STIR SHAKEN
FAQs
What is STIR/SHAKEN?
STIR/SHAKEN is a technology framework designed to help reduce fraudulent robocalling and illegal phone number spoofing. It uses protocols that allow service providers to create and verify a digital signature for a call that includes calling party information to securely pass to downstream carriers its assertion of the authenticity of the calling party and the calling number. STIR/SHAKEN is necessary because it is far easier to spoof an outbound display number (Calling Line Identification, or CLI) using IP voice than it was using traditional TDM technology. The regulators in the United States (FCC) and Canada (CRTC) have ordered carriers to implement STIR/SHAKEN in their networks for all traffic that originates in the USA or Canada for termination in the USA or Canada. France has also implemented a version of call authentication similar to STIR/SHAKEN. Other countries may also choose to do so depending on the success of other measures that they are taking to try to reduce scam calls.
Who must add the digital signatures?
Consider a voice call to have three (or more) segments:
-
Originating Service Provider. The carrier serving the end user making the call. The Originating Service Provider has the obligation to add the digital signature when the call is initiated.
- Terminating Service Provider. The carrier serving the end user receiving the call. The Terminating Service Provider has the obligation to verify that the digital signature is valid.
- Intermediate Provider(s). Any carrier(s) between the Originating Service Provider and the Terminating Service Provider. The Intermediate Provider has the obligation to pass through any digital signature that it receives. The Intermediate Provider may, but is not required to, add a digital signature for a call it receives without a digital signature. In most cases, TC America and TC Canada are intermediate providers.
What is in the digital signatures?
The digital signatures are encrypted and contain one of three levels of attestation. The attestation is the level of trust that the calling party and the calling number are authentic.
-
Level-A or Full Attestation: The carrier adding the digital signature claims to know the identity of the party making the call, and it asserts that the number being displayed is a legitimate number assigned to the customer.
- Level-B or Partial Attestation: The carrier adding the digital signature claims to know either the identity of the party making the call, or it asserts that the number being displayed is a legitimate number assigned to the customer.
- Level-C or Gateway Attestation: The carrier adding the digital signature knows neither the identity of the party making the call, nor that the number being displayed is a legitimate number assigned to the customer. The carrier is attesting only that the call arrived on its network without any attestation.
How do I have my calls attested with Level A so as to reduce the likelihood of them being labelled as SPAM?
Speak with your Tata Communications account manager. If you are an enterprise customer and are only using CLI numbers for your outbound calls, which are provided to you by Tata Communications, then we will be able to work with you on arranging A Level attestation.
What do carriers do with the Attestations?
Terminating carriers use the attestations to determine what notification should be sent to the called party. Terminating carriers combine the attestations with other analytical software and call parameters, which may include data on historical traffic patterns from a given number, to notify a called party whether the carrier considers the number to be “valid,” or “likely spam,” for example. Attestations alone are usually not used. As a result, a call with an A attestation — which means the calling party and number are known to the originating carrier — could be labelled as “likely spam” if the terminating carrier has other information about the number or calling party being analysed.
In addition to STIR/SHAKEN certificates are there other reasons that calls could be blocked or labelled as 'Spam'?
Even if your organisation has:
- A-Level STIR/SHAKEN Attestation;
- Free caller registry registration (see next question);
- Configured a specific branded caller ID, sometimes referred to as CNAM; and
- Valid and authorised CLIs,
your calls can still be labelled Spam Likely, Potential Spam, or Scam Likely by downstream carriers and reputation analytics providers. Carriers evaluate not only caller identity, but also calling behaviour, customer feedback, call patterns, and reputation signals.
All of the primary service providers in the US are now also using information from analytics providers to further evaluate and label calls.
I have legitimate traffic using a USA number as outbound CLI and Tata Communications is already attesting calls with Level A but some carriers are still tagging my calls as 'likely spam.' How can I correct that?
Sites are available to provide information to terminating carriers that have tagged traffic as “likely spam.” Customers will need to complete the process themselves. It is recommended to proactively register numbers with the analytics providers (See Appendix A) to minimise inadvertent call labelling. A list of sites is attached as Appendix A. Please note this is not a comprehensive list.
What happens if traffic does not have a digital signature?
If an Intermediate Provider does not add Level-C or Gateway Attestation, the call will be delivered to the Terminating Service Provider without any digital signature. Calls without digital signatures will not be blocked at this time, although they could receive negative labelling such as “Possible Spam.” However, even signed calls could receive negative labelling as doing so is at the discretion of the terminating carrier and their call analytics partners.
