Systems and methods for call spoofing detection

The registry check mechanism in the device verifies the legitimacy of incoming call numbers by comparing them against a stored registry, effectively preventing call spoofing and protecting users from fraudulent calls.

WO2026107631A1PCT designated stage Publication Date: 2026-05-28QUALCOMM INC +6
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
QUALCOMM INC
Filing Date
2024-11-19
Publication Date
2026-05-28

AI Technical Summary

Technical Problem

Existing technologies fail to accurately detect call spoofing, allowing scammers to falsify caller IDs, which can deceive users into answering fraudulent calls.

Method used

A device or method that includes a registry check mechanism to verify the validity of an incoming call's phone number by comparing it against a stored registry of registered IDs, generating a call spoofing indicator based on the comparison.

Benefits of technology

Enhances the accuracy of call spoofing detection by determining whether an incoming phone number is legitimate, preventing users from being deceived by fraudulent calls.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024132901_28052026_PF_FP_ABST
    Figure CN2024132901_28052026_PF_FP_ABST
Patent Text Reader

Abstract

A device includes a memory configured to store a first phone number indicated by a call invitation message. The device also includes one or more processors coupled to the memory and configured to receive, from a second device, the call invitation message associated with a call from the second device. The call invitation message indicates the first phone number as an originating phone number of the call. The one or more processors are configured to send, to the second device, a registry check request that includes the first phone number, and to receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. The one or more processors are configured to output a call spoofing indicator associated with the call and that is based on whether the first phone number is included in the registry.
Need to check novelty before this filing date? Find Prior Art

Description

SYSTEMS AND METHODS FOR CALL SPOOFING DETECTIONI. Field

[0001] The present disclosure is generally related to call spoofing detection. II. Description of Related Art

[0002] Advances in technology have resulted in smaller and more powerful computing devices. For example, there currently exist a variety of portable personal computing devices, including wireless telephones such as mobile and smart phones, tablets and laptop computers that are small, lightweight, and easily carried by users. These devices can communicate voice and data packets over wireless networks. Further, many such devices incorporate additional functionality such as a digital still camera, a digital video camera, a digital recorder, and an audio file player. Also, such devices can process executable instructions, including software applications, such as a web browser application, that can be used to access the Internet. As such, these devices can include significant computing capabilities.

[0003] With the proliferation of mobile phones in daily life, fraudulent calls by scammers and other illegal entities have become a significant problem for users. Some fraudulent calls include call spoofing technology that enables a caller to deliberately falsify identifying information sent to the phone of a recipient of a call, so that the phone displays caller identifier (ID) information that does not match the caller. Call spoofing may be used by criminals or scammers to present their callback number as a different number than the number they are calling from, such as a trusted number to the recipient or one that is less likely to be immediately identified as belonging to a malicious entity. Many spoofed calls originate from devices on internet protocol (IP) networks using session initiation protocol (SIP) calling to make voice over IP (VoIP) calls to devices on a cellular network. In such examples, a “from” header in an SIP call invitation is end-user-specified, enabling a malicious user to provide a phone number that is not registered to them. Servers and proxies in IP networks typically do not restrict the values in from fields during call routing, even if the values indicate numbers that is not registered to the end-users. Although end-user devices in packet switched networks, such as cellular networks, are not permitted to claim phone numbers the devices are not registered for, the network can modify the from field during call setup to enable legal or illegal call spoofing. As such, a user may be victimized by scammers or criminals when answering a call, even if the phone number that is displayed as the caller ID information appears to be a phone number that is registered to a trusted entity. III. Summary

[0004] According to one implementation of the present disclosure, a device includes a memory configured to store a first phone number indicated by a call invitation message. The device also includes one or more processors coupled to the memory. The one or more processors are configured to receive, from a second device, the call invitation message associated with a call from the second device. The call invitation message indicates the first phone number as an originating phone number of the call. The one or more processors are also configured to send, to the second device, a registry check request that includes the first phone number. The one or more processors are also configured to receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. The one or more processors are also configured to output a call spoofing indicator associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry.

[0005] According to another implementation of the present disclosure, a method includes receiving, by a first device from a second device, a call invitation message associated with a call from the second device. The call invitation message indicates a first phone number as an originating phone number of the call. The method also includes sending, from the first device to the second device, a registry check request that includes the first phone number. The method also includes receiving, by the first device from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. The method also includes outputting, by the first device, a call spoofing indicator associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry.

[0006] According to another implementation of the present disclosure, a non-transitory computer-readable medium stores instructions that are executable by one or more processors to cause the one or more processors to receive, from a second device, the call invitation message associated with a call from the second device. The call invitation message indicates the first phone number as an originating phone number of the call. The instructions also cause the one or more processors to send, to the second device, a registry check request that includes the first phone number. The instructions also cause the one or more processors to receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. The instructions also cause the one or more processors to output a call spoofing indicator associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry.

[0007] According to another implementation of the present disclosure, an apparatus includes means for receiving, from a second device, a call invitation message associated with a call from the second device. The call invitation message indicates a first phone number as an originating phone number of the call. The apparatus also includes means for transmitting, to the second device, a registry check request that includes the first phone number. The apparatus also includes means for receiving, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. The apparatus also includes means for outputting a call spoofing indicator associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry.

[0008] According to another implementation of the present disclosure, a device includes a memory configured to store a registry including one or more unique identifiers (IDs) associated with the device. The device also includes one or more processors coupled to the memory. The one or more processors are configured to receive, from a second device, a registry check request associated with a call at the second device. The registry check request includes a first phone number. The one or more processors are also configured to compare the first phone number to the one or more unique IDs included in the registry. The one or more processors are also configured to, based on the comparison, send, to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0009] According to another implementation of the present disclosure, a method includes receiving, by a first device from a second device, a registry check request associated with a call at the second device. The registry check request includes a first phone number. The method also includes comparing, by the first device, the first phone number to one or more unique IDs included in a registry stored at the first device. The method also includes, based on the comparison, sending, from the first device to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0010] According to another implementation of the present disclosure, a non-transitory computer-readable medium stores instructions that are executable by one or more processors to cause the one or more processors to receive, from a second device, a registry check request associated with a call at the second device. The registry check request includes a first phone number. The instructions also cause the one or more processors to compare the first phone number to the one or more unique IDs included in a registry. The instructions also cause the one or more processors to, based on the comparison, send, to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0011] According to another implementation of the present disclosure, an apparatus includes means for receiving, from a second device, a registry check request associated with a call at the second device. The registry check request includes a first phone number. The apparatus also includes means for comparing the first phone number to one or more unique IDs included in a registry. The apparatus also includes means for transmitting, based on the comparison and to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0012] Other aspects, advantages, and features of the present disclosure will become apparent after review of the entire application, including the following sections: Brief Description of the Drawings, Detailed Description, and the Claims. IV. Brief Description of the Drawings

[0013] FIG. 1 is a block diagram of an example of a system operable to detect call spoofing, in accordance with one or more aspects of the present disclosure.

[0014] FIG. 2 is a block diagram of an example of a wireless communication system configured to support call spoofing detection, in accordance with one or more aspects of the present disclosure.

[0015] FIGs. 3A-3F depict a ladder diagram of an example of a method of detecting call spoofing, in accordance with some aspects of the present disclosure.

[0016] FIGs. 4A-4E are block diagrams of examples of systems associated with operations of the method of FIGs. 3A-3F

[0017] FIG. 5 is a diagram of an example of an integrated circuit operable to detect call spoofing, in accordance with some examples of the present disclosure.

[0018] FIG. 6 is a diagram of a mobile device operable to detect call spoofing, in accordance with some examples of the present disclosure.

[0019] FIG. 7 is a diagram of a wearable electronic device operable to detect call spoofing, in accordance with some examples of the present disclosure.

[0020] FIG. 8 is a diagram of a voice-controlled speaker system operable to detect call spoofing, in accordance with some examples of the present disclosure.

[0021] FIG. 9 is a diagram of a headset operable to detect call spoofing, in accordance with some examples of the present disclosure.

[0022] FIG. 10 is a diagram of a second example of a vehicle operable to detect call spoofing, in accordance with some examples of the present disclosure.

[0023] FIG. 11 is a diagram of an example of a method of detecting call spoofing, in accordance with some aspects of the present disclosure.

[0024] FIG. 12 is a diagram of an example of a method that supports call spoofing detection, in accordance with some aspects of the present disclosure.

[0025] FIG. 13 is a block diagram of an illustrative example of a device that is operable to detect call spoofing, in accordance with one or more aspects of the present disclosure. V. Detailed Description

[0026] The present disclosure provides systems, apparatus, methods, and computer-readable media for call spoofing detection. Aspects disclosed herein enable a user equipment (UE) , such as a smart phone, to perform call spoofing detection prior to, or during, a phone call initiated by another party from a device that is part of the same packet-switched network as the UE (or another packet-switched network that implements common identifier (ID) registration) . For example, a first device (e.g., a UE of a user) may receive a call invitation message to initiate a call with a second device. The call invitation message includes a first phone number that is indicated as an originating phone number associated with the call, although the first phone number may be legitimate or may be a spoofed phone number. The first device may generate and send, to the second device, a registry check request that includes the first phone number. Because the second device implements the same ID registration as the first device, each of the first device and the second device may store registries of unique IDs that are registered with the respective device. Based on receiving the registry check request, the second device generates and sends, to the first device, a registry check response that indicates whether the first phone number is included in the registry stored at the second device. The first device may generate a call spoofing indicator or perform additional actions based on the registry check response. For example, if the registry check response indicates that the first phone number is included in the registry of the second device, the call spoofing indicator indicates that the first phone number is valid as the originating phone number for the call.

[0027] However, if the registry check response indicates that the first phone number is not included in the registry of the second device, the first device may send a call invitation message for a second call to a third device that is associated with the first phone number. This call invitation message indicates a second phone number registered to the first device as an originating phone number of the second call. If the third device confirms receipt of the call invitation message, the first device may generate and send, to the third device, another registry check request that includes the first phone number to cause the third device to provide a registry request response that indicates whether the first phone number is stored in a registry of the third device. If this registry request response indicates that the first phone number is stored in the registry of the third device, the call spoofing indicator output by the first device indicates that the first number is invalid (e.g., is spoofed) as the originating phone number for the call from the second device, and the first device may terminate the call or take action to report the fraudulent use of the first phone number. Alternatively, if the first phone number is not stored in the registry of the third device (as indicated by the registry request response received from the third device) , the call spoofing indicator may indicate that the validity of the first phone number as the originating phone number for the call from the second device is undeterminable, and the call may proceed, or be terminated, based on user input. The first device may also maintain its own registry of unique IDs associated with the first device to enable the first device to respond to registry check requests from other devices performing call spoofing detection in a similar manner.

[0028] Particular implementations of the subject matter described in this disclosure can be implemented to realize one or more of the following potential advantages. In some aspects, the present disclosure provides techniques for call spoofing detection that can detect the validity of an originating phone number of a call provided by another device. In some examples, the techniques disclosed herein enable detection of call spoofing that is performed by an end-user device or by a network that facilitates communication with the end-user device by enabling communication of registry request checks and registry request responses that indicated whether a requested ID (e.g., phone number) is stored in a registry at the requested device. Because the registries are created and maintained as a condition of joining and belonging to the packet-switched network, regardless of if a phone number in a “from” field of a call invitation message is modified, the recipient device is able to request other devices to indicate whether the same phone number is included in their registries, thereby enabling the recipient device to indicate to the user whether the originating phone number is being spoofed with higher accuracy than other call spoofing detection techniques. Improving the accuracy of call spoofing detection enables the systems and methods disclosed herein to prevent users from being victimized by scammers or criminals when answering a call, even if the phone number being displayed as part of caller ID is a fraudulently spoofed phone number.

[0029] Particular aspects of the present disclosure are described below with reference to the drawings. In the description, common features are designated by common reference numbers. As used herein, various terminology is used for the purpose of describing particular implementations only and is not intended to be limiting of implementations. For example, the singular forms “a, ” “an, ” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. Further, some features described herein are singular in some implementations and plural in other implementations. To illustrate, FIG. 1 depicts a device 102 including one or more processors ( “processor (s) ” 108 of FIG. 1) , which indicates that in some implementations the device 102 includes a single processor 108 and in other implementations the device 102 includes multiple processors 108. For ease of reference herein, such features are generally introduced as “one or more” features and are subsequently referred to in the singular or optional plural (as indicated by “ (s) ” ) unless aspects related to multiple of the features are being described.

[0030] In some drawings, multiple instances of a particular type of feature are used. Although these features are physically and / or logically distinct, the same reference number is used for each, and the different instances are distinguished by addition of a letter to the reference number. When the features as a group or a type are referred to herein -e.g., when no particular one of the features is being referenced, the reference number is used without a distinguishing letter. However, when one particular feature of multiple features of the same type is referred to herein, the reference number is used with the distinguishing letter. For example, referring to FIG. 4A, multiple call spoofing managers are illustrated and associated with reference numbers 120A and 120B. When referring to a particular one of these call spoofing managers, such as a call spoofing manager 120A, the distinguishing letter “A” is used. However, when referring to any arbitrary one of these call spoofing managers or to these call spoofing managers as a group, the reference number 120 is used without a distinguishing letter.

[0031] As used herein, the terms “comprise, ” “comprises, ” and “comprising” may be used interchangeably with “include, ” “includes, ” or “including. ” Additionally, the term “wherein” may be used interchangeably with “where. ” As used herein, “exemplary” indicates an example, an implementation, and / or an aspect, and should not be construed as limiting or as indicating a preference or a preferred implementation. As used herein, an ordinal term (e.g., “first, ” “second, ” “third, ” etc. ) used to modify an element, such as a structure, a component, an operation, etc., does not by itself indicate any priority or order of the element with respect to another element, but rather merely distinguishes the element from another element having a same name (but for use of the ordinal term) . As used herein, the term “set” refers to one or more of a particular element, and the term “plurality” refers to multiple (e.g., two or more) of a particular element.

[0032] As used herein, “coupled” may include “communicatively coupled, ” “electrically coupled, ” or “physically coupled, ” and may also (or alternatively) include any combinations thereof. Two devices (or components) may be coupled (e.g., communicatively coupled, electrically coupled, or physically coupled) directly or indirectly via one or more other devices, components, wires, buses, networks (e.g., a wired network, a wireless network, or a combination thereof) , etc. Two devices (or components) that are electrically coupled may be included in the same device or in different devices and may be connected via electronics, one or more connectors, or inductive coupling, as illustrative, non-limiting examples. In some implementations, two devices (or components) that are communicatively coupled, such as in electrical communication, may send and receive signals (e.g., digital signals or analog signals) directly or indirectly, via one or more wires, buses, networks, etc. As used herein, “directly coupled” may include two devices that are coupled (e.g., communicatively coupled, electrically coupled, or physically coupled) without intervening components.

[0033] In the present disclosure, terms such as “obtaining, ” “determining, ” “calculating, ” “estimating, ” “shifting, ” “adjusting, ” etc. may be used to describe how one or more operations are performed. It should be noted that such terms are not to be construed as limiting and other techniques may be utilized to perform similar operations. Additionally, as referred to herein, “obtaining, ” “generating, ” “calculating, ” “estimating, ” “using, ” “selecting, ” “accessing, ” and “determining” may be used interchangeably. For example, “obtaining, ” “generating, ” “calculating, ” “estimating, ” or “determining” a parameter (or a signal) may refer to actively generating, estimating, calculating, or determining the parameter (or the signal) or may refer to using, selecting, or accessing the parameter (or signal) that is already generated, such as by another component or device.

[0034] FIG. 1 is a block diagram of an example of a system 100 operable to detect call spoofing, in accordance with one or more aspects of the present disclosure. The system 100 includes a device 102 and one or more devices 152 that are communicatively coupled together via a network 150. Although referred to in the singular, the network 150 may include one or more networks that are communicatively coupled to each other or that together facilitate communication between the device 102 and the devices 152. For example, the network 150 may include one or more wired networks, one or more wireless networks, or a combination thereof, such as cellular networks, voice over internet protocol (VoIP) networks, the Internet, or the like, as non-limiting examples. The device 102 is operable to detect call spoofing with respect to phone calls from at least some other devices (e.g., the devices 152) , as further explained herein.

