Ask HN:绕过智能手机通话应用?通过 RTP 扩展实现静默 VoLTE
2 分•作者: sigureitimonnji•3 个月前
我设计了一个名为NVAP的协议,旨在消除在呼叫中心身份验证过程中通过语音播报个人信息的必要性。核心时间线逻辑请参见仓库中的 `docs/sequence.md` 文件。
为了绕过 iOS/Android 严格的 API/内核级 RTP 限制,我正考虑完全绕过原生通话应用,通过耳机层进行处理(利用 RFC 8285 / 9335 Cryptex)。
然而,在时间线和生物识别方面,我面临两个实际挑战:
1. **入站/出站时间线不匹配:** 在外呼电话中,如果对方立即接听;或在来电中,用户在将手机放到耳边之前按下接听按钮,VoLTE 连接会在耳机实际接触耳朵**之前**建立,从而破坏声学扫描的时间线。
2. **生物识别所有权:** 如果主生物识别数据位于智能手机的安全隔区 (Secure Enclave) 内,通过蓝牙进行数据来回传输会引入无线风险。
我很少听说有人以这种方式绕过智能手机的原生通话应用。以目前蓝牙/LE Audio 的技术栈来看,这在技术上是否可行?我很想听听您的想法,或者寻找贡献者来讨论如何克服这两个障碍并构建一个概念验证 (PoC)。
查看原文
https://github.com/sigureitimonnji/nvap-protocol
[EN]
I designed a protocol called NVAP to eliminate the need for vocalizing personal information during call center verification. Check docs/sequence.md in the repo for the core timeline logic.<p>To bypass the strict API/kernel-level RTP restrictions of iOS/Android, I'm thinking of completely bypassing the native call app and handling it via the earphone layer (utilizing RFC 8285 / 9335 Cryptex).<p>However, I am facing two practical challenges regarding the timeline and biometrics:<p>1. The Inbound/Outbound Timeline Mismatch: If the other party answers instantly on an outbound call, or if the user presses the answer button before putting the phone to their ear on an inbound call, the VoLTE connection starts BEFORE the earphone is actually in contact with the ear, ruining the acoustic scanning timeline.<p>2. Biometric Ownership: If the master biometric data is inside the smartphone's Secure Enclave, transferring data back and forth over Bluetooth introduces wireless risks.<p>I’ve rarely heard of anyone bypassing a smartphone's native call app this way. Is this technically feasible with current Bluetooth/LE Audio stacks? I'd love to hear your thoughts or find contributors to discuss how we can overcome these two obstacles and build a PoC.<p>[JP]
コールセンターの本人確認で、わざわざ個人情報を発声させられる不条理を解決するプロトコル「NVAP」を設計しました。コアロジックはリポジトリの docs/sequence.md にあります。<p>iOS/Androidの頑固なRTP制限を避けるため、スマホの通話アプリを完全にスルーしてイヤホンレイヤーで処理すること(RFC 8285 / 9335 Cryptexの利用)を考えています。しかし、タイムラインと生体認証に関して、現在以下の2つの現実的な課題に直面しています。<p>1. 発着信時のタイムラインのミスマッチ:発信時に相手が秒で出た場合や、着信時に耳に当てる前に応答ボタンを押した場合、イヤホンが耳に密着する前にVoLTE回線が繋がりRTPパケットが飛び出してしまうため、耳音響スキャンのタイムラインが崩れてしまう。<p>2. 生体データの所有権:耳紋の正解データがスマホのSecure Enclave内にある場合、Bluetoothを介してデータをやり取りするのは無線区間のリスクがある。<p>スマホの純正通話アプリをこんな風にバイパスする話はあまり聞いたことがありません。現在のBluetoothやLE Audioの仕様でこれは技術的に可能でしょうか?低レイヤーに詳しい方の知見を聞きたいですし、この2つの障害をどう乗り越えてPoCを作るか、ぜひ皆さんのアイデアを聞かせてください。