Methods, communication devices and system relating to performing lawful interception

By implementing unique identifiers in alarm issue reporting, the solution addresses the ambiguity in existing lawful interception systems, enabling clear and effective management of alarm issues within the system.

WO2025256759A1PCT designated stage Publication Date: 2025-12-18TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/066667
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-12-18

AI Technical Summary

Technical Problem

Existing lawful interception systems face challenges in accurately reporting and distinguishing between multiple alarm issues of the same type relating to a specific destination, leading to ambiguity and difficulty in determining which issues persist or have been resolved, hindering effective system administration.

Method used

The introduction of an Issue Correlation Number and enhanced Report Issue request messages, including unique identifiers, allows for precise identification and reporting of alarm issues, enabling clear distinction between different types of issues and their status, thereby facilitating accurate reporting to system administrators.

Benefits of technology

This solution enables unambiguous reporting of alarm issues, allowing system administrators to take appropriate recovery actions and ensuring that specific alarm statuses are correctly reported and managed within the lawful interception system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024066667_18122025_PF_FP_ABST
    Figure EP2024066667_18122025_PF_FP_ABST
Patent Text Reader

Abstract

A method (200) performed by a communication device hosting an element of lawful interception, ELI. The method comprises: receiving (202) an indication of an alarm Issue; assigning (204) an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing (206) a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending (208) the Report Issue request message to a lawful interception administration function, LI ADMF.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHODS, COMMUNICATION DEVICES AND SYSTEM RELATING TO

[0002] PERFORMING LAWFUL INTERCEPTION

[0003] Technical Field

[0004] The invention relates to a method performed by a communication device hosting an Element of Lawful Interception, a method performed by a communication device hosting a Lawful Interception Administration Function, a method of Issue reporting during lawful interception in a telecommunication network, communication devices, a lawful interception system implemented in a communication network, a corresponding computer program and a data carrier.

[0005] Background

[0006] Figure 1 shows an exemplary Lawful Interception, LI, network and system according to document ETSI GR NFV-SEC 011 V1.1.1 . Figure 1 shows a high-level architecture for lawful interception in a virtualized environment. Entities are logically represented, therefore it does not necessary reflect separate physical entities. Entities will be described herein for a non-virtualized environment and for a virtualized environment.

[0007] The exemplary LI system comprises a Law Enforcement Agency, LEA, network and a Communications Service Provider, CSP, network. LEA 101 is an organization authorized by a lawful authorization based on the applicable jurisdiction to request and receive the results of telecommunications interceptions of an interception target. The target is a person of interest and / or user equipment possessed or used by the person of interest being surveyed by the LEA 101 . Said LEA 101 communicates with the CSP network through a network interface, called Handover Interface, HI. LEA 101 comprises a Warrant Issuing Authority / Warrant Issuing Authority device 102 and a Law Enforcement Monitoring Facility, LEMF 103. The Warrant Issuing Authority 102 issues an intercept request, e.g. lawful authorization or warrant to the CSP through a first Handover Interface, HI1. The LEMF 103 collects the intercepted information of the interception target. The LEMF 103 communicates with an LI site 104 through a second Handover Interface, HI2, for receiving Intercept Related Information, IRI, and through a third Handover Interface, HI3, for receiving Content of Communication, CC. Interfaces HI1 , HI2, and HI3 are specified in more detail in the ETSI TS 102 232-1 V3.21 .1 standard, “Lawful Interception (LI); Part 1 : Internal Network Interface X1 for Lawful Interception”.

[0008] Entities within the CSP network communicate through internal network interfaces.

[0009] The LI site 104 comprises an LI Administration Function, ADMF, 105 and a Mediation and Delivery Function, MF / DF, 106. The LI ADMF 105 communicates with the MF / DF 106 through an X1_2 interface and an X1_3 interface. The LI ADMF 105 generate, based on said received intercept request, a warrant comprising one or more interception target identities, and send the warrant to a Point Of Interception, POI, 107, to a network element, NE, 108 (also known as an element of lawful interception, ELI) via an interface denoted by X1_1 ; the NE 108 is an entity that performs the interception. The POI 107 detects the interception target communication, derives the IRI or CC from the target communications, and delivers the POI Output to the MD / MF 106. POIs are divided into two types based on the type of data they send to the MF / DF 106: IRI-POI delivers Intercept Related Information to the MF through an X2 interface and CC-POI delivers CC to the MF through an X3 interface. IRI are collection of information or data associated with telecommunications services involving the interception target identity, specifically call associated information or data (e.g. unsuccessful call attempts), service associated information or data (e.g. service profile management by subscriber) and location information. The CC is information exchanged between two or more users of a telecommunications service, excluding IRI. The MF receives IRI and CC and transforms them from internal interface format to Handover Interface format. The DF will then handle dispatching of said data to the one or more designated LEAs 101 .