[0035] The device 102 includes, or is coupled to, a memory 106, one or more processors 108 (collectively referred to herein as the “processor 108” ) , a microphone 110, an image sensor 112, an input device 114, a display device 116, a speaker 117, and a modem 118. The memory 106 may include one or more memories, such as a single memory or multiple different memories (of the same type or of different types) . The memory 106 is configured to store instructions 109, a registry 130, and one or more call-related phone numbers 134 (referred to herein as “call-related phone numbers 134” ) . The registry 130 is configured to store one or more registered (identifiers) IDs 132 that are registered to the device 102 with respect to the network 150, as further described herein. As an illustrative example, the device 102 may register the registered IDs 132 with a network, such as during a session initiation protocol (SIP) registration process, and the registry 130 may be configured to store the registered IDs 132 obtained during the SIP registration process and associated with the device 102.

[0036] In some examples, the memory 106 further includes or stores the instructions 109 that, when executed by the processor 108, cause the processor 108 to perform one or more operations as described herein. In some examples, the memory 106 stores other information or data, such as other phone numbers or IDs, one or more messages received by the device 102, one or more messages generated for transmission by the device 102, one or more indicators, other information or data, or a combination thereof.

[0037] The processor 108 includes a call spoofing manager 120. The call spoofing manager 120, or a portion thereof, may be implemented by the processor 108 executing instructions (e.g., software) , dedicated hardware (e.g., circuitry) , or a combination thereof. The call spoofing manager 120 is configured to manage call spoofing detection operation (s) , to support call spoofing detection operation (s) at other devices (e.g., the devices 152) , or a combination thereof, for one or more phone calls. In some embodiments, the one or more phone calls include one or more session initiation protocol (SIP) -based calls. Additionally, the processor 108 may include other components that are configured to, or the processor 108 may be configured to, facilitate a phone call (e.g., a SIP-based call) between the device 102 and one or more of the devices 152 during which the call spoofing manager 120 manages various operations described herein.

[0038] In some examples, the call spoofing manager 120 is configured to support call spoofing detection operations at other devices, such as one or more of the devices 152. For example, the call spoofing manager 120 may include a call registry validator 122 configured to generate a registry check response 140 based on a comparison of a phone number included in a registry check request received at the device 102 and the registry 130. The registry check response 140 may indicate whether the phone number indicated in the received registry check request, which may be stored at the memory 106 as the call-related phone numbers 134, is included in the registered IDs 132 of the registry 130 (e.g., one or more unique IDs registered to the device 102) . For example, the registry check response 140 may include a field (or a bit or other indicator) within a message or other signaling, such as a response message, in which a first value of the field (e.g., a logical ‘1’ value) indicates that the received phone number is included in the registered IDs 132 of the registry 130 and a second value of the field (e.g., a logical ‘0’ value) indicates that the received phone number is not included in the registered IDs 132 (e.g., that the received phone number is not registered to the device 102) . The device 102 may send the registry check response 140 to the devices 152, such as in response to a received registry check request associated with a call initiated by the device 102 or a call initiated by one of the devices 152, as further described herein.

[0039] In some examples, the call spoofing manager 120 is configured to perform call spoofing detection operations for the device 102. For example, the call spoofing manager 120 may include a call spoofing detector 124 configured to generate a registry check request 144 that indicates a phone number for which call spoofing detection is being performed and a call spoofing indicator 146 that indicates the results of the call spoofing detection with respect to the phone number. To illustrate, the registry check request 144 may indicate a phone number (e.g., one of the call-related phone numbers 134) that is indicated as an originating phone number of a phone call received by the device 102, and the registry check request 144 may be transmitted (e.g., via the modem 118) to one of the devices 152 to cause the receiving device to determine whether the phone number is included in a respective registry stored at the device. To further illustrate, the call spoofing indicator 146 may indicate, based on a registry check response received by the device 102, whether the phone number is valid as the originating phone number for the phone call, whether the phone number is invalid as the originating phone number for the phone call (e.g., that the phone number is being spoofed) , whether a validity of the phone number as the originating phone number is unconfirmed (e.g., due to one or more devices being unable to receive a phone call from the device 102) , or whether the validity of the phone number as the originating phone number is undeterminable, as further described herein. The call spoofing indicator 146 may be displayed, such as via the input device 114 or the display device 116 to provide a user of the device 102 with the results of the call spoofing detection.

[0040] In some embodiments, the call spoofing detector 124 is configured to initiate the call spoofing detection automatically, such as based on receipt of a call invitation from one of the devices 152 or based on the user selected to answer a phone call associated with a received call invitation. In some other embodiments, the call spoofing detector 124 is configured to initiate the call spoofing detection (e.g., one or more call spoofing detection operations) based on user input. For example, the call spoofing detector 124 may be configured to output an authorization request 142 based on receipt of a call invitation message, or the user selecting to answer the associated phone call. The authorization request 142 may be output via the input device 114 or the display device 116 and may indicate a request for the user to authorize performance of call spoofing detection. The call spoofing detector 124 may be configured to perform the call spoofing detection operations based on a received user input (e.g., input data 115) that is responsive to the authorization request, as further described herein.

[0041] The modem 118 is coupled to the processor 108 and is configured to send data to one or more of the devices 152, receive data from one or more of the devices 152, or a combination thereof. For example, the data transmitted by the modem 118 may include the registry check response 140, the registry check request 144, a call invitation message associated with a call to one or more of the devices 152, other messages, or a combination thereof. As another example, the data received by the modem 118 may include a registry check request from one or more of the devices 152, a call invitation message associated with a call from one or more of the devices 152, a registry check response from one or more of the devices 152, an invitation response from one or more of the devices 152, an error message from one or more of the devices 152, other types of messages or signaling, or a combination thereof.

[0042] The processor 108 is also coupled to the microphone 110, the image sensor 112, the input device 114 (e.g., another microphone, a keyboard or touch screen, etc. ) , the display device 116, and the speaker 117. The microphone 110 may include one or more microphones (e.g., audio capture device (s) ) and be configured to generate audio data 111, such as audio data that represents user speech associated with a phone call between the device 102 and one of the devices 152. The image sensor 112 may include one or more cameras and may be configured to generate image data 113, such as one or more images or video frames associated with a multimedia call. The input device 114 is configured to receive an input and provide the input to the processor 108 as input data 115. For example, the input device 114 may include a keyboard, a touch screen, or a microphone configured to receive the input (e.g., a user input) and provide the input data 115 (e.g., an input signal) to the processor 108.

[0043] The display device 116 is coupled to the processor 108 and is configured to output visual outputs for display to a user, such as images or video associated with a phone call or a multimedia call between the device 102 and the devices 152, the authorization request 142, or the call spoofing indicator 146. In some examples, the display device 116 includes a display screen, a monitor or television, a projector, or a combination thereof. The speaker 117 includes one or more speakers coupled to the processor 108 and is configured to output audio to the user, such as audio associated with a phone call or a multimedia call between the device 102 and the devices 152.

[0044] The microphone 110, the image sensor 112, the input device 114, the display device 116, the speaker 117, or a combination thereof, may be coupled to or integrated within the device 102. In some implementations, one or more of the microphone 110, the image sensor 112, the input device 114, the display device 116, or the speaker 117 may be included in another device that is coupled (e.g., communicatively coupled) to the device 102. For example, the other device may include a mobile device (e.g., a smart phone) or a wearable device (e.g., a smartwatch or headset) that includes the microphone 110, the image sensor 112, the input device 114, the speaker 117, or a combination thereof. Although the device 102 is described as being coupled to or including the microphone 110, the image sensor 112, the input device 114, the display device 116, the speaker 117, and the modem 118, in other embodiments such elements are optional and, in such embodiments, the device 102 may not include or be coupled to the microphone 110, the image sensor 112, the input device 114, the display device 116, the speaker 117, the modem 118, or a combination thereof.

[0045] During operation of the system 100, the device 102 can perform call spoofing detection, support call spoofing detection at other devices, or both. To illustrate an example of call spoofing detection performed by the device 102, the device 102 may receive a call invitation message from a second device (e.g., one of the devices 152) . The call invitation message is associated with a call from the second device. For example, the second device may initiate a call with the device 102 (e.g., a first device) by sending a call invitation message that triggers a message exchange process to initiate a call between the second device and the device 102. The call invitation message may include various information associated with the call, such as an originating phone number, a destination phone number, other information, or a combination thereof. In this example, the call invitation message indicates a first phone number as an originating phone number of the call, and the device 102 may store the first phone number at the memory 106 as one of the call-related phone numbers 134.

[0046] In some embodiments, the call is a SIP-based call, and the call invitation message complies with the SIP protocol. In some such embodiments, as part of a registration process (e.g., a SIP registration process) , the device 102 registers one or more identifiers (IDs) associated with the device 102 and stores these IDs as the registered IDs 132 in the registry 130. For example, as part of the SIP registration process, the device 102 may register one or more phone numbers, one or more device IDs, or the like, as the registered IDs 132 that are stored in the registry 130 in the memory 106, and optionally with one or more wireless networks, such as one or more cellular networks. Additionally, other devices including the second device (e.g., the devices 152) similarly register and store respective registered IDs as part of a registration process for communication via the same wireless communication network (s) . In some other embodiments, the call invitation message may comply with a different protocol or communication standard, and the registry 130 may be maintained according to different rules.

[0047] To protect the user from being the target of fraudulent, spoofed phone calls, the device 102 may initiate or offer call spoofing detection operations when a call is received. In some embodiments, the device 102 automatically initiates call spoofing detection. For example, the processor 108 (e.g., the call spoofing manager 120) may initiate one or more call spoofing detection operations based on receipt of the call invitation message from the second device prior to connecting the call. In some other embodiments, call spoofing detection may be initiated by the user. For example, based on receipt of the invitation message, the call spoofing detector 124 may output an authorization request 142 to request user permission to initiate one or more call spoofing detection operations. The device 102 may provide the authorization request 142 to the user, such as by displaying the authorization request 142 via the display device 116, outputting audio of text-to-speech (TTS) conversion of the authorization request 142 via the speaker 117, or using other techniques. The authorization request 142 may include a prompt to the user requesting input to confirm initiation of call spoofing detection operations. The user can allow call spoofing detection to be performed by providing a user input to the device 102 responsive to the authorization request 142. For example, the device 102 may receive a user input responsive to the authorization request 142 via the input device 114, such as the user providing input via a keypad, a touchscreen, or the like, and the input data 115 may indicate the user input. The call spoofing detector 124 may initiate performance of call spoofing detection operations based on the input data 115 that is provided in response to the authorization request 142. For example, if the input data 115 indicates that the user wishes to proceed with call spoofing detection, the call spoofing detector 124 may initiate performance of one or more operations described below. Alternatively, if the input data 115 indicates that the user does not wish to proceed with the call spoofing detection, the call spoofing manager 120 may refrain from performing call-spoofing detection operations, and the processor 108 may connect the call. Although described as being performed upon receipt of the call invitation message, the output of the authorization request 142 may be provided to the user for one or more time periods during the call, such that the user can select to perform call spoofing detection even after a call has already been connected.

[0048] If call spoofing detection operations are initiated, either automatically or based on user input (e.g., the input data 115 indicating an instruction to initiate one or more call spoofing detection operations) , the processor 108 (e.g., the call spoofing detector 124) may generate a registry check request 144 for transmission from the device 102 to the second device (e.g., one of the devices 152) . The registry check request 144 includes the first phone number that was indicated as an originating phone number in the call invitation message received by the device 102. For example, the registry check request 144 may indicate a request for the second device to provide a response that indicates whether the first phone number is stored in the respective registry of the second device. Additional examples of registry check requests are described further herein with reference to FIGs. 3A-3F and 4A-4E.

[0049] Based on sending the registry check request 144, the device 102 may receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. To illustrate, if the second device is similarly compliant with the registration of IDs described herein with reference to the device 102, the device 102 may receive a registry check response from the second device (e.g., one of the devices 152) . If the first phone number is associated with the second device (e.g., if the first phone number has been registered by the second device) , the registry check response indicates confirmation that the first phone number is included in the registered IDs stored at the registry of the second device. Alternatively, if the first phone number is not associated with the second device (e.g., if the first phone number has not been registered by the second device) , the registry check response indicates that the first phone number is not stored in the registry of the second device. If the second device does not comply with the ID registration, or if the second device cannot be reached, the device 102 may receive an error message or another response instead of the registry check response in response to sending the registry check request 144, as further described herein with reference to FIGs. 3A-3F and 4A-4E.

[0050] Based at least in part on the registry check response or the other response received by the device 102, the call spoofing detector 124 outputs a call spoofing indicator 146 that is associated with the call and that may indicate whether call spoofing is detected. To illustrate, based on the registry check response indicating that the first phone number is stored in the registry of the second device, the call spoofing indicator 146 indicates that the first phone number is valid as the originating phone number for the call. However, if there is no response from the second device or the device 102 receives an error message (or other indicator that registry check requests are not supported) , the call spoofing indicator 146 indicates that a validity of the first phone number as the originating phone number for the call is undeterminable. Alternatively, if the registry check response indicates that the first phone number is not stored in the registry of the second device (e.g., the device that originated the call) , the device 102 may initiate a call, or a SIP-connection, with a third device as part of the call spoofing detection operations.

[0051] To illustrate, in response to the registry check response indicating that the first phone number is not stored in the registry of the second device, the processor 108 (e.g., the call spoofing detector 124) may generate a second call invitation message as part of a second call, or at least a second SIP connection process. The second call invitation message may indicate a second phone number that is included in the registered IDs 132 stored in the registry 130 as the originating phone number and the first phone number as a target phone number. The device 102 may send in association with a second call from the device 102, the second call invitation message to the wireless communication network, and the second call invitation message may be routed to a third device (e.g., another one of the devices 152) by the wireless communication network. For example, if the third device is associated with the first phone number at the wireless communication network, the second call invitation message may be routed to the third device. The device 102 may receive an invitation response that is responsive to the second call invitation message. For example, if the third device does not respond to the second call invitation message, the wireless communication network may provide an invitation response that indicates that the third device is unavailable. Based on receiving such an invitation response, the call spoofing detector 124 outputs the call spoofing indicator 146 that indicates that a validity of the first phone number as the originating phone number for the call is unconfirmed (e.g., based on the invitation response indicating that the other device is unable to receive the second call) . As another example, if the third device receives the second call invitation message, the third device may send an invitation response that begins a call connection process with the device 102.

[0052] If the invitation response indicates that the third device is available (e.g., is able to receive the second call) , the call spoofing detector 124 generates a second registry check request for transmission to the third device by the device 102. Similar to as described above, the second registry check request includes the first number and requests the third device to provide an indication whether the first number is stored in a respective registry of the third device. If the third device complies with the registration of IDs described herein, the device 102 receives, from the third device, a second registry check response that indicates whether the first phone number is included in the registry associated with the third device. If the second registry check response indicates that the first phone number is included in the registry of the third device, the call spoofing detector 124 generates the call spoofing indicator 146 that indicates that the first phone number is invalid as the originating phone number. In this example, the first call may be an instance of call spoofing due to the second device providing a phone number that is registered to the third device as the originating phone number for a call initiated by the second device. In some embodiments, the call spoofing indicator 146 may indicate to the user of the device 102 the invalidity of the first call, and optionally provide the user with one or more options for additional call spoofing management, such as terminating the call, logging the call, reporting the call, sending the call to voicemail, other actions, or a combination thereof. In some other embodiments, the call spoofing manager 120 may automatically terminate the first call based on the call spoofing indicator 146 indicating that the first phone number is invalid.

