4G/LTE - Timers

 

 

 

Timer - EPS Mobility Management - UE Side

 

EMM timers decide how long the UE waits for an answer from the MME, and what the UE does when the MME does not answer. They also decide how often an idle UE performs a periodic tracking area update. So when a UE repeats an attach every 10 seconds, or stops all attempts for 12 minutes, one of these timers is the reason.

I'll start with the UE side table from 24.301, and then explain how to read it, which values the network can change, and what later releases have added. The network side timers are on a separate page, Timer - EPS Mobility Management - NW Side.

EMM Timers on the UE Side

Let's look at the table itself first. Each row is one timer, and the columns follow the life of that timer. They give the EMM state it runs in, the event that starts it, the event that stops it, and the action the UE takes on expiry.

Following table comes from 24.301 - 10.2 Timers of EPS mobility management (Table 10.2.1: EPS mobility management timers – UE side)

 

TIMER
NUM.

TIMER
VALUE

STATE

CAUSE OF START

NORMAL STOP

ON
EXPIRY

T3402

Default 12 min.
NOTE 1

EMM DEREGISTERED
EMM REGISTERED

At attach failure and the attempt counter is equal to 5.
At tracking area updating failure
and the attempt counter is equal to 5.

ATTACH REQUEST sent TRACKING AREA UPDATE REQUEST sent

Initiation of the attach procedure or TAU procedure

T3410

15s

EMMREGISTEREDINITIATED

ATTACH REQUEST sent

ATTACH ACCEPT received
ATTACH REJECT received

Start T3411 or T3402 as described in subclause 5.5.1.2.6

T3411

10s

EMM DEREGISTERED.
ATTEMPTING TO-ATTACH EMM REGISTERED.
ATTEMPTING TO-UPDATE

At attach failure due to lower layer failure, T3410 timeout or attach rejected with other EMM cause values than those treated in subclause 5.5.1.2.5.
At tracking area updating failure due to lower layer failure, T3430 timeout or TAU rejected with other EMM cause values than those treated in subclause 5.5.3.2.5.

ATTACH REQUEST sent
TRACKING AREA UPDATE REQUEST sent

Retransmission of the ATTACH REQUEST or TRACKING AREA UPDATE REQUEST

T3412

Default 54 min.
NOTE 2
NOTE 5

EMM REGISTERED

In EMM-REGISTERED, when
EMM-CONNECTED mode is left.

When entering state EMM DEREGISTERED
or
when entering EMM-CONNECTED mode.

Initiation of the periodic TAU procedure

T3416

30s

EMM REGISTERED INITIATED
EMM REGISTERED
EMM DEREGISTERED INITIATED
EMM-TRACKINGAREA UPDATING INITIATED

EMM-SERVICE REQUEST INITIATED

RAND and RES stored as a result of a UMTS authentication challenge

SECURITY MODE COMMAND received
SERVICE REJECT received
TRACKING AREA UPDATE ACCEPT received
AUTHENTICATION REJECT received
AUTHENTICATION FAILURE sent
EMM DEREGISTERED
or
EMM-NULL entered

Delete the stored RAND and RES

T3417

5s

EMM-SERVICEREQUESTINITIATED

SERVICE REQUEST sent EXTENDED SERVICE
REQUEST sent in case f and g in subclause 5.6.1.1

Bearers have been set up
SERVICE REJECT received

Abort the procedure

T3417ext

10s

EMM-SERVICEREQUESTINITIATED

EXTENDED SERVICE REQUEST sent in case d in
subclause 5.6.1.1
EXTENDED SERVICE REQUEST sent in case e in
subclause 5.6.1.1 and the CSFB response was set to "CS fallback
accepted by the UE"

Inter-system change from S1 mode to A/Gb mode or Iu mode is completed
Inter-system change from S1 mode to A/Gb mode or Iu mode is failed
SERVICE REJECT received

