WO2012119464A1 - 合法监听的方法和系统 - Google Patents

合法监听的方法和系统 Download PDF

Info

Publication number
WO2012119464A1
WO2012119464A1 PCT/CN2011/082862 CN2011082862W WO2012119464A1 WO 2012119464 A1 WO2012119464 A1 WO 2012119464A1 CN 2011082862 W CN2011082862 W CN 2011082862W WO 2012119464 A1 WO2012119464 A1 WO 2012119464A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
ilr
monitored terminal
monitoring
terminal
Prior art date
Application number
PCT/CN2011/082862
Other languages
English (en)
French (fr)
Inventor
颜正清
张世伟
符涛
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2012119464A1 publication Critical patent/WO2012119464A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/30Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
    • H04L63/306Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information intercepting packet switched data communications, e.g. Web, Internet or IMS communications

Definitions

  • the invention relates to the field of mobile communication and the field of the Internet, and relates to a method for implementing lawful interception in a whole network in an identity identification and location separation network.
  • the typical problem is the dual attribute of the IP address, that is, the IP address represents both the user identity and the network topology of the user. , that is, the dual attribute of the IP address.
  • IP addresses The inherent contradiction of the dual attributes of IP addresses will lead to a series of problems such as routing scalability issues, mobility issues, multiple home issues, and security and location privacy issues.
  • ZTE proposed the identity and location separation network architecture shown in Figure 1.
  • the identity and location separation system SILSN is accessed by the access server (Access).
  • the Service Router (ASR) is composed of a User Equipment (UE), an Identity and Location Register (ILR), and an Authentication Center (AC).
  • the access servers ASR1 and ASR2 are used to access the user terminal devices UE1 and UE2, and are responsible for implementing access for the user terminal, and performing functions such as charging and switching.
  • the ILR assumes the user's location registration and identity recognition functions, and the AC assumes user access.
  • UE1 and UE2 respectively have unique Access Identification AID1 and AID2.
  • the network shown in Figure 1 has the following characteristics: Each user in the network can only access after strict authentication. When sending each data packet, the user carries its own real user access identifier AID. This symbol is only assigned to The user uses and is unique to the entire network. The data packets sent by users in various services always carry this identifier. Each data packet sent by the user must be authenticated by the access server ASR to ensure that the data packets sent by the user are carried. Is your own access identity, will not impersonate other uses The AID accesses the network, and this identifier will remain unchanged throughout the network, and will not change when the user moves or switches.
  • the user identity and location separation network is simply referred to as Subscriber Identifier & Locator Separation Network (SILSN).
  • SILSN Subscriber Identifier & Locator Separation Network
  • Lawful Interception refers to a kind of secret investigation measure that uses telecommunications technology to detect and record the electronic communication of the intercepted object in order to collect evidence and find out the facts of the crime. Lawful interception can be implemented directly by the investigating agency or by the assistance of a telecommunications service provider. This implementation process is a secret investigation process for the monitored object, so a certain confidentiality requirement should be met for the telecommunication service provider.
  • Figure 2 shows the model of lawful interception of IP data services. Its components include: LEA (Legal Enforcement Agency), LI Administration Function, LI MD (Meditation Device), and monitoring related information. Intercept Related Information Intercept Access Point and Content of Communication Intercept Access Point.
  • LEA Legal Enforcement Agency
  • LI Administration Function LI Administration Function
  • LI MD Meditation Device
  • monitoring related information Intercept Related Information Intercept Access Point and Content of Communication Intercept Access Point.
  • a “listening content listening access point” is a device node in a carrier's network, typically a router or switch with a legitimate listening function.
  • the “listening related information monitoring access point” generally refers to the network authentication and management devices, such as the AAA server (AAA, Authentication, Authorization, Accounting) and the DHCP server. It provides the address and time information for the listener.
  • AAA server AAA, Authentication, Authorization, Accounting
  • DHCP server DHCP server
  • the "management module” and “arbitration equipment” are collectively referred to as the arbitration system.
  • the arbitration system interacts with the "legal enforcement agency” and the operator's “network unit”, where the “management module” serves the operator or “legal enforcement agency”. Used to manage and control the interception; the "arbitration device” is responsible for obtaining the interception information from the "network unit” and passing the information to the "legal enforcement agency” through the standard interface.
  • Intercept Related Information Includes IP address, time, and network location.
  • the IRI information includes the user's IP address
  • the CC content information is also composed of the IP address and content.
  • the IP address is ambiguous and represents both the identity of the listenee and the location of the listener.
  • the IP address changes, that is, the identity information and location information of the listener change. This brings trouble to the monitor.
  • the first scheme is not flexible, which causes a large number of redundant configurations in the network.
  • the second scheme interrupts the monitoring and may miss important information.
  • the technical problem to be solved by the present invention is to provide a lawful interception method and system to solve the problem that there is no monitoring scheme in the identity identification and location separation network architecture.
  • the present invention provides a lawful interception method, which is implemented based on a user identity identifier and a location separation network.
  • the identity location register (ILR) in the network is responsible for saving and maintaining the first information and the second of the terminal.
  • Information mapping relationship the method includes:
  • the monitoring center sends an information monitoring command to the identity location register (ILR), including the first information of the monitored terminal;
  • ILR identity location register
  • the ILR queries the corresponding mapping relationship according to the first information in the information listening command, and reports the second information of the monitored terminal to the monitoring center.
  • the ILR is further responsible for detecting whether the second information in the mapping relationship of the monitored terminal changes. After the ILR reports the second information to the monitoring center, if the location identifier of the monitored terminal is detected to be changed, And then to the monitoring center the second information of the latest monitored terminal.
  • the first information is an identity identifier of the terminal
  • the second information includes a location identifier of the terminal.
  • the present invention also provides another lawful interception method, which is implemented based on a user identity identifier and a location separation network.
  • the identity location register (ILR) in the network is responsible for saving and maintaining the identity of the terminal and related.
  • the mapping relationship of the information, the related information includes a location identifier of the monitored terminal, and the method includes:
  • the monitoring center sends an information monitoring command to the identity location register (ILR), including the identity of the monitored terminal;
  • ILR identity location register
  • the ILR queries the mapping relationship corresponding to the identity identifier in the information monitoring command, and reports the related information of the monitored terminal to the monitoring center;
  • the monitoring center sends a content listening command to the access server (ASR) where the monitored terminal is located according to the location identifier of the monitored terminal, including an identifier of the monitored terminal; and the ASR monitors according to the content.
  • the command copies the related message of the monitored terminal and forwards it to the monitoring center.
  • the related packet listening command includes a packet type
  • the ASR obtains a corresponding packet according to the packet type and reports the packet.
  • the ILR is also responsible for detecting whether the location identifier in the mapping relationship of the monitored terminal changes. After the ILR reports the location identifier to the monitoring center, if the location identifier of the monitored terminal is detected, The information about the latest monitored terminal is sent to the monitoring center; after receiving, the monitoring center sends a content monitoring command to the new ASR.
  • the present invention provides a lawful interception system, which is implemented based on a user identity and a location separation network, and the system includes:
  • the information monitoring module of the monitoring center is configured to: send an information monitoring command to the identity location register (ILR), including the first information of the monitored terminal; and receive the second information of the monitored terminal reported by the ILR;
  • ILR identity location register
  • the mapping relationship maintenance module of the ILR is configured to: save and maintain a mapping relationship between the first information and the second information of the terminal;
  • the information reporting module of the ILR is configured to: query a corresponding mapping relationship according to the first information in the information monitoring command, and send the second information of the monitored terminal to the monitoring center.
