Managing data delivery flow
Dynamic data truncation by ELI devices addresses LI system resource overload, enhancing data delivery efficiency and scalability while conserving energy.
Patent Information
- Application Number
- PCT/EP2025/062706
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-10
- Filing Date
- 2025-05-09
- Publication Date
- 2025-11-13
AI Technical Summary
Existing Lawful Interception (LI) systems face challenges with resource overload due to excessive data payload, leading to potential system congestion and inefficiencies in delivering targeted information to Law Enforcement Agencies (LEAs).
Implementing dynamic data truncation methods by Element of Interception (ELI) devices based on network conditions, allowing for targeted data reduction and notification to Law Enforcement Monitoring Functions (LEMFs) to manage data delivery flow effectively.
Reduces resource overload, ensures more relevant and targeted data delivery, improves system scalability, and conserves energy by dynamically adjusting data delivery based on network load and conditions.
Smart Images

Figure EP2025062706_13112025_PF_FP_ABST
Abstract
Description
[0001] MANAGING DATA DELIVERY FLOW
[0002] TECHNICAL FIELD
[0003] The present disclosure relates to methods for managing data delivery flow. Corresponding network nodes, a computer program, and a carrier are also disclosed.
[0004] BACKGROUND
[0005] European Telecommunications Standards Institute (ETSI) managed several requests in 2023 to reduce data payload size primarily on the HI3 interface that conveys Content of Communication (CC) data between a Communications Service Provider (CSP) and a Law Enforcement Agency (LEA), and the X3 interface which conveys CC data within the CSP, for Lawful Interception (LI). Specifically, intercepted data truncation was requested by several LEAs as a new requirement with reference to use cases of Internet Access Service interception such as described in ETSI Technical Specification (TS) 102 232-3 V3.13.1 (2024-01), and of Layer 2 Service interception as described in ETSI TS 102 232- 4 V3.7.1 (2024-01). HI interface was enhanced to allow the CSP to deliver truncated intercepted data to the LEA.
[0006] Warrant interface, e.g., ETSI TS 103 120 VI.15.1 (2024-01) and ETSI TS 103 280 V2.10.1 (2023-08) has been extended to allow LEA to order truncation action to CSP when delivering content data on X3 / HI3.
[0007] SUMMARY
[0008] An object of the present invention is to enable a reduction of an amount of Lawful Interception (LI) data received by a Law Enforcement Monitoring Function (LEMF) of a Law Enforcement Agency (LEA) to decrease the likelihood of resource overload, as well as to enable a provision of more targeted and relevant information to support LI.
[0009] The present disclosure provides methods for supporting LI by Element of Interception (ELI) devices, such as ELI-Point of Interception (ELI-POI) devices, and ELI- Mediation and Delivery Function (ELI-MDF) devices, as well as LI-Administration Function (LI-ADMF) devices. An LI-ADMF device configures an ELI device with an activate task message or modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a LEMF associated with a task is to be truncated upon occurrence of a network condition. The ELI device then directly truncates the LI data when the network condition occurs, or the ELI device sends a notification to the LEMF that a network condition is about to occur. Upon receiving a modify task message from the LEA via the LI-ADMF, the ELI device then delivers the truncated LI data to the LEMF. An first aspect of the invention relates to an method for managing data delivery flow performed by an ELI device. The method comprises: receiving, from an LI- ADMF device, an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a LEMF device associated with a task is to be truncated upon occurrence of a network condition; determining that the network condition has occurred at the ELI device or at another ELI device associated with the task; and delivering truncated intercepted data towards the LEMF device, wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
[0010] In an embodiment, the method further comprises providing a notification to the LI-ADMF device that data delivery to the LEMF device associated with the task will be truncated. This embodiment may also comprise, in response to the network condition no longer occurring: providing another notification to the LI-ADMF device that data delivery to the LEMF device associated with the task will not be truncated; and delivering untruncated intercepted data towards the LEMF device, wherein the untruncated data further comprises an indicator that the untruncated intercepted data is not truncated.
[0011] A second aspect relates to a network node that implements an ELI device and comprises a processing circuitry configured to cause the network node to: receive from an LI-ADMF device, an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a LEMF device associated with a task is to be truncated upon occurrence of a network condition; determine that the network condition has occurred at the ELI device or at another ELI device associated with the task; and deliver truncated intercepted data towards the LEMF device, wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
[0012] In an embodiment of the second aspect, the processing circuitry is further configured to cause the network node to perform a method according to any of the above embodiments of the first aspect. A third aspect relates to a method for managing data delivery flow performed by an ELI device. The method comprises providing towards a LEMF device, a notification that a network condition has occurred; receiving, from an LI-ADMF device, a modify task message comprising a truncate indicator that indicates that data delivery of intercepted data to the LEMF device associated with a task is to be truncated; and delivering truncated intercepted data towards the LEMF device, wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
[0013] In an embodiment of the third aspect, the method further comprises providing a notification to the LI-ADMF device that data delivery to the LEMF device associated with the task will be truncated.
[0014] In an embodiment of the third aspect, the method further comprises providing an acknowledgement to the LI-ADMF device that the modify task message was received.
[0015] In an embodiment of the first and third aspects, the intercepted data is truncated based on a priority order associated with the activate task message or the modify task message.
[0016] In an embodiment of the first and third aspects, the network condition is associated with a load of the ELI device or the other ELI device associated with the task exceeding a threshold load.
[0017] In an embodiment of the first and third aspects, an amount of truncation of the truncated intercepted data is based on a level of the load of the ELI device or the other ELI device.
