Methods, systems, and computer-readable media for routing of packets for lawful interception
Patent Information
- Application Number
- CN202180067083.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-08-29
- Filing Date
- 2021-02-26
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2041-02-26
Smart Images

Figure CN116325659B_ABST
Abstract
Description
[0001] Priority Statement
[0002] This application claims priority to U.S. Patent Application Serial No. 17 / 006,800, filed August 29, 2020, the disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0003] The topics described herein relate to methods and systems for routing packets for lawful interception (LI). More specifically, the topics described herein relate to methods, systems, and computer-readable media for routing packets for LI in centralized networks. Background Technology
[0004] Some telecommunications network operators deploy centralized networks to provide session-based IP communication services (voice or multimedia) to users from multiple countries. These networks can use Session Border Controllers (SBCs) to provide services to residential and / or enterprise customers. SBCs are typically located between two service provider networks (i.e., interconnect / peer SBCs) or between an access network and a backbone network (i.e., access SBCs). These SBCs are often deployed at the boundary between two VoIP networks, making them a good location for implementing legitimate snooping solutions.
[0005] Enabling lawful eavesdropping in a centralized network may require providing an authorization order (legally permitted eavesdropping targets and associated rules) to an access session border controller deployed outside the relevant country. In some countries, regulations prohibit this practice because the authorization order is considered sensitive information.
[0006] Therefore, there is a need for methods, systems, and computer-readable media for routing packets in a centralized network (LI). Summary of the Invention
[0007] Methods, systems, and computer-readable media for routing packets used for lawful interception. In one aspect, a system includes at least one Session Border Controller (SBC), wherein the at least one SBC is configured to forward multiple media streams to a forwarding function. The system includes a forwarding function implemented on a centralized node in a telecommunications network, the centralized node including one or more processors. The forwarding function is configured to receive multiple media streams and forward each media stream to a corresponding lawful interception intermediary server in at least one country associated with that media stream.
[0008] The forwarding function is configured to, in response to receiving a first packet of a first media stream from the at least one SBC, perform a destination lookup for the first media stream and send an intermediary server identifier of the first media stream to the at least one SBC. The at least one SBC is configured to store the intermediary server identifier and send it along with each of a plurality of subsequent packets of the first media stream to the forwarding function.
[0009] In some examples, the forwarding function is configured to, in response to receiving subsequent packets, route each subsequent packet in the subsequent packets to a first legitimate listening intermediary server identified by the intermediary server identifier. The at least one SBC may be configured to send a first associated identifier of the first media stream along with the first packets and subsequent packets of the first media stream.
[0010] The forwarding function can be configured to associate a first relevant identifier of a first media stream with an intermediary server identifier in a mapping of relevant identifiers to legitimate listening intermediary servers. The forwarding function can also be configured to, in response to receiving a second packet that includes a second relevant identifier but lacks an intermediary server identifier, route the second packet to a second legitimate listening intermediary server associated with the second relevant identifier in the mapping of relevant identifiers.
[0011] In some examples, the first packet of the first media stream is a signaling packet establishing the first media stream, and each subsequent packet in the subsequent packets is a media packet. Typically, subsequent packets can be either signaling packets or media packets. In some examples, the at least one SBC is an access SBC configured to provide access to a telecommunications service provider's access network.
[0012] In another aspect, a system includes at least one Session Border Controller (SBC), wherein the at least one SBC is configured to forward multiple media streams to a forwarding function. The system includes a forwarding function implemented on a centralized node in a telecommunications network, the centralized node comprising one or more processors. The forwarding function is configured to receive multiple media streams and forward each media stream to a corresponding legitimate eavesdropping intermediary server in at least one country associated with that media stream.
[0013] The at least one SBC is configured to send a first associated identifier of the first media stream along with a first packet and a plurality of subsequent packets of the first media stream.
[0014] The forwarding function is configured to, in response to receiving a first packet, perform a destination lookup for the first media stream and associate a first relevant identifier of the first media stream with an intermediary server identifier in a mapping of relevant identifiers to legitimate listening intermediary servers. The at least one SBC is configured to, in response to determining that the first media stream is terminating, send a second packet of the first media stream with a session release indicator to the forwarding function.
[0015] In some examples, the forwarding function is configured to receive a session release indicator and, in response to receiving the session release indicator, remove the association between the first relevant identifier of the first media stream and the intermediary server identifier in the mapping of relevant identifiers to legitimate listening intermediary servers.
[0016] The forwarding function can be configured to, in response to receiving a subsequent packet, route each subsequent packet in the subsequent packet to the first legitimate listening intermediary server identified by the intermediary server identifier.
[0017] The forwarding function can be configured to, in response to receiving a second packet that includes a second relevant identifier but lacks an intermediary server identifier, route the second packet to a second legitimate listening intermediary server associated with the second relevant identifier in the mapping of relevant identifiers.
