Methods and apparatus to preserve original attestation/signature information for diverted calls
View Patent ↗Communications methods and apparatus for preserving STIR/SHAKEN original attestation/signature information for diverted Session Initiation Protocol (SIP) messages and/or calls. An exemplary method embodiment includes the steps of: receiving, at a first Session Border Controller (SBC), a diverted Session Initiation Protocol (SIP) INVITE message corresponding to a first call, the diverted SIP INVITE message not including an Identity header; obtaining an original Identity header or information from the original Identity header corresponding to the first call using one or more of the following: information included in the diverted SIP INVITE message, information included in a Session Description Protocol message included in the diverted SIP INVITE message, an SBC trunk group, or a source Internet Protocol (IP) address transport protocol port of an IP packet carrying the diverted SIP Invite message; and generating an Identity header based on the original Identity header or information from the original identity header.
1 . A communications method comprising:
encrypting, at a first Session Border Controller (SBC), an original Identity header or attestation information from the original Identity header corresponding to a first call;
placing, by the first SBC, the encrypted original Identity header or the encrypted attestation information from the original Identity header corresponding to the first call in a proprietary parameter of a Session Initiation Protocol (SIP) INVITE message;
communicating, from the first SBC, the SIP INVITE message to an endpoint device;
subsequent to said communicating, from the first SBC, the SIP INVITE message to the endpoint device, receiving, at a second SBC, a diverted SIP INVITE message corresponding to the first call, said diverted SIP INVITE message not including an Identity header;
obtaining the original Identity header or the attestation information from the original Identity header corresponding to the first call from information included in the diverted SIP INVITE message; and
generating an Identity header based on the original Identity header or the attestation information from the original Identity header corresponding to the first call obtained from the information included in the diverted SIP INVITE message; and
wherein said original Identity header is a SIP Identity header which includes: originating identity of the first call, destination information for the first call, and said attestation information; and
wherein at least some of the information included in the SIP Identity header has been digitally signed or encrypted.
2 . The communications method of claim 1 , wherein said information included in the diverted SIP INVITE message includes the encrypted original Identity header or the encrypted attestation information from the original Identity header corresponding to the first call.
3 . The communications method of claim 1 ,
wherein said generated Identity header is generated based on information contained in the original Identity header, said information contained in the original Identity header being said attestation information, said attestation information being an attestation level indicating a specific level of confidence in the correctness of the originating identity of the first call; and
wherein said generated Identity header includes the same originating identity for the first call and the same attestation level which is included in the original Identity header.
4 . The communications method of claim 1 , wherein the original Identity header or the attestation information from the original Identity header corresponding to the first call is encrypted by the first SBC using a shared key known to the second SBC.
5 . The communications method of claim 1 ,
wherein said Identity header not included in the diverted SIP INVITE message, said original Identity header, and said generated Identity header are SIP Identity headers including a Secure Handling of Asserted information using toKENS (SHAKEN) Personal ASSertion Token (PASSporT).
6 . A communications system comprising:
a first Session Border Controller (SBC) including:
memory;
one or more Input/Output Interfaces; and
a first processor, said first processor controlling the first SBC to perform the following operations:
encrypting an original Identity header or attestation information from the original Identity header corresponding to a first call;
placing the encrypted original Identity header or the encrypted attestation information from the original Identity header corresponding to the first call in a proprietary parameter of a Session Initiation Protocol (SIP) INVITE message; and
communicating the SIP INVITE message to an endpoint device; and
a second SBC including:
memory;
one or more Input/Output Interfaces; and
a second processor, said second processor controlling the second SBC to perform the following operations:
receiving, at the second SBC, a diverted SIP INVITE message corresponding to the first call subsequent to the first SBC communicating the SIP INVITE message to the endpoint device, said diverted SIP INVITE message not including an Identity header;
obtaining the original Identity header or the attestation information from the original Identity header corresponding to the first call from information included in the diverted SIP INVITE message; and
generating an Identity header based on the original Identity header or the attestation information from the original Identity header corresponding to the first call obtained from the information included in the diverted SIP INVITE message; and
wherein said original Identity header is a SIP Identity header which includes: originating identity of the first call, destination information for the first call, and said attestation information; and
wherein at least some of the information included in the SIP Identity header has been digitally signed or encrypted.
7 . The communications system of claim 6 , wherein said information included in the diverted SIP INVITE message includes the encrypted original Identity header or the encrypted attestation information from the original Identity header corresponding to the first call.