[0018] The ELI device is in an embodiment of the first and third aspects an ELI-POI device. In such an embodiment the delivering of the truncated intercepted data may comprise delivering truncated intercepted data to an ELI-MDF device.
[0019] The ELI device is an ELI-MDF device in an embodiment of the first and third aspects. In such an embodiment the delivering of the truncated intercepted data may comprise delivering truncated intercepted data to the LEMF device. Furthermore, the embodiment may further comprise receiving untruncated lawful intercept data from an ELI-POI device. Alternatively to what is disclosed in the preceding sentence, this embodiment may comprise receiving truncated lawful intercept data from an ELI-POI device. A fourth aspect relates to a network node that implements an ELI device and comprises a processing circuitry configured to cause the network node to: provide, towards a LEMF device, a notification that a network condition has occurred; receive, from an LI-ADMF device, a modify task message comprising a truncate indicator that indicates that data delivery of intercepted data to the LEMF device associated with a task is to be truncated; and deliver truncated intercepted data towards the LEMF device, wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
[0020] In an embodiment of the fourth aspect, the processing circuitry is further configured to cause the network node to perform a method according to any of the above embodiments of the third aspect.
[0021] A fifth aspect relates to a method for managing data delivery flow performed by an LI-ADMF device, the method comprising: providing, to an ELI device an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a LEMF device associated with a task is to be truncated upon occurrence of a network condition; and receiving a notification from the LI-ADMF device that data delivery to the LEMF device associated with the task will be truncated.
[0022] In an embodiment of the first, third and fifth aspects, the network condition is associated with a load of the ELI device or the other ELI device associated with the task exceeding a threshold load.
[0023] In an embodiment of the fifth aspect, the ELI device is an ELI-POI device.
[0024] In an embodiment of the fifth aspect, the ELI device is an ELI-MDF device.
[0025] A sixth aspect relates to a network node that implements an LI-ADMF device, and comprises a processing circuitry configured to cause the network node to: provide, to an ELI device, an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a LEMF device associated with a task is to be truncated upon occurrence of a network condition; and receive a notification from the LI-ADMF device that data delivery to the LEMF device associated with the task will be truncated.
[0026] In an embodiment of the sixth aspect, the processing circuitry is further configured to cause the network node to perform a method according to any of the above embodiments of the fifth aspect. A seventh aspect relates to a computer program which comprises instructions which, when executed on at least one processing circuitry of a network node, cause the network node to carry out a method according to the first, third and fifth aspects or any of their respective embodiments.
[0027] An eighth aspect relates to a carrier containing a computer program according to the seventh aspect, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium.
[0028] BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.
[0030] Figure 1 illustrates a block diagram schematic of a Lawful Interception (LI) architecture between a communication service provider and a law enforcement agency according to some embodiments of the present disclosure;
[0031] Figure 2 illustrates a message sequence chart of a method for managing data delivery flow performed by an LI Administration Function (LI-ADMF) device according to some embodiments of the present disclosure;
[0032] Figure 3 illustrates a message sequence chart of a method for managing data delivery flow performed by an Element of Interception (ELI) Point of Interception (POI) device according to some embodiments of the present disclosure;
[0033] Figure 4 illustrates a message sequence chart of a method for managing data delivery flow performed by an Element of Interception (ELI) Mediation and Delivery Function (MDF) device according to some embodiments of the present disclosure;
[0034] Figure 5 illustrates a message sequence chart of another method for managing data delivery flow performed by an ELI-POI device according to some embodiments of the present disclosure;
[0035] Figure 6 illustrates a message sequence chart of another method for managing data delivery flow performed by an ELI-MDF device according to some embodiments of the present disclosure;
[0036] Figure 7 is a schematic block diagram of a network node according to some embodiments of the present disclosure; Figure 8 is a schematic block diagram that illustrates a virtualized embodiment of the network node according to some embodiments of the present disclosure; and
[0037] Figure 9 is a schematic block diagram of the network node according to some other embodiments of the present disclosure.
[0038] DETAILED DESCRIPTION
[0039] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein, the disclosed subject matter should not be construed as limited to only the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.
[0040] Network Node: As used herein, a "network node" can be any type of apparatus / device in a core network or any apparatus / device that implements a core network function. Some examples of a core network node include a computer or server host for e.g., a Mobility Management Entity (MME), a Packet Data Network Gateway (P- GW), a Service Capability Exposure Function (SCEF), a Home Subscriber Server (HSS), or the like. Some other examples of a core network node include a node implementing an Access and Mobility Management Function (AMF), a User Plane Function (UPF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a Network Function (NF) Repository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), or the like. In the following description, when stating that any of these functions, such as Lawful Intercept (LI) Administration Function (ADMF) device, Element of Interception (ELI) device, ELI-Point of Intercept (POI) device or ELI-Mediation and Delivery Function (MDF) device, perform an action, such as receiving / matching / performing / configuring then it is to be understood that it is in practice the network node / computer / server host / LI ADMF device / ELI-POI device, ELI- MDF device, that hosts the LI ADMF , ELI-POI, or ELIO-MDF, respectively, that performs the action. It shall also be understood that the LI ADMF may also be the abbreviation for LI Administrative Function. There currently exist certain challenge(s). In some cases, LI data detected by network nodes is too large to be processed by a Law Enforcement Agency's (LEA's) monitoring facility whose capability may be limited allowing to manage only part of the content of payload. Furthermore, many investigations use cases have been noted as being covered by analyzing only internet protocol (IP) headers and / or limited session data.