[0010] In a Network Functions Virtualization, NFV, environment, MF / DF 106 and POI 107 may be embedded within a Network Function, NF. In this scenario, an X1_DC interface is used by a virtualized POI, vPOl and virtualized MF / DF, vMF / vDF to inform each other of changes (e.g. scaling or mobility) in the virtualized environment. An NFV Management and Orchestration function, MANO, and / or a Security Orchestrator, SO, 109 handle the management and orchestration of all resources in a virtualized data center including computing, networking, storage, and virtual machine, VM, resources. An LI controller is responsible for creating, modifying, deleting, and auditing vPOl and vMF / vDF configuration during their lifecycle. The LI controller has two sub-functions: LI controller at network service application level, called LI App Controller 110, and LI controller at NFV level, called LI NFV controller 111 . LI App Controller 110 and LI ADMF 105 communicate through an Ll-Os-O interface; LI App controller 110 and vPOl 107 communicate through an X0_1 interface; LI App controller 110 and vMF / vDF 106 communicate through an X0_2 interface. The LI NFV controller 111 is managed by the LI App controller 110 via an LI-OS-1 interface. X1_DC, X0_1 , X0_2, LI-OS-O and LI-OS-1 interfaces are specified in more detail in ETSI GR NFV-SEC 01 1 V1 .1 .1.

[0011] A Lawful Interception Routing Proxy Gateway, LRPG, 112 can be used to provide a Handover Interface proxy function to isolate the LEMF 103 and prevent the LEMF 103 to be visible to MANO 109. This function is optional.

[0012] Figure 2 is a block diagram of an exemplary LI network and system according to document ETSI TS 103 221-1 , for example V1.14.1 . The exemplary LI system comprises a number of communication devices, which host an NE, 108 connected to the lawful interception ADMF 105 through the X1 interface, which is connected to a law enforcement agency, LEA, through the HI-1 interface.

[0013] According to the ETSI TS 103 221-1 standard, a command is sent from an LI ADMF to an NE as a “task”, such as “activate”, “modify” and “deactivate” on the X1 interface using a message structure defined in the standard, and the NE responds to the LI ADMF with a response message. The NE is manually provided (at installation and during network maintenance) with a specific destination for reporting alarm issues to the LI ADMF. Alarm issues can be reported using, for example ReportTasklssue, ReportDestinationlssue or ReportNEIssue requests sent by the NE to the LI ADMF on the X1 interface as a spontaneous notification. In case of any alarm issue (warning or fault) relating to a Task, a NE or a Destination to which intercepted traffic is delivered, the NE informs the LI ADMF with a related Reportxxxlssue request.

[0014] As defined at clause 6.5 ETSI TS 103 221-1 , for example V1.14.1 , The NE shall send a ReportTasklssue request when it becomes aware of an issue (warning or fault) relating specifically to a particular task identity, XID. The NE shall send a ReportDestinationlssue request when it becomes aware of an issue (warning or fault) relating specifically to a particular destination identity, DID. The NE shall send a ReportNEIssue request when it becomes aware of an issue (warning, alert or fault) relating to the whole NE.

[0015] Summary

[0016] It is an object to enable improved alarm issue status reporting by a lawful interception, LI, administrative function, ADMF, e.g. through improved certainty at the LI ADMF of alarm issue status, within a lawful interception system.

[0017] A first aspect provides a method performed by a communication device hosting an element of lawful interception, ELI. The method comprises receiving an indication of an alarm Issue. An Issue identifier is assigned to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue. The method further comprises preparing a Report Issue request message for reporting of the alarm Issue. The Report Issue request message includes the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue. The Report Issue request message is sent to a lawful interception administration function, LI ADMF.

[0018] Currently, in the case where an ELI reports more than one alarm issue of the same Issue type relating to the same destination to which intercepted traffic is delivered, lawful interception task or ELI, it is not possible for an LI ADMF to uniquely identify each alarm issue. The method advantageously enables a way for an LI ADMF to uniquely identify each alarm issue reported to it. This may enable the reporting of alarm issues without ambiguity.

[0019] In certain embodiments, the Issue identifier comprises at least one identifier identifying the ELI and at least one identifier identifying the alarm Issue. The Issue identifier may be an Issue Correlation Number comprising an Identification of the ELI, ELIID, and a number identifying the alarm Issue.

[0020] In certain embodiments, the Report Issue request message includes an Issue Identifier field. In certain embodiments, the Issue identifier is included in the Issue Identifier field. The Issue Identifier field may be an Issue Correlation Number field.

[0021] In certain embodiments, the Report Issue request message additionally includes a Report Type field. The indication of the Issue type is included in the Report Type field.

[0022] In certain embodiments, the Issue type is a type of alarm Issue which the ELI is required to report to the LI ADMF when the alarm Issue is cleared. The Issue type may be one of Warning, Non-terminating Fault, or Terminating Fault.

[0023] In certain embodiments, the method further comprises, in response to receiving an indication that the alarm Issue is cleared, preparing a further Report Issue request message including the Issue identifier and an indication that the alarm Issue is cleared. The further Report Issue request message is sent to the LI ADMF. Currently, it is only possible for an ELI to report to an LI ADMF that all alarm issues of the same Issue type relating to the same destination, task or ELI, are cleared. The method advantageously enables an ELI to report to an LI ADMF that a specific alarm Issue is cleared. This advantageously enables an LI ADMF to correctly know specific alarm status and to report that to a system administrator.

[0024] Adding an indication that the alarm Issue is cleared may comprise including a Specific Issue Clear Issue type in the Report Type field.

[0025] In certain embodiments, the alarm Issue is one of an alarm issue relating to the ELI, or an alarm issue relating to a Destination to which intercepted traffic is delivered by the ELI, or an alarm issue relating to a Task at the ELI.

[0026] In certain embodiments, the method further comprises, in response to receiving an indication that all non-terminating faults relating to one of the ELI or a specific Destination or a specific Task are cleared, preparing a further Report Issue request message including an indication that all non-terminating faults are cleared and having an empty Issue Identifier field. The further Report Issue request message, including the indication that all non-terminating faults are cleared, is sent to the LI ADMF. The method advantageously enables an ELI to report to an LI ADMG that all non-terminating faults relating to one of the ELI or a specific Destination or a specific Task are cleared.