[0018] In some examples, the first packet of the first media stream is a signaling packet establishing the first media stream, and each subsequent packet in the subsequent packets is a media packet. In some examples, the at least one SBC is an access SBC configured to provide access to a telecommunications service provider's access network.
[0019] In another aspect, a system includes at least one Session Border Controller (SBC), wherein the at least one SBC is configured to forward multiple media streams to a forwarding function. The system includes a forwarding function implemented on a centralized node in a telecommunications network, the centralized node comprising one or more processors. The forwarding function is configured to receive multiple media streams and forward each media stream to a corresponding legitimate eavesdropping intermediary server in at least one country associated with that media stream.
[0020] The at least one SBC is configured to send a first direction indicator along with a first packet of the first media stream to the forwarding function. The first direction indicator specifies whether the first packet is an inbound initiation request or an outbound initiation request. The forwarding function is configured to perform a destination lookup for the first media stream using the first direction indicator in response to receiving the first packet.
[0021] In some examples, the forwarding function is configured to perform destination lookup using the originating user identity of the first packet in response to determining that a first direction indicator specifies an inbound initial request. The forwarding function can also be configured to perform destination lookup using the terminating user identity of the first packet in response to determining that a first direction indicator specifies an outbound initial request.
[0022] The at least one SBC can be configured to send a first associated identifier of the first media stream along with a first packet and a plurality of subsequent packets of the first media stream.
[0023] The forwarding function can be configured to, in response to receiving a first packet, associate a first relevant identifier of the first media stream with an intermediary server identifier in a mapping of relevant identifiers to legitimate listening intermediary servers. The forwarding function is also configured to, in response to receiving subsequent packets, route each subsequent packet in the subsequent packets to a first legitimate listening intermediary server identified by the intermediary server identifier, using the intermediary server identifier.
[0024] In some examples, the first packet of the first media stream is a signaling packet that establishes the first media stream, and each subsequent packet in the subsequent packets is a media packet. Typically, subsequent packets can be either signaling packets or media packets.
[0025] The subjects described herein can be implemented using software in combination with hardware and / or firmware. For example, the subjects described herein can be implemented using software executed by a processor. In one example implementation, the subjects described herein can be implemented using a computer-readable medium having computer-executable instructions stored thereon, which, when executed by the computer's processor, control the computer to perform steps.
[0026] Example computer-readable media suitable for implementing the topics described herein include non-transitory devices such as disk storage devices, chip memory devices, programmable logic devices, and application-specific integrated circuits. Furthermore, computer-readable media implementing the topics described herein may reside on a single device or computing platform, or may be distributed across multiple devices or computing platforms. Attached Figure Description
[0027] Figure 1 This is a block diagram of an example network environment used for routing packets for lawful eavesdropping;
[0028] Figure 2 This is a block diagram of a sample network environment used to establish a legitimate listening environment for a sample call;
[0029] Figure 3 This is a block diagram illustrating an example packet sent in response to a legitimate interception packet forwarding example; and
[0030] Figure 4 This is a flowchart of an example method for routing legitimate listening packets in the example forwarding function. Detailed Implementation
[0031] Telecommunications network equipment providers can enhance network nodes (e.g., SBCs) to replicate signaling (e.g., SIP) and media (e.g., RTP, MSRP) traffic passing through them to LI intermediary servers (hereinafter referred to as LI-MS) deployed in the respective countries (i.e., the countries of the originating / calling and terminating / called users). This allows authorization orders to remain within the network of each country, thus enabling them to be easily controlled and managed locally by the law enforcement agencies (LEAs) of each country.
[0032] The module / function responsible for forwarding these packets to the LI-MS in each country is referred to below as the forwarding function (FF). The FF typically needs to provide destination and routing lookup rules in order to determine the destination country (and its LI-MS) based on the originating / terminating user identity from the signaling packet.
[0033] Centralized networks typically consist of hundreds of access / interconnection SBCs (which can be called replica nodes or RNs) and can meet the needs of dozens of countries. Implementing FF on RNs would require configuring and maintaining routing rules on all of these nodes, in addition to managing an excessive number of connections.
[0034] Therefore, it may be useful to deploy a separate and dedicated network node (centralized FF), which terminates packets from all replica nodes and forwards them to the LI-MS of the corresponding country, even if this means additional traffic between the RN and the FF.
[0035] In this method, the RN embeds raw signaling packets and media packets into the outer packets sent to the FF. The FF then performs a destination lookup for each session and forwards all packets in that session to the LI-MS. This RN-FF interface can use any proprietary or standard protocol, such as Diameter, SIP, or IPFIX (Internet Protocol Stream Information Export).
[0036] Typically, there is a single connection / stream (one for signaling and one for media) from each RN to the FF, carrying all replicated signaling packets and media packets from multiple connections / streams on that RN.
