IMS data stream legal interception method and system based on GEO satellite communication
By deploying edge service nodes and dedicated network slices in GEO satellite communication environment, localized processing and interception of IMS data flow is achieved, solving the response time problem of traditional mechanisms in high-latency environments, ensuring timely capture and integrity of data.
Patent Information
- Application Number
- CN202510454508.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-06-24
AI Technical Summary
The legitimate interception mechanism of traditional IMS is difficult to adapt in GEO satellite communication environment. Due to the limitations of high latency and long link distance, the interception response time is too long and critical data cannot be captured in time.
Deploy the edge service node in the base station or ground station, supports local cache, SIP signaling pre-parsement and resource reservation, and builds a dedicated network slice dedicated to intercept data transmission. Through the edge service node, IMS call signaling is parsed and target list comparison is compared to realize signaling localization processing and data flow replication.
It greatly reduces the interception response time, meets the capture timeliness requirements of key data in a 250ms-level delay environment for voice data flow, and effectively overcomes the signal attenuation problem through dedicated network slices, ensuring the integrity of intercepted data.
Smart Images

Figure CN120201011A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of communication data interception, and particularly to a legal interception method and system for IMS data streams based on GEO satellite communication. Background Art
[0002] With the popularization of 5G and IMS (IP Multimedia Subsystem), communication based on GEO (Geostationary Earth Orbit) satellites has become a key solution for remote areas, oceans, and aviation scenarios. Due to its wide-area coverage and stable link characteristics, GEO satellites have become the preferred choice for long-distance communication. However, when supporting IMS voice services, physical limitations such as high latency (single-hop latency is about 250 ms), long link distance (about 36,000 kilometers), and link loss make it difficult for traditional legal interception mechanisms to be directly adapted.
[0003] Specifically, traditional IMS legal interception relies on centralized processing of the core network (such as S-CSCF, P-CSCF) and requires multiple signaling round-trips. The high latency of GEO satellites significantly increases the interception response time, resulting in the inability to capture critical data (such as voice data streams) in a timely manner. For example, traditional SIP signaling needs to complete authentication and session establishment through multiple interactions via satellite links. Summary of the Invention
[0004] The object of the present invention is to provide a legal interception method and system for IMS data streams based on GEO satellite communication, which can effectively avoid the negative impact of the high latency of GEO satellites on traditional IMS interception mechanisms.
[0005] To achieve the above object, the present invention provides a legal interception method for IMS data streams based on GEO satellite communication, which includes:
[0006] Deploy an edge service node in a base station or a ground station, where the edge service node supports local caching, SIP signaling pre-parsing, and resource reservation; an interception target list is also preset in the edge service node, and the identity information of a number of users to be intercepted is recorded in the interception target list;
[0007] Build a dedicated network slice for interception data transmission on the basis of a general service slice;
[0008] Parse the IMS call signaling from a first terminal device based on the edge service node to extract the corresponding user identity information;
[0009] If the user identity information exists in the interception target list, the edge service node applies to the base station or the ground station for reserved slice resources corresponding to the dedicated network slice and reports the interception session ID to the core network;
[0010] The edge service node copies the voice data stream of the first terminal device to the specified interface according to the user policy sent by the core network, which includes the specified interface for receiving intercepted data, through the dedicated network slice.
[0011] Preferably, bandwidth resources and the highest priority are configured for the dedicated network slice.
[0012] Preferably, the user identity information in the IMS call signaling includes a subscription hidden identifier encrypted by a public key and a globally unique temporary user identifier temporarily allocated, where the subscription hidden identifier protects the subscription permanent identifier through an elliptic curve encryption algorithm, and the globally unique temporary user identifier replaces the subscription permanent identifier for signaling interaction after the session is established.
[0013] Preferably, the edge service node is deployed on the side of the proxy call session control function network element, and the edge service node executes the following two filtering policies by parsing the Via header field in the session initial protocol signaling:
[0014] Filtering policy one: Check whether the source proxy call session control function address belongs to the trusted domain name list;
[0015] Filtering policy two: Verify the consistency between the service call session control function address obtained from the CX interface and the topological information in the authentication vector of the home subscriber server.
[0016] Preferably, the intercepted voice data stream is split into multiple data packets and transmitted simultaneously through the satellite link and the base station or ground station link, and the key packets are preferentially transmitted using the low-latency path.
