4G/LTE - LTE NB

 

 

 

Full Stack Protocol Sequence

 

This page follows one NB-IoT UE from power-on to a completed attach, using messages captured from a test system. The table lists every step, including the NPDCCH grants, HARQ ACKs and RLC ACKs between the messages, and the sections after it show the decoded content of the main messages.

Followings are the topics to be covered in this page.

Protocol Sequence Overview

The attach itself needs only a handful of RRC and NAS messages, but the table below has 41 steps. Most of the extra steps are the lower-layer traffic that NB-IoT puts around each message. SS in the table is the system simulator that plays the eNB and the core network.

Step

Direction

Message

Comments

1

UE <--- SS

MIB

 

2

UE <--- SS

SIB1

 

3

UE <--- SS

SIB2,3 and others

 

4

UE ---> SS

PRACH (RACH Preamble)

 

5

UE <--- SS

NPDCCH(DCI N1)

Resource Decoding information for RAR message

6

UE <--- SS

RACH Response

 

7

UE ---> SS

RRC Connection Request  

 

8

< UE >

UE MAC start mac-ContentionResolutionTimer

3GPP 36.321 5.1.5

CR Timer value is set in SIB2

9

UE <--- SS

NPDCCH(DCI N1)

Resource Decoding information for CR

10

UE <--- SS

Contention Resolution + RRC Connection Setup

 

11

UE ---> SS

HARQ ACK (NPUSCH format2)

HARQ ACK for CR Reception

12

< UE >

UE MAC stop mac-ContentionResolutionTimer

 

13

UE <--- SS

UL Grant (DCI N0, NPDCCH)

Grant for transmitting 'RRC Connection Setup Complete'

14

UE ---> SS

RRC Connection Setup Complete

+ Attach Requeset

+ PDN Conn Request

 

15

UE <--- SS

DCI N1(NPDCCH)

Resource Decoding information for RLC ACK

16

UE <--- SS

RLC ACK

 

17

UE <--- SS

DCI N1(NPDCCH)

Resource Decoding information for Athentication Request

18

UE <--- SS

Authentication Request

 

19

UE ---> SS

HARQ ACK (NPUSCH format2)

 

20

UE <--- SS

UL Grant (DCI N0, NPDCCH)

Grant to send RLC ACK

21

UE ---> SS

RLC ACK

 

22

UE <--- SS

UL Grant (DCI N0, NPDCCH)

 

23

UE ---> SS

Authentication Response

 

24

UE <--- SS

DCI N1(NPDCCH)

Resource Decoding information for RLC ACK

25

UE <--- SS

RLC ACK

 

26

UE <--- SS

DCI N1(NPDCCH)

Resource Decoding information for NAS Security Mode Command

27

UE <--- SS

NAS Security Mode Command

 

28

UE ---> SS

HARQ ACK (NPUSCH format2)

 

29

UE <--- SS

UL Grant (DCI N0, NPDCCH)

Grant to send RLC ACK

30

UE ---> SS

RLC ACK

 

31

UE <--- SS

UL Grant (DCI N0, NPDCCH)

Grant to send NAS Security Mode Complete

32

UE ---> SS

NAS Security Mode  Complete  

 

33

UE <--- SS

DCI N1(NPDCCH)

Resource Decoding information for RLC ACK

34

UE <--- SS

RLC ACK

 

35

UE <--- SS

DCI N1(NPDCCH)

Resource Decoding information for Attach Accept

36

UE <--- SS

RRC : dlInformationTransfer

+ Attach Accept

+ Activate Default EPS Bearer Context Request

 

37

UE ---> SS

HARQ ACK (NPUSCH format2)

 

38

UE <--- SS

UL Grant (DCI N0, NPDCCH)

Grant to send RLC ACK

39

UE ---> SS

RLC ACK

 

40

UE ---> SS

RRC ulInformationTransfer

+ Attach Complete

+ Activate Default EPS Bearer Context Accept

 

41

UE <--- SS

RLC ACK

 

Look at steps 14 to 40 and a pattern repeats. Each NAS message in the downlink needs an NPDCCH with DCI N1, the NPDSCH itself and a HARQ ACK on NPUSCH format 2. An UL grant with DCI N0 for the RLC ACK then follows. With a single HARQ process, as in Release 13, these steps cannot overlap, so the latency of the attach adds up step by step.

  • Steps 1 to 3 are system information : MIB-NB, SIB1-NB and SIB2-NB, with no DCI involved.
  • Steps 4 to 12 are random access : preamble, RAR, Msg3 and Msg4 with contention resolution.
  • Steps 14 to 40 are the attach : NAS messages carried in RRC, each surrounded by grants and ACKs.
  • No RRC security appears : only the NAS Security Mode procedure protects this attach.

Message Details

The sections below show the decoded messages that the table links to. Each one keeps the capture as it was recorded, with the author's red highlights on the fields that matter. The heading numbers follow the step numbers of the table above.

