This page follows one NB-IoT UE from power-on to a completed attach, using messages captured from a test system. The table lists every step, including the NPDCCH grants, HARQ ACKs and RLC ACKs between the messages, and the sections after it show the decoded content of the main messages.
Followings are the topics to be covered in this page.
- Protocol Sequence Overview
- Message Details
- Step 1 - MIB
- Step 2 - SIB1
- Step 3 - SIB2 and others
- Step 7 - RRC Connection Request
- Step 10 - Contention Resolution + RRC Connection Setup
- Step 14 - RRC Connection Setup Complete + Attach Requeset + PDN Conn Request
- Step 18 - Authentication Request
- Step 23 - Authentication Response
- Step 27 - NAS Security Mode Command
- Step 32 - NAS Security Mode Complete
- Step 36 - Attach Accept + Activate Default EPS Bearer Context Request
- Reference
Protocol Sequence Overview
The attach itself needs only a handful of RRC and NAS messages, but the table below has 41 steps. Most of the extra steps are the lower-layer traffic that NB-IoT puts around each message. SS in the table is the system simulator that plays the eNB and the core network.
|
Step |
Direction |
Message |
Comments |
|
1 |
UE <--- SS |
||
|
2 |
UE <--- SS |
||
|
3 |
UE <--- SS |
||
|
4 |
UE ---> SS |
PRACH (RACH Preamble) |
|
|
5 |
UE <--- SS |
NPDCCH(DCI N1) |
Resource Decoding information for RAR message |
|
6 |
UE <--- SS |
RACH Response |
|
|
7 |
UE ---> SS |
||
|
8 |
< UE > |
UE MAC start mac-ContentionResolutionTimer |
3GPP 36.321 5.1.5 CR Timer value is set in SIB2 |
|
9 |
UE <--- SS |
NPDCCH(DCI N1) |
Resource Decoding information for CR |
|
10 |
UE <--- SS |
||
|
11 |
UE ---> SS |
HARQ ACK (NPUSCH format2) |
HARQ ACK for CR Reception |
|
12 |
< UE > |
UE MAC stop mac-ContentionResolutionTimer |
|
|
13 |
UE <--- SS |
UL Grant (DCI N0, NPDCCH) |
Grant for transmitting 'RRC Connection Setup Complete' |
|
14 |
UE ---> SS |
||
|
15 |
UE <--- SS |
DCI N1(NPDCCH) |
Resource Decoding information for RLC ACK |
|
16 |
UE <--- SS |
RLC ACK |
|
|
17 |
UE <--- SS |
DCI N1(NPDCCH) |
Resource Decoding information for Athentication Request |
|
18 |
UE <--- SS |
||
|
19 |
UE ---> SS |
HARQ ACK (NPUSCH format2) |
|
|
20 |
UE <--- SS |
UL Grant (DCI N0, NPDCCH) |
Grant to send RLC ACK |
|
21 |
UE ---> SS |
RLC ACK |
|
|
22 |
UE <--- SS |
UL Grant (DCI N0, NPDCCH) |
|
|
23 |
UE ---> SS |
||
|
24 |
UE <--- SS |
DCI N1(NPDCCH) |
Resource Decoding information for RLC ACK |
|
25 |
UE <--- SS |
RLC ACK |
|
|
26 |
UE <--- SS |
DCI N1(NPDCCH) |
Resource Decoding information for NAS Security Mode Command |
|
27 |
UE <--- SS |
||
|
28 |
UE ---> SS |
HARQ ACK (NPUSCH format2) |
|
|
29 |
UE <--- SS |
UL Grant (DCI N0, NPDCCH) |
Grant to send RLC ACK |
|
30 |
UE ---> SS |
RLC ACK |
|
|
31 |
UE <--- SS |
UL Grant (DCI N0, NPDCCH) |
Grant to send NAS Security Mode Complete |
|
32 |
UE ---> SS |
||
|
33 |
UE <--- SS |
DCI N1(NPDCCH) |
Resource Decoding information for RLC ACK |
|
34 |
UE <--- SS |
RLC ACK |
|
|
35 |
UE <--- SS |
DCI N1(NPDCCH) |
Resource Decoding information for Attach Accept |
|
36 |
UE <--- SS |
||
|
37 |
UE ---> SS |
HARQ ACK (NPUSCH format2) |
|
|
38 |
UE <--- SS |
UL Grant (DCI N0, NPDCCH) |
Grant to send RLC ACK |
|
39 |
UE ---> SS |
RLC ACK |
|
|
40 |
UE ---> SS |
RRC ulInformationTransfer + Attach Complete + Activate Default EPS Bearer Context Accept |
|
|
41 |
UE <--- SS |
RLC ACK |
Look at steps 14 to 40 and a pattern repeats. Each NAS message in the downlink needs an NPDCCH with DCI N1, the NPDSCH itself and a HARQ ACK on NPUSCH format 2. An UL grant with DCI N0 for the RLC ACK then follows. With a single HARQ process, as in Release 13, these steps cannot overlap, so the latency of the attach adds up step by step.
