Что такое LEMF? За кулисами современного центра мониторинга правоохранительных органов

Архитектура LEMF: центр мониторинга правоохранительных органов, получающий данные HI1, HI2 и HI3 от телекоммуникационных провайдеров для управления ордерами, а также для анализа аудиозаписей и IP-трафика

A LEMF (Law Enforcement Monitoring Facility) is the system on the law enforcement side of lawful interception. It receives, records, decodes and analyses the data that telecommunication service providers (CSPs) deliver under a court order. For years, a LEMF was essentially a very secure call recorder. Today it has to manage hundreds of obligated providers and thousands of warrant lifecycles, and above all it has to turn encrypted IP traffic into usable intelligence.

This guide explains what a modern LEMF does, which ETSI interfaces it relies on, why fax is still part of the picture, and why IP data analytics with deep packet inspection (DPI) is now what sets one LEMF apart from another.

Key Takeaways

  • A LEMF is the agency-side counterpart to the operator’s mediation function. It receives warrant-related information via HI1, intercept-related information (IRI) via HI2 and content of communication (CC) via HI3.
  • Управление CSP (provider onboarding, handover endpoints, certificates, delivery quality) is as important as the recording itself.
  • Управление ордерами covers the full lifecycle, from court order and LIID assignment to activation, extension and deactivation. Electronic interfaces such as ETSI TS 103 120 for orders and Germany’s ETSI-ESB for information requests are replacing fax, but fax fallback workflows are still required.
  • Listening to audio is still a core task. Most investigative value, however, now lies in Аналитика IP-адресов: session reconstruction, DPI-based classification of encrypted apps, timelines, maps and relationship graphs.
  • Evidence integrity (signed raw data, audit trails, versioned decoding) decides whether results hold up in court.

What Is a LEMF?

In the ETSI and 3GPP lawful interception reference model, the CSP operates the administration function (ADMF), the points of interception and a mediation/delivery function. The law enforcement agency (LEA) operates the LEMF. Between the two sit the handover interfaces:

  • HI1 carries administrative information: warrant activation, modification and deactivation. For the basics, see our article on HI1, HI2 and HI3.
  • HI2 carries IRI: who communicated with whom, when, from which location and with which identifiers.
  • HI3 carries the content: voice, video, messages or raw IP packets.

The LEMF is where these three streams come together, are matched to a case and are made available to authorised investigators, analysts and interpreters.

The Building Blocks of a Modern LEMF

Module Цель Typical standards / interfaces
Управление CSP Register obligated providers, endpoints, certificates, test intercepts, delivery monitoring ETSI TS 102 232-1, TLS/IPsec, national crypto gateways
Управление ордерами Case files, LIIDs, deadlines, activation, extension, deactivation ETSI TS 103 120 (HI1), fax fallback; for information requests ETSI-ESB / E-Mail-ESB (Germany)
Data reception (backend) Receive and store HI2/HI3 around the clock, buffer, check integrity ETSI TS 101 671 / ES 201 671, ETSI TS 102 232-1 to -7, 3GPP TS 33.108 / 33.128
Декодирование Reconstruct calls, messages, web sessions, e-mails, files Protocol decoders, OCR, metadata extraction
IP analytics & DPI Classify encrypted traffic, fingerprint, correlate, visualise DPI signatures, TLS fingerprints (JA4), flow analytics
Аудио-рабочая станция Playback, transcription, speaker identification, live monitoring SIP/RTP, speech-to-text, voice biometrics
Evidence & export Chain of custody, signed exports, court-ready reports Hashing, digital signatures, audit logs
Inter-LEMF exchange Share intercept data between agencies ETSI TS 103 462 (ILHI)

CSP Management: The Part Nobody Talks About

An agency does not receive data from one operator, but from dozens or even hundreds: mobile network operators, MVNOs, fixed-line ISPs, VoIP providers and, increasingly, OTT and cloud communication services. Each one has its own handover endpoints, IP addresses, certificates, supported standard versions and quirks.

A mature LEMF therefore includes a dedicated Управление CSP module:

  • Provider registry: legal entity, contact points, 24/7 hotline, supported services and ETSI versions, and the mapping of target identifier types (MSISDN, IMSI, IMEI, SIP URI, user name, IP address) to the provider that has to be addressed.
  • Endpoint and crypto management: IP addresses of the CSP delivery functions (ideally with human-readable aliases in the monitoring view), certificate lifecycles and the national crypto gateways that protect the handover.
  • Onboarding and test intercepts: structured acceptance tests before a new provider goes live, including format validation of HI2 and HI3 records. The same discipline applies in reverse when an operator connects a new agency.
  • Delivery quality monitoring: automated checks for missing sequence numbers, malformed records, keep-alive failures and IRI that cannot be matched to content.

The quality of this module decides how quickly a new warrant goes live, and whether analysts end up working with complete data.

