EP4649634A1 - Encrypting and decrypting payload for lawful interception - Google Patents

Encrypting and decrypting payload for lawful interception

Info

Publication number
EP4649634A1
EP4649634A1 EP23700177.1A EP23700177A EP4649634A1 EP 4649634 A1 EP4649634 A1 EP 4649634A1 EP 23700177 A EP23700177 A EP 23700177A EP 4649634 A1 EP4649634 A1 EP 4649634A1
Authority
EP
European Patent Office
Prior art keywords
ned
nonce
core device
interface
algorithm
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP23700177.1A
Other languages
German (de)
French (fr)
Inventor
Maria Donata DE BONIS
Chiara SANTELLA
Antonio GIORGIO GAGGIA
Carmine Galotto
Mariano RUSSO
Daniele GAITO
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Telefonaktiebolaget LM Ericsson AB
Original Assignee
Telefonaktiebolaget LM Ericsson AB
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Telefonaktiebolaget LM Ericsson AB filed Critical Telefonaktiebolaget LM Ericsson AB
Publication of EP4649634A1 publication Critical patent/EP4649634A1/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/30Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/80Arrangements enabling lawful interception [LI]

Definitions

  • the invention generally relates to lawful interception (LI) in a communication system; more specifically, to a network element device, a method performed by the network element device, an LI core device, a method performed by the LI core device, corresponding computer programs and corresponding computer program products.
  • LI lawful interception
  • Lawful interception (LI) of traffic between communicating entities in a telecommunication network is subject to standardization work carried out by the 3 rd Generation Partnership Project (3GPP) and the European Telecommunications Standards Institute (ETSI).
  • 3GPP 3 rd Generation Partnership Project
  • ETSI European Telecommunications Standards Institute
  • 5G network architecture is characterized by freely combinable, highly scalable microservices distributed over a cluster of network nodes in the network. This has spread services across the network, exposing such services to more opportunities for security breaches unless mitigated.
  • An LI system is connected to a Network Element/Point of Intercept (NE/POI) via interfaces XI, X2 and X3.
  • the NED is a discrete telecommunications function hosted in an entity, which can be managed over a specific interface.
  • the NED is functionally equivalent to a network function (NF) and the NED and NF may be used interchangeably.
  • the XI interface is used by the LI system to manage the intercept function in the POI; the X2 interface is used by POI to send intercept related information (IRI) to the LI system; the X3 interface is used by NE/POI to send call content (CC) to the LI system.
  • an LI Core comprises an administration function (ADMF) which exchanges messages with the POI via the XI interface, and the NE/POI sends data related to IRI and CC.
  • the data related to IRI and CC may be referred to as xIRI and xCC respectively, on the X2 and X3 interface according to ETSI TS 103 221-2 Vl.6.1.
  • US 2020/0267189 discloses an LI ADMF and a method performed by the LI ADMF related to LI.
  • xIRI and xCC contain information related to the target along with other sensitive information involved in the network traffic with the target. It would be desirable to address this potential exposure of sensitive target information over the network while allowing for flexibility inherent in a distributed and scalable network.
  • An object of the invention is to enable for management of lawful interception data related to a target to be more secure and/or more flexible.
  • a method performed by a network element device (NED) in a communication system comprises a lawful interception (LI) point of interception (POI).
  • the method comprises receiving a nonce associated with a target identifier.
  • the method comprises obtaining an indication of an encryption algorithm and encrypting a payload of LI data.
  • the payload of LI data is related to the target identifier.
  • the payload is encrypted using the nonce and the encryption algorithm.
  • the method enables the transfer of encrypted LI data from the NED to an LI core device (e.g.
  • ADMF administrative function
  • ADMF administrative function
  • an attack surface of a related communication system is reduced by making gathering of sensitive information of target identifiers from vulnerable microservices in the communication system more difficult.
  • Another advantage of the method is that confidentiality related to information of the target identifier is improved.
  • Another possible advantage of the method is increased robustness of a communication system related to the NED.
  • the placement of a POI in a communication system can be made more flexibly, e.g. by enabling an Access and Management Function (AMF) provided with a POI to be positioned in less secure sites than a typical, heavily secure core network of a mobile network operator or a communications service provider.
  • AMF Access and Management Function
  • the method comprises obtaining an indication of a hashing algorithm.
  • the method comprises calculating a hash value obtained by applying the hashing algorithm to the target identifier using the nonce.
  • encrypting a payload of LI data comprises using the hash value as a cryptographic key for the encryption algorithm.
  • the method comprises sending the encrypted payload over an X interface.
  • receiving a nonce associated with a target identifier comprises receiving a nonce associated with the target identifier and an X interface.
  • the method comprises obtaining an indication of a further encryption algorithm, receiving a further nonce associated with the target identifier, encrypting a further payload of LI data using the further encryption algorithm and the further nonce and sending the encrypted further payload over a different X interface.
  • the communication system comprises a LI core device and the method comprises sending to the LI core device, information indicative of one or more of the encrypted payload, the indication of the hashing algorithm and the indication of the encryption algorithm.
  • the method comprises sending to the LI core device, information indicative of the calculated hash value.
  • the method of obtaining an encryption algorithm comprises receiving a first list of encryption algorithms that are available for use by the LI core device.
  • the method comprises transmitting to the LI core device a second list of encryption algorithms that are available for use by the NED.
  • the method of obtaining the hashing algorithm comprises receiving a first list of hashing algorithms that are available for use by the LI core device.
  • the method comprises transmitting to the LI core device, a second list of hashing algorithms that are available for use by the NED.
  • the method comprises informing other network element devices in the communication system to cease using the T ransport Layer Security Protocol for messages communicated over an X interface.
  • T ransport Layer Security Protocol for messages communicated over an X interface.
  • obtaining an indication of an encryption algorithm comprises comparing the first list of encryption algorithms to the second list of encryption algorithms and selecting, based on the comparison, a mutual encryption algorithm, wherein the mutual encryption algorithm is common to the first list and second list of encryption algorithms.
  • the method comprises transmitting an indication of the mutual encryption algorithm to the LI core device.
  • obtaining an indication of an encryption algorithm comprises receiving, from an LI core device, information indicative of the encryption algorithm.
  • the method comprises receiving from the LI core device, an indication of the hashing algorithm and a hash value obtained by applying the hashing algorithm to the target identifier using the nonce, intercepting a payload of data for the LI core device, retrieving intercepted target identifiers (ITIs) from the intercepted payload of data, applying the hashing algorithm using the hash value to the ITIs to obtain intercepted target identifier hashed values, if one of the obtained intercepted target identifier hashed values matches the hash value, transmitting the intercepted payload of data to the LI core device.
  • ITIs intercepted target identifiers
  • the method of obtaining an indication of the hashing algorithm comprises comparing the first list of hashing algorithms to the second list of hashing algorithms, and selecting, based on the comparison, a mutual hashing algorithm, wherein the mutual hashing algorithm is common to the first list and second list of hashing algorithms.
  • the method comprises transmitting an indication of the mutual hashing algorithm to the LI core device.
  • receiving a nonce associated with a target identifier comprises one or more of: receiving a first nonce associated to an XI interface; receiving a second nonce associated to an X2 interface; and receiving a third nonce associated to an X3 interface; and wherein obtaining an indication of an encryption algorithm comprises one or more of: obtaining an indication of a first encryption algorithm associated to the XI interface; obtaining an indication of a second encryption algorithm associated to the X2 interface; and obtaining an indication of a third encryption algorithm associated to the X3 interface.
  • encrypting a payload of LI data related to the target identifier comprises one or more of: encrypting the payload of LI data, to be sent through the X2 interface, using the second nonce and the second encryption algorithm; and encrypting the payload of LI data, to be sent through the X3 interface, using the third nonce and the third encryption algorithm.
  • the method comprises receiving, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: a first hashing algorithm associated to the XI interface; a second hashing algorithm associated to the X2 interface; a third hashing algorithm associated to the X3 interface; a hash value associated to the XI interface; the first nonce; the second nonce; the third nonce; the first encryption algorithm; the second encryption algorithm; and the third encryption algorithm.
  • a NED in a communications system comprises a LI POI.
  • the NED is adapted to receive a nonce associated with a target identifier and obtain an indication of an encryption algorithm.
  • the NED is adapted to encrypt a payload of LI data related to the target identifier, using the nonce and the encryption algorithm.
  • the NED is adapted to obtain an indication of a hashing algorithm. According to an embodiment, the NED is adapted to calculate a hash value obtained by applying the hashing algorithm to the target identifier using the nonce.
  • the NED adapted to encrypt a payload of LI data comprises the NED adapted to use the hash value as a cryptographic key for the encryption algorithm.
  • the NED is adapted to send the encrypted payload over an X interface.
  • the NED adapted to receive a nonce associated with a target identifier comprises the NED adapted to receive a nonce associated with the target identifier and an X interface.
  • the NED is adapted to obtain an indication of a further encryption algorithm, receive a further nonce associated with the target identifier, encrypt a further payload using the further encryption algorithm and the further nonce, and send the encrypted further payload over a different X interface.
  • the communication system comprises a LI core device and the NED is adapted to send to the LI core device, information indicative of one or more of the encrypted payload, the indication of the hashing algorithm and the indication of the encryption algorithm.
  • the NED is adapted to send to the LI core device, information indicative of the calculated hash value.
  • the NED adapted to obtain an indication of an encryption algorithm comprises the NED adapted to receive a first list of encryption algorithms that are available for use by the LI core device.
  • the NED is adapted to transmit to the LI core device a second list of encryption algorithms that are available for use by the NED.
  • the NED is adapted to inform other network element devices in the communication system to cease using the T ransport Layer Security Protocol for messages communicated over an X interface.
  • the NED adapted to obtain an indication of the encryption algorithm comprises the NED adapted to compare the first list of encryption algorithms to the second list of encryption algorithms and select, based on the comparison, a mutual encryption algorithm, wherein the mutual encryption algorithm is common to the first list and second list of encryption algorithms.
  • the method comprises transmitting an indication of the mutual encryption algorithm to the LI core device.
  • the NED adapted to obtaining an indication of an encryption algorithm comprises the NED adapted to receive, from an LI core device, information indicative of the encryption algorithm.
  • the NED adapted to receive from the LI core device, an indication of the hashing algorithm and a hash value obtained by applying the hashing algorithm to the target identifier using the nonce; intercept a payload of data for the LI core device; retrieve intercepted target identifiers, ITIs from the intercepted payload of data; apply the hashing algorithm using the hash value to the ITIs to obtain intercepted target identifier hashed values; and if one of the obtained intercepted target identifier hashed values matches the hash value, transmit the intercepted payload of data to the LI core device.
  • the NED adapted to obtaining an indication of the hashing algorithm comprises the NED adapted to receive a first list of hashing algorithms that are available for use by the LI core device.
  • the NED is adapted to transmit to the LI core device, a second list of hashing algorithms that are available for use by the NED.
  • the NED adapted to obtaining an indication of the hashing algorithm comprises the NED adapted to compare the first list of hashing algorithms to the second list of hashing algorithms, and select, based on the comparison, a mutual hashing algorithm, wherein the mutual hashing algorithm is common to the first list and second list of hashing algorithms.
  • the NED is adapted to transmit an indication of the mutual hashing algorithm to the LI core device.
  • the NED adapted to receiving a nonce associated with a target identifier comprises one or more of the NED adapted to: receive a first nonce associated to an XI interface; receive a second nonce associated to an X2 interface; and receive a third nonce associated to an X3 interface; and the NED adapted to obtaining an indication of an encryption algorithm comprises one or more of the NED adapted to: obtain an indication of a first encryption algorithm associated to the XI interface; obtain an indication of a second encryption algorithm associated to the X2 interface; and obtain an indication of a third encryption algorithm associated to the X3 interface.
  • the NED adapted to encrypting a payload of LI data related to the target identifier comprises one or more of the NED adapted to: encrypt the payload of LI data, to be sent through the X2 interface, using the second nonce and the second encryption algorithm; and encrypt the payload of LI data, to be sent through the X3 interface, using the third nonce and the third encryption algorithm.
  • the NED adapted to receiving, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: an indication of a first hashing algorithm associated to the XI interface; an indication of a second hashing algorithm associated to the X2 interface; an indication of a third hashing algorithm associated to the X3 interface; a hash value associated to the XI interface; the first nonce; the second nonce; the third nonce; the first encryption algorithm; the second encryption algorithm; and the third encryption algorithm.
  • a NED in a communications system comprises a LI POI.
  • the NED comprises a processing circuitry and storage medium containing instructions.
  • the instructions when executed by the processing circuitry make the NED operative to receive a nonce associated with a target identifier.
  • the instructions when executed by the processing circuitry make the NED operative to obtain an indication of an encryption algorithm.
  • the instructions when executed by the processing circuitry make the NED operative to encrypt a payload of LI data related to the target identifier, using the nonce and the encryption algorithm.
  • the instructions when executed by the processing circuitry make the NED operative to perform operations according to embodiments of the first aspect.
  • a computer program comprises computer readable instructions to be executed by processing circuitry of a NED comprising a LI POI. Execution of the computer readable instructions causes the NED to perform operations according to the first aspect and embodiments of the first aspect.
  • a computer program product comprises a computer readable storage medium on which a computer program according to the fourth aspect is stored.
  • a method performed by a LI core device in a communication system comprising a NED comprises sending to the NED, an indication of an encryption algorithm.
  • the method comprises obtaining an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
  • the method of obtaining an encrypted payload of LI data related to a target identifier comprises receiving from the NED, the encrypted payload over an X interface.
  • the method comprises sending to the NED, a first list of hashing algorithms that are available for use by the LI core device.
  • the method of sending to the NED, an indication of an encryption algorithm comprises sending to the NED, a first list of encryption algorithms that are available for use by the LI core device.
  • the method comprises sending to the NED, the nonce associated with the target identifier.
  • the method comprises sending to the NED, a further list of encryption algorithms that are available for use by the LI core device; sending to the NED, a further nonce associated with the target identifier; and receiving a further encrypted payload of LI data related to the target identifier, the further encrypted payload being encrypted using the further nonce and an encryption algorithm from the further list of encryption algorithms.
  • the method comprises receiving from the NED, the encrypted further payload over a different X interface.
  • the method comprises determining a mutual hashing algorithm to be used by the LI core device and by the NED; calculating a hash value corresponding to the target identifier, by applying the mutual hashing algorithm to the target identifier using the nonce; storing the hash value and an information indicative of the mutual hashing algorithm; and transmitting, to the NED, the hash value and the information indicative of the mutual hashing algorithm.
  • the method of determining a mutual hashing algorithm to be used by the LI core device and by the NED comprises: receiving from the NED, an indication of the mutual hashing algorithm, the mutual hashing algorithm obtained by comparing the first list of hashing algorithms to the second list of hashing algorithms; and selecting, based on the comparison, a hashing algorithm which is common to the first list and second list of hashing algorithms.
  • the method comprises receiving from the NED, information indicative of one or more of: an hashing algorithm that is available for use by the NED and an indication of an encryption algorithm that is available for use by the NED.
  • the method comprises receiving from the NED, information indicative of: a calculated hash value obtained by applying the hashing algorithm that is available to the NED, to the target identifier using the nonce.
  • the method comprises receiving from the NED, a second list of encryption algorithms that are available for use by the NED.
  • the method of receiving information indicative of an encryption algorithm comprises receiving from the NED, an indication of a mutual encryption algorithm, the mutual encryption algorithm obtained by comparing the first list of encryption algorithms to the second list of encryption algorithms; and selecting, based on the comparison, an encryption algorithm which is common to the first list and second list of encryption algorithms.
  • the method of sending an encryption algorithm comprises one or more of: sending a first list of encryption algorithms associated to an XI interface; sending a second list of encryption algorithms associated to an X2 interface; and sending a third list of encryption algorithms associated to an X3 interface.
  • the method of sending the nonce associated with a target identifier comprises one or more of: sending a first nonce associated to an XI interface; sending a second nonce associated to an X2 interface; and sending a third nonce associated to an X3 interface.
  • the method of obtaining an encrypted payload of LI data related comprises one or more of: receiving the encrypted payload using the second nonce and an indication of an encryption algorithm from the second list of encryption algorithms associated to the X2 interface; and receiving the encrypted payload using the third nonce and an indication of an encryption algorithm from the third list of encryption algorithms associated to the X3 interface.
  • the method comprises sending, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: a first list of hashing algorithms associated to the XI interface; a second list of hashing algorithms associated to the X2 interface; a third list of hashing algorithms associated to the X3 interface; the first nonce; the second nonce; the third nonce; the first list of encryption algorithms associated to the XI interface; the second list of encryption algorithms associated to the X2 interface; and the third list of encryption algorithms associated to the X3 interface.
  • the method comprises obtaining a hash value; using the calculated hash value as a cryptographic key for a decryption algorithm which performs an operation equivalent to an inverse of the mutual encryption algorithm; and decrypting the obtained encrypted payload using the decryption algorithm.
  • the method of obtaining a hash value comprises: obtaining a hash value comprises: retrieving from the obtained encrypted LI data, a task identifier associated with an X interface, XID and retrieving at least one hash value associated with the XID.
  • the method of obtaining a hash value comprises: calculating the hash value by applying a hashing algorithm from the list of hashing algorithms to the target identifier using the nonce.
  • a LI core device in a communications system is provided.
  • the LI core device is adapted to send to the NED, an indication of an encryption algorithm.
  • the LI core device is adapted to obtain an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
  • the LI core device adapted to obtain an encrypted payload of LI data related to a target identifier comprises the LI core device adapted to receive from the NED, the encrypted payload over an X interface.
  • the LI core device is adapted to send to the NED, a first list of hashing algorithms that are available for use by the LI core device.
  • the LI core device adapted to send to the NED, an indication of an encryption algorithm comprises the LI core device adapted to send to the NED, a first list of encryption algorithms that are available for use by the LI core device.
  • the LI core device is adapted to send to the NED, the nonce associated with the target identifier.
  • the LI core device is adapted to send to the NED, a further list of encryption algorithms that are available for use by the LI core device; send to the NED, a further nonce associated with the target identifier; and receive a further encrypted payload of LI data related to the target identifier, the further encrypted payload being encrypted using the further nonce and an indication of an encryption algorithm from the further list of encryption algorithms.
  • the LI core device is adapted to receive from the NED, the encrypted further payload over a different X interface.
  • the LI core device is adapted to determine a mutual hashing algorithm to be used by the LI core device and by the NED; calculate a hash value corresponding to the target identifier, by applying the mutual hashing algorithm to the target identifier using the nonce; store the hash value and an information indicative of the mutual hashing algorithm; and transmit, to the NED, the hash value and the information indicative of the mutual hashing algorithm.
  • the LI core device adapted to determine a mutual hashing algorithm to be used by the LI core device and by the NED comprises the LI core device adapted to receive from the NED, an indication of the mutual hashing algorithm, the mutual hashing algorithm obtained by comparing the first list of hashing algorithms to the second list of hashing algorithms; and selecting, based on the comparison, a hashing algorithm which is common to the first list and second list of hashing algorithms.
  • the LI core device is adapted to receive from the NED, information indicative of one or more of: a hashing algorithm that is available for use by the NED and an indication of an encryption algorithm that is available for use by the NED.
  • the LI core device is adapted to receive from the NED, information indicative of: a calculated hash value obtained by applying the hashing algorithm that is available to the NED, to the target identifier using the nonce.
  • the LI core device is adapted to receive from the NED, a second list of encryption algorithms that are available for use by the NED.
  • the LI core device adapted to receive information indicative of an encryption algorithm comprises the LI core device adapted to receive from the NED, an indication of a mutual encryption algorithm, the mutual encryption algorithm obtained by comparing the first list of encryption algorithms to the second list of encryption algorithms; and selecting, based on the comparison, an encryption algorithm which is common to the first list and second list of encryption algorithms.
  • the LI core device adapted to send an indication of an encryption algorithm comprises one or more of the LI core device adapted to: send a first list of encryption algorithms associated to an XI interface; send a second list of encryption algorithms associated to an X2 interface; and send a third list of encryption algorithms associated to an X3 interface.
  • the LI core device adapted to send the nonce associated with a target identifier comprises one or more of the LI core device adapted to: send a first nonce associated to an XI interface; send a second nonce associated to an X2 interface; and send a third nonce associated to an X3 interface.
  • the LI core device adapted to obtain an encrypted payload of LI data related comprises one or more of the LI core device adapted to: receive the encrypted payload using the second nonce and an encryption algorithm from the second list of encryption algorithms associated to the X2 interface; and receive the encrypted payload using the third nonce and an encryption algorithm from the third list of encryption algorithms associated to the X3 interface.
  • the LI core device is adapted to send, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: a first list of hashing algorithms associated to the XI interface; a second list of hashing algorithms associated to the X2 interface; a third list of hashing algorithms associated to the X3 interface; the first nonce; the second nonce; the third nonce; a hash value associated to the XI interface; the first list of encryption algorithms associated to the XI interface; the second list of encryption algorithms associated to the X2 interface; and the third list of encryption algorithms associated to the X3 interface.
  • the LI core device is adapted to obtain a hash value; using the obtained hash value as a cryptographic key for a decryption algorithm which performs an operation equivalent to an inverse of the mutual encryption algorithm; and decrypting the obtained encrypted payload using the decryption algorithm.
  • the LI core device adapted to obtain a hash value comprises the LI core device adapted to retrieve from the obtained encrypted LI data, a task identifier associated with an X interface, XID and retrieve at least one hash value associated with the XID.
  • the LI core device adapted to obtain a hash value comprises calculating the hash value by applying a hashing algorithm from the list of hashing algorithms to the target identifier using the nonce.
  • a LI core device in a communications system comprises an interface circuitry, a processing circuitry and storage medium containing instructions that when executed by the processing circuitry make the NED operative to send to the NED, an indication of an encryption algorithm.
  • the LI core device of the eighth aspect is adapted to perform operations according to one or more of the embodiments of the sixth aspect.
  • a computer program comprises computer readable instructions to be executed by processing circuitry of a LI core device. Execution of the computer readable instructions causes the NED to perform operations according to the sixth aspect and embodiments of the sixth aspect.
  • a computer program product comprises a computer readable storage medium on which a computer program according to the ninth aspect is stored.
  • Figure 1 is a diagram showing functional units of a communication network according to an embodiment.
  • Figure 2 is a flow chart illustrating a process according to an embodiment.
  • Figure 3 is a flow chart illustrating a process according to an embodiment.
  • Figure 4 is a flow chart illustrating a process according to an embodiment.
  • Figure 5 is a diagram showing functional units of a lawful interception system according to an embodiment.
  • Figure 6 is a signaling diagram showing a process according to an embodiment.
  • Figure 7 is a signaling diagram showing a process according to an embodiment.
  • Figure 8 is a flow chart illustrating a process according to an embodiment.
  • Figure 9a is a flow chart illustrating a process according to an embodiment.
  • Figure 9b is a flow chart illustrating a process according to an embodiment.
  • Figure 9c is a flow chart illustrating a process according to an embodiment.
  • Figure 10a is a flow chart illustrating a process according to an embodiment.
  • Figure 10b is a flow chart illustrating a process according to an embodiment.
  • Figure 11 is a signaling diagram showing a process according to an embodiment.
  • Figure 12 is a flow chart illustrating a process according to an embodiment.
  • Figure 13 is a flow chart illustrating a process according to an embodiment.
  • Figure 14 is a flow chart illustrating a process according to an embodiment.
  • Figure 15 is a diagram showing functional modules of a network element device according to an embodiment.
  • Figure 16 is a diagram showing functional modules of a lawful interception core device according to an embodiment.
  • Figure 17 shows one example of a computer program product comprising computer readable means according to an embodiment.
  • Embodiments of the invention are configured to allow a network element device (NED) in a communication system.
  • the NED comprises a Point of Intercept (POI), and the NED is adapted/ configured/ operative to receive a nonce ("number used only once") associated with a target identifier, obtain an indication of an encryption algorithm and, using the nonce and the encryption algorithm, encrypt a payload of lawful interception (LI) data related to the target identifier.
  • POI Point of Intercept
  • the invention allows for encryption keys that are not transmitted between the NED and an LI core device, and encryption keys that are different for each task. Thereby, minimizing the risk of a data breach, even if an attacker was to break an encryption. Additionally, load on the communication system may be reduced since payloads comprising LI data are encrypted from creation to destination. Thus, making encryption of data for internal security handling between the NED and a communication device and making external security handling such as transport layer security protocol in the microservices hosting an LI core device, unnecessary. Additionally, in some embodiments, the encryption may be tailored in complexity and computational cost to the task and target or turned off for certain aspects if deemed unnecessary. This may reduce the attack surface of an LI system by making the gathering of sensitive data from vulnerable microservices in the communication system or an attached network significantly more difficult. Another advantage of the invention herein is that encryption of the LI data allows for a more secure way of handling the LI data. These added features are not in conflict with other conventional security mechanisms, which may be used in parallel.
  • the various embodiments may be embedded in an LI system such as communication system 100 illustrated in Figure 1.
  • the communication system 100 comprises a network element device (NED) 110 comprising a POI. Further functions may be present in the communication system of the invention, as detailed below.
  • the communication system 100 may comprise other network element devices beyond those shown in Figure 1 both related to LI and not related to LI.
  • the other network element devices may reside between the NED and and/or may be a part of an attached network.
  • the communication system 100 comprises the NED 110 and an LI core device 120 comprising a first communication device 122 and/or a second communication device 125.
  • the NED comprises a Point of Interception (POI) 111.
  • An interface between the first communication device 122 and the NED, and an interface between the second communication device 125 and the NED may be present.
  • the first communication device 122 comprises an LI administration function (ADMF) or is able to perform as an ADMF.
  • the first communication device 122 may also be able to perform as an LI mediation and delivery function (MDF).
  • the second communication device 125 comprises the MDF or is able to perform tasks associated with an MDF.
  • the second communication device 125 may also be able to perform as an LI ADMF.
  • LI core device 120 in the current disclosure, is used interchangeably to describe the characteristics and actions of either the first communication device, the second communication device, or both.
  • the LI core device 120 is configured to intermediate between a law enforcement agency (LEA) that supplies warrants specifying LI targets and a type of interception and receives LI data such as Intercept Related Information (IRI) and/or Content of Communication (CC) and NEs comprising POIs. This is done via e.g. a LEA device 140.
  • POI is a network element device employed for interception and to produce LI data.
  • NED Network Element device
  • NF Network Function
  • ADMF Access Management Function
  • LI ADMF Network Element Function
  • the POI may be implemented as a virtual network function or any software.
  • LI refers to hardware and software support in radio communication systems (e.g., wireless networks, the communication system 100) enabling law enforcement agencies with legal authorization to selectively intercept communications or acquire communication-related information of targeted subscribers.
  • LI data may be considered as any data collected during lawful interception by the NED 110 related to a target.
  • a targeted subscriber of the targeted subscribers is hereafter referred to as a target.
  • LI data may, for example, be IRI on X2 interface (xIRI), CC on X3 interface (xCC), IRI, and CC data.
  • the xIRI and xCC are sometimes referred to as raw IRI and raw CC, respectively.
  • the LI core device performs functions such as the administrative function, mediation function and delivery functions related to LI.
  • the LI core device and the NED may communicate the communication network 100.
  • a radio access network (RAN) of the communication network may comprise the LI core device and the NED.
  • a core network (CN) of the communication network may comprise the LI core device and the NED.
  • the RAN may comprise the NED and the CN may comprise the LI core device.
  • the RAN may comprise the NED and another CN of another communication network may comprise the LI core device to enable LI across communication networks.
  • placement of the NE comprising the POI in the communication system can be made more flexibly, e.g.
  • the LI core device 120 is configured to send to the NED 110, indication/ identity of an encryption algorithm.
  • the LI core device 120 is further configured to obtain an encrypted payload of LI data related to a target identifier wherein the encrypted payload is encrypted using a nonce associated with the target identifier and the encryption algorithm.
  • the LI core device 120 is configured to obtain a hash value. The hash value is obtained by applying a hashing algorithm to the target identifier using the nonce. The obtained hash value is used as a cryptographic key for a decryption algorithm which performs an operation equivalent to an inverse of the encryption algorithm.
  • the LI core device is configured to decrypt the obtained encrypted payload using the decryption algorithm.
  • the NED 110 comprises the POI 111.
  • the NED 110 is configured to receive the nonce associated with the target identifier, obtain an indication of an encryption algorithm and encrypt the payload of LI data related to the target identifier (for example: IRI and/or CC data), using the nonce and the encryption algorithm.
  • embodiments of the invention described are configured to allow the LI core device 120 to communicate with the NED 110 via, for example, an X interface comprising the functionality of one or more of an XI, X2, and X3 interface.
  • the LI core device 120 and the NED 110 are configured to agree on a mutual encryption algorithm for xIRI and xCC data transmitted over the X2 and X3 interface.
  • the LI core device 120 and the NED 110 are configured to agree on a mutual hashing algorithm for the XI, X2 and X3 interfaces.
  • the transmitted data is, in the current state of the art, exposed to services throughout the communication network 100 where the LI data passes.
  • a payload of LI data may comprise CC, xCC, IRI or xIRI or any other type of information that is same as CC, xCC, IRI, or xIRI as defined in the lawful intercept system as defined by ETSI.
  • the LI core device 120 is configured to perform the method 200 illustrated in figure 2.
  • the LI core device 120 is configured to send an indication of an encryption algorithm to the NED.
  • the LI core device 120 is configured to obtain an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
