GB2374497A

Facilitating legal interception of IP connections

Abstract

A method of facilitating the legal interception of IP connections, where two or more terminals can communicate with each other over the Internet using IPSec to provide security. The method comprises allocating to each terminal T1,T2 a public/private key pair for use in negotiating IKE and IPSec Security Associations (SAs) with other terminals. Where a terminal T1,T2 is coupled to the Internet via an access network 1,2, the private key of that terminal is stored within the access network at an interception server S1,S2. When an IP connection is initiated to or from a terminal T1,T2 on which a legal interception order has been placed, the private key stored for that terminal T1,T2 within the access network 1,2 is used to intercept the connection.

GB2374497A, drawing sheet 1
Sheet 1 of 16

Term

Term ended

Projected expiry passed 3 April 2021, 5.5 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

11 claims: 4 independent, 7 dependent

  1. 1
    A method of facilitating the legal interception of IP connections, where two or more terminals can communicate with each other over the Internet using IPSec to provide security, the method comprising:allocating to each terminal a public/private key pair for use in negotiating IKE and IPSec Security Associations (SAs) with other terminals;where a terminal is coupled to the Internet via an access network, storing the private key of that terminal within the access network;and when an IP connection is initiated to or from a terminal on which a legal interception order has been placed, using the private key stored for that terminal within the access network to intercept the communication.
  2. 5
    A method according to any one of the preceding claims, wherein, following the receipt of a request for an ISAKMP S A at the access network of a terminal initiating an IP connection, the access network negotiates an ISAKMP SA with a remote node on behalf of the initiating terminal, and passes the SA parameters to the initiating terminal over a secure connection.
  3. 7
    A method according to any one of claims 1 to 4 and comprising:receiving at an access network, the “first” network, a request for establishment of an ISAKMP SA from an initiating terminal;forwarding the request to the access network, the “second” network, of the other terminal;making a decision at the second network on legal interception;and if legal interception is required, negotiating an ISAKMP SA directly between the second network and the initiating terminal and negotiating a second ISAKMP SA directly between the first access network and the destination terminal.
  4. 9
    A method according to any one of claims 1 to 4 and comprising passing a private key of a terminal to be monitored from one access network to another so that one access network is in possession of the private keys of both or all parties involved in an IP connection.
  5. 10
    A method according to any one of the preceding claims and comprising storing the public/private key pair allocated to a terminal in a memory of or coupled to the terminal in such a way that the user of the terminal cannot alter the private key without the consent of the operator of the relevant access network.
  6. 11
    A server for use in intercepting IP connections between two or more terminals, 5 the server comprising a memory for storing the private keys of public/private key pairs of respective terminals, and processing means for identifying when legal interception is to be carried out on a connection to or from a terminal, and for intercepting that connection using the private key of the terminal.