  • the ILR further includes an information detecting module, configured to: detect whether the second information in the mapping relationship of the monitored terminal changes; and notify the information reporting module of the ILR when the second information of the monitored terminal changes. ;
  • the information reporting module of the ILR is further configured to report the second information of the latest monitored terminal to the monitoring center when the second information of the monitored terminal changes.
  • the first information is an identity of the terminal
  • the second information includes a location identifier of the terminal.
  • the present invention also provides another lawful interception system, which is implemented based on a user identity and a location separation network, and the system includes:
  • the information monitoring module of the monitoring center is configured to: send an information monitoring command to the identity location register (ILR), including an identifier of the monitored terminal; and receive information about the monitored terminal reported by the ILR;
  • ILR identity location register
  • the mapping relationship maintenance module of the ILR is configured to: save and maintain a mapping relationship between the identity of the terminal and the related information, where the related information includes a location identifier of the monitored terminal; and the information reporting module of the ILR, The setting is: querying a mapping relationship corresponding to the identity identifier in the information monitoring command, and sending related information of the monitored terminal to the monitoring center;
  • the content monitoring module of the monitoring center is configured to send a content listening command to the access server (ASR) where the monitored terminal is located according to the location identifier of the monitored terminal, where the monitored terminal includes An identity identifier; receiving a related packet of the monitored terminal reported by the ASR;
  • ASR access server
  • the content monitoring module of the ASR is configured to: copy the related message of the monitored terminal according to the content monitoring command, and forward the message to the monitoring center.
  • the ILR further includes an information detecting module, configured to: detect whether a location identifier in the mapping relationship of the monitored terminal changes; and notify the information reporting module of the ILR when the location identifier of the monitored terminal changes;
  • the information reporting module of the ILR is further configured to: when the location identifier of the monitored terminal changes, the related information of the latest monitored terminal to the monitoring center;
  • the information monitoring module of the monitoring center is further configured to: notify the content monitoring module to send a content monitoring command to the new ASR according to the latest information of the monitored terminal.
  • the present invention also provides an identity location register (ILR), which is applied to a system implemented based on a user identity identifier and a location separation network, where the ILR includes a mapping relationship maintenance module and an information reporting module.
  • ILR identity location register
  • the mapping relationship maintenance module of the ILR is configured to: save and maintain a mapping relationship between the first information and the second information of the terminal;
  • the information reporting module of the ILR is configured to: query a corresponding mapping relationship according to the first information in the information monitoring command, and report the second information of the monitored terminal to the monitoring center.
  • the ILR further includes an information detecting module, configured to: detect whether the second information in the mapping relationship of the monitored terminal changes; and notify the information reporting module of the ILR when the second information of the monitored terminal changes. .
  • the information reporting module of the ILR is further configured to: when the second information of the monitored terminal changes, the second information of the latest monitored terminal to the monitoring center.
  • the first information is an identity of the terminal
  • the second information includes a location identifier of the terminal.
  • the present invention also provides another identity location register (ILR), which is applied to a system implemented based on a user identity identifier and a location separation network, where the ILR includes a mapping relationship maintenance module and an information reporting module.
  • ILR identity location register
  • the mapping relationship maintenance module of the ILR is configured to: save and maintain a mapping relationship between the identity of the terminal and related information, where the related information includes a location identifier of the monitored terminal;
  • the information reporting module of the ILR is configured to: query the mapping relationship corresponding to the identity identifier in the information monitoring command, and report the related information of the monitored terminal to the monitoring center.
  • the ILR further includes an information detecting module, configured to: detect whether a location identifier in the mapping relationship of the monitored terminal changes; and notify the information reporting module of the ILR when the location identifier of the monitored terminal changes.
  • an information detecting module configured to: detect whether a location identifier in the mapping relationship of the monitored terminal changes; and notify the information reporting module of the ILR when the location identifier of the monitored terminal changes.
  • the information reporting module of the ILR is further configured to: when the location identifier of the monitored terminal changes, the related information of the latest monitored terminal to the monitoring center.
  • the present invention also provides a monitoring center, which is applied to a system implemented based on a user identity identifier and a location separation network, including:
  • the information monitoring module of the monitoring center is configured to: send an information monitoring command to the identity location register (ILR), including an identifier of the monitored terminal; and receive information about the monitored terminal reported by the ILR;
  • ILR identity location register
  • the content monitoring module of the monitoring center is configured to send a content listening command to the access server (ASR) where the monitored terminal is located according to the location identifier of the monitored terminal, where the monitored terminal includes An identity identifier; receiving, by the ASR, a related packet of the monitored terminal that is copied according to the content listening command.
  • ASR access server
  • the information monitoring module of the monitoring center is further configured to: notify the content monitoring module to deliver a content monitoring command to the new ASR according to the latest information about the monitored terminal.
  • the method and system of the embodiment of the present invention implements information monitoring of a dynamic mapping relationship and content monitoring based on the information monitoring by transmitting a monitoring command to the identity identifier and the location register of the mapping relationship by the monitoring center.
  • FIG. 1 is a schematic diagram of an identity identification and location separation network architecture
  • FIG. 2 is a schematic diagram of a legal listening model of an existing IP network
  • Embodiment 3 is a schematic flowchart of Embodiment 1 of a lawful interception method according to the present invention.
  • Embodiment 4 is a schematic flowchart of Embodiment 2 of a lawful interception method according to the present invention.
  • FIG. 5 is a schematic flowchart of a lawful interception application example
  • FIG. 6 is a schematic structural diagram of a module of Embodiment 1 of a lawful interception system according to the present invention.
  • FIG. 7 is a schematic structural diagram of a module of Embodiment 1 of a lawful interception system according to the present invention.
  • FIG. 8 is a schematic structural diagram of a module of Embodiment 1 of a lawful interception system of the present invention.
  • FIG. 9 is a schematic structural diagram of a module of Embodiment 1 of a lawful interception system according to the present invention. Preferred embodiment of the invention
  • the user Since the user sends each data packet carrying the user's access identity AID in the SILSN network, and the access identity can be uniquely changed in the network transmission, and the user moves in the network, the AID does not change. , the whole network is unique.
  • the present invention collectively refers to a network element in the identity and location separation network (SILSN) responsible for maintaining or maintaining a mapping relationship between identity and UE-related information, and is generally referred to as an identity and location register (IRR). It is understood that the ILR may be included.
  • a series of nodes that have an association relationship in the network may also be a node corresponding to the entire network, and may also have other names, such as a mapping server.
  • CC Content of Communication
  • CC Content of Communication
  • it is also referred to as a related message of the monitored UE: including various messages sent and received by the monitored UE, such as mail, voice, video, etc. .
  • Intercept Related Information which is also referred to as monitored UE related information in the present invention: refers to information related to the monitored UE itself, such as its current location identifier, network access time, and previous location identifier. Wait.
  • the information about the monitored UE includes at least its location identifier. It can be understood that the location identifier of the UE in the SILSN network reflects the location information of the UE to a certain extent, and the monitoring center knows that the location information can achieve a certain degree of monitoring purposes.
  • the method embodiment 1 includes: Step 301: Monitoring Center Direction
  • the identity location register (ILR) sends an information listening command, including the identity of the monitored terminal;