[0053] If the second registry check response indicates that the first phone number is not stored in the registry of the third device, or if the third device provides a response that indicates that registry check requests are not supported, the call spoofing detector 124 generates the call spoofing indicator 146 that indicates that a validity of the first phone number as the originating phone number for the call is undeterminable. In some embodiments, the call spoofing indicator 146 may also include one or more options for additional actions by the user, such as continuing or terminating the call, logging the call, etc. Alternatively, the device 102 may display or otherwise provide the call spoofing indicator 146 to the user and continue with the call if the call spoofing indicator 146 indicates that the validity is undeterminable. If the call spoofing detection is performed prior to acceptance of the first call, the call spoofing indicator 146 is output prior to acceptance of the first call (and optionally the first call is further initiated based on user input replying to the call spoofing indicator 146) . Alternatively, if the call spoofing indicator 146 is output during performance of one or more call operations, the call spoofing manager 120 may provide a prompt for additional actions, such as enabling a user to terminate call or automatically performing a preset action that is stored at the memory 106. In this manner, the call spoofing manager 120 and the call spoofing detector 124 operate to detect phone calls in which call spoofing may be occurring and to provide the user of the device 102 with relevant information (e.g., the call spoofing indicator 146) to protect themselves from being victimized by malicious actors.

[0054] As described above, in addition to performing call spoofing detection, the device 102 can also support call spoofing detection by other devices. To illustrate an example of call spoofing detection support performed by the device 102, the device 102 may receive a registry check request from a second device (e.g., one of the devices 152) . The registry check request, which is similar to the registry check request 144 generated by the call spoofing detector 124, is associated with a call between the second device and the device 102 and includes a phone number (referred to here as a “requested phone number” ) associated with a request to check whether the phone number is stored as one of the registered IDs 132 at the registry 130. In some examples, the call associated with the received registry check request may be initiated by the device 102 (e.g., the device 102 may be the “second device” in the above-described call spoofing detection example) . To illustrate, the device 102 may send, prior to receipt of the registry check request from second device, a call invitation message associated with the call to the second device. In this example, the call invitation message indicates the requested phone number as an originating phone number of the call, and the second device sends the registry check request to the device 102 to detect whether the originating phone number for the call is being spoofed. In some other examples, the call associated with the registry check request is initiated by the second device (e.g., the device 102 may be the “third device” in the above-described call spoofing detection example) . To illustrate, the device 102 may receive, prior to receipt of the registry check request, a call invitation message associated with the call from the second device, and the call invitation message may be part of a call connection process. In both examples, the call may be a SIP-based call, as described above.

[0055] Based on receiving the registry check request, the processor 108 (e.g., the call registry validator 122) may compare the requested phone number to the registered IDs 132 included in the registry 130 and, based on a result of the comparison, the call registry validator 122 may generate a registry check response 140 for transmission to the second device. The registry check response 140 indicates whether the requested phone number is included in the registry 130 (e.g., whether the requested phone number is one of the registered IDs 132) . For example, if the requested phone number is included in the registered IDs 132 (e.g., the requested phone number is registered to the device 102) , the registry check response 140 indicates confirmation that the requested number is stored at the registry 130 associated with the device 102. However, if the requested phone number is not included in the registered IDs 132 (e.g., the requested phone number is not registered to the device 102) , the registry check response 140 indicates that the requested number is not stored at the registry 130. The second device may receive the registry check response 140 from the device 102 and perform one or more of the call spoofing detection operations described above, such as generating a call spoofing indicator for a user of the second device.

[0056] In some examples, the device 102 corresponds to or is included in one of various types of devices, such that the processor 108 can be integrated in multiple types of devices. In an illustrative example, the processor 108 is integrated in a wearable device, such as a headset as depicted in FIG. 9, a wearable electronic device as depicted in FIG. 7, or another wearable device. In another illustrative example, the processor 108 is integrated in a mobile device (amobile phone or a tablet) as depicted in FIG. 6, a voice-controlled speaker system as depicted in FIG. 8, a vehicle as depicted in FIG. 10, a computer or a server, or another system or device.

[0057] In a particular example, the device 102 includes a memory (e.g., the memory 106) configured to store a first phone number (e.g., one of the call-related phone numbers 134) indicated by a call invitation message. The device 102 also includes one or more processors (e.g., the processor 108) coupled to the memory. The one or more processors are configured to receive, from a second device (e.g., one of the devices 152) , the call invitation message associated with a call from the second device. The call invitation message indicates the first phone number as an originating phone number of the call. The one or more processors are also configured to send, to the second device, a registry check request (e.g., the registry check request 144) that includes the first phone number. The one or more processors are configured to receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. The one or more processors are also configured to output (e.g., to the input device 114, the display device 116, or the speaker 117) a call spoofing indicator (e.g., the call spoofing indicator 146) associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry.

[0058] In another particular example, the device 102 includes a memory (e.g., the memory 106) configured to store a registry (e.g., the registry 130) including one or more unique IDs (e.g., the registered IDs 132) associated with the device 102. The device 102 also includes one or more processors (e.g., the processor 108) coupled to the memory. The one or more processors are configured to receive, from a second device (e.g., one of the devices 152) , a registry check request associated with a call at the second device. The registry check request includes a first phone number (e.g., one of the call-related phone numbers 134) . The one or more processors are configured to compare the first phone number to the one or more unique IDs included in the registry. The one or more processors are also configured to, based on the comparison, send, to the second device, a registry check response (e.g., the registry check response 140) that indicates whether the first phone number is included in the registry.

[0059] One technical advantage of implementing the device 102 as described above is that the call spoofing manager 120 supports call spoofing detection with higher accuracy than other devices that attempt to detect call spoofing. For example, because the call spoofing manager 120 communicates with the devices 152 using the registry check request 144 and an associated registry check response, the call spoofing manager 120 is able to detect whether an originating phone number associated with a call is stored in a registry of the device that initiates the call, or another device associated with the phone number, which enables detection of call spoofing regardless of whether the spoofing is performed at the end-device level or the network-level. The improved accuracy of the call spoofing detection provided by the call spoofing manager 120 enables the device 102 to prevent a user from being victimized by scammers or criminals when answering a phone call, even if the phone number being displayed as part of caller ID is a fraudulently spoofed phone number. Additionally, or alternatively, because the call spoofing manager 120 can respond to a received registry check request with the registry check response 140 that indicates whether a phone number is stored at the registered IDs 132, the call spoofing manager 120 enables the device 102 to support call spoofing detection at other devices that maintain similar registries (e.g., other devices associated with the same service provider, the same manufacturer, or a service provider or manufacturer that implements the registry protocols described herein) . Supporting call spoofing detection for other devices enables the device 102 to increase the trust associated with phone calls initiated by the user, thereby increasing the likelihood that the user is able to participate in a wide variety of beneficial telecommunications.

[0060] FIG. 2 is a block diagram of an example of a wireless communication system 200 configured to support call spoofing detection, in accordance with one or more aspects of the present disclosure. In some embodiments, the wireless communication system 200 may include or correspond to the system 100 of FIG. 1 (or elements thereof) . For example, a UE 260 of the wireless communication system 200 may include or correspond to the device 102 of FIG. 1.

[0061] In the example illustrated in FIG. 2, the wireless communication system 200 includes an internet protocol (IP) multimedia subsystem (IMS) service / application layer 202, an IMS control layer 210, and an IMS transport layer 230 that include or correspond to one or more wireless communication networks and supporting architecture. The IMS service / application layer 202, the IMS control layer 210, and the IMS transport layer 230 may support an IMS architecture that hosts and supports services, such as calls (e.g., phone calls, voice over internet protocol (VoIP) calls, etc. ) , messaging services, and the like, between devices of one or more network infrastructures. In some implementations, the IMS may be implemented by a single service provided. In other implementations, the IMS may be implemented or shared by multiple service providers that provide a common service, such as SIP calls, and that have common registration processes for IDs of devices that participate in the service. Although the wireless communication system 200 is described in the context of a SIP server, in other embodiments, the wireless communication system 200 may be compliant with a different communication protocol or standard.

[0062] In the example shown in FIG. 2, the IMS service / application layer 202 includes SIP application servers (AS) 204 and SIP AS back-to-back user agents (B2BUA) 206. The IMS control layer 210 includes a home subscriber server (HSS) 212, a SIP server operating as a serving call session control function (S-CSCF) 214 (referred to herein as the “S-CSCF server 214” ) , a call session control function (CSCF) 216, a breakout gateway control function (BGCF) 224, a media gateway control function (MGCF) 226, and a media gateway (MGW) 228. In some embodiments, the CSCF 216 includes a SIP server operating as a S-CSCF 218 (referred to herein as the “S-CSCF server 218” ) , an interrogating call session control function (I-CSCF) 220, and a SIP proxy operating as a proxy call session control function (P-CSCF) 222 (referred to herein as the “P-CSCF proxy 222” ) . The IMS transport layer 230 includes a virtual SIP IP-based phone system (virtual SIP IP-based PBX) 232, Internet 234, a public land mobile network (PLMN) packet-switched core network 236, a radio access network 238 (e.g., a 4G or 5G network) , and a circuit-switched network 240 (e.g., a public switched telephone network (PSTN) network, a 2G network, or a 3G network circuit switched (CS) network) . In other embodiments, the IMS service / application layer 202, the IMS control layer 210, the IMS transport layer 230, or a combination thereof, may include fewer elements, more elements, or different elements than shown in FIG. 2.

[0063] The wireless communication system 200 also includes multiple end devices or user devices coupled to the various networks included in the IMS transport layer 230. For example, the wireless communication system 200 may include a user equipment (UE) 250, a UE 252, a physical SIP IP PBX 254, a UE 256, a UE 258, a UE 260, and a UE 262, as non-limiting examples. Each of the devices 250-262 may be included in one or more networks that access the wireless communication system 200 via one or more of the transport-layer networks of the IMS transport layer 230. To illustrate, an IP network 242 may include the UE 250, the UE 252, the physical SIP IP PBX 254, the UE 256, and the UE 258. The UE 250 and the UE 252 may access the IMS transport layer 230 via the virtual SIP IP PBX 232, and the UE 256 and the UE 258 may be communicatively coupled to the physical SIP IP PBX 254, which accesses the IMS transport layer 230 via the Internet 234. To further illustrate, a PLMN 244 may include the UE 260 that accesses the IMS transport layer 230 via the radio access network 238 and the PLMN packet-switched core network 236, and a PSTN 246 may include a UE 262 that accesses the IMS transport layer 230 via the circuit-switched network 240.

[0064] Call spoofing may occur in an IMS, such as the wireless communication system 200, when a caller deliberately falsifies the information transmitted to a caller ID display to disguise their identity. Call spoofing may not be illegal, or be performed for non-malicious purposes, such as: an online-to-offline (O2O) platform, such as a car-hailing app or a food delivery app, where a customer and an offline order taker use an intermediate phone number selected by the platform to communicate; a real-estate agent intermediate phone number listed on the website; or a business phone system in which employees can use any phone extension for internal calls but they share a finite set of business phone numbers for external calls. However, call spoofing may also be performed by a malicious actor to obscure their phone number and to gain the trust associated with a phone number being spoofed, in order to scam a user or perform other criminal or illegal activities.

[0065] A cause of most call spoofing is that the incoming phone number displayed at the callee (e.g., the party being called) is from an invitation message (e.g., SIP INVITE) “From” header field. Call spoofing is often initiated from an IP network on a VoIP softphone. To illustrate, when the VoIP SIP call is initiated from IP network, the SIP INVITE “From” header field is end-user-specified, such that it can be filled with any phone number the caller (e.g., the party calling) wants. For example, to establish a call from the UE 252 to the UE 260, the UE 252 may send a SIP invite 270 to the UE 260. The SIP invite 270 may include any user-selected number as the indicated originating phone number, regardless of whether the user-selected number is associated with the UE 252. PBX SIP Proxies do not restrict any “From” header field value specified by the user during the SIP dialog establishment. On the contrary, PBX providers which market “wholesale VoIP” are typically intended to allow any displayed number to be sent, as resellers want their end user’s numbers to appear in the caller ID of the callees. With open-source software, a malicious actor can spoof calls with minimal cost and effort, which can be abused by the malicious actor to spoof their phone number as another’s phone number to deceive the callee.

[0066] Call spoofing can also originate from devices on the same PLMN during a cellular IMS call without a VoIP app at the calling UE. To illustrate, when call spoofing is initiated from the PLMN 244, it is the network (e.g., the SIP AS 204 or the SIP AS B2BUA 206) , not the calling UE, that modifies the “From” header field and / or the “To” header field during the call setup. A UE within the PLMN 244 cannot illegitimately claim any other phone number not belonging to it, because the CSCF 216 can check the HSS 212 to determine an entire set of phone number that the UE can legitimately claim, and UE is restricted to claim its phone number to one from that set. The CSCF 216 (e.g., a PLMN CSCF) will correct the “From” header field when a UE specifies a phone number that is not associated with (e.g., registered with) the UE. This contrasts with normal SIP usage, where the “From” header field is explicitly an end-user-specified field. This can result in some PLMNS blocking legitimate uses for changing phone numbers in addition to attempting to block illegitimate call spoofing. Such legitimate use cases can include: an intermediate phone number selected by the platform, such as for car-hailing apps or food delivery apps, as compared to illegitimate cases such as caller ID faking software. In this case, the SIP AS 204 supports callback to caller and the SIP AS B2BUA 206 connects to the callee, with any phone number specified by the caller via the website or caller ID faking software.

[0067] To prevent illegitimate uses of call spoofing by malicious actors, systems and methods described herein perform call spoofing detection operations and support call spoofing operations at other devices. For example, the UE 260 may include the call spoofing manager 120 that is configured to perform the call spoofing detection operations, the call spoofing detection support operations, or both, described with reference to FIG. 1. For example, in response to receiving a call from a second device of the PLMN 244 (or to a user input triggering call spoofing detection operations) , the UE 260 may send a registry check request 272 to a second device of the PLMN 244 to determine whether an originating phone number associated with the received call is registered to the second device. Depending on a response to the registry check request 272, the call spoofing manager 120 of the UE 260 may output a call spoofing indicator to indicate to a user of the UE 260 whether the originating phone number is valid, invalid, or whether a validity is undeterminable or has not been determined, as described above with reference to FIG. 1. Additional details and examples of call spoofing detection are also further described herein, with reference to FIGs. 3A-3F and 4A-4E.

[0068] In some embodiments, the wireless communication system 200 supports exchange of secure messages between peer UEs to check whether IDs are stored in respective registries. For example, the session initiation protocol may include (or be extended to include) that each device maintains one or more uniform resource identifiers (URIs) associated with the device in a private list of associated URIs (a “PAU list” ) , and that devices be configured to support register requests from peer devices with an indication whether a URI included in the request is included in the PAU list of the device. For example, receipt of the registry check request 272 by another UE may cause the other UE to determine whether a URI, which can include a phone number, is included in the other UE’s PAU and provide the result, which may enable the UE 260 to output a call spoofing indicator that indicates whether an originating phone number of a call is valid, invalid, or cannot be determined, as described above with reference to FIG. 1.

[0069] FIGs. 3A-3F depict a ladder diagram of an example of a method 300 of detecting call spoofing, in accordance with some aspects of the present disclosure. Each of FIGs. 3A-3F illustrate one or more respective operations of the method 300. The method 300 may be performed by a device 302 (corresponding to a first user, “User A” ) , one or more wireless networks 304 (referred to herein collectively as the “wireless network (s) 304” ) , a device 306 (corresponding to a second user, “User B” ) , and a device 308 (corresponding to a third user, “User C” ) . The wireless networks 304 include or correspond to one or more wireless networks, such as one or more cellular networks, operated by one or multiple service providers, that enable wireless communication of calls between the device 302 and the device 306, and between the device 306 and the device 308. In embodiments, the wireless network (s) 304 support SIP call services and provide for devices to register IDs used to access the SIP call services in respective registries, as described above with reference to FIG. 1.

[0070] Operations of the method 300 of FIGs. 3A-3F will be described with reference to FIGs. 4A-4E, which are block diagrams of examples of systems associated with operations of the method 300 of FIGs. 3A-3F. For example, each of FIGs. 4A-4E may illustrate a respective system 400 that is configured to support at least some of the operations described with reference to the method 300 of FIGs. 3A-3F to support call spoofing detection. In the examples illustrated in FIGs 4A-4E, the system 400 includes the device 302, the device 306, and the network (s) 304. In the examples illustrated in FIGs. 4C-4E, the system 400 also includes the device 308. The devices 302, 306, and 308 may each include a respective call spoofing manager 120. For example, the device 302 includes the call spoofing manager 120A, the device 306 includes the call spoofing manager 120B, and the device 308 includes the call spoofing manager 120C. In some examples, the device 302, the device 306, and the device 308 may each include or correspond to one or more of the device 102 or the devices 152 of FIG. 1 or the UE 260 or the UEs 252, 256, or 258 of FIG. 2.

