Lawful Intercept Trigger Configuration on Network Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for lawful intercept of network traffic in service provider networks face challenges, particularly in environments with high network traffic and frequent subscriber logins, and often require external authentication devices that not all service providers have access to.

Innovation Solution

The implementation of identification triggers on network devices within service provider networks, which allow for lawful intercept of subscriber sessions without relying on external authentication devices, using a command line interface to configure trigger rules and prioritize specific identification triggers for precise interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external authentication devices (RADIUS) are used to enable lawful intercept, then lawful intercept can be enabled for specific subscribers, but service providers without access to such devices cannot implement lawful intercept

Engineering Contradiction:
Improvelawful intercept capabilityVSAvoidapplicability to different service provider environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The invention extracts the lawful intercept functionality from the external authentication device (RADIUS) and implements it directly within the network device itself. The network device now contains internal trigger rules and identification mechanisms that enable it to independently perform lawful intercept without requiring external authentication devices, thus resolving the contradiction between reliability and adaptability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network device is enhanced with multi-functionality by integrating both authentication capabilities and lawful intercept capabilities into a single device. This universal approach allows the network device to perform lawful intercept in environments with or without external authentication devices, making the solution applicable to diverse service provider environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If lawful intercept is enabled on a specific interface via CLI, then intercept can be activated for that interface, but it becomes difficult to manage as network traffic and devices increase

Engineering Contradiction:
Improvelawful intercept activationVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention segments the lawful intercept configuration into modular trigger rules that can be independently defined, stored, and managed within the network device. Each trigger rule contains specific identification criteria (source/destination IP addresses, port numbers, protocol types) that can be individually configured and activated, making management scalable and organized even as network complexity increases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces trigger rules as intermediary elements between the CLI interface and the actual packet interception process. These trigger rules act as a structured intermediary layer that simplifies the configuration process by providing a standardized format for defining intercept criteria, reducing the complexity of managing lawful intercept across multiple interfaces and devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple identification triggers are configured for subscribers, then precise identification is achieved, but determining which trigger to apply when multiple match becomes complex

Engineering Contradiction:
Improvesubscriber identification precisionVSAvoidtrigger selection complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The invention applies preliminary action by pre-configuring trigger rules with hierarchical priorities before any packet matching occurs. Each trigger rule is assigned a priority level during configuration, establishing a predetermined selection order. When multiple triggers match a packet, the system automatically selects the highest-priority rule without requiring complex real-time decision logic, thus maintaining precision while reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8548132B1Lawful intercept trigger support within service provider networks
Publication Date: 2013.10.01 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8548132B1 patent drawing
  • US8548132B1 patent drawing
  • US8548132B1 patent drawing

AI summary

The invention is directed to techniques for initiating lawful intercept of packets associated with subscriber sessions on a network device of a service provider network based on identification triggers. A law enforcement agency may send an intercept request for a subscriber to an administration device of the service provider network. The administration device may then configure one or more identification triggers for the subscriber based on the intercept request. The techniques described herein initiate lawful intercept when one or more subscriber sessions on a network device match the one or more identification triggers. The techniques described herein include configuring trigger rules that include identification triggers for subscribers on a network device via a command line interface (CLI) of the network device. In addition, the techniques described herein include configuring identification triggers in a subscriber profile on an authentication device connected to a network device.