+91 98186 32779
πŸŽ–οΈ 500+ Officers SelectedSince 2001Retired SSB Officer FacultyOwn 5-Acre GTO GroundSee Results β†’
NDA Current Affairs · Sci/Tech · 9 Oct 2026

The Number on Your Screen Was Never Verified

When a call arrives, your phone shows you a number. That number is not a measurement. It is a claim, made by whichever network originated the call, and passed down the chain without anybody checking whether that network had the right to make it.

Almost every telecom fraud that has worked in India rests on that single design fact. On 9 October 2026, at the ITU Roundtable on "Implementing ITU Standards to Combat Fraudulent Communications" β€” held alongside the India Mobile Congress (IMC) 2026 at Yashobhoomi, which the Prime Minister inaugurated on 8 October β€” the Minister of State for Communications and Rural Development, Dr Chandra Sekhar Pemmasani, said India would help fix it.

He welcomed the ITU's proposal for joint trials of digital verification of caller identity across international networks, and offered a concrete method: begin between willing countries on selected international routes, ensure that different network technologies are represented, and feed the results back into the standards. His formulation of the problem was the right one: "Fraud is a network problem. It needs a network answer. And because networks are global, the answer must also be global."

Why the number can lie

In the telephone network, the calling party number is inserted into the signalling message by the originating operator. Everything downstream β€” transit carriers, the terminating operator, your handset β€” treats it as given. There is no signature, no certificate, and no way for the receiving network to test whether the number was legitimately held by whoever placed the call.

This was not negligence. It was a reasonable design for a world in which the only entities able to originate a call were a handful of state-owned monopolies who could be trusted and, failing that, sued. In a world of internet telephony, where anyone can buy origination capacity and set the calling number as a configuration field, the assumption no longer holds.

The fix is conceptually simple: sign the number. If the originating provider attaches a cryptographic token asserting both the number and its own authority over it, the terminating provider can verify the signature and know whether to trust the display.

That is what the STIR/SHAKEN framework does in North America. STIR is the set of IETF standards defining how the identity token is created and attached; SHAKEN is the industry specification describing how carriers actually deploy it. The signature travels inside the SIP signalling of an IP call. Crucially, the signing provider also records how much it knows about the caller, as one of three attestation levels.

The level that explains why India cannot do this alone

The three attestation levels are the technical heart of this story.

Full attestation says: this is my customer, and this is their number. Partial attestation says: this is my customer, but I cannot vouch for the number they presented. And gateway attestation β€” level C β€” says something much weaker: I know which network handed me this call, and nothing more.

Gateway attestation is precisely the case of a call entering from an international gateway. The receiving country's operator can confirm where the call came into its network. It cannot authenticate the source, because the source is in another jurisdiction, behind operators it has no relationship with and no visibility into.

This is the structural reason a national anti-spoofing framework terminates at the border. India can, and does, block calls that arrive from abroad while displaying an Indian number β€” those are provably false, because a genuine Indian number would not be originating overseas. What it cannot do is verify a genuine foreign number, or detect a spoofed foreign number, because the verification would have to happen in the network that originated the call.

Hence the ITU. The International Telecommunication Union is the body where globally interoperable telecommunication standards are agreed between national administrations, which is exactly the shape of this problem: the fix requires every participating country's operators to sign on origination and verify on termination, using a common method. A regional framework, however good, produces islands of trust. Dr Pemmasani's proposal β€” trials on selected routes between willing countries, deliberately spanning different network technologies β€” is how such a standard gets tested before it is universal.

What India has built, and what each layer actually does

The Minister described a five-layered approach, and it is worth separating the layers by what they attack, because they are not variations of the same idea.

Layer one β€” blocking spoofed international calls in real time. Catching calls that arrive from abroad asserting an Indian number. This addresses impersonation of domestic institutions and is the layer the ITU work would extend.

Layer two β€” finding fraudulent connections. ASTR, an AI-based tool developed by C-DOT (the Centre for Development of Telematics, the Department of Telecommunications' own research arm), analyses subscriber and usage data to flag connections obtained on forged or duplicated identity documents. Flagged connections are referred to operators for re-verification, and those that fail are disconnected. The Minister put the figure at over 82 lakh fraudulent connections disconnected.

