TTR: 00:10:082,026 WordsBookmarkShareSummary

Mobile Core Networks for MVNOs and Private Networks: A Guide

by Rajesh Kumar | Oct 1, 2026 | Connectivity, Mobile Networks, MVNO

A phone call, a text alert, and a sensor reading from a warehouse forklift—all of it eventually passes through a core network. Most attention goes to the radio link, the part that gets a device talking to a cell tower. But the core is where the real work happens: confirming who's on the network, keeping sessions alive, and deciding where traffic goes next. For a mobile virtual network operator (MVNO) or a company standing up its own private network, the design of that core isn't a side detail. It decides what services can actually be offered and how much control an operator has when something goes wrong.

Mobile Core Networks for MVNOs and Private Networks image

This guide covers the core network's main jobs, how a Full MVNO's core differs from a Light MVNO that leans on its host operator, and where a private mobile network breaks from the MVNO model entirely. Along the way it looks at a handful of components that show up constantly in these environments — the Home Subscriber Server (HSS), Diameter Routing Agents, SMPP, USSD, and SMS firewalls — and what each one is actually responsible for.

Understanding the Telecom Core Network

Once a device's radio signal reaches a cell site, something has to authenticate it, track it, and figure out where its traffic should go. That's the Telecom core network's job. The radio access network, or RAN, manages the link over the air. After that, the core part takes control.

A few of its main responsibilities:

  • Subscriber authentication— confirming a device and SIM are allowed on the network
  • Subscriber data management — storing profile, subscription, and authorization details
  • Mobility management — tracking a device as it moves between cells
  • Session management — setting up and maintaining data sessions
  • Signaling — the control messages that coordinate everything above
  • Routing — getting traffic to the right destination, whether that's another subscriber, the internet, or an interconnect partner
  • Policy and charging — enforcing quality-of-service rules and usage limits
  • Voice and messaging— call setup, SMS delivery
  • Connectivity to external networks — the internet, or other operators' networks

RAN and core don't overlap so much as hand off to each other. One deals with spectrum and physical connectivity; the other deals with everything that connection is supposed to accomplish.

That said, the core's architecture has changed generation to generation. LTE networks run on what's called the Evolved Packet Core (EPC), built around a specific set of elements for authentication, mobility, and sessions. 5G moved toward a more modular, service-based architecture — the 5G Core — where the same broad functions exist but are organized differently. Which one a given network runs depends on the generation deployed and the vendor's design choices, not on any single fixed standard.

How a Full MVNO's Core Network Operates

For any telecom MVNO, the core network is what determines how much control it actually has over its own service. An MVNO sells mobile service without owning the spectrum or the physical RAN that delivers it — instead, it has a commercial agreement with a mobile network operator (MNO) that does. Within that arrangement, MVNOs sit
at different points on a spectrum of control. Two common positions are Full MVNO and Light MVNO.

A Light MVNO leans heavily on the host MNO's core: its own brand and customer relationships sit on top of infrastructure it doesn't really touch. A Full MVNO takes on more of that infrastructure itself — subscriber data management, authentication, sometimes its own messaging systems — while still borrowing radio access from the host.

Picture the traffic path for a Full MVNO: MNO radio access network, into the MVNO's own core, out to subscribers and external networks. That extra control over the core tends to translate into more flexibility — in how subscribers are managed, how services get configured, how routing and messaging decisions get made, and in day-to-day operations generally.

None of this locks Full MVNOs into one blueprint, though. The technology in use, the specifics of the agreement with the host MNO, local regulation, and the market itself all shape how any particular Full MVNO's core actually gets built.

Private Networks: Where the Core Diverges from an MVNO

A private mobile network exists to serve one organization, site, or operational environment — not the general public. Unlike an MVNO, which resells someone else's radio network.

Private LTE and 5G often appear in factories, warehouses, ports and large campuses. These are places where predictable coverage and controlled access matter more than reaching a broad consumer base and the network can be shaped around the specific footprint and device density of that one location rather than a general population of subscribers.

There's no single blueprint for how these networks are built. Some run as standalone deployments with a dedicated core, while others integrate parts of a public network under commercial arrangements. Spectrum access varies too (licensed, shared, or unlicensed), depending on what a country allows. Because regulation differs so much by jurisdiction, there's no universal licensing model for private networks.

Inside the MVNO Core: Key Components at a Glance

A handful of components come up again and again in MVNO and private-network conversations, and it's worth being precise about what each actually is not everything on this list is a "core network element" in the strict 3GPP sense. Some qualify as core network services in their own right; others are messaging, routing, or security infrastructure that sits alongside the core rather than inside it.

    1. HSS— subscriber data and authentication, from the LTE era
    2. PGW — the LTE-era gateway that anchors data sessions and connects subscribers to the internet and other external networks
    3. Diameter Routing Agent — routes Diameter signaling traffic between elements
    4. SMPP— a protocol connecting external applications to SMS infrastructure
    5. USSD servers— handle real-time, session-based services, distinct from SMS
    6. SMS firewalls— security infrastructure that filters and manages messaging traffic

The next several sections go through each in more depth.

1. The Home Subscriber Server (HSS): Subscriber Data and Authentication

The HSS is the central subscriber database in LTE-era networks — identity, authentication credentials, subscription data, service authorization, and mobility-related information all live there. Other network elements reach it through Diameter-based interfaces to query or update that data as needed.

