<?xml version="1.0" encoding="US-ASCII"?>
<!DOCTYPE rfc SYSTEM "rfc2629.dtd" [

<!ENTITY RFC2119 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.2119.xml">
<!ENTITY RFC2397 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.2397.xml">
<!ENTITY RFC3261 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.3261.xml">
<!ENTITY RFC3324 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.3324.xml">
<!ENTITY RFC3968 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.3968.xml">
<!ENTITY RFC5039 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.5039.xml">
<!ENTITY RFC5226 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.5226.xml">
<!ENTITY RFC6809 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.6809.xml">
<!ENTITY RFC8174 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.8174.xml">
<!ENTITY RFC8224 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.8224.xml">
<!ENTITY RFC8446 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.8446.xml">
<!ENTITY RFC8588 PUBLIC '' "http://xml.resource.org/public/rfc/bibxml/reference.RFC.8588.xml">

]>
<?xml-stylesheet type='text/xsl' href='rfc2629.xslt' ?>
<?rfc strict="yes" ?>
<?rfc toc="yes"?>
<?rfc tocdepth="4"?>
<?rfc symrefs="yes"?>
<?rfc sortrefs="yes" ?>
<?rfc compact="yes" ?>
<?rfc subcompact="no" ?>
<rfc category="std" docName="draft-ietf-sipcore-callinfo-spam-04" ipr="trust200902">
    
    <!-- ***** FRONT MATTER ***** -->
    
    <front>
        <title abbrev="Call-Info Spam">SIP Call-Info Parameters for Labeling Calls</title>
        
        <!-- add 'role="editor"' below for the editors if appropriate -->
        
        <!-- Another author who claims to be an editor -->
        
        <author fullname="Henning Schulzrinne" initials="H."
            surname="Schulzrinne">
            <organization>Columbia University</organization>
            
            <address>
                <postal>
                    <street>450 Computer Science Bldg.</street>
                    <city>New York</city>
                    <region>NY</region>
                    <code>10027</code>
                    <country>US</country>
                </postal>
                
                <phone></phone>
                
                <email>hgs@cs.columbia.edu</email>
                
                <!-- uri and facsimile elements may also be added -->
            </address>
        </author>
        
        <date />
        
        <!-- Meta-data Declarations -->
        
        <area>ART</area>
        <workgroup>SIPCORE</workgroup>
        
        <keyword>SIP</keyword>
        <keyword>robocall</keyword>
        <keyword>call type</keyword>
        <keyword>spam over Internet telephony</keyword>
        
        <abstract>
            <t>
            Called parties often wish to decide whether to accept, reject or redirect calls based on the likely nature of the call. For example, they may want to reject unwanted telemarketing or fraudulent calls, but accept emergency alerts from numbers not in their address book. This document describes SIP Call-Info parameters and a feature tag that allow originating, intermediate and terminating SIP entities to label calls as to their type, confidence and references to additional information.
            </t>
        </abstract>
    </front>
    <!-- *********************************************************************** -->
    <middle>
        <section title="Introduction">

<t>In many countries, an increasing number of calls are unwanted <xref target="RFC5039"/>, as they might be fraudulent, telemarketing or the receiving party does not want to be disturbed by, say, surveys or solicitation by charities. Currently, called parties have to rely exclusively on the caller's number or, if provided, caller name, but unwanted callers may not provide their true name or may use a name that misleads, e.g., "Cardholder Services". On the other hand, many calls from unknown numbers may be important to the called party, whether this is an emergency alert from their emergency management office or a reminder about a doctor's appointment. Since many subscribers now reject all calls from unknown numbers, such calls may also inadvertently be left unanswered. Users may also install smartphone apps that can benefit from additional information in making decisions as to whether to ring, reject or redirect a call to voicemail.</t>
<t>To allow called parties to make more informed decisions on how to handle incoming calls from unknown callers, we describe a new set of parameters for the <xref target="RFC3261">SIP</xref> Call-Info header field for labeling the nature of the call.</t>
<t>This specification assumes that the user agent can trust its SIP provider to correctly label the nature of calls. This may not always be the case and not all SIP service providers will label calls, so users may need to draw on other, third-party, sources of call information beyond the scope of this specification or may decide to disregard the call labeling offered by their service provider. (Service providers may, for example, be reluctant to label calls as spam.) However, the SIP registrar already occupies a position of trust by necessity; also, the user agent is typically a customer of the operator of the registrar or within the same organization, e.g., if the registrar is part of a PBX. Thus, the entity inserting the Call-Info header field and the UAS relying on it SHOULD be part of the same <xref target="RFC3324">trust domain</xref>. Conversely, the entity signing the <xref target="RFC8224">caller information</xref> is likely either to be the caller itself or the originating service provider, neither of which is likely to label the caller as a category unlikely to be answered by the called party.</t>
<t>The service provider inserting the Call-Info header field may draw on a wide variety of sources. For example, service providers offering alerting or notification services (e.g., for packages or health alerts) may register their phone numbers, after suitable vetting, in shared databases. Government agencies could publish electronic directories of official telephone numbers, drawing on the historical precedent of the "blue pages" found in printed phone directories. Government regulators for financial services, health care providers and charitable organizations could provide sources of telephone numbers and service types belonging to such organizations. Finally, crowd-sourcing might also be used to populate databases of call types. In the United States, industry organizations have proposed variations of such caller databases to prevent accidental blocking of calls based on their statistics such as frequency or duration alone.</t>
<t>Providers may also find the SIP Priority header (<xref target="RFC3261"/>, Section 20.26) field useful in helping called parties decide how to respond to an incoming call.</t>
</section>
        