[0027] The indication that all non-terminating faults are cleared may be an All Clear Issue type included in the Report Type field.

[0028] In certain embodiments, Report Issue request messages are one of a ReportTasklssueRequest for reporting an Issue relating to a Task at the ELI, a ReportNEIssueRequest for reporting an Issue relating to the ELI or a ReportDestinationlssueRequest for reporting an Issue relating to a Destination to which intercepted traffic is delivered by the ELI. The method may advantageously be applied to each of the types of ReportxxIssueRequest message specified in the ETSI TS 103 221-1 standard.

[0029] Corresponding embodiments and advantages apply also to the method of alarm Issue reporting during lawful interception in a telecommunication network, the communication device of the sixth aspect and the lawful interception system described below.

[0030] A second aspect provides a method performed by a communication device hosting a lawful interception, LI, administration function, ADMF. The method comprises receiving a Report Issue request message from an element of LI, ELI, the Report Issue request message reporting an alarm Issue. The method further comprises obtaining information indicative of the alarm Issue, an indication of an Issue type of the alarm issue and an Issue identifier of the alarm Issue from the Report Issue request message. The Issue identifier and the information indicative of the alarm Issue are stored. A Report Issue response message, in response to the Report Issue request message, is prepared and sent to the ELI.

[0031] The method advantageously enables an LI ADMF to correctly report specific ELI alarm status to a system administrator.

[0032] Corresponding advantages apply also to the method of alarm Issue reporting during lawful interception in a telecommunication network, the communication device of the seventh aspect and the lawful interception system described below. A third aspect provides a method of alarm Issue reporting during lawful interception in a telecommunication network. The method comprises the following at a communication device hosting an element of lawful interception, ELI. Receiving an indication of an alarm Issue and assigning an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue. A Report Issue request message for reporting of the alarm Issue is prepared. The Report Issue request message includes the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue. The Report Issue request message is sent to a lawful interception administration function, LI ADMF. The method further comprises the following at a communication device hosting the LI ADMF. Receiving the Report Issue request message from the ELI, the Report Issue request message reporting the alarm Issue. The information indicative of the alarm Issue, the indication of the Issue type of the alarm issue and the Issue identifier of the alarm Issue are obtained from the Report Issue request message. The Issue identifier and the information indicative of the alarm Issue are stored. A Report Issue response message is prepared in response to the Report Issue request message and the Report Issue response message is sent to the ELI.

[0033] The method advantageously enables a mechanism for correlating specific alarm issues reported by an ELI to an LI ADMF.

[0034] A fourth aspect provides a computer program comprising instructions which, when executed on a communication device, cause the communication device to carry out any of the above steps of any of the methods according to any of the first, second and third aspects.

[0035] A fourth aspect provides a data carrier having computer readable instructions embodied therein, the computer readable instructions for providing access to resources available on a communication device and the computer readable instructions comprising instructions to cause the communication device to perform any of the above steps of the methods according to any of the first, second and third aspects.

[0036] A sixth aspect provides a communication device comprising interface circuitry, at least one processor and memory. The memory comprises instructions which when performed by the at least one processor cause the communication device to perform the following element of lawful interception, ELI, operations. An operation of receiving an indication of an alarm Issue. An operation of assigning an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue. An operation of preparing a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue. An operation of sending the Report Issue request message to a lawful interception administration function, LI ADMF.

[0037] A seventh aspect provides a communication device comprising interface circuitry, at least one processor and memory. The memory comprises instructions which when performed by the at least one processor cause the communication device to perform the following lawful interception, LI, administrative function, ADMF, operations. An operation of receiving a Report Issue request message from an element of LI, ELI, the Report Issue request message reporting an alarm Issue. An operation of obtaining information indicative of the alarm Issue and an Issue identifier from the Report Issue request message. An operation of storing the Issue identifier and information indicative of the alarm Issue. An operation of preparing a Report Issue response message in response to the Report Issue request message. An operation of sending the Report Issue response message to the ELI.

[0038] An eighth aspect provides a lawful interception system in a telecommunication network, the system comprising a first communication device and a second communication device. The first communication device comprises interface circuitry, at least one processor and memory. The memory comprises instructions which when performed by the at least one processor cause the communication device to perform the following element of lawful interception, ELI, operations. An operation of receiving an indication of an alarm Issue. An operation of assigning an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue. An operation of preparing a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue. An operation of sending the Report Issue request message to a lawful interception administration function, LI ADMF. The second communication device comprises interface circuitry, at least one processor and memory. The memory comprises instructions which when performed by the at least one processor cause the communication device to perform the following lawful interception, LI, administrative function, ADMF, operations. An operation of receiving a Report Issue request message from an element of LI, ELI, the Report Issue request message reporting an alarm Issue. An operation of obtaining information indicative of the alarm Issue and an Issue identifier from the Report Issue request message. An operation of storing the Issue identifier and information indicative of the alarm Issue. An operation of preparing a Report Issue response message in response to the Report Issue request message. An operation of sending the Report Issue response message to the ELI.

[0039] Embodiments of the invention will now be described, by way of example only, with reference to the accompanying drawings.

