Secure Injection Channel for Lawful Interception Identity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of 5G communication networks, existing lawful interception systems face challenges in managing information when an intercept access point is outside the network operator's domain, particularly with the rapid growth of Over-The-Top (OTT) services, leading to security concerns and regulatory imbalances.

Innovation Solution

A method is introduced that involves establishing a secure injection channel via the X1 interface between the lawful interception function and a network element, allowing the transmission of a lawful interception software module and target information, which is stored in a protected memory area, enabling the interception of user traffic while hiding target subscriber identities from the network element.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an intercept access point is placed outside the network operator's domain to monitor OTT services, then the ability to intercept user traffic is improved, but security concerns arise and target subscriber identities may be exposed to unauthorized parties

Engineering Contradiction:
Improveinterception capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a secure injection channel as an intermediary mechanism between the LI function and network elements. This channel acts as a protected mediator that enables target information to be transmitted to the IAP without exposing it to unauthorized access, thus maintaining security while enabling interception capability outside the operator's domain

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the LI system into distinct functional components: the LI function that manages target information, the secure injection channel that protects transmission, and the IAP that performs interception. This segmentation allows the IAP to operate independently outside the operator's domain while the LI function maintains secure control, resolving the contradiction between versatility and security

Inventive Principle:
Principle #1Segmentation

2Productivity

If target information is transmitted to an external intercept access point, then monitoring of OTT services is enabled, but target subscriber identities may be exposed

Engineering Contradiction:
Improvemonitoring capabilityVSAvoididentity exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The secure injection channel serves as a protected intermediary that transmits target information from the LI function to the IAP. This intermediary mechanism enables the IAP to obtain necessary targeting information for monitoring OTT services while preventing unauthorized access to subscriber identities, thus enabling productivity without exposing sensitive information

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different security qualities to different parts of the system: the secure injection channel provides high-level protection for target information transmission, while the IAP operates with localized access only to the extent necessary for its interception function. This differentiated security approach enables monitoring capability while minimizing identity exposure risk

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3861695B1Secure lawful interception in network elements
Publication Date: 2024.04.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3861695B1 patent drawingFigure 1a~1b
  • EP3861695B1 patent drawingFigure 2
  • EP3861695B1 patent drawingFigure 3a~3c

AI summary

A mechanism is provided that enables hiding identities of a target subscriber that is to be subject of lawful interception, LI, when the intercept access point, IAP, is outside the network operator part of the LI domain. Monitoring of data traffic such as over-the-top, OTT, services is enabled while at the same time hiding LI target identities to a network element, NE, containing the IAP. A secure memory area in the NE is dedicated to the LI functionality necessary to intercept and report interception data to the operator part of the LI domain. The interface between the NE and the operator part of the LI domain is the use of a secure injection channel via which the necessary LI software and target information are conveyed between the NE and the operator part of the LI domain.