WO2010145233A1 - 获取密钥管理服务器信息的方法、监听方法及系统、设备 - Google Patents
获取密钥管理服务器信息的方法、监听方法及系统、设备 Download PDFInfo
- Publication number
- WO2010145233A1 WO2010145233A1 PCT/CN2010/071168 CN2010071168W WO2010145233A1 WO 2010145233 A1 WO2010145233 A1 WO 2010145233A1 CN 2010071168 W CN2010071168 W CN 2010071168W WO 2010145233 A1 WO2010145233 A1 WO 2010145233A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- user
- call
- advance
- phase
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/083—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0807—Network architectures or network communication protocols for network security for authentication of entities using tickets, e.g. Kerberos
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/30—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
- H04L63/306—Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information intercepting packet switched data communications, e.g. Web, Internet or IMS communications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/10—Architectures or entities
- H04L65/1016—IP multimedia subsystem [IMS]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/1066—Session management
- H04L65/1073—Registration or de-registration
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the call is first introduced to the phase and the cke, in the cke, the phase of the call direction is included in it.
- Calls and parties can utilize common, closed, and intermittent communications. There may be more than one case, there are many situations, the user will use, and the distribution method involved.
- the distribution method is non-existent, is not, the user has pre-configured the second is by, by
- the plaintext is used in the command, that is, in the VT of the call, in the interception of the signaling, the legally required materials and the plaintext users use, and then the phase
- the wood to be solved by the firm is to provide methods, methods and systems for managing various information, so that it can be deployed in P-multi-media, and does not depend on the security of the order to meet legal requirements.
- this method has been upgraded to manage each ( ) information, including
- the user's information is stored in advance and
- the user's order is intercepted, and the user's information is retrieved from the user's information.
- storing each user's information in a prior step includes
- the message will be pre-configured information in advance and
- Steps include
- the user is assigned to each user in advance, and the user's information is stored in the prior.
- Each call control function (SC C ), proxy call control function (-CC), and user () methods legally find each user's information , to ask for the required materials, to generate the home.
- the literary system has recently been promoted, including the P-multi-media sub-system ( ) and legal, including
- the user's information is stored, and the user's order is intercepted.
- the user's information in the order the user's information in each user's information.
- the user's respective messages are received, and the pre-configured information of the user is taken and saved.
- the user and the user are assigned to each other and save the information.
- the steps of legally requesting the information of each phase include In the case of the call, the K information of the desired phase in the caller and its information stored in advance.
- the phase flow is repaired, and the user's information is stored in the phase.
- the main reason is that existing user information and distribution information can be repaired, and the user's information is stored in the phase, and the legally intercepted signaling takes the user's information, and then the user's information is in phase. Information, but the phase material of the phase is generated, and finally the user can be secret.
- Step 202 -C CF receives, uses the provided P-address of the -C CF
- Step 203 -C CF user each ( ), so -C CF
- Step 204, in -C CF, -C CF will be special S-C CF
- Step 205 since -C CF is not, therefore, to request 206, the S-C CF 401 message is not displayed by the user. Steps 207-208, which will be 401.
- Step 209 receiving the 401 message, the 401 message is presented, and the P-C CF is calculated again, and the pre-configured
- Steps 210-212, -C CF -C CF will have a special phase of -C CF
- Step 213 the S-C CF receives, where, -C CF , the downloaded user configuration, and the storage
- Steps 214-216, and P-C CF is 20 O accepted.
- the information in the call, and then the information in the phase of the information phase is generated to the phase material of the phase, and finally the user can be secreted.
- the configuration it can be stored in PC CF or more in the near future.
- the user has pre-configured S, and the S assigned by SA can override the user configuration.
- step 309 to step 312 the difference between the two is that in step 309 to step 312, the user can configure the information in the RGTR message, or the user does not have any phase information.
- step 314 the user is assigned and will be allocated. 20 message users, with storage users and theirs. , legally need to fold, intercept the call, the call information, and then call the information in the phase of the information, but the phase material is generated, and finally the user's secret.
- the function is assigned by the -C CF user, and the functions that will be assigned to each of the rest situations are in other
- a user's, 4 the difference is that in step 409, A is in the middle phase.
- the phase material is generated and finally can be user-secured.
