STIR/SHAKEN Overview

STIR/SHAKEN is an industry-standard framework designed to prevent Caller ID spoofing. NovoOne platform allows you to configure STIR/SHAKEN for trunks, enabling signed outbound calls and verified inbound calls to ensure caller ID authenticity and build trust with customers.

Applicable scope

STIR/SHAKEN (outbound call signing and inbound call verification) can be configured only for Register Trunk and Peer Trunk.

Terminology

The table below outlines the key terminologies for STIR/SHAKEN.

Term Description
STIR Secure Telephone Identity Revisited. The technical protocol that defines how digital signatures are created and verified for SIP calls.
SHAKEN Signature-based Handling of Asserted Information using toKENs. The industry framework that specifies how STIR is implemented and deployed across telecommunications networks.
STI-AS STI Authentication Service. The entity at the originating provider that signs outgoing calls and assigns an attestation level.
STI-VS STI Verification Service. The entity at the terminating provider that validates the signature of incoming calls.
Attestation A trust level (A, B, or C) assigned to a signed call, indicating the degree of confidence the originating provider has in the caller's identity and their right to use the calling number.

Caller ID authentication

To comply with the STIR/SHAKEN framework, the caller needs to digitally sign outbound calls, and the called party needs to verify inbound calls.

The following features are available to support caller ID authentication in different communication roles.

Sign outbound calls
When outbound call signing feature is enabled for a trunk, the system (as the calling party) digitally signs all outbound calls routed through the trunk (excluding emergency and anonymous calls), enhancing the call credibility.

For more information, see the following topics:

Verify inbound calls

STIR/SHAKEN supports two inbound verification methods. The key difference is whether the system (as the called party) performs verification itself or relies on verification results provided by the up-streaming ITSP.

Method Description Instruction
Inbound call verification The system directly verifies the signature of inbound calls routed through the trunk, and reject calls based on the global rejection criteria configured in the STIR/SHAKEN module.
Inbound call filtering ITSP verifies the calls and sends the verification results to the system.

The system then uses these verification results to reject calls based on the specific rejection criteria configured on the shared trunk.

Enable Inbound Call Filtering for a Trunk