REVIEW 5 major objections 4 minor 22 references
The Security Overview and Analysis of 3GPP 5G MAC CE
T0 review · 5 major / 4 minor · reviewed 2026-08-07 · deepseek-v4-flash
Pith's one-line read 5G MAC Control Elements are transmitted without PDCP encryption or integrity protection, and their fields can be combined to leak location and enable tampering.
desk verdict A useful survey of MAC CE security risks, stronger on passive exposure than on the feasibility of active tampering; worth refereeing after the risk ratings and protection framework are substantiated. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the MAC Control Element (MAC CE), a fixed- or variable-sized control payload inside the MAC PDU that the receiving MAC entity identifies by a reserved Logical Channel ID (LCID) in the subheader. The load-bearing mechanism of the analysis is the field-combination chain: individually benign parameters such as C-RNTI, Serving Cell ID, TA Command, and SSB Index, when correlated with public base-station geolocation databases and beam-pattern knowledge, yield an annular-sector estimate of the user's position and a long-term movement profile. The paper's proposed countermeasure is a four-tier graded security framework, M1 through M4, that assigns plaintext transmission, integrity protection, encryption, or a hybrid of the latter two to each MAC CE type according to its confidentiality, integrity, and latency requirements.
What would settle it
A testbed experiment in which a software-defined radio transmits a forged Timing Advance Command MAC CE toward a commercial 5G UE would settle the DoS claim: if the UE rejects the message or the PHY layer blocks injection, desynchronization does not occur; if the UE loses uplink synchronization, the claimed tampering risk is real. Separately, a measurement campaign pairing ground-truth positions with observed TA and SSB indices would test whether the claimed annular-sector localization accuracy actually holds.
Extended reading notes
Core claim
The paper's central claim is that MAC CE control signaling is unprotected at the MAC layer because PDCP's encryption and integrity protection do not extend to it, and that this exposure is systemic, not limited to the Layer 1/Layer 2 Triggered Mobility (LTM) case that the standard body has already acknowledged. It identifies sixteen privacy-sensitive fields, including C-RNTI, Timing Advance Command, Serving Cell ID, SSB Index, TCI State ID, and LCG ID, and argues that each one leaks information or enables tampering: C-RNTI enables identity hijacking, TA tampering causes uplink desynchronization, and beam-related IDs expose direction. The paper further claims that combining fields creates location disclosure chains: for example, C-RNTI plus Serving Cell ID plus TA plus SSB Index narrows a user's position to an annular sector around a known base station, and long-term monitoring reconstructs movement trajectories. It concludes by recommending that future security mechanisms grade MAC CEs into four classes so that low-risk fields stay in plaintext for latency while high-risk fields receive integrity protection, encryption, or both.
Load-bearing premise
The analysis assumes an attacker can passively decode and actively forge MAC CE fields over the air without being detected or blocked by lower-layer mechanisms, and that public base-station and beam-pattern databases are accurate enough to turn those fields into user locations.
Editorial extensions
If this is right
- Passive eavesdroppers can reconstruct application usage, daily routines, residence, and workplace from MAC CE field patterns such as LCG ID, BWP ID, Serving Cell ID, and TA Command.
- Active attackers can cause denial of service by forging TA Commands, DRX commands, or UE Contention Resolution Identities, and can hijack a user's C-RNTI to impersonate the device.
- Beam-related fields such as SSB Index, TCI State ID, and Spatial Relation Info ID turn beam management into a location oracle when combined with public base-station data.
- Without protection changes, newer 5G-Advanced procedures such as LTM cell switches and multi-TRP coordination inherit the same exposure, so the proposed M1-M4 grading is a candidate input to future standard security work.
Reading between the lines
- The same field-combination reasoning would apply to 6G integrated sensing and positioning, where MAC-level timing and beam fields could support even finer localization than in 5G.
