IP Library › Granted Patent US 12,500,944
Granted Patent B2
US 12,500,944 · App. 17/590,688 · Granted Dec 16, 2025

Methods and apparatus for automatically securing communications between a mediation device and a law enforcement device

Inventor: Girard Hoffpauir, IV (Austin, TX)
Assignee: Charter Communications Operating, LLC
H04L63/30H04L63/0823H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,944
App. No.
17/590,688
Granted
Dec 16, 2025
Kind
B2
Abstract

Methods and apparatus for automatically securing communications between a mediation device (MD) and a law enforcement device, such as an agent's terminal, to which intercepted communications, e.g., traffic, is sent are described. Based on a desired intercept request to be implemented, a Lawful Interception (LI) administration (admin) device (LID) identifies at least a first mediation device (MD) which will be involved in implementing the intercept request. The LID then proceeds to enable the use of a private certificate authority to automatically generate and provision the MD and a law enforcement device with certificates and private keys via an automated process. Each of the MD and law enforcement device automatically obtain a security certificate and corresponding private key. The security certificates and corresponding private keys are then used, in an automated manner, to establish a mutual TLS connection between the MD and the law enforcement device.

Claims (45)

1 . A method of supporting lawful intercept, the method comprising:

operating a mediation device (MD) to obtain a security token from a lawful intercept certificate authority (LICA);

operating the MD to send the security token to a law enforcement device;

operating the law enforcement device to receive the security token from the MD;

operating the law enforcement device to send a request for a security certificate and a private key to the LICA, said request including the security token; and

operating the law enforcement device to establish a secure connection with the MD, operating the law enforcement device to establish a secure connection with the MD including using keys for mutual authentication, said keys for mutual authentication including the private key corresponding to the law enforcement device that is supplied by the LICA in response to the request from the law enforcement device.

2 . The method of claim 1 , wherein said security certificate is received by the law enforcement device via a communications channel which is different from a connection used to: i) support intercept related control signals between the MD and the law enforcement device and ii) deliver intercepted traffic from the MD to the law enforcement device.

3 . The method of claim 1 , wherein the law enforcement device further receives from the MD an IP address to be used for requesting the security certificate.

4 . The method of claim 3 , further comprising:

operating the MD to perform an authentication operation with a lawful intercept secrets engine (LISE) in which said LICA is located, said authentication operation being a successful authentication operation; and

sending the security token from the LICA to the MD following said successful authentication operation.

5 . The method of claim 3 , further comprising:

operating the law enforcement device to receive intercepted traffic from the MD via the secure connection; and

operating the law enforcement device to recover intercepted traffic by using the private key from the LICA to decrypt intercepted traffic communicated via the secure connection.

6 . The method of claim 5 , further comprising:

operating the MD to request the security token, to be used by the law enforcement device to obtain a certificate, from a lawful intercept secrets engine (LISE) as part of obtaining the security token from the LICA.

7 . The method of claim 6 , further comprising:

operating the MD to receive a MD username and a password from a legal intercept administrative device (LID) to be used to authenticate to the LISE when requesting the security token which can be used for certificate creation requests.

8 . The method of claim 7 , further comprising:

operating the MD to receive a MD security certificate and a corresponding MD private key from the LICA.

9 . The method of claim 7 , further comprising:

operating the MD to automatically request the MD security certificate and the corresponding MD private key from the LICA following being provisioned with the MD username and the password that can be used by the MD to authenticate to the LISE.

10 . The method of claim 9 , further comprising:

operating the MD to automatically request, using the MD username and the password, the security token from the LISE to be used to obtain the MD security certificate and the corresponding MD private key.

11 . The method of claim 10 , wherein the MD communicates the security token to the LISE when requesting the MD security certificate.

12 . A communications system supporting lawful intercept, the communications system comprising:

a mediation device (MD) including a MD processor configured to control the MD to obtain a security token from a lawful intercept certificate authority (LICA) and send the security token to a law enforcement device;

the law enforcement device, said law enforcement device including a first processor configured to control the law enforcement device to:

receive the security token from the MD;

send a request for a security certificate and a private key to the LICA, said request including the security token; and

establish a secure connection with the MD using keys for mutual authentication, said keys including the private key corresponding to the law enforcement device that is supplied by the LICA in response to the request from the law enforcement device.

13 . The communications system of claim 12 , wherein said security certificate is received by the law enforcement device via a communications channel which is different from a connection used to: i) support intercept related control signals between the MD and law enforcement device and ii) deliver intercepted traffic from the MD to the law enforcement device.

14 . The communications system of claim 12 , wherein said first processor in the law enforcement device is further configured to control the law enforcement device to:

receive from the MD an IP address to be used for requesting the security certificate.

15 . The communications system of claim 14 , wherein said received information from the MD further includes the security token to be used to authenticate to the LICA when requesting the security certificate.

16 . The communications system of claim 14 , wherein the first processor is further configured to control the law enforcement device to:

receive intercepted traffic from the MD via the secure connection; and

recover intercepted traffic by using the private key from the LICA to decrypt intercepted traffic communicated via the secure connection.

17 . The communications system of claim 16 , wherein the MD processor is further configured to control the MD to: request the security token, to be used by the law enforcement device to obtain the security certificate, as part of obtaining the security token from the LICA.

18 . The communications system of claim 17 , wherein said MD processor is further configured to control the MD to:

receive a MD username and a password from a legal intercept administrative device (LID) to be used to authenticate to a lawful intercept secrets engine (LISE) when requesting the security token which can be used for certificate creation requests.

19 . The communications system of claim 18 , wherein said MD processor is further configured to control the MD to:

receive a MD security certificate and a corresponding MD private key from the LICA.