<section anchor="normative" title="Normative Language">
    
    <t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 <xref target="RFC2119"/><xref target="RFC8174"/> when, and only when, they appear in all capitals, as shown here.</t>
</section>

<section title="Overview of Operation">
    <t>This document describes a new set of optional parameters and usage for the <xref target="RFC3261">SIP</xref> Call-Info header field, with a purpose "info", for labeling the nature of the call. The header field may be inserted by the call originator, an intermediate proxy or B2BUA or the terminating carrier, based on assertions by the caller, number-indexed databases, call analytics or other sources of information. The SIP provider serving the called party MUST remove any parameters enumerated in this specification that it does not trust.</t>
    <t>To ensure that an untrusted originating caller does not mislead the called party, a new feature capability indicator <xref target="RFC6809"/>, sip.call-info.spam, in the REGISTER response signals whether the terminating carrier supports the feature described in this document and thus will remove any untrusted 'confidence', 'origin', 'source' and 'type' Call-Info header field information parameters. It is possible for the terminating carrier to support this feature by simply removing all parameters defined in the document, without inserting any of its own information, although this is likely to be unusual. A user agent MUST ignore any of the parameters defined in this document unless the feature capability indicator is present in the response to the REGISTER request. An example of the REGISTER response is shown in <xref target="example.register"/>.</t>
    <t>SIP proxies or B2BUAs MUST add a new Call-Info "info" header field value, rather than add parameters to an existing value. Thus, one SIP request MAY contain several Call-Info header instances of purpose "info", either as a single header with a comma-separated list of header values or separate headers, or some combination.</t>
    <t>As defined in <xref target="RFC3261"/>, the Call-Info header field contains a URI that can provide additional information about the caller or call. For example, many call filtering services provide a web page with crowd-sourced information about the calling number. If the entity inserting the header field does not have information it wants to link to, it MUST use an empty <xref target="RFC2397">data URL</xref> as a placeholder, as in <spanx style="verb">data:,</spanx>. (The Call-Info header field syntax makes the URI itself mandatory.) An example is shown in <xref target="example.invite"/>.</t>
</section>
    
<section title="Parameters">
    <t>All of the parameters listed below are optional and may appear in any combination and order. Their ABNF is defined in <xref target="abnf"/>. All except the 'type' parameter are optional.</t>
    <t><list style="hanging">
        <t hangText="confidence">The 'confidence' parameter carries an estimated probability that the call is of the nature indicated in the 'type' parameter, expressed as a whole-number percentage between 0 and 100, inclusive, with larger numbers indicating higher probability. The computation of the estimate is beyond the scope of this specification. If a 'type' is not specified, this parameter estimates the likelihood that the call is unwanted spam by the called party. If the confidence level is not specified, the sender considers the information reliable enough to act on, according to its local decision thresholds.</t>
        <t hangText="origin">The origin parameter provides free-text information, as a quoted-text (UTF8-encoded) string, about the source of the 'type' or 'confidence' parameter and is meant to be used for debugging, rather than for display to the end user. For example, it may indicate the name of an external information source, such as a list of known emergency alerters or a government agency.</t>
        <t hangText="source">The source parameter identifies the entity, by host name, domain or IP address, that inserted the 'confidence', 'origin' and 'type' parameters. It uses the "host" ABNF syntax.</t>
        <t hangText="type">The type parameter indicates the type of the call or caller. It is drawn from an extensible set of values, with the initial set listed below. Gateways to analog phone systems MAY include the label in caller name (CNAM) information delivered to user equipement. Automated call classification systems MAY use this information as one factor in deciding how to handle the call. Calls SHOULD be labeled with types that may make it more likely that the caller will answer (e.g., for alert and health-related calls) if the entity inserting the information is confident that the calling party number is valid, e.g., because the request has been signed <xref target="RFC8224"/>.</t>
        </list></t>
</section>

