XMPP (Extensible Messaging and Presence Protocol)

Extensible Messaging and Presence Protocol is the IETF XML-based standard (RFC 6120) for near-real-time messaging, presence, and request-response services. It powers federated chat networks, parts of messaging clients (including major consumer chat platforms), gaming and IoT messaging. XMPP supports TLS, SASL authentication, and end-to-end extensions such as OMEMO.

Categories: Security ControlsProtocols and StandardsEncryption and Cryptography

XMPP in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom security is written into standards from 3GPP, GSMA, ETSI, IETF and ITU-T. Understanding which body owns which specification, and how they interlock, is essential for both design and audit work.

To place XMPP in the wider telecom-security picture, review HKDF, DTLS-SRTP, OASIS, SSH, TR-069 and Zigbee: each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

Related topic hubs

  • SEPP Security N32-c/N32-f, PRINS, JWE and OAuth 2.0 at the 5G roaming edge.
  • NAS Security Non-Access Stratum security, integrity and ciphering algorithms.

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.