Network-based
authentication.
Your network is the proof.
Identity verified by SIM cryptography at the carrier level — no OTP, no user action, phishing-resistant, under 300 ms.
104+
Operator networks, global reach
<300ms
Authentication latency, zero OTP wait
0
User actions required
2G–5G
Coverage, USSD fallback included
WHAT IS NETWORK BASED AUTHENTICATION
Every SIM already holds an unextractable cryptographic key. This is how operators make it useful.
Network-based authentication exposes the carrier's native EAP-AKA verification — the same mechanism behind every call and data session — as a billable API. The SIM proves possession of its key, the HSS confirms the match, and there is no code for anyone to intercept, relay, or phish.
one API call
Enterprise app
Fires a silent verification request on login, transaction, or onboarding.
TS.43 · EAP-AKA · HSS
Carrier network
Entitlement server issues an EAP-AKA challenge; the SIM answers with its on-device key; the HSS verifies.
per-verification revenue
Identity verified
Confirmed match returned in under 300 ms. No prompt, no wait, no phishable credential.
NETWORK AUTH FLOW — TS.43 EAP-AKA
Five steps. Zero user actions. Revenue on every call.
The entire exchange runs inside carrier signalling — invisible to the subscriber and architecturally out of reach for phishing.
01
Enterprise calls your network auth API
A silent verification request fires against the subscriber's phone number — on login, transaction, or any configured trigger.
02
U2opia routes to the operator's entitlement server
The request reaches the correct MNO's TS.43 server based on the subscriber's home network — across 104+ operators.
03
EAP-AKA challenge issued to the SIM
A per-session cryptographic challenge travels over carrier signalling. It cannot be replayed.
04
SIM responds with cryptographic proof
The SIM computes the response with a key that never leaves the SIM; the HSS verifies it against the subscriber record.
05
Match confirmed — your network earns per call
Result returned in under 300 ms. No OTP sent, no user action, one per-verification revenue event.
NETWORK AUTH vs SMS OTP vs APP BASED
Three authentication methods. Only one is invisible, phishing-resistant, and pays your network.
Regulators are deciding for your enterprise customers: NIST SP 800-63B-4 restricts SMS OTP, and app biometrics bypass your network entirely. Network auth is the only method that routes through your infrastructure at a higher margin — with zero AIT fraud exposure.
Network Auth
App Biometric
SMS OTP
Phishing-resistant
Yes — no code
Partial
Relay risk
User action required
None — invisible
Biometric scan
Read + type code
Works without an app
Yes
App required
Yes
2G / 3G coverage
USSD fallback
Smartphone only
Usually
NIST AAL2 compliant
Yes (EAP-AKA)
Yes (FIDO2)
Restricted
AIT fraud surface
None
None
High
Revenue for operator
Per-verification API
None
A2P SMS (declining)
Regulatory status
Approved replacement
Approved
Being phased out
US MARKET — JULY 2026
AT&T, T-Mobile and Verizon are live. The commercial model is confirmed.
The three major US carriers now sell CAMARA-compliant network authentication as a per-verification API across 300M+ connections — the largest deployment to date. Operators not yet in market are watching enterprise revenue migrate to those that are.
FOR MOBILE NETWORK OPERATORS
Your network already authenticates every subscriber. Turn that into API revenue.
Every enterprise replacing SMS OTP is a buyer of your authentication capability — at higher per-event margin and zero AIT exposure. U2opia deploys the entitlement server, handles CAMARA compliance and enterprise routing, and settles revenue share per verification. You provide network access; enterprise sales and billing are handled for you.
01
Deploy TS.43 entitlement server
U2opia deploys and manages the entitlement server infrastructure that enables EAP-AKA network-based authentication. Operators provide network access; U2opia handles integration, CAMARA compliance, and enterprise connectivity.
02
Expose authentication as an API
Your network's subscriber authentication capability becomes a billable API via GSMA Open Gateway and U2opia's aggregation layer. Enterprises integrate once; your network earns per-verification on every call.
03
Eliminate AIT fraud in one move
Network-based authentication has no per-message delivery step — so there is no OTP message to inflate artificially. AIT fraud, which costs the industry over $1.2 billion annually on SMS routes, cannot exist on a network auth API call.
04
Reach 2G and 3G subscribers too
SilentAuth+ includes a USSD fallback channel — the only network authentication implementation that extends silent verification to 2G and 3G networks. In emerging markets, this is the difference between serving your whole base and serving only smartphone users.
U2OPIA SILENTAUTH+ — THE IMPLEMENTATION
SilentAuth+ — the implementation, live across 104+ operators.
TS.43 EAP-AKA with the only USSD fallback in market, CAMARA NV2-compliant, and revenue-sharing from day one.
Sub-300 ms authentication
Verification completes before the user notices the login has started.
avg ~240ms · p99 <300ms
TS.43 + USSD fallback
4G/5G and Wi-Fi via CIBA token; USSD extends silent auth to 2G/3G feature phones.
TS.43 R11 · USSD · EAP-AKA
CAMARA NV2 compliant
Silent auth and number verification exposed via a single Open Gateway platform.
CAMARA Fall25 · NV2 stable
104+ operator reach
One integration reaches every network — India, SEA, MENA, Africa, Europe, Americas.
104+ MNOs · 60+ countries
Revenue-share model
No upfront licensing; U2opia handles enterprise sales, infrastructure, and settlement.
per-verification · no capex
BSS/OSS integration ready
Works with HLR/HSS subscriber data, Diameter signalling, and existing entitlement servers.
HLR/HSS · Diameter · REST
Talk To An Expert
NIST SP 800-63B-4 COMPLIANCE
NIST's 2025 update made SMS OTP a liability. EAP-AKA satisfies every AAL2 criterion.
For enterprises in US federal, financial services, and healthcare, AAL2 is now a procurement mandate — and your network is the only source of a carrier-grade, zero-friction replacement. EAP-AKA passes because the SIM's cryptographic proof cannot be relayed, replayed, or intercepted.
NIST AAL2 criterion
Network Auth (EAP-AKA)
SMS OTP
Phishing-resistant
No credential relayable
OTP relay possible
Cryptographic proof
Challenge-response
Shared secret (code)
Replay-resistant
Per-session challenge
Code valid until expiry
Channel binding
SIM-to-device bound
Deliverable anywhere
Satisfies AAL2
Phishing-resistant MFA
Restricted authenticator
COMPETITIVE ANALYSIS
How SilentAuth+ Compares to IPification and Shush
Both IPification and Shush are silent authentication providers, but their technical approach and geographic reach differ significantly from SilentAuth+.