  • the encryption algorithm being derived from the indication of the encryption algorithm.
  • a nonce may be a random number, and may be based on a timeliness factor such as a timestamp or a sequence number.
  • the "nonce" means a number which is substantially (for the purpose of the present disclosure) used only once for one or more LI specific actions.
  • the LI specific action may be encrypting a payload of LI data and decrypting an encrypted version of an LI payload.
  • the LI core device 120 generates a nonce associated with the target identifier.
  • the nonce may be generated using processing circuitry, a cryptographically secure random number generator, a cryptographically secure token generator, or similar to generate the random number forming the nonce, optionally together with padding bits, salt. timestamp, or other data.
  • the association of the nonce with the target identifier may mean that the value of the nonce depends on the target identifier itself (i.e. different target identifiers have different nonces, and/or a target identifier may have different nonces over time).
  • the association of the nonce with an X interface may mean that the nonce is, and sometimes only is, used with data that is passing over the X interface or may mean that itself only passes over the X interface.
  • the LI core device 120 is configured to generate a different nonce associated with the target identifier.
  • the generation of the different nonce occurring after: a set period of time, a certain number of received messages from the NED 110, failing to decrypt a received payload, a random period of time and/or a received message from the LEA, e.g. from the LEA device 140.
  • the sending step 210 may comprise sending of an indication of an encryption algorithm, sending of the encryption algorithm itself, or sending of a list of encryption algorithms that are available to use by the LI core device 120 and/or a list of encryption algorithms that are available to use by the NED 110.
  • the LI core device 120 may be configured to obtain the encryption algorithm by either copying, moving, taking, receiving, or otherwise coming into possession of the encryption algorithm or the indication of the encryption algorithm.
  • a hash value of the target identifier is an output of a hashing algorithm wherein an input is the target identifier.
  • the target identifier may be a technical identity that uniquely identifies the target of interception and can be but is not limited to an International mobile subscription identity (IMSI), international mobile equipment identity (IMEI), subscription permanent identifier (SUPI) or any other UE identifying value set by European Telecommunications Standards Institute (ETSI), Third Generation Partnership Project (3GPP), or Global System for Mobile Communications.
  • IMSI International mobile subscription identity
  • IMEI international mobile equipment identity
  • SUPI subscription permanent identifier
  • ETSI European Telecommunications Standards Institute
  • 3GPP Third Generation Partnership Project
  • Global System for Mobile Communications Global System for Mobile Communications
  • the hash value of the target identifier could, for example, be a hash, the hash with padding values, the hash combined with other information such as a timestamp, an index value referring to the hash from a database, or similar value derived from the hash of the target identifier.
  • the hashing algorithm comprises a function that takes a value or message of arbitrary length as an input and produces an output of a fixed length.
  • the hashing algorithm comprises a keyed hash algorithm.
  • the keyed hash algorithm has two inputs: a value associated with the target identifier and a hash key (for e.g.: the nonce) to produce an output of fixed length.
  • the hash key is a value associated with the nonce, the nonce being associated with the target identifier.
  • the hash key being a value associated with the nonce could be, for example, the nonce itself or a value depending on the nonce itself such as the nonce with padding values.
  • the nonce and the value based on the hash of the target identifier may also be received from the LEA device 140 or other device.
  • the LI core device 120 sends to the NED 110, the nonce associated with the target identifier.
  • the nonce may be sent to the NED over an XI interface or any other lawful intercept standardized interface, such as the X0 interface, connecting the LI core device to the NED.
  • the LI core device may send to the NED, a hash value based on the target identifier, or both the hash value of the target identifier and the nonce.
  • the LI core device 120 may, in some embodiments, store the nonce associated with the target identifier and/or the hash value based on the target identifier.
  • the LI core device 120 may store the nonce and/or the hash value in the LI core device's storage medium or in a storage medium outside the LI core device 120.
  • the nonce may be associated with a specific X interface (for example, the XI interface) and the LI core device 120 may send multiple nonces, each nonce associated with a specific X interface (for example, a nonce for the XI interface and a nonce for the X2 interface) and/or each unique target identifier.
  • an embodiment may comprise a unique nonce for each X interface used by the NED and the LI core device 120 and each unique target identifier that the NED is sent from the LI core device.
  • six nonces may be sent to the NED 110 from the LI core device 120, three nonces associated with one target identifier and three nonces associated with one target identifier further associated with a specific X interface.
  • the LI core device 120 is configured to obtain an indication of an encryption algorithm.
  • the indication of the encryption algorithm may be obtained from an internal storage medium in the LI core device 120, the NED 110, or an external device.
  • the LI core device may obtain the indication of the encryption algorithm by either copying, moving, taking, receiving, or otherwise coming into possession of the encryption algorithm from a list of encryption algorithms that are available for use by the LI core device 120.
  • the LI core device 120 may be configured to send to the NED, information indicative of one or more of a hashing algorithm; the encryption algorithm; the nonce associated with target identifiers; and/or the hash value of the target identifier. In some embodiments, this may be necessary such as, for example, if the NED is lacking any such information such as in a situation where, at some point in time, the LI core device 120 was active while the NED 110 was not. This may increase the robustness of the LI system.
  • the NED 110 is configured to perform the method 300 illustrated in figure 3.
  • the NED 110 is configured to receive a nonce associated with a target identifier.
  • the nonce is the same nonce generated by the LI core device 110 described with reference to figure 2.
  • the NED 110 is configured to receive the nonce from the LI core device 120.
  • the nonce may be associated with an individual X interface where, for example, a nonce is specified for being used to hash or encrypt LI data related to a target that is sent over the individual X interface.
  • the NED 110 may be configured to receive a nonce associated with an X interface and/or a target identifier.
  • the NED 110 is configured to receive multiple nonces associated with different X interfaces and target identifiers. In some embodiments, the NED 110 is configured to receive a hash value based on the target identifier obtained by calculating the hash value. In some embodiments, the hash value is calculated by applying a hashing algorithm to the target identifier and using the nonce associated with the target identifier as a hash key. In some embodiments, the NED 110 may be configured to obtain the hash value from the LI core device 120.
  • the NED 110 may be configured to send, to the LI core device 120, information indicative of the hashing algorithm; the encryption algorithm; the nonce associated with target identifiers; and/or the value based on the hash of the target identifier. In some embodiments, this may be necessary such as, for example, if the LI core device 120 is lacking any such information such as in a situation where, at some point in time, the NED 110 was active while the LI core device 120 was not. This may increase robustness of the LI system.
  • the NED 110 obtains an indication of an encryption algorithm.
  • the indication of the encryption algorithm may be obtained from an internal storage medium, from the LI core device 120, or from another external device.
  • the NED 110 is configured to obtain an indication of multiple encryption algorithms.
  • each encryption algorithm of the plurality is specific to a target identifier, e.g. different encryption algorithms are used for different target identifiers.
  • each encryption algorithm of the plurality may be specific to an X interface, e.g. different encryption algorithms are used for different X interfaces.
  • the different encryption algorithms may also be specific for certain types of LI data such as CC and IRI, e.g. different encryption algorithms are used for CC and IRI.
  • the hash value and the encryption algorithm mentioned with respect to figure 3 may result in a more secure exchange of communications such as CC and IRI payloads between the LI core device 120 and the NED 110. This more secure exchange may be the result of the NED 110 already having the target identifier preloaded. Thereby, avoiding sending of the hash value between the LI core node and the NED and risking possible interception of the hash value.
  • the indication of the encryption algorithm obtained by the LI core device in some embodiments described in relation to figure 2 is the same as the indication of the encryption algorithm in step 320 of figure 3.
  • the obtaining step 320 may comprise the receiving of an indication of an encryption algorithm, the receiving of the encryption algorithm itself, or the receiving of a list of encryption algorithms that are available to use by the LI core device 120 and/or a list of encryption algorithms that are available to use by the NED 110.
  • the NED 110 may be configured to obtain the encryption algorithm by either copying, moving, taking, receiving, or otherwise coming into possession of the encryption algorithm or the indication of the encryption algorithm.
  • the NED 110 encrypts a payload of LI data related to the target identifier using the nonce and the encryption algorithm.
  • the payload may comprise data associated with IRI, CC, and/or information related to the target identifier.
  • the payload may comprise the whole amount of LI data or only a portion of the LI data.
  • the relation of the LI data to the target identifier may mean that the LI data originated from an LI target or was associated with the LI target such as data with the LI target as the destination.
  • the nonce or a value associated with the nonce is used as a cryptographic key in the encryption algorithm.
  • the NED 110 is configured to encrypt the payload for the LI data related to the target identifier using the hash value based on the target identifier by applying the hashing algorithm to the target identifier and using the nonce.
  • the NED 110 may be configured to encrypt the payload for LI data by using the hash value as the encryption key for the encryption algorithm.
  • the NED 110 is configured to encrypt a payload for LI data related to the target identifier for an X interface using the nonce associated with the X interface and with the target identifier. In some embodiments, the NED 110 is configured to obtain an indication of a further encryption algorithm and encrypt the payload for LI data for an X interface with the encryption algorithm and the payload with the further encryption algorithm for a different X interface.
  • the indication of the further encryption algorithm may be a different one than the indication of the encryption algorithm referred to previously. Using the encryption algorithm and the further encryption algorithm may increase the security of the LI data sent from the NED 110 as an attacker would need to crack multiple encryptions with different keys to access the LI data sent over all the interfaces.
  • the NED 110 may be configured to selectively not encrypt the payload of LI data related to the target identifier for an X interface. This may give rise to a reduction of computational resource usage for a case when there is a shortage of computational resources.
  • the NED 110 is configured to send the encrypted payload of LI data.
  • the payload is sent directly to the LI core device 120.
  • the payload is sent to other network element devices, network functions, microservices, and/or similar directly or indirectly connected to the LI core device 120.
  • the NED 110 is configured to send the payload to the LI core device 120 over an attached network comprising network element devices, network functions, microservices, and/orsimilar.
  • the NED 110 is configured to send the payload over an X interface whereby the X interface may comprise the functionality of the X2, and/or X3 interface.
  • the X interface may comprise the functionality of the X2 and/or X3 interface by communicating the same information as the interfaces are standardized to carry and/or sending information from the same source to the same destination as the interfaces.
  • the LI core device 120 is further configured to perform the method 400 illustrated in figure 4.
  • the first three steps are same as the steps 210, 220 and 230 presented in the description for figure 2.
  • the LI core device 120 is configured to receive the encrypted payload for LI data related to the target identifier wherein the payload message is encrypted using the nonce and the encryption algorithm.
  • the payload is sent by the NED 110.
  • the payload message is encrypted using the same nonce and encryption algorithms as defined by step 330.
  • the payload is received over an X interface, whereby the X interface may comprise the functionality of an X2, and/or X3 interface.
  • the payload may comprise data associated with intercept related information, content of communication, and/or information related to the target identifier.
  • the LI core device 120 may calculate the hash value associated with the target identifier using a hashing algorithm and the nonce associated with the target identifier. In some embodiments, the hash value may be obtained by applying the hashing algorithm to the target identifier and using the nonce as a hash key.
  • the LI core device 120 may, in some embodiments, store the target identifier, the nonce associated with the target identifier and/or the hash value of the target identifier.
  • the LI core device 120 may store the target identifier, the nonce, and/or the hash value in the LI core device's storage medium or in a storage medium outside the LI core device. In some embodiments, the LI core device calculates the hash value associated with the target identifier by using the hashing algorithm and the nonce that was stored or by using the hashing algorithm and nonce received from another network element device, or the LEA device 140.
  • the LI core device 120 is configured to decrypt the payload for LI data related to the target identifier.
  • the decryption is performed using the hash value associated with the target identifier and a decryption algorithm associated with the encryption algorithm.
  • the decryption algorithm associated with the encryption algorithm may be a function that performs the inverse of the encryption algorithm by using the hash value as a cryptographic key to decrypt the encrypted payload into plaintext.
  • the hash value associated with the target identifier is the nonce or the hash value is derived from the nonce and/or a hash value based on the target identifier.
  • the hash value may be derived by calculating the value associated with the target identifier using a hashing algorithm and the nonce associated with the target identifier.
  • the decryption algorithm associated with the encryption algorithm is the inverse of the encryption algorithm.
  • the method 400 may further comprise calculating hashed target values, hashed_target_Xl, hashed_target_X2, and/or hashed_target_X3 for each X interface (for e.g.: XI interface, X2 interface and X3 interface) corresponding to an LI target identifier.
  • the calculation is done using hashing algorithms XlHashingAlgorithm, X2HashingAlgorithm, and/or X3HashingAlgorithm and nonces Nonce_Xl, Nonce_X2, and/or Nonce_X3 at a step 405, which may be before both the steps 410 and 420.
  • the nonce may be selected from a predetermined list of nonces or may be at least partially randomly generated (for example, using one of the methods discussed in WO 2019/093932 in regard to hash keys which are functionally the same).
  • the hash value may also be left blank if the associated hashing algorithm variable was set to none.
  • Figures 5-14 describe an embodiment of the invention implemented in a lawful intercept system operating in a 5 th generation 3GPP access network.
  • the same elements and functions depicted in figure 1 in connection with the communication system 100 are indicated with the same reference numbers. It should be clear to the skilled person how the details of the embodiment presented in figures 5-14 may be changed to better suit other 3GPP access networks comprising lawful intercept implementations but also other access networks comprising lawful intercept implementations.
  • the embodiment is not exclusive to how the invention may be implemented in such a network but representative of an implementation.
  • the various embodiments may be embedded in a communication system such as in system 500 depicted in figure 5 which is an embodiment of the communication system 100 illustrated in Figure 1.
  • the system 500 also referred to the LI system comprises a LI core device 120.
  • the LI core device 120 intermediates between the LEA device 140 that supplies warrants specifying LI targets and type of interception and receives LI data (IRI and/or CC) from network element devices having attached POIs.
  • the LI core device 120 preforms one or more of the administrative, mediation and/or delivery functions related to LI, and comprises one or more devices such as the first communication device 122 and second communication device 125.
  • the LI core device 120 and the NED 110 comprising a POI communicate over X interfaces comprising the functionality of an X0, XI, X2, and/or X3 interfaces.
  • the LI system is a system designed to identify, intercept, gather, mediate, deliver and store communications and information related to communications between a device, also known as a target, and the telecommunications network on behalf of a law enforcement agency with legal authorization.
  • a target also referred to as an LI target, may be a user equipment or a machine type communications device.
  • a target has a target identifier such as an International mobile subscription identity (IMSI), International Mobile Equipment Identity (IMEI), or Network Access Identifier (NAI).
  • IMSI International mobile subscription identity
  • IMEI International Mobile Equipment Identity
  • NAI Network Access Identifier
  • the communication system may be, for example, a 3GPP radio access network of the 3rd, 4th, or 5th generation or a non-standardized telecommunications network compliant with an ETSI lawful interception system.
  • NED 110 comprises a POI 111.
  • Figure 5 is based on a similar figure in the ETSI standard "Network Functions Virtualization (NFV); Security; Report on NFV LI Architecture" published by the European Telecommunications Standards Institute (ETSI) as ETSI GR NVF-SEC 011 vl.1.1 in April 2018.
  • the LI core device 120 comprises the MDF 125 and administrative functions 521.
  • the administrative functions comprise the ADMF 122 and the Lawful Intercept Application Controller 523.
  • the LEA device 140 comprises the warrant issuing authority 543 and the Law Enforcement Monitoring Function/Facility (LEMF) 545.
  • LEMF Law Enforcement Monitoring Function/Facility
  • Communications between the LI core device 120 and the NED 110 are performed via LI interfaces internal to a communication service provider (CSP) or in a communication system 100: X0 (for configuring a POI and transmitting other application parameters), XI (for task and target management), X2 (for delivering information related to IRI data, xIRI, to the vMF/vDF), and X3 (for delivery of information related to CC data, xCC, to the vMF/vDF).
  • the vMF and vDF are virtualized mediation functions and virtualized delivery functions respectively.
  • Communications between the LI core device 120 and devices outside the CSP or the communication system 100, such as the LEA functions take place via external handover HI1, HI2, and HI3.
  • the LI core device which in some embodiments of the invention comprises the ADMF, receives an LI request from LEA device via HI1 and delivers, via the MDF, IRI and CC to LEMF through the HI2 and HI3 interfaces, respectively.
  • a bidirectional XI interface is used for communication between the LI core device 120 comprising a controlling function such as the first communication device 122 (for e.g.: an ADMF) and a controlled function such as the NED 110.
  • the NED 110 is any network element device employed to intercept or mediate and deliver LI data (xIRI, IRI, xCC and CC) and the LI core device 120 comprising the ADMF 122 represents any core function in communication with the NED and/or the LEA device 140.
  • the messages exchanged via the XI interface include messages for starting, modifying, and stopping tasks (detailed in section 6.2 of ETSI TS 103 221-1 Vl.13.1), messages for creating, modifying, and removing destinations (detailed in section 6.3) and messages for getting information from the NED (detailed in section 6.4).
  • h ActivateTaskand ModifyTask messages sent from the LI core device to an NED to add a new LI task or modify an existing task, respectively typically include a TaskDetails structure with a plurality of fields: XID that uniquely identifies the task. Targetidentifiers that identifies the LI target, DeliveryType (IRI, CC or both), etc.
  • Targetldentifers may be an E164 Number, an International Mobile Subscriber Identity (IMSI), and International Mobile station Equipment Identity (IMEI), a Hashedldentifier, or any other format specified by an ETSI standard.
  • IMSI International Mobile Subscriber Identity
  • IMEI International Mobile station Equipment Identity
  • Hashedldentifier a Hashedldentifier
  • the ActivateTask message is sent over a secure connection, there is a possibility that the LEA device 140 or the LI core device or the LEA request that the LI target is hashed. In case of a hashed LI target, the TaskDetailsExtensions and/or TargetldentifierExtension private extensions should be used.
  • unidirectional X2 and X3 interfaces are used for communication between the NED 110 containing the POI 111 and the LI core device 120 comprising a second communication device 125 (which may be an MF, DF, vMF, and/or vDF).
  • the MDF represents any core function in communication with the POI and/orthe LEA device 140.
  • Messages exchanged via the X2 and X3 interface include messages for sending Protocol Data Units (PDUs) from a POI to the MDF detailed in section 5 of ETSI 103 221-2 vl.6.1.
  • PDUs Protocol Data Units
  • Each PDU contains a set of mandatory PDU header fields containing identifiers, routing and correlation information, and information related to the target/task id, XID (detailed in section 5.2), a set of additional conditional attributes conveying additional metadata about the intercepted material (detailed in section 5.3), and a copy of the intercepted payload material (detailed in section 5.4).
  • the payload material contains either information related to IRI for PDUs for the X2 interface and information related to CC for PDUs for the X3 interface.
  • the contents of these payloads are defined by several standards such as ETSI TS 102 232- 1, 3GPP TS 33.128, 3GPP TS 33.108, IPv4, IPv6, RADIUS, etc. or may be a unique non-standardized payload related to the task/target.
  • An LI core device 120 comprising a first communication device 122 according to an embodiment is configured to perform the method 800 illustrated in Figure 8.
  • the method comprises obtaining a nonce associated with a target identifier.
  • the nonce may be obtained by selecting the nonce from a predetermined list of nonces or may be at least partially randomly generated (for example, using one of the methods discussed in WO 2019/093932 regarding hashing keys which are functionally the same as the nonce).
  • the LI core device 120 obtains a nonce associated with a target identifier, that is different from an already existing nonce associated with the same target identifier. Obtaining a different nonce that is different from an already existing nonce associated with the same target may occur after: a set period of time, a certain number of received messages, failure to decrypt a received encrypted payload, a random period of time and/or a received messaged from the LEA device 140.
  • Such a re-obtainment of the different may not result in needing to perform step 820 or a step similar, particularly if step 820 or a step similar has been done for a previous nonce associated with a target identifier, the same target or otherwise, and instead move straight to step 830 or a similar step.
  • the process of obtaining the nonce may thus accomplish an increased security of the communication system 100, as the nonce and subsequently encrypted payloads are refreshed with new encryption parameters.
  • the method comprises obtaining an indication of hashing and encryption algorithms among site-available hashing algorithms and site-available encryption algorithms, both usable by the LI core device 120 and by the NED 110.
  • the hashing and encryption algorithms may instead reside outside of the LI core device 120 such as at the LEA device 140, the NED 110, or an external device.
  • the step 820 may further comprise a handshake mechanism for determining and selecting an encryption algorithm and a hashing algorithm that is commonly available to the LI core device 120 and the NED 110, to encrypt xIRI and xCC payloads, and calculate the hash value, respectively.
  • the LI core device In order to determine the hashing algorithm and the encryption algorithm, the LI core device
  • the LI core device 120 and the NED 110 may send a list indicating the hashing and encryption algorithms available to the LI core device 120, either at the LI core device or accessible to the LI core device over a network connection, to the NED, and then receive from the NED 110 a list indicating available hashing and encryption algorithms that are available to the NED 110, either at the NED 110 or accessible to the NED 110 over a network connection.
  • the LI core device 120 may send a list indicating the hashing and encryption algorithms available to the LI core device, to the NED, and then receive in response from the NED 120, an indication of the hashing and encryption algorithms.
  • the LI core device 120 may receive a list indicating hashing and encryption algorithms available to the NED and send an indication of a selection of the hashing algorithm and encryption algorithm.
  • two new messages, SecurityTaskDetailRequest and SecurityTaskDetailResponse are added to the relevant LI standard for facilitating a hashing and encryption algorithm list exchange.
  • the SecurityTaskDetailRequest may be used either by the LI core device 120 or NED 110 to request a list of available hashing algorithms and encryption algorithms.
  • SecurityTaskDetailResponse may be used, by the LI core device 120 or the NED 110 receiving the SecurityTaskDetailRequest, to indicate a list of hashing algorithms and encryption algorithms present at the LI core device 120 or the NED 110.
  • the method comprises obtaining a hash value corresponding to the LI target identifier using the hashing algorithm and the nonce.
  • the hash value may be calculated by applying the hashing algorithm to the target identifier using the nonce as a hash key.
  • the method comprises obtain multiple hash values corresponding to the target identifier for each of the X interfaces.
  • the method comprises calculating three hash values corresponding to each of XI, X2 and X3 by applying a hashing algorithm to the target identifier using a nonce associated with XI, applying a hashing algorithm to the target identifier using a nonce associated with X2 and applying a hashing algorithm to the target identifier using a nonce associated with X3.
  • Method 800 further includes storing information indicative of one or more of: the hashing algorithm; the nonce associated with the target identifier; the value based on the hash of the target identifier; and the encryption algorithm at a fourth step 840.
  • This information may be organized as a database.
  • method 800 includes sending and/or transmitting an indication of one or more of the hashing algorithms, the encryption algorithms, the nonces associated with the target identifiers (for e.g.: nonce_Xl, nonce_X2 and nonce_X3) and the value associated to the XI interface, hashed_target_Xl, based on the hash of the target identifier to the NED.
  • One way of sending this information is by using a modified ActivateTaskRequest or modified ModifyTaskRequest message.
  • the conventional ActivateTaskRequest message and ModifyTaskRequest message defined in the ETSI TS 103 221-1 standard may be improved for this purpose by adding a field named SecureTargetldentifier in the TaskDetails structure.
  • the SecureTargetldentifier field is filled with information when target identifier is not transmitted as plaintext.
  • Secure Targetidentifier f e ⁇ d has a SecurityDetails format that includes: XlHashingAlgorithm, X2HashingAlgorithm, and X3HashingAlgorithm (number or alpha-numeric) indicating the selected hashing algorithm for each X interface; a TargetType (a UTF-8 string) indicating format of the target identifier prior to being hashed (e.g., IMSI, IMEI, etc.,); a HashedTarget (also a UTF-8 string) containing the hashed_target_Xl; and Nonce_Xl, Nonce_X2, and Nonce_X3 (UTF-8 strings) providing the nonces used by the hashing algorithm to hash the target identifier.
  • XlHashingAlgorithm e.g., X2HashingAlgorithm
  • X3HashingAlgorithm number or alpha-numeric
  • an OtherlnfoHashed field may also be included in the SecurityDetails format and be used to indicate other hash-related information (e.g., other information hashed together with the target identifier).
  • an OtherEncryption field may also be included in the SecurityDetails format and be used to indicate other encryption-related information (e.g. other information also passed on the XI interface that requires encryption in addition to other information encrypted together with xIRI and xCC information for the X2 and X3 interfaces). Since the ActivateTaskRequest and ModifyTaskRequest message uses the same TaskDetails structure, both benefit from the presence of the additional SecureTargetldentifier.
  • the presence of the SecureTargetldentifier field in the TaskDetails structure makes it easier and faster to enhance secure handling of hashed LI target identifiers as described for the embodiments in this section.
  • the embodiments include an automatic handshake mechanism for establishing security details such as the hashing or encryption algorithm (i.e., hashing algorithm or encryption algorithms), nonces and any other security parameters, as well as to update these characteristics in case changes are caused by discovered vulnerabilities or the capabilities of network element devices are upgraded.
  • the automatic handshake mechanism increases the security and serviceability also in 5G LI networks.
  • Figure 9a illustrates a method including a handshake mechanism indicated by step 820 in which a hashing algorithm and an encryption algorithm is selected using the SecurityTaskDetailRequest and the SecurityTaskDetailResponse messages.
  • a hashing algorithm and an encryption algorithm is selected using the SecurityTaskDetailRequest and the SecurityTaskDetailResponse messages.
  • other messages for determining the hashing algorithm and the encryption algorithm to be used by the LI core device 120 and NED 110 may be used, such as the lists and indications specified previously.
  • the LI core device 120 comprising a first communication device 122 (for e.g.: an ADMF) and a second communication device 125 (for e.g.: an MDF), performs steps of the method 900. Starting at a first step 910, with NED 110 not connected to the LI core device 120 in the communication system 100.
  • the variables NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, and NEX2EncryptionAlgorithm, NEX3EncryptionAlgorithm are set to None.
  • the NED 110 is connected to the LI core device 120 (a preliminary connection that may become operative at 950 or declined at 985).
  • LI data destinations are created.
  • each task is uniquely identified by an XI identifier (XID), and each task is handled independently of all others and released once each task has ended.
  • the XID is a version 4 UUID as per IETF RFC 4122 "A Universally Unique Identifier (UUID) URN Namespace.”
  • the LI core device is responsible for correlating the XID to any LI instance identifiers (LIID) used to communicate with the LEA device 140.
  • the LI core device may map an XID to a single LIID or to multiple LIIDs.
  • the LIID(s) or more precisely the second communication device 125 (for e.g.: MDF(s)) of the LI core device 120 thereof is/are the destination(s) for the LI data.
  • Intercepted traffic is delivered by the NED 110 to at least one destination (for e.g., an MDF that may be virtual/ physical).
  • destination for e.g., an MDF that may be virtual/ physical.
  • Each destination is uniquely identified by a destination identifier handled independently from other details of the task.
  • Each task is associated with one or more destinations.
  • a conventional first communication device that does not support selecting the hashing and encryption algorithm performs only steps 910, 930, 940 and 950.
  • a fifth step 945 it is checked whether hashing and encryption is requested for deployment of the NED 110. If hashing and encryption is not requested (i.e., "NO" branch of 945), the NED is operative to not encrypt the payload of LI data related to the target identifier and then an eleventh step 950 follows the NED being operatively connected to the LI core device.
  • step 945 it is tested whether NE's version of software supports selecting hashing and encryption algorithms at a sixth step 955.
  • the check in step 945 is done on an interface basis, such as if the NEX2EncryptionAlgorithm was blank or null for example, making the NED 110 operative to not encrypt the payload of LI data related to the target identifier for an X interface. This may result in a resource savings for the NED.
  • tenth step 985 follows using NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEX3EncryptionAlgorithm all being equal to None (set in step 920).
  • Step 985 checks if NEX1 HashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEX3EncryptionAlgorithm value are acceptable (i.e., greater or equal to MinReqAIg).
  • NED 110 is operatively connected to the LI core device.
  • Step 960 comprises two different procedures, method 960a and method 960b presented in Figure 9b and 9c, respectively.
  • the LI core device 120 according to one embodiment of step 960 is configured to perform the method 960a illustrated in Figure 9b.
  • LI core device 120 in a first step, 962a, requests hashing and encryption information from the NED 110 and subsequently receives the NE's response at a second step 964a.
  • the LI core device's request for the NE's hashing and encryption information uses a SecurityTaskDetailRequest message.
  • the SecurityTaskDetailRequest message contain fields XlHashingAlgorithm, X2HashingAlgorithm, X3HashingAlgorithm,X2EncryptionAlgorithm, and X3EncryptionAlgorithm that includes a list of hashing and encryption algorithms available to the LI Core. These lists may be, for example, a list of numbers corresponding to known hashing algorithms or known encryption algorithms.
  • the field XlHashingAlgorithm may be a list of numbers [3, 4, 6], In view of previously established convention, that 0 indicates no hashing, 1 indicates SHA-0, 2: SHA-1, 3: SHA-224; 4: SHA-256; 5: SHA-384; 6: SHA-512; 7: SHA-3 (SHA being a family of cryptographic hashing algorithms published by the National Institute of Standards and Technology). Thus, the list [3, 4, 6] indicates that algorithms implementing SHA-224, SHA-256 and SHA-512 are available for use by the LI core device 120.
  • SHA-0 and SHA-1 are here mentioned only as examples, but should in preferred embodiments not be used as they are withdrawn/cryptographically broken algorithms.
  • the list of numbers may also have one or more numbers reserved for proprietary hashing algorithms or new algorithms to meet the demand for so- called post-quantum algorithms.
  • the list may include hashing algorithm names: [SHA- 224, SHA-256, SHA-512] instead of [3, 4, 6],
  • the field XlHashingAlgorithm of the SecurityTaskDetailRequest message may be empty providing no information about the hashing algorithm available to the LI core device 120.
  • the field X2EncryptionAlgorithm may be a list of numbers [1, 2, 4], In view of previously established convention, that 0 indicates no encryption, 1 indicates AES_128_GCM, 2: AES-256_GCM, 3: AES_128_CBC, 4: AES-256JZBC, 5: DES, 6: Chacha20 (AES and DES being a family of cryptographic encryption algorithms published by the National Institute of Standards and Technology and Chacha20 being a cryptographic encryption algorithm used by, for example, IETF RFC 7539). Thus, the list [1, 2, 4] indicates that algorithms implementing AES_128_GCM.
  • AES-256_GCM; and AES-256_CBC are available for use by the LI core device.
  • the list of numbers of encryption algorithms may also have one or more numbers reserved for proprietary hashing algorithms or new algorithms like CRYSTALS-Kyber or any other encryption algorithm that ultimately will be selected by US National Institute of Standards and Technology (NIST), to meet the demand for post-quantum encryption algorithms.
  • the list may contain encryption algorithm names.
  • the field X2EncryptionAlgorithm of the SecurityTaskDetailRequest message may be empty providing no information about the encryption algorithm available to the LI core device.
  • the LI core device 120 receives a second list of encryption algorithms that are available for use by the NED 110.