[0041] It is also difficult to dimension hardware (HW) and connections to allow forwarding all intercepted data to the Law Enforcement Monitoring Function (LEMF).
[0042] As of today, European Telecommunications Standards Institute (ETSI) has approached truncation procedures only by direct orders of LEA ("static truncation") without any further evaluation of payload reduction methods. The decision to truncate a task interception is ordered / activated by LEA without considering the actual Communications Service Provider (CSP) network conditions. Indeed, several LEA organizations are showing interest in a more structured and flexible LI solution to manage a supervised payload reduction feature.
[0043] Certain aspects of the present disclosure and their embodiments may provide solutions to the aforementioned or other challenges. The technique proposed in this disclosure will implement a method and algorithm to manage the payload size of the intercepted data to control the load of delivery on the interfaces Handover Interface Port 2 (HI2) / Handover Interface Port 3 (HI3) and possibly of incoming mediation connections / interfaces (X2 / X3).
[0044] Payload reduction is proposed to be implemented "dynamically" by the CSP and the ELI devices (ELI-POI devices and ELI-MDF devices) based on the actual load detected by the ELI devices managing the intercepted data.
[0045] The idea is to provide the CSP with a new feature allowing them to monitor the intercepted data size per group of tasks at ELI level to manage proper intercepted data reduction according to well pre-defined methods based on an agreement between CSP and LEA.
[0046] Any ELI (e.g. ELI-POI, ELI-MDF, see Figure 1 below) is enhanced to include a monitoring functionality on the intercepted traffic volume involving a group of tasks (identified by the LEA), controlling its size. The upper size of the cumulated intercepted data (at ELI level) engaging the activation of the tasks' downsizing procedure is evaluated in relation to different criteria, i.e. threshold limits. When a downsizing criterion is met, i.e. an upper threshold limit is reached, ELI may manage different actions based on agreed policy CSP-LEA on overloaded intercepted traffic management.
[0047] The primary option is to: downsize, i.e. truncate, directly the intercepted data traffic and notify LEA immediately on the downsizing started action (at single task / target level). Further actions may be defined as well, i.e. firstly notifying LEA (and a CSP central entity) on the threshold limit reached for intercepted data size per each task. Then, it will be up to LEA to decide on explicit downsizing, i.e. truncation, orders towards CSP.
[0048] Direct downsize includes as sub-case the already standardized ETSI procedures of "static truncation" when the group of tasks / target corresponds to a single task / target and truncation is indicated as downsizing action. The group of tasks / targets may be defined considering a priority list as well on the order of tasks to be downsized. The algorithm may start downsizing on a sequence of well-defined tasks, also verifying one by one when it may stop in case of downsizing criteria not met anymore, i.e. data load under a low safe threshold.
[0049] The techniques disclosed herein implement a method and algorithm to control the intercepted payload size and therefore the load of the delivery on HI2 / HI3 and of the incoming mediation connections on X2 / X3. This latter feature on the X interface is subject to the ELI-POIs capability to support downsizing procedures. When the CSP interception domain is based on ELI-POIs not supporting the downsizing I truncation feature, procedures will be implemented at the ELI-MDF level to guarantee the HI data delivery size under a pre-defined upper threshold. The indication of the direct downsizing (e.g. option "direct downsizing'7"truncation") or other actions to be implemented by ELI when a downsizing criteria is met, may be provided directly by LEA to the ELI device at single task / target level when creating / activating a task within the CSP.
[0050] Thresholds may be configured at ELI level while the proper group of tasks / targets where downsizing, i.e. truncation, will apply are dynamically defined by LEA by e-warrants, e.g. via HI1 and further XI messages towards ELIs. Different threshold upper values may be configured for each ELI type, i.e. ELI-MDF will have a threshold mainly based on the HI and LEA data capacity while ELI-POIs threshold may be defined on POIs capacity and X dimensioning. The ELI may be provided by LEAs also with a priority indication per each task or target so that it will manage the order of tasks / targets to be firstly downsized, i.e. truncated. If a priority list on the order of tasks to be downsized, i.e. truncated, is defined the algorithm will start downsizing, i.e. truncation, on a sequence of well- defined tasks and verify one by one if it may be stopped when safe threshold (at group of tasks level) is crossed downwards and the load is under a safe level.
[0051] The modified intercepted data for each downsized, i.e. truncated task / target of the identified group will be notified to the LEA by using HI2 / HI3 and, in case of ELI- POIs supporting downsizing, by X2 / X3 interfaces.
[0052] The proposed LI solution may be enhanced to include a further option ("notify and wait") where ELI will notify the LEA (and any CSP central entity) on the threshold upper limit reached for intercepted data size waiting for explicit truncation orders by the LEA to the CSP.
[0053] In case of upper threshold reached, ELI will act per each single task / target interception, by notifying the LEA by a dedicated intercept related information (IRI) message (i.e. a THRESHOLD-STATUS message with status OVERLOAD) on the HI2 interface and, if ELI-POI supports downsizing, on X2. Moreover, coordination will be managed between the ELI and the ADMF via a proper XI notification to the ADMF.
[0054] A notification by the ELI may be activated as well when the threshold is again under a certain safe level by means of a dedicated IRI message (i.e. THRESHOLDSTATUS message with status BELOW-THRESHOLD) on HI2 interface and, if ELI-POI supports downsizing, on X2. The LEA in this case may decide to revert the truncation commands.