Abort the procedure

T3418

20s

EMM REGISTEREDINITIATED
EMM REGISTERED
EMM-TRACKINGARE AUPDATINGINITIATED
EMM DEREGISTEREDINITIATED
EMM-SERVICEREQUESTINITIATED

AUTHENTICATION FAILURE (EMM cause = #20 "MAC failure"
or #26 "non-EPS authentication unacceptable") sent

AUTHENTICATION REQUEST received

On first expiry, the UE should consider the network as false

T3420

15s

EMM REGISTERED INITIATED
EMM REGISTERED
EMM DEREGISTERED INITIATED
EMM-TRACKINGAREA UPDATING INITIATED
EMM-SERVICE REQUEST INITIATED

AUTHENTICATION FAILURE (cause = #21 "synch failure") sent

AUTHENTICATION REQUEST received

On first expiry, the UE should consider the network as false

T3421

15s

EMM DEREGISTERED INITIATED

DETACH REQUEST sent

DETACH ACCEPT received

Retransmission of DETACH REQUEST

T3423

NOTE 3

EMM REGISTERED

T3412 expires while the UE is in EMM-REGISTERED.NO-CELLAVAILABLE
and ISR is activated.

When entering state EMM DEREGISTERED
or
when entering EMM-CONNECTED mode.

Set TIN to "P-TMSI"

T3430

15s

EMM-TRACKING AREA UPDATING INITIATED

TRACKING AREA UPDATE
REQUEST sent

TRACKING AREA UPDATE ACCEPT received
TRACKING AREA UPDATE REJECT received

Start T3411 or T3402 as described in subclause 5.5.3.2.6

T3440

10s

EMM REGISTERED INITIATED
EMM-TRACKING AREA UPDATING INITIATED
EMM DEREGISTERED INITIATED
EMM-SERVICE REQUEST INITIATED
EMM REGISTERED

ATTACH REJECT, DETACH REQUEST, TRACKING AREA
UPDATE REJECT with any of the EMM cause #11, #12, #13, #14 or #15 SERVICE REJECT received with any of the EMM cause #11,#12, #13 or #15
TRACKING AREA UPDATE ACCEPT received after the UE
sent TRACKING AREA UPDATE REQUEST in EMMIDLE mode with no "active" flag

Signalling connection released
Bearers have been set up

Release the signalling connection and
proceed as described in subclause 5.3.1.2

T3442

NOTE 4

EMM REGISTERED

SERVICE REJECT received with EMM cause #39 "CS domain temporarily not available"

TRACKING AREA UPDATE REQUEST sent

None

           

Note 1

The default value of this timer is used if the network does not indicate another value in an EMM signalling procedure.

Note 2

The value of this timer is provided by the network operator during the attach and tracking area updating procedures. (This Timer value is set in Attach Accept message as well).

Note 3

The value of this timer may be provided by the network in the ATTACH ACCEPT message and TRACKING AREA UPDATE ACCEPT message. The default value of this timer is identical to the value of T3412.

Note 4

The value of this timer is provided by the network operator when a service request for CS fallback is rejected by the network with EMM cause #39 "CS domain temporarily not available".

Note 5

The default value of this timer is used if the network does not indicate a value in the TRACKING AREA UPDATE ACCEPT message and the UE does not have a stored value for this timer.

(This Timer value is set in Attach Accept message as well).

 

Four of the timer names in the first column link to pages of their own: T3402, T3410, T3411 and T3418. Those pages go through the procedure around each timer in more detail. The NOTE rows at the bottom of the table belong to the TIMER VALUE column. The section on network controlled timer values explains them.

  • Each timer runs only in the EMM states of its STATE column : for example, T3410 runs only in EMM-REGISTERED-INITIATED, that is, while an attach is in progress.
  • The start event is almost always a message the UE sends : the normal stop event is the answer the UE expects from the MME.
  • The ON EXPIRY column is where the UE behaviour changes : check it first when a log shows a retransmission or an aborted procedure.

How to read the timer table ?