- A natural test of the framework is to implement a proof-of-concept that forges a Timing Advance Command in a testbed and measures whether a commercial UE actually loses uplink synchronization; the paper does not quantify the practical difficulty of injecting a MAC PDU at the correct time and frequency.
- The M1-M4 proposal would benefit from a latency and signaling-overhead analysis: adding integrity protection or encryption to every MAC CE has a cost per transmission that the paper identifies qualitatively but does not measure.
- The location disclosure chains assume public base-station and beam-pattern databases are accurate and current; a field study comparing predicted versus ground-truth positions would bound how much privacy is actually lost.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper surveys security aspects of the MAC Control Element (MAC CE) in 3GPP 5G NR. It argues that MAC CE control signaling is sent below PDCP and therefore receives neither PDCP encryption nor integrity protection, making it susceptible to passive interception and active tampering. The paper introduces the structure and typical types of MAC CE, analyzes privacy risks of individual fields such as C-RNTI, TA Command, SSB Index, and TCI State ID, provides a starred risk table (Table I), develops location-disclosure chains for current and long-term user location, and proposes four protection mechanisms (M1-M4) in Table II. The central observation about the absence of PDCP-layer protection for MAC CE is consistent with 3GPP specifications, but the active-tampering half of the claim and the risk ratings require additional support.
Significance. If substantiated, the paper addresses a relevant and under-studied topic: low-layer control signaling in 5G is security-critical, and MAC CE carries scheduling, timing, and beam-management commands that are not protected by PDCP. The paper usefully organizes a large set of MAC CE types and privacy-sensitive fields, and it connects to prior work on LTE/5G low-layer attacks. Its contribution, however, is primarily a classification and recommendations framework rather than a new attack or a quantitative evaluation. The passive-interception concern is well grounded in the protocol architecture. The active-tampering claims and the star-based risk ratings are less solid, and the protection framework is not evaluated for feasibility or overhead. With additional analysis these gaps are fixable, so the manuscript has potential but is not yet ready in its current form.
major comments (5)
- [Section III.B, Table I] The one- to five-star security risk ratings in Table I are presented without any stated methodology. The text only says “We have conducted an analysis,” but does not define what determines one star versus five stars, nor does it cite a quantitative or qualitative scoring rubric. Since Table II maps these same ratings to the M1-M4 protection mechanisms, the entire recommendation framework inherits this arbitrary scaling. The authors should either define an explicit risk-scoring methodology (e.g., impact × exploitability with concrete criteria) or replace the stars with a transparent ordinal classification justified by supporting evidence.
- [Section III.B and III.C] The active-tampering analysis is load-bearing but its feasibility is not established. The attacks described in Section III.B implicitly assume that an attacker can forge or modify a MAC CE on PDSCH or PUSCH at the correct time and frequency, using the victim's C-RNTI, scheduling grant, HARQ process, and timing alignment, without being detected. The manuscript does not analyze how an attacker obtains these prerequisites, nor whether a forged MAC PDU would survive the CRC, HARQ combining, and lower-layer checks. Prior work cited in the paper (e.g., [13], [14], [16]) demonstrates overshadowing or injection on specific channels such as PDCCH or paging, often under LTE conditions, not generic 5G PDSCH MAC CE injection. Section III.C then builds location-spoofing and desynchronization scenarios on this unverified capability. The authors should either provide a feasibility analysis grounded in the cited attacks or explicitly downgrade the tampering claims to conditional statements.
- [Section III.C] The location-disclosure chains assume a level of localization accuracy that is never quantified. For example, the combination “C-RNTI + Serving Cell ID + TA Command + SSB Index” is claimed to narrow the UE to a sector and an annular region, but the paper does not account for the quantization of the TA value, the beamwidth of the SSB, or the accuracy of public base-station and beam-pattern databases. The claimed ability to reconstruct movement trajectories depends on these error sources. The authors should provide a quantitative error analysis or at least state the assumptions about database accuracy and field granularity, so that the privacy risk is not overstated.
