USRE45348E

Method and apparatus for intercepting events in a communication system

Claim Score by NHIP

Read claim 26, the broadest

Abstract

An intercept system provides more effective and more efficient compliance with legal intercept warrants. The intercept system can provide any combination of operations that include near-real-time intercept, capture of intercepted data in structured authenticated form, clear text intercept for communications where there is access to encryption keys, cipher text intercept for communications where there is no access to encryption keys, provision of transactional logs to the authorized agency, interception without altering the operation of the target services, and encryption of stored intercepted information.

USRE45348E, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 20 October 2025, 0.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

45 claims: 4 independent, 41 dependent

  1. 1
    A method for intercepting data, comprising:receiving, at a management server, a connection from a remote client, the connection being initiated by the remote client and established outbound from the remote client;negotiating a point-to-point encryption scheme with a remote mobile device, the point-to-point encryption scheme negotiated between the management server and the remote mobile device;receiving, at the management server, a value identifying an intercept target for a legal intercept and an indication that interception is authorized by a warrant, the intercept target corresponding to the remote mobile device;automatically intercepting, at the management server, data received and/or sent by the intercept target identified by the value, wherein data is intercepted without altering operation of email application services that operate on the remote mobile device;inspecting packets having the intercepted data to distinguish end-to-end encrypted information from other information that is encrypted according to the point-to-point encryption scheme negotiated with the remote mobile device;preserving encryption that is included on the end-to-end encrypted information when received while removing encryption that is included on at least a portion of the other information, said other information decrypted using a key obtained during the point-to-point encryption scheme negotiation;and transferring both the decrypted other information and the end-to-end information from the management server to a remote device.
  2. 17
    A communication management system, comprising:a management server configured to receive a connection initiated by a remote client and established outbound from the remote client;the management server configured to negotiate a point-to-point encryption scheme with a remote mobile device, the point-to-point encryption scheme negotiated between the management server and the remote mobile device;the management server configured to receive a value identifying an intercept target for a legal intercept and an indication that interception is authorized by a warrant, the intercept target corresponding to the remote mobile device;the management server configured to automatically intercept data received and/or sent by the intercept target identified by the value, wherein the data is intercepted without altering operation of email application services that operate on the remote mobile device;the management server configured to inspect packets having the intercepted data to distinguish end-to-end encrypted information from other information that is encrypted according to the point-to-point encryption scheme negotiated with the remote mobile device;the management server configured to preserve encryption that is included on the end-to-end encrypted information when received while removing encryption that is included on at least a portion of the other information, said other information decrypted using a key obtained during the point-to-point encryption scheme negotiation;and the management server configured to transfer both the decrypted other information and the end-to-end information from the management server to a remote device.
  3. 26
    Broadest claimClaim Score 62, broad(NHIP)A method for intercepting data, comprising:in response to receiving a connection request, negotiating a point-to-point encryption scheme with a mobile device, the point-to-point encryption scheme negotiated between a management server and the mobile device;automatically intercepting, at the management server, data received and/or sent by an intercept target, wherein data is intercepted without altering operation of application services on the mobile device;inspecting packets having the intercepted data to distinguish end-to-end encrypted information from other information that is encrypted according to the point-to-point encryption scheme negotiated with the device;preserving encryption that is included on the end-to-end encrypted information when received while removing encryption that is included on at least a portion of the other information, said other information decrypted using a key obtained during the point-to-point encryption scheme negotiation;and transferring both the decrypted other information and the end-to-end information.
  4. 45
    A communication management system for intercepting data, comprising:a processor;a network interface configured to receive a connection request;and a memory unit having instructions stored thereon, wherein the instructions, when executed by the processor, causes the communication management system to: negotiate a point-to-point encryption scheme;inspect packets having the data to be intercepted to distinguish end-to-end encrypted information from other information that is encrypted according to the point-to-point encryption scheme;preserve encryption that is included on the encrypted information when received while removing encryption that is included on at least a portion of the other information, said other information decrypted using a key obtained in association with the point-to-point encryption scheme;transfer both the decrypted other information and the end-to-end encrypted information;automatically format the intercepted data into log files including: generating log files that identify intercepted data for associated contiguous predetermined time periods extending over a continuous intercept period;and generating the log files for back-to-back time periods, the management server generating each log file by selecting between inserting the intercepted data and an inactivity indication therein such that each of the log files contains at least one selected from the group including the intercepted data for the associated time period and an indication that no data was intercepted during the associated time period;negotiate the point-to-point encryption scheme with a mobile device in response to receiving the connection request, and intercept data received and/or sent by an intercept target, wherein data is intercepted without altering operation of application services on the mobile device.