[0037] In a centralized FF approach, a challenge is to correlate signaling and media flows on the FF for all traffic originating from all RNs. This correlation is necessary because media packets typically lack the information needed for destination lookup. They must be routed to the LI-MS previously determined for signaling packets that established the session to which these media packets belong.
[0038] The FF can be configured to process embedded signaling packets and also maintains information about all replicated signaling and media streams, thus enabling them to correlate. In some examples, the FF can also send the associated ID along with each signaling and media packet from the RN to the FF.
[0039] In some examples, the RN (e.g., SBC) stores the correlation, so the additional overhead of sending this information can be minimal. The correlation ID, along with the RN identity, can uniquely identify the replicated stream on the FF.
[0040] This allows the FF to create and maintain an association / mapping between a relevant ID (uniquely identifying a specific flow / session) and the destination route for the corresponding LI-MS. This mapping is created when the first signaling packet for a new session arrives at the FF.
[0041] While this approach allows FF to avoid parsing all packets in a session and performing destination lookups, it still requires FF to perform lookups in the relevant ID → LI-MS mapping. This could be a mapping per RN, or a global mapping if the relevant ID is globally unique across all RNs. Because FF needs to handle traffic from hundreds of RNs, each hosting millions of subscribers, it can easily become a bottleneck.
[0042] The system described in this specification can be improved using one or more of the following three features:
[0043] 1) Improved forwarding logic at FF
[0044] This feature is achieved through the following:
[0045] - After performing a destination lookup on the first group of the new dialogue, the LI-MS identifier (MS-ID) is sent from the FF back to the RN; and
[0046] - Store the MS-ID at the replication node or access SBC (A-SBC) and send it along with the associated ID to the FF in each subsequent packet of the session.
[0047] Upon packet arrival, the FF will look for the MS-ID in the external packet (e.g., IPFIX). If it exists, the packet can be forwarded directly to the relevant LI-MS without performing a related ID lookup or resolving the embedded packet. Any packet arriving at the FF without an MS-ID can fall back to a related ID lookup.
[0048] 2) Improved cleanup of related ID→MS-ID mappings
[0049] FFs are typically configured to determine conversation termination (e.g., SIP BYE / CANCEL) so that the associated ID→MS-ID association / mapping can be removed. This could potentially require parsing all signaling packets, which would be an additional overhead for FFs that have to handle millions of packets / second from all RNs.
[0050] This burden is mitigated by sending a "session release" flag as additional metadata along with each packet from the RN to the FF. The RN already tracks the sessions, making this information available when packets are copied to the FF. The FF then only needs to monitor this flag in external packets instead of parsing each "embedded" signaling packet, saving significant CPU cycles.
[0051] 3) Prevent unnecessary copying when the originating user and the receiving user are from different countries.
[0052] Some network nodes (e.g., SBCs) maintain two separate branches for each session: one with the client and another with the server. These conversations are also known as client-server conversations.
[0053] In the case of call forking, there may be more than one conversation with the server. Packets expected to reach these SBCs (or any other proxy nodes) are sometimes modified before they are sent to the other side. Therefore, it is useful to copy packets separately from all conversations in the session.
[0054] In a centralized LI architecture, if the originating and terminating users of a session are from different countries, the originating country will be interested in packets from or destined for its users and will preferably not accept packets destined for or from the terminating user.
[0055] The features described in this section enable the FF to selectively look up and determine the MS-ID for different conversations within the same session by having the RN also send a "direction" flag to the FF. The "direction (ingress / egress)" flag for signaling packets establishing a new conversation (e.g., SIP INVITE) helps the FF determine whether the packet belongs to an inbound or outbound branch of the call at the RN, and accordingly uses the calling or called user identity (e.g., SIP FROM / TO header) for destination lookup.
[0056] In this way, FF associates different countries (or MS-IDs) with different conversations within the same session, thus replicating only packets from the relevant conversation to the LI-MS in each country. FF can still prevent unwanted replication in the absence of this flag, but only if both the originating and ending users belong to the same country. The proposed flag helps achieve this even when users are from different countries.
[0057] Figure 1 This is a block diagram of an example network environment 100 for routing packets used for lawful eavesdropping. Network environment 100 includes a centralized telecommunications network 102 providing telecommunications services to several different networks 104, 106, and 108 in different countries. The centralized telecommunications network 102 includes several Session Border Controllers (SBCs) 110 and forwarding functions 112. The forwarding functions 112 are implemented on centralized computing nodes having one or more processors.
[0058] Typically, an SBC is a system of one or more computers that is appropriately programmed to control signaling and media streams used to establish, conduct, and terminate telephone calls and other types of media communications. For example, an SBC can control Voice over Internet Protocol (VoIP) calls.
