Lawful interception for local selected ip traffic offload and local ip access performed at a non-core gateway
Abstract
Systems, methods, and instrumentalities are described to implement reporting of surveillance information associated with a device. A gateway device may intercept a communication associated with the device. The gateway device may route the communication such that the communication bypasses a core network. The gateway device may report information associated with the communication to a core network entity. The gateway device may receive a command message. The command message may include a request for a surveillance status of the device. The gateway device may send a response message. The response message may indicate a surveillance status of the device. The gateway device may receive an activate surveillance signal for the device. The gateway device may receive a deactivate surveillance signal for the device. Upon receiving the deactivate surveillance signal, the gateway device may stop further reporting.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
a gateway device routing a first communication associated with a user equipment (UE) to an application server such that the first communication bypasses a mobile core network; the gateway device receiving a request indicating activation of surveillance on communications associated with the UE; the gateway device dropping packets associated with the first communication from the UE in order to cause the application to time out on the UE; and the gateway device, based on the request indicating activation of surveillance on communications associated with the UE, routing a second communication from the UE to the application server via the mobile core network.
22 . The method of claim 21 , wherein the gateway device is connected to the mobile core network via a secured tunnel.
23 . The method of claim 22 , wherein the secured tunnel is an interne protocol security (IPsec) tunnel.
24 . The method of claim 21 , further comprising:
receiving a deactivate surveillance signal for the UE; and stopping routing communications from the UE via the mobile core network.
25 . The method of claim 21 comprising:
the gateway device sending a request for identity of a Law Enforcement Monitoring Function (LEMF) node; and
the gateway device receiving a response including the requested identity of the LEMF node.
26 . The method of claim 25 comprising the gateway device, based on the received identity of the LEMF node, sending a registration message to LEMF node.
27 . The method of claim 21 , wherein the first communication or the second communication is a Local Internet Protocol Access (LIPA) or Local Selected Internet Protocol Traffic Offload (L-SIPTO) type communication.
28 . A gateway device comprising:
a processor configured to at least: route a first communication associated with a user equipment (UE) to an application server such that the first communication bypasses a mobile core network; receive a request indicating activation of surveillance on communications associated with the UE; drop packets associated with the first communication from the UE in order to cause the application to time out on the UE; and based on the request indicating activation of surveillance on communications associated with the UE, route a second communication from the UE to the application server via the mobile core network.
29 . The gateway device of claim 28 , wherein the gateway device is connected to the mobile core network via a secured tunnel.
30 . The gateway device of claim 29 , wherein the secured tunnel is an internet protocol security (IPsec) tunnel.
31 . The gateway device of claim 28 , wherein the processor is further configured to:
receive a deactivate surveillance signal for the UE; and stop routing communications from the UE via the mobile core network.
32 . The gateway device of claim 28 , wherein the processor is further configured to:
send a request for identity of a Law Enforcement Monitoring Function (LEMF) node; and receive a response including the requested identity of the LEMF node.
33 . The gateway device of claim 32 , wherein the processor is further configured to, based on the received identity of the LEMF node, send a registration message to LEMF node.
34 . The gateway device of claim 28 , wherein the first communication or the second communication is a Local Internet Protocol Access (LIPA) or Local Selected Internet Protocol Traffic Offload (L-SIPTO) type communication.Join the waitlist — get patent alerts
Track US2017155687A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.