Step 1 - MIB

MIB-NB is the only message a UE can read before it knows anything else about the cell. The red lines are the two fields the next steps depend on. The field schedulingInfoSIB1-r13 is 0, which the decoder expands to 4 NPDSCH repetitions and a TBS of 208 bits, and operationModeInfo-r13 is standalone.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

BCCH-BCH-Message-NB
    message
        systemFrameNumber-MSB-r13: 00 [bit length 4, 4 LSB pad bits, 0000 .... decimal value 0]
        hyperSFN-LSB-r13: 00 [bit length 2, 6 LSB pad bits, 00.. .... decimal value 0]
        schedulingInfoSIB1-r13: 4 NPDSCH repetitions - TBS 208 bits (0)
        systemInfoValueTag-r13: 0
        .... ...0 ab-Enabled-r13: False
        operationModeInfo-r13: standalone-r13 (3)
            standalone-r13
                spare: 00 [bit length 5, 3 LSB pad bits, 0000 0... decimal value 0]
        spare: 0000 [bit length 11, 5 LSB pad bits, 0000 0000  000. .... decimal value 0]

HEX : 00 00 C0 00 00
  • schedulingInfoSIB1-r13 = 0 : 4 repetitions and 208 bits, from 36.213 Tables 16.4.1.3-3 and 16.4.1.5.2-1.
  • operationModeInfo-r13 = standalone : the carrier is not inside an LTE carrier.

Step 2 - SIB1

SIB1-NB tells the UE how to find the other SI messages, and the red lines are those scheduling fields. The capture lists one SI message carrying SIB3-NB, with si-Periodicity rf64, si-RepetitionPattern every4thRF and si-TB b256, inside an SI-window of 160 ms.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

systemInformationBlockType1-r13
    hyperSFN-MSB-r13: 00 [bit length 8, 0000 0000 decimal value 0]
    cellAccessRelatedInfo-r13
        plmn-IdentityList-r13: 1 item
            Item 0
                PLMN-IdentityInfo-NB-r13
                    plmn-Identity-r13
                        mcc: 3 items
                            Item 0
                                MCC-MNC-Digit: 0
                            Item 1
                                MCC-MNC-Digit: 0
                            Item 2
                                MCC-MNC-Digit: 1
                        mnc: 2 items
                            Item 0
                                MCC-MNC-Digit: 0
                            Item 1
                                MCC-MNC-Digit: 1
                    cellReservedForOperatorUse-r13: notReserved (1)
                    attachWithoutPDN-Connectivity-r13: true (0)
        trackingAreaCode-r13: 0001
        cellIdentity-r13: 00000010
        cellBarred-r13: notBarred (1)
        intraFreqReselection-r13: allowed (0)
    cellSelectionInfo-r13
        q-RxLevMin-r13: -140dBm (-70)
        q-QualMin-r13: -34dB
    p-Max-r13: -30dBm
    freqBandIndicator-r13: 2
    eutraControlRegionSize-r13: n2 (1)
    nrs-CRS-PowerOffset-r13: dB6 (12)
    schedulingInfoList-r13: 1 item
        Item 0
            SchedulingInfo-NB-r13
                si-Periodicity-r13: rf64 (0)
                si-RepetitionPattern-r13: every4thRF (1)
                sib-MappingInfo-r13: 1 item
                    Item 0
                        SIB-Type-NB-r13: sibType3-NB-r13 (0)
                si-TB-r13: b256 (3)
     si-WindowLength-r13: ms160 (0)

HEX : 63 00 01 80 08 06 00 02 00 00 00 30 00 00 05 C0 10 86 00

The capture also carries eutraControlRegionSize-r13 and nrs-CRS-PowerOffset-r13, which are defined only for in-band operation. The MIB-NB above reports standalone mode, so the two messages do not describe the same cell configuration. The SIB Scheduling page explains these fields.

Step 3 - SIB2 and others

SIB2-NB carries everything the UE needs for random access, and the red lines are the random access part. The NPRACH resource uses a 66.7 µs cyclic prefix, a 640 ms period, an 8 ms start time and 12 subcarriers from subcarrier 12. SIB3-NB follows at the end of the capture.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

