The anatomy of a lawful intercept.
A CALEA solution isn’t one box — it’s a chain of components that must provision a target, capture the right traffic, mediate it into a standardized format, and deliver it to an authorized agency without ever touching an innocent subscriber. Here’s how each piece of Subsentio’s lawful intercept system works.
One discipline, every network type.
Subsentio’s lawful intercept technology deploys across the network types carriers actually run — in either an active configuration (the mediation server talks directly to the network element) or a passive one (the Safe Harbor Probe watches a TAP or SPAN mirror port). Both end the same way: a standardized stream in the Subsentio NOC, routed to the agency named in the order.
Circuit-switched
Legacy time-division-multiplexing environments. The access function provisions the target and intercepts call-data and call-content — content is sometimes handled independently via a dial-out function. Targeted traffic is routed to the Subsentio NOC over a secure VPN tunnel, converted to a standardized LI format, and delivered to the agency’s collection tunnel.
Voice over IP (VoIP)
Deployed active or passive. Active: the access function provisions the target and delivers a data stream of CII/CC to the mediation server. Passive: the Subsentio Safe Harbor Probe watches signaling and audio on a TAP/SPAN port, filters the target’s traffic once identified, and mediates it into a standardized stream to the NOC.
ISP / broadband
Active or passive. Active: the access function delivers the data streams to the mediation server for CmII/CmC delivery. Passive: the Safe Harbor Probe monitors authentication and IP traffic on a TAP/SPAN port, captures the identified target, and mediates a standardized LI stream to the NOC for delivery to the LEA.
Mobile packet-data
Active or passive. The access function provisions the target and delivers the data streams to the mediation server; in passive mode the Safe Harbor Probe monitors authentication and IP traffic on a TAP/SPAN port, then filters and mediates the target’s streams into a standardized LI format bound for the NOC.
What sits between the switch and the agency.
Every accurate intercept passes through the same functional components — properly implemented and able to speak to the network elements around them.
Access function
Provisions the target on the network element and taps call-data and call-content — actively via protocol, or passively via probe on a mirror port.
Mediation & delivery server
Three jobs: target/provisioning, session collection, and standardized delivery — converting intercepted traffic into the lawful delivery standard for the agency.
Provisioning administration
A unified interface to administer different network and target types — over SSH, HTTPS, the X1 interface, or a vendor mechanism.
Provisioning database
Stores configuration, target criteria, user records and activity logs — encrypted in flight and at rest on an industry-standard database.
Subsentio NOC
Receives targeted traffic over a site-to-site IPSec VPN, formats it to standard, and hands it to the agency’s collection tunnel.
LEA collection servers
The agency-side clients that decode, display and record the delivered stream — used by the FBI, DEA, Secret Service, US Marshals, DHS and others.
Standardized delivery, end-to-end encrypted.
The mediation server delivers call-data and call-content to the agency’s collection server in a protocol designed specifically for lawful interception. Transport is a TCP/IP (sometimes UDP/IP) socket from the Subsentio NOC to the LEA collection point.
Every connection — carrier to Subsentio, and Subsentio to agency — is a site-to-site IPSec VPN. Sessions are encapsulated by the IPSec Encapsulating Security Payload (ESP), which provides confidentiality, data-origin authentication and integrity between the VPN endpoints, with matched Phase-1/Phase-2 IPSec and ISAKMP parameters and encryption domains.
Built to the safe-harbor standards
Conform to the standard for your network type and CALEA §107 deems you compliant.
Need a lawful intercept solution for your network?
We operate every component above as a trusted third party — so your team never has to. Tell us your network type and we’ll map the fit.