[0071] Referring to FIG. 3A, the method 300 begins at 320, and the device 302 sends a call invitation message to the device 306. For example, as shown in FIG. 4A, the device 302 may send a call invitation message 410 to the device 306 via the wireless network (s) 304 to initiate a call to the device 306. The call invitation message 410 includes a first phone number 412 that is indicated as the originating number for the call. In this example, the device 302 (e.g., User A) is the caller and the device 306 (e.g., User B) is the callee, with respect to the call. As described above with reference to FIG. 2, because SIP call invitation messages include a “From” field that can be defined by the end-user (e.g., the device 302) , the first phone number 412 included in the call invitation message 410 may not be the actual phone number of the caller. Although only a single message (e.g., the call invitation message 410) is illustrated as being exchanged, additional signaling or messaging to facilitate a SIP call between the device 302 and the device 306 may also be exchanged, such as ringing requests, acknowledgements (ACKs) , negative acknowledgements (NACKs) , other signaling or messaging, or a combination thereof.

[0072] At 322, the device 306 initiates call spoofing detection (e.g., performance of one or more call spoofing detection operations are initiated) . For example, the device 306 may automatically initiate the call spoofing detection operations based on receipt of the call invitation message 410. As another example, the device 306 may initiate the call spoofing detection operations based on receipt of user input that indicates a command to initiate call spoofing detection (e.g., based on the input data 115 of FIG. 1) . As such, the call spoofing detection may be performed before setting up the call between the device 302 and the device 306 (e.g., between User A, as caller, and User B, as callee) , or optionally the call spoofing detection can be initiated after the call is set up and in progress between the parties. For example, upon receiving the call invitation message 410, the device 306 may output a user interface (UI) that indicates “Accept, decline or spoofing call screen” options to User B (e.g., the callee) . If User B selects “Accept” , the “spoofing call screen” option may still be provided for a particular time period or for a duration of the call. Upon User B selecting “spoofing call screen, ” the device 306 may initiate one or more call spoofing detection operations. In some embodiments, the one or more call spoofing operations include requesting additional consent from User B, such as by outputting an additional UI requesting consent or confirmation to continue.

[0073] At 324, the device 306 generates and sends a registry check request to the device 302. For example, as shown in FIG. 4A, the device 306 may send a registry check request 414 to the device 302 via the wireless network (s) 304. The registry check request 414 includes the first phone number 412 (e.g., the registry check request 414 indicates a request for the recipient device to check whether the first phone number 412 is included in a registry of the recipient device) . Although described as a registry check request, in other embodiments, the registry check request 414 may be a different type of message or signaling. As an illustrative example, the registry check request 414 may include or correspond to a field included in a SIP information message.

[0074] At 326, the device 302 determines whether storing IDs within a registry is enabled (e.g., whether processing of registry check requests is enabled) . If storing IDs in a registry is not enabled at the device 302, the method 300 proceeds to 336 of FIG. 3B, described further below. Alternatively, if storing IDs in a registry is enabled at the device 302, the method 300 continues to 328.

[0075] At 328, the device 302 determines whether the requested phone number is stored in a registry at the device 302. For example, as shown in FIG. 4A, the device 302 may compare the first phone number 412 to a call registry 408 maintained by the call spoofing manager 120B to determine if the first phone number 412 matches one of the stored IDs within the call registry 408. If the first phone number 412 is not stored in the call registry 408, the method 300 proceeds to 342 of FIG. 3C, described further below. Alternatively, if the first phone number 412 is stored in the call registry 408, the method 300 continues to 330.

[0076] At 330, the device 302 generates and sends a registry check response to the device 306. For example, as shown in FIG. 4A, the device 302 may send a registry check response 416 to the device 306 via the wireless network (s) 304, and the device 306 may receive and process the registry check response 416. The registry check response 416 includes an indicator 418 that indicates whether the first phone number 412 is included in the call registry 408 associated with the device 302. In the example shown in FIG. 4A, the indicator 418 indicates that the first phone number 412 is stored in the call registry 408 (e.g., that the first phone number 412 is registered to the device 302) . To illustrate, the indicator 418 may include or correspond to a field of the registry check response 416 that is set to a value that indicates ‘true’ .

[0077] At 332, the device 306 outputs a call spoofing indicator associated with the call (e.g., with the device 302) based on the received registry check response. For example, as shown in FIG. 4A, the call spoofing manager 120A of the device 306 may generate a spoofing indicator 420 based on the indicator 418 included in the registry check response 416. In this example, because the first phone number 412 is included in the IDs stored at the call registry 408 associated with the device 302, the spoofing indicator 420 indicates that the first phone number 412 is valid as the originating phone number for the call. The method 300 continues to 334 and, because the originating phone number is valid, the device 302 and the device 306 perform one or more operations to establish, or facilitate, the call between the device 302 and the device 306. The method 300 terminates after establishing, or facilitating, the call. As can be appreciated, the example described with reference to FIG. 4A represents successful validation of the originating phone number of the call, which provides the user of the device 306 with confidence that the call is not being spoofed.

[0078] Returning to 326 of FIG. 3A, if storing IDs in a registry is not enabled at the device 302, the method 300 proceeds to 336 of FIG. 3B. At 336, the device 302 generates and sends an error message to the device 306. For example, as shown in FIG. 4B, the device 302 does not include the call spoofing manager 120B or the call registry 408 of FIG. 4A, and therefore responds to the registry check request 414 by sending an error message 430 to the device 306. Although described as an error message, in other embodiments, the error message 430 can instead be any type of message that indicates that the device 302 is not configured to support the registry check request 414.

[0079] At 338, the device 306 outputs a call spoofing indicator associated with the call (e.g., with the device 302) based on the received error message. For example, as shown in FIG. 4B, the call spoofing manager 120A of the device 306 may generate a spoofing indicator 432 based on the error message 430. In this example, because the device 302 is unable to perform a registry check, the spoofing indicator 432 indicates that a validity of the first phone number 412 as the originating phone number for the call is undeterminable.

[0080] The method 300 continues to 340 and the device 302 and the device 306 perform one or more operations to establish, or facilitate, the call between the device 302 and the device 306. The method 300 terminates after establishing, or facilitating, the call. In other embodiments, instead of establishing, or facilitating, the call at 340, the device 306 may terminate the call due to the validity of the first phone number 412 as the originating phone number being undeterminable. For example, the user of the device 306 may configure settings of the device 306 to terminate calls for which the originating phone number cannot be verified. As can be appreciated, the example described with reference to FIG. 4B represents a situation in which the validation of the originating phone number of the call is not possible due to the device 302 not supporting registry checks, which results in the spoofing indicator 432 providing the user of the device 306 with information indicating that the caller (User A) may be using a virtual number, such as used by ride-share applications, delivery applications, offices, or the like, or that call spoofing is occurring but cannot be confirmed.

[0081] Returning to 328 of FIG. 3A, if the first phone number 412 is not stored in the call registry 408, the method 300 proceeds to 342 of FIG. 3C. At 342, the device 302 generates and sends a registry check response to the device 306 to indicate that the first phone number 412 is not stored in the call registry 408. For example, as shown in FIG. 4C, the device 302 may send the registry check response 416 to the device 306 via the wireless network (s) 304, and the device 306 may receive and process the registry check response 416. The registry check response 416 includes an indicator 440 that indicates whether the first phone number 412 is included in the call registry 408 associated with the device 302. In the example shown in FIG. 4C, the indicator 440 indicates that the first phone number 412 is not stored in the call registry 408 (e.g., that the first phone number 412 is not registered to the device 302) . To illustrate, the indicator 440 may include or correspond to a field of the registry check response 416 that is set to a value that indicates ‘false’ . The device 306 receives the registry check response 416 and based on the indicator 440, determines that call spoofing may be occurring, and thus performs additional call spoofing detection operations.

[0082] At 344, the device 306 sends a call invitation message to the device 308. For example, as shown in FIG. 4C, the device 306 may send a call invitation message 442 to the device 308 via the wireless network (s) 304 to initiate a second call to the device 308. The call invitation message 442 includes the first phone number 412 that is indicated as a target number for the second call and a second phone number 444 that is indicated as an originating number for the second call. The second phone number 444 is included in a registry maintained by the call spoofing manager 120A of the device 306 (e.g., the second phone number 444 is a phone number that is registered to the device 306) . In this example, the device 306 (e.g., User B) is the caller and the device 308 (e.g., User C) is the callee, with respect to the second call. Because the device 302 indicated that the originating number (e.g., the first phone number 412) of the call between the device 302 and the device 306 is not registered to the device 302, the device 306 sends the call invitation message 442 to initiate a call with the party associated with the first phone number 412 (e.g., the device 308) . Although the call invitation message 442 is described as being sent by the device 306 to the device 308, the call invitation message 442 may be sent to the wireless network (s) 304, and a network node of the wireless network (s) 304 may route the call invitation message 442 to the device 308. Although only a single message (e.g., the call invitation message 442) is illustrated as being exchanged, additional signaling or messaging to facilitate a SIP call between the device 306 and the device 308 may also be exchanged, such as ringing requests, ACKs, NACKs, other signaling or messaging, or a combination thereof.

[0083] At 346, a determination is made whether the device 308 is able to receive the second call. If the device 308 is able to receive the second call (e.g., the call invitation message 442) , the method 300 proceeds to 354 of FIG. 3D, which is further described below. Alternatively, if the device 308 is not able to receive the second call (e.g., User C does not answer, the device 308 is on another call, a party associated with the first phone number 412 cannot be found, etc. ) , the method 300 continues to 348.

[0084] At 348, the device 306 receives an error message that is responsive to the call invitation message. For example, as shown in FIG. 4C, the device 308 may send an error message 446 to the device 306 via the wireless network (s) 304. Although described as an error message, in other embodiments, the error message 446 can instead be any type of message, such as an invitation response message, that indicates that the device 308 is not able to receive the second call. To illustrate, the device 306 may receive a message that includes one or more of SIP response codes 404, 485, 604, or 484, as non-limiting examples, which may be interpreted by the device 306 as the first phone number 412 being an invalid / virtual phone number that cannot be called back. Although described as being generated and sent by the device 308, in other examples, the error message 446 may be generated and sent to the device 306 by one or more elements of the wireless network (s) 304.

[0085] At 350, the device 306 outputs a call spoofing indicator associated with the call (e.g., with the device 302) based on the received error message from the device 308. For example, as shown in FIG. 4C, the call spoofing manager 120A of the device 306 may generate a spoofing indicator 448 based on the error message 446. In this example, because the device 308 is unable to receive the second call to enable performance of additional call spoofing detection operations by the device 306, the spoofing indicator 448 indicates that a validity of the first phone number 412 as the originating phone number for the call is unconfirmed (e.g., that User C or the device 308 are unreachable) .

[0086] The method 300 continues to 352, and the device 302 and the device 306 perform one or more operations to establish, or facilitate, the call between the device 302 and the device 306. Additionally, the device 306 terminates the second call to the device 308. The method 300 terminates after establishing, or facilitating, the call between the device 302 and the device 306. In some embodiments, the device 306 may be configured to periodically attempt to call the device 308 in order to complete the call spoofing detection process, and results may be stored in a log at or accessible to the device 306. Additionally, if the call is still ongoing upon completion of the call spoofing detection process, the device 306 may output an updated spoofing indicator to inform the user of the results.

[0087] In other embodiments, instead of establishing, or facilitating, the call at 352, the device 306 may terminate the call due to the validity of the first phone number 412 as the originating phone number being undeterminable. For example, the user of the device 306 may configure settings of the device 306 to terminate calls for which the originating phone number cannot be validated. As can be appreciated, the example described with reference to FIG. 4C represents a situation in which the validity of the originating phone number of the call is unconfirmed due to the device 308 not being able to respond to the second call, which results in the spoofing indicator 448 providing the user of the device 306 with information indicating that the caller (User A) cannot be validated and, optionally, that call spoofing may be occurring but cannot be confirmed.

[0088] Returning to 346 of FIG. 3C, if the device 308 is able to receive the second call (e.g., the call invitation message 442) , the method 300 proceeds to 354 of FIG. 3D. At 354, the device 308 generates and sends an invitation response message to the device 306 that indicates that the device 308 is able to receive the second call. For example, as shown in FIG. 4D, the device 308 sends an invitation response 452 to the device 306 via the wireless network (s) 304. The invitation response 452 indicates that the device 308 is able to establish the second call with the device 306. In some examples, the device 306 and the device 308 may exchange additional message (s) or signaling to establish a SIP connection (not shown in FIG. 4D) .

[0089] At 356, the device 306 generates and sends a registry check request to the device 308 based on the invitation response 452 indicating that the device 308 is able to receive the second call. For example, as shown in FIG. 4D, the device 306 sends a registry check request 454 to the device 308 via the wireless network (s) 304. The registry check request 454 includes the first phone number 412 (e.g., the registry check request 454 indicates a request for the recipient device to check whether the first phone number 412 is included in a registry of the recipient device) . Although described as a registry check request, in other embodiments, the registry check request 454 may be a different type of message or signaling. As an illustrative example, the registry check request 454 may include or correspond to a field included in a SIP information message.

[0090] At 358, the device 308 determines whether storing IDs within a registry is enabled (e.g., whether processing of registry check requests is enabled) . If storing IDs in a registry is not enabled at the device 308, the method 300 proceeds to 368 of FIG. 3E, described further below. Alternatively, if storing IDs in a registry is enabled at the device 308, the method 300 continues to 360.

[0091] At 360, the device 308 determines whether the requested phone number is stored in a registry at the device 308. For example, as shown in FIG. 4D, the device 308 may compare the first phone number 412 to a call registry 450 maintained by the call spoofing manager 120C to determine if the first phone number 412 matches one of the stored IDs within the call registry 450. If the first phone number 412 is not stored in the call registry 450, the method 300 proceeds to 374 of FIG. 3F, described further below. Alternatively, if the first phone number 412 is stored in the call registry 450, the method 300 continues to 362.

[0092] At 362, the device 308 generates and sends a registry check response to the device 306. For example, as shown in FIG. 4D, the device 308 may send a registry check response 456 to the device 306 via the wireless network (s) 304, and the device 306 may receive and process the registry check response 456. The registry check response 456 includes an indicator 458 that indicates whether the first phone number 412 is included in the call registry 450 associated with the device 308. In the example shown in FIG. 4D, the indicator 458 indicates that the first phone number 412 is stored in the call registry 450 (e.g., that the first phone number 412 is registered to the device 308) . To illustrate, the indicator 458 may include or correspond to a field of the registry check response 456 that is set to a value that indicates ‘true’ .

[0093] At 364, the device 306 outputs a call spoofing indicator associated with the call (e.g., with the device 302) based on the received registry check response from the device 308. For example, as shown in FIG. 4D, the call spoofing manager 120A of the device 306 may generate a spoofing indicator 459 based on the indicator 458 included in the registry check response 456. In this example, because the first phone number 412 is included in the IDs stored at the call registry 450 associated with the device 308, the spoofing indicator 459 indicates that the first phone number 412 is invalid as the originating phone number for the call between the device 302 and the device 306 (e.g., that a phone number registered to the device 308 is being spoofed by the device 302) .

[0094] The method 300 continues to 366 and, because the originating phone number is invalid (e.g., because call spoofing has been detected) , the device 306 terminates the call between the device 302 and the device 306. Although not shown in FIG. 4D, the device 306 may also terminate the second call with the device 308. The method 300 terminates after the call (s) are terminated. As can be appreciated, the example described with reference to FIG. 4D represents detection of call spoofing of the originating phone number of the call, which results in termination of the call in order to protect the user of the device 306 from being victimized by a malicious actor spoofing a phone number that is registered to another party. In some other embodiments, instead of terminating the call, the device 306 may display the spoofing indicator 459 to indicate that call spoofing has been detected, and the device 306 may output a UI with options for the user to select to terminate the call, continue the call, perform additional operations (e.g., log the call, report the first phone number 412, etc. ) , or a combination thereof.

