Element of lawful intercept as a point of intercept for multiple network functions
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2026-08-13
Smart Images

Figure EP2025053461_13082026_PF_FP_ABST
Abstract
Description
[0001] ELEMENT OF LAWFUL INTERCEPT AS A POINT OF INTERCEPT FOR MULTIPLE NETWORK FUNCTIONS
[0002] TECHNICAL FIELD
[0003] The disclosure relates to methods for enabling an element of lawful intercept (ELI) to act as a point of intercept (POI) for multiple network functions in Lawful Interception (LI), performed by a network node in a communication network. The disclosure also relates to network nodes, computer program, and computer program products configured to perform the same.
[0004] BACKGROUND
[0005] European Telecommunications Standards Institute (ETSI) Technical Specification (TS) 104007 Vl.1.1 (2024-11) on Lawful Interception Architecture, specifies that one ELI is defined for each Network Function (NF), regardless of the location of the physical infrastructure that hosts the multiple NFs. Therefore, for each NF, there is an instance of its corresponding ELI, a copy of the targets, and at least a separate interface for each Xi interface for each NF. If more than one Destination Identifier (DID) is indicated for an Xi interface, than there would consequently be additional interfaces.
[0006] ETSI TS 104007 Vl.1.1 (2024-11) also discloses how attestation and provisioning of different parts, function and / or components, of the LI infrastructure is performed, and identifiers of the different parts, function and / or components. For example, a POI is identified by an ELI ID, an NF is identified by a NF ID. The Mediation and Delivery Function (MDF) is also identified by an ELI ID. The LI Provisioning Function (LIPF) is able to acquire NF IDs and ELI IDs and to use them to identify a POI and MDF functions. The identifiers are necessary to ensure that ELIs are correctly provisioned and are used between trust domains.
[0007] ETSI Group Report (GR) NFV-MAN 001 Vl.2.1 (2021-12) on Network Functions Virtualisation (NFV), Management and Orchestration, Report on Management and Orchestration Framework, described the management and orchestration framework for the provisioning of Virtualised Network Function (VNF), and the related operations.such as the configuration of the virtualised network functions and the infrastructure these functions run on, i.e., a virtual infrastructure.
[0008] ETSI GR NFV-SEC 011 Vl.1.1 (2018-04) on Network Functions Virtualisation (NFV), Security and Report on NFV LI Architecture, describes LI architectures with particular attention to the security aspects of the LI architecture, and particularly with regards to Virtual NFs. Clause 6.2 discloses that it is possible to send information about a target under monitoring to a virtual POI (vPOI) when a virtual NF (VNF) is in a trusted environment. Clause 6.3 discloses that is not possible to send information about a target under monitoring to the vPOI, when the VNF, associated with the vPOI, is in a Low-Trust environment. Instead, a Target Control Function (TCF), which is associated with one vPOI and its associated VNF, receives task information from an Admin Function (ADMF) via an XI interface. The vPOI communicates with its associated TCF via another XI interface.
[0009] ETSI Group Specification (GS) NFV-IFA 026 V5.2.1 (2024-12) on Network Functions Virtualisation (NFV) Release 5 Management and Orchestration, and Architecture enhancement for Security Management Specification, describes the two main trust domains of LI: the Network T rust domain (TD-A), which relates to the customer serving (CSP) network, and the LI T rust domain (TD-B), which relates to the LI elements in the CSP network.
[0010] SUMMARY
[0011] An object of the invention is to enable an ELI to act as a POI for multiple NFs.
[0012] According to a first aspect of the invention, there is provided a method for enabling an Element of Lawful Intercept, ELI, to act as a Point of Intercept, POI, for a plurality of Network Functions, NFs. The method is performed by the ELI. The ELI is hosted in a Virtual Infrastructure, VI, hosting the plurality of NFs. The method comprises receiving a task, via an XI interface, from a lawful interception, LI, administrative function, ADMF. The task comprises a target identifier, task details indicating which one or more NFs of the plurality of NFs for which the task is applicable, and one or more destinationidentifiers, DIDs. The method further comprises storing the task in the ELI, and receiving a request message, via a QI interface, from a NF of the plurality of NFs. The request message comprises an identifier of a communication entity. The method further comprises determining, based on said received request message and a task stored in the ELI, if said NF having sent said received request message is to intercept traffic of the communication entity, and if said NF is to intercept traffic of the communication entity, transmitting an indication message, via the QI interface, to said NF. The indication message indicates that traffic of the communication entity is to be intercepted. The method further comprises receiving, via an X2 and / or an X3 interface, from said NF, intercepted traffic of said communication entity, and forwarding, via an X2 and / or an X3 interface, the intercepted traffic to a mediation and delivery function, MDF.
[0013] According to a second aspect of the invention, there is provided a network node that implements an ELI. The ELI is configured as a POI for a plurality of NFs. The ELI is hosted in a VI hosting the plurality of NFs. The ELI is configured to receive a task, via an XI interface, from a LI ADMF. The task comprises a target identifier, task details indicating which one or more NFs of the plurality of NFs for which the task is applicable, and one or more DIDs. The ELI is further configured to store the task in the ELI, and to receive a request message, via a QI interface, from a NF of the plurality of NFs. The request message comprises an identifier of a communication entity. The ELI is further configured to determine, based on said received request message and a task stored in the ELI, if said NF having sent said received request message is to intercept traffic of the communication entity, and if said NF is to intercept traffic of the communication entity, to transmit an indication message, via the QI interface, to said NF. The indication message indicates that traffic of the communication entity is to be intercepted. The ELI is further configured to receive, via an X2 and / or an X3 interface, from said NF, intercepted traffic of said communication entity, and to forward, via an X2 and / or an X3 interface, the intercepted traffic to an MDF.
[0014] According to a third aspect of the invention, there is provided a method for enabling an ELI to act as a POI for a plurality of NFs. The method is performed by an LI ADMF. TheELI is hosted in a VI hosting the plurality of NFs. The method comprises attesting, via an X0 interface, the ELI, provisioning, via an XI interface, the ELI, and sending a task, via the XI interface, to the ELL The task comprises a target identifier, task details indicating which one or more NFs of the plurality of NFs for which the task is applicable, and one or more destination identifiers, DIDs.
[0015] According to a fourth aspect of the invention, there is provided network node that implements an LI ADMF. The ADMF is configured to attest, via an X0 interface, an ELL The ELI is configured as a POI for a plurality of NFs. The ELI is hosted in a VI hosting the plurality of NFs. The ADMF is further configured to provision, via an XI interface, the ELI, and to send a task, via the XI interface, to the, ELL The task comprises a target identifier, task details indicating which one or more NFs of the plurality of NFs for which the task is applicable, and one or more destination identifiers, DIDs.
