3GPP TS 24.008
3GPP TS 24.008
3GPP TS 24.008
3GPP TS 24.008
Technical Specification Group Core Network and Terminals;
Mobile radio interface Layer 3V10.6.1 (2012-03)
specification;
Core network protocols; Stage
Technical 3
Specification
(Release 10)
The present document has been developed within the 3rd Generation Partnership Project (3GPP TM) and may be further elaborated for the purposes of 3GPP.
The present document has not been subject to any approval process by the 3GPP Organisational Partners and shall not be implemented.
This Specification is provided for future development work within 3GPP only. The Organisational Partners accept no liability for any use of this
Specification.
Specifications and reports for implementation of the 3GPP TM system should be obtained via the 3GPP Organisational Partners' Publications Offices.
Release 10 2 3GPP TS 24.008 V10.6.1 (2012-03)
Keywords
UMTS, GSM, radio, layer 3, stage 3, network, LTE
3GPP
Postal address
Internet
http://www.3gpp.org
Copyright Notification
© 2012, 3GPP Organizational Partners (ARIB, ATIS, CCSA, ETSI, TTA, TTC).
All rights reserved.
UMTS™ is a Trade Mark of ETSI registered for the benefit of its members
3GPP™ is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners
LTE™ is a Trade Mark of ETSI currently being registered for the benefit of its Members and of the 3GPP
Organizational Partners
GSM® and the GSM logo are registered and owned by the GSM Association
3GPP
Release 10 3 3GPP TS 24.008 V10.6.1 (2012-03)
Contents
Foreword........................................................................................................................................................25
Introduction....................................................................................................................................................25
1 Scope....................................................................................................................................................26
1.1 Scope of the Technical Specification.................................................................................................................26
1.2 Application to the interface structures...............................................................................................................26
1.3 Structure of layer 3 procedures..........................................................................................................................26
1.4 Test procedures..................................................................................................................................................27
1.5 Use of logical channels in A/Gb mode..............................................................................................................27
1.6 Overview of control procedures........................................................................................................................27
1.6.1 List of procedures.........................................................................................................................................27
1.7 Applicability of implementations......................................................................................................................29
1.7.1 Voice Group Call Service (VGCS) and Voice Broadcast Service (VBS)....................................................29
1.7.2 General Packet Radio Service (GPRS)........................................................................................................29
1.7.2.1 Packet services in GSM (A/Gb mode only)...........................................................................................29
1.7.2.2 Packet services in Iu mode (Iu mode only)............................................................................................30
1.8 Handling of NAS signalling low priority indication.........................................................................................30
2 References............................................................................................................................................31
2.1 Definitions and abbreviations............................................................................................................................36
2.1.1 Random values.............................................................................................................................................37
2.1.2 Vocabulary...................................................................................................................................................37
3 Radio Resource management procedures.............................................................................................40
4 Elementary procedures for Mobility Management...............................................................................40
4.1 General...............................................................................................................................................................40
4.1.1 MM and GMM procedures..........................................................................................................................41
4.1.1.1 Types of MM and GMM procedures......................................................................................................41
4.1.1.1.1 Integrity Checking of Signalling Messages in the Mobile Station (Iu mode only)..........................42
4.1.1.1.1a Integrity protection for emergency call (Iu mode only)...................................................................44
4.1.1.2 MM-GMM co-ordination for GPRS MS's.............................................................................................45
4.1.1.2.1 GPRS MS operating in mode A or B in a network that operates in mode I.....................................45
4.1.1.2.2 GPRS MS operating in mode A or B in a network that operates in mode II or III...........................46
4.1.1.2A Coordination between GMM and EMM................................................................................................46
4.1.1.3 Core Network System Information for MM (Iu mode only).................................................................46
4.1.1.4 Core Network System Information for GMM (Iu mode only)...............................................................46
4.1.1.4.1 General..............................................................................................................................................46
4.1.1.4.2 Control of Network Mode of Operation I.........................................................................................47
4.1.1.5 Access class control...............................................................................................................................47
4.1.1.6 Specific requirements for MS configured to use timer T3245...............................................................48
4.1.1.7 Handling of NAS level mobility management congestion control........................................................48
4.1.2 MM sublayer states......................................................................................................................................49
4.1.2.1 MM sublayer states in the mobile station...............................................................................................49
4.1.2.1.1 Main states........................................................................................................................................49
4.1.2.1.2 Substates of the MM IDLE state......................................................................................................53
4.1.2.2 The update Status...................................................................................................................................55
4.1.2.3 MM sublayer states on the network side................................................................................................55
4.1.3 GPRS mobility management (GMM) sublayer states..................................................................................57
4.1.3.1 GMM states in the MS...........................................................................................................................57
4.1.3.1.1 Main states........................................................................................................................................57
4.1.3.1.2 Substates of state GMM-DEREGISTERED....................................................................................58
4.1.3.1.3 Substates of state GMM-REGISTERED..........................................................................................58
4.1.3.2 GPRS update status................................................................................................................................61
4.1.3.3 GMM mobility management states on the network side........................................................................61
4.1.3.3.1 Main States.......................................................................................................................................61
4.1.3.3.2 Substates of state GMM-REGISTERED..........................................................................................62
3GPP
Release 10 4 3GPP TS 24.008 V10.6.1 (2012-03)
4.2 Behaviour of the MS in MM Idle state, GMM-DEREGISTERED state and GMM-REGISTERED state
...........................................................................................................................................................................63
4.2.1 Primary Service State selection....................................................................................................................63
4.2.1.1 Selection of the Service State after Power On.......................................................................................63
4.2.1.2 Other Cases............................................................................................................................................64
4.2.2 Detailed Description of the MS behaviour in MM IDLE State...................................................................64
4.2.2.1 Service State, NORMAL SERVICE......................................................................................................64
4.2.2.2 Service State, ATTEMPTING TO UPDATE..........................................................................................65
4.2.2.3 Service State, LIMITED SERVICE.......................................................................................................65
4.2.2.4 Service State, NO IMSI..........................................................................................................................66
4.2.2.5 Service State, SEARCH FOR PLMN, NORMAL SERVICE................................................................66
4.2.2.6 Service State, SEARCH FOR PLMN....................................................................................................66
4.2.2.7 Service State, RECEIVING GROUP CALL (NORMAL SERVICE)...................................................67
4.2.2.8 Service State, RECEIVING GROUP CALL (LIMITED SERVICE)....................................................67
4.2.2.9 Service State, eCALL INACTIVE.........................................................................................................67
4.2.3 Service state when back to state MM IDLE from another state..................................................................68
4.2.4 Behaviour in state GMM-DEREGISTERED..............................................................................................68
4.2.4.1 Primary substate selection......................................................................................................................69
4.2.4.1.1 Selection of the substate after power on or enabling the MS's GPRS capability.............................69
4.2.4.1.2 Other Cases.......................................................................................................................................69
4.2.4.2 Detailed description of the MS behaviour in state GMM-DEREGISTERED.......................................70
4.2.4.2.1 Substate, NORMAL-SERVICE........................................................................................................70
4.2.4.2.2 Substate, ATTEMPTING-TO-ATTACH..........................................................................................70
4.2.4.2.3 Substate, LIMITED-SERVICE.........................................................................................................70
4.2.4.2.4 Substate, NO-IMSI...........................................................................................................................70
4.2.4.2.5 Substate, NO-CELL..........................................................................................................................71
4.2.4.2.6 Substate, PLMN-SEARCH..............................................................................................................71
4.2.4.2.7 Substate, ATTACH-NEEDED..........................................................................................................71
4.2.4.2.8 Substate, SUSPENDED (A/Gb mode only).....................................................................................71
4.2.4.3 Substate when back to state GMM-DEREGISTERED from another GMM state................................71
4.2.5 Behaviour in state GMM-REGISTERED....................................................................................................71
4.2.5.1 Detailed description of the MS behaviour in state GMM-REGISTERED............................................72
4.2.5.1.1 Substate, NORMAL-SERVICE........................................................................................................72
4.2.5.1.2 Substate, SUSPENDED (A/Gb mode only).....................................................................................72
4.2.5.1.3 Substate, UPDATE-NEEDED..........................................................................................................72
4.2.5.1.4 Substate, ATTEMPTING-TO-UPDATE...........................................................................................72
4.2.5.1.5 Substate, NO-CELL-AVAILABLE..................................................................................................73
4.2.5.1.6 Substate, LIMITED-SERVICE.........................................................................................................73
4.2.5.1.7 Substate, ATTEMPTING-TO-UPDATE-MM..................................................................................73
4.2.5.1.8 Substate, PLMN-SEARCH..............................................................................................................73
4.3 MM common procedures...................................................................................................................................73
4.3.1 TMSI reallocation procedure.......................................................................................................................74
4.3.1.1 TMSI reallocation initiation by the network..........................................................................................74
4.3.1.2 TMSI reallocation completion by the mobile station.............................................................................74
4.3.1.3 TMSI reallocation completion in the network.......................................................................................74
4.3.1.4 Abnormal cases......................................................................................................................................75
4.3.2 Authentication procedure.............................................................................................................................75
4.3.2a Authentication procedure used for a UMTS authentication challenge..................................................75
4.3.2b Authentication Procedure used for a GSM authentication challenge.....................................................76
4.3.2.1 Authentication request by the network...................................................................................................76
4.3.2.2 Authentication response by the mobile station.......................................................................................76
4.3.2.3 Authentication processing in the network..............................................................................................77
4.3.2.3a 128-bit circuit-switched GSM ciphering key.........................................................................................77
4.3.2.4 Ciphering key sequence number............................................................................................................77
4.3.2.5 Authentication not accepted by the network..........................................................................................78
4.3.2.5.1 Authentication not accepted by the MS............................................................................................79
4.3.2.6 Abnormal cases......................................................................................................................................79
4.3.2.6.1 MS behaviour towards a network that has failed the authentication procedure...............................82
4.3.2.7 Handling of keys at intersystem change from Iu mode to A/Gb mode..................................................82
4.3.2.7a Use of established security contexts.......................................................................................................83
4.3.2.8 Handling of keys at intersystem change from A/Gb mode to Iu mode..................................................84
3GPP
Release 10 5 3GPP TS 24.008 V10.6.1 (2012-03)
4.3.2.9 Void........................................................................................................................................................84
4.3.2.10 Derivation of keys at SRVCC handover from S1 mode.........................................................................84
4.3.2.10.1 PDN connection with integrity protection........................................................................................84
4.3.2.10.2 PDN connection without integrity protection...................................................................................85
4.3.2.11 Derivation of keys at SRVCC handover from Iu mode to Iu mode.......................................................85
4.3.2.11.1 PDN connection with integrity protection........................................................................................85
4.3.2.11.2 PDN connection without integrity protection...................................................................................86
4.3.2.12 Derivation of keys at SRVCC handover from Iu mode to A/Gb mode..................................................86
4.3.2.12.1 PDN connection with integrity protection........................................................................................86
4.3.2.12.2 PDN connection without integrity protection...................................................................................87
4.3.3 Identification procedure...............................................................................................................................87
4.3.3.1 Identity request by the network..............................................................................................................88
4.3.3.2 Identification response by the mobile station.........................................................................................88
4.3.3.3 Abnormal cases......................................................................................................................................88
4.3.4 IMSI detach procedure.................................................................................................................................88
4.3.4.0 General...................................................................................................................................................88
4.3.4.1 IMSI detach initiation by the mobile station..........................................................................................89
4.3.4.2 IMSI detach procedure in the network...................................................................................................89
4.3.4.3 IMSI detach completion by the mobile station......................................................................................89
4.3.4.4 Abnormal cases......................................................................................................................................89
4.3.5 Abort procedure...........................................................................................................................................90
4.3.5.1 Abort procedure initiation by the network.............................................................................................90
4.3.5.2 Abort procedure in the mobile station....................................................................................................90
4.3.6 MM information procedure..........................................................................................................................90
4.3.6.1 MM information procedure initiation by the network............................................................................90
4.3.6.2 MM information procedure in the mobile station..................................................................................91
4.4 MM specific procedures....................................................................................................................................91
4.4.1 Location updating procedure.......................................................................................................................91
4.4.2 Periodic updating.........................................................................................................................................93
4.4.3 IMSI attach procedure..................................................................................................................................94
4.4.4 Generic Location Updating procedure.........................................................................................................94
4.4.4.1 Location updating initiation by the mobile station.................................................................................94
4.4.4.1a Network Request for Additional mobile station Capability Information...............................................94
4.4.4.2 Identification request from the network.................................................................................................94
4.4.4.3 Authentication by the network...............................................................................................................95
4.4.4.4 Security mode setting by the network....................................................................................................95
4.4.4.5 Attempt Counter.....................................................................................................................................95
4.4.4.6 Location updating accepted by the network...........................................................................................95
4.4.4.7 Location updating not accepted by the network.....................................................................................97
4.4.4.8 Release of RR connection after location updating.................................................................................98
4.4.4.9 Abnormal cases on the mobile station side............................................................................................99
4.4.4.10 Abnormal cases on the network side....................................................................................................101
4.4.5 Void............................................................................................................................................................101
4.4.6 Void............................................................................................................................................................101
4.4.7 eCall inactivity procedure..........................................................................................................................101
4.5 Connection management sublayer service provision......................................................................................102
4.5.1 MM connection establishment...................................................................................................................102
4.5.1.1 MM connection establishment initiated by the mobile station.............................................................102
4.5.1.2 Abnormal cases....................................................................................................................................106
4.5.1.3 MM connection establishment initiated by the network......................................................................107
4.5.1.3.1 Mobile Terminating CM Activity...................................................................................................107
4.5.1.3.2 Mobile Originating CM Activity $(CCBS)$..................................................................................108
4.5.1.3.3 Paging response in Iu mode (Iu mode only)...................................................................................109
