EP1374533B1

Facilitating legal interception of ip connections

Abstract

A method of facilitating the legal interception of IP connections, where two or more terminals can communicate with each other over the Internet using IPSec to provide security. The method comprises allocating to each terminal T 1 ,T 2 a public/private key pair for use in negotiating IKE and IPSec Security Associations (SAs) with other terminals. Where a terminal T 1 ,T 2 is coupled to the Internet via an access network 1,2 , the private key of that terminal is stored within the access network at an interception server S 1 ,S 2 . When an IP connection is initiated to or from a terminal T 1 ,T 2 on which a legal interception order has been placed, the private key stored for that terminal T 1 ,T 2 within the access network 1,2 is used to intercept the connection.

EP1374533B1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Expired 28 March 2022, 4.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

18 claims: 18 independent, 0 dependent

  1. 1
    A method of facilitating the legal interception of network connections, where two or more terminals can communicate with each other over insecure networks using a standard security protocol to provide a secure session, the method comprising:allocating to each terminal at least one public/private key pair for use in negotiating session encryption keys with other terminals;where a terminal is coupled to an interconnecting network via an access network, storing the private key of that terminal within the access network;and    when a connection is initiated to or from a terminal on which a legal interception order has been placed, using the private key stored for that terminal within the access network to intercept the communication,    characterised in that    the access network for a terminal interposes itself between that terminal and a remote node during the negotiation of session encryption keys between the terminal and the remote node, such that the access network has a knowledge of negotiated session encryption keys. Méthode pour faciliter l'interception légale de connexions de réseau, dans laquelle deux terminaux ou plus peuvent communiquer entre chacun d'eux sur réseaux réseau non sûrs, en utilisant un protocole de sécurité standard pour procurer une session sûre, la méthode comprenant : l'attribution à chaque terminal d'au moins une paire de clés publique/privée, pour utilisation dans des négociations de clés de cryptage de session avec d'autres terminaux ;dans laquelle un terminal est couplé à un réseau d'interconnexion via un réseau d'accès, l'enregistrement de la clé privée du terminal à l'intérieur du réseau d'accès ;et lorsqu'une connexion est initialisée à destination ou en provenance d'un terminal sur lequel un ordre d'interception légal a été placé, l'utilisation de la clé privée enregistrée pour ce terminal à l'intérieur du réseau d'accès pour intercepter la communication, caractérisée en ce que le réseau d'accès à un terminal s'interpose entre ce terminal et un noeud éloigné au cours de la négociation de clés de cryptage de session entre le terminal et le noeud éloigné, de façon que le réseau d'accès a connaissance des clés de cryptage de session négociées. Verfahren zur Vereinfachung der rechtmäßigen Überwachung von Netzverbindungen, bei dem zwei oder mehr Endgeräte miteinander über unsichere Netze kommunizieren können, indem ein Standardsicherheitsprotokoll zum Bereitstellen einer sicheren Sitzung verwendet wird, wobei das Verfahren folgendes umfaßt: - Zuordnen wenigstens eines öffentlichen/privaten Schlüsselpaares an jedes Endgerät zur Verwendung in der Verhandlung von Sitzungsverschlüsselungsschlüsseln mit anderen Endgeräten;- wenn ein Endgerät über ein Zugangsnetz mit einem Verbindungsnetz verknüpft ist, Speichern des privaten Schlüssels dieses Endgerätes im Zugangsnetz;und- wenn eine Verbindung zu oder von einem Endgerät initiiert wird, für das ein rechtmäßiger Überwachungsauftrag besteht, Verwenden des privaten Schlüssels, der für dieses Endgerät im Zugangsnetz gespeichert ist, um die Kommunikation zu überwachen,dadurch gekennzeichnet, daß sich das Zugangsnetz für das Endgerät zwischen diesem Endgerät und einem Fernknoten während der Verhandlung von Sitzungsverschlüsselungsschlüsseln zwischen dem Endgerät und dem Fernknoten derart zwischenschaltet, daß das Zugangsnetz Kenntnis von verhandelten Sitzungsverschlüsselungsschlüsseln hat.
