MAC

Message Authentication Code

Security →
Introduced in R99 Also in: Security, Core Network

MAC is a cryptographic checksum used in the 3GPP authentication protocol to verify data integrity and authenticate the network to the user equipment.

Category
Security
Introduced
R99
Where
Radio Access Network › NG-RAN (5G)
Also touches
2 segments
Specifications
98 specs
MAC Description Purpose Related Classification Detected Changes Specifications

Description

In 3GPP security, the Message Authentication Code (MAC) is a critical element generated during the Authentication and Key Agreement (AKA) procedure. Specifically, it refers to the MAC included within the Authentication Token (AUTN) that the network sends to the User Equipment (UE) for mutual authentication. The MAC is computed by the network's Authentication Centre (AuC) using the cryptographic algorithm f1 (or its variant f1* for 5G AKA) with a secret key K (shared with the UE's USIM), a random challenge RAND, a sequence number SQN, and an Authentication Management Field (AMF) as inputs. The formula is MAC = f1_K(SQN || RAND || AMF).

The architecture involves the Home Subscriber Server (HSS)/AuC in the core network generating the authentication vector, which contains RAND, AUTN (which includes MAC and other fields), XRES, and session keys. The AUTN is sent to the serving network (e.g., MME in 4G, AMF in 5G), which forwards RAND and AUTN to the UE. Upon receipt, the UE's USIM independently computes an expected MAC (XMAC) using the same f1 algorithm, its shared key K, and the received RAND, SQN, and AMF. The USIM then compares the computed XMAC with the MAC value extracted from the received AUTN. If they match, it proves to the UE that the authentication vector was generated by an entity possessing the correct secret key K, thereby authenticating the network. A mismatch indicates a potential security threat, and authentication fails.

How it works is deeply tied to the AKA protocol's mutual authentication goal. The MAC's inclusion in AUTN allows the UE to verify the network's legitimacy before proceeding. It protects against forgery attacks; an attacker cannot construct a valid AUTN without knowledge of K. The MAC computation is one-way and cryptographically strong, ensuring that even if RAND and AUTN are intercepted, the secret key cannot be derived. Its role is foundational for establishing a trusted session, as successful MAC validation is a prerequisite for the UE to compute the session keys (CK, IK) and the network's expected response (RES), completing the mutual authentication handshake. This mechanism is used across 3G (UMTS), 4G (EPS-AKA), and 5G (5G AKA, EAP-AKA').

Purpose & Motivation

The Message Authentication Code within AKA was created to provide explicit network authentication to the user equipment, addressing a security weakness in the earlier 2G (GSM) system. In GSM, only the network authenticated the mobile station (one-way authentication), leaving it vulnerable to false base station attacks ("IMSI catchers") where a rogue network could impersonate a legitimate one. The introduction of mutual authentication in 3GPP UMTS was a fundamental security enhancement, and the MAC is the mechanism that enables the UE to verify the network.

The problem it solves is proving the network's authenticity to the UE in a shared secret key context. Without the MAC, a UE could not distinguish between a legitimate network and an attacker broadcasting a captured RAND. The MAC, derived from the shared secret K and other freshness parameters (SQN, RAND), provides this proof. Its creation was motivated by the need for stronger security as mobile networks evolved to carry sensitive data and transactions. It addresses the limitation of one-way authentication by ensuring that both parties in the communication are verified, forming the basis for secure key derivation and protecting against man-in-the-middle and replay attacks. This established the trusted foundation for all subsequent 3GPP security architectures.

Classification

Part ofAKA
Specific typesLCGMDMPDUXMAC
Related approachesAUTN

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (53 CRs across 5 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 22 changes

In Release 15, the MAC function saw enhancements for tighter integration between LTE and NR in EN-DC, including clarifications and corrections for Dual Connectivity Power Headroom Report (PHR) and other MAC Control Elements (CEs). It introduced support for a MAC PDU containing a UE contention resolution identity MAC CE without an RRC response message specifically for NB-IoT. The release also provided corrections and clarifications on procedures such as Early Data Transmission (EDT), MAC-I calculation for resume/reestablishment, and the MAC header and subheader structure.

