Mediation Device for Lawful Intercept Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing amount of IP Video traffic poses a challenge for lawful intercepts, as commercial IP Video has limited investigative value and consumes significant bandwidth and processing resources.
Innovation Solution
A mediation device is used to filter lawfully intercepted content delivery network (CDN) traffic by receiving provisioned intercepts, sending intercept requests to point of interception devices, and acquiring private keys for CDNs to decrypt and filter intercepted traffic based on predefined rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all intercepted CDN traffic is forwarded to law enforcement networks for processing, then complete monitoring capability is maintained, but bandwidth and processing resources are excessively consumed
Solution Approach 1:
The mediation device performs preliminary decryption and filtering of intercepted CDN traffic before forwarding it to law enforcement networks. By decrypting traffic using acquired private keys and applying filter rules to identify and discard non-interesting traffic (such as commercial IP video), the system prepares the traffic in advance, ensuring only relevant content reaches the law enforcement network for processing.
Solution Approach 2:
The mediation device extracts and removes non-interesting traffic from the intercepted CDN stream by applying filter rules. Commercial IP video and other low-value content are identified and discarded, separating only the potentially investigative-relevant traffic for forwarding to law enforcement networks, thereby reducing resource consumption while maintaining monitoring effectiveness.
2Loss of energy
If filtering rules are applied to decrypt and filter intercepted traffic, then resource consumption is reduced, but device complexity increases
Solution Approach 1:
The mediation device is designed to perform multiple functions: acquiring private keys from CDN servers, decrypting intercepted encrypted traffic, applying filter rules to identify and discard non-interesting traffic, and forwarding filtered traffic to law enforcement networks. This multi-functional approach consolidates complex operations into a single device, managing complexity through integration rather than distribution.
Solution Approach 2:
The mediation device serves as an intermediary between the point of interception and law enforcement networks. It acquires private keys from CDN servers, decrypts traffic, applies filtering, and forwards results. This intermediary role manages complexity by centralizing key management and filtering operations in a dedicated mediation layer, simplifying the overall system architecture.
3Loss of energy
If commercial IP video is excluded from delivery to law enforcement, then bandwidth is saved, but investigative completeness may be compromised
Solution Approach 1:
The filter rules apply different quality standards to different types of traffic. Commercial IP video and other low-value content are discarded with lower priority, while traffic that may have investigative value is preserved and forwarded. This local quality approach ensures that bandwidth is saved on clearly non-essential content while maintaining investigative completeness for potentially relevant traffic.
Data Source
AI summary
Methods and apparatus for filtering lawfully intercepted encrypted traffic are described. A communications service provider network includes a mediation device and a security device. The mediation device receives a provisioned intercept request including a target IP address and one or more unique identifies corresponding to the target. The security device acquires certificates and private keys corresponding to one or more content distribution networks of interest for which intercepted traffic is to be partially or fully discarded. The mediation device receives filtering requests specifying filtering rules to be applied. Intercepted traffic is processed by the mediation device operating in conjunction with the security device to attempt decryption and identify the corresponding CDN network for the intercepted traffic. The mediation devices filters the decrypted traffic in accordance with the filtering rules, discarding traffic that is not of interest to the law enforcement agency (LEA) and sending traffic of interest to the LEA.


