IP Library Granted Patent US 9,871,827
Granted Patent B2
US 9,871,827 · App. 15/225,543 · Granted Jan 16, 2018

System and method of lawful access to secure communications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,871,827
App. No.
15/225,543
Granted
Jan 16, 2018
Kind
B2
Abstract

The present disclosure relates to systems and methods for secure communications. In some aspects, a method of signalling an interception time period is described. At least one keying information used by a KMF to regenerate a key is stored. A start_interception message is signaled from an ADMF to a CSCF. A halt_message is signaled from the ADMF to the CSCF.

Claims (29)

1. A call session control function (CSCF), comprising:

a memory; and

at least one hardware processor communicatively coupled with the memory and configured to:

receive a start_interception message from an administration function (ADMF) in a network node over a X1_1 interface, wherein the start_interception message indicates a starting time for an interception time period of a lawful interception;

in response to receiving the start_interception message, initiate a request to a key management service (KMS) to regenerate a key based on stored keying information, wherein the regenerated key is used to decrypt one or more intercepted packets during the interception time period; and

receive a halt_message from the ADMF, wherein the halt_message indicates that the lawful interception is to be stopped.

2. The CSCF of claim 1 , wherein the halt_message includes a target user identifier.

3. The CSCF of claim 1 , wherein the key is regenerated using at least one keying information included in a TRANSFER_INIT message.

4. The CSCF of claim 1 , wherein the key is regenerated using at least one keying information included in a TRANSFER_RESP message.

5. The CSCF of claim 1 , wherein the key is regenerated using at least one of RANDRi, RANDRr, Initiator's Identity (IDRi), Responder's Identity (IDRr), crypto session identity (CS ID), modifier (MOD), header payload (HDR), key data transport payload (KEMAC), traffic encryption key (TEK) generation key (TGK), or TEK generation key (TGK).

6. The CSCF of claim 1 , wherein the halt_message is received over the X1_1 interface.

7. A non-transitory computer-readable medium containing instructions which, when executed, cause a computing device to perform operations comprising:

receiving, at a call session control function (CSCF), a start_interception message from an administration function (ADMF) in a network node over a X1_1 interface, wherein the start_interception message indicates a starting time for an interception time period of a lawful interception,

in response to receiving the start_interception message, initiating a request to a key management service (KMS) to regenerate a key based on stored keying information, wherein the regenerated key is used to decrypt one or more intercepted packets during the interception time period; and

receiving, at the CSCF, a halt_message from the ADMF, wherein the halt_message indicates that the lawful interception is to be stopped.

8. The non-transitory computer-readable medium of claim 7 , wherein the halt_message includes a target user identifier.

9. The non-transitory computer-readable medium of claim 7 , wherein the key is regenerated using at least one keying information included in a TRANSFER_INIT message.

10. The non-transitory computer-readable medium of claim 7 , wherein the key is regenerated using at least one keying information included in a TRANSFER_RESP message.

11. The non-transitory computer-readable medium of claim 7 , wherein the key is regenerated using at least one of RANDRi, RANDRr, Initiator's Identity (IDRi), Responder's Identity (IDRr), crypto session identity (CS ID), modifier (MOD), header payload (HDR), key data transport payload (KEMAC), traffic encryption key (TEK) generation key (TGK), or TEK generation key (TGK).

12. The non-transitory computer-readable medium of claim 7 , wherein the halt_message is received over the X1_1 interface.

13. A method, comprising:

receiving, at a call session control function (CSCF), a start_interception message from an administration function (ADMF) in a network node over a X1_1 interface, wherein the start_interception message indicates a starting time for an interception time period of a lawful interception;

in response to receiving the start_interception message, initiating a request to a key management service (KMS) to regenerate a key based on stored keying information;

decrypting the one or more intercepted packets during the interception time period using the regenerated key; and

receiving, at the CSCF, a halt_message from the ADMF, wherein the halt_message indicates that the lawful interception is to be stopped.

14. The method of claim 13 , wherein the halt_message includes a target user identifier.

15. The method of claim 13 , wherein the key is regenerated using at least one keying information included in a TRANSFER_INIT message.

16. The method of claim 13 , wherein the key is regenerated using at least one keying information included in a TRANSFER_RESP message.

17. The method of claim 13 , wherein the key is regenerated using at least one of RANDRi, RANDRr, Initiator's Identity (IDRi), Responder's Identity (IDRr), crypto session identity (CS ID), modifier (MOD), header payload (HDR), key data transport payload (KEMAC), traffic encryption key (TEK) generation key (TGK), or TEK generation key (TGK).

Assignments (14)
CORRECTIVE ASSIGNMENT TO CORRECT THE ADDED PATENT NUMBER TO REMOVE PATENT NO. 8,873,407 AT PREVIOUSLY RECORDED ON REEL 64066 FRAME 1. ASSIGNOR(S) HEREBY CONFIRMS THE NUNC PRO TUNC ASSIGNMENT EFFECTIVE DATE MARCH 20, 2023. Recorded Feb 2, 2026
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 074921/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT 12817157 APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 064015 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064807/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET AT PAGE 50 TO REMOVE 12817157 PREVIOUSLY RECORDED ON REEL 063471 FRAME 0474. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 5, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 064806/0669 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064066/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 16, 2023
From: OT PATENT ESCROW, LLC
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064015/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: BLACKBERRY LIMITED
To: OT PATENT ESCROW, LLC
Reel/Frame 063471/0474 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2019
From: CERTICOM CORP.
To: BLACKBERRY LIMITED
Reel/Frame 050610/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: CERTICOM (US) LIMITED
To: CERTICOM CORP.
Reel/Frame 043741/0914 →
CHANGE OF NAME Recorded Aug 31, 2017
From: RESEARCH IN MOTION CORPORATION
To: BLACKBERRY CORPORATION
Reel/Frame 043741/0572 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: BUCKLEY, MICHAEL EOIN
To: RESEARCH IN MOTION CORPORATION
Reel/Frame 043741/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: ZAVERUCHA, GREGORY MARC
To: CERTICOM CORP.
Reel/Frame 043466/0389 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: ZAVERUCHA, GREGORY MARC
To: CERTICOM CORP.
Reel/Frame 043466/0299 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: CAMPAGNA, MATTHEW JOHN
To: CERTICOM (U.S.) LIMITED
Reel/Frame 043466/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 043466/0097 →