<section anchor="type" title="Call Types">
    <t>The following initial set of types are defined. The call types are generally based on the caller's telephone number or possibly an assertion by a trusted caller, as the content cannot be not known. Each call is tagged with at most one type label, i.e., the labels are meant to be mutually exclusive. The definitions are meant to be informal and reflect the common understanding of subscribers who are not lawyers. By their very nature, this classification may sometimes be erroneous, e.g., if a number has been re-assigned to another entity or if crowd-sourced information is wrong, and thus should be treated as a hint or estimate. Each entity inserting type information will need to define its own policy as to the level of certainty it requires before it inserts type information.</t>
        <t>Other strings may be used; there does not appear to be a need for defining vendor-defined strings as the likelihood of confusion between a service-provider-specific usage and a later extension to the list appears low. Additional labels are registered with IANA.</t>
        <t><list style="hanging">
            <t hangText="business">Calls placed by businesses, i.e., an entity or enterprise entered into for profit. This type is used if no other, more precise, category fits.</t>
            <t hangText="debt-collection">Calls related to collecting of debt owed or alleged to be owed by the called party.</t>
            <t hangText="emergency-alert">Calls that provide the recipient warnings and alerts regarding a pending or on-going emergency. (This call type is unrelated to emergency calls placed by individuals using emergency numbers such as 9-1-1 or 1-1-2.)</t>
            <t hangText="fraud">The call is considered to be fraudulent.</t>
            <t hangText="government">A call placed by a government entity, if no more specific label such as "health" or "debt-collection" is known or applies.</t>
            <t hangText="health">Informational calls by health plans, health care clearinghouses or health care provider, where health care means care, services, or supplies related to the health of an individual.</t>
            <t hangText="informational">Calls intended to convey information to the called party about a transaction such as package delivery, appointment reminder, or order confirmation.</t>
            <t hangText="not-for-profit">A call placed by a not-for-profit organization, including for soliciting donations or providing information.</t>
            <t hangText="personal">A non-business, person-to-person, call, e.g., from a residential line or personal mobile number.</t>
            <t hangText="political">Calls related to elections or other political purposes.</t>
            <t hangText="public-service">Calls that provide the recipient information regarding public services, e.g., school closings.</t>
            <t hangText="prison">Calls from jails, prisons and other correctional facilities.</t>
            <t hangText="spam">A call that is likely unwanted, if not otherwise classified.</t>
            <t hangText="spoofed">The calling number for this call has been spoofed. (For example, the call has failed <xref target="RFC8224">STIR validation</xref> within the SIP service provider network or the telephone number is not a valid number or is known not to have been assigned.)</t>
            <t hangText="survey">A call that solicits the opinions or data of the called party.</t>
            <t hangText="telemarketing">Calls placed in order to induce the purchase of a product or service to the called party.</t>
            <t hangText="trusted">The call is being placed by a trusted entity and falls outside the other categories listed. This may include call backs, e.g., from a conferencing service, or messages from telecommunication carriers and utilities.</t>
        </list></t>
</section>

<section anchor="example" title="Examples">
    <section anchor="example.register" title="REGISTER Response">
        <t>The example below shows a partial REGISTER response showing that the registrar and proxy will remove any untrusted Call-Info header elements.</t>
        <figure><artwork>
<![CDATA[
SIP/2.0 200 OK
...
From: Bob <sips:bob@biloxi.example.com>;tag=a73kszlfl
To: Bob <sips:bob@biloxi.example.com>;tag=34095828jh
...
Feature-Caps: *; +sip.call-info.spam
]]>
</artwork></figure>
        </section>
    <section anchor="example.invite" title="INVITE Request">
        <figure><artwork>
    INVITE sip:alice@example.com SIP/2.0
    ...
    Call-Info: &lt;http://wwww.example.com/5974c8d942f120351143>
      ;source=carrier.example.com
      ;purpose=info ;confidence=85 ;type=fraud
      ;origin="FTC fraud list"
</artwork></figure>
</section>
    </section>
    
<section anchor="abnf" title="ABNF">
        <figure>
            <artwork type="abnf">
                label-info-params = [ci-confidence] / [ci-source] / [ci-origin] / ci-type
                ci-confidence = "confidence" EQUAL 1*3DIGIT
                ci-origin = "origin" EQUAL quoted-string
                ci-source = "source" EQUAL host
                ci-type = "type" EQUAL ("business" / "debt-collection" / "emergency-alert" / "fraud" /
                            "government" / "health" / "informational" / "not-for-profit" /
                            "personal" / "political" / "public-service" / "prison" / "spam" /
                            "spoofed" / "survey" / "telemarketing" / "trusted" /
                            iana-token)
            </artwork>
        </figure>
</section>