[0059] In some cases, SBCs can be deployed at the boundary between two service provider networks in a peer-to-peer environment, or between a service provider’s access network and backbone network, to provide services to the service provider’s customers.
[0060] SBC 110 is configured to forward media streams (e.g., voice and video calls, and other types of media) to forwarding function 112. Forwarding function 112 is configured to receive media streams and forward each media stream to a corresponding legitimate listening intermediary server (one of servers 114, 116, and 118) in at least one country associated with that media stream. In some examples, forwarding function 112 is implemented as an enhanced SBC.
[0061] The centralized telecommunications network 102 can be configured to implement one, two, or all three of the above characteristics as follows:
[0062] 1. Improved forwarding function: forwarding logic at position 112
[0063] In some examples, forwarding function 112 is configured to, in response to receiving a first packet of a first media stream from one of SBCs 110, perform a destination lookup for the first media stream and send an intermediary server identifier of the first media stream to that SBC. The SBC is configured to store the intermediary server identifier and send it along with each subsequent packet of the first media stream to forwarding function 112.
[0064] In some examples, forwarding function 112 is configured to, in response to receiving a subsequent packet, route each subsequent packet in the subsequent packets to a first legitimate listening intermediary server identified by the intermediary server identifier, using the intermediary server identifier. The SBC can be configured to send a first relevant identifier of the first media stream along with the first packet and subsequent packets of the first media stream. The forwarding function can be configured to associate the first relevant identifier of the first media stream with the intermediary server identifier in a mapping of relevant identifiers to legitimate listening intermediary servers. Forwarding function 112 can be configured to, in response to receiving a second packet that includes a second relevant identifier but lacks an intermediary server identifier, route the second packet to a second legitimate listening intermediary server associated with the second relevant identifier in the mapping of relevant identifiers, using the mapping of relevant identifiers.
[0065] 2. Improved cleanup of related ID→MS-ID mappings
[0066] In some examples, one of the SBCs 110 is configured to send a first associated identifier of the first media stream along with a first packet and several subsequent packets. The forwarding function 112 is configured, in response to receiving the first packet, to perform a destination lookup for the first media stream and associate the first associated identifier of the first media stream with an intermediary server identifier in a mapping of associated identifiers to legitimate listening intermediary servers. The SBC is configured, in response to determining that the first media stream is terminated, to send a second packet of the first media stream with a session release indicator to the forwarding function.
[0067] In some examples, forwarding function 112 is configured to receive a session release indicator and, in response to receiving the session release indicator, remove the association between the first relevant identifier of the first media stream and the intermediary server identifier in the mapping of relevant identifiers to legitimate listening intermediary servers. Forwarding function 112 may be configured to, in response to receiving subsequent packets, route each subsequent packet in the subsequent packets to the first legitimate listening intermediary server identified by the intermediary server identifier using the intermediary server identifier.
[0068] Forwarding function 112 can be configured to, in response to receiving a second packet that includes a second relevant identifier but lacks an intermediary server identifier, route the second packet to a second legitimate listening intermediary server associated with the second relevant identifier in the mapping of relevant identifiers. This could happen, for example, if the second packet is part of the same flow but lacks an intermediary server identifier due to an error. In some examples, the second packet is part of a new flow (e.g., the second packet is the initiating packet of a new flow), and forwarding function 112 will not be able to route the second packet using the mapping of relevant identifiers; instead, forwarding function 112 will perform a destination lookup and create a new association for the new flow in the mapping.
[0069] 3. Prevent unnecessary copying when the originating user and the receiving user are from different countries.
[0070] In some examples, one of the SBCs 110 is configured to send a first direction indicator along with a first packet of the first media stream to the forwarding function 112. The first direction indicator specifies whether the first packet is an inbound initiation request or an outbound initiation request. The forwarding function 112 is configured to perform a destination lookup for the first media stream using the first direction indicator in response to receiving the first packet.
[0071] In some examples, forwarding function 112 is configured to perform destination lookup using the originating user identity of the first packet in response to determining that a first direction indicator specifies an inbound initiation request. Forwarding function 112 may also be configured to perform destination lookup using the terminating user identity of the first packet in response to determining that a first direction indicator specifies an outbound initiation request.
[0072] The SBC can be configured to send a first associated identifier of the first media stream along with a first packet and multiple subsequent packets. Forwarding function 112 can be configured, in response to receiving the first packet, to associate the first associated identifier of the first media stream with an intermediary server identifier in a mapping of associated identifiers to legitimate listening intermediary servers. Forwarding function 112 is configured, in response to receiving subsequent packets, to route each subsequent packet in the subsequent packets to a first legitimate listening intermediary server identified by the intermediary server identifier, using the intermediary server identifier.
[0073] In some examples, forwarding functionality 112 is implemented on the SBC platform or system. The SBC, acting as a centralized forwarding function, is configured to route signaling packets and media packets to the lawful listening intermediary server.