Warrant Management: From Court Order to Deactivation

Every interception starts with a legal order. The LEMF’s warrant management maps this order onto a technical measure:

  1. Case creation: investigating authority, public prosecutor’s file number, legal basis and responsible investigators.
  2. Measure definition: target identifiers, services (voice, SMS, data, messaging), start and end dates, and the addressed CSP.
  3. LIID assignment: a unique Lawful Interception Identifier ties every IRI and CC record back to exactly this measure.
  4. Transmission to the CSP: electronically via HI1 wherever possible.
  5. Deadline control: automatic reminders before expiry, extension workflows and immediate deactivation when the order ends.
  6. Four-eyes principle and audit trail for every step.

HI1 and ETSI TS 103 120

ETSI TS 103 120 defines a structured, XML-based interface for warrant information. It can carry authorisations, tasking objects and delivery instructions between agencies and providers. It replaces paper and fax, cuts activation times and removes typing errors from target identifiers. For a deeper look, read ETSI TS 103 120 explained.

ETSI-ESB and E-Mail-ESB in Germany

In Germany, the Technical Directive TR TKÜV describes the ETSI-ESB procedure (Elektronische Schnittstelle Behörden) for information requests and responses, such as traffic data requests. It is based on ETSI TS 102 657. The TR TKÜV also describes the lighter E-Mail-ESB procedure, and it references ETSI TS 103 120, the ETSI interface for warrant information, as an additional electronic option. A LEMF operated by a German agency, or one that works with German CSPs, must be able to handle both. The upcoming rules on quick freeze and Хранение IP-адресов will add new request types to these channels.

Why Fax Is Still Part of the Picture

Fax is outdated, but it has not disappeared. Many smaller providers and some cross-border processes still accept orders only by fax. Agencies therefore still expect:

  • Fax templates for activation, extension and deactivation, filled automatically from the case data (authority, file number, target identifier, LIID, period, contact person).
  • Fax reception with OCR, so that returned confirmations are indexed and searchable.
  • A fax viewer in the analysis application, because fax is also a communication service that can be intercepted.

The goal is to run fax as a controlled fallback while moving every provider that can support it to HI1 or ESB.

Receiving the Data: HI2 and HI3 at Scale

The LEMF backend must accept deliveries around the clock and never lose data, even when a site fails or downstream storage is unavailable. Typical requirements are:

  • Active/active clustering across two geographically separated sites, with each site able to carry most of the load on its own.
  • Legacy and IP reception in parallel: ISDN primary rate interfaces (with a migration path to SIP), plus Gigabit or 10-Gigabit IP inputs for ETSI TS 102 232 deliveries.
  • Local buffering on the receiving servers, so that several days of raw data survive a storage outage.
  • Digital signing of raw data immediately after it is stored, so that integrity can be proven at any time.
  • Correlation of IRI and CC: matching by correlation number, and rule-based assignment of IRI-CONTINUE and IRI-REPORT records that arrive without matching content. For background, see IRI vs CC.
  • Standard support: ETSI TS 101 671 / ES 201 671 for circuit-switched services, ETSI TS 102 232 parts 1 to 7 for IP-based services, 3GPP TS 33.108 and TS 33.128 for mobile networks up to 5G, and ETSI TS 103 462 for handover between LEMFs.

Listening: The Audio Workbench

Voice interception is far from obsolete. Investigators expect a professional audio workbench:

  • Playback with markers, loops, direction-separated channels (incoming/outgoing), speed control with pitch correction and audio filters, without ever changing the original recording.
  • Live monitoring of prioritised measures, including call-out to authorised phone numbers with PIN authentication.
  • Speech-to-text и speaker identification to search hours of audio in minutes.
  • Transcription windows with templates, links between related products and full-text search across a whole case.
  • Role-based access for interpreters, limited to the recordings they are assigned.

The Real Differentiator: IP Data Analytics and Deep Packet Inspection

For most targets today, the bulk of intercepted data is IP traffic, and most of it is encrypted. A LEMF that can only show “10 GB of TLS” is of little use. This is where глубокий анализ пакетов and analytics come in:

  • Session reconstruction and decoding: web pages, e-mail (POP3, IMAP, SMTP), file transfers, VoIP calls and unencrypted chat protocols are rebuilt as readable “products”, including metadata and attachments opened in a secure sandbox.
  • Classification of encrypted services: even when content cannot be recovered, DPI identifies the application (for example WhatsApp, Signal, Threema or Telegram) and shows how much data was exchanged and when. Agencies increasingly expect classifiers to be updated continuously and to be adjustable by their own staff.
  • Content classification: decoded content is automatically assigned to categories such as messaging, shopping, finance or violence.
  • OCR and metadata extraction from images, documents and faxes (EXIF, IPTC), all indexed for full-text search.
  • Timeline view: every protocol and product on one zoomable, second-accurate timeline, synchronised with the product list.
  • Drill-down traffic analysis, similar to a network monitoring tool, restricted to the measures an analyst is authorised for.
  • Geo-analytics: location data from IRI and from apps on a map, movement paths, cell-ID-to-coordinate imports and geofence alerts when targets enter or leave an area or meet each other.
  • Entity and relationship graphs that link phone numbers, accounts, devices and locations to people and groups.
  • Rule-based alerts on phone numbers, IP identifiers, keywords, time windows and geo zones, delivered in the application, by e-mail or by SMS.
  • PCAP hand-off to tools such as Wireshark, and a decoder API that lets the agency add its own protocol modules without changing the core.