[0055] In case of the upper threshold reached for a group of tasks / targets, a notification may be managed by means of XI from ELI to ADMF.
[0056] ETSI Handover Interface Port 1 (HI1) and XI interfaces are structured to transport the same Traffic policy information which instructs the final ELI-POI on the way to manage the intercepted data. HI1 defines it at clause 7.5 of ETSI TS 103 120 VI.15.1 and XI at annex F of ETSI TS 103 221-1 VI.16.1. This allows deployments where Traffic policy information is required to be shared with any ELI-POI interfacing ADMF via XI.
[0057] The actual Traffic Policy information implemented by a CSP is for an agreement between the LEA and the CSP. ETSI standard currently also considers situations where the CSP interception domain, e.g. ELI-POIs, are not aligned to manage downsizing, i.e. truncation and in this case no resizing will apply at all. This limitation is overtaken by the present disclosure as the LI-ADMF is proposed to proceed additionally to instruct the ELI-MDF to act to control the load of HI2 / HI3 intercepted traffic level. Based on the approach delineated by LI(24)P65015r5 TS 103 120 vl.15.1 CR
[0058] 058 - Traffic Policy for Truncating Data Packets, the TrafficPolicyObject is proposed to be enhanced with new Actions to define the possibility to downsize data traffic; as first possibility is the "Truncable" value to indicate that the intercepted data of the referred task will be subject to truncation based on dynamic conditions detected in the ELI where such a command (via XI) is forwarded by the ADMF (based on LEA indication and / or agreement).
[0059] New Actions values may be defined based on the actual LEA indications, i.e. downsizing / truncation may be tuned also at service level for a specific task / target. The following table is a proposed update to Table 7.25 of section 7.6.3 of ETSI TS 103 120 Vl.15.1 (2024-01), with the underlined line for "Truncable" indicator being the new value.
[0060] New Actions codes are proposed to be used by LEA when proceeding to generate a warrant to be communicated via HI1. Furthermore, for option "notify and wait", when notified on a task for an overload condition, LEA may proceed to order downsizing / truncation for that task by using update action request an HI1 towards CSP / ADMF.
[0061] The HI1 update LITaskObject orders are managed on XI level as Modify Task messages. The HI1 Create LITaskObject orders are managed on XI level as Activate Task messages.
[0062] All the following descriptions refer to the case of truncation traffic action by introducing the new value "Truncable". This value is managed by CSP as "Truncate" only for specific detected network conditions, otherwise it will be forwarded to LEA entirely.
[0063] Certain embodiments may provide one or more of the following technical advantage(s). The proposed solution has especially important advantages to systematize an area of growing interest by the CSP and LEAs. Specifically, the network system conditions (i.e. proper upper threshold limits) may be properly formulated at ELI-POIs and ELI-MDF levels to address different relevant use cases. The LEA will always have the control by specifying the group of tasks / targets for which it may apply downsizing due to the specific detected conditions.
[0064] With this solution the ADMF / MDF improves the scalability and introduces the possibility to apply, when needed because the load is too high, the possibility to apply and report truncation of packets.
[0065] Assuring the following advantages: The solution proposed can perform automatic truncation of packets in case of overload on the connection between the node and the ADMF / MDF.
[0066] Another advantage is in improving the availability of the ADMF / MDF, by enabling the possibility of the AMDF / MDF to perform an automatic truncation which can avoid overload of the system which in turn could cause major losses of data due to complete congestion of the LI System and LEMF. Dimensioning of the system shall not always be done considering extremely border line traffic loads that occasionally happen in the networks and allows a smoother and more controlled scalability, on all parts involved on the LI System on the nodes and on the LEMFs.
[0067] Another advantage is reduced energy consumption by reducing the throughput of the system with the appropriate thresholds setting.
[0068] Energy savings are obtained in two ways:
[0069] 1) reducing the data transferred on the running system or by 2) scaling down the hardware of the system because truncation is used to handle the throughput.
[0070] The algorithm described above is complemented with a solution that reduces the energy consumption regardless of the load based on a "power save mode" setup on the solution that involves the ADMF / MDF and the nodes. When this mode is selected, truncation is applied to obtain just saving on power reducing the data transferred regardless of the current system load like in the standard behavior. This is triggered in diverse ways and is equivalent to starting the truncation with a lower threshold to reduce the total load.
[0071] Thresholds are also used in this case to start payload reduction if a certain connection or a certain node produces too much data. Some exemplary thresholds include the following below. These are just representative thresholds and in other embodiments, different thresholds are possible.
[0072] • MaxLoadllpperThreshold
[0073] • MaxLoadSafeThreshold = MaxLoadllpperThreshold * 0,9 (reduce of 10% from the MaxLoadllpperThreshold)
[0074] This is an example of the relationship between the two thresholds. Generally, however, the MaxLoadllpperThreshold is larger than the MaxLoadSafeThreshold. The solution improves availability on the ELI (e.g. Mediation and Delivery Function 3 (MDF3) which generates Communication Content (CC) from raw CC (xCC)) if the ELI device applies the truncation or if the packet is truncated when the load might result in dropping packets.
[0075] In case truncation is made on the node this reduces the load on both systems and on the LEMF and all the connecting network paths.
[0076] Figure 1 illustrates a block diagram schematic of an LI architecture between a CSP and a LEA according to some embodiments of the present disclosure.
