MediaTek Filogic 850 is a cost-effective, mainstream dual-band Wi-Fi 7 (IEEE 802.11be) access point (AP) system-on-chip (SoC) platform designed for reliable, low-latency wireless networking in mid-range devices.
It targets applications such as GPON and fiber gateways, 5G CPE, consumer routers, repeaters, mesh nodes, access points, and other Wi-Fi-enabled networking hardware. The platform emphasizes balanced performance, power efficiency, integration (including integrated FEM), and affordability rather than flagship multi-gigabit or tri-band peak speeds.
Position in the Filogic Family
MediaTek’s Filogic series covers Wi-Fi solutions across generations and market segments:
- Earlier Wi-Fi 6/6E parts (e.g., Filogic 830).
- Wi-Fi 7 lineup ranging from flagship (Filogic 880 with up to BE36000 / ~36 Gbps tri/penta-band potential) and mid-high (Filogic 860 / BE7200-class dual-band) down to more accessible options.
- Client-side chips (300-series).
The Filogic 850 (internally associated with MT7987A/B “Griffin”) sits in the mainstream/cost-effective tier of the Wi-Fi 7 AP platforms. It pairs a host SoC with flexible NIC options (including support for pairing with higher-end Wi-Fi NICs such as Filogic 650/660/680 equivalents in development/reference designs). It delivers up to BE3600-class performance while incorporating key Wi-Fi 7 features.
Core Specifications
CPU and Compute
- Quad-core Arm Cortex-A53 at up to 2 GHz (~18.4K DMIPS).
- Dedicated Network Processing Unit (NPU) for up to 7.5 Gbps packet processing, wired + wireless offload, and hardware acceleration of common networking functions (PPPoE, VLAN, MAP-E, DS-Lite, etc.).
- Memory support up to DDR4-3200.
- The NPU offloads traffic so the CPU cores remain available for OS customization, apps, or value-added services.
Wi-Fi Capabilities
- Dual-band concurrent Wi-Fi 7 (2.4 GHz + 5 GHz).
- Antenna configuration: 2.4 GHz 2T2R (2 spatial streams) + 5 GHz 3T3R (2 spatial streams), with options for 2T2R + 1R zero-wait DFS.
- Peak PHY throughput: up to 3.6 Gbps (BE3600 class).
- Channel bandwidths: up to 40 MHz on 2.4 GHz and 160 MHz on 5 GHz.
- Key Wi-Fi 7 features: 4096-QAM, Multi-Link Operation (MLO) with single-MAC architecture, Multi-RU, OFDMA (RU 4+8), MU-MIMO (2+2), flexible shared MAC entries (up to 512), MBSSID (16+16).
- Integrated iFEM (PA + LNA) in the MediaTek RFIC for both bands — this reduces external component count, board size, power draw, and cost.
- Supports full Wi-Fi Alliance Wi-Fi 7 certification features.
Wired Connectivity and Interfaces
- Multi-gigabit Ethernet support via 5 Gbps HSGMII (enabling 2×2.5G configurations in designs) plus integrated 1 GbE PHY.
- PCIe 3.0 (2×1-lane or 1×2-lane configurations).
- USB 3.2 Gen 1 (5 Gbps, shared with HSGMII in some configurations).
- Standard peripherals: SPI, I²C, UART, GPIO, plus PCM/I²S for VoIP or audio services.
Security
- Secure Boot, Arm TrustZone, hardware cryptography engine (EIP-197 class for acceleration of IPv4 NATP, IPv6, DS-Lite, 6RD, etc.).
- FIPS 140-3 support.
Key Architectural and Performance Highlights
MediaTek highlights its single-chip / single-MAC MLO design as a differentiator. This architecture manages multi-link aggregation and band switching more efficiently than multi-MAC approaches used by some competitors, claiming substantially lower latency (up to 100× in certain scenarios according to MediaTek) and smoother operation under load or when switching bands. Combined with the dedicated NPU, the platform aims for consistent real-world throughput and low latency even in congested or challenging RF environments.