8 . The communications system of claim 6 ,
wherein said generated Identity header is generated based on information contained in the original Identity header, said information contained in the original Identity header being said attestation information, said attestation information being an attestation level indicating a specific level of confidence in the correctness of the originating identity of the first call; and
wherein said generated Identity header includes the same originating identity for the first call and the same attestation level which is included in the original Identity header.
9 . The communications system of claim 6 , wherein the original Identity header or the attestation information from the original Identity header corresponding to the first call is encrypted by the first SBC using a shared key known to the second SBC.
10 . A non-transitory machine readable medium including first processor executable instructions and second processor executable instructions, said first processor executable instructions when executed by a processor of a first Session Border Controller (SBC) controls the first SBC to:
encrypt an original Identity header or attestation information from the original Identity header corresponding to a first call;
place the encrypted original Identity header or the encrypted attestation information from the original Identity header corresponding to the first call in a proprietary parameter of a Session Initiation Protocol (SIP) INVITE message; and
communicate the SIP INVITE message to an endpoint device; and
wherein said second processor executable instructions when executed by a processor of a second SBC controls the second SBC to:
receive, at the second SBC, a diverted Session Initiation Protocol (SIP) SIP INVITE message corresponding to the first call subsequent to the first SBC communicating the SIP INVITE message to the endpoint device, said diverted SIP INVITE message not including an Identity header;
obtain the original Identity header or the attestation information from the original Identity header corresponding to the first call from information included in the diverted SIP INVITE message; and
generate an Identity header based on the original Identity header or the attestation information from the original identity header corresponding to the first call obtained from the information included in the diverted SIP INVITE message; and
wherein said original Identity header is a SIP Identity header which includes: originating identity of the first call, destination information for the first call, and said attestation information; and
wherein at least some of the information included in the SIP Identity header has been digitally signed or encrypted.
11 . The method of claim 1 , wherein said first SBC and said second SBC are the same SBC.
12 . The method of claim 1 , wherein the endpoint device is an Internet Protocol-Private Branch Exchange (IP-PBX).
13 . The method of claim 1 ,
wherein the first SBC, the second SBC, and the endpoint device are part of a first service provider network;
wherein the diverted SIP INVITE message received at the second SBC is received from the endpoint device, said diverted SIP INVITE message having been generated by the endpoint device based on the SIP INVITE message communicated to the endpoint device from the first SBC; and
wherein said diverted SIP INVITE message includes: (i) the proprietary parameter in which the encrypted original Identity header or the encrypted attestation information from the original Identity header corresponding to the first call was placed by the first SBC, and (ii) a To header including a destination address located in a second service provider network.
14 . The method of claim 13 , further comprising:
generating, by the second SBC, a second diverted SIP INVITE message based on the received diverted SIP INVITE message, said second diverted SIP INVITE message including the generated Identity header; and
communicating, by the second SBC, the second diverted SIP INVITE message to the destination address located in the second service provider network.
15 . The method of claim 14 , further comprising:
generating, by the first SBC, the SIP INVITE message communicated to the endpoint device based on a SIP INVITE message received by the first SBC from a third service provider network, said SIP INVITE message received from the third service provider network including the original Identity header.
16 . The communications system of claim 6 , wherein said first SBC and said second SBC are the same SBC.
17 . The communications system of claim 6 , wherein the endpoint device is an Internet Protocol-Private Branch Exchange (IP-PBX).
18 . The communications system of claim 6 ,
wherein the first SBC, the second SBC, and the endpoint device are part of a first service provider network;
wherein the diverted SIP INVITE message received at the second SBC is received from the endpoint device, said diverted SIP INVITE message having been generated by the endpoint device based on the SIP INVITE message communicated to the endpoint device from the first SBC; and
wherein said diverted SIP INVITE message includes: (i) the proprietary parameter in which the encrypted original Identity header or the encrypted attestation information from the original Identity header corresponding to the first call was placed by the first SBC, and (ii) a To header including a destination address located in a second service provider network.
19 . The communications system of claim 18 , wherein the second processor further controls the second SBC to perform the following additional operations:
generating, by the second SBC, a second diverted SIP INVITE message based on the received diverted SIP INVITE message, said second diverted SIP INVITE message including the generated Identity header; and
communicating, by the second SBC, the second diverted SIP INVITE message to the destination address located in the second service provider network.
20 . The communications system of claim 6 ,
wherein said Identity header not included in the diverted SIP INVITE message, said original Identity header, and said generated Identity header are SIP Identity headers including a Secure Handling of Asserted information using toKENS (SHAKEN) Personal ASSertion Token (PASSporT).