[0040] Brief Description of the drawings

[0041] Figure 1 is a block diagram of an exemplary LI network and system according to prior art; Figure 2 is a block diagram of an exemplary LI network and system according to prior art;

[0042] Figures 3 to 5 are flowcharts illustrating a method performed by a communication device according to embodiments;

[0043] Figure 6 is a flowchart illustrating a method performed by a communication device according to embodiments;

[0044] Figures 7 and 8 are block diagrams depicting communication devices according to embodiments;

[0045] Figure 9 is a block diagram depicting a lawful interception system according to an embodiment; and Figures 10 to 12 are signalling diagrams illustrating exchanges of messages in embodiments of the invention.

[0046] Detailed description

[0047] The present disclosure relates to alarm handling within Lawful Interception, LI, which is handled via the X1 Internal Network Interface as defined in standard ETSI TS 103 221-1 , for example V1.14.1. According to the present disclosure, the problem that the can NE report more than one issue, each of a different type, relating to a specific DID, XID or NE on the X1 standard interface, has been identified. For example, in the case of multiple issues relating to the same DID, the NE may send multiple separate reportDestination Issue Request messages to the LI ADMF all including the same DID. Table 1 gives some example issues that may be notified from the ELI to the LI ADMF:

[0048] Table 1 : Example issues than may be notified from the ELI to the LI ADMF

[0049] As shown in Table 1 , it can happen that the NE reports different types of issues, for example (c), (e) and (h) in relation to a specific destination, identified by its DID (Destination I Dentity) on the X1 standard interface.

[0050] In such case, the NE will send three different reportDestinationlssue Request messages to the LI ADMF all including the same DID:

[0051] 1. DID = 1 ,

[0052] DestinationReportType=”Non-terminating fault”,

[0053] DestinationlssueErrorCode=9020,

[0054] Destination lssueDetails= “IAP is Unable To Setup X2 Interface”

[0055] 2. DID = 1 ,

[0056] DestinationReportType=”Non-terminating fault”,

[0057] DestinationlssueErrorCode=9020,

[0058] Destination lssueDetails= “X2 Communication Fault”

[0059] 3. DID = 1 ,

[0060] DestinationReportType=”Non-terminating fault”,

[0061] DestinationlssueErrorCode=9020,

[0062] DestinationlssueDetails= “IRI Buffer Overflow” According to the ETSI TS 103 221-1 standard it is only possible to report the complete clearing of all alarm issues relating to a specific DID, i.e. it is only possible for the NE to report to the LI ADMF that all alarm issues relating to that DID have ceased or have been resolved using a reportDestinationlssue, Request message:

[0063] 4. DID = 1 ,

[0064] DestinationReportType=”AII clear: non-terminating fault resolved. “

[0065] According to the present disclosure, the problem that a system administrator is not able to understand which alarm issues persist and which have cleared (i.e. ceased or been resolved), in order to take the proper recovery action, has been identified.

[0066] These needs are met by the features of the independent claims. Further aspects are described in the dependent claims.

[0067] The present disclosure provides enhancements to the LI Internal Network Interface X1 as specified in standard ETSI TS 103 221-1 , for example V1.14.1 , to allow an ADMF to correctly report specific ELI alarm status, allowing a system administrator to properly act on alarms relating to targets of interceptions, destinations to which intercepted traffic is delivered or generically to the ELI. The present disclosure provides a correlation mechanism among specific issues reported by an ELI to an LI ADMF. The present disclosure advantageously enables the reporting of alarm status without ambiguity and avoiding the use of proprietary mechanisms from different vendors.

[0068] The same reference numbers will be used for corresponding features in different embodiments.

[0069] Referring to Figure 3, an embodiment provides a method 200 performed by a communication device hosting an element of lawful interception, ELI. The method 200 comprises:

[0070] - receiving (202) an indication of an alarm Issue;

[0071] - assigning (204) an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue;

[0072] - preparing (206) a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and

[0073] - sending (208) the Report Issue request message to a lawful interception administration function, LI ADMF.

[0074] In certain embodiments, the Issue identifier comprises at least one identifier identifying the ELI and at least one identifier identifying the alarm Issue. The Issue identifier may be an Issue Correlation Number comprising an Identification of the ELI, ELIID, and a number identifying the alarm Issue.

[0075] In certain embodiments, the Report Issue request message includes an Issue Identifier field. The Issue Identifier field may be an Issue Correlation Number field. The Issue identifier may be included in the Issue Identifier field.

[0076] In certain embodiments, the Report Issue request message additionally includes a Report Type field. The indication of the Issue type is included in the Report Type field. In certain embodiments, the Issue type is a type of alarm Issue which the ELI is required to report to the LI ADMF when the alarm Issue is cleared. The alarm Issue may be an alarm issue relating to the ELI. The alarm Issue may be an alarm issue relating to a Destination to which intercepted traffic is delivered by the ELI. The alarm Issue may be an alarm issue relating to a Task at the ELI. The Issue type may be one of Warning, Non-terminating Fault, or Terminating Fault.

[0077] In certain embodiments, a report Issue request message is a ReportTasklssueRequest message for reporting an Issue relating to a Task at the ELI. For example, the ReportTasklssueRequest message format defined in Table 34 of the ETSI TS 103 221-1 standard, for example v14, for the LI X1 interface may be modified to include an IssueCorrelationNumber field, as illustrated in Table 34A below:

[0078] Table 34A: Modified ReportTasklssueRequest

[0079] As defined at clause 6.5.2 of ETSI TS 103 221-1 , for example V1 .14.1 , “the NE (ELI) shall send a ReportTasklssue request when it becomes aware of an issue (warning or fault) relating specifically to a particular XID”. Faults and warnings are defined in clause 5.3 of ETSI TS 103 221-1 , for example V1.14.1. The expression “receiving information indicative of an alarm issue” in the present disclosure should be understood to include the expression “becomes aware of an issue” used in the X1 standard.

