SMS (Short Message Service)

Short Message Service is the GSM-era 160-character text messaging service that operates over the SS7 signalling channel rather than a data bearer, using MAP for delivery and the SMSC for store-and-forward. Despite the rise of OTT messaging, SMS remains critical because billions of services rely on it for one-time passwords and account recovery. Its security weaknesses, interception via SS7 attacks, SIM-swap-driven OTP theft, and CLI spoofing, make SMS a poor second factor for high-value accounts and have driven adoption of SMS Home Routing and FIDO/WebAuthn alternatives.

Categories: Core NetworkSignalingIdentity and Subscriber

SMS in context

The mobile core carries subscriber sessions, mobility and policy. In 4G it is the EPC (MME, HSS, S/PGW); in 5G it is the Service-Based Architecture with AMF, SMF, UPF, AUSF, UDM and the NRF.

Signaling protocols carry the control-plane messages that set up calls, register subscribers and route SMS. SS7, Diameter, GTP-C and SIP are the four dominant families, and interconnect exposure of any of them is treated by GSMA as top-tier telecom risk.

To place SMS in the wider telecom-security picture, review IAMF, MSC, OTP Bypass Attacks, SMSC, SRI and VoLTE — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.