Summary
- RFC 9888 defines service-provider-operated CPSs for carrying STIR PASSporTs outside SIP when end-to-end header carriage is unavailable.
- The architecture is plural, not a single global repository: a provider may run a CPS, use a third party, or share one.
- Advertisements bind HTTPS CPS URIs to telephone-number authority expressed through TNAuthList information. Submission uses STIR credentials, the CPS applies local authorization, and TLS is required between the out-of-band authentication service and CPS.
- Pull retrieval is mandatory; push notification is optional. PASSporTs normally remain only long enough to retrieve them and no longer than their validity interval, described by RFC 9888 as a maximum of sixty seconds.
The operational sequence is specific. An out-of-band authentication service submits a PASSporT to an advertised CPS over TLS after authenticating with STIR credentials. The CPS decides locally whether that submitter is authorized. The destination verification service then locates the relevant CPS through Internet connectivity and must be able to pull the token. A push signal may accelerate discovery, but it does not replace pull support. Where one CPS serves multiple providers, it inspects the PASSporT destination and selects the authorized verification service.
The advertisement is not merely a URL directory entry. TNAuthList information supplies the telephone-number authority against which a relying party can validate whether the signer is entitled to advertise a destination. That makes discovery and authorization linked but distinct controls: a valid-looking endpoint does not by itself establish submission authority, and an authorized submitter still needs a usable, correctly advertised route.
Gateways can bridge in-band and out-of-band STIR or act for legacy providers. They can solve a signaling-path limitation, but they do not erase trust decisions about credential issuance, authorization, destination inspection, or retrieval. Operators should test those decisions as separate failure domains rather than treating the gateway as the whole security boundary.
RFC 9888 also changes where sensitive call-processing information is concentrated. The service-provider model assumes that a CPS operator already participates in call processing, yet centralized or federated CPS arrangements can still increase data-collection and correlation risk. Stored PASSporTs need not be encrypted under this service-provider model; TLS protects the service-to-service exchange, while short persistence limits the intended storage interval.
Verification fixtures. A test plan should include: (1) a call whose SIP path loses the Identity header at a gateway while the PASSporT is submitted over HTTPS; (2) an advertisement whose CPS URI and TNAuthList authority validate, plus one that does not; (3) an authenticated submitter that fails local CPS authorization; (4) a TLS failure and a pull timeout; (5) a push notification followed by successful mandatory pull; (6) a multi-provider destination that selects the correct verification service; and (7) an expired token that is no longer retained beyond its validity interval.
Operator decision path. First establish whether end-to-end SIP carriage is actually unavailable. If so, identify the destination CPS and validate its advertisement and TNAuthList authority. Then authenticate the submission service with STIR credentials, confirm local authorization, require TLS, and measure pull retrieval before the token expires. If several providers share the CPS, verify destination inspection. Finally, document gateway credentials, retention deletion, access logging, outage behavior, and privacy ownership.
The frozen evidence does not establish current production adoption by carriers or enterprises, measured robocall or impersonation outcomes, observed CPS availability or retrieval latency, commercial or federation arrangements, vendor implementation coverage, or actual retention beyond the protocol requirement. Those are unknown boundaries, not results implied by the RFC.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