[0077] In Figure 1 a CSP 102 includes an LI-ADMF device 104 as well as an ELI-POI device 106 and an ELI-MDF device 108, that can collectively be referred to as ELI devices. The LI-ADMF device 104 can administer and configure the ELI-POI device 106 and the ELI-MDF device 108 via an XI interface, while the ELI-POI provides LI data or intercepted data to the ELI-MDF device 108 via an X2 interface (IRI data) and an X3 interface (Content of Communication (CC) data).
[0078] The ELI-MDF device 108 then provides the IRI data to a LEMF device 114 that is part of a LEA 110 via an HI2 interface, and CC data to the LEMF device 114 via an HI3 interface. The LEA Administrator 112 sends warrants or other configuration information to the LI-ADMF 104 via the HI1 interface.
[0079] Figure 2 illustrates a message sequence chart of a method for managing data delivery flow performed by the LI Administration Function (LI-ADMF) device 104 according to some embodiments of the present disclosure.
[0080] At 202, the LEA Administrator 112 sends a Create LI task message over the HI1 interface to the LI-ADMF 104. The Create LI Task message includes the "truncable" indicator that indicates that data delivery should be truncated upon occurrence of a network condition that is related to load or energy usage of the network or one of the ELI devices. The LI-ADMF device 104 responds at step 204 with a response acknowledging reception of the Create LI Task message. At step 206, the LI-ADMF device 104 sends an Activate LI task message via the XI interface to the ELI-MDF device 108 with the truncable indicator, and the ELI-MDF device 108 at step 208 responds with an acknowledgement. At step 210, the ELI-MDF device 108 inserts the task in the group of tasks which cumulated intercepted data flow size is under monitoring with respond to the ELI-POI threshold and the ELI-MDF device 108 starts monitoring cumulated intercepted data size for the selected tasks.
[0081] At steps 212, 214, and 216, the same operations are performed with the ELI- POI device 106 as were performed in steps 206, 208, and 210 with respect to the ELI- MDF device 108.
[0082] The same flow in Figure 2 applies when the LEA Administrator 112, informed on an approaching threshold upper limit by an ELI device (e.g., as shown in Figures 5 and 6), will decide and configure the ELI device to truncate the selected task by sending the Update / Modify messages on HI1 / XI with action set to "Truncate."
[0083] Figure 3 illustrates a message sequence chart of a method for managing data delivery flow performed by the ELI-POI device 106 according to some embodiments of the present disclosure. In the method shown in Figure 3, the ELI-POI device 106 performs the direct truncation after receiving the configuration from the LI-ADMF 104 in step 212.
[0084] While the ELI-POI device 106 is monitoring the activity of the ELI-POI device 106 and other ELI devices in the CSP, the ELI-POI device at step 302 determines that a network condition has occurred. Where the network condition is defined by the truncable indicator and other information in the Activate LI Task message in step 212 or based on another configuration received from the LI-ADMF device 104. For example, the network condition may relate to load on one or more ELI devices, either in terms of percentage of capacity used, absolute load (e.g., data rate, or data transferred) or in terms of energy use exceeding a defined threshold. If the network condition is met, the ELI-POI device 106 provides a notification towards the LI-ADMF device 104 at step 304 that the network condition has occurred, and that the ELI-POI device 106 will initiate truncation of intercept data.
[0085] At step 306, the ELI-POI device 106 provides the truncated intercept data to the ELI-MDF 108, which then forwards the truncated intercept data to the LEMF device 114 at step 310. Once the network condition has abated, or is otherwise not active at step 312, the ELI-POI device 106 sends a notification to the LI-ADMF device at step 314, and starts sending untruncated intercept data at step 316 to the ELI-MDF device 108 and ELI-MDF device 108 forwards the entire intercept data (e.g., untruncated) to the LEMF device 114 at step 318.
[0086] The truncated intercept data is generally truncated CC data sent from the ELI-POI device 106 to the ELI-MDF device 108 via the X3 interface, and then from the ELI-MDF device 108 to the LEMF device 114 via the HI3 interface. In some embodiments, however, the truncated intercept data is IRI data sent via the X2 and HI2 interface as well.
[0087] In Figure 4, a flow chart for direct truncation by the ELI-MDF device 108 is described, similar to the method in Figure 3, except the truncation is performed by the ELI-MDF device 108.
[0088] While the ELI-MDF device 108 is monitoring the activity of the ELI-MDF device 108 and other ELI devices in the CSP, the ELI-MDF device 108 at step 402 determines that a network condition has occurred. Where the network condition is defined by the truncable indicator and other information in the Activate LI Task message in step 206 or based on another configuration received from the LI-ADMF device 104. For example, the network condition may relate to load on one or more ELI devices, either in terms of percentage of capacity used, absolute load (e.g., data rate, or data transferred) or in terms of energy use exceeding a defined threshold.
[0089] At step 404, the ELI-MDF device 108 receives the intercept data from the ELI- POI device 106. If the network condition is met, the ELI-MDF device 108 provides a notification towards the LI-ADMF device 104 at step 406 that the network condition has occurred, and that the ELI-MDF device 108 will initiate truncation of intercept data.
[0090] The intercept data can be either whole / untruncated or can already be truncated. At step 408, the ELI-MDF device 108 provides the truncated intercept data to the LEMF device 114.
[0091] Once the network condition has abated, or is otherwise not active at step 410, and the ELI-MDF device 108 receives intercept data at step 412, the ELI-MDF device 108 sends a notification to the LI-ADMF device at step 414 and starts sending untruncated intercept data at step 416 to the LEMF device 114.
[0092] Figure 5 illustrates a message sequence chart of another method for managing data delivery flow performed by an ELI-POI device according to some embodiments of the present disclosure.
