Pith. sign in

REVIEW 5 major objections 4 minor 22 references

The Security Overview and Analysis of 3GPP 5G MAC CE

T0 review · 5 major / 4 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read 5G MAC Control Elements are transmitted without PDCP encryption or integrity protection, and their fields can be combined to leak location and enable tampering.

desk verdict A useful survey of MAC CE security risks, stronger on passive exposure than on the feasibility of active tampering; worth refereeing after the risk ratings and protection framework are substantiated. read the letter →

arxiv 2506.09502 v2 pith:ZKALUZLG submitted 2025-06-11 cs.CR

classification cs.CR
keywords MACCE5GNRcontrolplanesecuritylocationprivacyintegrityprotectiontimingadvancephysicallayerattacks3GPP
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper argues that MAC Control Elements (MAC CEs), the low-layer control messages exchanged between a base station and a phone to schedule resources, adjust timing, and manage beams, are sent without the encryption and integrity protection that the higher PDCP layer applies to ordinary signaling. An attacker who can read or forge over-the-air MAC PDUs can therefore infer what services a user runs, where the user is, and how the user moves, or can disrupt uplink synchronization, force devices into sleep, and redirect handovers to rogue cells. The paper catalogues the privacy-sensitive fields inside MAC CEs, shows how combinations of fields disclose current and long-term location, and proposes a four-tier protection framework (plaintext, integrity protection, encryption, and hybrid) matched to each field's risk level. The intended contribution is to push MAC CE security into the 5G standard's future security specifications.

What carries the argument

The central object is the MAC Control Element (MAC CE), a fixed- or variable-sized control payload inside the MAC PDU that the receiving MAC entity identifies by a reserved Logical Channel ID (LCID) in the subheader. The load-bearing mechanism of the analysis is the field-combination chain: individually benign parameters such as C-RNTI, Serving Cell ID, TA Command, and SSB Index, when correlated with public base-station geolocation databases and beam-pattern knowledge, yield an annular-sector estimate of the user's position and a long-term movement profile. The paper's proposed countermeasure is a four-tier graded security framework, M1 through M4, that assigns plaintext transmission, integrity protection, encryption, or a hybrid of the latter two to each MAC CE type according to its confidentiality, integrity, and latency requirements.

What would settle it

A testbed experiment in which a software-defined radio transmits a forged Timing Advance Command MAC CE toward a commercial 5G UE would settle the DoS claim: if the UE rejects the message or the PHY layer blocks injection, desynchronization does not occur; if the UE loses uplink synchronization, the claimed tampering risk is real. Separately, a measurement campaign pairing ground-truth positions with observed TA and SSB indices would test whether the claimed annular-sector localization accuracy actually holds.

Watch

Extended reading notes

Core claim

The paper's central claim is that MAC CE control signaling is unprotected at the MAC layer because PDCP's encryption and integrity protection do not extend to it, and that this exposure is systemic, not limited to the Layer 1/Layer 2 Triggered Mobility (LTM) case that the standard body has already acknowledged. It identifies sixteen privacy-sensitive fields, including C-RNTI, Timing Advance Command, Serving Cell ID, SSB Index, TCI State ID, and LCG ID, and argues that each one leaks information or enables tampering: C-RNTI enables identity hijacking, TA tampering causes uplink desynchronization, and beam-related IDs expose direction. The paper further claims that combining fields creates location disclosure chains: for example, C-RNTI plus Serving Cell ID plus TA plus SSB Index narrows a user's position to an annular sector around a known base station, and long-term monitoring reconstructs movement trajectories. It concludes by recommending that future security mechanisms grade MAC CEs into four classes so that low-risk fields stay in plaintext for latency while high-risk fields receive integrity protection, encryption, or both.

Load-bearing premise

The analysis assumes an attacker can passively decode and actively forge MAC CE fields over the air without being detected or blocked by lower-layer mechanisms, and that public base-station and beam-pattern databases are accurate enough to turn those fields into user locations.