sib2-r13
    radioResourceConfigCommon-r13
        rach-ConfigCommon-r13
            preambleTransMax-CE-r13: n20 (7)
            powerRampingParameters-r13
                powerRampingStep: dB4 (2)
                preambleInitialReceivedTargetPower: dBm-92 (14)
            rach-InfoList-r13: 1 item
                Item 0
                    RACH-Info-NB-r13
                        ra-ResponseWindowSize-r13: pp10 (7)
                        mac-ContentionResolutionTimer-r13: pp8 (4)
        bcch-Config-r13
            modificationPeriodCoeff-r13: n16 (0)
        pcch-Config-r13
            defaultPagingCycle-r13: rf128 (0)
            nB-r13: fourT (0)
            npdcch-NumRepetitionPaging-r13: r1 (0)
        nprach-Config-r13
            nprach-CP-Length-r13: us66dot7 (0)
            nprach-ParametersList-r13: 1 item
                Item 0
                    NPRACH-Parameters-NB-r13
                        nprach-Periodicity-r13: ms640 (5)
                        nprach-StartTime-r13: ms8 (0)
                        nprach-SubcarrierOffset-r13: n12 (1)
                        nprach-NumSubcarriers-r13: n12 (0)
                        nprach-SubcarrierMSG3-RangeStart-r13: one (3)
                        maxNumPreambleAttemptCE-r13: n10 (6)
                        numRepetitionsPerPreambleAttempt-r13: n1 (0)
                        npdcch-NumRepetitions-RA-r13: r16 (4)
                        npdcch-StartSF-CSS-RA-r13: v4 (2)
                        npdcch-Offset-RA-r13: zero (0)
        npdsch-ConfigCommon-r13
            nrs-Power-r13: 1dBm
        npusch-ConfigCommon-r13
            ack-NACK-NumRepetitions-Msg4-r13: 1 item
                Item 0
                    ACK-NACK-NumRepetitions-NB-r13: r1 (0)
            dmrs-Config-r13
                threeTone-BaseSequence-r13: 0
                threeTone-CyclicShift-r13: 0
                sixTone-CyclicShift-r13: 0
            ul-ReferenceSignalsNPUSCH-r13
                .... 0... groupHoppingEnabled-r13: False
                groupAssignmentNPUSCH-r13: 0
        uplinkPowerControlCommon-r13
            p0-NominalNPUSCH-r13: -92dBm
            alpha-r13: al1 (7)
            deltaPreambleMsg3-r13: -2dB (-1)
    ue-TimersAndConstants-r13
        t300-r13: ms2500 (0)
        t301-r13: ms2500 (0)
        t310-r13: ms0 (0)
        n310-r13: n1 (0)
        t311-r13: ms1000 (0)
        n311-r13: n1 (0)
    freqInfo-r13
        additionalSpectrumEmission-r13: 1
    timeAlignmentTimerCommon-r13: infinity (7)
                               sib-TypeAndInfo-r13 item: sib3-r13 (1)
sib3-r13
    cellReselectionInfoCommon-r13
        q-Hyst-r13: dB0 (0)
    cellReselectionServingFreqInfo-r13
        s-NonIntraSearch-r13: 0dB (0)
    intraFreqCellReselectionInfo-r13
        q-RxLevMin-r13: -140dBm (-70)
        s-IntraSearchP-r13: 0dB (0)
        t-Reselection-r13: s6 (2)

HEX : 00 40 03 DC 78 00 01 41 3C 11 0F 50 40 00 08 B8 00 00 00 71 00 00 00 10
  • nprach-CP-Length-r13 = us66dot7 : preamble format 0.
  • mac-ContentionResolutionTimer-r13 = pp8 : the timer that step 8 of the table starts.
  • ack-NACK-NumRepetitions-Msg4-r13 = r1 : the HARQ ACK for Msg4 in step 11 is sent once.
  • npdcch-NumRepetitions-RA-r13 = r16 : the NPDCCH for the RAR and Msg4 in steps 5 and 9 uses up to 16 repetitions.

Step 7 - RRC Connection Request

The RRC Connection Request is Msg3, sent on SRB0 with the UL grant from the RAR. The UE identifies itself with a 40-bit random value, gives mo-Signalling as the establishment cause, and sets multiToneSupport-r13 to true.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

rrcConnectionRequest-r13
    ue-Identity-r13: randomValue (1)
        randomValue: 59aa46959a
    establishmentCause-r13: mo-Signalling (1)
    multiToneSupport-r13: true (0)
    spare: 000000

HEX : 2A B3 54 8D 2B 34 40 00 00

Step 10 - Contention Resolution + RRC Connection Setup

Msg4 carries the contention resolution and the RRC Connection Setup together, and the UE stops mac-ContentionResolutionTimer when it decodes it. The red lines are the dedicated NPDCCH and NPUSCH settings the UE uses from now on.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

rrcConnectionSetup-r13
    radioResourceConfigDedicated-r13
        srb-ToAddModList-r13: 1 item
            Item 0
                SRB-ToAddMod-NB-r13
                    rlc-Config-r13: defaultValue (1)
                        defaultValue: NULL
                    logicalChannelConfig-r13: defaultValue (1)
                        defaultValue: NULL
        mac-MainConfig-r13: explicitValue-r13 (0)
            explicitValue-r13
                ul-SCH-Config-r13
                    periodicBSR-Timer-r13: pp8 (2)
                    retxBSR-Timer-r13: infinity (6)
                drx-Config-r13: release (0)
                    release: NULL
                timeAlignmentTimerDedicated-r13: infinity (7)
                logicalChannelSR-Config-r13: setup (1)
                    setup
                        logicalChannelSR-ProhibitTimer-r13: pp2048 (6)
        physicalConfigDedicated-r13
            npdcch-ConfigDedicated-r13
                npdcch-NumRepetitions-r13: r16 (4)
                npdcch-StartSF-USS-r13: v4 (2)
                npdcch-Offset-USS-r13: zero (0)
            npusch-ConfigDedicated-r13
                ack-NACK-NumRepetitions-r13: r8 (3)
                .... ..1. npusch-AllSymbols-r13: True
            uplinkPowerControlDedicated-r13
                p0-UE-NPUSCH-r13: 0dB

HEX :  30 13 3C F5 9F 8E 88 CF 00
  • npdcch-NumRepetitions-r13 = r16 : the UE-specific search space Rmax is 16.
  • ack-NACK-NumRepetitions-r13 = r8 : each HARQ ACK on NPUSCH format 2 is repeated 8 times.
  • srb-ToAddModList-r13 has one item : SRB1 with default configuration. 36.331 clause 5.3.1 establishes SRB1bis implicitly with it.

