Voice Fraud & Compliance Wiki

    Call Authentication

    STI-CASecure Telephone Identity Certification Authority

    An approved certification authority that issues the X.509 certificates carriers use to cryptographically sign outbound calls.

    An STI-CA issues a signing certificate only after the requesting provider presents a valid token from the STI-PA. The certificate embeds the provider's Service Provider Code so that verification services can identify who signed a call.

    Certificates are short-lived by design and must be rotated regularly. The certificate is published at a public repository URL, which is the address carried in the Identity header's 'x5u' parameter.

    Why it matters to carriers

    An unreachable or expired certificate repository causes every downstream verification to fail even though your signing is working perfectly. Monitor that public URL like any other production endpoint.

    Handling sti-ca on your own switch

    SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.