[0095] Returning to 358 of FIG. 3D, if storing IDs in a registry is not enabled at the device 308, the method 300 proceeds to 368 of FIG. 3E. At 368, the device 308 generates and sends an error message to the device 306. For example, if the device 308 does not include the call spoofing manager 120C or the call registry 450 of FIG. 4D, and the device 308 may respond to the registry check request 454 by sending an error message to the device 306, similar to as described above for the error message 430 sent by the device 302. At 370, the device 306 outputs a call spoofing indicator associated with the call (e.g., with the device 302) based on the received error message from the device 308. In this example, because the device 308 is unable to perform a registry check, the spoofing indicator indicates that a validity of the first phone number 412 as the originating phone number for the call is undeterminable, similar to the spoofing indicator 432. The method 300 continues to 372 and the device 302 and the device 306 perform one or more operations to establish, or facilitate, the call between the device 302 and the device 306. Additionally, the device 306 may terminate the second call with the device 308. The method 300 terminates after establishing, or facilitating, the call between the device 302 and the device 306. In other embodiments, instead of establishing, or facilitating, the call at 372, the device 306 may terminate the call with the device 302 due to the validity of the first phone number 412 as the originating phone number being undeterminable.

[0096] Returning to 360 of FIG. 3D, if the first phone number 412 is not stored in the call registry 450 of the device 308, the method 300 proceeds to 374 of FIG. 3F. At 374, the device 308 generates and sends a registry check response to the device 306 to indicate that the first phone number 412 is not stored in the call registry 450. For example, as shown in FIG. 4E, the device 308 may send the registry check response 456 to the device 306 via the wireless network (s) 304, and the device 306 may receive and process the registry check response 456. The registry check response 456 includes an indicator 460 that indicates whether the first phone number 412 is included in the call registry 450 associated with the device 308. In the example shown in FIG. 4E, the indicator 460 indicates that the first phone number 412 is not stored in the call registry 450 (e.g., that the first phone number 412 is not registered to the device 308) . To illustrate, the indicator 460 may include or correspond to a field of the registry check response 456 that is set to a value that indicates ‘false’ .

[0097] At 376, the device 306 outputs a call spoofing indicator associated with the call (e.g., with the device 302) based on the indicator 460. For example, as shown in FIG. 4E, the call spoofing manager 120A of the device 306 may generate a spoofing indicator 462 based on the indicator 460. In this example, because the first phone number 412 is not stored at the call registry 450 of the device 308, the spoofing indicator 462 indicates that a validity of the first phone number 412 as the originating phone number for the call between the device 302 and the device 306 is undeterminable.

[0098] The method 300 continues to 378, and the device 302 and the device 306 perform one or more operations to establish, or facilitate, the call between the device 302 and the device 306. Additionally, the device 306 may terminate the second call with the device 308. The method 300 terminates after establishing, or facilitating, the call between the device 302 and the device 306. In other embodiments, instead of establishing, or facilitating, the call at 378, the device 306 may terminate the call due to the validity of the first phone number 412 as the originating phone number being undeterminable. As can be appreciated, the example described with reference to FIG. 4E represents a situation in which the validation of the originating phone number of the call is not possible due to the originating phone number not being registered to the caller (e.g., User A and / or the device 302) and the party (e.g., User C and / or the device 308) associated with the first phone number 412 by the wireless network (s) 304. In such situations, the spoofing indicator 462 provides the user of the device 306 with information indicating that the caller (User A) may be using a virtual number, such as used by ride-share applications, delivery applications, offices, or the like, or that call spoofing may be occurring but cannot be confirmed.

[0099] FIG. 5 depicts a diagram of an example of an integrated circuit 500 operable to detecting call spoofing, in accordance with some examples of the present disclosure. The integrated circuit 500 includes one or more processors 508 (herein after referred to as the “processor 508” ) and a memory 506. The processor 508 and the memory 506 may include or correspond to the processor 108 and the memory 106, respectively. The processor 508 may include a call spoofing manager 520, which may include or correspond to the call spoofing manager 120 of FIG. 1. The memory 506 may include (e.g., store) a registry 530, which may include or correspond to the registry 130 of FIG. 1. The registry 530 is optional, and in some other embodiments, the memory 506 does not store the registry 530 (e.g., the registry 530 is stored at another device or is not included) .

[0100] The integrated circuit 500 also includes an input interface 504, such as one or more bus interfaces, to enable the integrated circuit 500 to receive signals representing input data 570 for processing. For example, the input data 570 can correspond to or include the audio data 111, the input data 115, the call-related phone number (s) 134, the SIP invite 270, the call invitation message 410, the first phone number 412, the registry check response 416, the indicator 418, the error message 430, the error message 446, the invitation response 452, the registry check response 456, the indicator 458, the indicator 460, or a combination thereof.

[0101] The integrated circuit 500 also includes an output interface 505, such as a bus interface, to enable the integrated circuit 500 to output signals representing output data 572. For example, the output data 572 can correspond to or include the registry check response 140, the registry check request 144, the call spoofing indicator 146, the registry check request 272, the registry check request 414, the spoofing indicator 420, the spoofing indicator 432, the call invitation message 442, the spoofing indicator 448, the spoofing indicator 459, the spoofing indicator 462, or a combination thereof.

[0102] The integrated circuit 500 including the call spoofing manager 520 and the registry 530 enables implementation of call spoofing detection as a component in a system or a device. For example, the system or the device may include a mobile device (e.g., a mobile phone or tablet) as depicted in FIG. 6, a wearable electronic device as depicted in FIG. 7, a voice-controlled speaker system as depicted in FIG. 8, a headset as depicted in FIG. 9, or a vehicle as depicted in FIG. 10.

[0103] In some embodiments, the system or the device that includes the integrated circuit 500 also includes or is coupled to an image sensor (e.g., a camera) , an input device (e.g., a microphone, a keyboard or touch screen, etc. ) , a display device, a speaker, a modem, or a combination thereof. For example, the image sensor, the microphone, the input device, the display device, the speaker, and the modem may include or correspond to the image sensor 112, the microphone 110, the input device 114, the display device 116, the speaker 117, and the modem 118, respectively.

[0104] In some embodiments, the system or the device that includes the integrated circuit 500 is operable to obtain a first number that is indicated as an originating phone number of a call received by the system or the device, and the call spoofing manager 520 is operable to generate a registry check request that includes the first phone number for transmission to a second device, such as via the modem of the system or the device. The system or the device is to operable to receive a registry check responses, such as via the modem, that indicates whether the first phone number is associated with the second device, and the call spoofing manager 520 is operable to output a call spoofing indicator to indicate to a user of the system or device whether the first phone number is included in the registry of the other device (e.g., whether the call is a legitimate, non-spoofed call) . Additionally, or alternatively, the system or device that includes the integrated circuit 500 is operable to receive a registry check request from a second device, such as via a modem of the system or the device. The call spoofing manager 520 is operable to compare a first phone number included in the registry check request to one or more unique IDs included in the registry 530 and based on the comparison, generate a registry check response for transmission to the second device, such as via the modem, to enable the second device to verify whether the system or the device is spoofing the first phone number.

[0105] FIG. 6 depicts a diagram of a mobile device 600 operable to detect call spoofing, in accordance with some examples of the present disclosure. The mobile device 600 may include or correspond to a phone or a tablet, as illustrative, non-limiting examples. The mobile device 600 includes a camera 602 (e.g., an image sensor) , a display 604 (e.g., a display screen) , a microphone 606, a speaker 608, and the integrated circuit 500. Components of the integrated circuit 500, including the call spoofing manager 520, and optionally the registry 530, are integrated in the mobile device 600 and are illustrated using dashed lines to indicate internal components that are not generally visible to a user of the mobile device 600.

[0106] In a particular example, the call spoofing manager 520 is operable to obtain a first number that is indicated as an originating phone number of a call received by the mobile device 600 and to generate a registry check request that includes the first phone number for transmission to a second device that initiated the call. The call spoofing manager 520 is also operable to obtain a registry check response received from the second device and to output, via the display 604, a call spoofing indicator that is based on the registry check response. Outputting the call spoofing indicator enables the mobile device 600 to indicate to a user whether the first phone number is a valid phone number or is being spoofed, or that a spoofing status is undeterminable, which can prevent the user from being victimized by fraudulent calls and scams. In another particular example, the call spoofing manager 520 is operable to receive a registry check request from a second device, to compare a first phone number included in the registry check request to one or more unique IDs included in a registry stored at the integrated circuit 500 (e.g., the registry 530) , and based on the comparison, to generate a registry check response for transmission to the second device. Sending the registry check response that indicates whether the first phone number is included in the stored IDs enables the mobile device 600 to support call spoofing detection at other devices and increases trust associated with the user by other callers.

[0107] FIG. 7 depicts a diagram of a wearable electronic device 700 operable to detect call spoofing, in accordance with some examples of the present disclosure. The wearable electronic device 700 may include or correspond to a “smart watch, ” as an illustrative, non-limiting example. The wearable electronic device 700 includes a camera 702 (e.g., an image sensor) , a display 704 (e.g., a display screen) , a microphone 706, a speaker 708, and the integrated circuit 500. Components of the integrated circuit 500, including the call spoofing manager 520, and optionally the registry 530, is integrated in the wearable electronic device 700 and are illustrated using dashed lines to indicate internal components that are not generally visible to a user of the wearable electronic device 700.

[0108] In a particular example, the call spoofing manager 520 is operable to obtain a first number that is indicated as an originating phone number of a call received by the wearable electronic device 700 and to generate a registry check request that includes the first phone number for transmission to a second device that initiated the call. The call spoofing manager 520 is also operable to obtain a registry check response received from the second device and to output, via the display 704, a call spoofing indicator that is based on the registry check response. Outputting the call spoofing indicator enables the wearable electronic device 700 to indicate to a user whether the first phone number is a valid phone number or is being spoofed, or that a spoofing status is undeterminable, which can prevent the user from being victimized by fraudulent calls and scams. In another particular example, the call spoofing manager 520 is operable to receive a registry check request from a second device, to compare a first phone number included in the registry check request to one or more unique IDs included in a registry stored at the integrated circuit 500 (e.g., the registry 530) , and based on the comparison, to generate a registry check response for transmission to the second device. Sending the registry check response that indicates whether the first phone number is included in the stored IDs enables the wearable electronic device 700 to support call spoofing detection at other devices and increases trust associated with the user by other callers.

[0109] FIG. 8 is a diagram of a voice-controlled speaker system 800 operable to detect call spoofing, in accordance with some examples of the present disclosure. The voice-controlled speaker system 800 may include or correspond to a wireless speaker and voice activated device, as an illustrative, non-limiting example. The voice-controlled speaker system 800 can have wireless network connectivity and is configured to execute an assistant operation. The voice-controlled speaker system 800 includes a camera 802 (e.g., an image sensor) , a display 804 (e.g., a display screen) , a microphone 806, a speaker 808, and the integrated circuit 500. Components of the integrated circuit 500, including the call spoofing manager 520, and optionally the registry 530, are integrated in the voice-controlled speaker system 800 and are illustrated using dashed lines to indicate internal components that are not generally visible to a user of the voice-controlled speaker system 800.

[0110] In a particular example, the call spoofing manager 520 is operable to obtain a first number that is indicated as an originating phone number of a call received by the voice-controlled speaker system 800 and to generate a registry check request that includes the first phone number for transmission to a second device that initiated the call. The call spoofing manager 520 is also operable to obtain a registry check response received from the second device and to output, via the display 804, a call spoofing indicator that is based on the registry check response. Outputting the call spoofing indicator enables the voice-controlled speaker system 800 to indicate to a user whether the first phone number is a valid phone number or is being spoofed, or that a spoofing status is undeterminable, which can prevent the user from being victimized by fraudulent calls and scams. In another particular example, the call spoofing manager 520 is operable to receive a registry check request from a second device, to compare a first phone number included in the registry check request to one or more unique IDs included in a registry stored at the integrated circuit 500 (e.g., the registry 530) , and based on the comparison, to generate a registry check response for transmission to the second device. Sending the registry check response that indicates whether the first phone number is included in the stored IDs enables the voice-controlled speaker system 800 to support call spoofing detection at other devices and increases trust associated with the user by other callers.

[0111] FIG. 9 depicts a diagram of a headset device 900 operable to detect call spoofing, in accordance with some examples of the present disclosure. The headset device 900 includes one or more microphones 906 and one or more speakers 908. In some examples, the one or more microphones 906 include an input microphone 906A and an inner ear, or bone conduction, microphone 906B. Components of the integrated circuit 500, including the call spoofing manager 520, and optionally the registry 530, are integrated in the headset device 900.

[0112] In a particular example, the call spoofing manager 520 is operable to obtain a first number that is indicated as an originating phone number of a call received by the headset device 900 and to generate a registry check request that includes the first phone number for transmission to a second device that initiated the call. The call spoofing manager 520 is also operable to obtain a registry check response received from the second device and to output, such as via display of automatically generated speech from the one or more speakers 908, a call spoofing indicator that is based on the registry check response. Outputting the call spoofing indicator enables the headset device 900 to indicate to a user whether the first phone number is a valid phone number or is being spoofed, or that a spoofing status is undeterminable, which can prevent the user from being victimized by fraudulent calls and scams. In another particular example, the call spoofing manager 520 is operable to receive a registry check request from a second device, to compare a first phone number included in the registry check request to one or more unique IDs included in a registry stored at the integrated circuit 500 (e.g., the registry 530) , and based on the comparison, to generate a registry check response for transmission to the second device. Sending the registry check response that indicates whether the first phone number is included in the stored IDs enables the headset device 900 to support call spoofing detection at other devices and increases trust associated with the user by other callers.

[0113] FIG. 10 is a diagram of a second example of a vehicle 1000 operable to detect call spoofing, in accordance with some examples of the present disclosure. The vehicle 1000 may include or correspond to a car. The vehicle 1000 includes a camera 1002 (e.g., an image sensor) , a display 1004 (e.g., a display screen) , a microphone 1006, one or more speakers 1008, and the integrated circuit 500. Components of the integrated circuit 500, including the call spoofing manager 520, and optionally the registry 530, are integrated in the vehicle 1000 and are illustrated using dashed lines to indicate internal components that are not generally visible to a user of the vehicle 1000.

[0114] In a particular example, the call spoofing manager 520 is operable to obtain a first number that is indicated as an originating phone number of a call received by the vehicle 1000 and to generate a registry check request that includes the first phone number for transmission to a second device that initiated the call. The call spoofing manager 520 is also operable to obtain a registry check response received from the second device and to output, via the display 1004, a call spoofing indicator that is based on the registry check response. Outputting the call spoofing indicator enables the vehicle 1000 to indicate to a user whether the first phone number is a valid phone number or is being spoofed, or that a spoofing status is undeterminable, which can prevent the user from being victimized by fraudulent calls and scams. In another particular example, the call spoofing manager 520 is operable to receive a registry check request from a second device, to compare a first phone number included in the registry check request to one or more unique IDs included in a registry stored at the integrated circuit 500 (e.g., the registry 530) , and based on the comparison, to generate a registry check response for transmission to the second device. Sending the registry check response that indicates whether the first phone number is included in the stored IDs enables the vehicle 1000 to support call spoofing detection at other devices and increases trust associated with the user by other callers.

[0115] The embodiments of the systems or devices as described with reference to FIGs. 6-10 are described, respectively, as including a display, a microphone, an input device, a speaker, a camera, or a combination thereof. As described with reference to FIGs. 6-10, the display, the microphone, the input device, the speaker, and the camera may include or correspond to the display device 116, the microphone 110, the input device 114, the speaker 117, and the image sensor 112, respectively. It is noted that in other embodiments of the systems or devices of FIGs. 6-10, one or more of the systems or devices of FIGs. 6-10 may not include the display, the microphone, the input device, the speaker, the camera, or a combination thereof. Additionally, or alternatively, one or more of the systems or devices of FIGs. 6-10 may include an additional component. For example, the additional component may include a modem, such as the modem 118.

