My 4G lawful interception notes: Difference between revisions
m added section for 33 107 abbreviations |
m moved abbreviations to end of page |
||
| Line 7: | Line 7: | ||
=== IRI === | === IRI === | ||
'''The following events are applicable to the MME:''' | '''The following events are applicable to the MME:''' | ||
| Line 47: | Line 46: | ||
* Table 10.5.1.1.19: Register location REPORT Record | * Table 10.5.1.1.19: Register location REPORT Record | ||
* Table 10.5.1.1.20: Location information request REPORT Record | * Table 10.5.1.1.20: Location information request REPORT Record | ||
== EPS Multimedia == | |||
This includes IMS-based voice (VoLTE) or other services. | |||
33.108 12.1.4 | |||
Lawful intercept identifier (LIID) and Network identifier are same as data. The correlation number is unique per VoIP session. | |||
For IMS-based VoIP, the S-CSCF and optionally, the P-CSCF provide the IRI events. For IMS-based VoIP, the functional element that provides the communication content (CC) interception depends on the call scenario and network configuration. | |||
The term "CC Intercept Function" is a generic term used to denote a network function that has access to the voice media of an intercepted call. The term "CC Interception Triggering Function" is a generic term used to denote a network function that provides a trigger to intercept the CC. | |||
As described in 33.107, CC interception may be done by one of the following functional elements (referred to as CC Intercept Function) | |||
* PDN-GW/GGSN | |||
* IMS-AGW | |||
* TrGW | |||
* IM-MGW | |||
* MRF | |||
The trigger to perform the CC interception at the above functional elements may be provided by the following functional elements (referred to as CC Interception Triggering Function) | |||
{| class="wikitable sortable" | |||
|- | |||
! CC Interception Triggering Function !! CC Intercept Function | |||
|- | |||
| P-CSCF|| PDN-GW/GGSN | |||
|- | |||
| P-CSCF || IMS-AGW | |||
|- | |||
| IBCF || TrGW | |||
|- | |||
| MGCF || IM-MGW | |||
|- | |||
| S-CSCF || MRF | |||
|} | |||
== Abbreviations == | == Abbreviations == | ||
| Line 313: | Line 348: | ||
|- | |- | ||
| WWSF || WebRTC Web Server Function || 3GPP TS 33.107 V15.6.0 (2019-06) | | WWSF || WebRTC Web Server Function || 3GPP TS 33.107 V15.6.0 (2019-06) | ||
|} | |} | ||
<center>[[My lawful interception notes]]</center> | <center>[[My lawful interception notes]]</center> | ||
Revision as of 09:40, 3 June 2021
Evolved Packet Systems (EPS)
- 3GPP TS 33.107
- 3GPP TS 33.108
EPS Data
IRI
The following events are applicable to the MME:
- Attach;
- Detach;
- Tracking Area/EPS Location Update;
- UE requested PDN connectivity;
- UE Requested PDN disconnection;
- Start of interception with E-UTRAN attached UE.
The following events are applicable to the Serving GW (S-GW) and PDN GW (P-GW):
- Bearer activation (valid for both Default and Dedicated bearer);
- Start of intercept with bearer active;
- Bearer modification;
- Bearer deactivation;
- UE Requested Bearer Resource Modification;
- Packet Data Header Information.
The following events are applicable to the HSS:
- Serving Evolved Packet System.
- HSS subscriber record change;
- Cancel location
- Register location;
- Location information request.
The following LALS Reports are applicable to the EPS (see Clause 19):
- Report for LALS Target Positioning;
- Report for LALS Enhanced Location for IRI.
Home Subscriber Server (HSS) IRI
Clause 10.5.1.1
- as a national option, a mobile terminal is authorized for service with another network operator or service provider; in that case, other related events are required as cancel location, register location, location information request from a third party’s node;
- as a national option, a REPORT record have to be generated when there is a HSS subscriber record change of IMSI or of MSISDN or IMEI triggered by a messages to or from the HSS;
IRI reports
- Table 10.5.1.1.12: Serving Evolved Packet System REPORT Record
- Table 10.5.1.1.17: HSS subscriber record change REPORT Record
- Table 10.5.1.1.18: Cancel location REPORT Record
- Table 10.5.1.1.19: Register location REPORT Record
- Table 10.5.1.1.20: Location information request REPORT Record
EPS Multimedia
This includes IMS-based voice (VoLTE) or other services.
33.108 12.1.4 Lawful intercept identifier (LIID) and Network identifier are same as data. The correlation number is unique per VoIP session.
For IMS-based VoIP, the S-CSCF and optionally, the P-CSCF provide the IRI events. For IMS-based VoIP, the functional element that provides the communication content (CC) interception depends on the call scenario and network configuration.
The term "CC Intercept Function" is a generic term used to denote a network function that has access to the voice media of an intercepted call. The term "CC Interception Triggering Function" is a generic term used to denote a network function that provides a trigger to intercept the CC.
