SMPP (Short Message Peer-to-Peer)

Short Message Peer-to-Peer is the IETF/SMS-Forum protocol used between SMSCs, ESMEs, and aggregators to submit and deliver SMS messages over IP. SMPP carries A2P traffic that includes one-time passwords, marketing, and notifications, and is the principal interface used by enterprise SMS platforms. Weak authentication, plaintext transport, and lax binding controls have enabled high-profile abuse such as SMS spoofing and OTP interception, so TLS, IP allow-listing, and aggregator due diligence are essential.

Categories: Radio Access NetworkCore NetworkSecurity Controls

SMPP in context

The radio access network is where mobile devices attach to the operator's infrastructure. Attacks in this layer include IMSI catching, rogue base stations and downgrade attacks; defenses rest on mutual authentication, integrity-protected signaling and Open RAN supply-chain hygiene.

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

To place SMPP in the wider telecom-security picture, review Cipher, HTTP, Inter-Network Function Authentication, OAuth2 in 5G Core, NRF Poisoning and 1G — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.