Even though the name still remain as 'LTE-something", LTE-NB is pretty new design from the very bottom (Physical Layer). The biggest difference of any new wireless communication technology starts from physical layer frame structure. LTE-NB frame structure can be summarized as follows.
Since LTE-NB is considered as a LTE family, it has some commonalities with the legacy LTE as follows :
- The length of a subframe is 1 ms
- One Radio Frame is made up of 10 subframes
- Number of Subcarriers whithin a RB is 12
However, there are some characteristics of LTE-NB which are different from the legacy LTE :
- System Bandwidth is always 180 Khz
- The number of RB within a system bandwidh is always 1
- NPSS and NSSS are located in different subframes (whereas PSS, SSS in legacy LTE are located in same subframes).
- NPSS is transmitted in every radio frame but NSSS is transmitted in every two radio frames (in even frame) (whereas both PSS, SSS are transmitted in every radio frame)
< Physical Channel Allocations within a Radio Frame >

Each radio frame carries NPBCH in subframe 0 and NPSS in subframe 5. NSSS takes subframe 9 in every second frame, and every other subframe is free for NPDCCH or NPDSCH.
The picture above has two slips, and the text is right where they disagree. The even frame row labels its last subframe as a second Subframe 8, where it should read Subframe 9. The picture also draws NSSS in the odd frame. 36.211 v19.3.0 places NSSS in subframe 9 of the even radio frames, as the list above says and as the resource element maps below show.
Now let's look into the details (RE map) of each subframe. As mentioned in LTE-NB Operation Mode page, there are three different Operation Mode (Deployment Mode) namely In-Band, Guardband, Standalone mode. The detailed RE mapping varies a little bit depending on Operation Mode as showin in following sections.
Followings are the topics to be covered in this page.
- Frame Structure for In-Band Deplyment : Operation Mode
- Frame Structure for Guarband and StandAlone Deplyment : Operation Mode
- What changed after Release 13 ?
- Reference
Frame Structure for In-Band Deplyment : Operation Mode
In-band deployment puts the NB-IoT carrier inside a working LTE carrier, so the LTE signals in that resource block are still on the air. The question for this mode is which resource elements NB-IoT can use without damaging the LTE cell around it.
Following subframe structure shows the case in In-Band operation mode. Some of highlights of this frame structure can be summarized as follows (Think of your own interpretation before reading the following description) :
- LTE (Legacy LTE) Reference Signal still exists (This is because LTE Reference Signal is spread across the full systemband. LTE-NB deployment within the system bandwidth should not block the legacy LTE reference signal)
- The first thre symbols of each subframe is always reserved for legacy LTE. They are not used for LTE-NB (This is because LTE Control Signal region is spread across the full systemband. LTE-NB deployment within the system bandwidth should not block the legacy LTE Control Signal region)
- NPBCH occupies a whole subframe except the first three symbols at subframe 0 (See NPBCH Page for further details)
- NPSS occupies a whole subframe except the first three symbols and the last subcarrier at subframe 5 of every radio frame (See NPSS Page for further details)
- NSSS occupies a whole subframe except the first three symbols at subframe 9 of every even radio frame (See NSSS Page for further details)
- LTE-NB Reference Signal is located in symbol 5,6 and 12,13 of every subframe except the subframe for NPSS, NSSS subframe.
Following illustration is kindly provided by Damodar D from Lekha Wireless who is working on LTE-NB impementation and has been throughly reviewed by Samuele Riva from PRISMA Telecom Testing and some other additional correction by Venkatesh Yadav. Many of my initial mistake were corrected by his effort.
When you allocate the resources for Reference Signal, NPBCH, NPSS,NSSS, you should consider following factors since LTE-NB deployment should not interfere with the existing Legacy LTE resource allocation.
NPBCH : Based on 36.211-10.2.4.4
For the purpose of the mapping, the UE shall assume cell-specific reference signals for antenna ports 0-3 and narrowband reference signals for antenna ports 0 and 1 being present irrespective of the actual configuration
NPSS : Based on 36.211-10.2.7.1.2.
For resource elements (k,l) overlapping with resource elements where cell-specific reference signals according to clause 6.10 (Legacy LTE CRS) are transmitted, the corresponding sequence element d(n) is not used for the NPSS but counted in the mapping process.
NSSS : Based on 36.211-10.2.7.2.2.
For resource elements (k,l) overlapping with resource elements where cell-specific reference signals according to clause 6.10 (Legacy LTE CRS) are transmitted, the corresponding sequence element d(n) is not used for the NSSS but counted in the mapping process.
< LTE-NB Frame Structure for In-Band Deployment (Even Radio Frame) >

An in-band even radio frame. The LTE PDCCH region and the LTE CRS stay in place, and NPBCH, NPSS and NSSS fill what is left of subframes 0, 5 and 9.
< LTE-NB Frame Structure for In-Band Deployment (Odd Radio Frame) >

