EP4659406A1 - Location integrity protection - Google Patents

Location integrity protection

Info

Publication number
EP4659406A1
EP4659406A1 EP23918985.5A EP23918985A EP4659406A1 EP 4659406 A1 EP4659406 A1 EP 4659406A1 EP 23918985 A EP23918985 A EP 23918985A EP 4659406 A1 EP4659406 A1 EP 4659406A1
Authority
EP
European Patent Office
Prior art keywords
location information
location
information
sip message
sti
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP23918985.5A
Other languages
German (de)
French (fr)
Inventor
Kang-Che HSU
Guang Tai ZOU
Ting Ye
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Nokia Solutions and Networks Oy
Original Assignee
Nokia Solutions and Networks Oy
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nokia Solutions and Networks Oy filed Critical Nokia Solutions and Networks Oy
Publication of EP4659406A1 publication Critical patent/EP4659406A1/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/107Network architectures or network communication protocols for network security for controlling access to devices or network resources wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/126Applying verification of the received information the source of the received data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1076Screening of IP real time communications, e.g. spam over Internet telephony [SPIT]
    • H04L65/1079Screening of IP real time communications, e.g. spam over Internet telephony [SPIT] of unsolicited session attempts, e.g. SPIT
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1101Session protocols
    • H04L65/1104Session initiation protocol [SIP]