[0074] Signaling packets will be routed based on the routing rules / policies configured at forwarding function 112. These lookups can be performed at the host application. In some cases, as further described in this specification, only the first signaling packet of a new session will be routed based on the policy lookup at the host. All subsequent signaling packets should also be routed as further described below.
[0075] • Configure the module to implement this function on the SBC
[0076] – This module should be IPFIX-aware, as it will receive / send IPFIX packets.
[0077] – This module needs to be SIP-aware because it needs to decode the SIP header from the SIP packet embedded within the IPFIX packet and then perform the lookup.
[0078] It will also manage session mappings at the platform to allow routing of subsequent signaling packets and / or media packets via fast paths.
[0079] Routing rules should specify
[0080] – Extract the SIP header name from it (e.g., From, To, Referred-By, Refer-To, R-URI, Diversion header).
[0081] - Number prefix used for lookup
[0082] – as the destination of the next hop ME
[0083] • In some examples, routing will be based on the CGPN of inbound packets (i.e., packets arriving at the A-SBC) and the CDPN of outbound packets (i.e., packets leaving the A-SBC).
[0084] Figure 2 This is a block diagram of a sample network environment 200 used to establish a legitimate listening for a sample call.
[0085] like Figure 2 As shown, a first user equipment 202 (“UA A”) in country A initiates a call to a second user equipment 206 (“UA B”) in country B via access SBC 204 (A-SBC). Messages flowing to country A are marked as “West”, while messages flowing to country B are marked as “East”.
[0086] SBC 204 forwards packets in the media stream of the call to centralized forwarding function 208. Forwarding function 208 forwards packets sent by user equipment 202 to lawful interception intermediary server 210 of country A (“ME A”), and forwarding function 208 forwards packets sent to user equipment 206 to lawful interception intermediary server 212 of country B (“ME B”). Although Figure 2 The example shows a grouping to the east, but the system can perform similar operations for a grouping to the west, or in general, for a grouping in any other direction.
[0087] Figure 2 The example shown describes the actions performed at SBC 204 and forwarding function 208 for Session Initiation Protocol (SIP) and Message Session Relay Protocol (MSRP).
[0088] In the first step, user equipment 202 sends invitation 1A to SBC 204. SBC 204 performs the following actions:
[0089] ■ Add a unique, relevant ID (e.g., randomly generated) to the IPFIX packet and send it as an IPFIX (Invitation 1A) to the forwarding function 208.
[0090] ■ When creating a media stream, the system will add a relevant ID and an "entry" direction indicator.
[0091] In the second step, the forwarding function 208 performs the following actions:
[0092] ■ Route lookup based on the "FROM" header (because the direction indicator is inbound), and find the destination flow.
[0093] ■ Add relevant ID (from IPFIX) → Mapping of destination flow
[0094] ■ Use the relevant ID → New mapping for the destination stream to update the media stream (corresponding to the ASBC configuration)
[0095] In the third step, SBC 204 sends Invitation 1B to User Equipment 206 and IPFIX (Invitation 1B) to Forwarding Function 208. SBC 204 performs the following actions:
[0096] • Add a unique, relevant ID and an "outbound" flag to the IPFIX packet and send it to FF
[0097] In the fourth step, forwarding function 208 performs the following actions:
[0098] ■ Find and locate the destination stream based on the "TO" header
[0099] ■ Add relevant ID (from IPFIX) → Mapping of destination flow
[0100] ■ Use the relevant ID → New mapping for the destination stream to update the media stream (corresponding to the ASBC configuration)
[0101] In the fifth step, user equipment 202 sends MSRP E-1A to SBC 204, and SBC 204 sends MSRP E-1B to user equipment 206. SBC 204 performs the following actions:
[0102] ■SBC 204 adds the relevant ID to the IPFIX packet and sends it to FF
[0103] In the sixth step, SBC 204 sends IPFIX (MSRP E-1A) and IPFIX (MSRP E-1B) to forwarding function 208. Forwarding function 208 performs the following actions:
[0104] • Determine the destination flow based on the relevant ID in IPFIX.
[0105] In the seventh step, user equipment 206 sends MSRP W-1B to SBC 204, and SBC 204 sends MSRP W-1A to user equipment 202. SBC 204 performs the following actions:
[0106] The system will add the relevant ID to the IPFIX packet and send it to FF.
[0107] In step eight, SBC 204 sends IPFIX (MSRP W-1A) and IPFIX (MSRP W-1B) to forwarding function 208. Forwarding function 208 performs the following actions:
[0108] • Determine the destination flow based on the relevant ID in IPFIX.
[0109] Figure 3 This is a block diagram illustrating an example packet sent in response to a legitimate interception packet forwarding 300.