4.5.1.3.4 Paging response for CS fallback.....................................................................................................109
4.5.1.4 Abnormal cases....................................................................................................................................110
4.5.1.5 MM connection establishment for emergency calls.............................................................................110
4.5.1.5a MM connection establishment for emergency calls for CS fallback...................................................110
4.5.1.6 Call re-establishment............................................................................................................................111
4.5.1.6.1 Call re-establishment, initiation by the mobile station...................................................................111
4.5.1.6.2 Abnormal cases...............................................................................................................................113
4.5.1.7 Forced release during MO MM connection establishment..................................................................113
3GPP
Release 10 6 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 7 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 8 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 9 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 10 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 11 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 12 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 13 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 14 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.7 Disconnect..................................................................................................................................................324
9.3.7.1 Disconnect (network to mobile station direction)................................................................................324
9.3.7.1.1 Facility............................................................................................................................................324
9.3.7.1.2 Progress indicator...........................................................................................................................324
9.3.7.1.3 User-user.........................................................................................................................................324
9.3.7.1.4 Allowed actions $(CCBS)$............................................................................................................324
9.3.7.2 Disconnect (mobile station to network direction)................................................................................325
9.3.7.2.1 Facility............................................................................................................................................325
9.3.7.2.2 User-user.........................................................................................................................................325
9.3.7.2.3 SS version.......................................................................................................................................325
9.3.8 Emergency setup........................................................................................................................................325
9.3.8.1 Bearer capability..................................................................................................................................326
9.3.8.2 Stream Identifier...................................................................................................................................326
9.3.8.3 Supported Codecs.................................................................................................................................326
9.3.8.4 Emergency category.............................................................................................................................326
9.3.9 Facility.......................................................................................................................................................326
9.3.9.1 Facility (network to mobile station direction)......................................................................................326
9.3.9.2 Facility (mobile station to network direction)......................................................................................327
9.3.9.2.1 SS version.......................................................................................................................................327
9.3.10 Hold............................................................................................................................................................328
9.3.11 Hold Acknowledge.....................................................................................................................................328
9.3.12 Hold Reject................................................................................................................................................328
9.3.13 Modify........................................................................................................................................................329
9.3.13.1 Low layer compatibility.......................................................................................................................329
9.3.13.2 High layer compatibility.......................................................................................................................329
9.3.13.3 Reverse call setup direction..................................................................................................................329
9.3.13.4 Void......................................................................................................................................................330
9.3.13.5 Network-initiated Service Upgrade indicator.......................................................................................330
9.3.14 Modify complete........................................................................................................................................330
9.3.14.1 Low layer compatibility.......................................................................................................................330
9.3.14.2 High layer compatibility.......................................................................................................................330
9.3.14.3 Reverse call setup direction..................................................................................................................330
9.3.15 Modify reject..............................................................................................................................................330
9.3.15.1 Low layer compatibility.......................................................................................................................331
9.3.15.2 High layer compatibility.......................................................................................................................331
9.3.16 Notify.........................................................................................................................................................331
9.3.17 Progress......................................................................................................................................................331
9.3.17.1 User-user..............................................................................................................................................332
9.3.17.2 Progress indicator.................................................................................................................................332
9.3.17a CC-Establishment $(CCBS)$....................................................................................................................332
9.3.17a.1 Void......................................................................................................................................................333
9.3.17a.2 Setup container.....................................................................................................................................333
9.3.17b CC-Establishment confirmed $(CCBS)$...................................................................................................333
9.3.17b.1 Repeat indicator....................................................................................................................................333
9.3.17b.2 Bearer capability 1 and bearer capability 2..........................................................................................334
9.3.17b.3 Cause....................................................................................................................................................334
9.3.17b.4 Supported Codecs.................................................................................................................................334
9.3.18 Release.......................................................................................................................................................334
9.3.18.1 Release (network to mobile station direction)......................................................................................334
9.3.18.1.1 Cause..............................................................................................................................................334
9.3.18.1.2 Second cause...................................................................................................................................334
9.3.18.1.3 Facility............................................................................................................................................335
9.3.18.1.4 User-user.........................................................................................................................................335
9.3.18.2 Release (mobile station to network direction)......................................................................................335
9.3.18.2.1 Cause..............................................................................................................................................335
9.3.18.2.2 Second cause...................................................................................................................................335
9.3.18.2.3 Facility............................................................................................................................................335
9.3.18.2.4 User-user.........................................................................................................................................336
9.3.18.2.5 SS version.......................................................................................................................................336
9.3.18a Recall $(CCBS)$........................................................................................................................................336
9.3.18a.1 Recall Type...........................................................................................................................................336
3GPP
Release 10 15 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.18a.2 Facility..................................................................................................................................................336
9.3.19 Release complete........................................................................................................................................336
9.3.19.1 Release complete (network to mobile station direction)......................................................................336
9.3.19.1.1 Cause..............................................................................................................................................337
9.3.19.1.2 Facility............................................................................................................................................337
9.3.19.1.3 User-user.........................................................................................................................................337
9.3.19.2 Release complete (mobile station to network direction)......................................................................337
9.3.19.2.1 Cause..............................................................................................................................................338
9.3.19.2.2 Facility............................................................................................................................................338
9.3.19.2.3 User-user.........................................................................................................................................338
9.3.19.2.4 SS version.......................................................................................................................................338
9.3.20 Retrieve......................................................................................................................................................338
9.3.21 Retrieve Acknowledge...............................................................................................................................339
9.3.22 Retrieve Reject...........................................................................................................................................339
9.3.23 Setup..........................................................................................................................................................340
9.3.23.1 Setup (mobile terminated call establishment)......................................................................................340
9.3.23.1.1 BC repeat indicator.........................................................................................................................341
9.3.23.1.2 Bearer capability 1 and bearer capability 2....................................................................................342
9.3.23.1.3 Facility............................................................................................................................................342
9.3.23.1.4 Progress indicator...........................................................................................................................342
9.3.23.1.4a Called party BCD number..............................................................................................................342
9.3.23.1.5 Called party subaddress..................................................................................................................342
9.3.23.1.6 LLC repeat indicator.......................................................................................................................342
9.3.23.1.7 Low layer compatibility I...............................................................................................................342
9.3.23.1.8 Low layer compatibility II..............................................................................................................342
9.3.23.1.9 HLC repeat indicator......................................................................................................................342
9.3.23.1.10 High layer compatibility i...............................................................................................................342
9.3.23.1.11 High layer compatibility ii..............................................................................................................343
9.3.23.1.12 User-user.........................................................................................................................................343
9.3.23.1.13 Redirecting party BCD number......................................................................................................343
9.3.23.1.14 Redirecting party subaddress..........................................................................................................343
9.3.23.1.15 Priority............................................................................................................................................343
9.3.23.1.16 Alert $(Network Indication of Alerting in the MS)$......................................................................343
9.3.23.1.17 Network Call Control Capabilities.................................................................................................343
9.3.23.1.18 Cause of No CLI.............................................................................................................................343
9.3.23.1.19 Backup bearer capability................................................................................................................343
9.3.23.2 Setup (mobile originating call establishment)......................................................................................343
9.3.23.2.1 BC repeat indicator.........................................................................................................................344
9.3.23.2.2 Facility............................................................................................................................................345
9.3.23.2.3 LLC repeat indicator.......................................................................................................................345
9.3.23.2.4 Low layer compatibility I...............................................................................................................345
9.3.23.2.5 Low layer compatibility II..............................................................................................................345
9.3.23.2.6 HLC repeat indicator......................................................................................................................345
9.3.23.2.7 High layer compatibility i...............................................................................................................345
9.3.23.2.8 High layer compatibility ii..............................................................................................................345
9.3.23.2.9 User-user.........................................................................................................................................345
9.3.23.2.10 SS version.......................................................................................................................................345
9.3.23.2.11 CLIR suppression...........................................................................................................................345
9.3.23.2.12 CLIR invocation.............................................................................................................................346
9.3.23.2.13 CC Capabilities...............................................................................................................................346
9.3.23.2.14 Stream Identifier.............................................................................................................................346
9.3.23.2.15 Bearer capability 1 and bearer capability 2....................................................................................346
9.3.23.2.16 Supported Codecs...........................................................................................................................346
9.3.23.2.17 Redial..............................................................................................................................................346
9.3.23a Start CC $(CCBS)$....................................................................................................................................346
9.3.23a.1 CC Capabilities....................................................................................................................................346
9.3.24 Start DTMF................................................................................................................................................347
9.3.25 Start DTMF Acknowledge.........................................................................................................................347
9.3.25.1 Keypad facility.....................................................................................................................................347
9.3.26 Start DTMF reject......................................................................................................................................347
9.3.27 Status..........................................................................................................................................................348
3GPP
Release 10 16 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 17 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 18 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 19 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 20 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 21 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 22 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 23 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 24 3GPP TS 24.008 V10.6.1 (2012-03)
Annex I (informative): GPRS specific cause values for GPRS Session Management...................609
I.1 Causes related to nature of request.....................................................................................................609
I.2 Causes related to invalid messages.....................................................................................................611
Annex J (informative): Algorithm to encode frequency list information elements.......................613
Annex K (informative): Default Codings of Information Elements................................................614
K.1 Common information elements...........................................................................................................614
K.2 Radio Resource management information elements...........................................................................614
K.3 Mobility management information elements......................................................................................614
K.4 Call control information elements......................................................................................................615
Annex L (normative): Establishment cause (Iu mode only)..........................................................617
L.1 Mapping of NAS procedure to RRC establishment cause(Iu mode only)...........................................617
Annex M (normative): Additional Requirements for backward compatibility with PCS 1900
for NA revision 0 ME..................................................................................620
Annex N (normative): Ranking of reject causes for Location Registration (MM and GMM)
in a shared network....................................................................................620
Annex O (normative): 3GPP capability exchange protocol...........................................................621
O.1 Scope..................................................................................................................................................621
O.2 User-user protocol contents................................................................................................................622
O.3 Information element identifier............................................................................................................622
O.4 Information elements..........................................................................................................................623
O.4.1 Personal ME identifier.....................................................................................................................................623
O.4.2 Radio environment capability..........................................................................................................................624
O.4.3 UE capability version......................................................................................................................................624
O.4.4 IM Status..........................................................................................................................................................625
O.5 Handling of unknown, unforeseen, and erroneous protocol data........................................................626
O.5.1 General.............................................................................................................................................................626
O.5.2 Not supported IEs, unknown IEIs....................................................................................................................626
O.5.3 Repeated IEs....................................................................................................................................................626
O.5.4 Syntactically incorrect IEs...............................................................................................................................627
O.5.5 Semantically incorrect IEs...............................................................................................................................627
3GPP
Release 10 25 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 26 3GPP TS 24.008 V10.6.1 (2012-03)
Foreword
This Technical Specification has been produced by the 3rd Generation Partnership Project (3GPP).