Step 14 - RRC Connection Setup Complete + Attach Requeset + PDN Conn Request

The RRC Connection Setup Complete carries the Attach Request and the PDN Connectivity Request in dedicatedInfoNAS. The red lines in UE network capability show that this UE supports only the Control Plane CIoT EPS optimisation, and the later red lines request extended DRX.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

rrcConnectionSetupComplete-r13
    selectedPLMN-Identity-r13: 1
    registeredMME-r13
        mmegi: 8001 [bit length 16, 1000 0000  0000 0001 decimal value 32769]
        mmec: 01 [bit length 8, 0000 0001 decimal value 1]
    dedicatedInfoNAS-r13: 1730bb646f020741020bf600f1108001010000000107f070...
        Non-Access-Stratum (NAS)PDU
            0001 .... = Security header type: Integrity protected (1)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            Message authentication code: 0x30bb646f
            Sequence number: 2
            0000 .... = Security header type: Plain NAS message, not security protected (0)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            NAS EPS Mobility Management Message Type: Attach request (0x41)
            0... .... = Type of security context flag (TSC): Native security context (for KSIasme)
            .000 .... = NAS key set identifier:  (0)
            .... 0... = Spare bit(s): 0x00
            .... .010 = EPS attach type: Combined EPS/IMSI attach (2)
            EPS mobile identity
                Length: 11
                .... 0... = Odd/even indication: Even number of identity digits
                .... .110 = Type of identity: GUTI (6)
                Mobile Country Code (MCC): Unknown (1)
                Mobile Network Code (MNC): Unknown (01)
                MME Group ID: 32769
                MME Code: 1
                M-TMSI: 0x00000001
            UE network capability
                Length: 7
                1... .... = EEA0: Supported
                .1.. .... = 128-EEA1: Supported
                ..1. .... = 128-EEA2: Supported
                ...1 .... = 128-EEA3: Supported
                .... 0... = EEA4: Not supported
                .... .0.. = EEA5: Not supported
                .... ..0. = EEA6: Not supported
                .... ...0 = EEA7: Not supported
                0... .... = EIA0: Not supported
                .1.. .... = 128-EIA1: Supported
                ..1. .... = 128-EIA2: Supported
                ...1 .... = 128-EIA3: Supported
                .... 0... = EIA4: Not supported
                .... .0.. = EIA5: Not supported
                .... ..0. = EIA6: Not supported
                .... ...0 = EIA7: Not supported
                0... .... = UEA0: Not supported
                .0.. .... = UEA1: Not supported
                ..0. .... = UEA2: Not supported
                ...0 .... = UEA3: Not supported
                .... 0... = UEA4: Not supported
                .... .0.. = UEA5: Not supported
                .... ..0. = UEA6: Not supported
                .... ...0 = UEA7: Not supported
                0... .... = UCS2 support (UCS2): The UE has a preference for the default alphabet
                .0.. .... = UMTS integrity algorithm UIA1: Not supported
                ..0. .... = UMTS integrity algorithm UIA2: Not supported
                ...0 .... = UMTS integrity algorithm UIA3: Not supported
                .... 0... = UMTS integrity algorithm UIA4: Not supported
                .... .0.. = UMTS integrity algorithm UIA5: Not supported
                .... ..0. = UMTS integrity algorithm UIA6: Not supported
                .... ...0 = UMTS integrity algorithm UIA7: Not supported
                0... .... = ProSe direct discovery: Not supported
                .0.. .... = ProSe: Not supported
                ..0. .... = H.245 After SRVCC Handover: Not supported
                ...1 .... = Access class control for CSFB: Supported
                .... 0... = LTE Positioning Protocol: Not supported
                .... .0.. = Location services (LCS) notification mechanisms: Not supported
                .... ..0. = SRVCC from E-UTRAN to cdma2000 1xCS: Not supported
                .... ...0 = Notification procedure: Not supported
                1... .... = Extended protocol configuration options: Supported
                .0.. .... = Header compression for control plane CIoT EPS optimization: 
                            Not supported
                ..0. .... = EMM-REGISTERED w/o PDN connectivity: Not supported
                ...0 .... = S1-U data transfer: Not supported
                .... 0... = User plane CIoT EPS optimization: Not supported
                .... .1.. = Control plane CIoT EPS optimization: Supported
                .... ..0. = ProSe UE-to-network relay: Not supported
                .... ...0 = ProSe direct communication: Not supported
                0000 000. = Spare bit(s): 0x00
                .... ...1 = Multiple DRB: Supported
            ESM message container
                Length: 48
                ESM message container contents: 021bd03127268080211001000010810...
                    0000 .... = EPS bearer identity: No EPS bearer identity assigned (0)
                    .... 0010 = Protocol discriminator: EPS session management messages (0x2)
                    Procedure transaction identity: 27
                    NAS EPS session management messages: PDN connectivity request (0xd0)
                    0011 .... = PDN type: IPv4v6 (3)
                    .... 0001 = Request type: Initial request (1)
                    Protocol Configuration Options
                        Element ID: 0x27
                        Length: 38
                        [Link direction: MS to network (0)]
                        1... .... = Extension: True
                        .... .000 = Configuration Protocol:
                                       PPP for use with IP PDP type or IP PDN type (0)
                        Protocol or Container ID: Internet Protocol Control Protocol (0x8021)
                            Length: 0x10 (16)
                            PPP IP Control Protocol
                                Code: Configuration Request (1)
                                Identifier: 0 (0x00)
                                Length: 16
                                Options: (12 bytes), Primary DNS Server IP Address,
                                                     Secondary DNS Server IP Address
