Summary
- RFC 9970, co-authored by Chris Wendt, permits selected SIP responses to carry an
rspPASSporT that signs the reached destination indest; a party without an appropriate credential for that value must not send it. - The token is evidence about a signalling response, not proof of media provenance, continuous party identity, delivery, or the action a caller should take. Certificate eligibility and local caller policy supply the consequential judgment.
The dangerous word in connected identity is often connected. It invites the reader to imagine a completed guarantee: the intended institution answered; the person who spoke was that institution; the call remained with that institution; and the device knew what to do. A cryptographic signal does not carry all of those conclusions merely because it crosses the call in the reverse direction.
RFC 9970, Connected Identity for Secure Telephone Identity Revisited (STIR), is valuable precisely because it refuses that shortcut. Chris Wendt and Jon Peterson define a way for a SIP response to contain an Identity header. A provisional or final response such as 100, 180, 183 or 200 may carry an rsp PASSporT. Its central semantic move is narrow: the certificate signs dest, the address-of-record of the reached party, rather than the request-side orig claim.
That makes a meaningful new fact available to a caller. In a straightforward setup, an originating user can otherwise see an answer without a cryptographic indication in the backward direction of who the network reached. In a retargeted call, a response may also bring back a div PASSporT chain, which explains an authorized diversion. A caller can compare the expected destination, the reached destination and any documented diversion instead of silently treating a successful dialog as identity evidence.
But the standard makes the admission conditions difficult on purpose. The terminating side must possess an appropriate credential to sign for the dest value; without one, it MUST NOT send an rsp. A relying party then has its own job: it must trust the certificate and have reasonable assurance that the certificate is eligible to sign for that telephone number. A signature validates a statement under a key. It does not supply the local evidence that a particular credential deserves that role.
The distinction becomes sharper where call routing changes the destination. If rsp signs a different dest from the one in the original dialog-forming request, RFC 9970 requires at least one div PASSporT with it. Even then, the RFC says the decision to trust div or rsp is local policy. Some systems may refuse an unexpected destination even with a technically valid chain; another caller may accept a known forwarder. The protocol exposes a basis for judgment. It does not nationalize the judgment into a single universal rule.
The response itself also cannot be treated like an ordinary request. SIP gives the recipient no way to reject a response and report an error back to its sender. If a provisional response carries a problematic PASSporT, the caller’s available protocol action is CANCEL; once the dialog exists, it is BYE. Provisional responses can also be lost or consumed by intermediaries unless the relevant reliability mechanism is used. An absent token therefore cannot be collapsed into a simple network verdict without considering delivery and the caller’s own risk posture.
Most importantly, the RFC marks a physical boundary that a good dashboard should not blur. It is a signalling mechanism. A call can be answered and later transferred, parked or otherwise handled so that the caller no longer knows who is effectively on the other end. RFC 9970 identifies that limitation rather than promising to eliminate it. It can also protect eligible mid-dialog and dialog-terminating SIP traffic, such as a signed BYE or re-INVITE, against particular impersonation paths. It does not authenticate the source of later media merely because a response-side PASSporT was valid.
This is where the article belongs beside Lu Heng’s Running-Code Primacy: a technical artifact should describe exactly what its running validation can establish, not borrow authority from a friendly interface or a broad institutional label. rsp can make a response claim checkable. The owner of certificate governance must establish who may sign; the relying party must decide whether the evidence fits the intended destination and call; and a media-security design must provide its own assurance where that assurance matters. Conflating those layers makes a portable token look like a sovereign decision.
RFC 9970 does not prescribe the caller’s user experience. It assumes, reasonably, that a caller may specify an authorization posture per call or per destination when connected identity is crucial. That is particularly relevant for a financial, government or emergency contact, where a wrong destination can convert an ordinary routing surprise into a security event. The mature design is not a glowing green badge. It is an explicit record of what was signed, why the signer was accepted, what destination was expected, what diversions were accepted and what action the caller chose.
Sources
- https://datatracker.ietf.org/person/chris%40appliedbits.com
- https://heng.lu/running-code-primary-the-patch-needed-to-preserve-the-internet-original-design/
- https://www.rfc-editor.org/rfc/rfc9970.html
- https://www.somos.com/insights/somos-inc-announces-new-hire-chris-wendt-vice-president-systems-engineering
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
