Method and system for communications monitoring
Abstract
The present invention provides for a system, and related method, for use in the monitoring of communications traffic, comprising the step of recording the said traffic and storing the recorded traffic in an encrypted data format such that the data can be decrypted only by means of keys that exhibit restricted availability.

Term
Term ended
Expired 21 August 2023, 3.1 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
14 claims: 9 independent, 5 dependent
- 1A method for use in the monitoring of communications traffic, comprising the steps of:connecting a recorder (16) to a telecommunications switch (14) to record packet-data communication traffic received from, and passing through, the said switch;encrypting the packet-data communication traffic at an encryption engine (18) communicatively connected to the recorder after the packet-data communication traffic has passed through the said switch to create encrypted data;recording the encrypted data and storing the encrypted data such that the data can be decrypted only by means of keys (22) that exhibit restricted availability, characterized in that a said key includes embedded clauses such that access to an encrypted data record is only allowed where a match is made between search criteria associated with the embedded clauses and the encrypted data record.
- 2A method as claimed in Claim 1 and including the step of employing a spare disk and/or CPU capacity within a telecommunications system.
- 5A method as claimed in any preceding claim, including the step of logging all accesses to the stored data to an encrypted secure audit trail.
- 6A method as claimed in any preceding claim including a tamper detection reference within the encrypted data.
- 7A method as claimed in any preceding claim, including the step of monitoring all the available communications traffic.
- 8A method as claimed in Claim 7, wherein storing the recorded traffic comprises storing all of the recorded traffic.
- 9A method as claimed in any preceding claim, wherein the communications traffic to be recorded comprises traffic through a telecommunications switch, router or gateway.
- 10A method as claimed in any preceding claim, including encrypting details relating to the communications traffic and storing the said encrypted details for subsequent access.
- 11A method as claimed in any preceding claim including authorising use of the required decryption key in a restricted manner.
- 12A method as claimed in Claim 10 wherein storing the recorded traffic comprises encrypting the details.
- 13A method as claimed in Claim 12 wherein the details comprise at least one of a source of the content, a destination of the contest, and a time frame.
- 14A system (10) comprising means (16, 18, 20, 22) for executing the method of any preceding claim.
Independent claims14
38 paragraphs, as filed
0001The present invention relates to a method and system for communications monitoring and, in particular, to a method and system for use in the surveillance of communications traffic.
0002With the increase in commercial transactions conducted via the internet, or via a telephone call, commercial organisations have increasingly turned to recording technology to assist with monitoring the performance of their customer service employees who, quite commonly, might be located within a call centre designed specifically to handle a large number and variety of telephone enquires and transactions. It is therefore now quite common for such transactions to be monitored and prior warnings are given providing a customer with a clear indication that the conversation may be recorded for training and quality-control purposes. The recording of such transactions can also prove to be of assistance in meeting regularity requirements and enhancing the possibilities for dispute resolution.
0003The employment of such recording techniques has however remained very much in the commercial environment since the indiscriminate recording of, for example, telephone communications traffic in general, and including mere public communications traffic, carries with it far greater data protection and privacy issues.
0004The paper 'Wiretapping the Internet' by Antonelli, C.J. and Honeyman P., suggests to create a full encrypted record of all activity on a network and to encrypt packets with address-dependent keys.
0005Although it is known for law enforcement agencies to obtain authorisation to place wire-taps in order to monitor, for example, telephone communications involving a likely criminal source, such authorisation is granted only once particular criteria concerning the level of suspicion of the criminal source are met: which, of course somewhat disadvantageously can often prove to be after incriminating communications traffic has already been sent.
0006The present invention seeks to overcome such disadvantages with regard to the time-lag that can currently exist when seeking to monitor communications traffic and with regard to the likely occurrence of potentially incriminating traffic and the initiation of a monitoring/surveillance program.
0007According to claim 1 of the present invention, there is provided a method for use in the monitoring of communications traffic, comprising the steps of connecting a recorder to a telecommunications switch to record packet-data communication traffic received from, and passing through, the said switch; encrypting the packet-data communication traffic at an encryption engine communicatively connected to the recorder after the packet-data communication traffic has passed through the said switch to create encrypted data; recording the encrypted data and storing the encrypted data such that the data can be decrypted only by means of keys that exhibit restricted availability, characterized in that a said key includes embedded clauses such that access to an encrypted data record is only allowed where a match is made between search criteria associated with the embedded clauses and the encrypted data record. Claim 14 describes a corresponding system.