[0080] The Issue type (“Type of Issue”) used in the present disclosure may be one of Warning, Nonterminating Fault, or Terminating Fault, as defined at clause 6.5.2.2 of ETSI TS 103 221-1 , for example V1.14.1.

[0081] In certain embodiments, a report Issue request message is a ReportDestinationlssueRequest message for reporting an Issue relating to a Destination to which intercepted traffic is delivered by the ELI. For example, the ReportDestinationlssueRequest message format defined in Table 36 of the ETSI TS 103 221-1 standard for the LI X1 interface may be modified to include an IssueCorrelationNumber field, as illustrated in Table 36A below:

[0082] Table 36A: Modified ReportDestinationlssueRequest

[0083] As defined at clause 6.5.3 of ETSI TS 103 221-1 , for example V1 .14.1 , “The NE shall send a ReportDestination Issue request when it becomes aware of an issue (warning or fault) relating specifically to a particular DID.” Faults and warnings are defined in clause 5.3 of ETSI TS 103 221-1 , for example V1 .14.1 . The expression “receiving information indicative of an alarm issue” in the present disclosure should be understood to include the expression “becomes aware of an issue” used in the X1 standard.

[0084] The Issue type (“Type of Issue”) used in the present disclosure may be one of Warning, Nonterminating Fault, or Terminating Fault, as defined at clause 6.5.2.2 of ETSI TS 103 221-1 , for example V1.14.1.

[0085] In the above example where the ELI (NE) receives indications of three different alarm issues, it will now send three different ReportDestinationlssueRequest messages to the LI ADMF all including the same DID but now each including a unique identifier, i.e. a unique Issue Correlation Number, in the IssueCorrelationNumber field of the modified ReportDestinationlssueRequest message:

[0086] 1. DID = 1 ,

[0087] DestinationReportType=”Non-terminating fault”,

[0088] DestinationlssueErrorCode=9020,

[0089] Destination lssueDetails= “IAP is Unable To Setup X2 Interface”, lssueCorrelationNumber=”123456”

[0090] 2. DID = 1 ,

[0091] DestinationReportType=”Non-terminating fault”

[0092] DestinationlssueErrorCode=9020,

[0093] Destination lssueDetails= “X2 Communication Fault” lssueCorrelationNumber=”123456”

[0094] 3. DID = 1 ,

[0095] DestinationReportType=”Non-terminating fault”,

[0096] DestinationlssueErrorCode=9020,

[0097] Destination lssueDetails= “IRI Buffer Overflow”, lssueCorrelationNumber=”123456”

[0098] In certain embodiments, a report Issue request message is a ReportNEIssueRequest message for reporting an Issue relating to the ELI. For example, the ReportNEIssueRequest message format defined in Table 38 of the ETSI TS 103 221-1 standard for the LI X1 interface may be modified to include an IssueCorrelationNumber field, as illustrated in Table 38A below: Table 38A: Modified ReportNEIssueRequest

[0099] As defined at clause 6.5.4 of ETSI TS 103 221-1 , for example V1 .14.1 , “The NE shall send a ReportNEIssue request when it becomes aware of an issue (warning or fault) relating to the whole NE.” Faults and warnings are defined in clause 5.3 of ETSI TS 103 221-1 , for example V1 .14.1 . The expression “receiving information indicative of an alarm issue” in the present disclosure should be understood to include the expression “becomes aware of an issue” used in the X1 standard.

[0100] As noted above, NE is equivalent to ELI in the present disclosure. The message may therefore be renamed ReportELIIssueRequest.

[0101] The Issue type (“Type of Issue”) used in the present disclosure may be one of Warning, Nonterminating Fault, or Terminating Fault, as defined at clause 6.5.2.2 of ETSI TS 103 221-1 , for example V1.14.1.

[0102] ELI issues can relate to:

[0103] Any hardware issue on ELI (storage nearly full, power issue).

[0104] Current security issue on ELI.

[0105] Any issues with logging or audit material.

[0106] Any report from manual changes to ELI configuration.

[0107] In a further embodiment, the method further comprises the following steps 300, illustrated in Figure 4, in response to receiving 302 an indication that the alarm Issue is cleared:

[0108] - preparing 304 a further Report Issue request message including the Issue identifier and an indication that the alarm Issue is cleared; and

[0109] - sending 306 the further Report Issue request message to the LI ADMF.

[0110] In certain embodiments, adding an indication that the alarm Issue is cleared comprises including a “Specific Issue Clear” Issue type in the Report Type field.

[0111] In certain embodiments, the further report Issue request message is a further ReportTasklssueRequest message. For example, the modified ReportTasklssueRequest message format shown in Table 34A above may be used. In certain embodiments, the further report Issue request message is a further ReportDestinationlssueRequest message. For example, the modified ReportDestinationlssueRequest message format shown in Table 36A above may be used.

[0112] For example,

[0113] 4. DID = 1 ,

[0114] DestinationReportType-’Specific Issue Clear”,

[0115] DestinationlssueErrorCode=9020,

[0116] Destination lssueDetails= “IAP is Unable To Setup X2 Interface”, lssueCorrelationNumber=”123456”

[0117] In certain embodiments, the further report Issue request message is a further ReportNEIssueRequest message. For example, the modified ReportNEIssueRequest message format shown in Table 38A above may be used.