- Step 50 A first to
- Step 503 A VT message, the message includes cke and other
- Step 504 the VT message special user, that is, B, step 505, B can not solve cke, therefore, this cke
- Step 506 the user, then cke will return the B
- the information can be managed according to the existing wood, the intercepted information, or the information can be intercepted according to the legal operation of the system.
- Call (ie) then call, to, example-C CF, call management information (ie MS)
- Step A is legal and takes the required
- the legal ones can be taken according to the legal requirements of the existing wooden picking, and the only ones that can be intercepted.
- Steps are legal. Take all the materials you need, build, and finally.
- the technical solution of the present invention proposes different configuration schemes, the user repairs the process, and perfects the existing wood, and no longer depends on the warranty.
- the phase flow is performed, and the user's information is stored in the phase.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Multimedia (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- Business, Economics & Management (AREA)
- General Business, Economics & Management (AREA)
- Technology Law (AREA)
- Telephonic Communication Services (AREA)
- Mobile Radio Communication Systems (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本发明公开了一种获取密钥管理服务器信息的方法、监听方法及系统、设备,在用户设备进行 IP多媒体子系统(IMS)注册的过程中,将与用户设备对应的KMS信息存储在事先设定的IMS核心网网元中;以及当合法监听设备监听用户设备发起的会话时,截取用户设备发送的会话请求信令,并从会话请求信令中获取用户设备的标识信息,根据用户设备的标识信息从事先设定的 IMS核心网网元中查找与所述用户对应的KMS信息。本发明技术方案使得在IP多媒体子系统中部署多个KMS时,不依赖于信令面的安全而满 足合法监听需求。
Description
管理 各 信息的方法、 方法及 統、 各 木領域
本 涉及 通信安全及合法 木, 休東說, 涉及
管理 各 信息的方法、 方法及 統、 各。
背景 木
目前在3GPP 于 P多媒休子 統 ( ) 的 休安全的最新 木 T 33.32 1.1.0中, 提出了使用 于 管理 各 的方案 休 的 到 安全。
T 33.328 V .1.0 中的方案 于 管理 各 ( )和 " cke" 的 概念。 現有方案可 羊
呼叫 首先向 相 和 介 cke, 在 cke 中, 呼叫方向 求得到的相 包含在其
得到相 和 cke , 呼叫方 cke
由于 法解 cke 得其中包含的信息,被 則將此 cke , 由 cke 將其中的相 返
呼叫 和 方可以利用 共同的相 密的 休流通信。 而 中可能存在不止 介 , 存在多 的情況 , 用戶將 使用 , 涉及 的分配方式。
的分配方式 非有 , 是 不 的, 由用戶 己預先配置 介 第二 是由 的, 由
用戶分配 使用的
現有 木中, 的 明文 在 令中, 即在呼叫 的 VT 中 明文的 使用的 , 在截取信令 , 合法 各 取所需的 材料和 明文 用戶所使用的 , 再向相 的
相 的 材料。 由此可以看出, 現有 木方案依賴于 令 的安全, 安全 較低。
內容
本 所要解決的 木 是, 提供 管理 各 信息的方 法、 方法及 統、 各, 使得在 P多媒休子 統中部署多 , 不依賴于 令 的安全而滿足合法 需求。
了解決上 , 本 公升了 管理 各 ( )信 息的方法, 包括
在用戶 各 P多媒休子 統 ( ) 的 中, 將 用戶 各 的 信息存儲在事先 的 以及
合法 各 用戶 各 的 , 截取所 用戶 各 的 令, 令中 取所 用戶 各的 信息, 用戶 各的 信息 中 用戶 的 "。
上 方法中,將 用戶 各 的 信息存儲在事先 的 的步驟包括
所迷用戶 各預先配置 信息 , 通 消息將預先配置的 信息 事先 的 以及
