LI Assurance Fieldbookauthority · standards · evidence
Law · ETSI · 3GPP · Security · AssuranceView Markdown source

Roadmap, scope, and the safety boundary

Lawful interception (LI) is a legally authorized, targeted capability for obtaining communications data under applicable law. The engineering problem is not simply moving data. It is proving that every action had authority, stayed inside scope, preserved integrity, reached the approved recipient, expired on time, and can be audited without exposing sensitive material.

Safety boundary: this chapter teaches lawful, governed system design from public standards. It does not provide operational targeting, activation, decryption, surveillance-evasion, or covert collection instructions.

The mental model

Concept Plain meaning Control that must travel with it
Authority before capability A valid legal mandate is the root permission for every technical action Technology cannot repair a missing or invalid legal basis
Targeted and bounded Identifiers, services, jurisdiction, and time are explicitly limited Broad or ambiguous scope must stop before activation
Separation of duties No one person can authorize, configure, collect, and erase evidence alone Dual control and independent review reduce misuse
Data minimization Collect and retain only what the mandate and law permit Collateral and out-of-scope data need defined handling
End-to-end assurance Correctness covers authorization through delivery, expiry, and audit A working interface is not proof of a lawful system
Standards with national profiles ETSI and 3GPP provide interoperable technical building blocks National law and profiles decide what is actually permitted

Apply it as a controlled workflow

  1. Start with law, jurisdiction, competent authority, and an accountable policy owner.
  2. Translate the mandate into a machine-checkable scope without changing its legal meaning.
  3. Map administration, collection, mediation, delivery, receipt, expiry, and audit as separate responsibilities.
  4. Attach controls and evidence to every state transition.
  5. Test denial, expiry, duplication, loss, clock error, and insider misuse before production.
  6. Reconcile the closed case and prove de-provisioning and retention outcomes.

Evidence to demand

  • A standards applicability matrix with publication date, version, national profile, and owner.
  • A trace from legal authority to approved technical scope and controlled lifecycle state.
  • Independent audit evidence that excludes communication content from ordinary operational logs.
  • Named stop conditions for invalid, expired, conflicting, or technically unsafe requests.

Failure to reason about

A platform can be technically available yet legally unusable. If an authorization expires while a delivery queue is delayed, the design must know which already-lawful records may complete delivery, which new collection must stop, and who resolves ambiguity. The answer belongs in policy, state machines, and tested evidence—not operator memory.

Feynman check

Explain LI as a sealed, timed delivery job: a judge or competent authority supplies the permission; the provider verifies the label; machines collect only the named parcel; an approved recipient signs for it; the job stops at expiry; auditors can later prove each step.

LI Assurance FieldbookIndependent study material · verify standards and national law at primary sources