The contents of the present document are subject to continuing work within the TSG and may change following formal
TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an
identifying change of release date and an increase in version number as follows:
Version x.y.z
where:
y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections,
updates, etc.
z the third digit is incremented when editorial only changes have been incorporated in the document.
Introduction
The present document includes references to features which are not part of the Phase 2+ Release 96 of the GSM
Technical specifications. All subclauses which were changed as a result of these features contain a marker (see table
below) relevant to the particular feature.
The following table lists all features that were introduced after GSM Release 96.
Feature Designator
BA Range IE handling $(impr-BA-range-handling)$
Advanced Speech Call Item $(ASCI)$
Call Completion Busy Subscriber $(CCBS)$
Mobile Assisted Frequency Allocation $(MAFA)$
Network Indication of Alerting in MS $(NIA)$
3GPP
Release 10 27 3GPP TS 24.008 V10.6.1 (2012-03)
1 Scope
The present document specifies the procedures used at the radio interface core network protocols within the 3rd
generation mobile telecommunications system and the digital cellular telecommunications system.
It specifies the procedures used at the radio interface (Reference Point Um or Uu, see 3GPP TS 24.002 [15] or
3GPP TS 23.002 [127]) for Call Control (CC), Mobility Management (MM), and Session Management (SM).
When the notations for "further study" or "FS" or "FFS" are present in this TS they mean that the indicated text is not a
normative portion of the present document.
These procedures are defined in terms of messages exchanged over the control channels of the radio interface. The
control channels are described in 3GPP TS 44.003 [16] and 3GPP TS 25.301 [128].
The structured functions and procedures of this protocol and the relationship with other layers and entities are described
in general terms in 3GPP TS 24.007 [20].
3GPP TS 24.010 [21] contains functional procedures for support of supplementary services.
3GPP TS 24.011 [22] contains functional procedures for support of point-to-point short message services.
3GPP TS 24.012 [23] contains functional description of short message - cell broadcast.
3GPP TS 44.060 [76] contains procedures for radio link control and medium access control (RLC/MAC) of packet data
physical channels.
3GPP TS 44.071 [23a] contains functional descriptions and procedures for support of location services.
NOTE: "layer 3" includes the functions and protocols described in the present document. The terms "data link
layer" and "layer 2" are used interchangeably to refer to the layer immediately below layer 3.
The basic building blocks are "elementary procedures" provided by the protocol control entities of the three sublayers,
i.e. radio resource management, mobility management and connection management sublayer.
Complete layer 3 transactions consist of specific sequences of elementary procedures. The term "structured procedure"
is used for these sequences.
3GPP
Release 10 28 3GPP TS 24.008 V10.6.1 (2012-03)
i) Broadcast Control CHannel (BCCH): downlink only, used to broadcast Cell specific information;
ii) Synchronization CHannel (SCH): downlink only, used to broadcast synchronization and BSS identification
information;
iii) Paging CHannel (PCH): downlink only, used to send page requests to Mobile Stations (MSs);
iv) Random Access CHannel (RACH): uplink only, used to request a Dedicated Control CHannel;
v) Access Grant CHannel (AGCH): downlink only, used to allocate a Dedicated Control CHannel;
vii)Fast Associated Control CHannel (FACCH): bi-directional, associated with a Traffic CHannel;
viii) Slow Associated Control CHannel (SACCH): bi-directional, associated with a SDCCH or a Traffic CHannel;
ix) Cell Broadcast CHannel (CBCH): downlink only used for general (not point to point) short message
information;
x) Notification CHannel (NCH): downlink only, used to notify mobile stations of VBS (Voice Broadcast Service)
calls or VGCS (Voice Group Call Service) calls.
Two service access points are defined on signalling layer 2 which are discriminated by their Service Access Point
Identifiers (SAPI) (see 3GPP TS 44.006 [19]):
Layer 3 selects the service access point, the logical control channel and the mode of operation of layer 2
(acknowledged, unacknowledged or random access, see 3GPP TS 44.005 [18] and 3GPP TS 44.006 [19]) as required
for each individual message.
3GPP
Release 10 29 3GPP TS 24.008 V10.6.1 (2012-03)
b) Clause 5 specifies elementary procedures for circuit switched Call Control comprising the following elementary
procedures:
- miscellaneous procedures:
3GPP
Release 10 30 3GPP TS 24.008 V10.6.1 (2012-03)
The elementary procedures can be combined to form structured procedures. Examples of such structured procedures are
given in clause 7. This part of the present document is only provided for guidance to assist implementations.
Clause 8 specifies actions to be taken on various error conditions and also provides rules to ensure compatibility with
future enhancements of the protocol.
1.7.1 Voice Group Call Service (VGCS) and Voice Broadcast Service (VBS)
Voice Group Call Service and Voice Broadcast Service are applicable in A/Gb mode only.
For mobile stations supporting the Voice Group Call Service or the Voice Broadcast Service, it is explicitly mentioned
throughout the present document if a certain procedure is applicable only for such a service and, if necessary, how
mobile stations not supporting such a service shall behave.
For VGCS and VBS, the following possible mobile station implementations exist:
- support of talking in voice group calls (VGCS talking. This always includes the implementation for VGCS
listening);
- support of originating a voice group call (VGCS originating. This always includes the implementation for VGCS
talking).
Apart from the explicitly mentioned combinations, all possible combinations are optional and supported by the present
document.
The related terms are used in the present document, if information on these implementation options is required.
A GPRS MS may operate in one of the following MS operation modes, see 3GPP TS 23.060 [74]:
- MS operation mode A;
3GPP
Release 10 31 3GPP TS 24.008 V10.6.1 (2012-03)
- MS operation mode B; or
- MS operation mode C.
The MS operation mode depends on the services that the MS is attached to, i.e., only GPRS or both GPRS and non-
GPRS services, and upon the MS's capabilities to operate GPRS and other GSM services simultaneously. Mobile
stations that are capable to operate GPRS services are referred to as GPRS MSs.
NOTE: Other GSM technical specifications may refer to the MS operation modes A, B, and C as GPRS class-A
MS, GPRS class-B MS, and GPRS class-C MS.
It should be noted that it is possible that for a GPRS MS, the GMM procedures currently described in the ETS do not
support combinations of VGCS, VBS and GPRS. The possible interactions are not studied yet.
- PS mode of operation.
The terms 'PS/CS mode of operation' and 'PS mode of operation' are not used in the present document with some
exceptions. Instead the terms 'MS operation mode A' and 'MS operation mode C' are used.
In network operation mode I and II (see 3GPP TS 23.060 [74]), an MS in PS/CS mode of operation shall use the same
procedures as for a GPRS MS operating in MS operation mode A, unless it is explicitly stated for A/Gb mode only or
Iu mode only.
In network operation mode I and II, an MS in PS mode of operation shall use the same procedures as for a GPRS MS
operating in MS operation mode C, unless it is explicitly stated for A/Gb mode only or Iu mode only.
NOTE: Network operation mode III is not applicable for Iu mode, see 3GPP TS 23.060 [74].
- the MS has a PDN connection for emergency bearer services established and is performing mobility
management procedures, or is establishing a PDN connection for emergency bearer services;
The network may use the NAS signalling low priority indication for NAS level mobility management congestion
control on a per core network node basis and APN based congestion control.
If the NAS signalling low priority indication is provided in an ACTIVATE PDP CONTEXT REQUEST message, the
SGSN stores the NAS signalling low priority indication within the default PDP context activated due to this request.
2 References
The following documents contain provisions which, through reference in this text, constitute provisions of the present
document.
3GPP
Release 10 32 3GPP TS 24.008 V10.6.1 (2012-03)
References are either specific (identified by date of publication, edition number, version number, etc.) or
non-specific.
For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including
a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same
Release as the present document.
[1] Void.
[2] Void.
[3] 3GPP TS 22.002: "Circuit Bearer Services (BS) supported by a Public Land Mobile Network
(PLMN)".
[4] 3GPP TS 22.003: "Teleservices supported by a Public Land Mobile Network (PLMN)".
[6] Void.
[8a] 3GPP TS 22.001: "Principles of circuit telecommunication services supported by a Public Land
Mobile Network (PLMN)".
[9a] 3GPP TS 23.108: "Mobile radio interface layer 3 specification core network protocols; Stage 2
(structured procedures)".
[11] Void.
[12a] ETSI ES 201 235-2, v1.2.1: "Specification of Dual Tone Multi-Frequency (DTMF); Transmitters
and Receivers; Part 2: Transmitters".
[14] 3GPP TS 23.122: "Non-Access-Stratum functions related to Mobile Station (MS) in idle mode".
[15] 3GPP TS 24.002: "GSM-UMTS Public Land Mobile Network (PLMN) access reference
configuration".
[16] 3GPP TS 44.003: "Mobile Station - Base Station System (MS - BSS) interface; Channel structures
and access capabilities".
[17] Void.
[19] 3GPP TS 44.006: "Mobile Station - Base Station System (MS - BSS) interface; Data Link (DL)
layer specification".
3GPP
Release 10 33 3GPP TS 24.008 V10.6.1 (2012-03)
[20] 3GPP TS 24.007: "Mobile radio interface signalling layer 3; General aspects".
[21] 3GPP TS 24.010: "Mobile radio interface layer 3; Supplementary services specification; General
aspects".
[22] 3GPP TS 24.011: "Point-to-Point (PP) Short Message Service (SMS) support on mobile radio
interface".
[23] 3GPP TS 24.012: "Short Message Service Cell Broadcast (SMSCB) support on the mobile radio
interface".
[23a] 3GPP TS 44.071: "Location Services (LCS); Mobile radio interface layer 3 specification."
[23b] 3GPP TS 44.031 "Location Services LCS); Mobile Station (MS) - Serving Mobile Location Centre
(SMLC); Radio Resource LCS Protocol (RRLP)".
[24] 3GPP TS 24.080: "Mobile radio Layer 3 supplementary service specification; Formats and
coding".
[26] Void.
[27] 3GPP TS 24.083: "Call Waiting (CW) and Call Hold (HOLD) supplementary services; Stage 3".
[29] Void.
[30] Void.
[31] Void.
[32] 3GPP TS 45.002: "Multiplexing and multiple access on the radio path".
[35] Void.
[36] 3GPP TS 27.001: "General on Terminal Adaptation Functions (TAF) for Mobile Stations (MS)".
[36a] 3GPP TS 27.060: "Mobile Station (MS) supporting Packet Switched Services ".
[38] 3GPP TS 29.007: "General requirements on interworking between the Public Land Mobile
Network (PLMN) and the Integrated Services Digital Network (ISDN) or Public Switched
Telephone Network (PSTN)".
[40] Void.
[41] ISO/IEC 646 (1991): "Information technology - ISO 7-bit coded character set for information
interchange".
[42] ISO/IEC 6429: "Information technology - Control functions for coded character sets".
[43] ISO 8348 (1987): "Information technology -- Open Systems Interconnection -- Network Service
Definition".
3GPP
Release 10 34 3GPP TS 24.008 V10.6.1 (2012-03)
[44] ITU-T Recommendation E.163: "Numbering plan for the international telephone service".
[45] ITU-T Recommendation E.164: "The international public telecommunication numbering plan".
[46] ITU-T Recommendation E.212: "The international identification plan for mobile terminals and
mobile users".
[47] ITU-T Recommendation F.69 (1993): "The international telex service - Service and operational
provisions of telex destination codes and telex network identification codes".
[49] ITU-T Recommendation I.440 (1989): "ISDN user-network interface data link layer - General
aspects".
[50] ITU-T Recommendation I.450 (1989): "ISDN user-network interface layer 3 General aspects".
[51] ITU-T Recommendation I.500 (1993): "General structure of the ISDN interworking
recommendations".
[52] ITU-T Recommendation T.50: "International Reference Alphabet (IRA) (Formerly International
Alphabet No. 5 or IA5) - Information technology - 7-bit coded character set for information
interchange".
[53] ITU Recommendation Q.931: ISDN user-network interface layer 3 specification for basic control".
[54] ITU-T Recommendation V.21: "300 bits per second duplex modem standardized for use in the
general switched telephone network".
[55] ITU-T Recommendation V.22: "1200 bits per second duplex modem standardized for use in the
general switched telephone network and on point-to-point 2-wire leased telephone-type circuits".