Steps 1 to 3 are system information : MIB-NB, SIB1-NB and SIB2-NB, with no DCI involved.Steps 4 to 12 are random access : preamble, RAR, Msg3 and Msg4 with contention resolution.Steps 14 to 40 are the attach : NAS messages carried in RRC, each surrounded by grants and ACKs.No RRC security appears : only the NAS Security Mode procedure protects this attach.
Message Details
The sections below show the decoded messages that the table links to. Each one keeps the capture as it was recorded, with the author's red highlights on the fields that matter. The heading numbers follow the step numbers of the table above.
Step 1 - MIB
MIB-NB is the only message a UE can read before it knows anything else about the cell. The red lines are the two fields the next steps depend on. The field schedulingInfoSIB1-r13 is 0, which the decoder expands to 4 NPDSCH repetitions and a TBS of 208 bits, and operationModeInfo-r13 is standalone.
Decoded message,
BCCH-BCH-Message-NB
message
systemFrameNumber-MSB-r13: 00 [bit length 4, 4 LSB pad bits, 0000 .... decimal value 0]
hyperSFN-LSB-r13: 00 [bit length 2, 6 LSB pad bits, 00.. .... decimal value 0]
schedulingInfoSIB1-r13: 4 NPDSCH repetitions - TBS 208 bits (0)
systemInfoValueTag-r13: 0
.... ...0 ab-Enabled-r13: False
operationModeInfo-r13: standalone-r13 (3)
standalone-r13
spare: 00 [bit length 5, 3 LSB pad bits, 0000 0... decimal value 0]
spare: 0000 [bit length 11, 5 LSB pad bits, 0000 0000 000. .... decimal value 0]
HEX : 00 00 C0 00 00
schedulingInfoSIB1-r13 = 0 : 4 repetitions and 208 bits, from 36.213 Tables 16.4.1.3-3 and 16.4.1.5.2-1.operationModeInfo-r13 = standalone : the carrier is not inside an LTE carrier.
Step 2 - SIB1
SIB1-NB tells the UE how to find the other SI messages, and the red lines are those scheduling fields. The capture lists one SI message carrying SIB3-NB, with si-Periodicity rf64, si-RepetitionPattern every4thRF and si-TB b256, inside an SI-window of 160 ms.
Decoded message,
systemInformationBlockType1-r13
hyperSFN-MSB-r13: 00 [bit length 8, 0000 0000 decimal value 0]
cellAccessRelatedInfo-r13
plmn-IdentityList-r13: 1 item
Item 0
PLMN-IdentityInfo-NB-r13
plmn-Identity-r13
mcc: 3 items
Item 0
MCC-MNC-Digit: 0
Item 1
MCC-MNC-Digit: 0
Item 2
MCC-MNC-Digit: 1
mnc: 2 items
Item 0
MCC-MNC-Digit: 0
Item 1
MCC-MNC-Digit: 1
cellReservedForOperatorUse-r13: notReserved (1)
attachWithoutPDN-Connectivity-r13: true (0)
trackingAreaCode-r13: 0001
cellIdentity-r13: 00000010
cellBarred-r13: notBarred (1)
intraFreqReselection-r13: allowed (0)
cellSelectionInfo-r13
q-RxLevMin-r13: -140dBm (-70)
q-QualMin-r13: -34dB
p-Max-r13: -30dBm
freqBandIndicator-r13: 2
eutraControlRegionSize-r13: n2 (1)
nrs-CRS-PowerOffset-r13: dB6 (12)
schedulingInfoList-r13: 1 item
Item 0
SchedulingInfo-NB-r13
si-Periodicity-r13: rf64 (0)
si-RepetitionPattern-r13: every4thRF (1)
sib-MappingInfo-r13: 1 item
Item 0
SIB-Type-NB-r13: sibType3-NB-r13 (0)
si-TB-r13: b256 (3)
si-WindowLength-r13: ms160 (0)
HEX : 63 00 01 80 08 06 00 02 00 00 00 30 00 00 05 C0 10 86 00
The capture also carries eutraControlRegionSize-r13 and nrs-CRS-PowerOffset-r13, which are defined only for in-band operation. The MIB-NB above reports standalone mode, so the two messages do not describe the same cell configuration. The SIB Scheduling page explains these fields.
Step 3 - SIB2 and others
SIB2-NB carries everything the UE needs for random access, and the red lines are the random access part. The NPRACH resource uses a 66.7 µs cyclic prefix, a 640 ms period, an 8 ms start time and 12 subcarriers from subcarrier 12. SIB3-NB follows at the end of the capture.
