Modernizing MNP routing in the 5G era
The rollout of 5G Standalone (SA) networks is forcing telecom operators to modernize Mobile Number Portability (MNP) routing, as integrating legacy protocols (SS7/Diameter) with modern service-based architectures creates critical latency and security vulnerabilities.
MNP routing challenges in the transition to 5G
The transition to cloud-native architectures reshapes subscriber data management. MNP requires tight coordination of signaling traffic and synchronization of distributed databases.
Routing asymmetry and latency
For every call, the network must identify the actual serving operator. There are two routing methods:
- Direct routing: the network queries a local database (LDB) and routes the call directly, minimizing setup time.
- Indirect routing: the call is routed through the donor operator, creating a hairpin route. Up to 53.7% of latency in hybrid networks is caused by protocol translation at the interface with legacy databases.
Security threats and financial risks
According to the ENISA Threat Landscape 2025 report, exploiting SS7 and Diameter vulnerabilities remains a significant risk. Around 27.7% of signaling security incidents in roaming are linked to routing data manipulation aimed at intercepting SMS or OTP passwords.
Slow MNP database synchronization also fuels fraud. The CFCA Global Fraud Loss Survey 2025 estimates global telecom fraud losses at $41.82 billion, with subscription fraud accounting for $5.31 billion. Fraudsters exploit the time window between number porting and billing system updates.
What this means for the market
For telecom operators, inefficient MNP routing leads to increased operational costs, high latency, and severe financial losses from subscription fraud. For end-users, these vulnerabilities result in delayed call setups and heightened security risks, such as the interception of one-time passwords (OTPs) and sensitive SMS communications during the porting window.
Action plan
To mitigate these risks and modernize MNP routing, companies should adopt the following practical steps:
- Transition to an API-first architecture: Replace monolithic BSS/OSS with component-based architectures using TM Forum's Open APIs and an event-driven model for instant data propagation.
- Deploy modern integration platforms: Leverage platforms like UnityBase by the Intecracy Group consortium to build an integration layer, utilizing its Domain metadata model to create REST APIs and synchronize data across various DBMSs.
- Enhance security and performance: Implement asynchronous, non-blocking servers to ensure high transaction speeds, alongside robust access control (RBAC/RLS) and audit logging to prevent routing data manipulation.
Prepared by a Software Ukraine member. Original publication.