CN1870543A - Reporting method and system of using server, monitoring correlation event using it - Google Patents

Reporting method and system of using server, monitoring correlation event using it Download PDF

Info

Publication number
CN1870543A
CN1870543A CN 200510097593 CN200510097593A CN1870543A CN 1870543 A CN1870543 A CN 1870543A CN 200510097593 CN200510097593 CN 200510097593 CN 200510097593 A CN200510097593 A CN 200510097593A CN 1870543 A CN1870543 A CN 1870543A
Authority
CN
China
Prior art keywords
application server
monitoring
supplementary service
correlation event
incident
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN 200510097593
Other languages
Chinese (zh)
Other versions
CN100428700C (en
Inventor
郑波
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CNB2005100975939A priority Critical patent/CN100428700C/en
Publication of CN1870543A publication Critical patent/CN1870543A/en
Application granted granted Critical
Publication of CN100428700C publication Critical patent/CN100428700C/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Telephonic Communication Services (AREA)

Abstract

This invention provides an application server, a method for reporting related events monitored by it, in which, the method includes: requiring corresponding monitored data based on that of a legal monitor function entity, the application server judges if the related objects in the messages received or transmitted are monitored, if so, it reports the monitored related events, which can meet the needs of reporting the monitored attached service events to increase the application of the IMS network.

