Lawful intercept in a VoIP network: where the taps really sit
Short version: in a packet voice network, signalling and media take different paths — so interception has to catch them in different places and then prove they belong together. Signalling is easy: it always crosses the core. Media is the hard part, because it only passes a tappable point if the network makes it do so. That single fact drives most of the engineering.
The two products come from two different places
IRI — the who-called-whom record — falls out of signalling, and every SIP message for a subscriber passes their S-CSCF (or, in a plainer SIP network, the proxy/registrar). So the IRI point of interception is simply the box already reading the signalling, emitting an event per REGISTER, INVITE, answer and release on X2.
Content is different. RTP flows wherever SDP pointed it, and a network that allows direct media — endpoint to endpoint, the ideal for latency — has nothing in the media path to copy packets from. Content interception therefore depends on a media-plane node the call can be held at: the SBC or IMS access gateway at the edge, the transition gateway at an interconnect, or the media gateway at PSTN breakout. For a warranted target the network quietly ensures media anchors at such a node, which then mirrors the streams onto X3. Done correctly this is indistinguishable from ordinary anchoring — operators anchor media all the time for NAT and topology reasons anyway.
What encryption changes — and what it does not
- Access encryption (TLS + SRTP to the SBC): changes nothing. The operator's edge terminates it; inside the border the signalling and media the POIs see are clear. The encryption protected the radio/internet leg, which was its job.
- Interconnect encryption: same story at the transition gateway.
- True end-to-end encryption (the OTT messenger model): changes everything. If the operator never holds keys, X3 can only deliver ciphertext, and the standards say exactly that — deliver what you have. This is the technical core of every "crypto wars" policy argument, and it is why those arguments are about apps, not about carrier voice: VoLTE and carrier SIP are operator-terminated by construction.
Correlation: proving the streams belong to the warrant
A delivered call is only evidence if the pieces bind together. Each IRI event and
each CC stream carries the warrant's LIID plus a correlation identifier generated at
interception time; the mediation layer uses them to present "this audio goes with
this call record". Inside IMS, the network's own correlation key — the
icid-value in P-Charging-Vector — often seeds that
binding, which is a nice reminder that LI mostly reuses the machinery the network
already has for billing.
Coexisting with SIP without breaking it
The undetectability requirement has a practical engineering translation: the tap must be a copy, never an inline hop. No extra Via, no Record-Route entry, no added latency a target could measure, no different behaviour when the X3 link is down (delivery buffers or fails silently — the call must proceed regardless). The POI mirrors packets and emits events; the call's own state machine never learns about it. In IMS the intercept logic is embedded in nodes that were already in the path, so nothing about the path changes at all.
What this means for the engineer reading traces
- You will never see it. A correctly built intercept leaves no fingerprint in SIP or RTP. If a capture seems to show one, what it is actually showing is ordinary media anchoring or port mirroring for operations.
- "Could the intercept have broken the call?" — the answer the architecture is built to guarantee is no. Faults travel the other direction: network problems break interception, not vice versa. Debug the call as a call.
- Your own monitoring is the same physics. Port mirroring, SBC "record this call" features, SIPREC recording — operationally these are the same copy-the-stream problem, with the same failure mode: the copy silently missing media the original happily carried. If your recording platform has gaps, ask where media actually flowed — the answer is usually "not through the box doing the copying".
- Legal line worth respecting: everything above is the standardised, warrant-driven system. Capturing traffic you operate, for troubleshooting, is normal engineering. Intercepting other people's communications without authority is a crime more or less everywhere. The tooling on this site is for the first thing.
hiccup analyses the captures you take on your own network — pairs legs, reads SDP against the media that actually flowed, and finds where the audio went missing. Self-hosted, free for individual users.
upload a trace