STIR/SHAKEN Attestation Levels Explained
Understand the mechanics of digital call signing, the critical difference between A, B, and C-level attestation, and how network pathing directly dictates your answer rates.
What STIR and SHAKEN Actually Are
While often spoken as a single acronym, STIR and SHAKEN represent two distinct halves of the North American call authentication ecosystem. Understanding the difference is critical for telecommunications engineers tasked with routing outbound traffic reliably.
STIR (Secure Telephone Identity Revisited) defines the technical IETF protocol suite. It outlines exactly how digital certificates are used to securely sign a SIP call. It dictates the cryptographic creation of a JSON Web Token (JWT) that asserts the caller's identity and bounds it to the SIP INVITE.
SHAKEN (Signature-based Handling of Asserted information using toKENs) is the operational ATIS framework. It governs how the telecommunications industry actually implements STIR. SHAKEN establishes the certificate authorities, the policy administrator, and the rigid rules determining which providers are allowed to hold signing certificates and how they must apply them to live network traffic.
How a Call Gets Signed and Verified End-to-End
Call authentication operates on a public key infrastructure (PKI) model applied to SIP signaling. When a call originates on an authorized carrier's network, the switch constructs a PASSporT (Personal Assertion Token) payload containing the calling number, the called number, and a timestamp.
The originating provider signs this PASSporT using its private cryptographic key (SP-KI). The resulting base64-encoded token is injected into the SIP INVITE as the 'Identity' header before the call is routed outward across the PSTN.
When the SIP INVITE reaches the terminating carrier (the provider hosting the destination handset), that switch parses the Identity header. It extracts the URI located in the 'info' parameter, fetches the originating provider's public X.509 certificate, and executes a mathematical verification over the PASSporT signature. If the signature is valid, the terminating carrier feeds the embedded attestation claim into its analytics engine to determine how to present the call to the end user.
The Three Attestation Levels
The SHAKEN framework mandates that the originating provider assigns a specific confidence level to the call being signed. This level dictates how much trust downstream carriers should place in the Caller ID.
| Level | Name | Trigger | Meaning | Impact |
|---|---|---|---|---|
| A | Full Attestation | Originating provider has a direct authenticated relationship with the customer AND has verified the customer's right to use the calling number. | The provider vouches for both the caller's identity and their authorization to use the caller ID. | Highest downstream trust; yields the best terminating-carrier treatment, lowest spam scoring, and highest answer rates. |
| B | Partial Attestation | Provider has a direct authenticated relationship with the customer but has NOT verified the customer's right to use that particular calling number. | The identity of the caller is known, but number ownership is unverified. | Analytics engines treat B-level attestation as materially less trustworthy. This commonly correlates with reduced answer rates and increased spam labeling. This is the typical outcome when traffic passes through an unverified reseller chain. |
| C | Gateway Attestation | Provider originated the call onto its network but cannot authenticate the call source (e.g., an international gateway or legacy TDM interconnect). | The provider is essentially making no vouching claim regarding the caller or the number. | Lowest trust; frequently filtered, dropped, or immediately labeled as 'Spam Risk' by carrier analytics. |
Anatomy of the SIP Identity Header
The physical manifestation of STIR/SHAKEN is the SIP Identity header. When inspecting SIP traces (PCAPs) on your edge SBC, the presence, formatting, and survival of this header dictates the authentication status of the call.
| Token Component | Engineering Explanation |
|---|---|
| eyJhbGciOi... | The base64-encoded PASSporT JWT containing the claimed attestation level (e.g., 'A'), origin number, destination number, timestamp, and the cryptographic signature. |
| info=<...sp.pem> | The URI where the terminating carrier can retrieve the signing provider's X.509 public key certificate to verify the signature. |
| ppt=shaken | Indicates the PASSporT extension type is SHAKEN, adhering to the specific telecom identity framework rather than generic SIP identity. |
| alg=ES256 | Specifies the ECDSA P-256 signing algorithm used to generate the signature. |
Why Reseller Chains Land on B-Level
A critical vulnerability for many VoIP resellers is routing architecture. If your PBX passes traffic to a middleman aggregator, who passes it to a wholesaler, who finally passes it to an authorized signing carrier, the attestation is irreparably degraded.
Because the signing carrier at the end of the chain has no direct authenticated relationship with the originating customer, they are legally barred from applying A-level attestation. They must apply B-level. This fundamentally disadvantages the traffic, exposing it to severe downstream filtering.
| Routing Path | Network Hops | Attestation Outcome |
|---|---|---|
| Direct Wholesale Integration | Your Softswitch / Dialer → Originating Provider (signs the call) → Tier-1 PSTN Interconnect → Terminating Carrier → Called Party | A-Level (if numbers are verified): Clean routing, high answer rates, carrier trust maintained. |
| Multi-Hop Reseller Chain | Your Softswitch / Dialer → Reseller → Upstream Wholesaler → Originating Provider (signs here, not at the source) → Terminating Carrier → Called Party | B-Level or C-Level: Signing entity has no authenticated relationship with the true originator. Call is downgraded, increasing the likelihood of spam blocking or rejection. |
Why Attestation Moves Answer Rates
Terminating carriers do not passively deliver calls; they actively shield their subscribers. Mobile network operators employ sophisticated analytics engines to score incoming traffic in real-time.
While A-level attestation is not a 'free pass' to spam consumers, B-level and C-level attestation act as aggressive negative modifiers. Traffic lacking A-level validation is exponentially more likely to be intercepted by analytics algorithms, resulting in calls being silently dropped to voicemail or permanently scarred with a 'Spam Risk' display label on the handset. For legitimate business traffic, securing direct A-level attestation is a non-negotiable requirement for acceptable Answer Seizure Ratios (ASR).
The VirPhone Attestation Advantage
VirPhone holds its own FCC filing and maintains its own robocall mitigation program (RMD listing). We sign traffic directly under STIR/SHAKEN at the source, applying full A-level attestation where the partner's right to use the calling number is verified. We do not rely on upstream proxies to sign your traffic.
Robocall Mitigation Obligations
The FCC mandates that all voice service providers operating in the United States must implement a comprehensive Robocall Mitigation Program. Merely signing traffic is insufficient; providers must actively monitor their networks for anomalous dialing patterns, short-duration velocity spikes, and invalid Caller ID spoofing.
Failure to adhere to these obligations results in removal from the Robocall Mitigation Database (RMD). If a provider is stripped from the RMD, all downstream carriers are legally obligated to block their traffic network-wide.
- Verify your wholesale provider holds a valid, active FCC 499 filing.
- Confirm the provider manages their own SP-KI certificate directly.
- Ensure your numbers are properly registered and verified to guarantee A-level signing.
Frequently Asked Questions
Ready to Connect?
Experience enterprise-grade wholesale termination and origination with transparent pricing and real-time control.