[0118] In a further embodiment, the method further comprises the following steps 400, illustrated in Figure 5, in response to receiving 402 an indication that all non-terminating faults relating to one of the ELI or a specific Destination or a specific Task are cleared: preparing 404 a further Report Issue request message including an indication that all nonterminating faults are cleared and having an empty Issue Identifier field; and sending 410 the further Report Issue request message including the indication that all nonterminating faults are cleared to the LI ADMF.

[0119] In certain embodiments, the indication that all non-terminating faults are cleared is an “All Clear” Issue type included in the Report Type field.

[0120] In certain embodiments, the further report Issue request message is a further ReportTasklssueRequest message. For example, the modified ReportTasklssueRequest message format shown in Table 34A above may be used.

[0121] In certain embodiments, the further report Issue request message is a further ReportDestinationlssueRequest message. For example, the modified ReportDestinationlssueRequest message format shown in Table 36A above may be used.

[0122] For example,

[0123] 5. DID = 1 ,

[0124] DestinationReportType=”AII Clear”,

[0125] DestinationlssueErrorCode=,

[0126] Destination IssueDetails-”’,

[0127] IssueCorrelationNumber-’”

[0128] In certain embodiments, the further report Issue request message is a further ReportNEIssueRequest message. For example, the modified ReportNEIssueRequest message format shown in Table 38A above may be used.

[0129] Referring to Figure 6, a further embodiment provides a method 500 performed by a communication device hosting a lawful interception, LI, administration function, ADMF. The method comprises: receiving 502 a Report Issue request message from an element of LI, ELI, the Report Issue request message reporting an alarm Issue; obtaining 504 information indicative of the alarm Issue, an indication of an Issue type of the alarm issue and an Issue identifier of the alarm Issue from the Report Issue request message; storing 506 the Issue identifier and the information indicative of the alarm Issue; preparing 508 a Report Issue response message in response to the Report Issue request message; and sending 510 the Report Issue response message to the ELI.

[0130] Referring to Figures 3 and 6, a further embodiment provides a method of alarm Issue reporting during lawful interception in a telecommunication network.

[0131] The method comprises, at a communication device hosting an element of lawful interception, ELI: receiving 202 an indication of an alarm Issue; assigning 204 an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing 206 a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending 208 the Report Issue request message to a lawful interception administration function, LI ADMF.

[0132] The method further comprises, at a communication device hosting a lawful interception, LI, administrative function, ADMF: receiving 502 the Report Issue request message from the ELI, the Report Issue request message reporting the alarm Issue; obtaining 504 the information indicative of the alarm Issue, the indication of the Issue type of the alarm issue and the Issue identifier of the alarm Issue from the Report Issue request message; storing 506 the Issue identifier and the information indicative of the alarm Issue; preparing 508 a Report Issue response message in response to the Report Issue request message; and sending 510 the Report Issue response message to the ELI.

[0133] Referring to Figure 7, a further embodiment provides a communication device 600 comprising interface circuitry 602, a processor 604 and memory 606. The memory comprises instructions 608 which when performed by the processor cause the communication device to perform ELI operations of: receiving an indication of an alarm Issue; assigning an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending the Report Issue request message to a lawful interception administration function, LI ADMF.

[0134] A further embodiment provides a computer program 610 comprising instructions 608 which, when executed on a communication device 600, cause the communication device to carry out the method 200 described above with reference to Figures 3 to 5.

[0135] A further embodiment provides a data carrier 606 having computer readable instructions embodied therein. The computer readable instructions are for providing access to resources available on a communication device. The computer readable instructions comprising instructions to cause the communication device to perform the steps of the method 200 described above with reference to Figures 3 to 5.

[0136] Referring to Figure 8, a further embodiment provides a communication device 700 comprising interface circuitry 702, a processor 704 and memory 706. The memory 706 comprises instructions 708 which when performed by the processor cause the communication device to perform LI ADMF operations of: receiving a Report Issue request message from an ELI, the Report Issue request message reporting an alarm Issue; obtaining information indicative of the alarm Issue and an Issue identifier from the Report Issue request message; storing the Issue identifier and information indicative of the alarm Issue; preparing a Report Issue response message in response to the Report Issue request message; and sending the Report Issue response message to the ELI.

[0137] A further embodiment provides a computer program 710 comprising instructions 708 which, when executed on a communication device 700, cause the communication device to carry out the method 500 described above with reference to Figure 6.

[0138] A further embodiment provides a data carrier 706 having computer readable instructions embodied therein. The computer readable instructions are for providing access to resources available on a communication device. The computer readable instructions comprising instructions to cause the communication device to perform the steps of the method 500 described above with reference to Figure 6.

[0139] Referring to Figure 9, a further embodiment provides a lawful interception, LI, system 800 in a telecommunication network. The LI system comprises a first communication device 600 as described above and a second communication device 700 as described above.

[0140] Figure is a signalling diagram illustrating a method, according to a further embodiment, of Task Issue reporting during lawful interception in a telecommunication network. The method comprises, at a communication device 600 hosting an ELI: receiving 202 an indication of an alarm Issue relating to a Task; assigning 204 an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing a ReportTasklssueRequest message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending 820 the ReportTasklssueRequest message to an LI ADMF.