Description

Application server, use the report method and the system of its monitoring correlation event
Technical field
The present invention relates to communication technical field, relate in particular to a kind of application server that is used for reporting IMS territory legal monitoring business monitoring correlation event, and the report method and the system that use the monitoring correlation event of this application server.
Background technology
Lawful Interception (LI) is meant the needs of (country) release mechanism for law enforcement, and certain user or certain communication process are monitored.Monitoring comprises that the signaling aspect is monitored and the medium aspect is monitored: for the monitoring of signaling aspect, need output eavesdropping target's Intercept related information (IRI); For the monitoring of medium aspect, need output eavesdropping target's Content of Communication (CC).
ETSI (ETSI) has provided the demand of monitoring in ETSI TS 101331 (annex [01]), and has provided three interfaces between the communication equipment and Lawful Interception law actuating equipment in traditional circuit switching (CS) territory in ETSI ES 201671 (annex [02]): data-interface, Intercept related information report interface and Content of Communication to report interface.Wherein, to report interface (for example, X2 interface) be the interface that communication network reports Intercept related information to Intercept related information.
At present, continuous maturation along with group technology, to the broadband telecommunication net development based on packet switching, wherein, using Session Initiation Protocol is one of current technology trends as the call control signalling of grouping telecommunications core network based on Circuit-switched conventional telecommunication network.Based on the Lawful Interception standard in packet switching (PS) territory and the disappearance of operation flow and scheme, the user who causes being arranged in packet network is in the blind area of monitoring, thus the potential safety hazard of some countries and regions is also brought influence.
At this situation, in 3GPP TS33.107 (annex [05]), the identify label that has provided the Lawful Interception object in IP Multimedia System (IMS) territory is SIP URI and TEL URL; Think that the monitoring control network element (ICEs) in the IMS territory is P-CSCF (Proxy-CSCF) and S-CSCF (Serving-CSCF); And provided the Lawful Interception model in 3GPP IMS territory as shown in Figure 1.
Fig. 1 has shown the cellular logic structure chart that the monitoring correlation event in the legal monitoring business of 3GPP IMS territory reports.As shown in Figure 1, in this cellular logic structure chart, judicial execution monitoring equipment (LEMF) links to each other with the management function entity (ADMF) of Lawful Interception by non-electrical interface HI1, and by electrical interface HI2 with submit functional entity 2 (DF2) and link to each other; The management function entity of Lawful Interception links to each other with call conversation control function entity (CSCF) by electrical interface X11, and links to each other with DF2 by electrical interface X12; And this call conversation control function entity (CSCF) reports interface (X2) to link to each other with this DF2 by Intercept related information (IRI).Wherein, this call conversation control function entity comprise as the P-CSCF that monitors control network element (ICE) (agency-CSCF) and S-CSCF (serve-CSCF), this P-CSCF is used for professional registration, authentication and authentication, and this S-CSCF is used for calling out control, route and continues etc.This DF2 is corresponding with X2.
Easy and simple and clear for what describe, the appellation to functional entity will directly adopt english abbreviation below.
In the process that the administration of justice performed according to network configuration shown in Figure 1 monitored, LEMF at first by HI1, utilizes nonelectronic mode, as paper spare, interception request is notified to ADMF, for example provides eavesdropping target's identify label SIP URI.
Afterwards, this ADMF sends to DF2 and CSCF (comprising P-CSCF and S-CSCF) simultaneously with this interception request, and at this moment, this P-CSCF and S-CSCF are reported to DF2 as the IRI information source with the Intercept related information incident (IRI incident) of eavesdropping target in the IMS territory.
DF2 is according to the interception request from this ADMF, utilize monitoring correlation event to submit functional block (Mediation Function block, MF), the Intercept related information that reports is handled (for example judge whether to belong to eavesdropping target's Intercept related information or not for the Intercept related information that repeats etc.), afterwards, DF2 is reported to LEMF with this Intercept related information, thereby can be in the monitoring of LEMF realization to the eavesdropping target.
It should be noted that, above-mentioned DF2 can link to each other with a plurality of LEMF (for example listening center of law enforcement agency), and the cellular logic structure of the Intercept related information reporting events in the legal monitoring business of above-mentioned IMS territory clearly definition in the 3GPP agreement, here only sketch the method that CSCF reports monitoring correlation event, no longer the report relevant method and functional entity and above-mentioned interface to Content of Communication (CC) specifically describes.
Yet in the cellular logic structure in above-mentioned IMS territory, P-CSCF and S-CSCF can not solve all listen requirement as monitoring the control network element.In other words, the monitoring correlation event that above-mentioned P-CSCF and/or S-CSCF can report (IRI incident) is meant other IRI incident (in 3GPP TS 33.107 appendix corresponding description is arranged, no longer repeat at this) except that the supplementary service incident.Wherein, this supplementary service is meant other business except that basic session, for example application of Call Forwarding Unconditional business, register, cancel and call out or the like, caller identification or the like.
