|
TECHNICAL SPECIFICATION
Lawful Interception (LI);
Handover Interface and
Service-Specific Details (SSD) for IP delivery;
Part 1: Handover specification for IP delivery
---------------------- Page: 1 ----------------------
2 ETSI TS 102 232-1 V3.17.1 (2018-09)
Reference
RTS/LI-00159-1
Keywords
handover, IP, lawful interception, security
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Important notice
The present document can be downloaded from:
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the
print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
If you find errors in the present document, please send your comment to one of the following services:
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying
and microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.
© ETSI 2018.
All rights reserved.
TM TM TM
DECT , PLUGTESTS , UMTS and the ETSI logo are trademarks of ETSI registered for the benefit of its Members.
TM TM
3GPP and LTE are trademarks of ETSI registered for the benefit of its Members and
of the 3GPP Organizational Partners.
oneM2M logo is protected for the benefit of its Members.
GSM and the GSM logo are trademarks registered and owned by the GSM Association.
ETSI
---------------------- Page: 2 ----------------------
3 ETSI TS 102 232-1 V3.17.1 (2018-09)
Contents
Intellectual Property Rights . 6
Foreword . 6
Modal verbs terminology . 6
Introduction . 7
1 Scope . 8
2 References . 8
2.1 Normative references . 8
2.2 Informative references . 11
3 Definitions, symbols and abbreviations . 11
3.1 Definitions . 11
3.2 Symbols . 12
3.3 Abbreviations . 12
4 General . 13
4.1 Functionality . 13
4.2 Intercepted data types . 14
4.2.1 Introduction. 14
4.2.2 Interception at network operator or access provider . 14
4.2.3 Interception at service providers . 14
4.3 Relationship to other standards . 15
4.4 Handover for GPRS/UMTS/EPS and 3GPP CS Domains . 16
4.4.1 PS Access . 16
4.4.2 Applications . 17
4.5 Common parameters. 17
5 Headers . 17
5.1 General . 17
5.2 Description and purpose of the header fields . 18
5.2.1 Version . 18
5.2.2 LIID . 18
5.2.3 Authorization country code. 18
5.2.4 Communication identifier . 18
5.2.5 Sequence number . 18
5.2.6 Payload timestamp . 19
5.2.7 Payload direction . 19
5.2.8 Payload type. 19
5.2.9 Interception type . 20
5.2.10 IRI type . 20
5.2.11 Interception Point Identifier . 20
5.2.12 Session direction . 20
5.3 Encoding of header fields . 20
6 Data exchange . 21
6.1 Introduction . 21
6.2 Handover layer . 21
6.2.1 General . 21
6.2.2 Error reporting . 22
6.2.3 Aggregation of payloads . 23
6.2.4 Sending a large block of application-level data . 23
6.2.5 Padding data. 23
6.2.6 Payload encryption . 24
6.3 Session layer . 24
6.3.1 General . 24
6.3.2 Opening and closing connections . 24
6.3.3 Buffering . 24
ETSI
---------------------- Page: 3 ----------------------
4 ETSI TS 102 232-1 V3.17.1 (2018-09)
6.3.4 Keep-alives . 25
6.3.5 Option negotiation . 25
6.3.5.1 Introduction . 25
6.3.5.2 Option negotiation message exchange . 26
6.3.6 PDU acknowledgement . 27
6.4 Transport layer . 27
6.4.1 Introduction. 27
6.4.2 TCP settings . 27
6.4.3 Acknowledging data . 28
6.5 Network layer . 28
7 Delivery networks . 28
7.1 Types of network . 28
7.1.1 General . 28
7.1.2 Private networks . 28
7.1.3 Public networks with strict control . 29
7.1.4 Public networks with loose control . 29
7.2 Security requirements . 29
7.2.1 General . 29
7.2.2 Confidentiality and authentication . 29
7.2.3 Integrity . 29
7.3 Further delivery requirements . 30
7.3.1 Test data . 30
7.3.2 Timeliness . 30
Annex A (normative): ASN.1 syntax trees . 31
A.1 ASN.1 syntax tree for HI2 and HI3 headers. 31
A.2 ASN.1 specification. 32
A.3 Importing parameters from other standards . 42
Annex B (informative): Requirements . 43
B.1 Types of intercepted information . 43
B.2 Identification of traffic . 43
B.3 Performance . 43
B.4 Timeliness . 44
B.5 Reliability and availability . 44
B.6 Discarding information. 44
B.7 Security. 44
B.8 Other . 45
Annex C (informative): Notes on TCP tuning. 46
C.1 Implement IETF RFC 5681 . 46
C.2 Minimize roundtrip times . 46
C.3 Enable maximum segment size option . 46
C.4 Path MTU discovery . 46
C.5 Selective acknowledgement . 46
C.6 High speed options . 46
C.7 PUSH flag . 47
C.8 Nagle's algorithm . 47
C.9 Buffer size . 47
ETSI
---------------------- Page: 4 ----------------------
5 ETSI TS 102 232-1 V3.17.1 (2018-09)
Annex D (informative): IRI-only interception . 48
D.1 Introduction . 48
D.2 Definition HI information . 48
D.3 IRI deriving . 48
D.4 IRI by post and pre-processing HI3 information . 49
Annex E (informative): Purpose of profiles . 50
E.0 Background . 50
E.1 Formal definitions . 50
E.2 Purpose of profiles . 50
Annex F (informative): Traffic management of the handover interface . 52
F.0 Rationale . 52
F.1 Factors to consider . 52
F.1.0 Background . 52