[0141] The method further comprises, at a communication device 700 hosting an LI ADMF: receiving the ReportTasklssueRequest message from the ELI, the Report Issue request message reporting the alarm Issue; obtaining 504 the information indicative of the alarm Issue, the indication of the Issue type of the alarm issue and the Issue identifier of the alarm Issue from the ReportTasklssueRequest message; storing 506 the Issue identifier and the information indicative of the alarm Issue; preparing a ReportTasklssueResponse message in response to the Report Issue request message; and sending 822 the ReportTasklssueResponse message to the ELI.

[0142] In certain embodiments, the ReportTasklssueResponse message format defined in Table 35 of the ETSI TS 103 221-1 standard, for example v14, is used.

[0143] Figure 11 is a signalling diagram illustrating a method, according to a further embodiment, of Destination Issue reporting during lawful interception in a telecommunication network.

[0144] The method comprises, at a communication device 600 hosting an ELI: receiving 202 an indication of an alarm Issue relating to a specific Destination; assigning 204 an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing a ReportDestinationlssueRequest message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending 820 the ReportDestinationlssueRequest message to an LI ADMF.

[0145] The method further comprises, at a communication device 700 hosting an LI ADMF: receiving the ReportDestinationlssueRequest message from the ELI, the Report Issue request message reporting the alarm Issue; obtaining 504 the information indicative of the alarm Issue, the indication of the Issue type of the alarm issue and the Issue identifier of the alarm Issue from the ReportDestinationlssueRequest message; storing 506 the Issue identifier and the information indicative of the alarm Issue; preparing a ReportDestinationlssueResponse message in response to the Report Issue request message; and sending 822 the ReportDestinationlssueResponse message to the ELI.

[0146] In certain embodiments, the ReportDestinationlssueResponse message format defined in Table

[0147] 37 of the ETSI TS 103 221-1 standard, for example v14, is used.

[0148] Figure 12 is a signalling diagram illustrating a method, according to a further embodiment, of ELI Issue reporting during lawful interception in a telecommunication network.

[0149] The method comprises, at a communication device 600 hosting an ELI: receiving 202 an indication of an alarm Issue relating to the ELI; assigning 204 an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing a ReportNEIssueRequest message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending 820 the ReportNEIssueRequest message to an LI ADMF.

[0150] The method further comprises, at a communication device 700 hosting an LI ADMF: receiving the ReportNEIssueRequest message from the ELI, the Report Issue request message reporting the alarm Issue; obtaining 504 the information indicative of the alarm Issue, the indication of the Issue type of the alarm issue and the Issue identifier of the alarm Issue from the ReportNEIssueRequest message; storing 506 the Issue identifier and the information indicative of the alarm Issue; preparing a ReportNEIssueResponse message in response to the Report Issue request message; and sending 822 the ReportNEssueResponse message to the ELI.

[0151] In certain embodiments, the ReportNEIssueResponse message format defined in Table 39 of the ETSI TS 103 221-1 standard, for example v14, is used.

[0152] Abbreviations and Definitions:

[0153] LI: Lawful Interception.

[0154] LEA: Law enforcement agency.

[0155] LEMF: Law Enforcement Monitoring Function (managed by the LEA).

[0156] CSP: Communication Service Provider.

[0157] X1 : LI interfaces internal to the CSP for management tasking.

[0158] X2: LI interfaces internal to the CSP for delivery of interception related information, xIRI.

[0159] X3: LI interfaces internal to the CSP for delivery of content of communications that are intercepted, xCC.

[0160] POI: Point of interception (also known as IAP, interception access point).

[0161] Element of LI: an element that performs an LI function (equivalent to network element, NE, or POI / IAP) ELIID: the ID of the Element of LI that is tasked to perform any LI function. LI ADMF: the LI Administrative Function is the heart of the LI system. It is responsible for controlling the other LI functions within the CSP’s network, in response to warrant and tasking information received from the LEA administrative function.

[0162] Task: continuous instance of interception at a single ELI carried out against a set of target identifiers, identified by an X1 Identifier, starting from an activate command and ending with a deactivate command or terminating fault.

[0163] XID: X1 Identifier that Uniquely identifies a Task.

[0164] Destination: point to which xIRI and / or xCC is delivered by the NE. Intercepted traffic is delivered by the ELI to a Destination. Each Destination is uniquely identified by a Destination Identifier (DID) and is handled independently from details of the Task.

[0165] Destination IDentifier (DID): identifier to uniquely identify a Destination internally to the X1 interface.

[0166] Issue: A Warning or Fault. Issues may be relating to a particular XID, relating to a particular DID or relating to the whole ELI performing the interception.

[0167] Terminating fault: a fault signalled from ELI to ADMF which terminates a specific Task.

Claims

CLAIMS1 . A method (200) performed by a communication device hosting an element of lawful interception, ELI, the method comprising: receiving (202) an indication of an alarm Issue; assigning (204) an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing (206) a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending (208) the Report Issue request message to a lawful interception administration function, LI ADMF.

2. The method of claim 1 , wherein the Issue identifier comprises at least one identifier identifying the ELI and at least one identifier identifying the alarm Issue.

3. The method of claim 2, wherein the Issue identifier is an Issue Correlation Number comprising an Identification of the ELI, ELIID, and a number identifying the alarm Issue.