  • EN-DC impacts to LTE MAC TS 36.321CR1196
  • MAC functionality for euCA TS 36.321CR1274
  • Delay budget report and MAC CE adaptation for NR for TS 38.306 TS 38.306CR0013
  • Removal of MAC editor´s note TS 24.501CR0040
  • Introduction of support for MAC PDU containing UE contention resolution identity MAC control element without RRC response message in NB-IoT TS 36.306CR1570
  • Alignment of MAC CEs between LTE and NR TS 36.321CR1340

+ 16 more changes

Rel-16 12 changes

In Release 16, enhancements to the MAC function included the introduction of signaling for UE support of MAC address transfer for DS-TT operation and clarifications regarding the DS-TT MAC address itself. The release also specified the use of a Short MAC and ngKSI in the Control Plane Service Request NAS message and provided corrections and clarifications for MAC procedures in NB-IoT and eMTC, particularly related to Preconfigured Uplink Resources (PUR).

  • Signalling of UE support for transfer of port management information containers, MAC address and DS-TT residence time TS 24.501CR1358
  • Clarification of the DS-TT MAC address TS 29.521CR0069
  • Short MAC and ngKSI in Control plane service request NAS message TS 24.501CR1651
  • NAS-MAC calculation for RRC connection reestablishment for NB-IoT CP optimisation TS 24.501CR2174
  • NAS MAC terminology TS 24.501CR2434
  • Calculation of MAC in NAS transparent containers TS 24.501CR2482

+ 6 more changes

Rel-17 13 changes

In Release 17, enhancements to the MAC function included new MAC Control Element (MAC CE) configurations for Integrated Access and Backhaul (IAB) and for activating/deactivating positioning measurement gaps via RRC. The release also introduced support for specifying MAC address ranges within packet filters and provided clarifications on source and destination MAC address handling, particularly for Ethernet-type PDU sessions and IoT over Non-Terrestrial Networks (NTN).

  • Introducing IAB MAC CE Configurations in RRC TS 38.331CR3194
  • NAS MAC terminology TS 24.301CR3462
  • DS-TT Ethernet port MAC address only sent when the PDU session type is Ethernet TS 24.501CR3141
  • Clarification of destination and source MAC addresses TS 24.501CR3477
  • Support MAC address range in packet filter TS 24.501CR3408
  • Clarification on destination and source MAC address range TS 24.501CR3774

+ 7 more changes

Rel-18 3 changes

In Release 18, key MAC layer enhancements included the introduction of a MAC Control Element (MAC-CE) based procedure for updating Phase Tracking Reference Signal (PL RS) parameters for configured grant Type-1 PUSCH transmissions. Additionally, specifications were refined to preclude the simultaneous configuration of both a specific MAC address and a MAC address range within the same packet filter component. The release also encompassed miscellaneous MAC corrections for IoT operations over Non-Terrestrial Networks (NTN).

  • Introduction of MAC CE based PL RS updates for Type-1 CG-PUSCH [PL RS Type 1 CG] TS 38.331CR4513
  • Precluding inclusion of both a destination (resp. source) MAC address type and a destination (resp. source) MAC address range type packet filter components in a packet filter TS 24.501CR4468
  • Miscellaneous MAC correction for IoT NTN TS 36.321CR1588
Rel-19 3 changes

In Release 19, the MAC layer introduced new support for Scheduling Request (SR) resources within a MAC Control Element (MAC CE) used for Long-Term Mobility (LTM) cell switching procedures. Additionally, this release defined an extension to the k-Mac parameter specifically for IoT devices operating in Non-Terrestrial Networks (NTN) with TDD duplexing.

  • Introducing SR resources in LTM cell switch MAC CE [LTM_enh_SR] TS 38.306CR1367
  • Introducing SR resources in LTM cell switch MAC CE [LTM_enh_SR] TS 38.331CR5530
  • Introduction of the extended k-Mac for IoT NTN TDD TS 36.331CR5197

Explore further

Broader topics and technologies where MAC plays a role.

