Lawful Intercept in VoIP Network

IntroductionAdministration Function (ADMF) This function handles
Lawful Intercept (LI) is a requirement placed uponthe serving of interception orders and communicates
service providers to provide legally sanctioned officialwith the IIFs and MF though an Internal Network
access to private communications. In the existing PublicInterface.
Telephone Network, Lawful Intercept is performed byImplementing LI within an VoIP Network
applying a physical 'tap' on the telephone line of theOne of the primary problems faced when managing
target in response to a warrant from a LawVoIP calls is the separation of the signalling and media
Enforcement Agency (LEA). However, Voice over IPstreams. It is quite possible that the two streams may
(VoIP) has enabled the mobility of the end-user, so it istake completely different paths through the network. In
no longer possible to guarantee the interception of callsaddition, even when they do pass through the same
based on tapping a physical line.device, it may not be aware of the relationship
Whilst the detailed requirements for LI may differ frombetween the streams. Some devices within the
one jurisdiction to another, the general requirementsnetwork are however specifically designed to
are the same. The LI system must provide transparentunderstand and manage the separate signalling and
interception of specified traffic only and the subjectmedia streams - session border controllers. Typically
must not be aware of the interception. The servicelocated at the borders of the network, they receive
provided to other users must not be affected duringIntercept Related Information from the signalling stream
interception.and Contents of Communication directly from the
Architecture Overviewmedia stream.
Although the detail of LI may vary from country toConclusion
country we can describe the general requirements andIt has become clear that VoIP services will be
also explain much of the common terminology used.expected to provide Lawful Intercept capabilities to the
The primary purpose of the service provider networksame level experienced in the PSTN. The FCC in
is to enable private communications betweenNorth America has mandated that both emergency
individuals; any LI functionality built into the networkcalls and Lawful Intercept must be available. Whilst not
must not affect the normal service to those individuals.all countries mandate this capability, any network
The interfaces between the PTN and the Lawoperator building a publicly available voice or multimedia
Enforcement Monitoring Facility (LEMF) areover IP service today will need to plan a network
standardised within a particular territory.which is flexible enough to implement these regulatory
LI deals with two 'products', these are:services in the future.
- Contents of Communications (CC): exactly what itTerminology
sounds like, the voice, video or message contents.ADMF Administration Function
- Intercept Related Information (IRI): information aboutCALEA Communications Assistance for Law
the source and destination of the call etc. EuropeanEnforcement Act
requirements are often based on the ETSI standards.CC Contents of Communication
In North America CALEA (CommunicationsETSI European Telecommunications Standards
Assistance for Law Enforcement Act) requiresInstitute
operators to provide LI capabilities. The networkHI Handover Interface
architecture and handover specifications are based onIIF Internal Intercept Function
the PacketCable(TM) surveillance model, however theINI Internal Networks Interface
architectures are very similar.IRI Intercept Related Information
Basic Elements of LI in a Public Telecom NetworkLEA Law Enforcement Agency
There are three primary elements required within theLEMF Law Enforcement Monitoring Facility
public network to achieve Lawful Intercept, these are:LI Lawful Interception
- An Internal Intercept Function (IIF) located in theMF Mediation Function
network nodes.PSTN Public Switched Telephone Network
- A Mediation Function (MF) between the PTN andPTN Public Telecom Network
LEMF.VoIP Voice over IP
- An Administration Function (ADMF) to manageReferences
orders for interception in the PTN.ETSI TS 101 332 v1.1.1 (2001-08) Telecommunications
Internal Intercept Function (IIF) These functions aresecurity; Lawful Interception (LI) Requirements of Law
located within the network nodes and are responsibleEnforcement Agencies ETSI TR 101 943 V1.1.1
for generating the Intercept Related Information (IRI)(2001-07) Telecommunications security; Lawful
and Contents of Communications (CC).Interception (LI); Concepts of Interception in a Generic
Mediation Function (MF) This function clearly delineatesNetwork Architecture
the PTN from the LEMF. It communicates with the IIFsETSI TS 101 671 V2.8.1 (2003-11) Telecommunications
using Internal Network Interfaces (INIs) which can besecurity; Lawful Interception (LI); Handover interface for
proprietary. The MF communicates to one or morethe lawful interception of telecommunications traffic
LEMFs through locally standardized interfaces: thePKT-SP-ESP1.5-I01-050128; PacketCable(TM) 1.
Handover Interfaces (HI2 and HI3).