Editorial extensions

If this is right

  • Passive eavesdroppers can reconstruct application usage, daily routines, residence, and workplace from MAC CE field patterns such as LCG ID, BWP ID, Serving Cell ID, and TA Command.
  • Active attackers can cause denial of service by forging TA Commands, DRX commands, or UE Contention Resolution Identities, and can hijack a user's C-RNTI to impersonate the device.
  • Beam-related fields such as SSB Index, TCI State ID, and Spatial Relation Info ID turn beam management into a location oracle when combined with public base-station data.
  • Without protection changes, newer 5G-Advanced procedures such as LTM cell switches and multi-TRP coordination inherit the same exposure, so the proposed M1-M4 grading is a candidate input to future standard security work.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same field-combination reasoning would apply to 6G integrated sensing and positioning, where MAC-level timing and beam fields could support even finer localization than in 5G.
  • A natural test of the framework is to implement a proof-of-concept that forges a Timing Advance Command in a testbed and measures whether a commercial UE actually loses uplink synchronization; the paper does not quantify the practical difficulty of injecting a MAC PDU at the correct time and frequency.
  • The M1-M4 proposal would benefit from a latency and signaling-overhead analysis: adding integrity protection or encryption to every MAC CE has a cost per transmission that the paper identifies qualitatively but does not measure.
  • The location disclosure chains assume public base-station and beam-pattern databases are accurate and current; a field study comparing predicted versus ground-truth positions would bound how much privacy is actually lost.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

5 major / 4 minor

Summary. The paper surveys security aspects of the MAC Control Element (MAC CE) in 3GPP 5G NR. It argues that MAC CE control signaling is sent below PDCP and therefore receives neither PDCP encryption nor integrity protection, making it susceptible to passive interception and active tampering. The paper introduces the structure and typical types of MAC CE, analyzes privacy risks of individual fields such as C-RNTI, TA Command, SSB Index, and TCI State ID, provides a starred risk table (Table I), develops location-disclosure chains for current and long-term user location, and proposes four protection mechanisms (M1-M4) in Table II. The central observation about the absence of PDCP-layer protection for MAC CE is consistent with 3GPP specifications, but the active-tampering half of the claim and the risk ratings require additional support.

Significance. If substantiated, the paper addresses a relevant and under-studied topic: low-layer control signaling in 5G is security-critical, and MAC CE carries scheduling, timing, and beam-management commands that are not protected by PDCP. The paper usefully organizes a large set of MAC CE types and privacy-sensitive fields, and it connects to prior work on LTE/5G low-layer attacks. Its contribution, however, is primarily a classification and recommendations framework rather than a new attack or a quantitative evaluation. The passive-interception concern is well grounded in the protocol architecture. The active-tampering claims and the star-based risk ratings are less solid, and the protection framework is not evaluated for feasibility or overhead. With additional analysis these gaps are fixable, so the manuscript has potential but is not yet ready in its current form.

