Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion registry.json
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@
"EHFdm3U_4nML6lo-q_xDTO8183hC9HlWif2l4ycNo8TW": "ovc-org-vet/ovc-org-vet.schema.json",
"EG68irpfVX667KCLwG85Cn1Mp3sCe38ftARyQJrxP2kF": "proof-of-control/proof-of-control.schema.json",
"EPy_7LE3tVdl8qEKN5i4L8eAgIM-1I51-DNiewmcq-fe": "tcr-vetting/tcr-vetting.schema.json",
"EFvnoHDY7I-kaBBeKlbDbkjG4BaI0nKLGadxBdjMGgSQ": "tn-alloc/tn-alloc.schema.json",
"EIEe3CAVep2SfJFidtPJNwJtfEAwYt2SQ4vln2nl-rrf": "tn-alloc/tn-alloc.schema.json",
"EGEebb1pVRcZ6OXHlYitl5DNh-LDrMWPwRtstiKiDhRy": "tn/tn.schema.json",
"EH6ekLjSr8V32WyFbGe1zXjTzFs9PkTYmupJ9H65O14g": "vLEI/acdc/ecr-authorization-vlei-credential.json",
"EEy9PkikFcANV1l7EHukCeXqrzT1hNZjGlUk7wuMO5jw": "vLEI/acdc/legal-entity-engagement-context-role-vLEI-credential.json",
Expand Down
46 changes: 24 additions & 22 deletions tn-alloc/example-tn-alloc.json
Original file line number Diff line number Diff line change
@@ -1,32 +1,34 @@
{
"v": "ACDC10JSON0003cd_",
"d": "EEeg55Yr01gDyCScFUaE2QgzC7IOjQRpX2sTckFZp1RP",
"v": "ACDC10JSON00040b_",
"d": "ELqKnm3DBEM1gqd9jrBiZOBgXPJe3nL0Bdl-6Y9WToaF",
"u": "0AC8kpfo-uHQvxkuGZdlSjGy",
"i": "EANghOmfYKURt3rufd9JNzQDw_7sQFxnDlIew4C3YCnM",
"ri": "EDoSO5PEPLsstDr_XXa8aHAf0YKfPlJQcxZvkpMSzQDB",
"s": "EFvnoHDY7I-kaBBeKlbDbkjG4BaI0nKLGadxBdjMGgSQ",
"s": "EIEe3CAVep2SfJFidtPJNwJtfEAwYt2SQ4vln2nl-rrf",
"a": {
"d": "ECFFejktQA0ThTqLtAUTmW46unVGf28I_arbBFnIwnWB",
"u": "0ADSLntzn8x8eNU6PhUF26hk",
"i": "EERawEn-XgvmDR_-2ESVUVC6pW-rkqBkxMTsL36HosAz",
"dt": "2024-12-20T20:40:57.888000+00:00",
"numbers": {
"rangeStart": "+1801361002",
"rangeEnd": "+1801361009"
},
"channel": "voice",
"doNotOriginate": false
"d": "EGSM6KZWVOXxmoNHlNNYBllu4DXs9Xx5-UhOnpTnDCO7",
"u": "0ADSLntzn8x8eNU6PhUF26hk",
"i": "EERawEn-XgvmDR_-2ESVUVC6pW-rkqBkxMTsL36HosAz",
"dt": "2024-12-20T20:40:57.888000+00:00",
"numbers": [
"+1801361001-+1801361002",
"+1801361005"
],
"channel": [
"voice"
]
},
"e": {
"d": "EI9qlgiDbMeJ7JTZTJfVanUFAoa0TMz281loi63nCSAH",
"tnalloc": {
"n": "EG16t8CpJROovnGpgEW1_pLxH5nSBs1xQCbRexINYJgz",
"s": "EFvnoHDY7I-kaBBeKlbDbkjG4BaI0nKLGadxBdjMGgSQ",
"o": "I2I"
}
"d": "EBY3ewECLPVjjk96hojtlfw826eL_pR_9BmjPHCpOq9i",
"tnalloc": {
"n": "EG16t8CpJROovnGpgEW1_pLxH5nSBs1xQCbRexINYJgz",
"s": "EIEe3CAVep2SfJFidtPJNwJtfEAwYt2SQ4vln2nl-rrf",
"o": "I2I"
}
},
"r": {
"d": "EJFhpp0uU7D7PKooYM5QIO1hhPKTjHE18sR4Dn0GFscR",
"perBrand": "Issuees agree not to share the phone number with other brands which may have a common owner but which will make it difficult to consistently identify the originator of traffic."
"d": "EFC5aL2PUkGzu0BdKxWwL-jGkdqzKH8UQMrJg8T0HeYW",
"governance": "Issued under governance published at https://provenant.net/governance/tn-alloc/",
"noSharing": "Issuees agree not to share or lend the allocated telephone number(s) to other parties in a way that would make it difficult to consistently identify the originator of traffic."
}
}
}
71 changes: 68 additions & 3 deletions tn-alloc/index.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,70 @@
## Telephone Number (TN) Allocation Credentials
## Telephone Number Allocation Credential