[0017] Preferably, during the intercepted session establishment phase, the edge service node and the policy control function in the core network cooperate to execute dynamic policy control, including: adjusting the service quality flow buffer threshold according to the satellite link round-trip delay value, and reallocating the data replication thread resources of the user plane function based on the service type priority.
[0018] Preferably, it further includes an intelligent fault recovery mechanism: when it is detected that the packet loss rate of the dedicated network slice exceeds the set threshold, the following three-phase strategy is executed in sequence:
[0019] Phase one: Send a link degradation notification to the application function through the network capability open function;
[0020] Phase two: Trigger the Xn interface handover process between the base stations or ground stations;
[0021] Phase three: Start local temporary backup of encrypted data at the multi-access edge service node.
[0022] The present invention also provides an IMS data stream legal interception system based on GEO satellite communication, and this interception system operates based on the IMS data stream legal interception method described above.
[0023] The present invention also provides an IMS data stream legal interception system based on GEO satellite communication, which specifically includes:
[0024] One or more processors;
[0025] A memory;
[0026] And one or more programs, where one or more programs are stored in the memory and are configured to be executed by the one or more processors. The programs include instructions for executing the IMS data stream legal interception method described above.
[0027] The present invention also provides a computer-readable storage medium, which includes a computer program that can be executed by a processor to complete the IMS data stream legal interception method described above.
[0028] Compared with the prior art, the IMS data stream legal interception method provided by the above technical solution of the present invention realizes signaling localization processing (such as authentication and session establishment) by deploying edge service nodes, compresses the operations that the traditional IMS core network (S-CSCF / P-CSCF) needs to make multiple satellite link round trips (about 500 ms round trip delay × N times) to a single satellite interaction, greatly reduces the interception response time, and meets the capture timeliness requirements of key data of voice data streams in an environment with a delay of about 250 ms. In addition, by using a dedicated network slice, the problem of signal attenuation caused by long-distance transmission is effectively overcome. Compared with the traditional public network slice, the dedicated slice greatly reduces the bit error rate of the satellite link and ensures the integrity of the intercepted data. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 It is a flowchart of the interception method in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] To describe in detail the technical content, structural features, achieved objectives and effects of the present invention, the following is described in detail in conjunction with the embodiments and with reference to the accompanying drawings.
[0031] This embodiment discloses an IMS data stream legal interception method based on GEO satellite communication, which is used to intercept the calls of some key users based on a legal agency (such as a national security agency), so as to monitor the calls of key users.
[0032] Such as Figure 1 , this interception method includes the following steps:
[0033] S1: Deploy an edge service node (MEC) in a base station or a ground station. The MEC supports local caching, SIP signaling pre - parsing, and resource reservation. An interception target list is also preset in the MEC, and the identity information of several users to be intercepted is recorded in the interception target list. In this embodiment and the following embodiments, the MEC is deployed in the base station as an example for illustration.
[0034] Build a dedicated network slice dedicated to intercepting data transmission on the basis of a general service slice.
[0035] S2: Based on the MEC, parse the IMS call signaling from the first terminal device to extract the corresponding user identity information.
[0036] S3: Compare the extracted user identity information with the interception target list. If the user identity information exists in the interception target list, the MEC applies to the base station for reserved slice resources corresponding to the dedicated network slice and reports the interception session ID to the core network.
[0037] S4: The MEC follows the user policy issued by the core network, which includes a specified interface for receiving intercepted data, and copies the voice data stream of the first terminal device to the specified interface through the dedicated network slice.
[0038] For the construction of the dedicated network slice, the specific method is as follows:
[0039] On the basis of a general IMS service slice (QoS level L1), create a dedicated network slice (QoS level L4). The dedicated network slice is isolated from the general IMS service slice by using hard isolation technology.
[0040] On the radio side: The dedicated network slice exclusively occupies the physical layer beam resources, configures an independent security association (SA) encrypted with AES - 256, and the key material is dynamically generated.
[0041] On the transmission side: The dedicated network slice divides an independent channel (bandwidth 125 MHz) through the FlexE interface, deploys the MTN cross - isolation technology, and the single - hop delay ≤ 10 μs.
[0042] On the core network side: The UPF (user plane function) sinks to the base station and is directly connected to the law enforcement agency's legal interception entity (LIG) through the N6 interface. The data flow is locally processed to avoid cross - domain transmission.
