Updating inbound roamer target identities for li

WO2026201313A1PCT designated stage Publication Date: 2026-10-01TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/058364
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2026-10-01

Smart Images

  • Figure EP2025058364_01102026_PF_FP_ABST
    Figure EP2025058364_01102026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides methods for updating inbound roamer target identities for lawful intercept, LI, performed by an LI Mirror Internet Protocol (IP) Multimedia Subsystem State Function (LMISF) device 108, where the method includes receiving 322 a registration message associated with an inbound roaming target device 116, wherein the registration message comprises a plurality of target identifiers associated with the inbound roaming target device 116 The method includes transmitting 340, to a Mediation and Delivery function (MDF2) 202 a subscriber record change message comprising the plurality of target identifiers and the corresponding previous target identifier of the previous registration message, wherein one or more of target identifiers of the plurality of target identifiers are different from corresponding target identifiers of a previous registration message, wherein at least one target identifier of the plurality of target identifiers matches a corresponding previous target identifier of the previous registration message.
Need to check novelty before this filing date? Find Prior Art

Description

UPDATING INBOUND ROAMER TARGET IDENTITIES FOR LI TECHNICAL FIELD

[0001] The disclosure relates to methods for updating inbound roamer target identities for Lawful Interception (LI) in a wireless communication system. This disclosure also relates to network nodes configured to perform the same as well as a corresponding computer program and a carrier.BACKGROUND

[0002] In the case of Voice over Long Term Evolution (VoLTE) inbound roamers (IBR), according to Third Generation Partnership Program (3GPP) Technical Specification (TS) 33.107 V18.0.0 (2024-04-03) and 3GPP TS 33.108 V19.0.0 (2024-09-19) any change of the subscriber identity is implemented in the Home Subscriber Server (HSS) 118 of the Home network (e.g., the Home Public Land Mobile Network - HPLMN) 104. Meanwhile, the HSS (or Unified Data Management - UDM) of the Visited PLMN (VPLMN) 102 are not involved at all, therefore the standard Lawful Interception (LI) solution does not apply.

[0003] An example of this is seen in Figure 1, where an LI Mirror Internet Protocol (IP) Multimedia Subsystem Function (LMISF) 108 receives a registration with target identities associated with the IBR User Equipment (UE) 116 from the HSS 118 of the HPLMN 104 via the Bearer Binding Intercept and Forward Function (BBIFF) 114 at the Serving Gateway (S-GW) 112 of the VPLMN 102. The IBR UE 116 is registered with the IP Multimedia Subsystem (IMS) 122 of the HPLMN 104.SUMMARY

[0004] An object of the invention is to improve Lawful Interception (LI) in a roaming communication session at the visited network.

[0005] The present disclosure provides methods for updating inbound roamer target identities for lawful intercept, LI, performed by an LI Mirror Internet Protocol (IP) Multimedia Subsystem State Function (LMISF) device, where the method includes receiving a registration message associated with an inbound roaming target device, wherein the registration message comprises a plurality of target identifiers associated with the inbound roaming target device. The method also includes transmitting, to a Mediation and Delivery function (MDF2) a subscriber record change message comprising the plurality of target identifiers of the registration message and the corresponding previous target identifier of the previous registration message, wherein one or more of target identifiers of the plurality of target identifiers are different fromcorresponding target identifiers of a previous registration message, wherein at least one target identifier of the plurality of target identifiers matches a corresponding previous target identifier of the previous registration message.

[0006] In an embodiment, the method further includes receiving the previous registration message comprising the previous target identifiers and storing in the data repository, the previous target identifiers.

[0007] In an embodiment, the determining that one or more of the target identifiers of the plurality target identifiers is different comprises comparing the plurality of target identifiers received in the registration message with the previous target identifiers stored in the data repository.

[0008] In an embodiment, the method further includes storing, in a data repository, the plurality of target identifiers from the registration message.

[0009] In an embodiment, the registration message and the previous registration message are Session Initiation Protocol 200OK messages.

[0010] In an embodiment, the subscriber record change message is provided via an X2 interface.

[0011] In an embodiment, the data repository is located in at least one of the LMISF or another network node.