#### Purpose
### Purpose

These credentials document the issuee's right to use a phone number to make phone calls.
This credential proves that an enterprise or individual holds the **right to use (RTU)** one or more specific telephone numbers. The right-to-use may come directly from a telecommunications regulator or may be sub-allocated through a telephone number provider. The credential is channel-agnostic: the same number can carry voice calls, SMS messages, or both, and a single Telephone Number Allocation Credential covers the number regardless of channel.

### Why this credential matters

In telephony fraud and spam ecosystems, a caller or sender can trivially spoof any number they choose. Downstream recipients — call analytics platforms, carriers, campaign registries — have no way to distinguish a legitimate originator from a bad actor by looking at the calling number alone. The Telephone Number Allocation Credential establishes a cryptographic chain of custody from the regulator (who originally assigned the number block) to the enterprise that legitimately operates the number today.

A verifier who holds this credential, together with the edges that chain back to the regulating authority, has a strong basis to assert that a call or message from the claimed number was originated by the holder of this credential — and only that holder.

### Schema

See [tn-alloc.schema.json](tn-alloc.schema.json).

### Number expressions

The `numbers` attribute is an array of **number expressions**. Each expression is either:

- A **single E.164 number** — e.g., `+15551234567`
- An **inclusive range** — two E.164 numbers joined by a hyphen, e.g., `+15551230000-+15551239999`

All numbers in a single credential must share the **same granting authority** — the issuer uses a single edge to point to the party that granted the right to use those numbers. If a holder has numbers from two different source authorities, they must hold two separate credentials.

Verifiers evaluate each expression in the array. For a single number, it must match exactly. For a range, the number under test must be numerically between the start and end values, inclusive.

### Multichannel readiness

This schema supports both **voice** and **SMS** use cases without modification:

- For **voice**, the holder uses the credential to assert origin identity when initiating a call.
- For **SMS / A2P campaigns**, the holder presents this credential to a campaign registry (e.g., The Campaign Registry) as proof of number ownership before campaign provisioning. The credential does not carry a campaign ID — campaign-level attributes belong in a separate campaign credential that references this one.

The optional `channel` field can narrow the scope of the credential to a specific channel or set of channels. If omitted, no channel restriction is implied — the credential is valid for any use of the allocated numbers. If present, it is an array of one or both of `"sms"` and `"voice"`.

| `channel` value | Meaning |
|---|---|
| `["voice"]` | Numbers are allocated for voice use only. |
| `["sms"]` | Numbers are allocated for SMS use only. |
| `["sms", "voice"]` | Numbers are allocated for both channels. |
| *(omitted)* | No channel restriction; allocation is channel-agnostic. |

This design keeps number ownership and campaign intent cleanly separated, avoiding schema proliferation and making it easy to reuse the same number credential across multiple campaigns or channels over time.

### Optional fields

| Field | Type | Purpose |
|---|---|---|
| `channel` | array of `"sms"` / `"voice"` | Restricts the credential to specific channels. Omit for channel-agnostic allocation. |
| `startDate` | ISO-8601 datetime | Earliest date from which the allocation is valid. Useful for proving long-term continuous ownership. |
| `endDate` | ISO-8601 datetime | Expiry date of the allocation. If absent, the allocation is open-ended and governed solely by credential revocation. |

### Edge structure

The `e` (edges) block is optional to accommodate **regulators** who originate numbers directly and have no parent issuer. When present, the edges block may contain:

| Edge | Required in block? | Purpose |
|---|---|---|
| `tnalloc` | No | Chain to a parent Telephone Number Allocation Credential, proving sub-allocation authority all the way back to the regulator. |
| `issuer` | No | Links to an identity credential (e.g., OVC Org Identity, vLEI) that proves who the issuer is. Intentionally generic — does not constrain the schema of the identity credential. |

### Rules and governance

The `r` (rules) block must contain:

- **`noSharing`** — The credential holder agrees not to share or lend the allocated numbers to other parties in a way that would obscure traffic origin. This rule exists because phone numbers are the accountability anchor for calls and messages: if a number is informally lent, regulators and recipients lose the ability to trace bad traffic back to a responsible party.
- **`governance`** — A statement identifying the governance framework under which this credential was issued. Issuers must populate this field with the URI of their applicable governance document.

The act of issuing or accepting this credential constitutes binding acceptance of these rules.
Loading