Defining Specifications

3GPP specifications that define or reference MAC, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TR 21.905 vj00 3GPP Technical Terms and Definitions Rel-19
TR 22.944 vj00 UE Functionality Split Scenarios and Requirements Rel-19
TS 23.050 v1100 UMTS Network Principles and Architecture R99
TS 23.060 vj00 GPRS Service Description Stage 2 Rel-19
TS 23.146 vj00 3G Facsimile Group 3 Technical Realization Rel-19
TS 24.109 vj00 HTTP Digest AKA & GAA Stage 3 Rel-19
TS 24.229 vj50 IMS call control protocol based on SIP and SDP Rel-19
TS 24.244 vj00 Wireless LAN Control Plane Protocol Rel-19
TS 24.301 vj60 NAS protocol for Evolved Packet System Rel-19
TS 24.369 vj00 AIoT NAS protocol for 5G System Rel-19
TS 24.501 vj50 5G NAS Protocols Specification Rel-19
TS 25.201 vj00 UTRA Physical Layer General Description Rel-19
TS 25.212 vj00 UTRA FDD Layer 1 Multiplexing & Channel Coding Rel-19
TS 25.222 vj00 UTRA TDD Multiplexing & Channel Coding Rel-19
TS 25.224 vj00 UTRA TDD Physical Layer Procedures Rel-19
TS 25.301 vj00 UE-UTRAN Radio Interface Protocol Architecture Rel-19
TS 25.302 vj00 UTRA Physical Layer Services Rel-19
TS 25.321 vj00 MAC Protocol Specification for UTRAN Rel-19
TS 25.322 vj00 RLC Protocol Specification Rel-19
TS 25.324 vj00 Broadcast/Multicast Control Protocol Rel-19
TS 25.331 vj00 UTRAN RRC Protocol Specification Rel-19
TS 25.401 vj00 UTRAN Overall Architecture Rel-19
TS 25.402 vj00 UTRAN Synchronisation Mechanisms Rel-19
TS 25.420 vj00 Iur Interface Introduction for UTRAN Rel-19
TS 25.423 vj00 UTRAN RNSAP Specification Rel-19
TR 25.912 vj00 Evolved UTRA and UTRAN Technical Report Rel-19
TR 25.931 vj00 UTRAN Signalling Procedures Examples Rel-19
TS 26.202 vj00 AMR-WB Speech Codec Mapping Specification Rel-19
TR 26.902 vj00 Video Codec Performance for 3GPP Packet Services Rel-19
TR 26.935 vj00 Speech Codec Performance for Packet Switched Multimedia Rel-19
TS 27.060 vj00 TE-MT Interworking for Packet Domain Rel-19
TS 29.204 vj00 SS7 Security Gateway Functional Description Rel-19
TS 29.509 vj50 AUSF Service Based Interface Protocol Rel-19
TS 29.521 vj40 5G Binding Support Management Service Stage 3 Rel-19
TS 29.890 vg00 CT3 5G System Technical Report Rel-16
TS 31.102 vj40 USIM Application Specification Rel-19
TS 31.103 vj00 ISIM Application Specification Rel-19
TS 31.113 v1800 USAT Interpreter Byte Code Specification Rel-8
TS 31.114 v1800 USAT Interpreter Transmission Protocol Rel-8
TR 31.900 vj00 3GPP TS 31.900: Security Interworking Guidance Rel-19
TS 33.102 vj10 3G Security Architecture Specification Rel-19
TS 33.105 vj00 3G Security: Cryptographic Algorithm Requirements Rel-19
TS 33.110 vj00 UICC-Terminal Key Establishment Rel-19
TS 33.203 vj10 IMS Security Specification Rel-19
TS 33.204 vj00 TCAP Security (TCAPsec) Stage 2 Specification Rel-19
TS 33.210 vj20 UMTS Security for IP Networks Rel-19
TS 33.224 vj00 Generic Push Layer (GPL) Specification Rel-19
TS 33.246 vj00 MBMS Security Specification Rel-19
TS 33.259 vj00 Key Establishment between UICC Hosting & Remote Device Rel-19