The integrated FEM and relatively modest antenna counts (versus higher-end 4×4 or 5×5 designs) help keep BOM cost, power consumption, and physical size down — important for high-volume mainstream routers, ISP gateways, and CPE devices.
Target Use Cases and Design Flexibility
- Cost-sensitive consumer and ISP broadband equipment (GPON ONTs with Wi-Fi, 5G fixed wireless CPE, mid-tier routers and mesh systems).
- Access points and repeaters where dual-band Wi-Fi 7 with solid MLO performance is desired without flagship pricing or complexity.
- Designs that may later pair the SoC with higher-capability external Wi-Fi NICs for scaled performance.
Open-source and development activity (e.g., MediaTek OpenWrt feeds and reference boards such as MTK RFB or Banana Pi BPI-R4-Lite variants) indicates active support for Linux-based firmware, which is common in this segment.
Context and Trade-offs
Compared with higher Filogic 800-series parts:
- Lower peak wireless rate and no native 6 GHz / 320 MHz support in the base dual-band configuration.
- More modest CPU (Cortex-A53 vs. higher-IPC A73 cores in some siblings) and simpler Ethernet options in base configurations.
- Stronger emphasis on integration, cost, and power efficiency.
In return, it brings modern Wi-Fi 7 capabilities (especially MLO and 4096-QAM) into a broader set of devices than pure flagship silicon allows. As Wi-Fi 7 adoption expands beyond premium gear into mainstream and operator equipment, platforms like the Filogic 850 help bridge the gap between older Wi-Fi 6/6E silicon and full high-end Wi-Fi 7 implementations.
In short, the Filogic 850 is MediaTek’s practical, feature-complete dual-band Wi-Fi 7 SoC for volume networking products that need reliable multi-gigabit-class wireless performance, modern multi-link operation, hardware offload, and competitive cost/power characteristics without requiring the absolute highest theoretical speeds or tri-band complexity.
CPU and Compute capabilities
The CPU and compute subsystem of the MediaTek Filogic 850 centers on a practical, power-efficient application processor paired with a dedicated Network Processing Unit (NPU), optimized for networking workloads rather than general-purpose high-performance computing.
This design prioritizes reliable packet handling, offloading of networking tasks, and headroom for device customization (OS, services, and light applications) in mainstream Wi-Fi 7 routers, gateways, CPE, and access points.
Application Processor (Main CPU)
- Architecture: Quad-core Arm Cortex-A53 (64-bit, ARMv8-A).
- Clock speed: Up to 2 GHz.
- Performance rating: Approximately 18.4K DMIPS (Dhrystone Million Instructions Per Second).
- Role: Handles the operating system (typically Linux/OpenWrt-based), control-plane tasks, management interfaces, user applications, and any residual networking work not offloaded to the NPU.
The Cortex-A53 is a power-efficient “little” core known for solid multi-threaded efficiency and low thermal/power footprints. It is well-suited to the always-on nature of networking equipment. Compared with higher-end Filogic platforms (such as the Filogic 880’s Cortex-A73 cores delivering closer to 30K DMIPS), the A53 configuration trades peak single-thread performance and IPC for cost, power efficiency, and integration simplicity.
In practice, this CPU provides enough compute for:
- Running a full-featured router OS with web UI, VPN services, QoS policies, and parental controls.
- Supporting value-added features (mesh management, basic analytics, or ISP-specific software).
- Handling control traffic and exceptions while the NPU manages the data plane.
Network Processing Unit (NPU)
The integrated NPU is the more specialized compute engine for high-throughput networking:
- Packet processing capacity: Up to 7.5 Gbps.
- Wi-Fi offload: Supports approximately 800K packets per second (pps) Tx/Rx Wi-Fi offloading.
- Hardware acceleration: PPPoE, VLAN, MAP-E, DS-Lite, and related tunneling/encapsulation functions.
