Call Authentication
An approved certification authority that issues the X.509 certificates carriers use to cryptographically sign outbound calls.
An STI-CA issues a signing certificate only after the requesting provider presents a valid token from the STI-PA. The certificate embeds the provider's Service Provider Code so that verification services can identify who signed a call.
Certificates are short-lived by design and must be rotated regularly. The certificate is published at a public repository URL, which is the address carried in the Identity header's 'x5u' parameter.
An unreachable or expired certificate repository causes every downstream verification to fail even though your signing is working perfectly. Monitor that public URL like any other production endpoint.
The central authority that decides which providers are eligible to obtain STIR/SHAKEN signing certificates and issues the tokens needed to request them.
The SIP header that carries the signed PASSporT token proving a call's caller ID was authenticated by the originating provider.
The originating-side service that decides an attestation level, builds the PASSporT, signs it, and inserts the Identity header into the outbound SIP INVITE.
The FCC-mandated framework that cryptographically signs calling numbers so terminating carriers can verify the caller ID was not spoofed.
SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.