事先 的 接收 消息, 中 保存 "。
可 , 將 用戶 各 的 信息存儲在事先 的
的步驟包括
所迷用戶 各向 ,事先 的 用 戶 各分配 用戶 各相 的 , 將 的 信息存儲在所 事先 的 中。
其中, 事先 的 力以下 或
各呼叫 控制功能 休 (S-C C ) 、 代理 各呼叫 控制功能 休 ( -C C ) 以及 用戶 各 ( ) 上 方法中, 合法 各 找到 用戶 各 的 信息
, 向 索取所要 的 的 材料, 生成舍 , 。
本 近公升了 統, 其包括 P多媒休子 統 ( ) 元和合法 各, 其中
所述 在用戶 各 的 中,存儲 用戶 各 的 信息 所述合法 各 截取所 用戶 的 令,
令中 的用戶 各的 信息, 用戶 各的 信息 中 用戶 各 的 信息。
上述 統中, 近 接收用戶 各 的 消 息, 中 取用戶預先配置的 信息, 保存。
其中, 近 在用戶 各 用戶 , 用戶 各分配相 的 , 保存 的 信息。
所述 力以下 或
各呼叫 控制功能 休 (S-C C ) 、 代理 各呼叫 控制功能 休 ( -C C ) 以及 用戶 各 ( ) 上述 統中, 合法 各近 向 索取所要 的 的 材料, 生成舍 , 。
本 近公升了 方法, 其
合法 各 所要 的 相 的 管理 各 ( ) 信息, 在 上索取所要 的 的 材料, 生成舍 ,
。
上 方法中, 合法 各 所要 的 相 的 信息的步驟包括
令中 取所 呼叫 的 , 呼叫 的 , 在 事先 的存儲有 呼叫方及其 信息的 中, 所要 的 相 的K 信息。
本 近公升了 各, 其包括信息 和 , 其中 迷信息 管理 各 信息
迷信息 中的 管理 各 信息, 在 管理 各 上 取所要 的 的所有 材料,生成舍 , 。
其中, 迷信息 近 截取的 令中 取所 呼叫 的 , 呼叫 的 , 在事先 的存儲有 呼叫方及 其 信息的 中, 所要 的 相 的
, 。
本 明技木方案 用戶 分配的 的分配信息情況,修 了相 流程, 將用戶 的 信息儲存在相 的
中, 使得合法 截取到的信令消息 相 相 的 , 而 兔用戶惡意 或 令消息, 合法 各找到 的 行合法 。
1 是本 提出的 統
2 1中 用戶 流程
3 2中 用戶 流程
4 3中 用戶 流程
5 3中 用戶 的流程 。
本 的較佳 方式
本 的主要 是, 現有用戶 信息和 分配 信 息的 , 可以修 流程, 而將用戶 各 的 信息儲存在相 的 中, 而合法 各 截取到的信令 取用戶 各信息, 再 用戶 各信息 相 中 相 的 信息, 然 向相 的 相 材料生成 , 最終可以 用戶的 密通 。
下面結合 因及 休 本 明技木方案 步 細說明。
中的"'、 、
可信的"管理 各"。
A和 B, 于 用戶 , 以及
, 于在用戶 各( A和 B) 用戶 中, 儲存 用戶 各及其 的 信息 ( ) 合法 各, 于 中的接 截取呼叫 的 令, 截取的 令 得呼叫 (即 A ) , 再 呼叫 , 在 例 -C CF (Se Vce-Ca SessoCo o F c o 各呼叫 控制功能 休)中 呼叫 的
, 再向相 的 要用「A、 B 使用的 材料, 生成
合法 。
下面結合各 介紹上 統中合法 各 管理 各 信息的 。
1
本 于用戶 配置或者由其他 預先 得 信息,而
分配的 。
在 中, 用戶的 , 2所示, 包括以下步驟 步驟20 , 介 PR G T R( ) P-C CF(代理 各呼叫 控制功能 休) , 中包含 的 和 的 , 即 -C CF ( 各呼叫 控制功能 休)地址
步驟202, -C CF接收 , 使用所提供的 解 析 -C CF的 P地址
步驟203, -C CF 用戶 各 ( ), 以便 -C CF
取所需的 -C CF能力要求
步驟 204, 在 -C CF 定 , -C CF 將 特 的S-C CF
步驟205, 由于 -C CF 沒有 , 因此, 向 索取 步驟206, S-C CF 介401消息未 用戶的 表示 步驟207-208, 將上 401消息特
步驟209, 收到上 401消息, 401消息所提出的 的 ,再次 另 介 P-C CF, 中 算出的 以及預先配置的
步驟210-212, -C CF -C CF將 帶有 和 的 特 相 的 -C CF
步驟213, S-C CF接收上 , 其中的 , -C CF , 下載 的用戶配置, 同 存儲 中 帶的
步驟214-216, 且P-C CF 介20 O 接受 。
, 合法 各需要 , 截取呼叫 的
令, 中 呼叫 信息, 再 呼叫 信息 相 中 相 的 信息, 然 向相 的 相 材料生成 , 最終可以 用戶的 密通 。
在 配置中, 近可以 各 休情況而 將 存儲 在P-C CF或者 或者多 中。 方案中, 將
存儲在 -C CF和/或 中。 2
本 于 分配的 , 下 果 用戶已 預先配置好 S , 由 S 阿阿 分配的 S 可以將用 戶 配置的 覆蓋。
本 中 用戶的 3所示, 其 2的不同 在于步驟309到步驟312中, 用戶在R G T R消息 可以 用戶 配置的 信息, 也可不 任何 相 信息, 而在步驟314中, 將 用戶分配 , 將分配好的 20 消息 用戶, 同 存儲 用戶及其 的 。 , 合法 各需要 折合 , 截取呼叫 的 令, 中 呼叫 信息,再 呼叫 信息 相 中 相 的 信息, 然 向相 的 相 材料生成 ,最終可以 用戶的 密通 。
在本 中, 由 -C CF 用戶 分配, 部署中, 也可 各的 休情況將 分配的功能 在其他
中, 例 等。 3 本 于 用戶 □ A)預先配置 使用的 的 、。
A 用戶 的 , 4所示, 其 1的不同 在于, 步驟 409 中 A向 中相 的
R GST R信息 , 在 R GST R信息中 預先配置的 , 而 S
