HFN

Hyper Frame Number

Identifier →
Introduced in Rel-4

HFN is a counter used in 3GPP protocols to extend the range of sequence numbers for ciphering and integrity protection, forming a longer COUNT parameter to ensure cryptographic synchronization and prevent replay attacks.

Category
Identifier
Introduced
Rel-4
Where
Radio Access Network › NG-RAN (5G)
Specifications
10 specs
HFN Description Purpose Related Classification Detected Changes Specifications

Description

The Hyper Frame Number (HFN) is a critical component in 3GPP security and protocol mechanisms, functioning as a high-order part of a counter used to generate cryptographic keys and ensure data freshness. It is employed alongside a shorter Sequence Number (SN) to construct a longer, composite COUNT value. For example, in LTE and NR, the COUNT parameter used in ciphering and integrity protection algorithms is typically 32 bits long, composed of a 20- to 25-bit HFN and a 7- to 12-bit SN, depending on the radio bearer and specific protocol. The SN increments with each Protocol Data Unit (PDU) and rolls over upon reaching its maximum value, at which point the HFN is incremented by one, effectively extending the counter's range to trillions of frames, thereby preventing reuse of the same COUNT value within a practical timeframe.

Architecturally, the HFN is maintained independently by both the sender and receiver (e.g., UE and base station or UE and core network) for each radio bearer or signaling connection. Synchronization of the HFN is crucial; it is typically initialized during connection establishment or handover procedures and then updated based on the rollover of the SN. The 3GPP specifications define precise rules for HFN management to avoid desynchronization, which could lead to decryption failures or integrity check mismatches. In scenarios like handovers, the HFN may be transferred or recalculated to maintain continuity. The HFN is also used in other contexts, such as in the Packet Data Convergence Protocol (PDCP) for sequence numbering and in some cases for timing alignment.

HFN's role is fundamental to the security and reliability of mobile networks. By providing a vast counter space, it ensures that the same ciphering key stream is not reused, which is essential to prevent cryptographic attacks such as keystream reuse. It also supports integrity protection by providing input for freshness parameters. The management of HFN is tightly integrated with mobility procedures, including handovers and connection re-establishments, to ensure seamless security continuity. Its implementation is transparent to higher layers but is vital for the underlying security framework that protects user data and signaling across 3GPP generations from UMTS to 5G NR.

Purpose & Motivation

The Hyper Frame Number was introduced to address the limitation of finite sequence number spaces in cryptographic protocols. Early mobile systems used sequence numbers alone for ciphering, but as data volumes increased, these sequence numbers could wrap around too quickly, leading to the reuse of cryptographic keystreams—a severe security vulnerability. The HFN extends the effective counter length, ensuring that the combined COUNT value (HFN || SN) does not repeat during the lifetime of a security key, thereby maintaining cryptographic strength and preventing replay attacks.

Historically, the concept evolved from GSM's ciphering mechanisms and was formally integrated into 3GPP standards starting with UMTS (Release 4) to provide robust security for the new packet-switched domains. The motivation was to support long-lived sessions and high data rates without compromising security. Without HFN, frequent rekeying would be necessary, increasing signaling overhead and potential service disruption. HFN enables efficient, long-term security synchronization, which is especially critical for always-on services and IoT devices with extended battery life. It solves the problem of managing secure communications over potentially years of device operation without key repetition, a foundational requirement for modern mobile networks.

Classification

Part ofPDCP

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (1 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 1 change

In Release 15, a specific Change Request was dedicated to the maintenance of the Hyper Frame Number (HFN) function. This work item, titled "CR on HFN maintenance," indicates focused updates to the procedures or handling of the HFN. The introduction of this CR signifies that Release 15 included targeted refinements to ensure the robust and correct operation of the HFN within the system.

Explore further

Broader topics and technologies where HFN plays a role.

Defining Specifications

3GPP specifications that define or reference HFN, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TS 23.401 vj50 Evolved Packet System (EPS) Stage 2 Description Rel-19
TS 25.331 vj00 UTRAN RRC Protocol Specification Rel-19
TS 33.401 vj10 EPS Security Architecture Rel-19
TS 36.323 vj00 PDCP Protocol Specification Rel-19
TS 36.331 vj00 LTE RRC Protocol Specification Rel-19
TS 36.413 vj10 S1 Application Protocol (S1AP) Rel-19
TS 36.423 vj10 X2 Application Protocol (X2AP) Specification Rel-19
TS 38.323 vj00 Packet Data Convergence Protocol (PDCP) Rel-19
TS 44.160 vg00 GERAN Iu Mode RLC/MAC Protocol Specification Rel-16
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.