Apparatus and method for lawful interception

US2016219082A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016219082-A1
Application numberUS-201314917343-A
CountryUS
Kind codeA1
Filing dateSep 9, 2013
Priority dateSep 9, 2013
Publication dateJul 28, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In accordance with an example embodiment of the present invention, a method is provided for receiving ( 414 ) from a gateway apparatus an intercept request regarding user equipment in the communication system; creating or modifying a processing rule regarding the user equipment by including interception in the rule; transmitting ( 502 ) to a network switch processing user equipment connections a command to clone and encrypt each signalling or data packet of the user equipment connection and to transmit the encrypted signalling and data packets to a given network apparatus.

First claim

Opening claim text (preview).

1 . An apparatus in a communication system, said apparatus configured to control a network switch of the communication system, said apparatus comprising: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform: receive from a gateway apparatus an intercept request regarding user equipment in the communication system; create or modify a processing rule regarding the user equipment by including interception in the rule; transmit to the network switch processing user equipment connections a command to clone and encrypt each signalling or data packet of the user equipment connection and to transmit the encrypted signalling and data packets to a given network apparatus. 2 . The apparatus of claim 1 , wherein the apparatus is configured to if a processing rule regarding the user equipment exists, modify the processing rule by including interception in the rule. 3 . The apparatus of claim 1 , wherein the apparatus is configured to if a processing rule regarding the user equipment does not exist, create the processing rule and include interception command in the rule. 4 . The apparatus of claim 1 , wherein the user equipment connection is identified by an Internet Protocol (IP) address or a General packet radio service (GPRS) tunnelling protocol (GTP) tunnel endpoint identifier (TEID). 5 . The apparatus of claim 1 , wherein the apparatus is configured to send the network switch processing user equipment connections a command utilising an OpenFlow secure channel. 6 . The apparatus of claim 1 , wherein the apparatus is configured to obtain information that the user equipment connection is terminated; send the network switch a command to cease cloning and encrypting. 7 . The apparatus of claim 1 , wherein the apparatus is configured to direct cloned packets to a given output port; and wherein the apparatus comprises an encryption module configured to encrypt all packets directed to the given output port and forward the encrypted packets to a given network apparatus. 8 . The apparatus of claim 1 , wherein the apparatus is configured to prohibit Operation & Maintenance interfaces access to the rules related to interception. 9 . An apparatus in a communication system, said apparatus configured to be controlled by a controlling network element of the communication system, said apparatus comprising: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform: process user equipment connections by directing data signalling packets between user equipment and a gateway apparatus; receive from a controlling network element an intercept command related to a given user equipment connection; clone each signalling or data packet of the given user equipment connection; encrypt the cloned signalling and data packets; and transmit the encrypted signalling and data packets to a given network apparatus. 10 . The apparatus of claim 9 , wherein the user equipment connection is identified by an Internet Protocol (IP) address or a General packet radio service (GPRS) tunnelling protocol (GTP) tunnel endpoint identifier (TEID). 11 . The apparatus of claim 9 , wherein the apparatus is configured to receive the command utilising an OpenFlow secure channel. 12 . The apparatus of claim 9 , wherein the apparatus is configured to receive from a controlling network element a command to cease cloning and encrypting; cease the cloning and encrypting on the basis of the command and delete the intercept command. 13 . The apparatus of claim 9 , wherein the apparatus is configured to prohibit Operation & Maintenance interfaces access to the cloned signalling and data packets. 14 . The apparatus of claim 9 , wherein the apparatus is an OpenFlow switch. 15 . An apparatus in a communication system, said apparatus comprising: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform: receive from a network apparatus an intercept request regarding a user equipment in the communication system, obtain information that a connection has been set up for the user equipment; transmit, to controlling network element that is controlling a network switch, a command to intercept the user equipment connection, the command comprising identification of the connection; transmit to the network apparatus interception related information (IRI). 16 . The apparatus of claim 15 , wherein the user equipment is identified by Mobile Subscriber Integrated Services Digital Network Number, International mobile subscriber identity or International Mobile Station Equipment Identity. 17 . The apparatus of claim 15 , wherein the user equipment connection is identified by an Internet Protocol (IP) address or a General packet radio service (GPRS) tunnelling protocol (GTP) tunnel identifier (TEID). 18 . A method in a communication system, comprising: receiving, by a controlling network element, from a gateway apparatus an intercept request regarding user equipment in the communication system; creating or modifying a processing rule regarding the user equipment by including interception in the rule; transmitting to a network switch processing user equipment connections a command to clone and encrypt each signalling or data packet of the user equipment connection and to transmit the encrypted signalling and data packets to a given network apparatus. 19 .- 25 . (canceled) 26 . A method in a communication system, comprising: processing, by a network switch, user equipment connections by directing data signalling packets between user equipment and a gateway apparatus; receiving from a controlling network element an intercept command related to a given user equipment connection; cloning each signalling or data packet of the given user equipment connection; encrypting the cloned signalling and data packets; and transmitting the encrypted signalling and data packets to a given network apparatus. 27 .- 30 . (canceled) 31 . A method in a communication system, comprising: receiving, by a gateway apparatus, from a network apparatus an intercept request regarding user equipment in the communication system; obtaining information that a connection has been set up for the user equipment; transmitting, to a controlling network element that is controlling a network switch, a command to intercept the user equipment connection, the command comprising identification of the connection; transmitting to the network apparatus interception related information (IRI). 32 . (canceled) 33 . (canceled) 34 . A non-transitory computer readable storage medium storing instructions which, when executed by one or more processors of an apparatus, at least one of a first method, a second method, and a third method, wherein the first method comprises: receiving from a gateway apparatus an intercept request regarding user equipment in the communication system; creating or modifying a processing rule regarding the user equipment by including interception in the ru

Assignees

Inventors

Classifications

  • Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title

  • H04L63/306Primary

    intercepting packet switched data communications, e.g. Web, Internet or IMS communications · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • of the control plane, e.g. signalling traffic · CPC title

  • of the user plane, e.g. user's traffic · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016219082A1 cover?
In accordance with an example embodiment of the present invention, a method is provided for receiving ( 414 ) from a gateway apparatus an intercept request regarding user equipment in the communication system; creating or modifying a processing rule regarding the user equipment by including interception in the rule; transmitting ( 502 ) to a network switch processing user equipment connections …
Who is the assignee on this patent?
Nokia Solutions & Networks Oy
What technology area does this patent fall under?
Primary CPC classification H04L63/306. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jul 28 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).