For any network service deployment it is mandatory in the country of deployment to provide a Lawful Intercept interface for the Law Enforcement Agencies(LEAs) in the corresponding country. It is a mandatory feature for network deployment. In GSM mobile network the LI framework is standardized by ETSI . The standard defines the overall architecture and abstract interface required for provisioning LI functionality. The following picture gives the high-level architecture defined by the standard.
The handover interface(HI) defined by ETSI standard is a set of abstract interfaces required for provisioning LI functionality between LEMF and LI server. The interface mainly consists of administration interface(HI1), Intercept related information(IRI) record delivery and actual Communication Content(CC) delivery.
The INI is a set of abstract interfaces defined by ETSI standard for provisioning LI on serving network elements. The interfaces that are defined under INI are X1, X2 and X3. The X1 interface is HI1 equivalent interface between LI server and the network elements that are serving the network domain of the LI target. Similarly, X2 and X3 interface are internal interface counterparts for HI2 and HI3 respectively.
The X1 interface is used by LE server to enable/disable and list targets. The LI could invoke X1 interface for single or multiple targets. Each target is identified by the service specific target identifier that will help network element to identify the target to be intercepted. For example IMSI, IMEI, IP address, MAC address etc. In addition to target identifier X1 interface will also indicate the delivery type(IRI only, CC only or both) and destination identifiers. The destination identifier specify where the interception information should be transferred. The destination specified are intermediate destination specified by the LI server where these records go through mediation function for transformation to the agreed HI2/HI3 formats. The delivery function on LI server will further transfer the records to the LEMF destination.
The X2 interface is used by network element to notify LE server of all the call related events. For example call establishment, call answer, call release, call handover etc. All these events carry a call correlation identifier that is used for uniquely identifying the span of a call. In addition all supplementary services related information like call directing, conferencing etc and non call events like location updates, SMS events will also be reported. All the events that are notified will carry the target identifiers like MSISDN, IMSI, IMEI, network element identifier, timestamps and local information etc. The event information delivered through X2 interface undergoes mediation function if required at LI server before delivery function transfers the IRI records using HI2 interface.
The X3 interface is used by network element to transfer CC payload to LE server. In addition to CC payload X3 interface also carries target identifier and call correlation identifier for LI server to identify the intercept content. The intercepted content may undergo transformation through mediation function before it is delivered to LEMF by delivery function.
Handover Interface 1(HI1)
The purpose of HI1 is for administrative control for LEMF to add/list/update/delete LI targets. The various modes of HI1 interface are:
However, in any of the modes listed above when LEMF manages LI targets using HI1 each LI target is identified by following identifiers:
In addition to the LIID above, LEMF provides other information required to provision LI for the target service:
Handover Interface 2(HI2)
After LI target is added/enabled by the LEMF, the network elements in the mobile network will start tracking the target services. For each communication/call activity of the LI target the LI server will publish the IRI record furnishing all the call related and required information. The communication/call activity may translate into single or multiple IRI records. The IRI records belonging to same call could be identified by IRI control information. The following are the main fields in IRI control information:
In addition to IRI control information, the IRI record also consists of basic call information and supplementary service attributes of the current call.
Handover Interface 3(HI3)
The HI3 interface is used for transferring of actual communication information during the call establishment phase. The form of information transferred depends on the service that is being intercepted. In some cases the the CC payload information is transformed to the required format using mediation function provided by LI server. The CC payload is encoded using TLVs with other metadata information relating the CC payload to a specific LI target and IRI records etc. The CC records are streamed to LEMF target destination using secure FTP.