Routable Packet Structure for Lawful Intercept Traffic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for lawful intercept of network traffic, particularly in VoIP services, face challenges such as difficulty in predicting mobile user login locations, increased complexity with multiple network services and devices, and issues with mirroring data packet streams across different network types, making it hard to separate the interception and analysis points.

Innovation Solution

The implementation of an authentication device that communicates with network service devices to enable and disable monitoring, using a unique packet structure to form routable packets that encapsulate mirrored data streams, allowing them to be forwarded through any network type, regardless of the interface, and enabling dynamic initiation of intercepts during user sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional command line interface techniques are used to enable lawful intercept at network devices, then intercept functionality can be provided, but device complexity and difficulty of management increase as the number of network services and devices increase

Engineering Contradiction:
Improvelawful intercept capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication device as an intermediary that centralizes the control of lawful intercept functionality. Instead of managing intercept settings at each individual network device through command line interfaces, the authentication device acts as a mediator that receives intercept requests and automatically configures the appropriate network devices. This reduces management complexity by consolidating control in a single location while maintaining the ability to intercept traffic across multiple services and devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If mirrored data packet streams are forwarded across different network types, then traffic analysis can be performed remotely, but the packet structure becomes incompatible with standard routing protocols

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidpacket structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements packet encapsulation where the original mirrored data packet streams are nested inside a standardized outer packet structure. The inner packet contains the actual mirrored traffic data, while the outer packet includes standardized routing headers and control information that comply with standard routing protocols. This nested structure allows the mirrored traffic to be transported across different network types using conventional routing infrastructure without requiring modifications to the underlying packet format or routing behavior.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Ease of operation

If software applications are used to collect traffic flow information in conventional network analyzers, then traffic monitoring can be performed, but the system cannot dynamically adapt to mobile users logging in at different locations

Engineering Contradiction:
Improvetraffic monitoringVSAvoidmobile user support
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static traffic monitoring approach into a dynamic system by integrating lawful intercept functionality with the authentication process. When a mobile user logs in at any location, the authentication device dynamically determines which network devices are handling that user's traffic and automatically configures intercept settings accordingly. This dynamic adaptation allows the system to follow mobile users to any login location without requiring manual reconfiguration or prediction of user behavior patterns.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8116307B1Packet structure for mirrored traffic flow
Publication Date: 2012.02.14 JUNIPER NETWORKS INC
  • US8116307B1 patent drawing
  • US8116307B1 patent drawing
  • US8116307B1 patent drawing

AI summary

Network traffic associated with a user is lawfully intercepted by mirroring data packets flowing to and from the user for which interception has been designated. A unique packet structure enables analysis of mirrored data packets of any network type. In one implementation, a packet structure comprises routable packets that encapsulate the mirrored packet stream. The routable packet structure may be formed by prepending a correlation header to each mirrored packet. The correlation header includes a routing header to allow the mirrored packets to be transportable across the public Internet. In addition, an intercept header may be embedded within the correlation header to easily support various analyzer-specific implementations. The intercept header may include a version field that is extensible for the various analyzer implementations.