Entitlement servers and SIM-based Number Verification: What every MNO needs to know

Entitlement servers are no longer optional, and SIM-based Number Verification is a clear SMS OTP replacement. In this guide, explore what they are, who is already deploying these solutions, and why businesses need to act now.

Tomislav Nikić Senior Product Marketing Manager
Skip to table of contents

Mobile networks authenticate subscribers billions of times a day. Every time a phone connects to a cell tower, registers for service, or initiates a packet data session, the network verifies that the SIM card in that device is legitimate. This happens silently, constantly, and at a scale no external authentication provider can match. 

Yet for years, that capability stayed locked inside the network. The knowledge that a specific SIM is present in a specific device, the most reliable proof of identity mobile networks possess, was never available as a service that operators could commercialize or enterprises could integrate. 

That is changing. Two developments are converging to reshape how mobile user authentication works. The first is the Entitlement Configuration Server (ECS) – the entitlement server component that manages service entitlements through SIM-based authentication. The second is SIM-based Number Verification (also known as Phone Number Verification or Number Verification v2), which brings SIM-based authentication to mobile number verification. It uses the same underlying infrastructure to authenticate users by verifying the SIM associated with their mobile number, delivering what the industry has needed for years: a silent, fraud-resistant verification method without relying on one-time passwords (OTPs).

The earlier versions of Number Verification authenticate users differently. It uses the network-based approach, verifying a user’s phone number through the device’s active data session with the mobile network. 

What is an Entitlement Configuration Server?

The Entitlement Configuration Server is the GSMA TS.43-defined component mobile operators use to manage service entitlements. In practical terms, it is the system that helps a device check whether a subscriber is allowed to use a service and then provisions that service if the answer is yes. 

When a mobile device needs to confirm that a subscriber is entitled to use a specific service, the ECS is part of the real-time decision-making path. The user does not see it, but the ECS is what makes the service work consistently across devices, networks, and use cases. The ECS validates the device’s identity by confirming SIM-based credentials, checks the subscriber’s entitlements, and either grants or denies access. 

The TS.43 standard supports over a dozen use cases. The most important ones include RCS client provisioning, eSIM management, companion device enablement, satellite and non-terrestrial network (NTN) connectivity, and most strategically – SIM-based Number Verification. 

Why ECS is becoming mandatory right now

ECS has been part of the operator toolbox for a while, but the demands around it are increasing. Device ecosystems are standardizing how they connect to operator capabilities to improve customer experience. At the same time, regulators and enterprises are moving away from SMS OTP as a preferred authentication method. 

That combination changes the role of ECS. It is no longer just something operators use behind the scenes. It is becoming part of the infrastructure that determines whether a mobile service can be activated quickly, securely, and consistently. 

For operators, that matters in three ways: it helps with device and service compatibility, it supports new entitlement-based use cases, and it gives the network a role in modern authentication flows that can help enterprises regain trust through stronger, fraud-resistant authentication, especially in scenarios where SMS OTP is vulnerable to AIT fraud. 

1. Google Android Network Ready 

At Mobile World Congress Barcelona 2026, Google announced the Android Network Ready program. Under this initiative, ECS support is now mandatory for Android device certification, with three required use cases that every certified device must support, improving enhanced security and customer experience. For operators who want their networks to be Android Network Ready, and millions of Android users expect this, deploying and maintaining an ECS is no longer optional. 

2. Apple supports its own entitlement stack 

Apple already supports its own entitlement protocol stack on iOS e.g. for IMS, Facetime, iMessage and RCS services. It is anticipated that Apple will support SIM-based Number Verification in the near future. While the technical approach may differ from Google’s, the direction is the same: device manufacturers are standardizing how they talk to operator networks, and they expect operators to have the infrastructure in place. Cross-platform interoperability between iOS and Android around entitlements means ECS becomes table stakes for every operator serving both ecosystems and the authentication apps running on the mobile device.