[0116] FIG. 11 is a diagram of an example of a method 1100 of detecting call spoofing, in accordance with some aspects of the present disclosure. In a particular aspect, one or more operations of the method 1100 are performed by the system 100, the device 102, the processor 108, the call spoofing manager 120, the call registry validator 122, the call spoofing detector 124, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the processor 508, the call spoofing manager 520, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, or a combination thereof.

[0117] In some embodiments, the method 1100 includes, at block 1102, receiving, by a first device from a second device, a call invitation message associated with a call from the second device. The call invitation message indicates a first phone number as an originating phone number of the call. For example, the first device may include or correspond to the device 102 of or the device 306, the second device may include or correspond to one of the devices 152, the device 302, or the device 308 , and the first phone number may be stored as one of the call-related phone numbers 134. As additional examples, the call invitation message may include or correspond to the call invitation message 410 of FIGs. 4A-4E, and the first phone number may include or correspond to the first phone number 412.

[0118] The method 1100 also includes, at block 1104, sending, from the first device to the second device, a registry check request that includes the first phone number. For example, the registry check request may include or correspond to the registry check request 144 of FIG. 1 that is sent by the device 102 to one of the devices 152.

[0119] The method 1100 also includes, at block 1106, receiving, by the first device from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. For example, the device 102 of FIG. 1 may receive a registry check request from one of the devices 152 that indicates whether the first phone number (e.g., stored in the call-related phone numbers 134) is stored in a respective registry at the device 152. As additional examples, the registry check request may include or correspond to the registry check response 416 of FIGs. 4A, 4C, 4D, and 4E.

[0120] The method 1100 also includes, at block 1108, outputting a call spoofing indicator associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry. For example, the call spoofing detector 124 of FIG. 1 may output the call spoofing indicator 146. As additional examples, the call spoofing indicator may include or correspond to the spoofing indicators 420, 432, 448, 459, and 462 of FIGs. 4A-4E, respectively. In some examples, the call spoofing indicator is output prior to acceptance of the call, and in others, the call spoofing indicator is output after the call has been established.

[0121] In some embodiments, the method 1100 also includes, after acceptance of the call, receiving a user input that indicates an instruction to initiate one or more call spoofing detection operations. The registry check request is sent based on the user input. For example, the user input may be represented by the input data 115 of FIG. 1 received from the input device 114.

[0122] In some embodiments, the call is a SIP-based call and the registry stores, based on an SIP registration process, one or more unique identifiers associated with the second device. For example, the device 102 and the devices 152 of FIG. 1 may store one or more respective IDs at corresponding registries, such as the registry 130, during SIP registration processes with the network 150. Additionally, or alternatively, the call spoofing indicator may indicate that the first phone number is valid as the originating phone number for the call based on the registry check response indicating that the first phone number is included in the registry. For example, the spoofing indicator 420 of FIG. 4A indicates that the first phone number 412 is valid as the originating number based on the call registry 408 storing the first phone number 412.

[0123] In some embodiments, the method 1100 also includes generating a second call invitation message that indicates the first phone number as a target phone number and sending, in association with a second call from the device, the second call invitation message to another device. The method 1100 can also include receiving, from the other device, an invitation response that is responsive to the second call invitation message. For example, the second call invitation message may include or correspond to the call invitation message 442 of FIGs. 4C-4E that is sent from the device 306 to the device 308, and the invitation response may include or correspond to the error message 446 of FIG. 4C or the invitation response 452 of FIGs. 4D and 4E. In some such embodiments, the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is unconfirmed based on the invitation response indicating that the other device is unable to receive the second call. For example, the spoofing indicator 448 of FIG. 4C indicates that a validity of the first phone number 412 as the originating phone number is unconfirmed based on the error message 446 received by the device 306 from the device 308. Alternatively, in some such embodiments, the method 1100 also includes sending, to the other device and based on the invitation response indicating that the other device is able to receive the second call, a second registry check request that includes the first phone number. For example, the second registry check request may include or correspond to the registry check request 454 of FIGs. 4D and 4E that is sent from the device 306 to the device 308.

[0124] The method 1100 also includes receiving, from the other device, a second registry check response that indicates whether the first phone number is included in a second registry associated with the other device. For example, the second registry check response may include or correspond to the registry check response 456 of FIGs. 4D and 4E. In some such embodiments, the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is undeterminable based on the second registry check response indicating that the first phone number is not included in the second registry. For example, the spoofing indicator 462 of FIG. 4E indicates that the validity of the first phone number 412 as the originating phone number is undeterminable. Alternatively, the call spoofing indicator may indicate that the first phone number is invalid as the originating phone number for the call based on the second registry check response indicating that the first phone number is included in the second registry. For example, the spoofing indicator 459 of FIG. 4D indicates that the first phone number 412 is invalid as the originating phone number (e.g., that call spoofing is detected) .

[0125] In some embodiments, the method 1100 also includes, based on receipt of the call invitation message, outputting an authorization request to initiate one or more call spoofing detection operations, and receiving a user input responsive to the authorization request. For example, the authorization request may include or correspond to the authorization request 142 of FIG. 1 that is output by the call spoofing detector 124, and the user input may be represented by the input data 115 received via the input device 114. In some such embodiments, the registry check request is sent to the second device based on the user input indicating to initiate the one or more call spoofing detection operations. For example, if the input data 115 of FIG. 1 represents an instruction from the user to initiate a call spoofing detection process, the call spoofing detector 124 generates the registry check request 144 for transmission to one of the devices 152. In some alternate embodiments, the method 1100 also includes initiating one or more call spoofing detection operations based on receipt of the call invitation message. For example, the call spoofing detector 124 of FIG. 1 may automatically initiate the call spoofing detection process that causes generation of the registry check request 144 in response to receiving a call invitation message from one of the devices 152.

[0126] In some embodiments, the method 1100 also includes sending, to a third device, a third call invitation message associated with a third call to the third device. The third call invitation message indicates a second phone number as an originating phone number of the third call. For example, the device 102 of FIG. 1 may send a call invitation message to another one of the devices 152, and this call invitation message may include a phone number included in the registered IDs 132. As another example, the device 306 may send a call invitation message to the device 302 or the device 308 that is independent of the call initiated by the device 302 to the device 306. The third device may be the same as the second device, or a different device, in various examples. In such embodiments, the method 1100 also includes receiving, from the third device, a third registry check request associated with the third call. The third registry check request includes the second phone number. For example, the device 102 may receive a registry check request from one of the devices 152 as part of a call spoofing detection process. In such embodiments, the method 1100 also includes comparing the second phone number to one or more unique IDs included in a third registry stored at the memory, and based on the comparison, sending, to the third device, a third registry check response that indicates whether the second phone number is included in the third registry. For example, the device 102 may compare the number in the received registry check request to the registered IDs 132 stored in the registry 130 and based on the comparison, the call spoofing detector 124 may generate the registry check response 140 for transmission to one of the devices 152.

[0127] FIG. 12 is a diagram of an example of a method 1200 that supports call spoofing detection, in accordance with some aspects of the present disclosure. In a particular aspect, one or more operations of the method 1200 are performed by the system 100, the device 102, the processor 108, the call spoofing manager 120, the call registry validator 122, the call spoofing detector 124, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the processor 508, the call spoofing manager 520, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, or a combination thereof.

[0128] In some embodiments, the method 1200 includes, at block 1202, receiving, by a first device from a second device, a registry check request associated with a call at the second device. The registry check request includes a first phone number. For example, the device 102 of FIG. 1 may receive a registry check request from one of the devices 152, and a phone number included in the registry check request may be stored as one of the call-related phone numbers 134. In some embodiments, the call is a SIP-based call from one of the devices 152.

[0129] The method 1200 also includes, at block 1204, comparing the first phone number to one or more unique IDs included in a registry stored at the first device. For example, the call registry validator 122 of FIG. 1 may compare the phone number included in the call-related phone numbers 134 to the registered IDs 132 stored at the registry 130. As another example, the device 302 may compare the first phone number 412 included in the registry check request 414 to the call registry 408, or the device 308 may compare the first phone number 412 included in the registry check request 454 to the call registry 450.

[0130] The method 1200 also includes, at block 1206, based on the comparison, sending, from the first device to the second device, a registry check response that indicates whether the first phone number is included in the registry. For example, the registry check response 140 of FIG. 1 that is generated by the call registry validator 122 indicates whether the received phone number is included in the registry 130. The device 102 sends the registry check response 140 to one of the devices 152 as part of the call spoofing detection process at that device. As another example, the device 302 may send the registry check response 416 to the device 306, or the device 308 may send the registry check response 456 to the device 306.

[0131] In some embodiments, the method 1200 also includes sending, prior to receipt of the registry check request, a call invitation message associated with the call to the second device. The call invitation message indicates the first phone number as an originating phone number of the call. For example, a device that receives a registry check request may be the device that initiated a call by sending a call invitation message, as described with reference to the device 302 of FIG. 4A. In some alternate embodiments, the method 1200 also includes receiving, prior to receipt of the registry check request, a call invitation message associated with the call from the second device. For example, a device that receives a registry check request may be the device that receives a call, as described with reference to the device 308 of FIG. 4D.

[0132] The method 1100 of FIG. 11, the method 1200 of FIG. 12, or both, may be implemented by a field-programmable gate array (FPGA) device, an application-specific integrated circuit (ASIC) , a processing unit such as a central processing unit (CPU) , a DSP, a controller, another hardware device, firmware device, or any combination thereof. As an example, the method 1100 of FIG. 11, the method 1200 of FIG. 12, or both, may be performed by a processor that executes instructions, such as described with reference to FIG. 13.

[0133] It is noted that one or more blocks (or operations) described with reference to FIGs. 11 and 12 may be combined with one or more blocks (or operations) described with reference to another of the figures. For example, one or more blocks (or operations) of FIG. 11 may be combined with one or more blocks (or operations) of FIG. 12. As another example, one or more blocks associated with FIG. 11 or with FIG. 12 may be combined with one or more blocks (or operations) associated with FIGs. 1-10. Additionally, or alternatively, one or more operations described above with reference to FIGs. 1-12 may be combined with one or more operations described with reference to FIG. 13.

[0134] Referring to FIG. 13, FIG. 13 is a block diagram of an illustrative example of a device 1300 that is operable to detect call spoofing, in accordance with one or more aspects of the present disclosure. In various implementations, the device 1300 may have more or fewer components than illustrated in FIG. 13. In an illustrative implementation, the device 1300 may correspond to the device 102, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, or the vehicle 1000. In an illustrative implementation, the device 1300 may perform one or more operations described with reference to FIGs. 1-12.

[0135] In a particular implementation, the device 1300 includes a processor 1306 (e.g., a central processing unit (CPU) ) . The device 1300 may include one or more additional processors 1310 (e.g., one or more DSPs) . In a particular aspect, the processor 108 of FIG. 1 or the processor 508 of FIG. 5 corresponds to the processor 1306, the processors 1310, or a combination thereof. The processors 1310 may include a speech and music coder-decoder (CODEC) 1308 that includes a voice coder ( “vocoder” ) encoder 1336, a vocoder decoder 1338, or a combination thereof. The processors 1310 may also include the call spoofing manager 120.

[0136] In this context, the term “processor” refers to an integrated circuit consisting of logic cells, interconnects, input / output blocks, clock management components, memory, and optionally other special purpose hardware components, designed to execute instructions and perform various computational tasks. Examples of processors include, without limitation, central processing units (CPUs) , digital signal processors (DSPs) , neural processing units (NPU) , graphics processing units (GPUs) , field programmable gate arrays (FPGAs) , microcontrollers, quantum processors, coprocessors, vector processors, other similar circuits, and variants and combinations thereof. In some cases, a processor can be integrated with other components, such as communication components, input / output components, etc. to form a system on a chip (SOC) device or a packaged electronic device.

[0137] Taking CPUs as a starting point, a CPU typically includes one or more processor cores, each of which includes a complex, interconnected network of transistors and other circuit components defining logic gates, memory elements, etc. A core is responsible for executing instructions to, for example, perform arithmetic and logical operations. Typically, a CPU includes an Arithmetic Logic Unit (ALU) that handles mathematical operations and a Control Unit that generates signals to coordinate the operation of other CPU components, such as to manage operations a fetch-decode-execute cycle.

[0138] CPUs and / or individual processor cores generally include local memory circuits, such as registers and cache to temporarily store data during operations. Registers include high-speed, small-sized memory units intimately connected to the logic cells of a CPU. Often registers include transistors arranged as groups of flip-flops, which are configured to store binary data. Caches include fast, on-chip memory circuits used to store frequently accessed data. Caches can be implemented, for example, using Static Random-Access Memory (SRAM) circuits.

[0139] Operations of a CPU (e.g., arithmetic operations, logic operations, and flow control operations) are directed by software and firmware. At the lowest level, the CPU includes an instruction set architecture (ISA) that specifies how individual operations are performed using hardware resources (e.g., registers, arithmetic units, etc. ) . Higher level software and firmware is translated into various combinations of ISA operations to cause the CPU to perform specific higher-level operations. For example, an ISA typically specifies how the hardware components of the CPU move and modify data to perform operations such as addition, multiplication, and subtraction, and high-level software is translated into sets of such operations to accomplish larger tasks, such as adding two columns in a spreadsheet. Generally, a CPU operates on various levels of software, including a kernel, an operating system, applications, and so forth, with each higher level of software generally being more abstracted from the ISA and usually more readily understandable by human users.

[0140] GPUs, NPUs, DSPs, microcontrollers, coprocessors, FPGAs, ASICS, and vector processors include components similar to those described above for CPUs. The differences among these various types of processors are generally related to the use of specialized interconnection schemes and ISAs to improve a processor’s ability to perform particular types of operations. For example, the logic gates, local memory circuits, and the interconnects therebetween of a GPU are specifically designed to improve parallel processing, sharing of data between processor cores, and vector operations, and the ISA of the GPU may define operations that take advantage of these structures. As another example, ASICs are highly specialized processors that include similar circuitry arranged and interconnected for a particular task, such as encryption or signal processing. As yet another example, FPGAs are programmable devices that include an array of configurable logic blocks (e.g., interconnect sets of transistors and memory elements) that can be configured (often on the fly) to perform customizable logic functions.

[0141] The device 1300 may include a memory 1386 and a CODEC 1334. The memory 1386 may include or correspond to the memory 106 or 506. The memory 1386 may include instructions 1356, that are executable by the one or more additional processors 1310 (or the processor 1306) to implement the functionality described with reference to the call spoofing manager 120, or both. The instructions 1356 may include or correspond to the instructions 109. The memory 1386 also includes the registry 130. The device 1300 may include a modem 1370 coupled, via a transceiver 1350, to an antenna 1352. The modem 1370 may include or correspond to the modem 118.

[0142] The device 1300 may include a display 1328 coupled to a display controller 1326. The display 1328 may include or correspond to the display device 116. One or more speaker (s) 1392, the microphone (s) 1394 may be coupled to the CODEC 1334. The one or more speakers 1392 and the microphone 1394 may include or correspond to the speaker 117 and the microphone 110, respectively. The CODEC 1334 may include a digital-to-analog converter (DAC) 1302, an analog-to-digital converter (ADC) 1304, or both. In a particular implementation, the CODEC 1334 may receive analog signals from the microphone (s) 1394, convert the analog signals to digital signals using the analog-to-digital converter 1304, and provide the digital signals to the speech and music codec 1308. The speech and music codec 1308 may process the digital signals, and the digital signals may further be processed by the call spoofing manager 120. In a particular implementation, the speech and music codec 1308 may provide digital signals to the CODEC 1334. The CODEC 1334 may convert the digital signals to analog signals using the digital-to-analog converter 1302 and may provide the analog signals to the speaker (s) 1392.

