STIR/SHAKEN ID Headers for VoIP Authentication and PSTN Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional VoIP call routing through PSTN is inefficient and computationally resource-intensive, lacking automation and effective accountability mechanisms, particularly in interconnects between service providers.

Innovation Solution

Implementing an identity (ID) header with a public encryption key from a certificate authority infrastructure to authenticate and trace VoIP calls, allowing them to bypass PSTN and establish billing relationships through a public proxy/platform, using a STIR/SHAKEN ID header for administrative traceback and billing purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If VoIP calls are routed through PSTN and firewalls using conventional manual interconnect methods, then calls can be established between providers, but the process is inefficient, computationally resource intensive, and lacks automation

Engineering Contradiction:
Improvecall routing efficiencyVSAvoidmanual interconnect complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system enables self-service through automated validation of ID headers containing cryptographic signatures. The public proxy automatically validates signatures, traces calls to source providers, and establishes billing relationships without manual intervention, replacing complex manual interconnect processes with autonomous cryptographic verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A public proxy acts as an intermediary between VoIP networks and PSTN, validating ID headers and enabling automated routing. This intermediary simplifies the interface between different networks by centralizing validation and traceback functions, reducing the complexity of direct provider-to-provider manual interconnects

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If manual business relationships and contracts are established between providers for traffic exchange, then interconnects can be set up, but the process is not automatic and requires manual configuration

Engineering Contradiction:
Improvecall routing automationVSAvoidmanual setup time
Core Design Contradiction:
Extent of automationVSLoss of time

Solution Approach 1:

The system replaces manual business relationship setup with self-service automated validation. ID headers containing cryptographic signatures enable the public proxy to automatically verify provider identity and establish billing relationships without manual contract configuration, dramatically reducing setup time and enabling instant interconnect activation

Inventive Principle:
Principle #25Self-service

3Reliability

If conventional routing methods are used without cryptographic authentication, then call routing can proceed, but accountability and traceability to source providers are insufficient

Engineering Contradiction:
Improvecall source accountabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The public proxy serves as a trusted intermediary that validates cryptographic signatures in ID headers, providing reliable authentication and traceback capabilities. This centralized validation mechanism ensures accountability to source providers while managing authentication complexity in one location rather than requiring distributed verification across all network elements

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12166926B2Using STIR/SHAKEN ID headers to allow access into VoIP networks
Publication Date: 2024.12.10 GOOGLE LLC
  • US12166926B2 patent drawing
  • US12166926B2 patent drawing
  • US12166926B2 patent drawing

AI summary

The subject matter described herein provides systems and techniques for adding an identity (ID) header to IP packets associated with a VoIP call. This ID header may be used to authenticate the source provider/originator of a VoIP call, may be used to traceback to the source provider/originator of the VoIP call, and may be used to create a relationship between the source provider/originator and the destination provider/destination of the VoIP call. Such steps may be performed by a public proxy/platform. The ID header may include a certificate and/or a public encryption key, from a public certificate authority (CA) infrastructure, which assists in authenticating the source provider/originator of the VoIP call. The public proxy/platform may directly route authenticated VoIP calls through a VoIP network towards its destination, bypassing a public switched telephone network (PSTN).