Specifically, when utilizing above-mentioned cellular logic structure that the eavesdropping target is monitored, P-CSCF and/or S-CSCF can not perception services.Therefore, when supplementary service took place the eavesdropping target, P-CSCF and/or S-CSCF can not be known the business of concrete generation, can not report this supplementary service incident.
The example that is applied as with the Call Forwarding Unconditional business: in the registered Call Forwarding Unconditional business of a user A, changeing object before it is user B, and this user A is monitored under the situation of (according to the interception request of ADMF), if certain user C calls out this user A, then the S-CSCF corresponding to user A carries out triggering rule (IFC), and this call request is routed to the application server (not showing among AS, the figure) of Call Forwarding Unconditional business, carry out the service logic of Call Forwarding Unconditional business by the AS of this Call Forwarding Unconditional business, call out the preceding commentaries on classics object (user B) that is finally before forwarded to registration.In said process, S-CSCF still is P-CSCF does not carry out the Call Forwarding Unconditional business in calling a service logic, thereby can not report Call Forwarding Unconditional service application incident (supplementary service).It should be noted that the implementation about application server (AS) and above-mentioned supplementary service all is to adopt existing techniques in realizing (referring to list of references: 3GPP TS 24.229 " IP Multimedia Call Control based on SIP and SDp; Stage 3 " And 3GPP TS24.228 " Signalling flows for the IP multimedia call control based on SIP and SDP; Stage 3 "), no longer repeat at this.
In sum, be necessary to propose can report the monitoring correlation event method of (comprising the supplementary service incident) in a kind of new IMS territory, thus the exploitativeness of enhancing IMS network.
Summary of the invention
First purpose of the present invention is to provide the report method of monitoring correlation event in the legal monitoring business of a kind of IMS territory, thereby can satisfy the supplementary service reporting events demand of monitoring, strengthens the exploitativeness of IMS network.
Second purpose of the present invention is to provide the reporting system of monitoring correlation event in the legal monitoring business of a kind of IMS territory, thereby can satisfy the supplementary service reporting events demand of monitoring, strengthens the exploitativeness of IMS network.
The 3rd purpose of the present invention is to provide the application server of monitoring correlation event in the legal monitoring business of a kind of IMS territory, thereby can satisfy the supplementary service reporting events demand of monitoring, strengthens the exploitativeness of IMS network.
According to first purpose of the present invention, the invention provides a kind of report method of monitoring correlation event, its basis is from the monitored data of the interception request correspondence of the management function entity of Lawful Interception, application server judge its reception and/or the message sent in related object whether monitored, if monitored, then report monitoring correlation event.
According to second purpose of the present invention, the invention provides a kind of reporting system of monitoring correlation event, it comprises judicial execution monitoring equipment, the management function entity of Lawful Interception, call conversation control function entity, and monitoring correlation event is submitted functional block, wherein judicial execution monitoring equipment sends to interception request the management function entity of Lawful Interception, call conversation control function entity and monitoring correlation event are submitted functional block and are obtained this interception request from the management function entity of this Lawful Interception, and this monitoring correlation event is submitted functional block will report judicial execution monitoring equipment from the monitoring correlation event except that supplementary service of call conversation control function entity, comprise: application server, it is used for the monitored data of basis from the interception request correspondence of the management function entity of Lawful Interception, judge whether it is monitored from call conversation control function entity reception and/or the related object to the message that call conversation control function entity sends, if monitored, then submit functional block and report monitoring correlation event to this monitoring correlation event.
According to the 3rd purpose of the present invention, the invention provides a kind of application server, comprising: business logic modules is used for carrying out service logic according to the message that this application server receives and/or sends; And the monitoring correlation event reporting module, be used for the monitored data of basis from the interception request correspondence of the management function entity of Lawful Interception, judge whether the related object in this message is monitored, if monitored, then report monitoring correlation event.
The invention has the beneficial effects as follows: the method, system and the application server that report according to monitoring correlation event provided by the invention, solved the problem that existing standard can not solve the supplementary service reporting events, having remedied P-CSCF and S-CSCF all can not perception service, and report the defective of supplementary service incident, thereby the present invention is perfect original monitoring correlation event report scheme, satisfy the supplementary service reporting events demand of monitoring, strengthened the exploitativeness of IMS network.
Description of drawings
Fig. 1 is the cellular logic structure chart that reports according to the monitoring correlation event in the IMS territory legal monitoring business of prior art;
Fig. 2 is the cellular logic structure chart that reports according to the monitoring correlation event in the legal monitoring business of IMS of the present invention territory;
