Glossary · Protocols and standards
STIR/SHAKEN
The caller ID authentication framework for IP phone networks: the originating carrier signs the calling number, and the receiving carrier verifies it.
STIR/SHAKEN is the caller ID authentication framework for IP-based phone networks, in which the originating carrier signs the calling number on a call and carriers downstream verify that signature before the call reaches the person or system that answers.
The two halves. STIR (Secure Telephone Identity Revisited) is the IETF work. RFC 8224 adds an Identity header to SIP that carries a signed token, RFC 8225 defines that token, the PASSporT, and RFC 8226 defines the certificates that sign it. SHAKEN (Signature-based Handling of Asserted information using toKENs) is the industry profile from ATIS and the SIP Forum that tells carriers how to deploy STIR. RFC 8588 adds the SHAKEN-specific claims to the PASSporT.
Attestation levels. The attest claim records how much the signing carrier vouches for:
A, full attestation: the carrier originated the call, can identify its customer, and has verified the customer’s association with the calling number.B, partial attestation: the carrier originated the call and can identify the customer, but has not verified the association with the number.C, gateway attestation: the carrier is only the call’s entry point into its network and has no relationship with the caller, as at an international gateway.
The origid claim is a UUID that lets the signing carrier identify where the call originated within its network. A decoded SHAKEN PASSporT payload, following RFC 8588 with its claim keys in lexicographic order (illustrative values):
{"attest": "A", "dest": {"tn": ["12155550131"]}, "iat": 1790445600, "orig": {"tn": "12155550121"}, "origid": "123e4567-e89b-12d3-a456-426655440000"}
Regulation. In 2020 the FCC required US voice service providers to implement STIR/SHAKEN in the IP portions of their networks by 30 June 2021, and it has since extended the obligation to more provider types. In Canada, CRTC Decision 2021-123 required it for IP-based voice calls from 30 November 2021.
Limits. STIR/SHAKEN covers only IP networks and authenticates only the calling number. It does not say what software is speaking, which person or company it represents, or what it is authorized to do.
Neighbouring terms. SIP carries the Identity header. A PASSporT is built on JWT and JWS.
Sources
- RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) (accessed )
- RFC 8225: PASSporT: Personal Assertion Token (accessed )
- RFC 8226: Secure Telephone Identity Credentials: Certificates (accessed )
- RFC 8588: PASSporT Extension for SHAKEN (accessed )
- ATIS-0300116: Interoperability Standards between Next Generation Networks for SHAKEN (attestation levels) (accessed )
- FCC: Combating Spoofed Robocalls with Caller ID Authentication (accessed )
- Compliance and Enforcement and Telecom Decision CRTC 2021-123: STIR/SHAKEN implementation for IP-based voice calls (accessed )