Lawful Intercept KMS Identification in IMS Core Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication security solutions for IP multimedia subsystems (IMS) rely on the security of the signaling plane, which is compromised when multiple Key Management Servers (KMSs) are deployed, making lawful intercepting insecure.

Innovation Solution

Storing KMS information in the IMS core network network elements during user registration and intercepting session request signaling to obtain identification information, allowing lawful intercepting devices to find and retrieve key material from the corresponding KMS, independent of the signaling plane security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the KMS ID is transmitted in plaintext in signaling, then the lawful intercepting device can easily obtain the KMS information, but the security of the system is compromised

Engineering Contradiction:
Improveease of obtaining KMS informationVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the KMS information transmission from the plaintext signaling domain and relocates it to the encrypted domain. The KMS ID is encrypted using the first encryption algorithm along with other signaling parameters, separating secure key management information from the unprotected signaling plane. This allows lawful intercepting devices to access encrypted traffic and extract KMS information without relying on plaintext signaling security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an encryption algorithm as an intermediary between the KMS ID and the signaling transmission. Instead of directly transmitting the KMS ID in plaintext, the system uses encryption as a mediator to transform the KMS ID into ciphertext that can be securely transmitted within the signaling message, maintaining both security and accessibility for lawful interception.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple KMSs are deployed in the network, then the system flexibility and load distribution are improved, but the complexity of KMS identification and selection increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidKMS identification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring the mapping relationship between user equipment and KMS in the network element before actual communication occurs. During user registration, the network element stores the correspondence between user identifiers and their assigned KMS identifiers. When lawful interception is needed, the intercepting device can directly query this pre-established mapping using the user's identifier to quickly determine which KMS to access, eliminating the need for complex real-time selection algorithms.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the signaling plane security is relied upon for lawful intercepting, then the intercepting process is simplified, but the intercepting security is reduced when signaling is tampered with

Engineering Contradiction:
Improveintercepting process simplicityVSAvoidintercepting security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent converts the potential harm of signaling tampering into a benefit by using the same encryption mechanism that protects user communication to also protect KMS information transmission. The lawful intercepting device, which has access to the decryption keys, can decrypt the encrypted signaling to extract KMS information, while any unauthorized tampering with the signaling would result in decryption failures or invalid data, automatically preventing unauthorized access. This transforms the security vulnerability of plaintext signaling into a secure authenticated access mechanism.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP2472769B1Method for obtaining information of key management server, and method, system and device for monitoring
Publication Date: 2016.08.17 ZTE CORP
  • EP2472769B1 patent drawingFigure 1~2
  • EP2472769B1 patent drawingFigure 3
  • EP2472769B1 patent drawingFigure 4~5

AI summary

The present invention discloses a method for obtaining key management server information, and an intercepting method, system and device, including: in the process of a user equipment registering an IP multimedia subsystem (IMS), storing the KMS information corresponding to the user equipment in a preset IMS core network network element; and when a lawful intercepting device monitors a session initiated by the user equipment, intercepting a session request signaling sent by the user equipment, and obtaining an identification information of the user equipment from the session request signaling, and searching the KMS information corresponding to the user equipment from the preset IMS core network network element according to the identification information of the user equipment. The technical solution of the present invention makes the requirement of lawful intercepting be met without depending on security of the signaling plane when a plurality of KMSs are deployed in the IP multimedia subsystem.