[0110] like Figure 3 As shown, access SBC 302 forwards the first packet 304 and subsequent packets 306 to forwarding function 308. Forwarding function 308 forwards packets 304 and 306 to legitimate eavesdropping intermediary server 314 by sending modified packets 310 and 312.
[0111] Packet 304 is an IPFIX packet, specifically a SIP packet transmitted via Transmission Control Protocol (TCP). Packet 304 includes an IPFIX header and IPv4 data. It also includes an associated ID, direction flag, and session release flag. Packet 304 contains a SIP message.
[0112] Packet 306 is an IPFIX packet, specifically an MSRP packet over TCP. Packet 306 includes an IPFIX header and IPv4 data. Packet 306 includes a mediator server identifier, which is stored at SBC 302 after the destination lookup is performed on packet 304 by forwarding function 308. Packet 306 includes an MSRP message.
[0113] When forwarding function 308 receives packet 304 from SBC 302, it performs a destination lookup to determine that legitimate listening intermediary server 314 is the destination of packet 304 and subsequent packets (such as packet 306) belonging to the same media stream as packet 304. Forwarding function 308 stores the association between the relevant ID and the intermediary server identifier of legitimate listening intermediary server 314 in a mapping from relevant identifier to legitimate listening intermediary server. Forwarding function 308 also sends the intermediary server identifier to SBC 302.
[0114] Forwarding function 308 generates packet 310 based on packet 304 and sends packet 310 to the legitimate listening intermediary server 314. Packet 310 is an IPFIX packet (SIP over TCP). Packet 310 includes the IPFIX header, IPv4 data, and SIP message of packet 304. Packet 310 lacks the associated ID, direction flag, and session release flag of packet 304.
[0115] When forwarding function 308 receives packet 306 from SBC 302, forwarding function 308 can avoid checking the mapping of the relevant identifier to the legitimate listening intermediary server. Instead, forwarding function 308 uses the intermediary server identifier in packet 306 to route packet 306.
[0116] Forwarding function 308 generates packet 312 based on packet 306 and sends packet 312 to the legitimate listening intermediary server 314. Packet 312 is an IPFIX packet (via TCP MSRP). Packet 312 includes the IPFIX header, IPv4 data, and MSRP message of packet 306. Packet 312 lacks the intermediary server identifier of packet 306.
[0117] In some examples, newly configured IDs and templates are used to implement the features described in this specification. For example, a common template can be used to replicate both inbound and outbound signaling packets at SBC 302.
[0118] • Directional signs should indicate whether this is an entering or exiting group.
[0119] The forwarding function 308 should use this flag to determine which SIP header (for the calling or called number) it must use for routing lookup.
[0120] • The “Session Release” flag should indicate whether session cleanup is required on the FF.
[0121] Similarly, a common template can be used to copy both inbound and outbound media packets at SBC 302. MSRP media IPFIX packets do not require a direction flag because the forwarding function will use the identified relevance to determine the destination legitimate listening intermediary server; it will also not require a session release flag.
[0122] To facilitate session cleanup at forwarding function 308, when forwarding function 308 receives an IPFIX packet with the “session release” flag set, forwarding function 308 should clear / erase saved session information (e.g., related ID → destination flow mapping).
[0123] In some examples, there is also a timer implemented at forwarding function 308 to clean up the session at forwarding function 308, thereby handling the situation where an IPFIX packet with the “session release” flag set is dropped for some reason.
[0124] This can also happen if A-SBC restarts in the middle of a session.
[0125] - The timer should be canceled / stopped upon receiving an IPFIX packet with the "session release" flag set.
[0126] Regarding the associated ID, a unique associated (or replicated) ID can be sent from SBC 302 to forwarding function 308. This will uniquely identify each conversation on SBC 302 or even forwarding function 308 (e.g., if the ID also includes the A-SBC hostname).
[0127] This is per dialogue rather than per session to handle forked scenarios, where multiple client dialogues can exist, and each client dialogue is replicated to ME in different countries.
[0128] There are several options for generating this ID at SBC 302:
[0129] – Option 1: Using media-specific information from the group
[0130] This requires a separate method for each media type, and it can be cumbersome to implement.
[0131] – For offer-less INVITE, this requires parsing each signaling packet until no media information is received.
[0132] – Option 2: Use a media stream identifier. Sometimes, this might not be a reasonable solution because...
[0133] - Media stream identifiers cannot be used without an offer invitation.
[0134] Following an A-SBC switch, the (locally generated) media stream identifiers will change for the same session. Therefore, they will need to be copied.
[0135] When A-SBC is deployed in standalone mode, a mechanism needs to be built to ensure that the same ID is not used across different sessions that have been restarted.
[0136] – Option 3: Use a randomly generated unique replication ID.
[0137] – It will be unique across all A-SBCs and will also work in no-offer invitation scenarios.
[0138] Figure 4 This is a flowchart of example method 400 for routing legitimate listening packets in the example forwarding function.
