Lawful Interception of VPN Calls via Intercept Configuration Unit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current lawful interception standards cannot monitor Virtual Private Network (VPN) calls, as calling and called party numbers are not validated, making it impossible to intercept VPN calls and report Intercept Related Information events.

Innovation Solution

Introducing a new target type for interception in a telecommunication system that allows Lawful Enforcement Agencies to monitor VPN calls by using an Intercept Configuration Unit to request and receive Interception Related Information related to defined Corporate Networks, enabling the identification and interception of VPN calls within the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Virtual Private Network calls are intercepted using existing standards, then calling and called party numbers can be validated for public E.164 subscribers, but VPN calls cannot be monitored because they use private numbering

Engineering Contradiction:
Improveinterception capabilityVSAvoidnumbering system compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intercept point within the VPN infrastructure that acts as an intermediary between the private VPN network and the public lawful interception system. This intercept point validates VPN-specific identifiers and translates them into a format compatible with existing lawful interception standards, enabling monitoring without requiring changes to either VPN or public network numbering systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the identification parameter from public E.164 numbers to VPN-specific identifiers (such as private E.164 numbers or other VPN addressing schemes). By modifying which parameter is used for identification while maintaining the same interception functionality, the system can monitor VPN calls without relying on public numbering validation.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If existing Intercept Related Information events are used for monitoring, then public network calls can be reported, but VPN call events cannot be reported because they lack public subscriber identification

Engineering Contradiction:
Improvecall information reportingVSAvoidtarget identification accuracy
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent creates a copy of the existing lawful interception framework adapted for VPN use. Instead of modifying the core interception mechanism, it replicates the IRI event structure and fills it with VPN-specific identification data, allowing VPN calls to be reported using the same standardized events as public calls but with appropriate VPN identifier substitution.

Inventive Principle:
Principle #26Copying

3Ease of operation

If Lawful Enforcement Agencies want to monitor VPN calls, then they need access to VPN-specific identification systems, but current standards only support public E.164 subscriber identification

Engineering Contradiction:
Improvemonitoring accessVSAvoidinterception system structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent designs the interception system to serve multiple functions: it can handle both traditional public E.164 subscriber interception and VPN call interception through a unified interface. The system universally accepts different types of identifiers (public and private) and processes them through the same lawful interception workflow, eliminating the need for separate monitoring systems for VPN and public calls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8520804B2Lawful interception of DSS1 based virtual private network
Publication Date: 2013.08.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8520804B2 patent drawing
  • US8520804B2 patent drawing
  • US8520804B2 patent drawing

AI summary

The present invention relates to methods and arrangements in a telecommunication system to generate Interception Related Information IRI related to Virtual Private Network VPN calls, which telecommunication system provides Virtual Private Network services to at least one integrated exchange LE-C; in the system. The exchange LE-C is associated with an Intercept Configuration Unit ICU. The method comprises the following steps:—Sending from the Intercept Configuration Unit ICU to the exchange LE-C, a request REQ to monitor Virtual Private Network calls involving a defined Corporate Network CN-A.—Receiving by the exchange LE-C, a call message SETUP; IAM in Virtual Private Network context comprising an identification field identifying the defined Corporate Network CN-A.—Sending from the exchange LE-C to the Intercept Configuration Unit ICU, Interception Related Information IRI related to the call.