major comments (5)
  1. [Section III.B, Table I] The one- to five-star security risk ratings in Table I are presented without any stated methodology. The text only says “We have conducted an analysis,” but does not define what determines one star versus five stars, nor does it cite a quantitative or qualitative scoring rubric. Since Table II maps these same ratings to the M1-M4 protection mechanisms, the entire recommendation framework inherits this arbitrary scaling. The authors should either define an explicit risk-scoring methodology (e.g., impact × exploitability with concrete criteria) or replace the stars with a transparent ordinal classification justified by supporting evidence.
  2. [Section III.B and III.C] The active-tampering analysis is load-bearing but its feasibility is not established. The attacks described in Section III.B implicitly assume that an attacker can forge or modify a MAC CE on PDSCH or PUSCH at the correct time and frequency, using the victim's C-RNTI, scheduling grant, HARQ process, and timing alignment, without being detected. The manuscript does not analyze how an attacker obtains these prerequisites, nor whether a forged MAC PDU would survive the CRC, HARQ combining, and lower-layer checks. Prior work cited in the paper (e.g., [13], [14], [16]) demonstrates overshadowing or injection on specific channels such as PDCCH or paging, often under LTE conditions, not generic 5G PDSCH MAC CE injection. Section III.C then builds location-spoofing and desynchronization scenarios on this unverified capability. The authors should either provide a feasibility analysis grounded in the cited attacks or explicitly downgrade the tampering claims to conditional statements.
  3. [Section III.C] The location-disclosure chains assume a level of localization accuracy that is never quantified. For example, the combination “C-RNTI + Serving Cell ID + TA Command + SSB Index” is claimed to narrow the UE to a sector and an annular region, but the paper does not account for the quantization of the TA value, the beamwidth of the SSB, or the accuracy of public base-station and beam-pattern databases. The claimed ability to reconstruct movement trajectories depends on these error sources. The authors should provide a quantitative error analysis or at least state the assumptions about database accuracy and field granularity, so that the privacy risk is not overstated.
  4. [Section III.D, Table II] The proposed M1-M4 framework is not evaluated. M2 (integrity protection) is described as appending a hash or HMAC to plaintext, but no key-management or authentication mechanism is specified for the MAC layer, and HMAC requires a shared key that is not available below PDCP. M3 and M4 (encryption and hybrid) would add latency and overhead, which conflicts with the low-latency purpose of MAC CE; no quantitative or simulation results are provided. Moreover, the mapping of fields to M1-M4 in Table II appears arbitrary: for example, C-RNTI is assigned M4 while TA Command, which has a five-star tampering rating, is assigned M2. The framework needs a clear derivation from the risk analysis and a feasibility assessment in the context of 3GPP procedures.
  5. [Section III.A] The analysis in Section III.A mixes MAC CE-borne fields with physical-layer identifiers that are not carried inside MAC CE. PCI and SSB Index are broadcast as physical-layer signals, not as MAC CE fields; the paper itself acknowledges they are “transmitted in the clear” and “transmitted in the plain text.” Including them in a privacy analysis of MAC CE overstates the set of fields that are exposed specifically because of missing MAC-layer protection. The authors should clearly separate fields that are sent inside MAC CE from those broadcast at the PHY layer, and adjust the security claims accordingly.
minor comments (4)
  1. [Abstract and throughout] The phrase “lacks encryption and integrity protection mechanisms provided by PDCP” is imprecise: PDCP integrity protection in 5G applies to the control plane (RRC), not generally to user-plane data or to MAC CE, which is below PDCP. The wording should be clarified to avoid implying that PDCP would protect MAC CE if it were present.
  2. [Section I] There are several typographical and grammatical issues, such as “I N the 5G NR protocol stack”, “we conduct an discussion”, and inconsistent article usage. A careful proofread would improve readability.
  3. [Figures 1-6] The text refers to figures as “in 1” and “in 2” rather than “Fig. 1” and “Fig. 2”. The figure references should be standardized and all figures should be explicitly cited in the text.
  4. [Section III.A] The claim that “Based on 3GPP specs, this section analyzes the privacy risks” is followed by citations to attack papers ([14]-[18]) rather than to specific clause numbers of TS 38.321 or TS 38.331. Tying each field to the relevant specification clause would make the analysis more verifiable.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the paper's security claims rest on external 3GPP specifications and independent prior attacks, while its star ratings and M1–M4 framework are qualitative classifications and normative recommendations, not derived predictions.

full rationale

This is a survey and threat-analysis paper with no equations, no fitted parameters, and no quantitative predictions, so the fitted-input-called-prediction and self-definitional patterns do not apply. The central claim that MAC CE is interceptable and tamperable because it is carried below PDCP's encryption and integrity protection ('Since MAC CE lacks encryption and integrity protection mechanisms provided by PDCP, the control signaling carried by MAC CE is vulnerable to interception or tampering by attackers') is grounded in the 3GPP TS 38.321 protocol architecture, an external standard, and is independently corroborated by published experimental attacks cited in the paper ([4] 'Touching the Untouchables', [8] 'Breaking LTE on Layer Two', [13], [14], [16]). Field-level risk statements such as 'the TA value is positively correlated with the UE-to-base-station distance' are externally validated properties from the protocol and measurement literature, not derived predictions. Table I's star ratings and the M1–M4 framework are presented as the authors' qualitative assessment and normative design proposal; assigning stronger mechanisms to higher-rated risks is a stated design rule, not a claimed empirical discovery, so no rating is a fitted input renamed as a prediction. The only possible self-citation is [5] (an IEEE S&P 2025 paper listing 'H. Li', plausibly co-author Hui Li), used alongside [4] for the premise that attackers can intercept and tamper with control signaling via malicious base stations; this is not load-bearing because [4] and the 3GPP specifications independently support the same premise, and the cited work is a peer-reviewed external artifact. No uniqueness theorem is imported from the authors' prior work, and no ansatz is smuggled in via citation. The main gap noted by skeptical readers — that active MAC CE forging presupposes knowledge of the victim's C-RNTI, scheduling grant, timing, and frequency without detection — concerns the practical feasibility and completeness of the attack model and belongs to correctness risk, not circularity. The analysis is self-contained against external benchmarks, so the honest finding is no significant circularity.

