned microphone voice is input, the user's image is captured by the above-mentioned camera, and the above-mentioned Bluetooth chip does not detect a BT headset that is not paired with the above-mentioned external electronic device.

15. In a non-transient computer-readable storage medium storing one or more programs, the one or more programs are executed individually or collectively by at least one processor of an electronic device (210), thereby causing the electronic device, Confirm that a call is being sent to an external electronic device (220), While the above call is maintained, first information related to whether the call was initiated by a user of the electronic device is generated based on at least one of sensing data collected by a proximity sensor, data collected by a camera, data collected by a microphone, or data collected by a Bluetooth (BT) chip, and While the above call is maintained, second information is generated indicating whether a modulation application related to voice and / or video is running on the electronic device, and A storage medium comprising instructions for transmitting caller attestation information, including the first information and the second information, to the external electronic device.

Citation Information

Patent Citations

  • Method of operating an application for providing a voice modulation service using mobile voice over internet protocol

    KR101361311B1

  • System for preventing phising in video-telecommunication and method thereof

    KR1020100038796A

  • Electronic apparatus and method for counterfeiting prevention of telephone number, and program stored in computer readable medium performing the same

    KR102095303B1

  • System for providing Anti-phishing service using video call

    KR102379613B1

  • KR20240042921A