                                    Primary DNS Server IP Address
                                        Type: Primary DNS Server IP Address (129)
                                        Length: 6
                                        Primary DNS Address: 0.0.0.0
                                    Secondary DNS Server IP Address
                                        Type: Secondary DNS Server IP Address (131)
                                        Length: 6
                                        Secondary DNS Address: 0.0.0.0
                        Protocol or Container ID: DNS Server IPv4 Address Request (0x000d)
                            Length: 0x00 (0)
                        Protocol or Container ID: DNS Server IPv6 Address Request (0x0003)
                            Length: 0x00 (0)
                        Protocol or Container ID: IP address allocation via NAS signalling(0x000a)
                            Length: 0x00 (0)
                        Protocol or Container ID: MS Support of Network Requested Bearer
                                                  Control indicator (0x0005)
                            Length: 0x00 (0)
                        Protocol or Container ID: IPv4 Link MTU Request (0x0010)
                            Length: 0x00 (0)
                        Protocol or Container ID: MS support of Local address
                                                  in TFT indicator (0x0011)
                            Length: 0x00 (0)
                    Extended protocol configuration options
                        Element ID: 0x7b
                        Length: 1
                        [Link direction: MS to network (0)]
                        0... .... = Extension: False
                        .... .001 = Configuration Protocol: PPP for use with IP PDP type or
                                     IP PDN type (1)
            Tracking area identity - Last visited registered TAI
                Element ID: 0x52
                Mobile Country Code (MCC): Unknown (1)
                Mobile Network Code (MNC): Unknown (01)
                Tracking area code(TAC): 1
            Location area identification - Old location area identification
                Element ID: 0x13
                Location Area Identification (LAI) - 001/01/1
                    Mobile Country Code (MCC): Unknown (1)
                    Mobile Network Code (MNC): Unknown (01)
                    Location Area Code (LAC): 0x0001 (1)
            Mobile station classmark 2
                Element ID: 0x11
                Length: 3
                0... .... = Spare: 0
                .10. .... = Revision Level: Used by mobile stations supporting R99 or
                                            later versions of the protocol (2)
                ...0 .... = ES IND: Controlled Early Classmark Sending option is not implemented
                            in the MS
                .... 1... = A5/1 algorithm supported: encryption algorithm A5/1 not available
                .... .111 = RF Power Capability: RF Power capability is irrelevant
                            in this information element (7)
                0... .... = Spare: 0
                .0.. .... = PS capability (pseudo-synchronization capability):
                            PS capability not present
                ..01 .... = SS Screening Indicator: Capability of handling of ellipsis notation
                            and phase 2 error handling  (1)
                .... 1... = SM capability (MT SMS pt to pt capability): Mobile station supports
                            mobile terminated point to point SMS
                .... .0.. = VBS notification reception: no VBS capability or
                            no notifications wanted
                .... ..0. = VGCS notification reception: no VGCS capability or
                            no notifications wanted
                .... ...0 = FC Frequency Capability: The MS does not support the E-GSM or
                            R-GSM band
                1... .... = CM3: The MS supports options that are indicated in classmark 3 IE
                .0.. .... = Spare: 0
                ..1. .... = LCS VA capability (LCS value added location request
                            notification capability): LCS value added location request
                            notification capability supported
                ...0 .... = UCS2 treatment: the ME has a preference for the default alphabet
                .... 0... = SoLSA: The ME does not support SoLSA
                .... .1.. = CMSP: CM Service Prompt: Network initiated MO CM connection request
                            supported for at least one CM protocol
                .... ..1. = A5/3 algorithm supported: encryption algorithm A5/3 available
                .... ...0 = A5/2 algorithm supported: encryption algorithm A5/2 not available
            Additional update type
                1111 .... = Element ID: 0xf-
                .... 01.. = Preferred CIoT network behaviour:
                            Control-plane CIoT EPS optimization (1)
                .... ..0. = SAF: Keeping the NAS signalling connection is not required after
                            the completion of the tracking area updating procedure
                .... ...0 = AUTV: No additional information (shall be interpreted as request for
                            combined attach or combined tracking area updating)
            GUTI type - Old GUTI type
                1110 .... = Element ID: 0xe-
                .... 000. = Spare bit(s): 0x00
                .... ...0 = GUTI type: Native GUTI
            MS network feature support
                1100 .... = Element ID: 0xc-
                .... 000. = Spare bit(s): 0
                .... ...1 = Extended periodic timers: MS supports the extended periodic timer
                            in this domain
            Network Resource Identifier Container - TMSI based NRI container
                Element ID: 0x10
                Length: 2
                0000 0000 00.. .... = NRI container value: 0x000
                ..00 0000 = Spare bit(s): 0
            Extended DRX Parameters
                Element ID: 0x6e
                Length: 1
                0100 .... = Paging Time Window: Iu: 4 s / WB-S1: 6.4 s / NB-S1: 12.8 s (0x4)
                .... 1101 = eDRX value: GERAN: 1.88 s / UTRAN: 10.24 s / E-UTRAN: 2621.44 s (0xd)

