Abstract
In response to an epidemic of unlawful unsolicited telephone calls, the United States mandated the use of a novel, previously unimplemented call attestation framework called STIR/SHAKEN (S/S) in 2019. The mandate required telephone network operators to deploy a new, federated, industry-wide PKI in timelines shorter than 2 years for large providers. Under those circumstances, achieving any degree of successful deployment would be remarkable.
In this paper, we present a longitudinal study of S/S deployment, evaluating compliance with standards, certificate authority practices, and provider call signatures and metadata. Our primary data source is signaling data from 7.75 million calls collected by multiple telephone honeypots over four years (November 2021–February 2026). Our results show rapid adoption of S/S, but with pervasive non-compliance with standards.
We also found repeated instances of problematic practices, including providers misreferencing the keys used to sign calls and originating calls with pre-signed attestations from unrelated calls. Despite these lapses, we find that most calls are correctly signed and that certificate authority and operator practices and standards compliance are improving at a modest pace. Our discussions highlight concrete directions to strengthen policy and deployment, enabling more effective mitigation of telephone network abuse.