[0093] Figures 5 and 6 illustrate the notify and wait embodiment where the ELI devices notify the LEA (and any CSP central entity) on the threshold upper limit reached for intercepted data size and then wait for explicit truncation orders by LEA to CSP.
[0094] In case of detected overload, each ELI device will act per each single task / target interception, by notifying the LEA by a dedicated IRI message (i.e. a status message with overload notification status) on the HI2 interface and, if the ELI-POI device 106 supports downsizing, on the X2 interface. Coordination will be managed between the ELI devices and the LI-ADMF device 104 via an XI notification to the LI- ADMF device 104.
[0095] It is left to the LEA to decide how to manage the intercepted data per task / target. In case of a LEA decision to start intercepted data downsizing / truncation, the ELI device will act consequently as detailed in Figures 5 and 6.
[0096] A notification by the ELI may be activated as well when the threshold is again under a certain safe level by means of a dedicated IRI message (i.e. status message with status -below safe threshold) on the HI2 interface and, if ELI-POI device 106 supports downsizing, on X2. The LEA in this case may decide to revert the truncation commands.
[0097] For example, at step 502, the ELI-POI device 106 determines whether a network condition has occurred or is about to occur, and then at step 504 sends the notification of the overload threshold status to the ELI-MDF device 108 on the X2 / X3 interface, and the ELI-MDF device 108 forwards the notification to the LEMF device 114 on the HI2 / HI3 interface at step 506.
[0098] At step 508, the LEA 112 / LEMF device 114 provides an update LI task message on the Hl interface to the LI-ADMF 104 with a "truncate" indicator, and LI- ADMF device 104 sends a response at step 510, and also sends a Modify LI task message with the truncate indicator to the ELI-POI device 106 at step 512. ELI-POI device 106 sends a response at 514, and then at step 516, sends a ReportTasklssue notification that ELI-POI device 106 is going to initiate truncation of intercept data. At step 518, the ELI-POI device 106 sends the truncated data to the ELI-MDF device 108 on the X2 / X3 interface, and the ELI-MDF device 108 forwards the truncated intercept data to the LEMF device 114 on the HI2 / HI3 interface at step 520.
[0099] Figure 6 illustrates a message sequence chart of another method for managing data delivery flow performed by the ELI-MDF device 108 according to some embodiments of the present disclosure.
[0100] For example, at step 602, the ELI-MDF device 108 determines whether a network condition has occurred or is about to occur, and then at step 604 sends the notification of the overload threshold status to the LEMF device 114 on the HI2 / HI3 interface.
[0101] At step 606, the LEA 112 / LEMF device 114 provides an update LI task message on the Hl interface to the LI-ADMF 104 with a "truncate" indicator, and LI- ADMF device 104 sends a response at step 608, and also sends a Modify LI task message with the truncate indicator to the ELI-MDF device 108 at step 610. ELI-MDF device 108 sends a response at 612, and then at step 614, sends a ReportTasklssue notification that ELI-MDF device 108 is going to initiate truncation of intercept data. At step 616, the ELI-MDF device 108 receives the intercept from the ELI-POI device 106 on the X2 / X3 interface, and at step 618 sends the truncated data to the LEMF device 114 on the HI2 / HI3 interface. The steps described and illustrated above in conjunction with Figures 2 to 6 with dashed arrows or dashed boxes, are optional steps.
[0102] The algorithms performed by the ELI devices in both the direct truncation (e.g., Figures 3 and 4) and in the notify and wait scenario (Figures 5 and 6) are similar.
[0103] • If an MDF3 is overloaded, select (autonomously) one or more tasks with truncated action defined and start truncation.
[0104] • Notify the LEMF that one or more tasks are being truncated (note the messages from MDF3 have special parameters to identify them as truncated ones).
[0105] Energy saving algorithms are implemented within truncate and notify flow and shall be triggered instead that on overload on high consumption threshold based on a certain level of energy consumption desired, configuration is not part of the protocol currently, although in the future, this could be part of the XO / automatic configuration interface.
[0106] For notify and wait:
[0107] • If an MDF3 is overloaded, notify the LEA and only when one or more tasks are received from the LEA in a list of truncated tasks, then;
[0108] • select 1 or more tasks with a truncated action defined and start truncation.
[0109] Figure 7 is a schematic block diagram of a network node 700 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The network node 700 may be, for example, a network node that is the ELI-POI device 106, the ELI-MDF device 108 or the LI-ADMF device 104, or implements all or part of the functionality of the ELI-POI device 106, ELI-MDF device 108, or LI- ADMF device 104 as described herein, and may in the future thus be a network node according to any future telecommunication network standard, such as the emerging 3GPP 6thGeneration network. As illustrated, the network node 700 includes a control system 702 that includes one or more processors 704 (e.g., Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory / computer readable storage medium 706, and a network interface 708. The one or more processors 704 are also referred to herein as processing circuitry.
[0110] The one or more processors 704 operate to provide one or more functions of a network node 700 as described herein. In some embodiments, the function(s) are implemented in one or more computer programs 710 that are stored, e.g., in the computer readable storage medium 706 and executed by the one or more processors 704.
[0111] Figure 8 is a schematic block diagram that illustrates a virtualized embodiment of the network node 700 according to some embodiments of the present disclosure. This discussion is equally applicable to other types of network nodes. Further, other types of network nodes may have similar virtualized architectures. Again, optional features are represented by dashed boxes.