3. Regulatory mandates are eliminating SMS OTP 

The third force is regulatory. The UAE eliminated SMS OTP as an acceptable authentication method by March 2026. In the United States, the National Institute of Standards and Technology (NIST) classified SMS OTP as not phishing-resistant in July 2025. In Malaysia, Bank Negara Malaysia instructed financial institutions to move away from SMS OTP and adopt more secure authentication methods. In Singapore, the Monetary Authority of Singapore has directed banks to phase out SMS OTP as the sole authentication factor for higher-risk transactions. In the Philippines, BSP Circular No. 1213 requires covered institutions to replace SMS- and email-based OTPs for high-risk transactions with stronger authentication methods. 

These mandates create an immediate need for alternative authentication methods, and the most secure alternative runs through the ECS. They also raise account takeover, data breaches, and customer support concerns. 

Taken together, these three forces mean that ECS is transitioning from a specialized capability to core infrastructure, much like how IMS (IP Multimedia Subsystem) shifted from optional to essential as VoLTE became the standard for voice from 4G to VoNR (Voice over New Radio) in 5G. 

What ECS enables

The real value of an ECS lies in the revenue-generating use cases it enables. Here is what a properly deployed ECS can do.

RCS provisioning 

Rich Communication Services (RCS) is the successor to SMS and, alongside OTT messaging, is now part of the current mobile messaging landscape across Android and iOS. But before any business or person-to-person RCS message can be sent, the messaging client on the device must be verified and provisioned in real time for a better customer experience. That means the device must authenticate with the ECS via EAP-AKA, receive a Temporary Token, and exchange it with the RCS Auto Configuration Server (ACS) for the configuration needed to activate messaging. For operators launching or expanding RCS for Business, ECS-based provisioning is the only path forward. 

eSIM transfer 

eSIM transfer is the number one demand driver for ECS deployments among MNOs. As physical SIM cards give way to embedded eSIMs across phones, tablets, laptops, and wearables, operators need a reliable way to manage which devices can access which services. This is especially urgent as eSIM-only devices, like the iPhone Air, enter the market. Without ECS-backed entitlement checking, operators have no standardized way to verify that a user requesting an eSIM transfer is entitled to do so. 

Companion devices and satellite connectivity

Smartwatches, tablets, and IoT devices that share a mobile subscription all need entitlement verification. The ECS handles this through the same infrastructure, authenticating user sessions in real time. Emerging use cases like satellite and non-terrestrial network (NTN) connectivity also rely on ECS-based entitlement management to authenticate devices that move between terrestrial and satellite networks. 

The common thread across all of these: one ECS investment supports multiple, independently valuable capabilities. The ROI calculation changes when the same infrastructure powers RCS, eSIM, companion devices, satellite connectivity, and SIM-based Number Verification. This shared foundation is what makes the business case stronger than any single use case alone. 

SIM-based Number Verification: The most strategic ECS use case

SIM-based Number Verification is an industry-agreed specification developed through the Linux Foundation’s CAMARA project, co-created with the GSMA Operator Platform Group, and it is a form of silent network authentication. 

The SMS OTP issue 

SMS one-time passwords remain the dominant method of mobile number verification. But their weaknesses are no longer tolerable, and the data proves it. For many industries, this is the point where SMS OTP replacement becomes a priority: 

  • 15-20% delivery failure rate: one in five users never receives the OTP code, creating friction, dropped conversions, and support costs. 
  • SIM swap fraud has surged 1,055%. Once criminals take control of a victim’s number, they can intercept calls and messages, including crucial two-factor authentication codes, enabling further fraudulent activity such as account takeovers and other forms of identity theft. 
  • Artificially Inflated Traffic (AIT) fraud, where bots trigger fake OTP requests to generate SMS delivery fees, costs the industry an estimated $2.4 billion over two years. 
  • Phone Verified Account (PVA) services use SIM farms to receive OTPs and create fake accounts at scale, undermining the integrity of identity verification systems. 