[0012] In an embodiment, the plurality of target identifiers comprises one or more private identities and one or more public identities.

[0013] In an embodiment, the one or more private identities comprise an International Mobile Subscriber Identity (IMSI) and an International Mobile Equipment Identity (IMEI).

[0014] In an embodiment, the one or more public identities comprise a Session Initiation Protocol Uniform Resource Identifier (SIP-URI) a telephone URI (TEL-URI) or a Mobile Station International Subscriber Directory Number (MSISDN).

[0015] In an embodiment, a network node is provided that implements an LMISF for updating inbound roamer target identities for LI, where the network node comprises processing circuitry configured to cause the network node to receive a registration message associated with an inbound roaming target device, wherein the registration message comprises a plurality of target identifiers associated with the inbound roaming target device. The processing circuitry also causes the network node to transmit, to a MDF2 a subscriber record change message comprising the plurality of target identifiers of the registration message and the corresponding previous target identifier of the previous registration message, wherein one or more of target identifiers of the plurality of target identifiers are different from corresponding target identifiersof a previous registration message, wherein at least one target identifier of the plurality of target identifiers matches a corresponding previous target identifier of the previous registration message. The network node can also perform any of the embodiments described above with regard to the method.

[0016] In an embodiment, a computer program is provided that includes instructions that when executed on processing circuitry causes the processing circuitry to carry out the method described above. Furthermore, a carrier is provided that contains the computer program wherein the carrier is one of: an electronic signal, an optical signal, a radio signal, or a computer readable storage medium.BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawing figures incorporated in and forming a part of this specification illustrate several aspects of the disclosure, and together with the description serve to explain the principles of the disclosure.

[0018] Figure 1 shows an example of Lawful Interception (LI) in a Voice over Long Term Evolution (VoLTE) communications system with home and visited networks in accordance with some embodiments of the present disclosure;

[0019] Figure 2 shows an example of LI in a VoLTE communications system with the improved LI Mirror Internet Protocol (IP) Multimedia Subsystem State Function (LMISF) device of the present disclosure in accordance with some embodiments of the present disclosure;

[0020] Figure 3 shows an exemplary message sequence chart of the method for updating inbound roamer target identities for LI performed by the LMISF in accordance with some embodiments of the present disclosure;

[0021] Figure 4 shows a network node in accordance with some embodiments of the present disclosure;

[0022] Figure 5 is a block diagram illustrating a virtualization environment in which functions implemented by some embodiments of the present disclosure may be virtualized; and

[0023] Figure 6 shows another example of the network node implementing the LMISF in accordance with some embodiments of the present disclosure.DETAILED DESCRIPTION

[0024] The embodiments set forth below represent information to enable those skilled in the art to practice the embodiments and illustrate the best mode of practicing the embodiments. Upon reading the following description in light of the accompanying drawing figures, thoseskilled in the art will understand the concepts of the disclosure and will recognize applications of these concepts not particularly addressed herein. It should be understood that these concepts and applications fall within the scope of the disclosure.

[0025] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0026] There currently exist certain challenge(s). Many mobile telecom operators allow their subscribers to change the Mobile Station International Subscriber Directory Number (MSISDN) very easily by means of do it yourself online panels, of the subscriber’s account menu.

[0027] In addition to that, targets usually have many handsets and many Subscriber Identity Modules (SIMs) that they continuously swap with the intent to interrupt and / or confuse the interception. As described above, since any changes to the subscriber identity is implemented in the Home Subscriber Server of the Home Public Land Mobile Network (PLMN) (instead, the HSS (or Unified Data Management - UDM) of the Visited PLMN are not involved at all.

[0028] Consequently, if the target (e.g., the inbound roamer - IBR) were to make one or more identity swaps of one of the target identities such as the one of the public identities like International Mobile Subscriber Identity (IMSI) or an International Mobile Equipment Identity (IMEI) or one of the private identities such as Session Initiation Protocol Uniform Resource Identifier (SIP-URI) a telephone URI (TEL-URI) or a Mobile Station International Subscriber Directory Number (MSISDN) the Law Enforcement Agency (LEA) in the VPLMN will not be informed that the change happened and with details about the new identity.

