Unified Serving Node Packet Deciphering for LTE Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Monitoring ciphered traffic flowing over S1 interfaces in modern LTE networks is challenging due to the lack of access to critical information exchanged between SGSNs and MMEs, which is essential for network performance monitoring.

Innovation Solution

A system that captures and deciphers packets across multiple interfaces, including those between UE and USN, HLR, and HSS, to extract and correlate user identifying information and ciphering keys, enabling the deciphering of NAS ciphered packets using stored mappings and keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If packets are captured only on external network interfaces, then network monitoring coverage is limited, but critical internal information flows are missed

Engineering Contradiction:
Improvecritical information flowsVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The monitoring system is nested within the USN architecture, with the USN containing both SGSN and MME functions. This nesting allows the monitoring point to access critical internal information flows between SGSN and MME that are otherwise inaccessible from external interfaces, resolving the contradiction between monitoring coverage and system complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The USN acts as an intermediary entity that bridges the gap between external network monitoring and internal critical information flows. By positioning the monitoring point at the USN level, the system can capture both external interface traffic and internal SGSN-MME communications without requiring direct access to multiple separate systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If ciphered packets are monitored without access to deciphering keys, then network security is maintained, but network performance analysis is impaired

Engineering Contradiction:
Improvenetwork performance analysisVSAvoidciphered traffic content
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system performs preliminary capture of deciphering keys and authentication information from authentication vectors before the actual ciphered traffic monitoring begins. This preliminary action stores the necessary keys in the monitoring system, enabling subsequent decryption of NAS ciphered packets without compromising network security during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring process is segmented into distinct phases: key capture phase (where authentication vectors and deciphering keys are obtained), and traffic analysis phase (where ciphered packets are decrypted and analyzed). This segmentation allows secure key management separate from the actual monitoring operations, resolving the contradiction between security and analysis capability.

Inventive Principle:
Principle #1Segmentation

3Loss of information

If multiple interfaces are monitored simultaneously, then comprehensive traffic capture is achieved, but system complexity increases

Engineering Contradiction:
Improvetraffic capture completenessVSAvoidmulti-interface monitoring complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The USN monitoring point is designed with multi-functionality, capable of simultaneously monitoring multiple interfaces (S1-MME, S11, S6a) and handling both ciphered and unciphered traffic. This universal monitoring capability achieves comprehensive traffic capture while consolidating complexity into a single multi-functional platform rather than requiring separate systems for each interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3393101B1Monitoring deciphered s1 packets on unified serving nodes
Publication Date: 2020.07.15 NETSCOUT SYSTEMS INC
  • EP3393101B1 patent drawingFigure 1
  • EP3393101B1 patent drawingFigure 2
  • EP3393101B1 patent drawingFigure 3

AI summary

First and second pluralities of packets transmitted between UE and the USN over a first interface and a second interface are continuously captured. The first, second and third pluralities contains temporary and permanent identifying information and ciphering key information. A fourth plurality of packets transmitted between the USN and a HSS over a fourth interface is captured. The temporary, permanent identifying information and the ciphering key information are correlated to determine mappings stored in a data repository. A fifth plurality transmitted over a fifth interface is continuously captured. Permanent identifying information corresponding to the temporary identifying information retrieved from the unciphered packets of the fifth plurality is retrieved from the data repository based on the stored mappings. NAS deciphering key information corresponding to the retrieved permanent identifying information is retrieved. The ciphered packets of the fifth plurality of packets are deciphered based on the retrieved NAS deciphering key information.