As described in 33.107, CC interception may be done by one of the following functional elements (referred to as CC Intercept Function)
- PDN-GW/GGSN
- IMS-AGW
- TrGW
- IM-MGW
- MRF
The trigger to perform the CC interception at the above functional elements may be provided by the following functional elements (referred to as CC Interception Triggering Function)
| CC Interception Triggering Function | CC Intercept Function |
|---|---|
| P-CSCF | PDN-GW/GGSN |
| P-CSCF | IMS-AGW |
| IBCF | TrGW |
| MGCF | IM-MGW |
| S-CSCF | MRF |
Abbreviations
3GPP TS 33.107 V15.6.0 (2019-06)
| Abbreviation | Description | Source |
|---|---|---|
| 3GMS | 3rd Generation Mobile Communications System | 3GPP TS 33.107 V15.6.0 (2019-06) |
| 3G GGSN | 3rd Generation Gateway GPRS Support Node | 3GPP TS 33.107 V15.6.0 (2019-06) |
| 3G GSN | 3rd Generation GPRS Support Node (GGSN/SGSN) | 3GPP TS 33.107 V15.6.0 (2019-06) |
| 3G MSC | 3rd Generation Mobile Switching Centre | 3GPP TS 33.107 V15.6.0 (2019-06) |
| 3G SGSN | 3rd Generation Serving GPRS Support Node | 3GPP TS 33.107 V15.6.0 (2019-06) |
| 3G UMSC | 3rd Generation Unified Mobile Switching Centre | 3GPP TS 33.107 V15.6.0 (2019-06) |
| AAA | Authentication, Authorization, and Accounting | 3GPP TS 33.107 V15.6.0 (2019-06) |
| ADMF | Administration Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| AGW | Access Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| AN | Access Network | 3GPP TS 33.107 V15.6.0 (2019-06) |
| AP | Access Provider | 3GPP TS 33.107 V15.6.0 (2019-06) |
| AS | Application Server | 3GPP TS 33.107 V15.6.0 (2019-06) |
| BBIFF | Bearer Binding Intercept and Forwarding Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| BM-SC | Broadcast-Multicast Service Centre | 3GPP TS 33.107 V15.6.0 (2019-06) |
| BSF | Bootstrapping Serving Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| B-TID | Bootstrapping Transaction Identifier | 3GPP TS 33.107 V15.6.0 (2019-06) |
| CC | Content of Communication | 3GPP TS 33.107 V15.6.0 (2019-06) |
| CS | Circuit Switched | 3GPP TS 33.107 V15.6.0 (2019-06) |
| CSCF | Call Session Control Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| CSG | Closed Subscriber Group | 3GPP TS 33.107 V15.6.0 (2019-06) |
| CSP | Communications Service Provider | 3GPP TS 33.107 V15.6.0 (2019-06) |
| CSR | Cell Site Report | 3GPP TS 33.107 V15.6.0 (2019-06) |
| CUPS | Control and User Plane Separation of EPC nodes | 3GPP TS 33.107 V15.6.0 (2019-06) |
| DF | Delivery Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| DSMIP | Dual Stack Mobile IP | 3GPP TS 33.107 V15.6.0 (2019-06) |
| ECT | Explicit Call Transfer | 3GPP TS 33.107 V15.6.0 (2019-06) |
| EPC | Evolved Packet Core | 3GPP TS 33.107 V15.6.0 (2019-06) |
| ePDG | Evolved PDG | 3GPP TS 33.107 V15.6.0 (2019-06) |
| EPS | Evolved Packet System | 3GPP TS 33.107 V15.6.0 (2019-06) |
| E-UTRAN | Evolved UTRAN | 3GPP TS 33.107 V15.6.0 (2019-06) |
| FTP | File Transfer Protocol | 3GPP TS 33.107 V15.6.0 (2019-06) |
| GBA | Generic Bootstrapping Architecture | 3GPP TS 33.107 V15.6.0 (2019-06) |
| GGSN | Gateway GPRS Support Node | 3GPP TS 33.107 V15.6.0 (2019-06) |
| GPRS | General Packet Radio Service | 3GPP TS 33.107 V15.6.0 (2019-06) |
| GSM | Global System for Mobile communications | 3GPP TS 33.107 V15.6.0 (2019-06) |
| GSN | GPRS Support Node (SGSN or GGSN) | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HA | Home Agent | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HeMS | HeNB Management System | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HeNB | Home enhanced NodeB | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HeNB GW | HeNB Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| H(e)NB | Home and Home enhanced NodeB | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HI | Handover Interface | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HLR | Home Location Register | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HMS | HNB Management System | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HNB | Home NodeB | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HNB GW | HNB Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HRPD | High Rate Packet Data | 3GPP TS 33.107 V15.6.0 (2019-06) |
| HSS | Home Subscriber Server | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IA | Interception Area | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IBCF | Interconnecting Border Control Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| ICEs | Intercepting Control Elements (3G MSC Server, 3G GMSC Server, P-CSCF, S-CSCF, SGSN, GGSN, HLR, AAA Server, PDG, MME, S-GW, PDN-GW, HSS) | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IETF | Internet Engineering Task Force | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IM-MGW | IMS Media Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IMEI | International Mobile station Equipment Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IMPI | IP Multimedia Private Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IMPU | IP Multimedia Public Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IMS | IP Multimedia Core Network Subsystem | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IMS-AGW | IMS Access Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IMSI | International Mobile Subscriber Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| INEs | Intercepting Network Elements (3G MSC Server, 3G GMSC Server, P-CSCF, S-CSCF, SGSN, GGSN, MGW, HLR, AAA Server, PDG) | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IP | Internet Protocol | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IP-SM-GW | IP-Short-Message-Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| IRI | Intercept Related Information | 3GPP TS 33.107 V15.6.0 (2019-06) |