IPification relies on IP-address matching, which requires mobile data and does not work on Wi-Fi or 2G/3G. Shush is designed for mature 4G/5G markets. Neither covers the full 2G-to-5G and Wi-Fi range with USSD fallback that SilentAuth+ delivers.
SilentAuth+ IPification Shush
Authentication method
TS.43 EAP-AKA (SIM-based)
IP address matching Network-based
Works on Wi-Fi
Yes SIM credentials
No — Mobile data only Limited
2G / 3G support
Yes USSD fallback
Partial — LTE+ required Partial — Aggregator model
GSMA TS.43 standard
Native
No — Proprietary No
CAMARA NV2 compliant
Yes
No Partial
Emerging market depth
Africa, SEA, MENA, South Asia
Limited Primarily developed markets
USSD fallback
Yes Unique advantage
No No
SIM swap detection
Yes
Limited Partial
SilentAuth+ IPification Shush
Authentication method

TS.43 EAP-AKA (SIM-based)
IP address matching
Network-based
Works on Wi-Fi

Yes SIM credentials
No — Mobile data only
Limited
2G / 3G support

Yes USSD fallback
Partial — LTE+ required
Partial — Aggregator model
GSMA TS.43 standard

Native
No — Proprietary
No
CAMARA NV2 compliant

Yes
No
Partial
Emerging market depth

Africa, SEA, MENA, South Asia
Limited
Primarily developed markets
USSD fallback

Yes Unique advantage
No
No
SIM swap detection

Yes
Limited
Partial
Talk To An Expert
FREQUENTLY ASKED QUESTIONS
Mobile Authentication API Questions, Answered

How can telcos monetise authentication APIs?

Telcos can monetise authentication by exposing network-based identity APIs to enterprises, generating revenue from user verification instead of relying on declining SMS OTP traffic. This creates a new high-margin API revenue stream.

What is TS.43 authentication and why does it matter for operators?

TS.43 is a GSMA standard that enables SIM-based authentication using EAP-AKA across mobile and Wi-Fi networks. It allows operators to act as trusted identity providers instead of relying on third-party authentication methods.

How does silent authentication help telcos reclaim authentication from OTT players?

Silent authentication shifts identity verification from apps and SMS OTP back into the mobile network. This allows telcos to control authentication flows and capture value from every login and transaction.

What is Number Verify 2 (NV2) and how is it used by telcos?

Number Verify 2 is a GSMA Open Gateway API that confirms a phone number matches the active SIM card. Telcos can offer NV2 as a standardised API for real-time identity verification.

How does network-based authentication compare to SMS OTP?

Network-based authentication is faster, more secure, and does not require user input. Unlike SMS OTP, it is resistant to SIM swap fraud, phishing, and delivery failures.

Can telco authentication work across 2G, 3G, 4G, and 5G networks?

Yes, network-based authentication can work across all generations of mobile networks using a combination of TS.43, USSD fallback, and operator integrations.

How does authentication API revenue compare to SMS OTP revenue?

Authentication APIs provide scalable, usage-based revenue with higher margins, while SMS OTP revenues are declining due to fraud, regulation, and user friction.

What role do telcos play in digital identity and GSMA Open Gateway?

Telcos are positioned to become global identity providers through GSMA Open Gateway APIs like Number Verify. They can offer secure, interoperable identity services to enterprises worldwide.

GET STARTED
Ready To Reach Every Mobile User?
Start with SilentAuth+ and add customer experience and payments as you grow. One platform, carrier-grade, global.