Registry for Country-Specific Secure Telephone Identity (STIR) Trust Anchors

STIR                                                           E. Burger
Internet-Draft                                     Georgetown University
Intended status: Standards Track                           March 8, 2020
Expires: September 9, 2020

  Registry for Country-Specific Secure Telephone Identity (STIR) Trust


   National policy defines telephone numbering governance.  One area of
   such governance are the policies applied to the Secure Telephone
   Identity Credentials defined in RFC 8226.  Nations have policies for
   the acceptable trust anchors for these credentials.  This document
   defines an IANA registry that enables a SIP call recipient in one
   country to validate the signature, as defined in RFC 8224, that
   originates in another country useing an appropriate trust anchor for
   the signer's certification path, per the origination country's trust
   anchor policy.

1.  Introduction

   One problem that plagues some communications applications is a caller
   deliberately misrepresenting their identity with the intent to
   defraud, cause harm, or wrongfully obtain anything of value.  The
   IETF Secure Telephone Identity Revisited (STIR) work group has
   developed a series of RFCs specifying the mechanisms for
   cryptographically signing the asserted identity and other elements in
   Session Initiation Protocol (SIP) [RFC3261] messages.  One kind of
   identity used in SIP is an E.164 [E.164] telephone number.  A
   telephone number is a string of digits, where the first one to three
   digits indicate a country code.  The International Telecommunications
   Union - Telecommunications Sector (ITU-T) defines country codes and
   delegates the authority for numbers under a country code to the
   respective national communications authority for that country, as
   listed in E.164 Annex D [E.164D].  Note the country code does not
   itself necessarily uniquely identify a country.  For example, in
   country codes +1 and +7, multiple countries share the country code.
   In the cases of +1 and +7, further digits in the E.164 number, known
   as national significant digits (also known as area codes in +1)
   further identify the country.  As well, there are non-geographic
   services with country codes assigned to them.

   Section 7 of Authenticated Identity Management in the Session
   Initiation Protocol [RFC8224] describes the process for signing
   identity tokens.  Correspondingly, the STIR Certificates document
   [RFC8226] describes the format of the signing certificate.  The
   protocol and formats are independent of and can have uses beyond that
   of signing originating telephone numbers.  As well, given that for
   the most part governments are responsible for managing the numbering
   resources within their country code, governmental policy may impact
   who is authorized to issue signing certificates and what constitutes
   a valid certification path.  As such, the base STIR documents defer
   certificate and validation policy to other documents.  This document
   describes a registry for finding a STIR trust anchor for a given
   country code for signed telephone numbers.  This document only
   enables policies for E.164 number identity assertions.  Moreover,
   while this document describes the STIR trust anchor registry for
   various national STIR trust anchors, it does not mandate any
