SRTP Header Storage for Undetectable Lawful Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current lawful interception methods for MIKEY-TICKET TEK based SRTP communications are detectable by both initiator and responder UEs, violating the requirement of undetectable interception, as the RANDRi and TGK information is discarded by the KMS, making mid-call interception possible only through re-keying.

Innovation Solution

Storing a nonce value, crypto session identity (CS ID), and traffic encryption key generation key (TGK) in the SRTP packet header's Master Key Identifier (MKI) field, allowing the KMS to regenerate the TEK for lawful interception without re-keying, ensuring non-detectable interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If re-keying is performed for mid-call interception, then interception capability is enabled, but detectability increases and lawful interception requirements are violated

Engineering Contradiction:
Improveinterception capabilityVSAvoiddetectability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-storing the RANDRi value in the KMS before the communication session ends. This allows the KMS to have the necessary key material readily available for future interception operations without needing to perform re-keying, thereby enabling undetectable mid-call interception while maintaining reliability of interception capability

Inventive Principle:
Principle #10Preliminary action

2Reliability

If RANDRi and TGK information is discarded by the KMS, then security is maintained, but mid-call interception becomes impossible without detectable re-keying

Engineering Contradiction:
Improveinterception capabilityVSAvoidkey material availability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies the discarding and recovering principle by selectively retaining the RANDRi value in the KMS while allowing other temporary key materials to be discarded. The RANDRi is recovered and stored in a manner that enables future TEK regeneration for lawful interception purposes, balancing security requirements with interception capability

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If key material is stored for future interception, then mid-call interception capability is improved, but storage requirements and system complexity increase

Engineering Contradiction:
Improveinterception capabilityVSAvoidKMS storage requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the extraction principle by isolating and storing only the essential RANDRi value in the KMS, rather than storing complete key material or multiple redundant copies. This minimal extraction of key material provides sufficient capability for TEK regeneration while minimizing storage requirements and system complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2803165B1System and method of lawful access to secure communications
Publication Date: 2019.04.24 BLACKBERRY LTD
  • EP2803165B1 patent drawingFigure 1
  • EP2803165B1 patent drawingFigure 2
  • EP2803165B1 patent drawingFigure 3

AI summary

The present disclosure relates to systems and methods for secure communications. In some aspects, one or more values used to generate an encryption key used to encrypt a packet are stored in a header of the packet. The packet is transmitted with the encrypted data portion in a communication. In some aspects, one or more values used to generate an encryption key are received. The encryption key is regenerated using the one or more values.