For years, SMS one-time passwords (OTPs) have been the default method of verifying digital identity. Banks use them to authorise payments, online retailers rely on them to validate purchases, and government services continue to send verification codes to millions of users every day.
Yet the security assumptions underpinning SMS authentication have changed dramatically.
Fraudsters have become increasingly adept at exploiting weaknesses in SMS-based verification through SIM swap attacks, phishing campaigns and message interception.
As a result, one of the most widely used authentication methods has also become one of the most frequently targeted.
For operators, this creates an important challenge. The mobile network already possesses one of the strongest identity credentials available, yet many digital services continue to rely on a less secure method of proving a user's identity.
SMS authentication is reaching its limits
The growing reliance on digital services has exposed the structural weaknesses of SMS authentication. Every one-time password creates multiple opportunities for fraud, from interception and SIM swap attacks to phishing campaigns that trick users into revealing their credentials.
Unlike network authentication, these attacks do not require criminals to compromise an operator's infrastructure. Instead, they exploit the gap between what the network already knows about a subscriber and what external services ask it to prove.
As fraud becomes more sophisticated, adding extra authentication steps is unlikely to solve the problem. Instead, operators are increasingly looking to strengthen the identity infrastructure that already exists within their networks.
The SIM is already the strongest identity credential
Every SIM card is a cryptographically verified identity credential that is continuously authenticated by the network. Operators trust this process every time a subscriber connects, yet historically that trusted identity has rarely extended beyond network access itself.
This presents a significant opportunity. Rather than relying on SMS codes that can be intercepted or manipulated, operators can use SIM-based authentication to verify users silently through credentials that already exist within the network.
Authentication takes place in the background without requiring users to enter a code, creating a more secure and seamless experience while removing many of the vulnerabilities associated with SMS authentication.
Why entitlement servers matter more than ever
Making this possible is an often overlooked piece of telecoms infrastructure: the entitlement server.
Traditionally, entitlement servers have been responsible for determining which services and features a subscriber is authorised to access, supporting capabilities such as VoLTE, VoWiFi and eSIM provisioning. Today, however, their role is expanding considerably.
Modern entitlement servers authenticate users through SIM credentials, dynamically provision services and enforce access rights in real time. Because authentication happens entirely within the secure mobile network, there is no SMS to intercept, no code to steal and no opportunity for attackers to exploit the delivery channel.
This shift is becoming increasingly important as digital identity moves closer to the heart of telecoms infrastructure. Industry initiatives such as GSMA Open Gateway are enabling operators to expose secure identity capabilities through standardised APIs, allowing enterprises and developers to verify users without relying on traditional SMS-based authentication.
Identity is becoming a strategic asset
The implications extend beyond fraud prevention too. The mobile phone number has become the primary identifier for many digital services, from banking and healthcare to government platforms and eCommerce.
As organisations look for stronger ways to verify users, operators are uniquely positioned to provide trusted identity because they control the cryptographic relationship between the subscriber, the SIM and the network.
This creates new commercial opportunities alongside stronger security. Identity verification, phone number verification and fraud prevention are increasingly becoming services that enterprises are willing to consume through operator APIs.
At the same time, operators can reduce operational costs by eliminating SMS authentication flows and lowering the volume of activation and authentication-related support requests. Recent industry research has highlighted measurable reductions in activation support tickets and customer service calls following entitlement server deployments.
A growing opportunity for global operators
As markets across the globe continue to embrace eSIM-enabled smartphones, connected wearables and enterprise IoT deployments, expectations around digital identity and consumer security continue to rise. As operators expand into new services, secure subscriber authentication becomes increasingly important.
In markets including APAC, EMEA and North America, emerging technologies, including satellite connectivity, network slicing and Open Gateway APIs, all depend on trusted identity. Every new connected device and every new digital service requires operators to know not only who a subscriber is, but whether they are entitled to access a service at that moment.
The entitlement server is becoming the common foundation that supports these capabilities, enabling secure eSIM transfers, silent authentication, connected devices and future network services through a single trusted identity platform.
Building the foundation for the next generation of services
The conversation around telecoms innovation often focuses on the services themselves, whether that's eSIM, satellite connectivity or premium 5G experiences. Less attention is given to the identity infrastructure that makes those services possible.
As digital ecosystems become increasingly connected, trusted identity will be just as important as network coverage or capacity. Operators that invest in modern entitlement infrastructure today will be better positioned to combat fraud, simplify customer onboarding and participate in the growing digital identity economy.
For years, entitlement servers quietly supported mobile services behind the scenes. As identity becomes one of telecoms' most valuable assets, they are evolving into the strategic infrastructure that underpins security, customer trust and future revenue opportunities. That may prove to be one of the industry's most significant transformations over the coming decade.