VoP Network Surveillance via Encryption Key Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in implementing electronic surveillance in Voice over Packet (VoP) networks, particularly in tunnel mode and with network address translation (NAT), as they do not support the Communications Assistance for Law Enforcement Act (CALEA) requirements due to end-to-end encryption and lack of access to encryption keys.

Innovation Solution

The solution involves intercepting end-user encryption setup messages during call establishment to effect end-user identification and decryption, targeting NAT and encryption-capable devices for surveillance, and using application-specific algorithms to obtain necessary information for packet filtering and decryption, enabling law enforcement agencies to intercept and decode VoP communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end encryption is implemented in VoP networks, then security and privacy are improved, but surveillance capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsurveillance capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a surveillance access point (SAP) as an intermediary device in the network path between encrypted endpoints. The SAP intercepts encryption setup messages (such as SDP offers/answers containing ice-ufrag, ice-pwd, encryption keys) without breaking the end-to-end encryption between actual communication parties. This mediator enables law enforcement to obtain decryption credentials while maintaining the appearance of secure communication for normal users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary interception of encryption setup messages during the call establishment phase, before actual encrypted communication begins. By capturing SDP messages, ICE credentials, and encryption keys during the setup phase (INVITE, 200 OK, ACK exchanges), the surveillance system obtains decryption capabilities in advance, allowing subsequent decryption of the encrypted media streams without interfering with the established secure channel.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If network address translation (NAT) is used in VoP networks, then network flexibility and security are improved, but packet filtering and identification capability deteriorates

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidpacket filtering capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The SAP acts as an intermediary that observes and analyzes NAT translation behavior in the network path. By monitoring packet headers and NAT mapping relationships between private and public IP addresses, the SAP identifies the actual source and destination devices behind NAT gateways. This enables the system to filter and target specific packets for surveillance even when multiple devices share a single public IP address through NAT.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes its approach to packet identification by not relying on traditional IP address matching alone. Instead, it uses cryptographic identifiers from SDP messages (such as ice-ufrag and ice-pwd) and encryption key associations to identify packets, effectively changing the identification 'color' from network-layer IP addresses to application-layer cryptographic markers that remain consistent despite NAT translation.

Inventive Principle:
Principle #32Color changes

3Reliability

If tunnel mode encryption is implemented, then security is improved, but access to encryption keys for surveillance deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to encryption keys
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The surveillance system performs preliminary interception of key exchange messages during the tunnel establishment phase. By capturing SDP messages containing ice-pwd (ICE password), DTLS-SRTP credentials, and other encryption parameters before the encrypted tunnel is fully established, the system obtains the necessary keys and credentials to decrypt subsequent tunnel-encrypted traffic without needing to break the encryption itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The SAP serves as a mediator that passively observes the key exchange process between endpoints. Rather than attempting to penetrate the encrypted tunnel, the SAP intercepts the unencrypted or lightly encrypted setup messages (SDP, SIP) that carry the encryption credentials in plain text or weakly protected form, thereby obtaining access to the tunnel's decryption keys through the setup phase rather than through the encrypted data phase.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7587757B2Surveillance implementation in managed VOP networks
Publication Date: 2009.09.08 TELOGY NETWORKS INC
  • US7587757B2 patent drawing
  • US7587757B2 patent drawing
  • US7587757B2 patent drawing

AI summary

A procedure for accomplishing surveillance within a managed VoP network when end-user encryption/decryption and NAT are in place. The procedure comprises first analyzing the network from call signaling and message standpoints, leading to the identification of suitable surveillance access points (SAPs) for packet interception. A Delivery Function (DF) facilitated by the network service provider provides the means to intercept (without alteration) and replicate packets transmitted across the SAPs. The packets are then transmitted via the DF for collection within a Collection Function (CF), which is managed by a Law Enforcement Agency (LEA), for analysis by the LEA. This analysis provides, among other benefits, the opportunity to decrypt the intercepted packets and to identify additional suitable SAPs. In demonstrating the procedure, several embodiments of network surveillance models are described. Each one identifies the location of SAPs for that model. In each model, different information is collected and different processes are followed.