  • Step 302 The ILR queries the corresponding mapping relationship according to the identity identifier in the information monitoring command, and reports related information of the monitored terminal to the monitoring center.
  • the ILR needs to query the local according to the identity of the monitored terminal in the interception command.
  • the database is obtained to obtain related information of the monitored terminal including its location identifier.
  • the above method will be combined with the identity identification and location separation network, and the user's AID's network uniqueness is used to perform relatively large-scale monitoring on the user.
  • the investigating agency needs not only the relevant information of the monitored terminal but also the content, e-mail or video, short message, etc. that the intercepted terminal dials or receives.
  • Another monitoring method is provided below. As shown in FIG. 4, the method embodiment 2 includes:
  • Step 401 The monitoring center sends an information monitoring command to the identity location register (ILR), including the identity of the monitored terminal.
  • ILR identity location register
  • Step 402 The ILR queries the corresponding mapping relationship according to the identity identifier in the information monitoring command, and reports related information of the monitored terminal to the monitoring center.
  • Step 403 The monitoring center sends a content listening command to the access server (ASR) where the monitored terminal is located according to the location identifier of the monitored terminal, where the identifier of the monitored terminal is included;
  • ASR access server
  • Step 404 The ASR copies the related packet of the monitored terminal according to the content listening command, and forwards the related packet to the monitoring center.
  • the present invention implements comprehensive monitoring of related messages and related information of the monitored UE by the monitoring center.
  • the monitoring configuration information in the monitoring command can be changed to achieve more specific and detailed monitoring requirements, such as configuration monitoring.
  • the type of the message (such as text, voice, video, etc.), the range of related information to be monitored, etc., correspondingly, the ILR or ASR that receives the interception command, obtains the corresponding information or message according to the configuration information in the interception command, and reports it. .
  • the ILR is also responsible for detecting whether the location identifier in the mapping relationship of the monitored terminal changes.
  • the ILR reports the location identifier to the monitoring center. After the location identifier of the monitored terminal is detected, the information about the latest monitored terminal is reported to the monitoring center. After receiving the content, the monitoring center sends a content monitoring command to the new ASR.
  • Figure 5 shows an embodiment of listening to users in an identity and location separation network.
  • the user accesses the ASR1, and the law enforcement agency (such as the judicial authority) conducts IRI and CC monitoring on the user.
  • the ILR returns an update of the user location information to the MD
  • the MD device deploys the monitoring configuration to the ASR2 according to the updated location information of the user, and performs dynamic monitoring on the user.
  • the LEA judicial institution sends a monitoring command to the MD, listens to the user's AID, and
  • the MD after receiving the interception command, the MD sends an information monitoring command to the ILR according to the AID, and monitors the user's IRI information;
  • the ILR receives an information monitoring command, and collects information such as a location identifier of the user.
  • the ILR sends the collected IRI information such as the location identifier of the user to the MD;
  • S516 The MD forwards the user's IRI information to the LEA.
  • the MD sends a related packet listening command to the ASR1 where the user is located according to the received IRI information.
  • the ASR1 forwards the packet of the related user to the MD according to the related packet listening command sent by the MD.
  • S532 The monitored user moves, and the ILR receives a location update message that the user moves;
  • the ILR updates the IRI information to the MD
  • S544 The MD sends a related packet listening command to the new ASR2 where the user is located according to the received updated IRI information.
  • the ASR2 forwards the packet of the related user to the MD according to the command sent by the MD.
  • S552. The MD forwards the CC information of the user to the LEA.
  • the MD sends a related packet monitoring release command to the original access point ASR1 of the user.
  • the process of dynamically monitoring users on the entire network ends.
  • the ILR information of the user is monitored by the ILR, and when the location of the user is changed, the ILR sends a new IRI message to the MD, triggering the MD to send a monitoring command to the new ASR where the user is located, thereby implementing dynamic diagnosis of the entire network. monitor.
  • User AID is unique across the network, which creates a prerequisite for dynamic monitoring of users across the network.
  • the ILR can notify the MD in time to perform related monitoring and monitoring.
  • the LEA, the management module, and the arbitration device collectively implement the functions of the monitoring center referred to in the present invention.
  • the present invention further provides a network-wide lawful interception system, which is implemented based on a user identity identifier and a location separation network.
  • the system embodiment includes:
  • An information monitoring module of the monitoring center configured to send an information monitoring command to the identity location register (ILR), including the first information of the monitored terminal; and configured to receive the second information of the monitored terminal reported by the ILR;
  • ILR identity location register
  • the mapping relationship maintenance module of the ILR is configured to save and maintain a mapping relationship between the first information and the second information of the terminal;
  • the information reporting module of the ILR is configured to query a corresponding mapping relationship according to the first information in the information monitoring command, and send the second information of the monitored terminal to the monitoring center.
  • the ILR further includes an information detecting module, configured to detect whether the second information in the mapping relationship of the monitored terminal is A change occurs; when the second information of the monitored terminal changes, notifying the information reporting module of the ILR;
  • the information reporting module of the ILR is further configured to report, to the monitoring center, the second information of the latest monitored terminal when the second information of the monitored terminal changes.
  • the first information is an identity identifier of the terminal
  • the second information includes a location identifier of the terminal.
  • the present invention further provides a network-wide lawful interception system, which is implemented based on a user identity identifier and a location separation network.
  • the system embodiment includes:
  • An information monitoring module of the monitoring center configured to send an information monitoring command to the identity location register (ILR), including an identifier of the monitored terminal, and configured to receive related information of the monitored terminal reported by the ILR;
  • ILR identity location register
  • the mapping relationship maintenance module of the ILR is configured to save and maintain a mapping relationship between the identity identifier of the terminal and related information, where the related information includes a location identifier of the monitored terminal,
  • the information reporting module of the ILR is configured to query a mapping relationship corresponding to the identity identifier in the information monitoring command, and send information about the monitored terminal to the monitoring center; content of the monitoring center a monitoring module, configured to send a content listening command to the access server (ASR) where the monitored terminal is located according to the location identifier of the monitored terminal, where the identifier of the monitored terminal is included; The related message of the monitored terminal reported by the ASR;
  • ASR access server
  • the content monitoring module of the ASR is configured to copy related messages of the monitored terminal according to the content monitoring command and forward the related message to the monitoring center.
  • the ILR further includes an information detecting module, configured to detect whether a location identifier in a mapping relationship of the monitored terminal changes; When the change is made, the information of the ILR is notified to the module;
  • the information reporting module of the ILR is further configured to: when the location identifier of the monitored terminal changes, send information about the latest monitored terminal to the monitoring center; and the information monitoring module of the monitoring center is based on the latest The content monitoring module notifies the content monitoring module to deliver a content monitoring command to the new ASR.
  • This method utilizes the identity and location identifier to separate the superiority of the network, and based on the unique AID of the whole network, The location information in the IRI information of the user is monitored on the ILR, so that the CC information of the user is dynamically monitored on the entire network, which can effectively solve the problem that the user continuously moves to avoid the monitoring.
  • the dynamic monitoring user on the whole network can realize the continuity of the user's CC information monitoring, which has a greater advantage than the original IP network user moving to bring the incompleteness of the monitoring information.
  • the method and system of the embodiment of the present invention implements information monitoring of a dynamic mapping relationship by means of a monitoring center sending a listening command to an identity identifier and a location register of a mapping relationship, and content monitoring based on the information monitoring. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Technology Law (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