Fig. 3 has shown the logical construction module map according to the application server of embodiments of the invention 1;
Fig. 4 has shown the schematic diagram that reports the Call Forwarding Unconditional business procedure according to IMS of the present invention territory;
Fig. 5 has shown the flow chart that reports the IRI incident according to the Lawful Interception application server of embodiments of the invention 2.
Embodiment
Below in conjunction with accompanying drawing the present invention is specifically described.
Embodiment 1
Fig. 2 is the cellular logic structure chart that reports according to the monitoring correlation event in the IMS territory legal monitoring business of embodiments of the invention 1.
According to the description to the functional entity among Fig. 1, identical processing procedure is not described in detail in this.
As shown in Figure 2, basic identical according to cellular logic structure and structure shown in Figure 1 that the monitoring correlation event in the legal monitoring business of IMS of the present invention territory reports, be outside unique difference: application server in the present embodiment (AS) is except that carrying out the service logic, it also can be used as the monitoring control network element (ICE) of IMS territory Lawful Interception, thereby on the basis of carrying out service logic, also can further report the supplementary service incident to DF2.Wherein, this application server also links to each other with this DF2 by interface X2.
This X2 interface is to monitor control gateway (ICE, Interception Control Element) and the interface between the DF2, this interface defines its transport layer in existing standard be TCP/IP, and provided the HI2 interface that the X2 interface application layer is near the mark as far as possible when transmitting Intercept related information (IRI), and transmitted initial data in the call signaling as far as possible and do not make amendment.Application server (AS) is followed above-mentioned criterion equally with the X2 interface of DF2 in the present invention.Adopt the mode of FTP (File Transfer Protocol, file transfer protocol (FTP)) to give DF2 with the IRI reporting events as AS.
Fig. 3 has shown the logical construction module map according to the application server of embodiments of the invention 1, wherein, according to the application server of embodiments of the invention 1 corresponding to the supplementary service application server.
According to above-mentioned cellular logic structure, and the module map of application server shown in Figure 3, the supplementary service application server comprises business logic modules 11 and monitoring correlation event reporting module 12, this business logic modules 11 is according to receiving from call conversation control function entity and/or to the message that call conversation control function entity sends, and carries out service logic (comprise professional registration, professional cancel, professional application and professional checking etc.).
And this monitoring correlation event reporting module 12 is according to the interception request from ADMF, judge and take place whether professional object is the eavesdropping target, if, then monitoring correlation event reporting module 12 reports corresponding supplementary service incident (incident and supplementary service checking incident etc. are cancelled in supplementary service registering events, supplementary service application affairs, supplementary service), if not, then only carry out service logic.
To be example with the Call Forwarding Unconditional business below, the method for the cellular logic structure realization supplementary service reporting events that monitoring correlation event of the present invention reports will be described.
Fig. 4 has shown the schematic diagram that reports the Call Forwarding Unconditional business procedure according to IMS of the present invention territory.
Be understood that, the application server AS that the present invention mentions is known functional entity, different business is to there being different application server AS, be that the Call Forwarding Unconditional business is with regard to a corresponding Call Forwarding Unconditional service application service device (CFU-AS), and in above-mentioned cellular logic structure, there is the application server of the different supplementary services of a plurality of correspondences; And in the IMS territory, the corresponding different CSCF (comprising P-CSCF and S-CSCF) of different user possibility also may be corresponding to identical CSCF.
Shown in Figure 4 reporting in the Call Forwarding Unconditional business procedure, Call Forwarding Unconditional business that user SIP URI B is registered, and preceding commentaries on classics is to liking user SIP URI C.Simultaneously, according to interception request from ADMF, the CSCF of user SIP URI B correspondence has known that user SIP URI B is the eavesdropping target, and the monitoring correlation event reporting module 12 in the Call Forwarding Unconditional service application service device is according to acquisitions and the corresponding monitored data of this interception request such as monitored data query interfaces.
When user UE calling party SIP URI B (called subscriber), the professional AS of Call Forwarding Unconditional reports the process of Call Forwarding Unconditional business as follows:
Step 1: user UE is initiated to the calling (Invite URI B) of called subscriber (SIP URI B), the P-CSCF that this call request arrival is corresponding with user UE;
Step 2: the P-CSCF corresponding with user UE further is forwarded to this call request the corresponding S-CSCF of called subscriber (SIP URI B), wherein, because above-mentioned forwarded call request process is consistent with existing operation flow, so omitted the S-CSCF of user UE correspondence and the I-CSCF of called subscriber's correspondence (the processing description of inquiry-CSCF) herein;
Step 3: the corresponding S-CSCF of called subscriber (SIP URI B) receives after the call request, carries out called subscriber's initial filter criteria (IFC); And in step 4: this call request is routed to corresponding Call Forwarding Unconditional service application service device;