[0043] In addition, bandwidth resources and the highest priority can also be configured for the dedicated network slice.
[0044] Deploy the MEC inside the base station. The MEC includes:
[0045] Local cache module: Configure a certain amount of memory space to temporarily store unprocessed SIP signaling packets.
[0046] SIP Signaling Pre - parsing Engine: Developed based on the open - source oSIP library, it supports parsing basic SIP methods such as INVITE, ACK, BYE, etc.
[0047] Resource Reservation Controller: Connects to the base station resource management system through an API interface and can dynamically apply for bandwidth resources.
[0048] Specifically, within the communication range covered by a certain GEO satellite, user A (sip:user_001@ims.domain) makes an IMS voice call to user B via the GEO satellite link, and the interception process is as follows:
[0049] 1. The MEC completes SIP signaling parsing within 0.5 ms and extracts the identity information of user A.
[0050] 2. A complete match is found in the interception target list, and dedicated slice resource reservation is completed within 10 ms.
[0051] 3. The core network returns the specified interface information within 50 ms and establishes an interception session LI - 20231001 - 0001.
[0052] 4. The voice data stream is replicated and transmitted through a dedicated network slice, and the measured end - to - end delay is 78 ms (meeting the SLA requirements).
[0053] It can be seen that the above - mentioned interception method realizes local signaling processing (such as authentication and session establishment) by deploying edge service nodes, compresses the operations that the traditional IMS core network (S - CSCF / P - CSCF) needs to make multiple satellite link round - trips (about 500 ms round - trip delay × N times) to a single satellite interaction, greatly reducing the interception response time and meeting the capture timeliness requirements of key data in the voice data stream in a 250 - ms - level delay environment. In addition, by using a dedicated network slice, the problem of signal attenuation caused by long - distance transmission is effectively overcome. Compared with the traditional public network slice, the dedicated slice significantly reduces the bit error rate of the satellite link and ensures the integrity of intercepted data.
[0054] On the other hand, while IMS realizes service flexibility based on the IP protocol, the plain - text transmission between core network nodes (such as CSCF and HSS) is vulnerable to eavesdropping or tampering. Especially in the satellite backhaul link, the plain - text data is exposed to a long - distance transmission environment, increasing the risk of third - party attacks.
[0055] If a third - party attacker steals or tampers with IMS communication data, two consequences may occur:
[0056] Data tampering: The attacker forges call content or user identity, resulting in the "evidence" intercepted losing legal effect.
[0057] Data leakage: Attackers obtain sensitive information (such as user location, call records) in advance, rendering the legal interception by law enforcement agencies ineffective.
[0058] Therefore, this embodiment further improves the interception method: The user identity information in the IMS call signaling includes a subscription concealed identifier (SUCI) encrypted by a public key and a globally unique temporary user identifier (GUTI) temporarily assigned. Among them, the SUCI protects the subscription permanent identifier (SUPI) through the elliptic curve encryption algorithm, and the GUTI replaces the SUPI for signaling interaction after the session is established.
[0059] For example, in the scenario of ocean-going ships covered by GEO satellites, crew members use satellite terminals for IMS voice communication.
[0060] The attacker deploys a fake base station near the ship and broadcasts forged satellite cell signals.
[0061] When the crew terminal initiates registration, the fake base station sends an Identity Request message to attempt to obtain the SUPI.
[0062] The terminal responds with the SUCI (encrypted SUPI). Since the fake base station does not have the UDM private key, it cannot decrypt and thus cannot obtain the real identity.
[0063] The legitimate AMF decrypts the SUCI and assigns a GUTI. All subsequent signaling interactions use the GUTI, and the fake base station cannot associate with the user session.
[0064] It can be seen that the fake base station attack is blocked 100%, and the communication content of the crew is not leaked at all.
[0065] The legitimate interception agency obtains the GUTI-SUPI mapping of the target user accurately through UDM authorization and completes the monitoring task.
[0066] Therefore, through the dual mechanisms of SUCI encryption and GUTI replacement, this embodiment achieves multiple technical effects such as identity privacy protection, signaling efficiency improvement, and anti-attack ability enhancement in the high-exposure-risk environment of satellite communication, taking into account both security and the needs of legitimate interception.
