Serial Number defines the geographical range(scope) that the PWS message applies and how UE should process the message (alerting method) and along with message identifier informs further details of message type.
Those 16 bits hold three separate fields, and two bits inside the middle one change their meaning with the type of warning. So the Serial Number cannot be read on its own. You need the Message Identifier beside it, and the capture on this page shows why. I'll decode the capture first, then walk through the fields, and finish with the job the Serial Number does inside RRC.
- Where does the Serial Number sit in a warning SIB ?
- How are the 16 bits divided ?
- Do bits 5 and 4 mean the same thing for CMAS ?
- How does the UE use the Serial Number while segments arrive ?
- Reference
Where does the Serial Number sit in a warning SIB ?
The Serial Number is the second field of every warning SIB, right after messageIdentifier. The capture below is the same SIB12 that the page PWS Message Identifier decodes, with the serial number highlighted this time. Its value is 0011000000000000, or hex 3000.
Capture : SIB12 inside a BCCH-DL-SCH system information message, shown as a decoder tree. The values come from one recorded exchange and not from the specification.
BCCH-DL-SCH-Message ::= SEQUENCE
+-message ::= CHOICE [c1]
+-c1 ::= CHOICE [systemInformation]
+-systemInformation ::= SEQUENCE
+-criticalExtensions ::= CHOICE [systemInformation-r8]
+-systemInformation-r8 ::= SEQUENCE [0]
+-sib-TypeAndInfo ::= SEQUENCE OF SIZE(1..maxSIB[32]) [1]
| +- ::= CHOICE [sib12-v920]
| +-sib12-v920 ::= SEQUENCE [10]
| +-messageIdentifier-r9 ::= BIT STRING SIZE(16) [0001000100010010]
| +-serialNumber-r9 ::= BIT STRING SIZE(16) [0011000000000000]
| +-warningMessageSegmentType-r9 ::= ENUMERATED [lastSegment]
| +-warningMessageSegmentNumber-r9 ::= INTEGER (0..63) [0]
| +-warningMessageSegment-r9 ::= OCTET STRING SIZE(ALIGNED)
[01C576597E2EBBC7F950A8D168341A8D46A3D168341
A8D46A3D168341A8D46A3D168341A8D46A3D168341A
8D46A3D168341A8D46A3D168341A8D46A3D168341A8
D46A3D168341A8D46A3D168341A8D46A3D1000A]
| +-dataCodingScheme-r9 ::= OCTET STRING SIZE(1) [01] OPTIONAL:Exist
| +-lateNonCriticalExtension ::= OCTET STRING OPTIONAL:Omit
| +-EXTENSION ::= SEQUENCE
+-nonCriticalExtension ::= SEQUENCE OPTIONAL:Omit
serialNumber-r9 ::= BIT STRING SIZE(16) [0011000000000000] is hex 3000. Split into 2, 10 and 4 bits, it gives a GS of 00, a Message Code of 11 0000 0000 and an Update Number of 0000.- A GS of 00 means cell wide, with the display mode immediate.
- The Message Code 11 0000 0000 is 768 in decimal. Its two leading bits are octet 1 bits 5 and 4, and both are 1. The section on bits 5 and 4 below explains why that matters.
- An Update Number of 0000 means that this is the first version of the message.
messageIdentifier-r9 ::= BIT STRING SIZE(16) [0001000100010010] is hex 1112, or 4370, a CMAS Presidential Level Alert. So the CMAS reading of bits 5 and 4 is the one that applies here.
36.331 carries the field as a BIT STRING of size 16. Its field description maps the leading bit to bit 7 of the first octet of the Serial Number IE in 36.413 clause 9.2.1.45. From there it points to 23.041 clause 9.4.3.2.2, which refers to clause 9.4.1.2.1 for the structure. So the bit string reads straight across the layout in the next section, from the GS on the left to the Update Number on the right.
The capture is cell wide and immediate : the GS bits are 00.This is the first version of the message : the Update Number is 0000.Bits 5 and 4 of octet 1 are both set : and their meaning depends on the Message Identifier, which here is a CMAS value.The bit string reads in normal order : the leading bit is bit 7 of the first octet.
How are the 16 bits divided ?
Three fields share the 16 bits, and each one answers a different question. The Geographical Scope says over which area the Message Code is unique, and how the message is displayed. The Message Code says which message this is. The Update Number says which version of that message this is.
The drawing below lays the 16 bits out as octet 1 bits 7 to 0, followed by octet 2 bits 7 to 0. The brackets under the bits point to three small tables. Bit 4 leads to the Popup table, bit 5 to the Emergency User Alert table, and bits 7 and 6 to the GS code table.
< Based on 23.041 9.4.1.2.1 Serial Number >

- The GS is octet 1 bits 7 and 6. The most significant bit of the GS is octet 1 bit 7.
- The Message Code runs from octet 1 bit 5 to octet 2 bit 4, which is 10 bits. 23.041 leaves its values for allocation by PLMN or SNPN operators.
- The Update Number is octet 2 bits 3 to 0, with its most significant bit at octet 2 bit 3.
- The Popup and Emergency User Alert tables are the ETWS reading of octet 1 bits 4 and 5. They apply only when the Message Identifier is an ETWS value.
- The GS table is older than the current 23.041 text. GS 01 now reads PLMN/SNPN wide, and GS 10 now also covers a Tracking Area in NG-RAN.
The Update Number is the field that changes most often. It marks a change of content in the same message, which means the same Message Identifier, Geographical Scope and Message Code. A new message may start at 0000, and each update increments the number by 1.
The GS also decides when a message counts as new. With a cell wide GS, a message received again in the next cell is treated as new. With a PLMN/SNPN wide GS, the Message Code or the Update Number has to change before the message is new, and any change of PLMN or SNPN makes it new. With a Tracking Area wide GS in E-UTRAN, the answer depends on whether the next cell is in the same Tracking Area.
GS 00 carries one more rule. 23.041 intends it for base station IDs, but other applications may use it, and GS 00 takes precedence over the message class in the DCS. For ETWS, the Popup bit also takes precedence over the DCS message class and over the immediate display mode of the GS.
GS, Message Code and Update Number are 2, 10 and 4 bits : in that order, from octet 1 bit 7 to octet 2 bit 0.The operator allocates the Message Code : 23.041 defines only its position and, for ETWS and CMAS, the meaning of its two leading bits.The Update Number marks new content : it increments by 1 each time the same message is updated.The drawing shows an older GS table : the current text adds SNPN and NG-RAN to the scope names.
Do bits 5 and 4 mean the same thing for CMAS ?
The drawing above reads octet 1 bits 5 and 4 as Emergency User Alert and Popup. That reading holds only for an ETWS Message Identifier. For a CMAS Message Identifier, the current 23.041 gives the same two bits a different job, and the capture on this page is a CMAS message.
The table below puts the two readings side by side. The bit positions are the same in both columns. Only the instruction to the terminal changes.
< Based on 23.041 v20.0.0 Figures 9.4.1.2.1-2 and 9.4.1.2.1-3 >
Bit | ETWS Message Identifier | CMAS Message Identifier |
Octet 1 bit 5 | Emergency User Alert. 1 = activate emergency user alert | Suppress Alerting Tone. 1 = activate alerting tone suppression |
Octet 1 bit 4 | Popup. 1 = activate popup on the display | Suppress Vibration Cadence. 1 = activate vibration cadence suppression |
A value of 0 in either bit means no instruction, for both systems. A UE that cannot vibrate ignores bit 4, and a UE that cannot generate an alerting tone ignores bit 5. If the MMI is configured not to suppress the vibration cadence, the UE ignores the Suppress Vibration Cadence field. For ETWS, 23.041 leaves the exact UE behaviour to 22.268, and regulatory requirements decide whether the UE setting is overridden.
Now let's apply this to the capture. Its Message Identifier is 4370, a CMAS value, and bits 5 and 4 are both 1. Under the current 23.041, that asks the UE to suppress both the alerting tone and the vibration cadence for a Presidential Level Alert. Under the ETWS reading in the drawing, the same bits would ask for an emergency user alert and a popup. The capture does not show which of the two readings the test equipment intended. So check the Message Identifier first, and only then read bits 5 and 4.
Bits 5 and 4 have two meanings : ETWS uses them for alert and popup, and CMAS uses them for tone and vibration suppression.The Message Identifier decides the reading : the same Serial Number means different things under an ETWS and a CMAS identifier.A 0 is always safe : it means no instruction in both readings.Hex 3000 on a CMAS message suppresses tone and vibration : under the current 23.041 text.
How does the UE use the Serial Number while segments arrive ?
The Serial Number also has a job inside RRC. A warning in SIB11 or SIB12 can arrive in several segments, and the UE needs a key to know which segments belong together. 36.331 uses the pair of messageIdentifier and serialNumber as that key.
For SIB11, the UE keeps one current pair. If a received pair differs from the current one in either value, the UE takes the new pair as current and discards any segments it had buffered. When all segments have arrived, the UE assembles the message and forwards it to upper layers with messageIdentifier, serialNumber and dataCodingScheme. Then it stops receiving SIB11.
For SIB12, the UE can assemble several warnings in parallel. Each new pair starts a new assembly, and a segment whose pair matches an assembly in progress is added to that assembly. The number of warnings a UE can assemble at the same time is left to the UE implementation. SIB10 needs no assembly at all. The UE forwards its warningType, messageIdentifier and serialNumber to upper layers as soon as it receives them.
In both SIB11 and SIB12, the UE should discard the stored segments and the pair if the complete message has not been assembled within 3 hours. The Update Number matters here. A network that changes the text of a warning also changes the Update Number, and so the Serial Number. The UE then treats the changed text as a new pair, rather than mixing its segments with those of the old one. The page ETWS shows where SIB10 and SIB11 fit into the ETWS procedure.
The pair is the assembly key : 36.331 matches segments by messageIdentifier and serialNumber together.SIB11 follows one warning at a time : a new pair discards the segments buffered for the old one.SIB12 can follow several warnings : each pair has its own assembly, up to a limit the UE implementation sets.Incomplete warnings expire : the UE should discard them after 3 hours.
Reference
- 23.041 : 3GPP - Technical realization of Cell Broadcast Service (CBS), v20.0.0. Clause 9.4.1.2.1 with Figures 9.4.1.2.1-1 to 9.4.1.2.1-3 and Tables 9.4.1.2.1-1, 9.4.1.2.1-1a and 9.4.1.2.1-2, and clause 9.4.3.2.2.
- 36.331 : 3GPP - E-UTRA; Radio Resource Control (RRC); Protocol specification, v19.3.0. The SystemInformationBlockType12 field descriptions, and clauses 5.2.2.17 to 5.2.2.19 for the reception of SIB10, SIB11 and SIB12.