Lawful interception of encrypted communications

US10432606B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10432606-B2
Application numberUS-201214370862-A
CountryUS
Kind codeB2
Filing dateApr 27, 2012
Priority dateFeb 7, 2012
Publication dateOct 1, 2019
Grant dateOct 1, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and apparatus for providing access to an encrypted communication between a sending node and a receiving node to a Law Enforcement Agency (LEA). A Key Management Server (KMS) function stores cryptographic information used to encrypt the communication at a database. The cryptographic information is associated with an identifier used to identify the encrypted communication between the sending node and the receiving node. The KMS receives a request for Lawful Interception, the request including an identity of a Lawful Interception target. The KMS uses the target identity to determine the identifier, and retrieves the cryptographic information associated with the identifier from the database. The cryptographic information can be used to decrypt the encrypted communication. The KMS then sends either information derived from the cryptographic information or a decrypted communication towards the LEA. This allows the LEA to obtain a decrypted version of the communication.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method of providing access to an encrypted communication between a sending node and a receiving node to a Law Enforcement Agency, the method comprising, at a Key Management Server function, by first: storing at a database cryptographic information used to encrypt the communication, the cryptographic information associated with an identifier used to identify the encrypted communication between the sending node and receiving node; then receiving a request originating from a Law Enforcement Agency for Lawful Intercept, the request including an identity of a target for Lawful Interception and wherein the request is received after the encrypted communication between the sending node and the receiving node has started; then using the target identity to determine the identifier, and retrieving from the database the cryptographic information associated with the identifier, the cryptographic information usable to decrypt the encrypted communication; and then sending one of information derived from the cryptographic information and a decrypted communication towards the Law Enforcement Agency. 2. The method according to claim 1 , the method comprising, at the Key Management Server function: receiving from the sending node, a request for a ticket, the request containing cryptographic information relating to the sending node; generating a first key to be used by the sending node, a ticket, and storing the first key and sending node cryptographic information associated with the identifier in the database; sending the first key and ticket and information related to the identifier to the sending node; receiving from the receiving node a request, the request message including the ticket, information related to the identifier and further cryptographic information relating to the receiving node; generating a second key to be used by the receiving node, and receiving node cryptographic information, associated with the identifier in the database; sending the second key to the receiving node. 3. The method according to claim 2 , wherein the Key Management Server function is provided in more than one Key Management Server and wherein the step of generating the second key comprises information exchange between at least two of the more than one Key Management Servers. 4. The method according to claim 1 , wherein the identifier is derived using at least any of a timestamp, implicit knowledge of the current time, a sequence number associated with the session, a ticket identifier, a key identifier, and a session identifier. 5. The method according to claim 1 , wherein the identifier is derived using the identities of at least one of the sending node and receiving node. 6. A method of providing Lawful Interception of an encrypted communication between a sending node and a receiving node, the method comprising, at a Lawful Intercept node, by first receiving packets relating to the encrypted communication, the packets including information associated with an identifier, the identifier being associated with cryptographic information used to encrypt the communication and stored in a Key Management Server; then sending a request to a Key Management Server, the request including the information associated with the identifier, and wherein the request is sent after the encrypted communication between the sending node and the receiving node has started; then receiving any of the cryptographic information associated with the identifier and a decrypted version of the encrypted communication; and then sending the cryptographic information associated with the identifier and/or the decrypted version of the encrypted communication towards a Law Enforcement Agency. 7. A Key Management Server, KMS, for use in a communications network, the KMS comprising: a processing function for first storing at a database cryptographic information used to encrypt a communication between a sending node and receiving node, the cryptographic information being associated with an identifier; a receiver for then receiving a request originating from a Law Enforcement Agency for Lawful Intercept, the request including an identity of a target for Lawful Interception, and wherein the request is received after the encrypted communication between the sending node and the receiving node has started; wherein the processing function is configured to then use the target identity to determine the identifier, and then retrieve from the database the cryptographic information associated with the identifier, the cryptographic information usable to decrypt the encrypted communication; and a transmitter for then sending the cryptographic information towards the Law Enforcement Agency. 8. The KMS according to claim 7 , wherein the receiver is arranged to receive from the sending node a request for a ticket, the request containing cryptographic information relating to the sending node, the KMS further comprising: a generation function for generating a first key to be used by the sending node, the key and sending node cryptographic information being associated with the identifier in the database; the transmitter being further arranged to send the key, the ticket and information related to the identifier to the sending node; the receiver being further arranged to receive from the receiving node a request, the request message including the ticket, information related to the identifier and further cryptographic information relating to the receiving node; the generation function being further arranged to generate a second key to be used by the receiving node, the second key and receiving node cryptographic information being associated with the identifier in the database; the transmitter being further arranged to send the second key to the receiving node. 9. A Lawful Intercept node for use in a communications network, the Lawful Intercept node comprising: a receiver for first receiving packets relating to an encrypted communication between a sending node and a receiving node, the packets including information associated with an identifier, the identifier being associated with cryptographic information used to encrypt the communication; a transmitter for then sending a request to a Key Management Server to provide encryption information for an encrypted communication, the request including the information associated with the identifier, and wherein the request is sent after the encrypted communication between the sending node and the receiving node has started; the receiver being further arranged to then receive any of the cryptographic information associated with the identifier and a decrypted version of the encrypted communication; and the transmitter being further arranged to then send the cryptographic information associated with the identifier and/or the decrypted version of the encrypted communication towards a Law Enforcement Agency. 10. The method according to claim 1 , wherein the method is performed by a processor, which when executed, performs the method of a computer program comprising computer readable code means, stored on a memory. 11. The method according to claim 1 , wherein the method is performed by a computer program stored on a non-transitory computer readable medium.

Assignees

Inventors

Classifications

  • intercepting packet switched data communications, e.g. Web, Internet or IMS communications · CPC title

  • using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title

  • using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • for key distribution, e.g. centrally by trusted party (cryptographic mechanisms or cryptographic arrangements for key distribution involving a central third party H04L9/0819) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10432606B2 cover?
A method and apparatus for providing access to an encrypted communication between a sending node and a receiving node to a Law Enforcement Agency (LEA). A Key Management Server (KMS) function stores cryptographic information used to encrypt the communication at a database. The cryptographic information is associated with an identifier used to identify the encrypted communication between the sen…
Who is the assignee on this patent?
Naslund Mats, Iovieno Maurizio, Norrman Karl, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0807. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 01 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).