4G/LTE - SMS

 

 

 

SMS with LTE (SG-SMS)

 

Everybody would know what SMS (Short Messaging Service) is. So I will not talk about what SMS is. The question you are more interested in would be "Is it possible to send SMS in LTE ?" and "How to do it ?".

Yes, SMS is possible in LTE and there are two ways to implement SMS in LTE. The ideal solution would be doing SMS using IMS. IMS over LTE is specified to transfer any form of data (e.g, voice, SMS and any other form of multi media data), but the question is when every body (both network implementation and UE implementation) will seamlessly implement this IMS on their network and UE. It seems that they are not implemented fully at least for now. So they thought out a kind of interim solution called SG SMS. (It is like we have CS Fallback as an interim solution before they fully implement voice call over IMS). For the over view of SG SMS, refer to this blog. I found the explanation in the blog is short, practical and easy to understand.

In terms of network Architecture, SG SMS goes through a special interface marked in red below.

Network architecture with GSM, UMTS and LTE access, MSC, SGSN, MME, SGW and PGW, and the SGs interface in red between MME and MSC

SGs connects the MME to the MSC. An SMS for an LTE UE travels on SGs between the MSC and the MME, and inside NAS messages between the MME and the UE.

  • The UE on the left can reach three radio access networks: BTS for GSM, NodeB for UMTS and eNodeB for LTE.
  • The BSC and the RNC connect to both the MSC and the SGSN, which are the CS and PS cores of GSM and UMTS.
  • The eNodeB connects to the MME and to the SGW, and the SGW connects through the PGW to IP.
  • The red line marked SGs is the only link between the LTE core and the CS core in the picture.

I'll first place SMS over SGs in the 23.272 procedure, and then read the captures step by step. The later sections show how the TPDU carries the number type, the message class and the time stamp. The last one shows what the UE must send at attach, so that the network allows SMS over SGs.

Followings are the topics I will deal with in this page.

Which nodes carry an SMS over SGs ?

Before we read the captures, we need to know which node sends each message. SMS over SGs reuses the CS SMS protocols, but the UE never falls back to GERAN or UTRAN for it. So the MSC still handles the SMS, while the MME only relays it between NAS and SGs.

23.272 v20.0.0 clause 8.2.1 sets the precondition. The procedures apply only if the UE is EPS/IMSI attached, for example after a combined attach. The SMS itself uses the same layers as in the CS domain: CP-DATA, RP-DATA and a TPDU such as SMS-SUBMIT or SMS-DELIVER. The MME forwards the SMS to the MSC/VLR in an SGs Uplink Unitdata message, and it receives the other direction in a Downlink Unitdata message.

Let's follow the MT case in 23.272 clause 8.2.4, because the captures below are MT. The table below maps each step of that procedure to the message that the UE sees.

 

23.272 step

What happens in the network

What the UE sees

5 to 7

The MSC/VLR sends Paging with an SMS indicator to the MME, and the MME pages the UE with its S-TMSI

Paging, if the UE is in idle mode

8

The UE sends a Service Request, and the eNodeB establishes the radio bearers

Service Request and RRC Connection Reconfiguration, steps i) and ii) below

9a, 9b

The MSC/VLR builds CP-DATA, RP-DATA and SMS-DELIVER and sends them in Downlink Unitdata, and the MME wraps them in NAS

DOWNLINK NAS TRANSPORT with CP-DATA, step iii)

9c, 9d

The UE acknowledges receipt of the SMS to the MSC/VLR

UPLINK NAS TRANSPORT with CP-ACK, step iv)

10, 11

The UE returns the delivery report, and the MME forwards it in Uplink Unitdata

UPLINK NAS TRANSPORT with CP-DATA and RP-ACK, step v)

14, 15

The MSC/VLR acknowledges receipt of the delivery report

DOWNLINK NAS TRANSPORT with CP-ACK, step vi)

16

The MSC/VLR tells the MME that no more NAS messages need to be tunnelled

nothing on the air interface

 

The MO case in clause 8.2.2 is the mirror image. The UE sends CP-DATA with RP-DATA and SMS-SUBMIT in an UPLINK NAS TRANSPORT, and the MSC/VLR acknowledges it. The delivery report from the SC comes back in a DOWNLINK NAS TRANSPORT, and the UE acknowledges that. In both directions every CP-DATA is answered with a CP-ACK, so one SMS always costs four NAS transport messages.

