● Learn, Hack, Win
DEF CON 34
Workshop Module · IMSI · MSISDN · SS7

IMSI, MSISDN, and the Protocols That Connect Them

Understand the two key identifiers used in mobile networks, why both exist, and how legacy protocols let anyone with network access resolve one from the other.

Learning Objectives

Key terms appear highlighted like this throughout — click any to see its definition.

1

The Phone Number You Know: MSISDN

The external identifier you share with the world

A MSISDN (Mobile Station ISDN Number) is simply a subscriber's phone number — the string of digits you dial or share with someone. The name comes from ISDN, an older digital telephone standard, but in practice a MSISDN is what every carrier uses to route calls and SMS to a specific subscriber.

Every MSISDN is structured in three parts defined by the ITU-T E.164 standard. Click each segment to explore its role:

PartNameDescriptionExample
CC Country Code Identifies the country (1–3 digits) 1 (USA)
NDC National Destination Code Area code / network prefix 555
SN Subscriber Number Unique number within the NDC 1234567

The full MSISDN is at most 15 digits. In international format it is prefixed with + — for example, +15551234567.

Key point The MSISDN is public-facing. You hand it to friends, print it on a business card, and give it to apps. The network uses it as the address it advertises to the outside world.

2

The Identity the Network Knows: IMSI

The internal identifier stored on your SIM

An IMSI (International Mobile Subscriber Identity) is the true internal identifier for a subscriber. It is a number of up to 15 digits (commonly 15) stored on the SIM card and not normally exposed to the subscriber or outside parties. Networks use temporary identifiers (TMSI/GUTI) for most signaling, but the phone still presents its IMSI when the network has no valid temporary identity for it — for example on first attach.

IMSI anatomy — click each segment to explore:

PartNameDescriptionExample
MCC Mobile Country Code Identifies the country (3 digits) 310 (USA)
MNC Mobile Network Code Identifies the operator (2–3 digits) 260 (T-Mobile US)
MSIN Mobile Subscription ID Number Fills out the IMSI to at most 15 digits — up to 9 digits when the MNC is 3 digits (as here), up to 10 when the MNC is 2 123456789

Where it lives: The IMSI is stored in the SIM card's secure element and in the carrier's subscriber database. It does not change when you get a new phone, but it does change when you get a new SIM.

Key point The IMSI is private by design. Unlike a phone number, it is never meant to leave the trusted network. This distinction becomes critical once we look at how SS7 signaling commands can pull the IMSI back out.

3

MSISDN vs. IMSI — Why Both Exist

Stability vs. routability — a deliberate architectural split
Core design principle: The separation exists deliberately — the MSISDN is a stable public address you can share, while the IMSI is a fixed internal identity used for authentication and routing inside the carrier's network.
MSISDNIMSI
Visible to Everyone Carrier's internal systems
Can change? Yes — number porting, reassignment Only with a new SIM
Purpose External addressing (calls, SMS) Internal network identity and authentication
Stored on Carrier databases, contact lists SIM card + carrier HLR/HSS

A subscriber can change their phone number (MSISDN) without getting a new SIM, and can get a new SIM (new IMSI) while keeping the same number. The carrier's subscriber database bridges the two.

↓

The Mapping Database: HLR and HSS

The database responsible for mapping MSISDN → IMSI (and tracking where a subscriber currently is) is called the:

MSISDN INPUT +15551234567 MAP-SRI HLR / HSS subscriber database IMSI + MSRN IMSI OUTPUT 310260…

When a call or SMS arrives for +15551234567, the network queries the HLR to find:

  1. Which IMSI owns that number
  2. Which serving node the subscriber is currently attached to — the network equipment closest to where the phone is right now. The node type depends on the network generation:

NodeFull NameGenerationRole
MSC Mobile Switching Center 2G / 3G Routes voice calls
VLR Visitor Location Register 2G / 3G Temporary subscriber cache co-located with the MSC
SGSN Serving GPRS Support Node 2G / 3G Handles packet (internet) data — the data-plane counterpart to the MSC
MME Mobility Management Entity 4G / LTE Replaces the MSC and VLR; manages registration, authentication, and handoffs between towers
This lookup is entirely normal and happens billions of times a day. The security concern, as you'll see next, is that the protocols designed to perform this lookup were built with minimal origin authentication — any SS7-connected node can issue the query.