- Scope: Operates across both wireless (Wi-Fi) and wired (Ethernet) paths, enabling full-speed bridging and routing between interfaces without saturating the main CPU.
By offloading the bulk of data-plane work, the NPU keeps the Cortex-A53 cores free for higher-level tasks. This architecture is a hallmark of modern Filogic designs and helps maintain low latency and consistent throughput even under mixed wired/wireless traffic loads.
Memory Subsystem
- Support for up to DDR4-3200.
- Typical implementations use DDR3 or DDR4 in bandwidth-appropriate configurations for the target market (often in the 256 MB–1 GB+ range depending on the final product design).
Adequate memory bandwidth supports the combined needs of the CPU, NPU, Wi-Fi MAC, and any concurrent services.
Security and Related Compute Features
Security is tightly integrated with the compute complex:
- Secure Boot.
- Arm TrustZone (for isolated secure execution environments).
- Hardware cryptography engine (EIP-197 class) accelerating IPv4 NATP, IPv6, DS-Lite, 6RD, and related functions.
- FIPS 140-3 support.
These features reduce software overhead on the main CPU for cryptographic and secure-boot operations while meeting operator and enterprise security requirements.
Design Implications and Trade-offs
| Aspect | Filogic 850 Characteristics | Implication for Devices |
|---|---|---|
| CPU cores / ISA | 4× Cortex-A53 @ 2 GHz | Efficient multi-threading; lower peak IPC vs. A73-class |
| Rated performance | ~18.4K DMIPS | Sufficient for mainstream router OS + light services |
| Data-plane engine | Dedicated NPU (up to 7.5 Gbps, 800 Kpps Wi-Fi offload) | High sustained throughput with low CPU utilization |
| Memory | Up to DDR4-3200 | Good bandwidth for dual-band Wi-Fi 7 + multi-gig Ethernet |
| Power / thermal profile | Optimized for efficiency | Suitable for compact, fanless, or cost-sensitive designs |
| Customization headroom | CPU freed by NPU offload | Room for vendor apps, mesh logic, or ISP features |
Strengths: Balanced cost, power, and networking performance; strong offload keeps the system responsive under load; mature Arm ecosystem and Linux support (including OpenWrt reference designs).
Limitations relative to higher Filogic parts: Lower absolute CPU performance and packet-processing peak rates than flagship platforms (e.g., Filogic 880). It is not intended for the most demanding multi-radio or ultra-high concurrent-session scenarios without additional external acceleration.
In summary, the Filogic 850’s compute architecture deliberately pairs a capable yet efficient quad-core Cortex-A53 application processor with a purpose-built NPU. This combination delivers the real-world networking performance and customization flexibility expected in mainstream dual-band Wi-Fi 7 equipment while controlling cost, power, and complexity.
Wi-Fi Capabilities
The Wi-Fi capabilities of the MediaTek Filogic 850 deliver mainstream dual-band Wi-Fi 7 (IEEE 802.11be) performance optimized for cost-effective routers, gateways, CPE, repeaters, and access points.
It focuses on reliable connectivity, low latency via Multi-Link Operation (MLO), and efficient spectrum use rather than the highest multi-band peak rates found in flagship platforms.
Core Wi-Fi Specifications
- Standard: Full Wi-Fi 7 (802.11be), with backward compatibility for 802.11a/b/g/n/ac/ax.
- Bands: Concurrent dual-band operation on 2.4 GHz and 5 GHz (no native 6 GHz support in the base configuration).
- Peak PHY throughput: Up to 3.6 Gbps (marketed as BE3600 class).
- Antenna configuration:
- 2.4 GHz: 2T2R (2 transmit / 2 receive) with 2 spatial streams (2SS); maximum channel bandwidth typically 40 MHz.
- 5 GHz: 3T3R (3 transmit / 3 receive) with 2 spatial streams (2SS), or alternative 2T2R + 1R configuration supporting zero-wait DFS (Dynamic Frequency Selection).
- Maximum channel bandwidth on 5 GHz: 160 MHz.