[0016] According to a fifth aspect of the invention, there is provided a computer program comprising instructions which, when executed by a processing circuitry of a network node, or a system, cause the network node or the system to perform a method according to the first or third aspect of the invention.
[0017] According to a sixth aspect of the invention, there is provided a carrier containing a computer program according to the fifth aspect of the invention, is stored. The carrier is one of wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium.
[0018] BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The above, as well as additional objects, features, and advantages of the invention, will be better understood through the following illustrative and non-limiting detailed description of embodiments of the invention, with reference to the appended drawings, in which:
[0020] Figure 1 illustrates an example of a Lawful Intercept architecture.
[0021] Figure 2 illustrates an example of a Lawful Intercept architecture.
[0022] Figure 3 illustrates an example of a method according to the present disclosure.Figure 4 illustrates an example of a method according to the present disclosure. Figure 5 illustrates a signalling diagram between a Network Function, an Element of Lawful Intercept and a Lawful Intercept Administrative Function.
[0023] Figure 6 illustrates an example of a network node according to the present disclosure.
[0024] Figure 7 illustrates an example of a network node according to the present disclosure.
[0025] All the figures are schematic, not necessarily to scale, and generally only show parts which are necessary to elucidate the invention, whereas other parts may be omitted or merely suggested.
[0026] DETAILED DESCRIPTION
[0027] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, those skilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure. The invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art
[0028] Note that the description given herein focuses on both European Telecommunications Standards Institute (ETSI) systems and Third Generation Partnership Project (3GPP) cellular communications systems. Therefore, ETSI and 3GPP terminology or terminology similar to ETSI or 3GPP terminology is oftentimes used. However, the concepts disclosed herein are not limited to ETSI or 3GPP systems. Further, the description herein may use ETSI terminology and 3GPP terminology interchangeably, when referring to entities which may have different names in ETSI and 3GPP. Forexample, the terms "Network Element" (NE) and "Network Function" (NF) may be used interchangeably throughout this description.
[0029] As used herein, a "network node" can be any type of apparatus / device in a core network or any apparatus / device that implements a core network function. Some examples of a core network node include, a computer or server host for e.g., a Mobility Management Entity (MME), a Packet Data Network Gateway (P-GW), a Service Capability Exposure Function (SCEF), a Home Subscriber Server (HSS), or the like. Some other examples of a core network node include a node implementing an Access and Mobility Management Function (AMF), a User Plane Function (UPF), a Session Management Function (SMF), an Authentication Server Function (AUSF), a Network Slice Selection Function (NSSF), a Network Exposure Function (NEF), a NetworkRepository Function (NRF), a Policy Control Function (PCF), a Unified Data Management (UDM), or the like. In the following description, when stating that any of these functions, such as Element of Lawful Intercept (LI, ELI), Point of Intercept (POI) function, or Administration Function (ADMF), perform an action, such as receiving / matching / performing / configuring then it is to be understood that it is in practice the network node / computer / server host / POI function device / LI ADMF device that hosts the POI and ADMF, respectively, that performs the action.
[0030] As use herein, the terms "ELI ID", or "ELIID" and "NF ID", or "NFID", should be understood as they are defined in ETSI TS 104000 Vl.1.1 (2024-11) and ETSI TS 104 007 Vl.1.1 (2024-11).
[0031] Figure 1 illustrates an LI infrastructure. The LI infrastructure illustrated in Figure 1 is defined in ETSI TS 104007 Vl.1.1 (2024-11) which provides further details on the LI infrastructure. The LI infrastructure illustrated is a Virtual Infrastructure (VI), as defined in ETSI GR NFV-MAN 001 Vl.2.1 (2021-12). Thereby, it is to be understood that one, some, or all of the NFs shown in Figure 1 may be virtualized NFs (VNFs). The Virtual Infrastructure may be a Network Functions Virtualisation Infrastructure (NFVI).The LI infrastructure in Figure 1 includes two trust domains. Trust Domain A (TD-A) and T rust Domain B (TD-B), as indicated by the dashed boxes. The TD-A is the network trust domain and contains the network itself and includes Operations Support Systems / Business Support Systems (OSS / BSS) 103, and all the standard NFs 101 that make up a communication network. Layer-wise, the TD-A includes both the infrastructure / virtualization layer, which are managed by a Management and Orchestration (MANO) 104, as well as the application layer NFs 101, which may be implemented as virtual functions, or virtual network functions (VNFs) that provide communication services to users. The TD-B is the LI trust domain is one of the most sensitive trust domains in the network. TD-B contains highly sensitive and correlated information on Law Enforcement Agencies (LEAs), warrants, targets, and in-network Ll-cleared administrator accounts. Functions in this domain may be virtualized, but, if they are, they may be virtualized in their own segregated cloud for better isolation.
[0032] The TD-A may include sub-TDs, such as TD-A1, TD-A2, and TD-A3. However, the sub-TDs are not illustrated in Figure 1. TD-A1 may contain the OSS / BSS 103, which may include an OS-LI OSS-layer LI management function, a root Certificate Authority (CA) for the Communication Service Provider (CSP) of the network, and a core of the attestation system. The TD-A2 may contain the application layer of the network. The TD-A3 may contain the virtual layer of the network, which may include virtual NFs 101 and the MANO 104.
[0033] TD-B, as illustrated in Figure 1, includes the four sub-TDs TD-B1, TD-B2, TD-B3, and TD-B5. However, the TD-B may comprise additional sub-TDs, such as TD-B4. TD-B1 may be the domain with the primary role of segregating the most important assets (warrants, targets. Law Enforcement Agencies (LEAs), etc.) of the LI domain. TD-B2 holds the trust state of LI elements in the network, and contains the trust / validation state of LI in the network, as well as the certification mechanisms. TD-B3 is a buffer domain that separates the more sensitive sub-domains in TD-B (TD-B1 and TD-B2) from the network at large. TD-B3 contains cross-trust-domain gateways (not shown), the LI gateway (LIGW) 210-3, which ingests a standard, non-LI interface, and the LI provisioning function (LIPF) 210-2, which firewalls LI functions distributed throughoutthe network and holds the mappings of the LI elements to the NFs 101. TD-B5 is a "demilitarized zone" (DMZ) between the CSP and the LEA. TD-B5 hosts firewalls that interface the two domains and protect LEA delivery addresses and topology from the Mediation and Delivery Functions (MDFs), which are still part of the network.
[0034] TD-A, as illustrated in Figure 1, includes the OSS / BSS 103 and the MANO 104. The MANO 104, may be a Network Function Virtualization (NFV) MANO. The OSS / BSS 103 and the MANO 104 are configured to communicate via an interface which may be an Os-Mano interface or an Os-Ma-Nfvo interface. TD-A further includes a MANO Gateway (MOGW) 105.