[0067] On the other hand, the MEC is deployed on the side of the proxy call session control function (P-CSCF) network element. The edge MEC executes the following two filtering strategies by parsing the Via header field in the session initiation protocol signaling:
[0068] Filtering strategy one: Check whether the source P-CSCF address belongs to the trusted domain name list;
[0069] Filtering Policy 2: Verify the consistency between the service call session control function (S-CSCF) address obtained through the CX interface and the topological information in the authentication vector of the home subscriber server (HSS).
[0070] In this embodiment, the two-dimensional filtering is completed at the edge side of the P-CSCF, avoiding the redundant operation of transmitting all signaling to the core network for inspection in the traditional solution. The forged P-CSCF nodes (such as attacker.pcscf.com) can be accurately identified through the trusted domain verification, and the defense success rate is high. In addition, the topological consistency verification blocks illegal S-CSCF routes (such as routing users to illegal core network nodes outside the country).
[0071] For example, an attacker forges a P-CSCF node (IP: 192.168.5.100) and attempts to hijack the IMS registration process of satellite users.
[0072] The REGISTER signaling sent by the user passes through the forged P-CSCF node, and the Via header field is recorded as Via: SIP / 2.0 / UDP 192.168.5.100:5060.
[0073] Then, the MEC performs trusted domain verification:
[0074] Query the trusted domain name list and find that 192.168.5.100 is not in the whitelist. The MEC immediately discards the signaling, generates a security log, and synchronously triggers a satellite link security alarm. The base station starts reverse tracing to locate the attack source.
[0075] Through the two-dimensional filtering mechanism on the edge side, this embodiment achieves a double breakthrough in signaling processing efficiency and security protection ability in the high-delay and vulnerable-to-attack scenarios unique to satellite communication.
[0076] On the other hand, the intercepted voice data stream is split into multiple data packets, which are transmitted simultaneously through the satellite link and the base station link, and the key packets are preferentially transmitted using the low-delay path.
[0077] Specifically, the voice data stream is split into RTP (Real-Time Transport Protocol) packets, and a data packet (payload size ≤ 160 bytes) is generated every 20 ms, and the key packet identifier is marked:
[0078] Key packet: Contains the first frame of voice after voice activity detection (VAD activation frame), DTMF signal, SIP session control instruction (such as BYE message).
[0079] Ordinary packet: Non-first-frame data in consecutive voice frames.
[0080] It can be based on the base station link (low-latency path, average delay ≤ 50 ms, dedicated to transmitting critical packets, using a strict priority queue (SPQ), and bandwidth reservation ≥ 30%).
[0081] Transmit ordinary packets and redundant copies of critical packets based on the satellite link (high-latency path, average delay 250 ms), and dynamically allocate bandwidth.
[0082] Through dual-link redundant transmission, the packet loss rate is reduced from 2% of the single link to less than 0.05%.
[0083] In this embodiment, through mechanisms such as intelligent fragmentation, dual-link coordination, and dynamic priority scheduling, "critical guarantee and elastic transmission" of voice interception data are achieved in the satellite communication scenario, taking into account real-time performance, reliability, and economy.
[0084] On the other hand, in the interception session establishment phase, the MEC and the PCF in the core network cooperate to perform dynamic policy control, including: adjusting the Quality of Service flow (QoS) buffer threshold according to the round-trip delay value (RTT) of the satellite link, and reallocating the data replication thread resources of the User Plane Function (UPF) based on the service type priority.
[0085] In this embodiment, the buffer threshold is dynamically adjusted, enabling the system to withstand large RTT fluctuations and effectively reducing the out-of-order rate of voice data packets. When the satellite link is affected by weather (such as RTT fluctuations caused by rain fade), the integrity of the intercepted data can still be maintained, and the packet loss recovery rate ≥ 99.9%.
[0086] For example, in a maritime satellite communication scenario, a sudden heavy rain causes the satellite link RTT to increase from 250 ms to 420 ms, and multiple voice calls need to be intercepted.
[0087] Then, the MEC detects the abnormal RTT and reports the link status (RTT = 420 ms, packet loss rate 3%) to the PCF.
[0088] The PCF triggers the dynamic policy:
[0089] Adjust the QoS flow buffer threshold from 50 ms to: 50 + (420 - 250) / 3 × 3 = 170 ms.
[0090] Allocate 2 high-priority threads for voice services, and downgrade video services to the shared thread pool.
[0091] The UPF reconstructs the data pipeline, preferentially ensuring the replication of voice data streams, and the interception delay is stabilized at 75 ms.