- Integrated RF front-end: iFEM (integrated Power Amplifier and Low-Noise Amplifier) inside the MediaTek RFIC for both bands. This reduces external component count, board size, power consumption, and overall BOM cost while improving efficiency.
Key Wi-Fi 7 Features Supported
The platform incorporates the major enhancements introduced with Wi-Fi 7:
- 4096-QAM (4K-QAM): Higher-order modulation that increases data density per symbol compared with Wi-Fi 6’s 1024-QAM, improving peak rates under good signal conditions.
- Multi-Link Operation (MLO): Simultaneous or coordinated use of multiple bands/links. MediaTek emphasizes its single-chip / single-MAC MLO architecture, which manages multi-link aggregation and band switching more efficiently than some multi-MAC designs. This is claimed to reduce latency significantly (MediaTek cites up to 100× improvement in certain scenarios versus competing solutions) and deliver smoother performance under load or when links change.
- Multi-RU (Multiple Resource Units): More flexible allocation of OFDMA resource units, allowing better efficiency for mixed traffic types.
- OFDMA: Supports Resource Units configured as 4+8 (downlink/uplink emphasis typical for this class of chip).
- MU-MIMO: 2+2 configuration (supporting multi-user simultaneous transmissions).
- MAC capacity: Flexible shared hardware MAC entries (up to 512) and MBSSID support (16+16), suitable for multi-SSID enterprise-style or ISP deployments.
- Additional capabilities: Zero-wait DFS options on the 5 GHz side for faster channel availability, along with standard Wi-Fi 7 mechanisms for improved reliability in dense or interference-prone environments.
The platform is designed to support full Wi-Fi Alliance Wi-Fi 7 certification features.
Performance Characteristics and Design Focus
| Aspect | Filogic 850 Capability | Practical Benefit |
|---|---|---|
| Peak rate | Up to 3.6 Gbps (BE3600) | Solid multi-gigabit wireless for mainstream homes and small offices |
| Spatial streams | 2SS per band | Balanced throughput vs. cost/power/antenna complexity |
| Channel bandwidth | 40 MHz (2.4 GHz) / 160 MHz (5 GHz) | Good efficiency on the more open 5 GHz band |
| MLO architecture | Single-chip / single-MAC | Lower latency and smoother multi-band operation |
| RF integration | Integrated iFEM (PA + LNA) | Smaller designs, lower power, reduced cost |
| Offload synergy | Works with dedicated NPU | Sustained throughput with low main-CPU load |
Real-world performance depends on client capabilities, channel conditions, interference, and firmware optimization. The dual-band focus (rather than tri-band with 6 GHz) keeps the platform simpler and more affordable while still delivering the core Wi-Fi 7 advantages—especially MLO for lower latency and better reliability when devices support multi-link operation.
Context Within the Filogic Portfolio
Compared with higher-end Filogic Wi-Fi 7 parts (e.g., Filogic 860 or 880):
- Lower peak aggregate rates and fewer spatial streams / antennas.
- No native 6 GHz or 320 MHz channel support in the standard dual-band configuration.
- Stronger emphasis on integration, cost, and power efficiency.
This makes the Filogic 850 well-suited for high-volume mainstream products where dual-band Wi-Fi 7 with modern features (MLO, 4K-QAM, Multi-RU) provides a meaningful upgrade over Wi-Fi 6/6E without the complexity or cost of flagship multi-radio platforms.
In summary, the Filogic 850’s Wi-Fi subsystem provides a complete, certification-ready dual-band Wi-Fi 7 solution with competitive latency and efficiency features, integrated RF, and practical antenna configurations tailored for cost-sensitive yet modern networking equipment.
Wired Connectivity and Interfaces
The wired connectivity and interfaces of the MediaTek Filogic 850 provide flexible multi-gigabit Ethernet options and a practical set of expansion ports tailored for mainstream routers, gateways, CPE, and access points.
These capabilities emphasize cost-effective multi-gigabit support, offload integration with the NPU, and sufficient expansion for peripherals, storage, or additional radios without the higher-end complexity of flagship Filogic platforms.