0008The method is particularly advantageous since it can allow for the recordal and encryption of all communications traffic so that potentially incriminating traffic from a later-identified criminal source has already been recorded and the restricted availability of the decryption keys can then allow for a means for accessing the potentially incriminating communications evidence in a same controlled manner as known wire-taps are currently permitted.
0009Preferably, the method can be implemented employing spare disk space, and/or CPU capacity within a currently existing telecommunications system. This has the particular advantage of allowing for implementation of the method at negligible additional cost.
0010Also, the decryption keys arranged to be issued in a secure and authorized manner can be arranged to contain encrypted search conditions serving to restrict their scope of use. For example, a "where" clause can be embedded within the decryption key so as to allow access only to those encrypted data records that match the authorized search criteria.
0011Further, the decryption key can contain discreet levels of authorisation for access to the encrypted data.
0012According to a further advantage, the decryption keys can be arranged to be used only once so as to advantageously prevent unauthorised subsequent searches through the recorded data.
0013Advantageously, the method includes the steps of logging all attempted accesses to the stored data. This can advantageously provide for secure and encrypted audit trail accessible only by means of specially granted keys available only to reviewing/auditing bodies rather than, for example, law enforcement agencies.
0014According to a further feature, the method can provide for the inclusion of tamper detection reference data.
0015Advantageously, the method is arranged to record all communications traffic and to likewise store all of the recorded traffic.
0016In particular, the method is applicable to communications traffic through a node such as a telecommunications switch, router or gateway.
0017Preferably, the method also includes the step of encrypting details concerning the communications traffic, which details are then also stored.
0018It will therefore be appreciated that the present invention can advantageously provide for a method for use in the monitoring of communications traffic as noted above and including the step of restricting the availability of the decryption keys in accordance with, in particular, legislative requirements.
0019Another aspect of the invention provides a system arranged to operate in accordance with the method steps outlined above.
0020The invention is described further hereinafter by way of example only, with reference to the accompanying drawing which comprises a schematic block diagram of a telecommunications monitoring system according to an embodiment of the present invention.
0021Turning now to the accompanying drawing, there is illustrated a telecommunications monitoring system 10 for monitoring communications traffic 12 travelling through, for example, a telecommunications switch 14. The system includes a recording device 16 that taps into the switch 14 so as to record all of the traffic passing there-through. The recorded traffic is then delivered to an encryption engine 18 which can employ any one or more of the appropriate currently available encryption schemes and in particular one or more of the 128-bit currently available encryption schemes.
0022The encrypted data is then delivered to the storage means 20 in which it can be stored for any appropriate amount of time, if not indefinitely, in accordance with legislative requirements. The encrypted data within the storage means 20 can be accessed and decrypted by means of decryption keys 22.
0023Typically, the available storage space can be recycled so as to provide a "first in first out" (FIFO) buffer of recordings which are retained for the maximum possible duration before being overwritten with more recent recordings.
0024However, an authorising system 24 is in place, which can be controlled by any appropriate authorising, or legislative body, such that the decryption keys 22 are only made available should specific criteria be met
0025As an example, the decryption keys can be issued in a manner similar to currently existing schemes for authorising wire-taps.
0026The availability of so-called wire-tap warrants is currently closely controlled for example in the US by means of the Federal Communications Commission by means of the Communications Assistance for Law Enforcement Act 1994 whereas similar legislation has been introduced in the United Kingdom by means of the Regulation of Investigatory Powers Act 2000.
0027Such systems can advantageously allow for separate levels of authorisation such as the so-called "pen and trace" warrant or the "wire-tap" warrant controlled in the US under the above-mentioned Communication Assistance for Law Enforcement Act 1994.
0028The decryption keys can themselves contain encrypted search conditions so as to satisfactorily reduce, or eliminate, the chance of abuse and error. That is, if a warrant is issued to allow for the review of the calls only from one particular source, to one particular destination, or only calls within a particular time frame, appropriate clauses can be embedded within the decryption key so that only those encrypted records that match the quite specific criteria are made available.