24.301 v20.0.0 clause 5.6.3.1 adds one more condition for these NAS transport messages. The UE must be in EMM-CONNECTED mode, and it must be attached for EPS services and non-EPS services, or for EPS services and "SMS only". The second option is for a UE that uses PS and SMS services without CS fallback for voice.

  • The MSC still owns the SMS : the MME only relays it between NAS and SGs, and no CS fallback happens.
  • A combined attach comes first : without EPS/IMSI attach, or EPS and "SMS only", the transport of NAS messages procedure cannot be used.
  • One SMS, four NAS messages : CP-DATA and CP-ACK run in each direction, once for the SMS and once for the delivery report.

Basic Signal Flow

The implementation logic of SG-SMS is very similar to WCDMA SMS. In WCDMA, we injected the SMS message into a DCCH channel and send it to the destination. It means that we carried the message over a control channel, not over a data channel. SG SMS is also using a similar concept, we send the message over a control channel. One example is as follows (This is for MT SMS case).

    i) UE <-- NW : RRC Connection Reconfiguration

    ii) UE --> NW : RRC Connection Reconfiguration Comlete

    iii) UE <-- NW : dlInformationTransfer (DOWNLINK NAS TRANSPORT : SMS message - CP Data)

    iv) UE --> NW : ulInformationTransfer (UPLINK NAS TRANSPORT : embedd CP-ACK into this message)

    v) UE --> NW : ulInformationTransfer (UPLINK NAS TRANSPORT : Delivery Report)

    vi) UE <-- NW : dlInformationTransfer (DOWNLINK NAS TRANSPORT : CP-ACK)

Actually Step iii) carries a special NAS message called "DOWNLINK NAS TRANSPORT" and this NAS message carries CP Data in it.

< Step iii) dlInformationTransfer with DOWNLINK NAS TRANSPORT and CP-DATA > RRC and NAS capture. Field values are from a live capture, not from the specification.