Step 5: this Call Forwarding Unconditional service application service device utilizes business logic modules 11 to carry out the Call Forwarding Unconditional service logic according to this call request (message of reception); Then in step 6: this Call Forwarding Unconditional service application service device is replied 181 message to the S-CSCF of called subscriber's correspondence, indicates this calling by preceding commentaries on classics; And in step 7: the S-CSCF of called subscriber's correspondence is forwarded to the P-CSCF of this user UE correspondence with this 181 message; In step 8: the P-CSCF of this user UE correspondence further finally is forwarded to user UE with this 181 message;
Step 9: after Call Forwarding Unconditional service application service device is carried out above-mentioned Call Forwarding Unconditional service logic, business logic modules 11 in this Call Forwarding Unconditional service application service device is according to the registered Call Forwarding Unconditional business of called subscriber, change purpose user's (user SIP URI C) sign before the inquiry, this Call Forwarding Unconditional service application service device is carried out two steps simultaneously:
Step 11: the business logic modules 11 in this Call Forwarding Unconditional service application service device, according to the preceding commentaries on classics purpose user's who inquires about sign, this call request is passed through S-CSCF, is routed to the preceding purpose user SIP URI C (transmission message) of commentaries on classics; And
Step 10: the monitoring correlation event module 12 in this Call Forwarding Unconditional service application service device, the pairing monitored data of interception request that sends according to aforementioned ADMF (for example eavesdropping target's number etc.), judge whether user SIP URI B is monitored, if monitored, then the monitoring correlation event module 12 of this application server is reported to DF2 by X2 interface with the Call Forwarding Unconditional business event of Lawful Interception.In being reported to the process of DF2, the supplementary service that reports is the Call Forwarding Unconditional business, and the business operation type is for using, and this reports and has carried preceding commentaries on classics purpose user ID SIP URI C simultaneously.
Wherein, Call Forwarding Unconditional service application service device judges that the method whether user SIP URI B is monitored is: according to the service logic of its execution, this Call Forwarding Unconditional service application service device reception just and/or the message that sends, judge whether this monitored data comprises the identify label of related object in this message (this related object may be meant aforementioned user UE, called subscriber or preceding commentaries on classics object), if comprise, think that then this related object is monitored.
In addition, application server is reported to DF2 by X2 interface with the Call Forwarding Unconditional business event of Lawful Interception.Carrying by the business of the current generation of eavesdropping target in the reporting message is the Call Forwarding Unconditional business, and professional action type is for using, and the purpose user ID of preceding commentaries on classics is SIP URI C.Thereby DF2 can therefrom obtain information, and according to the HI2 interface of standard, Intercept related information is sent to LEMF.
Be understood that, present embodiment has only provided service application service device (the professional AS except that legal monitoring business AS) with regard to the application of the Call Forwarding Unconditional business in the standard I P IP multimedia subsystem, IMS (IMS) and has reported the process of supplementary service incident to be described, but the present invention is equally applicable to registration, the Call Forwarding Unconditional of Call Forwarding Unconditional business to be cancelled etc., thereby is reported the Lawful Interception dependent event (IRI incident) of supplementary service by corresponding service application server (AS).Equally, the method in the present embodiment can be generalized to other supplementary service, and as when by business such as eavesdropping target's application (register or cancel) Call Waiting, caller identifications, corresponding professional application server also can report corresponding supplementary service incident.
And present embodiment also can be applicable in the PSTN/ISDN Emulation Subsystem (PES) based on IMS, and specific implementation method and flow process are consistent, no longer repeat at this.
By above-mentioned method to the supplementary service reporting events, application server reports the supplementary service incident to DF2, and P-CSCF and S-CSCF report except that the supplementary service incident other IRI incident (for example, call setup), the invention solves existing standard and can not solve the problem of supplementary service reporting events, having remedied P-CSCF and S-CSCF all can not perception service, and report the defective of supplementary service incident, thereby the present invention is perfect original monitoring correlation event report scheme, satisfy the supplementary service reporting events demand of monitoring, strengthened the exploitativeness of IMS network.
Embodiment 2
Consistent according to the cellular logic structure chart that the monitoring correlation event in the IMS territory legal monitoring business of embodiments of the invention 2 reports with structure shown in Figure 2, and method and flow process that monitoring correlation event reports are unanimous on the whole, unique difference is: the application server according to embodiment 2 is the Lawful Interception application server, and this application server reports the supplementary service incident to DF2, simultaneously, also to other IRI incident that reports except that the supplementary service incident.Wherein, the Lawful Interception application server also comprises business logic modules 11 and monitoring correlation event reporting module 12, and the business logic modules 11 in the Lawful Interception application server is carried out is the legal monitoring business logic, and its monitoring correlation event reporting module 12 reports is other IRI incident except that supplementary service.