Definitions

  • Example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to devices, methods, apparatuses and a computer readable storage medium for location integrity protection.
  • IP Internet Protocol
  • SIP Session Initiation Protocol
  • example embodiments of the present disclosure provide a solution for location integrity protection in an emergency service.
  • a device comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a location provider, a first session initiate protocol (SIP) message comprising location information; transmit, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; receive, from the STI-AS, a signing response comprising identity information associated with the location information; and transmit, to a further device, a second SIP message based on the first SIP message and the identity information.
  • SIP session initiate protocol
  • STI-AS secure telephone identity authentication server
  • a device comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and transmit, to the SBC, a signing response comprising identity information associated with the location information.
  • SBC session border controller
  • SIP session initiate protocol
  • a device comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; transmit, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; receive, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and transmit, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • SBC session border controller
  • SIP session initiate protocol
  • STI-VS secure telephone identity verification server
  • a device comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and transmit, to the SBC, a verification response comprising verification state information associated with the location information.
  • SBC session border controller
  • SIP session initiate protocol
  • a method performed by an SBC comprises: receiving, at a session border controller from a location provider, a first session initiate protocol (SIP) message comprising location information; transmitting, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; receiving, from the STI-AS, a signing response comprising identity information associated with the location information; and transmitting, to a further device, a second SIP message based on the first SIP message and the identity information.
  • SIP session initiate protocol
  • STI-AS secure telephone identity authentication server
  • a method performed by an STI-AS comprises: receiving, at a secure telephone identity authentication server (STI-AS) from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and transmitting, to the SBC, a signing response comprising identity information associated with the location information.
  • STI-AS secure telephone identity authentication server
  • SBC session border controller
  • SIP session initiate protocol
  • a method performed by an SBC comprises: receiving, at a session border controller from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; transmitting, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; receiving, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and transmitting, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • SIP session initiate protocol
  • a method performed by an STI-VS comprises: receiving, at a secure telephone identity verification server (STI-VS) from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and transmitting, to the SBC, a verification response comprising verification state information associated with the location information.
  • STI-VS secure telephone identity verification server
  • SBC session border controller
  • SIP session initiate protocol
  • an apparatus comprising: means for receiving, at a session border controller from a location provider, a first session initiate protocol (SIP) message comprising location information; means for transmitting, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; means for receiving, from the STI-AS, a signing response comprising identity information associated with the location information; and means for transmitting, to a further device, a second SIP message based on the first SIP message and the identity information.
  • SIP session initiate protocol
  • STI-AS secure telephone identity authentication server
  • an apparatus comprising: means for receiving, at a secure telephone identity authentication server (STI-AS) from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a signing response comprising identity information associated with the location information.
  • STI-AS secure telephone identity authentication server
  • SBC session border controller
  • SIP session initiate protocol
  • an apparatus comprising: means for receiving, at a session border controller from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; means for transmitting, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; means for receiving, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and means for transmitting, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • SBC session border controller
  • SIP session initiate protocol
  • STI-VS secure telephone identity verification server
  • an apparatus comprising: means for receiving, at a secure telephone identity verification server (STI-VS) from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a verification response comprising verification state information associated with the location information.
  • STI-VS secure telephone identity verification server
  • SBC session border controller
  • SIP session initiate protocol
  • a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the method in the fifth, sixth, seventh, or eighth aspect.
  • a fourteenth aspect there is provided a computer program comprising instructions, which, when executed by an apparatus, cause the apparatus at least to perform the method in the fifth, sixth, seventh, or eighth aspect.
  • an SBC comprises: receiving circuitry configured to receive, from a location provider, a first session initiate protocol (SIP) message comprising location information; transmitting circuitry configured to transmit, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; receiving circuitry configured to receive, from the STI-AS, a signing response comprising identity information associated with the location information; and transmitting circuitry configured to transmit, to a further device, a second SIP message based on the first SIP message and the identity information.
  • SIP session initiate protocol
  • STI-AS secure telephone identity authentication server
  • an STI-AS comprises: receiving circuitry configured to receive, from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and transmitting circuitry configured to transmit, to the SBC, a signing response comprising identity information associated with the location information.
  • SBC session border controller
  • SIP session initiate protocol
  • an SBC comprises: receiving circuitry configured to receive, from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; transmitting circuitry configured to transmit, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; receiving circuitry configured to receive, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and transmitting circuitry configured to transmit, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • SBC session border controller
  • SIP session initiate protocol
  • STI-VS secure telephone identity verification server
  • an STI-VS comprises: receiving circuitry configured to receive, from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and transmitting circuitry configured to transmit, to the SBC, a verification response comprising verification state information associated with the location information.
  • SBC session border controller
  • SIP session initiate protocol
  • a computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method in the fifth, sixth, seventh, or eighth aspect.
  • FIG. 1 illustrates an example call flow
  • FIG. 2 illustrates an overview of STIR-SHAKEN architecture for a call from an originating service provider to a terminating PSAP;
  • FIG. 3 illustrates an example emergency call flow in which the calling number may be verified
  • FIG. 4 illustrates an example process in accordance with some example embodiments of the present disclosure
  • FIG. 5A illustrates an example process of request handing at the IBCF with STI-AS for geolocation assertion in accordance with some example embodiments of the present disclosure
  • FIG. 5B illustrates an example process of request handing at the IBCF with STI-VS for geolocation verification in accordance with some example embodiments of the present disclosure
  • FIGS. 6A-6C illustrate some examples of geolocation header in accordance with some example embodiments of the present disclosure
  • FIG. 7 illustrates an example of a process flow performed by a session border controller, such as an egress IBCF, in accordance with some example embodiments of the present disclosure
  • FIG. 8 illustrates an example of a process flow performed by an STI-AS in accordance with some example embodiments of the present disclosure
  • FIG. 9 illustrates an example of a process flow performed by a session border controller, such as an ingress IBCF, in accordance with some example embodiments of the present disclosure
  • FIG. 10 illustrates an example of a process flow performed by an STI-VS in accordance with some example embodiments of the present disclosure
  • FIG. 11 illustrates a simplified block diagram of a device that is suitable for implementing some example embodiments of the present disclosure.
  • FIG. 12 illustrates a block diagram of an example of a computer readable medium in accordance with some example embodiments of the present disclosure.
  • references in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
  • first and second etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments.
  • the term “and/or” includes any and all combinations of one or more of the listed terms.
  • circuitry may refer to one or more or all of the following:
  • circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware.
  • circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
  • a phone call may be initiated by a device and terminated in another device.
  • FIG. 1 illustrated an example call flow 100 of an emergency 911 (E911) call.
  • E911 emergency 911
  • the location information of the caller may be important for the telecommunication service provider, however it may be attached, spoofed, or mocked by a hacker.
  • the terminating carrier performs validation checks against the signed caller identity before the calls are delivered to called users, allowing the carrier of the party receiving the call to provide an indication to the called party of the legitimacy of the caller identity information.
  • PASSport extensions such as RPH, DIV, DIV-O, SKAKEN, and msec.
  • FIG. 2 illustrates an overview of STIR-SHAKEN architecture 200 for a call from an originating service provider to a terminating PSAP.
  • the certificate provisioning service may be a logical service used to provision certificates used for STI.
  • the STI-CR may represent the public/accessible store for public key certificates.
  • the SKS may be a logical highly secure element that stores secret private keys.
  • the architecture 200 shown in FIG. 2 is only for the purpose of illustration and without suggesting any limitation as to the scope of the disclosure.
  • the “LRF/RDF” and “E-CSCF” at the originating service provider, and the “LRF/RDF/PRF” and “I/E-CSCF” at the terminating NG911 ESN provider may be implemented as other network elements.
  • the architecture 200 is illustrated with respect to the NG911, a similar architecture may be applied for any call other than an E911.
  • STIR and SHAKEN use digital certificates, based on common public key cryptography techniques, to ensure the calling number of a telephone call is secure. Every telephone service provider obtains their digital certificate from a certificate authority (STI-CA) who is trusted by other telephone service providers.
  • STI-CA certificate authority
  • the certificate technology enables the called party to verify that the calling number is accurate and has not been spoofed. This mechanism is not intended to protect the man-in-the-middle attacks.
  • a malicious intermediate network can remove the identity header, then this request will be treated as not signed and hence recipients of the call can act accordingly.
  • FIG. 3 illustrates an example emergency call flow 300 in which the calling number may be verified. It is understood that the flow 300 may be a basic call flow about how the STIR SHAKEN architecture is involved. The flow 300 may include the following steps 1 through 23.
  • the originating SIP UA creates a SIP INVITE with a telephone number identity.
  • the P-CSCF adds a PAI header field asserting the caller identity with “verstat” parameter, a RPH with value "esnet. 1" , and optional Attestation-Info and Origination-Id header fields.
  • the E-CSCF sends the SIP INVITE to the LRF to determine routing instructions.
  • the LRF acquires location, if required, and queries the RDF for the routing URI.
  • the LRF returns the routing URI to the E-CSCF.
  • the E-CSCF forwards the emergency call to the exit IBCF.
  • the exit IBCF sends a HTTP POST message containing two signing requests over the Ms interface to the STI-AS.
  • the STI-AS securely requests its private key from the SKS.
  • the SKS provides the private key in the response.
  • the STI-AS returns an HTTP 200 OK messages for a signed identityHeader field with identity and RPH.
  • the exit IBCF uses the identity Header parameters populated in the SIP INVITE message.
  • the IBCF will remove the "verstat" parameter from the PAI header prior and send the call to the next network.
  • the entry IBCF sends an HTTP POST containing a verificationRequest to the STI-VS.
  • the STI-VS determines the STI-CR URI and makes an HTTPS request to the STI-CR.
  • the STI-VS validates the certificate and then extracts the public key.
  • the STI-VS may interact with the CVT.
  • the STI-VS returns a verificationResponse to the IBCF.
  • the IBCF populates the content of the "verstatValue” in a "verstat” parameter within the PAI header and the content of the "verstatPriority" in the Priority-Verstat header field in the SIP INVITE, and passes the SIP INVITE to the I-CSCF.
  • the I-CSCF passes the SIP INVITE to E-CSCF.
  • the E-CSCF forwards the SIP INVITE to the LRF.
  • the LRF queries the RDF using the location information for routing URI associated with an i3 PSAP.
  • the LRF redirects the call back to the E-CSCF, passing the Routing (PSAP) URI.
  • the E-CSCF generates an outgoing SIP INVITE message, using the information received from the LRF, and forwards it to the IBCF.
  • the exit IBCF forwards the SIP INVITE to the i3 PSAP with the appropriate "verstat" value in the PAI header, the Priority-Verstat header field and the Identity headers, and normal call processing associated with the emergency origination continues.
  • the originating service provider and the NG911 emergency service network provider are related.
  • one or more intermediate networks may be involved. Specifically, if the entry IBCF of one intermediate network needs to do verification, a process similar with the steps 12-17 may be performed, and additionally, the exit IBCF of the intermediate network will forward the verification result to the next network element, such as an entry IBCF of the next intermediate network or the entry IBCF of the NG9-1-1 emergency service network provider.
  • Location information is essential; however, there is no mechanism to ensure such information integrity during traversing between different networks.
  • the practices don’t provide an assurance, integrity, and protection of location information conveyed in SIP body in the end-to-end call path while relying on the existing security mechanism and practices of SKAKEN framework.
  • Example embodiments of the present disclosure provide a solution for location information protection.
  • a fingerprint associated with the location information may be transmitted to the STI-AS for signing, and the downstream network may validate the signed information for data integrity.
  • the location information in a SIP message may be validated, to determine whether it has not been spoofed, mocked, or attacked.
  • FIG. 4 illustrates an example process 400 in accordance with some example embodiments of the present disclosure.
  • the process 400 involves a location provider 401, an egress IBCF 402, an STI-AS 403, an ingress IBCF 404, an STI-VS 405, and a location consumer 406.
  • the location provider 401, the egress IBCF 402 and the STI-AS 403 may be in a network (such as an originating network)
  • the ingress IBCF 404, the STI-VS 405, and the location consumer 406 may be in another network.
  • the process 400 has been described with reference to NG911, however this process flow may be likewise applied to other communication scenarios.
  • the egress IBCF 402 in FIG. 4 may be implemented as another BCF, such as an IBGW, the present disclosure does not limit this aspect.
  • the location provider 401 may be a network element which adds the location information in the SIP signal flow in NG911.
  • the location consumer 406 may be a network element which uses the location information, for example, the location consumer 406 may be an ESRP which will route emergency call based on the location information.
  • the location provider 401 transmits 410 a SIP message 412 to the egress IBCF 402.
  • the location provider 401 may include an LRF.
  • the LRF may transmit the SIP message 412 to the egress IBCF 402 through other network element, such as an E-CSCF.
  • the SIP message 412 includes location information.
  • the location information may include longitude information and latitude information.
  • the location information may include information of a specific geographic position, such as a building.
  • the location information may be represented as an identifier of a location URI.
  • the location information may be in a format of one or more of: a SIP URI, a SIPS URI, an HTTP URI, an HTTPS URI, or a CID URI.
  • the location information in a format of CID URI may be “cid: user@example. com” .
  • the location information in a format of HTTPS URI may be “https: //operator. net/yzWuekc7Ye48CM5X0On_sA” .
  • the location information in a format of SIP URI may be “sip: 1234567890@operator. net” .
  • the location information may be carried in at least one geolocation header of the SIP message.
  • one geolocation header may include location information of the caller’s terminal device.
  • one geolocation header may include location information of a location which the caller inputs.
  • one geolocation header may include location information of a base station communicated with the caller’s terminal device.
  • the location provider 401 may determine 409 a fingerprint associated with the location information.
  • the length of the fingerprint may equal to a predefined value, such as 64 bits.
  • the location provider 401 may generate the fingerprint from the location information using an algorithm.
  • the algorithm may be a hash algorithm.
  • a hash function may be used for the generation of the fingerprint.
  • the hash algorithm may be any one of: “SHA256” , “SHA384” , or “SHA512” , which are defined as part of the SHA-2 set of cryptographic hash functions by the NIST.
  • a default hash algorithm used by the location provider 401 may be “SHA256” .
  • the algorithm may be a Rabin’s algorithm. It is to be understood that the algorithm may be another one other than the hash or Rabin’s algorithm, the present disclosure does not limit this aspect.