[0112] As used herein, a "virtualized" network node is an implementation of the network node 700 in which at least a portion of the functionality of the network node 700 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). The network node 700 includes one or more processing nodes 800 coupled to or included as part of a network(s) 802. Each processing node 800 includes one or more processors 704 (e.g., CPUs, ASICs, FPGAs, and / or the like), memory / computer readable storage medium 706, and a network interface 708.
[0113] In this example, computer programs 710 of the network node 700 described herein are implemented at the one or more processing nodes 800 or distributed across the one or more processing nodes 800 in any desired manner. In some particular embodiments, some or all of the computer programs 710 of the network node 700 described herein are implemented as virtual components executed by one or more virtual machines implemented in a virtual environ ment(s) hosted by the processing node(s) 700. As will be appreciated by one of ordinary skill in the art, additional signaling or communication between the processing node(s) 800 is used in order to carry out at least some of the desired computer programs 710.
[0114] In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of network node 700 or a node (e.g., a processing node 800) implementing one or more of the computer program 710 of the network node 700 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory). Figure 9 is a schematic block diagram of the network node 700 according to some other embodiments of the present disclosure. The network node 700 includes one or more modules such as ELI-POI, ELI-MDF, or LI-ADMF, each of which is implemented in software. The ELI-POI, ELI-MD, or LI-ADM provide the functionality of the network node 700 described herein. This discussion is equally applicable to the processing node 800 of Figure 8 where the modules ELI-POI device 106, ELI-MDF device 108, or LI- ADMF device 104 may be implemented at one of the processing nodes 800 or distributed across multiple processing nodes 800 and / or distributed across the processing node(s) 800 and the control system 702.
[0115] Any appropriate steps, methods, features, functions, or benefits disclosed herein may be performed through one or more functional units or modules of one or more virtual apparatuses. Each virtual apparatus may comprise a number of these functional units. These functional units may be implemented via processing circuitry, which may include one or more microprocessor or microcontrollers, as well as other digital hardware, which may include Digital Signal Processor (DSPs), special-purpose digital logic, and the like. The processing circuitry may be configured to execute program code stored in memory, which may include one or several types of memory such as Read Only Memory (ROM), Random Access Memory (RAM), cache memory, flash memory devices, optical storage devices, etc. Program code stored in memory includes program instructions for executing one or more telecommunications and / or data communications protocols as well as instructions for carrying out one or more of the techniques described herein. In some implementations, the processing circuitry may be used to cause the respective functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.
[0116] While processes in the figures may show a particular order of operations performed by certain embodiments of the present disclosure, it should be understood that such order is exemplary (e.g., alternative embodiments may perform the operations in a different order, combine certain operations, overlap certain operations, etc.).
Claims
CLAIMS1. A method for managing data delivery flow performed by an Element of Lawful Interception, ELI, device, (106, 108) the method comprising: receiving (206, 212), from a Lawful Interception, LI, Administration Function, LI- ADMF, device (104), an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a Law Enforcement Monitoring Facility, LEMF, device (114) associated with a task is to be truncated upon occurrence of a network condition; determining (302, 402) that the network condition has occurred at the ELI device (106, 108) or at another ELI device (106, 108) associated with the task; and delivering (306, 408) truncated intercepted data towards the LEMF device (114), wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
2. The method of claim 1, the method further comprising: providing (304, 406) a notification to the LI-ADMF device (104) that data delivery to the LEMF device (114) associated with the task will be truncated.
3. The method of claim 2, wherein in response to the network condition no longer occurring, the method further comprises: providing (314, 414) another notification to the LI-ADMF device (104) that data delivery to the LEMF device (114) associated with the task will not be truncated; and delivering (316, 416) untruncated intercepted data towards the LEMF device (114), wherein the untruncated data further comprises an indicator that the untruncated intercepted data is not truncated.
4. The method of any one of claims 1 to 3, wherein the intercepted data is truncated based on a priority order associated with the activate task message or the modify task message.
5. The method of any one of claims 1 to 4, wherein the network condition is associated with a load of the ELI device (106, 108) or the other ELI device (106, 108) associated with the task exceeding a threshold load.
6. The method of any one of claims 1 to 5, wherein an amount of truncation of the truncated intercepted data is based on a level of the load of the ELI device (106, 108) or the other ELI device (106, 108).
7. The method of any one of claims 1 to 6, wherein the ELI device (106, 108) is an ELI Point of Interception, ELI-POI, device (106).
8. The method of claim 7, wherein the delivering truncated intercepted data comprises delivering truncated intercepted data to an ELI Mediation and Delivery Function, ELI-MDF, device (108).
9. The method of any one of claims 1 to 6, wherein the ELI device (106, 108) is an ELI Mediation and Delivery Function, ELI-MDF device (108).
10. The method of claim 9, wherein the delivering truncated intercepted data comprises delivering truncated intercepted data to the LEMF device (114).
11. The method of any one of claims 9 to 10, further comprising: receiving (404) untruncated lawful intercept data from an ELI Point of Interception, ELI-POI device (106).
12. The method of any one of claims 9 to 10, further comprising: receiving (404) truncated lawful intercept data from an ELI Point of Interception, ELI-POI, device (106).