[0139] Method 400 illustrates the forwarding logic at the improved forwarding function, which is implemented as follows:
[0140] - After performing a destination lookup for the first packet of a new media stream, the LI-MS identifier (MS-ID) is sent back to the SBC from the forwarding function; and
[0141] - Store the MS-ID at A-SBC and send it along with the associated ID to the forwarding function in each subsequent packet of the media stream.
[0142] Upon packet arrival, the forwarding function searches for the MS-ID in the external packet (e.g., IPFIX). If it exists, the packet can be forwarded directly to the relevant LI-MS without requiring a related ID lookup or parsing of the embedded packet. Any packet arriving at the forwarding function without an MS-ID can fall back to a related ID lookup.
[0143] Method 400 includes parsing the packet (402) and determining whether a destination identifier (e.g., an MS-ID mentioned elsewhere in this specification) exists in the packet (404). If a destination identifier exists, method 400 includes forwarding the packet to a legitimate listening intermediary server identified by the destination identifier (410).
[0144] If no destination identifier is found, method 400 includes checking the mapping of the relevant identifier to a legitimate listening intermediary server for the entry of the relevant identifier in the packet (406). If a match is found in the mapping of the relevant identifier to a legitimate listening intermediary server, method 400 includes forwarding the packet to the legitimate listening intermediary server identified in the entry of the relevant identifier in the packet.
[0145] If no match is found, method 400 includes determining whether the packet is a signaling packet (e.g., whether the packet is a SIP packet) (412). If the packet is not a signaling packet, method 400 includes discarding the packet (414). If the packet is a signaling packet, method 400 includes obtaining the originating user identity and the terminating user identity of the packet from the packet (416).
[0146] Method 400 includes performing a destination lookup in a destination table using one of the user identities as a key (418). The destination table specifies legitimate listening intermediary servers in different countries. Method 400 includes determining whether a destination legitimate listening intermediary server has been found (420).
[0147] If a destination legitimate listening intermediary server is found, method 400 includes creating an association between the relevant identifier of the packet and the destination legitimate listening intermediary server in the mapping of relevant identifier to legitimate listening intermediary server (422), sending the intermediary server identifier identifying the destination legitimate listening intermediary server to the SBC (424), and forwarding the packet to the destination legitimate listening intermediary server (410).
[0148] If no legitimate intermediary server for the destination is found, method 400 includes dropping packets 414.
[0149] Although specific examples and features have been described above, these examples and features are not intended to limit the scope of this disclosure, even if only a single example has been described with respect to a particular feature. Unless otherwise stated, the examples of features provided in this disclosure are intended to be illustrative and not restrictive. The foregoing description is intended to cover such alternatives, modifications, and equivalents that will be apparent to those skilled in the art as to benefit from this disclosure.
[0150] The scope of this disclosure includes any feature or combination of features disclosed (expressly or implicitly) in this specification, or any generalization of the disclosed features, whether or not such features or generalizations alleviate any or all of the problems described in this specification. Therefore, during the execution of this application (or an application claiming priority to this application), new claims may be made for any such combination of features.
[0151] In particular, referring to the appended claims, features from dependent claims may be combined with features from independent claims, and features from each independent claim may be combined in any suitable manner, not just in the specific combinations listed in the appended claims.
Claims
1. A system for routing packets for lawful eavesdropping, the system comprising: At least one session boundary controller (SBC), wherein at least one SBC is configured to forward multiple media streams to a forwarding function; and A forwarding function implemented on a centralized node in a telecommunications network, the centralized node including one or more processors, wherein the forwarding function is configured to receive the plurality of media streams and forward each media stream to a corresponding legitimate listening intermediary server in at least one country associated with the media stream. The forwarding function is configured to, in response to receiving a first packet of a first media stream from the at least one SBC, perform a destination lookup on the first media stream and send an intermediary server identifier of the first media stream to the at least one SBC, wherein the intermediary server identifier identifies a first legitimate listening intermediary server found by the destination lookup. and The at least one SBC is configured to store an intermediary server identifier and send the intermediary server identifier along with each of the plurality of subsequent packets of the first media stream to the forwarding function.
2. The system of claim 1, wherein the forwarding function is configured to, in response to receiving a subsequent packet, route each subsequent packet in the subsequent packets to a first legitimate listening intermediary server identified by the intermediary server identifier using an intermediary server identifier.
3. The system of claim 1 or 2, wherein the at least one SBC is configured to send a first associated identifier of the first media stream together with a first packet and subsequent packets of the first media stream.
4. The system of claim 3, wherein the forwarding function is configured to associate a first relevant identifier of the first media stream with an intermediary server identifier in a mapping from relevant identifier to a legitimate listening intermediary server.
