RobocallScience

Research to restore trust in telephones



Characterizing the Deployment of the STIR/SHAKEN Telephone Network PKI

ACM Internet Measurement Conference

Hamim Hamid, David Adei, Bradley Reaves

Summary:

Providers are signing 91% of phone calls with the STIR/SHAKEN suite of standards after a rapid rollout. While the vast majority of call attestations fulfill the spirit and intent of STIR/SHAKEN, few implementations satisfy a strict interpretation of standards.

Abstract

In response to an epidemic of unlawful unsolicited telephone calls, the United States mandated the use of a novel, previously unimplemented call attestation framework called STIR/SHAKEN (S/S) in 2019. The mandate required telephone network operators to deploy a new, federated, industry-wide PKI in timelines shorter than 2 years for large providers. Under those circumstances, achieving any degree of successful deployment would be remarkable.

In this paper, we present a longitudinal study of S/S deployment, evaluating compliance with standards, certificate authority practices, and provider call signatures and metadata. Our primary data source is signaling data from 7.75 million calls collected by multiple telephone honeypots over four years (November 2021–February 2026). Our results show rapid adoption of S/S, but with pervasive non-compliance with standards.

We also found repeated instances of problematic practices, including providers misreferencing the keys used to sign calls and originating calls with pre-signed attestations from unrelated calls. Despite these lapses, we find that most calls are correctly signed and that certificate authority and operator practices and standards compliance are improving at a modest pace. Our discussions highlight concrete directions to strengthen policy and deployment, enabling more effective mitigation of telephone network abuse.