4

The SS7 Protocol Commands That Bridge the Gap

MAP operations that expose IMSI over the signaling network

SS7 (Signaling System No. 7) is the protocol suite that has run the world's telephone networks since the 1970s. It handles call setup, teardown, SMS routing, and subscriber database lookups. Despite being decades old, SS7 still underpins most carrier infrastructure worldwide and interconnects 2G, 3G, and 4G networks at the roaming layer.

SS7 uses a sub-protocol called MAP (Mobile Application Part) for interactions between mobile network nodes. Two MAP operations are particularly relevant here.

→

MAP SendRoutingInfo (MAP-SRI)

Originally designed to route incoming calls to a subscriber, MAP-SRI asks the HLR: "I want to route a call to this phone number — where is the subscriber and what is their IMSI?"

The HLR responds with:

Security gap Any SS7-connected node can send this query. The HLR does not verify whether the requesting node is a legitimate roaming partner — it has no built-in origin authentication. This is the core design-era vulnerability researchers and defenders need to understand.
→

MAP SendRoutingInfoForSM (MAP-SRI-SM)

Similar to MAP-SRI but designed for SMS routing. It asks the HLR where to deliver an SMS for a given phone number. The response again includes the IMSI and the current serving node.

↓

Summary of Relevant Commands

CommandProtocolOriginal PurposeData Returned
SendRoutingInfo SS7 MAP Route incoming voice calls IMSI + roaming number (MSRN)
SendRoutingInfoForSM SS7 MAP Route incoming SMS IMSI + serving MSC (2G/3G voice node) or SGSN (3G data node) address
AnyTimeInterrogation SS7 MAP Query subscriber info for value-added services IMSI + location cell ID
User-Data-Request Diameter (Sh) Retrieve subscriber data over Sh (Application Server ↔ HSS) Selected profile data, which can include IMSI
Send-Routing-Info-for-SM Diameter (S6c) Route incoming SMS in LTE — the Diameter parallel to MAP SendRoutingInfoForSM IMSI + serving node
Note on naming: The Diameter "Send-Routing-Info-for-SM" (on the S6c interface) mirrors the SS7 MAP SendRoutingInfoForSM — different stacks, same conceptual job of resolving where to deliver a message and exposing the IMSI. The Sh interface has no "Send-Routing-Info" command; an Application Server there uses User-Data-Request (UDR) to fetch selected subscriber data, which can include the IMSI.

5

Diameter: The 4G Evolution

SS7's successor — same exposure, different protocol

Diameter is the protocol that replaced SS7's MAP for 4G/LTE network signaling. Where SS7 uses a layered stack of protocols (MTP for raw transport → SCCP for routing → TCAP for transactions → MAP for mobile operations), Diameter is an IP-based protocol designed for telecom-grade reliability and scalability — think of it as a purpose-built messaging system where network nodes send structured request/response messages to each other over TCP or SCTP (Stream Control Transmission Protocol — a transport similar to TCP but designed for telecom signaling, with built-in multi-path support).

What is a "Diameter interface"? In telecom, an interface is not a software API — it is a named, standardized connection point between two specific types of network nodes. Each interface has a defined protocol, message types, and expected behaviors. Naming them (Sh, S6a, Gx, etc.) lets engineers and standards bodies say "this exact set of rules applies when node A talks to node B" without ambiguity. Think of it like a labeled electrical socket standard: the name tells you which plug fits and what voltage to expect.

In 4G networks the HSS exposes its MSISDN → IMSI mapping through two Diameter interfaces:

There is no single "MSISDN in, IMSI out" routing command on Sh the way MAP-SRI works in SS7. Instead, an Application Server issues a User-Data-Request (UDR) over Sh to pull subscriber data — which can include the IMSI. The closest direct parallel to MAP-SRI-SM is Send-Routing-Info-for-SM on the separate S6c interface, used for LTE SMS delivery.

Same problem The Sh interface was designed for trusted internal use between operator nodes. Diameter's transport security (IPSec or TLS) protects the connection itself, but authorization — should this node be allowed to query this subscriber? — is often weakly enforced or absent in inter-carrier configurations.