[0092] The results show that during the heavy rain, the integrity rate of the voice interception data remains 99.8%, and no critical data is lost.
[0093] Thus, in this embodiment, through the RTT adaptive buffer adjustment and service-aware thread allocation mechanism, the intelligent optimization of the interception strategy is achieved in the high-dynamic environment of the satellite link, significantly improving the reliability, real-time performance, and resource utilization rate of the legal interception system.
[0094] On the other hand, the interception method further includes an intelligent fault recovery mechanism: when it is detected that the packet loss rate of the dedicated network slice exceeds the set threshold, the strategies in the following three stages are executed in sequence:
[0095] Stage 1: Send a link degradation notification to the application function (AF) through the network exposure function (NEF);
[0096] Stage 2: Trigger the Xn interface handover process between base stations;
[0097] Stage 3: Start the local temporary backup of encrypted data at the MEC node.
[0098] In this embodiment, the end-to-end recovery time from detecting packet loss anomalies to completing the handover is effectively reduced. During the satellite link interruption time (such as 5 minutes), the MEC local backup can maintain the integrity of the intercepted data.
[0099] For example, in a maritime law enforcement operation, when the target ship enters a heavy rainfall area, the packet loss rate of the satellite link rises to 8%.
[0100] Then the recovery process is as follows:
[0101] Stage 1: The NEF detects the anomaly within 3 seconds, sends an alarm to the law enforcement command center AF, and starts the emergency process.
[0102] Stage 2: Trigger the Xn interface to hand over to the adjacent base station (linear distance 80 km), and the resources of the dedicated network slice are seamlessly migrated, with the handover taking 320 ms.
[0103] Stage 3: After the satellite link is interrupted due to heavy rainfall, the MEC node automatically caches the subsequent 45 minutes of call data and completes the encrypted backhaul within 2 minutes after the link is restored.
[0104] During the handover, the packet loss rate of the voice interception stream drops to 0.2%, and the call content is completely restored.
[0105] Thus, in this embodiment, through the intelligent three-stage recovery mechanism, in the high-dynamic and high-risk physical environment of satellite communication, the anti-destruction, real-time performance, and compliance of the legal interception system are achieved.
[0106] On the other hand, the IMS voice service interception policy for GEO satellite access can also be dynamically adjusted according to the geographical location, service type, and network conditions of different users to ensure the coverage rate and efficiency of interception. Then, the interception method further includes the step of dynamically generating an interception policy based on multi-dimensional user characteristics:
[0107] a) Geographical location adaptation: Match the user's current longitude and latitude coordinates through the GEO satellite beam coverage area. When the user enters a preset sensitive geographical fence, automatically raise the interception priority to the highest level;
[0108] b) Service type differentiation: Identify the media stream types in the IMS voice service, allocate 90% of the bandwidth resources of a dedicated network slice to real-time voice (RTP payloadtype = 0), and only allocate 10% of the bandwidth to video streams (RTP payload type = 34);
[0109] c) Network status response: Real-time monitor the propagation loss value (unit: dB) of the GEO satellite link. When the loss exceeds the threshold (L ≥ 12 dB), trigger the following joint adjustment:
[0110] i. Extend the pre-parsing depth of the MEC from the SIP header to the RTP payload;
[0111] ii. Activate a dual-buffer queue for voice data streams at the MEC node (main queue capacity = 10 seconds of voice data, backup queue = 5 seconds);
[0112] iii. Force the PCF to update the QoS flow identifier (QFI) mapping table to preferentially guarantee the anti-interference frequency band resources of high-loss links.
[0113] In this embodiment, by matching the satellite beam coverage through the geographical fence, the error of the law enforcement interception range is effectively reduced, and the interception coverage rate is improved. The interception delay of real-time voice data streams is reduced, the satellite spectrum utilization rate is increased, and the ability to resist channel degradation is enhanced.
[0114] The present invention also discloses an IMS data stream legal interception system based on GEO satellite communication. The interception system operates based on the IMS data stream legal interception method in the above embodiment.
[0115] The present invention also discloses another IMS data stream legal interception system, which includes one or more processors, a memory, and one or more programs. One or more programs are stored in the memory and are configured to be executed by the one or more processors. The programs include instructions for executing the legal interception method as described above. The processor may adopt a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits to execute relevant programs to implement the functions required by the modules in the legal interception system of the embodiments of the present application, or to execute the legal interception method of the method embodiments of the present application.
