HLR (Home Location Register)

The Home Location Register is the master subscriber database in 2G and 3G mobile networks, storing IMSI, MSISDN, service profile, authentication keys, and the current visited network of every subscriber. The MSC, VLR, SMSC, and other network elements query the HLR over MAP/SS7 to authenticate users, route calls and SMS, and apply service permissions. Because compromise of the HLR exposes every subscriber's identity, location, and authentication material, it is one of the most security-sensitive systems in a mobile operator and a primary target for both insider abuse and SS7 attacks.

Categories: Core NetworkSignalingRoaming and Interconnect

HLR in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

To place HLR in the wider telecom-security picture, review FS.07, FS.19, GGSN, GTP, GTP Firewall and HSS — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.