6

The Full Lookup Flow

How a MAP-SRI query resolves a phone number to an IMSI — and why unauthenticated access is a problem

Putting it all together, here is the end-to-end path from a known phone number to a retrieved IMSI. Press Play to trace the lookup flow step by step:

REQUESTING NODE MSISDN: +15551234567 ① has MSISDN sends query ② MAP-SRI query SendRoutingInfo → REMOTE HLR Home Location Register ③ HLR lookup: MSISDN → IMSI ④ IMSI + MSRN returned (no auth) REQUESTING NODE RECEIVES IMSI: 310260123456789 MSRN: 14085552999 awaiting response…

Because the IMSI is the internal handle for all subscriber operations, uncontrolled access to this lookup exposes several capabilities the protocol was never designed to guard against:

The MSISDN → IMSI resolution step is always the starting point. It converts the public-facing phone number into the internal handle that controls all subsequent network operations — which is why carriers and standards bodies have added SS7 firewalls and filtering rules to block unsolicited MAP-SRI queries from outside the trusted network.

7

Hands-On Challenge

Apply what you've learned in a simulated SS7 environment

CTF Challenge

Try It Yourself

You have been given a phone number. Use what you've learned about how SS7 MAP lookups work to retrieve the corresponding IMSI from a simulated HLR environment.

1 Identify the correct SS7 MAP command to query the HLR
2 Send the query to the provided test HLR with the challenge MSISDN
3 Parse the response and extract the IMSI

Tools available

  • sigtran-shell — a command-line SS7 signaling tool pre-configured with the workshop's test SCTP endpoints

Success criteria

  • You retrieve a valid 15-digit IMSI from the HLR response
  • Submit the IMSI to the challenge portal to claim the flag
▶ Launch Simulator ↗ Opens in a new tab — these instructions stay open here. Interactive SS7 / Diameter terminal with animated protocol stack.
Hint: Which SS7 MAP command was designed for call routing and returns the IMSI as part of its response?

8

There's Another Way In: Over-the-Air IMSI Disclosure

How phones are tricked into broadcasting their IMSI directly — no SS7 access required

The SS7 and Diameter lookups you just practiced work by querying the network's database. But there is a second path: asking the phone itself. When a handset connects to a cellular tower, part of the registration exchange involves the phone transmitting its IMSI directly over the radio link. The network uses this to look up the subscriber before setting up an encrypted session.

Key fact: In 2G (GSM) the network never authenticates itself to the phone, so a base station can ask for the IMSI before any encryption and the phone has no way to tell a legitimate tower from a rogue one. 3G (UMTS) added mutual authentication, but an Identity Request can still occur before authentication completes, and an attacker can force a downgrade to 2G — so the exposure remains relevant.
→

How a Phone Decides Which Tower to Use

Phones continuously scan for available base stations and select the one broadcasting the strongest signal with a matching network identifier (MCC+MNC). In 2G (GSM) the phone authenticates to the network but the network does not authenticate to the phone, so a rogue base station broadcasting a stronger signal than the legitimate tower simply wins the connection. 3G (UMTS) added mutual authentication, but downgrade-to-2G and pre-authentication identity requests keep the attack viable in practice.

Once the phone connects, the rogue station issues an Identity Request — an over-the-air message that asks the phone to send its IMSI in plaintext. The phone, following the standard, responds with its IMSI before any session key is exchanged.

GenerationPhone auth to network?Network auth to phone?IMSI sent in cleartext?
2G (GSM) Yes No Yes — on request
3G (UMTS) Yes Yes (mutual auth) Yes — on initial attach
4G (LTE) Yes Yes (mutual auth) Only if TMSI unknown
5G (NR) Yes Yes (mutual auth) No — SUCI concealment
5G improvement 5G New Radio introduced SUCI (Subscription Concealed Identifier) — the phone encrypts its permanent identity (the SUPI) with the operator's public key before transmitting it. Even if a rogue tower intercepts the registration, it only sees a one-time encrypted blob, not the raw identity. Caveat: the standard also defines a null scheme that leaves the identity unconcealed, so protection depends on operator configuration.
→

The Rogue Base Station (IMSI Catcher)

An IMSI catcher — sometimes called a "Stingray" after a commercial product — is a device that impersonates a legitimate cell tower to collect IMSIs from nearby phones. The attack flow:

  1. 1 Broadcast a strong fake signal — the rogue BTS broadcasts on a legitimate MCC+MNC with higher power than nearby real towers. Phones in range connect automatically.
  2. 2 Issue an Identity Request — the rogue station sends a standard GSM/3GPP Identity Request message before establishing encryption, asking the phone for its IMSI.
  3. 3 Collect the IMSI response — the phone complies, sending its IMSI in plaintext. The attacker now has the IMSI without touching any carrier network.
  4. 4 Relay or drop the connection — the rogue BTS can silently relay the phone to a real tower (passive collection) or drop it, forcing a reconnect. More advanced attacks intercept and manipulate traffic in between.
Why this matters: This attack path requires no credentials, no SS7 access, and no insider knowledge. Impersonating a tower needs transmit-capable RF hardware, an appropriate RF setup, and a working cellular base-station stack.
Up next — Section 2
Rogue BTS & OTP Theft

Section 2 builds on this concept with a hands-on simulation. You'll see how a rogue base station harvests IMSIs from nearby devices — and how attackers layer that access to intercept one-time passwords sent over SMS.

Continue to Section 2 →
≡

Quick Reference Glossary

Key terms for this module
MSISDN
Mobile Station ISDN Number — the subscriber's phone number (public-facing)
IMSI
International Mobile Subscriber Identity — the network-internal SIM identity (private)
MCC
Mobile Country Code — 3-digit country identifier, first part of an IMSI
MNC
Mobile Network Code — 2–3 digit operator identifier, second part of an IMSI
MSIN
Mobile Subscription Identification Number — up to 10 digits, unique within the operator
HLR
Home Location Register — 2G/3G subscriber database that maps MSISDN ↔ IMSI
HSS
Home Subscriber Server — the 4G/LTE and IMS subscriber database (HLR equivalent over Diameter). A native 5G core uses UDM/UDR/AUSF; the HSS remains in EPC, IMS, and 5G non-standalone/interworking.
SS7
Signaling System No. 7 — legacy telecom signaling protocol suite, still in global use
MAP
Mobile Application Part — SS7 sub-protocol for mobile network operations
MAP-SRI
SendRoutingInfo — MAP command returning IMSI + MSC address for call routing
MAP-SRI-SM
SendRoutingInfoForSM — MAP command returning IMSI for SMS routing
Diameter
IP-based signaling protocol replacing SS7 MAP in 4G/5G networks
MSC
Mobile Switching Center — the 2G/3G node that routes voice calls, roughly equivalent to a telephone exchange. A roaming number (MSRN) pointing at it is returned alongside the IMSI in a MAP-SRI response.
MSRN
Mobile Station Roaming Number — a temporary E.164 number the HLR/VLR hands back so an incoming call can be routed to the subscriber's current MSC. It is the routing information returned in a MAP-SRI response (a number-like address, not an IP).
VLR
Visitor Location Register — a temporary subscriber database co-located with the MSC. When your phone enters an MSC's coverage area it copies your profile from the HLR into the VLR so the MSC can serve you without querying the HLR for every call.
SGSN
Serving GPRS Support Node — the 2G/3G node responsible for routing packet data (internet traffic), the data-plane equivalent of the MSC. Returned instead of the MSC in SMS-routing responses when a subscriber is on a 3G data session.
MME
Mobility Management Entity — the 4G/LTE equivalent of the MSC. Manages which cell tower a phone is attached to, handles authentication by talking to the HSS over the S6a interface, and orchestrates handoffs between towers.
Interface (telecom)
A named, standardized connection point between two specific network node types with defined protocol, messages, and rules — e.g., S6a (MME ↔ HSS), Sh (App Server ↔ HSS). Not to be confused with a software API; it describes the entire contract for how two kinds of nodes communicate.
SUCI
Subscription Concealed Identifier — a 5G construct where the phone encrypts its IMSI (called SUPI in 5G) with the operator's public key before transmitting it over the air. A rogue base station only sees the one-time encrypted value, not the raw identity.
IMSI Catcher
A device (also called a Stingray or rogue BTS) that impersonates a legitimate cell tower to capture IMSIs from nearby phones by exploiting the lack of mutual authentication in 2G/3G.
Rogue BTS
A fake base transceiver station that broadcasts a strong signal to attract phones, then issues over-the-air identity requests to harvest IMSIs or intercept traffic before relaying to the real network.