STIR/SHAKEN (Secure Telephone Identity Revisited / Signature-based Handling of Asserted information using toKENs)
Also known as: STIR, SHAKEN, RFC 8224, RFC 8225
Categories: SignalingSecurity ControlsThreats and Attacks
STIR/SHAKEN in context
Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.
Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.
To place STIR/SHAKEN in the wider telecom-security picture, review STIR, Global Title Abuse, ISUP, SIP, RTP and CLI Spoofing: each entry cross-references back to this page so you can walk the topic in either direction.
Related terms
Related topic hubs
- Diameter Security 4G/LTE Diameter threats across IPX/roaming and DEA defenses.
- Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.
- Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.
- Roaming Security IPX/GRX interconnect risk, home-routed vs local-breakout, SEPP.
More from the TelcoSec Glossary
Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.