[56] ITU-T Recommendation V.22bis: "2400 bits per second duplex modem using the frequency
division technique standardized for use on the general switched telephone network and on point-
to-point 2-wire leased telephone-type circuits".
[57] Void.
[58] ITU-T Recommendation V.26ter: "2400 bits per second duplex modem using the echo cancellation
technique standardized for use on the general switched telephone network and on point-to-point 2-
wire leased telephone-type circuits".
[59] ITU-T Recommendation V.32: "A family of 2-wire, duplex modems operating at data signalling
rates of up to 9600 bit/s for use on the general switched telephone network and on leased
telephone-type circuits".
[60] ITU-T Recommendation V.110: "Support by an ISDN of data terminal equipments with V-Series
type interfaces".
[61] ITU-T Recommendation V.120: "Support by an ISDN of data terminal equipment with V-Series
type interfaces with provision for statistical multiplexing".
[62] ITU-T Recommendation X.21: "Interface between Data Terminal Equipment (DTE) and Data
Circuit-terminating Equipment (DCE) for synchronous operation on public data networks".
[63] Void.
[64] Void.
[65] ITU-T Recommendation X.30: "Support of X.21, X.21 bis and X.20 bis based Data Terminal
Equipments (DTEs) by an Integrated Services Digital Network (ISDN)".
[66] ITU-T Recommendation X.31: "Support of packet mode terminal equipment by an ISDN".
[67] Void.
[68] Void.
3GPP
Release 10 35 3GPP TS 24.008 V10.6.1 (2012-03)
[69] ITU-T Recommendation X.121: "International numbering plan for public data networks".
[70] ETSI ETS 300 102-1: "Integrated Services Digital Network (ISDN); User-network interface
layer 3; Specifications for basic call control".
[71] ETSI ETS 300 102-2: "Integrated Services Digital Network (ISDN); User-network interface
layer 3; Specifications for basic call control; Specification Description Language (SDL)
diagrams".
[72] ISO/IEC 10646: "Information technology -- Universal Multiple-Octet Coded Character Set
(UCS)".
[73] 3GPP TS 22.060: "General Packet Radio Service (GPRS); Service Description; Stage 1".
[74] 3GPP TS 23.060: "General Packet Radio Service (GPRS); Service Description; Stage 2".
[75] Void.
[76] 3GPP TS 44.060: "General Packet Radio Service (GPRS); Mobile Station (MS) - Base Station
System (BSS) interface; Radio Link Control/Medium Access Control (RLC/MAC) protocol".
[76b] 3GPP TS 44.318: "Generic Access Network (GAN); Mobile GAN interface layer 3 specification;
Stage 3".
[78] 3GPP TS 44.065: "Mobile Station (MS) - Serving GPRS Support Node (SGSN); Subnetwork
Dependent Convergence Protocol (SNDCP)".
[78a] 3GPP TS 44.064: "Mobile Station - Serving GPRS Support Node (MS-SGSN) Logical Link
Control (LLC) Layer Specification".
[79] ITU Recommendation I.460: "Multiplexing, rate adaption and support of existing interfaces".
[80] 3GPP TS 26.111: "Codec for Circuit Switched Multimedia Telephony Service; Modifications to
H.324".
[82] 3GPP TS 43.022: "Functions related to Mobile Station (MS) in idle mode and group receive
mode".
[83] 3GPP TS 26.103: "Speech Codec List for GSM and UMTS".
[84] 3GPP TS 44.018: "Mobile radio interface layer 3 specification, Radio Resource Control Protocol".
[85] 3GPP TS 48.008: "Mobile-services Switching Centre – Base Station System (MSC – BSS)
interface; layer 3 specification".
[86] 3GPP TS 48.018: "General Packet Radio Service (GPRS); Base Station System (BSS) - Serving
GPRS Support Node (SGSN); BSS GPRS Protocol (BSSGP)".
[88] 3GPP TS 23.067: "enhanced Multi-Level Precedence and Pre-emption service (eMLPP); Stage 2".
[88a] 3GPP TS 23.093: "Technical realization of Completion of Calls to Busy Subscriber (CCBS);
Stage 2".
[89] 3GPP TS 22.042: "Network Identity and Time Zone (NITZ), Stage 1".
[91] 3GPP TS 44.056: "GSM Cordless Telephony System (CTS), (Phase 1) CTS Radio Interface Layer
3 Specification".
3GPP
Release 10 36 3GPP TS 24.008 V10.6.1 (2012-03)
[93] 3GPP TS 26.226: "Cellular Text Telephone Modem (CTM), General Description "
[94] 3GPP TS 23.236: "Intra Domain Connection of RAN Nodes to Multiple CN Nodes"
[95] 3GPP TS 24.229: "IP Multimedia Call Control Protocol based on SIP and SDP"
[97] 3GPP TS 23.172: "UDI/RDI Fallback and Service Modification; Stage 2".
[98] 3GPP TS 25.304: "UE Procedures in Idle Mode and Procedures for Cell Reselection in Connected
Mode"
[99] IETF RFC 3513 (April 2003): "Internet Protocol Version 6 (IPv6) Addressing Architecture".
[102] IETF RFC 1661 (July 1994): "The Point-to-Point Protocol (PPP)".
[103] IETF RFC 3232 (January 2002): "Assigned Numbers: RFC 1700 is Replaced by an On-line
Database".
[104] 3GPP TS 23.034: "High Speed Circuit Switched Data (HSCSD) – Stage 2".
[106] 3GPP TS 23.246: "Multimedia Broadcast/Multicast Service (MBMS); Architecture and Functional
Description".
[107] IETF RFC 3376 (October 2002): "Internet Group Management Protocol, Version 3".
[108] IETF RFC 2710 (October 1999): "Multicast Listener Discovery (MLD) for IPv6".
[110] 3GPP TS 25.346: "Introduction of the Multimedia Broadcast Multicast Service (MBMS) in the
Radio Access Network"
[113] 3GPP TS 43.129: "Packet-switched handover for GERAN A/Gb mode; Stage 2".
[116] 3GPP TS 24.279: "Combining Circuit Switched (CS) and IP Multimedia Subsystem (IMS)
services, stage 3"
[117] ITU-T Recommendation H.324 Amendment 1: "New Annex K "Media Oriented Negotiation
Acceleration Procedure" and associated changes to Annex".
[118] ITU-T Recommendation H.324 Amendment 2: "New Annex L on text conversation and associated
changes; corrections and clarifications to Annex K".
[120] 3GPP TS 24.301: "Non-Access-Stratum (NAS) protocol for Evolved Packet System (EPS);
Stage 3".
[121] 3GPP TS 36.304: "Evolved Universal Terrestrial Radio Access (E-UTRA); User Equipment (UE)
procedures in idle mode".
3GPP
Release 10 37 3GPP TS 24.008 V10.6.1 (2012-03)
[124] 3GPP TS 24.303: "Mobility management based on Dual-Stack Mobile IPv6; Stage 3".
[125] 3GPP TS 24.327: "Mobility between 3GPP WLAN Interworking and 3GPP systems; GPRS and
3GPP I-WLAN aspects; Stage 3".
[126] 3GPP TS 23.216: "Single Radio Voice Call Continuity (SRVCC); Stage 2".
[129] 3GPP TS 36.331: "Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource
Control (RRC); Protocol specification".
[130] 3GPP TS 29.061: "Interworking between the Public Land Mobile Network (PLMN) supporting
packet based services and Packet Data Networks (PDN)".
[132] 3GPP TS 23.090: "Unstructured Supplementary Service Data (USSD); Stage 2".
[133] 3GPP TS 23.272: "Circuit Switched Fallback in Evolved Packet System; Stage 2".
[134] 3GPP TS 24.167: "3GPP IMS Management Object (MO); Stage 3".
[135] 3GPP TS 24.368: "Non-Access Stratum (NAS) configuration Management Object (MO)".
[136] 3GPP TS 24.237: "IP Multimedia Subsystem (IMS) Service Continuity; Stage 3".
[137] IETF RFC 3261 (June 2002): "SIP: Session Initiation Protocol".
[139] IETF RFC 3633 (December 2003): "IPv6 Prefix Options for Dynamic Host Configuration
Protocol (DHCP) version 6".
It is required that there is a low probability that two MSs in the same conditions (including the case of two MSs of the
same type from the same manufacturer) will choose the same value. Moreover, it is required that, if it happens that two
MSs in similar conditions choose the same value, the probability of their choices being identical at the next occasion is
the same as if their first choices had been different.
3GPP
Release 10 38 3GPP TS 24.008 V10.6.1 (2012-03)
The meaning of such a specification is that any statistical test for these values, done on a series of similar events, will
obtain a result statistically compatible with the specified distribution. This shall hold even in the cases where the tests
are conducted with a subset of possible events, with some common parameters. Moreover, basic tests of independence
of the values within the series shall pass.
Data against which correlation with the values shall not be found are the protocol state, or the IMSI, or identities or
other unrelated information broadcast by the network, or the current TDMA frame number.
2.1.2 Vocabulary
For the purposes of the present document, the following terms and definitions apply:
- A GSM security context is established and stored in the MS and the network as a result of a successful
execution of a GSM authentication challenge. The GSM security context for the CS domain consists of the GSM
ciphering key and the ciphering key sequence number. The GSM security context for the PS domain consists of
the GPRS GSM ciphering key and the GPRS ciphering key sequence number.
- A UMTS security context is established and stored in the MS and the network as a result of a successful
execution of a UMTS authentication challenge. The UMTS security context for the CS domain consists of the
UMTS ciphering key, the UMTS integrity key, the GSM ciphering key, the ciphering key sequence number and
the GSM Kc128 (if an A5 ciphering algorithm that requires a 128-bit ciphering key is in use). The UMTS security
context for the PS domain consists of the GPRS UMTS ciphering key, the GPRS UMTS integrity key, the GPRS
GSM ciphering key, the GPRS ciphering key sequence number and the GPRS GSM Kc128 (if a GEA ciphering
algorithm that requires a 128-bit ciphering key is in use).
- An MS is attached for emergency bearer services if it has successfully completed an attach for emergency
bearer services or if it has only a PDN connection for emergency bearer services established.
- idle mode: In this mode, the mobile station is not allocated any dedicated channel; it listens to the CCCH and the
BCCH;
- group receive mode: (only applicable for mobile stations supporting VGCS listening or VBS listening) In this
mode, the mobile station is not allocated a dedicated channel with the network; it listens to the downlink of a
voice broadcast channel or voice group call channel allocated to the cell. Occasionally, the mobile station has to
listen to the BCCH of the serving cell as defined in 3GPP TS 43.022 [82] and 3GPP TS 45.008 [34];
- dedicated mode: In this mode, the mobile station is allocated at least two dedicated channels, only one of them
being a SACCH;
- group transmit mode: (only applicable for mobile stations supporting VGCS talking) In this mode, one mobile
station of a voice group call is allocated two dedicated channels, one of them being a SACCH. These channels
can be allocated to one mobile station at a time but to different mobile stations during the voice group call;
- packet idle mode: (only applicable for mobile stations supporting GPRS) In this mode, mobile station is not
allocated any radio resource on a packet data physical channel; it listens to the PBCCH and PCCCH or, if those
are not provided by the network, to the BCCH and the CCCH, see 3GPP TS 44.060 [76].
- packet transfer mode: (only applicable for mobile stations supporting GPRS) In this mode, the mobile station is
allocated radio resource on one or more packet data physical channels for the transfer of LLC PDUs.
- main DCCH: In Dedicated mode and group transmit mode, only two channels are used as DCCH, one being a
SACCH, the other being a SDCCH or a FACCH; the SDCCH or FACCH is called here "the main DCCH";
- A channel is activated if it can be used for transmission, in particular for signalling, at least with UI frames. On
the SACCH, whenever activated, it must be ensured that a contiguous stream of layer 2 frames is sent;
- A TCH is connected if circuit mode user data can be transferred. A TCH cannot be connected if it is not
activated. A TCH which is activated but not connected is used only for signalling, i.e. as a DCCH;
- The data link of SAPI 0 on the main DCCH is called the main signalling link. Any message specified to be sent
on the main signalling link is sent in acknowledged mode except when otherwise specified;
3GPP
Release 10 39 3GPP TS 24.008 V10.6.1 (2012-03)
- The term "to establish" a link is a short form for "to establish the multiframe mode" on that data link. It is
possible to send UI frames on a data link even if it is not established as soon as the corresponding channel is
activated. Except when otherwise indicated, a data link layer establishment is done without an information field.