[0116] The present invention also discloses a computer-readable storage medium, which includes a computer program. The computer program can be executed by a processor to complete the legal interception method as described above. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium can be a read-only memory (ROM), a random access memory (RAM), a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape, a magnetic disk, or an optical medium, such as a digital versatile disc (DVD), or a semiconductor medium, such as a solid state disk (SSD), etc.
[0117] The embodiments of the present application also disclose a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the above-mentioned legal interception method.
[0118] The above-disclosed are only the preferred embodiments of the present invention. Of course, the scope of the rights of the present invention cannot be limited thereby. Therefore, equivalent changes made according to the scope of the patent application of the present invention still fall within the scope covered by the present invention.
Claims
1. A method for lawful interception of IMS data streams based on GEO satellite communications, characterized in that: include: An edge service node is deployed in a base station or ground station, and the edge service node supports local caching, SIP signaling pre-parsing, and resource reservation; the edge service node is also pre-set with an interception target list, and the interception target list records the identity information of several users to be intercepted; Building a dedicated network slice dedicated to intercepting data transmission based on the general service slice; Parsing the IMS call signaling from the first terminal device based on the edge service node to extract corresponding user identity information; If the user identity information exists in the interception target list, the edge service node applies to the base station or ground station for reserved slice resources corresponding to the dedicated network slice, and reports the interception session ID to the core network; The edge service node copies the voice data stream of the first terminal device to the designated interface through the dedicated network slice according to the user policy issued by the core network, including the designated interface for receiving intercepted data.
2. The method for lawful interception of IMS data stream based on GEO satellite communication according to claim 1, characterized in that: Bandwidth resources and the highest priority are configured for the dedicated network slice.
3. The method for lawful interception of IMS data stream based on GEO satellite communication according to claim 1, characterized in that: The user identity information in the IMS call signaling includes a subscription hidden identifier encrypted by a public key and a temporarily allocated globally unique temporary user identifier, wherein the subscription hidden identifier protects the subscription permanent identifier through an elliptic curve encryption algorithm, and the globally unique temporary user identifier replaces the subscription permanent identifier for signaling interaction after the session is established.
4. The IMS data flow lawful interception method based on GEO satellite communication according to claim 1, characterized in that: The edge service node is deployed on the proxy call session control function network element side. The edge service node executes the following two filtering strategies by parsing the Via header field in the session initiation protocol signaling: Filtering strategy 1: Check whether the source proxy call session control function address belongs to the trusted domain name list; Filtering strategy 2: Verify the consistency between the service call session control function address obtained by the CX interface and the topology information in the home user server authentication vector.
5. The IMS data flow lawful interception method based on GEO satellite communication according to claim 1, characterized in that: The intercepted voice data stream is split into multiple data packets, which are transmitted simultaneously via satellite links and base station or ground station links, with low-latency paths being used to preferentially complete the transmission of critical packets.
6. The method for lawful interception of IMS data stream based on GEO satellite communication according to claim 1, characterized in that: During the interception session establishment phase, the edge service node and the policy control function in the core network collaborate to perform dynamic policy control, including: adjusting the service quality flow buffer threshold according to the round-trip delay value of the satellite link, and reallocating data replication thread resources of the user plane function based on the service type priority.
7. The IMS data flow lawful interception method based on GEO satellite communication according to claim 1, characterized in that: It also includes an intelligent fault recovery mechanism: when it is detected that the packet loss rate of the dedicated network slice exceeds the set threshold, the following three-stage strategies are executed in sequence: Phase 1: Sending link degradation notification to application functions through network capability exposure functions; Phase 2: Triggering the Xn interface switching process between base stations or ground stations; Phase 3: Start local temporary backup of encrypted data at multi-access edge service nodes.
8. An IMS data flow lawful interception system based on GEO satellite communication, characterized in that: The interception system works based on the IMS data flow lawful interception method described in any one of claims 1 to 7.
9. An IMS data flow lawful interception system based on GEO satellite communication, characterized in that: include: one or more processors; Memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the programs comprising instructions for executing the IMS data flow lawful interception method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The invention comprises a computer program, wherein the computer program can be executed by a processor to implement the IMS data flow lawful interception method according to any one of claims 1 to 7.