HEX : 10 40 20 00 40 5A 85 CC 2E D9 1B C0 81 D0 40 82 FD 80 3C 44 20 00 40 40 00 00 00 41 FC 1C 00 00 04 21 00 40 0C 00 86 F4 0C 49 C9 A0 20 08 44 00 40 00 04 20 41 80 00 00 00 20 C1 80 00 00 00 00 03 40 00 00 C0 00 02 80 00 01 40 00 04 00 00 04 40 1E C0 00 40 54 80 3C 44 00 00 44 C0 3C 44 00 00 44 40 D3 C6 29 BD 38 30 44 00 80 00 1B 80 53 40

The capability matters for the rest of the sequence. A UE that supports only the Control Plane CIoT EPS optimisation establishes SRB1bis alone, as the SRB mapping page explains. That is why the table shows no RRC Security Mode Command: the only security procedure in this attach is the NAS one.

Step 18 - Authentication Request

From here until the attach completes, every NAS message travels inside DLInformationTransfer-NB or ULInformationTransfer-NB. The Authentication Request is the first of them, and it is a plain NAS message, because no NAS security context exists yet.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

dlInformationTransfer-r13
    dedicatedInfoNAS-r13: 0752000123456789abcdef0123456789abcdef1054cdfeab...
        Non-Access-Stratum (NAS)PDU
            0000 .... = Security header type: Plain NAS message, not security protected (0)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            NAS EPS Mobility Management Message Type: Authentication request (0x52)
            0000 .... = Spare half octet: 0
            .... 0... = Type of security context flag (TSC): Native security context (for KSIasme)
            .... .000 = NAS key set identifier:  (0) ASME
            Authentication Parameter RAND - EPS challenge
                RAND value: 0123456789abcdef0123456789abcdef
            Authentication Parameter AUTN (UMTS and EPS authentication challenge) - EPS challenge
                Length: 16
                AUTN value: 54cdfeab9889800001326754cdfe2b98
                    SQN xor AK: 54cdfeab9889
                    AMF: 8000
                    MAC: 01326754cdfe2b98

HEX : 00 09 01 D4 80 00 48 D1 59 E2 6A F3 7B C0 48 D1 59 E2 6A F3 7B C4 15 33 7F AA E6 22 60 00 00 4C 99 D5 33 7F 8A E6 00

Step 23 - Authentication Response

The UE answers the challenge with the Authentication Response inside ULInformationTransfer-NB. The table above shows the cost of this small exchange on NB-IoT: RLC ACKs, HARQ ACKs and separate grants surround every NAS message.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

ulInformationTransfer-r13
    dedicatedInfoNAS-r13: 17f9cb55fe0307531001326754cdfeab9889baefdc457623...
        Non-Access-Stratum (NAS)PDU
            0001 .... = Security header type: Integrity protected (1)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            Message authentication code: 0xf9cb55fe
            Sequence number: 3
            0000 .... = Security header type: Plain NAS message, not security protected (0)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            NAS EPS Mobility Management Message Type: Authentication response (0x53)
            Authentication response parameter
                Length: 16
                RES: 01326754cdfeab9889baefdc45762310

HEX : 30 19 17 F9 CB 55 FE 03 07 53 10 01 32 67 54 CD FE AB 98 89 BA EF DC 45 76 23 10

Step 27 - NAS Security Mode Command

The NAS Security Mode Command selects the NAS algorithms and starts the new EPS security context. In this capture the MME selects EEA0, the null ciphering algorithm, and 128-EIA1 for integrity protection.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

dlInformationTransfer-r13
    dedicatedInfoNAS-r13: 37205a892300075d010002f070c1
        Non-Access-Stratum (NAS)PDU
            0011 .... = Security header type: Integrity protected with new EPS security context (3)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            Message authentication code: 0x205a8923
            Sequence number: 0
            0000 .... = Security header type: Plain NAS message, not security protected (0)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            NAS EPS Mobility Management Message Type: Security mode command (0x5d)
            NAS security algorithms - Selected NAS security algorithms
                0... .... = Spare bit(s): 0x00
                .000 .... = Type of ciphering algorithm: EPS encryption algorithm EEA0
                            (null ciphering algorithm) (0)
                .... 0... = Spare bit(s): 0x00
                .... .001 = Type of integrity protection algorithm:
                            EPS integrity algorithm 128-EIA1 (1)
            0000 .... = Spare half octet: 0
            .... 0... = Type of security context flag (TSC): Native security context (for KSIasme)
            .... .000 = NAS key set identifier:  (0) ASME
            UE security capability - Replayed UE security capabilities
                Length: 2
                1... .... = EEA0: Supported
                .1.. .... = 128-EEA1: Supported
                ..1. .... = 128-EEA2: Supported
                ...1 .... = 128-EEA3: Supported
                .... 0... = EEA4: Not supported
                .... .0.. = EEA5: Not supported
                .... ..0. = EEA6: Not supported
                .... ...0 = EEA7: Not supported
                0... .... = EIA0: Not supported
                .1.. .... = 128-EIA1: Supported
                ..1. .... = 128-EIA2: Supported
                ...1 .... = 128-EIA3: Supported
                .... 0... = EIA4: Not supported
                .... .0.. = EIA5: Not supported
                .... ..0. = EIA6: Not supported
                .... ...0 = EIA7: Not supported
            IMEISV request
                1100 .... = Element ID: 0xc-
                .... 0... = Spare bit(s): 0x00
                .... .001 = IMEISV request: IMEISV requested (1)

HEX : 00 03 8D C8 16 A2 48 C0 01 D7 40 40 00 BC 1C 30 40

This is NAS security between the UE and the MME, not AS security between the UE and the eNB. The RRC messages around it stay on SRB1bis, and only the NAS payload inside them is protected.