- "channel set" is used to identify TCHs that carry related user information flows, e.g., in a multislot
configuration used to support circuit switched connection(s), which therefore need to be handled together.
- A temporary block flow (TBF) is a physical connection used by the two RR peer entities to support the uni-
directional transfer of LLC PDUs on packet data physical channels, see 3GPP TS 44.060 [76].
- RLC/MAC block: A RLC/MAC block is the protocol data unit exchanged between RLC/MAC entities, see
3GPP TS 44.060 [76].
The three different network operation modes I, II, and III are defined in 3GPP TS 23.060 [74].
The network operation mode shall be indicated as system information. For proper operation, the network
operation mode should be the same in each cell of one routing area.
The three different GPRS MS operation modes A, B, and C are defined in 3GPP TS 23.060 [74].
- RR connection: A RR connection is a dedicated physical circuit switched domain connection used by the two
RR or RRC peer entities to support the upper layers' exchange of information flows.
- PS signalling connection is a peer to peer Iu mode connection between MS and CN packet domain node.
- Inter-System change is a change of an MS from A/Gb mode to Iu mode of operation or vice versa. or from S1
mode to A/Gb mode or Iu mode of operation.
- GPRS: Packet Services for systems which operate the Gb or Iu-PS interfaces.
- The label (A/Gb mode only) indicates this section or paragraph applies only to a system which operates in A/Gb
mode, i.e. with a functional division that is in accordance with the use of an A or a Gb interface between the
radio access network and the core network. For multi system case this is determined by the current serving radio
access network.
- The label (Iu mode only) indicates this section or paragraph applies only to a system which operates in Iu mode.
The Iu mode includes UTRAN and GERAN Iu modes, i.e. with a functional division that is in accordance with
the use of an Iu-CS or Iu-PS interface between the radio access network and the core network. For multi system
case this is determined by the current serving radio access network.
- In A/Gb mode,... Indicates this paragraph applies only to a system which operates in A/Gb mode. For multi
system case this is determined by the current serving radio access network.
- In Iu mode,... Indicates this paragraph applies only to a system which operates in Iu mode. The Iu mode
includes both UTRAN Iu mode and GERAN Iu mode. For multi system case this is determined by the current
serving radio access network.
- In A/Gb mode and GERAN Iu mode,... Indicates this paragraph applies only to a system which operates in
A/Gb mode or GERAN Iu mode. For multi system case this is determined by the current serving radio access
network.
3GPP
Release 10 40 3GPP TS 24.008 V10.6.1 (2012-03)
- In UTRAN Iu mode,... Indicates this paragraph applies only to a system which operates in UTRAN Iu mode.
For multi system case this is determined by the current serving radio access network.
- In a shared network,... Indicates this paragraph applies only to a shared network. For the definition of shared
network see 3GPP TS 23.122 [14].
NOTE: According to this definition, a multi-operator core network (MOCN) with common GERAN is not
considered a shared network in 3GPP TS 23.122 [14] and in the present specification.
- Multi-Operator Core Network (MOCN) with common GERAN: a network in which different core network
operators are connected to a shared GERAN broadcasting only a single, common PLMN identity.
- A default PDP context is a PDP context activated by the PDP context activation procedure that establishes a
PDN connection. The default PDP context remains active during the lifetime of the PDN connection.
- A PDP context for emergency bearer services is a default PDP context which was activated with request type
"emergency", or any secondary PDP contexts associated to this default PDP context.
- Non-emergency PDP context: any PDP context which is not a PDP context for emergency bearer services.
- MS, Mobile Station. The present document makes no distinction between MS and UE.
- Cell Notification is an (optimised) variant of the Cell Update Procedure which uses the LLC NULL frame for
cell change notification which does not trigger the restart of the READY timer
- DTM: dual transfer mode, see 3GPP TS 44.018 [84] and 3GPP TS 43.055 [87]
- The term "eCall only" applies to a mobile station which is in the eCall only mode, as described in
3GPP TS 22.101 [8].
- "removal of eCall only restriction" means that all the limitations as described in 3GPP TS 22.101 [8] for the
eCall only mode do not apply any more.
- Access domain selection: The process to select whether the CS domain or the IMS/IP-CAN is used to transmit
the call control signalling between MS and core network. Definition derived from 3GPP TS 23.221 [131].
- NAS level mobility management congestion control: Congestion control mechanism in the network in
mobility management. "NAS level mobility management congestion control" consists of "subscribed APN based
congestion control" and "general NAS level mobility management congestion control".
- General NAS level mobility management congestion control: The type of congestion control that is applied at
a general overload or congestion situation in the network, e.g. lack of processing resources.
- Subscribed APN based congestion control: Congestion control in mobility management where the network can
reject attach requests from MSs with a certain APN in the subscription.
- Mapped P-TMSI: a P-TMSI which is mapped from a GUTI previously allocated to the MS by an MME.
Mapping rules are defined in 3GPP TS 23.003 [10]. Definition derived from 3GPP TS 23.401 [122].
- Native P-TMSI: a P-TMSI previously allocated by an SGSN. Definition derived from 3GPP TS 23.401 [122].
For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.401 [122],
subclause 3.2, apply:
3GPP
Release 10 41 3GPP TS 24.008 V10.6.1 (2012-03)
For the purposes of the present document, the following terms and definitions given in 3GPP TS 24.301 [120] apply:
CSG cell
CSG ID
CSG selection
LIPA PDN connection
PDN connection for emergency bearer services
S1 mode
For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.272 [133] apply:
CS fallback
SMS over SGs
For the purposes of the present document, the following terms and definitions given in 3GPP TS 33.401 [123] apply:
For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.251 [109] apply:
Common PLMN
Network Sharing non-supporting MS: see non-supporting UE.
Network Sharing supporting MS: see supporting UE.
For the purposes of the present document, the following terms and definitions given in 3GPP TS 23.122 [14] apply:
Suitable Cell
4.1 General
This clause describes the procedures used for mobility management for non-GPRS services and for GPRS-services at
the radio interface (Reference Point Um and Uu).
The main function of the Mobility Management sublayer is to support the mobility of user terminals, such as informing
the network of its present location and providing user identity confidentiality.
A further function of the MM sublayer is to provide connection management services to the different entities of the
upper Connection Management (CM) sublayer (see 3GPP TS 24.007 [20]).
- MM procedures for non-GPRS services (performed by the MM entity of the MM sublayer); and
- GMM procedures for GPRS services (performed by the GMM entity of the MM sublayer), see
3GPP TS 24.007 [20].
3GPP
Release 10 42 3GPP TS 24.008 V10.6.1 (2012-03)
All the MM procedures described in this clause can only be performed if a RR connection has been established between
the MS and the network. Else, the MM sublayer has to initiate the establishment of a RR connection (see
3GPP TS 44.018 [84] subclause 3.3 and 3GPP TS 25.331 [23c]).
In A/Gb mode, the GMM procedures described in this clause, use services provided by the RR sublayer without prior
RR connection establishment.
In Iu mode: all the GMM procedures described in this clause can only be performed if a PS signalling connection has
been established between the MS and the network. Else, the GMM sublayer has to initiate the establishment of a PS
signalling connection (see 3GPP TS 25.331 [23c]).
GMM procedures are mandatory and applicable only for GPRS MSs and networks supporting those MSs. For GPRS
MSs which are IMSI attached for both GPRS and non-GPRS services, some MM procedures are replaced by GMM
combined procedures provided that the network operates in network operation mode I, i.e. is supporting combined
GMM procedures. GMM combined procedures are not applicable for the GPRS MS operation mode C but are
mandatory for the GPRS MS operation modes A and B and networks supporting network operation mode I, see
3GPP TS 23.060 [74].
1) MM common procedures:
A MM common procedure can always be initiated whilst a RR connection exists. The procedures belonging to
this type are:
- authentication procedure;
- identification procedure;
- MM information procedure;
- abort procedure.
However, abort procedure is used only if an MM connection is being established or has already been established i.e. not
during MM specific procedures or during IMSI detach procedure, see subclause 4.3.5.
2) MM specific procedures:
These procedures are used to establish, maintain and release a MM connection between the mobile station and the
network, over which an entity of the upper CM layer can exchange information with its peer. A MM connection
3GPP
Release 10 43 3GPP TS 24.008 V10.6.1 (2012-03)
establishment can only be performed if no MM specific procedure is running. More than one MM connection may be
active at the same time.
Depending on how they can be initiated, three types of GMM procedures can be distinguished:
In Iu mode, a GMM common procedure can always be initiated whilst a PS signalling connection exists.
- GPRS identification;
- GPRS information.
Initiated by the network and used to detach the IMSI in the network for GPRS services and/or non-GPRS
services and to release a GMM context:
- GPRS detach.
Initiated by the MS and used to attach or detach the IMSI in the network for GPRS services and/or non-
GPRS services and to establish or release a GMM context:
Initiated by the MS and used to establish a secure connection to the network and/or to request the resource
reservation for sending data:
Service Request.
The Service Request procedure can only be initiated if no MS initiated GMM specific procedure is ongoing.
4.1.1.1.1 Integrity Checking of Signalling Messages in the Mobile Station (Iu mode only)
In Iu mode only, integrity protected signalling is mandatory with one exception regarding emergency calls (see
subclause 4.1.1.1.1a). In Iu mode only, all layer 3 protocols shall use integrity protected signalling once the security
mode procedure has been successfully activated in the network and the MS. Integrity protection of all layer 3 signalling
messages is the responsibility of lower layers. It is the network which activates integrity protection. This is done using
the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
The supervision that integrity protection is activated shall be the responsibility of the MM and GMM layer in the MS
(see 3GPP TS 33.102 [5a]). In order to do this, the lower layers shall provide the MM and GMM layer with an
indication on when the integrity protection is activated in the MS (i.e. one indication to the MM layer when a security
mode control procedure for the CS domain is processed successfully and one indication to the GMM layer when a
security mode control procedure for the PS domain is processed successfully).
3GPP
Release 10 44 3GPP TS 24.008 V10.6.1 (2012-03)
The CS and PS domains in the network and the MM and GMM layers in the MS, are not aware of whether integrity
protection has been started in the lower layers by the other domain. It is mandatory for the network to initiate one
security mode control procedure for the CS domain and one for the PS domain.
Except the messages listed below, no layer 3 signalling messages shall be processed by the receiving MM and GMM
entities or forwarded to the CM entities, unless the network has activated the integrity protection for that domain.
- MM messages:
- AUTHENTICATION REQUEST
- AUTHENTICATION REJECT
- IDENTITY REQUEST
- LOCATION UPDATING ACCEPT (at periodic location update with no change of location area or
temporary identity, and, any Per MS T3212 value is not changed)
- the CM SERVICE ACCEPT is the response to a CM SERVICE REQUEST with CM SERVICE TYPE
IE set to ‘emergency call establishment’
- ABORT
- GMM messages:
- IDENTITY REQUEST
- the MS performs periodic routing area updating with no change of routing area or temporary identity,
and the T3312 extended value and the Network feature support value are not changed;
- the GMM entity in the MS has received an ATTACH ACCEPT message with neither ciphering nor
integrity protection applied in response to an ATTACH REQUEST message with attach type set to
"emergency attach"; or
- the MS has performed intersystem change from S1 mode to Iu mode with a PDN connection for
emergency bearer services for which the "null integrity protection algorithm" EIA0 has been used
while in S1 mode.
- ATTACH ACCEPT, if the ATTACH ACCEPT is the response to an ATTACH REQUEST with attach type
set to "emergency attach".
3GPP
Release 10 45 3GPP TS 24.008 V10.6.1 (2012-03)
- the GMM entity in the MS has received an ATTACH ACCEPT message with neither ciphering nor
integrity protection applied in response to an ATTACH REQUEST message, with attach type set to
"emergency attach"; or
- the MS has performed intersystem change from S1 mode to Iu mode with a PDN connection for
emergency bearer services for which the "null integrity protection algorithm" EIA0 has been used
while in S1 mode.