A note on that number, because the arithmetic does not sit still. A reply in the Rajya Sabha earlier in 2026 reported more than 88 lakh connections disconnected for failing re-verification as of mid-July 2026 β€” a larger figure at an earlier date. The two almost certainly count different things: one the connections identified specifically through ASTR, the other all disconnections following re-verification from every source, including citizen reports. It is a reminder to check what a telecom statistic is counting before quoting it, since these figures circulate interchangeably.

Layer three β€” citizen participation. The Sanchar Saathi platform, whose app the Minister said has recorded around 25 million downloads, lets subscribers check the connections registered in their own name, report suspected fraud communications, and block a lost handset. Its device-identity functions are built on the same 15-digit IMEI machinery that decides whether a stolen phone can be traced.

Layer four β€” intelligence sharing. The Digital Intelligence Platform (DIP) connects more than 1,600 organisations β€” telecom operators, banks and law-enforcement agencies, including the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs β€” for two-way exchange. Its most visible output is the Financial Fraud Risk Indicator, which scores a mobile number's fraud risk and pushes it to banks so that a transfer to a flagged number can be held. The Minister said it has prevented suspected losses exceeding β‚Ή5,000 crore in 15 months, which is consistent with the β‚Ή5,043 crore figure reported in September.

Layer five β€” emerging channels, covering the migration of fraud from voice and SMS to messaging apps and other over-the-top services.

The loss figure against which all of this is set: the Minister put losses to such fraud at over β‚Ή22,800 crore in 2024. Independent reporting of adjacent years gives numbers of the same order β€” around β‚Ή22,495 crore across some 28.1 lakh reported cases in 2025 β€” so the magnitude is well corroborated even where the year-on-year attribution varies between sources.

What verification will and will not fix

This is where a careful reader should slow down, because authentication is routinely oversold.

Verifying a caller ID establishes that the number is authorised. It does not establish that the person using it is honest. A fraudster calling from a number they genuinely hold will pass verification perfectly. What authentication removes is a narrower and more valuable thing: impersonation. It stops a call from displaying your bank's number, a police station's number, or a government helpline's number when it did not come from there.

That narrower fix happens to strike at the dominant fraud pattern. The "digital arrest" scam, the impersonated bank officer, the fake courier or customs official β€” all of them depend on the victim seeing an institutional number and extending institutional trust to it. Remove the ability to wear someone else's number and the script loses its opening move. The fraud does not disappear; it has to fall back on persuasion without borrowed authority, which is a far weaker position. The same logic applies to synthetic media: AI-generated voice cloning and deepfakes, which the Minister listed among the growing threats, are much more effective when the call also appears to come from a trusted number, which is why regulating the content layer alone leaves the strongest attack intact.

There is a second limit, and it is about policy rather than cryptography. A verification framework produces a verdict β€” verified, not verified, or unable to verify. What the terminating network does with that verdict is a separate decision: pass the call through, label it on the screen, or block it. A standard that is implemented without an agreed handling policy changes very little for the person holding the phone. Most unverified calls today are not malicious; they are legacy. Block them all and you cut off legitimate traffic from networks that have not upgraded, which is why adoption has to be sequenced β€” and why trials on selected routes, rather than a flag day, is the sensible approach.

The point about 6G, which is the real lesson

Dr Pemmasani closed on a design principle: as 6G networks are developed, trust must be designed in from the beginning.

That sentence is the whole problem stated backwards. Caller identity is being retrofitted onto a signalling architecture laid down when the network was a closed club, and the retrofit is expensive, partial, and will take a decade of international coordination to complete. Had authentication been a property of the protocol rather than an overlay, none of this would be necessary.

Which is why the argument matters for India specifically. A country that writes standards gets to put properties like verifiable identity into the base layer; a country that adopts them inherits whatever was decided elsewhere and then pays to patch it. India's ambition to hold a meaningful share of 6G patents and standards is usually discussed in terms of royalties. This release shows the other half of the case: standards decide what the network can be trusted to tell you, and that is a security interest, not just a commercial one.

