IP Library Granted Patent US 11,323,488
Granted Patent B2
US 11,323,488 · App. 16/620,035 · Granted May 3, 2022

Enhanced lawful interception

Inventors: Catherine Truchan (Lorraine, CA); Suresh Krishnan (Suwanee, GA); Daniel Migault (Montreal, CA); Stere Preda (Longueuil, CA)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L63/306H04L9/0819H04L9/0869H04W12/033H04W12/037H04W12/80H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,323,488
App. No.
16/620,035
Granted
May 3, 2022
Kind
B2
Abstract

Systems and methods are disclosed herein that relate to secure monitoring or interception of traffic in a wireless communications system. In some embodiments, a method of operation of a network node comprises receiving a list of one or more obfuscated target identifiers from a monitoring node, where each obfuscated target identifier is a user identifier of a target user that is encrypted using a first encryption key that is unknown to the network node. The method further comprises receiving an encrypted packet from another network node and determining whether an encrypted user identifier of the encrypted packet matches one of the obfuscated target identifiers. The method further comprises, if the encrypted user identifier matches one of the obfuscated target identifiers, further encrypting the encrypted packet using a second encryption key negotiated between the network node and the monitoring node and transmitting the further encrypted packet to the monitoring node.

Claims (37)

1. A method of operation of a network node in a cellular communications network to provide monitoring of cellular network traffic, comprising:

receiving a list of one or more obfuscated target identifiers from a monitoring node, each obfuscated target identifier of the one or more obfuscated target identifiers being a user identifier of a target user that is encrypted using a first encryption key that is unknown to the network node;

receiving an encrypted packet from an element that operates to intercept traffic on another network node in the cellular communications network, where the encrypted packet is a concatenation of:

a first encrypted user identifier, which is a user identifier encrypted using the first encryption key; and

an encrypted data block, which is a block of data associated with the user identifier where the block of data is encrypted using the first encryption key;

determining whether the first encrypted user identifier of the encrypted packet matches one of the one or more obfuscated target identifiers; and

if the first encrypted user identifier of the encrypted packet matches one of the one or more obfuscated target identifiers:

further encrypting the encrypted packet using a second encryption key negotiated between the network node and the monitoring node to thereby provide a further encrypted packet; and

transmitting the further encrypted packet to the monitoring node.

2. The method of claim 1 wherein the block of data is an intercept related information or communication of content type of data.

3. The method of claim 1 wherein the block of data comprises data related to an attach procedure performed for a wireless device having the associated user identifier, data related to a connection procedure performed for the wireless device having the associated user identifier, data related to a tracking area update performed for the wireless device having the associated user identifier, an Internet Protocol, IP, header for an IP packet to or from the wireless device having the associated user identifier, and/or an IP payload for the IP packet to or from the wireless device having the associated user identifier.

4. The method of claim 1 further comprising:

receiving, from the element, a second encrypted packet and associated cryptographic information, where the second encrypted packet is a concatenation of:

a second encrypted user identifier, which is a second user identifier encrypted using an updated version of the first encryption key; and

a second encrypted data block, which is a block of data associated with the second user identifier where the block of data is encrypted using the updated version of the first encryption key;

updating the one or more obfuscated target identifiers based on the associated cryptographic information to provide one or more updated obfuscated target identifiers;

determining whether the second encrypted user identifier of the second encrypted packet matches one of the one or more updated obfuscated target identifiers; and

if the second encrypted user identifier of the second encrypted packet matches one of the one or more updated obfuscated target identifiers:

further encrypting the second encrypted packet using the second encryption key negotiated between the network node and the monitoring node to thereby provide a second further encrypted packet; and

transmitting the second further encrypted packet to the monitoring node.

5. The method of claim 4 wherein transmitting the second further encrypted packet to the monitoring node comprises transmitting the second further encrypted packet and at least a portion of the cryptographic information to the monitoring node.

6. The method of claim 5 wherein the at least a portion of the cryptographic information comprises an indication that enables the monitoring node to update the one or more obfuscated target identifiers.

7. The method of claim 4 wherein the cryptographic information comprises information that enables updating the one or more obfuscated target identifiers without secret keys.

8. The method of claim 4 wherein the cryptographic information comprises a delta value that represents a difference between a first pseudorandom keystream that represents the first encryption key and a second pseudorandom keystream that represents the updated version of the first encryption key.

9. The method of claim 8 wherein the cryptographic information further comprises a sequence number used to generate the updated version of the first encryption key.

10. The method of claim 8 wherein the first encryption key is a pseudorandom keystream generated via Advanced Encryption Standard, AES, in counter mode.

11. A network node in a cellular communications network to provide monitoring of cellular network traffic, comprising:

at least one processor; and

memory comprising instructions executable by the at least one processor whereby the network node is operable to:

receive a list of one or more obfuscated target identifiers from a monitoring node, each obfuscated target identifier of the one or more obfuscated target identifiers being a user identifier of a target user that is encrypted using a first encryption key that is unknown to the network node;

receive an encrypted packet from an element that operates to intercept traffic on another network node in the cellular communications network, where the encrypted packet is a concatenation of:

a first encrypted user identifier, which is a user identifier encrypted using the first encryption key; and

an encrypted data block, which is a block of data associated with the user identifier where the block of data is encrypted using the first encryption key;

determine whether the first encrypted user identifier of the encrypted packet matches one of the one or more obfuscated target identifiers; and

if the first encrypted user identifier of the encrypted packet matches one of the one or more obfuscated target identifiers:

further encrypt the encrypted packet using a second encryption key negotiated between the network node and the monitoring node to thereby provide a further encrypted packet; and

transmit the further encrypted packet to the monitoring node.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2019
From: TRUCHAN, CATHERINE; KRISHNAN, SURESH; MIGAULT, DANIEL; PREDA, STERE
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 051199/0627 →
Continuity (1)
Related Publication 20200213839A1 · Jul 2, 2020