Selective Attestation for VoIP Call Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication networks face challenges in verifying the authenticity of incoming calls due to data loss during handoffs between telecommunication providers, allowing nuisance calls and illegitimate spoofing to evade mitigation techniques, especially in Voice over Internet Protocol (VoIP) networks, which complicates interoperability and customer satisfaction.
Innovation Solution
Implementing a selective attestation system that verifies the identity of the originating client device based on the Administrative Operator Carrier Number (AOCN) or Operator Carrier Number (OCN) associated with the destination network, using the STIR/SHAKEN framework to ensure end-to-end authentication and assertion of telephone identity, by inserting attestation information into SIP messages to facilitate secure call handoffs across multiple networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If universal attestation is implemented across all networks, then call authentication reliability improves, but interoperability challenges and system complexity increase
Solution Approach 1:
The patent implements selective attestation where only specific networks (destination networks with valid AOCN/OCN) receive full attestation verification. This localizes the quality of authentication to where it is most needed, rather than uniformly applying it across all networks, thereby reducing overall system complexity while maintaining reliability for critical paths.
Solution Approach 2:
The attestation system is segmented into different levels: originating networks generate attestation, carrying nodes transport it, and destination networks validate it. This segmentation allows each component to perform its specific function without requiring full system complexity at every node, resolving the contradiction between reliability and complexity.
2Reliability
If attestation data is retained through all handoffs, then call authenticity verification improves, but data loss during handoff increases
Solution Approach 1:
The attestation certificate is generated and attached to the SIP message before the call traverses multiple networks. This preliminary action ensures the authentication data is established upfront and can be validated at any point along the transmission path, preventing data loss during handoffs while maintaining verification capability.
Solution Approach 2:
The attestation certificate acts as an intermediary object that carries authentication information through multiple network handoffs. Instead of requiring continuous data exchange between networks, the certificate serves as a self-contained mediator that preserves authentication data across all transitions, eliminating data loss.
3Object-affected harmful factors
If selective attestation based on AOCN/OCN is implemented, then nuisance call reduction improves, but ease of operation decreases
Solution Approach 1:
The system automatically performs selective attestation verification based on destination network identification (AOCN/OCN) without requiring manual configuration or user intervention. The carrying nodes and destination networks self-serve by autonomously determining whether to apply attestation based on the destination's properties, reducing nuisance calls while maintaining ease of operation.
Data Source
AI summary
The present disclosure describes techniques for selective attestation of a wireless communication session between an originating device and destination device. Attestation of the originating device identity depends in part on determining that the destination network associated with the destination device deploys a STIR/SHAKEN framework for end-to-end authentication and assertion of a telephone identity. This disclosure describes techniques to verify that the destination network has deployed the STIR/SHAKEN framework based on the administrative operator carrier number (AOCN) or operator carrier number (OCN) of the destination network. In response to determining the destination network has deployed the STIR/SHAKEN framework, a carrying node is configured to selectively generate instructions to include an attestation of an identity of the originating device in the SIP INVITE message sent to the destination network.