-C CF收到R G T R信息中 帶的 , 將 及
的 信息保存下 。 , A , 合法 各可以截取 A 的 令, 中 A信息, 再 A信息 相 中 相 的 信息, 然 向相 的
相 材料生成 , 最終可以 用戶的 密通 。
休 , A 的 , 5所示, 包括以下步驟
步驟50 , A首先向
步驟502, cke A
步驟503, A VT 消息, 消息中包含 cke 以及其他
其他 教具休可 -TC T
步驟504, 將 VT 消息特 用戶, 即 B, 步驟 505, B由于不能解 cke,因此, 則將此 cke
, L cke
步驟506, 用戶, 然 cke 將其中的相 返 B
步驟507-508, 成功, 被 B 返 20 消息 A, , A和 B就可以利用 共同的相 密的 休流通信。
其同,合法 各可以 A 出的 VT 消息, 中 A 的 ,再 A的 向相 A 的 , 即 , 然 向 索取相 材料, 生成 A和B的
A和B的 密通 。
下面再介紹本 所提供的 合法 各, 各包括信息 和 。 其中
信息 , 于 管理 各 信息
, 信息 可以按照現有 木, 截取 的 的 信息, 中 管理 各 信息 即 ) 或者信息 可以按照上 統中合法 各的操作, 通 截取的
令 得呼叫 (即 的 ) , 再 呼叫 , 向 , 例 -C CF, 呼叫 的 管理 各 信息 (即 M S )
, 于根 信息 中的 管理 各 信息, 在 管理 各 上 取所要 的 的所有 材料, 生成 。
步驟A 合法 各 取所要 的 的
步驟中, 合法 各可以按照現有 木 取所要 的 的 合法 各也可以截取 的 令, 中 的 , 的 祇在事先 的 上 的
步驟 合法 各在所 的 上 取所要 的 的所有 材料, 生成 , 最終 。
上 例可以看出,本 明技木方案提出了 于不同的 的配 置方案 , 用戶在 流程的修 , 而完善了現有 木, 不再 依賴于 令 的保 。
本 近可有其他多 , 也 于 中只有 介 的情況。 在不 本 精神及其 的情況下, 熟悉本領域的 木 可 本 作出各 相 的 和 , 但 相 的 和 都 于本 的 要求的保 。
用性
本 明技木方案 用戶 分配的 的分配信息情況, 了相 流程, 將用戶 的 信息儲存在相 的
中, 使得合法 截取到的信令消息 相 相 的 , 而 兔用戶惡意 或 令消息, 合法 各找到 的 行合法 ,完善了現有 木,不再依賴于
令 的保 。
Claims
要 求 1、 管理 各 ( )信息的方法, 其包括
在用戶 各 P多媒休子 統 ( ) 的 中, 將 用戶 各 的 信息存儲在事先 的 以及
合法 各 用戶 各 的 , 截取所 用戶 各 的 令, 令中 取所 用戶 各的 信息, 用戶 各的 信息 事先 的 中 用戶 的 信息。
2、 要求1 的方法, 其中,
將 用戶 各 的 信息存儲在事先 的
中的 步驟包括
所迷用戶 各預先配置 信息 , 通 消息將預先配置的 信息 事先 的 以及
事先 的 接收 消息, 中 保存 信息。
3、 要求1 的方法, 其中,
將 用戶 各 的 信息存儲在事先 的
中的 步驟包括
所迷用戶 各向 , 事先 的
用戶 各分配 用戶 各相 的 , 將 分配的 的 信息存儲在所 事先 的 中。
4、 要求1、 2或3 的方法, 其中,
事先 的 力以下 或
各呼叫 控制功能 休 (S-C C ) 、 代理 各呼叫 控制功能 休 ( -C C ) 以及 用戶 各 ( )
5、 要求 1、 2或3 的方法, 在所 合法 各 找到 用戶 各 的 信息的步驟 , 方法近包括
所迷合法 各向 索取所要 的 的 材料,生成舍 , 。
6、 統, 其包括 P多媒休子 統 ( ) 元和合法 各, 其中
在用戶 各 的 中,存儲 用戶 各 的 管理 各 ( )信息 合法 各 截取所 用戶 的 令, 令中 取所 用戶 各的 信息, 用戶 各的 信 息 中 用戶 各 的 信息。
7、 要求6 的 統, 其中,
接收 用戶 各 的 消息, 中 取用戶預先配置的 信息, 保存。
、 要求6 的 統, 其中,
在所 用戶 各 用戶 , 用戶 各分配相 的K , 保存 K 的K 信息。
9、 要求6、 7或8 的 統, 其中,
力以下 或
各呼叫 控制功能 休 (S-C C ) 、 代理 各呼叫 控制功能 休 ( -C C ) 以及 用戶 各 ( ) 1 、 要求6、 7或8 的 統, 其中,
合法 各近 向 索取所要 的 的 材 料, 生成舍 , 。
、 方法, 其包括
合法 各 所要 的 相 的 管理 各 ( ) 信息, 在所 上索取所要 的 的 材料, 生成舍 , 。 12、 要求11 的方法, 其
所述合法 各 所要 的 相 的 信息的步驟包 括
令中 取所 呼叫 的 呼叫 的 , 在 事先 的存儲有所 呼叫方及 呼叫 的 K 信息的
中, 所要 的 相 的 信息。 13、 各, 其包括信息 和 , 其中
所述信息 管理 各 信息 所述 迷信息 中的 管理 各 信息, 在所 管理 各 上 取所要 的 的 材料, 生成舍 , 。 14、 要求13 的 各, 其中, 所述信息 近 截取的 令中 呼叫 的 , 呼叫 的 , 在事先 的存儲有所 呼叫方及 呼叫 的 信息的 中, 所要 的 相 的
。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP10788629.3A EP2472769B1 (en) | 2009-11-06 | 2010-03-19 | Method for obtaining information of key management server, and method, system and device for monitoring |