  • the second list of encryption algorithms is a list of encryption algorithms are available at or supported by the NED 110. In some embodiments, the second list of encryption algorithms are a list of encryption algorithms are available at or supported by the NED. In some embodiments, the LI core device 120 receives, in the form of the NE's response, a SecurityTaskDetailResponse message including the second list of NE-available hashing and encryption algorithms.
  • the SecurityTaskDetailResponse message has XlHashingAlgorithm, X2HashingAlgorithm, X3HashingAlgorithm,X2EncryptionAlgorithm, and X3EncryptionAlgorithm fields with a list of numbers, hashing algorithm names, and/or encryption algorithm names.
  • the XlHashingAlgorithm field of the SecurityTaskDetailResponse message may include [3, 6] or [SHA- 224, SHA-512], that is, a subset of the hashing algorithms available to the LI core device 120.
  • the SecurityTaskDetailRequest message did not indicate hashing algorithm(s)
  • the SecurityTaskDetailResponse message may return a list with all the hashing algorithms available to the NED 110 (e.g., [1, 3, 6] or [SHA-0, SHA-224, SHA-226]).
  • the LI core device 120 may receive from the NED 110, only the best (most complex) among the hashing algorithms that the NED can use (e.g., [6] or [SHA-512]). A similar procedure would be applicable for encryption algorithms in the SecurityTaskDetailRequest message and SecurityTaskDetailResponse message.
  • the LI core device 120 obtaining the encryption algorithm comprises comparing the second list to a first list of encryption algorithms that are available for use by the LI core device 120; and selecting, based on the comparison, the encryption algorithm, wherein the selected encryption algorithm is common to the first and second list of encryption algorithms.
  • the first LI core device may compare the list of LI core device-available hashing and encryption algorithms from, for example, the SecurityTaskDetailRequest message to the list of NE-available hashing and encryption algorithms from, for example, the SecurityTaskDetailResponse message.
  • the LI core device 120 may select hashing and encryption algorithms that are common to both the first lists and the second lists of the hashing and encryption algorithms. This selection may take a variety of different factors into account or may simply be random. The selection may be to choose the most recent, complex, or least computationally expensive algorithms shared by both lists. The selection may also be different for the individual X interfaces. The selection may also be left blank if there are no common algorithms in both lists.
  • this selection is made by the LI core device setting the value of NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEXJEncryptionAlgorithm equal to the hashing and encryption algorithms to be used by both the LI core device 120 and NED 110 for securing Targetidentifiers, xIRI and xCC data before storing and/or transmitting.
  • the hashing and encryption algorithms are set to be best (i.e., the most complex) among the commonly available algorithms.
  • a hashing or encryption algorithm providing the best compromise between security and execution speed may be preferred.
  • the LI core device may also be set to 0 or not chosen if the LI core device determines that a hashing algorithm or an encryption algorithm is not needed or preferred. This may be the result of the sensitivity or lack thereof of the LI target or the amount of LI targets to be handled by the NED or the LI core device. Through this selection, the LI core device may then obtain information indicative of the selection of the hashing and the encryption algorithm.
  • the selected hashing and encryption algorithm may be referred to as mutual hashing algorithm and mutual encryption algorithm, respectively.
  • the LI core device 120 transmits an indication of the selected encryption algorithm and hashing algorithm to the NED 110.
  • the indication of the selected hashing and encryption algorithms may be the hashing and the encryption algorithms, a location in a database where the hashing and the encryption algorithms may be found, or a selection of an encryption algorithm or a hashing algorithm from a list.
  • the LI core device may also transmit, to the NED, information indicative of a rejection of the selection of the hashing algorithm and/or the encryption algorithm.
  • the lack of a selection may be in the form of information indicative of a rejection by the LI core device of the selection or the LI core device being unable to make a selection.
  • Information indicative of may mean that the LI core device transmits a negative response or no response or a response that is understood by the communication system 100 that there is a lack of a selection or rejection of the selection.
  • the LI core device may be configured to perform method 960b, illustrated by figure 9c.
  • the LI core device then in a second step, 964b, sends a first list of encryption algorithms that are available for use by the LI core device.
  • the first list of encryption algorithms is a list of encryption algorithms are available at or supported by the LI core device.
  • the LI core device may also send a list of hashing and encryption algorithms to the NED. This may take the form of a list of hashing and encryption algorithms supported by the NED.
  • the LI core device 120 then in a third step, 966b, receives information indicative of a selection of the encryption algorithm and the hashing algorithm.
  • Information indicative of a selection may comprise the encryption algorithm and the hashing algorithm, a description of the encryption algorithm and the hashing algorithm such as a name, a location in a list of encryption and hashing algorithms, or a location in a database.
  • the LI core device may also receive information indicative of a selection of hashing and encryption algorithms from the NED 110.
  • the LI core device 120 through the receiving, may then obtain information indicative of the selection of the encryption and hashing algorithms.
  • the selected hashing and encryption algorithm may be referred to as mutual hashing algorithm and mutual encryption algorithm, respectively.
  • Figures 10a and 10b illustrate the two methods 1000a and 1000b, respectively which are two alternative embodiments of the NED 110.
  • the first embodiment illustrated by method 1000a and performed by the NED corresponds to some of the steps of the method 960a performed by the LI core device 120.
  • the second embodiment illustrated by method 1000b and performed by the NED corresponds to some of the steps in the method 960b performed by the LI core device.
  • the NED 110 is configured to perform the method 1000a, illustrated in figure 10a, which is reciprocal to the steps taken by the LI core in method 960b.
  • the NED in a first step, 1010a receives a request for hashing and encryption information.
  • the LI core device's request for the NE's hashing and encryption information uses the SecurityTaskDetailRequest message.
  • the NED 110 sends back information related to hashing and encryption algorithms, which in the embodiment illustrated in figure 10a, is in the form of a SecurityTaskDetailResponse message including a list of NE-available hashing and encryption algorithms.
  • the NED 110 transmits a second list of encryption algorithms that are available for use by the NED.
  • the second list of encryption algorithms is a list of encryption algorithms are available at or supported by the NED.
  • the NED receives, from the LI core, information indicative of a selection of one or more of the hashing algorithm and/or encryption algorithm.
  • the NED receives, from the LI core device, information indicative of the encryption algorithm and the hashing algorithm.
  • the information indicative of the hashing algorithm and the encryption algorithm may be the encryption algorithm and the hashing algorithm to be used, a location in a list, a location in a database where the encryption algorithm and the hashing algorithm may be found, or a selection of an encryption algorithm and a hashing algorithm.
  • the NED device is configured to perform the method 1000b, illustrated in figure 10b, which is reciprocal to those steps performed by the LI core device in method 960c.
  • the NED in a first optional step, 1010b, sends a request for hashing and encryption information from the LI core device.
  • the NED 110 receives hashing and encryption information from the LI core device.
  • This information may be in the form of a list of LI core device-available hashing and encryption algorithms.
  • the NED receives a first list of encryption algorithms that are available that are available for use by the LI core device.
  • the first list of encryption algorithms is a list of encryption algorithms are available at or supported by the LI core device 120.
  • the NED 110 obtaining an indication of the encryption algorithm and the hashing algorithm includes comparing the first list to a second list of encryption and hashing algorithms that are available for use by the NED; and selecting, based on the comparison, the encryption algorithm and the hashing algorithm, wherein both the selected encryption algorithm and the hashing algorithm are common to the first and second list of hashing and encryption algorithms.
  • the NED may compare the first list of LI core device- available hashing and encryption algorithm to a second list of NE- available hashing and encryption algorithms.
  • the NED may then select hashing and encryption algorithms that are common to both lists.
  • the selection may take a variety of different factors into account or may simply be random. The selection may be to choose the most recent, complex, or least computationally expensive algorithms shared by both lists. The selection may also be different for the individual X interfaces. The selection may also be left blank if there are no common algorithms in both lists.
  • the NED transmits an indication of the selected encryption algorithm and the hashing algorithm to the LI core device.
  • the indication of the encryption algorithm and the hashing algorithm may be the encryption algorithm and the hashing algorithm, a location in a database where the encryption algorithm and the hashing algorithm may be found, or a selection of an encryption algorithm and a hashing algorithm from a list.
  • the NED may also transmit, to the LI core device, information indicative of a rejection of the selection of the hashing algorithm and/or the encryption algorithm.
  • the lack of a selection may be in the form of information indicative of a rejection by the NED of the selection or the NED being unable to make a selection.
  • Information indicative of may mean that the NED transmits a negative response or no response or a response that is understood by the LI core device that there is a lack of a selection or rejection of the selection.
  • the LI core device may deny, as a result of the obtaining of information indicative of the encryption algorithm and the hashing algorithm, an operative connection between the NED and the LI core device.
  • An operative connection may be a connection between the NED and the LI core device.
  • the connection may be an X interface or other means of sending and receiving data. Denying an operative connection would mean that no data or not certain types of data could be sent over the connection.
  • NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEX3EncryptionAlgorithm variable values may be compared with predetermined values representing a minimum required complexity or a maximum value of computational cost of the hashing and encryption algorithms. If the selected hashing and encryption algorithms do not meet the minimum required complexity MinReqAIg) or the exceed the maximum computational cost, the NE's operative connection is denied. An error message may be sent to the NED to signal that the NED does not support the minimum required complexity of the hashing and encryption algorithms.
  • the LI core device may send information indicating to the NED to not encrypt a payload message.
  • the information may be a flag in a message, a message, or other data sent to the NED from the LI core device.
  • Figure 11 illustrates an embodiment in which an NED 110 comprising a POI 111 and a LI core 120 comprising a first communications device 122 (for e.g.: LI ADMF) interact.
  • the NED and the LI core device are configured to perform methods using the handshake mechanism to establish and update the hashing and encryption algorithms used for both securing the LI target identifier(s) and any IRI or CC related information produced by the POI.
  • the LI core device 120 comprising the first communications device 122 (for e.g.: an ADMF) performs the method 1100.
  • NED and LI Core connect and then, at a second step 1103, LI data destinations are transmitted from the LI core device to the NED and confirmed by the NED.
  • the LI core device transmits the SecurityTaskDetailRequest message at a third step 1105, the NED responds by sending the SecurityTaskDetailResponse message, comprising information indicative of one or more of the hashing algorithm, the encryption algorithm, the nonce associated to the target identifiers and/or the value based on the hash of the target identifier, at fourth step 1107.
  • the securityTaskDetailResponse message comprising information indicative of one or more of the hashing algorithm, the encryption algorithm, the nonce associated to the target identifiers and/or the value based on the hash of the target identifier.
  • Section 1140 is also optional in the sense that no LI task may occur and therefore the task will not be activated for the NED comprising the POI.
  • an LI task in which the NED is required to intercept a payload of data for the LI core device starts when the LEA device comprising the Warrant Issuing Authority activates or modifies, at a fifth step 1109, a warrant containing a target identifier, e.g. via the LEA device 140.
  • the LI core device sends, through an ActivateTaskRequest message or a ModifyTaskRequest message, information, at a sixth step 1111.
  • the NED receives information through the ActivateTaskRequest or ModifyTaskRequest message.
  • the information may be indicative of an XI hashing algorithm; an X2 hashing algorithm; an X3 hashing algorithm; a nonce associated with the XI interface; a nonce associated with the X2 interface; a nonce associated with the X3 interface; a hash value associated to the XI interface (the hash value being obtained by using the XI hashing algorithm on the target identifier by using the nonce associated with the XI interface as hash key); an X2 encryption algorithm; and/or an X3 encryption algorithm.
  • the NED may mean that the information contains the algorithms and nonces or may refer to items on a list of algorithms and nonces, or may mean that the information may refer to a database containing the algorithms and nonces indicated.
  • the NED receives the activate or modify message, the message enabled to compromise a nonce for each X interface associated with the NED and a hashed target identifier.
  • the NED replies with an A ctivateTaskResponse or ModifyTaskResponse response at a seventh step 1113.
  • the TaskDetails structure of the ActivateTaskRequest or ModifyTaskRequest message includes the SecureTargetldentifier field to convey the selected hashing and encryption algorithms, format of the target identifier prior to being hashed, the hashed target identifier and the nonce used to hash the target identifier.
  • Method 1200 includes receiving from a LI core device comprising a first communication device (e.g., LI ADMF) at a first step 1210, an indication of one or more of hashing algorithms, encryption algorithms, nonces for each X interface and a value based on the hash of the target identifier.
  • the NED may also instead calculate the value based on the hash of the target identifier using the hashing algorithm and the nonce associated with target identifier.
  • the NED may already have the target identifier and the hashing algorithm preloaded (for e.g.: in a case where the preloaded target identifier was received by the NED from the LI core device before a connection breakdown) and avoid the value based on the hash of the target identifier from having to be sent.
  • the NED obtains encryption and hashing algorithms associated with X interfaces.
  • the algorithms may be obtained from internal memory, LI core device comprising the first communication device, and/or a different external device.
  • the NED retrieves intercepted target identifiers, from LI data (IRI or CC).
  • LI data is formatted to be transmitted on an X2 or X3 interface is known as xIRI or xCC, respectively.
  • IRI and CC are reformatted by the MDF function before being transmitted on HI2 and HI3 interface, respectively, to LEMF.
  • Encryption and hashing algorithms may be obtained by the NED from internal memory, the LI core device or and external device.
  • method 1200 includes applying the hashing algorithm, XlHashingAlgorithm, using the nonce, Nonce_Xl, as the hashing key, to the intercepted target identifiers to obtain intercepted target identifiers hashed values, at a fourth step 1240. Then, if one of the intercepted target identifier hashed values matches the hashed_target_Xl received from the LI core device, the NED proceeds to a fifth step 1250.
  • the hashing algorithm XlHashingAlgorithm
  • the NED uses the hashed target identifiers associated with X2 and X3, hashed_target_X2 and hashed_target_X2 to encrypt, with the respective encryption algorithms, X2EncryptionAlgorithm and X3EncryptionAlgorithm, all sensitive data associated with the gathered xIRI and xCC data of the intercepted target identifier.
  • the hashed_target_X2 and hashed_target_X3 calculated by applying a corresponding hashing algorithm associated with the X interfaces to the target identifier using the nonce associated with the X3 interface, nonce_X2, and the nonce associated with the X3 interface, nonce_X3, as hashing key, respectively.
  • the xIRI and xCC data is then transmitted to the LI core device comprising the second communication device, more specifically the MDF, at a sixth step 1260. In the embodiment illustrated in figure 12, the xIRI and xCC data is sent using the X2 or X3 PDUs.
  • the X2 or X3 PDUs have a field Encryption Level to indicate to the MDF if the Conditional Attribute Field and Payload are encrypted.
  • This field may be, for example, a value of 0, 1, or 2 where 0 indicates no encryption is used, 1 indicates that the payload is encrypted and 2 indicates that both the payload and conditional attributes are encrypted.
  • the NED 110 may use an X2 or an X3 interface to deliver the encrypted xIRI or xCC to the MDF.
  • FIG. 13 is a flowchart illustrating matching the target identifier of LI data to the hash of the target identifier of the relevant target and payload encryption in an NED 110 according to an embodiment.
  • NED awaits events, that is, LI data (IRI and/or CC) interception and in a first step, intercepts a payload of data for the LI core device.
  • NED 110 retrieves intercepted target identifiers from the LI data.
  • NED applies the hashing algorithm(s) stored with corresponding nonces to the intercepted target identifiers to obtain intercepted target identifier hashed values.
  • the hashing algorithm XlHashingAlgorithm using Nonce_Xl as the hashing key, is applied to the intercepted target identifiers to obtain the intercepted target identifier hashed values.
  • Each of the intercepted target identifiers hashed values is compared with each hashed target identifier, hashed_target_Xl in the current embodiment, previously received by the NED (at the same time with a hashing algorithm indication and a nonce) at fourth step 1340.
  • a fifth step 1350 if there is a match of one of the intercepted target identifier hashed values with a respective hashed_target_Xl (i.e., YES branch of 1350), then the hashed target identities for the other X interfaces are determined in sixth step 1360.
  • the method comprises receiving from the LI core device, an indication of the hashing algorithm and a hash value obtained by applying the hashing algorithm to the target identifier using the nonce and intercepting a payload of data for the LI core device.
  • the method further comprises retrieving intercepted target identifiers, ITIs, from the intercepted payload of data, applying the hashing algorithm using the hash value to the ITIs to obtain intercepted target identifier hashed values and if one of the obtained intercepted target identifier hashed values matches the hash value, transmitting the intercepted payload of data to the LI core device. Otherwise in the "NO" branch of 1350, the method returns to step 1310 and the NED waits for new payload of data to be intercepted.
  • the sixth step 1360 is done by hashing the target id using the hashing algorithms associated with the X interfaces, X2HashingAlgorithms and X3HashingAlgorithms, together with the nonces as algorithm keys, the nonces associated with the X interfaces, Nonce_X2 and Nonce_X3.
  • the target identifier may be the intercepted target identification or maybe derived preemptively from the hashed_target_Xl, using XlHashingAlgorithm and Nonce_Xl. This results in the hashed target identifiers hashed_target_X2 and hashed_target_X3 which are used as the keys to encrypt the LI data in a seventh step 1370.
  • the encryption of step 1370 uses the encryption algorithms X2EncryptionAlgorithm and X3EncryptionAlgorithm, received from the LI core device in steps of method 600, to encrypt all the sensitive data in the LI data.
  • Sensitive data in the LI data may be the payload and conditional attribute fields of X2/X3 PDUs as defined in ETSI standard 103 221-2 vl.6.1 or payload and conditional attribute fields of X2/X3 PDUs defined by a similar, later, or complimentary standard.
  • the encrypted data is then formatted, in an eighth step 1380, into xIRI data and xCC data. If LI data is IRI, then it is formatted as xIRI when transmitted via the X2 interface.
  • LI data is CC, then it is formatted as xCC and transmitted on an X3 interface.
  • LI data is sent to the LI core device comprising the second communication device 125 (for e.g.: MDF) in PDUs via the X2 and/or X3 interface in a ninth step 1390 and the NED then proceeds to await a new event with new LI data.
  • the hashed_target_X2 and the hashed_target_X3 will be used as cryptographic keys to encrypt all the sensitive data in xIRI and xCC, so that the sensitive information on xIRI and xCC is encrypted and no sensitive data are sent in plaintext in xIRI and xCC.
  • obtaining a hash value comprises retrieving from the obtained encrypted LI data, a task identifier associated with an X interface, XID from the internal storage medium of the LI core device or the NED and retrieving at least one hash value associated with the XID.
  • the at least one hash value may be one or more of: the hash value of the target identifier associated to the X2 interface, hashed_target_X2 and the hash value of the target identifier associated to the X3 interface, hashed_target_X3. Both the hashed_target_X2 and the hashed_target_X3 are retrieved by searching for the XID in a database or the internal storage medium of the LI core device or the NED.
  • Transmission of the PDUs with encrypted payloads over the X2 or X3 interface may occur over a single connection between the NED and the LI core device or also occur across multiple other nodes in the communication system such as microservices, other network element devices, network servers and similar.
  • Microservices may be, in the current terminology, processes that communicate over a network or communication system to fulfill a goal using technology-agnostic protocols such as HTTP.
  • Transmission between the NED and the LI core device comprising the first and/or the second communication devices over the network occurs in the current embodiment using the Transport Layer Security, TLS, protocol or the IPsec protocol to secure communications between the NED, other nodes, and the LI Core.
  • TLS and the IPsec protocol serves to encrypt and otherwise secure communications between nodes but not inside the nodes themselves.
  • the payload of PDUs being transmitted across nodes in the communication system using TLS is visible to the nodes that the PDUs are passing through.
  • the encrypted payload in the current embodiment renders the payload unreadable to the nodes the PDU is passing through as it is transmitted to the LI core device comprising the second communication device.
  • the LI core device comprising the first communication device and the second communication device, the NED or other network administration function may inform network element devices in the communication system 100 or a network to cease using the Transport Layer Protocol or the IPsec protocol for one, some, or all messages communicated over an X interface.
  • the messages may comprise payloads for LI data such as for example, payloads sent over an X interface such as X2 or X3.
  • the NED would be operative to inform other network element devices in the communication system 100 to cease using the TLS protocol for messages communicated over the X interface. This would enable the reduction of computational resources of the network nodes and microservices that would otherwise have to implement the TLS protocol for xIRI and xCC messages while maintaining the security of the messages.
  • the LI core device may also send information indicating to the NED to not encrypt a payload message. This may be a result of computational limitations of the LI core device.
  • the NED proceeds to, in tenth step 1395, to delete the hashed target ids, hashed_target_X2 and hashed_target_X3, along with the encrypted payloads related to the LI data from its associated storage medium. This prevents this information from later being obtained and the encryption broken if the NED is compromised.
  • Figure 14 is a flowchart illustrating matching the target identifier of LI data to the hash of the target identifier of the relevant target and payload decryption in the LI core device 120 comprising the second communication device 125 according to an embodiment.
  • the LI core device waits for data sent to the LI core device over the X2 or X3 interface.
  • the LI core device receives, in a first step 1410, encrypted LI data with XID in plaintext over the X2 and/or X3 interfaces originating from the NED.
  • the LI core device retrieves using the received XID, the hashed_target_X2 and hashed_target_X3 at a second step 1420.
  • the hashed target identities for the X2 and X3 interfaces are used, in a third step 1430 to as the key for the decryption algorithm, X2EncryptionAlgorithm and X3EncryptionAlgorithm, to retrieve the encrypted data in the encrypted fields of the PDUs being sent over the X2 and X3 interfaces, the PDUs comprising the xIRI and/or xCC data.
  • the LI core device will then, in a fourth step 1440, format the decrypted LI data from the xIRI and xCC data to IRI and CC data for transmission on HI2 and HI3 interfaces respectively.
  • the LI core device uses, in a fifth step 1450, an HI2 or HI3 interface to deliver IRI and CC data, derived from the xIRI and xCC data, in plaintext to the LEMF.
  • the LI core device if the LI core device receives, in step 1410, a message over an X interface that cannot be decrypted, in step 1430, using the associated hashed target identifier, the LI core device alerts a law enforcement agency or another network element device. This alert would inform of a potential fault in the LI core or NED or inform of either the LI core or NED being compromised.
  • the alert may be in the form of a message, a shutdown of the LI core device, or some other transmission of information.
  • the functions of the LI core device comprising the first communication device and the second communication device may be handled by the LI MDF and LI ADMF, respectively.
  • the LI core device will delete, in a sixth step 1460, the data belonging to the decrypted LI data from its associated storage medium but keep the hashed target identifiers for when the NED detects the target and receives new LI data and begins method 800 and 1000 again.
  • the method of the LI core device comprises determining an indication of a mutual hashing algorithm to be used by the LI core device and by the NED.
  • the method comprises calculating a hash value corresponding to the target identifier, by applying the mutual hashing algorithm to the target identifier using the nonce.
  • the method further comprises storing the hash value and an information indicative of the mutual hashing algorithm and transmitting, to the NED, the hash value and the information indicative of the mutual hashing algorithm.
  • a similar method of determining a mutual encryption algorithm to be used by the LI core device and by the NED is also possible.
  • the method of the LI core comprises receiving from the NED, an indication of the mutual hashing algorithm.
  • the indication of the mutual hashing algorithm obtained by comparing the first list of hashing algorithms to the second list of hashing algorithms and selecting, based on the comparison, a hashing algorithm which is common to the first list and second list of hashing algorithms.
  • a similar method of receiving from the NED, an indication of a mutual encryption algorithm is also possible.
  • the method comprises sending one or more of a first list of encryption algorithms associated to an XI interface, a second list of encryption algorithms associated to an X2 interface and a third list of encryption algorithms associated to an X3 interface.
  • sending the nonce associated with a target identifier comprises one or more of sending: a first nonce associated to an XI interface, a second nonce associated to an X2 interface and sending a third nonce associated to an X3 interface.
  • obtaining an encrypted payload of LI data related comprises one or more of receiving the encrypted payload using the second nonce and an encryption algorithm from the second list of encryption algorithms associated to the X2 interface, and receiving the encrypted payload using the third nonce and an encryption algorithm from the third list of encryption algorithms associated to the X3 interface.
  • the second nonce and the third nonce may be the same if the third nonce is not specified.
  • the second list and the third list of encryption algorithms may be the same if the third list is not specified.
  • obtaining a hash value comprises reading a task identifier associated with an X interface, XID from the internal storage medium of the LI core device and retrieving the hash value corresponding to the XID.
  • the LI core device will store, together with plaintext target, a task identifier, XID, the three nonces (hashed_target_Xl, hashed_target_X2, hashed_target_X3) and the three hashed target identifiers (Nonce_Xl, Nonce_X2, Nonce_X3). In some embodiments, it may be possible to search the LI core device's internal storage or a database for a corresponding pair of hashed_target_Xl and XID.
  • the first communication device 125 for each target will send to the second communication device: the XID, the hashed_target_X2 and the hashed_target_X3.
  • the first communication device 122 provides to both the NED 110 and the second communication device 125, an indication of the encryption algorithm to be used on X2 and X3 interfaces.
  • the time required for the matching and decryption depends by the number of hashing algorithms/decryption keys used, so this number should preferably be small. For example, one set of algorithm/key pairs may be used, and a different set may be introduced only periodically or when a threat or security violation incident occurs. The update of the hashing and encryption algorithms and nonces occurs gradually, target by target as further explained, so no LI monitoring gaps occur.
  • the task-related information is deleted.
  • a similar procedure may also be performed whereby the hashing algorithms, nonces and stored target identifiers aren't updated but the encryption algorithms are updated whereby the encryption algorithms are updated.
  • Hashing algorithms, nonces, and stored target identifiers associated with a single or multiple X interfaces may also be updated per interface individually or as a group.
  • the LI core device may determine that encryption is not necessary for one or more of the LI data associated with an X interface. This may be the result of a lacking capability of the NED or that the LI network is designed in such a way that the NED has direct and secure transmission of data to the LI core device with no nodes in between. This may also be the result of a large amount of CC data being anticipated and that the encryption overhead may risk bottlenecks in the NED and result in CC data not being successfully received by the LEMF.
  • the LI system may determine that TLS encryption may be downgraded or eliminated altogether if the invention is enabled. Thereby, allowing for faster transmission and less computation at nodes in the network.
  • FIG. 15 is a block diagram of the NED 110 according to some embodiments.
  • the NED 110 may comprise: processing circuitry 1510 which may include one or more processors (e.g., a general purpose microprocessor and/or one or more processors, such as an application specific integrated circuit (ASIC), field-programmable gate arrays (FPGAs) and the like); interface circuitry 1520 for communicating with other nodes connected to a network 100; and a storage medium 1530 which may include one or more non-volatile storage devices and/or one or more volatile storage devices (e.g., random access memory (RAM)).
  • ASIC application specific integrated circuit
  • FPGAs field-programmable gate arrays
  • storage medium 1530 which may include one or more non-volatile storage devices and/or one or more volatile storage devices (e.g., random access memory (RAM)).
  • RAM random access memory
  • a computer program product includes a computer readable medium 1520 such as, but not limited to, the storage medium 1530, magnetic media (e.g., a hard disk), optical media, memory devices, and the like.
  • the storage medium may contain a computer program 1730a containing computer readable instructions 1740a that when executed by the processor circuit 1510 causes the processor circuit to perform operations according to embodiments disclosed herein.
  • processor circuitry 1510 may be defined to include a storage medium so a separate storage medium is not required.
  • FIG 16 is a block diagram of the LI core device 120 according to some embodiments.
  • the LI core device 120 may comprise: processing circuitry 1610 which may include one or more processors (e.g., a general purpose microprocessor and/or one or more processors, such as an application specific integrated circuit (ASIC), field-programmable gate arrays (FPGAs) and the like); interface circuitry 1620 for communicating with other nodes connected to a communication system 100; and a storage medium 1630 which may include one or more non-volatile storage devices and/or one or more volatile storage devices(e.g., random access memory (RAM)).
  • ASIC application specific integrated circuit
  • FPGAs field-programmable gate arrays
  • storage medium 1630 which may include one or more non-volatile storage devices and/or one or more volatile storage devices(e.g., random access memory (RAM)).
  • RAM random access memory
  • a computer program product includes a computer readable medium 1620 such as, but not limited to, the storage medium 1630, magnetic media (e.g., a hard disk), optical media, memory devices, and the like.
  • the storage medium may contain a computer program 1730b containing computer readable instructions 1740b that when executed by the processor circuit 1610 causes the processor circuit to perform operations according to embodiments disclosed herein.
  • processor circuitry 1610 may be defined to include a storage medium so a separate storage medium is not required.
  • Figure 17 is a diagram showing an embodiment of the invention.
  • the computer program product 1710 comprises a computer readable medium 1720 storing a computer program 1730a and 1730b comprising computer readable instructions 1740a and 1740b.
  • the computer readable medium may be but is not limited to, a storage medium 1530 and 1630, magnetic media (e.g., a hard disk), optical media, memory devices (e.g., random access memory, flash memory) and the like.
  • a method performed by a NED 110 in a communication system 100 comprises a LI POI.
  • the method comprises receiving a nonce associated with a target identifier.
  • the method comprises obtaining an indication of an encryption algorithm.
  • the method comprises encrypting a payload of LI data.
  • the payload of LI data is related to the target identifier.
  • the payload is encrypted using the nonce.
  • the payload is encrypted using the encryption algorithm.
  • the method comprises obtaining an indication of a hashing algorithm.
  • the method comprises calculating a hash value obtained by applying the hashing algorithm to the nonce.
  • encrypting a payload of LI data comprises using the hash value as a cryptographic key for the encryption algorithm.
  • the NED receives on an XI interface, a hash value associated to the XI interface and corresponding to the target identifier.
  • the method comprises receiving from the LI core device, three different nonces.
  • the three different nonces being a first nonce associated with the XI interface, a second nonce associated with an X2 interface and a third nonce associated with an X3 interface.
  • the first nonce is used as a hash key for the target identifier received on the XI interface.
  • the second nonce and the third nonce are used as a hash key for the target identifier to generate a second hash value and a third hash value, respectively.
  • the second hash value and the third hash value are used as an encryption key to encrypt the payload of LI data on the X2 interface and the X3 interface, respectively.
  • Traffic on the X2 interface and the X3 interface contains private and/or sensitive data of individuals which may be used to infer the identity of the individuals.
  • the private and/or sensitive data of individuals are communicated in clear text or plain text in the xIRI and the xCC. Thus, the private data could be stolen by an attacker and/or a malicious device.
  • An advantage of the various embodiments presented herein is providing better confidentiality and protection to the data of the individuals.
  • Another advantage of embodiments presented herein is providing better security and isolation to data of the individuals, especially private and/or sensitive data.
  • an attacker or a malicious device trying to retrieve or obtain the data of individuals may not be able to capture or try to derive the nonce when in transit via an X interface.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Technology Law (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

