Method and switch for lawful interception
US-2016072850-A1 · Mar 10, 2016 · US
US2016219082A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016219082-A1 |
| Application number | US-201314917343-A |
| Country | US |
| Kind code | A1 |
| Filing date | Sep 9, 2013 |
| Priority date | Sep 9, 2013 |
| Publication date | Jul 28, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
In accordance with an example embodiment of the present invention, a method is provided for receiving ( 414 ) from a gateway apparatus an intercept request regarding user equipment in the communication system; creating or modifying a processing rule regarding the user equipment by including interception in the rule; transmitting ( 502 ) to a network switch processing user equipment connections a command to clone and encrypt each signalling or data packet of the user equipment connection and to transmit the encrypted signalling and data packets to a given network apparatus.
Opening claim text (preview).
1 . An apparatus in a communication system, said apparatus configured to control a network switch of the communication system, said apparatus comprising: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform: receive from a gateway apparatus an intercept request regarding user equipment in the communication system; create or modify a processing rule regarding the user equipment by including interception in the rule; transmit to the network switch processing user equipment connections a command to clone and encrypt each signalling or data packet of the user equipment connection and to transmit the encrypted signalling and data packets to a given network apparatus. 2 . The apparatus of claim 1 , wherein the apparatus is configured to if a processing rule regarding the user equipment exists, modify the processing rule by including interception in the rule. 3 . The apparatus of claim 1 , wherein the apparatus is configured to if a processing rule regarding the user equipment does not exist, create the processing rule and include interception command in the rule. 4 . The apparatus of claim 1 , wherein the user equipment connection is identified by an Internet Protocol (IP) address or a General packet radio service (GPRS) tunnelling protocol (GTP) tunnel endpoint identifier (TEID). 5 . The apparatus of claim 1 , wherein the apparatus is configured to send the network switch processing user equipment connections a command utilising an OpenFlow secure channel. 6 . The apparatus of claim 1 , wherein the apparatus is configured to obtain information that the user equipment connection is terminated; send the network switch a command to cease cloning and encrypting. 7 . The apparatus of claim 1 , wherein the apparatus is configured to direct cloned packets to a given output port; and wherein the apparatus comprises an encryption module configured to encrypt all packets directed to the given output port and forward the encrypted packets to a given network apparatus. 8 . The apparatus of claim 1 , wherein the apparatus is configured to prohibit Operation & Maintenance interfaces access to the rules related to interception. 9 . An apparatus in a communication system, said apparatus configured to be controlled by a controlling network element of the communication system, said apparatus comprising: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform: process user equipment connections by directing data signalling packets between user equipment and a gateway apparatus; receive from a controlling network element an intercept command related to a given user equipment connection; clone each signalling or data packet of the given user equipment connection; encrypt the cloned signalling and data packets; and transmit the encrypted signalling and data packets to a given network apparatus. 10 . The apparatus of claim 9 , wherein the user equipment connection is identified by an Internet Protocol (IP) address or a General packet radio service (GPRS) tunnelling protocol (GTP) tunnel endpoint identifier (TEID). 11 . The apparatus of claim 9 , wherein the apparatus is configured to receive the command utilising an OpenFlow secure channel. 12 . The apparatus of claim 9 , wherein the apparatus is configured to receive from a controlling network element a command to cease cloning and encrypting; cease the cloning and encrypting on the basis of the command and delete the intercept command. 13 . The apparatus of claim 9 , wherein the apparatus is configured to prohibit Operation & Maintenance interfaces access to the cloned signalling and data packets. 14 . The apparatus of claim 9 , wherein the apparatus is an OpenFlow switch. 15 . An apparatus in a communication system, said apparatus comprising: at least one processor; and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to perform: receive from a network apparatus an intercept request regarding a user equipment in the communication system, obtain information that a connection has been set up for the user equipment; transmit, to controlling network element that is controlling a network switch, a command to intercept the user equipment connection, the command comprising identification of the connection; transmit to the network apparatus interception related information (IRI). 16 . The apparatus of claim 15 , wherein the user equipment is identified by Mobile Subscriber Integrated Services Digital Network Number, International mobile subscriber identity or International Mobile Station Equipment Identity. 17 . The apparatus of claim 15 , wherein the user equipment connection is identified by an Internet Protocol (IP) address or a General packet radio service (GPRS) tunnelling protocol (GTP) tunnel identifier (TEID). 18 . A method in a communication system, comprising: receiving, by a controlling network element, from a gateway apparatus an intercept request regarding user equipment in the communication system; creating or modifying a processing rule regarding the user equipment by including interception in the rule; transmitting to a network switch processing user equipment connections a command to clone and encrypt each signalling or data packet of the user equipment connection and to transmit the encrypted signalling and data packets to a given network apparatus. 19 .- 25 . (canceled) 26 . A method in a communication system, comprising: processing, by a network switch, user equipment connections by directing data signalling packets between user equipment and a gateway apparatus; receiving from a controlling network element an intercept command related to a given user equipment connection; cloning each signalling or data packet of the given user equipment connection; encrypting the cloned signalling and data packets; and transmitting the encrypted signalling and data packets to a given network apparatus. 27 .- 30 . (canceled) 31 . A method in a communication system, comprising: receiving, by a gateway apparatus, from a network apparatus an intercept request regarding user equipment in the communication system; obtaining information that a connection has been set up for the user equipment; transmitting, to a controlling network element that is controlling a network switch, a command to intercept the user equipment connection, the command comprising identification of the connection; transmitting to the network apparatus interception related information (IRI). 32 . (canceled) 33 . (canceled) 34 . A non-transitory computer readable storage medium storing instructions which, when executed by one or more processors of an apparatus, at least one of a first method, a second method, and a third method, wherein the first method comprises: receiving from a gateway apparatus an intercept request regarding user equipment in the communication system; creating or modifying a processing rule regarding the user equipment by including interception in the ru
Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title
intercepting packet switched data communications, e.g. Web, Internet or IMS communications · CPC title
wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title
of the control plane, e.g. signalling traffic · CPC title
of the user plane, e.g. user's traffic · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.