[0035] TD-B, as illustrated in Figure 1, includes an Administration Function (ADMF) 210. The ADMF 210 comprises a LI Control function (LICF) 210-1, a LI Provisioning Function (LIPF) 210-2 and a LI Gateway (LIGW) 210-3. The LICF 210-1 is contained in the TD-Bl. The LIPF 210-2 and the LIGW 210-3 are contained in the TD-B2. Therefore, the ADMF 210 can be understood as being contained in the TD-B1 and the TD-B2. The LIGW 210-3 and the LIPF 210-2 may be configured to communicate via an Oss-Li interface. The LIPF 210-2 and the LICF 210-1 are configured to communicate via a XI interface. The LIPF 210-2 and the LICF 210-1 may be further configured to communicate via an Oss-Li interface, a LI-Network Output (LI-NO) interface and / or a LIPF-C interface.
[0036] TD-B further includes a Mediation and Delivery Function (MDF) 212, which is an Element of LI, and a LI Routing Proxy Gateway (LRPG) 114. The MDF 212 is illustrated in Figure 1 to be contained in TD-B3 and the LRPG 214 is illustrated in Figure 1 to be contained in TD-B5. The MDF 212 and the LRPG 214 are configured to communicate via a Handover Interface 2 (HI2) and a Handover Interface 3 (HI3).
[0037] The ADMF 210 is configured to receive a warrant over a Handover Interface 1 (HI1). The warrant may be received from a Warrant Issuing Authority (not shown). The warrant may be sent from the Warrant Issuing Authority via the LRPG 214. The LRPG 214 is further configured to communicate with a Law Enforcement Monitoring Facility(LEMF) 220 via a HI2 and a HI3. The Warrant Issuing Authority and the LEMF 220 may be contained in a Trust Domain different from TD-A and TD-B, which may be understood as T rust Domain C (TD-C) or a trust domain managed by a Law Enforcement Agency (LEA).
[0038] Each NF 101 has a defined, or associated, ELI 102, regardless of the location in a physical infrastructure that hosts the NF, or the Component Network Function CNF. This further means that for each NF 101, there is a copy of targets, i.e., target database, and separate XI, X2, and X3 interfaces. However, if more than one Destination Identifier (DID) is indicated for a XI, X2, and / or X3 interface, then there would be additional XI-X3 interfaces for that NF. Further, the targets are very commonly the same for different NFs 101, or at least sharing many of targets.
[0039] An ELI 102-2 which is close to, or hosted in / by, a NF 101-2 (or VNF) is called a Point of Interception POL The ELI 102-2, which illustrated as being inside the NF 101-2, may be understood as being close to, or hosted in the NF 101-2, and may therefore be understood as a POL If the NF 101-2 is in a trusted environment, then it is possible to send, from the ADMF and via the XI interface, information about a target under monitoring to its defined ELI 102-2.
[0040] However, if an NF 101-1 is in a low-trust environment, i.e., not a trusted environment, then it is not possible to send, from the ADMF and via the XI interface, information about a target under monitoring directly to a POI of the NF 101-1, since the POI is also in the low-trust environment. Therefore, the use of an ELI 102-1 which is configured as a Triggering Control Function (TCF) is required. The ELI 102-1, configured as a TCF, is hosted in a trusted environment such that all sensitive information stored in the ELI 102-1 is stored in a trusted environment. The ELI 102-1, configured as a TCF, receives information from the ADMF via an XI interface. Each TCF is associated with a POL Therefore, it may be understood that the NF 101-1, which is in a low-trust environment, has an associated POI (not shown) which is associated with the ELI 102-1 which is configured as a TCF. While using a TCF decreases security risk in low-trust environmentdeployment scenarios, the TCF introduces triggering delays and may place significant restrictions on (V)NF mobility and routing configurations.
[0041] The MOGW 105 is responsible for converting MANO NFV events into events usable by the LI network overlay to ensure that the correct ELIs 110 are paired with the correct NFs 101 both at the virtual and application layers. The MOGW 105 translates virtual network outputs from ETSI NFV deployments, or others, into the standard LI-NO interface to the ADMF 210. The MOGW 105 is communicatively connected to the ADMF 210, and may be communicatively connected to the LIPF.
[0042] The LI architecture as illustrated in Figure 1, and as defined in ETSI TS 104007 Vl.1.1 (2024-11), has a few limitations and efficiencies which will be discussed in the description relating to Figure 2.
[0043] Figure 2 illustrates an LI infrastructure. The LI infrastructure illustrated in Figure 2 shares a lot of similarities with the LI infrastructure illustrated in Figure 1. Therefore, reference to Figure 1 and the description relating thereto is made for a better understanding of the LI infrastructure illustrated in Figure 2.
[0044] A difference between the LI infrastructures shown in Figures 1 and 2 is that the LI infrastructure illustrated in Figure 2 comprises an ELI 110 which is configured as a POI for a plurality of NFs 101. The ELI 110 may be understood as a Multi POI (MPOI) 110. For an increased legibility, the ELI 110 will hereinafter be referred to as the MPOI 110. However, it is to be understood that the ELI 110 is not limited to being configured, or referred to, as a MPOI 110.
[0045] The MPOI 110 may comprise a Mediation Function Proxy (MDFP) 111 and / or a Target Repository Component (TRC) 112. The MPOI 110 may be contained in the sub-TD TD-Al of TD-A.
[0046] The MPOI 110 is associated with one or more NFs 101-1, 101-2, and is communicatively connected to the NFs via a 01 interface, an X2 interface, and an X3interface. The connection between the MPOI 110 and NFs 101-1, 101-2 is done in in the same, or similar manner, as is described in ETSI GS NFV-IFA 026 V5.2.1 (2024-12) with regards to how an NF is connected to an ELI-POL
[0047] The MPOI 110 is associated and connected with all NFs 101-1, 101-2 of a Virtual Infrastructure, VI, hosting the NFs 101-1, 101-2 and the MPOI 110. Correspondingly, all NFs 101-1, 101-2 in a VI use the MPO 110 as their respective POL
[0048] The X2 interface and the X3 interface between the NFs 101-1, 101-2 and the MPOI 110 may be an internal X2_L interface and an internal X3_L interface, respectively. The X2_L and X3_L interfaces may be understood as local interfaces between the NFs 101 and the MPOI 110 within the virtual infrastructure. A difference between the X2 interface and the internal X2_L interface, and the X3 interface and the internal X3_L interface, respectively, is that the internal X2_L and X3_L interfaces may comprise raw data and / or media. The MPOI 110 may be configured to receive the raw data and / or media via the internal X2_L and X3_L interfaces and may then be configured to add additional data to the raw data and / or media as required by the standards regarding the X2 and X3 interfaces, thereby enabling the MPO 110 to send the data and / or media received from the NFS 101 to the ADMF 210 via the X2 and X3 interfaces. A benefit of using the internal X2_L and / or X3_L interfaces is that it may reduce the amount of traffic, or data, communicated within the virtual infrastructure.