Decoded message,
sib2-r13
radioResourceConfigCommon-r13
rach-ConfigCommon-r13
preambleTransMax-CE-r13: n20 (7)
powerRampingParameters-r13
powerRampingStep: dB4 (2)
preambleInitialReceivedTargetPower: dBm-92 (14)
rach-InfoList-r13: 1 item
Item 0
RACH-Info-NB-r13
ra-ResponseWindowSize-r13: pp10 (7)
mac-ContentionResolutionTimer-r13: pp8 (4)
bcch-Config-r13
modificationPeriodCoeff-r13: n16 (0)
pcch-Config-r13
defaultPagingCycle-r13: rf128 (0)
nB-r13: fourT (0)
npdcch-NumRepetitionPaging-r13: r1 (0)
nprach-Config-r13
nprach-CP-Length-r13: us66dot7 (0)
nprach-ParametersList-r13: 1 item
Item 0
NPRACH-Parameters-NB-r13
nprach-Periodicity-r13: ms640 (5)
nprach-StartTime-r13: ms8 (0)
nprach-SubcarrierOffset-r13: n12 (1)
nprach-NumSubcarriers-r13: n12 (0)
nprach-SubcarrierMSG3-RangeStart-r13: one (3)
maxNumPreambleAttemptCE-r13: n10 (6)
numRepetitionsPerPreambleAttempt-r13: n1 (0)
npdcch-NumRepetitions-RA-r13: r16 (4)
npdcch-StartSF-CSS-RA-r13: v4 (2)
npdcch-Offset-RA-r13: zero (0)
npdsch-ConfigCommon-r13
nrs-Power-r13: 1dBm
npusch-ConfigCommon-r13
ack-NACK-NumRepetitions-Msg4-r13: 1 item
Item 0
ACK-NACK-NumRepetitions-NB-r13: r1 (0)
dmrs-Config-r13
threeTone-BaseSequence-r13: 0
threeTone-CyclicShift-r13: 0
sixTone-CyclicShift-r13: 0
ul-ReferenceSignalsNPUSCH-r13
.... 0... groupHoppingEnabled-r13: False
groupAssignmentNPUSCH-r13: 0
uplinkPowerControlCommon-r13
p0-NominalNPUSCH-r13: -92dBm
alpha-r13: al1 (7)
deltaPreambleMsg3-r13: -2dB (-1)
ue-TimersAndConstants-r13
t300-r13: ms2500 (0)
t301-r13: ms2500 (0)
t310-r13: ms0 (0)
n310-r13: n1 (0)
t311-r13: ms1000 (0)
n311-r13: n1 (0)
freqInfo-r13
additionalSpectrumEmission-r13: 1
timeAlignmentTimerCommon-r13: infinity (7)
sib-TypeAndInfo-r13 item: sib3-r13 (1)
sib3-r13
cellReselectionInfoCommon-r13
q-Hyst-r13: dB0 (0)
cellReselectionServingFreqInfo-r13
s-NonIntraSearch-r13: 0dB (0)
intraFreqCellReselectionInfo-r13
q-RxLevMin-r13: -140dBm (-70)
s-IntraSearchP-r13: 0dB (0)
t-Reselection-r13: s6 (2)
HEX : 00 40 03 DC 78 00 01 41 3C 11 0F 50 40 00 08 B8 00 00 00 71 00 00 00 10
nprach-CP-Length-r13 = us66dot7 : preamble format 0.mac-ContentionResolutionTimer-r13 = pp8 : the timer that step 8 of the table starts.ack-NACK-NumRepetitions-Msg4-r13 = r1 : the HARQ ACK for Msg4 in step 11 is sent once.npdcch-NumRepetitions-RA-r13 = r16 : the NPDCCH for the RAR and Msg4 in steps 5 and 9 uses up to 16 repetitions.
Step 7 - RRC Connection Request
The RRC Connection Request is Msg3, sent on SRB0 with the UL grant from the RAR. The UE identifies itself with a 40-bit random value, gives mo-Signalling as the establishment cause, and sets multiToneSupport-r13 to true.
Decoded message,
rrcConnectionRequest-r13
ue-Identity-r13: randomValue (1)
randomValue: 59aa46959a
establishmentCause-r13: mo-Signalling (1)
multiToneSupport-r13: true (0)
spare: 000000
HEX : 2A B3 54 8D 2B 34 40 00 00
Step 10 - Contention Resolution + RRC Connection Setup
Msg4 carries the contention resolution and the RRC Connection Setup together, and the UE stops mac-ContentionResolutionTimer when it decodes it. The red lines are the dedicated NPDCCH and NPUSCH settings the UE uses from now on.
Decoded message,
rrcConnectionSetup-r13
radioResourceConfigDedicated-r13
srb-ToAddModList-r13: 1 item
Item 0
SRB-ToAddMod-NB-r13
rlc-Config-r13: defaultValue (1)
defaultValue: NULL
logicalChannelConfig-r13: defaultValue (1)
defaultValue: NULL
mac-MainConfig-r13: explicitValue-r13 (0)
explicitValue-r13
ul-SCH-Config-r13
periodicBSR-Timer-r13: pp8 (2)
retxBSR-Timer-r13: infinity (6)
drx-Config-r13: release (0)
release: NULL
timeAlignmentTimerDedicated-r13: infinity (7)
logicalChannelSR-Config-r13: setup (1)
setup
logicalChannelSR-ProhibitTimer-r13: pp2048 (6)
physicalConfigDedicated-r13
npdcch-ConfigDedicated-r13
npdcch-NumRepetitions-r13: r16 (4)
npdcch-StartSF-USS-r13: v4 (2)
npdcch-Offset-USS-r13: zero (0)
npusch-ConfigDedicated-r13
ack-NACK-NumRepetitions-r13: r8 (3)
.... ..1. npusch-AllSymbols-r13: True
uplinkPowerControlDedicated-r13
p0-UE-NPUSCH-r13: 0dB
HEX : 30 13 3C F5 9F 8E 88 CF 00
npdcch-NumRepetitions-r13 = r16 : the UE-specific search space Rmax is 16.ack-NACK-NumRepetitions-r13 = r8 : each HARQ ACK on NPUSCH format 2 is repeated 8 times.srb-ToAddModList-r13 has one item : SRB1 with default configuration. 36.331 clause 5.3.1 establishes SRB1bis implicitly with it.
