Ticket Number
Project GoalEnable PortaSwitch to detect and handle inbound calls where an external party presents a local subscriber's number as CLI, by validating the inbound CLI against the accounts, aliases, and DIDs registered in the CSP's own PortaSwitch environment.
Why this project exists ?Currently, PortaSwitch allows incoming calls from Vendor Connections to pass any CLI (Calling Line Identification) or PAI (P-Asserted-Identity) without validation. This opens a major security gap where external malicious actors can spoof the DID (Direct Inward Dialing) numbers of legitimate local customers. When these spoofed calls reach other customers within the same PortaSwitch instance, it leads to severe trust issues and potential vishing fraud.
Who are the users / whom we bring value ?
  • End users: Protected from calls that impersonate another local subscriber by using their number as CLI, and their phone numbers cannot easily be abused by external parties to impersonate them when calling other subscribers.
  • CSP Support: faster investigation of blocked/anonymised calls and validation results through xRs.
What are the benefits for CSP/ PortaSwitch owner?Prevents CLI spoofing and vishing, protects the network and customers, and supports compliance with Swiss regulatory requirements.
Target Release

AreaPortaSIP, PortaBilling

Additional Info

Specifications

References

  1. Swiss regulations about identification of the calling line.

Definitions, acronyms and abbreviation

AbbreviationDescription
CSPCommunication Service Provider
CLICalling Line Identification