Assumptions & free parameters 1 free parameters · 3 assumptions · 0 invented entities

The paper does not introduce physical entities or formal parameters. Its main hand-chosen elements are the star risk ratings and the M1-M4 protection labels, which are qualitative classifications rather than fitted quantities. The core assumptions are about the attack model and the availability of public geolocation databases, both of which are plausible but not empirically validated here.

free parameters (1)
  • Subjective risk ratings (1 to 5 stars) = Per-field star counts in Table I
    Each MAC CE field is assigned a risk level by hand, with no stated methodology or calibration data. These ratings directly determine the recommended protection mechanism in Table II, so they function as hand-chosen parameters for the paper's security framework.
assumptions (3)
  • domain assumption MAC CE is transmitted without encryption or integrity protection at the MAC layer.
    This is the central premise, stated in the abstract and Section I, and it matches 3GPP TS 38.321 and the cited literature.
  • domain assumption An attacker can passively observe MAC CE fields and actively forge or modify them over the air.
    The threat analysis in Section III depends on this capability, but the paper does not analyze the practical difficulty of achieving it against PHY-layer scrambling, CRC, or timing requirements.
  • domain assumption Publicly available base station databases and beam pattern databases provide accurate mappings from cell IDs, PCIs, and beam indices to geographic locations.
    The location disclosure chains in Section III-C rely on this mapping to convert identifiers like Serving Cell ID, SSB Index, and TCI State ID into physical positions.

how reviews work

0 comments
Cite this review

Pith. "Pith review of The Security Overview and Analysis of 3GPP 5G MAC CE." pith.science (2026). https://pith.science/paper/ZKALUZLG

@misc{pith2026250609502,
  author       = {Pith},
  title        = {Pith review of: The Security Overview and Analysis of 3GPP 5G MAC CE},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ZKALUZLG}},
  note         = {Machine review of arXiv:2506.09502}
}
read the original abstract

To more effectively control and allocate network resources, MAC CE has been introduced into the network protocol, which is a type of control signaling located in the MAC layer. Since MAC CE lacks encryption and integrity protection mechanisms provided by PDCP, the control signaling carried by MAC CE is vulnerable to interception or tampering by attackers during resource scheduling and allocation. Currently, the 3GPP has analyzed the security risks of Layer 1/Layer 2 Triggered Mobility (LTM), where handover signaling sent to the UE via MAC CE by the network can lead to privacy leaks and network attacks. However, in addition to LTM, there may be other potential security vulnerabilities in other protocol procedures. Therefore, this paper explores the security threats to MAC CE and the corresponding protection mechanisms. The research is expected to support the 3GPP's study of MAC CE and be integrated with the security research of lower-layer protocols, thereby enhancing the security and reliability of the entire communication system.

Figures

Figures reproduced from arXiv: 2506.09502 by the authors.

Figure 1
Figure 1. Examples of Downlink MAC PDUs. MAC subPDU including MAC CE 1 MAC subPDU including MAC CE 2 MAC subPDU including MAC SDU ... MAC subPDU including MAC SDU MAC subPDU including padding (opt) R/LCID subheader Fixed-sized MAC CE R/F/LCID/L subheader Variable-sized MAC CE R/F/LCID/L subheader MAC SDU [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Examples of Uplink MAC PDUs [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 5
Figure 5. Structure of SP CSI reporting on PUCCH Activation/Deactivation [PITH_FULL_IMAGE:figures/full_fig_p003_5.png] view at source ↗
Figures from the paper (1 more)
Figure 6
Figure 6. Figure 6: Structure of LTM MAC CE. III. THE SECURITY RISKS OF MAC CES A. Analysis on Privacy-sensitive Field The MAC CE serves as a pivotal mechanism for enabling dynamic radio resource allocation and adaptive beamforming optimization. However, the privacy risks associated with …

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

22 extracted references · 22 canonical work pages

  1. [13]

    Unprotected 4G/5G Control Procedures at Low Layers Considered Dangerous

    N. Ludant, M. V omvas, G. Noubir, Unprotected 4g/5g control procedures at low layers considered dangerous, arXiv preprint arXiv:2403.06717 (2024)

  2. [14]

    S. Erni, M. Kotuliak, P. Leu, M. Roeschlin, S. Capkun, Adaptover: adaptive overshadowing attacks in cellular networks, in: Proceedings of the 28th Annual International Conference on Mobile Computing And Networking, 2022, pp. 743–755

  3. [16]

    H. Yang, S. Bae, M. Son, H. Kim, S. M. Kim, Y . Kim, Hiding in plain signal: Physical signal overshadowing attack on{LTE}, in: 28th USENIX Security Symposium (USENIX Security 19), 2019, pp. 55–72

  4. [1]