TS 33.700 3GPP TR 33.700 R99
TS 33.814 vg01 Security aspects of enhanced Location Services (eLCS) Rel-16
TS 33.821 v900 LTE/SAE Security Threat Analysis and Countermeasures Rel-9
TR 33.851 vh10 Security for Industrial IoT in 5G Rel-17
TS 35.205 vj00 MILENAGE Algorithm Set: General Overview Rel-19
TS 35.234 vj00 MILENAGE-256 Algorithm Set Specification Rel-19
TS 35.235 vj00 MILENAGE-256 Algorithm Set Specification Rel-19
TS 35.236 vj00 MILENAGE-256 Algorithm Set Specification Rel-19
TS 35.249 vj10 f5** Algorithm for MILENAGE and Tuak Rel-19
TR 35.909 vj00 3GPP MILENAGE Algorithm Design Report Rel-19
TR 35.934 vj00 Tuak algorithm set for 3GPP auth & key gen Rel-19
TR 35.937 vj00 MILENAGE-256 Algorithm Set Specification Rel-19
TS 36.133 vj20 E-UTRA RRM Requirements Rel-19
TS 36.201 vj00 LTE Physical Layer General Description Rel-19
TS 36.300 vj00 E-UTRAN Radio Interface Protocol Architecture Overview Rel-19
TS 36.302 vj00 E-UTRA Physical Layer Services Rel-19
TS 36.305 vj00 UE Positioning in E-UTRAN Stage 2 Rel-19
TS 36.306 vj00 E-UTRA UE Radio Access Capability Parameters Rel-19
TS 36.321 vj00 E-UTRA MAC Protocol Specification Rel-19
TS 36.322 vj00 E-UTRA Radio Link Control Protocol Specification Rel-19
TS 36.323 vj00 PDCP Protocol Specification Rel-19
TS 36.331 vj00 LTE RRC Protocol Specification Rel-19
TS 36.509 vh40 EPC Special UE Conformance Testing Functions Rel-17
TS 36.938 v900 E-UTRAN to 3GPP2/Mobile WiMAX Mobility Rel-9
TS 37.320 vj00 Minimization of Drive Tests (MDT) Overview Rel-19
TS 37.355 vj20 LTE Positioning Protocol (LPP) Rel-19
TR 37.901 vf10 UE Application Layer Data Throughput Performance Rel-15
TS 38.133 vj20 5G UE Radio Requirements for RRC_IDLE Mobility Rel-19
TS 38.201 vj00 NR Physical Layer General Description Rel-19
TS 38.202 vj00 5G NR Physical Layer Services Rel-19
TS 38.305 vj00 NG-RAN UE Positioning Stage 2 Rel-19
TS 38.306 vj00 NR UE Radio Access Capability Parameters Rel-19
TS 38.323 vj00 Packet Data Convergence Protocol (PDCP) Rel-19
TS 38.331 vj00 NR Radio Resource Control (RRC) Protocol Specification Rel-19
TS 38.522 vj11 UE Conformance Test Applicability Statement Rel-19
TS 43.051 vj00 GERAN Stage 2 Service Description Rel-19
TS 43.064 vj00 GPRS Radio Interface Lower-Layer Functions Rel-19
TS 43.129 vj00 PS Handover in GERAN A/Gb and GAN Modes Rel-19
TS 43.318 vj00 Generic Access Network (GAN) Stage 2 Rel-19
TR 43.901 vj00 Generic Access to A/Gb Interface Feasibility Study Rel-19
TR 43.902 vj00 GAN Enhancements Feasibility Study Rel-19
TS 44.060 vj00 GERAN RLC/MAC Protocol Specification Rel-19
TS 44.160 vg00 GERAN Iu Mode RLC/MAC Protocol Specification Rel-16
TS 44.318 vj00 Generic Access Network (GAN) Interface Procedures Rel-19
TS 45.820 vd10 CIoT for Internet of Things Rel-13
TR 45.902 vj00 Flexible Layer One (FLO) for GERAN Rel-19
TS 48.016 vj00 Gb Interface Network Service Specification Rel-19
TS 55.241 vj00 3GPP Integrity Algorithm GIA4 Specification Rel-19
TS 55.251 vj00 GEA5 and GIA5 Encryption Algorithm Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.