Lawful Interception Switch Offloading Gateway Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing EPC networks face performance issues and scalability limitations when handling increased payload and lawful interception requests, leading to overloading of processing resources due to inefficient payload handling methods.
Innovation Solution
Implementing a method using an Openflow-enabled switch to offload intercepted traffic from the gateway to the switch, where packets are duplicated and forwarded directly to the lawful interception service provider entity, utilizing a flow control protocol to manage packet flow and handle lawful interception, thereby reducing the gateway's workload.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the gateway processes all intercepted packets directly, then lawful interception functionality is provided, but the gateway becomes overloaded and performance deteriorates under increased payload
Solution Approach 1:
The patent extracts the packet duplication and forwarding function from the gateway to a dedicated switch. The gateway only needs to identify packets requiring interception and send them to the switch, while the switch handles the resource-intensive duplication and forwarding to the lawful interception service provider entity, thus relieving the gateway's processing burden
Solution Approach 2:
The patent introduces a switch as an intermediary component between the gateway and the lawful interception service provider entity. This switch acts as a mediator that receives packets from the gateway, duplicates them, and forwards the duplicates to the service provider entity, thereby protecting the gateway from direct handling of high-volume intercepted traffic
2Reliability
If the gateway handles packet duplication and forwarding, then lawful interception is achieved, but device complexity and resource requirements of the gateway increase
Solution Approach 1:
The patent extracts the complex packet duplication and forwarding logic from the gateway to a dedicated switch. The gateway's responsibility is reduced to identifying packets requiring interception and routing them to the switch, while the switch handles the complex operations of duplication, encapsulation, and forwarding to the lawful interception service provider entity
Solution Approach 2:
The patent segments the lawful interception system into distinct functional components: the gateway responsible for packet identification and initial routing, the switch responsible for packet duplication and forwarding, and the lawful interception service provider entity responsible for processing intercepted data. This segmentation distributes complexity across multiple specialized components rather than concentrating it in the gateway
3Reliability
If packets are duplicated and forwarded to lawful interception service provider entity, then interception data is provided, but network payload increases and processing resources are consumed
Solution Approach 1:
The switch acts as an intermediary that efficiently handles packet duplication and forwarding. It receives packets from the gateway, creates duplicates, encapsulates them with appropriate headers containing target identity and routing information, and forwards only the necessary duplicated packets to the lawful interception service provider entity, thereby managing network payload efficiently
Data Source
AI summary
The present disclosure relates to methods and devices, of activating lawful interception. According to the present disclosure, a gateway comprises a controller for controlling, using a flow control protocol, the flow of packets through a switch controlled by the gateway. The switch receives (S11), from the controller, a lawful interception activation request, comprising a target identity; activates (S12), in response to said request, lawful interception on a target identified by the target identity; duplicates (S13), in the switch, packets targeting the target; encapsulates (S14) the duplicated packets with an additional header; and forwards (S15) duplicates from the switch directly to the lawful interception service provider entity (1) for further distribution to a Lawful interception Agency.