Step 32 - NAS Security Mode Complete

The NAS Security Mode Complete is the first message protected under the new context. Its outer security header type says integrity protected and ciphered with new EPS security context, even though the selected ciphering algorithm is EEA0.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

ulInformationTransfer-r13
    dedicatedInfoNAS-r13: 47f678b4ff00075e23090310200790999909f0
        Non-Access-Stratum (NAS)PDU
            0100 .... = Security header type: Integrity protected and ciphered with
                        new EPS security context (4)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            Message authentication code: 0xf678b4ff
            Sequence number: 0
            0000 .... = Security header type: Plain NAS message, not security protected (0)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            NAS EPS Mobility Management Message Type: Security mode complete (0x5e)
            Mobile identity - IMEISV - IMEISV (0010270099999900)
                Element ID: 0x23
                Length: 9
                0000 .... = Identity Digit 1: 0
                .... 0... = Odd/even indication: Even number of identity digits
                .... .011 = Mobile Identity Type: IMEISV (3)
                BCD Digits: 0010270099999900
                1111 .... = Filler: 0xf

HEX : 30 13 47 F6 78 B4 FF 00 07 5E 23 09 03 10 20 07 90 99 99 09 F0

Step 36 - Attach Accept + Activate Default EPS Bearer Context Request

The Attach Accept carries the Activate Default EPS Bearer Context Request, and together they finish the attach. The capture assigns EPS bearer identity 5, the APN www.sharetechnote.com and the IPv4 address 192.168.20.11.

Decoded message, decoder tree format. Field values are from a captured message, not from the specification.