Ethernet Connectivity
- Primary multi-gigabit support: 5 Gbps HSGMII interface(s), enabling designs with up to 2× 2.5 Gigabit Ethernet ports.
- Integrated PHY: Built-in 1 GbE PHY for a standard Gigabit Ethernet port (useful as a WAN or LAN interface without external components).
- Flexibility for designers: The HSGMII links can connect to external multi-gigabit switches, PHYs, or SFP modules in product designs. Reference configurations (such as those in OpenWrt/MediaTek feeds) commonly pair the platform with internal/external 2.5G PHYs or switches (e.g., AN8855-class switches) for multi-port setups.
This combination supports common mainstream product configurations such as:
- 1× 2.5G WAN + multiple 1G LAN ports
- Dual 2.5G ports (WAN + LAN or dual WAN)
- Hybrid setups with SFP for fiber CPE applications
The dedicated NPU provides hardware acceleration and offload across both wired and wireless paths (up to 7.5 Gbps packet processing), ensuring full-speed bridging/routing between Ethernet and Wi-Fi without saturating the main CPU.
Expansion and Peripheral Interfaces
- PCI Express: PCIe 3.0 supporting 2×1-lane or 1×2-lane configurations. This is commonly used to attach external Wi-Fi NICs (for higher-performance or multi-radio designs), storage controllers, or other high-speed peripherals.
- USB: USB 3.2 Gen 1 (5 Gbps). Note that this interface is shared with one of the HSGMII resources in some pinmux configurations, so designers must choose between maximizing Ethernet ports or enabling the high-speed USB port depending on the product requirements.
- Serial and control interfaces:
- SPI
- I²C
- UART
- GPIO (general-purpose input/output)
- Audio interfaces: PCM and I²S, supporting VoIP, voice services, or basic audio applications common in some gateways and CPE devices.
- Additional typical support (seen in Filogic-family and reference designs): Storage options such as SPI-NOR/SPI-NAND flash, eMMC, or SD interfaces for firmware and data storage.
Design Implications and Typical Use
| Interface | Key Specs | Common Applications in Filogic 850 Designs |
|---|---|---|
| HSGMII (5 Gbps) | Enables 2× 2.5G Ethernet | Multi-gigabit WAN/LAN, SFP fiber, external switches |
| 1 GbE PHY | Integrated Gigabit Ethernet | Cost-effective LAN or secondary WAN port |
| PCIe 3.0 | 2×1 or 1×2 lanes | External Wi-Fi NICs, expansion cards |
| USB 3.2 Gen 1 | 5 Gbps (shared with HSGMII option) | External storage, dongles, or peripherals |
| SPI / I²C / UART / GPIO | Standard control buses | Sensors, LEDs, buttons, management chips |
| PCM / I²S | Audio interfaces | VoIP or voice gateway features |
Strengths: The multi-gigabit Ethernet options (via HSGMII + integrated 1G PHY) deliver practical wired performance that matches the dual-band BE3600 Wi-Fi capabilities for most mainstream use cases. Pinmux flexibility and NPU offload keep the platform efficient. PCIe support allows manufacturers to scale wireless performance by pairing with higher-end Filogic NICs when needed.
Trade-offs relative to higher Filogic platforms (e.g., Filogic 880): Fewer and lower-speed Ethernet interfaces (no native dual 10G USXGMII), more constrained PCIe resources, and shared USB/HSGMII pins. This keeps the Filogic 850 simpler and more affordable while still supporting the multi-gigabit wired needs of typical consumer and ISP equipment.
In summary, the Filogic 850’s wired connectivity and interfaces strike a practical balance—delivering multi-gigabit Ethernet flexibility, solid expansion options via PCIe and USB, and the control interfaces needed for complete product designs—while remaining aligned with its cost-effective, mainstream Wi-Fi 7 positioning
Security capabilities
The security features of the MediaTek Filogic 850 provide a solid foundation for trusted boot, isolated execution, hardware-accelerated cryptography, and compliance-oriented design suitable for mainstream networking equipment such as routers, gateways, CPE, and access points.