Does STIR/SHAKEN require call filtering?
The STIR/SHAKEN protocols are not call filtering systems. They are digital signatures indicating a carrier’s assessment of the authenticity of customers and numbers. Most terminating carriers have implemented separate robocall filtering measures or are expected to do so. The level of attestation on a call is likely to be one input into the call filtering measures taken by terminating carriers and their analytics partners. TC will continue to apply its Fraud Prevention measures as it has in the past. STIR/SHAKEN does not require any call-blocking as currently implemented by the FCC. There is potential for call-blocking of international voice traffic as discussed below, but this is apart from implementation of STIR/SHAKEN.
What rules apply to traffic originated outside the United States or Canada?
In Canada, the rules only require implementation of STIR/SHAKEN and robocall mitigation. There are no specific rules regarding international traffic.
In the United States, a foreign voice service provider that uses USA numbering resources as the display CLI for calls to be terminated in the USA must do two things: (1) it must register in the FCC Robocall Mitigation Database, and (2) it must file a Robocall Mitigation Plan describing the steps it is taking to reduce robocall traffic into the USA. (A customer has the option of satisfying (2) by implementing STIR/SHAKEN in its network, but this is not a requirement).
All of the TC affiliates that handle international voice traffic have been registered in the FCC Robocall Mitigation Database. A list of affiliates with their RMD registration numbers is attached as Appendix B.
The FCC rules apply to any foreign voice service provider that has the ability to originate traffic that uses a USA CLI. We expect this requirement to apply to all customers handing TC traffic to terminate in the USA. If a carrier does not serve any end users, and is acting solely as an intermediate transit provider, we recommend registering in the foreign carrier database anyway in order to avoid potential complications.
The legitimate traffic that uses USA numbers as outbound CLI, and therefore potentially subject to the call-blocking regime for unregistered foreign voice service providers, would be USA-number roaming traffic, legitimate call-center traffic, and app/platform-based traffic (e.g., Skype) into the USA. The FCC is aware that there are legitimate reasons to have USA numbers as outbound CLI for calls originated outside the USA, so it wants to permit this traffic while blocking illegitimate fraudulent traffic. The FCC expects foreign voice service providers to differentiate and block illegitimate traffic.
Do customers have to register in the Robocall Mitigation Database?
No. Only foreign voice service providers (carriers) that are sending traffic to the USA that has a USA number as the outbound CLI must register in the Robocall Mitigation Database.
What is the consequence of a foreign voice service provider failing to register in the Robocall Mitigation Database?
The operator which receives a call into the US with a USA-number is required to block that call. Tata Communications is set up to and does block such calls.
Can TC help an operator to register in the FCC Robocall Mitigation Database?
Operators must register for themselves. TC cannot register on its behalf. Instructions can be found here:
-
Robocall Mitigation Database Notice https://www.fcc.gov/document/robocall-mitigation-database-opens-filing-instructions-and-deadlines
-
Robocall Mitigation Database Welcome Page https://fccprod.servicenowservices.com/rmd?id=rmd_welcome
Does Canada-to-USA traffic fall under the rule requiring registration in the Robocall Mitigation Database?
Foreign voice service providers that use USA numbers as outbound CLI for traffic into the US must register in the Robocall Mitigation Database. If traffic from Canada uses USA CLI, then the carrier handling that call must be registered in the Robocall Mitigation Database.
How will my US LNS or ITFS numbers be affected?
LNS/DID and ITFS numbers have been provided to you as an inbound service. They will not be affected by STIR/SHAKEN since only the party calling the number is subject to the attestation requirement.
US regulations require us to review all international traffic entering the US that uses US LNS or US ITFS numbers as your outbound CLI presentation. The US regulator has identified international traffic using US numbers as likely to be robocalls or fraudulent traffic. Among other measures, we reserve the right to block any traffic using a US LNS or US ITFS number that we have not provided to you because we do not have the ability to confirm that you have proper authority to use the numbers as outbound CLI. Further, we also reserve the right to block any traffic using a US LNS or US ITFS number that we have provided to you if we determine that we need to do so in order to manage robocall or suspicious traffic.
Will TC America be adding A-Level or B-Level attestation to its international enterprise traffic?