The table is dense, and it is easier to read once the timers are sorted by the job they do. Most of them fall into five groups, and each group answers a different question about the UE.

The first group supervises a request from the UE. T3410 runs after ATTACH REQUEST, T3430 after TRACKING AREA UPDATE REQUEST, T3421 after DETACH REQUEST, and T3417 after SERVICE REQUEST. Each one starts when the UE sends the request and stops when the MME answers. On expiry, the UE retransmits DETACH REQUEST, aborts the service request, or counts an attach or TAU failure.

The second group decides when to try again. The UE keeps an attempt counter for attach and for TAU. While the counter is below 5, a failure starts T3411, and the UE retries after 10 seconds. When the counter reaches 5, the UE starts T3402 instead, and waits 12 minutes by default. This is why a UE that fails five attaches in a row often looks silent for a long time in a log.

The third group is periodic. T3412 starts when the UE leaves EMM-CONNECTED mode, and its expiry triggers a periodic TAU. T3423 is its partner for ISR. It starts when T3412 expires while ISR is activated and the UE cannot perform the TAU, for example in EMM-REGISTERED.NO-CELL-AVAILABLE. On expiry of T3423, the UE sets TIN to "P-TMSI".

The fourth group protects authentication. T3416 limits how long the UE keeps a stored RAND and RES. T3418 and T3420 start when the UE sends AUTHENTICATION FAILURE, and on their first expiry the UE considers the network as false.

The fifth group handles the end of a connection and CS fallback. T3440 gives the network time to release the signalling connection after a reject or a TAU without the "active" flag. T3417ext supervises EXTENDED SERVICE REQUEST for CS fallback. T3442 starts on SERVICE REJECT with cause #39. While it runs, the UE does not send another EXTENDED SERVICE REQUEST for mobile originating CS fallback, except for an emergency call.

  • A short timer usually guards a single message : T3410, T3417, T3421 and T3430 are 15 seconds or less, because each one waits for one answer.
  • A long timer usually controls the load on the network : T3402 and T3412 run for minutes, because they decide how often a UE may signal at all.
  • T3411 and T3402 share one attempt counter : the counter value tells you which one the UE starts after a failure.
  • T3442 blocks only mobile originating CS fallback : an emergency call and a TRACKING AREA UPDATE REQUEST are still allowed while it runs.

Which timer values does the network set for the UE ?

Several rows show NOTE instead of a number in the TIMER VALUE column. Those notes mean that the MME can replace the default value, or that the timer has no default value at all. So before comparing a log with the table, check which value the network actually sent.

The values travel in NAS messages as a GPRS timer IE. ATTACH REJECT uses the GPRS timer 2 format, which carries the same value octet with a length field in front of it. The table below lists where each network controlled value comes from, based on 24.301 v20.0.0.

 

Timer

Message that carries the value

If no value is sent

T3412

ATTACH ACCEPT - mandatory
TRACKING AREA UPDATE ACCEPT - optional

default 54 min, or the stored value

T3402

ATTACH ACCEPT, TRACKING AREA UPDATE ACCEPT, ATTACH REJECT

default 12 min

T3423

ATTACH ACCEPT, TRACKING AREA UPDATE ACCEPT

same value as T3412

T3442

SERVICE REJECT with EMM cause #39

not started

 

The GPRS timer IE is one octet of value. Bits 8 to 6 give the unit, and bits 5 to 1 give a binary value from 0 to 31. The unit is 2 seconds for 000, 1 minute for 001 and decihours, that is 6 minutes, for 010. The code 111 means that the timer is deactivated.

Let's decode two common values. The default T3412 of 54 minutes is 9 decihours, so the octet is unit 010 and value 01001, which is 0x49. The default T3402 of 12 minutes is unit 001 and value 01100, which is 0x2C. When 31 decihours is not long enough, the MME adds the T3412 extended value IE, which uses the GPRS timer 3 format and a longer unit.

The page Timer & Constants and RRC/NAS Message puts these NAS timers next to the RRC timers that come from SIB2.