For now, the position is precise and limited. No standard has been adopted. No trial has been scheduled. India has welcomed a proposal and offered to take part. The useful thing to carry away is not the announcement but the mechanism β€” that the number on a screen is an unverified assertion, and that fixing it is a problem of international standardisation rather than of national enforcement.

πŸ”‘ Revision block

  • What: At the ITU Roundtable on Implementing ITU Standards to Combat Fraudulent Communications, alongside IMC 2026 at Yashobhoomi (inaugurated by the PM on 8 October 2026), MoS Communications Dr Chandra Sekhar Pemmasani welcomed the ITU proposal for joint trials of digital caller identity verification across international networks.
  • India's proposed method: trials between willing countries on selected international routes, spanning different network technologies, with lessons fed back into the standards.
  • The underlying flaw: the calling party number is asserted by the originating network and trusted downstream; there is no cryptographic binding between a number and the right to use it.
  • The comparison to know: STIR/SHAKEN β€” STIR (IETF) defines the identity token, SHAKEN defines carrier deployment; the signature travels in SIP signalling.
  • Attestation levels: full (my customer, my number), partial (my customer, not their number), gateway (I know only which network handed me the call) β€” gateway attestation is the international gateway case, and the reason national frameworks stop at the border.
  • Why the ITU: globally interoperable telecom standards are agreed between national administrations there; regional frameworks create islands of trust.
  • India's five layers: real-time blocking of spoofed international calls; ASTR (C-DOT's AI tool) for fraudulent connections; Sanchar Saathi for citizen reporting; the Digital Intelligence Platform for intelligence sharing; measures for emerging channels.
  • Figures cited: over 82 lakh connections disconnected via ASTR; Sanchar Saathi app ~25 million downloads; DIP connects 1,600+ organisations; Financial Fraud Risk Indicator prevented suspected losses over β‚Ή5,000 crore in 15 months; losses to such fraud put at over β‚Ή22,800 crore in 2024.
  • The honest limit: verification proves the number is authorised, not that the caller is honest β€” it defeats impersonation, which is the opening move of digital-arrest and fake-official frauds.
  • Exam hook: trust must be a property of the protocol, not an overlay. Retrofitting identity onto legacy signalling is why this needs a decade of international coordination.

🎯 Practice MCQs

Q1. Caller ID spoofing is possible principally because: (a) Mobile numbers are reused after disconnection (b) SIM cards can be cloned electronically (c) The calling number is asserted by the originating network and not cryptographically verified (d) Handsets cannot display international numbers correctly

β†’ (c) Downstream networks and the handset treat the calling number as given. There is no signature binding the number to a right to use it.

Q2. In the STIR/SHAKEN framework, "gateway attestation" indicates that the signing provider: (a) Knows only which network handed it the call, and cannot authenticate the source (b) Has verified both the customer and the number (c) Has verified the customer but not the number presented (d) Has blocked the call as fraudulent

β†’ (a) This is the international-gateway case, and the reason a national framework cannot verify calls originating abroad.

Q3. ASTR, used to identify fraudulent mobile connections, was developed by: (a) The Telecom Regulatory Authority of India (b) C-DOT, the Centre for Development of Telematics (c) The Indian Cyber Crime Coordination Centre (d) The Bureau of Indian Standards

β†’ (b) C-DOT is the Department of Telecommunications' own research and development arm.

Q4. The Digital Intelligence Platform principally enables: (a) Blocking of stolen handsets by IMEI (b) Real-time deflection of spam SMS traffic (c) Verification of caller identity on international routes (d) Two-way intelligence sharing among operators, banks and law-enforcement agencies

β†’ (d) It connects more than 1,600 organisations, and the Financial Fraud Risk Indicator is among its outputs.

Q5. The ITU is the appropriate forum for caller identity verification because: (a) Globally interoperable telecommunication standards are agreed there between national administrations (b) It operates the international gateways through which calls transit (c) It has powers to prosecute cross-border telecom fraud (d) It licenses telecom operators in member states

β†’ (a) The ITU sets standards; it neither operates networks nor prosecutes offences. A common method adopted across administrations is what the problem requires.

