Caller Identity Authentication via STIR/SHAKEN Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identity spoofing techniques, often used in conjunction with robocalls, make it difficult for users to distinguish legitimate calls from malicious ones, leading to annoyance, resource wastage, and potential fraud, as traditional blocklists are easily thwarted by evolving spoofing methods.
Innovation Solution
A call security system that utilizes the STIR/SHAKEN framework to authenticate caller identities by adding cryptographic signatures, allowing users to verify the authenticity of calls through a carrier identifier, thereby restoring confidence in caller information and conserving resources by distinguishing between valid and malicious calls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional blocklists are used to filter robocalls, then some unwanted calls can be blocked, but identity spoofing techniques easily thwart these blocklists making them ineffective
Solution Approach 1:
The patent replaces the mechanical blocklist filtering system with a cryptographic authentication system. Instead of manually maintained lists that can be easily bypassed, the system uses digital signatures and cryptographic verification to authenticate caller identities, making spoofing extremely difficult without the proper cryptographic keys.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism between the caller and callee. The originating network signs the caller ID information cryptographically, and the terminating network verifies this signature, acting as a trusted mediator that prevents spoofing without requiring end users to manually update blocklists.
2Measurement precision
If cryptographic authentication is implemented for all calls, then caller identity verification is improved, but system complexity increases significantly
Solution Approach 1:
The patent implements a universal authentication framework that works across different networks and devices through standardized cryptographic protocols. The STIR/SHAKEN framework provides a multi-functional system that can authenticate various types of calls (voice, video, messaging) using the same cryptographic mechanisms, reducing overall system complexity through standardization.
Solution Approach 2:
The system enables networks to automatically sign and verify caller ID information without requiring manual intervention. The cryptographic authentication happens automatically in the background during call setup, making the complex verification process transparent to end users while maintaining high accuracy.
3Reliability
If manual review of caller information is required, then users can avoid some fraud, but user convenience and call acceptance rate decrease
Solution Approach 1:
The patent performs cryptographic authentication of caller identities in advance, before the user needs to make a decision about answering the call. The verification happens automatically during call setup, and users receive clear indicators of authentication status, eliminating the need for manual review while maintaining high fraud prevention capability.
Solution Approach 2:
The system uses visual indicators (such as colored badges or icons) to show the authentication status of incoming calls. This provides users with immediate, intuitive information about call legitimacy without requiring them to manually review technical details, maintaining both reliability and ease of operation.
Data Source
AI summary
In some implementations, a device may receive a SIP invite associated with a call to a first user device from a second user device. The first user device may be associated with a first network and the second user device may be associated with a second network that is separate from the first network. The SIP invite may include an identity header that indicates a carrier identifier associated with the second network. The device may authenticate the call based on a caller identification associated with the second user device and the carrier identifier. The device may send, based on authenticating the call, the SIP invite to the first user device to indicate, in association with receiving the call and via a user interface, an authorized entity associated with the carrier identifier according to the SIP update.