[0049] The MPOI 110 is a new type of NF, which needs to be instantiated, attested, and provisioned. The MPOI 110 may be instantiated by the Network Function Virtualization, NFV, MANO 104, or a function of the MANO 104. The MPOI 110 may be attested via an X0 interface. The MPOI 110 may be provisioned by the LIPF 210-2 of the ADMF 210 via the XI, or X1_E, interface. The MPOI 110 is identified by the MANO 104 as a NF, and as it is an ELI (for one or more NFs 101) it is attested and configured via the X0 interface.
[0050] The MPOI 110 is configured to receive a task, via the XI interface, from the LI ADMF 210. The XI interface may be an enhanced X1_E interface. The task may be received from the LIPF 210-2 of the ADMF 210. The task comprises a target identifier, taskdetails indicating which one or more NFs 101 for which the task is applicable, and one or more destination identifiers, DIDs. The task may comprise a TaskObject and / or a TaskDetailsExtensions. The task details may be comprised by the TaskObject and / or the TaskDetailsExtensions.
[0051] The MPOI 110 is configured to store the task. The MPOI 110 may be configured to store the task in the TRC 112. Further, the TRC 112 may be configured to receive and store the task via the XI, or X1_E, interface.
[0052] The MPOI 110 is configured to a request message, via a 01 interface, from one NF 101-1, 101-2. The 01 interface may, alternatively be understood as internal 01 interface, and may be referred to as a Q1_L interface, and the terms may be used interchangeably within the present disclosure. Further, the 01 interface may be understood as a Query interface. The purpose of the 01 interface may be understood as interface which the NFs 101 uses to query the MPOI 110, or more specifically the TRC of the MPOI 110. The request message may be received by the TRC 112 of the MPOI 110. The request message comprises an identifier of a communication entity. The communication entity may alternatively be understood as, for example, a user equipment (UE) or a communication device. The communication entity may be any of a wide variety of communication entities or devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with network nodes and other communication devices.
[0053] The request message may comprise one or more identifiers of communication entities. Therefore, fewer request messages may need to be sent from a NF 101-1, 101-2 to the MPOI 110, thereby increasing the efficiency of communication by reducing the amount of data communicated.
[0054] The MPOI 110 is further configured to determine, based on said received request message and a task stored in the MPOI 110, if the NF 101-1, 101-2, which sent the request message, is to intercept traffic of the communication entity. If it is determined, by the MPOI 110, that the NF 101-1, 101-2, is to intercept traffic of the communicationentity, then the MPOI 110 is configured to transmit an indication message, via the QI interface to the NF 101-1, 101-2. The indication message indicates that the traffic of the communication entity is to be intercepted.
[0055] If the received request message comprised more than one identifier, then the MPOI 110 may further be configured to determine which communication entities for which the NF 101-1, 101-2, which sent the request message, is to intercept traffic of. In other words, the MPOI 110 may be configured to determine that the traffic of one or more communication entities should be intercepted. Each communication entity is associated with a specific identifier, and the request message may comprise one or more identifiers.
[0056] The MPOI 110 is configured to receive, via the X2, or X2_L, and / or the X3, or X3_L, interface(s), intercepted traffic of the communication device. The intercepted traffic is received from the NF 101 having intercepted said traffic. The intercepted traffic may be received by the MDFP 111 of the MPOI 110. The MDFP 111 of the MPOI 110 may be configured to receive the raw data and / or media via the internal X2_L and X3_L interfaces and may then be configured to add additional data to the raw data and / or media as required by the standards regarding the X2 and X3 interfaces.
[0057] The MPOI 110 is further configured to forward, via the X2 and / or the X3 interface(s), the intercepted traffic to the MDF 212. The forwarding of the intercepted traffic may be done by the MDFP 111 of the MPOI 110. The intercepted traffic may comprise X3 Content of Communication (xCC) traffic or data, and / or X2 Intercept Related Information, (xIRI). xCC data may be sent from the NFs 101 to the MPOI 110 using the X3 or X3_L interface. xIRI data may be sent from the NFs 101-1, 101-2 to the MPOI 110 using the X2 or X2_L interface. The xCC data and / or the xIRI data may be received by the MDFP 111 of the MPOI 110. Correspondingly, the MPOI 110 may be configured to forward, i.e., send, xCC data and / or xIRI data to the MDF 212 via the X2, and / or the X3 interface(s).The MPOI 110 may be further configured to receive a first report message from any of the NFs 101. The report message may be received via the Q1_L interface. The MPOI 110 may be further configured to send, via the XI interface, a second report message to the ADMF 210. The MPOI 110 sending the second report message to the ADMF 210 may, alternatively, be understood as forwarding the first report message. However, the second report message comprises at least a part of the first report message. The first report message may be indicative of an issue with the NF 101 which sent first report message. The second report message may comprise the first report message. Further, the second report message may comprise at least a part of a plurality of first report messages. For example, the MPOI 110 may receive first report messages from multiple NFs 101 and / or multiple first report messages from one NF 101. Furthermore, the first report message may be indicative with one or more issues of one or more NFs 101, such as a group of NFs 101. The MPOI 110 may be configured to store the one or more received first report messages and then send a second report message comprising at least parts of the one or more received first report messages. The first report message may be a ReportNEIssue message or a ReportGroupIssue message. The MPOI 110 may be further configured to generate a first report message and or a second report message upon notifying an issue with an NF 101, and to send the generate first or second report message to the ADMF 210. In other words, the MPOI 110 may be configured to handle reporting issues for a plurality of NFs 101. Therefore, the number of messages sent to the ADMF 210 may be reduced, thereby reducing the amount traffic communicated to the ADMF 210.
[0058] The VI, hosting the MPOI 110 and the NFs 101, may comprise a second, or additional, NF (not shown, see Figure 5). The second NF may be a NF which is not compatible with the MPOI 110, or phrased differently, the second NF may not support the functionality of the MPOI 110. In order to be able to handle the second NF, the MPOI 110 may be configured to receive a first message, via the XI, or the X1_E, interface from the ADMF 210. The first message may indicate the second NF. The MPOI 110 may be configured to send, or forward, a second message, via a XI interface, to a POI (not shown) associated with the second NF. The second message may comprise at least a part of the message. The second message may be equal to the first message. In other words, theMPOI 110 may be configured as a proxy for NFs which do not support the functionality of the MPOI 110. Thereby, backwards compatibility is provided by the MPOI 110.