- CC messages:
- the MM entity in the MS has received a CM SERVICE ACCEPT message with no ciphering or
integrity protection applied as response to a CM SERVICE REQUEST message, with CM SERVICE
TYPE set to ‘Emergency call establishment’ sent to the network.; or
- the MM connection was established locally due to the SRVCC handover of a PDN connection for
emergency bearer services for which the "null integrity protection algorithm" EIA0 has been used
while in S1 mode or for which integrity protection has not been activated while in Iu mode.
- SM messages:
- the GMM entity in the MS has received an ATTACH ACCEPT message with neither ciphering nor
integrity protection applied in response to an ATTACH REQUEST message, with attach type set to
"emergency attach"; or
- the MS has performed intersystem change from S1 mode to Iu mode with a PDN connection for
emergency bearer services for which the "null integrity protection algorithm" EIA0 has been used
while in S1 mode.
Once integrity protection is activated, the receiving layer 3 entity in the MS shall not process any other layer 3
signalling messages or any ATTACH ACCEPT message unless they have been successfully integrity checked by the
lower layers. If any signalling messages, having not successfully passed the integrity check, are received, then the lower
layers in the MS shall discard that message (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). If any layer 3
signalling message is received, in either PS or CS domains, as not integrity protected even though the integrity
protection has been activated in the MS by that domain in the network, then the lower layers shall discard this message
(see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
Integrity checking on the network side is performed by the RNC and is described in 3GPP TS 25.331 [23c] and
3GPP TS 44.118 [111].
For the establishment of a MM connection for an emergency call when no other MM connection is established (e.g. for
an emergency call initiated without a SIM/USIM no other MM connections can exist) the decision on whether or not to
apply the security procedures shall be made by the network as defined in the subclause "Emergency Call Handling" in
3GPP TS 33.102 [5a]. If the MM connection was established locally due to the SRVCC handover of a PDN connection
for emergency bearer services for which the "null integrity protection algorithm" EIA0 has been used while in S1 mode
or for which integrity protection has not been activated while in Iu mode, the network need not apply the security
procedures for this call.
For an attach for emergency bearer services, (e.g. initiated without a SIM/USIM) the decision on whether or not to
apply the security procedures shall be made by the network as defined in the subclause "Emergency Call Handling" in
3GPP TS 33.102 [5a]. After intersystem change from S1 mode to Iu mode with a PDN connection for emergency bearer
services for which the "null integrity protection algorithm" EIA0 has been used while in S1 mode, the network need not
apply the security procedures for this connection.
3GPP
Release 10 46 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: A GPRS MS operating in mode A or B in a network that operates in mode I, shall perform the combined
GPRS attach or routing area update procedure regardless the value of the ATT flag.
If a GPRS MS is operating in mode A or B in a network that operates in mode I the IMSI detach shall be performed by
the GMM using the combined GPRS detach procedure.
NOTE 2: A GPRS MS operating in mode A or B in a network that operates in mode I, shall perform the combined
GPRS detach procedure regardless the value of the ATT flag.
A GPRS MS operating in mode A or B in network that operates in mode I, shall use the combined GMM specific
procedures in place of the MM specific procedures unless the re-activation of the MM specific procedures is explicitly
described, so all conditions describing when to trigger an MM specific procedure listed in subclauses 4.3 and 4.4 shall
not apply.
A GPRS MS operating in mode A or B in a network that operates in mode I should not use any MM timers relating to
MM specific procedures, (e.g. T3210, T3211, T3212, T3213) unless the re-activation of the MM specific procedures is
explicitly described. If the MM timers are already running, the MS should not react on the expiration of the timers.
NOTE 3: Whenever GMM performs a combined GMM procedure, a GPRS MS enters the MM state MM
LOCATION UPDATING PENDING in order to prevent the MM from performing a location area
updating procedure.
If the authentication procedure is performed by MM and the authentication is rejected by the network (i.e. upon receive
of AUTHENTICATION REJECT), the MS shall in addition set the GPRS update status to GU3 ROAMING NOT
ALLOWED and shall, if available, delete the P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number stored. The SIM/USIM shall be considered as invalid for GPRS and non-GPRS services until switching off or
the SIM/USIM is removed. The MS shall abort any GMM procedure and shall enter state GMM-DEREGISTERED. If
S1 mode is supported in the MS, the MS shall handle the EMM parameters EPS update status, GUTI, last visited
registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the EPS authentication is not
accepted by the network.
If the PS or CS domain is barred because of domain specific access control, a GPRS MS operating in mode A or B in a
network that operates in mode I shall act as if in network operation mode II or III (depending on whether a PCCCH is
present in Gb-mode) and access to the barred domain shall be stopped entirely. If the MS detects that a domain is
barred, this shall not trigger any MM or GMM specific procedure.
A GPRS MS operating in mode A or B in a network that operates in mode I shall perform a normal location updating
procedure (in order to remove the Gs association in the MSC/VLR) when the following conditions are fulfilled:
- the GPRS MS has camped on a cell where the PS domain is barred and the CS domain is unbarred; and
- for the last attempt to update the registration of the location area a combined GMM procedure was performed.
Additionally the MS shall treat the expiry of T3312 when the PS domain changes from barred to unbarred, analogous to
the descriptions for the cases when the timer expires out of coverage or in a cell that does not support GPRS (see
subclause 4.7.2.2).
If timer T3312 expires and both the PS and CS domain are barred, then a GPRS MS operating in mode A or B in a
network that operates in mode I shall treat the expiry of T3312 when the GPRS MS detects that the PS or CS domain
becomes unbarred, analogous to the descriptions for the cases when the timer expires out of coverage (see
subclause 4.7.2.2).
3GPP
Release 10 47 3GPP TS 24.008 V10.6.1 (2012-03)
If the PS domain is barred and timer T3312 expires during an ongoing CS connection, then a GPRS MS operating in
mode A or B in a network that operates in mode I shall treat the expiry of T3312 when the MM state MM-IDLE is
entered, analogous to the descriptions for the cases when the timer expires out of coverage or in a cell that does not
support GPRS (see subclause 4.7.2.2), or in a cell where the PS domain is barred.
A GPRS MS operating in mode A or B in a network that operates in mode I shall perform a combined routing area
update procedure indicating "combined RA/LA updating with IMSI attach" (in order to establish the Gs association in
the MSC/VLR) when the following conditions are fulfilled:
- the GPRS MS detects that CS or PS domain or both change from barred to unbarred;
- as a result of the change of the domain specific barring status, both domains are unbarred; and
- for the last attempt to update the registration of the location area an MM specific procedure was performed (see
subclause 4.7.5.2.1) or for the last attempt to update the registration of the routing area a normal routing area
update was performed.
If the authentication procedure is performed by MM and the authentication is rejected by the network (i.e upon receive
of AUTHENTICATION REJECT), the MS shall in addition set the GPRS update status to GU3 ROAMING NOT
ALLOWED and shall, if available, delete the P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number stored. The SIM/USIM shall be considered as invalid for GPRS and non-GPRS services until switching off or
the SIM/USIM is removed. The MS shall abort any GMM procedure and shall enter state GMM-DEREGISTERED. If
S1 mode is supported in the MS, the MS shall handle the EMM parameters EPS update status, GUTI, last visited
registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the EPS authentication is not
accepted by the network.
If the PS or CS domain is barred because of domain specific access control, a GPRS MS operating in mode A or B in a
network that operates in mode II or III shall use the MM specific procedures or GMM specific procedures, respectively,
in the domain which is unbarred. If the MS detects that a domain changes from barred to unbarred, it shall behave as
specified in subclauses 4.3.4.4, 4.4.4.9, 4.5.1.2, 4.7.3.1.5, 4.7.4.1.4, 4.7.5.1.5, and 4.7.13.5.
At reception of new system information, the RRC layer in the MS delivers the contents of the CN common system
information and the CS domain specific system information to the MM layer in the MS.
The Core Network system information is included in specific information elements within some RRC messages sent to
MS (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). In the Core Network system information the Common
system information part and the CS domain specific system information part contains settings of parameters controlling
MM functionality. No MM messages contain the Core Network System Information.
4.1.1.4 Core Network System Information for GMM (Iu mode only)
4.1.1.4.1 General
In the network broadcast system information some of the system information is used by GMM.
At reception of new system information, the RRC layer in the MS delivers the contents of the CN common system
information and the PS domain specific system information to the GMM layer in the MS.
3GPP
Release 10 48 3GPP TS 24.008 V10.6.1 (2012-03)
The Core Network system information is included in specific information elements within some RRC messages sent to
MS (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). In the Core Network system information the Common
system information part and the PS domain specific system information part contains settings of parameters controlling
GMM functionality. No GMM messages contain the Core Network System Information.
- if the parameter "NMO_I_Behaviour" in the NAS configuration Management Object is set to the value of "1",
the bit 2 "NMO I" of system information as described in figure 10.5.1.12.3/table 10.5.1.12.3 is applied; or
- if the parameter "NMO_I_Behaviour" in the NAS configuration Management Object is set to the value of zero or
is not provisioned, the bit 1 "NMO" of system information as described in figure 10.5.1.12.3/table 10.5.1.12.3 is
applied.
The restriction can apply for access to both domains (common access class control or EAB, depending on EAB
configuration) or to one domain only (domain specific access control) (see 3GPP TS 23.122 [14]).
Additionally, the network can alleviate the access restriction in both domains or domain specifically, and allow
restricted mobile stations to respond to paging messages or to perform generic location updating, or GPRS attach or
routing area updating procedure.
A network operator can also restrict some MSs to access the network for location registration, although via common
access class control or domain specific access class control the MSs are permitted to access the network for other
purposes. Therefore, for each access to the network the mobile station shall determine from the information received via
the system information broadcast whether access is allowed or not:
- For paging response the mobile station shall evaluate the control information for common access control (as
specified in 3GPP TS 44.018 [84], 3GPP TS 44.060 [76], and 3GPP TS 25.331 [23c]), domain specific access
control (as specified in 3GPP TS 25.331 [23c]), and the specific control information for paging response (as
specified in 3GPP TS 25.331 [23c]; see "Paging Permission with Access Control").
- For generic location updating, GPRS attach and routing area updating procedures the mobile station shall
evaluate the control information for:
- common access control (as specified in 3GPP TS 44.018 [84], 3GPP TS 44.060 [76], and
3GPP TS 25.331 [23c]);
- specific control information for location registration (as specified in 3GPP TS 25.331 [23c]; see "Paging
Permission with Access Control"); and
The same control information shall also be taken into account, when the present document requires the mobile
station to initiate a generic location updating, or GPRS attach or routing area updating procedure when it detects
that a domain changes from barred to unbarred (see e.g. subclauses 4.1.1.2.1 and 4.1.1.2.2).
- For all other purposes the mobile station shall evaluate the control information for common access control as
specified in 3GPP TS 44.018 [84], 3GPP TS 44.060 [76], and 3GPP TS 25.331 [23c], the control information for
EAB (as specified in 3GPP TS 44.018 [84] and 3GPP TS 44.060 [76]) and domain specific access control (as
specified in 3GPP TS 25.331 [23c]).
In this version of the specification EAB is specified for A/Gb mode only.
3GPP
Release 10 49 3GPP TS 24.008 V10.6.1 (2012-03)
When the MS adds a PLMN identity to the "forbidden PLMN list" or the "forbidden PLMNs for GPRS service" list or
sets the SIM/USIM as invalid for non-GPRS services or GPRS services or both, and timer T3245 is not running, the MS
shall start timer T3245 with a random value, uniformly drawn from the range between 24h and 48h.
Upon expiry of the timer T3245, the MS shall erase the "forbidden PLMN list" and the "forbidden PLMNs for GPRS
service" list and set the SIM/USIM to valid for non-GPRS services and GPRS services.
If the MS is switched off when the timer T3245 is running, the MS shall behave as follows when the MS is switched on:
- let t1 be the time remaining for T3245 timeout at switch off and let t be the time elapsed between switch off and
switch on. If t1 is greater than t, then the timer shall be restarted with the value t1 – t. If t1 is equal to or less than
t, then the MS will follow the behaviour as defined in the paragraph above upon expiry of the timer T3245. If the
MS is not capable of determining t, then the MS shall restart the timer with the value t1.