  2. 2
    A method according to claim 1, wherein said access network is one of a wireless telecommunication network, a fixed line telephone network, and a cable network. Méthode selon la revendication 1, dans laquelle ledit réseau d'accès est l'un d'un réseau de télécommunications sans fil, d'un réseau de téléphonie à ligne fixe, et d'un réseau de câblé. Verfahren nach Anspruch 1, wobei das Zugangsnetz entweder ein drahtloses Telekommunikationsnetz, ein Festtelefonnetz oder ein Kabelnetz ist.
  3. 3
    A method according to claim 2, where the access network is a wireless telecommunication networks, and the private keys for subscribers are stored at a network switch or at a server coupled to a switch. Méthode selon la revendication 2, dans laquelle le réseau d'accès est un réseau de télécommunications sans fil, et les clés privées pour abonnés sont enregistrées au niveau d'un commutateur de réseau ou d'un serveur couplé à un commutateur. Verfahren nach Anspruch 2, wobei das Zugangsnetz ein drahtloses Telekommunikationsnetz ist und die privaten Schlüssel für Teilnehmer in einer Netzvermittlungsstelle oder einem mit einer Vermittlungsstelle verknüpften Server gespeichert sind.
  4. 4
    A method according to any one of the preceding claims, wherein said insecure network is the Internet. Méthode selon l'une des revendications qui précèdent, dans laquelle ledit réseau non sûr est l'Internet. Verfahren nach einem der vorangegangenen Ansprüche, wobei das unsichere Netz das Internet ist.
  5. 5
    A method according to claim 4, wherein said secure session is established using IPSec. Méthode selon la revendication 4, dans laquelle ladite session sûre est établie en utilisant IPSec. Verfahren nach Anspruch 4, wobei die sichere Sitzung durch Verwendung des IPSec aufgebaut wird.
  6. 6
    A method according to claim 5, wherein said public/private key pair is used to negotiate IKE and IPSec Security Associations hereinafter referred to as SA, comprising said session encryption keys. Méthode selon la revendication 5, dans laquelle la paire de clés publique/privée est utilisée pour négocier des Associations IKE et IPSec Security, appelées ci-après SA, comprenant lesdites clés de cryptage de session. Verfahren nach Anspruch 5, wobei das öffentliche/private Schlüsselpaar zum Verhandeln von IKE und IPSec Security Associations, im folgenden als SAs bezeichnet, verwendet wird, die die Sitzungsverschlüsselungsschlüssel umfassen.
  7. 7
    A method according to claim 6, wherein, following the receipt of a request for an ISAKMP SA at the access network of a terminal initiating an IP connection, the access network negotiates an ISAKMP SA with a remote node on behalf of the initiating terminal, and passes the SA parameters to the initiating terminal over a secure connection. Méthode selon la revendication 6, dans laquelle, après la réception d'une demande pour une ISAKMP SA au niveau du réseau d'accès d'un terminal initialisant une connexion IP, le réseau d'accès négocie une ISAKMP SA avec un noeud éloigné pour le compte du terminal initialisant, et passe les paramètres SA au terminal initialisant via une connexion sûre. Verfahren nach Anspruch 6, wobei nach dem Empfang einer Anforderung für eine ISAKMP SA im Zugangsnetz eines eine IP-Verbindung initiierenden Endgerätes das Zugangsnetz eine ISAKMP SA mit einem Fernknoten für das initiierende Endgerät verhandelt und die SA-Parameter über eine sichere Verbindung an das initiierende Endgerät übergibt.