For a Full MVNO this matters because owning an HSS means owning subscriber identity and authorization outright, rather than borrowing it from the host MNO's database. That's a meaningful difference in operational independence.

One caveat worth flagging: HSS is specifically an LTE-generation concept. In 5G Core, subscriber data management has moved to the Unified Data Management and Unified Data Repository functions, structured differently within 5G's service-based architecture. So HSS shouldn't be treated as the default subscriber-data model across every modern network — it depends on which generation is actually running.

2. Packet Data Network Gateway (PGW): Data Sessions and Network Exit Point

The PGW is where a subscriber's data traffic leaves the core and reaches the internet. In LTE, it assigns the device's IP address, enforces policy rules, and reports usage for charging over Diameter. A Full MVNO running its own PGW controls APN setup and traffic breakout, while a Light MVNO relies on the host MNO's gateway.Like the HSS, the PGW is LTE-specific. In 5G Core, its work is split between the SMF and the UPF.

3. Diameter Routing Agent (DRA): Managing Signaling Traffic

Diameter is the signaling protocol LTE-era networks use to carry authentication, authorization, and accounting messages — including the traffic going to and from the HSS. Once a network has more than a handful of signaling endpoints, having every element talk directly to every other element stops being practical.

That's the gap a DRA fills. It sits between network elements and routes Diameter messages on their behalf, rather than requiring direct point-to-point connections everywhere. In practice that buys a network load distribution across signaling paths, redundant routing for high availability, and room to scale as more elements get added, all handled through consistent routing logic.

Whether an MVNO needs one really comes down to scale. A core with several internal elements, external interconnections, and roaming relationships generating heavy signaling volume benefits a lot from a DRA. A smaller, simpler deployment might not need one at all.

4. SMPP: The Protocol Behind SMS Delivery

SMPP — Short Message Peer-to-Peer — is how messaging platforms talk to SMS infrastructure like Short Message Service Centers (SMSCs). It's the glue connecting application-to-person messaging systems & notification platforms to the machinery that actually gets a text delivered.

An SMPP client binds a session with an SMPP server, submits messages and gets delivery receipts back confirming whether they landed. This is the layer underneath one-time passcodes, account alerts & appointment reminders and most other business-to-consumer texting.

One distinction worth being precise about: SMPP doesn't carry SMS over the mobile radio network itself. It's an application-layer protocol that interfaces external systems with SMS infrastructure — the actual radio-side delivery to a handset happens through the mobile network's own signaling and messaging systems, with SMPP sitting at the connection point into that infrastructure.

5. USSD Servers: Real-Time Session-Based Services

USSD stands for Unstructured Supplementary Service Data. It lets a phone and a network app talk in real time during one session. This is different from SMS, which sits in a queue and may wait before it arrives.

Because of that, USSD works well for quick tasks. For example, you can check your balance, view account details, turn on a service, or move through a menu in self help mode.
. A USSD server processes each request, builds the menu the subscriber sees, and talks to whatever backend system holds the actual data.
Because it doesn't rely on a data connection the way app-based services do, USSD has stuck around as a lightweight, broadly compatible option — still common for quick balance checks and service management across both MVNOs and MNOs.

6. SMS Firewalls: Filtering, Fraud Prevention, and Network Protection

An SMS firewall is placed in the message flow. It looks at incoming SMS messages. It filters them when needed. It also helps control the SMS traffic that moves through. As messaging fraud has gotten more sophisticated — beyond simple spam into more targeted schemes — firewalls have become a standard piece of messaging security for MNOs and for MVNOs running their own messaging infrastructure.

What they typically catch: spam and unwanted messages, fraud patterns, so-called grey-route traffic that skips proper commercial agreements, sender ID spoofing, malicious content, and gaps in revenue accounting where messaging traffic isn't being billed correctly.

How much a firewall actually does, and where it sits in the architecture, depends on the messaging setup and traffic volume involved. And no, an SMS firewall isn't a universal legal or technical requirement for every MVNO — whether one gets deployed usually comes down to messaging volume and how much fraud risk an operator is carrying.

F&Q

What's the difference between a Full MVNO and a Light MVNO core network?

Mostly ownership and control. A Full MVNO runs key parts of its own core, like subscriber management, while still using the host MNO for radio access. A Light MVNO relies on the host's core for nearly everything except branding and the customer relationship.

Do private networks use the same core components as MVNOs?

Some overlap, yes: subscriber management, authentication, and signaling infrastructure, in either LTE/EPC or 5G Core. But the purposes diverge. An MVNO sells commercial service over someone else's radio access, while a private network serves one site or organization. The exact components depend on the setup such as LTE with EPC, 5G Core or a standalone private core.

What does a Diameter Routing Agent (DRA) do?

It routes Diameter signaling between network elements, so they don't need direct connections to each other. That gives a network load distribution, redundant paths for high availability, and better scalability as its signaling environment grows.

Why do MVNOs need an SMS Firewall?

To catch spam, fraud, spoofed sender IDs, and other malicious messaging traffic, and to keep that traffic properly accounted for. It matters most for MVNOs running their own messaging infrastructure. It isn't a universal requirement, though, and depends on traffic volume and risk.

Rajesh Kumar

About the author

Rajesh Kumar

Founder · ComCode Technology