| US13/258,063 US8565382B2 (en) | 2009-11-06 | 2010-03-19 | Method for obtaining information of key management server, and method, system and device for monitoring |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN200910212359.4 | 2009-11-06 | ||
| CN200910212359.4A CN102055747B (zh) | 2009-11-06 | 2009-11-06 | 获取密钥管理服务器信息的方法、监听方法及系统、设备 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2010145233A1 true WO2010145233A1 (zh) | 2010-12-23 |
Family
ID=43355738
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2010/071168 Ceased WO2010145233A1 (zh) | 2009-11-06 | 2010-03-19 | 获取密钥管理服务器信息的方法、监听方法及系统、设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US8565382B2 (zh) |
| EP (1) | EP2472769B1 (zh) |
| CN (1) | CN102055747B (zh) |
| WO (1) | WO2010145233A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2803164A4 (en) * | 2012-01-12 | 2015-09-16 | Blackberry Ltd | SYSTEM AND METHOD FOR LEGAL ACCESS TO SAFE COMMUNICATION |
| US9264227B2 (en) | 2012-01-12 | 2016-02-16 | Blackberry Limited | System and method of lawful access to secure communications |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR101776928B1 (ko) * | 2010-12-21 | 2017-09-29 | 한국전자통신연구원 | 합법적 감청 장치 및 방법 |
| EP2803165B1 (en) | 2012-01-12 | 2019-04-24 | BlackBerry Limited | System and method of lawful access to secure communications |
| CN104683098B (zh) * | 2013-11-29 | 2019-09-10 | 中国移动通信集团公司 | 一种保密通信业务的实现方法、设备及系统 |
| US10257175B2 (en) * | 2015-09-28 | 2019-04-09 | Fornetix Llc | Encryption deployment discovery |
| CN109946595B (zh) * | 2019-03-25 | 2022-01-04 | 中国科学院微电子研究所 | 一种扫描测试执行方法、装置及系统 |
| US11128672B2 (en) * | 2019-11-13 | 2021-09-21 | Verizon Patent And Licensing Inc. | Lawful intercept in future core interworking with evolved packet system |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030120598A1 (en) * | 2001-12-21 | 2003-06-26 | Lam Chui-Shan Teresa | Method and system for initializing a key management system |
| CN101009551A (zh) * | 2006-01-24 | 2007-08-01 | 华为技术有限公司 | 基于ip多媒体子系统的媒体流的密钥管理系统和方法 |
| CN101523797A (zh) * | 2006-10-18 | 2009-09-02 | 艾利森电话股份有限公司 | 通信网络中的密码密钥管理 |
| CN101572694A (zh) * | 2008-04-29 | 2009-11-04 | 华为技术有限公司 | 媒体流密钥的获取方法、会话设备与密钥管理功能实体 |
Family Cites Families (10)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP3391271B2 (ja) * | 1998-09-01 | 2003-03-31 | 株式会社村田製作所 | 高周波用低損失電極 |
| US6438695B1 (en) * | 1998-10-30 | 2002-08-20 | 3Com Corporation | Secure wiretap support for internet protocol security |
