STIR/SHAKEN (Secure Telephone Identity Revisited / Signature-based Handling of Asserted information using toKENs)

Also known as: STIR, SHAKEN, RFC 8224, RFC 8225

STIR/SHAKEN is the caller ID authentication framework for SIP-based voice networks. STIR (IETF RFC 8224/8225) defines PASSporT tokens signed by the originating provider that assert the calling number and an attestation level (A, B or C). SHAKEN (ATIS) is the North American deployment profile covering certificate governance, SIP Identity header transport across interconnects and verification at the terminating side, aimed at curbing illegal caller ID spoofing and robocalling.

Categories: SignalingSecurity ControlsThreats and Attacks

STIR/SHAKEN in context

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

To place STIR/SHAKEN in the wider telecom-security picture, review Global Title Abuse, Indicators of Compromise (Telecom IoCs), IPS, PCAP, 1G and 5G SBA — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.