4. The method of any one of claims 1 to 3 wherein the Report Issue request message includes an Issue Identifier field.

5. The method of claim 4, wherein the Issue Identifier field is an Issue Correlation Number field.

6. The method of any one of claim 4 or claim 5, wherein the Issue identifier is included in the Issue Identifier field.

7. The method of any one of claims 1 to 6, wherein the Report Issue request message additionally includes a Report Type field and the indication of the Issue type is included in the Report Type field.

8. The method of any one of claims 1 to 7, wherein the Issue type is a type of alarm Issue which the ELI is required to report to the LI ADMF when the alarm Issue is cleared.

9. The method of claim 8, wherein the Issue type is one of Warning, Non-terminating Fault, or Terminating Fault.

10. The method of any one of claims 7 to 9, further comprising, in response to receiving (302) an indication that the alarm Issue is cleared:preparing (304) a further Report Issue request message including the Issue identifier and an indication that the alarm Issue is cleared; and sending (306) the further Report Issue request message to the LI ADMF.11 . The method of claim 10 and claim 8, wherein adding an indication that the alarm Issue is cleared comprises including a Specific Issue Clear Issue type in the Report Type field.

12. The method of any one of claims 1 to 11 , wherein the alarm Issue is one of an alarm issue relating to the ELI, or an alarm issue relating to a Destination to which intercepted traffic is delivered by the ELI, or an alarm issue relating to a Task at the ELI.

13. The method of claim 12, any one of claim 4 or claim 5, and any one of claims 6 to 8, further comprising, in response to receiving (402) an indication that all nonterminating faults relating to one of the ELI or a specific Destination or a specific Task are cleared: preparing (404) a further Report Issue request message including an indication that all non-terminating faults are cleared and having an empty Issue Identifier field; and sending (410) the further Report Issue request message including the indication that all non-terminating faults are cleared to the LI ADMF.

14. The method of claim 13 and claim 8, wherein the indication that all non-terminating faults are cleared is an All Clear Issue type included in the Report Type field.

15. The method of any one of claims 1 to 14, wherein Report Issue request messages are one of a ReportTasklssueRequest for reporting an Issue relating to a Task at the ELI, a ReportNEIssueRequest for reporting an Issue relating to the ELI or a ReportDestinationlssueRequest for reporting an Issue relating to a Destination to which intercepted traffic is delivered by the ELI.

16. A method (500) performed by a communication device hosting a lawful interception, LI, administration function, ADMF, the method comprising: receiving (502) a Report Issue request message from an element of LI, ELI, the Report Issue request message reporting an alarm Issue; obtaining (504) information indicative of the alarm Issue, an indication of an Issue type of the alarm issue and an Issue identifier of the alarm Issue from the Report Issue request message; storing (506) the Issue identifier and the information indicative of the alarm Issue; preparing (508) a Report Issue response message in response to the Report Issue request message; andsending (510) the Report Issue response message to the ELI.

17. A method of alarm Issue reporting during lawful interception in a telecommunication network, the method comprising: at a communication device hosting an element of lawful interception, ELI: receiving (202) an indication of an alarm Issue; assigning (204) an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing (206) a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending (208) the Report Issue request message to a lawful interception administration function, LI ADMF; and at a communication device hosting a lawful interception, LI, administrative function, ADMF: receiving (502) the Report Issue request message from the ELI, the Report Issue request message reporting the alarm Issue; obtaining (504) the information indicative of the alarm Issue, the indication of the Issue type of the alarm issue and the Issue identifier of the alarm Issue from the Report Issue request message; storing (506) the Issue identifier and the information indicative of the alarm Issue; preparing (508) a Report Issue response message in response to the Report Issue request message; and sending (510) the Report Issue response message to the ELI.

18. A computer program (610, 710) comprising instructions (608, 708) which, when executed on a communication device (600, 700), cause the communication device to carry out the method according to any one of claims 1 to 17.

19. A data carrier (606, 706) having computer readable instructions embodied therein, the computer readable instructions for providing access to resources available on a communication device and the computer readable instructions comprising instructions to cause the communication device to perform the steps of the method according to any one of claims 1 to 17.

20. A communication device (600) comprising interface circuitry (602), at least one processor (604) and memory (606) comprising instructions (608) which when performed by the at least one processor cause the communication device to perform element of lawful interception, ELI, operations of: receiving an indication of an alarm Issue;assigning an Issue identifier to the alarm Issue, wherein the Issue identifier uniquely identifies the alarm Issue; preparing a Report Issue request message for reporting of the alarm Issue, the Report Issue request message including the Issue identifier, an indication of an Issue type of the alarm Issue and information indicative of the alarm Issue; and sending the Report Issue request message to a lawful interception administration function, LI ADMF.21 . A communication device (700) comprising interface circuitry (702) , at least one processor (704) and memory (706) comprising instructions (708) which when performed by the at least one processor cause the communication device to perform lawful interception, LI, administrative function, ADMF, operations of: receiving a Report Issue request message from an element of LI, ELI, the Report Issue request message reporting an alarm Issue; obtaining information indicative of the alarm Issue and an Issue identifier from the Report Issue request message; storing the Issue identifier and information indicative of the alarm Issue; preparing a Report Issue response message in response to the Report Issue request message; and sending the Report Issue response message to the ELI.

22. A lawful interception system (800) in a telecommunication network, the system comprising a first communication device (600) according to claim 20 and a second communication device (700) according to claim 21 .

Citation Information

Patent Citations

  • Methods, system and communication devices related to lawful interception

    EP4169219B1

  • Methods, Communication Devices and System Relating to Performing Lawful Interception

    US20230370501A1