  8. 8
    A method according to claim 7, wherein, once the ISAKMP SA has been established, if the initiating terminal sends a request for the establishment of IPSec SAs towards a destination terminal, the access network determines whether or not a legal interception order has been placed on that terminal or on the terminal to which the initiating terminal wishes to connect and, if such an order has been placed, the access network interposes itself between the terminal and the remote node during the negotiation of a pair of IPSec SAs. Méthode selon la revendication 7, dans laquelle, une fois que la ISAKMP SA a été établie, si le terminal initialisant envoie une demande d'établissement d'IPSec SA vers un terminal de destination, le réseau d'accès détermine si un ordre légal d'interception a été placé ou pas sur ce terminal ou sur le terminal auquel le terminal initialisant souhaite se connecter et, si un tel ordre a été placé, le réseau d'accès s'interpose entre le terminal et le noeud éloigné au cours d'une négociation d'une paire d'IPSec SA. Verfahren nach Anspruch 7, wobei, sobald die ISAKMP SA aufgebaut worden ist, und wenn das initiierende Endgerät eine Anforderung zum Aufbauen von IPSec SAs an ein Zielendgerät sendet, das Zugangsnetz bestimmt, ob für dieses Endgerät oder das Endgerät, mit dem das initiierende Endgerät eine Verbindung wünscht, ein rechtmäßiger Überwachungsauftrag besteht oder nicht, und, wenn ein solcher Auftrag besteht, sich das Zugangsnetz zwischen dem Endgerät und dem Fernknoten während der Verhandlung eines Paares von IPSec SAs zwischenschaltet.
  9. 9
    A method according to claim 6 and comprising:receiving at an access network, the "first" network, a request for establishment of an ISAKMP SA from an initiating terminal;forwarding the request to the access network, the "second" network, of the other terminal;making a decision at the second network on legal interception;andif legal interception is required, negotiating an ISAKMP SA directly between the second network and the initiating terminal and negotiating a second ISAKMP SA directly between the first access network and the destination terminal. Méthode selon la revendication 6 et comprenant : la réception au niveau d'un réseau d'accès, du « premier » réseau, une demande d'établissement d'une ISAKMP SA à partir d'un terminal initialisant ;l'envoi de la demande au réseau d'accès, le « second » réseau, de l'autre terminal ;la prise d'une décision au niveau du second réseau sur l'interception légale ;etsi une interception légale est requise, la négociation d'une ISAKMP SA directement entre le second réseau et le terminal initialisant, et la négociation d'une seconde ISAKMP SA directement entre le premier réseau d'accès et le terminal de destination. Verfahren nach Anspruch 6, umfassend - Empfangen einer Anforderung zum Aufbauen einer ISAKMP SA von einem initiierenden Endgerät bei einem Zugangsnetz, dem "ersten" Netz,- Weiterleiten der Anforderung an das Zugangsnetz, das "zweite" Netz, des anderen Endgerätes;- Treffen einer Entscheidung im zweiten Netz über das rechtmäßige Überwachen;und- wenn rechtmäßiges Überwachen erforderlich ist, Verhandeln einer ISAKMP SA direkt zwischen dem zweiten Netz und dem initiierenden Endgerät und Verhandeln einer zweiten ISAKMP SA direkt zwischen dem ersten Zugangsnetz und dem Zielendgerät.
  10. 10
    A method according to claim 9, wherein when the fist access network receives from the initiating terminal a request for the establishment of IPSec SAs, the second access network negotiates a pair of IPSec SAs directly with the initiating terminal whilst the first access node negotiates a second pair of FPSec SAs directly with the destination terminal. Méthode selon la revendication 9, dans laquelle lorsque le premier réseau d'accès reçoit à partir du terminal initialisant une demande d'établissement d'IPSec SA, le second réseau d'accès négocie une paire d'IPSec SA directement avec le terminal initialisant, tandis que le premier noeud d'accès négocie une seconde paire d'IPSec SA directement avec le terminal de destination. Verfahren nach Anspruch 9, wobei, wenn das erste Zugangsnetz von dem initiierenden Endgerät eine Anforderung zum Aufbauen von IPSec SAs empfängt, das zweite Zugangsnetz ein Paar von IPSec SAs direkt mit dem initiierenden Endgerät verhandelt, während der erste Zugriffsknoten ein zweites Paar von IPSec SAs direkt mit dem Zielendgerät verhandelt.