- [Section III.D, Table II] The proposed M1-M4 framework is not evaluated. M2 (integrity protection) is described as appending a hash or HMAC to plaintext, but no key-management or authentication mechanism is specified for the MAC layer, and HMAC requires a shared key that is not available below PDCP. M3 and M4 (encryption and hybrid) would add latency and overhead, which conflicts with the low-latency purpose of MAC CE; no quantitative or simulation results are provided. Moreover, the mapping of fields to M1-M4 in Table II appears arbitrary: for example, C-RNTI is assigned M4 while TA Command, which has a five-star tampering rating, is assigned M2. The framework needs a clear derivation from the risk analysis and a feasibility assessment in the context of 3GPP procedures.
- [Section III.A] The analysis in Section III.A mixes MAC CE-borne fields with physical-layer identifiers that are not carried inside MAC CE. PCI and SSB Index are broadcast as physical-layer signals, not as MAC CE fields; the paper itself acknowledges they are “transmitted in the clear” and “transmitted in the plain text.” Including them in a privacy analysis of MAC CE overstates the set of fields that are exposed specifically because of missing MAC-layer protection. The authors should clearly separate fields that are sent inside MAC CE from those broadcast at the PHY layer, and adjust the security claims accordingly.
minor comments (4)
- [Abstract and throughout] The phrase “lacks encryption and integrity protection mechanisms provided by PDCP” is imprecise: PDCP integrity protection in 5G applies to the control plane (RRC), not generally to user-plane data or to MAC CE, which is below PDCP. The wording should be clarified to avoid implying that PDCP would protect MAC CE if it were present.
- [Section I] There are several typographical and grammatical issues, such as “I N the 5G NR protocol stack”, “we conduct an discussion”, and inconsistent article usage. A careful proofread would improve readability.
- [Figures 1-6] The text refers to figures as “in 1” and “in 2” rather than “Fig. 1” and “Fig. 2”. The figure references should be standardized and all figures should be explicitly cited in the text.
- [Section III.A] The claim that “Based on 3GPP specs, this section analyzes the privacy risks” is followed by citations to attack papers ([14]-[18]) rather than to specific clause numbers of TS 38.321 or TS 38.331. Tying each field to the relevant specification clause would make the analysis more verifiable.
Circularity Check
No significant circularity: the paper's security claims rest on external 3GPP specifications and independent prior attacks, while its star ratings and M1–M4 framework are qualitative classifications and normative recommendations, not derived predictions.
full rationale
This is a survey and threat-analysis paper with no equations, no fitted parameters, and no quantitative predictions, so the fitted-input-called-prediction and self-definitional patterns do not apply. The central claim that MAC CE is interceptable and tamperable because it is carried below PDCP's encryption and integrity protection ('Since MAC CE lacks encryption and integrity protection mechanisms provided by PDCP, the control signaling carried by MAC CE is vulnerable to interception or tampering by attackers') is grounded in the 3GPP TS 38.321 protocol architecture, an external standard, and is independently corroborated by published experimental attacks cited in the paper ([4] 'Touching the Untouchables', [8] 'Breaking LTE on Layer Two', [13], [14], [16]). Field-level risk statements such as 'the TA value is positively correlated with the UE-to-base-station distance' are externally validated properties from the protocol and measurement literature, not derived predictions. Table I's star ratings and the M1–M4 framework are presented as the authors' qualitative assessment and normative design proposal; assigning stronger mechanisms to higher-rated risks is a stated design rule, not a claimed empirical discovery, so no rating is a fitted input renamed as a prediction. The only possible self-citation is [5] (an IEEE S&P 2025 paper listing 'H. Li', plausibly co-author Hui Li), used alongside [4] for the premise that attackers can intercept and tamper with control signaling via malicious base stations; this is not load-bearing because [4] and the 3GPP specifications independently support the same premise, and the cited work is a peer-reviewed external artifact. No uniqueness theorem is imported from the authors' prior work, and no ansatz is smuggled in via citation. The main gap noted by skeptical readers — that active MAC CE forging presupposes knowledge of the victim's C-RNTI, scheduling grant, timing, and frequency without detection — concerns the practical feasibility and completeness of the attack model and belongs to correctness risk, not circularity. The analysis is self-contained against external benchmarks, so the honest finding is no significant circularity.
