Neat job.
Question you might know the answer to: I've noticed it's a pretty common practice to get appointment reminders with caller ID from the doctor's office. I like that feature. I'd imagine there are plenty of other legitimate use cases for caller ID spoofing as well. Do you have any idea how that's going to work with STIR/SHAKEN?
I'd guess it's going to be some kind of oauth for your phone number, where you own it and can grant spoofing access to other entities?
Google seems to be supporting it: https://ecfsapi.fcc.gov/file/1119583115056/2018-11-19%20Goog... (via https://www.fcc.gov/call-authentication)