[0059] With regards to the limitations and efficiencies of the LI infrastructure as illustrated in Figure 1, and as defined in ETSI TS 104007 Vl.1.1 (2024-11), the invention according to the present disclosure provides a number of advantages. For example, deployment of the LI architecture of Figure 1 in, or at least partly in, a cloud environment could lead to more than one NF 101, and its associated ELI 102, being deployed in the same Internet as a Service (laaS) physical infrastructure. Since each ELI 102 includes a target database, then there is a high risk that there will be complete or partial duplicates of targets databases of the ELIs which are deployed in the same laaS physical infrastructure, which would be a waste of storage and would require additional overhead with regards to management and / or security implementation. Thus, by implementing an MPOI 110, as shown in Figure 2 and described in the relating description, these limitations and efficiencies are greatly reduced.
[0060] Additionally, if the network, in which the LI infrastructure as illustrated in Figure 1 and as defined in ETSI TS 104007 Vl.1.1 (2024-11), is deployed using an Ultra Compact Core (UCC), then there is a need to minimize software (SW) and hardware (HW) requirements by centralizing functionalities. For example, the UCC may include, at least, the following 5G Core NFs, each having an associated ELI: Unified Data Management (UDM), Home Subscriber Server (HSS), Network Exposure Function (NEF), Access and Mobility Management Function (AMF), Session Management Function (SMF), and User Plane Function (UPF). Therefore, there is a high risk that there will be complete or partial duplicates of targets databases of the ELIs 102 of the UCC. Further, each time that a new target needs to be added, deleted or modified, then it needs to be done for each separate NF 101. Similarly, audit & synch procedures, which relates to checking the target DB for inconsistencies, would also have to be done for each separate NF 101. Moreover, if, for some reason, a NF is compromised, then, access to its copy of the target database could be exploited. Therefore, having multiple copies of target databases increases the risk of any one of them being exploited. Thus, by implementing an MPOI 110, as shown in Figure 2 and described in the relating description, then the securityrelated to target DB(s) is greatly increased, and the amount of communication and / or computation needed for audit & synch procedures would be greatly reduced.
[0061] Furthermore, internal traffic of physical infrastructure, e.g., hardware, has delay that is at least one order of magnitude smaller than the delay of traffic to an external network. For example, local traffic may have a delay of 0.1-1 millisecond compared to >20 milliseconds in case of metropolitan transport networks. Geographical networks may have delays that are above 100 milliseconds. Therefore, having NFs 101 deployed in the same Internet as a Service (laaS) physical infrastructure may greatly reduce the delay.
[0062] Figure 3 illustrates an example of a method 1000 for enabling ELI 110 to act as a POI for a plurality of NFs 101. The method 1000 is performed by the ELI 110. The ELI 110 is hosted in a VI hosting the plurality of NFs 101. The method 1000 comprises receiving 1100 a task, via an XI interface, from a LI ADMF 210. The task comprises a target identifier, task details indicating which one or more NFs 101 of the plurality of NFs 101 for which the task is applicable, and one or more destination identifiers, DIDs. The method 1000 further comprises storing 1200 the task in the ELI 110, and receiving 1300 a request message, via a QI interface, from a NF 101 of the plurality of NFs 101. The request message comprises an identifier of a communication entity. The method further comprises determining 1400, based on said received request message and a task stored in the ELI 110, if said NF 101 having sent said received request message is to intercept traffic of the communication entity. The method 1000 further comprises, if said NF 101 is to intercept traffic of the communication entity, transmitting 1500 an indication message, via the QI interface, to said NF 101. The indication message indicates that traffic of the communication entity is to be intercepted. The method 1000 further comprises receiving 1600, via an X2 and / or an X3 interface, from said NF 101, intercepted traffic of said communication entity, and forwarding 1700, via an X2 and / or an X3 interface, the intercepted traffic to a mediation and delivery function, MDF 212.The method 1000 may further comprise receiving 1800, via an QI interface, a first report message from a NF 101 of the plurality of NFs 101, and sending 1850, via the XI interface, a second report message comprising at least a part of the first report message to the ADMF 210. Furthermore, the method 1000 may comprise receiving 1900, via an XI interface, from the ADMF 210, a first message indicating a second NF hosted in the VI, and forwarding 1950, via an XI interface, a second message to a Point of Intercept, POI, associated with the second NF, wherein the second message comprises at least a part of the first message. The method steps 1800 and 1850, and 1900 and 1950 are illustrated as being performed after the method step 1700. However, it is to be understood that they may performed at any time, such as before any of the method steps 1100-1700, or simultaneously as any of method steps 1100-1700. Further, method steps 1800 and 1850 may performed after methods steps 1900 and 1950.
[0063] Figure 4 illustrates an example of a method 2000 for enabling an ELI 110 to act as a POI for a plurality of NFs 101. The method 2000 is performed by a LI ADMF 210. The ELI 110 is hosted in a VI hosting the plurality of NFs 101. The method 2000 comprises attesting 2100, via an X0 interface, the ELI 110, provisioning 2200, via an XI interface, the ELI 110, and sending 2300 a task, via the XI interface, to the ELI 110. The task comprises a target identifier, task details indicating which one or more NFs 101 of the plurality of NFs 101 for which the task is applicable, and one or more destination identifiers, DIDs.
[0064] The method 2000 may further comprise the receiving 2400, via an XI interface, a report message from the ELI 110. The report message relates to the one or more NFs 101 of the plurality of NFs 101. Further, the method 2000 may comprise sending 2500 a second task, via the XI interface, to the ELI 110. The second task indicates that at least two NFs 101 of the plurality of NFs 101 are defined as Group having a Group Identifier, GID. Furthermore, the method 2000 may comprise sending 2600 a third task, via the XI interface, to the ELI 110. The third task indicates that one or more Groups should be removed.Figure 5 illustrates a signalling diagram between an NF 101, an ELI 110, i.e., a MPOI 110 (the ELI 110 will be referred to as the MPOI 110 in the following), and a LI ADMF 210. The signalling diagram further illustrates messages to a POI 107 associated with a second NF 108. The NF 101, the MPOI 110, the ADMF 210, and the POI 107 and its associated second NF 108, their functions, and methods performed by them, have been described in Figures 1 to 4 and the text relating thereto, and therefore, references those figures and their corresponding descriptions are made for a better understanding.
[0065] The ADMF 210 is configured to attest 2100, via an X0 interface, and provision 2200, via an XI interface, the MPOI 110.
[0066] The ADMF 210 sends 1100, 2300 a task, via the XI interface, to the MPOI 110.