TC America is negotiating with US terminating suppliers to add attestation to its international enterprise traffic. Note, however, that even if A-Level or B-Level attestation is added, the terminating carrier will apply its own standards to determine what validation message will be sent to called parties. It is likely that A-Level or B-Level traffic will be labelled as “Potential Spam” if the call parameters trigger the terminating carrier’s analytics for suspicious traffic. Such analytics are outside the control of TC America, so adding A-Level or BLevel attestation does not guarantee that traffic will avoid being labelled as Spam. Customers that believe that their traffic is being inappropriately labelled can follow the steps at the websites listed in Appendix A or engage a vendor that provides call-reputation scoring.
Will TC America be adding C-Level attestation on international traffic that does not use USA numbers as outbound CLI?
Intermediate providers receiving international traffic are not required to add C-Level attestation. TC America will not be adding C-Level attestation at this time. Other intermediate providers in the call path may add CLevel attestation, but they are not required to do so.
What specific rules apply to Call Center traffic?
In order to reduce the likelihood of calls being blocked by Tata Communications, Call Centre customers should adhere to the following:
- Call Centers that use US LNS or US ITFS numbers as outbound CLI must ensure that they are sending only legitimate traffic. All traffic from a customer is likely to be blocked if we determine any traffic must be blocked in order to manage robocall or suspicious traffic.
- Outbound CLI must only use numbers provided to the customer by an authorised carrier. We reserve the right to block any traffic using a US LNS or US ITFS number that we have not provided to you because we do not have the ability to confirm that you have proper authority to use the numbers as outbound CLI. Further, we also reserve the right to block any traffic using a US LNS or US ITFS number that we have provided to you if we determine that we need to do so in order to manage robocall or suspicious traffic.
- Outbound CLI must be displayed in E.164 format.
- Any call returned to the displayed number must be able to be answered. A return call can be answered by IVR. However, an IVR recording that does not identify the Call Centre is likely to be considered suspicious and subject to blocking.
- Tata Communications cannot provide legal advice for Call Centres to comply with rules applicable to Call Centres. The following links to regulators may be helpful:
Appendix A
Sites to Provide Information to Remove “Likely Spam” Tagging
Registering your phone numbers with the companies that provide “Analytics Engine” services to the major service providers is the simplest method. This can be done either proactively (recommended) or after any reports of inappropriate labelling.
Registering your numbers at the Free Caller Registry site covers 3 of the most prominent Analytics Providers (First Orion, Hiya, and TNS) with a single submission
Free Caller Registry:
https://www.freecallerregistry.com/fcr/
The Analytics Providers can also be contacted individually.
First Orion:
http://www.calltransparency.com/
Used by T-Mobile
Hiya:
http://www.hiya.com/manageyourcallerid
Used by AT&T
Transaction Network Services (TNS):
http://www.reportarobocall.com/trf/
Used by Verizon, Comcast, Sprint/US Cellular, Spectrum
Neustar:
http://www.home.neustar/support
(Refer to the contact information under Communications, Robocall Mitigation)
A few individual service provider reporting sites are listed below. Note: In some instances, the sites may automatically redirect to an Analytics Provider site.
| AT&T: | https://www.att.com/reviewmycalllabel |
| Verizon: | https://www.voicespamfeedback.com/vsf/ |
| T-Mobile: | https://feedback.fosrvt.com/ |
| Sprint/US Cellular: | http://reportarobocall.com/ |
| TrueCaller: | https://support.truecaller.com/support/solutions/articles/81000392600 |
| NOMOROBO: | http://www.nomorobo.com/contact (choose “Report a number”) |
The US Telecom site has contact/redress information for additional service providers and analytics services
https://www.ustelecom.org/the-industry-traceback-group-itg/call-labeling-and-blocking-points-of-contact/
Appendix B
Robocall Mitigation Database Registrations
| Tata Communications (America) Inc. | RMD0003179 |
| Tata Communications (Australia) Pty Limited | RMD0004078 |
| Tata Communications (Canada) Ltd. | RMD0001838 |
| Tata Communications Deutschland Gmbh | RMD0003175 |
| Tata Communications (Hong Kong) Limited | RMD0004445 |
| Tata Communications International Pte. Ltd. | RMD0004082 |
| Tata Communications Lanka Limited | RMD0004900 |
| Tata Communications Limited | RMD0004787 |
| Tata Communications (Spain), S.L. | RMD0004448 |
| Tata Communications (UK) Limited | RMD0003172 |
What’s next?
Experience our solutions
Engage with interactive demos, insightful surveys, and calculators to uncover how our solutions fit your needs.
Exclusively for you
Get exclusive insights on the Tata Communications Digital Fabric and other platforms and solutions