[0143] In a particular implementation, the device 1300 may be included in a system-in-package or system-on-chip device 1322. In a particular implementation, the memory 1386, the processor 1306, the processors 1310, the display controller 1326, the CODEC 1334, and the modem 1370 are included in the system-in-package or system-on-chip device 1322. In a particular implementation, an input device 1330, a power supply 1344, and a camera 1345 are coupled to the system-in-package or the system-on-chip device 1322. For example, the input device 1330 and the camera 1345 may include or correspond to the input device 114 and the image sensor 112, respectively. In some examples, the input device 1330 may include or be associated with the display device 116 or the display 1328. Moreover, in a particular implementation, as illustrated in FIG. 13, the display 1328, the input device 1330, the speaker (s) 1392, the microphone (s) 1394, the antenna 1352, the power supply 1344, and the camera 1345 are external to the system-in-package or the system-on-chip device 1322. In a particular implementation, each of the display 1328, the input device 1330, the speaker (s) 1392, the microphone (s) 1394, the antenna 1352, the power supply 1344, and the camera 1345 may be coupled to a component of the system-in-package or the system-on-chip device 1322, such as an interface or a controller.

[0144] The device 1300 may include a smart speaker, a speaker bar, a mobile communication device, a smart phone, a cellular phone, a laptop computer, a computer, a tablet, a personal digital assistant, a display device, a television, a gaming console, a music player, a radio, a digital video player, a digital video disc (DVD) player, a tuner, a camera, a navigation device, a vehicle, a headset, an augmented reality headset, a mixed reality headset, a virtual reality headset, an aerial vehicle, a home automation system, a voice-activated device, a wireless speaker and voice activated device, a portable electronic device, a car, a computing device, a communication device, an internet-of-things (IoT) device, a virtual reality (VR) device, a base station, a mobile device, or any combination thereof.

[0145] In conjunction with the described implementations, an apparatus includes means for receiving, from a second device, a call invitation message associated with a call from the second device. The call invitation message indicates a first phone number as an originating phone number of the call. For example, the means for receiving can include the modem 118, the processor 108, the device 102, the system 100, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the input interface 504, the processor 508, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, the processor 1306, the processor (s) 1310, the system-in-package or the system-on-chip device 1322, the modem 1370, the device 1300, other circuitry configured to receive a call invitation message from a second device, or a combination thereof.

[0146] The apparatus also includes means for transmitting, to the second device, a registry check request that includes the first phone number. For example, the means for transmitting can include the modem 118, the call spoofing manager 120, the call spoofing detector 124, the processor 108, the device 102, the system 100, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the output interface 505, the processor 508, the call spoofing manager 520, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, the processor 1306, the processor (s) 1310, the system-in-package or the system-on-chip device 1322, the modem 1370, the device 1300, other circuitry configured to transmit a registry check request to a second device, or a combination thereof.

[0147] The apparatus includes means for receiving, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device. For example, the means for receiving can include the modem 118, the processor 108, the device 102, the system 100, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the input interface 504, the processor 508, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, the processor 1306, the processor (s) 1310, the system-in-package or the system-on-chip device 1322, the modem 1370, the device 1300, other circuitry configured to receive a registry check response from a second device, or a combination thereof.

[0148] The apparatus also includes means for outputting a call spoofing indicator associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry. For example, the means for outputting can include the call spoofing manager 120, the call spoofing detector 124, the processor 108, the display device 116, the speaker 117, the device 102, the system 100, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the processor 508, the call spoofing manager 520, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, the processor 1306, the processor (s) 1310, the system-in-package or the system-on-chip device 1322, the device 1300, other circuitry configured to output a call spoofing indicator, or a combination thereof.

[0149] Also in conjunction with the described implementations, an apparatus includes means for receiving, from a second device, a registry check request associated with a call at the second device. The registry check request includes a first phone number. For example, the means for receiving can include the modem 118, the processor 108, the device 102, the system 100, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the input interface 504, the processor 508, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, the processor 1306, the processor (s) 1310, the system-in-package or the system-on-chip device 1322, the modem 1370, the device 1300, other circuitry configured to receive a registry check request from a second device, or a combination thereof.

[0150] The apparatus also includes means for comparing the first phone number to one or more unique IDs included in a registry. For example, the means for comparing can include the call spoofing manager 120, the call registry validator 122, the processor 108, the device 102, the system 100, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the processor 508, the call spoofing manager 520, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, the processor 1306, the processor (s) 1310, the system-in-package or the system-on-chip device 1322, the device 1300, other circuitry configured to compare a first phone number to one or more unique IDs included in a registry, or a combination thereof.

[0151] The apparatus further includes means for transmitting, based on the comparison and to the second device, a registry check response that indicates whether the first phone number is included in the registry. For example, the means for transmitting can include the modem 118, the call spoofing manager 120, the call registry validator 122, the processor 108, the device 102, the system 100, the UE 260, the device 302, the device 306, the device 308, the integrated circuit 500, the output interface 505, the processor 508, the call spoofing manager 520, the mobile device 600, the wearable electronic device 700, the voice-controlled speaker system 800, the headset device 900, the vehicle 1000, the processor 1306, the processor (s) 1310, the system-in-package or the system-on-chip device 1322, the modem 1370, the device 1300, other circuitry configured to transmit a registry check response to a second device, or a combination thereof.

[0152] In some implementations, a non-transitory computer-readable medium (e.g., a computer-readable storage device, such as the memory 106, the memory 506, or the memory 1386) includes instructions (e.g., the instructions 109 or the instructions 1356) that, when executed by one or more processors (e.g., the processor 108, the processor 508, the one or more processors 1310, or the processor 1306) , cause the one or more processors to receive, from a second device (e.g., one of the devices 152 or the device 302) , the call invitation message (e.g., the call invitation message 410) associated with a call from the second device. The call invitation message indicates a first phone number (e.g., one of the call-related phone numbers 134 or the first phone number 412) as an originating phone number of the call. The instructions also cause the one or more processors to send, to the second device, a registry check request (e.g., the registry check request 414) that includes the first phone number. The instructions also cause the one or more processors to receive, from the second device, a registry check response (e.g., the registry check response 416) that indicates whether the first phone number is included in a registry (e.g., the call registry 408) associated with the second device. The instructions also cause the one or more processors to output a call spoofing indicator (e.g., the call spoofing indicator 146 or one of the spoofing indicators 420, 432, 448, 459, or 462) associated with the call. The call spoofing indicator is based on whether the first phone number is included in the registry.

[0153] In some implementations, a non-transitory computer-readable medium (e.g., a computer-readable storage device, such as the memory 106, the memory 506, or the memory 1386) includes instructions (e.g., the instructions 109 or the instructions 1356) that, when executed by one or more processors (e.g., the processor 108, the processor 508, the one or more processors 1310, or the processor 1306) , cause the one or more processors to receive, from a second device (e.g., one of the devices 152, the device 302, or the device 308) , a registry check request (e.g., the registry check request 414 or the registry check request 454) associated with a call at the second device. The registry check request includes a first phone number (e.g., one of the call-related phone numbers 134 or the first phone number 412) . The instructions also cause the one or more processors to compare the first phone number to the one or more unique IDs (e.g., the registered IDs 132) included in the registry (e.g., the registry 130, the call registry 408, or the call registry 450) . The instructions also cause the one or more processors to, based on the comparison, send, to the second device, a registry check response (e.g., the registry check response 416 or the registry check response 456) that indicates whether the first phone number is included in the registry.

[0154] Particular aspects of the disclosure are described below in sets of interrelated Examples:

[0155] According to Example 1, a device includes: a memory configured to store a first phone number indicated by a call invitation message; and one or more processors coupled to the memory. The one or more processors are configured to: receive, from a second device, the call invitation message associated with a call from the second device, wherein the call invitation message indicates the first phone number as an originating phone number of the call; send, to the second device, a registry check request that includes the first phone number; receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device; and output a call spoofing indicator associated with the call, the call spoofing indicator based on whether the first phone number is included in the registry.

[0156] Example 2 includes the device of Example 1, wherein: the call is a session initiation protocol (SIP) -based call; and the registry stores, based on an SIP registration process, one or more unique identifiers associated with the second device.

[0157] Example 3 includes the device of Example 1 or Example 2, wherein the call spoofing indicator indicates that the first phone number is valid as the originating phone number for the call based on the registry check response indicating that the first phone number is included in the registry.

[0158] Example 4 includes the device of Examples 1 or Example 2, wherein the one or more processors are further configured to: generate a second call invitation message that indicates the first phone number as a target phone number; send, in association with a second call from the device, the second call invitation message to another device; and receive, from the other device, an invitation response that is responsive to the second call invitation message.

[0159] Example 5 includes the device of Example 4, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is unconfirmed based on the invitation response indicating that the other device is unable to receive the second call.

[0160] Example 6 includes the device of Example 4, wherein the one or more processors are further configured to: send, to the other device and based on the invitation response indicating that the other device is able to receive the second call, a second registry check request that includes the first phone number; and receive, from the other device, a second registry check response that indicates whether the first phone number is included in a second registry associated with the other device.

[0161] Example 7 includes the device of Example 6, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is undeterminable based on the second registry check response indicating that the first phone number is not included in the second registry.

[0162] Example 8 includes the device of Example 6, wherein the call spoofing indicator indicates that the first phone number is invalid as the originating phone number for the call based on the second registry check response indicating that the first phone number is included in the second registry.

[0163] Example 9 includes the device of any of Examples 1 to 8, wherein the one or more processors are further configured to: based on receipt of the call invitation message, output an authorization request to initiate one or more call spoofing detection operations; and receive a user input responsive to the authorization request.

[0164] Example 10 includes the device of Example 9, wherein the registry check request is sent to the second device based on the user input indicating to initiate the one or more call spoofing detection operations.

[0165] Example 11 includes the device of any of Examples 1 to 10, wherein the one or more processors are further configured to initiate one or more call spoofing detection operations based on receipt of the call invitation message.

[0166] Example 12 includes the device of any of Examples 1 to 11, wherein the one or more processors are further configured to: send, to a third device, a third call invitation message associated with a third call to the third device, wherein the third call invitation message indicates a second phone number as an originating phone number of the third call; receive, from the third device, a third registry check request associated with the third call, wherein the third registry check request includes the second phone number; compare the second phone number to one or more unique identifiers (IDs) included in a third registry stored at the memory; and based on the comparison, send, to the third device, a third registry check response that indicates whether the second phone number is included in the third registry.

[0167] Example 13 includes the device of any of Examples 1 to 12, and further includes a modem coupled to the one or more processors and configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0168] Example 14 includes the device of any of Examples 1 to 13, and further includes one or more speakers configured to output audio associated with the call.

[0169] Example 15 includes the device of any of Examples 1 to 14, and further includes one or more microphones configured to capture user speech associated with the call.

[0170] Example 16 includes the device of any of Examples 1 to 15, wherein the one or more processors are integrated in a headset device configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0171] Example 17 includes the device of any of Examples 1 to 15, wherein the one or more processors are integrated in at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0172] Example 18 includes the device of any of Examples 1 to 15, wherein the one or more processors are integrated in a vehicle that is configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0173] Example 19 includes the device of any of Examples 1 to 18, wherein the one or more processors are configured to, after acceptance of the call, receive a user input that indicates an instruction to initiate one or more call spoofing detection operations, and wherein sending the registry check request is based on the user input.

[0174] According to Example 20, a method includes: receiving, by a first device from a second device, a call invitation message associated with a call from the second device, wherein the call invitation message indicates a first phone number as an originating phone number of the call; sending, from the first device to the second device, a registry check request that includes the first phone number; receiving, by the first device from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device; and outputting, by the first device, a call spoofing indicator associated with the call, the call spoofing indicator based on whether the first phone number is included in the registry.

[0175] Example 21 includes the method of Example 20, and further includes, after acceptance of the call, receiving, by the first device, a user input that indicates an instruction to initiate one or more call spoofing detection operations, wherein the sending of the registry check request is based on the user input.

[0176] Example 22 includes the method of Example 20 or Example 21, wherein: the call is a session initiation protocol (SIP) -based call; and the registry stores, based on an SIP registration process, one or more unique identifiers associated with the second device.

[0177] Example 23 includes the method of any of Examples 20 to 22, wherein the call spoofing indicator indicates that the first phone number is valid as the originating phone number for the call based on the registry check response indicating that the first phone number is included in the registry.

[0178] Example 24 includes the method of any of Examples 20 to 22, and further includes: generating a second call invitation message that indicates the first phone number as a target phone number; sending, in association with a second call from the device, the second call invitation message to another device; and receiving, from the other device, an invitation response that is responsive to the second call invitation message.

[0179] Example 25 includes the method of Example 24, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is unconfirmed based on the invitation response indicating that the other device is unable to receive the second call.

[0180] Example 26 includes the method of Example 24, and further includes: sending, to the other device and based on the invitation response indicating that the other device is able to receive the second call, a second registry check request that includes the first phone number; and receiving, from the other device, a second registry check response that indicates whether the first phone number is included in a second registry associated with the other device.

[0181] Example 27 includes the method of Example 26, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is undeterminable based on the second registry check response indicating that the first phone number is not included in the second registry.

[0182] Example 28 includes the method of Example 26, wherein the call spoofing indicator indicates that the first phone number is invalid as the originating phone number for the call based on the second registry check response indicating that the first phone number is included in the second registry.

[0183] Example 29 includes the method of any of Examples 20 to 28, and further includes: based on receipt of the call invitation message, outputting an authorization request to initiate one or more call spoofing detection operations; and receiving a user input responsive to the authorization request.

[0184] Example 30 includes the method of Example 29, wherein the registry check request is sent to the second device based on the user input indicating to initiate the one or more call spoofing detection operations.

[0185] Example 31 includes the method of any of Examples 20 to 30, and further includes initiating one or more call spoofing detection operations based on receipt of the call invitation message.

[0186] Example 32 includes the method of any of Examples 20 to 31, and further including: sending, to a third device, a third call invitation message associated with a third call to the third device, wherein the third call invitation message indicates a second phone number as an originating phone number of the third call; receiving, from the third device, a third registry check request associated with the third call, wherein the third registry check request includes the second phone number; comparing the second phone number to one or more unique identifiers (IDs) included in a third registry stored at the memory; and based on the comparison, sending, to the third device, a third registry check response that indicates whether the second phone number is included in the third registry.

[0187] Example 33 includes the method of any of Examples 20 to 32, wherein the first device includes a modem configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0188] Example 34 includes the method of any of Examples 20 to 33, wherein the first device includes one or more speakers configured to output audio associated with the call.

[0189] Example 35 includes the method of any of Examples 20 to 34, wherein the first device includes one or more microphones configured to capture user speech associated with the call.

[0190] Example 36 includes the method of any of Examples 20 to 35, wherein the is a headset device configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0191] Example 37 includes the method of any of Examples 20 to 35, wherein the first device is at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0192] Example 38 includes the method of any of Examples 20 to 35, wherein the first device is a vehicle that is configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0193] According to Example 39, a non-transitory computer-readable medium stores instructions that are executable by one or more processors to cause the one or more processors to: receive, from a second device, the call invitation message associated with a call from the second device, wherein the call invitation message indicates the first phone number as an originating phone number of the call; send, to the second device, a registry check request that includes the first phone number; receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device; and output a call spoofing indicator associated with the call, wherein the call spoofing indicator is based on whether the first phone number is included in the registry.

[0194] Example 40 includes the non-transitory computer-readable medium of Example 39, wherein the instructions also cause the one or more processors to, after acceptance of the call, receive a user input that indicates an instruction to initiate one or more call spoofing detection operations, wherein the sending of the registry check request is based on the user input.

[0195] Example 41 includes the non-transitory computer-readable medium of Example 39 or Example 40, wherein: the call is a session initiation protocol (SIP) -based call; and the registry stores, based on an SIP registration process, one or more unique identifiers associated with the second device.

[0196] Example 42 includes the non-transitory computer-readable medium of any of Examples 39 to 41, wherein the call spoofing indicator indicates that the first phone number is valid as the originating phone number for the call based on the registry check response indicating that the first phone number is included in the registry.

[0197] Example 43 includes the non-transitory computer-readable medium of any of Examples 39 to 41, wherein the instructions also cause the one or more processors to: generate a second call invitation message that indicates the first phone number as a target phone number; send, in association with a second call from the device, the second call invitation message to another device; and receive, from the other device, an invitation response that is responsive to the second call invitation message.