[0067] Correspondingly, the MPOI 110 receives the task, via the XI interface, from the ADMF 210. The task may be a ActivateTaskRequest, as defined in e.g. ETSI TS 103221-1 Vl.19.1 (2024-04). The task may comprise TaskDetails, as disclosed in e.g. clause 6.2, Table 4 of ETSI TS 103221-1 Vl.19.1 (2024-04). It is to be noted that the following relates to ETSI standards, more specifically ETSI TS 103221-1, and that the term Network Element, NE, and Network Function, NF, may be used interchangeably.
[0068] The TaskDetails is proposed to be updated adding the following new field:
[0069] Table 4: TaskDetails
[0070]
[0071] Further, the ListOfTargetNEsOrGroups, as shown in updated Table 4, is defined in a new Table 4a, see below.Table 4a: ListOfTargetNEsOrGroups Formats
[0072] Field
[0073]
[0074] Description
[0075]
[0076] Format
[0077]
[0078] M / C / 0
[0079]
[0080] Each NE or NE Group may indicate a related list of DIDs to be applied. If there is not ListOfRelatedDIDs, then the existing ListOfDIDs described in Table 4 is to be applied. If a single NE is defined as a Group (i.e., including the single NE as an item), then the ListOfTargetNEsOrGroups can be equal to ListOfTargetGroups. A task may not be associated to 2 or more Groups which include the same NE.
[0081] The illustrated messages or steps of storing 1200 a task in the MPOI 110, the NF 101 sending 1300 a request message to the MPOI 110, the determining 1400 by the MPOI 110, the MPOI 110 sending 1500 a indication message to the NF 101, the NF 101 sending 1600 intercepted traffic to the MPOI 110, and the MPOI 110 sending / forwarding intercepted traffic to ADMF 210 have been explained thoroughly in the text relating to Figures 1 to 4 and will therefore not be discussed in detail here.
[0082] The NF 101 may send 1800, via the QI interface, a report message to the MPOI 110. The MPOI 110 may send 1850, 2400, via the XI interface, a second report message to the ADMF 210 Sending 1850, 2400 the second report message may be initiated by receiving the first report message or by the MPOI 110 determining that there is an issue with a NF 101.The second report message may be a Reportissue message or request. Alternatively, the second report message be a ReportGroupIssue message or request, and relate to a Group of NEs / NFs 101. The MPOI 101 may send a ReportGroupIssue request when it becomes aware of an issue (i.e., a warning or a fault) relating specifically to a particular GID of a Group of NEs. The ReportGroupIssue request may also be used to follow up on an "OK - Acknowledged" response, to signal that a request has been completed (see clause 5.2 of ETSI TS 103221-1 Vl.19.1 (2024-04)) successfully or unsuccessfully. Faults and warnings are defined in clause 5.3 ETSI TS 103221-1 Vl.19.1 (2024-04), and clause 5.1 of ETSI TS 103221-1 Vl.19.1 (2024-04) relates to terminating and nonterminating faults. If a non-terminating fault becomes terminating, the MPOI 110 may send another ReportGroupIssue request. If a non-terminating fault is cleared, the MPOI 110 may send another ReportGroupIssue request indicating the fault is cleared.
[0083] Therefore, it is proposed that the following new tables are added:
[0084] Tablew: ReportGroupIssueRequest > _ Field
[0085]
[0086] Description
[0087]
[0088] Format
[0089]
[0090] M / C / O
[0091]
[0092] Table w+1: ReportGroupIssueResponse
[0093]
[0094] The MPOI 110 may send 2500 a second task and / or send 2600 a third task, via the XI interface, to the MPOI 110.
[0095] The second task may indicate that one or more NFs 101 are defined as Group having a Group Identifier, GID. Therefore, it is proposed that ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to add a new clause, CreateGroup, relating on how to create a new Group of NEs. It is proposed that the following new tables are added:
[0096] Table x: CreateGroupRequest
[0097]
[0098] Table x+1: CreateGroupResponse >
[0099]
[0100] GroupDetails relate to the NE(s) for which delivery of information is of interest. It is proposed that the GroupDetails structure is defined as follows:
[0101] Table x+2: GroupDetails
[0102]
[0103] The List of NEs structure is defined as follows.
[0104] Table x+3: ListofNEs > >
[0105] > >
[0106] "" "" "" "" "" ""
[0107]
[0108] "" "" ""The third task may indicate that a Group should be modified. It is therefore proposed that ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to include:
[0109] Table x+4: ModifyGroupRequest
[0110]
[0111] Table x+5: ModifyGroupResponse
[0112]
[0113] The purpose of ModifyGroupRequest is for the ADMF 210 to be able to modify an existing Group of NE. All details for the Group shall be given (i.e., the modified details and the information that is unchanged) to totally replace the previous Group details.
[0114] The third task may alternatively indicate that a Group, a plurality of Groups, or all Groups should be removed. It is therefore proposed that ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to include:
[0115] Table x+6: RemoveGroupRequest
[0116]
[0117] Table x+7: RemoveGroupResponse
[0118] Field Description
[0119]
[0120] Format
[0121]
[0122] M / C / 0
[0123]
[0124] A Group may only be removed if it is not referenced by any Tasks. An MPOI 110 shall respond with an appropriate error if the ADMF 210 attempts to remove a Group that is referenced by a Task.
[0125] The third task may include a RemoveAIIGroupsRequest, which is a request to may completely and permanently remove all Groups of NE. All Groups may only be removed if no NE(s) in any of the Groups is referenced by any Tasks. An MPOI 110 shall respondwith an appropriate error if the ADMF 210 attempts to remove a Group that is referenced by a Task.
[0126] Table x+8: RemoveAIIGroupsRequest
[0127]
[0128] Table x+9: RemoveAIIGroupsResponse > > >
[0129] > >
[0130]
[0131] The RemoveAIIGroups request shall be supported by all implementations of the present invention. It shall be agreed in advance as to whether the RemoveAIIGroups request is enabled or disabled. By default (i.e., if there has been no agreement in advance) then RemoveAIIGroups is enabled. If RemoveAIIGroups is disabled, then a RemoveAIIGroups request shall always trigger an ErrorResponse indicating " RemoveAIIGroups request is not enabled". If RemoveAIIGroups is enabled, then a RemoveAIIGroups request shall remove all Groups on that NE, or it shall trigger an error for the general error conditions listed in clause 6.7 of ETSI TS 103221-1 Vl.19.1 (2024-04). Since a RemoveGroup request can only be issued against groups that are not in use, a MPOI 110 shall respond with an error if the ADMF sends a RemoveAIIGroups request while any of the Groups are referenced by Tasks.
[0132] The ADMF 210 may send (not shown) another task to the MPOI 110 in order to retrieve the details or status of a particular Group. It is therefore proposed that ETSI TS 103 221-1 Vl.19.1 (2024-04) is updated to include:
[0133] Table y: GetGroupRequest > >
[0134]
[0135] Table y+1: GetGroupResponse
[0136] Field Description
[0137]
[0138] Format
[0139]
[0140] M / C / 0
[0141]
[0142] Table y+2: GroupStatus >
[0143]
[0144] " " ""
[0145]
[0146] The GroupStatus relates only to the status of the NE Group as seen by the MPOI 110.