[0029] Certain aspects of the disclosure and their embodiments may provide solutions to these or other challenges. For detecting the IBR identity changes, the proposal is to use the LI Mirror Internet Protocol (IP) Multimedia Subsystem State Function (LMISF) of the VPLMN enriched with new functionalities allowing the detection of the changes and delivery of detailed information including new and disconnected identities.

[0030] Leveraging on the information about the identities available in the design base for the current LMISF standard functions, the proposal is to introduce a logic in the system for detecting changes, happening at new IBR User Equipment (UE) regi strati on / deregi strati on, and prepare specific X2 messages to be sent over the X2 to the Mediation and Delivery Function (MDF2) which in turn delivers new Intercept Related Information (IRIs) to the LEA over the HI2 interface for reporting the change with the deregistered identity and the new identity(ies).

[0031] To at least these ends, the present disclosure provides methods for updating inbound roamer target identities for lawful intercept, LI, performed by an LMISF, where the method includes receiving a registration message associated with an inbound roaming target device, wherein the registration message comprises a plurality of target identifiers associated with the inbound roaming target device. The method also includes transmitting, to a MDF2 a subscriber record change message comprising the plurality of target identifiers of the registration message and the corresponding previous target identifier of the previous registration message, wherein one or more of target identifiers of the plurality of target identifiers are different from corresponding target identifiers of a previous registration message, wherein at least one target identifier of the plurality of target identifiers matches a corresponding previous target identifier of the previous registration message.

[0032] Certain embodiments may provide one or more of the following technical advantage(s). The methods enable the LMISF to store information about registration updates with new identities received from the HSS in the HPLMN, and be able to provide prompt information to the LEA without deviating from the current LMISF basic functions and without additional major load onto the system.

[0033] Figure 3 shows an exemplary message sequence chart of the method for updating inbound roamer target identities for LI performed by the LMISF 108 in accordance with some embodiments of the present disclosure. The steps of the message sequence chart of Figure 3 will be discussed in the context of the content of Figure 2 which shows an example of LI in a VoLTE communications system with the improved LMISF 108 of the present disclosure.

[0034] In the current state of the art, the at step 302, the IBR UE 116 registers with the IMS 122 of the HPLMN 104 via a Session Initiation Protocol (SIP) register message that includes the private and public identities of the IBR UE 116. At step 304, the Bearer Binding Intercept and Forward Function (BBIFF) 114 of the VPLM 102 that is located at the Serving Gateway (S-GW) 112 of the VPLMN 102 sends the SIP Register message including the identities to the LMISF 108. At 306 and 308 the IMS Home 122 sends a 200OK message to the IBR UE 116, and the BBIFF 114 sends a 200OK message to the LMISF 108.

[0035] When the LMISF 108 detects a SIP REGISTER message, it records all the identities present in the registration message. In case one of the identities is also a target and there are no previous records of registration or the LMISF 108 already has recorded the registration, but no identities are changed, then the LMISF 108 triggers an MDF2 to send IRI REPORT IRI at 312 for both SIP REGISTER and at 316 for the 200 OK message to the LEA 204. The IRI messages to the LEA 204 can be sent via the HI2 protocol. The LMISF 108 triggers the IRI report IRIS bysending information associated with the SIP Register message and 200 OK messages as X2 Protocol Data Unit (PDU) messages at 310 and 314 to the MDF2. At 318, the LMISF 108 stores the public and / or private identities of the target IBR UE 116.

[0036] It is to be appreciated that in an embodiment, the SIP Register message at 310 comprises the public and private identities of the IBR UE 116. In an embodiment, in addition to the SIP Register message, the 200 OK message at 314 may also contain the public and private identities of the IBR UE 116.

[0037] The new proposed new functionality comes with steps 320 to 342, which can occur in response to a subscriber associated with the target changing one or more of the public and / or private identities.

[0038] When the LMISF detects a change of the identity(ies) in a registration, it triggers a subscriber record change to the MDF2202. The subscriber record change will report both the old and new identities to the MDF2202 and thus to the LEA 204, which can facilitate the LEA 204 identifying all the intercept data associated with the target.

[0039] For example, at step 320, the IBR UE 116 can report back to its HPLMN 104’s IMS 122 with a changed public or private identity (e.g., one or more of the IMEI, IMSI, MSISDN, SIP-URI, or TEL-URI) via a SIP Register message. The BBIFF 114 of the VPLMN relays the SIP register message with the changed identity(ies) to the LMISF 108. At 324 and 326 the IMS Home 122 sends a 200OK message to the IBR UE 116, and the BBIFF 114 sends a 200OK message to the LMISF 108.

[0040] At 328, via the X2 connection 212, the LMISF 108 sends the X2 PDU message associated with the SIP Register message to the MDF2202, and at 332 sends the X2 PDU message associated with the 200OK message to the MDF2202. The message at 332 includes the current identities of the IBR UE 116, that includes the changed identity(ies) and the identity(ies) that are unchanged.

[0041] At 336, the LMISF 108 may optionally determine that the one or more of the identifiers in the messages at 322 and 326 don’t match the identifiers provided by the IBR UE 116 in messages 304 and 308, and if so, will store at step 338, in a data repository 210, the plurality of target identifiers from the registration message. The data repository 210 can be located at the LMISF 108 or at another network node such as an HSS 206 or UDM 208 in the VPLMN 102.

[0042] At step 340, via the X2 interface 212, the LMISF 108 sends a subscriber record change message to the MDF2202, where the subscriber record change message comprises the plurality of target identifiers of the registration message and the corresponding previous targetidentifier of the previous registration message, wherein one or more of target identifiers of the plurality of target identifiers are different from corresponding target identifiers of a previous registration message, wherein at least one target identifier of the plurality of target identifiers matches a corresponding previous target identifier of the previous registration message. At 342, the MDF2202 then sends the IRI Report comprising the information associated with the subscriber record change message to the LEA 204 via the HI2 interface.

[0043] Figure 4 shows a network node 400 in accordance with some embodiments. As used herein, network node refers to equipment capable, configured, arranged and / or operable to communicate directly or indirectly with other network nodes or equipment, in a telecommunications network. In accordance with respective embodiments, network node 400 may be configured to operate in the VPLMN 102 or HPLMN 104 Figures 1 or 2. The network node 400 may implement for example the LMISF 108.

[0044] Other examples of network nodes 400 include core network nodes, nodes belonging to the LI IMS, Operation and Maintenance (O&M) nodes, Operations Support System (OSS) nodes, Self-Organizing Network (SON) nodes, positioning nodes (e.g., Evolved Serving Mobile Location Centers (E-SMLCs)), and / or Minimization of Drive Tests (MDTs). In embodiments, the network node may also include nodes in the Radio Access Network.

[0045] In particular embodiments, network node 400 includes a processing circuitry 402, a memory 404, a communication interface 406, and a power source 408. In general, in a particular embodiment of network node 400, processing circuitry 402, memory 404, communication interface 406, and power source 408 may, in whole or in part, represent or include physical components common to or shared by one or more of the other elements of network node 400.

[0046] The processing circuitry 402 may comprise a combination of one or more of a microprocessor, controller, microcontroller, central processing unit, digital signal processor, application-specific integrated circuit, field programmable gate array, or any other suitable computing device, resource, or combination of hardware, software and / or encoded logic operable to provide, either alone or in conjunction with other components, such as the memory 404, to provide network node 400 functionality.

[0047] In some embodiments, the processing circuitry 402 includes a system on a chip (SOC). In some embodiments, the processing circuitry 402 includes one or more of radio frequency (RF) transceiver circuitry 412 and baseband processing circuitry 414. In some embodiments, the RF transceiver circuitry 412 and the baseband processing circuitry 414 may be on separate chips (or sets of chips), boards, or units, such as radio units and digital units. Inalternative embodiments, part or all of RF transceiver circuitry 412 and baseband processing circuitry 414 may be on the same chip or set of chips, boards, or units.

[0048] The memory 404 may comprise any form of volatile or non-volatile computer-readable memory including, without limitation, persistent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (for example, a hard disk), removable storage media (for example, a flash drive, a Compact Disk (CD) or a Digital Video Disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory devices that store information, data, and / or instructions that may be used by the processing circuitry 402. The memory 404 may store any suitable instructions, data, or information, including a computer program, software, an application including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by the processing circuitry 402 and utilized by the network node 400. The memory 404 may be used to store any calculations made by the processing circuitry 402 and / or any data received via the communication interface 406. In some embodiments, the processing circuitry 402 and memory 404 is integrated.

[0049] The communication interface 406 is used in wired or wireless communication of signaling and / or data with UEs, other network nodes, and / or any other network equipment. In the illustrated embodiment, communication interface 406 comprises port(s) / terminal(s) 416 to send and receive data, for example to and from a network over a wired connection. In particular embodiments, network node 400 may be capable of wireless communication and communication interface 406 may also include radio front-end circuitry 418 that may be coupled to, or in certain embodiments a part of, an antenna 410. Particular embodiments of radio front-end circuitry 418 include filter(s) 420 and amplifier(s) 422. The radio front-end circuitry 418 may be connected to an antenna 410 and processing circuitry 402. The radio front-end circuitry may be configured to condition signals communicated between antenna 410 and processing circuitry 402. The radio front-end circuitry 418 may receive digital data that is to be sent out to other network nodes or UEs via a wireless connection. The radio front-end circuitry 418 may convert the digital data into a radio signal(s) having the appropriate channel and bandwidth parameters using a combination of filters 420 and / or amplifiers 422. The radio signal(s) may then be transmitted via the antenna 410. Similarly, when receiving data, the antenna 410 may collect radio signals which are then converted into digital data by the radio front-end circuitry 418. The digital data may be passed to the processing circuitry 402. In other embodiments, the communication interface may comprise different components and / or different combinations of components.

[0050] In certain alternative embodiments, network node 400 may be capable of wireless communication but does not include separate radio front-end circuitry 418, instead, the processing circuitry 402 includes radio front-end circuitry and is connected to the antenna 410. Similarly, in some embodiments, all or some of the RF transceiver circuitry 412 is part of the communication interface 406. In still other embodiments, the communication interface 406 includes one or more ports or terminals 416, the radio front-end circuitry 418, and the RF transceiver circuitry 412, as part of a radio unit (not shown), and the communication interface 406 communicates with the baseband processing circuitry 414, which is part of a digital unit (not shown).

[0051] The power source 408 provides power to the various components of network node 400 in a form suitable for the respective components (e.g., at a voltage and current level needed for each respective component). The power source 408 may further comprise, or be coupled to, power management circuitry to supply the components of the network node 400 with power for performing the functionality described herein. For example, the network node 400 may be connectable to an external power source (e.g., the power grid, an electricity outlet) via an input circuitry or interface such as an electrical cable, whereby the external power source supplies power to power circuitry of the power source 408. As a further example, the power source 408 may comprise a source of power in the form of a battery or battery pack which is connected to, or integrated in, power circuitry. The battery may provide backup power should the external power source fail.

[0052] Embodiments of the network node 400 may include additional components beyond those shown in Figure 4 for providing certain aspects of the network node’s functionality, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 400 may include user interface equipment to allow input of information into the network node 400 and to allow output of information from the network node 400. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for the network node 400.

[0053] Figure 5 is a block diagram illustrating a virtualization environment 500 in which functions implemented by some embodiments may be virtualized. In the present context, virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to any device described herein, or components thereof, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein may be implemented asvirtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 500 hosted by one or more of hardware nodes, such as a hardware computing device that operates as an access network node, UE, core network node, or host. Further, in embodiments in which a virtual node does not require radio connectivity (e.g., a core network node or host), then the node may be entirely virtualized. In some embodiments, the virtualization environment 500 includes components defined by the O-RAN Alliance, such as an O-Cloud environment orchestrated by a Service Management and Orchestration Framework via an O-2 interface.

[0054] Applications 502 (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) are run in the virtualization environment 400 to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein.

[0055] Hardware 504 includes processing circuitry, memory that stores software and / or instructions executable by hardware processing circuitry, and / or other hardware devices as described herein, such as a network interface, input / output interface, and so forth. Software may be executed by the processing circuitry to instantiate one or more virtualization layers 506 (also referred to as hypervisors or virtual machine monitors (VMMs)), provide VM 508A and VM 508B (which may be collectively referred to as VMs 508), and / or perform any of the functions, features and / or benefits described in relation with some embodiments described herein. The virtualization layer 506 may present a virtual operating platform that appears like networking hardware to one or more of the VMs 508.

[0056] The VMs 508 comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by virtualization layer 506. Different embodiments of the instance of a virtual appliance 502 may be implemented on one or more of VMs 508, and the implementations may be made in different ways. Virtualization of the hardware is in some contexts referred to as network function virtualization (NFV). NFV may be used to consolidate many network equipment types onto industry standard high volume server hardware, physical switches, and physical storage, which can be located in data centers, and customer premise equipment.

[0057] In the context of NFV, each of the VMs 508 may be a software implementation of a physical machine that runs programs as if they were executing on a physical, non-virtualized machine. Each of the VMs 508, and that part of hardware 504 that executes that VM, be it hardware dedicated to that VM and / or hardware shared by that VM with others of the VMs, forms separate virtual network elements. Still in the context of NFV, a virtual network functionis responsible for handling specific network functions that run in one or more of the VMs 508 on top of the hardware 504 and corresponds to an application 502.

[0058] Hardware 504 may be implemented in a standalone network node with generic or specific components. Hardware 504 may implement some functions via virtualization.Alternatively, hardware 504 may be part of a larger cluster of hardware (e.g., such as in a data center or CPE) where many hardware nodes work together and are managed via management and orchestration 510, which, among others, oversees lifecycle management of applications 502. In some embodiments, hardware 504 is coupled to one or more radio units that each include one or more transmitters and one or more receivers that may be coupled to one or more antennas. Radio units may communicate directly with other hardware nodes via one or more appropriate network interfaces and may be used in combination with the virtual components to provide a virtual node with radio capabilities, such as a radio access node or a base station. In some embodiments, some signaling can be provided with the use of a control system 512 which may alternatively be used for communication between hardware nodes and radio units.

[0059] Figure 6 is a schematic block diagram of the network node 400 according to some other embodiments of the present disclosure. The network node 400 may include one or more modules LMISF 108, which is implemented in software. The modules LMISF 108 provide the functionality of the network node 400 described herein.

[0060] Although the computing devices described herein (e.g., UEs, network nodes, hosts) may include the illustrated combination of hardware components, other embodiments may comprise computing devices with different combinations of components. It is to be understood that these computing devices may comprise any suitable combination of hardware and / or software needed to perform the tasks, features, functions, and methods disclosed herein.Determining, calculating, obtaining or similar operations described herein may be performed by processing circuitry, which may process information by, for example, converting the obtained information into other information, comparing the obtained information or converted information to information stored in the network node, and / or performing one or more operations based on the obtained information or converted information, and as a result of said processing making a determination. Moreover, while components are depicted as single boxes located within a larger box, or nested within multiple boxes, in practice, computing devices may comprise multiple different physical components that make up a single illustrated component, and functionality may be partitioned between separate components. For example, a communication interface may be configured to include any of the components described herein, and / or the functionality of the components may be partitioned between the processing circuitry and the communicationinterface. In another example, non-computationally intensive functions of any of such components may be implemented in software or firmware and computationally intensive functions may be implemented in hardware.

[0061] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionality may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.

[0062] Those skilled in the art will recognize improvements and modifications to the embodiments of the present disclosure. All such improvements and modifications are considered within the scope of the concepts disclosed herein.

Claims

CLAIMS1. A method for updating inbound roamer target identities for lawful interception, LI, performed by an LI Mirror Internet Protocol, IP, Multimedia Subsystem, IMS, State Function, LMISF (108), the method comprising:receiving (322) a registration message associated with an inbound roaming target device (116), wherein the registration message comprises a plurality of target identifiers associated with the inbound roaming target device (116); andtransmitting (340), to a Mediation and Delivery function, MDF2, (202) a subscriber record change message comprising the plurality of target identifiers of the registration message and the corresponding previous target identifier of the previous registration message, wherein one or more of target identifiers of the plurality of target identifiers are different from corresponding target identifiers of a previous registration message, wherein at least one target identifier of the plurality of target identifiers matches a corresponding previous target identifier of the previous registration message.

2. The method of claim 1, further comprising:receiving (304) the previous registration message comprising the previous target identifiers; andstoring (318), in a data repository (210), the previous target identifiers.

3. The method of claim 2, wherein the determining that one or more of the target identifiers of the plurality target identifiers is different comprises comparing the plurality of target identifiers received in the registration message with the previous target identifiers stored in the data repository.

4. The method of any of claims 1 to 3, further comprising:storing (338), in the data repository (210), the plurality of target identifiers from the registration message.

5. The method of any of claims 1 to 4, wherein the registration message and the previous registration message are Session Initiation Protocol 200OK messages.

6. The method of any of claims 1 to 5, wherein the subscriber record change message isprovided via an X2 interface (212).

7. The method of any of claims 2 or 4, wherein the data repository (210) is located in at least one of the LMISF (108) or another network node.

8. The method of any of claims 1 to 7, wherein the plurality of target identifiers comprises one or more private identities and one or more public identities.

9. The method of claim 8, wherein the one or more private identities comprise an International Mobile Subscriber Identity, IMSI, and an International Mobile Equipment Identity, IMEI.

10. The method of any of claims 8 to 9, wherein the one or more public identities comprise a Session Initiation Protocol Uniform Resource Identifier, SIP-URI, a telephone URI, TEL-URI, or a Mobile Station International Subscriber Directory Number, MSISDN.

11. A network node (400) that implements a Lawful Interception, LI, Mirror Internet Protocol, IP, Multimedia Subsystem, IMS, State Function, LMISF (108) for updating inbound roamer target identities for LI, the network node (400) comprising processing circuitry (402) configured to cause the network node (400) to:receive (322) a registration message associated with an inbound roaming target device (116), wherein the registration message comprises a plurality of target identifiers associated with the inbound roaming target device (116); andtransmit (340), to a Mediation and Delivery Function, MDF2, (202) a subscriber record change message comprising the plurality of target identifiers of the registration message and the corresponding previous target identifier of the previous registration message, wherein one or more of target identifiers of the plurality of target identifiers are different from corresponding target identifiers of a previous registration message, wherein at least one target identifier of the plurality of target identifiers matches a corresponding previous target identifier of the previous registration message.

12. The network node (400) of claim 11, wherein the processing circuitry is further configured to cause the network node (400) to:receive (304) the previous registration message comprising the previous target identifiers;15andstore (318), in a data repository (210), the previous target identifiers.

13. The network node (400) of claim 12, wherein the determining that one or more of the target identifiers of the plurality target identifiers is different comprises comparing the plurality of target identifiers received in the registration message with the previous target identifiers stored in the data repository.

14. The network node (400) of any of claims 11 to 14, wherein the processing circuitry is further configured to cause the network node (400) to:store (338), in the data repository (210), the plurality of target identifiers from the registration message.

15. The network node (400) of any of claims 11 to 14, wherein the registration message and the previous registration message are Session Initiation Protocol 200OK messages.

16. The network node (400) of any of claims 11 to 15, wherein the subscriber record change message is provided via an X2 interface (212).

17. The network node (400) of any of claims 12 or 14, wherein the data repository (210) is located in at least one of the LMISF (108) or another network node.

18. The network node (400) of any of claims 11 to 17, wherein the plurality of target identifiers comprises one or more private identities and one or more public identities.

19. The network node (400) of claim 18, wherein the one or more private identities comprise an International Mobile Subscriber Identity, IMSI, and an International Mobile Equipment Identity, IMEI.

20. The network node (400) of any of claims 18 to 19, wherein the one or more public identities comprise a Session Initiation Protocol Uniform Resource Identifier, SIP-URI, a telephone URI, TEL-URI, or a Mobile Station International Subscriber Directory Number, MSISDN.

27. A computer program (424) comprising instructions which, when executed on processing circuitry (402), causes the processing circuitry (402) to carry out the method according to any one of claims 1 to 10.

28. A carrier containing the computer program (424) of claim 27, wherein the carrier is one of: an electronic signal, an optical signal, a radio signal, or a computer readable storage medium (424).