These capabilities help protect firmware integrity, isolate sensitive operations, accelerate common networking security functions, and support regulatory or operator requirements without significantly increasing cost or power.
Core Security Features
MediaTek lists the following as the primary built-in security capabilities of the Filogic 850 SoC:
- Secure Boot
- Ensures that only authenticated and unmodified firmware can run at startup. This establishes a hardware root of trust, verifying the integrity of the bootloader and subsequent software stages before they execute. It helps prevent unauthorized or malicious firmware from loading on the device.
- Arm TrustZone
- Provides hardware-enforced isolation between a secure world (trusted execution environment) and a normal world (standard OS and applications). Sensitive operations—such as key handling, cryptographic services, or privileged management functions—can run in the protected TrustZone environment, reducing the attack surface of the main Linux-based OS.
- Cryptography Engine (EIP-197 class)
- A dedicated hardware cryptographic accelerator (based on Rambus/Inside Secure EIP-197 technology commonly used in Filogic platforms). It offloads compute-intensive cryptographic operations from the main CPU and NPU.Key accelerated functions include:
- IPv4 NAPT / NATPIPv6 processingDS-Lite and 6RD tunnelingRelated security and tunneling operations
- A dedicated hardware cryptographic accelerator (based on Rambus/Inside Secure EIP-197 technology commonly used in Filogic platforms). It offloads compute-intensive cryptographic operations from the main CPU and NPU.Key accelerated functions include:
- FIPS 140-3 Support
- The platform is designed to support FIPS 140-3 grade security. This indicates compliance readiness for the U.S. government cryptographic module standard (and similar requirements used by many operators and enterprises). It covers validated cryptographic algorithms, key management practices, and operational modes that can meet formal certification needs when the full system (hardware + firmware + software) is properly configured and validated.
How These Features Work Together
| Feature | Primary Role | Benefit in Networking Devices |
|---|---|---|
| Secure Boot | Firmware authenticity and integrity at boot | Prevents rootkits or unauthorized OS/firmware |
| Arm TrustZone | Runtime isolation of sensitive code and data | Protects keys and privileged services |
| EIP-197 Crypto Engine | Hardware acceleration of crypto and tunneling | High-throughput secure networking with low CPU load |
| FIPS 140-3 Support | Compliance and validated cryptographic operations | Meets operator, enterprise, or regulatory requirements |
The cryptography engine integrates with the platform’s Network Processing Unit (NPU) so that security and tunneling operations can run efficiently alongside general packet processing. This keeps the main Cortex-A53 CPU free for control-plane tasks and applications.
Practical Implications for Device Makers and Deployments
- ISP and operator equipment (GPON, 5G CPE, gateways) can leverage Secure Boot and FIPS-oriented design for secure remote management and compliance.
- Consumer routers and mesh systems gain protection against firmware tampering and support for modern encrypted traffic without heavy software overhead.
- VoIP or service gateways benefit from the combination of crypto acceleration and TrustZone for secure voice or management services.
- Open-source ecosystems (such as OpenWrt with MediaTek feeds) include progressive support for these security features, though full Secure Boot enablement may depend on specific firmware versions and board configurations.
Positioning and Limitations
The Filogic 850’s security suite is comprehensive for its mainstream market segment. It provides the essential hardware roots of trust and acceleration expected in modern Wi-Fi 7 networking silicon. Higher-end Filogic platforms may offer additional performance headroom in the crypto engine or more extensive isolation features, but the 850’s implementation is well-matched to dual-band BE3600-class devices.
In summary, the Filogic 850 combines Secure Boot, Arm TrustZone, a capable hardware cryptography engine (EIP-197 class), and FIPS 140-3 support to deliver trusted operation, efficient secure networking, and compliance readiness in a cost-effective Wi-Fi 7 platform.