Assumptions & free parameters
free parameters (1)
- Subjective risk ratings (1 to 5 stars) =
Per-field star counts in Table I
assumptions (3)
- domain assumption MAC CE is transmitted without encryption or integrity protection at the MAC layer.
- domain assumption An attacker can passively observe MAC CE fields and actively forge or modify them over the air.
- domain assumption Publicly available base station databases and beam pattern databases provide accurate mappings from cell IDs, PCIs, and beam indices to geographic locations.
Cite this review
Pith. "Pith review of The Security Overview and Analysis of 3GPP 5G MAC CE." pith.science (2026). https://pith.science/paper/ZKALUZLG
@misc{pith2026250609502,
author = {Pith},
title = {Pith review of: The Security Overview and Analysis of 3GPP 5G MAC CE},
year = {2026},
howpublished = {\url{https://pith.science/paper/ZKALUZLG}},
note = {Machine review of arXiv:2506.09502}
}
read the original abstract
To more effectively control and allocate network resources, MAC CE has been introduced into the network protocol, which is a type of control signaling located in the MAC layer. Since MAC CE lacks encryption and integrity protection mechanisms provided by PDCP, the control signaling carried by MAC CE is vulnerable to interception or tampering by attackers during resource scheduling and allocation. Currently, the 3GPP has analyzed the security risks of Layer 1/Layer 2 Triggered Mobility (LTM), where handover signaling sent to the UE via MAC CE by the network can lead to privacy leaks and network attacks. However, in addition to LTM, there may be other potential security vulnerabilities in other protocol procedures. Therefore, this paper explores the security threats to MAC CE and the corresponding protection mechanisms. The research is expected to support the 3GPP's study of MAC CE and be integrated with the security research of lower-layer protocols, thereby enhancing the security and reliability of the entire communication system.
Figures
Figures from the paper (1 more)
Reference graph
Works this paper leans on
-
[13]
Unprotected 4G/5G Control Procedures at Low Layers Considered Dangerous
N. Ludant, M. V omvas, G. Noubir, Unprotected 4g/5g control procedures at low layers considered dangerous, arXiv preprint arXiv:2403.06717 (2024)
work page Pith review arXiv 2024
-
[14]
S. Erni, M. Kotuliak, P. Leu, M. Roeschlin, S. Capkun, Adaptover: adaptive overshadowing attacks in cellular networks, in: Proceedings of the 28th Annual International Conference on Mobile Computing And Networking, 2022, pp. 743–755
work page 2022
-
[16]
H. Yang, S. Bae, M. Son, H. Kim, S. M. Kim, Y . Kim, Hiding in plain signal: Physical signal overshadowing attack on{LTE}, in: 28th USENIX Security Symposium (USENIX Security 19), 2019, pp. 55–72
work page 2019
-
[1]
3GPP, 5g; nr; medium access control (mac) protocol specification, Tech. Rep. 38.321, 3rd Generation Partnership Project (3GPP), version V18.5.0 (2025)
work page 2025
-
[2]
S. Yi, S. Chun, Y . Lee, S. Park, S. Jung, Radio Protocols for LTE and LTE-advanced, John Wiley & Sons, 2012
work page 2012
-
[3]
W. LEI., A. Soong, L. Jianghua, W. Yong, B. Classon, W. Xiao, D. Mazzarese, Z. Yang, T. Saboorian, 5G system design, Springer, 2021
work page 2021
-
[4]