c1: dlInformationTransfer (1)
    dlInformationTransfer
        rrc-TransactionIdentifier: 0
        criticalExtensions: c1 (0)
            c1: dlInformationTransfer-r8 (0)
                dlInformationTransfer-r8
                    dedicatedInfoType: dedicatedInfoNAS (0)
                        dedicatedInfoNAS: 27d1356f030407622809012501000481999999001c040a81...
                        Non-Access-Stratum (NAS)PDU
                            0010 .... = Security header type: Integrity protected and ciphered (2)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            Message authentication code: 0xd1356f03
                            Sequence number: 4
                            0000 .... = Security header type: Plain NAS message, not security protected (0)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            NAS EPS Mobility Management Message Type: Downlink NAS transport (0x62)
                            NAS message container
                                Length: 40
                                NAS message container content: 09012501000481999999001c040a81214365870900003111...
                                    GSM A-I/F DTAP - CP-DATA
                                        Protocol Discriminator: SMS messages
                                            .... 1001 = Protocol discriminator: SMS messages (0x09)
                                            0... .... = TI flag: allocated by sender
                                            .000 .... = TIO: 0
                                        DTAP Short Message Service Message Type: CP-DATA (0x01)
                                        CP-User Data
                                            Length: 37
                                            RPDU (not displayed)
                                    GSM A-I/F RP - RP-DATA (Network to MS)
                                        Message Type RP-DATA (Network to MS)
                                        RP-Message Reference
                                            RP-Message Reference: 0x00 (0)
                                        RP-Origination Address - (999999)
                                            Length: 4
                                            1... .... = Extension: No Extension
                                            .000 .... = Type of number: unknown (0x00)
                                            .... 0001 = Numbering plan identification:
                                                            ISDN/Telephony Numbering (Rec ITU-T E.164) (0x01)
                                            BCD Digits: 999999
                                        RP-Destination Address
                                            Length: 0
                                        RP-User Data
                                            Length: 28
                                            TPDU (not displayed)
                                    GSM SMS TPDU (GSM 03.40) SMS-DELIVER
                                        0... .... = TP-RP: TP Reply Path parameter is not set in this SMS SUBMIT/DELIVER
                                        .0.. .... = TP-UDHI: The TP UD field contains only the short message
                                        ..0. .... = TP-SRI: A status report shall not be returned to the SME
                                        .... .1.. = TP-MMS: No more messages are waiting for the MS in this SC
                                        .... ..00 = TP-MTI: SMS-DELIVER (0)
                                        TP-Originating-Address - (1234567890)
                                            Length: 10 address digits
                                            1... .... :  No extension
                                            .000 .... :  Type of number: (0) Unknown
                                            .... 0001 :  Numbering plan: (1) ISDN/telephone (E.164/E.163)
                                            TP-OA Digits: 1234567890
                                        TP-PID: 0
                                            00.. .... :  defines formatting for subsequent bits
                                            ..0. .... :  no telematic interworking, but SME-to-SME protocol
                                            ...0 0000 :  the SM-AL protocol being used between the SME and the MS (0)
                                        TP-DCS: 0
                                            00.. .... = Coding Group Bits: General Data Coding indication (0)
                                            Special case, GSM 7 bit default alphabet
                                        TP-Service-Centre-Time-Stamp
                                            Year 13, Month 11, Day 06
                                            Hour 10, Minutes 05, Seconds 55
                                            Timezone: GMT + 5 hours 0 minutes
                                        TP-User-Data-Length: (11) depends on Data-Coding-Scheme
                                        TP-User-Data
                                            SMS text: mt sms test

Actually Step iv) carries a special NAS message called "UPLINK NAS TRANSPORT" and this NAS message carries CP ACK in it.

< Step iv) ulInformationTransfer with UPLINK NAS TRANSPORT and CP-ACK > RRC and NAS capture. Field values are from a live capture, not from the specification.

c1: ulInformationTransfer (9)
    ulInformationTransfer
        criticalExtensions: c1 (0)
            c1: ulInformationTransfer-r8 (0)
                ulInformationTransfer-r8
                    dedicatedInfoType: dedicatedInfoNAS (0)
                        dedicatedInfoNAS: 27602658f6040763028904
                        Non-Access-Stratum (NAS)PDU
                            0010 .... = Security header type: Integrity protected and ciphered (2)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            Message authentication code: 0x602658f6
                            Sequence number: 4
                            0000 .... = Security header type: Plain NAS message, not security protected (0)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            NAS EPS Mobility Management Message Type: Uplink NAS transport (0x63)
                            NAS message container
                                Length: 2
                                NAS message container content: 8904
                                    GSM A-I/F DTAP - CP-ACK
                                        Protocol Discriminator: SMS messages
                                            .... 1001 = Protocol discriminator: SMS messages (0x09)
                                            1... .... = TI flag: allocated by receiver
                                            .000 .... = TIO: 0
                                        DTAP Short Message Service Message Type: CP-ACK (0x04)

Step v) is not optional. This is for delivery report.

< Step v) ulInformationTransfer with UPLINK NAS TRANSPORT, CP-DATA and RP-ACK > RRC and NAS capture. Field values are from a live capture, not from the specification.

c1: ulInformationTransfer (9)
    ulInformationTransfer
        criticalExtensions: c1 (0)
            c1: ulInformationTransfer-r8 (0)
                ulInformationTransfer-r8
                    dedicatedInfoType: dedicatedInfoNAS (0)
                        dedicatedInfoNAS: 27608e1cd405076309890106020041020000
                        Non-Access-Stratum (NAS)PDU
                            0010 .... = Security header type: Integrity protected and ciphered (2)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            Message authentication code: 0x608e1cd4
                            Sequence number: 5
                            0000 .... = Security header type: Plain NAS message, not security protected (0)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            NAS EPS Mobility Management Message Type: Uplink NAS transport (0x63)
                            NAS message container
                                Length: 9
                                NAS message container content: 890106020041020000
                                    GSM A-I/F DTAP - CP-DATA
                                        Protocol Discriminator: SMS messages
                                            .... 1001 = Protocol discriminator: SMS messages (0x09)
                                            1... .... = TI flag: allocated by receiver
                                            .000 .... = TIO: 0
                                        DTAP Short Message Service Message Type: CP-DATA (0x01)
                                        CP-User Data
                                            Length: 6
                                            RPDU (not displayed)
                                    GSM A-I/F RP - RP-ACK (MS to Network)
                                        Message Type RP-ACK (MS to Network)
                                        RP-Message Reference
                                            RP-Message Reference: 0x00 (0)
                                        RP-User Data
                                            Element ID: 0x41
                                            Length: 2
                                            TPDU (not displayed)
                                    GSM SMS TPDU (GSM 03.40) SMS-DELIVER REPORT
                                        .0.. .... = TP-UDHI: The TP UD field contains only the short message
                                        .... .0.. = TP-MMS: More messages are waiting for the MS in this SC
                                        .... ..00 = TP-MTI: SMS-DELIVER REPORT (0)
                                        TP-Parameter-Indicator
                                            0... .... :  No extension
                                            .000 0... :  Reserved
                                            .... .0.. :  TP-UDL not present
                                            .... ..0. :  TP-DCS not present
                                            .... ...0 :  TP-PID not present

Step vi) is the CP-ACK for Step v)

< Step vi) dlInformationTransfer with DOWNLINK NAS TRANSPORT and CP-ACK > RRC and NAS capture. Field values are from a live capture, not from the specification.

c1: dlInformationTransfer (1)
    dlInformationTransfer
        rrc-TransactionIdentifier: 0
        criticalExtensions: c1 (0)
            c1: dlInformationTransfer-r8 (0)
                dlInformationTransfer-r8
                    dedicatedInfoType: dedicatedInfoNAS (0)
                        dedicatedInfoNAS: 27b0d94c40050762020904
                        Non-Access-Stratum (NAS)PDU
                            0010 .... = Security header type: Integrity protected and ciphered (2)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            Message authentication code: 0xb0d94c40
                            Sequence number: 5
                            0000 .... = Security header type: Plain NAS message, not security protected (0)
                            .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                            NAS EPS Mobility Management Message Type: Downlink NAS transport (0x62)
                            NAS message container
                                Length: 2
                                NAS message container content: 0904
                                    GSM A-I/F DTAP - CP-ACK
                                        Protocol Discriminator: SMS messages
                                            .... 1001 = Protocol discriminator: SMS messages (0x09)
                                            0... .... = TI flag: allocated by sender
                                            .000 .... = TIO: 0
                                        DTAP Short Message Service Message Type: CP-ACK (0x04)

Now let's read the four captures together. Every NAS message is integrity protected and ciphered, and the decoder shows both the security header and the plain DOWNLINK or UPLINK NAS TRANSPORT inside it. The NAS sequence number goes from 4 to 5 in each direction, one step per message. In the NAS message container, the first octet 09 or 89 carries the SMS protocol discriminator 1001 and the TI flag.

The TI flag shows which side started the transaction. The network allocated the transaction identifier, so its CP-DATA and CP-ACK carry TI flag 0, allocated by sender. The UE answers in the same transaction with TI flag 1, allocated by receiver, even for its own CP-DATA in step v). RP-Message Reference 0x00 in the RP-ACK also matches the RP-DATA of step iii).

Step v) needs a word of care, because two different acknowledgements are involved. The CP-ACK in step iv) confirms only the CP-DATA at the CM sublayer. The result for the SMS travels in the RP layer. 24.011 v20.0.0 clause 6.3.1 says that the SMR entity starts timer TR2M when it passes the received RP-DATA to the transfer layer. It then relays an RP-ACK or an RP-ERROR to the network, and clause 10.1 sets TR2M between 12 and 20 seconds.

What is optional is the content of the RP-ACK. RP-User Data, with Element ID 0x41, may carry an SMS-DELIVER-REPORT TPDU. In this capture it does, and its TP-Parameter-Indicator shows that TP-PID, TP-DCS and TP-UDL are all absent.

  • Each layer has its own acknowledgement : CP-ACK closes a CP-DATA, and RP-ACK closes the SMS transfer.
  • The TI flag follows the transaction : the network side sends 0 and the UE side sends 1 for the whole MT transaction.
  • The RP-ACK is mandatory : only the SMS-DELIVER-REPORT inside it is optional.

Addional Example - International Number / Message Class / Message Time Stamp

These information is specified in specific information elements in CP-DATA as shown in color below. Red indicate 'International Number Type', Green indicates 'Message Class' and Blue indicate 'Message Time Stamp'

< dlInformationTransfer with CP-DATA, international number and Class 1 > RRC and NAS capture. Field values are from a live capture, not from the specification.

DLT: 147, Payload: lte-rrc.dl.dcch (LTE Radio Resource Control (RRC) protocol)
DL-DCCH-Message
    message: c1 (0)
        c1: dlInformationTransfer (1)
            dlInformationTransfer
                rrc-TransactionIdentifier: 0
                criticalExtensions: c1 (0)
                    c1: dlInformationTransfer-r8 (0)
                        dlInformationTransfer-r8
                            dedicatedInfoType: dedicatedInfoNAS (0)
                                dedicatedInfoNAS: 27d05511ee0507622c090129010004819999990020a40a90...
                                    Non-Access-Stratum (NAS)PDU
                                        0010 .... = Security header type: Integrity protected and ciphered (2)
                                        .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                                        Message authentication code: 0xd05511ee
                                        Sequence number: 5
                                        0000 .... = Security header type: Plain NAS message,
                                                                          not security protected (0)
                                        .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                                        NAS EPS Mobility Management Message Type: Downlink NAS transport (0x62)
                                        NAS message container
                                            Length: 44
                                            NAS message container content:
                                                GSM A-I/F DTAP - CP-DATA
                                                    Protocol Discriminator: SMS messages
                                                        .... 1001 = Protocol discriminator: SMS messages (0x09)
                                                        0... .... = TI flag: allocated by sender
                                                        .000 .... = TIO: 0
                                                    DTAP Short Message Service Message Type: CP-DATA (0x01)
                                                    CP-User Data
                                                        Length: 41
                                                        RPDU (not displayed)
                                                GSM A-I/F RP - RP-DATA (Network to MS)
                                                    Message Type RP-DATA (Network to MS)
                                                    RP-Message Reference
                                                        RP-Message Reference: 0x00 (0)
                                                    RP-Originator Address - (999999)
                                                        Length: 4
                                                        1... .... = Extension: No Extension
                                                        .000 .... = Type of number: unknown (0x00)
                                                        .... 0001 = Numbering plan identification:
                                                                    ISDN/Telephony Numbering
                                                                    (ITU-T Rec. E.164 / ITU-T Rec. E.163) (0x01)
                                                        BCD Digits: 999999
                                                    RP-Destination Address
                                                        Length: 0
                                                    RP-User Data
                                                        Length: 32
                                                        TPDU (not displayed)
                                                GSM SMS TPDU (GSM 03.40) SMS-DELIVER
                                                    1... .... = TP-RP: TP Reply Path parameter is set
                                                                        in this SMS SUBMIT/DELIVER
                                                    .0.. .... = TP-UDHI: The TP UD field contains only
                                                                         the short message
                                                    ..1. .... = TP-SRI: A status report shall be returned
                                                                        to the SME
                                                    .... .1.. = TP-MMS: No more messages are waiting
                                                                         for the MS in this SC
                                                    .... ..00 = TP-MTI: SMS-DELIVER (0)
                                                    TP-Originating-Address - (1234567890)
                                                        Length: 10 address digits
                                                        1... .... :  No extension
                                                        .001 .... :  Type of number: (1) International
                                                        .... 0000 :  Numbering plan: (0) Unknown
                                                        TP-OA Digits: 1234567890
                                                    TP-PID: 0
                                                        00.. .... :  defines formatting for subsequent bits
                                                        ..0. .... :  no telematic interworking,
                                                                        but SME-to-SME protocol
                                                        ...0 0000 :  the SM-AL protocol being used
                                                                        between the SME and the MS (0)
                                                    TP-DCS: 17
                                                        00.. .... = Coding Group Bits:
                                                                        General Data Coding indication (0)
                                                        00.. .... :  General Data Coding indication
                                                        ..0. .... :  Text is not compressed
                                                        ...1 .... :  Message class is defined below
                                                        .... 00.. :  Character set: GSM 7 bit default alphabet
                                                        .... ..01 :  Message Class: Class 1 Default meaning: 
                                                                         ME-specific
                                                    TP-Service-Centre-Time-Stamp
                                                        Year 15, Month 04, Day 07
                                                        Hour 13, Minutes 41, Seconds 28
                                                        Timezone: GMT + 5 hours 0 minutes
                                                    TP-User-Data-Length: (16) depends on Data-Coding-Scheme
                                                    TP-User-Data
                                                        SMS text: MT SMS -  Class1

Let's check the three highlighted fields against the raw bytes as well. In the dedicatedInfoNAS, the TPDU starts with a4 0a 90. The first octet a4 sets TP-RP, TP-SRI and TP-MMS, with TP-MTI = 00 for SMS-DELIVER. Then 0a is the address length of 10 digits, and 90 is the type of address.

In the type of address 90, bits 7 to 5 are 001, which is the international number type. The lower four bits are 0000, numbering plan Unknown. For comparison, the MT SMS in the basic example uses 81, which is type Unknown with numbering plan ISDN/telephone. The UE uses this field to tell an international sender number from a national one.

TP-DCS = 17 is 0x11, or 0001 0001 in binary. The coding group 00 is General Data Coding. Bit 4 set to 1 means that bits 1 and 0 carry a message class, and 01 is Class 1, default meaning ME-specific. Bits 3 and 2 are 00, the GSM 7 bit default alphabet. 23.038 v20.0.0 defines this coding, and in the same table Class 2 means (U)SIM specific.

The time stamp is 7 octets in semi-octet form. 23.040 v20.0.0 clause 9.2.3.11 puts the time zone in the last octet. It counts the difference between local time and GMT in quarters of an hour, with a sign bit. GMT + 5 hours 0 minutes is therefore 20 quarters. This time comes from the SC, not from the UE clock.

  • The type of address holds the international flag : 0x90 means international number type with numbering plan Unknown.
  • TP-DCS 0x11 is Class 1 : bit 4 enables the class, and bits 1 and 0 select Class 1, ME-specific.
  • The time zone counts quarters of an hour : GMT + 5 hours is sent as 20 quarters in the last octet of TP-SCTS.

Tips from 3GPP Sepcification

The captures above work only if the network accepted SMS over SGs when the UE attached. The quotes below come from 24.301 and are updated to v20.0.0 where the wording has changed. They show what the UE must send at attach and which NAS procedure carries the SMS.

For further information on these special NAS TRANSPORT Message, you can refer to 24.301

[TS 24.301, clause 8.2.4.13 - Voice domain preference and UE's usage setting]

This IE shall be included in WB-S1 mode if and only if the UE supports:

- CS fallback and SMS over SGs; or

- if the UE is configured to support IMS voice, but does not support 1xCS fallback.

NOTE : If this IE is not configured in the NAS message from UE, Network may not allow SMS over SGs. Following is an example of the NAS message from UE configuring this IE.

< ATTACH REQUEST, excerpt > NAS capture, shortened with ... in the original. Field values are from a live capture, not from the specification.

ESM message container:
    Protocol discriminator = 0x2 (EPS Session Management)
    EPS bearer identity = 0
    Procedure transaction identity = 94
    Message type = 0xd0 (PDN connectivity request)
    Request type = 1 (initial request)
    ...
  Last visited registered TAI:
    ...
  Voice domain preference and UE's usage setting = 0x07 
                                    (IMS PS voice preferred, CS Voice as secondary, Data centric)
  ...

The value 0x07 decodes with 24.008 v20.0.0 clause 10.5.5.28, to which 24.301 clause 9.9.3.44 refers. Bit 3 is the UE's usage setting, and 1 means data centric. Bits 2 and 1 are the voice domain preference for E-UTRAN, and 11 means IMS PS voice preferred, CS Voice as secondary. The decoder text in the capture matches this bit pattern.

[TS 24.301, clause 5.6.3.1]

The purpose of the transport of NAS messages procedure is to carry SMS messages in an encapsulated form between the MME and the UE. The procedure may be initiated by the UE or the network and can only be used when the UE is attached for EPS services and non-EPS services or for EPS services and "SMS only", and the UE is in EMM-CONNECTED mode.

[TS 24.301, clause 5.6.3.3]

The network initiates the procedure by sending a DOWNLINK NAS TRANSPORT message. When receiving the DOWNLINK NAS TRANSPORT message, the EMM entity in the UE shall forward the contents of the NAS message container IE to the SMS entity.

[TS 24.301, clause 9.9.3.22]

This information element is used to encapsulate the SMS messages transferred between the UE and the network. The NAS message container information element is coded as shown in figure 9.9.3.22.1 and table 9.9.3.22.1.

The NAS message container is a type 4 information element with a minimum length of 4 octets and a maximum length of 253 octets.

The answer to the combined attach comes back in the ATTACH ACCEPT. 24.301 clause 9.9.3.0A defines the Additional update result IE, with the values no additional information, CS Fallback not preferred and SMS only. So when a UE gets SMS but no CS fallback, check this IE before you look for a problem in the SMS itself.

  • The IE is conditional : 24.301 v20.0.0 includes it if and only if the UE supports CS fallback and SMS over SGs, or IMS voice without 1xCS fallback.
  • "SMS only" is enough for SMS : the transport of NAS messages procedure also works for a UE attached for EPS services and "SMS only".
  • The ATTACH ACCEPT shows the result : the Additional update result IE tells you whether the network accepted SMS only or preferred no CS fallback.

Reference

  • 3GPP TS 23.272 v20.0.0 - clause 8.2 Short Message Service
  • 3GPP TS 24.301 v20.0.0 - clause 5.6.3, 8.2.4.13, 9.9.3.0A, 9.9.3.22, 9.9.3.44
  • 3GPP TS 24.011 v20.0.0 - clause 6.3.1 TPDU relaying, clause 10.1 Timers
  • 3GPP TS 23.040 v20.0.0 - clause 9.2.3.11 TP-Service-Centre-Time-Stamp
  • 3GPP TS 23.038 v20.0.0 - SMS Data Coding Scheme
  • 3GPP TS 24.008 v20.0.0 - clause 10.5.5.28 Voice domain preference and UE's usage setting