Step 14 - RRC Connection Setup Complete + Attach Requeset + PDN Conn Request
The RRC Connection Setup Complete carries the Attach Request and the PDN Connectivity Request in dedicatedInfoNAS. The red lines in UE network capability show that this UE supports only the Control Plane CIoT EPS optimisation, and the later red lines request extended DRX.
Decoded message,
rrcConnectionSetupComplete-r13
selectedPLMN-Identity-r13: 1
registeredMME-r13
mmegi: 8001 [bit length 16, 1000 0000 0000 0001 decimal value 32769]
mmec: 01 [bit length 8, 0000 0001 decimal value 1]
dedicatedInfoNAS-r13: 1730bb646f020741020bf600f1108001010000000107f070...
Non-Access-Stratum (NAS)PDU
0001 .... = Security header type: Integrity protected (1)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
Message authentication code: 0x30bb646f
Sequence number: 2
0000 .... = Security header type: Plain NAS message, not security protected (0)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
NAS EPS Mobility Management Message Type: Attach request (0x41)
0... .... = Type of security context flag (TSC): Native security context (for KSIasme)
.000 .... = NAS key set identifier: (0)
.... 0... = Spare bit(s): 0x00
.... .010 = EPS attach type: Combined EPS/IMSI attach (2)
EPS mobile identity
Length: 11
.... 0... = Odd/even indication: Even number of identity digits
.... .110 = Type of identity: GUTI (6)
Mobile Country Code (MCC): Unknown (1)
Mobile Network Code (MNC): Unknown (01)
MME Group ID: 32769
MME Code: 1
M-TMSI: 0x00000001
UE network capability
Length: 7
1... .... = EEA0: Supported
.1.. .... = 128-EEA1: Supported
..1. .... = 128-EEA2: Supported
...1 .... = 128-EEA3: Supported
.... 0... = EEA4: Not supported
.... .0.. = EEA5: Not supported
.... ..0. = EEA6: Not supported
.... ...0 = EEA7: Not supported
0... .... = EIA0: Not supported
.1.. .... = 128-EIA1: Supported
..1. .... = 128-EIA2: Supported
...1 .... = 128-EIA3: Supported
.... 0... = EIA4: Not supported
.... .0.. = EIA5: Not supported
.... ..0. = EIA6: Not supported
.... ...0 = EIA7: Not supported
0... .... = UEA0: Not supported
.0.. .... = UEA1: Not supported
..0. .... = UEA2: Not supported
...0 .... = UEA3: Not supported
.... 0... = UEA4: Not supported
.... .0.. = UEA5: Not supported
.... ..0. = UEA6: Not supported
.... ...0 = UEA7: Not supported
0... .... = UCS2 support (UCS2): The UE has a preference for the default alphabet
.0.. .... = UMTS integrity algorithm UIA1: Not supported
..0. .... = UMTS integrity algorithm UIA2: Not supported
...0 .... = UMTS integrity algorithm UIA3: Not supported
.... 0... = UMTS integrity algorithm UIA4: Not supported
.... .0.. = UMTS integrity algorithm UIA5: Not supported
.... ..0. = UMTS integrity algorithm UIA6: Not supported
.... ...0 = UMTS integrity algorithm UIA7: Not supported
0... .... = ProSe direct discovery: Not supported
.0.. .... = ProSe: Not supported
..0. .... = H.245 After SRVCC Handover: Not supported
...1 .... = Access class control for CSFB: Supported
.... 0... = LTE Positioning Protocol: Not supported
.... .0.. = Location services (LCS) notification mechanisms: Not supported
.... ..0. = SRVCC from E-UTRAN to cdma2000 1xCS: Not supported
.... ...0 = Notification procedure: Not supported
1... .... = Extended protocol configuration options: Supported
.0.. .... = Header compression for control plane CIoT EPS optimization:
Not supported
..0. .... = EMM-REGISTERED w/o PDN connectivity: Not supported
...0 .... = S1-U data transfer: Not supported
.... 0... = User plane CIoT EPS optimization: Not supported
.... .1.. = Control plane CIoT EPS optimization: Supported
.... ..0. = ProSe UE-to-network relay: Not supported
.... ...0 = ProSe direct communication: Not supported
0000 000. = Spare bit(s): 0x00
.... ...1 = Multiple DRB: Supported
ESM message container
Length: 48
ESM message container contents: 021bd03127268080211001000010810...