These vulnerabilities exist because SMS OTP has fundamental architectural weaknesses:

  • The SIM possession factor is not verified during authentication. The application has no way to confirm the SIM is actually in the user’s device, which leaves room for fraudulent account creation. 
  • The authenticating application is not bound to the SIM. A fraudster who intercepts the OTP can use it from any mobile device, which raises the risk of unauthorized access and account takeover for apps and services that rely on SMS OTP for login or 2FA. 
  • The SMS channel is not cryptographically secured. SMS payloads are transmitted in plaintext and are vulnerable to interception at the mobile network signaling layers. 
  • The OTP or code is transferrable. Once obtained, through malware, social engineering, or interception, it can be used by anyone, anywhere, which is why secure authentication apps are replacing it in many workflows. 

Number Verification v1: What it solved and where it falls short 

CAMARA Number Verification with network-based authentication was the first step toward OTP-free authentication. It uses network-based authentication: when a user’s device has an active packet data session on the mobile network, the operator can map the device’s IP address to its MSISDN and verify the phone number without any OTP. 

Number Verification v1 eliminated OTPs, which was a meaningful improvement. But it has some limitations: 

  • It only works over mobile data. Users on Wi-Fi, which accounts for the majority of smartphone traffic, must switch to cellular data for authentication, which hurts the user experience and often requires user intervention. 
  • It may be susceptible to well-documented exploits including man-in-the-middle proxy attacks and GPRS Tunnelling Protocol (GTP) signaling manipulation, though these can be mitigated with appropriate security measures. 
  • It requires IP-to-MSISDN mapping functionalities e.g. via HTTP header enrichment, which some carriers found tricky to deploy in view of HTTP security. 

As a result, some carriers may consider skipping Number Verification v1 entirely, waiting for a more robust solution. 

How SIM-based Number Verification changes the equation 

SIM-based Number Verification integrates with the ECS instead of observing a device’s data session. This supports seamless authentication for secure authentication flows. The device authenticates with the network through the ECS using EAP-AKA, the same cryptographic protocol used for primary network access. This confirms, with cryptographic certainty, that the SIM card is physically present in the device and that the device running the application is the same device that holds the SIM.

The technical flow works as follows: the aggregator is present in both the mobile device operating system and device-manufacturer SIM-based NV designs and is the required intermediary in the Number Verification flow. 

  1. The device application client initiates an operation with the application backend that triggers a user authentication request. The application client includes information about the subscriber’s home mobile network.
  2. The application backend then triggers a SIM-based Number Verification request to the aggregator, along with the mobile network information. The aggregator responds with the digital credential package for the application backend to relay to the device application client.
  3. The device application client then relays the digital credential package to the mobile device operating system to trigger the SIM-based Number Verification operation.
  4. The mobile device operating system validates the aggregator’s credentials and prompts the user for consent. When successfully completed, the mobile device operating system then initiates the EAP-AKA authentication with the ECS and core network nodes. This is the same SIM-based authentication that happens when a device first connects to the network, now applied to application-level verification.
  5. After successful authentication, the ECS generates a Temporary Token and relays it to the mobile device operating system.
  6. The mobile device operating system then encrypts the Temporary Token using the aggregator’s public key and shares it with the application backend to be relayed to the aggregator in the corresponding API request.
  7. The aggregator decrypts the Temporary Token with its private key and uses the embedded routing information to direct the request to the correct mobile network operator. The aggregator embeds the Temporary Token in a CIBA (Client-Initiated Backchannel Authentication) or JWT Bearer flow authorization request toward the operator’s Open Gateway platform which then forwards the token to the ECS for validation and to request for the subscriber’s SIM information within a TS.43 operation.
  8. If the ECS validates the Temporary Token successfully, the ECS responds to the Open Gateway platform with the requested user SIM information, typically the MSISDN.
  9. The CIBA or JWT Bearer flow completes, a 3-legged access token is generated using the user information from the ECS, and the aggregator calls the /verify API to confirm the MSISDN match or the /device-phone-number API to obtain the MSISDN.
  10. The aggregator subsequently responds to the application backend with the corresponding API response for the application backend to respond to the device application client initial request.
Diagram showing the flow between “APP client” and “OS” within “Mobile OS,” connected by “Application call flows” to “Brand” and “Application Backend,” then by “Aggregator call flows” to “Aggregator” with “API Aggregation,” then by “Number Verification call flows” to “Operator Platform” and “MNO,” with a lower connection from “OS” to “ECS.”
Diagram showing the Number Verification flow.