Q6. Caller identity verification, once implemented, would principally prevent: (a) All forms of telecom-enabled financial fraud (b) The cloning of a subscriber's voice using AI (c) Impersonation of an institution's telephone number (d) The sale of connections on forged identity documents

β†’ (c) Verification establishes that a number is authorised, not that the caller is honest. What it removes is the ability to display someone else's number.

Q7. Which component of India's layered approach depends on subscriber participation? (a) ASTR (b) Sanchar Saathi (c) The Digital Intelligence Platform (d) Real-time blocking of spoofed international calls

β†’ (b) Sanchar Saathi lets subscribers check connections registered in their name, report suspect communications and block lost handsets.

Q8. The Financial Fraud Risk Indicator works by: (a) Blocking all calls from numbers registered outside India (b) Requiring two-factor authentication for every transfer (c) Disconnecting connections that fail re-verification (d) Scoring a mobile number's fraud risk and sharing it with banks so transfers can be held

β†’ (d) It converts telecom intelligence into a banking-side control, which is why the DIP's two-way sharing matters.

Q9. Why must adoption of a caller verification standard be sequenced rather than enforced at once? (a) Most unverified calls are legacy traffic, not fraud, and blocking them all would cut off legitimate callers (b) The ITU requires a ten-year transition for all standards (c) Cryptographic signatures cannot be verified on mobile handsets (d) Verification is prohibited on international routes

β†’ (a) Hence trials on selected routes between willing countries, rather than a flag day.

Q10. The design lesson the Minister drew for 6G was that: (a) Networks should be built entirely on indigenous hardware (b) Spectrum should be allocated administratively rather than by auction (c) Trust should be designed into the network from the beginning rather than retrofitted (d) Caller identity should be verified by the handset rather than the network

β†’ (c) Caller identity is being retrofitted onto signalling designed for a closed network of trusted operators, which is precisely why the fix is slow and partial.

πŸ“‹ How this gets asked (PYQ pattern)

Telecom and cyber questions have become a dependable part of the NDA general studies section, and they cluster around four things.

The first is acronym and parent body. ASTR belongs to C-DOT; Sanchar Saathi and the Digital Intelligence Platform to the Department of Telecommunications; the Indian Cyber Crime Coordination Centre to the Ministry of Home Affairs; TRAI is the regulator and sets rules on commercial communication. Papers swap these parents freely. Learn the tool with its owner, never on its own.

The second is the international organisation. The ITU is a United Nations specialised agency for telecommunication, headquartered in Geneva, and it sets standards; it does not operate networks or enforce law. A statement that the ITU will "block" fraudulent calls is a standard false option.

The third is the mechanism question, which is newer and more discriminating. Why is spoofing possible? Why can a national framework not fix cross-border spoofing? What does a cryptographic signature establish, and what does it not? These are reasoning questions dressed as factual ones, and the candidate who has understood attestation levels will answer all three from one idea.

The fourth is figures, which should be learnt as orders of magnitude with their source attached rather than as exact digits. Over 82 lakh connections disconnected, around 25 million app downloads, 1,600-plus organisations on the DIP, over β‚Ή5,000 crore of suspected losses prevented, losses to fraud above β‚Ή22,800 crore. Note that the disconnection count is reported differently in different replies β€” which is itself the useful lesson about telecom statistics.

For an interview, the distinction worth having ready is between authentication and intent. Verifying that a number is genuine does not make the caller honest; it only stops them borrowing an institution's authority. Being able to make that distinction crisply, and to say which frauds it defeats and which it does not, is a much better answer than reciting the five layers.

Preparing for NDA? On technology stories, find the design assumption that failed β€” here, that whoever originates a call can be trusted about the number. The mechanism is always more examinable than the announcement. Build the base with our NDA study material, follow the daily NDA current affairs, and prepare with our faculty in the upcoming Cavalier courses in Delhi.


✍️ Written by Col Vijyanat Thakur β€” Faculty, Science & Technology, at The Cavalier. Reviewed by the Cavalier Faculty Desk.