Lawful Interception - Overview (continued)
Basic Elements of LI in a Public Telecom Network
There are three primary elements required within the public network to achieve Lawful Interception, these are:
- An Internal Intercept Function (IIF) located in the network nodes.
- A Mediation Function (MF) between the PTN and LEMF.
- An Administration Function (ADMF) to manage orders for interception in the PTN.
1) Internal Intercept Function (IIF)
These functions are located within the network nodes and are responsible for generating the Intercept Related Information (IRI) and Contents of Communications (CC).
2) Mediation Function (MF)
This function clearly delineates the PTN from the LEMF. It communicates with the IIFs using Internal Network Interfaces (INIs) which can be proprietary. The MF communicates to one or more LEMFs through locally standardized interfaces: the Handover Interfaces (HI2 and HI3).
3) Administration Function (ADMF)
This function handles the serving of interception orders and communicates with the IIFs and MF though an Internal Network Interface.
Implementing LI within a VoIP Network
One of the primary problems that service providers face when managing VoIP and multimedia calls is the separation of the signalling and media streams. In other words it is quite possible that the two streams may take completely different paths through the network. In addition, even when they do pass through the same device, it may not be aware of the relationship between the streams. Some devices within the network are however specifically designed to understand and manage the separate signalling and media streams - session border controllers. Typically located at the borders of the service provider's network, these offer an ideal location to implement the IIF as they receive Intercept Related Information from the signalling stream and can intercept Contents of Communication directly from the media stream.
Figure 4 - Example Physical Architecture
Figure 4 above shows the physical elements of the LI system, their logical functions and the interfaces to the LEMF.
LI Administration Function (ADMF) is typically implemented on a hardened Management Unit; it provides a secure method to enable traffic to be targeted and routed. The ADMF uses a secure connection to one or more of the IIFs and to one or more Mediation Units. The ADMF is often backed up by a warm standby, which replicates all data between the units.
LI Mediation Function (MF) performs the mediation and delivery functions, it is typically implemented on a hardened Mediation Unit; it receives generic formatted IRI and CC data from one or more IIFs and translates it into the country specific format for the Handover Interfaces (HI2 & HI3) to the LEMF. The MF receives target details from the ADMF and validates the received IRI and CC data to ensure that only the warranted data is passed to the LEMF. The MF usually supports the forwarding of intercepted traffic to many LEMF interfaces simultaneously. The Mediation Unit is often backed up by a slave unit which takes over in case of failure of the primary unit.
Internal Intercept Function (IIF) is most effective when implemented in hardware within the network nodes in order to provide the most effective and rapid detection without incurring additional software processing and delays which may allow the presence of the intercept to be detected. The IIF collects Intercept Related Information (IRI) and Contents of Communication (CC) ask requested by the ADMF, and converts these to a generic format which is passed to the MF.
|