H. Kim, J. Lee, E. Lee, Y . Kim, Touching the untouchables: Dynamic security analysis of the lte control plane, in: 2019 IEEE Symposium on Security and Privacy (SP), IEEE, 2019, pp. 1153–1168
work page 2019
-
[5]
W. Liu, Z. Lai, Q. Wu, H. Li, Y . Weng, W. Liu, Q. Zhang, J. Li, Y . Li, J. Liu, Mind the location leakage in leo direct-to-cell satellite networks, in: 2025 IEEE Symposium on Security and Privacy (SP), IEEE Computer Society, 2025, pp. 1026–1042
work page 2025
Show all 22 references
-
[6]
C. Yu, S. Chen, Z. Cai, Lte phone number catcher: A practical attack against mobile privacy, Security and Communication Networks 2019 (1) (2019) 7425235
2019
-
[7]
Shaik, R
A. Shaik, R. Borgaonkar, N. Asokan, V . Niemi, J.-P. Seifert, Practical attacks against privacy and availability in 4g/lte mobile communication systems, arXiv preprint arXiv:1510.07563 (2015)
2015 arXiv
-
[8]
Rupprecht, K
D. Rupprecht, K. Kohls, T. Holz, C. P ¨opper, Breaking lte on layer two, in: 2019 IEEE Symposium on Security and Privacy (SP), IEEE, 2019, pp. 1121–1136
2019
-
[9]
S. R. Hussain, M. Echeverria, A. Singla, O. Chowdhury, E. Bertino, Insecure connection bootstrapping in cellular networks: the root of all evil, in: Proceedings of the 12th conference on security and privacy in wireless and mobile networks, 2019, pp. 1–11
2019
-
[10]
3GPP, Lte; evolved universal terrestrial radio access (e-utra); medium access control (mac) protocol specification, Tech. Rep. 36.321, 3rd Generation Partnership Project (3GPP), release 18 (2025)
2025
-
[11]
J. Song, H. Chung, A packet processing scheme in 5g mac protocol using dpdk, in: 2023 14th International Conference on Information and Communication Technology Convergence (ICTC), IEEE, 2023, pp. 1423–1426
2023
-
[12]
Ahmadi, New radio access layer 2/3 aspects and system operation, 5G NR (2019) 195–284
S. Ahmadi, New radio access layer 2/3 aspects and system operation, 5G NR (2019) 195–284
2019
-
[15]
Kotuliak, S
M. Kotuliak, S. Erni, P. Leu, M. R ¨oschlin, S. ˇCapkun,{LTrack}: Stealthy tracking of mobile phones in{LTE}, in: 31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 1291–1306
2022
-
[17]
Bitsikas, T
E. Bitsikas, T. Schnitzler, C. P ¨opper, A. Ranganathan, Freaky leaky {SMS}: Extracting user locations by analyzing{SMS}timings, in: 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 2151– 2168
2023
-
[18]
C. Yu, S. Chen, F. Wang, Z. Wei, Improving 4g/5g air interface security: A survey of existing attacks on different lte layers, Computer Networks 201 (2021) 108532
2021
-
[19]
Ahmad, S
I. Ahmad, S. Shahabuddin, T. Kumar, J. Okwuibe, A. Gurtov, M. Yliant- tila, Security for 5g and beyond, IEEE Communications Surveys & Tutorials 21 (4) (2019) 3682–3722
2019
-
[20]
Palam `a, F
I. Palam `a, F. Gringoli, G. Bianchi, N. Blefari-Melazzi, Imsi catchers in the wild: A real world 4g/5g assessment, Computer Networks 194 (2021) 108137
2021
-
[21]
3GPP, Technical specification group radio access network; nr; radio resource control (rrc) protocol specification, Tech. Rep. 38.331, 3rd Generation Partnership Project (3GPP), version 18.5.1 (2025)
2025
-
[22]
Ludant, G
N. Ludant, G. Noubir, Sigunder: A stealthy 5g low power attack and defenses, in: Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks, 2021, pp. 250–260
2021
Reviewed August 7, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.