A method of facilitating the lawful interception of an IP session between
two or more terminals 12,13, wherein session uses encryption to secure
traffic. The method includes storing a key allocated to at least one of
terminals 12,13 or to at least one of the subscribers using one of the
terminals 12,13, at the terminal 12,13 and at a node 5,8 within a network
1,6 through which session is conducted, or a node coupled to that
network. Prior to the creation of session, a seed value is exchanged
between the terminal 12,13 at which the key is stored and node 5,8. The
key and the seed value are used at both the terminal 12,13 and the node
5,8 to generate a pre-master key. The pre-master key becomes known to
each of the terminals 12,13 involved in the IP session and to the network
node 5,8. The pre-master key is used, directly or indirectly, to encrypt
and decrypt traffic associated with IP session.