Wherein, according to interception request from ADMF, the CSCF of user SIP URI B correspondence has known that user SIP URI B is the eavesdropping target, and Call Forwarding Unconditional service application service device can be according to acquisitions and the corresponding monitored data of this interception request such as monitored data query interfaces.
It should be noted that: because The present invention be directed to monitoring service, even so in basic call, the Lawful Interception application server also is present in the above-mentioned cellular logic structure always, and this Lawful Interception application server can at any time report IRI incident (for example call setup), and do not rely on other business (application of supplementary service etc.).That is, reporting of this supplementary service application server and this legal monitoring business application server is separate.
That is to say, at user SIP URI B is under eavesdropping target's the situation, the Lawful Interception application server is present in the aforementioned network logical construction always, and the monitoring correlation event reporting module 12 in the Lawful Interception application server can report other IRI incident except that supplementary service.Only in the aforementioned network logical construction, has other supplementary service application server, and when supplementary service takes place, business logic modules 11 in the supplementary service application server is carried out the service logic of supplementary service, and its monitoring correlation event 12 just reports the supplementary service incident.
Fig. 5 has shown the flow chart that reports the IRI incident according to the Lawful Interception application server of embodiments of the invention 2.
As shown in Figure 5, be that to make a call with user SIP URI B be that example explanation Lawful Interception application server reports the IRI incident here.Its idiographic flow is as follows:
Step 1: user SIP URI B (by the eavesdropping target) makes a call to called, and this call request (message) is routed to the S-CSCF (Invite) of user SIP URI B correspondence through the P-CSCF (not shown);
Step 2: this S-CSCF triggers and checks the initial filter criteria (IFC) of Lawful Interception;
After the step 3:IFC coupling, this S-CSCF routes the call to legal monitoring business application server (LI-AS);
Step 4:LI-AS calls out according to this, judges whether the user is monitored (identical with the criterion among the embodiment 1);
Step 5: under the situation that the user is monitored, the business logic modules 11 among the LI-AS is carried out the legal monitoring business logic, and should call out route and return this S-CSCF;
Step 6: the monitoring correlation event reporting module 12 in the legal monitoring business application server (LI-AS) reports Intercept related information incident (IRI incident) to give DF2, promptly points out to be attempted calling out by the eavesdropping target in the message that reports;
Step 7: this S-CSCF is routed to next jumping according to called identify label with call request.
On the basis of above-mentioned steps, when if professional (comprise and making a call and supplementary service) takes place in user SIP URI B, after then the S-CSCF of user SIP URI B correspondence carries out initial filter criteria, should call out (message) and be routed to Lawful Interception application server and supplementary service application server respectively, its corresponding supplementary service application server reports the supplementary service incident to DF2, and the processing procedure of Lawful Interception application server and supplementary service application server is independent of each other.
Be understood that, only provide the IRI incident that legal monitoring business application server (LI-AS) reports setup requests in the foregoing description, in fact, except that the supplementary service incident, legal monitoring business application server (LI-AS) can report other any IRI incidents.
Certainly, the method that present embodiment provides also can be applicable in the PSTN/ISDN Emulation Subsystem (PES) based on IMS, and specific implementation method and flow process are consistent, no longer repeat at this.
The method that the monitoring correlation event that provides by present embodiment reports, the legal monitoring business application server reports other IRI incident except that the supplementary service incident to DF2, other service application service device reports the supplementary service incident to DF2 simultaneously, then need not P-CSCF and S-CSCF and report the IRI incident, thus further perfect original monitoring correlation event report scheme.
In sum, the method that reports according to monitoring correlation event provided by the invention, solved the problem that existing standard can not solve the supplementary service reporting events, having remedied P-CSCF and S-CSCF all can not perception service, and report the defective of supplementary service incident, thereby the present invention is perfect original monitoring correlation event report scheme, satisfied the supplementary service reporting events demand of monitoring, strengthen the exploitativeness of IMS network.
Concerning those skilled in the art, can associate other advantage and distortion easily according to above implementation type.Therefore, the present invention is not limited to above-mentioned specific embodiment, and it carries out detailed, exemplary explanation as just example to a kind of form of the present invention.In the scope that does not deviate from aim of the present invention, those of ordinary skills can replace resulting technical scheme by various being equal to according to above-mentioned specific embodiment, but these technical schemes all should be included in the scope of claim of the present invention and the scope that is equal within.