| JP2002042413A (ja) * | 2000-05-18 | 2002-02-08 | Sony Corp | データ記録媒体、データ記録方法及び装置、データ再生方法及び装置、データ記録再生方法及び装置、データ送信方法及び装置、データ受信方法及び装置、コンテンツデータ |
| US8175277B2 (en) * | 2005-04-28 | 2012-05-08 | Cisco Technology, Inc. | Intercepting a communication session in a telecommunication network |
| GB0517592D0 (en) * | 2005-08-25 | 2005-10-05 | Vodafone Plc | Data transmission |
| US7631046B2 (en) * | 2006-10-26 | 2009-12-08 | Nice Systems, Ltd. | Method and apparatus for lawful interception of web based messaging communication |
| KR100858975B1 (ko) * | 2006-10-30 | 2008-09-17 | 한국전자통신연구원 | 전자감시 방법 및 그 시스템 |
| EP3079298B1 (en) * | 2007-11-30 | 2018-03-21 | Telefonaktiebolaget LM Ericsson (publ) | Key management for secure communication |
| US20090182668A1 (en) * | 2008-01-11 | 2009-07-16 | Nortel Networks Limited | Method and apparatus to enable lawful intercept of encrypted traffic |
| US8260258B1 (en) * | 2008-05-13 | 2012-09-04 | Cellco Partnership | Method of target provisioning for lawful intercept in IP multi-media service networks |
-
2009
- 2009-11-06 CN CN200910212359.4A patent/CN102055747B/zh active Active
-
2010
- 2010-03-19 WO PCT/CN2010/071168 patent/WO2010145233A1/zh not_active Ceased
- 2010-03-19 US US13/258,063 patent/US8565382B2/en active Active
- 2010-03-19 EP EP10788629.3A patent/EP2472769B1/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20030120598A1 (en) * | 2001-12-21 | 2003-06-26 | Lam Chui-Shan Teresa | Method and system for initializing a key management system |
| CN101009551A (zh) * | 2006-01-24 | 2007-08-01 | 华为技术有限公司 | 基于ip多媒体子系统的媒体流的密钥管理系统和方法 |
| CN101523797A (zh) * | 2006-10-18 | 2009-09-02 | 艾利森电话股份有限公司 | 通信网络中的密码密钥管理 |
| CN101572694A (zh) * | 2008-04-29 | 2009-11-04 | 华为技术有限公司 | 媒体流密钥的获取方法、会话设备与密钥管理功能实体 |
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2803164A4 (en) * | 2012-01-12 | 2015-09-16 | Blackberry Ltd | SYSTEM AND METHOD FOR LEGAL ACCESS TO SAFE COMMUNICATION |
| US9264227B2 (en) | 2012-01-12 | 2016-02-16 | Blackberry Limited | System and method of lawful access to secure communications |
| US9413530B2 (en) | 2012-01-12 | 2016-08-09 | Blackberry Limited | System and method of lawful access to secure communications |
| US9871827B2 (en) | 2012-01-12 | 2018-01-16 | Blackberry Limited | System and method of lawful access to secure communications |
| EP3687105A1 (en) * | 2012-01-12 | 2020-07-29 | BlackBerry Limited | System and method of lawful access to secure communications |
Also Published As
| Publication number | Publication date |