A network element device (110) and a LI core device (120) in a communications system (100), a corresponding method, computer program and computer program product are disclosed. The NED comprises a point of interception. The method of the NED comprises receiving a nonce associated with a target identifier, obtaining an indication of an encryption algorithm and encrypting a payload of LI data related to the target using the encryption algorithm and the nonce. The method of the LI core device comprises sending to the NED, the indication of the encryption algorithm and obtaining theencrypted payload of LI data related to the target identifier.

Description

ENCRYPTING AND DECRYPTING PAYLOAD FOR LAWFUL INTERCEPTION
TECHNICAL FIELD
The invention generally relates to lawful interception (LI) in a communication system; more specifically, to a network element device, a method performed by the network element device, an LI core device, a method performed by the LI core device, corresponding computer programs and corresponding computer program products.
BACKGROUND
Lawful interception (LI) of traffic between communicating entities in a telecommunication network is subject to standardization work carried out by the 3rd Generation Partnership Project (3GPP) and the European Telecommunications Standards Institute (ETSI). The standardization work has reached a stage where the specifications specify functionalities in 5th generation (5G) telecommunication system architectures. 5G network architecture is characterized by freely combinable, highly scalable microservices distributed over a cluster of network nodes in the network. This has spread services across the network, exposing such services to more opportunities for security breaches unless mitigated.
An LI system is connected to a Network Element/Point of Intercept (NE/POI) via interfaces XI, X2 and X3. The NED is a discrete telecommunications function hosted in an entity, which can be managed over a specific interface. The NED is functionally equivalent to a network function (NF) and the NED and NF may be used interchangeably. The XI interface is used by the LI system to manage the intercept function in the POI; the X2 interface is used by POI to send intercept related information (IRI) to the LI system; the X3 interface is used by NE/POI to send call content (CC) to the LI system. According to the ETSI TS 103 221-1 standard, V 1.13.1, an LI Core comprises an administration function (ADMF) which exchanges messages with the POI via the XI interface, and the NE/POI sends data related to IRI and CC. The data related to IRI and CC may be referred to as xIRI and xCC respectively, on the X2 and X3 interface according to ETSI TS 103 221-2 Vl.6.1.
US 2020/0267189 discloses an LI ADMF and a method performed by the LI ADMF related to LI.
In the current standardized architecture, xIRI and xCC contain information related to the target along with other sensitive information involved in the network traffic with the target. It would be desirable to address this potential exposure of sensitive target information over the network while allowing for flexibility inherent in a distributed and scalable network. SUMMARY
An object of the invention is to enable for management of lawful interception data related to a target to be more secure and/or more flexible.
According to a first aspect of the invention, a method performed by a network element device (NED) in a communication system is provided. The NED comprises a lawful interception (LI) point of interception (POI). The method comprises receiving a nonce associated with a target identifier. The method comprises obtaining an indication of an encryption algorithm and encrypting a payload of LI data. The payload of LI data is related to the target identifier. The payload is encrypted using the nonce and the encryption algorithm. Hereby is achieved that the LI data encrypted by the NED will be harder to understand for a hacker who illegally has somehow gained access to the encrypted LI data. Furthermore, the method enables the transfer of encrypted LI data from the NED to an LI core device (e.g. including an administrative function, ADMF) which increases the security of the LI data in transfer. Thus, it is enabled that an attack surface of a related communication system is reduced by making gathering of sensitive information of target identifiers from vulnerable microservices in the communication system more difficult. Another advantage of the method is that confidentiality related to information of the target identifier is improved. Another possible advantage of the method is increased robustness of a communication system related to the NED. Furthermore, by enabling LI data in transfer to be encrypted, the placement of a POI in a communication system can be made more flexibly, e.g. by enabling an Access and Management Function (AMF) provided with a POI to be positioned in less secure sites than a typical, heavily secure core network of a mobile network operator or a communications service provider.
According to an embodiment, the method comprises obtaining an indication of a hashing algorithm.
According to an embodiment, the method comprises calculating a hash value obtained by applying the hashing algorithm to the target identifier using the nonce.
According to an embodiment, encrypting a payload of LI data comprises using the hash value as a cryptographic key for the encryption algorithm.
According to an embodiment, the method comprises sending the encrypted payload over an X interface.
According to an embodiment, receiving a nonce associated with a target identifier comprises receiving a nonce associated with the target identifier and an X interface. According to an embodiment, the method comprises obtaining an indication of a further encryption algorithm, receiving a further nonce associated with the target identifier, encrypting a further payload of LI data using the further encryption algorithm and the further nonce and sending the encrypted further payload over a different X interface.
According to an embodiment, the communication system comprises a LI core device and the method comprises sending to the LI core device, information indicative of one or more of the encrypted payload, the indication of the hashing algorithm and the indication of the encryption algorithm. According to an embodiment, the method comprises sending to the LI core device, information indicative of the calculated hash value. According to an embodiment, the method of obtaining an encryption algorithm comprises receiving a first list of encryption algorithms that are available for use by the LI core device. According to an embodiment, the method comprises transmitting to the LI core device a second list of encryption algorithms that are available for use by the NED. According to an embodiment, the method of obtaining the hashing algorithm comprises receiving a first list of hashing algorithms that are available for use by the LI core device. According to an embodiment, the method comprises transmitting to the LI core device, a second list of hashing algorithms that are available for use by the NED.
According to an embodiment, the method comprises informing other network element devices in the communication system to cease using the T ransport Layer Security Protocol for messages communicated over an X interface. Hereby is achieved that handling of LI data is more secure and less complex within the communication system.
According to an embodiment, obtaining an indication of an encryption algorithm comprises comparing the first list of encryption algorithms to the second list of encryption algorithms and selecting, based on the comparison, a mutual encryption algorithm, wherein the mutual encryption algorithm is common to the first list and second list of encryption algorithms. According to an embodiment, the method comprises transmitting an indication of the mutual encryption algorithm to the LI core device.
According to an embodiment, obtaining an indication of an encryption algorithm comprises receiving, from an LI core device, information indicative of the encryption algorithm.
According to an embodiment, the method comprises receiving from the LI core device, an indication of the hashing algorithm and a hash value obtained by applying the hashing algorithm to the target identifier using the nonce, intercepting a payload of data for the LI core device, retrieving intercepted target identifiers (ITIs) from the intercepted payload of data, applying the hashing algorithm using the hash value to the ITIs to obtain intercepted target identifier hashed values, if one of the obtained intercepted target identifier hashed values matches the hash value, transmitting the intercepted payload of data to the LI core device.
According to an embodiment, the method of obtaining an indication of the hashing algorithm comprises comparing the first list of hashing algorithms to the second list of hashing algorithms, and selecting, based on the comparison, a mutual hashing algorithm, wherein the mutual hashing algorithm is common to the first list and second list of hashing algorithms. According to an embodiment, the method comprises transmitting an indication of the mutual hashing algorithm to the LI core device.
According to an embodiment, receiving a nonce associated with a target identifier comprises one or more of: receiving a first nonce associated to an XI interface; receiving a second nonce associated to an X2 interface; and receiving a third nonce associated to an X3 interface; and wherein obtaining an indication of an encryption algorithm comprises one or more of: obtaining an indication of a first encryption algorithm associated to the XI interface; obtaining an indication of a second encryption algorithm associated to the X2 interface; and obtaining an indication of a third encryption algorithm associated to the X3 interface.
According to an embodiment, encrypting a payload of LI data related to the target identifier comprises one or more of: encrypting the payload of LI data, to be sent through the X2 interface, using the second nonce and the second encryption algorithm; and encrypting the payload of LI data, to be sent through the X3 interface, using the third nonce and the third encryption algorithm. Hereby is achieved that the payload of LI data is transferred in more securely, reducing the possibility of an attacker who intercepts the payload to figure out the target identifier.
According to an embodiment, the method comprises receiving, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: a first hashing algorithm associated to the XI interface; a second hashing algorithm associated to the X2 interface; a third hashing algorithm associated to the X3 interface; a hash value associated to the XI interface; the first nonce; the second nonce; the third nonce; the first encryption algorithm; the second encryption algorithm; and the third encryption algorithm.
According to a second aspect of the invention, a NED in a communications system is provided. The NED comprises a LI POI. The NED is adapted to receive a nonce associated with a target identifier and obtain an indication of an encryption algorithm. The NED is adapted to encrypt a payload of LI data related to the target identifier, using the nonce and the encryption algorithm.
According to an embodiment, the NED is adapted to obtain an indication of a hashing algorithm. According to an embodiment, the NED is adapted to calculate a hash value obtained by applying the hashing algorithm to the target identifier using the nonce.
According to an embodiment, the NED adapted to encrypt a payload of LI data comprises the NED adapted to use the hash value as a cryptographic key for the encryption algorithm.
According to an embodiment, the NED is adapted to send the encrypted payload over an X interface.
According to an embodiment, the NED adapted to receive a nonce associated with a target identifier comprises the NED adapted to receive a nonce associated with the target identifier and an X interface.
According to an embodiment, the NED is adapted to obtain an indication of a further encryption algorithm, receive a further nonce associated with the target identifier, encrypt a further payload using the further encryption algorithm and the further nonce, and send the encrypted further payload over a different X interface.
According to an embodiment, the communication system comprises a LI core device and the NED is adapted to send to the LI core device, information indicative of one or more of the encrypted payload, the indication of the hashing algorithm and the indication of the encryption algorithm. According to an embodiment, the NED is adapted to send to the LI core device, information indicative of the calculated hash value. According to an embodiment, the NED adapted to obtain an indication of an encryption algorithm comprises the NED adapted to receive a first list of encryption algorithms that are available for use by the LI core device. According to an embodiment, the NED is adapted to transmit to the LI core device a second list of encryption algorithms that are available for use by the NED.
According to an embodiment, the NED is adapted to inform other network element devices in the communication system to cease using the T ransport Layer Security Protocol for messages communicated over an X interface.
According to an embodiment, the NED adapted to obtain an indication of the encryption algorithm comprises the NED adapted to compare the first list of encryption algorithms to the second list of encryption algorithms and select, based on the comparison, a mutual encryption algorithm, wherein the mutual encryption algorithm is common to the first list and second list of encryption algorithms. According to an embodiment, the method comprises transmitting an indication of the mutual encryption algorithm to the LI core device. According to an embodiment, the NED adapted to obtaining an indication of an encryption algorithm comprises the NED adapted to receive, from an LI core device, information indicative of the encryption algorithm.
According to an embodiment, the NED adapted to receive from the LI core device, an indication of the hashing algorithm and a hash value obtained by applying the hashing algorithm to the target identifier using the nonce; intercept a payload of data for the LI core device; retrieve intercepted target identifiers, ITIs from the intercepted payload of data; apply the hashing algorithm using the hash value to the ITIs to obtain intercepted target identifier hashed values; and if one of the obtained intercepted target identifier hashed values matches the hash value, transmit the intercepted payload of data to the LI core device.
According to an embodiment, the NED adapted to obtaining an indication of the hashing algorithm comprises the NED adapted to receive a first list of hashing algorithms that are available for use by the LI core device. According to an embodiment, the NED is adapted to transmit to the LI core device, a second list of hashing algorithms that are available for use by the NED.
According to an embodiment, the NED adapted to obtaining an indication of the hashing algorithm comprises the NED adapted to compare the first list of hashing algorithms to the second list of hashing algorithms, and select, based on the comparison, a mutual hashing algorithm, wherein the mutual hashing algorithm is common to the first list and second list of hashing algorithms. According to an embodiment, the NED is adapted to transmit an indication of the mutual hashing algorithm to the LI core device.
According to an embodiment, the NED adapted to receiving a nonce associated with a target identifier comprises one or more of the NED adapted to: receive a first nonce associated to an XI interface; receive a second nonce associated to an X2 interface; and receive a third nonce associated to an X3 interface; and the NED adapted to obtaining an indication of an encryption algorithm comprises one or more of the NED adapted to: obtain an indication of a first encryption algorithm associated to the XI interface; obtain an indication of a second encryption algorithm associated to the X2 interface; and obtain an indication of a third encryption algorithm associated to the X3 interface.
According to an embodiment, the NED adapted to encrypting a payload of LI data related to the target identifier comprises one or more of the NED adapted to: encrypt the payload of LI data, to be sent through the X2 interface, using the second nonce and the second encryption algorithm; and encrypt the payload of LI data, to be sent through the X3 interface, using the third nonce and the third encryption algorithm. According to an embodiment, the NED adapted to receiving, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: an indication of a first hashing algorithm associated to the XI interface; an indication of a second hashing algorithm associated to the X2 interface; an indication of a third hashing algorithm associated to the X3 interface; a hash value associated to the XI interface; the first nonce; the second nonce; the third nonce; the first encryption algorithm; the second encryption algorithm; and the third encryption algorithm.
According to a third aspect of the invention, a NED in a communications system is provided. The NED comprises a LI POI. The NED comprises a processing circuitry and storage medium containing instructions. The instructions when executed by the processing circuitry make the NED operative to receive a nonce associated with a target identifier. The instructions when executed by the processing circuitry make the NED operative to obtain an indication of an encryption algorithm. The instructions when executed by the processing circuitry make the NED operative to encrypt a payload of LI data related to the target identifier, using the nonce and the encryption algorithm.
According to an embodiment, the instructions when executed by the processing circuitry make the NED operative to perform operations according to embodiments of the first aspect.
According to a fourth aspect, a computer program is provided. The computer program comprises computer readable instructions to be executed by processing circuitry of a NED comprising a LI POI. Execution of the computer readable instructions causes the NED to perform operations according to the first aspect and embodiments of the first aspect.
According to a fifth aspect, a computer program product is provided. The computer program product comprises a computer readable storage medium on which a computer program according to the fourth aspect is stored.
According to a sixth aspect, a method performed by a LI core device in a communication system comprising a NED is provided. The method comprises sending to the NED, an indication of an encryption algorithm. The method comprises obtaining an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
According to an embodiment, the method of obtaining an encrypted payload of LI data related to a target identifier comprises receiving from the NED, the encrypted payload over an X interface.
According to an embodiment, the method comprises sending to the NED, a first list of hashing algorithms that are available for use by the LI core device. According to an embodiment, the method of sending to the NED, an indication of an encryption algorithm comprises sending to the NED, a first list of encryption algorithms that are available for use by the LI core device.
According to an embodiment, the method comprises sending to the NED, the nonce associated with the target identifier.
According to an embodiment, the method comprises sending to the NED, a further list of encryption algorithms that are available for use by the LI core device; sending to the NED, a further nonce associated with the target identifier; and receiving a further encrypted payload of LI data related to the target identifier, the further encrypted payload being encrypted using the further nonce and an encryption algorithm from the further list of encryption algorithms.
According to an embodiment, the method comprises receiving from the NED, the encrypted further payload over a different X interface.
According to an embodiment, the method comprises determining a mutual hashing algorithm to be used by the LI core device and by the NED; calculating a hash value corresponding to the target identifier, by applying the mutual hashing algorithm to the target identifier using the nonce; storing the hash value and an information indicative of the mutual hashing algorithm; and transmitting, to the NED, the hash value and the information indicative of the mutual hashing algorithm.
According to an embodiment, the method of determining a mutual hashing algorithm to be used by the LI core device and by the NED comprises: receiving from the NED, an indication of the mutual hashing algorithm, the mutual hashing algorithm obtained by comparing the first list of hashing algorithms to the second list of hashing algorithms; and selecting, based on the comparison, a hashing algorithm which is common to the first list and second list of hashing algorithms.
According to an embodiment, the method comprises receiving from the NED, information indicative of one or more of: an hashing algorithm that is available for use by the NED and an indication of an encryption algorithm that is available for use by the NED.
According to an embodiment, the method comprises receiving from the NED, information indicative of: a calculated hash value obtained by applying the hashing algorithm that is available to the NED, to the target identifier using the nonce.
According to an embodiment, the method comprises receiving from the NED, a second list of encryption algorithms that are available for use by the NED.
According to an embodiment, the method of receiving information indicative of an encryption algorithm comprises receiving from the NED, an indication of a mutual encryption algorithm, the mutual encryption algorithm obtained by comparing the first list of encryption algorithms to the second list of encryption algorithms; and selecting, based on the comparison, an encryption algorithm which is common to the first list and second list of encryption algorithms.
According to an embodiment, the method of sending an encryption algorithm comprises one or more of: sending a first list of encryption algorithms associated to an XI interface; sending a second list of encryption algorithms associated to an X2 interface; and sending a third list of encryption algorithms associated to an X3 interface.
According to an embodiment, the method of sending the nonce associated with a target identifier comprises one or more of: sending a first nonce associated to an XI interface; sending a second nonce associated to an X2 interface; and sending a third nonce associated to an X3 interface.
According to an embodiment, the method of obtaining an encrypted payload of LI data related comprises one or more of: receiving the encrypted payload using the second nonce and an indication of an encryption algorithm from the second list of encryption algorithms associated to the X2 interface; and receiving the encrypted payload using the third nonce and an indication of an encryption algorithm from the third list of encryption algorithms associated to the X3 interface.
According to an embodiment, the method comprises sending, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: a first list of hashing algorithms associated to the XI interface; a second list of hashing algorithms associated to the X2 interface; a third list of hashing algorithms associated to the X3 interface; the first nonce; the second nonce; the third nonce; the first list of encryption algorithms associated to the XI interface; the second list of encryption algorithms associated to the X2 interface; and the third list of encryption algorithms associated to the X3 interface.
According to an embodiment, the method comprises obtaining a hash value; using the calculated hash value as a cryptographic key for a decryption algorithm which performs an operation equivalent to an inverse of the mutual encryption algorithm; and decrypting the obtained encrypted payload using the decryption algorithm.
According to an embodiment, the method of obtaining a hash value comprises: obtaining a hash value comprises: retrieving from the obtained encrypted LI data, a task identifier associated with an X interface, XID and retrieving at least one hash value associated with the XID.
According to an embodiment, the method of obtaining a hash value comprises: calculating the hash value by applying a hashing algorithm from the list of hashing algorithms to the target identifier using the nonce. According to a seventh aspect, a LI core device in a communications system is provided. The LI core device is adapted to send to the NED, an indication of an encryption algorithm. The LI core device is adapted to obtain an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
According to an embodiment, the LI core device adapted to obtain an encrypted payload of LI data related to a target identifier comprises the LI core device adapted to receive from the NED, the encrypted payload over an X interface.
According to an embodiment, the LI core device is adapted to send to the NED, a first list of hashing algorithms that are available for use by the LI core device.
According to an embodiment, the LI core device adapted to send to the NED, an indication of an encryption algorithm comprises the LI core device adapted to send to the NED, a first list of encryption algorithms that are available for use by the LI core device.
According to an embodiment, the LI core device is adapted to send to the NED, the nonce associated with the target identifier.
According to an embodiment, the LI core device is adapted to send to the NED, a further list of encryption algorithms that are available for use by the LI core device; send to the NED, a further nonce associated with the target identifier; and receive a further encrypted payload of LI data related to the target identifier, the further encrypted payload being encrypted using the further nonce and an indication of an encryption algorithm from the further list of encryption algorithms.
According to an embodiment, the LI core device is adapted to receive from the NED, the encrypted further payload over a different X interface.
According to an embodiment, the LI core device is adapted to determine a mutual hashing algorithm to be used by the LI core device and by the NED; calculate a hash value corresponding to the target identifier, by applying the mutual hashing algorithm to the target identifier using the nonce; store the hash value and an information indicative of the mutual hashing algorithm; and transmit, to the NED, the hash value and the information indicative of the mutual hashing algorithm.
According to an embodiment, the LI core device adapted to determine a mutual hashing algorithm to be used by the LI core device and by the NED comprises the LI core device adapted to receive from the NED, an indication of the mutual hashing algorithm, the mutual hashing algorithm obtained by comparing the first list of hashing algorithms to the second list of hashing algorithms; and selecting, based on the comparison, a hashing algorithm which is common to the first list and second list of hashing algorithms. According to an embodiment, the LI core device is adapted to receive from the NED, information indicative of one or more of: a hashing algorithm that is available for use by the NED and an indication of an encryption algorithm that is available for use by the NED.
According to an embodiment, the LI core device is adapted to receive from the NED, information indicative of: a calculated hash value obtained by applying the hashing algorithm that is available to the NED, to the target identifier using the nonce.
According to an embodiment, the LI core device is adapted to receive from the NED, a second list of encryption algorithms that are available for use by the NED.
According to an embodiment, the LI core device adapted to receive information indicative of an encryption algorithm comprises the LI core device adapted to receive from the NED, an indication of a mutual encryption algorithm, the mutual encryption algorithm obtained by comparing the first list of encryption algorithms to the second list of encryption algorithms; and selecting, based on the comparison, an encryption algorithm which is common to the first list and second list of encryption algorithms.
According to an embodiment, the LI core device adapted to send an indication of an encryption algorithm comprises one or more of the LI core device adapted to: send a first list of encryption algorithms associated to an XI interface; send a second list of encryption algorithms associated to an X2 interface; and send a third list of encryption algorithms associated to an X3 interface.
According to an embodiment, the LI core device adapted to send the nonce associated with a target identifier comprises one or more of the LI core device adapted to: send a first nonce associated to an XI interface; send a second nonce associated to an X2 interface; and send a third nonce associated to an X3 interface.
According to an embodiment, the LI core device adapted to obtain an encrypted payload of LI data related comprises one or more of the LI core device adapted to: receive the encrypted payload using the second nonce and an encryption algorithm from the second list of encryption algorithms associated to the X2 interface; and receive the encrypted payload using the third nonce and an encryption algorithm from the third list of encryption algorithms associated to the X3 interface.
According to an embodiment, the LI core device is adapted to send, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: a first list of hashing algorithms associated to the XI interface; a second list of hashing algorithms associated to the X2 interface; a third list of hashing algorithms associated to the X3 interface; the first nonce; the second nonce; the third nonce; a hash value associated to the XI interface; the first list of encryption algorithms associated to the XI interface; the second list of encryption algorithms associated to the X2 interface; and the third list of encryption algorithms associated to the X3 interface.
According to an embodiment, the LI core device is adapted to obtain a hash value; using the obtained hash value as a cryptographic key for a decryption algorithm which performs an operation equivalent to an inverse of the mutual encryption algorithm; and decrypting the obtained encrypted payload using the decryption algorithm.
According to an embodiment, the LI core device adapted to obtain a hash value comprises the LI core device adapted to retrieve from the obtained encrypted LI data, a task identifier associated with an X interface, XID and retrieve at least one hash value associated with the XID.
According to an embodiment, the LI core device adapted to obtain a hash value comprises calculating the hash value by applying a hashing algorithm from the list of hashing algorithms to the target identifier using the nonce.
According to an eighth aspect, a LI core device in a communications system is provided. The LI core device comprises an interface circuitry, a processing circuitry and storage medium containing instructions that when executed by the processing circuitry make the NED operative to send to the NED, an indication of an encryption algorithm. The instructions that when executed by the processing circuitry make the NED operative to obtain an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
According to an embodiment, the LI core device of the eighth aspect is adapted to perform operations according to one or more of the embodiments of the sixth aspect.
According to a ninth aspect, a computer program is provided. The computer program comprises computer readable instructions to be executed by processing circuitry of a LI core device. Execution of the computer readable instructions causes the NED to perform operations according to the sixth aspect and embodiments of the sixth aspect.
According to a tenth aspect, a computer program product is provided. The computer program product comprises a computer readable storage medium on which a computer program according to the ninth aspect is stored.
BRIEF DESCRIPTION OF DRAWINGS
The accompanying drawings, which are incorporated herein and form part of the specification. illustrate various embodiments. Figure 1 is a diagram showing functional units of a communication network according to an embodiment.
Figure 2 is a flow chart illustrating a process according to an embodiment.
Figure 3 is a flow chart illustrating a process according to an embodiment.
Figure 4 is a flow chart illustrating a process according to an embodiment.
Figure 5 is a diagram showing functional units of a lawful interception system according to an embodiment.
Figure 6 is a signaling diagram showing a process according to an embodiment.
Figure 7 is a signaling diagram showing a process according to an embodiment.
Figure 8 is a flow chart illustrating a process according to an embodiment.
Figure 9a is a flow chart illustrating a process according to an embodiment.
Figure 9b is a flow chart illustrating a process according to an embodiment.
Figure 9c is a flow chart illustrating a process according to an embodiment.
Figure 10a is a flow chart illustrating a process according to an embodiment.
Figure 10b is a flow chart illustrating a process according to an embodiment.
Figure 11 is a signaling diagram showing a process according to an embodiment.
Figure 12 is a flow chart illustrating a process according to an embodiment.
Figure 13 is a flow chart illustrating a process according to an embodiment.
Figure 14 is a flow chart illustrating a process according to an embodiment.
Figure 15 is a diagram showing functional modules of a network element device according to an embodiment.
Figure 16 is a diagram showing functional modules of a lawful interception core device according to an embodiment.
Figure 17 shows one example of a computer program product comprising computer readable means according to an embodiment. DETAILED DESCRIPTION
The invention will now be described more fully herein with reference to the accompanying drawings, in which certain embodiments of the invention are shown. This invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
Embodiments of the invention are configured to allow a network element device (NED) in a communication system. The NED comprises a Point of Intercept (POI), and the NED is adapted/ configured/ operative to receive a nonce ("number used only once") associated with a target identifier, obtain an indication of an encryption algorithm and, using the nonce and the encryption algorithm, encrypt a payload of lawful interception (LI) data related to the target identifier.
The invention allows for encryption keys that are not transmitted between the NED and an LI core device, and encryption keys that are different for each task. Thereby, minimizing the risk of a data breach, even if an attacker was to break an encryption. Additionally, load on the communication system may be reduced since payloads comprising LI data are encrypted from creation to destination. Thus, making encryption of data for internal security handling between the NED and a communication device and making external security handling such as transport layer security protocol in the microservices hosting an LI core device, unnecessary. Additionally, in some embodiments, the encryption may be tailored in complexity and computational cost to the task and target or turned off for certain aspects if deemed unnecessary. This may reduce the attack surface of an LI system by making the gathering of sensitive data from vulnerable microservices in the communication system or an attached network significantly more difficult. Another advantage of the invention herein is that encryption of the LI data allows for a more secure way of handling the LI data. These added features are not in conflict with other conventional security mechanisms, which may be used in parallel.
The various embodiments may be embedded in an LI system such as communication system 100 illustrated in Figure 1. The communication system 100 comprises a network element device (NED) 110 comprising a POI. Further functions may be present in the communication system of the invention, as detailed below. The communication system 100 may comprise other network element devices beyond those shown in Figure 1 both related to LI and not related to LI. The other network element devices may reside between the NED and and/or may be a part of an attached network.
The communication system 100 comprises the NED 110 and an LI core device 120 comprising a first communication device 122 and/or a second communication device 125. The NED comprises a Point of Interception (POI) 111. An interface between the first communication device 122 and the NED, and an interface between the second communication device 125 and the NED may be present. In an embodiment, the first communication device 122 comprises an LI administration function (ADMF) or is able to perform as an ADMF. The first communication device 122 may also be able to perform as an LI mediation and delivery function (MDF). In an embodiment, the second communication device 125 comprises the MDF or is able to perform tasks associated with an MDF. The second communication device 125 may also be able to perform as an LI ADMF. The term LI core device 120, in the current disclosure, is used interchangeably to describe the characteristics and actions of either the first communication device, the second communication device, or both. The LI core device 120 is configured to intermediate between a law enforcement agency (LEA) that supplies warrants specifying LI targets and a type of interception and receives LI data such as Intercept Related Information (IRI) and/or Content of Communication (CC) and NEs comprising POIs. This is done via e.g. a LEA device 140. In an embodiment, POI is a network element device employed for interception and to produce LI data. While the present document uses the term Network Element device (NED), the term is intended to represent any given device performing tasks related to a Network Function (NF) which is intended to be given information regarding interception or mediation and delivery. Similarly, the term "ADMF" or "LI ADMF" is intended to represent any given network function that controls interception or mediation and delivery in other functions.
The POI may be implemented as a virtual network function or any software. LI refers to hardware and software support in radio communication systems (e.g., wireless networks, the communication system 100) enabling law enforcement agencies with legal authorization to selectively intercept communications or acquire communication-related information of targeted subscribers. LI data may be considered as any data collected during lawful interception by the NED 110 related to a target. A targeted subscriber of the targeted subscribers is hereafter referred to as a target. LI data may, for example, be IRI on X2 interface (xIRI), CC on X3 interface (xCC), IRI, and CC data. The xIRI and xCC are sometimes referred to as raw IRI and raw CC, respectively. The LI core device performs functions such as the administrative function, mediation function and delivery functions related to LI. The LI core device and the NED may communicate the communication network 100. In some embodiments, a radio access network (RAN) of the communication network may comprise the LI core device and the NED. In some embodiments, a core network (CN) of the communication network may comprise the LI core device and the NED. In some embodiments, the RAN may comprise the NED and the CN may comprise the LI core device. In some embodiments, the RAN may comprise the NED and another CN of another communication network may comprise the LI core device to enable LI across communication networks. Furthermore, by enabling LI data in transfer to be encrypted, placement of the NE comprising the POI in the communication system can be made more flexibly, e.g. by enabling an Access and Management Function (AMF) or any RAN node provided with a POI to be positioned in less secure sites than a typical, heavily secure core network of a mobile network operator or a communications service provider. In the communication system 100, the LI core device 120 is configured to send to the NED 110, indication/ identity of an encryption algorithm. The LI core device 120 is further configured to obtain an encrypted payload of LI data related to a target identifier wherein the encrypted payload is encrypted using a nonce associated with the target identifier and the encryption algorithm. Furthermore, the LI core device 120 is configured to obtain a hash value. The hash value is obtained by applying a hashing algorithm to the target identifier using the nonce. The obtained hash value is used as a cryptographic key for a decryption algorithm which performs an operation equivalent to an inverse of the encryption algorithm. Also, the LI core device is configured to decrypt the obtained encrypted payload using the decryption algorithm.
In the communication system 100, the NED 110 comprises the POI 111. The NED 110 is configured to receive the nonce associated with the target identifier, obtain an indication of an encryption algorithm and encrypt the payload of LI data related to the target identifier (for example: IRI and/or CC data), using the nonce and the encryption algorithm.
For example, embodiments of the invention described are configured to allow the LI core device 120 to communicate with the NED 110 via, for example, an X interface comprising the functionality of one or more of an XI, X2, and X3 interface. Furthermore, in some embodiments of the invention the LI core device 120 and the NED 110 are configured to agree on a mutual encryption algorithm for xIRI and xCC data transmitted over the X2 and X3 interface. Furthermore, in some embodiments of the invention the LI core device 120 and the NED 110 are configured to agree on a mutual hashing algorithm for the XI, X2 and X3 interfaces. The transmitted data is, in the current state of the art, exposed to services throughout the communication network 100 where the LI data passes. A payload of LI data may comprise CC, xCC, IRI or xIRI or any other type of information that is same as CC, xCC, IRI, or xIRI as defined in the lawful intercept system as defined by ETSI.
The LI core device 120 is configured to perform the method 200 illustrated in figure 2. In a first step 210 of method 200, the LI core device 120 is configured to send an indication of an encryption algorithm to the NED. In step 230, the LI core device 120 is configured to obtain an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm. The encryption algorithm being derived from the indication of the encryption algorithm. A nonce may be a random number, and may be based on a timeliness factor such as a timestamp or a sequence number. In the present context, the "nonce" means a number which is substantially (for the purpose of the present disclosure) used only once for one or more LI specific actions. The LI specific action may be encrypting a payload of LI data and decrypting an encrypted version of an LI payload. In an embodiment, the LI core device 120 generates a nonce associated with the target identifier. The nonce may be generated using processing circuitry, a cryptographically secure random number generator, a cryptographically secure token generator, or similar to generate the random number forming the nonce, optionally together with padding bits, salt. timestamp, or other data. The association of the nonce with the target identifier may mean that the value of the nonce depends on the target identifier itself (i.e. different target identifiers have different nonces, and/or a target identifier may have different nonces over time). The association of the nonce with an X interface may mean that the nonce is, and sometimes only is, used with data that is passing over the X interface or may mean that itself only passes over the X interface.
In some embodiments, after the LI core device 120 has generated the nonce associated with the target identifier, the LI core device 120 is configured to generate a different nonce associated with the target identifier. The generation of the different nonce occurring after: a set period of time, a certain number of received messages from the NED 110, failing to decrypt a received payload, a random period of time and/or a received message from the LEA, e.g. from the LEA device 140. In some embodiments, the sending step 210 may comprise sending of an indication of an encryption algorithm, sending of the encryption algorithm itself, or sending of a list of encryption algorithms that are available to use by the LI core device 120 and/or a list of encryption algorithms that are available to use by the NED 110. The LI core device 120 may be configured to obtain the encryption algorithm by either copying, moving, taking, receiving, or otherwise coming into possession of the encryption algorithm or the indication of the encryption algorithm.
A hash value of the target identifier is an output of a hashing algorithm wherein an input is the target identifier. The target identifier may be a technical identity that uniquely identifies the target of interception and can be but is not limited to an International mobile subscription identity (IMSI), international mobile equipment identity (IMEI), subscription permanent identifier (SUPI) or any other UE identifying value set by European Telecommunications Standards Institute (ETSI), Third Generation Partnership Project (3GPP), or Global System for Mobile Communications. The hash value of the target identifier could, for example, be a hash, the hash with padding values, the hash combined with other information such as a timestamp, an index value referring to the hash from a database, or similar value derived from the hash of the target identifier. The hashing algorithm comprises a function that takes a value or message of arbitrary length as an input and produces an output of a fixed length. In an embodiment of the invention, the hashing algorithm comprises a keyed hash algorithm. The keyed hash algorithm has two inputs: a value associated with the target identifier and a hash key (for e.g.: the nonce) to produce an output of fixed length. In an embodiment, the hash key is a value associated with the nonce, the nonce being associated with the target identifier. The hash key being a value associated with the nonce could be, for example, the nonce itself or a value depending on the nonce itself such as the nonce with padding values. In some embodiments, the nonce and the value based on the hash of the target identifier may also be received from the LEA device 140 or other device.
In an optional step 220 of method 200, the LI core device 120 sends to the NED 110, the nonce associated with the target identifier. The nonce may be sent to the NED over an XI interface or any other lawful intercept standardized interface, such as the X0 interface, connecting the LI core device to the NED. In certain embodiments, the LI core device may send to the NED, a hash value based on the target identifier, or both the hash value of the target identifier and the nonce. The LI core device 120 may, in some embodiments, store the nonce associated with the target identifier and/or the hash value based on the target identifier. The LI core device 120 may store the nonce and/or the hash value in the LI core device's storage medium or in a storage medium outside the LI core device 120. In some embodiments, the nonce may be associated with a specific X interface (for example, the XI interface) and the LI core device 120 may send multiple nonces, each nonce associated with a specific X interface (for example, a nonce for the XI interface and a nonce for the X2 interface) and/or each unique target identifier. For example, an embodiment may comprise a unique nonce for each X interface used by the NED and the LI core device 120 and each unique target identifier that the NED is sent from the LI core device. In one example set up, six nonces may be sent to the NED 110 from the LI core device 120, three nonces associated with one target identifier and three nonces associated with one target identifier further associated with a specific X interface.
In some embodiments, the LI core device 120 is configured to obtain an indication of an encryption algorithm. The indication of the encryption algorithm may be obtained from an internal storage medium in the LI core device 120, the NED 110, or an external device. The LI core device may obtain the indication of the encryption algorithm by either copying, moving, taking, receiving, or otherwise coming into possession of the encryption algorithm from a list of encryption algorithms that are available for use by the LI core device 120.
In some embodiments, the LI core device 120 may be configured to send to the NED, information indicative of one or more of a hashing algorithm; the encryption algorithm; the nonce associated with target identifiers; and/or the hash value of the target identifier. In some embodiments, this may be necessary such as, for example, if the NED is lacking any such information such as in a situation where, at some point in time, the LI core device 120 was active while the NED 110 was not. This may increase the robustness of the LI system.
The NED 110 according to the invention is configured to perform the method 300 illustrated in figure 3. In a first step 310 of method 300, the NED 110 is configured to receive a nonce associated with a target identifier. In an embodiment, the nonce is the same nonce generated by the LI core device 110 described with reference to figure 2. In some embodiments, the NED 110 is configured to receive the nonce from the LI core device 120. In some embodiments, the nonce may be associated with an individual X interface where, for example, a nonce is specified for being used to hash or encrypt LI data related to a target that is sent over the individual X interface. In some embodiments, the NED 110 may be configured to receive a nonce associated with an X interface and/or a target identifier. In some embodiments, the NED 110 is configured to receive multiple nonces associated with different X interfaces and target identifiers. In some embodiments, the NED 110 is configured to receive a hash value based on the target identifier obtained by calculating the hash value. In some embodiments, the hash value is calculated by applying a hashing algorithm to the target identifier and using the nonce associated with the target identifier as a hash key. In some embodiments, the NED 110 may be configured to obtain the hash value from the LI core device 120.
In some embodiments, the NED 110 may be configured to send, to the LI core device 120, information indicative of the hashing algorithm; the encryption algorithm; the nonce associated with target identifiers; and/or the value based on the hash of the target identifier. In some embodiments, this may be necessary such as, for example, if the LI core device 120 is lacking any such information such as in a situation where, at some point in time, the NED 110 was active while the LI core device 120 was not. This may increase robustness of the LI system.
In a second step 320 of method 300, the NED 110 obtains an indication of an encryption algorithm. The indication of the encryption algorithm may be obtained from an internal storage medium, from the LI core device 120, or from another external device. In some embodiments, the NED 110 is configured to obtain an indication of multiple encryption algorithms. In some embodiments, if an indication of a plurality of encryption algorithms is obtained, each encryption algorithm of the plurality is specific to a target identifier, e.g. different encryption algorithms are used for different target identifiers. In some embodiments, if an indication of a plurality of encryption algorithms is obtained, each encryption algorithm of the plurality may be specific to an X interface, e.g. different encryption algorithms are used for different X interfaces. The different encryption algorithms may also be specific for certain types of LI data such as CC and IRI, e.g. different encryption algorithms are used for CC and IRI. The hash value and the encryption algorithm mentioned with respect to figure 3 may result in a more secure exchange of communications such as CC and IRI payloads between the LI core device 120 and the NED 110. This more secure exchange may be the result of the NED 110 already having the target identifier preloaded. Thereby, avoiding sending of the hash value between the LI core node and the NED and risking possible interception of the hash value.
In some embodiments, the indication of the encryption algorithm obtained by the LI core device in some embodiments described in relation to figure 2 is the same as the indication of the encryption algorithm in step 320 of figure 3. The obtaining step 320 may comprise the receiving of an indication of an encryption algorithm, the receiving of the encryption algorithm itself, or the receiving of a list of encryption algorithms that are available to use by the LI core device 120 and/or a list of encryption algorithms that are available to use by the NED 110. The NED 110 may be configured to obtain the encryption algorithm by either copying, moving, taking, receiving, or otherwise coming into possession of the encryption algorithm or the indication of the encryption algorithm.
In a third step 330 of method 300, the NED 110 encrypts a payload of LI data related to the target identifier using the nonce and the encryption algorithm. The payload may comprise data associated with IRI, CC, and/or information related to the target identifier. The payload may comprise the whole amount of LI data or only a portion of the LI data. The relation of the LI data to the target identifier may mean that the LI data originated from an LI target or was associated with the LI target such as data with the LI target as the destination. In some embodiments, the nonce or a value associated with the nonce is used as a cryptographic key in the encryption algorithm. In some embodiments, the NED 110 is configured to encrypt the payload for the LI data related to the target identifier using the hash value based on the target identifier by applying the hashing algorithm to the target identifier and using the nonce. The NED 110 may be configured to encrypt the payload for LI data by using the hash value as the encryption key for the encryption algorithm.
In some embodiments, the NED 110 is configured to encrypt a payload for LI data related to the target identifier for an X interface using the nonce associated with the X interface and with the target identifier. In some embodiments, the NED 110 is configured to obtain an indication of a further encryption algorithm and encrypt the payload for LI data for an X interface with the encryption algorithm and the payload with the further encryption algorithm for a different X interface. The indication of the further encryption algorithm may be a different one than the indication of the encryption algorithm referred to previously. Using the encryption algorithm and the further encryption algorithm may increase the security of the LI data sent from the NED 110 as an attacker would need to crack multiple encryptions with different keys to access the LI data sent over all the interfaces. In some embodiments, the NED 110 may be configured to selectively not encrypt the payload of LI data related to the target identifier for an X interface. This may give rise to a reduction of computational resource usage for a case when there is a shortage of computational resources.
In an optional, fourth step 340 of method 300, the NED 110 is configured to send the encrypted payload of LI data. In some embodiments, the payload is sent directly to the LI core device 120. In some embodiments, the payload is sent to other network element devices, network functions, microservices, and/or similar directly or indirectly connected to the LI core device 120. In some embodiments, the NED 110 is configured to send the payload to the LI core device 120 over an attached network comprising network element devices, network functions, microservices, and/orsimilar. In some embodiments, the NED 110 is configured to send the payload over an X interface whereby the X interface may comprise the functionality of the X2, and/or X3 interface. The X interface may comprise the functionality of the X2 and/or X3 interface by communicating the same information as the interfaces are standardized to carry and/or sending information from the same source to the same destination as the interfaces.
The LI core device 120 according to the invention is further configured to perform the method 400 illustrated in figure 4. The first three steps are same as the steps 210, 220 and 230 presented in the description for figure 2. In step 410, the LI core device 120 is configured to receive the encrypted payload for LI data related to the target identifier wherein the payload message is encrypted using the nonce and the encryption algorithm. In some embodiments, the payload is sent by the NED 110. In some embodiments, the payload message is encrypted using the same nonce and encryption algorithms as defined by step 330. In some embodiments, the payload is received over an X interface, whereby the X interface may comprise the functionality of an X2, and/or X3 interface. In some embodiments, the payload may comprise data associated with intercept related information, content of communication, and/or information related to the target identifier.
In some embodiments, the LI core device 120 may calculate the hash value associated with the target identifier using a hashing algorithm and the nonce associated with the target identifier. In some embodiments, the hash value may be obtained by applying the hashing algorithm to the target identifier and using the nonce as a hash key. The LI core device 120 may, in some embodiments, store the target identifier, the nonce associated with the target identifier and/or the hash value of the target identifier. The LI core device 120 may store the target identifier, the nonce, and/or the hash value in the LI core device's storage medium or in a storage medium outside the LI core device. In some embodiments, the LI core device calculates the hash value associated with the target identifier by using the hashing algorithm and the nonce that was stored or by using the hashing algorithm and nonce received from another network element device, or the LEA device 140.
In step 420 of method 400, the LI core device 120 is configured to decrypt the payload for LI data related to the target identifier. In some embodiments, the decryption is performed using the hash value associated with the target identifier and a decryption algorithm associated with the encryption algorithm. In some embodiments, the decryption algorithm associated with the encryption algorithm may be a function that performs the inverse of the encryption algorithm by using the hash value as a cryptographic key to decrypt the encrypted payload into plaintext. In some embodiments, the hash value associated with the target identifier is the nonce or the hash value is derived from the nonce and/or a hash value based on the target identifier. In some embodiments, the hash value may be derived by calculating the value associated with the target identifier using a hashing algorithm and the nonce associated with the target identifier. In some embodiments, the decryption algorithm associated with the encryption algorithm is the inverse of the encryption algorithm.
The method 400 may further comprise calculating hashed target values, hashed_target_Xl, hashed_target_X2, and/or hashed_target_X3 for each X interface (for e.g.: XI interface, X2 interface and X3 interface) corresponding to an LI target identifier. The calculation is done using hashing algorithms XlHashingAlgorithm, X2HashingAlgorithm, and/or X3HashingAlgorithm and nonces Nonce_Xl, Nonce_X2, and/or Nonce_X3 at a step 405, which may be before both the steps 410 and 420. The nonce may be selected from a predetermined list of nonces or may be at least partially randomly generated (for example, using one of the methods discussed in WO 2019/093932 in regard to hash keys which are functionally the same). The hash value may also be left blank if the associated hashing algorithm variable was set to none.
Figures 5-14 describe an embodiment of the invention implemented in a lawful intercept system operating in a 5th generation 3GPP access network. The same elements and functions depicted in figure 1 in connection with the communication system 100 are indicated with the same reference numbers. It should be clear to the skilled person how the details of the embodiment presented in figures 5-14 may be changed to better suit other 3GPP access networks comprising lawful intercept implementations but also other access networks comprising lawful intercept implementations. The embodiment is not exclusive to how the invention may be implemented in such a network but representative of an implementation.
The various embodiments may be embedded in a communication system such as in system 500 depicted in figure 5 which is an embodiment of the communication system 100 illustrated in Figure 1. The system 500 also referred to the LI system comprises a LI core device 120. The LI core device 120 intermediates between the LEA device 140 that supplies warrants specifying LI targets and type of interception and receives LI data (IRI and/or CC) from network element devices having attached POIs. The LI core device 120 preforms one or more of the administrative, mediation and/or delivery functions related to LI, and comprises one or more devices such as the first communication device 122 and second communication device 125. The LI core device 120 and the NED 110 comprising a POI communicate over X interfaces comprising the functionality of an X0, XI, X2, and/or X3 interfaces.
The LI system is a system designed to identify, intercept, gather, mediate, deliver and store communications and information related to communications between a device, also known as a target, and the telecommunications network on behalf of a law enforcement agency with legal authorization. A target, also referred to as an LI target, may be a user equipment or a machine type communications device. A target has a target identifier such as an International mobile subscription identity (IMSI), International Mobile Equipment Identity (IMEI), or Network Access Identifier (NAI). The communication system may be, for example, a 3GPP radio access network of the 3rd, 4th, or 5th generation or a non-standardized telecommunications network compliant with an ETSI lawful interception system.
In figure 5, NED 110 comprises a POI 111. Figure 5 is based on a similar figure in the ETSI standard "Network Functions Virtualization (NFV); Security; Report on NFV LI Architecture" published by the European Telecommunications Standards Institute (ETSI) as ETSI GR NVF-SEC 011 vl.1.1 in April 2018. The LI core device 120 comprises the MDF 125 and administrative functions 521. The administrative functions comprise the ADMF 122 and the Lawful Intercept Application Controller 523. The LEA device 140 comprises the warrant issuing authority 543 and the Law Enforcement Monitoring Function/Facility (LEMF) 545. Communications between the LI core device 120 and the NED 110 are performed via LI interfaces internal to a communication service provider (CSP) or in a communication system 100: X0 (for configuring a POI and transmitting other application parameters), XI (for task and target management), X2 (for delivering information related to IRI data, xIRI, to the vMF/vDF), and X3 (for delivery of information related to CC data, xCC, to the vMF/vDF). The vMF and vDF are virtualized mediation functions and virtualized delivery functions respectively. Communications between the LI core device 120 and devices outside the CSP or the communication system 100, such as the LEA functions, take place via external handover HI1, HI2, and HI3. The LI core device, which in some embodiments of the invention comprises the ADMF, receives an LI request from LEA device via HI1 and delivers, via the MDF, IRI and CC to LEMF through the HI2 and HI3 interfaces, respectively.
In a reference model described in ETSI TS 103 221-1 vl.13.1 (2022-12) entitled "Lawful Interception (LI); Internal Network Interfaces; Part l:Xl" of December 2022, illustrated in Figure 6, a bidirectional XI interface is used for communication between the LI core device 120 comprising a controlling function such as the first communication device 122 (for e.g.: an ADMF) and a controlled function such as the NED 110. In some embodiments, the NED 110 is any network element device employed to intercept or mediate and deliver LI data (xIRI, IRI, xCC and CC) and the LI core device 120 comprising the ADMF 122 represents any core function in communication with the NED and/or the LEA device 140.
In some embodiments, the messages exchanged via the XI interface include messages for starting, modifying, and stopping tasks (detailed in section 6.2 of ETSI TS 103 221-1 Vl.13.1), messages for creating, modifying, and removing destinations (detailed in section 6.3) and messages for getting information from the NED (detailed in section 6.4). h ActivateTaskand ModifyTask messages sent from the LI core device to an NED to add a new LI task or modify an existing task, respectively, typically include a TaskDetails structure with a plurality of fields: XID that uniquely identifies the task. Targetidentifiers that identifies the LI target, DeliveryType (IRI, CC or both), etc. Targetldentifers may be an E164 Number, an International Mobile Subscriber Identity (IMSI), and International Mobile station Equipment Identity (IMEI), a Hashedldentifier, or any other format specified by an ETSI standard. Although the ActivateTask message is sent over a secure connection, there is a possibility that the LEA device 140 or the LI core device or the LEA request that the LI target is hashed. In case of a hashed LI target, the TaskDetailsExtensions and/or TargetldentifierExtension private extensions should be used.
In a reference model described in ETSI TS 103 221-2 v 1.6.1 (2022-03) entitled "Lawful Interception (LI); Internal Network Interfaces; Part 2: X2/X3" illustrated in Figure 7, unidirectional X2 and X3 interfaces are used for communication between the NED 110 containing the POI 111 and the LI core device 120 comprising a second communication device 125 (which may be an MF, DF, vMF, and/or vDF). The MDF represents any core function in communication with the POI and/orthe LEA device 140.
Messages exchanged via the X2 and X3 interface include messages for sending Protocol Data Units (PDUs) from a POI to the MDF detailed in section 5 of ETSI 103 221-2 vl.6.1. Each PDU contains a set of mandatory PDU header fields containing identifiers, routing and correlation information, and information related to the target/task id, XID (detailed in section 5.2), a set of additional conditional attributes conveying additional metadata about the intercepted material (detailed in section 5.3), and a copy of the intercepted payload material (detailed in section 5.4). The payload material contains either information related to IRI for PDUs for the X2 interface and information related to CC for PDUs for the X3 interface. The contents of these payloads are defined by several standards such as ETSI TS 102 232- 1, 3GPP TS 33.128, 3GPP TS 33.108, IPv4, IPv6, RADIUS, etc. or may be a unique non-standardized payload related to the task/target.
An LI core device 120 comprising a first communication device 122 according to an embodiment is configured to perform the method 800 illustrated in Figure 8. At a first step 810, the method comprises obtaining a nonce associated with a target identifier. The nonce may be obtained by selecting the nonce from a predetermined list of nonces or may be at least partially randomly generated (for example, using one of the methods discussed in WO 2019/093932 regarding hashing keys which are functionally the same as the nonce). In some embodiments, there may be multiple nonces associated with a target identifier, each nonce also associated with an X interface or other unique aspect of the LI system. In some embodiments, the LI core device 120 obtains a nonce associated with a target identifier, that is different from an already existing nonce associated with the same target identifier. Obtaining a different nonce that is different from an already existing nonce associated with the same target may occur after: a set period of time, a certain number of received messages, failure to decrypt a received encrypted payload, a random period of time and/or a received messaged from the LEA device 140. Such a re-obtainment of the different may not result in needing to perform step 820 or a step similar, particularly if step 820 or a step similar has been done for a previous nonce associated with a target identifier, the same target or otherwise, and instead move straight to step 830 or a similar step. The process of obtaining the nonce may thus accomplish an increased security of the communication system 100, as the nonce and subsequently encrypted payloads are refreshed with new encryption parameters.
At a second step 820, the method comprises obtaining an indication of hashing and encryption algorithms among site-available hashing algorithms and site-available encryption algorithms, both usable by the LI core device 120 and by the NED 110. In some embodiments, the hashing and encryption algorithms may instead reside outside of the LI core device 120 such as at the LEA device 140, the NED 110, or an external device. The step 820 may further comprise a handshake mechanism for determining and selecting an encryption algorithm and a hashing algorithm that is commonly available to the LI core device 120 and the NED 110, to encrypt xIRI and xCC payloads, and calculate the hash value, respectively.
In order to determine the hashing algorithm and the encryption algorithm, the LI core device
120 and the NED 110 may send a list indicating the hashing and encryption algorithms available to the LI core device 120, either at the LI core device or accessible to the LI core device over a network connection, to the NED, and then receive from the NED 110 a list indicating available hashing and encryption algorithms that are available to the NED 110, either at the NED 110 or accessible to the NED 110 over a network connection. In a different embodiment of determining the hashing and encryption algorithm, the LI core device 120 may send a list indicating the hashing and encryption algorithms available to the LI core device, to the NED, and then receive in response from the NED 120, an indication of the hashing and encryption algorithms. In a different embodiment of determining the hashing and encryption algorithm, the LI core device 120 may receive a list indicating hashing and encryption algorithms available to the NED and send an indication of a selection of the hashing algorithm and encryption algorithm. In one embodiment, two new messages, SecurityTaskDetailRequest and SecurityTaskDetailResponse, are added to the relevant LI standard for facilitating a hashing and encryption algorithm list exchange. The SecurityTaskDetailRequest may be used either by the LI core device 120 or NED 110 to request a list of available hashing algorithms and encryption algorithms. SecurityTaskDetailResponse may be used, by the LI core device 120 or the NED 110 receiving the SecurityTaskDetailRequest, to indicate a list of hashing algorithms and encryption algorithms present at the LI core device 120 or the NED 110.
At step 830, the method comprises obtaining a hash value corresponding to the LI target identifier using the hashing algorithm and the nonce. In some embodiments, the hash value may be calculated by applying the hashing algorithm to the target identifier using the nonce as a hash key. In some embodiments, wherein there are multiple nonces associated to the target identifier for each X interface, the method comprises obtain multiple hash values corresponding to the target identifier for each of the X interfaces. In an example, if there are three X interfaces XI, X2 and X3, then the method comprises calculating three hash values corresponding to each of XI, X2 and X3 by applying a hashing algorithm to the target identifier using a nonce associated with XI, applying a hashing algorithm to the target identifier using a nonce associated with X2 and applying a hashing algorithm to the target identifier using a nonce associated with X3.
Method 800 further includes storing information indicative of one or more of: the hashing algorithm; the nonce associated with the target identifier; the value based on the hash of the target identifier; and the encryption algorithm at a fourth step 840. This information may be organized as a database.
Further at a fifth step 850, method 800 includes sending and/or transmitting an indication of one or more of the hashing algorithms, the encryption algorithms, the nonces associated with the target identifiers (for e.g.: nonce_Xl, nonce_X2 and nonce_X3) and the value associated to the XI interface, hashed_target_Xl, based on the hash of the target identifier to the NED. One way of sending this information is by using a modified ActivateTaskRequest or modified ModifyTaskRequest message. The conventional ActivateTaskRequest message and ModifyTaskRequest message defined in the ETSI TS 103 221-1 standard may be improved for this purpose by adding a field named SecureTargetldentifier in the TaskDetails structure. In one embodiment, the SecureTargetldentifier field is filled with information when target identifier is not transmitted as plaintext. Secure Targetidentifier f e\d has a SecurityDetails format that includes: XlHashingAlgorithm, X2HashingAlgorithm, and X3HashingAlgorithm (number or alpha-numeric) indicating the selected hashing algorithm for each X interface; a TargetType (a UTF-8 string) indicating format of the target identifier prior to being hashed (e.g., IMSI, IMEI, etc.,); a HashedTarget (also a UTF-8 string) containing the hashed_target_Xl; and Nonce_Xl, Nonce_X2, and Nonce_X3 (UTF-8 strings) providing the nonces used by the hashing algorithm to hash the target identifier. Optionally, an OtherlnfoHashed field may also be included in the SecurityDetails format and be used to indicate other hash-related information (e.g., other information hashed together with the target identifier). Optionally, an OtherEncryption field may also be included in the SecurityDetails format and be used to indicate other encryption-related information (e.g. other information also passed on the XI interface that requires encryption in addition to other information encrypted together with xIRI and xCC information for the X2 and X3 interfaces). Since the ActivateTaskRequest and ModifyTaskRequest message uses the same TaskDetails structure, both benefit from the presence of the additional SecureTargetldentifier.
The presence of the SecureTargetldentifier field in the TaskDetails structure makes it easier and faster to enhance secure handling of hashed LI target identifiers as described for the embodiments in this section. The embodiments include an automatic handshake mechanism for establishing security details such as the hashing or encryption algorithm (i.e., hashing algorithm or encryption algorithms), nonces and any other security parameters, as well as to update these characteristics in case changes are caused by discovered vulnerabilities or the capabilities of network element devices are upgraded. The automatic handshake mechanism increases the security and serviceability also in 5G LI networks.
Figure 9a illustrates a method including a handshake mechanism indicated by step 820 in which a hashing algorithm and an encryption algorithm is selected using the SecurityTaskDetailRequest and the SecurityTaskDetailResponse messages. Although other messages for determining the hashing algorithm and the encryption algorithm to be used by the LI core device 120 and NED 110 may be used, such as the lists and indications specified previously. In an embodiment, the LI core device 120 comprising a first communication device 122 (for e.g.: an ADMF) and a second communication device 125 (for e.g.: an MDF), performs steps of the method 900. Starting at a first step 910, with NED 110 not connected to the LI core device 120 in the communication system 100. At step 920, the variables NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, and NEX2EncryptionAlgorithm, NEX3EncryptionAlgorithm are set to None. Then, at a third step 930, the NED 110 is connected to the LI core device 120 (a preliminary connection that may become operative at 950 or declined at 985). At a fourth step 940, LI data destinations are created. On XI, each task is uniquely identified by an XI identifier (XID), and each task is handled independently of all others and released once each task has ended. According to the current standard, the XID is a version 4 UUID as per IETF RFC 4122 "A Universally Unique Identifier (UUID) URN Namespace." The LI core device is responsible for correlating the XID to any LI instance identifiers (LIID) used to communicate with the LEA device 140. The LI core device may map an XID to a single LIID or to multiple LIIDs. The LIID(s) or more precisely the second communication device 125 (for e.g.: MDF(s)) of the LI core device 120 thereof is/are the destination(s) for the LI data.
Intercepted traffic is delivered by the NED 110 to at least one destination (for e.g., an MDF that may be virtual/ physical). Each destination is uniquely identified by a destination identifier handled independently from other details of the task. Each task is associated with one or more destinations.
Prior to associating a task with a destination identifier, the destination identifier must have been created (which happens at 940). Note that a conventional first communication device (that does not support selecting the hashing and encryption algorithm) performs only steps 910, 930, 940 and 950. According to the embodiment illustrated in Figures 9a, 9b, and 9c, at a fifth step 945 it is checked whether hashing and encryption is requested for deployment of the NED 110. If hashing and encryption is not requested (i.e., "NO" branch of 945), the NED is operative to not encrypt the payload of LI data related to the target identifier and then an eleventh step 950 follows the NED being operatively connected to the LI core device. If the hashing and encryption is requested ("YES" branch of 945), then it is tested whether NE's version of software supports selecting hashing and encryption algorithms at a sixth step 955. In some embodiments, the check in step 945 is done on an interface basis, such as if the NEX2EncryptionAlgorithm was blank or null for example, making the NED 110 operative to not encrypt the payload of LI data related to the target identifier for an X interface. This may result in a resource savings for the NED.
If NE's version of software does not support selecting hashing and encryption algorithms (i.e., "NO" branch of 955), then tenth step 985 follows using NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEX3EncryptionAlgorithm all being equal to None (set in step 920). Step 985 checks if NEX1 HashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEX3EncryptionAlgorithm value are acceptable (i.e., greater or equal to MinReqAIg). If the NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEX3EncryptionAlgorithm values are not acceptable then NE's connection is declined (i.e., "NO" branch of 985), otherwise (i.e., "YES" branch of 985) NED 110 is operatively connected to the LI core device.
If NE's version of software supports selecting hashing and encryption algorithms (i.e., "YES" branch of 955), the LI core device then performs a seventh step, 960. Step 960 comprises two different procedures, method 960a and method 960b presented in Figure 9b and 9c, respectively. The LI core device 120 according to one embodiment of step 960 is configured to perform the method 960a illustrated in Figure 9b. LI core device 120, in a first step, 962a, requests hashing and encryption information from the NED 110 and subsequently receives the NE's response at a second step 964a. In the embodiment illustrated in Figure 9b the LI core device's request for the NE's hashing and encryption information uses a SecurityTaskDetailRequest message. The SecurityTaskDetailRequest message contain fields XlHashingAlgorithm, X2HashingAlgorithm, X3HashingAlgorithm,X2EncryptionAlgorithm, and X3EncryptionAlgorithm that includes a list of hashing and encryption algorithms available to the LI Core. These lists may be, for example, a list of numbers corresponding to known hashing algorithms or known encryption algorithms.
In an indication of a hashing algorithm example, the field XlHashingAlgorithm may be a list of numbers [3, 4, 6], In view of previously established convention, that 0 indicates no hashing, 1 indicates SHA-0, 2: SHA-1, 3: SHA-224; 4: SHA-256; 5: SHA-384; 6: SHA-512; 7: SHA-3 (SHA being a family of cryptographic hashing algorithms published by the National Institute of Standards and Technology). Thus, the list [3, 4, 6] indicates that algorithms implementing SHA-224, SHA-256 and SHA-512 are available for use by the LI core device 120. SHA-0 and SHA-1 are here mentioned only as examples, but should in preferred embodiments not be used as they are withdrawn/cryptographically broken algorithms. The list of numbers may also have one or more numbers reserved for proprietary hashing algorithms or new algorithms to meet the demand for so- called post-quantum algorithms. Alternatively, the list may include hashing algorithm names: [SHA- 224, SHA-256, SHA-512] instead of [3, 4, 6], In one embodiment, the field XlHashingAlgorithm of the SecurityTaskDetailRequest message may be empty providing no information about the hashing algorithm available to the LI core device 120.
In an indication of an encryption algorithm example, the field X2EncryptionAlgorithm may be a list of numbers [1, 2, 4], In view of previously established convention, that 0 indicates no encryption, 1 indicates AES_128_GCM, 2: AES-256_GCM, 3: AES_128_CBC, 4: AES-256JZBC, 5: DES, 6: Chacha20 (AES and DES being a family of cryptographic encryption algorithms published by the National Institute of Standards and Technology and Chacha20 being a cryptographic encryption algorithm used by, for example, IETF RFC 7539). Thus, the list [1, 2, 4] indicates that algorithms implementing AES_128_GCM. AES-256_GCM; and AES-256_CBC are available for use by the LI core device. The list of numbers of encryption algorithms may also have one or more numbers reserved for proprietary hashing algorithms or new algorithms like CRYSTALS-Kyber or any other encryption algorithm that ultimately will be selected by US National Institute of Standards and Technology (NIST), to meet the demand for post-quantum encryption algorithms. Alternatively, the list may contain encryption algorithm names. In one embodiment, the field X2EncryptionAlgorithm of the SecurityTaskDetailRequest message may be empty providing no information about the encryption algorithm available to the LI core device. At step 964a, the LI core device 120 receives a second list of encryption algorithms that are available for use by the NED 110. The second list of encryption algorithms is a list of encryption algorithms are available at or supported by the NED 110. In some embodiments, the second list of encryption algorithms are a list of encryption algorithms are available at or supported by the NED. In some embodiments, the LI core device 120 receives, in the form of the NE's response, a SecurityTaskDetailResponse message including the second list of NE-available hashing and encryption algorithms. Similar to the SecurityTaskDetailRequest message, the SecurityTaskDetailResponse message has XlHashingAlgorithm, X2HashingAlgorithm, X3HashingAlgorithm,X2EncryptionAlgorithm, and X3EncryptionAlgorithm fields with a list of numbers, hashing algorithm names, and/or encryption algorithm names. For example, if the SecurityTaskDetailRequest message indicated [3, 4, 6] or [SHA-224, SHA-256, SHA-512], the XlHashingAlgorithm field of the SecurityTaskDetailResponse message may include [3, 6] or [SHA- 224, SHA-512], that is, a subset of the hashing algorithms available to the LI core device 120. In case the SecurityTaskDetailRequest message did not indicate hashing algorithm(s), the SecurityTaskDetailResponse message may return a list with all the hashing algorithms available to the NED 110 (e.g., [1, 3, 6] or [SHA-0, SHA-224, SHA-226]). In one embodiment, the LI core device 120 may receive from the NED 110, only the best (most complex) among the hashing algorithms that the NED can use (e.g., [6] or [SHA-512]). A similar procedure would be applicable for encryption algorithms in the SecurityTaskDetailRequest message and SecurityTaskDetailResponse message.
In some embodiments, for example, in steps 966a and 968a, the LI core device 120 obtaining the encryption algorithm comprises comparing the second list to a first list of encryption algorithms that are available for use by the LI core device 120; and selecting, based on the comparison, the encryption algorithm, wherein the selected encryption algorithm is common to the first and second list of encryption algorithms.
After receiving the NE's response, at a third step 966a, the first LI core device may compare the list of LI core device-available hashing and encryption algorithms from, for example, the SecurityTaskDetailRequest message to the list of NE-available hashing and encryption algorithms from, for example, the SecurityTaskDetailResponse message.
In a fourth step 968a, the LI core device 120 may select hashing and encryption algorithms that are common to both the first lists and the second lists of the hashing and encryption algorithms. This selection may take a variety of different factors into account or may simply be random. The selection may be to choose the most recent, complex, or least computationally expensive algorithms shared by both lists. The selection may also be different for the individual X interfaces. The selection may also be left blank if there are no common algorithms in both lists. In the present embodiment, this selection is made by the LI core device setting the value of NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEXJEncryptionAlgorithm equal to the hashing and encryption algorithms to be used by both the LI core device 120 and NED 110 for securing Targetidentifiers, xIRI and xCC data before storing and/or transmitting. For example, the hashing and encryption algorithms are set to be best (i.e., the most complex) among the commonly available algorithms. Alternatively, a hashing or encryption algorithm providing the best compromise between security and execution speed may be preferred. The LI core device may also be set to 0 or not chosen if the LI core device determines that a hashing algorithm or an encryption algorithm is not needed or preferred. This may be the result of the sensitivity or lack thereof of the LI target or the amount of LI targets to be handled by the NED or the LI core device. Through this selection, the LI core device may then obtain information indicative of the selection of the hashing and the encryption algorithm. The selected hashing and encryption algorithm may be referred to as mutual hashing algorithm and mutual encryption algorithm, respectively.
In a fifth step 969a, the LI core device 120 transmits an indication of the selected encryption algorithm and hashing algorithm to the NED 110. The indication of the selected hashing and encryption algorithms may be the hashing and the encryption algorithms, a location in a database where the hashing and the encryption algorithms may be found, or a selection of an encryption algorithm or a hashing algorithm from a list. The LI core device may also transmit, to the NED, information indicative of a rejection of the selection of the hashing algorithm and/or the encryption algorithm. The lack of a selection may be in the form of information indicative of a rejection by the LI core device of the selection or the LI core device being unable to make a selection. Information indicative of may mean that the LI core device transmits a negative response or no response or a response that is understood by the communication system 100 that there is a lack of a selection or rejection of the selection.
Alternatively to method 960a, the LI core device according to another embodiment, may be configured to perform method 960b, illustrated by figure 9c. The LI core device then in a second step, 964b, sends a first list of encryption algorithms that are available for use by the LI core device. The first list of encryption algorithms is a list of encryption algorithms are available at or supported by the LI core device. The LI core device may also send a list of hashing and encryption algorithms to the NED. This may take the form of a list of hashing and encryption algorithms supported by the NED.
The LI core device 120 then in a third step, 966b, receives information indicative of a selection of the encryption algorithm and the hashing algorithm. Information indicative of a selection may comprise the encryption algorithm and the hashing algorithm, a description of the encryption algorithm and the hashing algorithm such as a name, a location in a list of encryption and hashing algorithms, or a location in a database. The LI core device may also receive information indicative of a selection of hashing and encryption algorithms from the NED 110. The LI core device 120, through the receiving, may then obtain information indicative of the selection of the encryption and hashing algorithms. The selected hashing and encryption algorithm may be referred to as mutual hashing algorithm and mutual encryption algorithm, respectively.
Figures 10a and 10b illustrate the two methods 1000a and 1000b, respectively which are two alternative embodiments of the NED 110. The first embodiment illustrated by method 1000a and performed by the NED corresponds to some of the steps of the method 960a performed by the LI core device 120. The second embodiment illustrated by method 1000b and performed by the NED corresponds to some of the steps in the method 960b performed by the LI core device.
The NED 110 according to one embodiment is configured to perform the method 1000a, illustrated in figure 10a, which is reciprocal to the steps taken by the LI core in method 960b.
The NED in a first step, 1010a receives a request for hashing and encryption information. In the embodiment illustrated in figure 10a, the LI core device's request for the NE's hashing and encryption information uses the SecurityTaskDetailRequest message.
In a second step, 1020a, the NED 110 sends back information related to hashing and encryption algorithms, which in the embodiment illustrated in figure 10a, is in the form of a SecurityTaskDetailResponse message including a list of NE-available hashing and encryption algorithms. In some embodiments, the NED 110 transmits a second list of encryption algorithms that are available for use by the NED. The second list of encryption algorithms is a list of encryption algorithms are available at or supported by the NED.
In a third step, 1030a, the NED receives, from the LI core, information indicative of a selection of one or more of the hashing algorithm and/or encryption algorithm. In some embodiments, the NED receives, from the LI core device, information indicative of the encryption algorithm and the hashing algorithm. The information indicative of the hashing algorithm and the encryption algorithm may be the encryption algorithm and the hashing algorithm to be used, a location in a list, a location in a database where the encryption algorithm and the hashing algorithm may be found, or a selection of an encryption algorithm and a hashing algorithm.
In a different embodiment, the NED device is configured to perform the method 1000b, illustrated in figure 10b, which is reciprocal to those steps performed by the LI core device in method 960c.
The NED in a first optional step, 1010b, sends a request for hashing and encryption information from the LI core device.
In a second step, 1020b, the NED 110 receives hashing and encryption information from the LI core device. This information may be in the form of a list of LI core device-available hashing and encryption algorithms. In some embodiments, the NED receives a first list of encryption algorithms that are available that are available for use by the LI core device. The first list of encryption algorithms is a list of encryption algorithms are available at or supported by the LI core device 120. In some embodiments, for example, in steps 1030b and 1040b, the NED 110 obtaining an indication of the encryption algorithm and the hashing algorithm includes comparing the first list to a second list of encryption and hashing algorithms that are available for use by the NED; and selecting, based on the comparison, the encryption algorithm and the hashing algorithm, wherein both the selected encryption algorithm and the hashing algorithm are common to the first and second list of hashing and encryption algorithms.
After receiving the LI core device's response, at a third step 1030b, the NED may compare the first list of LI core device- available hashing and encryption algorithm to a second list of NE- available hashing and encryption algorithms.
In a fourth step, 1040b, the NED may then select hashing and encryption algorithms that are common to both lists. The selection may take a variety of different factors into account or may simply be random. The selection may be to choose the most recent, complex, or least computationally expensive algorithms shared by both lists. The selection may also be different for the individual X interfaces. The selection may also be left blank if there are no common algorithms in both lists.
In a fifth step, 1050b, the NED transmits an indication of the selected encryption algorithm and the hashing algorithm to the LI core device. The indication of the encryption algorithm and the hashing algorithm may be the encryption algorithm and the hashing algorithm, a location in a database where the encryption algorithm and the hashing algorithm may be found, or a selection of an encryption algorithm and a hashing algorithm from a list. The NED may also transmit, to the LI core device, information indicative of a rejection of the selection of the hashing algorithm and/or the encryption algorithm. The lack of a selection may be in the form of information indicative of a rejection by the NED of the selection or the NED being unable to make a selection. Information indicative of may mean that the NED transmits a negative response or no response or a response that is understood by the LI core device that there is a lack of a selection or rejection of the selection.
Returning to method 900, in the tenth step 985, the LI core device may deny, as a result of the obtaining of information indicative of the encryption algorithm and the hashing algorithm, an operative connection between the NED and the LI core device. An operative connection may be a connection between the NED and the LI core device. The connection may be an X interface or other means of sending and receiving data. Denying an operative connection would mean that no data or not certain types of data could be sent over the connection. NEXIHashingAlgorithm, NEX2HashingAlgorithm, NEX3HashingAlgorithm, NEX2EncryptionAlgorithm, and NEX3EncryptionAlgorithm variable values may be compared with predetermined values representing a minimum required complexity or a maximum value of computational cost of the hashing and encryption algorithms. If the selected hashing and encryption algorithms do not meet the minimum required complexity MinReqAIg) or the exceed the maximum computational cost, the NE's operative connection is denied. An error message may be sent to the NED to signal that the NED does not support the minimum required complexity of the hashing and encryption algorithms. Note that MinReqAlg=None for one of the hashing or encryption algorithms means that even if the use of the hashing or encryption algorithm is desirable, it is not mandatory, and target identifiers may be sent as plaintext to the NED or xIRI/xCC payloads may be sent to the MDF in plaintext or with internodal TLS encryption. If the selected hash or encryption algorithm equals or exceeds the minim required complexity (MinReqAIg) or, on the other hand, stays under the maximum allowed computational cost, NED is operatively connected to the LI core device at the eleventh step 950.
In some embodiments, the LI core device may send information indicating to the NED to not encrypt a payload message. The information may be a flag in a message, a message, or other data sent to the NED from the LI core device.
Figure 11 illustrates an embodiment in which an NED 110 comprising a POI 111 and a LI core 120 comprising a first communications device 122 (for e.g.: LI ADMF) interact. The NED and the LI core device are configured to perform methods using the handshake mechanism to establish and update the hashing and encryption algorithms used for both securing the LI target identifier(s) and any IRI or CC related information produced by the POI. In some embodiments, the LI core device 120 comprising the first communications device 122 (for e.g.: an ADMF) performs the method 1100. At a first step 1101, NED and LI Core connect and then, at a second step 1103, LI data destinations are transmitted from the LI core device to the NED and confirmed by the NED.
In section 1140 (optional depending on whether both NED and LI core device are configured to use the handshake mechanism for selecting the hashing and encryption algorithms to be used), the LI core device transmits the SecurityTaskDetailRequest message at a third step 1105, the NED responds by sending the SecurityTaskDetailResponse message, comprising information indicative of one or more of the hashing algorithm, the encryption algorithm, the nonce associated to the target identifiers and/or the value based on the hash of the target identifier, at fourth step 1107. The previously discussed variations of these messages, as presented in step 960a and 960b presented in figure 9b and 9c, respectively of method 900, are pertinent here.
Section 1140 is also optional in the sense that no LI task may occur and therefore the task will not be activated for the NED comprising the POI. However, an LI task in which the NED is required to intercept a payload of data for the LI core device (i.e., performs POI functions) starts when the LEA device comprising the Warrant Issuing Authority activates or modifies, at a fifth step 1109, a warrant containing a target identifier, e.g. via the LEA device 140. The LI core device sends, through an ActivateTaskRequest message or a ModifyTaskRequest message, information, at a sixth step 1111. The NED receives information through the ActivateTaskRequest or ModifyTaskRequest message. The information may be indicative of an XI hashing algorithm; an X2 hashing algorithm; an X3 hashing algorithm; a nonce associated with the XI interface; a nonce associated with the X2 interface; a nonce associated with the X3 interface; a hash value associated to the XI interface (the hash value being obtained by using the XI hashing algorithm on the target identifier by using the nonce associated with the XI interface as hash key); an X2 encryption algorithm; and/or an X3 encryption algorithm. Indicative, in some embodiments, may mean that the information contains the algorithms and nonces or may refer to items on a list of algorithms and nonces, or may mean that the information may refer to a database containing the algorithms and nonces indicated. The NED receives the activate or modify message, the message enabled to compromise a nonce for each X interface associated with the NED and a hashed target identifier. In response to receiving the activate or modify message, the NED replies with an A ctivateTaskResponse or ModifyTaskResponse response at a seventh step 1113. In case both NED and LI Core are configured to use the handshake mechanism for the hashing and encryption algorithms, the TaskDetails structure of the ActivateTaskRequest or ModifyTaskRequest message includes the SecureTargetldentifier field to convey the selected hashing and encryption algorithms, format of the target identifier prior to being hashed, the hashed target identifier and the nonce used to hash the target identifier. Once the LI core device receives the ActivateTaskResponse or ModifyTaskResponse message, the LI core device, at an eighth step 1115, sends an activate or modify warrant response message to the LEA Warrant Issuing Authority, e.g. to the LEA device 140, indicating either a success or failure of setting up the Warrant and by extension activating or modifying the POI in the NED.
Besides intercepting a payload of data for the LI core device, the NED may be configured to perform a method 1200 as illustrated in Figure 12. Method 1200 includes receiving from a LI core device comprising a first communication device (e.g., LI ADMF) at a first step 1210, an indication of one or more of hashing algorithms, encryption algorithms, nonces for each X interface and a value based on the hash of the target identifier. Optionally, the NED may also instead calculate the value based on the hash of the target identifier using the hashing algorithm and the nonce associated with target identifier. This may result in a more secure exchange since the NED may already have the target identifier and the hashing algorithm preloaded (for e.g.: in a case where the preloaded target identifier was received by the NED from the LI core device before a connection breakdown) and avoid the value based on the hash of the target identifier from having to be sent.
In a second step 1220, the NED obtains encryption and hashing algorithms associated with X interfaces. In some embodiments, the algorithms may be obtained from internal memory, LI core device comprising the first communication device, and/or a different external device.
In a third step 1230, the NED retrieves intercepted target identifiers, from LI data (IRI or CC). Note in the current state of the art, LI data is formatted to be transmitted on an X2 or X3 interface is known as xIRI or xCC, respectively. IRI and CC are reformatted by the MDF function before being transmitted on HI2 and HI3 interface, respectively, to LEMF. Encryption and hashing algorithms may be obtained by the NED from internal memory, the LI core device or and external device. Further, method 1200 includes applying the hashing algorithm, XlHashingAlgorithm, using the nonce, Nonce_Xl, as the hashing key, to the intercepted target identifiers to obtain intercepted target identifiers hashed values, at a fourth step 1240. Then, if one of the intercepted target identifier hashed values matches the hashed_target_Xl received from the LI core device, the NED proceeds to a fifth step 1250. The NED, in fifth step 1250 uses the hashed target identifiers associated with X2 and X3, hashed_target_X2 and hashed_target_X2 to encrypt, with the respective encryption algorithms, X2EncryptionAlgorithm and X3EncryptionAlgorithm, all sensitive data associated with the gathered xIRI and xCC data of the intercepted target identifier. The hashed_target_X2 and hashed_target_X3 calculated by applying a corresponding hashing algorithm associated with the X interfaces to the target identifier using the nonce associated with the X3 interface, nonce_X2, and the nonce associated with the X3 interface, nonce_X3, as hashing key, respectively. The xIRI and xCC data is then transmitted to the LI core device comprising the second communication device, more specifically the MDF, at a sixth step 1260. In the embodiment illustrated in figure 12, the xIRI and xCC data is sent using the X2 or X3 PDUs. The X2 or X3 PDUs have a field Encryption Level to indicate to the MDF if the Conditional Attribute Field and Payload are encrypted. This field may be, for example, a value of 0, 1, or 2 where 0 indicates no encryption is used, 1 indicates that the payload is encrypted and 2 indicates that both the payload and conditional attributes are encrypted. The NED 110 may use an X2 or an X3 interface to deliver the encrypted xIRI or xCC to the MDF.
Figure 13 is a flowchart illustrating matching the target identifier of LI data to the hash of the target identifier of the relevant target and payload encryption in an NED 110 according to an embodiment. Initially, NED awaits events, that is, LI data (IRI and/or CC) interception and in a first step, intercepts a payload of data for the LI core device. At second step 1320, NED 110 retrieves intercepted target identifiers from the LI data. Then, at a third step 1330, NED applies the hashing algorithm(s) stored with corresponding nonces to the intercepted target identifiers to obtain intercepted target identifier hashed values. In the current embodiment, the hashing algorithm XlHashingAlgorithm, using Nonce_Xl as the hashing key, is applied to the intercepted target identifiers to obtain the intercepted target identifier hashed values. Each of the intercepted target identifiers hashed values is compared with each hashed target identifier, hashed_target_Xl in the current embodiment, previously received by the NED (at the same time with a hashing algorithm indication and a nonce) at fourth step 1340. In a fifth step 1350, if there is a match of one of the intercepted target identifier hashed values with a respective hashed_target_Xl (i.e., YES branch of 1350), then the hashed target identities for the other X interfaces are determined in sixth step 1360. In some embodiments, the method comprises receiving from the LI core device, an indication of the hashing algorithm and a hash value obtained by applying the hashing algorithm to the target identifier using the nonce and intercepting a payload of data for the LI core device. The method further comprises retrieving intercepted target identifiers, ITIs, from the intercepted payload of data, applying the hashing algorithm using the hash value to the ITIs to obtain intercepted target identifier hashed values and if one of the obtained intercepted target identifier hashed values matches the hash value, transmitting the intercepted payload of data to the LI core device. Otherwise in the "NO" branch of 1350, the method returns to step 1310 and the NED waits for new payload of data to be intercepted. The sixth step 1360 is done by hashing the target id using the hashing algorithms associated with the X interfaces, X2HashingAlgorithms and X3HashingAlgorithms, together with the nonces as algorithm keys, the nonces associated with the X interfaces, Nonce_X2 and Nonce_X3. The target identifier may be the intercepted target identification or maybe derived preemptively from the hashed_target_Xl, using XlHashingAlgorithm and Nonce_Xl. This results in the hashed target identifiers hashed_target_X2 and hashed_target_X3 which are used as the keys to encrypt the LI data in a seventh step 1370. The encryption of step 1370 uses the encryption algorithms X2EncryptionAlgorithm and X3EncryptionAlgorithm, received from the LI core device in steps of method 600, to encrypt all the sensitive data in the LI data. Sensitive data in the LI data may be the payload and conditional attribute fields of X2/X3 PDUs as defined in ETSI standard 103 221-2 vl.6.1 or payload and conditional attribute fields of X2/X3 PDUs defined by a similar, later, or complimentary standard. The encrypted data is then formatted, in an eighth step 1380, into xIRI data and xCC data. If LI data is IRI, then it is formatted as xIRI when transmitted via the X2 interface. If LI data is CC, then it is formatted as xCC and transmitted on an X3 interface. LI data is sent to the LI core device comprising the second communication device 125 (for e.g.: MDF) in PDUs via the X2 and/or X3 interface in a ninth step 1390 and the NED then proceeds to await a new event with new LI data. In some embodiments, the hashed_target_X2 and the hashed_target_X3 will be used as cryptographic keys to encrypt all the sensitive data in xIRI and xCC, so that the sensitive information on xIRI and xCC is encrypted and no sensitive data are sent in plaintext in xIRI and xCC.
In some embodiments of the method performed by the NED, obtaining a hash value comprises retrieving from the obtained encrypted LI data, a task identifier associated with an X interface, XID from the internal storage medium of the LI core device or the NED and retrieving at least one hash value associated with the XID. In an example, the at least one hash value may be one or more of: the hash value of the target identifier associated to the X2 interface, hashed_target_X2 and the hash value of the target identifier associated to the X3 interface, hashed_target_X3. Both the hashed_target_X2 and the hashed_target_X3 are retrieved by searching for the XID in a database or the internal storage medium of the LI core device or the NED.
Transmission of the PDUs with encrypted payloads over the X2 or X3 interface may occur over a single connection between the NED and the LI core device or also occur across multiple other nodes in the communication system such as microservices, other network element devices, network servers and similar. Microservices may be, in the current terminology, processes that communicate over a network or communication system to fulfill a goal using technology-agnostic protocols such as HTTP. Transmission between the NED and the LI core device comprising the first and/or the second communication devices over the network occurs in the current embodiment using the Transport Layer Security, TLS, protocol or the IPsec protocol to secure communications between the NED, other nodes, and the LI Core. TLS and the IPsec protocol serves to encrypt and otherwise secure communications between nodes but not inside the nodes themselves. In the current state of the art, the payload of PDUs being transmitted across nodes in the communication system using TLS, is visible to the nodes that the PDUs are passing through. The encrypted payload in the current embodiment renders the payload unreadable to the nodes the PDU is passing through as it is transmitted to the LI core device comprising the second communication device.
In some embodiments, the LI core device comprising the first communication device and the second communication device, the NED or other network administration function may inform network element devices in the communication system 100 or a network to cease using the Transport Layer Protocol or the IPsec protocol for one, some, or all messages communicated over an X interface. The messages may comprise payloads for LI data such as for example, payloads sent over an X interface such as X2 or X3. In some embodiments, the NED would be operative to inform other network element devices in the communication system 100 to cease using the TLS protocol for messages communicated over the X interface. This would enable the reduction of computational resources of the network nodes and microservices that would otherwise have to implement the TLS protocol for xIRI and xCC messages while maintaining the security of the messages.
In some embodiments, the LI core device may also send information indicating to the NED to not encrypt a payload message. This may be a result of computational limitations of the LI core device.
Once the LI data is sent by the NED, the NED proceeds to, in tenth step 1395, to delete the hashed target ids, hashed_target_X2 and hashed_target_X3, along with the encrypted payloads related to the LI data from its associated storage medium. This prevents this information from later being obtained and the encryption broken if the NED is compromised.
Figure 14 is a flowchart illustrating matching the target identifier of LI data to the hash of the target identifier of the relevant target and payload decryption in the LI core device 120 comprising the second communication device 125 according to an embodiment. Initially, the LI core device waits for data sent to the LI core device over the X2 or X3 interface. The LI core device then receives, in a first step 1410, encrypted LI data with XID in plaintext over the X2 and/or X3 interfaces originating from the NED. Upon receiving the encrypted LI data, the LI core device retrieves using the received XID, the hashed_target_X2 and hashed_target_X3 at a second step 1420. Once found, the hashed target identities for the X2 and X3 interfaces are used, in a third step 1430 to as the key for the decryption algorithm, X2EncryptionAlgorithm and X3EncryptionAlgorithm, to retrieve the encrypted data in the encrypted fields of the PDUs being sent over the X2 and X3 interfaces, the PDUs comprising the xIRI and/or xCC data. The LI core device will then, in a fourth step 1440, format the decrypted LI data from the xIRI and xCC data to IRI and CC data for transmission on HI2 and HI3 interfaces respectively. The LI core device then uses, in a fifth step 1450, an HI2 or HI3 interface to deliver IRI and CC data, derived from the xIRI and xCC data, in plaintext to the LEMF. In certain embodiments of the invention, at the fifth step 1450, if the LI core device receives, in step 1410, a message over an X interface that cannot be decrypted, in step 1430, using the associated hashed target identifier, the LI core device alerts a law enforcement agency or another network element device. This alert would inform of a potential fault in the LI core or NED or inform of either the LI core or NED being compromised. The alert may be in the form of a message, a shutdown of the LI core device, or some other transmission of information. In some embodiments, the functions of the LI core device comprising the first communication device and the second communication device may be handled by the LI MDF and LI ADMF, respectively. After the LI data is sent to the LEMF, the LI core device will delete, in a sixth step 1460, the data belonging to the decrypted LI data from its associated storage medium but keep the hashed target identifiers for when the NED detects the target and receives new LI data and begins method 800 and 1000 again.
In some embodiments, the method of the LI core device comprises determining an indication of a mutual hashing algorithm to be used by the LI core device and by the NED. The method comprises calculating a hash value corresponding to the target identifier, by applying the mutual hashing algorithm to the target identifier using the nonce. The method further comprises storing the hash value and an information indicative of the mutual hashing algorithm and transmitting, to the NED, the hash value and the information indicative of the mutual hashing algorithm. A similar method of determining a mutual encryption algorithm to be used by the LI core device and by the NED is also possible.
In some embodiments, the method of the LI core comprises receiving from the NED, an indication of the mutual hashing algorithm. The indication of the mutual hashing algorithm obtained by comparing the first list of hashing algorithms to the second list of hashing algorithms and selecting, based on the comparison, a hashing algorithm which is common to the first list and second list of hashing algorithms. A similar method of receiving from the NED, an indication of a mutual encryption algorithm is also possible.
In some embodiments, the method comprises sending one or more of a first list of encryption algorithms associated to an XI interface, a second list of encryption algorithms associated to an X2 interface and a third list of encryption algorithms associated to an X3 interface.
In some embodiments, sending the nonce associated with a target identifier comprises one or more of sending: a first nonce associated to an XI interface, a second nonce associated to an X2 interface and sending a third nonce associated to an X3 interface. In some embodiments, obtaining an encrypted payload of LI data related comprises one or more of receiving the encrypted payload using the second nonce and an encryption algorithm from the second list of encryption algorithms associated to the X2 interface, and receiving the encrypted payload using the third nonce and an encryption algorithm from the third list of encryption algorithms associated to the X3 interface. In some embodiments, the second nonce and the third nonce may be the same if the third nonce is not specified. In some embodiments, the second list and the third list of encryption algorithms may be the same if the third list is not specified.
In some embodiments of the method performed by the LI core device, obtaining a hash value comprises reading a task identifier associated with an X interface, XID from the internal storage medium of the LI core device and retrieving the hash value corresponding to the XID.
In some embodiments, the LI core device will store, together with plaintext target, a task identifier, XID, the three nonces (hashed_target_Xl, hashed_target_X2, hashed_target_X3) and the three hashed target identifiers (Nonce_Xl, Nonce_X2, Nonce_X3). In some embodiments, it may be possible to search the LI core device's internal storage or a database for a corresponding pair of hashed_target_Xl and XID. In some embodiments, in the LI core device 120, if the second communication device 125 (for e.g.: LI-MDF) cannot directly access the first communication device's 122 (for e.g.: LI ADMF) database or internal storage, the first communication device 125 for each target will send to the second communication device: the XID, the hashed_target_X2 and the hashed_target_X3. In some embodiments, the first communication device 122 provides to both the NED 110 and the second communication device 125, an indication of the encryption algorithm to be used on X2 and X3 interfaces.
The time required for the matching and decryption depends by the number of hashing algorithms/decryption keys used, so this number should preferably be small. For example, one set of algorithm/key pairs may be used, and a different set may be introduced only periodically or when a threat or security violation incident occurs. The update of the hashing and encryption algorithms and nonces occurs gradually, target by target as further explained, so no LI monitoring gaps occur.
In some embodiments, once a task ends, the task-related information is deleted. A similar procedure may also be performed whereby the hashing algorithms, nonces and stored target identifiers aren't updated but the encryption algorithms are updated whereby the encryption algorithms are updated. Hashing algorithms, nonces, and stored target identifiers associated with a single or multiple X interfaces may also be updated per interface individually or as a group.
In another embodiment of the invention, the LI core device may determine that encryption is not necessary for one or more of the LI data associated with an X interface. This may be the result of a lacking capability of the NED or that the LI network is designed in such a way that the NED has direct and secure transmission of data to the LI core device with no nodes in between. This may also be the result of a large amount of CC data being anticipated and that the encryption overhead may risk bottlenecks in the NED and result in CC data not being successfully received by the LEMF.
In some embodiments, the LI system may determine that TLS encryption may be downgraded or eliminated altogether if the invention is enabled. Thereby, allowing for faster transmission and less computation at nodes in the network.
Figure 15 is a block diagram of the NED 110 according to some embodiments. As shown in Figure 15, the NED 110 may comprise: processing circuitry 1510 which may include one or more processors (e.g., a general purpose microprocessor and/or one or more processors, such as an application specific integrated circuit (ASIC), field-programmable gate arrays (FPGAs) and the like); interface circuitry 1520 for communicating with other nodes connected to a network 100; and a storage medium 1530 which may include one or more non-volatile storage devices and/or one or more volatile storage devices (e.g., random access memory (RAM)). In embodiments where the smart proxy includes a programmable processor 1510, a computer program product may be provided. A computer program product includes a computer readable medium 1520 such as, but not limited to, the storage medium 1530, magnetic media (e.g., a hard disk), optical media, memory devices, and the like. The storage medium may contain a computer program 1730a containing computer readable instructions 1740a that when executed by the processor circuit 1510 causes the processor circuit to perform operations according to embodiments disclosed herein. According to other embodiments, processor circuitry 1510 may be defined to include a storage medium so a separate storage medium is not required.
Figure 16 is a block diagram of the LI core device 120 according to some embodiments. As shown in Figure 16, the LI core device 120 may comprise: processing circuitry 1610 which may include one or more processors (e.g., a general purpose microprocessor and/or one or more processors, such as an application specific integrated circuit (ASIC), field-programmable gate arrays (FPGAs) and the like); interface circuitry 1620 for communicating with other nodes connected to a communication system 100; and a storage medium 1630 which may include one or more non-volatile storage devices and/or one or more volatile storage devices(e.g., random access memory (RAM)). In embodiments where the smart proxy includes a programmable processor 1610, a computer program product may be provided. A computer program product includes a computer readable medium 1620 such as, but not limited to, the storage medium 1630, magnetic media (e.g., a hard disk), optical media, memory devices, and the like. The storage medium may contain a computer program 1730b containing computer readable instructions 1740b that when executed by the processor circuit 1610 causes the processor circuit to perform operations according to embodiments disclosed herein. According to other embodiments, processor circuitry 1610 may be defined to include a storage medium so a separate storage medium is not required. Figure 17 is a diagram showing an embodiment of the invention. As shown in Figure 17, the computer program product 1710 comprises a computer readable medium 1720 storing a computer program 1730a and 1730b comprising computer readable instructions 1740a and 1740b. The computer readable medium may be but is not limited to, a storage medium 1530 and 1630, magnetic media (e.g., a hard disk), optical media, memory devices (e.g., random access memory, flash memory) and the like.
A method performed by a NED 110 in a communication system 100 is provided. The NED comprises a LI POI. The method comprises receiving a nonce associated with a target identifier. The method comprises obtaining an indication of an encryption algorithm. The method comprises encrypting a payload of LI data. The payload of LI data is related to the target identifier. The payload is encrypted using the nonce. The payload is encrypted using the encryption algorithm. In some embodiments, the method comprises obtaining an indication of a hashing algorithm. In some embodiments, the method comprises calculating a hash value obtained by applying the hashing algorithm to the nonce. In some embodiments, encrypting a payload of LI data comprises using the hash value as a cryptographic key for the encryption algorithm.
In some embodiments, the NED receives on an XI interface, a hash value associated to the XI interface and corresponding to the target identifier. The method comprises receiving from the LI core device, three different nonces. The three different nonces being a first nonce associated with the XI interface, a second nonce associated with an X2 interface and a third nonce associated with an X3 interface. The first nonce is used as a hash key for the target identifier received on the XI interface. The second nonce and the third nonce are used as a hash key for the target identifier to generate a second hash value and a third hash value, respectively. The second hash value and the third hash value are used as an encryption key to encrypt the payload of LI data on the X2 interface and the X3 interface, respectively.
Traffic on the X2 interface and the X3 interface contains private and/or sensitive data of individuals which may be used to infer the identity of the individuals. The private and/or sensitive data of individuals are communicated in clear text or plain text in the xIRI and the xCC. Thus, the private data could be stolen by an attacker and/or a malicious device. An advantage of the various embodiments presented herein is providing better confidentiality and protection to the data of the individuals. Another advantage of embodiments presented herein is providing better security and isolation to data of the individuals, especially private and/or sensitive data. In some embodiments, an attacker or a malicious device trying to retrieve or obtain the data of individuals may not be able to capture or try to derive the nonce when in transit via an X interface.
Also, while various embodiments of the present disclosure are described herein, it should be understood that they have been presented by way of example only, and not limitation. Thus, the breadth and scope of the present disclosure should not be limited by any of the above-described exemplary embodiments. Moreover, any combination of the above-described elements in all possible variations thereof is encompassed by the disclosure unless otherwise indicated herein or otherwise contradicted by context. Additionally, while the processes described above and illustrated in the drawings are shown as a sequence of steps, this was done solely for the sake of illustration. Accordingly, it is contemplated that some steps may be added, some steps may be omitted, the order of the steps may be re-arranged, and some steps may be performed in parallel.

Claims

1. A method performed by a network element device, NED, (110) in a communication system (100), the NED (110) comprising a lawful interception, LI, point of interception, POI, (111), the method comprising: receiving (310, 810, 1210) a nonce associated with a target identifier; obtaining (320, 820, 1220) an indication of an encryption algorithm; and encrypting (330, 1250, 1370) a payload of LI data related to the target identifier, using the nonce and the encryption algorithm.
2. The method according to claim 1, comprising: obtaining (820) an indication of a hashing algorithm.
3. The method according to claim 2, comprising: calculating (830) a hash value obtained by applying the hashing algorithm to the target identifier using the nonce.
4. The method according to claim 3, wherein encrypting a payload of LI data comprises: using the hash value as a cryptographic key for the encryption algorithm.
5. The method according to one or more of the preceding claims, comprising: sending (340, 1260) the encrypted payload over an X interface.
6. The method according to one or more of the preceding claims, wherein receiving (310, 1210) a nonce associated with a target identifier comprises: receiving (310) a nonce associated with the target identifier and an X interface.
7. The method according to one or more of the preceding claims, comprising: obtaining (320, 1220) an indication of a further encryption algorithm; receiving (310, 1210) a further nonce associated with the target identifier; encrypting (330, 1250,1370) a further payload, using the further encryption algorithm and the further nonce; and sending the encrypted further payload over a different X interface.
8. The method according to one or more of the preceding claims, wherein the communication system comprises an LI core device (120) and the method comprises: sending to the LI core device, information indicative of one or more of: the encrypted payload; the hashing algorithm; the encryption algorithm.
9. The method according to claim 8 when dependent on claim 3, comprising: sending to the LI core device, information indicative of: the calculated hash value.
10. The method according to one or more of the preceding claims, comprising: informing other network element devices in the communication system to cease using the T ransport Layer Security Protocol for messages communicated over an X interface.
11. The method according to one or more of the proceedings claims, wherein the communication system comprises a LI core device and wherein obtaining an indication of an encryption algorithm comprises: receiving (1020b) a first list of encryption algorithms that are available for use by the LI core device.
12. The method according to one or more of the preceding claims, wherein the communication system comprises a LI core device and the method comprises: transmitting (1020a) to the LI core device a second list of encryption algorithms that are available for use by the NED.
13. The method according to claims 11 and 12, wherein obtaining the indication of the encryption algorithm comprises: comparing (1030b) the first list of encryption algorithms to the second list of encryption algorithms; and selecting (1040b), based on the comparison, a mutual encryption algorithm, wherein the mutual encryption algorithm is common to the first list and second list of encryption algorithms.
14. The method according to claim 13, comprising: transmitting (1050b) an indication of the mutual encryption algorithm to the LI core device.
15. The method according to one or more of the preceding claims, wherein obtaining an encryption algorithm comprises: receiving (1210), from an LI core device, information indicative of the encryption algorithm.
16. The method according to one or more of claims 2 to 15, comprising: receiving from the LI core device, an indication of the hashing algorithm and a hash value obtained by applying the hashing algorithm to the target identifier using the nonce; intercepting a payload of data for the LI core device; retrieving intercepted target identifiers, ITIs, from the intercepted payload of data; applying the hashing algorithm using the hash value to the ITIs to obtain intercepted target identifier hashed values; and if one of the obtained intercepted target identifier hashed values matches the hash value, transmitting the intercepted payload of data to the LI core device.
17. The method according to one or more of the proceedings claims when dependent on claim 2, wherein the communication system comprises a LI core device and wherein obtaining the indication of the hashing algorithm comprises: receiving a first list of hashing algorithms that are available for use by the LI core device.
18. The method according to claim 17, wherein the communication system comprises a LI core device and the method comprising: transmitting to the LI core device, a second list of hashing algorithms that are available for use by the NED.
19. The method according to claims 17 and 18, wherein obtaining the indication of the hashing algorithm comprises: comparing the first list of hashing algorithms to the second list of hashing algorithms; and selecting, based on the comparison, a mutual hashing algorithm, wherein the mutual hashing algorithm is common to the first list and second list of hashing algorithms.
20. The method according to claim 19, comprising: transmitting an indication of the mutual hashing algorithm to the LI core device.
21. The method according to one or more of the preceding claims, wherein receiving (310, 1210) a nonce associated with a target identifier comprises one or more of: receiving a first nonce associated to an XI interface; receiving a second nonce associated to an X2 interface; and receiving a third nonce associated to an X3 interface; and wherein obtaining (320, 1220) an indication of an encryption algorithm comprises one or more of: obtaining an indication of a first encryption algorithm associated to the XI interface; obtaining an indication of a second encryption algorithm associated to the X2 interface; and obtaining an indication of a third encryption algorithm associated to the X3 interface.
22. The method according to claim 21, wherein encrypting (330, 1250, 1370) a payload of LI data related to the target identifier comprises one or more of: encrypting the payload of LI data, to be sent through the X2 interface, using the second nonce and the second encryption algorithm; and encrypting the payload of LI data, to be sent through the X3 interface, using the third nonce and the third encryption algorithm.
23. The method according to claims 21 or 22, comprising: receiving (1111), through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: an indication of a first hashing algorithm associated to the XI interface; an indication of a second hashing algorithm associated to the X2 interface; an indication of a third hashing algorithm associated to the X3 interface; a hash value associated to the XI interface; the first nonce; the second nonce; the third nonce; the first encryption algorithm; the second encryption algorithm; and the third encryption algorithm.
24. A network element device, NED, (110) in a communications system (100), the NED comprising a lawful interception, LI, point of interception (111), POI, and the NED adapted to: receive (310, 1210) a nonce associated with a target identifier; obtain (320, 1220) an indication of an encryption algorithm; and encrypt (330, 1250, 1370) a payload of LI data related to the target identifier, using the nonce and the encryption algorithm.
25. The NED according to claim 24, adapted to perform operations according to one or more of the claims 2-23.
26. A network element device, NED, (110) in a communications system (100), the NED comprising a lawful interception, LI, point of interception (111), POI, the NED comprising an interface circuitry (1520), a processing circuitry (1510) and storage medium (1530) containing instructions that when executed by the processing circuitry make the NED operative to: receive (310, 1210) a nonce associated with a target identifier; obtain (320, 1220) an indication of an encryption algorithm; and encrypt (330, 1250, 1370) a payload of LI data related to the target identifier, using the nonce and the encryption algorithm.
27. The NED according to claim 26, adapted to perform operations according to one or more of the claims 2-23.
28. A computer program (1730a), the computer program comprising computer readable instructions (1740a) to be executed by processing circuitry (1510) of a network element device, NED, (110) comprising a lawful interception, LI, point of interception, POI, (111) whereby execution of the computer readable instructions causes the NED to perform operations according to any of claims 1-23.
29. A computer program product (1710) which comprises a computer readable storage medium (1720) on which a computer program (1730a) according to claim 28 is stored.
30. A method performed by a lawful interception, LI, core device (120) in a communication system (100) comprising a network element device, NED, the method comprising: sending to the NED, an indication of an encryption algorithm; obtaining an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
31. The method according to claim 30, wherein obtaining an encrypted payload of LI data related to a target identifier comprises: receiving from the NED, the encrypted payload over an X interface.
32. The method according to claims 30 or 31, comprising: sending to the NED, a first list of hashing algorithms that are available for use by the LI core device.
33. The method according to claims one or more of claims 30 to 32, wherein sending to the NED, an indication of an encryption algorithm comprises: sending to the NED, a first list of encryption algorithms that are available for use by the LI core device.
34. The method according to one or more of claims 30-33, comprising: sending to the NED, the nonce associated with the target identifier.
35. The method according to one or more of claims 30-34, comprising: sending to the NED, a further list of encryption algorithms that are available for use by the LI core device; sending to the NED, a further nonce associated with the target identifier; and receiving a further encrypted payload of LI data related to the target identifier, the further encrypted payload being encrypted using the further nonce and an encryption algorithm from the further list of encryption algorithms.
36. The method according to claim 35, comprising: receiving from the NED, the encrypted further payload over a different X interface.
37. The method according to one or more of claims 30-36, comprising: determining a mutual hashing algorithm to be used by the LI core device and by the NED; calculating a hash value corresponding to the target identifier, by applying the mutual hashing algorithm to the target identifier using the nonce; storing the hash value and an information indicative of the mutual hashing algorithm; and transmitting, to the NED, the hash value and the information indicative of the mutual hashing algorithm.
38. The method according to one or more of claim 37, wherein determining a mutual hashing algorithm to be used by the LI core device and by the NED comprises: receiving from the NED, an indication of the mutual hashing algorithm, the mutual hashing algorithm obtained by: comparing the first list of hashing algorithms to the second list of hashing algorithms; and selecting, based on the comparison, a hashing algorithm which is common to the first list and second list of hashing algorithms.
39. The method according to one or more of claims 30-38, comprising: receiving from the NED, information indicative of one or more of: an indication of a hashing algorithm that is available for use by the NED; and an indication of an encryption algorithm that is available for use by the NED.
40. The method according to claim 39, comprising: receiving from the NED, information indicative of: a calculated hash value obtained by applying the hashing algorithm that is available to the NED, to the target identifier using the nonce.
41. The method according to one or more of claims 30-40, comprising: receiving from the NED, a second list of encryption algorithms that are available for use by the NED.
42. The method according to one or more of claims 30-41, wherein receiving information indicative of an encryption algorithm comprises: receiving from the NED, an indication of a mutual encryption algorithm, the mutual encryption algorithm obtained by: comparing the first list of encryption algorithms to the second list of encryption algorithms; and selecting, based on the comparison, an encryption algorithm which is common to the first list and second list of encryption algorithms.
43. The method according to one or more of claims 30-42, wherein sending an indication of an encryption algorithm comprises one or more of: sending a first list of encryption algorithms associated to an XI interface; sending a second list of encryption algorithms associated to an X2 interface; and sending a third list of encryption algorithms associated to an X3 interface.
44. The method according to one or more of claims 30-43, wherein sending the nonce associated with a target identifier comprises one or more of: sending a first nonce associated to an XI interface; sending a second nonce associated to an X2 interface; and sending a third nonce associated to an X3 interface.
45. The method according to claim 44, wherein obtaining an encrypted payload of LI data related comprises one or more of: receiving the encrypted payload using the second nonce and an encryption algorithm from the second list of encryption algorithms associated to the X2 interface; and receiving the encrypted payload using the third nonce and an encryption algorithm from the third list of encryption algorithms associated to the X3 interface.
46. The method according to claims 45, comprising: sending, through an ActivateTaskRequest message or a ModifyTaskRequest message, information indicative of: a first list of hashing algorithms associated to the XI interface; a second list of hashing algorithms associated to the X2 interface; a third list of hashing algorithms associated to the X3 interface; the first nonce; the second nonce; the third nonce; a hash value associated to the XI interface; the first list of encryption algorithms associated to the XI interface; the second list of encryption algorithms associated to the X2 interface; and the third list of encryption algorithms associated to the X3 interface.
47. The method according to one or more of claims 32-46, comprising: obtaining a hash value; using the obtained hash value as a cryptographic key for a decryption algorithm which performs an operation equivalent to an inverse of the mutual encryption algorithm; and decrypting the obtained encrypted payload using the decryption algorithm.
48. The method according to claim 47, wherein obtaining a hash value comprises: retrieving from the obtained encrypted LI data, a task identifier associated with an X interface, XID; and retrieving at least one hash value associated with the XID.
49. The method according to claim 47, wherein obtaining a hash value comprises: calculating the hash value by applying a hashing algorithm from the list of hashing algorithms to the target identifier using the nonce.
50. A lawful interception, LI, core device (120) in a communications system (100), the LI core device adapted to: send to the NED, an indication of an encryption algorithm; obtain an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
51. The LI core device according to claim 50, adapted to perform operations according to one or more of the claims 31-49.
52. A lawful interception, LI, core device (120) in a communications system (100), the LI core device comprising an interface circuitry (1620), a processing circuitry (1610) and storage medium (1630) containing instructions that when executed by the processing circuitry make the NED operative to: send to the NED, an indication of an encryption algorithm; obtain an encrypted payload of LI data related to a target identifier, the encrypted payload being encrypted using a nonce associated with the target identifier and the encryption algorithm.
53. The LI core device according to claim 52, adapted to perform operations according to one or more of the claims 31-49.
54. A computer program (1730b), the computer program comprising computer readable instructions (1740b) to be executed by processing circuitry (1610) of a lawful interception, LI, core device (120) in a communications system (100), whereby execution of the computer readable instructions causes the LI core device to perform operations according to any of claims 30-49.
55. A computer program product (1710) which comprises a computer readable storage medium (1720) on which a computer program (1730b) according to claim 54 is stored.
EP23700177.1A 2023-01-09 2023-01-09 Encrypting and decrypting payload for lawful interception Pending EP4649634A1 (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/EP2023/050344 WO2024149444A1 (en) 2023-01-09 2023-01-09 Encrypting and decrypting payload for lawful interception

Publications (1)

Publication Number Publication Date
EP4649634A1 true EP4649634A1 (en) 2025-11-19

Family

ID=84981306

Family Applications (1)

Application Number Title Priority Date Filing Date
EP23700177.1A Pending EP4649634A1 (en) 2023-01-09 2023-01-09 Encrypting and decrypting payload for lawful interception

Country Status (2)

Country Link
EP (1) EP4649634A1 (en)
WO (1) WO2024149444A1 (en)

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2566126A1 (en) * 2011-09-02 2013-03-06 Koninklijke KPN N.V. Secure storage of provisioning data on network for control of lawful intercept
US12244651B2 (en) 2017-11-07 2025-03-04 Telefonaktiebolaget Lm Ericsson (Publ) Lawful interception security
WO2021254630A1 (en) * 2020-06-18 2021-12-23 Telefonaktiebolaget Lm Ericsson (Publ) Methods and device for managing lawful interception
US11711402B2 (en) * 2021-05-22 2023-07-25 Charter Communications Operating, Llc Methods and apparatus for lawful interception of communications
WO2023287328A1 (en) * 2021-07-12 2023-01-19 Telefonaktiebolaget Lm Ericsson (Publ) Hash function and lawful interception

Also Published As

Publication number Publication date
WO2024149444A1 (en) 2024-07-18

Similar Documents

Publication Publication Date Title
US12015721B1 (en) System and method for dynamic retrieval of certificates with remote lifecycle management
EP2663109B1 (en) Method and nodes for providing secure access to cloud computing for mobile users
US9124563B2 (en) Method for asynchronously provisioning keys from one secure device to another
US11323488B2 (en) Enhanced lawful interception
KR20190102068A (en) Security implementation methods, devices, and systems
Khan et al. Defeating the downgrade attack on identity privacy in 5G
US11838409B2 (en) Method and apparatus for transferring data in a publish-subscribe system
KR102413497B1 (en) Systems and methods for secure electronic data transmission
CN115766002B (en) Method for implementing Ethernet data encryption and decryption using quantum key distribution and software definition
CN116569516A (en) Method for Preventing Authentication Serial Number Leakage of Mobile Terminal
WO2019093932A1 (en) Lawful interception security
CN115699672A (en) Method for preventing encrypted user identity from replay attack
CN115549900A (en) Quantum safety data transmitting and receiving method and communication system
US20230388353A1 (en) Methods and apparatus for lawful interception of communications
US7333612B2 (en) Methods and apparatus for confidentiality protection for Fibre Channel Common Transport
CN104618211A (en) Tunnel based message processing method and headquarters gateway device
EP4649634A1 (en) Encrypting and decrypting payload for lawful interception
CN116235462A (en) Method for protecting encrypted user identities from replay attacks
CN105432055B (en) Method for protecting telecommunication communication data
US12563401B2 (en) Hash function and lawful interception
EP3806517B1 (en) Loading security information with restricted access
CN112468453A (en) Access method, system, electronic device and storage medium of multi-protocol device
AU2022235328B2 (en) Secure key management device, authentication system, wide area network and method for generating session keys
CN121193495A (en) Communication Method and System Based on Network Slicing Quantum Encryption System
CN121193505A (en) A quantum-safe encryption device component for a novel power communication architecture

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20250801

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)