  • T3412 is always set by the network : ATTACH ACCEPT must carry it, so the UE uses the 54 minute default only in the case of NOTE 5.
  • T3402 and T3423 fall back to a default : without a value from the network, T3402 uses 12 minutes and T3423 copies T3412.
  • T3442 has no default at all : the UE starts it only when SERVICE REJECT with cause #39 carries a non-zero value.
  • A deactivated T3412 means no periodic TAU : the unit code 111 switches the timer off rather than setting it to zero.

What has changed in later releases ?

The table above matches an early release of 24.301. It is a good starting point, but it is not the full list any more. 24.301 v20.0.0, Release 20, keeps every timer shown above and adds several new ones.

Some existing rows have changed first. Most supervision timers now have a second value, written in the table as WB-S1/CE mode. It applies in WB-S1 mode when the UE supports CE mode B, and in some satellite access types. In NB-S1 mode, the timer value is calculated as described in clause 4.7 of 24.301. The table below compares the two values for the timers shown on this page.

 

Timer

Value

Value in WB-S1/CE mode

T3410

15 s

85 s

T3416

30 s

48 s

T3417

5 s

51 s

T3418

20 s

38 s

T3420

15 s

33 s

T3421

15 s

45 s

T3430

15 s

77 s

T3440

10 s

34 s, only for case k of clause 5.3.1.2.1

 

Four more differences are worth knowing when you compare the table with a current log or a current specification. The first is that T3417ext now covers only case d of clause 5.6.1.1. Case e, the mobile terminating CS fallback with "CS fallback accepted by the UE", uses a new timer T3417ext-mt of 4 seconds. The second is that EMM cause #39 is now named "CS service temporarily not available", and T3442 starts only when its value is not zero. The third is that T3416 now starts on RAND and RES stored from an EPS authentication challenge, where the table says UMTS. The fourth is that T3440 now starts in EMM-DEREGISTERED as well, and for many more EMM cause values.

The new timers are listed below. Each one belongs to a feature added after Release 9, so a UE that does not support the feature never starts it.

 

Timer

Value

What it controls

T3417ext-mt

4 s

Supervises EXTENDED SERVICE REQUEST for mobile terminating CS fallback that the UE has accepted

T3444

12 hours, or the time left on T3242

eCall only mode: on expiry the UE performs the eCall inactivity procedure after an eCall over IMS

T3445

12 hours, or the time left on T3243

eCall only mode: the same, after a call to a non-emergency number for test or terminal reconfiguration

T3447

set by the network

Service gap control: while it runs, the UE does not start a connection for uplink user data

T3448

set by the network, or a random default of 15 to 30 min

Congestion control for user data sent via the control plane

T3449

5 s, 51 s in WB-S1/CE mode

Waits for SERVICE ACCEPT after bearers are set up or SECURITY MODE COMMAND is received

T3451, T3452

set as in clause 4.11.5.2

S&F satellite operation: NAS procedures over restricted S&F satellite E-UTRAN cells

 

24.301 also uses T3324, T3346, T3245 and T3247, but defines none of them in this table. Those four timers are defined in 24.008.

  • The timer names above are still valid : a current UE uses the same T3410, T3411, T3402 and T3412, so the table is still the right place to start.
  • CE mode and satellite access lengthen the supervision timers : T3410 grows from 15 to 85 seconds, because repetitions make one exchange much slower.
  • A timer missing from the table usually belongs to a newer feature : for example eCall only mode, service gap control or S&F satellite operation.
  • Check the release before you treat a log as wrong : a recent UE correctly uses T3417ext-mt and the new cause #39 name, although the table does not show them.

Reference

  • 3GPP TS 24.301 v20.0.0 - clause 10.2, Table 10.2.1, EPS mobility management timers - UE side, and clause 8.2, message contents
  • 3GPP TS 24.008 v20.0.0 - clause 10.5.7.3, GPRS Timer, and clause 10.5.7.4a, GPRS Timer 3