    3GPP, 5g; nr; medium access control (mac) protocol specification, Tech. Rep. 38.321, 3rd Generation Partnership Project (3GPP), version V18.5.0 (2025)

  5. [2]

    S. Yi, S. Chun, Y . Lee, S. Park, S. Jung, Radio Protocols for LTE and LTE-advanced, John Wiley & Sons, 2012

  6. [3]

    W. LEI., A. Soong, L. Jianghua, W. Yong, B. Classon, W. Xiao, D. Mazzarese, Z. Yang, T. Saboorian, 5G system design, Springer, 2021

  7. [4]

    H. Kim, J. Lee, E. Lee, Y . Kim, Touching the untouchables: Dynamic security analysis of the lte control plane, in: 2019 IEEE Symposium on Security and Privacy (SP), IEEE, 2019, pp. 1153–1168

  8. [5]

    W. Liu, Z. Lai, Q. Wu, H. Li, Y . Weng, W. Liu, Q. Zhang, J. Li, Y . Li, J. Liu, Mind the location leakage in leo direct-to-cell satellite networks, in: 2025 IEEE Symposium on Security and Privacy (SP), IEEE Computer Society, 2025, pp. 1026–1042

Show all 22 references
  1. [6]

    C. Yu, S. Chen, Z. Cai, Lte phone number catcher: A practical attack against mobile privacy, Security and Communication Networks 2019 (1) (2019) 7425235

  2. [7]

    Shaik, R

    A. Shaik, R. Borgaonkar, N. Asokan, V . Niemi, J.-P. Seifert, Practical attacks against privacy and availability in 4g/lte mobile communication systems, arXiv preprint arXiv:1510.07563 (2015)

  3. [8]

    Rupprecht, K

    D. Rupprecht, K. Kohls, T. Holz, C. P ¨opper, Breaking lte on layer two, in: 2019 IEEE Symposium on Security and Privacy (SP), IEEE, 2019, pp. 1121–1136

  4. [9]

    S. R. Hussain, M. Echeverria, A. Singla, O. Chowdhury, E. Bertino, Insecure connection bootstrapping in cellular networks: the root of all evil, in: Proceedings of the 12th conference on security and privacy in wireless and mobile networks, 2019, pp. 1–11

  5. [10]

    3GPP, Lte; evolved universal terrestrial radio access (e-utra); medium access control (mac) protocol specification, Tech. Rep. 36.321, 3rd Generation Partnership Project (3GPP), release 18 (2025)

  6. [11]

    J. Song, H. Chung, A packet processing scheme in 5g mac protocol using dpdk, in: 2023 14th International Conference on Information and Communication Technology Convergence (ICTC), IEEE, 2023, pp. 1423–1426

  7. [12]

    Ahmadi, New radio access layer 2/3 aspects and system operation, 5G NR (2019) 195–284

    S. Ahmadi, New radio access layer 2/3 aspects and system operation, 5G NR (2019) 195–284

  8. [15]

    Kotuliak, S

    M. Kotuliak, S. Erni, P. Leu, M. R ¨oschlin, S. ˇCapkun,{LTrack}: Stealthy tracking of mobile phones in{LTE}, in: 31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 1291–1306

  9. [17]

    Bitsikas, T

    E. Bitsikas, T. Schnitzler, C. P ¨opper, A. Ranganathan, Freaky leaky {SMS}: Extracting user locations by analyzing{SMS}timings, in: 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 2151– 2168

  10. [18]

    C. Yu, S. Chen, F. Wang, Z. Wei, Improving 4g/5g air interface security: A survey of existing attacks on different lte layers, Computer Networks 201 (2021) 108532

  11. [19]

    Ahmad, S

    I. Ahmad, S. Shahabuddin, T. Kumar, J. Okwuibe, A. Gurtov, M. Yliant- tila, Security for 5g and beyond, IEEE Communications Surveys & Tutorials 21 (4) (2019) 3682–3722

  12. [20]

    Palam `a, F

    I. Palam `a, F. Gringoli, G. Bianchi, N. Blefari-Melazzi, Imsi catchers in the wild: A real world 4g/5g assessment, Computer Networks 194 (2021) 108137

  13. [21]

    3GPP, Technical specification group radio access network; nr; radio resource control (rrc) protocol specification, Tech. Rep. 38.331, 3rd Generation Partnership Project (3GPP), version 18.5.1 (2025)

  14. [22]

    Ludant, G

    N. Ludant, G. Noubir, Sigunder: A stealthy 5g low power attack and defenses, in: Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks, 2021, pp. 250–260

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.