20 . The communications system of claim 19 , wherein said MD processor is further configured to control the MD to:

automatically request the MD security certificate and the corresponding MD private key from the LICA following being provisioned with the MD username and the password that can be used by the MD to authenticate to the LISE.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2022
From: HOFFPAUIR, GIRARD, IV
To: CHARTER COMMUNICATIONS OPERATING, LLC
Reel/Frame 059638/0404 →
Continuity (1)
Related Publication 20230247065A1 · Aug 3, 2023
References Cited (64)
US 7730521B1 · Thesayi · 2010 [cited by examiner]
US 8307203B2 · Fraleigh · 2012 [cited by examiner]
US 8537818B1 · Thesayi · 2013 [cited by examiner]
US 8792505B2 · Iovieno · 2014 [cited by examiner]
US 8811956B2 · Venkatachalam · 2014 [cited by examiner]
US 8843750B1 · Sokolov · 2014 [cited by examiner]
US 8856920B2 · Khan · 2014 [cited by examiner]
US 9204293B2 · Imbimbo · 2015 [cited by examiner]
US 9456009B2 · Smoyer · 2016 [cited by examiner]
US 9961078B2 · Van Den Broeck · 2018 [cited by examiner]
US 10778659B2 · Tola · 2020 [cited by examiner]
US 11133999B1 · Brosnan · 2021 [cited by examiner]
US 11349821B2 · Hallam-Baker · 2022 [cited by examiner]
US 11777998B2 · Carotenuto · 2023 [cited by examiner]
US 20030005291A1 · Burn · 2003 [cited by examiner]
US 20030182559A1 · Curry · 2003 [cited by examiner]
US 20040157629A1 · Kallio · 2004 [cited by examiner]
US 20040255126A1 · Reith · 2004 [cited by examiner]
US 20060005011A1 · Satoh · 2006 [cited by examiner]
US 20060085633A1 · Balfanz · 2006 [cited by examiner]
US 20060282662A1 · Whitcomb · 2006 [cited by examiner]
US 20070174469A1 · Andress · 2007 [cited by examiner]
US 20090034510A1 · Smoyer · 2009 [cited by examiner]
US 20090100040A1 · Sheppard · 2009 [cited by examiner]
US 20090158031A1 · Wan · 2009 [cited by examiner]
US 20100086119A1 · De Luca · 2010 [cited by examiner]
US 20100310077A1 · Sun · 2010 [cited by examiner]
US 20110142240A1 · Yoon · 2011 [cited by examiner]
US 20110176460A1 · Lovieno · 2011 [cited by examiner]
US 20120069971A1 · Jayaraman · 2012 [cited by examiner]
US 20130191631A1 · Ylonen · 2013 [cited by examiner]
US 20130236019A1 · Zaverucha · 2013 [cited by examiner]
US 20130318354A1 · Entschew · 2013 [cited by examiner]
US 20140010228A1 · Maione · 2014 [cited by examiner]
US 20140156991A1 · Baskaran · 2014 [cited by examiner]
US 20140207939A1 · Mraz · 2014 [cited by examiner]
US 20140286177A1 · Ni · 2014 [cited by examiner]
US 20140365781A1 · Dmitrienko · 2014 [cited by examiner]
US 20150006887A1 · Brand · 2015 [cited by examiner]
US 20150200972A1 · Suryavanshi · 2015 [cited by examiner]
US 20150341392A1 · Marfia · 2015 [cited by examiner]
US 20160182571A1 · Van Phan · 2016 [cited by examiner]
US 20170163629A1 · Law · 2017 [cited by examiner]
US 20180034858A1 · Gummaraju · 2018 [cited by examiner]
US 20200179429A1 · Vuckovic · 2020 [cited by examiner]
US 20210119990A1 · Law · 2021 [cited by examiner]
US 20210385255A1 · Imbimbo · 2021 [cited by examiner]
US 20220006800A1 · Duchastel · 2022 [cited by examiner]
US 20220263873A1 · Somma · 2022 [cited by examiner]
US 20230007474A1 · Ni · 2023 [cited by examiner]
US 20230028642A1 · Li · 2023 [cited by examiner]
US 20230179429A1 · Rosenthol · 2023 [cited by examiner]
US 20230224336A1 · Hoffpauir, IV · 2023 [cited by examiner]
WO WO2008086639A1 · 2008 [cited by examiner]
WO WO2012079653A1 · 2012 [cited by examiner]
WO WO2015008158A2 · 2015 [cited by examiner]
WO WO2020050755A1 · 2020 [cited by examiner]
WO WO2020071972A1 · 2020 [cited by examiner]
WO WO2025032037A1 · 2025 [cited by examiner]
Catalyst 6500 Series Switched Lawful Intercept Configuration Guide, Cisco IOS Software Release 12.2(33)SXH and later releases, Aug. 2007, 22 Pages, Cisco Systems, Inc. [cited by applicant]
Creating Private Certificates Authorities for Internal Use, Sep. 21, 2021, 10 pages, SecureW2, https://www.securew2.com/blog/creating-private-certificates. [cited by applicant]
Lawful Interception, Jul. 19, 2021, 9 Pages, Wikipedia, https://en.wikipedia.org/wiki/Lawful_interception. [cited by applicant]
TLS Interception, July 19, 2021, 6 pages,ORG Open Rights Group, https://wiki.openrightsgroup.org/wiki/TLS_interception. [cited by applicant]
Vinugayathri Chinnasamy, Enabling TLS 1.3 Certificate—Are You Ready for Moving Forward?, Indusface, Jan. 22, 2021, 8 pages, downloaded from https://www.indusface.com/blog/enabling-tls-1-3-certificate-are-you-ready-for-m… [cited by applicant]