5. The system of claim 4, wherein the forwarding function is configured to, in response to receiving a second packet including a second relevant identifier and lacking an intermediary server identifier, route the second packet to a second legitimate eavesdropping intermediary server associated with the second relevant identifier in the mapping of relevant identifiers.
6. The system according to any one of the preceding claims, wherein the first packet of the first media stream is a signaling packet for establishing the first media stream, and wherein each subsequent packet in the subsequent packets is a media packet.
7. The system according to any one of the preceding claims, wherein the at least one SBC is an access SBC configured to provide access to a telecommunications service provider access network.
8. A system for routing packets for lawful eavesdropping, the system comprising: At least one session boundary controller (SBC), wherein at least one SBC is configured to forward multiple media streams to a forwarding function; and A forwarding function implemented on a centralized node in a telecommunications network, the centralized node including one or more processors, wherein the forwarding function is configured to receive the plurality of media streams and forward each media stream to a corresponding legitimate listening intermediary server in at least one country associated with the media stream. The at least one SBC is configured to send a first associated identifier of the first media stream along with a first packet and a plurality of subsequent packets of the first media stream; The forwarding function is configured to, in response to receiving a first packet, perform a destination lookup on the first media stream, associate a first relevant identifier of the first media stream with an intermediary server identifier in a mapping of relevant identifiers to legitimate listening intermediary servers, and send the intermediary server identifier of the first media stream to the at least one SBC, wherein the intermediary server identifier identifies the first legitimate listening intermediary server found by the destination lookup. and The at least one SBC is configured to send a second packet of the first media stream with a session release indicator to the forwarding function in response to determining that the first media stream is terminated.
9. The system of claim 8, wherein the forwarding function is configured to receive a session release indicator and, in response to receiving the session release indicator, remove the association between the first relevant identifier of the first media stream and the intermediary server identifier in the mapping of relevant identifiers to legitimate listening intermediary servers.
10. The system of claim 8 or 9, wherein the forwarding function is configured to, in response to receiving a subsequent packet, route each subsequent packet in the subsequent packets to a first legitimate listening intermediary server identified by the intermediary server identifier using an intermediary server identifier.
11. The system according to any one of claims 8-10, wherein the forwarding function is configured to, in response to receiving a second packet including a second relevant identifier and lacking an intermediary server identifier, route the second packet to a second legitimate listening intermediary server associated with the second relevant identifier in the mapping of relevant identifiers.
12. The system according to any one of claims 8-11, wherein the first packet of the first media stream is a signaling packet for establishing the first media stream, and wherein each subsequent packet in the subsequent packets is a media packet.
13. The system according to any one of claims 8-12, wherein the at least one SBC is an access SBC configured to provide access to a telecommunications service provider access network.
14. A system for routing packets for lawful eavesdropping, the system comprising: At least one session boundary controller (SBC), wherein at least one SBC is configured to forward multiple media streams to a forwarding function; and A forwarding function implemented on a centralized node in a telecommunications network, the centralized node including one or more processors, wherein the forwarding function is configured to receive the plurality of media streams and forward each media stream to a corresponding legitimate listening intermediary server in at least one country associated with the media stream. The at least one SBC is configured to send a first direction indicator along with a first packet of the first media stream to the forwarding function, the first direction indicator specifying whether the first packet is an inbound initial request or an outbound initial request; The forwarding function is configured to, in response to receiving a first packet, perform a destination lookup for the first media stream using a first direction indicator, and send an intermediary server identifier for the first media stream to the at least one SBC, wherein the intermediary server identifier identifies a first legitimate listening intermediary server found by the destination lookup.
15. The system of claim 14, wherein the forwarding function is configured to perform destination lookup using the originating user identity of the first packet in response to determining that a first direction indicator specifies an inbound initial request.
16. The system of claim 14, wherein the forwarding function is configured to perform destination lookup using the terminating user identity of the first packet in response to determining a first direction indicator specifying an outbound initiation request.
17. The system according to any one of claims 14-16, wherein the at least one SBC is configured to send a first associated identifier of the first media stream together with a first packet and a plurality of subsequent packets of the first media stream.
18. The system of claim 17, wherein the forwarding function is configured to, in response to receiving a first packet, associate a first relevant identifier of the first media stream with the intermediary server identifier in a mapping of relevant identifiers to legitimate listening intermediary servers.
19. The system of claim 18, wherein the forwarding function is configured to, in response to receiving a subsequent packet, route each subsequent packet in the subsequent packets to a first legitimate listening intermediary server identified by the intermediary server identifier using an intermediary server identifier.
20. The system according to any one of claims 14-19, wherein the first packet of the first media stream is a signaling packet for establishing the first media stream, and wherein each subsequent packet in the subsequent packets is a media packet.
Citation Information
Patent Citations
Integrated lawful intercept for internet protocol multimedia subsystem (IMS) over evolved packet core (EPC)
US20110141947A1