STIRSHAKEN
STIR/SHAKEN is a set of standards and best practices designed to combat caller ID spoofing in IP-based telephone networks. STIR, or Secure Telephone Identity Revisited, specifies how to convey cryptographic identity information for outgoing calls, while SHAKEN, standing for Signature-based Handling of Asserted information using toKENS, provides a policy framework for how carriers should handle and convey that information as calls are originated, forwarded, and terminated. Together, they aim to increase trust in caller ID and reduce robocalls and fraudulent activity.
Technical basis and operation: The core mechanism uses digital certificates and a SIP Identity header to bind
Deployment and scope: STIR/SHAKEN was developed in and is heavily promoted in the United States under regulatory
Limitations and impact: STIR/SHAKEN improves the ability to detect spoofed calls but does not eliminate spoofing