Claims (24)

1. the report method of a monitoring correlation event is characterized in that:
According to monitored data from the interception request correspondence of the management function entity of Lawful Interception, application server judge its reception and/or the message sent in related object whether monitored, if monitored, then report monitoring correlation event.
2. the report method of monitoring correlation event in the legal monitoring business of IMS as claimed in claim 1 territory, wherein,
Comprise at this monitored data under the situation of identify label of this related object, judge that this related object is monitored.
3. the report method of monitoring correlation event as claimed in claim 2, wherein,
This application server comprises legal monitoring business application server and supplementary service application server for all the professional application servers except that basic session.
4. the report method of monitoring correlation event as claimed in claim 3, wherein, this monitoring correlation event comprises supplementary service incident and other IRI incident except that the supplementary service incident.
5. the report method of monitoring correlation event in the legal monitoring business of IMS as claimed in claim 4 territory, wherein,
After carrying out service logic, this supplementary service application server reports the supplementary service incident.
6. the report method of monitoring correlation event as claimed in claim 4, wherein,
After the supplementary service application server was carried out service logic, this supplementary service application server reported the supplementary service incident; And
This legal monitoring business application server is carried out the legal monitoring business logic, and reports other IRI incident except that the supplementary service incident, and wherein, reporting of this supplementary service application server and this legal monitoring business application server is separate.
7. as the report method of claim 5 or 6 described monitoring correlation events, wherein,
The service logic that described application server is carried out is professional registration or professional cancelling or professional application or professional checking.
8. the report method of monitoring correlation event as claimed in claim 7, wherein,
This report method is applied to the IMS territory of standard, or based on the PSTN/ISDN Emulation Subsystem of IMS.
9. the reporting system of a monitoring correlation event, it comprises judicial execution monitoring equipment, the management function entity of Lawful Interception, call conversation control function entity, and monitoring correlation event is submitted functional block, wherein judicial execution monitoring equipment sends to interception request the management function entity of Lawful Interception, call conversation control function entity and monitoring correlation event are submitted functional block and are obtained this interception request from the management function entity of this Lawful Interception, and this monitoring correlation event is submitted functional block will report judicial execution monitoring equipment from the monitoring correlation event except that supplementary service of call conversation control function entity, it is characterized in that, further comprise:
Application server, be used for the monitored data of basis from the interception request correspondence of the management function entity of Lawful Interception, judge whether it is monitored from call conversation control function entity reception and/or the related object to the message that call conversation control function entity sends, if monitored, then submit functional block and report monitoring correlation event to this monitoring correlation event.
10. the reporting system of monitoring correlation event as claimed in claim 9, wherein,
This application server comprises at this monitored data under the situation of identify label of this related object, judges that this related object is monitored.
11. the reporting system of monitoring correlation event as claimed in claim 10, wherein,
This application server comprises legal monitoring business application server and supplementary service application server for all the professional application servers except that basic session.
12. the reporting system of monitoring correlation event as claimed in claim 11, wherein, the monitoring correlation event that this application server reports comprises supplementary service incident and other IRI incident except that the supplementary service incident.
13. the report method of monitoring correlation event as claimed in claim 12, wherein,
After carrying out the service logic of supplementary service, this supplementary service application server reports the supplementary service incident.
14. the reporting system of monitoring correlation event as claimed in claim 12, wherein,
After the supplementary service application server was carried out the service logic of supplementary service, this supplementary service application server reported the supplementary service incident; And
This legal monitoring business application server is carried out the legal monitoring business logic, and reports other IRI incident except that the supplementary service incident, and wherein, reporting of this supplementary service application server and this legal monitoring business application server is separate.
15. as the reporting system of claim 13 or 14 described monitoring correlation events, wherein,
The service logic that described application server is carried out is professional registration or professional cancelling or professional application or professional checking.
16. the reporting system of monitoring correlation event as claimed in claim 15, wherein,
This reporting system is applied to the IMS territory of standard, or based on the PSTN/ISDN Emulation Subsystem of IMS.
17. an application server is used to report monitoring correlation event, comprising:
Business logic modules is used for carrying out service logic according to the message that this application server receives and/or sends; And
The monitoring correlation event reporting module is used for the monitored data of basis from the interception request correspondence of the management function entity of Lawful Interception, judges whether the related object in this message is monitored, if monitored, then reports monitoring correlation event.
18. application server as claimed in claim 17, wherein, this application server comprises:
This monitoring correlation event reporting module comprises at this monitored data under the situation of identify label of this related object, judges that this related object is monitored.
19. application server as claimed in claim 18, wherein,
This application server comprises legal monitoring business application server and supplementary service application server for all the professional application servers except that basic session.
20. application server as claimed in claim 19, wherein,
This monitoring correlation event comprises supplementary service incident and other IRI incident except that the supplementary service incident.
21. application server as claimed in claim 20, wherein,
Business logic modules in this supplementary service application server is carried out the service logic of supplementary service, and after carrying out service logic, the monitoring correlation event reporting module in this supplementary service application server reports the supplementary service incident.
22. application server as claimed in claim 20, wherein,
Business logic modules in this supplementary service application server is carried out the service logic of supplementary service, and after carrying out service logic, the monitoring correlation event reporting module in this supplementary service application server reports the supplementary service incident; And
Business logic modules in this legal monitoring business application server is carried out the legal monitoring business logic, and the monitoring correlation event module in this legal monitoring business application server reports other IRI incident except that the supplementary service incident, wherein, reporting of this supplementary service application server and this legal monitoring business application server is separate.
23. as claim 21 or 22 described application servers, wherein,
The service logic that described application server is carried out is professional registration or professional cancelling or professional application or professional checking.
24. application server as claimed in claim 23, wherein,
This application server is in the IMS territory of standard, or based on the PSTN/ISDN Emulation Subsystem of IMS.
CNB2005100975939A 2005-12-30 2005-12-30 Reporting method and system of using server, monitoring correlation event using it Expired - Fee Related CN100428700C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB2005100975939A CN100428700C (en) 2005-12-30 2005-12-30 Reporting method and system of using server, monitoring correlation event using it