We look at how TLS fingerprinting, traffic pattern recognition and IP correlation work in our next article in this series. For the impact of encrypted DNS, see Encrypted DNS (DoH/DoT) and lawful interception.

Evidence Integrity, Privacy and Roles

A LEMF produces evidence, so it must meet the standards of a court:

  • Chain of custody: signed raw data, hashed exports and a complete audit log of who accessed what and when.
  • Versioned decoding: if a decoder is updated and data is decoded again, earlier results and annotations stay available, and changes are shown in a history.
  • Protection of privileged content: recordings that fall under an exclusionary rule (for example the core area of private life) can be flagged and locked, subject to administrator approval.
  • Role model: system administrators, LI administrators, case managers, analysts and interpreters, each with the least privilege they need, down to case level.
  • Рабочие процессы удаления that document the removal of data once retention is no longer lawful.

LEMF Buyer’s Checklist

  • Supports ETSI TS 101 671, TS 102 232-1 to -7, 3GPP TS 33.108 / 33.128 and has a roadmap for TS 103 120 and TS 103 462
  • Offers structured CSP management with onboarding tests and delivery quality monitoring
  • Provides warrant management with deadlines, the four-eyes principle, ESB support and fax fallback
  • Classifies encrypted apps with DPI, with continuous updates and agency-adjustable rules
  • Includes a decoder plugin API and PCAP export
  • Provides timeline, map, graph and alerting in one application
  • Signs data on ingest, keeps a complete audit trail and versions its decoding
  • Runs active/active with local buffering and scales horizontally

How ICS Helps Law Enforcement Agencies and Operators

ICS International Carrier Services has more than 20 years of experience in telecommunications, lawful interception and compliance, holds multiple BNetzA acceptances and works with security-cleared staff. Because we operate LI on the provider side every day, we know exactly what arrives at a LEMF, and what goes wrong on the way.

  • Требования и сопровождение тендера: we help agencies define realistic, standards-based LEMF requirements, from ETSI interfaces to DPI and analytics.
  • Внедрение CSP и тестирование интерфейса: handover configuration, certificate management, format validation and delivery testing for new providers.
  • HI1 / ESB integration: connecting warrant management to ETSI TS 103 120 and German ESB workflows, including controlled fax fallback.
  • Обеспечение качества доставки: automated validation of HI2/HI3 streams and completeness monitoring.
  • ICS LEMF: our own law enforcement monitoring facility software with CSP and warrant management, an audio workbench and DPI-based IP analytics. Operators use the Test LEMF edition to verify their HI2/HI3 delivery. See ICS LEMF.
  • Custom decoders and integrations built to fit your environment. See Интеграция и индивидуальная разработка.
  • Обучение for technical teams on ETSI standards, interfaces and troubleshooting.

Learn more about our law enforcement monitoring solution, our work with regulators and law enforcement, or request an ICS LEMF demo.

Часто задаваемые вопросы

What does LEMF stand for?

LEMF stands for Law Enforcement Monitoring Facility. It is the system operated by a law enforcement agency to receive, record and analyse lawfully intercepted telecommunications from service providers.

В чём заключается разница между LEMF и LIMS?

A LIMS (Система управления законным перехватом) runs on the operator side. It administers interception targets and controls the network’s points of interception and the mediation function. The LEMF runs on the agency side and receives the results. The two are connected through the HI1, HI2 and HI3 handover interfaces.

Which ETSI standards must a LEMF support?

At a minimum, ETSI TS 101 671 / ES 201 671 for circuit-switched services and ETSI TS 102 232 parts 1 to 7 for IP services, plus 3GPP TS 33.108 and TS 33.128 for mobile networks. ETSI TS 103 120 (warrant interface) and ETSI TS 103 462 (inter-LEMF handover) are increasingly required.

Can a LEMF analyse encrypted traffic?

A LEMF cannot break end-to-end encryption. With deep packet inspection, TLS fingerprinting and flow analysis, however, it can identify which application was used, when and how intensively, and correlate that activity with other data in the case.

Why do LEMFs still support fax?

Some providers and cross-border procedures still only accept orders by fax. A modern LEMF generates fax orders from case data, and indexes returned faxes with OCR, while providers are gradually moved to electronic interfaces such as ETSI TS 103 120 or ESB.

Внешние ресурсы

Прокрутить вверх
ICS
Обзор конфиденциальности

На этом сайте используются файлы cookie, что позволяет нам обеспечить наилучшее качество обслуживания пользователей. Информация о файлах cookie хранится в вашем браузере и выполняет такие функции, как распознавание вас при возвращении на наш сайт и помощь нашей команде в понимании того, какие разделы сайта вы считаете наиболее интересными и полезными.