[0147] It is further proposed that clause 6.4.5 "GetAI I Deta ils" of ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to include a field for the info related to NE groups, already existing fields are not reported, as shown in Table 31 below:
[0148] Table 31: GetAIIDetailsResponse
[0149]
[0150] It is further proposed that clause 6.4.6 "ListAI I Details" of ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to include a field for the info related to NE groups, already existing fields are not reported, as shown in Table 33 below:
[0151] Table 33: ListAIIDetailsResponse
[0152]
[0153] It is further proposed that ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to include a GetAIIGroupDetails request, in order for the ADMF 210 to able to retrieve all details of all Groups, as shown below:
[0154] Table z: GetAIIGroupDetailsRequest
[0155] >
[0156]
[0157] Table z+1: GetAIIGroupDetailsResponse
[0158]
[0159] The above discussed proposal messages, requests and responses may cause new types of errors. Therefore, it is proposed that Table 44 of clause 6.7, "Protocol error details" of ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to include the following:Table 44: Error response
[0160]
[0161] ""
[0162] ""
[0163] ""
[0164] "" "" "" "" "" " " "" "" "" "" "" "" " "
[0165] " " "" "" " " "" "" "" "" "" "" " "
[0166] "
[0167]
[0168] "
[0169] Further, it is proposed that Table 46 of ETSI TS 103221-1 Vl.19.1 (2024-04) is updated to include the following:Table 46: Error codes
[0170]
[0171] If an NE is not adapted to use an external Triggering Function (TF), wherein such an NE is illustrated in Figure 5 as a second NF 108, then the ADMF 210 can attempt to send messages to a POI 107 associated with the NE, i.e., the second NF 108. In such a case, new messages and new fields related to NEs and NE Groups are not sent to the NE / second NF 108. Figure 5 illustrates this by showing that the ADMF 210 may be configured to send 1900 a first message, via an XI interface, to the MPOI 110. The MPOI 110 may then be configured to send 1950 a second message to the POI 107 associated with the second NF 108. The second message comprises at least a part of the first message. Alternatively, the second message may comprise all of the first message, or be equal to first message, and the MPOI 110 may be configured to forward 1950 the second message.
[0172] Figure 6 illustrates an example of a network node 400 according to some embodiments of the present disclosure. Optional features are represented by dashed boxes. The network node 400 may be, for example, a network node that implements all or part of the functionality of the ELI 110, i.e., MPOI 110, or the LI ADMF 210 as described herein. As illustrated, the network node 400 includes a control system 402 that includes one ormore processors 404 (e.g.. Central Processing Units (CPUs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), and / or the like), memory / computer readable storage medium 406, and a network interface 408. The one or more processors 404 are also referred to herein as processing circuitry.
[0173] The one or more processors 404 operate to provide one or more functions of a network node 400 as described herein. In some embodiments, the function(s) are implemented in one or more computer programs 410 that are stored, e.g., in the computer readable storage medium 406 and executed by the one or more processors 404.
[0174] Figure 7 illustrates another example of a network node 400 according to the present disclosure. The network node 400 includes one or more modules ELI 110, i.e., MPOI 110, or ADMF 210, each of which is implemented in software. The modules ELI 110, i.e., MPOI 110, or ADMF 210 provide the functionality of the network node 400 described herein.
[0175] The examples of the network nodes 400 illustrated in Figures 6 and 7 may be examples of virtualized embodiments and may be understood as virtualized network nodes 400.
[0176] A "virtualized" network node may be understood as an implementation of the network node 400 in which at least a portion of the functionality of the network node 400 is implemented as a virtual component(s) (e.g., via a virtual machine(s) executing on a physical processing node(s) in a network(s)). The network node 400 may include one or more processing nodes coupled to or included as part of a network(s). If present, a control system 402 may be connected to the processing node(s) via the network. Each processing node may include one or more processors (e.g., CPUs, ASICs, FPGAs, and / or the like), memory / computer readable storage medium, and a network interface.
[0177] Functions of the network node 400 may be implemented at the one or more processing nodes or distributed across the one or more processing nodes and the control system 402 in any desired manner. In some particular embodiments, some or all of the functions of the network node 400 described herein may be implemented as virtual components executed by one or more virtual machines implemented in a virtualenvironment(s) hosted by the processing node(s). As will be appreciated by one of ordinary skill in the art, additional signaling or communication between the processing node(s) and the control system 402 may be used in order to carry out at least some of the desired functions. In some embodiments, a computer program including instructions which, when executed by at least one processor, causes the at least one processor to carry out the functionality of network node 400 or a node (e.g., a processing node) implementing one or more of the functions of the network node 400 in a virtual environment according to any of the embodiments described herein is provided. In some embodiments, a carrier comprising the aforementioned computer program product is provided. The carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (e.g., a non-transitory computer readable medium such as memory).
[0178] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or where it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may apply to any other embodiments, and vice versa. Other objectives, features, and advantages of the enclosed embodiments will be apparent from the description.
Claims
CLAIMS1. A method (1000) for enabling an Element of Lawful Intercept, ELI, (110) to act as a Point of Intercept, POI, for a plurality of Network Functions, NFs, (101) performed by the ELI (110), and wherein the ELI (110) is hosted in a Virtual Infrastructure, VI, hosting the plurality of NFs (101), the method comprising:receiving (1100) a task, via an XI interface, from a lawful interception, LI, administrative function, ADMF, (210) wherein the task comprises a target identifier, task details indicating which one or more NFs (101) of the plurality of NFs (101) for which the task is applicable, and one or more destination identifiers, DIDs;storing (1200) the task in the ELI (110);receiving (1300) a request message, via a QI interface, from a NF (101) of the plurality of NFs (101), wherein the request message comprises an identifier of a communication entity;determining (1400), based on said received request message and a task stored in the ELI (110), if said NF (101) having sent said received request message is to intercept traffic of the communication entity;if said NF (101) is to intercept traffic of the communication entity, transmitting (1500) an indication message, via the QI interface, to said NF (101), wherein the indication message indicates that traffic of the communication entity is to be intercepted;receiving (1600), via an X2 and / or an X3 interface, from said NF (101), intercepted traffic of said communication entity; andforwarding (1700), via an X2 and / or an X3 interface, the intercepted traffic to a mediation and delivery function, MDF (212).
2. The method (1000) according to claim 1, further comprising:storing (1200) the task in a target repository component, TRC, (112) of the ELI (110);receiving (1300) the request message, via the QI interface and using the TRC (112), from the NF (101) of the plurality of NFs (101); andif said NF (101) is to intercept traffic of the communication entity, transmitting (1500) the indication message, via the QI interface and using the TRC (112), to said NF (101).
3. The method (1000) according to claim 1 or 2, further comprising:receiving (1600), via an X2 and / or an X3 interface and using a Mediation Function Proxy, MDFP, (111) of the ELI (110), from said NF (101), intercepted traffic of said communication entity; andforwarding (1700), via an X2 and / or an X3 interface and using the MDFP (111), the intercepted traffic to the mediation and delivery function, MDF (212).
4. The method (1000) according to any one of claims 1 to 3, wherein the task comprises a TaskObject or a TaskDetailsExtensions, and wherein the task details are comprised by the TaskObject or the TaskDetailsExtensions.
5. The method (1000) according to any one of claims 1 to 4, wherein the ELI (110) has been attested via an X0 interface.
6. The method (1000) according to claim 5, wherein the ELI (110) has been provisioned by a Lawful Interception Provisioning Function, LIPF (210-2), of the ADMF (210), via an XI interface.
7. The method (1000) according to any of claims 1 to 6, wherein the ELI (110) has been instantiated by a Network Function Virtualization, NFV, Management and Orchestration, MANO (104), function.
8. The method (1000) according to any one of claims 1 to 7, further comprising:receiving (1100) the task, via an enhanced XI interface, X1_E interface, from the ADMF (210).
9. The method (1000) according to any one of claims 1 to 8, further comprising:receiving (1600), via an internal X2 interface, X2_L, and / or an internal X3 interface, X3_L, from said NF (101), intercepted traffic of said communication entity.
10. The method (1000) according to any one of claims 1 to 9, further comprising:receiving (1800), via an QI interface, a first report message from a NF (101) of the plurality of NFs (101); andsending (1850), via the XI interface, a second report message comprising at least a part of the first report message to the ADMF (210).
11. The method (1000) according to any one of claims 1 to 10, further comprising:receiving (1900), via an XI interface, from the ADMF (210), a first message indicating a second NF (108) hosted in the VI; andforwarding (1950), via an XI interface, a second message to a Point of Intercept, POI, (107) associated with the second NF (108), wherein the second message comprises at least a part of the first message.
12. A network node (400) that implements an Element of Lawful Intercept, ELI, (110) that is configured as a Point of Intercept, POI, for a plurality of Network Functions, NFs, (101) and wherein the ELI (110) is hosted in a Virtual Infrastructure, VI, hosting the plurality of NFs, (101) and wherein the ELI (110) is configured to:receive a task, via an XI interface, from a lawful interception, LI, administrative function, ADMF, (210) wherein the task comprises a target identifier, task details indicating which one or more NFs (101) of the plurality of NFs for which the task is applicable, and one or more destination identifiers, DIDs;store the task in the ELI (110);receive a request message, via a QI interface, from a NF (101) of the plurality of NFs (101), wherein the request message comprises an identifier of a communication entity;determine, based on said received request message and a task stored in the ELI (110), if said NF (101) having sent said received request message is to intercept traffic of the communication entity;if said NF (101) is to intercept traffic of the communication entity, transmit an indication message, via the QI interface, to said NF (101), wherein the indication message indicates that traffic of the communication entity is to be intercepted;receive, via an X2 and / or an X3 interface, from said NF (101), intercepted traffic of said communication entity; andforward, via an X2 and / or an X3 interface, the intercepted traffic to a mediation and delivery function, MDF (212).
13. The network node (400) according to claim 12, wherein the network node (400) comprises processing circuitry (404) configured to cause the ELI (110) to perform the method (1000) according to any one of claims 2 to 11, or wherein the ELI (110) is further configured to perform the method (1000) according to any one of claims 2 to 11.
14. The network node (400) according to claim 12 or 13, wherein the ELI (110) is a Multi-Point of Intercept, MPOI.
15. A method (2000) for enabling an Element of Lawful Intercept, ELI, (110) to act as a Point of Intercept, POI, for a plurality of Network Functions, NFs (101), performed by a lawful interception, LI, administrative function, ADMF (210), wherein the ELI (110) is hosted in a Virtual Infrastructure, VI, hosting the plurality of NFs (101), the method comprising:attesting (2100), via an X0 interface, the ELI (110);provisioning (2200), via an XI interface, the ELI (110); andsending (2300) a task, via the XI interface, to the ELI (110), wherein the task comprises a target identifier, task details indicating which one or more NFs (101) of the plurality of NFs (101) for which the task is applicable, and one or more destination identifiers, DIDs.
16. The method (2000) according to claim 15, comprising:sending (2300) the task, via an enhanced XI interface, X1_E interface, to the ELI.
17. The method (2000) according to claim 15 or 16, comprising:provisioning (2200), via the XI and using a Lawful Interception Provisioning Function, LIPF, (210-2) of the ADMF (210), the ELI (110).
18. The method (2000) according to any one of claims 15 to 17, further comprising: receiving (2400), via an XI interface, a report message from the ELI (110), wherein the report message relates to the one or more NFs (101) of the plurality of NFs (101).
19. The method (2000) according to any one of claims 15 to 18, further comprising: sending (2500) a second task, via the XI interface, to the ELI (110), wherein the second task indicates that at least two NFs (101) of the plurality of NFs (101) are defined as Group having a Group Identifier, GID.
20. The method (2000) according to claim 19, further comprising:sending (2600) a third task, via the XI interface, to the ELI (110), wherein the third task indicates that one or more Groups should be removed or modified.
21. A network node (400) that implements a lawful interception, LI, administrative function, ADMF (210), wherein the ADMF (210) is configured to:attest, via an X0 interface, an Element of Lawful Intercept, ELI (110), wherein the ELI (110) is configured as a Point of Intercept, POI, for a plurality of Network Functions, NFs (101), and wherein the ELI (110) is hosted in a Virtual Infrastructure, VI, hosting the plurality of NFs (101);provision, via an XI interface, the ELI (110); andsend a task, via the XI interface, to the ELI (110), wherein the task comprises a target identifier, task details indicating which one or more NFs (101) of the plurality of NFs (101) for which the task is applicable, and one or more destination identifiers, DIDs.
22. The network node (400) according to claim 21, wherein the network node (400) comprises processing circuitry (404) configured to cause the ADMF (210) to perform the method (2000) according to any one of claims 16 to 20, or wherein the ADMF (210)is further configured to perform the method (2000) according to any one of claims 16 to 20.
23. A computer program (414) comprising instructions which, when executed on at least one processor (404), cause the processor (404) to carry out the method (1000, 2000) according to any of claims 1 to 11 and 14 to 20.
24. A carrier (406) containing the computer program (414) of claim 23, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, or a computer readable storage medium.