    <section anchor="IANA" title="IANA Considerations">
        <section title="SIP Call-Info Header Field Parameters">
            <t>This document defines the 'confidence', 'origin', 'source' and 'type' parameters in the Call-Info
                header in the "Header Field Parameters and Parameter Values" registry
                defined by <xref target="RFC3968"/>.</t>
            <texttable>
                <ttcol>Header Field</ttcol>
                <ttcol>Parameter Name</ttcol>
                <ttcol>Predefined Values</ttcol>
                <ttcol>Reference</ttcol>
                <c>[this RFC]</c>
                <c>Call-Info</c>
                <c>confidence</c>
                <c>No</c>
                <c>Call-Info</c>
                <c>origin</c>
                <c>No</c>
                <c>[this RFC]</c>
                <c>Call-Info</c>
                <c>source</c>
                <c>No</c>
                <c>[this RFC]</c>
                <c>Call-Info</c>
                <c>type</c>
                <c>Yes</c>
                <c>[this RFC]</c>
            </texttable>
        </section>
        <section title="SIP Global Feature-Capability Indicator">
        <t>This document defines the feature capability sip.call-info.spam in the "SIP Feature-Capability Indicator Registration Tree" registry defined in <xref target="RFC6809"/>.</t>
        <t><list style="hanging">
            <t hangText="Name">sip.call-info.spam</t>
            <t hangText="Description">This feature-capability indicator when used in a REGISTER response indicates that the server will add, inspect, alter and possibly remove the Call-Info header field parameters defined in the reference.</t>
            <t hangText="Reference">[this RFC]</t>
            </list>
        </t>
        </section>
        <section title="SIP Call-Info Type Parameter">
            <t>This specification establishes the "Call-Info Type" sub-registry under http://www.iana.org/assignments/sip-parameters. Call-Info "type" parameters are used in the "type" parameter in the SIP Call-Info header field. The initial values are listed in <xref target="type"/>. Additional values are allocated by <xref target="RFC5226">expert review</xref>; only the token value, using the ABNF iana-token, and a brief description, typically no more than a few sentences, is required. The ABNF for iana-token is defined in <xref target="RFC3261"/>. A specification is not required.</t>
        </section>
    </section>
    
    <section anchor="security" title="Security Considerations">
        <t>The security considerations in <xref target="RFC3261"/> (Section 20.9) apply. A user agent MUST ignore the parameters defined in this document unless the SIP REGISTER response contained the sip.call-info.spam feature capability. B2BUAs or proxies that maintain user registrations MUST remove any parameters defined in this document that were provided by untrusted third parties.</t>
       <t>The UAS SHOULD only consider Call-Info header field information that originates from a registrar that is part of the same <xref target="RFC3324">trust domain</xref>.</t>
       <t>The protection offered against rogue SIP entities by the feature capability relies on protecting the REGISTER response against man-in-the-middle attacks that maliciously add the capability indicator. Thus, a UAS SHOULD NOT trust the information in the "Call-Info" header field unless the SIP session between the entity inserting the header field and the UAS is protected by <xref target="RFC8446">TLS</xref>.</t>
        <t>Labeling calls is likely only useful if the caller identity can be trusted, e.g., by having the call signaling requests <xref target="RFC8224">signed</xref>, as otherwise spoofed calls would likely be mislabeled and thus increase the likelihood that the called party is mislead, answers unwanted calls or is defrauded. Thus, this information MUST only be added calls with an attestation level of <xref target="RFC8588">"Full Attestation"</xref> or for calls where the SIP entity inserting the header knows to have correct calling number information, e.g., because the call originated within the same PBX or the same carrier and the operating entity ensures that caller ID spoofing is highly unlikely within their realm of responsibility.</t>
    </section>
    <section title="Acknowledgements">
        <t>Jim Calme and other members of the Robocall Strikeforce helped draft the initial list of call types. Tolga Asveren, Ben Campbell, Keith Drage, Christer Holmberg, Paul Kyzivat and Dale Worley provided helpful comments on the document.</t>
    </section>
    
</middle>

<!-- ********************************************************************************* -->

<back>
    <references title="Normative References">
        &RFC2119;
        &RFC2397;
        &RFC3261;
        &RFC3324;
        &RFC3968;
        &RFC5226;
        &RFC6809;
        &RFC8174;
        &RFC8224;
        &RFC8446;
    </references>
    <references title="Informative References">
        &RFC5039;
        &RFC8588;
    </references>
    
</back>
</rfc>
