Extending shaken framework to validate and verify device identity
Patent Information
- Application Number
- GB2024000450
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-07-16
- Estimated Expiration
- Not applicable · inactive patent
Smart Images

Figure 00000000_0000_ABST
Abstract
Claims
What is claimed is:
1. An apparatus, comprising: at least one processor; and at least one memory storing instructions, that when executed by the at least one processor, cause the apparatus at least to:identify a session initiation protocol INVITE comprising an indication of a caller identity;based on the identifying, initiate an origination trigger to an identity authenticationservice (STI-AS) for the session initiation protocol INVITE, wherein the identity authentication service functions as an authentication service for device identity; anddetermine whether to accept the session initiation protocol INVITE based on a legitimacy of the caller identity being used in the session initiation protocol INVITE.
2. The apparatus of claim 1, wherein the identifying comprises extracting the caller identity and extracting the device identity from a contact international mobile station equipment identity parameter of the session initiation protocol and performing validation of both identities.
3. The apparatus of claim 1, wherein the identity authentication service comprises a secure telephone identity authentication service and a secure telephone identity verification service.
4. The apparatus of claim 3, wherein at least one of the secure telephone identity authentication service or the secure telephone identity verification service is used for the caller identity and the device identity.
5. The apparatus of claim 1, wherein the at least one memory stores furtherinstructions, that when executed by the at least one processor, further cause the apparatus at least to:create an emergency session initiation protocol INVITE with a telephone identity; andbased on the creating, add a device identity to a session initiation protocol contact header.
6. The apparatus of claim 1, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:identify an identity header field identifying the caller identity of an originating session initiation protocol UA.
7. The apparatus of claim 1, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:validate an international mobile station equipment identity parameter of the device identity; andcommunicate an origination trigger to the identity authentication service for the session initiation protocol INVITE.
8. The apparatus of claim 7, wherein the identity authentication service is invoked for both the caller identity and the device identity if present in a session initiation protocol contact header.
9. The apparatus of claim 1, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:use service provider specific means and device validation procedures for determining whether there is legitimacy of a secured telephone identity based on a determined legitimacy of the caller identity and the device identity based on a presence in the session initiation protocol INVITE.
10. The apparatus of claim 1, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:add at least one identity header field using the caller identity in an identity header field; and add a new session initiation protocol header for device identity.
11. The apparatus of claim 10, wherein the identity header field comprises a JSON web token and at least one parameter, wherein the at least one parameter comprises at least one of: info, alg, and Ppt, wherein the JSON web token comprises at least one of a header, payload, or signature, wherein alg indicates the encryption algorithm, wherein Ppt - indicates the token type.
12. The apparatus of claim 11, wherein alg indicates the encryption algorithm and must be ES256, and wherein Ppt indicates the token type and must be passport.
13. The apparatus of claim 1, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:communicate with a terminating network side, an updated session initiation protocol INVITE message with a caller identity and a device identity validated.
14. The apparatus of claim 1, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:route a call to an egress interconnection border control function (IBCF), wherein the session initiation protocol INVITE is routed over network to network interface (NNI) through a standard inter-domain routing configuration.
15. The apparatus of claim 14, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:terminate a service provider (SP) ingress, where the interconnection border control function receives the session initiation protocol INVITE over NNI.
16. The apparatus of claim 15, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:initiate a terminating trigger to the secure telephone identity verification service for the session initiation protocol INVITE to verify the caller identity and the device identity validation results.
17. The apparatus of claim 16, wherein the terminating uses an“x5u” field in PASSporT Protected header to determine the secure telephone identity certificate repository (STI-CR) uniform resource identifier (URI) and connects to it.
18. The apparatus of claim 17, wherein the PASSporT Protected header is identifying a service provider that is vouching for the device identity and indicating what information the service provider is attesting to.
19. The apparatus of claim 18, wherein the attesting is using a “devAttest” indication comprising one of a “D” or “E” values, wherein the values correspond to “Full Device Attestation” and “No Device Attestation” respectively.
20. The apparatus of claim 18, wherein the Full Device Attestation “D” means the service provider has validated the device ID and has control over the device, and wherein the No Device Attestation “E” means the service provider could not validate the device identity and the identity seems invalid.
21. The apparatus of claim 17, wherein the secure telephone identity verification service (STI-VS) uses a new field “x6u” or other value to determine the secure telephone identity certificate repository uniform resource identifier (URI) for device identity validation.
22. The apparatus of claim 16, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:validate using the secure telephone identity verification service (STI-VS) certificates for the caller identity and the device identity, and extract respective public keys.
23. The apparatus of claim 16, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:drop an emergency call for which caller identity is not present and device identity validation fails.
24. The apparatus of claim 16, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:based on a secure telephony identity verification result, determine that the call is to be completed with the appropriate “verstaf ’ and “devstaf ’ values.
25. The apparatus of claim 24, wherein a value for devstat would be one of: “D” - device-identity-validation-passed, or “E” - device-identity-validation-failed.
26. The apparatus of claim 24, wherein the at least one memory stores further instructions, that when executed by the at least one processor, further cause the apparatus at least to:based on determined caller identity verification error conditions, define a device identity verification as a value of: 403, New 4xx, or 437.
27. The apparatus of claim 26, wherein the value of 403 is retained, the value New 4xx indicates one of a “Use devidentity” header or a “Bad device identity info” header or “Invalid devidentity” header, and the value 437 indicates “Unsupported credential”.
28. A method, comprising:identifying a session initiation protocol INVITE comprising an indication of a caller identity;based on the identifying, initiating an origination trigger to an identity authentication service (STI-AS) for the session initiation protocol INVITE, 5 wherein the identity authentication service functions as an authenticationservice for device identity; anddetermining whether to accept the session initiation protocol INVITE based on a legitimacy of the caller identity being used in the session initiation protocol INVITE.10
Citation Information
Patent Citations
System and method of admission control of a communication session
US20170289207A1
Phone call endpoint security
US20220166751A1
Systems and methods for stir-shaken attestation using spid
US20230284016A1