13. A network node (700) that implements an Element of Lawful Interception, ELI, device, (106, 108) and comprises a processing circuitry (704) configured to cause the network node to:receive (206, 212), from a Lawful Interception, LI, Administration Function, LI- ADMF, device (104), an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a Law Enforcement Monitoring Facility, LEMF, device (114) associated with a task is to be truncated upon occurrence of a network condition; determine (302, 402) that the network condition has occurred at the ELI device (106, 108) or at another ELI device (106, 108) associated with the task; and deliver (306, 408) truncated intercepted data towards the LEMF device (114), wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
14. The network node of claim 13, wherein the processing circuitry (704) is further configured to cause the network node to perform a method according to any one of claims 2 to 12.
15. A method for managing data delivery flow performed by an Element of Lawful Interception, ELI, device, (106, 108) the method comprising: providing (504, 604), towards a Law Enforcement Monitoring Facility, LEMF, device (114), a notification that a network condition has occurred; receiving (512, 610), from a Lawful Interception, LI, Administration Function, LI- ADMF, device (104), a modify task message comprising a truncate indicator that indicates that data delivery of intercepted data to the LEMF device (114) associated with a task is to be truncated; and delivering (518, 618) truncated intercepted data towards the LEMF device (114), wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
16. The method of claim 15, the method further comprising: providing (516, 614) a notification to the LI-ADMF device (104) that data delivery to the LEMF device (114) associated with the task will be truncated.
17. The method of any one of claims 15 to 16, the method further comprising:providing (514, 612) an acknowledgement to the LI-ADMF device (104) that the modify task message was received.
18. The method of any one of claims 15 to 17, wherein the intercepted data is truncated based on a priority order associated with the activate task message or the modify task message.
19. The method of any one of claims 15 to 18, wherein the network condition is associated with a load of the ELI device (106, 108) or the other ELI device (106, 108) associated with the task exceeding a threshold load.
20. The method of any one of claims 15 to 19, wherein an amount of truncation of the truncated intercepted data is based on a level of the load of the ELI device (106, 108) or the other ELI device (106, 108).
21. The method of any one of claims 15 to 20, wherein the ELI device (106, 108) is an ELI Point of Interception, ELI-POI device (106).
22. The method of claim 21, wherein the delivering truncated intercepted data comprises delivering truncated intercepted data to an ELI Mediation and Delivery Function, ELI-MDF, device (108).
23. The method of any one of claims 15 to 20, wherein the ELI device (106, 108) is an ELI Mediation and Delivery Function, ELI-MDF device (108).
24. The method of any one of claim 23, wherein the delivering truncated intercepted data comprises delivering truncated intercepted data to the LEMF device (114).
25. The method of any one of claims 23 to 24, further comprising: receiving (616) untruncated lawful intercept data from an ELI Point of Interception, ELI-POI device (106).
26. The method of any one of claims 23 to 24, further comprising:receiving (616) truncated lawful intercept data from an ELI Point of Interception, ELI-POI device (106).
27. A network node (700) that implements an Element of Lawful Interception, ELI, device, (106, 108) and comprises a processing circuitry (704) configured to cause the network node to: provide (504, 604), towards a Law Enforcement Monitoring Facility, LEMF, device (114), a notification that a network condition has occurred; receive (512, 610), from a Lawful Interception, LI, Administration Function, LI- ADMF, device, (104) a modify task message comprising a truncate indicator that indicates that data delivery of intercepted data to the LEMF device (114) associated with a task is to be truncated; and deliver (518, 618) truncated intercepted data towards the LEMF device (114), wherein the truncated intercepted data further comprises an indicator that the truncated intercepted data is truncated.
28. The network node (700) of claim 27, wherein the processing circuitry (704) is further configured to cause the network node to perform a method according to any one of claims 16 to 26.
29. A method for managing data delivery flow performed by a Lawful Interception, LI, Administration Function, LI-ADMF, device (104), the method comprising: providing (206, 212), to an Element of Lawful Interception, ELI, device, (106, 108) an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a Law Enforcement Monitoring Facility, LEMF, device (114) associated with a task is to be truncated upon occurrence of a network condition; and receiving (304, 406) a notification from the LI-ADMF device (104) that data delivery to the LEMF device (114) associated with the task will be truncated.
30. The method of claim 29, wherein the network condition is associated with a load of the ELI device (106, 108) or another ELI device (106, 108) associated with the task exceeding a threshold load.
31. The method of any one of claims 29 to 30, wherein the ELI device (106, 108) is an ELI Point of Interception, ELI-POI device (106).
32. The method of any one of claims 29 to 31, wherein the ELI device (106, 108) is an ELI Mediation and Delivery Function, ELI-MDF device (108).
33. A network node (700) that implements a Lawful Interception, LI, Administration Function, LI-ADMF, device (104), and comprises a processing circuitry (704) configured to cause the network node to: provide (206, 212), to an Element of Lawful Interception, ELI, device, an activate task message or a modify task message comprising a truncable indicator that indicates that data delivery of intercepted data to a Law Enforcement Monitoring Facility, LEMF, device (114) associated with a task is to be truncated upon occurrence of a network condition; and receive (304, 406) a notification from the LI-ADMF device (104) that data delivery to the LEMF device (114) associated with the task will be truncated.
34. The network node of claim 33 wherein the processing circuitry (704) is further configured to cause the network node to perform a method according to any one of claims 30 to 32.
35. A computer program (710) comprising instructions which, when executed on at least one processing circuitry (704) of a network node (700), cause the network node (700) to carry out a method according to any one of claims 1 to 12, 15 to 26, or 29 to 32.
36. A carrier containing a computer program (710) of claim 35, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (706).
Citation Information
Patent Citations
Smart delivery of li data in emergency conditions
US20150049613A1
Method for providing a law enforcement agency with sampled content of communications
US20150341392A1