Routable Packet Structure for Lawful Intercept Traffic Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for lawful intercept of network traffic, particularly in VoIP services, face challenges such as difficulty in predicting mobile user login locations, increased complexity with multiple network services and devices, and issues with mirroring data packet streams across different network types, making it hard to separate the interception and analysis points.
Innovation Solution
The implementation of an authentication device that communicates with network service devices to enable and disable monitoring, using a unique packet structure to form routable packets that encapsulate mirrored data streams, allowing them to be forwarded through any network type, regardless of the interface, and enabling dynamic initiation of intercepts during user sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional command line interface techniques are used to enable lawful intercept at network devices, then intercept functionality can be provided, but device complexity and difficulty of management increase as the number of network services and devices increase
Solution Approach 1:
The patent introduces an authentication device as an intermediary that centralizes the control of lawful intercept functionality. Instead of managing intercept settings at each individual network device through command line interfaces, the authentication device acts as a mediator that receives intercept requests and automatically configures the appropriate network devices. This reduces management complexity by consolidating control in a single location while maintaining the ability to intercept traffic across multiple services and devices.
2Adaptability or versatility
If mirrored data packet streams are forwarded across different network types, then traffic analysis can be performed remotely, but the packet structure becomes incompatible with standard routing protocols
Solution Approach 1:
The patent implements packet encapsulation where the original mirrored data packet streams are nested inside a standardized outer packet structure. The inner packet contains the actual mirrored traffic data, while the outer packet includes standardized routing headers and control information that comply with standard routing protocols. This nested structure allows the mirrored traffic to be transported across different network types using conventional routing infrastructure without requiring modifications to the underlying packet format or routing behavior.
3Ease of operation
If software applications are used to collect traffic flow information in conventional network analyzers, then traffic monitoring can be performed, but the system cannot dynamically adapt to mobile users logging in at different locations
Solution Approach 1:
The patent transforms the static traffic monitoring approach into a dynamic system by integrating lawful intercept functionality with the authentication process. When a mobile user logs in at any location, the authentication device dynamically determines which network devices are handling that user's traffic and automatically configures intercept settings accordingly. This dynamic adaptation allows the system to follow mobile users to any login location without requiring manual reconfiguration or prediction of user behavior patterns.
Data Source
AI summary
Network traffic associated with a user is lawfully intercepted by mirroring data packets flowing to and from the user for which interception has been designated. A unique packet structure enables analysis of mirrored data packets of any network type. In one implementation, a packet structure comprises routable packets that encapsulate the mirrored packet stream. The routable packet structure may be formed by prepending a correlation header to each mirrored packet. The correlation header includes a routing header to allow the mirrored packets to be transportable across the public Internet. In addition, an intercept header may be embedded within the correlation header to easily support various analyzer-specific implementations. The intercept header may include a version field that is extensible for the various analyzer implementations.