0000 .... = EPS bearer identity: No EPS bearer identity assigned (0)
.... 0010 = Protocol discriminator: EPS session management messages (0x2)
Procedure transaction identity: 27
NAS EPS session management messages: PDN connectivity request (0xd0)
0011 .... = PDN type: IPv4v6 (3)
.... 0001 = Request type: Initial request (1)
Protocol Configuration Options
Element ID: 0x27
Length: 38
[Link direction: MS to network (0)]
1... .... = Extension: True
.... .000 = Configuration Protocol:
PPP for use with IP PDP type or IP PDN type (0)
Protocol or Container ID: Internet Protocol Control Protocol (0x8021)
Length: 0x10 (16)
PPP IP Control Protocol
Code: Configuration Request (1)
Identifier: 0 (0x00)
Length: 16
Options: (12 bytes), Primary DNS Server IP Address,
Secondary DNS Server IP Address
Primary DNS Server IP Address
Type: Primary DNS Server IP Address (129)
Length: 6
Primary DNS Address: 0.0.0.0
Secondary DNS Server IP Address
Type: Secondary DNS Server IP Address (131)
Length: 6
Secondary DNS Address: 0.0.0.0
Protocol or Container ID: DNS Server IPv4 Address Request (0x000d)
Length: 0x00 (0)
Protocol or Container ID: DNS Server IPv6 Address Request (0x0003)
Length: 0x00 (0)
Protocol or Container ID: IP address allocation via NAS signalling(0x000a)
Length: 0x00 (0)
Protocol or Container ID: MS Support of Network Requested Bearer
Control indicator (0x0005)
Length: 0x00 (0)
Protocol or Container ID: IPv4 Link MTU Request (0x0010)
Length: 0x00 (0)
Protocol or Container ID: MS support of Local address
in TFT indicator (0x0011)
Length: 0x00 (0)
Extended protocol configuration options
Element ID: 0x7b
Length: 1
[Link direction: MS to network (0)]
0... .... = Extension: False
.... .001 = Configuration Protocol: PPP for use with IP PDP type or
IP PDN type (1)
Tracking area identity - Last visited registered TAI
Element ID: 0x52
Mobile Country Code (MCC): Unknown (1)
Mobile Network Code (MNC): Unknown (01)
Tracking area code(TAC): 1
Location area identification - Old location area identification
Element ID: 0x13
Location Area Identification (LAI) - 001/01/1
Mobile Country Code (MCC): Unknown (1)
Mobile Network Code (MNC): Unknown (01)
Location Area Code (LAC): 0x0001 (1)
Mobile station classmark 2
Element ID: 0x11
Length: 3
0... .... = Spare: 0
.10. .... = Revision Level: Used by mobile stations supporting R99 or
later versions of the protocol (2)
...0 .... = ES IND: Controlled Early Classmark Sending option is not implemented
in the MS
.... 1... = A5/1 algorithm supported: encryption algorithm A5/1 not available
.... .111 = RF Power Capability: RF Power capability is irrelevant
in this information element (7)
0... .... = Spare: 0
.0.. .... = PS capability (pseudo-synchronization capability):
PS capability not present
..01 .... = SS Screening Indicator: Capability of handling of ellipsis notation
and phase 2 error handling (1)
.... 1... = SM capability (MT SMS pt to pt capability): Mobile station supports
mobile terminated point to point SMS
.... .0.. = VBS notification reception: no VBS capability or
no notifications wanted
.... ..0. = VGCS notification reception: no VGCS capability or
no notifications wanted
.... ...0 = FC Frequency Capability: The MS does not support the E-GSM or
R-GSM band
1... .... = CM3: The MS supports options that are indicated in classmark 3 IE
.0.. .... = Spare: 0
..1. .... = LCS VA capability (LCS value added location request
notification capability): LCS value added location request
notification capability supported
...0 .... = UCS2 treatment: the ME has a preference for the default alphabet
.... 0... = SoLSA: The ME does not support SoLSA
.... .1.. = CMSP: CM Service Prompt: Network initiated MO CM connection request
supported for at least one CM protocol
.... ..1. = A5/3 algorithm supported: encryption algorithm A5/3 available
.... ...0 = A5/2 algorithm supported: encryption algorithm A5/2 not available
Additional update type
1111 .... = Element ID: 0xf-
.... 01.. = Preferred CIoT network behaviour:
Control-plane CIoT EPS optimization (1)
.... ..0. = SAF: Keeping the NAS signalling connection is not required after
the completion of the tracking area updating procedure
.... ...0 = AUTV: No additional information (shall be interpreted as request for
combined attach or combined tracking area updating)
GUTI type - Old GUTI type
1110 .... = Element ID: 0xe-
.... 000. = Spare bit(s): 0x00
.... ...0 = GUTI type: Native GUTI
MS network feature support
1100 .... = Element ID: 0xc-
.... 000. = Spare bit(s): 0
.... ...1 = Extended periodic timers: MS supports the extended periodic timer
in this domain
Network Resource Identifier Container - TMSI based NRI container
Element ID: 0x10
Length: 2
0000 0000 00.. .... = NRI container value: 0x000
..00 0000 = Spare bit(s): 0
Extended DRX Parameters
Element ID: 0x6e
Length: 1
0100 .... = Paging Time Window: Iu: 4 s / WB-S1: 6.4 s / NB-S1: 12.8 s (0x4)
.... 1101 = eDRX value: GERAN: 1.88 s / UTRAN: 10.24 s / E-UTRAN: 2621.44 s (0xd)
HEX : 10 40 20 00 40 5A 85 CC 2E D9 1B C0 81 D0 40 82 FD 80 3C 44 20 00 40 40 00 00 00 41 FC 1C 00 00 04 21 00 40 0C 00 86 F4 0C 49 C9 A0 20 08 44 00 40 00 04 20 41 80 00 00 00 20 C1 80 00 00 00 00 03 40 00 00 C0 00 02 80 00 01 40 00 04 00 00 04 40 1E C0 00 40 54 80 3C 44 00 00 44 C0 3C 44 00 00 44 40 D3 C6 29 BD 38 30 44 00 80 00 1B 80 53 40
The capability matters for the rest of the sequence. A UE that supports only the Control Plane CIoT EPS optimisation establishes SRB1bis alone, as the SRB mapping page explains. That is why the table shows no RRC Security Mode Command: the only security procedure in this attach is the NAS one.
Step 18 - Authentication Request
From here until the attach completes, every NAS message travels inside DLInformationTransfer-NB or ULInformationTransfer-NB. The Authentication Request is the first of them, and it is a plain NAS message, because no NAS security context exists yet.
Decoded message,
dlInformationTransfer-r13
dedicatedInfoNAS-r13: 0752000123456789abcdef0123456789abcdef1054cdfeab...
Non-Access-Stratum (NAS)PDU
0000 .... = Security header type: Plain NAS message, not security protected (0)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
NAS EPS Mobility Management Message Type: Authentication request (0x52)
0000 .... = Spare half octet: 0
.... 0... = Type of security context flag (TSC): Native security context (for KSIasme)
.... .000 = NAS key set identifier: (0) ASME
Authentication Parameter RAND - EPS challenge
RAND value: 0123456789abcdef0123456789abcdef
Authentication Parameter AUTN (UMTS and EPS authentication challenge) - EPS challenge
Length: 16
AUTN value: 54cdfeab9889800001326754cdfe2b98
SQN xor AK: 54cdfeab9889
AMF: 8000
MAC: 01326754cdfe2b98
HEX : 00 09 01 D4 80 00 48 D1 59 E2 6A F3 7B C0 48 D1 59 E2 6A F3 7B C4 15 33 7F AA E6 22 60 00 00 4C 99 D5 33 7F 8A E6 00
Step 23 - Authentication Response
The UE answers the challenge with the Authentication Response inside ULInformationTransfer-NB. The table above shows the cost of this small exchange on NB-IoT: RLC ACKs, HARQ ACKs and separate grants surround every NAS message.
Decoded message,
ulInformationTransfer-r13
dedicatedInfoNAS-r13: 17f9cb55fe0307531001326754cdfeab9889baefdc457623...
Non-Access-Stratum (NAS)PDU
0001 .... = Security header type: Integrity protected (1)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
Message authentication code: 0xf9cb55fe
Sequence number: 3
0000 .... = Security header type: Plain NAS message, not security protected (0)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
NAS EPS Mobility Management Message Type: Authentication response (0x53)
Authentication response parameter
Length: 16
RES: 01326754cdfeab9889baefdc45762310
HEX : 30 19 17 F9 CB 55 FE 03 07 53 10 01 32 67 54 CD FE AB 98 89 BA EF DC 45 76 23 10
Step 27 - NAS Security Mode Command
The NAS Security Mode Command selects the NAS algorithms and starts the new EPS security context. In this capture the MME selects EEA0, the null ciphering algorithm, and 128-EIA1 for integrity protection.
Decoded message,
dlInformationTransfer-r13
dedicatedInfoNAS-r13: 37205a892300075d010002f070c1
Non-Access-Stratum (NAS)PDU
0011 .... = Security header type: Integrity protected with new EPS security context (3)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
Message authentication code: 0x205a8923
Sequence number: 0
0000 .... = Security header type: Plain NAS message, not security protected (0)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
NAS EPS Mobility Management Message Type: Security mode command (0x5d)
NAS security algorithms - Selected NAS security algorithms
0... .... = Spare bit(s): 0x00
.000 .... = Type of ciphering algorithm: EPS encryption algorithm EEA0
(null ciphering algorithm) (0)
.... 0... = Spare bit(s): 0x00
.... .001 = Type of integrity protection algorithm:
EPS integrity algorithm 128-EIA1 (1)
0000 .... = Spare half octet: 0
.... 0... = Type of security context flag (TSC): Native security context (for KSIasme)
.... .000 = NAS key set identifier: (0) ASME
UE security capability - Replayed UE security capabilities
Length: 2
1... .... = EEA0: Supported
.1.. .... = 128-EEA1: Supported
..1. .... = 128-EEA2: Supported
...1 .... = 128-EEA3: Supported
.... 0... = EEA4: Not supported
.... .0.. = EEA5: Not supported
.... ..0. = EEA6: Not supported
.... ...0 = EEA7: Not supported
0... .... = EIA0: Not supported
.1.. .... = 128-EIA1: Supported
..1. .... = 128-EIA2: Supported
...1 .... = 128-EIA3: Supported
.... 0... = EIA4: Not supported
.... .0.. = EIA5: Not supported
.... ..0. = EIA6: Not supported
.... ...0 = EIA7: Not supported
IMEISV request
1100 .... = Element ID: 0xc-
.... 0... = Spare bit(s): 0x00
.... .001 = IMEISV request: IMEISV requested (1)
HEX : 00 03 8D C8 16 A2 48 C0 01 D7 40 40 00 BC 1C 30 40
This is NAS security between the UE and the MME, not AS security between the UE and the eNB. The RRC messages around it stay on SRB1bis, and only the NAS payload inside them is protected.