Under NAS level mobility management congestion control the network may reject mobility management signalling
requests from MSs. The network should not reject requests for emergency bearer services and requests from high
priority users. When general NAS level mobility management congestion control is active, the network may reject
messages including the NAS signalling low priority indicator before rejecting messages without the NAS signalling low
priority indicator.
When subscribed APN based congestion control is active for a particular APN, the network may reject attach request
from MSs with subscription to this APN.
In mobility management the network may detect NAS signalling congestion. The network may start or stop performing
the subscribed APN based congestion control based on mobility management level criteria such as:
- rate of mobility management NAS messages from a group of MSs with a subscription to a particular APN
exceeds or falls below certain thresholds; or
When the NAS level mobility management congestion control is active, the network may include a value for the
mobility management back-off timer T3246 or T3346 in the reject messages. The MS starts the mobility management
backoff timer with the value received in the mobility management reject messages. To avoid that large numbers of MSs
simultaneously initiate deferred requests, the network should select the value for the mobility management backoff
timer for the rejected MSs so that timeouts are not synchronised.
For subscribed APN based congestion control the backoff timer value for a particular APN may be APN dependent.
If the MS is switched off when the timers T3246 or T3346 are running, the MS shall behave as follows for each of these
timers when the MS is switched on:
- let t1 be the time remaining untiltimeout at switch off and let t be the time elapsed between switch off and switch
on. If t1 is greater than t, then the timer shall be restarted with the value t1 – t. If t1 is equal to or less than t, then
the timer need not be restarted. If the MS is not capable of determining t, then the MS shall restart the timer with
the value t1.
If the MS enters a new PLMN which is not in the list of equivalent PLMNs, it shall stop timers T3246 and T3346, if
running, when initiating mobility management procedures in the new PLMN.
3GPP
Release 10 50 3GPP TS 24.008 V10.6.1 (2012-03)
The mobile station is inactive (e.g. power down). Important parameters are stored. Only manual action by the
user may transfer the MM sublayer to another state.
A location updating procedure has been started and the MM awaits a response from the network. The timer
T3210 is running.
The MM connection establishment has been started, and the MM awaits a response from the network. The
timer T3230 is running.
6 MM CONNECTION ACTIVE
The MM sublayer has a RR connection to its peer entity on the network side. One or more MM connections
are active.
The IMSI detach procedure has been started. The timer T3220 is running.
The MM sublayer has a RR connection to its peer entity on the network side. The Mobile Station has
received a CM SERVICE PROMPT message but has not yet responded $(CCBS)$.
The MM sublayer has a RR connection to its peer entity in the network, but no MM connection is
established. The mobile station is passive, awaiting further commands from the network. The timer T3240
may be running.
A location updating procedure has been rejected and RR connection release is awaited. The timer T3240 is
running.
3GPP
Release 10 51 3GPP TS 24.008 V10.6.1 (2012-03)
14
MS 18
W AI T F OR Re q u e st NULL a c ti v a te d A c ti v a te R R
R R C O N N E C TI O N R R c o n n e c tio n W AIT F OR
( M M C O N N E C TI O N) R R A C TI V E
S I M / US I M
i n s e r te d A t t a c h o r L o c a t io n
R R c o n n e c ti o n S tate s 3 , 5, 9 , U p d a te S I M / U S I M u p d a te n e e d e d
10 , 13 , 14 , 1 5
e s ta b lis he d M M - c o n n e c ti o n
A tta c h a n d L o c a ti o n
re q u e s t
M S d e a c tiv a te d u p d a te n o t n e e d e d Re q u e st
S e n d c m s e r vic e lo w la y e r
a n d a tta c h N O T R R c o n n e c ti o n
S ta te s 6 , f a il u r e D e le te
r e q u e st a ll o w e d
20 sy s te m N e w L A I, c o n n e c tio n r e q u e s t
lo w la y e r fa ilu re a n d in f o !! o r T 3 2 1 2 / T 3 2 1 1 t im e o u t
n o r e e s t a b li s h
19
5
M M-I D L E
W AI T F OR 20 R R c o n n e c ti o n r ele a s e d
10 13
O U T G O I NG W A IT F O R
A D DIT I O N A L L O C A TI O N U P D A T E W AI T F OR
M M C O N N E C TI O N
O U TG O IN G RE J E C TE D R R C O N N E C TI O N
M M C O N N E C TI O N ( L O C A TI O N U P D A T E )
C i p h e r in g s t a r t e d
o r C M s e r v ic e R R c o n n e c ti o n
C M s e r v ic e r e le a s e d
accept L o w l a y e r f a il u r e M S d e a c ti va t e d
acc ept D e le te s y s te m i n fo
a n d r e e s t a b lis h R R c o n n e c ti o n a n d a tta c h
R R c o n n e c ti o n
e s ta b li s h e d a llo w e d
e s ta b li s h e d
C o n fi r m ( paging)
M M c o n n e c ti o n S e n d c m s e r vi c e
r e q u e st S end c m u p d a te S I M / U S I M
r e e s ta b li s h R e e s ta b li s h
7
r e q u e st n o t p o s si b le
I M SI D E TA C H
S e n d lo c a ti o n
M M c o n n e c ti o n I NI TI A T E D
RR connection up d a te r e q u e s t
r e q u e st Re q u e st
released R R c o nn e c ti on
L o w l a y e r f a il u r e
a n d r e e s t a b li s h L o c a tio n
17 S e n d IM S I u p d a t e re j e c t
R R c o n n e c ti o n d e ta c h
6 W AIT F OR
r e le a s e d
M M C O N NE C TI ON C M r e e s ta b li s h - RE E S TA B LI S H R R c o n n e c ti o n
A C TI V E m e n t a c c e p te d e s ta b li s h e d 15
RR connection
established due to W AIT F OR
M S d e a c t iv a t e d a n d
SRVCC handover 25 R R C O N N E C TI O N
a t t a c h a l lo w e d
RR ( I M S I D E T A C H)
L a s t c o n n e c ti o n First message
CONNECTION
r e le a s e d received
RELEASE NOT
ALLOWED 9
3
L o c a tio n u p d a te
I n di c a te W AIT F O R NE T W O R K S to r e s y s te m i n f o L O C A TI O N U P D A T IN G
a c ce p t
M M c o n n e c tio n Fir st me s s a g e COMMAND I N IT I A T E D
r e c ei ve d
3GPP
Release 10 52 3GPP TS 24.008 V10.6.1 (2012-03)
21 22
MM CONNECTION RR Connection WAIT FOR RR
ACTIVE CONNECTION
( Group TX MODE ) ( Group TX MODE )
established
Uplink
Uplink Uplink
release
access access
rejected requested
RR gone to RR gone to
Group Transmit
Dedicated
mode 19
mode
MM-IDLE
RR connection RR connection
released, gone released, gone
6 to group receiv e to Group Receive
MM CONNECTION Mode mode
ACTIVE
5
WAIT FOR
OUTGOING
MM CONNECTION
Send CM service
request
or
Notification Response
The MM sublayer has requested RR connection establishment for starting the location updating procedure.
The MM sublayer has requested RR connection establishment for dedicated mode for starting the MM
connection establishment.
The MM sublayer has requested RR connection establishment for starting the IMSI detach procedure.
3GPP
Release 10 53 3GPP TS 24.008 V10.6.1 (2012-03)
A lower layer failure has occurred and re-establishment may be performed from the disturbed CM layer
entities.
19. MM IDLE
There is no MM procedure running and no RR connection exists except that a local MM context may exist
when the RR sublayer is in Group Receive mode. This is a compound state, and the actual behaviour of the
mobile station to Connection Management requests is determined by the actual substate as described
hereafter.
The MM connection establishment for an additional MM connection has been started, and the MM awaits
response from the network.
(Only applicable for mobile stations supporting VGCS talking:) The MM sublayer has a RR connection on
the VGCS channel to its peer entity on the network side. Only one MM connection is active.
(Only applicable for mobile stations supporting VGCS talking:) The MM sublayer has requested to perform
an uplink access on the VGCS channel.
(Only applicable for GPRS MS operation modes A and B; not shown in figure 4.1a) A location updating has
been started using the combined GPRS routing area updating procedure.
(Only applicable for GPRS MS operation modes A and B; not shown in figure 4.1a) An IMSI detach for non-
GPRS services has been started using the combined GPRS detach procedure at not switching off.
(Only applicable for mobile stations supporting RRLP procedures (see 3GPP TS 44.031 [23b]) or LCS
procedures over RRC (see 3GPP TS 25.331 [23c])). All MM connections are released by their CM entities,
but the RR connection is maintained by the network due to an ongoing RRLP procedure or LCS procedure
over RRC.
Valid subscriber data are available, update status is U1, a cell is selected that belongs to the LA where the
subscriber is registered.
In this state, all requests from the CM layers are treated normally.
3GPP
Release 10 54 3GPP TS 24.008 V10.6.1 (2012-03)
Valid subscriber data are available, update status is U2 and a cell is selected. Requests from upper layers are
accepted. Emergency call requests are treated normally, otherwise the request triggers first a location
updating attempt in the selected cell, and then triggers the needed procedure only in case of successful
location updating, otherwise the request is rejected.
Valid subscriber data are available, update status is U3, and a cell is selected, which is known not to be able
to provide normal service. Only emergency services are offered.
19.4 NO IMSI
No valid subscriber data (no SIM/USIM, or the SIM/USIM is not considered valid by the ME), and a cell is
selected. Only emergency services are offered.
No cell can be selected. This state is entered after a first intensive search failed (state 19.7). Cells are
searched at a low rhythm.
This state is also entered when S1 mode is activated in the MS and current cell is an E-UTRAN cell. No services,
except those provided by CS fallback and SMS over SGs, are offered.
Valid subscriber data are available, and for some reason a location updating must be done as soon as possible
(for instance update status is U1 but the selected cell is not in the registered LA, or the timer has expired).
This state is usually of no duration, but can last, e.g. due to access class control, (see subclause 4.1.1.2.1).
The mobile station is searching for PLMNs, and the conditions for state 19.8 are not met. This state is ended
when either a cell is selected (the new state is 19.1, 19.3 or 19.6), or when it is concluded that no cell is
available for the moment (the new state is 19.5).
Valid subscriber data are available, update status is U1, a cell is selected which belongs to the LA where the
subscriber is registered, and the mobile station is searching for PLMNs. This state is ended when either a cell
is selected (the new state is 19.1, 19.3 or 19.6), or when it is concluded that no cell is available for the
moment (the new state is 19.5).
Only applicable for mobile stations supporting VGCS listening or VBS listening. Valid subscriber data are
available, update status is U1, a VGCS channel or VBS channel is received in a cell that belongs to the LA
where the subscriber is registered.
In this state, only requests from the GCC or BCC layers are treated.
Only applicable for mobile stations supporting VGCS listening or VBS listening. Valid subscriber data are
available, update status is U3, a VGCS channel or VBS channel is received in a cell which is known not to be
able to provide normal service.
In this state, only requests from the GCC or BCC layers for the reception of VGCS or VBS calls are treated
and group call emergency services are offered.
Valid subscriber data are available, update status is U4, and a cell is selected, which is expected to be able to
provide normal service. Only emergency services and test/reconfiguration calls[8] can be initiated by the
mobile station. This state is applicable only to an eCall only mobile station (as determined by information
3GPP
Release 10 55 3GPP TS 24.008 V10.6.1 (2012-03)
configured in USIM). The state is entered by the mobile station in order to avoid MM activity and MM
signalling in the absence of an emergency call or test/reconfiguration call. The state is ended when an
emergency services or test/reconfiguration calls[8] is initiated by the mobile station, the new state depends on
the result of the procedure when returning to MM-IDLE described in subclause 4.2.3.
The update status pertains to a specific subscriber embodied by a SIM/USIM. This status is defined even when the
subscriber is not activated (SIM/USIM removed or connected to a switched-off ME). It is stored in a non volatile
memory in the SIM/USIM. The update status is changed only as a result of a location updating procedure attempt (with
the exception of an authentication failure and of some cases of CM service rejection). In some cases, the update status is
changed as a result of a GPRS attach, GPRS routing area update, service request or network initiated GPRS detach
procedure.
