C-RNTI

Cell Radio Network Temporary Identifier

Identifier →
Introduced in Rel-4 Also in: Security

C-RNTI is a temporary, unique identifier assigned by the gNB/eNB to a UE for its connection in a specific cell, crucial for scheduling, resource allocation, and addressing the UE over the air interface.

Category
Identifier
Introduced
Rel-4
Where
Radio Access Network › NG-RAN (5G)
Also touches
1 segments
Specifications
15 specs
C-RNTI Description Purpose Related Classification Detected Changes Specifications

Description

The Cell Radio Network Temporary Identifier (C-RNTI) is a fundamental identifier used in 3GPP radio access networks (RAN), including UMTS, LTE, and NR. It is a 16-bit value in LTE and NR, uniquely assigned by the serving base station (eNB in LTE, gNB in NR) to a User Equipment (UE) upon successful random access and connection establishment within that specific cell. The C-RNTI's primary role is to serve as a temporary address for the UE on the physical and MAC layers, allowing the network to efficiently manage and direct radio resources to that specific user.

Architecturally, the C-RNTI is a key component of the RAN's control plane. It is used to scramble the Cyclic Redundancy Check (CRC) of Downlink Control Information (DCI) messages on the Physical Downlink Control Channel (PDCCH). When a UE monitors the PDCCH, it attempts to decode DCI messages using its assigned C-RNTI as part of the de-scrambling process. A successful decode indicates that the control message (e.g., an uplink grant or downlink assignment) is intended for that specific UE. This mechanism provides secure and efficient addressing without requiring constant transmission of longer, permanent UE identities over the vulnerable air interface.

The C-RNTI is central to dynamic scheduling. For every Transmission Time Interval (TTI), the scheduler in the base station uses the C-RNTI to address grants and assignments to specific UEs. It is used for both uplink (UL-SCH) and downlink (DL-SCH) shared channel transmissions. The identifier is temporary and cell-specific; if a UE hands over to a new cell, it is assigned a new C-RNTI by the target cell. This ensures identifier uniqueness within a cell's coverage area and simplifies resource management. The C-RNTI is released when the UE's RRC connection is released or during handover procedures.

Beyond basic scheduling, the C-RNTI plays a role in other procedures. It is used for contention-based random access, where a UE may be assigned a Temporary C-RNTI initially, which can later be confirmed as its permanent C-RNTI for the connection. In connected mode, it is used for power control commands (TPC-PUCCH-RNTI, TPC-PUSCH-RNTI are derived concepts) and other MAC control elements. Its temporary nature is a critical security and privacy feature, preventing long-term tracking of a UE based on its radio signaling identifier.

Purpose & Motivation

The C-RNTI was created to solve the fundamental problem of efficiently and securely addressing a specific User Equipment within a radio cell for the purpose of resource allocation and control signaling. Prior to concepts like the C-RNTI, networks might have relied on longer, permanent identifiers for scheduling, which would be inefficient for frequent, small control messages and would pose a significant privacy risk due to the ease of tracking a device over the air.

Its introduction, particularly as LTE was designed, was motivated by the need for a highly dynamic, packet-scheduled air interface. Unlike circuit-switched systems, LTE and NR allocate resources on a millisecond basis. Transmitting a full UE identity (like the IMSI or S-TMSI) with every scheduling grant would create enormous overhead. The C-RNTI provides a short, locally significant handle that minimizes control channel overhead while enabling the high-speed, low-latency scheduling required for broadband data services.

The C-RNTI also addresses security and privacy concerns. By being temporary and cell-specific, it mitigates the risk of passive eavesdroppers tracking a user's location and connection patterns over a wide area. A UE is assigned a new C-RNTI in each cell, breaking the linkability of its radio signaling identity across different locations. This design is a core part of 3GPP's subscriber privacy protections. Furthermore, it simplifies RAN implementation by confining identifier management to a single cell or gNB, avoiding the need for global coordination of these temporary addresses.

Classification

Part ofRNTI

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (2 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-16 2 changes

In Release 16, corrections were introduced to clarify the prioritization between specific control messages and the Random Access Response (RAR) when assigning a C-RNTI during a Contention-Free Random Access (CFRA) procedure for Beam Failure Recovery (BFR). Additionally, corrections were made regarding the conditions for C-RNTI replacement and its application within the 2-step Random Access (RA) procedure. These updates provided more precise rules for C-RNTI handling in these advanced access scenarios.

  • Correction on prioritization between DCP and RAR to C-RNTI for CFRA BFR TS 38.300CR0295
  • Correction on C-RNTI replacement and conditions for 2-step RA TS 38.331CR2440

Explore further

Broader topics and technologies where C-RNTI plays a role.

Defining Specifications

3GPP specifications that define or reference C-RNTI, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TS 25.331 vj00 UTRAN RRC Protocol Specification Rel-19
TS 25.423 vj00 UTRAN RNSAP Specification Rel-19
TR 25.931 vj00 UTRAN Signalling Procedures Examples Rel-19
TS 32.836 vc00 NM Centralized Coverage and Capacity Optimization Study Rel-12
TS 33.401 vj10 EPS Security Architecture Rel-19
TS 33.843 vf10 Security Study for ProSe UE-to-Network Relay Rel-15
TS 36.133 vj20 E-UTRA RRM Requirements Rel-19
TS 36.300 vj00 E-UTRAN Radio Interface Protocol Architecture Overview Rel-19
TS 36.321 vj00 E-UTRA MAC Protocol Specification Rel-19
TS 36.331 vj00 LTE RRC Protocol Specification Rel-19
TS 36.401 vj00 E-UTRAN Overall Architecture Description Rel-19
TS 38.213 vj10 NR Physical Layer Control Procedures Rel-19
TS 38.300 vj00 NG-RAN Overall Description Rel-19
TS 38.331 vj00 NR Radio Resource Control (RRC) Protocol Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.