EP1374533A2

Facilitating legal interception of ip connections

Abstract

A method of facilitating the legal interception of IP connections, where two or more terminals can communicate with each other over the Internet using IPSec to provide security. The method comprises allocating to each terminal T 1 ,T 2 a public/private key pair for use in negotiating IKE and IPSec Security Associations (SAs) with other terminals. Where a terminal T 1 ,T 2 is coupled to the Internet via an access network 1,2 , the private key of that terminal is stored within the access network at an interception server S 1 ,S 2 . When an IP connection is initiated to or from a terminal T 1 ,T 2 on which a legal interception order has been placed, the private key stored for that terminal T 1 ,T 2 within the access network 1,2 is used to intercept the connection.

Term

Term ended

Projected expiry passed 28 March 2022, 4.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

19 claims: 5 independent, 14 dependent

  1. 1
    Claims of equivalent WO 02082769 A2 Claims 1. A method of facilitating the legal interception of network connections, where two or more terminals can communicate with each other over insecure networks using a standard security protocol to provide a secure session, the method comprising:allocating to each terminal at least one public/private key pair for use in negotiating session encryption keys with other terminals;where a terminal is coupled to an interconnecting network via an access network, storing the private key of that terminal within the access network;and when a connection is initiated to or from a terminal on which a legal interception order has been placed, using the private key stored for that terminal within the access network to intercept the communication.
  2. 5
    A method according to any one of the preceding claims, wherein said insecure network is the Internet.
  3. 15
    A method according to any one of the preceding claims and comprising storing the public/private key pair allocated to a terminal in a memory of or coupled to the terminal in such a way that the user of the terminal cannot alter the private key without the consent of the operator of the relevant access network.
  4. 18
    A method according to any one of the preceding claims and comprising storing in the access network terminal security capabilities.
  5. 19
    A server for use in intercepting IP connections between two or more terminals, the server comprising a memory for storing the private keys of public/private key pairs of respective terminals, and processing means for identifying when legal interception is to be carried out on a connection to or from a terminal, and for intercepting that connection using the private key of the terminal.