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB2005100975939A CN100428700C (en) 2005-12-30 2005-12-30 Reporting method and system of using server, monitoring correlation event using it

Publications (2)

Publication Number Publication Date
CN1870543A true CN1870543A (en) 2006-11-29
CN100428700C CN100428700C (en) 2008-10-22

Family

ID=37444099

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB2005100975939A Expired - Fee Related CN100428700C (en) 2005-12-30 2005-12-30 Reporting method and system of using server, monitoring correlation event using it

Country Status (1)

Country Link
CN (1) CN100428700C (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2010063174A1 (en) * 2008-12-01 2010-06-10 华为技术有限公司 Implementation method, system and device for ims monitoring
CN101222539B (en) * 2008-01-30 2012-02-29 中兴通讯股份有限公司 IP multimedia subsystem and its supplementary service monitoring method
US8320363B2 (en) 2008-12-01 2012-11-27 Huawei Technologies Co., Ltd. Implementation method, system and device of IMS interception
CN103905398A (en) * 2012-12-27 2014-07-02 华为技术有限公司 Distributed monitoring method and system, proxy monitoring apparatus, and monitoring control apparatus

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100359976C (en) * 2003-04-15 2008-01-02 华为技术有限公司 Method of proceeding grouping business listening based on mobile telephone number
DE60325907D1 (en) * 2003-09-05 2009-03-05 Ericsson Telefon Ab L M MONITORING IN A TELECOMMUNICATIONS NETWORK
CN1612563A (en) * 2003-10-28 2005-05-04 华为技术有限公司 System and method for monitoring and intercepting activity
US20050152275A1 (en) * 2004-01-14 2005-07-14 Nokia Corporation Method, system, and network element for monitoring of both session content and signalling information in networks
CN100397831C (en) * 2004-01-16 2008-06-25 华为技术有限公司 System and method for realizing IP multimedia business monitoring
CN100407800C (en) * 2004-04-12 2008-07-30 华为技术有限公司 Monitoring method based on general mobile communication system
CN1277433C (en) * 2005-03-18 2006-09-27 华为技术有限公司 Method for implementing listening

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101222539B (en) * 2008-01-30 2012-02-29 中兴通讯股份有限公司 IP multimedia subsystem and its supplementary service monitoring method
WO2010063174A1 (en) * 2008-12-01 2010-06-10 华为技术有限公司 Implementation method, system and device for ims monitoring
CN101420432B (en) * 2008-12-01 2012-10-17 华为技术有限公司 Implementing method, system and apparatus for IMS listening
US8320363B2 (en) 2008-12-01 2012-11-27 Huawei Technologies Co., Ltd. Implementation method, system and device of IMS interception
CN103905398A (en) * 2012-12-27 2014-07-02 华为技术有限公司 Distributed monitoring method and system, proxy monitoring apparatus, and monitoring control apparatus
CN103905398B (en) * 2012-12-27 2018-01-23 华为技术有限公司 Distributed monitor method, act on behalf of monitoring device, interception control device and system

Also Published As

Publication number Publication date
CN100428700C (en) 2008-10-22

Similar Documents

Publication Publication Date Title
US9973541B2 (en) Lawful interception in an IP multimedia subsystem network
JP5518485B2 (en) Authenticate caller ID information to protect against caller ID spoofing
CN101237692B (en) Apparatus, and associated method, for providing an instance identifier to a network database node of a mobile network
US20010052081A1 (en) Communication network with a service agent element and method for providing surveillance services
US20020051518A1 (en) Communication network with a collection gateway and method for providing surveillance services
CN1574985A (en) Server component redirection of new media path portion between packet-switched and circuit-switched portions of mobile switching center
US20140092782A1 (en) Communication system and communication control method
WO2010041414A1 (en) Communication system and communication control method
CN101043691B (en) Legal monitor method for IMS network
CN1870543A (en) Reporting method and system of using server, monitoring correlation event using it
CN101123822B (en) Implementation method for emergent call service in IP multimedia subsystem central service
CN1871832A (en) Sessions in a communication system
EP2569998B1 (en) Enabling set up of a connection from a non-registered UE in IMS
US20070274462A1 (en) Method, System and Access Control Function for Detecting Emergency Service
CN101068279B (en) Emergency call return call realizing method
CN101102612B (en) Implementation method for emergent call service in IP multimedia subsystem central service
CN101001444A (en) Anonymous emergency session setting method
CN101448233A (en) Method for realizing IP multimedia subsystem emergency call
CN101110683B (en) Method for implementing forced registration of urgent call
US20110289217A1 (en) Protection against unsolicited communication for internet protocol multimedia subsystem
JP5381087B2 (en) Communication system and communication control method
CN101022475A (en) Method, device and system for legal monitoring
CN101159761A (en) Method of processing login state subscription
Cisco Traffic Measurements
CN101047980A (en) Emmergency log-on method of Internet protocol multimedia subsystem field

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20081022