What SIM-based Number Verification means for operators: A new revenue stream 

For operators, SIM-based NV represents something rare in telecommunications: a genuinely new revenue stream built on existing infrastructure that offers strong user authentication.

The SIM is one of the most trusted assets in mobile. Every subscriber has one. The network has always known it is there, but that knowledge was never available as a commercial service. SIM-based NV changes that. It turns the network’s built-in knowledge of the SIM into a service operators can sell. One that no third party can replicate because no third party has access to the SIM authentication process until now. 

The sectors with the most urgent need are those where a failed authentication has direct financial consequences: banking, digital wallets, eCommerce, healthcare, and more. These industries have relied on OTP-based verification for years. They know not only its benefits, but also weaknesses. They are actively looking for alternatives that improve customer experience and enhance security. 

For operators, this creates a new value proposition: SIM-based NV enables value-based billing by tying commercial value to a successful verification result, rather than to SMS delivery, with pay-per-use (transactional) as the simplest model and other models such as flat fee or per-subscriber pricing available depending on scale and commercial strategy. 

One infrastructure, multiple capabilities

One of the most compelling arguments for ECS investment is that the same infrastructure that powers SIM-based NV also powers two other major revenue-generating capabilities. 

SIM-based Number Verification, eSIM management, and RCS provisioning all run on the same ECS foundation. An operator that deploys an ECS for any one of these use cases can use the same infrastructure to support the other two, as long as the ECS meets the prerequisites for each service, such as the relevant TS.43 specification version and network integration requirements. 

This changes the business case calculation entirely. A single infrastructure investment unlocks three distinct service offerings, each with its own revenue model and addressable market. SIM-based NV addresses the enterprise authentication market (worth billions in SMS OTP spend alone). eSIM addresses the device management and subscription transfer market. RCS addresses the messaging market. 

For MNOs building a business case for ECS deployment, the question should not be ‘does SIM-based NV alone justify the investment?’ The question should be ‘what is the combined return from SIM-based Number Verification, eSIM, and RCS?’ 

Infobip’s role in making SIM-based Number Verification real 

Connecting enterprises to operator network capabilities is complex. Each operator has its own infrastructure, commercial terms, and integration requirements.  

This is where Infobip fits. With direct partnerships across 190+ countries and connections to more than 800 operators globally, Infobip helps MNOs expose network capabilities to enterprise customers and turn them into commercial services. One integration gives enterprises access to CAMARA capabilities, including SIM-based Number Verification, across the operators and markets where coverage is available. Enterprises can also be reassured that SIM-based Number Verification is resistant to Artificially Inflated Traffic (AIT) fraud. 

In practice, that means helping operators bring SIM-based Number Verification, eSIM, and RCS to market through a single integration layer, while handling connectivity, consent management, and cross-operator routing so operators can focus on monetizing their infrastructure and improving customer experience. 

We have worked with operators to bring SIM-based Number Verification to production within the Open Gateway framework, working with the mobile operating system platforms and enabling the aggregator function within the flows as the accredited aggregator, handling the connectivity, consent management, and cross-operator routing so operators can focus on capturing the value.

In Brazil, Infobip partnered with Claro, TIM, and Vivo to deploy three CAMARA-compliant network APIs; Number Verifiy, SIM Swap, and Device Location, under the GSMA Open Gateway initiative. It was one of the first multi-operator Open Gateway deployments in Latin America, and it confirmed that a single integration can reach network capabilities across multiple operators without bilateral agreements for each market. 

Infobip is actively working with multiple major telecom operators on SIM-based Number Verification pilots, with production deployments in progress. For operators evaluating their ECS and SIM-based NV strategy, Infobip offers a proven path from pilot to production. 

Improve authentication and user experience with SIM-based Number Verification 

Keep reading:

Get the latest insights and tips to elevate your business

By subscribing, you consent to receive email marketing communications from INFOBIP. You have the right to withdraw your consent at any time using the unsubscribe link provided in all INFOBIP’s email communications. For more information please read our Privacy Notice