[0198] Example 44 includes the non-transitory computer-readable medium of Example 43, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is unconfirmed based on the invitation response indicating that the other device is unable to receive the second call.

[0199] Example 44 includes the non-transitory computer-readable medium of Example 43, wherein the instructions also cause the one or more processors to: send, to the other device and based on the invitation response indicating that the other device is able to receive the second call, a second registry check request that includes the first phone number; and receive, from the other device, a second registry check response that indicates whether the first phone number is included in a second registry associated with the other device.

[0200] Example 45 includes the non-transitory computer-readable medium of Example 44, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is undeterminable based on the second registry check response indicating that the first phone number is not included in the second registry.

[0201] Example 46 includes the non-transitory computer-readable medium of Example 44, wherein the call spoofing indicator indicates that the first phone number is invalid as the originating phone number for the call based on the second registry check response indicating that the first phone number is included in the second registry.

[0202] Example 47 includes the non-transitory computer-readable medium of any of Examples 39 to 46, wherein the instructions also cause the one or more processors to: based on receipt of the call invitation message, output an authorization request to initiate one or more call spoofing detection operations; and receive a user input responsive to the authorization request.

[0203] Example 48 includes the non-transitory computer-readable medium of Example 47, wherein the registry check request is sent to the second device based on the user input indicating to initiate the one or more call spoofing detection operations.

[0204] Example 49 includes the non-transitory computer-readable medium of any of Examples 39 to 48, wherein the instructions also cause the one or more processors to initiate one or more call spoofing detection operations based on receipt of the call invitation message.

[0205] Example 50 includes the non-transitory computer-readable medium of any of Examples 39 to 49, wherein the instructions also cause the one or more processors to: send, to a third device, a third call invitation message associated with a third call to the third device, wherein the third call invitation message indicates a second phone number as an originating phone number of the third call; receive, from the third device, a third registry check request associated with the third call, wherein the third registry check request includes the second phone number; compare the second phone number to one or more unique identifiers (IDs) included in a third registry stored at the memory; and based on the comparison, send, to the third device, a third registry check response that indicates whether the second phone number is included in the third registry.

[0206] Example 51 includes the non-transitory computer-readable medium of any of Examples 39 to 50, wherein a modem is coupled to the one or more processors and configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0207] Example 52 includes the non-transitory computer-readable medium of any of Examples 39 to 51, wherein one or more speakers are coupled to the one or more processors and are configured to output audio associated with the call.

[0208] Example 53 includes the non-transitory computer-readable medium of any of Examples 39 to 52, wherein one or more microphones are coupled to the one or more processors and are configured to capture user speech associated with the call.

[0209] Example 54 includes the non-transitory computer-readable medium of any of Examples 39 to 53, wherein the one or more processors are integrated in a headset device configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0210] Example 55 includes the non-transitory computer-readable medium of any of Examples 39 to 53, wherein the one or more processors are integrated in at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0211] Example 56 includes the non-transitory computer-readable medium of any of Examples 39 to 53, wherein the one or more processors are integrated in a vehicle that is configured to receive the call invitation message, send the registry check request, and receive the registry check response.

[0212] According to Example 57, an apparatus includes: means for receiving, from a second device, a call invitation message associated with a call from the second device, wherein the call invitation message indicates a first phone number as an originating phone number of the call; means for transmitting, to the second device, a registry check request that includes the first phone number; means for receiving, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device; and means for outputting a call spoofing indicator associated with the call, wherein the call spoofing indicator is based on whether the first phone number is included in the registry.

[0213] According to Example 58, a device includes: a memory configured to store a registry including one or more unique identifiers (IDs) associated with the device; and one or more processors coupled to the memory. The one or more processors are configured to: receive, from a second device, a registry check request associated with a call at the second device, wherein the registry check request includes a first phone number; compare the first phone number to the one or more unique IDs included in the registry; and based on the comparison, send, to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0214] Example 59 includes the device of Example 58, wherein the one or more processors are further configured to send, prior to receipt of the registry check request, a call invitation message associated with the call to the second device, the call invitation message indicating the first phone number as an originating phone number of the call.

[0215] Example 60 includes the device of Example 58, wherein the one or more processors are further configured to receive, prior to receipt of the registry check request, a call invitation message associated with the call from the second device.

[0216] Example 61 includes the device of any of Examples 58 to 60, and further includes a modem coupled to the one or more processors and configured to receive the registry check request and send the registry check response.

[0217] Example 62 includes the device of any of Examples 58 to 61, and further includes one or more speakers configured to output audio associated with the call.

[0218] Example 63 includes the device of any of Examples 58 to 62, and further includes one or more microphones configured to capture user speech associated with the call.

[0219] Example 64 includes the device of any of Examples 58 to 63, wherein the one or more processors are integrated in a headset device configured to receive the registry check request and send the registry check response.

[0220] Example 65 includes the device of any of Examples 58 to 63, wherein the one or more processors are integrated in at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the registry check request and send the registry check response.

[0221] Example 66 includes the device of any of Examples 58 to 63, wherein the one or more processors are integrated in a vehicle that is configured to receive the registry check request and send the registry check response.

[0222] According to Example 67, a method includes: receiving, by a first device from a second device, a registry check request associated with a call at the second device, wherein the registry check request includes a first phone number; comparing, by the first device, the first phone number to one or more unique IDs included in a registry stored at the first device; and based on the comparison, sending, from the first device to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0223] Example 68 includes the method of Example 67, and further includes sending, prior to receipt of the registry check request, a call invitation message associated with the call to the second device, the call invitation message indicating the first phone number as an originating phone number of the call.

[0224] Example 69 includes the method of Example 67, and further includes receiving, prior to receipt of the registry check request, a call invitation message associated with the call from the second device.

[0225] Example 70 includes the method of any of Examples 67 to 69, wherein the first device includes a modem configured to receive the registry check request and send the registry check response.

[0226] Example 71 includes the method of any of Examples 67 to 70, wherein the first device includes one or more speakers configured to output audio associated with the call.

[0227] Example 72 includes the method of any of Examples 67 to 71, wherein the first device includes one or more microphones configured to capture user speech associated with the call.

[0228] Example 73 includes the method of any of Examples 67 to 72, wherein the first device is a headset device configured to receive the registry check request and send the registry check response.

[0229] Example 74 includes the method of any of Examples 67 to 72, wherein the first device is at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the registry check request and send the registry check response.

[0230] Example 75 includes the method of any of Examples 67 to 72, wherein the first device is a vehicle that is configured to receive the registry check request and send the registry check response.

[0231] According to Example 76, a non-transitory computer-readable medium stores instructions that are executable by one or more processors to cause the one or more processors to: receive, from a second device, a registry check request associated with a call at the second device, wherein the registry check request includes a first phone number; compare the first phone number to the one or more unique IDs included in a registry; and based on the comparison, send, to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0232] Example 77 includes the non-transitory computer-readable medium of Example 76, wherein the instructions also cause the one or more processors to send, prior to receipt of the registry check request, a call invitation message associated with the call to the second device, the call invitation message indicating the first phone number as an originating phone number of the call.

[0233] Example 78 includes the non-transitory computer-readable medium of Example 76, wherein the instructions also cause the one or more processors to receive, prior to receipt of the registry check request, a call invitation message associated with the call from the second device.

[0234] Example 79 includes the non-transitory computer-readable medium of any of Examples 76 to 78, wherein a modem is coupled to the one or more processors and configured to receive the registry check request and send the registry check response.

[0235] Example 80 includes the non-transitory computer-readable medium of any of Examples 76 to 79, wherein one or more speakers are coupled to the one or more processors and are configured to output audio associated with the call.

[0236] Example 81 includes the non-transitory computer-readable medium of any of Examples 76 to 80, wherein one or more microphones are coupled to the one or more processors and are configured to capture user speech associated with the call.

[0237] Example 82 includes the non-transitory computer-readable medium of any of Examples 76 to 81, wherein the one or more processors are integrated in a headset device configured to receive the registry check request and send the registry check response.

[0238] Example 83 includes the non-transitory computer-readable medium of any of Examples 76 to 81, wherein the one or more processors are integrated in at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the registry check request and send the registry check response.

[0239] Example 84 includes the non-transitory computer-readable medium of any of Examples 76 to 81, wherein the one or more processors are integrated in a vehicle that is configured to receive the registry check request and send the registry check response.

[0240] According to Example 85, an apparatus includes: means for receiving, from a second device, a registry check request associated with a call at the second device, wherein the registry check request includes a first phone number; means for comparing the first phone number to one or more unique IDs included in a registry; and means for transmitting, based on the comparison and to the second device, a registry check response that indicates whether the first phone number is included in the registry.

[0241] Those of skill would further appreciate that the various illustrative logical blocks, configurations, modules, circuits, and algorithm steps described in connection with the implementations disclosed herein may be implemented as electronic hardware, computer software executed by a processor, or combinations of both. Various illustrative components, blocks, configurations, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or processor executable instructions depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, such implementation decisions are not to be interpreted as causing a departure from the scope of the present disclosure.

[0242] The steps of a method or algorithm described in connection with the implementations disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module may reside in random access memory (RAM) , flash memory, read-only memory (ROM) , programmable read-only memory (PROM) , erasable programmable read-only memory (EPROM) , electrically erasable programmable read-only memory (EEPROM) , registers, hard disk, a removable disk, a compact disc read-only memory (CD-ROM) , or any other form of non-transient storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor may read information from, and write information to, the storage medium. In the alternative, the storage medium may be integral to the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC) . The ASIC may reside in a computing device or a user terminal. In the alternative, the processor and the storage medium may reside as discrete components in a computing device or user terminal.

[0243] The previous description of the disclosed aspects is provided to enable a person skilled in the art to make or use the disclosed aspects. Various modifications to these aspects will be readily apparent to those skilled in the art, and the principles defined herein may be applied to other aspects without departing from the scope of the disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope possible consistent with the principles and novel features as defined by the following claims.

Claims

1.A device comprising:a memory configured to store a first phone number indicated by a call invitation message; andone or more processors coupled to the memory, wherein the one or more processors are configured to:receive, from a second device, the call invitation message associated with a call from the second device, wherein the call invitation message indicates the first phone number as an originating phone number of the call;send, to the second device, a registry check request that includes the first phone number;receive, from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device; andoutput a call spoofing indicator associated with the call, the call spoofing indicator based on whether the first phone number is included in the registry.2.The device of claim 1, wherein:the call is a session initiation protocol (SIP) -based call; andthe registry stores, based on an SIP registration process, one or more unique identifiers associated with the second device.3.The device of claim 1, wherein the call spoofing indicator indicates that the first phone number is valid as the originating phone number for the call based on the registry check response indicating that the first phone number is included in the registry.4.The device of claim 1, wherein the one or more processors are further configured to:generate a second call invitation message that indicates the first phone number as a target phone number;send, in association with a second call from the device, the second call invitation message to another device; andreceive, from the other device, an invitation response that is responsive to the second call invitation message.5.The device of claim 4, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is unconfirmed based on the invitation response indicating that the other device is unable to receive the second call.6.The device of claim 4, wherein the one or more processors are further configured to:send, to the other device and based on the invitation response indicating that the other device is able to receive the second call, a second registry check request that includes the first phone number; andreceive, from the other device, a second registry check response that indicates whether the first phone number is included in a second registry associated with the other device.7.The device of claim 6, wherein the call spoofing indicator indicates that a validity of the first phone number as the originating phone number for the call is undeterminable based on the second registry check response indicating that the first phone number is not included in the second registry.8.The device of claim 6, wherein the call spoofing indicator indicates that the first phone number is invalid as the originating phone number for the call based on the second registry check response indicating that the first phone number is included in the second registry.9.The device of claim 1, wherein the one or more processors are further configured to:based on receipt of the call invitation message, output an authorization request to initiate one or more call spoofing detection operations; andreceive a user input responsive to the authorization request.10.The device of claim 9, wherein the registry check request is sent to the second device based on the user input indicating to initiate the one or more call spoofing detection operations.11.The device of claim 1, wherein the one or more processors are further configured to initiate one or more call spoofing detection operations based on receipt of the call invitation message.12.The device of claim 1, wherein the one or more processors are further configured to:send, to a third device, a third call invitation message associated with a third call to the third device, wherein the third call invitation message indicates a second phone number as an originating phone number of the third call;receive, from the third device, a third registry check request associated with the third call, wherein the third registry check request includes the second phone number;compare the second phone number to one or more unique identifiers (IDs) included in a third registry stored at the memory; andbased on the comparison, send, to the third device, a third registry check response that indicates whether the second phone number is included in the third registry.13.The device of claim 1, further comprising a modem coupled to the one or more processors and configured to receive the call invitation message, send the registry check request, and receive the registry check response.14.The device of claim 1, further comprising one or more speakers configured to output audio associated with the call.15.The device of claim 1, further comprising one or more microphones configured to capture user speech associated with the call.16.The device of claim 1, wherein the one or more processors are integrated in a headset device configured to receive the call invitation message, send the registry check request, and receive the registry check response.17.The device of claim 1, wherein the one or more processors are integrated in at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the call invitation message, send the registry check request, and receive the registry check response.18.The device of claim 1, wherein the one or more processors are integrated in a vehicle that is configured to receive the call invitation message, send the registry check request, and receive the registry check response.19.A method comprising:receiving, by a first device from a second device, a call invitation message associated with a call from the second device, wherein the call invitation message indicates a first phone number as an originating phone number of the call;sending, from the first device to the second device, a registry check request that includes the first phone number;receiving, by the first device from the second device, a registry check response that indicates whether the first phone number is included in a registry associated with the second device; andoutputting, by the first device, a call spoofing indicator associated with the call, the call spoofing indicator based on whether the first phone number is included in the registry.20.The method of claim 19, further comprising:after acceptance of the call, receiving, by the first device, a user input that indicates an instruction to initiate one or more call spoofing detection operations, wherein the sending of the registry check request is based on the user input.21.A device comprising:a memory configured to store a registry including one or more unique identifiers (IDs) associated with the device; andone or more processors coupled to the memory, wherein the one or more processors are configured to:receive, from a second device, a registry check request associated with a call at the second device, wherein the registry check request includes a first phone number;compare the first phone number to the one or more unique IDs included in the registry; andbased on the comparison, send, to the second device, a registry check response that indicates whether the first phone number is included in the registry.22.The device of claim 21, wherein the one or more processors are further configured to send, prior to receipt of the registry check request, a call invitation message associated with the call to the second device, the call invitation message indicating the first phone number as an originating phone number of the call.23.The device of claim 21, wherein the one or more processors are further configured to receive, prior to receipt of the registry check request, a call invitation message associated with the call from the second device.24.The device of claim 21, further comprising a modem coupled to the one or more processors and configured to receive the registry check request and send the registry check response.25.The device of claim 21, further comprising one or more speakers configured to output audio associated with the call.26.The device of claim 21, further comprising one or more microphones configured to capture user speech associated with the call.27.The device of claim 21, wherein the one or more processors are integrated in a headset device configured to receive the registry check request and send the registry check response.28.The device of claim 21, wherein the one or more processors are integrated in at least one of a mobile phone, a tablet computer device, or a wearable electronic device, and wherein the mobile phone, the tablet computer device, or the wearable electronic device is configured to receive the registry check request and send the registry check response.29.The device of claim 21, wherein the one or more processors are integrated in a vehicle that is configured to receive the registry check request and send the registry check response.30.A method comprising:receiving, by a first device from a second device, a registry check request associated with a call at the second device, wherein the registry check request includes a first phone number;comparing, by the first device, the first phone number to one or more unique IDs included in a registry stored at the first device; andbased on the comparison, sending, from the first device to the second device, a registry check response that indicates whether the first phone number is included in the registry.

Citation Information

Patent Citations

  • Detecting a spoofed call

    US10681206B1

  • Caller identity verification based on unique multi-device signatures

    US10681207B1

  • Method and system for detection of call signal manipulation

    US10951775B1

  • Detection of spoofed call information

    US20180295140A1