|---|---|
| CN102055747A (zh) | 2011-05-11 |
| US20120207284A1 (en) | 2012-08-16 |
| EP2472769A4 (en) | 2014-08-06 |
| US8565382B2 (en) | 2013-10-22 |
| CN102055747B (zh) | 2014-09-10 |
| EP2472769B1 (en) | 2016-08-17 |
| EP2472769A1 (en) | 2012-07-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2010145233A1 (zh) | 获取密钥管理服务器信息的方法、监听方法及系统、设备 | |
| JP2017502586A (ja) | セキュアメディアベース会議のための方法およびシステム | |
| US11617063B2 (en) | Method, apparatus, and system for changing association relationship between MCPTT user and MCPTT group | |
| CN101668016B (zh) | 鉴权方法及装置 | |
| EP2845404A1 (en) | Network application function authorisation in a generic bootstrapping architecture | |
| WO2015184410A1 (en) | Domain trusted video network | |
| WO2016165505A1 (zh) | 连接控制方法及装置 | |
| WO2022078214A1 (zh) | 签约数据更新方法、装置、节点和存储介质 | |
| CN118660023B (zh) | 设备调度接入方法、系统、可读存储介质和程序产品 | |
| US8769623B2 (en) | Grouping multiple network addresses of a subscriber into a single communication session | |
| WO2009024076A1 (en) | Method for configuring service and entity for storing service configuration | |
| EP2671366B1 (en) | Determining a location address for shared data | |
| CN105376706A (zh) | 一种订阅设备位置信息的方法和装置 | |
| US9654440B1 (en) | Modification of domain name systems using session initiation protocol messages | |
| CN108617014A (zh) | 一种业务承载建立方法和网络设备 | |
| WO2010075688A1 (zh) | Ims集群会议的创建和加入方法、装置及系统 | |
| CN105792196B (zh) | 一种mtc分组管理方法、装置及系统,网络实体 | |
| CN102984118B (zh) | 验证ip多媒体子系统用户身份的方法及自动配置服务器 | |
| CN115174387A (zh) | 配置访问管理方法、isim卡、终端及系统 | |
| CN102238175A (zh) | 指配及请求协作通信会话的控制角色的方法和装置 | |
| US9276776B2 (en) | Methods and apparatus for bandwidth management within a media over internet protocol network based on a session description | |
| CN107959674B (zh) | 网关设备、对第三方ldap服务器用户的访问控制方法及系统 | |
| EP4239977B1 (en) | Methods of initiating telecommunications sessions and devices, servers and computer software for performing the methods | |
| CN103765404A (zh) | 用于基于云的身份管理(c-idm)实现的方法和系统 | |
| CN101645882B (zh) | 基于条件的用户选择的管理方法、服务器和系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 10788629 Country of ref document: EP Kind code of ref document: A1 |
|
| REEP | Request for entry into the european phase |
Ref document number: 2010788629 Country of ref document: EP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2010788629 Country of ref document: EP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 13258063 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |