The SBC as Authentication and Verification Point for STIR/SHAKEN
Caller ID used to be trivial to fake, which is a large part of why illegal spoofing and robocalls became so common. A receiving provider had no way to know whether the number on an incoming call was legitimate or forged, and neither did the person answering the phone.
The FCC now requires voice service providers to sign their outbound calls and verify inbound ones using a cryptographic framework. Making that work in a live network means applying the signing and verification at the right place, consistently, across all traffic, without adding another device to the call path.
How STIR/SHAKEN Works at the SBC
STIR/SHAKEN is a framework in which the originating service provider attaches a cryptographically signed identity token to a call, so the terminating provider can retrieve the originating provider’s certificate and verify that the call’s origin is legitimate. The originating side makes a signed claim about the call, and the terminating side checks it.
The session border controller is where this happens in a live network. The SBC is already the point every call crosses on its way in or out, which makes it the natural place to sign outbound calls and verify inbound ones without adding a separate box. It integrates with a signing and verification service that performs the cryptographic work, and the SBC applies the result to the live call.
The detail of how strongly a provider vouches for a call is the subject of STIR/SHAKEN attestation levels, and the full mechanics of getting it running are covered in the STIR/SHAKEN SBC implementation guide.
STIR/SHAKEN at the SBC: the originating SBC works with an authentication service to sign the call, and the terminating SBC works with a verification service to validate the token. Click to enlarge.
What the SBC Does for STIR/SHAKEN
Authenticating Outbound Calls
On the originating side, the SBC works with the authentication service to sign each outbound call, attaching the cryptographic identity token that represents the provider’s attestation. Because the SBC sees every outbound call, it applies signing consistently across all traffic leaving the network.
Verifying Inbound Calls
On the terminating side, the SBC works with the verification service to check the token on each inbound call, and it acts on the outcome so the terminating provider can tell the end user whether the call is attested. This turns a signed call into useful information for the person receiving it.
Fitting the Framework to the Network
The SBC connects to the signing and verification service the operator uses and handles STIR/SHAKEN alongside the rest of its security work at the edge. For the broader context, see the STIR/SHAKEN solution page.
Deploy It Your Way
STIR/SHAKEN at the SBC can be operated in whatever model an operator prefers:
Self-Managed
Run ProSBC as software on your own infrastructure and configure the signing/verification integration directly. Full control over attestation policies and service partner selection.
Managed Service
Hand deployment and operation to TelcoBridges through the ProSBC managed service. The STIR/SHAKEN integration is configured and maintained as part of the managed edge, a common choice for smaller operators navigating compliance.
Fully Hosted
TelcoBridges hosts and manages the SBC entirely, including the signing and verification integration. The operator gets STIR/SHAKEN compliance without building the integration itself.
Frequently Asked Questions
What does the SBC do in STIR/SHAKEN?
The SBC acts as the point where outbound calls are authenticated (signed) and inbound calls are verified. It works with a signing and verification service to attach the cryptographic identity token on the way out and check it on the way in, applying the result to the live call.
What is the difference between authentication and verification?
Authentication happens on the originating side, where the call is signed to create the identity token. Verification happens on the terminating side, where that token is checked to confirm the originating provider vouched for the call. The SBC can perform both roles depending on the direction of the call.
Why is the SBC the right place for STIR/SHAKEN?
The SBC is already the point every call crosses entering or leaving the network, so signing and verifying there avoids adding another device to the call path. It applies the framework consistently to all traffic without changing how the rest of the network operates.
Does the SBC do the cryptography itself?
The SBC integrates with a signing and verification service that performs the cryptographic work, and the SBC applies the result to the call, adding the signed identity on outbound calls and acting on the verification outcome on inbound calls.
Run STIR/SHAKEN at the Edge with ProSBC
Talk to a solutions architect about deploying STIR/SHAKEN with ProSBC, or start evaluating on your own.
Prefer to evaluate on your own first? Start your 30-day free trial.