GMLC (Gateway Mobile Location Centre)

Also known as: Gateway Mobile Location Center

The Gateway Mobile Location Centre is the node that handles location-service (LCS) requests. It is the gateway through which external clients obtain a subscriber's location. It queries the HLR or HSS for routing information and the serving node (MSC, SGSN, MME or AMF) for the position, over SS7/MAP, Diameter and the Le interface. Because it turns signalling access into subscriber location, an exposed or abused GMLC is central to location-tracking risk.

Categories: Core NetworkIdentity and SubscriberThreats and Attacks

GMLC in context

The mobile core is where subscriber sessions, mobility and policy live. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF. Core exposure is the difference between a single-subscriber leak and a fleet-wide breach.

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) are the anchor for authentication, charging, lawful interception and fraud analytics. Any protocol or interface that leaks a permanent identifier is treated as a serious privacy defect, which is why 5G introduced SUCI concealment on the air interface.

To place GMLC in the wider telecom-security picture, review Location Tracking Attacks, HLR, HSS, MAP, Any-Time Interrogation (ATI) and SRI.

Related terms

Equipment

Location services (GMLC, LMF, E-SMLC, SUPL/SLP)

Articles in the P1 mobile network security guide

Related topic hubs

  • SS7 Security SS7/MAP/CAP/SCCP attacks and defenses across 2G/3G interconnect.
  • SS7 Firewall GSMA FS.11 category 1/2/3 SS7 message screening at the STP edge.
  • Diameter Attacks S6a IDR/PUR/CLR abuse, subscriber tracking, LTE signaling attacks.
  • Signaling Firewall Unified SS7/Diameter/GTP/SMS signaling firewall framework.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.