  • the location information used for generating the fingerprint may include all location related information.
  • the location information may include an MIME header information if it is included in the SIP body.
  • fingerprint may be also called as a fingerprint value, a fingerprint parameter, etc.
  • algorithm may be also called as an algorithm parameter, etc.
  • the SIP message 412 may further include the fingerprint and the algorithm.
  • the SIP message 412 may include a fingerprint header carrying a fingerprint header parameter, and an algorithm header carrying an algorithm header parameter.
  • the SIP message 412 may further include one or more of an algorithm header parameter, or a fingerprint header parameter associated with the location information.
  • the fingerprint header parameter may indicate the fingerprint determined at 409
  • the algorithm header parameter may indicate the algorithm used for generating the fingerprint.
  • the SIP message 412 may further include an indication of a location source associated with the location information.
  • the indication of the location source may include a host name, for example, an FQDN hostname.
  • the SIP message 412 includes a PAI header, and the location information, the algorithm and the signature are all carried in the PAI header.
  • the location-related information (including the location information, the algorithm and the signature) may be in a PIDF-Lo format.
  • an external resource such as a remote resource
  • the location information may be conveyed by reference, and there is no need to include the algorithm or the signature in the SIP message 412.
  • the egress IBCF 402 receives 414 the SIP message 412.
  • the egress IBCF 402 transmits 420 a signing request 422 to the STI-AS 403.
  • the signing request 422 may be transmitted via an Ms interface.
  • the signing request 422 may be in a PASSporT format through an HTTP/HTTPS protocol.
  • the signing request 422 includes location information, for example, the egress IBCF 402 may obtain the location information from the SIP message 412.
  • the signing request 422 may further include an indication of a PASSport type (ppt) , for example, it may indicate that the type is “geolocation” or “geo” .
  • ppt PASSport type
  • the signing request 422 may further include an indication of a location source associated with the location information.
  • the egress IBCF 402 may obtain the indication of the location source from the SIP message 412.
  • the indication of the location source may include a host name, for example, an FQDN hostname.
  • the location information is conveyed by value, and the algorithm header parameter and the fingerprint header parameter may be included.
  • the signing request 422 may include the location information, the algorithm, and the fingerprint which is generated from the location information by using the algorithm.
  • the location information is conveyed by reference, for example, an external resource (such as a remote resource) may be used, and the algorithm or the fingerprint may not be needed.
  • the signing request 422 may be in a PASSporT format, and it may include a PASSporT header and a PASSporT payload.
  • the PASSporT header may include a field “ppt” to indicate the PASSport type, for example, the type is “geo” .
  • the PASSporT payload may include a field “geo” to indicate the location information “Geolocation” and an associated location source “loc-src” .
  • Table 1 shows an example PASSporT Header and an example PASSporT payload in which the location information is conveyed by value.
  • a field “geofingerprint” is included.
  • the field “geofingerprint” may be used to indicate an algorithm (such as “SHA256” ) and the fingerprint generated based on the algorithm.
  • Table 2 shows an example PASSporT Header and an example PASSporT payload in which the location information is conveyed by reference. As shown in Table 2, there is no field “geofingerprint” included.
  • the STI-AS 403 receives 424 the signing request 422.
  • the signing request 422 may be received via the Ms interface.
  • the STI-AS 403 may securely request its private key from the SKS, which is not shown in FIG. 4, and the SKS may provide the private key in a response.
  • the STI-AS 403 transmits 430 a signing response 432 to the egress IBCF 402, and the egress IBCF 402 receives 434 the signing response 432.
  • the signing response 432 may include identity information associated with the location information.
  • the egress IBCF 402 transmits 440 a SIP message 442 to the ingress IBCF 404 in the next network along the path.
  • the SIP message 442 is different from the SIP message 422.
  • the egress IBCF 402 may populate the identity information into the SIP message 422 and remove the fingerprint (such as from the PAI header) to generate the SIP message 442.
  • the SIP message 442 may further include the algorithm as described above.
  • the SIP message 442 may further include an indication of a location source associated with the location information as described above.
  • the ingress IBCF 404 receives 444 the SIP message 442.
  • the ingress IBCF 404 transmits 450 a verification request 452 to the STI-VS 405.
  • the verification request 452 includes the location information and the identity information.
  • the IBCF 404 may re-determine (or recalculate) a fingerprint based on the location information.
  • the SIP message 442 may include the algorithm which was used by the location provider 410.
  • the IBCF 404 may obtain the location information and the algorithm from the SIP message 442, and re-determine (or recalculate) a fingerprint based on the location information and the algorithm.
  • the re-determined (or recalculated) fingerprint at the ingress IBCF 404 may be called as a first fingerprint.
  • the verification request 452 may further include the re-determined (or recalculated) fingerprint, i.e., the first fingerprint.
  • the location information in the verification request 452 may be carried in a field of “geo” , and the type of the location information in the verification request 452 may be a string.
  • the verification request 452 may further include the re-determined (or recalculated) fingerprint which is carried in a field of “geofingerprint” , and the type of the re-determined (or recalculated) fingerprint may be a string. It is understood that in case that the fingerprint is conveyed by reference, there is no need to include the fingerprint in the verification request 452.
  • the verification request 452 may further include an indication of a location source associated with the location information.
  • the indication of the location source may include a host name, for example, an FQDN hostname.
  • the STI-VS 405 receives 454 the verification request 452.
  • the STI-VS 405 transmits 460 a verification response 462 to the ingress IBCF 404.
  • the verification response 462 may include a verification state parameter associated with the location information.
  • the verification state parameter may also be called as verification information, a verification result, etc.
  • the STI-VS 405 may determine the STI-CR and transmit a request to the STI-CR for a public key. The STI-VS 405 may further receive the public key from the STI-CR. In some examples, the STI-VS 405 may determine a fingerprint (may be called as a second fingerprint) based on the identity information, for example, by using the public key. In some examples, the STI-VS 405 may compare the determined fingerprint (the second fingerprint) with the re-determined (or recalculated) fingerprint (the first fingerprint) included in the verification request 452. In some examples, if the second fingerprint is the same as the first fingerprint, the verification information may indicate that the verification is passed, for example, represented as Geo-Validation-Passed. In some examples, if the second fingerprint is different from the first fingerprint, the verification information may indicate that the verification is failed, for example, represented as Geo-Validation-Failed.
  • the verification information may indicate that there is no verification, for example, represented as No-GEO-Validation.
  • the verification state parameter associated with the location information may indicate one of: a geolocation validation passed state, a geolocation validation failed state, or no geolocation validation state.
  • the ingress IBCF 404 receives 464 the verification response 462. In some examples, the ingress IBCF 404 transmits 470 a SIP message 472 to the location consumer 406.
  • the SIP message 472 includes the location information and the verification information, such as a verification state parameter.
  • the ingress IBCF 404 may populate the verification information into the SIP message 442 to generate the SIP message 472. For example, the verification state parameter may be populated in to the PAI header of the SIP message 472.
  • the location consumer 406 receives 474 the SIP message 472.
  • the location consumer 406 may take an action based on the verification information (such as the verification state parameter) in the SIP message 472.
  • the SIP message 472 may be forwarded to the PSAP if the verification state parameter indicates a geolocation validation passed state.
  • a fingerprint associated with the location information may be transmitted to the STI-AS for signing, and the downstream network may validate the signed information for data integrity.
  • the STI-VS may verify whether the location information has been spoofed.
  • the location information in a SIP message may be validated, to determine whether it has not been spoofed, mocked, or attacked.
  • the framework or mechanism proposed in the present disclosure may be used to be an essential mechanism and process for location spoofing or data spoofing mitigation, for example, FCC regulations.
  • the framework or mechanism proposed in the present disclosure may be applied to several network elements defined in 3GPP, an example will be described with reference to FIGS. 5A-5B.
  • FIG. 5A illustrates an example process 510 of request handing at the IBCF with STI-AS for geolocation assertion in accordance with some example embodiments of the present disclosure.
  • the process 510 relates some operations in the originating network, and it involves an E-CSCF 511, an LRF 512, an IBCF 513, and an STI-AS 514. It is understood that the IBCF 513 may be an egress IBCF.
  • the E-CSCF 511 transmits 531 a SIP INVITE message to the LRF 512, where the SIP INVITE message may include a called number (To) , a calling number (From) , and a PAI header.
  • the SIP INVITE message may further include other information which will not be listed herein.
  • the LRF 512 transmits 532 a 300 MC message to the E-CSCF 511, where the 300MC message may include location information and at least one fingerprint associated with the location information.
  • the 300 MC message may include geolocation header and PIDF-Lo, where the geolocation header includes the location information and the PIDF-Lo includes the fingerprint.
  • the PIDF-Lo content is generated by the LRF 512 and is associated with the geolocation header.
  • the PIDF-Lo content is used for spoofing mitigation purpose.
  • the PIDF-Lo content may be hashed by an algorithm (such as SHA3) and populated into specific header parameter value for STI-AS 514 signing.
  • the E-CSCF 511 transmits 533 a SIP INVITE message to the IBCF 513, where the SIP INVITE message to the IBCF 513 includes a called number (To) , a calling number (From) , and a PAI header, where the PAI header may include location information.
  • the PAI header may further include one or more of: the algorithm (such as a harsh algorithm) , the fingerprint (in a PIDF-Lo format) and an indication of a location source.
  • the SIP INVITE message to the IBCF 513 includes:
  • the IBCF 513 transmits 534 a signing request to the STI-AS 514.
  • the signing request may be in PASSporT format through the HTTP/HTTPS protocol, and may include information required by STI-AS 514 to get the signing result.
  • the signing request may at least include the location information, for example, it may be indicated by “geo” .
  • the signing request may include the algorithm (such as a hash algorithm) and the fingerprint value (such as a hash value) , for examples, they may be indicated by “geofingerprint” .
  • the signing request to the STI-AS 514 includes the following contents for signing:
  • the STI-AS 514 transmits 535 a signing response to the IBCF 513, where the signing response may include identity information.
  • the identity information may be associated with the location information and the identity information may be used for verification by STI-VS.
  • the IBCF 513 transmits 536 a SIP INVITE message to an ingress IBCF in another network.
  • the IBCF 513 may populate the identity information into the SIP INVITE message received from the E-CSCF 511, and remove the fingerprint (in a PIDF-Lo format) from the PAI header.
  • the SIP INVITE message from the IBCF 513 includes:
  • each of the SIP INVITE messages received by the LRF 512, received by the IBCF 513, and transmitted by the IBCF 513 includes a PAI header, but they may include different information.
  • the PAI header at step 531 does not include location information or a fingerprint
  • the PAI header at step 533 includes the location information and the fingerprint
  • the PAI header at step 536 includes the location information but does not include the fingerprint.
  • FIG. 5B illustrates an example process 520 of request handing at the IBCF with STI-VS for geolocation verification in accordance with some example embodiments of the present disclosure.
  • the process 520 relates some operations in the terminating network or an intermediate network, and it involves an ingress IBCF 521, an STI-VS 522, and an I-CSCF or an E-CSCF 523.
  • the ingress IBCF 521 receives 541 a SIP INVITE message.
  • the SIP INVITE message may be received from an egress IBCF of a pervious network, such as the IBCF 513 as shown in FIG. 5A.
  • the SIP INVITE message received by the ingress IBCF 521 includes location information and identity information, and it may further include an indication of a location source and/or an algorithm.
  • the SIP INVITE message received by the ingress IBCF 521 includes:
  • the SIP INVITE message received by the ingress IBCF 521 may be the same as that transmitted by the IBCF 513 with reference to FIG. 5A, and thus will not be repeated herein.
  • the ingress IBCF 521 transmits 542 a verification request to the STI-VS 522.
  • the verification request may include information for verification.
  • the ingress IBCF 521 may re-determine a fingerprint from the location information carried in the SIP INVITE message, and the verification request may include the location information, the identity information, and the re-determined fingerprint.
  • the ingress IBCF 521 may use the algorithm (such as a hash algorithm) provided in the geolocation header of the SIP INVITE message and recalculate the fingerprint.
  • the verification request may include the following contents for verification:
  • geofingerprint “xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx” in the verification request includes the re-determined (or recalculated) fingerprint.
  • the STI-VS 522 transmits 543 a verification response to the ingress IBCF 521, where the verification response includes verification information.
  • the verification information may indicate whether the location information in the SIP INVITE message has been spoofed or mocked.
  • the STI-VS 522 may determine a fingerprint based on the identity information, and compare the determined fingerprint with the re-determined (or recalculated) fingerprint included in the verification request to determine the verification information. For example, the verification information may indicate that the verification is passed: “verstat: Geo-Validation-Passed” .
  • the ingress IBCF 521 transmits 544 a SIP INVITE message to the I-CSCF/E-CSCF 523.
  • the ingress IBCF 521 may populate the varification information into the SIP INVITE message.
  • the ingress IBCF 521 may populate the content of “verstat” from the verification response into the PAI header in the SIP INVITE message.
  • the SIP INVITE message transmitted from the ingress IBCF 521 includes:
  • LRF is a critical network element in the framework of the present disclosure
  • the LRF 512 may generate a fingerprint (ahashed token) which may be included in the 300 MC response returning back to the E-CSCF 511, accordingly, a new SIP INVITE message with the fingerprint may be transmitted to the next hop, such as the IBCF 513.
  • the IBCF 513 may interact with the STI-AS 514 so as to sign the token in an Identity header.
  • the downstream network such as ESINET or i3 Architecture can validate the signed information with STI-VS 522 for data integrity and validation result.
  • FIGS. 5A-5B are only for the purpose of illustration, in actual scenarios, there may be some other network elements, such as, a BCF, a CHE, an ESRP, etc., the present disclosure does not limit this aspect.
  • FIGS. 6A-6C illustrate some examples of geolocation header in accordance with some example embodiments of the present disclosure.
  • the geolocation header may be in a PASSporT format, specifically, it may include PASSport Header, PASSporT Payload, and PASSporT Signature.
  • the PASSport type may be “geo” , as indicated by “ppt” .
  • FIG. 6A illustrates an example GEO identity header with CID URI 610.
  • the location information may be “cid: user@example. com” , as indicated by “geo” .
  • the fingerprint may be “0beaa5a85b865a9cd1ea4f58fa8dda0e7e8e4dd2a0052 6213df44157aba5107f” using an algorithm “SHA3-256” , as indicated by “geofingerprint” .
  • the indication of the location source may be “lis. operator. net” , as indicated by “locSrc” .
  • FIG. 6B illustrates an example GEO identity header with HTTPS URI 620.
  • the location information may be “https: //operator. net/yzWuekc7Ye48C M5X0On_sA” , as indicated by “geo” .
  • the fingerprint may be “f8997f6e37eb53f2be5452 9246323c8623c344c6dd34f835f628166ae18db87f” using an algorithm “SHA3-256” , as indicated by “geofingerprint” .
  • the indication of the location source may be “lis. operator. net” , as indicated by “locSrc” .
  • FIG. 6C illustrates an example GEO identity header with SIP URI 630.
  • the location information may be “sip: 1234567890@operator. net” , as indicated by “geo” .
  • the fingerprint may be “77976383a6c695abf0a3cb0321826bb187881 b03877c743a1fb9f5ec16261522” using an algorithm “SHA3-256” , as indicated by “geofingerprint” .
  • the indication of the location source may be “lis. operator. net” , as indicated by “locSrc” .
  • the field “geofingerprint” used for indicating the algorithm and the fingerprint is described for the purpose of illustration without any limitation of the scope of the disclosure.
  • a field “geohash” may be used for indicating the algorithm and the fingerprint.
  • the algorithm and the fingerprint may be indicated separately, for example, the fields “alg” and “hash” may be used for indicating the algorithm and the fingerprint respectively.
  • the location information, the algorithm, and the indication of the location source may be indicated in a same field, such as a field “geo” , and the fingerprint may be indicated separately. It is to be appreciated that the algorithm and the fingerprint may be indicated by other means and the present disclosure does not limit this aspect.
  • the embodiments in the present disclosure provide a solution for data assurance, integrity and protection when critical information such as location information is conveyed in SIP body.
  • An associated SIP header which includes the critical information and signed by the providers with signatures may be used to ensure that the downstream service provider can validate the data whether it has been spoofed, mocked, or attacked, and authenticated by original provider.
  • the attestation and data integrity is introduced in order to mitigate the problem from bad actors mocking, spoofing, swatting the data in a call signal path so that the downstream system can detect whether the data is generated by the bad actor or not, and can take caution on it.
  • the data can be signed and attested by the data provider so that the public authority can trace back where the data was generated by which service provider in the call path. This brings the data authentication, authorization, integrity, and attestation into a next level of data assurance in the public safety networks.
  • FIG. 7 illustrates a flowchart 700 of a method implemented at a session border controller, such as an egress IBCF, in accordance with some example embodiments of the present disclosure.
  • the egress IBCF receives, from a location provider, a first SIP message comprising location information.
  • the egress IBCF transmits, to an STI-AS, a signing request comprising the location information.
  • the egress IBCF receives, from the STI-AS, a signing response comprising identity information associated with the location information.
  • the egress IBCF transmits, to a further device, a second SIP message based on the first SIP message and the identity information.
  • the first SIP message further comprises at least one of: an algorithm header parameter, or a fingerprint header parameter, and the fingerprint header parameter indicates a fingerprint value being generated from the location information using an algorithm indicated by the algorithm header parameter.
  • the location information is in a PIDF-Lo format.
  • the signing request further comprises the fingerprint value.
  • the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • the egress IBCF populates the identity information into the first SIP message; and removes at least one of: the algorithm header parameter, or the fingerprint header parameter.
  • the location information is determined by reference, and the first SIP message does not comprise the fingerprint header parameter.
  • the location information is carried in at least one geolocation header or a PAI header of the first SIP message.
  • the location information is in a format of at least one of: a SIP URI, a SIPS URI, an HTTP URI, an HTTPS URI, or a CID URI.
  • the first SIP message further comprises an indication of a location source associated with the location information
  • the signing request further comprises the indication of the location source.
  • the indication of the location source comprises an FQDN hostname.
  • FIG. 8 illustrates a flowchart 800 of a method implemented at an STI-AS in accordance with some example embodiments of the present disclosure.
  • the STI-AS receives, from an SBC, a signing request comprising location information being comprised in a SIP message.
  • the STI-AS transmits, to the SBC, a signing response comprising identity information associated with the location information.
  • the STI-AS transmits a request to a secure key store (SKS) for a private key; receives the private key from the SKS; and determines the identity information based on the location information and the private key.
  • SSLS secure key store
  • the signing request further comprises a fingerprint value indicated by a fingerprint header parameter in the SIP message and generated from the location information using an algorithm indicated by an algorithm header parameter in the SIP message.
  • the location information is in a PIDF-Lo format.
  • the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • the SIP message further comprises an indication of a location source associated with the location information
  • the signing request further comprises the indication of the location source.
  • the indication of the location source comprises an FQDN hostname.
  • FIG. 9 illustrates a flowchart 900 of a method implemented at an SBC, such as an ingress IBCF, in accordance with some example embodiments of the present disclosure.
  • the ingress IBCF receives, from a further SBC, a SIP message comprising location information and identity information.
  • the ingress IBCF transmits, to an STI-VS, a verification request comprising the location information and the identity information.
  • the ingress IBCF receives, from the STI-VS, a verification response comprising a verification state parameter associated with the location information.
  • the ingress IBCF transmits, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • the ingress IBCF populates the verification state parameter into the SIP message to generate the further SIP message.
  • the SIP message further comprises an algorithm header parameter indicating an algorithm
  • the ingress IBCF determines a first fingerprint value based on the location information using the algorithm, where the verification request further comprises the first fingerprint value.
  • the verification state parameter indicates one of: a location validation passed state, a location validation failed state, or no location validation state.
  • the location information is carried in at least one geolocation header or a PAI header of the SIP message.
  • the location information is in a format of at least one of: a SIP URI, a SIPS URI, an HTTP URI, an HTTPS URI, or a CID URI.
  • the SIP message further comprises an indication of a location source associated with the location information
  • the verification request further comprises the indication of the location source.
  • the indication of the location source is an FQDN hostname.
  • FIG. 10 illustrates a flowchart 1000 of a method implemented at an STI-AS in accordance with some example embodiments of the present disclosure.
  • the STI-VS receives, from an SBC, a verification request comprising location information and identity information being comprised in a SIP message.
  • the STI-VS transmits, to the SBC, a verification response comprising verification state information associated with the location information.
  • the STI-VS determines a secure telephone identity certificate repository (STI-CR) associated with the location information; transmits a request to the STI-CR for a public key; receives the public key from the STI-CR; and determines the verification state information based on the identity information and the public key.
  • STI-CR secure telephone identity certificate repository
  • the verification request further comprises a first fingerprint value determined by the SBC based on the location information, and the STI-VS determines a second fingerprint value based on the identity information; and determines the verification state parameter by comparing the first fingerprint value with the second fingerprint value.
  • the SIP message further comprises an indication of a location source associated with the location information
  • the verification request further comprises the indication of the location source.
  • the indication of the location source is an FQDN hostname.
  • an apparatus capable of performing the method 700 may comprise means for performing the respective steps of the method 700.
  • the means may be implemented in any suitable form.
  • the means may be implemented in a circuitry or software module.
  • the apparatus comprises: means for receiving, from a location provider, a first session initiate protocol (SIP) message comprising location information; meaning for transmitting, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; means for receiving, from the STI-AS, a signing response comprising identity information associated with the location information; and means for transmitting, to a further device, a second SIP message based on the first SIP message and the identity information.
  • SIP session initiate protocol
  • STI-AS secure telephone identity authentication server
  • the first SIP message further comprises at least one of: an algorithm header parameter, or a fingerprint header parameter, the fingerprint header parameter indicates a fingerprint value being generated from the location information using an algorithm indicated by the algorithm header parameter, and the location information is in a PIDF-Lo format.
  • the signing request further comprises the fingerprint value.
  • the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • the apparatus comprises: means for generating the second SIP message.
  • means for generating the second SIP message comprises: means for populating the identity information into the first SIP message; and means for removing at least one of: the algorithm header parameter, or the fingerprint header parameter.
  • the location information is determined by reference, and the first SIP message does not comprise the fingerprint header parameter.
  • the location information is carried in at least one geolocation header or a PAI header of the first SIP message.
  • the location information is in a format of at least one of: a SIP uniform resource identifier (URI) , a session initiation protocol secure (SIPS) URI, a hypertext transfer protocol (HTTP) URI, a hypertext transfer protocol secure (HTTPS) URI, or a content identity (CID) URI.
  • URI SIP uniform resource identifier
  • SSL session initiation protocol secure
  • HTTP hypertext transfer protocol
  • HTTPS hypertext transfer protocol secure
  • CID content identity
  • the first SIP message further comprises an indication of a location source associated with the location information
  • the signing request further comprises the indication of the location source.
  • the indication of the location source comprises a fully qualified domain name (FQDN) hostname.
  • an apparatus capable of performing the method 800 may comprise means for performing the respective steps of the method 800.
  • the means may be implemented in any suitable form.
  • the means may be implemented in a circuitry or software module.
  • the apparatus comprises: means for receiving, from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a signing response comprising identity information associated with the location information.
  • SBC session border controller
  • SIP session initiate protocol
  • the apparatus further comprises: means for transmitting a request to a secure key store (SKS) for a private key; means for receiving the private key from the SKS; and means for determining the identity information based on the location information and the private key.
  • SSLS secure key store
  • the signing request further comprises a fingerprint value indicated by a fingerprint header parameter in the SIP message and generated from the location information using an algorithm indicated by an algorithm header parameter in the SIP message, and the location information is in a presence information data format -location object (PIDF-Lo) format.
  • PIDF-Lo presence information data format -location object
  • the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • the SIP message further comprises an indication of a location source associated with the location information
  • the signing request further comprises the indication of the location source
  • the indication of the location source comprises a fully qualified domain name (FQDN) hostname.
  • FQDN fully qualified domain name
  • an apparatus capable of performing the method 900 may comprise means for performing the respective steps of the method 900.
  • the means may be implemented in any suitable form.
  • the means may be implemented in a circuitry or software module.
  • the apparatus comprises: means for receiving, from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; means for transmitting, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; means for receiving, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and means for transmitting, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • SBC session border controller
  • SIP session initiate protocol
  • STI-VS secure telephone identity verification server
  • the apparatus further comprises: means for generating the further SIP message.
  • means for generating the further SIP message comprises: means for populating the verification state parameter into the SIP message to generate the further SIP message.
  • the SIP message further comprises an algorithm header parameter indicating an algorithm
  • the apparatus further comprises: means for determining a first fingerprint value based on the location information using the algorithm, where the verification request further comprises the first fingerprint value.
  • the verification state parameter indicates one of: a location validation passed state, a location validation failed state, or no location validation state.
  • the location information is carried in at least one geolocation header or a P-asserted identity (PAI) header of the SIP message.
  • PAI P-asserted identity
  • the location information is in a format of at least one of: a SIP uniform resource identifier (URI) , a session initiation protocol secure (SIPS) URI, a hypertext transfer protocol (HTTP) URI, a hypertext transfer protocol secure (HTTPS) URI, or a content identity (CID) URI.
  • URI SIP uniform resource identifier
  • SSL session initiation protocol secure
  • HTTP hypertext transfer protocol
  • HTTPS hypertext transfer protocol secure
  • CID content identity
  • the SIP message further comprises an indication of a location source associated with the location information
  • the verification request further comprises the indication of the location source
  • the indication of the location source is a fully qualified domain name (FQDN) hostname.
  • FQDN fully qualified domain name
  • an apparatus capable of performing the method 1000 may comprise means for performing the respective steps of the method 1000.
  • the means may be implemented in any suitable form.
  • the means may be implemented in a circuitry or software module.
  • the apparatus comprises: means for receiving, from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a verification response comprising verification state information associated with the location information.
  • SBC session border controller
  • SIP session initiate protocol
  • the apparatus further comprises: means for determining a secure telephone identity certificate repository (STI-CR) associated with the location information; means for transmitting a request to the STI-CR for a public key; means for receiving the public key from the STI-CR; and means for determining the verification state information based on the identity information and the public key.
  • STI-CR secure telephone identity certificate repository
  • the verification request further comprises a first fingerprint value determined by the SBC based on the location information
  • the apparatus further comprises: means for determining a second fingerprint value based on the identity information; and means for determining the verification state parameter by comparing the first fingerprint value with the second fingerprint value.
  • the SIP message further comprises an indication of a location source associated with the location information
  • the verification request further comprises the indication of the location source
  • the indication of the location source is a fully qualified domain name (FQDN) hostname.
  • FQDN fully qualified domain name
  • FIG. 11 illustrates a simplified block diagram of a device 1100 that is suitable for implementing some example embodiments of the present disclosure.
  • the device 1100 may be provided to implement the communication device, for example an IBCF, an STI-AS, or an STI-VS as discussed above.
  • the device 1100 includes one or more processors 1110, one or more memories 1120 coupled to the processor 1110, and one or more communication modules 1140 coupled to the processor 1110.
  • the communication module 1140 is for bidirectional communications.
  • the communication module 1140 has at least one antenna to facilitate communication.
  • the communication interface may represent any interface that is necessary for communication with other network elements.
  • the processor 1110 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples.
  • the device 1100 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
  • the memory 1120 may include one or more non-volatile memories and one or more volatile memories.
  • the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1124, an electrically programmable read only memory (EPROM) , a flash memory, a hard disk, a compact disc (CD) , a digital video disk (DVD) , and other magnetic storage and/or optical storage.
  • the volatile memories include, but are not limited to, a random access memory (RAM) 1122 and other volatile memories that will not last in the power-down duration.
  • a computer program 1130 includes computer executable instructions that are executed by the associated processor 1110.
  • the program 1130 may be stored in the ROM 1124.
  • the processor 1110 may perform any suitable actions and processing by loading the program 1130 into the RAM 1122.
  • the embodiments of the present disclosure may be implemented by means of the program 1130 so that the device 1100 may perform any process of the disclosure as discussed with reference to FIGS. 4-10.
  • the embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
  • the program 1130 may be tangibly contained in a computer readable medium which may be included in the device 1100 (such as in the memory 1120) or other storage devices that are accessible by the device 1100.
  • the device 1100 may load the program 1130 from the computer readable medium to the RAM 1122 for execution.
  • the computer readable medium may include any types of tangible non-volatile storage, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like.
  • FIG. 12 illustrates a block diagram of an example of a computer readable medium 1200 in accordance with some example embodiments of the present disclosure.
  • the computer readable medium 1200 has the program 1130 stored thereon. It is noted that although the computer readable medium 1200 is depicted in form of CD or DVD in FIG. 12, the computer readable medium 1200 may be in any other form suitable for carry or hold the program 1130.
  • various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
  • the present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium.
  • the computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target real or virtual processor, to carry out the method as described above with reference to any of FIGS. 7-10.
  • program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types.
  • the functionality of the program modules may be combined or split between program modules as desired in various embodiments.
  • Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
  • Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions/operations specified in the flowcharts and/or block diagrams to be implemented.
  • the program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
  • the computer program codes or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above.
  • Examples of the carrier include a signal, computer readable medium, and the like.
  • the computer readable medium may be a computer readable signal medium or a computer readable storage medium.
  • a computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
  • non-transitory is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Business, Economics & Management (AREA)
  • General Business, Economics & Management (AREA)
  • Multimedia (AREA)
  • Power Engineering (AREA)
  • Telephonic Communication Services (AREA)

Abstract

Example embodiments of the present disclosure relate to an SBC, an STI-AS, an STI-VS, methods, apparatuses and a computer readable storage medium for location integrity protection. In some embodiments, the SBC receives, from a location provider, a first SIP message comprising location information; transmits, to an STI-AS, a signing request comprising the location information; receives, from the STI-AS, a signing response comprising identity information associated with the location information; and transmits, to a further device, a second SIP message based on the first SIP message and the identity information. As such, since the location information is signed by the STI-AS, the downstream network may validate the signed information for data integrity; therefore, the location information in a SIP message may be validated, to determine whether it has not been spoofed, mocked, or attacked.

Description

    LOCATION INTEGRITY PROTECTION FIELD
  • Example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to devices, methods, apparatuses and a computer readable storage medium for location integrity protection.
  • BACKGROUND
  • Illegitimate caller location or information spoofing is becoming a major concern for telecommunication service providers and/or public safety services/resources. With technology constantly advancing in Internet Protocol (IP) -based network, the location information carried over an IP networking using the Session Initiation Protocol (SIP) is widely implemented in the telecommunication industry; however, it’s possibly for anybody or middle-man to attack, spoof, or mock the information such as location of the device, personal medical data, emergency contact information, service provider information, presence information where it can provide the critical message for the public safety service accurately allocate the necessary resources (the first responders –ambulance, policy, firefighter, rescuing team, etc... ) to the scene where the actual emergency service is desired.
  • SUMMARY
  • In general, example embodiments of the present disclosure provide a solution for location integrity protection in an emergency service.
  • In a first aspect, there is provided a device. The device comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a location provider, a first session initiate protocol (SIP) message comprising location information; transmit, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; receive, from the STI-AS, a signing response comprising identity information associated with the location information; and transmit, to a further device, a second SIP message based on the first SIP message and the identity information.
  • In a second aspect, there is provided a device. The device comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and transmit, to the SBC, a signing response comprising identity information associated with the location information.
  • In a third aspect, there is provided a device. The device comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; transmit, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; receive, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and transmit, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • In a fourth aspect, there is provided a device. The device comprises at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to: receive, from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and transmit, to the SBC, a verification response comprising verification state information associated with the location information.
  • In a fifth aspect, there is provided a method performed by an SBC. The method comprises: receiving, at a session border controller from a location provider, a first session initiate protocol (SIP) message comprising location information; transmitting, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; receiving, from the STI-AS, a signing response comprising identity information associated with the location information; and transmitting, to a further device, a second SIP message based on the first SIP message and the identity information.
  • In a sixth aspect, there is provided a method performed by an STI-AS. The method comprises: receiving, at a secure telephone identity authentication server (STI-AS) from a session border controller (SBC) , a signing request comprising location information  being comprised in a session initiate protocol (SIP) message; and transmitting, to the SBC, a signing response comprising identity information associated with the location information.
  • In a seventh aspect, there is provided a method performed by an SBC. The method comprises: receiving, at a session border controller from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; transmitting, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; receiving, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and transmitting, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • In an eighth aspect, there is provided a method performed by an STI-VS. The method comprises: receiving, at a secure telephone identity verification server (STI-VS) from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and transmitting, to the SBC, a verification response comprising verification state information associated with the location information.
  • In a ninth aspect, there is provided an apparatus. The apparatus comprises: means for receiving, at a session border controller from a location provider, a first session initiate protocol (SIP) message comprising location information; means for transmitting, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; means for receiving, from the STI-AS, a signing response comprising identity information associated with the location information; and means for transmitting, to a further device, a second SIP message based on the first SIP message and the identity information.
  • In a tenth aspect, there is provided an apparatus. The apparatus comprises: means for receiving, at a secure telephone identity authentication server (STI-AS) from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a signing response comprising identity information associated with the location information.
  • In an eleventh aspect, there is provided an apparatus. The apparatus comprises: means for receiving, at a session border controller from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; means for transmitting, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; means for receiving, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and means for transmitting, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • In a twelfth aspect, there is provided an apparatus. The apparatus comprises: means for receiving, at a secure telephone identity verification server (STI-VS) from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a verification response comprising verification state information associated with the location information.
  • In a thirteenth aspect, there is provided a non-transitory computer readable medium comprising program instructions for causing an apparatus to perform at least the method in the fifth, sixth, seventh, or eighth aspect.
  • In a fourteenth aspect, there is provided a computer program comprising instructions, which, when executed by an apparatus, cause the apparatus at least to perform the method in the fifth, sixth, seventh, or eighth aspect.
  • In a fifteenth aspect, there is provided an SBC. The SBC comprises: receiving circuitry configured to receive, from a location provider, a first session initiate protocol (SIP) message comprising location information; transmitting circuitry configured to transmit, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; receiving circuitry configured to receive, from the STI-AS, a signing response comprising identity information associated with the location information; and transmitting circuitry configured to transmit, to a further device, a second SIP message based on the first SIP message and the identity information..
  • In a sixteenth aspect, there is provided an STI-AS. The STI-AS comprises: receiving circuitry configured to receive, from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP)  message; and transmitting circuitry configured to transmit, to the SBC, a signing response comprising identity information associated with the location information.
  • In a seventeenth aspect, there is provided an SBC. The SBC comprises: receiving circuitry configured to receive, from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; transmitting circuitry configured to transmit, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; receiving circuitry configured to receive, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and transmitting circuitry configured to transmit, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • In an eighteenth aspect, there is provided an STI-VS. The STI-VS comprises: receiving circuitry configured to receive, from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and transmitting circuitry configured to transmit, to the SBC, a verification response comprising verification state information associated with the location information.
  • In a nineteenth aspect, there is provided a computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the method in the fifth, sixth, seventh, or eighth aspect.
  • It is to be understood that the summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description.
  • BRIEF DESCRIPTION OF THE DRAWINGS
  • Some example embodiments will now be described with reference to the accompanying drawings, in which:
  • FIG. 1 illustrates an example call flow;
  • FIG. 2 illustrates an overview of STIR-SHAKEN architecture for a call from an originating service provider to a terminating PSAP;
  • FIG. 3 illustrates an example emergency call flow in which the calling number may be verified;
  • FIG. 4 illustrates an example process in accordance with some example embodiments of the present disclosure;
  • FIG. 5A illustrates an example process of request handing at the IBCF with STI-AS for geolocation assertion in accordance with some example embodiments of the present disclosure;
  • FIG. 5B illustrates an example process of request handing at the IBCF with STI-VS for geolocation verification in accordance with some example embodiments of the present disclosure;
  • FIGS. 6A-6C illustrate some examples of geolocation header in accordance with some example embodiments of the present disclosure;
  • FIG. 7 illustrates an example of a process flow performed by a session border controller, such as an egress IBCF, in accordance with some example embodiments of the present disclosure;
  • FIG. 8 illustrates an example of a process flow performed by an STI-AS in accordance with some example embodiments of the present disclosure;
  • FIG. 9 illustrates an example of a process flow performed by a session border controller, such as an ingress IBCF, in accordance with some example embodiments of the present disclosure;
  • FIG. 10 illustrates an example of a process flow performed by an STI-VS in accordance with some example embodiments of the present disclosure;
  • FIG. 11 illustrates a simplified block diagram of a device that is suitable for implementing some example embodiments of the present disclosure; and
  • FIG. 12 illustrates a block diagram of an example of a computer readable medium in accordance with some example embodiments of the present disclosure.
  • Throughout the drawings, the same or similar reference numerals represent the same or similar elements.
  • DETAILED DESCRIPTION
  • Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. The disclosure described herein can be implemented in various manners other than the ones described below.
  • In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
  • References in the present disclosure to “one embodiment, ” “an embodiment, ” “an example embodiment, ” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
  • It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and/or” includes any and all combinations of one or more of the listed terms.
  • The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a” , “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” , “comprising” , “has” , “having” , “includes” and/or “including” , when used herein, specify the presence of stated features, elements, and/or components etc., but do not preclude the presence or addition of one or more other features, elements, components and/or combinations thereof. As used herein, “at least one of the following:  <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
  • As used in this application, the term “circuitry” may refer to one or more or all of the following:
  • (a) hardware-only circuit implementations (such as implementations in only analog and/or digital circuitry) and
  • (b) combinations of hardware circuits and software, such as (as applicable) :
  • (i) a combination of analog and/or digital hardware circuit (s) with software/firmware and
  • (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
  • (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
  • This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and/or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
  • Some abbreviations being used in the present disclosure are listed below:
    3GPP  The 3rd Generation Partnership Project
    ATIS  Alliance for Telecommunications Industry Solutions
    BCF  Border Control Function
    CID   Content ID
    CHE  Call Handling equipment
    CPS  Certificate Provisioning Service
    CVT  Call Validation Treatment
    DIV  Diverted Call
    E-CSCF  Emergency Call Session Control Function
    E911  Emergency 9-1-1
    ESINET  Emergency Services IP Network
    ESN  Emergency Services Network
    ESRP  Emergency Service Routing Proxy
    FCC  Federal Communications Commission
    FQDN  Fully Qualified Domain Name
    HTTP  Hypertext Transfer Protocol
    HTTPS  Hypertext Transfer Protocol Secure
    IBCF  Interconnection Border Control Function
    IBGW  Interconnection Border Gateway
    I-CSCF  Interrogating Call Session Control Function
    IETF  Internet Engineering Task Force
    IP   Internet Protocol
    I-SBC  Interconnect Session Border Controller
    LRF  Location Retrieval Function
    MC   Multiple-Choice
    MIME  Multipurpose Internet Mail Extensions
    NG911  Next Generation 9-1-1
    NIST  National Institute of Standards and Technology
    OSP  Originating Service Provider
    PAI   P-Asserted-Identity
    PASSporT Personal Assertion Token
    P-CSCF  Proxy Call Session Control Function
    PIDF-LO Presence Information Data Format -Location Object
    PRF  Policy Routing Function
    PSAP  Public Safety Answering Point
    RDF  Routing Determination Function
    RPH  Resource-Priority Header
    RTP  Real-time Transport Protocol
    SERP  Emergency Service Routing Proxy
    SIP   Session Initiation Protocol
    SHAKEN Signature-based Handling of Asserted information using toKENS
    SKS  Secure Key Store
    STI   Secure Telephone Identity
    STI-AS  Secure Telephone Identity Authentication Server
    STI-CR  Secure Telephone Identity Certificate Repository
    STI-VS  Secure Telephone Identity Verification Server
    STIR  Secure Telephone Identity Revisited
    TN   Telephone Number
    UA   User Agent
    URI   Uniform Resource Identifier
  • A phone call may be initiated by a device and terminated in another device. For example, FIG. 1 illustrated an example call flow 100 of an emergency 911 (E911) call. The location information of the caller may be important for the telecommunication service provider, however it may be attached, spoofed, or mocked by a hacker.
  • For example, according to news report about swatting hoaxes in September 2022, dozens of schools in many states had gone into lockdown after the Public Safety Answering Point (PSAP) received false calls about shootings in progress in their buildings. Swatting calls can potentially disrupt the response capabilities to real public safety emergencies but also waste of resources and time on multiple departments such as fire, medical, and police. It becomes a new threat to the public safety, lawful enforcements, and citizens.
  • The SHAKEN standards developed by the ATIS, as well as specifications developed by the IETF STIR Working Group (WG) , allow calls traveling through interconnected carrier networks to have the legitimacy of their caller identity evaluated and, if asserted, "signed" as legitimate by the originating carrier. The terminating carrier performs validation checks against the signed caller identity before the calls are delivered to called users, allowing the carrier of the party receiving the call to provide an indication to the called party of the legitimacy of the caller identity information. In addition to the caller identity authentication or verification provided by the SHAKEN framework, there are several PASSport extensions defined such as RPH, DIV, DIV-O, SKAKEN, and msec.
  • FIG. 2 illustrates an overview of STIR-SHAKEN architecture 200 for a call from an originating service provider to a terminating PSAP. The certificate provisioning service may be a logical service used to provision certificates used for STI. The STI-CR may represent the public/accessible store for public key certificates. The SKS may be a logical highly secure element that stores secret private keys.
  • It is to be understood that the architecture 200 shown in FIG. 2 is only for the purpose of illustration and without suggesting any limitation as to the scope of the disclosure. For example, the “LRF/RDF” and “E-CSCF” at the originating service provider, and the “LRF/RDF/PRF” and “I/E-CSCF” at the terminating NG911 ESN provider may be implemented as other network elements. For example, although the architecture 200 is illustrated with respect to the NG911, a similar architecture may be applied for any call other than an E911.
  • STIR and SHAKEN use digital certificates, based on common public key cryptography techniques, to ensure the calling number of a telephone call is secure. Every telephone service provider obtains their digital certificate from a certificate authority (STI-CA) who is trusted by other telephone service providers. The certificate technology enables the called party to verify that the calling number is accurate and has not been spoofed. This mechanism is not intended to protect the man-in-the-middle attacks. A malicious intermediate network can remove the identity header, then this request will be treated as not signed and hence recipients of the call can act accordingly.
  • FIG. 3 illustrates an example emergency call flow 300 in which the calling number may be verified. It is understood that the flow 300 may be a basic call flow about how the  STIR SHAKEN architecture is involved. The flow 300 may include the following steps 1 through 23.
  • 1. The originating SIP UA creates a SIP INVITE with a telephone number identity.
  • 2. The P-CSCF adds a PAI header field asserting the caller identity with “verstat” parameter, a RPH with value "esnet. 1" , and optional Attestation-Info and Origination-Id header fields.
  • 3. The E-CSCF sends the SIP INVITE to the LRF to determine routing instructions.
  • 4. The LRF acquires location, if required, and queries the RDF for the routing URI.
  • 5. The LRF returns the routing URI to the E-CSCF.
  • 6. The E-CSCF forwards the emergency call to the exit IBCF.
  • 7. The exit IBCF sends a HTTP POST message containing two signing requests over the Ms interface to the STI-AS.
  • 8. The STI-AS securely requests its private key from the SKS.
  • 9. The SKS provides the private key in the response.
  • 10. The STI-AS returns an HTTP 200 OK messages for a signed identityHeader field with identity and RPH.
  • 11. The exit IBCF uses the identity Header parameters populated in the SIP INVITE message. The IBCF will remove the "verstat" parameter from the PAI header prior and send the call to the next network.
  • 12. The entry IBCF sends an HTTP POST containing a verificationRequest to the STI-VS.
  • 13. The STI-VS determines the STI-CR URI and makes an HTTPS request to the STI-CR.
  • 14. The STI-VS validates the certificate and then extracts the public key.
  • 15. The STI-VS may interact with the CVT.
  • 16. The STI-VS returns a verificationResponse to the IBCF.
  • 17. The IBCF populates the content of the "verstatValue" in a "verstat" parameter  within the PAI header and the content of the "verstatPriority" in the Priority-Verstat header field in the SIP INVITE, and passes the SIP INVITE to the I-CSCF.
  • 18. The I-CSCF passes the SIP INVITE to E-CSCF.
  • 19. The E-CSCF forwards the SIP INVITE to the LRF.
  • 20. The LRF queries the RDF using the location information for routing URI associated with an i3 PSAP.
  • 21. The LRF redirects the call back to the E-CSCF, passing the Routing (PSAP) URI.
  • 22. The E-CSCF generates an outgoing SIP INVITE message, using the information received from the LRF, and forwards it to the IBCF.
  • 23. The exit IBCF forwards the SIP INVITE to the i3 PSAP with the appropriate "verstat" value in the PAI header, the Priority-Verstat header field and the Identity headers, and normal call processing associated with the emergency origination continues.
  • As shown in FIG. 3, the originating service provider and the NG911 emergency service network provider are related. In some cases, one or more intermediate networks may be involved. Specifically, if the entry IBCF of one intermediate network needs to do verification, a process similar with the steps 12-17 may be performed, and additionally, the exit IBCF of the intermediate network will forward the verification result to the next network element, such as an entry IBCF of the next intermediate network or the entry IBCF of the NG9-1-1 emergency service network provider.
  • Many swatting calls might be called from outside of the states, unknown caller identity, or using a fake location generated by the device where there is no mechanism to assure the data integrity and source validity when those information are traversal between different networks from the device, carrier network, intermediate network, terminating network, and to the call handling equipment where the call taker picks up the emergency call. The information can be easily mocked at any point in the end-to-end IP networks. Providing authenticated and validated information from the originating network all the way to terminating network without being mocked is the key concern.
  • Location information is essential; however, there is no mechanism to ensure such information integrity during traversing between different networks. The practices don’t provide an assurance, integrity, and protection of location information conveyed in SIP  body in the end-to-end call path while relying on the existing security mechanism and practices of SKAKEN framework. Thus, it is hard for the location consumer to know whether the location information is manipulated or not when making a decision based on the location provided, and it will be impossible to prioritize the locations based on whether it is signed or not.
  • Example embodiments of the present disclosure provide a solution for location information protection. A fingerprint associated with the location information may be transmitted to the STI-AS for signing, and the downstream network may validate the signed information for data integrity. As such, the location information in a SIP message may be validated, to determine whether it has not been spoofed, mocked, or attacked.
  • FIG. 4 illustrates an example process 400 in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the process 400 involves a location provider 401, an egress IBCF 402, an STI-AS 403, an ingress IBCF 404, an STI-VS 405, and a location consumer 406. In some example embodiments, the location provider 401, the egress IBCF 402 and the STI-AS 403 may be in a network (such as an originating network) , and the ingress IBCF 404, the STI-VS 405, and the location consumer 406 may be in another network. It would be appreciated that although the process 400 has been described with reference to NG911, however this process flow may be likewise applied to other communication scenarios. It is noted that the egress IBCF 402 in FIG. 4 may be implemented as another BCF, such as an IBGW, the present disclosure does not limit this aspect.
  • The location provider 401 may be a network element which adds the location information in the SIP signal flow in NG911. The location consumer 406 may be a network element which uses the location information, for example, the location consumer 406 may be an ESRP which will route emergency call based on the location information.
  • In the process 400, the location provider 401 transmits 410 a SIP message 412 to the egress IBCF 402. In some example embodiments, the location provider 401 may include an LRF. In some examples, the LRF may transmit the SIP message 412 to the egress IBCF 402 through other network element, such as an E-CSCF.
  • In some example embodiments, the SIP message 412 includes location information. In some example embodiments, the location information may include longitude information and latitude information. In some example embodiments, the location information may  include information of a specific geographic position, such as a building.
  • In some example embodiments, the location information may be represented as an identifier of a location URI. In some examples, the location information may be in a format of one or more of: a SIP URI, a SIPS URI, an HTTP URI, an HTTPS URI, or a CID URI. For example, the location information in a format of CID URI may be “cid: user@example. com” . For example, the location information in a format of HTTPS URI may be “https: //operator. net/yzWuekc7Ye48CM5X0On_sA” . For example, the location information in a format of SIP URI may be “sip: 1234567890@operator. net” .
  • In some example embodiments, the location information may be carried in at least one geolocation header of the SIP message. In some examples, one geolocation header may include location information of the caller’s terminal device. In some examples, one geolocation header may include location information of a location which the caller inputs. In some examples, one geolocation header may include location information of a base station communicated with the caller’s terminal device.
  • In addition or alternatively, the location provider 401 may determine 409 a fingerprint associated with the location information. In some examples, the length of the fingerprint may equal to a predefined value, such as 64 bits. In some example embodiments, the location provider 401 may generate the fingerprint from the location information using an algorithm.
  • In some examples, the algorithm may be a hash algorithm. For example, a hash function may be used for the generation of the fingerprint. For example, the hash algorithm may be any one of: “SHA256” , “SHA384” , or “SHA512” , which are defined as part of the SHA-2 set of cryptographic hash functions by the NIST. In some examples, a default hash algorithm used by the location provider 401 may be “SHA256” .
  • In some other examples, the algorithm may be a Rabin’s algorithm. It is to be understood that the algorithm may be another one other than the hash or Rabin’s algorithm, the present disclosure does not limit this aspect.
  • In some example embodiments, the location information used for generating the fingerprint may include all location related information. For example, the location information may include an MIME header information if it is included in the SIP body.
  • It is to be appreciated that the term “fingerprint” may be also called as a fingerprint value, a fingerprint parameter, etc., the term “algorithm” may be also called as an algorithm  parameter, etc., the present disclosure does not limit this aspect.
  • In some example embodiments, the SIP message 412 may further include the fingerprint and the algorithm. For example, the SIP message 412 may include a fingerprint header carrying a fingerprint header parameter, and an algorithm header carrying an algorithm header parameter.
  • In some example embodiments, the SIP message 412 may further include one or more of an algorithm header parameter, or a fingerprint header parameter associated with the location information. In some examples, the fingerprint header parameter may indicate the fingerprint determined at 409, and the algorithm header parameter may indicate the algorithm used for generating the fingerprint. For example, the SIP message 412 may further include “alg=algorithm_token; fingerprint=fingerprint_value” to represent the algorithm and the fingerprint respectively.
  • In some example embodiments, the SIP message 412 may further include an indication of a location source associated with the location information. In some examples, the indication of the location source may include a host name, for example, an FQDN hostname.
  • In some example embodiments, the SIP message 412 includes a PAI header, and the location information, the algorithm and the signature are all carried in the PAI header. In some examples, the location-related information (including the location information, the algorithm and the signature) may be in a PIDF-Lo format.
  • In some other example embodiments, an external resource (such as a remote resource) may be used to convey the location information, as such, the location information may be conveyed by reference, and there is no need to include the algorithm or the signature in the SIP message 412.
  • The egress IBCF 402 receives 414 the SIP message 412. The egress IBCF 402 transmits 420 a signing request 422 to the STI-AS 403. In some example embodiments, the signing request 422 may be transmitted via an Ms interface. In some example embodiments, the signing request 422 may be in a PASSporT format through an HTTP/HTTPS protocol.
  • In some example embodiments, the signing request 422 includes location information, for example, the egress IBCF 402 may obtain the location information from the SIP message 412.
  • In some example embodiments, the signing request 422 may further include an indication of a PASSport type (ppt) , for example, it may indicate that the type is “geolocation” or “geo” .
  • In some example embodiments, the signing request 422 may further include an indication of a location source associated with the location information. For example, the egress IBCF 402 may obtain the indication of the location source from the SIP message 412. In some examples, the indication of the location source may include a host name, for example, an FQDN hostname.
  • In some example embodiments, the location information is conveyed by value, and the algorithm header parameter and the fingerprint header parameter may be included. For example, the signing request 422 may include the location information, the algorithm, and the fingerprint which is generated from the location information by using the algorithm. In some other example embodiments, the location information is conveyed by reference, for example, an external resource (such as a remote resource) may be used, and the algorithm or the fingerprint may not be needed.
  • In some examples, the signing request 422 may be in a PASSporT format, and it may include a PASSporT header and a PASSporT payload. In some examples, the PASSporT header may include a field “ppt” to indicate the PASSport type, for example, the type is “geo” . In some examples, the PASSporT payload may include a field “geo” to indicate the location information “Geolocation” and an associated location source “loc-src” .
  • As a specific example, Table 1 shows an example PASSporT Header and an example PASSporT payload in which the location information is conveyed by value. As shown in Table 1, a field “geofingerprint” is included. Specifically, the field “geofingerprint” may be used to indicate an algorithm (such as “SHA256” ) and the fingerprint generated based on the algorithm.
  • Table 1


  • As another specific example, Table 2 shows an example PASSporT Header and an example PASSporT payload in which the location information is conveyed by reference. As shown in Table 2, there is no field “geofingerprint” included.
  • Table 2

  • It is to be understood that the examples shown in Table 1 and Table 2 are only for the purpose of illustration and without suggesting any limitation as to the scope of the disclosure, for example, some other examples may be refer to FIGS. 6A-6C.
  • Continue refer to FIG. 4, the STI-AS 403 receives 424 the signing request 422. In some example embodiments, the signing request 422 may be received via the Ms interface. In some example embodiments, the STI-AS 403 may securely request its private key from the SKS, which is not shown in FIG. 4, and the SKS may provide the private key in a response.
  • The STI-AS 403 transmits 430 a signing response 432 to the egress IBCF 402, and the egress IBCF 402 receives 434 the signing response 432. In some example embodiments, the signing response 432 may include identity information associated with the location information.
  • The egress IBCF 402 transmits 440 a SIP message 442 to the ingress IBCF 404 in the next network along the path. In some example embodiments, the SIP message 442 is different from the SIP message 422. In some examples, the egress IBCF 402 may populate the identity information into the SIP message 422 and remove the fingerprint (such as from the PAI header) to generate the SIP message 442. In some example embodiments, the SIP message 442 may further include the algorithm as described above.  In some example embodiments, the SIP message 442 may further include an indication of a location source associated with the location information as described above.
  • The ingress IBCF 404 receives 444 the SIP message 442. The ingress IBCF 404 transmits 450 a verification request 452 to the STI-VS 405. In some example embodiments, the verification request 452 includes the location information and the identity information.
  • In some example embodiments, the IBCF 404 may re-determine (or recalculate) a fingerprint based on the location information. For example, the SIP message 442 may include the algorithm which was used by the location provider 410. The IBCF 404 may obtain the location information and the algorithm from the SIP message 442, and re-determine (or recalculate) a fingerprint based on the location information and the algorithm. For ease of description, the re-determined (or recalculated) fingerprint at the ingress IBCF 404 may be called as a first fingerprint. In some examples, the verification request 452 may further include the re-determined (or recalculated) fingerprint, i.e., the first fingerprint.
  • In some examples, the location information in the verification request 452 may be carried in a field of “geo” , and the type of the location information in the verification request 452 may be a string. In some examples, the verification request 452 may further include the re-determined (or recalculated) fingerprint which is carried in a field of “geofingerprint” , and the type of the re-determined (or recalculated) fingerprint may be a string. It is understood that in case that the fingerprint is conveyed by reference, there is no need to include the fingerprint in the verification request 452.
  • In some example embodiments, the verification request 452 may further include an indication of a location source associated with the location information. In some examples, the indication of the location source may include a host name, for example, an FQDN hostname.
  • The STI-VS 405 receives 454 the verification request 452. The STI-VS 405 transmits 460 a verification response 462 to the ingress IBCF 404. The verification response 462 may include a verification state parameter associated with the location information. For example, the verification state parameter may also be called as verification information, a verification result, etc.
  • In some example embodiments, the STI-VS 405 may determine the STI-CR and  transmit a request to the STI-CR for a public key. The STI-VS 405 may further receive the public key from the STI-CR. In some examples, the STI-VS 405 may determine a fingerprint (may be called as a second fingerprint) based on the identity information, for example, by using the public key. In some examples, the STI-VS 405 may compare the determined fingerprint (the second fingerprint) with the re-determined (or recalculated) fingerprint (the first fingerprint) included in the verification request 452. In some examples, if the second fingerprint is the same as the first fingerprint, the verification information may indicate that the verification is passed, for example, represented as Geo-Validation-Passed. In some examples, if the second fingerprint is different from the first fingerprint, the verification information may indicate that the verification is failed, for example, represented as Geo-Validation-Failed.
  • In some examples, if the identity information cannot be used for determining the second fingerprint, or the STI-VS 405 cannot determine the second fingerprint, or some other cases, the verification information may indicate that there is no verification, for example, represented as No-GEO-Validation.
  • In some example embodiments, the verification state parameter associated with the location information may indicate one of: a geolocation validation passed state, a geolocation validation failed state, or no geolocation validation state.
  • The ingress IBCF 404 receives 464 the verification response 462. In some examples, the ingress IBCF 404 transmits 470 a SIP message 472 to the location consumer 406. The SIP message 472 includes the location information and the verification information, such as a verification state parameter. In some example embodiments, the ingress IBCF 404 may populate the verification information into the SIP message 442 to generate the SIP message 472. For example, the verification state parameter may be populated in to the PAI header of the SIP message 472.
  • Accordingly, the location consumer 406 receives 474 the SIP message 472. In some example embodiments, the location consumer 406 may take an action based on the verification information (such as the verification state parameter) in the SIP message 472. In some examples, the SIP message 472 may be forwarded to the PSAP if the verification state parameter indicates a geolocation validation passed state.
  • According to the embodiments of the present disclosure, a fingerprint associated with the location information may be transmitted to the STI-AS for signing, and the  downstream network may validate the signed information for data integrity. For example, the STI-VS may verify whether the location information has been spoofed. As such, the location information in a SIP message may be validated, to determine whether it has not been spoofed, mocked, or attacked.
  • The framework or mechanism proposed in the present disclosure may be used to be an essential mechanism and process for location spoofing or data spoofing mitigation, for example, FCC regulations. The framework or mechanism proposed in the present disclosure may be applied to several network elements defined in 3GPP, an example will be described with reference to FIGS. 5A-5B.
  • FIG. 5A illustrates an example process 510 of request handing at the IBCF with STI-AS for geolocation assertion in accordance with some example embodiments of the present disclosure. The process 510 relates some operations in the originating network, and it involves an E-CSCF 511, an LRF 512, an IBCF 513, and an STI-AS 514. It is understood that the IBCF 513 may be an egress IBCF.
  • The E-CSCF 511 transmits 531 a SIP INVITE message to the LRF 512, where the SIP INVITE message may include a called number (To) , a calling number (From) , and a PAI header. In some examples, the SIP INVITE message may further include other information which will not be listed herein.
  • The LRF 512 transmits 532 a 300 MC message to the E-CSCF 511, where the 300MC message may include location information and at least one fingerprint associated with the location information. In some example embodiments, the 300 MC message may include geolocation header and PIDF-Lo, where the geolocation header includes the location information and the PIDF-Lo includes the fingerprint. In some example embodiments, the PIDF-Lo content is generated by the LRF 512 and is associated with the geolocation header. In some example embodiments, the PIDF-Lo content is used for spoofing mitigation purpose. The PIDF-Lo content may be hashed by an algorithm (such as SHA3) and populated into specific header parameter value for STI-AS 514 signing.
  • The E-CSCF 511 transmits 533 a SIP INVITE message to the IBCF 513, where the SIP INVITE message to the IBCF 513 includes a called number (To) , a calling number (From) , and a PAI header, where the PAI header may include location information. In some examples, the PAI header may further include one or more of: the algorithm (such as a harsh algorithm) , the fingerprint (in a PIDF-Lo format) and an indication of a location  source. For example, the SIP INVITE message to the IBCF 513 includes:
  • The information “cid: Cas4rIOcdWxywmB6QS5M7lPEhewIcQ@operator. net” refers to the location information, “alg=SHA3-256” refers to the hash algorithm, “hash=xxxxxxxxxx” refers to the fingerprint generated by using the hash algorithm, and “locSrc=lis. operator. net” refers to the indication of the location source.
  • The IBCF 513 transmits 534 a signing request to the STI-AS 514. The signing request may be in PASSporT format through the HTTP/HTTPS protocol, and may include information required by STI-AS 514 to get the signing result. In some examples, the signing request may at least include the location information, for example, it may be indicated by “geo” . In some examples, the signing request may include the algorithm (such as a hash algorithm) and the fingerprint value (such as a hash value) , for examples, they may be indicated by “geofingerprint” . For example, the signing request to the STI-AS 514 includes the following contents for signing:
  • The STI-AS 514 transmits 535 a signing response to the IBCF 513, where the signing response may include identity information. The identity information may be  associated with the location information and the identity information may be used for verification by STI-VS. In some example embodiments, the signing response may further include an indication of signing result (such as, Result=Success) , and/or an indication of error code (such as Error Code=none) . As shown in FIG. 5A, the identity information includes “Identity = JhbG.. 35cw; info = https: example. com/passport. crt. ” 
  • The IBCF 513 transmits 536 a SIP INVITE message to an ingress IBCF in another network. Specifically, the IBCF 513 may populate the identity information into the SIP INVITE message received from the E-CSCF 511, and remove the fingerprint (in a PIDF-Lo format) from the PAI header. For example, the SIP INVITE message from the IBCF 513 includes:
  • It is to be understood that each of the SIP INVITE messages received by the LRF 512, received by the IBCF 513, and transmitted by the IBCF 513 includes a PAI header, but they may include different information. For example, the PAI header at step 531 does not include location information or a fingerprint, the PAI header at step 533 includes the location information and the fingerprint, while the PAI header at step 536 includes the location information but does not include the fingerprint.
  • FIG. 5B illustrates an example process 520 of request handing at the IBCF with STI-VS for geolocation verification in accordance with some example embodiments of the present disclosure. The process 520 relates some operations in the terminating network or an intermediate network, and it involves an ingress IBCF 521, an STI-VS 522, and an I-CSCF or an E-CSCF 523.
  • The ingress IBCF 521 receives 541 a SIP INVITE message. In some examples, the SIP INVITE message may be received from an egress IBCF of a pervious network, such as the IBCF 513 as shown in FIG. 5A. In some example embodiments, the SIP INVITE message received by the ingress IBCF 521 includes location information and identity information, and it may further include an indication of a location source and/or an algorithm. For example, the SIP INVITE message received by the ingress IBCF 521 includes:
  • In some example embodiments, the SIP INVITE message received by the ingress IBCF 521 may be the same as that transmitted by the IBCF 513 with reference to FIG. 5A, and thus will not be repeated herein.
  • The ingress IBCF 521 transmits 542 a verification request to the STI-VS 522. The verification request may include information for verification. In some example embodiments, the ingress IBCF 521 may re-determine a fingerprint from the location information carried in the SIP INVITE message, and the verification request may include the location information, the identity information, and the re-determined fingerprint. For example, the ingress IBCF 521 may use the algorithm (such as a hash algorithm) provided in the geolocation header of the SIP INVITE message and recalculate the fingerprint. For example, the verification request may include the following contents for verification:

  • It is understood that geofingerprint = “xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx” in the verification request includes the re-determined (or recalculated) fingerprint.
  • The STI-VS 522 transmits 543 a verification response to the ingress IBCF 521, where the verification response includes verification information. The verification information may indicate whether the location information in the SIP INVITE message has been spoofed or mocked. In some examples, the STI-VS 522 may determine a fingerprint based on the identity information, and compare the determined fingerprint with the re-determined (or recalculated) fingerprint included in the verification request to determine the verification information. For example, the verification information may indicate that the verification is passed: “verstat: Geo-Validation-Passed” .
  • In some examples, the verification response may further include an indication of verification result (such as, Result=Success) , and/or an indication of error code (such as Error Code=none) .
  • The ingress IBCF 521 transmits 544 a SIP INVITE message to the I-CSCF/E-CSCF 523. In some example embodiments, the ingress IBCF 521 may populate the varification information into the SIP INVITE message. In some examples, the ingress IBCF 521 may populate the content of “verstat” from the verification response into the PAI header in the SIP INVITE message. For example, the SIP INVITE message transmitted from the ingress IBCF 521 includes:
  • According to the embodiments with reference to FIGS. 5A-5B, LRF is a critical network element in the framework of the present disclosure, the LRF 512 may generate a fingerprint (ahashed token) which may be included in the 300 MC response returning back to the E-CSCF 511, accordingly, a new SIP INVITE message with the fingerprint may be transmitted to the next hop, such as the IBCF 513. The IBCF 513 may interact with the STI-AS 514 so as to sign the token in an Identity header. The downstream network such as ESINET or i3 Architecture can validate the signed information with STI-VS 522 for data integrity and validation result.
  • It is to be appreciated that the network elements shown in FIGS. 5A-5B are only for the purpose of illustration, in actual scenarios, there may be some other network elements, such as, a BCF, a CHE, an ESRP, etc., the present disclosure does not limit this aspect.
  • FIGS. 6A-6C illustrate some examples of geolocation header in accordance with some example embodiments of the present disclosure. The geolocation header (GEO) may be in a PASSporT format, specifically, it may include PASSport Header, PASSporT Payload, and PASSporT Signature. The PASSport type may be “geo” , as indicated by “ppt” .
  • FIG. 6A illustrates an example GEO identity header with CID URI 610. As shown in FIG. 6A, the location information may be “cid: user@example. com” , as indicated by “geo” . The fingerprint may be “0beaa5a85b865a9cd1ea4f58fa8dda0e7e8e4dd2a0052 6213df44157aba5107f” using an algorithm “SHA3-256” , as indicated by “geofingerprint” . The indication of the location source may be “lis. operator. net” , as indicated by “locSrc” .
  • FIG. 6B illustrates an example GEO identity header with HTTPS URI 620. As shown in FIG. 6B, the location information may be “https: //operator. net/yzWuekc7Ye48C M5X0On_sA” , as indicated by “geo” . The fingerprint may be “f8997f6e37eb53f2be5452 9246323c8623c344c6dd34f835f628166ae18db87f” using an algorithm “SHA3-256” , as indicated by “geofingerprint” . The indication of the location source may be “lis. operator. net” , as indicated by “locSrc” .
  • FIG. 6C illustrates an example GEO identity header with SIP URI 630. As shown in FIG. 6C, the location information may be “sip: 1234567890@operator. net” , as indicated by “geo” . The fingerprint may be “77976383a6c695abf0a3cb0321826bb187881 b03877c743a1fb9f5ec16261522” using an algorithm “SHA3-256” , as indicated by  “geofingerprint” . The indication of the location source may be “lis. operator. net” , as indicated by “locSrc” .
  • It is to be understood that the field “geofingerprint” used for indicating the algorithm and the fingerprint is described for the purpose of illustration without any limitation of the scope of the disclosure. In some examples, if the algorithm is a hash algorithm, a field “geohash” may be used for indicating the algorithm and the fingerprint. In some other examples, the algorithm and the fingerprint may be indicated separately, for example, the fields “alg” and “hash” may be used for indicating the algorithm and the fingerprint respectively. In some other examples, the location information, the algorithm, and the indication of the location source may be indicated in a same field, such as a field “geo” , and the fingerprint may be indicated separately. It is to be appreciated that the algorithm and the fingerprint may be indicated by other means and the present disclosure does not limit this aspect.
  • According to discussions with reference to FIGS. 4-6C, the embodiments in the present disclosure provide a solution for data assurance, integrity and protection when critical information such as location information is conveyed in SIP body. An associated SIP header which includes the critical information and signed by the providers with signatures may be used to ensure that the downstream service provider can validate the data whether it has been spoofed, mocked, or attacked, and authenticated by original provider.
  • In the present disclosure, the attestation and data integrity is introduced in order to mitigate the problem from bad actors mocking, spoofing, swatting the data in a call signal path so that the downstream system can detect whether the data is generated by the bad actor or not, and can take caution on it. Also, the data can be signed and attested by the data provider so that the public authority can trace back where the data was generated by which service provider in the call path. This brings the data authentication, authorization, integrity, and attestation into a next level of data assurance in the public safety networks.
  • FIG. 7 illustrates a flowchart 700 of a method implemented at a session border controller, such as an egress IBCF, in accordance with some example embodiments of the present disclosure. At block 710, the egress IBCF receives, from a location provider, a first SIP message comprising location information. At block 720, the egress IBCF transmits, to an STI-AS, a signing request comprising the location information. At block 730, the egress IBCF receives, from the STI-AS, a signing response comprising identity  information associated with the location information. At block 740, the egress IBCF transmits, to a further device, a second SIP message based on the first SIP message and the identity information.
  • In some example embodiments, the first SIP message further comprises at least one of: an algorithm header parameter, or a fingerprint header parameter, and the fingerprint header parameter indicates a fingerprint value being generated from the location information using an algorithm indicated by the algorithm header parameter. In some example embodiments, the location information is in a PIDF-Lo format. In some example embodiments, the signing request further comprises the fingerprint value. In some example embodiments, the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • In some example embodiments, the egress IBCF populates the identity information into the first SIP message; and removes at least one of: the algorithm header parameter, or the fingerprint header parameter.
  • In some example embodiments, the location information is determined by reference, and the first SIP message does not comprise the fingerprint header parameter.
  • In some example embodiments, the location information is carried in at least one geolocation header or a PAI header of the first SIP message.
  • In some example embodiments, the location information is in a format of at least one of: a SIP URI, a SIPS URI, an HTTP URI, an HTTPS URI, or a CID URI.
  • In some example embodiments, the first SIP message further comprises an indication of a location source associated with the location information, and the signing request further comprises the indication of the location source. In some example embodiments, the indication of the location source comprises an FQDN hostname.
  • FIG. 8 illustrates a flowchart 800 of a method implemented at an STI-AS in accordance with some example embodiments of the present disclosure. At block 810, The STI-AS receives, from an SBC, a signing request comprising location information being comprised in a SIP message. At block 820, the STI-AS transmits, to the SBC, a signing response comprising identity information associated with the location information.
  • In some example embodiments, the STI-AS transmits a request to a secure key store (SKS) for a private key; receives the private key from the SKS; and determines the identity information based on the location information and the private key.
  • In some example embodiments, the signing request further comprises a fingerprint value indicated by a fingerprint header parameter in the SIP message and generated from the location information using an algorithm indicated by an algorithm header parameter in the SIP message. In some example embodiments, the location information is in a PIDF-Lo format. In some example embodiments, the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • In some example embodiments, the SIP message further comprises an indication of a location source associated with the location information, and the signing request further comprises the indication of the location source. In some example embodiments, the indication of the location source comprises an FQDN hostname.
  • FIG. 9 illustrates a flowchart 900 of a method implemented at an SBC, such as an ingress IBCF, in accordance with some example embodiments of the present disclosure. At block 910, the ingress IBCF receives, from a further SBC, a SIP message comprising location information and identity information. At block 920, the ingress IBCF transmits, to an STI-VS, a verification request comprising the location information and the identity information. At block 930, the ingress IBCF receives, from the STI-VS, a verification response comprising a verification state parameter associated with the location information. At block 940, the ingress IBCF transmits, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • In some example embodiments, the ingress IBCF populates the verification state parameter into the SIP message to generate the further SIP message.
  • In some example embodiments, the SIP message further comprises an algorithm header parameter indicating an algorithm, and the ingress IBCF determines a first fingerprint value based on the location information using the algorithm, where the verification request further comprises the first fingerprint value.
  • In some example embodiments, the verification state parameter indicates one of: a location validation passed state, a location validation failed state, or no location validation state.
  • In some example embodiments, the location information is carried in at least one geolocation header or a PAI header of the SIP message.
  • In some example embodiments, the location information is in a format of at least one of: a SIP URI, a SIPS URI, an HTTP URI, an HTTPS URI, or a CID URI.
  • In some example embodiments, the SIP message further comprises an indication of a location source associated with the location information, and the verification request further comprises the indication of the location source. In some example embodiments, the indication of the location source is an FQDN hostname.
  • FIG. 10 illustrates a flowchart 1000 of a method implemented at an STI-AS in accordance with some example embodiments of the present disclosure. At block 1010, the STI-VS receives, from an SBC, a verification request comprising location information and identity information being comprised in a SIP message. At block 1020, the STI-VS transmits, to the SBC, a verification response comprising verification state information associated with the location information.
  • In some example embodiments, the STI-VS determines a secure telephone identity certificate repository (STI-CR) associated with the location information; transmits a request to the STI-CR for a public key; receives the public key from the STI-CR; and determines the verification state information based on the identity information and the public key.
  • In some example embodiments, the verification request further comprises a first fingerprint value determined by the SBC based on the location information, and the STI-VS determines a second fingerprint value based on the identity information; and determines the verification state parameter by comparing the first fingerprint value with the second fingerprint value.
  • In some example embodiments, the SIP message further comprises an indication of a location source associated with the location information, and the verification request further comprises the indication of the location source. In some example embodiments, the indication of the location source is an FQDN hostname.
  • In some example embodiments, an apparatus capable of performing the method 700 (for example, the egress IBCF) may comprise means for performing the respective steps of the method 700. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
  • In some example embodiments, the apparatus comprises: means for receiving, from a location provider, a first session initiate protocol (SIP) message comprising location information; meaning for transmitting, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information; means for receiving, from the STI-AS, a signing response comprising identity information associated with the location information; and means for transmitting, to a further device, a second SIP message based on the first SIP message and the identity information.
  • In some example embodiments, the first SIP message further comprises at least one of: an algorithm header parameter, or a fingerprint header parameter, the fingerprint header parameter indicates a fingerprint value being generated from the location information using an algorithm indicated by the algorithm header parameter, and the location information is in a PIDF-Lo format.
  • In some example embodiments, the signing request further comprises the fingerprint value.
  • In some example embodiments, the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • In some example embodiments, the apparatus comprises: means for generating the second SIP message. In some example embodiments, means for generating the second SIP message comprises: means for populating the identity information into the first SIP message; and means for removing at least one of: the algorithm header parameter, or the fingerprint header parameter.
  • In some example embodiments, the location information is determined by reference, and the first SIP message does not comprise the fingerprint header parameter.
  • In some example embodiments, the location information is carried in at least one geolocation header or a PAI header of the first SIP message.
  • In some example embodiments, the location information is in a format of at least one of: a SIP uniform resource identifier (URI) , a session initiation protocol secure (SIPS) URI, a hypertext transfer protocol (HTTP) URI, a hypertext transfer protocol secure (HTTPS) URI, or a content identity (CID) URI.
  • In some example embodiments, the first SIP message further comprises an indication of a location source associated with the location information, and the signing  request further comprises the indication of the location source. In some example embodiments, the indication of the location source comprises a fully qualified domain name (FQDN) hostname.
  • In some example embodiments, an apparatus capable of performing the method 800 (for example, the STI-AS) may comprise means for performing the respective steps of the method 800. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
  • In some example embodiments, the apparatus comprises: means for receiving, from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a signing response comprising identity information associated with the location information.
  • In some example embodiments, the apparatus further comprises: means for transmitting a request to a secure key store (SKS) for a private key; means for receiving the private key from the SKS; and means for determining the identity information based on the location information and the private key.
  • In some example embodiments, the signing request further comprises a fingerprint value indicated by a fingerprint header parameter in the SIP message and generated from the location information using an algorithm indicated by an algorithm header parameter in the SIP message, and the location information is in a presence information data format -location object (PIDF-Lo) format.
  • In some example embodiments, the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  • In some example embodiments, the SIP message further comprises an indication of a location source associated with the location information, and the signing request further comprises the indication of the location source.
  • In some example embodiments, the indication of the location source comprises a fully qualified domain name (FQDN) hostname.
  • In some example embodiments, an apparatus capable of performing the method 900 (for example, the ingress IBCF) may comprise means for performing the respective  steps of the method 900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
  • In some example embodiments, the apparatus comprises: means for receiving, from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information; means for transmitting, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information; means for receiving, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and means for transmitting, to a location consumer, a further SIP message based on the SIP message and the verification response.
  • In some example embodiments, the apparatus further comprises: means for generating the further SIP message. In some example embodiments, means for generating the further SIP message comprises: means for populating the verification state parameter into the SIP message to generate the further SIP message.
  • In some example embodiments, the SIP message further comprises an algorithm header parameter indicating an algorithm, the apparatus further comprises: means for determining a first fingerprint value based on the location information using the algorithm, where the verification request further comprises the first fingerprint value.
  • In some example embodiments, the verification state parameter indicates one of: a location validation passed state, a location validation failed state, or no location validation state.
  • In some example embodiments, the location information is carried in at least one geolocation header or a P-asserted identity (PAI) header of the SIP message.
  • In some example embodiments, the location information is in a format of at least one of: a SIP uniform resource identifier (URI) , a session initiation protocol secure (SIPS) URI, a hypertext transfer protocol (HTTP) URI, a hypertext transfer protocol secure (HTTPS) URI, or a content identity (CID) URI.
  • In some example embodiments, the SIP message further comprises an indication of a location source associated with the location information, and the verification request further comprises the indication of the location source.
  • In some example embodiments, the indication of the location source is a fully qualified domain name (FQDN) hostname.
  • In some example embodiments, an apparatus capable of performing the method 1000 (for example, the STI-VS) may comprise means for performing the respective steps of the method 1000. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module.
  • In some example embodiments, the apparatus comprises: means for receiving, from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and means for transmitting, to the SBC, a verification response comprising verification state information associated with the location information.
  • In some example embodiments, the apparatus further comprises: means for determining a secure telephone identity certificate repository (STI-CR) associated with the location information; means for transmitting a request to the STI-CR for a public key; means for receiving the public key from the STI-CR; and means for determining the verification state information based on the identity information and the public key.
  • In some example embodiments, the verification request further comprises a first fingerprint value determined by the SBC based on the location information, and the apparatus further comprises: means for determining a second fingerprint value based on the identity information; and means for determining the verification state parameter by comparing the first fingerprint value with the second fingerprint value.
  • In some example embodiments, the SIP message further comprises an indication of a location source associated with the location information, and the verification request further comprises the indication of the location source.
  • In some example embodiments, the indication of the location source is a fully qualified domain name (FQDN) hostname.
  • FIG. 11 illustrates a simplified block diagram of a device 1100 that is suitable for implementing some example embodiments of the present disclosure. The device 1100 may be provided to implement the communication device, for example an IBCF, an STI-AS, or an STI-VS as discussed above. As shown, the device 1100 includes one or more processors 1110, one or more memories 1120 coupled to the processor 1110, and one or more communication modules 1140 coupled to the processor 1110.
  • The communication module 1140 is for bidirectional communications. The communication module 1140 has at least one antenna to facilitate communication. The communication interface may represent any interface that is necessary for communication with other network elements.
  • The processor 1110 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1100 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
  • The memory 1120 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1124, an electrically programmable read only memory (EPROM) , a flash memory, a hard disk, a compact disc (CD) , a digital video disk (DVD) , and other magnetic storage and/or optical storage. Examples of the volatile memories include, but are not limited to, a random access memory (RAM) 1122 and other volatile memories that will not last in the power-down duration.
  • A computer program 1130 includes computer executable instructions that are executed by the associated processor 1110. The program 1130 may be stored in the ROM 1124. The processor 1110 may perform any suitable actions and processing by loading the program 1130 into the RAM 1122.
  • The embodiments of the present disclosure may be implemented by means of the program 1130 so that the device 1100 may perform any process of the disclosure as discussed with reference to FIGS. 4-10. The embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
  • In some example embodiments, the program 1130 may be tangibly contained in a computer readable medium which may be included in the device 1100 (such as in the memory 1120) or other storage devices that are accessible by the device 1100. The device 1100 may load the program 1130 from the computer readable medium to the RAM 1122 for execution. The computer readable medium may include any types of tangible non-volatile storage, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like.
  • FIG. 12 illustrates a block diagram of an example of a computer readable medium 1200 in accordance with some example embodiments of the present disclosure. The computer readable medium 1200 has the program 1130 stored thereon. It is noted that although the computer readable medium 1200 is depicted in form of CD or DVD in FIG. 12, the computer readable medium 1200 may be in any other form suitable for carry or hold the program 1130.
  • Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. While various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
  • The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer readable storage medium. The computer program product includes computer-executable instructions, such as those included in program modules, being executed in a device on a target real or virtual processor, to carry out the method as described above with reference to any of FIGS. 7-10. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
  • Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions/operations specified in the flowcharts and/or block diagrams to be implemented. The program code may execute  entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
  • In the context of the present disclosure, the computer program codes or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
  • The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM) , a read-only memory (ROM) , an erasable programmable read-only memory (EPROM or Flash memory) , an optical fiber, a portable compact disc read-only memory (CD-ROM) , an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .
  • Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
  • Although the present disclosure has been described in languages specific to structural features and/or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features  or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims (29)

  1. A device comprising:
    at least one processor; and
    at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to:
    receive, from a location provider, a first session initiate protocol (SIP) message comprising location information;
    transmit, to a secure telephone identity authentication server (STI-AS) , a signing request comprising the location information;
    receive, from the STI-AS, a signing response comprising identity information associated with the location information; and
    transmit, to a further device, a second SIP message based on the first SIP message and the identity information.
  2. The device of claim 1, wherein the first SIP message further comprises at least one of: an algorithm header parameter, or a fingerprint header parameter,
    wherein the fingerprint header parameter indicates a fingerprint value being generated from the location information using an algorithm indicated by the algorithm header parameter,
    and wherein the location information is in a presence information data format -location object (PIDF-Lo) format.
  3. The device of claim 2, wherein the signing request further comprises the fingerprint value.
  4. The device of claim 2 or 3, wherein the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  5. The device of any of claims 2-4, wherein the at least one memory storing instructions that, when executed by the at least one processor, further cause the device to generate the second SIP message by:
    populating the identity information into the first SIP message; and
    removing at least one of: the algorithm header parameter, or the fingerprint header parameter.
  6. The device of claim 2, wherein the location information is determined by reference, and the first SIP message does not comprise the fingerprint header parameter.
  7. The device of any of claims 1-6, wherein the location information is carried in at least one geolocation header or a P-asserted identity (PAI) header of the first SIP message.
  8. The device of any of claims 1-7, wherein the location information is in a format of at least one of:
    a SIP uniform resource identifier (URI) ,
    a session initiation protocol secure (SIPS) URI,
    a hypertext transfer protocol (HTTP) URI,
    a hypertext transfer protocol secure (HTTPS) URI, or
    a content identity (CID) URI.
  9. The device of any of claims 1-8, wherein the first SIP message further comprises an indication of a location source associated with the location information, and the signing request further comprises the indication of the location source.
  10. The device of claim 9, wherein the indication of the location source comprises a fully qualified domain name (FQDN) hostname.
  11. A device comprising:
    at least one processor; and
    at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to:
    receive, from a session border controller (SBC) , a signing request comprising location information being comprised in a session initiate protocol (SIP) message; and
    transmit, to the SBC, a signing response comprising identity information associated with the location information.
  12. The device of claim 11, wherein the at least one memory storing instructions that, when executed by the at least one processor, further cause the device to:
    transmit a request to a secure key store (SKS) for a private key;
    receive the private key from the SKS; and
    determine the identity information based on the location information and the private key.
  13. The device of claim 11 or 12, wherein the signing request further comprises a fingerprint value indicated by a fingerprint header parameter in the SIP message and generated from the location information using an algorithm indicated by an algorithm header parameter in the SIP message,
    and wherein the location information is in a presence information data format -location object (PIDF-Lo) format.
  14. The device of claim 13, wherein the algorithm indicated by the algorithm header parameter comprises a hash algorithm.
  15. The device of any of claims 11-14, wherein the SIP message further comprises an indication of a location source associated with the location information, and the signing request further comprises the indication of the location source.
  16. The device of claim 15, wherein the indication of the location source comprises a fully qualified domain name (FQDN) hostname.
  17. A device comprising:
    at least one processor; and
    at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to:
    receive, from a further session border controller (SBC) , a session initiate protocol (SIP) message comprising location information and identity information;
    transmit, to a secure telephone identity verification server (STI-VS) , a verification request comprising the location information and the identity information;
    receive, from the STI-VS, a verification response comprising a verification state parameter associated with the location information; and
    transmit, to a location consumer, a further SIP message based on the SIP message and the verification response.
  18. The device of claim 17, wherein the at least one memory storing instructions that, when executed by the at least one processor, further cause the device to generate the further SIP message by:
    populating the verification state parameter into the SIP message to generate the further SIP message.
  19. The device of claim 17 or 18, wherein the SIP message further comprises an algorithm header parameter indicating an algorithm, wherein the at least one memory storing instructions that, when executed by the at least one processor, further cause the device to:
    determine a first fingerprint value based on the location information using the algorithm,
    and wherein the verification request further comprises the first fingerprint value.
  20. The device of any of claims 17-19, wherein the verification state parameter indicates one of:
    a location validation passed state,
    a location validation failed state, or
    no location validation state.
  21. The device of any of claims 17-20, wherein the location information is carried in at least one geolocation header or a P-asserted identity (PAI) header of the SIP message.
  22. The device of any of claims 17-21, wherein the location information is in a format of at least one of:
    a SIP uniform resource identifier (URI) ,
    a session initiation protocol secure (SIPS) URI,
    a hypertext transfer protocol (HTTP) URI,
    a hypertext transfer protocol secure (HTTPS) URI, or
    a content identity (CID) URI.
  23. The device of any of claims 17-22, wherein the SIP message further comprises an indication of a location source associated with the location information, and the verification request further comprises the indication of the location source.
  24. The device of claim 23, wherein the indication of the location source is a fully qualified domain name (FQDN) hostname.
  25. A device comprising:
    at least one processor; and
    at least one memory storing instructions that, when executed by the at least one processor, cause the device at least to:
    receive, from a session border controller (SBC) , a verification request comprising location information and identity information being comprised in a session initiate protocol (SIP) message; and
    transmit, to the SBC, a verification response comprising verification state information associated with the location information.
  26. The device of claim 25, wherein the at least one memory storing instructions that, when executed by the at least one processor, further cause the device to:
    determine a secure telephone identity certificate repository (STI-CR) associated with the location information;
    transmit a request to the STI-CR for a public key;
    receive the public key from the STI-CR; and
    determine the verification state information based on the identity information and the public key.
  27. The device of claim 25 or 26, wherein the verification request further comprises a first fingerprint value determined by the SBC based on the location information, and wherein the at least one memory storing instructions that, when executed by the at least one processor, further cause the device to:
    determine a second fingerprint value based on the identity information; and
    determine the verification state parameter by comparing the first fingerprint value with the second fingerprint value.
  28. The device of any of claims 25-27, wherein the SIP message further comprises an indication of a location source associated with the location information, and the verification request further comprises the indication of the location source.
  29. The device of claim 28, wherein the indication of the location source is a fully qualified domain name (FQDN) hostname.
EP23918985.5A 2023-01-31 2023-01-31 Location integrity protection Pending EP4659406A1 (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2023/073969 WO2024159399A1 (en) 2023-01-31 2023-01-31 Location integrity protection

Publications (1)

Publication Number Publication Date
EP4659406A1 true EP4659406A1 (en) 2025-12-10

Family

ID=92145537

Family Applications (1)

Application Number Title Priority Date Filing Date
EP23918985.5A Pending EP4659406A1 (en) 2023-01-31 2023-01-31 Location integrity protection

Country Status (3)

Country Link
EP (1) EP4659406A1 (en)
CN (1) CN120660316A (en)
WO (1) WO2024159399A1 (en)

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10097979B2 (en) * 2014-11-24 2018-10-09 Qualcomm Incorporated Location by reference for an over-the-top emergency call
US11588632B2 (en) * 2020-09-22 2023-02-21 International Business Machines Corporation Private key creation using location data
US11770694B2 (en) * 2020-11-16 2023-09-26 Oracle International Corporation Methods, systems, and computer readable media for validating location update messages

Also Published As

Publication number Publication date
WO2024159399A1 (en) 2024-08-08
CN120660316A (en) 2025-09-16

Similar Documents

Publication Publication Date Title
US9077566B2 (en) Caller ID callback authenticationi for voice over internet protocol (“VoIP”) deployments
US9247427B2 (en) Multi-factor caller identification
US10893414B1 (en) Selective attestation of wireless communications
US20200304546A1 (en) Mobility caller authenticity service system and method
US11750593B2 (en) Call authorization and verification via a service provider code
US11290592B2 (en) Call authorization and verification via a service provider code
Geneiatakis et al. A lightweight protection mechanism against signaling attacks in a SIP-based VoIP environment
US20250168646A1 (en) Conveyance of stir/shaken attestation levels using carrier code
US10666691B2 (en) Dynamic session classification
WO2024159399A1 (en) Location integrity protection
Astrakhantsev et al. Improving user security during a call
US20240111846A1 (en) Watermark server
CN108270747B (en) Authentication method and device
Zheng et al. Spam Call Detection with Hybrid Call ID Spoofing Detection and Cryptographic User Authentication
US12531949B2 (en) Out-of-band call authentication using pseudo call routing
CN113453226A (en) Dual-stack user permission authentication method and device
Moore Denial-of-Service (DoS) Attacks Against the Availability of the Next Generation 911 (NG9-1-1) System
US20240396993A1 (en) Call enhancement service via in-network branded calling delivery
US20240396992A1 (en) Pre-call management of call enhancement services for in-network branded calling delivery
US12192401B2 (en) Real time switching from unsecured to secured signaling channel
Areo Transforming Communication: A Critical Review of VoIP and Its Role in Global Networking
WO2025150914A1 (en) Procedure for ims framework to support authorization and authentication of third-party user identities in ims sessions
WO2025149218A1 (en) Extending shaken framework to validate and verify device identity
US20230012577A1 (en) Low cost defense against denial-of-service attacks
Ramadass Highly effective filtration and prevention framework for secure incoming VoIP calls

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20250901

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR