Sampling Intercept Mediation Unit for Bandwidth Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Lawful Interception systems face challenges in efficiently identifying hidden content within intercepted data traffic, as current methods require thorough examination of large volumes of data, which is time-consuming and bandwidth-intensive, especially when dealing with voluminous data like P2P movies and IPTV streams.
Innovation Solution
Implementing a sampling mechanism within the Intercept Mediation and Delivery Unit to selectively sample content from intercepted data traffic at regular intervals, sending only these samples to Law Enforcement Agencies instead of the entire data stream, utilizing a configurable sampling rate to balance detection efficiency and bandwidth usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If all IP streams related to a target are intercepted and delivered as complete session data flows, then the Law Enforcement Agency can access all communication content, but the bandwidth consumption increases significantly
Solution Approach 1:
The patent segments the complete session data flow into individual IP packets and applies selective filtering to each packet based on its payload content. This allows the system to divide the data stream into manageable units and process them independently, keeping relevant packets while discarding irrelevant ones, thus reducing overall bandwidth consumption while maintaining access to important information.
Solution Approach 2:
The patent applies different quality levels to different parts of the data stream by performing Deep Packet Inspection on individual packets. Relevant packets (those containing potentially useful information) are retained in high quality, while irrelevant packets (such as those containing P2P movie data or IPTV streams) are discarded. This local differentiation of quality allows the system to focus bandwidth on important data while eliminating waste.
2Loss of energy
If Deep Packet Inspection is used to filter out voluminous non-relevant content in real time, then bandwidth usage is reduced, but hidden content inside data may not be detected
Solution Approach 1:
The patent applies partial filtering by examining only specific portions of packets (such as payload sections) rather than requiring complete reconstruction and analysis of entire data streams. The system performs selective Deep Packet Inspection on packets that appear relevant based on initial criteria, applying excessive scrutiny only where needed rather than uniformly across all data, thus balancing detection capability with bandwidth efficiency.
Solution Approach 2:
The patent introduces an intermediary filtering mechanism that sits between the complete data interception and the final analysis stage. This intermediary layer performs preliminary Deep Packet Inspection to identify and flag packets that may contain hidden content, allowing the system to focus detailed examination only on suspicious packets rather than all intercepted data, thus maintaining detection capability while reducing overall processing burden.
3Loss of information
If the entire intercepted data stream is delivered to the Law Enforcement Agency, then complete information is available for analysis, but the time required to examine the data increases significantly
Solution Approach 1:
The patent performs preliminary filtering and classification of intercepted packets before delivering them to the Law Enforcement Agency. By examining packet headers, protocols, and payload characteristics in advance, the system pre-sorts data into relevant and irrelevant categories, delivering only the relevant subset to analysts. This preliminary action significantly reduces the volume of data requiring detailed examination while ensuring that no potentially important information is missed.
Solution Approach 2:
The patent extracts and removes irrelevant data (such as known P2P traffic, video streaming content, and other non-communication-related data) from the intercepted stream before delivery. This extraction process creates a refined dataset containing primarily communication-related packets that are more likely to contain evidence of criminal activity, thus reducing examination time while maintaining information completeness for relevant cases.
4Loss of energy
If selective filtering is applied in the operator domain, then bandwidth is saved, but hidden messages embedded in voluminous content remain undetected
Solution Approach 1:
The patent applies preliminary anti-action by implementing Deep Packet Inspection specifically targeted at detecting steganographic patterns before the data is filtered or discarded. The system looks for anomalies in packet structures, unusual payload patterns, and metadata inconsistencies that may indicate hidden content. By taking this preliminary anti-action against potential steganography, the system can identify suspicious packets for further analysis even when they are embedded within voluminous otherwise-irrelevant data streams.
Solution Approach 2:
The patent introduces an intermediary detection layer that operates between the filtering mechanism and the final data delivery. This intermediary performs specialized analysis for steganographic content, examining packets that would otherwise be filtered out due to their apparent irrelevance. The intermediary acts as a safety net that catches potentially suspicious data before it is discarded, allowing the system to maintain bandwidth efficiency while preserving the ability to detect hidden messages through specialized pattern recognition.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method, entities and an arrangement in a node a Lawful Interception, LI, network, said arrangement being configured to provide a Law Enforcement Agency (200) with Intercept Related Information, IRI, and Content of Communications, CC,of data traffic in a digital communications network. The IRI and CC is forwarded to an Intercept Mediation and Delivery unit node (IMDU;114) of the LI network, wherein the Intercept Mediation and Delivery unit (IMDU;114)is configured to sample the content of communications according a certain sampling rate to achieve one or more samples of the CC, and to forward the generated one or more samples to the Law Enforcement Agency (200).