Trusted Execution Environment for D2D Lawful Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Lawful interception of device-to-device (D2D) communications poses a challenge as these communications do not traverse a core network, where interception is typically implemented, making it difficult for law enforcement to access content without disrupting the communication process.

Innovation Solution

Implementing a trusted execution environment (TEE) in mobile terminals to receive and verify messages instructing interception, allowing the terminal to store D2D communication content securely, either in its memory or a distinct memory, without informing the main operating system and enabling encrypted forwarding to a base station.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If D2D communication is implemented directly between devices, then communication quality and speed are improved, but lawful interception capability deteriorates

Engineering Contradiction:
Improvecommunication speedVSAvoidlawful interception capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary component within the mobile device that can intercept D2D communications locally. The TEE acts as a mediator between the direct device-to-device communication path and law enforcement access, enabling lawful interception without requiring the communication to traverse through core network nodes. This resolves the contradiction by maintaining direct D2D communication speed while providing an intermediate point for lawful access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If core network interception is used, then lawful access is enabled, but communication disruption occurs

Engineering Contradiction:
Improvelawful access capabilityVSAvoidcommunication continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the trusted execution environment with verification keys and interception capabilities before D2D communication occurs. The TEE is pre-established as a secure component that can autonomously verify authorization messages and intercept communications without requiring real-time core network intervention. This allows lawful access to be enabled while maintaining communication continuity, as the interception happens locally without disrupting the direct communication path.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If D2D communication bypasses core network, then interception difficulty increases, but communication privacy is improved

Engineering Contradiction:
Improvecommunication privacyVSAvoidinterception difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies local quality by implementing interception capability at the local device level rather than relying on network-level interception. The trusted execution environment is specifically configured within the mobile device to handle D2D communication interception, creating a localized interception point that maintains communication privacy for general traffic while enabling targeted lawful access where needed. This resolves the contradiction by improving privacy through direct D2D communication while maintaining interception capability through local TEE implementation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3028429B1Local communication interception
Publication Date: 2020.09.30 NOKIA TECHNOLOGIES OY
  • EP3028429B1 patent drawingFigure 1
  • EP3028429B1 patent drawingFigure 2
  • EP3028429B1 patent drawingFigure 3

AI summary

In accordance with an example embodiment of the present invention, there is provided an apparatus, comprising communication circuitry configured to receive a message, and execution circuitry configured to, in response to the message comprising an instruction to intercept a direct device-to-device (D2D) communication, render the apparatus capable of storing at least in part the direct device-to-device communication in at least one of the apparatus and a memory. The intercepting may comprise lawful interception.