F.1.1 Burstiness . 52
F.1.2 Mixed content . 52
F.1.3 Network facilities for traffic management . 53
F.1.4 Evidentiary considerations . 53
F.1.5 National considerations . 53
F.2 Traffic management strategies . 53
F.3 Bandwidth estimation . 54
F.4 National considerations . 54
F.5 Implementation considerations . 54
F.5.1 Volatile versus non-volatile storage . 54
F.5.2 Maximum buffering time . 55
F.5.3 Transmission order of buffered data . 55
F.5.4 Buffer overflow processing . 55
Annex G (normative): Implementation of payload encryption . 56
Annex H (informative): ETSI TS 102 232 family relationship . 57
Annex I (informative): Option negotiation . 60
I.0 Summary . 60
I.1 Example use cases . 60
I.1.1 Option negotiation not supported in LGW . 60
I.1.2 Simple negotiation by both endpoints . 61
I.1.3 Simple DF-only option request . 62
I.1.4 Simple LGW-only option request . 63
I.1.5 Complex negotiation . 64
Annex J (normative): Implementation of Integrity Checks . 65
J.1 Definitions . 65
J.2 Process description . 65
J.3 Example integrity Chain . 66
Annex K (informative): Change request history . 68
History . 73
ETSI
---------------------- Page: 5 ----------------------
6 ETSI TS 102 232-1 V3.17.1 (2018-09)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in
respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web
server (https://ipr.etsi.org/).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web
server) which are, or may be, or may become, essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
Foreword
This Technical Specification (TS) has been produced by ETSI Technical Committee Lawful Interception (LI).
The present document is part 1 of a multi-part deliverable covering the Handover Interface and Service-Specific Details
(SSD) for IP delivery, as identified below:
Part 1: "Handover specification for IP delivery";
Part 2: "Service-specific details for messaging services";
Part 3: "Service-specific details for internet access services";
Part 4: "Service-specific details for Layer 2 services";
Part 5: "Service-specific details for IP Multimedia Services";
Part 6: "Service-specific details for PSTN/ISDN services";
Part 7: "Service-specific details for Mobile Services".
The ASN.1 module is also available as an electronic attachment to the original document from the ETSI site (see
clause A.2 for more details).
Modal verbs terminology
In the present document "shall", "shall not", "should", "should not", "may", "need not", "will", "will not", "can" and
"cannot" are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of
provisions).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
ETSI
---------------------- Page: 6 ----------------------
7 ETSI TS 102 232-1 V3.17.1 (2018-09)
Introduction
The objective of the present document is to form the basis for a standardized handover interface for use by both
telecommunications service providers and network operators, including Internet Service Providers that will deliver the
interception information required by Law Enforcement Authorities under various European treaties and national
regulations.
The present document describes how to handover intercepted information via IP-based networks from a CSP to an
LEMF. The present document covers the transportation of traffic, but does not specify functionality within CSPs or
LEMF (see clause 4.1). The present document handles the transportation of intercepted Content of Communication
(CC), Intercept-Related Information (IRI), transport related information (TRI), and HI1 notification information. The
tasking and management of Lawful Interception via the HI1 interface is outside the scope of the present document.
The present document is intended to be general enough to be used in a variety of situations: it is not focused on a
particular IP-based service. The present document therefore provides information that is not dependent on the type of
service being intercepted. In particular the present document describes delivery mechanisms (clause 6), and the
structure and header details (clause 5) for both HI2 and HI3 information.
References within the main body of the present document are made if applicable to the 3GPP specification number with
in square brackets the reference number as listed in clause 2. In clause 2 "References" the corresponding ETSI
specification number is indicated with a reference to the 3GPP specification number. 3GPP specifications are available
faster than the equivalent ETSI specifications.
ETSI
---------------------- Page: 7 ----------------------
8 ETSI TS 102 232-1 V3.17.1 (2018-09)
1 Scope
The present document specifies the general aspects of HI2 and HI3 interfaces for handover via IP based networks.
The present document:
• specifies the modular approach used for specifying IP based handover interfaces;
• specifies the header(s) to be added to IRI and CC sent over the HI2 and
...