一种合法监听方法和系统。该方法基于用户身份标识和位置分离网络实现,该网络中的身份位置寄存器(ILR)负责保存及维护终端的第一信息与第二信息的映射关系,该方法包括:监控中心向身份位置寄存器(ILR)下发信息监听命令,包括被监听终端的第一信息;所述ILR根据所述信息监听命令中的第一信息查询对应的映射关系,并向所述监控中心上报所述被监听终端的第二信息。本发明方法和系统提供了一种基于身份标识和位置分离网络的监听方案。

Description

合法监听的方法和系统
技术领域
本发明涉及移动通讯领域和互联网领域, 涉及一种身份标识和位置分离 网络中的全网实施合法监听的方法。
背景技术
关于下一代信息网络架构的研究是当前最热门的课题之一, 目前大多数 研究接受的观点是: 未来网络将以互联网为统一承载网络。 然而, 互联网的 结构还远远没有达到最优, 存在很多重大的设计问题, 其中比较典型的是 IP 地址的双重属性的问题, 即 IP地址既代表用户身份, 又代表用户所处的网络 拓朴, 即 IP地址的双重属性。
IP地址双重属性的内在矛盾将导致路由可扩展问题、 移动性问题、 多家 乡问题及安全和位置隐私问题等一系列问题。
为解决 IP地址的双重属性所带来的问题, 中兴通讯提出了如图 1所示的 身份标识和位置分离网络架构,在图 1中,此身份标识和位置分离系统 SILSN 由接入服务器( Access Service Router, ASR )和用户终端 UE( User Equipment )、 身份标识和位置登记寄存器( Identification & Location Register, ILR ) 以及认 证中心(Authentication Center, AC )等组成。 其中接入服务器 ASR1和 ASR2 用来接入用户终端设备 UE1、 UE2, 负责为用户终端实现接入, 并承担计费、 切换等功能, ILR承担用户的位置注册和身份识别功能, AC承担用户接入认 证功能, UE1和 UE2分别存在唯一的身份标识符 (Access Identification)AIDl 和 AID2。
图 1所示网络有如下特征: 此网络内每个用户只有经过严格认证才能接 入, 用户在发送每个数据包时, 都同时携带自己的真实用户接入标识符 AID, 此符号仅分配给该用户使用且全网唯一, 用户在各种业务中所发送的数据包 都一直携带此标识符,用户发送的每个数据包都必须经过接入服务器 ASR验 证, 保证用户发出的数据包携带的是自己的接入身份标识, 不会假冒其他用 户 AID接入网络,并且此标识符在网内传送时将一直保持不变,当用户在移动 或切换时, 此标识符也不会发生变化。
为描述方便, 下文将此用户身份标识和位置分离网络简称为 (Subscriber Identifier & Locator Separation Network, SILSN ) 。 本发明所述方法^^于 J¾ SILSN架构来解决全网动态合法监听的问题。
由于防恐等警务信息需要, 各国法律往往规定电信企业开展的业务必须 能被合法机构监听。
合法监听 (Lawful Interception ) , 是指为了收集证据、 查明犯罪事实, 利用电信技术对监听对象的电子通信予以探知并记录的一种秘密侦查措施。 合法监听可以由侦查机关直接来实施, 也可以通过电信服务提供者协助来实 施。 这种实施的过程对于被监听对象而言, 属于秘密的侦查过程, 故对于电 信服务提供者而言, 应当满足一定的保密要求。
如图 2是 IP数据服务的合法监听的模型, 其组成部分包括: 法律强制机 构 (LEA , Law Enforcement Agency)、 管理模块 (LI Administration Function)、 仲 裁设备 (LI MD , Mediation Device)、监听相关信息监听接入点( Intercept Related Information Intercept Access Point ) 、 监听内容监听接入点 ( Content of Communication Intercept Access Point ) 。
"监听内容监听接入点 "是运营商网络中的某个设备节点, 一般是具有合 法监听功能的路由器或交换机。
"监听相关信息监听接入点"一般指网络的认证、 管理设备, 例如 AAA服 务器 ( AAA Server, Authentication, Authorization, Accounting )和 DHCP月良 务器, 它为监听者提供地址、 时间等信息。
"管理模块"和"仲裁设备"合称为仲裁系统, 仲裁系统与"法律强制机构" 和运营商的"网络单元"交互, 其中"管理模块"是为运营商或者"法律强制机 构"提供服务的, 用来管理和控制监听; "仲裁设备"负责从 "网络单元"中获得 监听信息, 并将信息通过标准的接口传递给"法律强制机构"。
合法监听信息分为两类:
监听内容(Content of Communication, 简称 CC ) : 邮件、 语音等。 监听相关信息(Intercept Related Information, 简称 IRI ) : 包括 IP地址、 时间、 网络位置。
目前, 在 SILSN网络架构下, 还没有实现监听功能。
发明内容
在现有的合法监听方案中, IRI信息包括用户的 IP地址, CC内容信息也 由 IP地址和内容组成。 IP地址存在二义性, 既代表被监听者的身份, 也代表 被监听者的位置。 当被监听者在现有网络中发生移动时, IP地址发生变化, 即被监听者的身份信息和位置信息都发生了变化。 这给监听带来了麻烦。 现 有的解决方案通常有两种, 一为向所有被监听者可能接入的设备布控进行监 听, 二为被监听者移动后, 人工通知被监听者最新的所在地的司法机构进行 监听。
以上两种方案都有其缺陷, 第一种方案布控不灵活, 使网络中产生大量 冗余配置; 第二种方案会中断监听, 可能遗漏重要信息。
本发明要解决的技术问题是提供一种合法监听方法和系统, 以解决身份 标识和位置分离网络架构中还没有监听方案的问题。
为解决以上技术问题, 本发明提供了一种合法监听方法, 该方法基于用 户身份标识和位置分离网络实现, 该网络中的身份位置寄存器(ILR )负责保 存及维护终端的第一信息与第二信息的映射关系, 该方法包括:
监控中心向身份位置寄存器(ILR )下发信息监听命令, 包括被监听终端 的第一信息;
所述 ILR根据所述信息监听命令中的第一信息查询对应的映射关系, 并 向所述监控中心上报所述被监听终端的第二信息。
优选地, 所述 ILR还负责检测被监听终端的映射关系中的第二信息是否 发生变化, 所述 ILR向所述监控中心上报所述第二信息后, 若检测到被监听 终端的位置标识变化,则向所述监控中心上 最新的被监听终端的第二信息。
优选地, 所述第一信息为所述终端的身份标识, 所述第二信息包括所述 终端的位置标识。 为解决以上技术问题, 本发明还提供了另一种合法监听方法, 该方法基 于用户身份标识和位置分离网络实现, 该网络中的身份位置寄存器(ILR )负 责保存及维护终端的身份标识与相关信息的映射关系, 所述相关信息包括所 述被监听终端的位置标识, 该方法包括:
监控中心向身份位置寄存器(ILR )下发信息监听命令, 包括被监听终端 的身份标识;
所述 ILR根据所述信息监听命令中的身份标识查询对应的映射关系, 并 向所述监控中心上报所述被监听终端的相关信息;
监控中心根据所述被监听终端的位置标识向所述被监听终端所在的接入 服务器(ASR ) 下发内容监听命令, 其中包括所述被监听终端的身份标识; 所述 ASR根据所述内容监听命令复制被监听终端的相关报文并转发给所 述监控中心。
优选地, 所述相关报文监听命令中包括报文类型, 所述 ASR根据所述报 文类型获取相应的报文并上报。
优选地, 所述 ILR还负责检测被监听终端的映射关系中的位置标识是否 发生变化, 所述 ILR向所述监控中心上报所述位置标识后, 若检测到被监听 终端的位置标识变化,则向所述监控中心上 ^艮最新的被监听终端的相关信息; 所述监控中心接收后, 向新的 ASR下发内容监听命令。
为解决以上技术问题, 本发明提供了一种合法监听系统, 该系统基于用 户身份标识和位置分离网络实现, 该系统包括:
监控中心的信息监听模块, 其设置为: 向身份位置寄存器(ILR )下发信 息监听命令, 包括被监听终端的第一信息; 接收所述 ILR上报的所述被监听 终端的第二信息;
所述 ILR的映射关系维护模块, 其设置为: 保存及维护终端的所述第一 信息与第二信息的映射关系;
所述 ILR的信息上报模块, 其设置为: 根据所述信息监听命令中的第一 信息查询对应的映射关系, 并向所述监控中心上 所述被监听终端的第二信 息。 优选地, 所述 ILR还包括信息检测模块, 设置为: 检测被监听终端的映 射关系中的第二信息是否发生变化; 当被监听终端的第二信息变化时, 通知 所述 ILR的信息上报模块;
所述 ILR的信息上报模块还设置为: 在被监听终端的第二信息变化时, 向所述监控中心上报最新的被监听终端的第二信息。
优选地, 所述第一信息为所述终端的身份标识, 所述第二信息包括所述 终端的位置标识。
为解决以上技术问题, 本发明还提供了另一种合法监听系统, 该系统基 于用户身份标识和位置分离网络实现, 该系统包括:
监控中心的信息监听模块, 其设置为: 向身份位置寄存器(ILR )下发信 息监听命令, 包括被监听终端的身份标识; 接收所述 ILR上报的所述被监听 终端的相关信息;
所述 ILR的映射关系维护模块, 其设置为: 保存及维护终端的身份标识 与相关信息的映射关系, 所述相关信息包括所述被监听终端的位置标识; 所述 ILR的信息上报模块, 其设置为: 根据所述信息监听命令中的身份 标识查询对应的映射关系, 并向所述监控中心上 所述被监听终端的相关信 息;
所述监控中心的内容监听模块, 其设置为: 根据所述被监听终端的位置 标识向所述被监听终端所在的接入服务器(ASR ) 下发内容监听命令, 其中 包括所述被监听终端的身份标识;接收所述 ASR上报的被监听终端的相关报 文;
所述 ASR的内容监听模块, 其设置为: 根据所述内容监听命令复制被监 听终端的相关报文并转发给所述监控中心。
优选地, 所述 ILR还包括信息检测模块, 设置为: 检测被监听终端的映 射关系中的位置标识是否发生变化; 当被监听终端的位置标识变化时, 通知 所述 ILR的信息上报模块;
所述 ILR的信息上报模块还设置为: 在被监听终端的位置标识变化时, 向所述监控中心上 最新的被监听终端的相关信息; 所述监控中心的信息监听模块还设置为: 根据最新的被监听终端的相关 信息通知所述内容监听模块向新的 ASR下发内容监听命令。
本发明还提供了一种身份位置寄存器(ILR ) , 应用于基于用户身份标识 和位置分离网络实现的系统, 所述 ILR包括映射关系维护模块和信息上报模 块,
所述 ILR的映射关系维护模块设置为: 保存及维护终端的第一信息与第 二信息的映射关系;
所述 ILR的信息上报模块设置为: 根据信息监听命令中的第一信息查询 对应的映射关系, 并向监控中心上报所述被监听终端的第二信息。
优选地, 所述 ILR还包括信息检测模块, 设置为: 检测被监听终端的映 射关系中的第二信息是否发生变化; 当被监听终端的第二信息变化时, 通知 所述 ILR的信息上报模块。
优选地, 所述 ILR的信息上报模块还设置为: 在被监听终端的第二信息 变化时, 向所述监控中心上 最新的被监听终端的第二信息。
优选地, 所述第一信息为所述终端的身份标识, 所述第二信息包括所述 终端的位置标识。
本发明还提供了另一种身份位置寄存器(ILR ) , 应用于基于用户身份标 识和位置分离网络实现的系统, 所述 ILR包括映射关系维护模块和信息上报 模块,
所述 ILR的映射关系维护模块设置为: 保存及维护终端的身份标识与相 关信息的映射关系, 所述相关信息包括所述被监听终端的位置标识;
所述 ILR的信息上报模块设置为: 根据信息监听命令中的身份标识查询 对应的映射关系, 并向监控中心上报所述被监听终端的相关信息。
优选地, 所述 ILR还包括信息检测模块, 设置为: 检测被监听终端的映 射关系中的位置标识是否发生变化; 当被监听终端的位置标识变化时, 通知 所述 ILR的信息上报模块。
优选地, 所述 ILR的信息上报模块还设置为: 在被监听终端的位置标识 变化时, 向所述监控中心上 最新的被监听终端的相关信息。 本发明还提供了一种监控中心, 应用于基于用户身份标识和位置分离网 络实现的系统, 包括:
监控中心的信息监听模块, 其设置为: 向身份位置寄存器(ILR )下发信 息监听命令, 包括被监听终端的身份标识; 接收所述 ILR上报的所述被监听 终端的相关信息;
所述监控中心的内容监听模块, 其设置为: 根据所述被监听终端的位置 标识向所述被监听终端所在的接入服务器(ASR ) 下发内容监听命令, 其中 包括所述被监听终端的身份标识;接收所述 ASR上报的根据所述内容监听命 令复制的被监听终端的相关报文。
优选地, 所述监控中心的信息监听模块还设置为: 根据最新的被监听终 端的相关信息通知所述内容监听模块向新的 ASR下发内容监听命令。
本发明实施例的方法和系统通过由监听中心向保存映射关系的身份标识 和位置寄存器发送监听命令的方式, 实现了对动态的映射关系的信息监听, 以及基于该信息监听的内容监听。 附图概述
图 1是身份标识和位置分离网络架构示意图;
图 2是现有 IP网络合法监听模型示意图;
图 3是本发明合法监听方法实施例 1的流程示意图;
图 4是本发明合法监听方法实施例 2的流程示意图;
图 5是合法监听应用实例的流程示意图;
图 6是本发明合法监听系统实施例 1的模块结构示意图;
图 7是本发明合法监听系统实施例 1的模块结构示意图;
图 8是本发明合法监听系统实施例 1的模块结构示意图;
图 9是本发明合法监听系统实施例 1的模块结构示意图。 本发明的较佳实施方式
由于 SILSN 网络中用户发送每一个数据包都携带用户的接入身份标识 AID , 而且此接入身份标识在网络传输中可以唯一不变, 并且用户在网络中 进行移动时, 该 AID也不会改变, 全网唯一。
在图 1中, 用户 UE1和 UE2分别通过 ASR1和 ASR2接入网络, 并需要 经过 AC进行接入认证。认证成功之后, ASR会将用户的位置信息上报到 ILR。
本发明将身份标识和位置分离网络(SILSN ) 中负责维护或保存有身份 标识与 UE相关信息的映射关系的网元统称为身份标识和位置寄存器( ILR ) , 可理解的, 该 ILR可以是包括分布在网络中具有关联关系的一系列节点, 也 可以是对应整个网络的一个节点, 其还可能有其他的称呼, 比如映射服务器 等。
如前所述, 合法监听信息分为两类:
一类是监听内容(Content of Communication, 简称 CC ) , 本发明中, 也 称为被监听 UE的相关报文: 包括被监听的 UE发送及接收的各种报文, 比如 邮件、 语音、 视频等。
另一类是监听相关信息 ( Intercept Related Information, 简称 IRI ) , 本 发明中也称为被监听 UE相关信息: 指除被监听的 UE自身相关的信息,如其 当前位置标识、 入网时间、 先前位置标识等。 在本发明中, 被监听 UE相关 信息至少包括其位置标识。 可理解地, 在 SILSN网络中 UE的位置标识一定 程度上体现了 UE的位置信息, 监控中心获知该位置信息可以达到一定程度 的监控目的。
以下利用 UE的身份标识在全网的唯一性, 以及 ILR保存的 UE的相关 信息的及时性, 提供一种监听方法, 如图 3所示, 该方法实施例 1包括: 步骤 301 : 监控中心向身份位置寄存器(ILR )下发信息监听命令, 包括 被监听终端的身份标识;
步骤 302: 所述 ILR根据所述信息监听命令中的身份标识查询对应的映 射关系, 并向所述监控中心上报所述被监听终端的相关信息。
该步骤中, ILR需要根据监听命令中的被监听终端的身份标识查询本地 数据库, 从而得到该被监听终端的包括其位置标识在内的相关信息。
以上方法将与身份标识和位置分离网络结合起来, 利用用户 AID的全网 唯一性来进行对用户进行比较粗放的监听。
为了达到更全面的监听需要, 比如侦查机关在某些时候不仅需要被监听 终端的相关信息, 还需要该被监听终端拨打或接听的电话内容、 邮件或视频、 短信等内容, 针对这种情形, 以下提供了另一种监听方法, 如图 4所示, 该 方法实施例 2包括:
步骤 401 : 监控中心向身份位置寄存器(ILR )下发信息监听命令, 包括 被监听终端的身份标识;
步骤 402: 所述 ILR根据所述信息监听命令中的身份标识查询对应的映 射关系, 并向所述监控中心上报所述被监听终端的相关信息;
步骤 403: 监控中心根据所述被监听终端的位置标识向所述被监听终端 所在的接入服务器 (ASR ) 下发内容监听命令, 其中包括所述被监听终端的 身份标识;
步骤 404: 所述 ASR根据所述内容监听命令复制被监听终端的相关报文 并转发给所述监控中心。
根据以上方法, 本发明实现了监控中心对被监听 UE的相关报文及相关 信息的全面监听, 另外, 可以通过改变监听命令中的监听配置信息, 达到更 具体细化的监听需求, 比如配置监听的报文类型(如文本、 语音、 视频等) 、 监听的相关信息的范围等, 相应的, 接收到监听命令的 ILR或 ASR, 根据监 听命令中的配置信息获取相应的信息或报文并上报。
为了实现全网动态监听, 所述 ILR还负责检测被监听终端的映射关系中 的位置标识是否发生变化, 以上图 3和图 4所示的流程中, 所述 ILR向监控 中心上报所述位置标识后, 若检测到被监听终端的位置标识变化, 则向所述 监控中心上报最新的被监听终端的相关信息; 所述监控中心接收后, 向新的 ASR下发内容监听命令。
从背景技术描述可以看出,由于传统的 IP地址存在身份和位置的二义性, 使得现有合法监听技术只能对被监听者进行部分监听, 或者进行全网强制冗 余设置监听点, 无法做到对被监听者的全网动态合法监听。
下面根据附图介绍各实施例。 需要说明的是, 本发明内容可以用以下实 施例解释, 但不限于以下的实施例。 下面给出具体说明。 图 5所示为在身份与位置分离网络中监听用户的实施例。 用户在 ASR1 接入, 法律强制机构 (如司法机关 )对用户进行 IRI和 CC监听。 当用户向 ASR2移动后, 由 ILR向 MD返回用户位置信息的更新, MD设备根据用户 更新的位置信息向 ASR2部署监听配置, 对用户实施动态监听。
图 5中, 合法监听的管理模块与仲裁设备逻辑上合二为一。
S500 , LEA司法机构向 MD发送监听命令,监听用户的 AID以及以所述
AID为基础所发送的任何信息;
S504, MD收到监听命令后, 根据 AID向 ILR发送信息监听命令, 监听 用户的 IRI信息;
S508, ILR接收信息监听命令, 收集用户的位置标识等信息;
S512, ILR将收集到的用户的位置标识等 IRI信息发送到 MD;
S516, MD向 LEA转发用户的 IRI信息;
S520, MD根据收到的 IRI信息, 向用户所在的 ASR1下发相关报文监听 命令;
S524, ASR1根据 MD下发的相关报文监听命令, 复制相关用户的报文向 MD转发;
S528, MD向 LEA转发用户的 CC信息;
S532, 被监听的用户发生移动, ILR收到用户发生移动的位置更新消息;
S536, ILR向 MD更新 IRI信息;
S540 , MD向 LEA转发更新的 IRI信息;
S544 , MD根据收到的更新的 IRI信息, 向用户所在的新的 ASR2发送相 关报文监听命令;
S548, ASR2根据 MD下发的命令, 复制相关用户的报文向 MD转发; S552, MD向 LEA转发用户的 CC信息;
S556, MD向用户原有的接入点 ASR1发送相关报文监听解除命令。 全网动态监听用户的流程结束。
在以上实施例中, 在 ILR监听用户的 IRI信息, 当用户的位置发生变换 时, ILR向 MD发送新的 IRI信息, 触发 MD向用户所在的新的 ASR下发监 听命令, 实现全网动态合法监听。
用户 AID全网唯一, 这为全网动态监听用户创造了先决条件。
在 ILR上根据 AID设置用户监听, 当用户位置发生变化时, ILR可及时 通知 MD进行相关艮文监听更新。
需要说明的是,如果用户再次发生移动,则需要重复以上的 S532至 S556。 可理解地, 在以上实施例中, LEA、 管理模块及仲裁设备共同实现了本 发明所说的监控中心的功能。
为实现以上图 3所示的方法, 本发明还提供了一种全网合法监听系统, 该系统基于用户身份标识和位置分离网络实现, 如图 6所示, 该系统实施例 包括:
监控中心的信息监听模块, 用于向身份位置寄存器(ILR )下发信息监听 命令, 包括被监听终端的第一信息; 还用于接收所述 ILR上报的所述被监听 终端的第二信息;
所述 ILR的映射关系维护模块, 用于保存及维护终端的第一信息与第二 信息的映射关系;
所述 ILR的信息上报模块, 用于根据所述信息监听命令中的第一信息查 询对应的映射关系, 并向所述监控中心上 >¾所述被监听终端的第二信息。
为了实现对被监听终端的跟踪监听, 另一实施例如图 7所示, 与图 6不 同的是, 所述 ILR还包括信息检测模块, 用于检测被监听终端的映射关系中 的第二信息是否发生变化; 当被监听终端的第二信息变化时, 通知所述 ILR 的信息上报模块; 所述 ILR的信息上报模块, 还用于在被监听终端的第二信息变化时, 向 所述监控中心上报最新的被监听终端的第二信息。
具体地, 所述第一信息为所述终端的身份标识, 所述第二信息包括所述 终端的位置标识。
为实现以上图 4所示的方法, 本发明还提供了一种全网合法监听系统, 该系统基于用户身份标识和位置分离网络实现, 如图 8所示, 该系统实施例 包括:
监控中心的信息监听模块, 用于向身份位置寄存器(ILR )下发信息监听 命令, 包括被监听终端的身份标识; 还用于接收所述 ILR上报的所述被监听 终端的相关信息;
所述 ILR的映射关系维护模块, 用于保存及维护终端的身份标识与相关 信息的映射关系, 所述相关信息包括所述被监听终端的位置标识,
所述 ILR的信息上报模块, 用于根据所述信息监听命令中的身份标识查 询对应的映射关系, 并向所述监控中心上 >¾所述被监听终端的相关信息; 所述监控中心的内容监听模块, 用于根据所述被监听终端的位置标识向 所述被监听终端所在的接入服务器 (ASR ) 下发内容监听命令, 其中包括所 述被监听终端的身份标识;还用于接收所述 ASR上报的被监听终端的相关报 文;
所述 ASR的内容监听模块,用于根据所述内容监听命令复制被监听终端 的相关报文并转发给所述监控中心。
另一系统实施例如图 9所示, 与图 8不同的是, 所述 ILR还包括信息检 测模块, 用于检测被监听终端的映射关系中的位置标识是否发生变化; 当被 监听终端的位置标识变化时, 通知所述 ILR的信息上^艮模块;
所述 ILR的信息上报模块, 还用于在被监听终端的位置标识变化时, 向 所述监控中心上 ^艮最新的被监听终端的相关信息; 所述监控中心的信息监听 模块根据最新的被监听终端的相关信息通知所述内容监听模块向新的 ASR下 发内容监听命令。
本领域普通技术人员可以理解上述方法中的全部或部分步骤可通过程序 来指令相关硬件完成, 所述程序可以存储于计算机可读存储介质中, 如只读 存储器、 磁盘或光盘等。 可选地, 上述实施例的全部或部分步骤也可以使用 一个或多个集成电路来实现。 相应地, 上述实施例中的各模块可以釆用硬件 的形式实现, 也可以釆用软件功能模块的形式实现。 本发明不限制于任何特 定形式的硬件和软件的结合。
相对于以前 IP网络只能对用户进行小范围用户监听,做不到完全的全网 动态用户监听, 该方法利用身份标识和位置标识分离网络的优越性, 在全网 AID唯一的基础上,通过在 ILR上对用户的 IRI信息中的位置信息进行监听, 从而实现全网动态监听用户的 CC信息, 可以有效解决用户不断移动来躱避 监听的问题。 全网动态监听用户可以实现用户 CC信息监听的连续性, 相比 原有 IP网络用户移动带来监听信息的不完整性有较大优势。
工业实用性 本发明实施例的方法和系统通过由监听中心向保存映射关系的身份标识 和位置寄存器发送监听命令的方式, 实现了对动态的映射关系的信息监听, 以及基于该信息监听的内容监听。

Claims

权 利 要 求 书
1、 一种合法监听方法, 该方法基于用户身份标识和位置分离网络实现, 该网络中的身份位置寄存器( ILR )负责保存及维护终端的第一信息与第二信 息的映射关系, 该方法包括:
监控中心向身份位置寄存器(ILR )下发信息监听命令, 包括被监听终端 的第一信息;
所述 ILR根据所述信息监听命令中的第一信息查询对应的映射关系, 并 向所述监控中心上报所述被监听终端的第二信息。
2、 如权利要求 1所述的方法,其中,所述 ILR还负责检测被监听终端的 映射关系中的第二信息是否发生变化, 所述 ILR向所述监控中心上报所述第 二信息后, 若检测到被监听终端的位置标识变化, 则向所述监控中心上报最 新的被监听终端的第二信息。
3、 如权利要求 1或 2所述的方法,其中, 所述第一信息为所述终端的身 份标识, 所述第二信息包括所述终端的位置标识。
4、 一种合法监听方法, 该方法基于用户身份标识和位置分离网络实现, 该网络中的身份位置寄存器(ILR )负责保存及维护终端的身份标识与相关信 息的映射关系, 所述相关信息包括所述被监听终端的位置标识, 该方法包括: 监控中心向身份位置寄存器(ILR )下发信息监听命令, 包括被监听终端 的身份标识;
所述 ILR根据所述信息监听命令中的身份标识查询对应的映射关系, 并 向所述监控中心上报所述被监听终端的相关信息;
监控中心根据所述被监听终端的位置标识向所述被监听终端所在的接入 服务器(ASR ) 下发内容监听命令, 其中包括所述被监听终端的身份标识; 所述 ASR根据所述内容监听命令复制被监听终端的相关报文并转发给所 述监控中心。
5、 如权利要求 4所述的方法,其中, 所述相关报文监听命令中包括报文 类型, 所述 ASR根据所述报文类型获取相应的^艮文并上才艮。
6、 如权利要求 4所述的方法,其中,所述 ILR还负责检测被监听终端的 映射关系中的位置标识是否发生变化, 所述 ILR向所述监控中心上报所述位 置标识后, 若检测到被监听终端的位置标识变化, 则向所述监控中心上报最 新的被监听终端的相关信息; 所述监控中心接收后, 向新的 ASR下发内容监 听命令。
7、 一种合法监听系统, 该系统基于用户身份标识和位置分离网络实现, 该系统包括:
监控中心的信息监听模块, 其设置为: 向身份位置寄存器(ILR )下发信 息监听命令, 包括被监听终端的第一信息; 接收所述 ILR上报的所述被监听 终端的第二信息;
所述 ILR的映射关系维护模块, 其设置为: 保存及维护终端的所述第一 信息与第二信息的映射关系; 所述 ILR的信息上报模块, 其设置为: 根据所述信息监听命令中的第一 信息查询对应的映射关系, 并向所述监控中心上 所述被监听终端的第二信 息。
8、 如权利要求 7所述的系统, 其中, 所述 ILR还包括信息检测模块,设 置为: 检测被监听终端的映射关系中的第二信息是否发生变化; 当被监听终 端的第二信息变化时, 通知所述 ILR的信息上^艮模块;
所述 ILR的信息上报模块还设置为: 在被监听终端的第二信息变化时, 向所述监控中心上报最新的被监听终端的第二信息。
9、 如权利要求 7或 8所述的系统,其中, 所述第一信息为所述终端的身 份标识, 所述第二信息包括所述终端的位置标识。
10、 一种合法监听系统,该系统基于用户身份标识和位置分离网络实现, 该系统包括:
监控中心的信息监听模块, 其设置为: 向身份位置寄存器(ILR )下发信 息监听命令, 包括被监听终端的身份标识; 接收所述 ILR上报的所述被监听 终端的相关信息;
所述 ILR的映射关系维护模块, 其设置为: 保存及维护终端的身份标识 与相关信息的映射关系, 所述相关信息包括所述被监听终端的位置标识; 所述 ILR的信息上报模块, 其设置为: 根据所述信息监听命令中的身份 标识查询对应的映射关系, 并向所述监控中心上 所述被监听终端的相关信 息;
所述监控中心的内容监听模块, 其设置为: 根据所述被监听终端的位置 标识向所述被监听终端所在的接入服务器(ASR ) 下发内容监听命令, 其中 包括所述被监听终端的身份标识;接收所述 ASR上报的被监听终端的相关报 文;
所述 ASR的内容监听模块, 其设置为: 根据所述内容监听命令复制被监 听终端的相关报文并转发给所述监控中心。
11、 如权利要求 10所述的系统, 其中, 所述 ILR还包括信息检测模块, 设置为: 检测被监听终端的映射关系中的位置标识是否发生变化; 当被监听 终端的位置标识变化时, 通知所述 ILR的信息上^艮模块;
所述 ILR的信息上报模块还设置为: 在被监听终端的位置标识变化时, 向所述监控中心上 最新的被监听终端的相关信息;
所述监控中心的信息监听模块还设置为: 根据最新的被监听终端的相关 信息通知所述内容监听模块向新的 ASR下发内容监听命令。
12、 一种身份位置寄存器(ILR ) , 应用于基于用户身份标识和位置分 离网络实现的系统, 所述 ILR包括映射关系维护模块和信息上报模块,
所述 ILR的映射关系维护模块设置为: 保存及维护终端的第一信息与第 二信息的映射关系;
所述 ILR的信息上报模块设置为: 根据信息监听命令中的第一信息查询 对应的映射关系, 并向监控中心上报所述被监听终端的第二信息。
13、 如权利要求 12所述的 ILR, 其中, 所述 ILR还包括信息检测模块, 设置为: 检测被监听终端的映射关系中的第二信息是否发生变化; 当被监听 终端的第二信息变化时, 通知所述 ILR的信息上^艮模块。
14、 如权利要求 13所述的 ILR, 其中, 所述 ILR的信息上报模块还设 置为: 在被监听终端的第二信息变化时, 向所述监控中心上报最新的被监听 终端的第二信息。
15、 如权利要求 13或 14所述的 ILR, 其中, 所述第一信息为所述终端 的身份标识, 所述第二信息包括所述终端的位置标识。
16、 一种身份位置寄存器(ILR ) , 应用于基于用户身份标识和位置分 离网络实现的系统, 所述 ILR包括映射关系维护模块和信息上报模块,
所述 ILR的映射关系维护模块设置为: 保存及维护终端的身份标识与相 关信息的映射关系, 所述相关信息包括所述被监听终端的位置标识;
所述 ILR的信息上报模块设置为: 根据信息监听命令中的身份标识查询 对应的映射关系, 并向监控中心上报所述被监听终端的相关信息。
17、 如权利要求 16所述的 ILR, 其中, 所述 ILR还包括信息检测模块, 设置为: 检测被监听终端的映射关系中的位置标识是否发生变化; 当被监听 终端的位置标识变化时, 通知所述 ILR的信息上^艮模块。
18、 如权利要求 17所述的 ILR, 其中, 所述 ILR的信息上报模块还设 置为: 在被监听终端的位置标识变化时, 向所述监控中心上报最新的被监听 终端的相关信息。
19、 一种监控中心,应用于基于用户身份标识和位置分离网络实现的系 统, 包括:
监控中心的信息监听模块, 其设置为: 向身份位置寄存器(ILR )下发信 息监听命令, 包括被监听终端的身份标识; 接收所述 ILR上报的所述被监听 终端的相关信息;
所述监控中心的内容监听模块, 其设置为: 根据所述被监听终端的位置 标识向所述被监听终端所在的接入服务器(ASR ) 下发内容监听命令, 其中 包括所述被监听终端的身份标识;接收所述 ASR上报的根据所述内容监听命 令复制的被监听终端的相关报文。
20、 如权利要求 19所述的监控中心, 其中, 所述监控中心的信息监听模 块还设置为: 根据最新的被监听终端的相关信息通知所述内容监听模块向新 的 ASR下发内容监听命令。
PCT/CN2011/082862 2011-03-07 2011-11-24 合法监听的方法和系统 WO2012119464A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201110054500.X 2011-03-07
CN201110054500.XA CN102685737B (zh) 2011-03-07 2011-03-07 合法监听的方法和系统

Publications (1)

Publication Number Publication Date
WO2012119464A1 true WO2012119464A1 (zh) 2012-09-13

Family

ID=46797464

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/082862 WO2012119464A1 (zh) 2011-03-07 2011-11-24 合法监听的方法和系统

Country Status (2)

Country Link
CN (1) CN102685737B (zh)
WO (1) WO2012119464A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105704153B (zh) * 2016-03-30 2020-02-07 中国联合网络通信集团有限公司 实时追踪网络访问信息的方法和系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1870683A (zh) * 2005-11-22 2006-11-29 华为技术有限公司 一种实现合法监听的方法
CN1929414A (zh) * 2006-10-12 2007-03-14 华为技术有限公司 设置监听用户的方法和系统
CN101001435A (zh) * 2007-01-15 2007-07-18 华为技术有限公司 获取监听对象物理位置信息的方法及装置、位置服务器
CN101325781A (zh) * 2007-06-15 2008-12-17 华为技术有限公司 一种合法监听方法、系统和网络设备
WO2010088963A1 (en) * 2009-02-06 2010-08-12 Telefonaktiebolaget Lm Ericsson (Publ) Lawful interception and data retention of messages

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1832098B1 (en) * 2004-12-29 2015-04-15 Telefonaktiebolaget L M Ericsson (Publ) Lawful interception of dss1 based virtual private network
TW200644495A (en) * 2005-06-10 2006-12-16 D Link Corp Regional joint detecting and guarding system for security of network information

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1870683A (zh) * 2005-11-22 2006-11-29 华为技术有限公司 一种实现合法监听的方法
CN1929414A (zh) * 2006-10-12 2007-03-14 华为技术有限公司 设置监听用户的方法和系统
CN101001435A (zh) * 2007-01-15 2007-07-18 华为技术有限公司 获取监听对象物理位置信息的方法及装置、位置服务器
CN101325781A (zh) * 2007-06-15 2008-12-17 华为技术有限公司 一种合法监听方法、系统和网络设备
WO2010088963A1 (en) * 2009-02-06 2010-08-12 Telefonaktiebolaget Lm Ericsson (Publ) Lawful interception and data retention of messages

Also Published As

Publication number Publication date
CN102685737B (zh) 2016-08-03
CN102685737A (zh) 2012-09-19

Similar Documents

Publication Publication Date Title
CN100370832C (zh) 一种多媒体监控系统
US20080276294A1 (en) Legal intercept of communication traffic particularly useful in a mobile environment
KR20150063906A (ko) M2m 환경에서 사용 가능한 장치를 검색하는 방법 및 장치
Li et al. A mobile phone based WSN infrastructure for IoT over future internet architecture
WO2011088693A1 (zh) 一种在公共设备上接入网络的方法及系统
WO2008014716A1 (fr) Système fournissant la position d'un terminal et méthode associée
WO2016070633A1 (zh) 上网日志生成方法和装置
EP2218214A1 (en) Network location service
WO2011088694A1 (zh) 一种在公共设备上接入网络的方法及系统
WO2013071821A1 (zh) 一种安全策略下发方法及实现该方法的网元和系统
EP2512089A1 (en) Method and system for accessing network through public equipment
CN1771744B (zh) 用于更新可移动节点位置信息的方法和设备
KR20150067037A (ko) M2m 시스템에서 구독의 기준정보 최적화 방법 및 장치
WO2012119464A1 (zh) 合法监听的方法和系统
CN112887339B (zh) 一种终端设备的分布式分组管理方法
CN101014047A (zh) 一种定位多媒体子系统网络攻击来源的方法、装置及防攻击系统
Atkinson et al. The personnel distributed environment
KR101013274B1 (ko) 무선 데이터 통신 환경에서 이상호 차단 방법 및 시스템
WO2012075768A1 (zh) 身份位置分离网络的监听方法和系统
KR20150014345A (ko) 요청 메시지의 신뢰성을 확보하는 방법 및 장치
KR20150014348A (ko) 개인 device의 사용정보를 이용한 맞춤형 M2M 서비스 제공 방법 및 시스템
JP2002183009A (ja) インターネット網で個人識別子による通信サービスを提供する装置及びその方法
WO2012089030A1 (zh) 一种多种接入方式接入网络的方法、接入设备和认证设备
WO2011150869A1 (zh) 一种ims网络中合法监听的布控方法及系统
KR20150066401A (ko) M2m 환경에서의 데이터 적용기술

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11860459

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11860459

Country of ref document: EP

Kind code of ref document: A1