| I-WLAN | Interworking WLAN (3GPP WLAN interworking subnetwork) | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LALS | Lawful Access Location Services | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LAN | Local Area Network | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LBO | Local Breakout | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LCS | Location Services | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LDI | Location Dependent Interception | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LEA | Law Enforcement Agency | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LEMF | Law Enforcement Monitoring Facility | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LIPA | Local IP Access | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LMISF | LI Mirror IMS State Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| LTE | Long Term Evolution | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MBMS | Multimedia Broadcast/Multicast Service | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MC ID | Mission Critical User Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MCPTT | Mission Critical Push-To-Talk | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MCPTT ID | Mission Critical Push to Talk Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MF | Mediation Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MGCF | Media Gateway Control Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MGW | Media Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| ME | Mobile Entity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MIP | Mobile IP | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MM | Multimedia Message | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MMBox | Multimedia Message Box | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MME | Mobility Management Entity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MN | Mobile Node | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MRF | Media Resource Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| MSISDN | Mobile Subscriber ISDN Number | 3GPP TS 33.107 V15.6.0 (2019-06) |
| NAF | Network Application Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| NAI | Network Access Identifier | 3GPP TS 33.107 V15.6.0 (2019-06) |
| NO | Network Operator | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PCRF | Policy and Charging Rules Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| P-CSCF | Proxy CSCF | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PDG | Packet Data Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PDN | Packet Data Network | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PDN-GW | PDN Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PMIP | Proxy Mobile IP | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PoC | Push to talk over Cellular | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PS | Packet Switched | 3GPP TS 33.107 V15.6.0 (2019-06) |
| PTC | Push to Talk over Cellular | 3GPP TS 33.107 V15.6.0 (2019-06) |
| RA | Routing Area | 3GPP TS 33.107 V15.6.0 (2019-06) |
| RAI | Routing Area Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| S8HR | S8 Home Routing | 3GPP TS 33.107 V15.6.0 (2019-06) |
| SAI | Service Area Identity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| S-CSCF | Serving CSCF | 3GPP TS 33.107 V15.6.0 (2019-06) |
| SeGW | Security Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| SGSN | Serving GPRS Support Node | 3GPP TS 33.107 V15.6.0 (2019-06) |
| SIP | Session Initiation Protocol | 3GPP TS 33.107 V15.6.0 (2019-06) |
| SMS | Short Message Service | 3GPP TS 33.107 V15.6.0 (2019-06) |
| S-GW | Serving Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| SR-VCC | Single Radio Voice Call Continuity | 3GPP TS 33.107 V15.6.0 (2019-06) |
| SX3LIF | Split X3 LI Interworking Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| TEL URI | "tel" URI, as defined in RFC 3966 [ 36] | 3GPP TS 33.107 V15.6.0 (2019-06) |
| TLS | Transport Layer Security | 3GPP TS 33.107 V15.6.0 (2019-06) |
| TrGW | Transit Gateway | 3GPP TS 33.107 V15.6.0 (2019-06) |
| TRF | Transit Routing Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| TWAN | Trusted WLAN Access Network | 3GPP TS 33.107 V15.6.0 (2019-06) |
| UE | User Equipment | 3GPP TS 33.107 V15.6.0 (2019-06) |
| UMTS | Universal Mobile Telecommunication System | 3GPP TS 33.107 V15.6.0 (2019-06) |
| URI | Universal Resource Identifier | 3GPP TS 33.107 V15.6.0 (2019-06) |
| URL | Universal Resource Locator | 3GPP TS 33.107 V15.6.0 (2019-06) |
| VoIP | Voice over IP | 3GPP TS 33.107 V15.6.0 (2019-06) |
| VoLTE | Voice over LTE | 3GPP TS 33.107 V15.6.0 (2019-06) |
| WLAN | Wireless LAN | 3GPP TS 33.107 V15.6.0 (2019-06) |
| WAF | WebRTC Authorisation Function | 3GPP TS 33.107 V15.6.0 (2019-06) |
| WebRTC | Web Real Time Communications | 3GPP TS 33.107 V15.6.0 (2019-06) |
| WIC | WebRTC IMS Client | 3GPP TS 33.107 V15.6.0 (2019-06) |
| WWSF | WebRTC Web Server Function | 3GPP TS 33.107 V15.6.0 (2019-06) |