Step 32 - NAS Security Mode Complete
The NAS Security Mode Complete is the first message protected under the new context. Its outer security header type says integrity protected and ciphered with new EPS security context, even though the selected ciphering algorithm is EEA0.
Decoded message,
ulInformationTransfer-r13
dedicatedInfoNAS-r13: 47f678b4ff00075e23090310200790999909f0
Non-Access-Stratum (NAS)PDU
0100 .... = Security header type: Integrity protected and ciphered with
new EPS security context (4)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
Message authentication code: 0xf678b4ff
Sequence number: 0
0000 .... = Security header type: Plain NAS message, not security protected (0)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
NAS EPS Mobility Management Message Type: Security mode complete (0x5e)
Mobile identity - IMEISV - IMEISV (0010270099999900)
Element ID: 0x23
Length: 9
0000 .... = Identity Digit 1: 0
.... 0... = Odd/even indication: Even number of identity digits
.... .011 = Mobile Identity Type: IMEISV (3)
BCD Digits: 0010270099999900
1111 .... = Filler: 0xf
HEX : 30 13 47 F6 78 B4 FF 00 07 5E 23 09 03 10 20 07 90 99 99 09 F0
Step 36 - Attach Accept + Activate Default EPS Bearer Context Request
The Attach Accept carries the Activate Default EPS Bearer Context Request, and together they finish the attach. The capture assigns EPS bearer identity 5, the APN www.sharetechnote.com and the IPv4 address 192.168.20.11.
Decoded message,
dlInformationTransfer-r13
dedicatedInfoNAS-r13: 27fb54f05e02074202e0060000f1100001003d5201c10109...
Non-Access-Stratum (NAS)PDU
0010 .... = Security header type: Integrity protected and ciphered (2)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
Message authentication code: 0xfb54f05e
Sequence number: 2
0000 .... = Security header type: Plain NAS message, not security protected (0)
.... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
NAS EPS Mobility Management Message Type: Attach accept (0x42)
0000 .... = Spare half octet: 0
.... 0... = Spare bit(s): 0x00
.... .010 = Attach result: Combined EPS/IMSI attach (2)
GPRS Timer - T3412 value
GPRS Timer: timer is deactivated
111. .... = Unit: value indicates that the timer is deactivated (7)
...0 0000 = Timer value: 0
Tracking area identity list - TAI list
Length: 6
0... .... = Spare bit(s): 0x00
.00. .... = Type of list: list of TACs belonging to one PLMN,
with non-consecutive TAC values (0)
...0 0000 = Number of elements: 0 [+1 = 1 element(s)]
Mobile Country Code (MCC): Unknown (1)
Mobile Network Code (MNC): Unknown (01)
Tracking area code(TAC): 1
ESM message container
Length: 61
ESM message container contents: 5201c10109100377777707616e72...
0101 .... = EPS bearer identity: EPS bearer identity value 5 (5)
.... 0010 = Protocol discriminator: EPS session management messages (0x2)
Procedure transaction identity: 1
NAS EPS session management messages:
Activate default EPS bearer context request (0xc1)
EPS quality of service
Length: 1
Quality of Service Class Identifier (QCI): QCI 9 (9)
Access Point Name
Length: 22
APN: www.sharetechnote.com
PDN address
Length: 13
0000 0... = Spare bit(s): 0x00
PDN type: IPv4v6 (3)
PDN IPv6 if id: 0000000000000001
PDN IPv4: 192.168.20.11
Linked TI - Transaction identifier
Element ID: 0x5d
Length: 1
1... .... = TI Flag:The message is sent to the side that originates the TI
TI value: 0x00 (0)
Quality Of Service - Negotiated QoS
Element ID: 0x30
Length: 14
00.. .... = Spare bit(s): 0
..10 0... = Quality of Service Delay class: Delay class 4(best effort)(4)
.... .011 = Reliability class: Unacknowledged GTP/LLC, Ack RLC,
Protected data (3)
1001 .... = Peak throughput: Up to 256 000 octet/s (9)
.... 0... = Spare bit(s): 0
.... .010 = Precedence class: Normal priority (2)
000. .... = Spare bit(s): 0
...0 1010 = Mean throughput: 100 000 octet/h (10)
100. .... = Traffic class: Background class (4)
...1 0... = Delivery order: Without delivery order ('no') (2)
.... .011 = Delivery of erroneous SDUs:
Erroneous SDUs are not delivered('No') (3)
Maximum SDU size: 1500 octets (150)
Maximum bitrate for uplink: 64 kbps (64)
Maximum bitrate for downlink: 384 kbps (104)
0111 .... = Residual Bit Error Rate (BER): 1*10-5 (7)
.... 0100 = SDU error ratio: 1*10-4 (4)
0000 00.. = Transfer delay: Subscribed transfer delay/reserved (0)
.... ..00 = Traffic handling priority:
Subscribed traffic handling priority/Reserved (0)
Guaranteed bitrate for uplink: 64 kbps (64)
Guaranteed bitrate for downlink: 568 kbps (127)
000. .... = Spare bit(s): 0
...0 .... = Signalling indication: Not optimised for signalling traffic
.... 0000 = Source statistics description: unknown (0)
Maximum bitrate for downlink (extended): Use the value indicated
by the Maximum bit rate for downlink (0)
Guaranteed bitrate for downlink (extended): Use the value indicated
by the Guaranteed bit rate for downlink (0)
LLC Service Access Point Identifier - Negotiated LLC SAPI
Element ID: 0x32
0000 .... = Spare bit(s): 0
.... 0011 = LLC SAPI: SAPI 3 (3)
Radio Priority
1000 .... = Element ID: 0x8-
.... .001 = Radio Priority (PDP or SMS): priority level 1 (highest) (1)
Protocol Configuration Options
Element ID: 0x27
Length: 1
[Link direction: Network to MS (1)]
1... .... = Extension: True
.... .000 = Configuration Protocol: PPP for use with IP PDP type
or IP PDN type (0)
EPS mobile identity - GUTI
Element ID: 0x50
Length: 11
.... 0... = Odd/even indication: Even number of identity digits
.... .110 = Type of identity: GUTI (6)
Mobile Country Code (MCC): Unknown (1)
Mobile Network Code (MNC): Unknown (01)
MME Group ID: 32769
MME Code: 1
M-TMSI: 0x00000001
Location area identification
Element ID: 0x13
Location Area Identification (LAI) - 001/01/1
Mobile Country Code (MCC): Unknown (1)
Mobile Network Code (MNC): Unknown (01)
Location Area Code (LAC): 0x0001 (1)
Mobile identity - MS identity - TMSI/P-TMSI (0x0000)
Element ID: 0x23
Length: 5
1111 .... = Unused: 0xf
.... 0... = Odd/even indication: Even number of identity digits
.... .100 = Mobile Identity Type: TMSI/P-TMSI/M-TMSI (4)
TMSI/P-TMSI: 0x00000000
EPS network feature support
Element ID: 0x64
Length: 2
1... .... = Control plane CIoT EPS optimization: Supported
.1.. .... = EMM-REGISTERED w/o PDN connectivity: Supported
..0. .... = Support of EXTENDED SERVICE REQUEST for packet services: Not supported
...0 0... = CS-LCS: no information about support of location services
via CS domain is available (0)
.... .0.. = Location services via EPC: Not supported
.... ..0. = Emergency bearer services in S1 mode: Not supported
.... ...0 = IMS voice over PS session in S1 mode: Not supported
0000 .... = Spare bit(s): 0x00
.... 0... = Extended protocol configuration options IE: Not supported
.... .0.. = Header compression for control plane CIoT EPS optimization:
Not supported
.... ..1. = S1-u data transfer: Supported
.... ...0 = User plane CIoT EPS optimization: Not supported
HEX : 00 1B 89 FE D5 3C 17 80 81 D0 80 B8 01 80 00 3C 44 00 00 40 0F 54 80 70 40 42 44 00 DD DD DD C1 D8 5B 9C 9A 5D 1C DD 40 D8 DB DB 43 40 C0 00 00 00 00 00 00 00 70 2A 05 02 D7 40 60 0C 03 88 E4 82 A4 E5 90 1A 1D 00 10 1F C0 00 00 0C 80 E0 49 C0 60 14 02 FD 80 3C 44 20 00 40 40 00 00 00 44 C0 3C 44 00 00 48 C1 7D 00 00 00 00 19 00 B0 00 80
The red lines are EPS network feature support. The network confirms Control plane CIoT EPS optimization as supported and User plane CIoT EPS optimization as not supported, which matches the UE capability in the RRC Connection Setup Complete. So the data of this UE will travel over the control plane, inside NAS messages.
Reference
[2] 3GPP TS 36.331 v19.3.0 - clause 5.3.1 for SRB1bis, clause 6.7 for NB-IoT RRC messages
[3] 3GPP TS 36.321 v19.3.0 - clause 5.1.5 for contention resolution
[4] 3GPP TS 24.301 - EPS NAS messages and the CIoT EPS optimisations