  11. 11
    A method according to any one of claims 1 to 6 and comprising passing a private key of a terminal to be monitored from one access network to another so that one access network is in possession of the private keys of both or all parties involved in an IP connection. Méthode selon l'une des revendications 1 à 6, et comprenant la passation d'une clé privée d'un terminal devant être surveillé à partir d'un réseau d'accès à l'autre, de sorte qu'un réseau d'accès est en possession des clés privées des deux ou de toutes les parties impliquées dans une connexion IP. Verfahren nach einem der vorangegangenen Ansprüche 1 bis 6, umfassend das Übergeben eines privaten Schlüssels eines zu überwachenden Endgerätes von einem Zugangsnetz zu einem anderen, so daß ein Zugangsnetz im Besitz der privaten Schlüssel von beiden oder sämtlichen in einer IP-Verbindung involvierten Parteien ist.
  12. 12
    A method according to claim 11, wherein said private key is passed from one access network to another without explicitly disclosing the private key to the receiving access network. Méthode selon la revendication 11, dans laquelle la clé privée est passée d'un réseau d'accès à l'autre sans dévoiler explicitement la clé privée au réseau d'accès récepteur. Verfahren nach Anspruch 11, wobei der private Schlüssel von einem Zugangsnetz an ein anderes übergeben wird, ohne den privaten Schlüssel dem empfangenden Zugangsnetz explizit zu offenbaren.
  13. 13
    A method according to claim 12, wherein said private key is passed from one access network to another as part of an executable code which can be executed by the receiving network to facilitate negotiation of session encryption keys with a terminal using the receiving network as access network. Méthode selon la revendication 12, dans lequel la clé privée est passée d'un réseau d'accès à l'autre en tant que partie d'un code exécutable qui peut être exécuté par le réseau récepteur pour faciliter la négociation de clés de cryptage de sessions avec un terminal utilisant le réseau récepteur en tant que réseau d'accès. Verfahren nach Anspruch 12, wobei dieser private Schlüssel von einem Zugangsnetz an ein anderes als Teil eines ausführbaren Codes übergeben wird, der von dem empfangenden Netz ausgeführt werden kann, um die Verhandlung von Sitzungsverschlüsselungsschlüsseln mit einem Endgerät zu erleichtern, das das empfangende Netz als Zugangsnetz verwendet.
  14. 14
    A method according to any one of the preceding claims and comprising storing the public/private key pair allocated to a terminal in a memory of or coupled to the terminal in such a way that the user of the terminal cannot alter the private key without the consent of the operator of the relevant access network. Méthode selon l'une des revendications qui précèdent, et comprenant l'enregistrement de la paire de clés publique/privée attribuée à un terminal dans une mémoire du ou couplé au terminal de telle façon que l'utilisateur du terminal ne peut pas altérer la clé privée sans le consentement de l'opérateur du réseau d'accès important. Verfahren nach einem der vorangegangenen Ansprüche, umfassend das Speichern des öffentlichen/privaten Schlüsselpaares, das einem Endgerät in einem Speicher des Endgerätes oder mit diesem verknüpft derart zugeordnet ist, daß der Benutzer des Endgerätes den privaten Schlüssel nicht ohne die Zustimmung des Betreibers des relevanten Zugangsnetzes ändern kann.
  15. 15
    A method according to any one of claims 1 to 6, wherein a node within the access network for a terminal negotiates session encryption keys for both commununication directions, on behalf of that terminal, with a remote terminal or a node within the access network for that remote terminal. Méthode selon l'une des revendications 1 à 6, dans laquelle un noeud à l'intérieur du réseau d'accès pour un terminal négocie des clés de cryptage de session pour les deux directions de communications, pour le compte de ce terminal, avec un terminal éloigné ou un noeud à l'intérieur du réseau d'accès pour ce terminal éloigné. Verfahren nach einem der Ansprüche 1 bis 6, wobei ein Knoten innerhalb des Zugangsnetzes für ein Endgerät Sitzungsverschlüsselungsschlüssel für beide Kommunikationsrichtungen im Namen dieses Endgerätes mit einem entfernten Endgerät oder einem Knoten innerhalb des Zugangsnetzes für dieses entfernte Endgerät verhandelt.