An in-band odd radio frame. It is the same as the even frame, except that subframe 9 carries NPDCCH or NPDSCH instead of NSSS.
The LTE CRS never moves : red LTE CRS resource elements appear in every subframe, inside the NB-IoT channels as well.The LTE control region stays free : symbols 0 to 2 of every subframe carry LTE PDCCH in these maps.NRS sits in the last two symbols of each slot : NRS port 0 and port 1 appear in symbols 5, 6, 12 and 13, except in the NPSS and NSSS subframes.Only the NSSS is missing from the odd frame : subframe 9 becomes an ordinary NPDCCH or NPDSCH subframe.
The three reserved symbols in these maps depend on the LTE cell. 36.213 v19.4.0 clause 16.4.1.4 starts NPDSCH at the symbol given by eutraControlRegionSize, which SIB1-NB carries only for in-band operation, with the values n1, n2 or n3. So an in-band cell with a one-symbol LTE control region gives NPDSCH two more symbols than the maps show. SIB1-NB subframes are the exception, and their start symbol is fixed by the operation mode, because the UE reads SIB1-NB before it knows eutraControlRegionSize.
Frame Structure for Guarband and StandAlone Deplyment : Operation Mode
Guardband and standalone deployments have no LTE signals inside the NB-IoT resource block, so the resource element map is simpler. The maps below still keep one thing from the in-band case, and the list explains which.
Following subframe structure shows the case in Guardband and Standalone operation mode. Some of highlights of this frame structure can be summarized as follows (Think of your own interpretation before reading the following description) :
- NPBCH occupies a whole subframe except the first three symbols at subframe 0 (See NPBCH Page for further details)
- NPSS occupies a whole subframe except the first three symbols and the last subcarrier at subframe 5 of every radio frame (See NPSS Page for further details)
- NSSS occupies a whole subframe except the first three symbols at subframe 9 of every even radio frame (See NSSS Page for further details)
- LTE-NB Reference Signal is located in symbol 5,6 and 12,13 of every subframe except the subframe for NPSS, NSSS subframe.
Following illustration is kindly provided by Damodar D from Lekha Wireless who is working on LTE-NB impementation and has been throughly reviewed by Samuele Riva from PRISMA Telecom Testing. Many of my initial mistake were corrected by his effort.
< LTE-NB Frame Structure for Guardband/Standalone Deployment (Even Radio Frame) >

A guardband or standalone even radio frame. There is no LTE CRS and no LTE PDCCH, so NPDCCH and NPDSCH start at symbol 0.
< LTE-NB Frame Structure for Guardband/Standalone Deployment (Odd Radio Frame) >

A guardband or standalone odd radio frame. As in the in-band case, subframe 9 carries NPDCCH or NPDSCH instead of NSSS.
The synchronization and broadcast channels keep their gap : NPBCH, NPSS and NSSS still leave symbols 0 to 2 unused, exactly as in the in-band maps.Everything else starts at symbol 0 : NPDCCH and NPDSCH use the whole subframe, because there is no LTE control region to protect.NRS stays where it was : NRS port 0 and port 1 keep the same positions as in the in-band maps.One map works for both modes : guardband and standalone differ in where the carrier sits, not in how its subframes are filled.
Keeping the same NPBCH, NPSS and NSSS layout in every mode has a clear benefit. A UE can detect the cell and decode NPBCH before it knows the operation mode, and MIB-NB then tells it the mode. That is also why the NSSS and NPSS descriptions above are the same in both lists.
What changed after Release 13 ?
The maps on this page describe Release 13 FDD. The specification has grown since then, and two changes affect the downlink frame structure. The frame structure itself did not change for FDD, so the maps above are still correct for an FDD cell.
The first change is TDD. Release 15 added NB-IoT for frame structure type 2. 36.211 v19.3.0 clause 10.2.7.2.2 maps NSSS to subframe 9 for frame structure type 1, as in the maps above, but to subframe 0 for frame structure type 2. So a TDD NB-IoT cell draws a different picture, and the maps on this page do not apply to it.
The second change is additional SIB1-NB transmissions. MIB-NB in 36.331 v19.3.0 carries additionalTransmissionSIB1-r15. Value TRUE means that additional SIB1-NB transmissions are present. The network sets it to TRUE only when schedulingInfoSIB1 indicates 16 NPDSCH repetitions. A cell that uses it fills some of the subframes shown here as NPDCCH or NPDSCH with SIB1-NB instead.
FDD is unchanged : NPBCH in subframe 0, NPSS in subframe 5 and NSSS in subframe 9 of even frames are the same today.TDD moves the NSSS : frame structure type 2 carries NSSS in subframe 0.SIB1-NB can take more subframes : additionalTransmissionSIB1-r15 adds SIB1-NB transmissions when 16 repetitions are configured.
Reference
[1] 3GPP TS 36.211 v19.3.0 - clause 10.2.7.1.2 and clause 10.2.7.2.2, mapping of NPSS and NSSS to resource elements
[2] 3GPP TS 36.213 v19.4.0 - clause 16.4.1.4, NPDSCH starting position
[3] 3GPP TS 36.331 v19.3.0 - MasterInformationBlock-NB and eutraControlRegionSize field descriptions