0029Thus, as will be appreciated, and with particular reference to the enclosed drawing, the present invention provides for a particular advantageous concept in communications monitoring in which there is a no danger of important communications evidence being lost due to delays in seeking appropriate surveillance authorisation since the obtaining of such authorisation is time-shifted to a point at which the recording is made, and the granting of the authorisation relates merely to accessing a secure recording thereof.
0030It should be appreciated that the present invention is not restricted to the details of the foregoing embodiments. For example, the concept can be applied to any appropriate form of communication, and indeed the communication of any appropriate data and whether comprising audio, modem, fax or data network packet data such that, for example, PC terminal activity can also be monitored for subsequent review if authorised.
0031With regard to realisation of the concept it should be noted that telephone switch manufacturers could readily embed the capability of recording all calls in next generation switches for a few percent of the total cost of the system.
0032All calls could be recorded using heavy-weight encryption so as to maintain public confidence that the same controls were in place to grant access to recordings that are used today to authorise wire-tapping, i.e. decryption keys are only issued as a warrant is granted. Initially it may only be viable to retain such recordings for a few days although increasingly inexpensive storage capabilities will assist in increasing such periods.
0033This capability could be added to every cellular base station, every central office switch and every corporate switch.
0034The ability to go back through all calls made after the event by identified terrorists can have a significant effect on follow-up operations.
0035Whilst the concept of the wire-tapping of telephone lines is well known, the use of a PC can also be monitored.
0036For example, while programmers first introduced "log files" into specific applications as diagnostic aids to help them understand how someone broke their program, and from the concept of being able to note everything that happened on a PC goes back to the venerable tools like "PC Anywhere" it was a fairly small step from there to keeping a log file of everything that happened on the screen during your session.
0037More recently, this concept has been increasingly used in call centres to review maybe 1 % of calls to see how customer service reps are using the computer system during phone calls.
0038Increasing amounts of business are conducted on mixed channels - with a caller on the line also looking at his browser where a staff member is highlighting terms and conditions on a competitor's web-site. Regulatory bodies have only just began to be aware of potential loop-holes in rules that insist on voice recording only. Where communication involves multiple channels it is vital that all channels are recorded together, archived together and replayable together.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US5414771A | Cites | United States of America |
| C.J. ANTONELLI, P. HONEYMAN: "Wiretapping the internet" SPIE SYMPOSIUM ON ENABLING TECHNOLOGIES FOR LAW ENFORCEMENT AND SECURITY, HELD ON 5 NOV 2000, RETRIEVED FROM INTERNET, WWW.SPIEDL.COM, vol. 4232, February 2001 (2001-02), pages 75-84, XP002262366 | Non-patent | – |
10 members in 7 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0219493 | United Kingdom | – | |
| 0219493 | United Kingdom | A | |
| 0303668 | United Kingdom | W |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| GB0219493D0 | United Kingdom | D0 | |
| WO2004019585A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003259339A1 | Australia | A1 | |
| EP1530865A1 | European Patent Office (EPO) | A1 | |
| US2006123106A1 | United States of America | A1 | |
| EP1530865B1This record | European Patent Office (EPO) | B1 | |
| US7925889B2 | United States of America | B2 | |
| AT504145T | Austria | T | |
| ATE504145T1 | Austria | T1 | |
| DE60336564D1 | Germany | D1 |
57 legal events, as 7 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Expiry of rightR071 | R071 | DE | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04L0029060000R079 | R079 | DE | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Discontinued in the netherlands as no translation has been filedVDEP | VDEP | NL | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1530865
- Application
- 37925104
Titles3
- German
- VERFAHREN UND SYSTEM ZUR KOMMUNIKATIONSÜBERWACHUNG
- English
- METHOD AND SYSTEM FOR COMMUNICATIONS MONITORING
- French
- PROCEDE ET SYSTEME PERMETTANT DE SURVEILLER DES TELECOMMUNICATIONS
Classification
- CPC, 3
- H04M3/42221
- G06F2221/2101
- H04L63/0428
- IPC, 5
- H04L29 06
- G06F1 00
- H04M3 22
- H04L12 26
- H04M3 42
Designated states27
- Contracting states, 27
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
and 3 moreShow fewer
- Slovenia
- Slovakia
- Türkiye