dlInformationTransfer-r13
    dedicatedInfoNAS-r13: 27fb54f05e02074202e0060000f1100001003d5201c10109...
        Non-Access-Stratum (NAS)PDU
            0010 .... = Security header type: Integrity protected and ciphered (2)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            Message authentication code: 0xfb54f05e
            Sequence number: 2
            0000 .... = Security header type: Plain NAS message, not security protected (0)
            .... 0111 = Protocol discriminator: EPS mobility management messages (0x7)
            NAS EPS Mobility Management Message Type: Attach accept (0x42)
            0000 .... = Spare half octet: 0
            .... 0... = Spare bit(s): 0x00
            .... .010 = Attach result: Combined EPS/IMSI attach (2)
            GPRS Timer - T3412 value
                GPRS Timer: timer is deactivated
                    111. .... = Unit: value indicates that the timer is deactivated (7)
                    ...0 0000 = Timer value: 0
            Tracking area identity list - TAI list
                Length: 6
                0... .... = Spare bit(s): 0x00
                .00. .... = Type of list: list of TACs belonging to one PLMN,
                            with non-consecutive TAC values (0)
                ...0 0000 = Number of elements: 0 [+1 = 1 element(s)]
                Mobile Country Code (MCC): Unknown (1)
                Mobile Network Code (MNC): Unknown (01)
                Tracking area code(TAC): 1
            ESM message container
                Length: 61
                ESM message container contents: 5201c10109100377777707616e72...
                    0101 .... = EPS bearer identity: EPS bearer identity value 5 (5)
                    .... 0010 = Protocol discriminator: EPS session management messages (0x2)
                    Procedure transaction identity: 1
                    NAS EPS session management messages:
                        Activate default EPS bearer context request (0xc1)
                    EPS quality of service
                        Length: 1
                        Quality of Service Class Identifier (QCI): QCI 9 (9)
                    Access Point Name
                        Length: 22
                        APN: www.sharetechnote.com
                    PDN address
                        Length: 13
                        0000 0... = Spare bit(s): 0x00
                        PDN type: IPv4v6 (3)
                        PDN IPv6 if id: 0000000000000001
                        PDN IPv4: 192.168.20.11
                    Linked TI - Transaction identifier
                        Element ID: 0x5d
                        Length: 1
                        1... .... = TI Flag:The message is sent to the side that originates the TI
                        TI value: 0x00 (0)
                    Quality Of Service - Negotiated QoS
                        Element ID: 0x30
                        Length: 14
                        00.. .... = Spare bit(s): 0
                        ..10 0... = Quality of Service Delay class: Delay class 4(best effort)(4)
                        .... .011 = Reliability class: Unacknowledged GTP/LLC, Ack RLC,
                                    Protected data (3)
                        1001 .... = Peak throughput: Up to 256 000 octet/s (9)
                        .... 0... = Spare bit(s): 0
                        .... .010 = Precedence class: Normal priority (2)
                        000. .... = Spare bit(s): 0
                        ...0 1010 = Mean throughput: 100 000 octet/h (10)
                        100. .... = Traffic class: Background class (4)
                        ...1 0... = Delivery order: Without delivery order ('no') (2)
                        .... .011 = Delivery of erroneous SDUs:
                                    Erroneous SDUs are not delivered('No') (3)
                        Maximum SDU size: 1500 octets (150)
                        Maximum bitrate for uplink: 64 kbps (64)
                        Maximum bitrate for downlink: 384 kbps (104)
                        0111 .... = Residual Bit Error Rate (BER): 1*10-5 (7)
                        .... 0100 = SDU error ratio: 1*10-4 (4)
                        0000 00.. = Transfer delay: Subscribed transfer delay/reserved (0)
                        .... ..00 = Traffic handling priority:
                                    Subscribed traffic handling priority/Reserved (0)
                        Guaranteed bitrate for uplink: 64 kbps (64)
                        Guaranteed bitrate for downlink: 568 kbps (127)
                        000. .... = Spare bit(s): 0
                        ...0 .... = Signalling indication: Not optimised for signalling traffic
                        .... 0000 = Source statistics description: unknown (0)
                        Maximum bitrate for downlink (extended): Use the value indicated
                                    by the Maximum bit rate for downlink (0)
                        Guaranteed bitrate for downlink (extended): Use the value indicated
                                    by the Guaranteed bit rate for downlink (0)
                    LLC Service Access Point Identifier - Negotiated LLC SAPI
                        Element ID: 0x32
                        0000 .... = Spare bit(s): 0
                        .... 0011 = LLC SAPI: SAPI 3 (3)
                    Radio Priority
                        1000 .... = Element ID: 0x8-
                        .... .001 = Radio Priority (PDP or SMS): priority level 1 (highest) (1)
                    Protocol Configuration Options
                        Element ID: 0x27
                        Length: 1
                        [Link direction: Network to MS (1)]
                        1... .... = Extension: True
                        .... .000 = Configuration Protocol: PPP for use with IP PDP type
                                                            or IP PDN type (0)
            EPS mobile identity - GUTI
                Element ID: 0x50
                Length: 11
                .... 0... = Odd/even indication: Even number of identity digits
                .... .110 = Type of identity: GUTI (6)
                Mobile Country Code (MCC): Unknown (1)
                Mobile Network Code (MNC): Unknown (01)
                MME Group ID: 32769
                MME Code: 1
                M-TMSI: 0x00000001
            Location area identification
                Element ID: 0x13
                Location Area Identification (LAI) - 001/01/1
                    Mobile Country Code (MCC): Unknown (1)
                    Mobile Network Code (MNC): Unknown (01)
                    Location Area Code (LAC): 0x0001 (1)
            Mobile identity - MS identity - TMSI/P-TMSI (0x0000)
                Element ID: 0x23
                Length: 5
                1111 .... = Unused: 0xf
                .... 0... = Odd/even indication: Even number of identity digits
                .... .100 = Mobile Identity Type: TMSI/P-TMSI/M-TMSI (4)
                TMSI/P-TMSI: 0x00000000
            EPS network feature support
                Element ID: 0x64
                Length: 2
                1... .... = Control plane CIoT EPS optimization: Supported
                .1.. .... = EMM-REGISTERED w/o PDN connectivity: Supported
                ..0. .... = Support of EXTENDED SERVICE REQUEST for packet services: Not supported
                ...0 0... = CS-LCS: no information about support of location services
                            via CS domain is available (0)
                .... .0.. = Location services via EPC: Not supported
                .... ..0. = Emergency bearer services in S1 mode: Not supported
                .... ...0 = IMS voice over PS session in S1 mode: Not supported
                0000 .... = Spare bit(s): 0x00
                .... 0... = Extended protocol configuration options IE: Not supported
                .... .0.. = Header compression for control plane CIoT EPS optimization: 
                            Not supported
                .... ..1. = S1-u data transfer: Supported
                .... ...0 = User plane CIoT EPS optimization: Not supported

HEX : 00 1B 89 FE D5 3C 17 80 81 D0 80 B8 01 80 00 3C 44 00 00 40 0F 54 80 70 40 42 44 00 DD DD DD C1 D8 5B 9C 9A 5D 1C DD 40 D8 DB DB 43 40 C0 00 00 00 00 00 00 00 70 2A 05 02 D7 40 60 0C 03 88 E4 82 A4 E5 90 1A 1D 00 10 1F C0 00 00 0C 80 E0 49 C0 60 14 02 FD 80 3C 44 20 00 40 40 00 00 00 44 C0 3C 44 00 00 48 C1 7D 00 00 00 00 19 00 B0 00 80

The red lines are EPS network feature support. The network confirms Control plane CIoT EPS optimization as supported and User plane CIoT EPS optimization as not supported, which matches the UE capability in the RRC Connection Setup Complete. So the data of this UE will travel over the control plane, inside NAS messages.

Reference

[1]

[2] 3GPP TS 36.331 v19.3.0 - clause 5.3.1 for SRB1bis, clause 6.7 for NB-IoT RRC messages

[3] 3GPP TS 36.321 v19.3.0 - clause 5.1.5 for contention resolution

[4] 3GPP TS 24.301 - EPS NAS messages and the CIoT EPS optimisations