  16. 16
    A method according to any one of claims 1 to 6, wherein nodes within the access networks of a pair of terminals negotiate session encryption keys with the respective remote terminals, and during interception of a connection each node intercepts communications in one direction, with at least one of the nodes echoing intercepted communications to the other of the nodes. Méthode selon l'une des revendications 1 à 6, dans laquelle des noeuds situés à l'intérieur du réseau d'accès d'une paire de terminaux négocie des clés de cryptage de session avec les terminaux éloignés respectifs, et durant l'interception d'une connexion, chaque noeud intercepte des communications dans une direction, avec au moins l'un des noeuds répercutant l'écho de communications interceptées aux autres des noeuds. Verfahren nach einem der Ansprüche 1 bis 6, wobei Knoten innerhalb des Zugangsnetzes eines Endgerätepaares Sitzungsverschlüsselungsschlüssel mit den jeweiligen entfernten Endgeräten verhandeln, und, während der Überwachung einer Verbindung, jeder Knoten Kommunikationen in einer Richtung überwacht, wobei wenigstens einer der Knoten überwachte Kommunikationen an die anderen der Knoten rückmeldet.
  17. 17
    A method according to any one of the preceding claims and comprising storing in the access network terminal security capabilities. Méthode selon l'une des revendications qui précèdent, et comprenant l'enregistrement dans le réseau d'accès, des capacités de sécurité de terminaux. Verfahren gemäß einem der vorangegangenen Ansprüche, umfassend das Speichern von Sicherheitsfähigkeiten des Endgerätes im Zugangsnetz.
  18. 18
    A server for use in intercepting IP connections between two or more terminals, the server comprising a memory for storing the private keys of public/private key pairs of respective terminals, first processing means for identifying when legal interception is to be carried out on a connection to or from a terminal, characterised in that it comprises second processing means for interposing the server between that terminal and a remote node during the negotiation of session encryption keys between the terminal and the remote node, such that the access network has a knowledge of negotiated session encryption keys, and third processing means for intercepting the connection using the private key of the terminal. Server zur Verwendung zur Überwachung von IP-Verbindungen zwischen zwei oder mehr Endgeräten, wobei der Server einen Speicher zum Speichern der privaten Schlüssel von öffentlichen/privaten Schlüsselpaaren der jeweiligen Endgeräte umfaßt, eine erste Verarbeitungseinrichtung zum Identifizieren, wann ein rechtmäßiges Überwachen einer Verbindung zu oder von einem Endgerät ausgeführt werden soll, dadurch gekennzeichnet, daß er eine zweite Verarbeitungseinrichtung zum Zwischenschalten des Servers zwischen das Endgerät und einem Fernknoten während der Verhandlung von Sitzungsverschlüsselungsschlüsseln zwischen dem Endgerät und dem Fernknoten umfaßt, so daß das Zugangsnetz Kenntnis über verhandelte Sitzungsverschlüsselungsschlüssel hat, und eine dritte Verarbeitungseinrichtung zum Überwachen der Verbindung durch Verwenden des privaten Schlüssels des Endgerätes. Serveur pour utilisation dans l'interception de connexions IP entre deux terminaux ou plus, le serveur comprenant une mémoire pour enregistrer les clés privées de paires de clés publique/privée de terminaux respectifs, des premiers moyens de traitement pour identifier lorsqu'une interception légale doit être exécutée sur une connexion à destination ou en provenance d'un terminal, caractérisée en ce qu'il comprend des seconds moyens de traitement pour interposer le serveur entre ce terminal et un noeud éloigné durant la négociation de clés de cryptage de session entre le terminal et le noeud éloigné, de façon à ce que le réseau d'accès ait connaissance de clés de cryptage de session négociées, et des troisième moyens de traitement pour intercepter la connexion utilisant la clé privée du terminal.
Independent claims18