U1 UPDATED
The last location updating attempt was successful (correct procedure outcome, and the answer was
acceptance from the network). With this status, the SIM/USIM contains also the LAI of the LA where the
subscriber is registered, and possibly valid TMSI, GSM ciphering key, UMTS integrity key, UMTS ciphering
key and ciphering key sequence number. Furthermore, if the ME supports any A5 ciphering algorithm that
requires a 128-bit ciphering key and a USIM is in use, then the ME may contain a valid GSM Kc 128. The
"Location update status" stored on the SIM/USIM shall be "updated".
U2 NOT UPDATED
The last location updating attempt made failed procedurally (no significant answer was received from the
network, including the cases of failures or congestion inside the network).
For this status, the SIM/USIM does not contain any valid LAI, TMSI, GSM ciphering key, UMTS integrity
key, UMTS ciphering key or ciphering key sequence number. For compatibility reasons, all these fields shall
be set to the "deleted" value at the moment the status is set to NOT UPDATED. However the presence of
other values shall not be considered an error by the mobile station. Furthermore, if the ME supports any A5
ciphering algorithm that requires a 128-bit ciphering key and a USIM is in use, then the ME shall delete the
GSM Kc128 stored at the moment the status is set to NOT UPDATED. The "Location update status" stored on
the SIM/USIM shall be "not updated".
The last location updating attempt run correctly, but the answer from the network was negative (because of
roaming or subscription restrictions).
For this status, the SIM/USIM may contain a valid LAI, TMSI, GSM ciphering key, UMTS integrity key,
UMTS ciphering key or ciphering key sequence number. For compatibility reasons, all these fields shall be
set to the "deleted" value if the LAI is deleted. However the presence of other values shall not be considered
an error by the mobile station. Furthermore, if the ME supports any A5 ciphering algorithm that requires a
128-bit ciphering key and a USIM is in use, then the ME shall delete the GSM Kc128 stored if the LAI is
deleted. The "Location update status" stored on the SIM/USIM shall be "Location Area not allowed".
U4 UPDATING DISABLED
For this status, the SIM/USIM does not contain any valid LAI, TMSI, GSM ciphering key, UMTS integrity
key, UMTS ciphering key or ciphering key sequence number. For compatibility reasons, all these fields shall
be set to the "deleted" value at the moment the status is set to eCALL INACTIVE. However the presence of
other values shall not be considered an error by the mobile station. Furthermore, if the ME supports any A5
ciphering algorithm that requires a 128-bit ciphering key and a USIM is in use, then the ME shall delete the
GSM Kc128 stored at the moment the status is set to eCALL INACTIVE. The "Location update status" stored
on the SIM/USIM shall be "not updated".
3GPP
Release 10 56 3GPP TS 24.008 V10.6.1 (2012-03)
The MM sublayer is not active except possibly when the RR sublayer is in Group Receive mode.
The MM sublayer has received a request for MM connection establishment from the CM layer. A RR
connection to the mobile station is requested from the RR sublayer (i.e. paging is performed).
3. MM CONNECTION ACTIVE
The MM sublayer has a RR connection to a mobile station. One or more MM connections are active, or no
MM connection is active but an RRLP procedure or LCS procedure over RRC is ongoing.
4. IDENTIFICATION INITIATED
The identification procedure has been started by the network. The timer T3270 is running.
5. AUTHENTICATION INITIATED
The authentication procedure has been started by the network. The timer T3260 is running.
The TMSI reallocation procedure has been started by the network. The timer T3250 is running.
In Iu mode, the security mode setting procedure has been requested to the RR sublayer. In A/Gb mode, the
cipher mode setting procedure has been requested to the RR sublayer.
A CM SERVICE REQUEST message is received and processed, and the MM sublayer awaits the "opening
message" of the MM connection.
A CM SERVICE PROMPT message has been sent by the network and the MM sublayer awaits the "opening
message" of the MM connection $(CCBS)$.
The RR connection to a mobile station with one or more active MM connection has been lost. The network
awaits a possible re-establishment request from the mobile station.
Only applicable in case for mobile station supporting VGCS talking. The MM sublayer has received a request
for establishing a VGCS from the GCC sublayer. The request for establishing a VGCS channels is given to
the RR sublayer.
Only applicable in case of mobile station supporting VGCS talking. A VGCS channel is established by the
RR sublayer. An RR connection to the talking mobile station can be established by the RR sublayer on the
VGCS channel. The MM sublayer is active but no sending of MM message between the network and the
mobile station has occurred.
Only applicable in case of mobile station supporting VGCS talking. The MM sublayer has a RR connection
to the talking mobile station on the VGCS channel. Only one MM connection is active.
3GPP
Release 10 57 3GPP TS 24.008 V10.6.1 (2012-03)
Only applicable in case of VBS. The MM sublayer has received a request for a VBS establishment from the
BCC sublayer. The request for establishment of VBS channels is given to the RR sublayer.
Only applicable in case of VBS. A VBS channel is established by the RR sublayer. The MM sublayer is
active but no explicit MM establishment between the Network and the mobile station has occurred.
However, it should be noted that this subclause does not include a description of the detailed behaviour of the MS in the
single states and does not cover abnormal cases. Thus, figure 4.1b of the present document is rather intended to give an
overview of the state transitions than to be a complete state transition diagram. A detailed description of the behaviour
of the MS is given in subclause 4.2. Especially, with respect to the behaviour of the MS in abnormal cases it is referred
to subclause 4.7.
4.1.3.1.1.1 GMM-NULL
The GPRS capability is disabled in the MS. No GPRS mobility management function shall be performed in this state.
4.1.3.1.1.2 GMM-DEREGISTERED
The GPRS capability has been enabled in the MS, but no GMM context has been established. In this state, the MS may
establish a GMM context by starting the GPRS attach or combined GPRS attach procedure.
4.1.3.1.1.3 GMM-REGISTERED-INITIATED
A GPRS attach or combined GPRS attach procedure has been started and the MS is awaiting a response from the
network.
4.1.3.1.1.4 GMM-REGISTERED
A GMM context has been established, i.e. the GPRS attach or combined GPRS attach procedure has been successfully
performed. In this state, the MS may activate PDP contexts, MBMS contexts, may send and receive user data and
signalling information and may reply to a page request. Furthermore, cell and routing area updating are performed.
4.1.3.1.1.5 GMM-DEREGISTERED-INITIATED
The MS has requested release of the GMM context by starting the GPRS detach or combined GPRS detach procedure.
This state is only entered if the MS is not being switched off at detach request.
4.1.3.1.1.6 GMM-ROUTING-AREA-UPDATING-INITIATED
A routing area updating procedure has been started and the MS is awaiting a response from the network.
3GPP
Release 10 58 3GPP TS 24.008 V10.6.1 (2012-03)
A service request procedure has been started and the MS is awaiting a response from the network.
4.1.3.1.2.1 GMM-DEREGISTERED.NORMAL-SERVICE
Valid subscriber data is available, the GPRS update status is GU1 or GU2, a suitable cell has been found and the PLMN
or LA is not in the forbidden list. In this state, a request for GPRS attach is performed using the stored temporary
mobile subscriber identity for GPRS (P-TMSI), routing area identification (RAI) and GPRS ciphering key sequence
number in case of GU1. If the GPRS update status is GU2, the IMSI shall be used to attach for GPRS services.
4.1.3.1.2.2 GMM-DEREGISTERED.LIMITED-SERVICE
Valid subscriber data is available, GPRS update status is GU3, and a cell is selected, which is known not to be able to
provide normal service.
4.1.3.1.2.3 GMM-DEREGISTERED.ATTACH-NEEDED
Valid subscriber data is available and for some reason a GPRS attach must be performed as soon as possible. This state
is usually of no duration, but can last, e.g. due to access class control (see subclause 4.1.1.2.1).
4.1.3.1.2.4 GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH
The GPRS update status is GU2, a cell is selected, a previous GPRS attach was rejected. The execution of further attach
procedures depends on the GPRS attach attempt counter. No GMM procedure except GPRS attach shall be initiated by
the MS in this substate.
4.1.3.1.2.5 GMM-DEREGISTERED.NO-IMSI
No valid subscriber data is available (no SIM/USIM, or the SIM/USIM is not considered valid by the ME) and a cell
has been selected.
4.1.3.1.2.6 GMM-DEREGISTERED.NO-CELL-AVAILABLE
No cell can be selected. This substate is entered after a first intensive search failed (substate PLMN SEARCH). Cells
are searched for at a low rhythm. No services are offered.
4.1.3.1.2.7 GMM-DEREGISTERED.PLMN-SEARCH
The mobile station is searching for PLMNs. This substate is left either when a cell has been selected (the new substate
is NORMAL-SERVICE or LIMITED-SERVICE) or when it has been concluded that no cell is available at the moment
(the new substate is NO-CELL-AVAILABLE).
The MS shall enter this substate when entering dedicated mode and the MS limitations make it unable to communicate
on GPRS channels. The MS shall leave this substate when leaving dedicated mode.
3GPP
Release 10 59 3GPP TS 24.008 V10.6.1 (2012-03)
4.1.3.1.3.1 GMM-REGISTERED.NORMAL-SERVICE
The MS shall enter this substate when entering dedicated mode and when the MS limitations makes it unable to
communicate on GPRS channels. In this substate, no user data should be sent and no signalling information shall be
sent. The MS shall leave this substate when leaving dedicated mode.
4.1.3.1.3.3 GMM-REGISTERED.UPDATE-NEEDED
The MS has to perform a routing area updating procedure, but its access class is not allowed in the cell due to access
class control (see subclause 4.1.1.2.1). The procedure will be initiated as soon as access is granted (this might be due to
a cell-reselection or due to change of the access classes allowed in the current cell). No GMM procedure except routing
area updating shall be initiated by the MS in this substate. In this substate, no user data and no signalling information
shall be sent.
4.1.3.1.3.4 GMM-REGISTERED.ATTEMPTING-TO-UPDATE
A routing area updating procedure failed due to a missing response from the network. The MS retries the procedure
controlled by timers and a GPRS attempt counter. No GMM procedure except routing area updating shall be initiated by
the MS in this substate. No data shall be sent or received.
4.1.3.1.3.5 GMM-REGISTERED.NO-CELL-AVAILABLE
GPRS coverage has been lost. In this substate, the MS shall not initiate any GMM procedures except of cell (and
PLMN) reselection.
3GPP
Release 10 60 3GPP TS 24.008 V10.6.1 (2012-03)
GMM-ROUTING-
GMM-NULL - RAU rejected AREA-UPDATING-
(other causes) INITIATED
GMM-
DEREGISTERED-
- enable - RAU accepted
INITIATED
GPRS mode - RAU failed
- RAU rejected
(#13, #15, #25)
- DETACH accepted
- Lower layer failure
GMM- GMM-
- Network init. DETACH requested
DEREGISTERED - implicit DETACH REGISTERED
- SR requested
- ATTACH accepted
requested - ATTACH rejected
- Network init. DETACH requested
- SR accepted
DETACH requested - Lower layer failure - SR failed
(power off) - SR rejected
- ATTACH (#13, #15,
accepted #25, #40)
GMM- GMM-SERVICE-
Any state REGISTERED- REQUEST-INITIATED
INITIATED
4.1.3.1.3.6 GMM-REGISTERED.LIMITED-SERVICE
A cell is selected, which is known not to be able to provide normal service. The MS will remain in this sub-state until a
cell is selected which is able to provide normal service.
4.1.3.1.3.7 GMM-REGISTERED.ATTEMPTING-TO-UPDATE-MM
A combined routing area updating procedure or a combined GPRS attach procedure was successful for GPRS services
only. The MS retries the procedure controlled by timers and a GPRS attempt counter. User data and signalling
information may be sent and received.
4.1.3.1.3.8 GMM-REGISTERED.IMSI-DETACH-INITIATED
The MS performs a combined GPRS detach procedure for non-GPRS services only (detach type "IMSI Detach"). This
state is entered if the MS is attached for GPRS and non-GPRS services in a network that operates in network mode I
and wants to detach for non-GPRS services only. User data and signalling information may be sent and received.
4.1.3.1.3.9 GMM-REGISTERED.PLMN-SEARCH
The mobile station is searching for PLMNs. This substate is left either when a cell has been selected (the new substate
is NORMAL-SERVICE or LIMITED-SERVICE) or when it has been concluded that no cell is available at the moment
(the new substate is NO-CELL-AVAILABLE).
3GPP
Release 10 61 3GPP TS 24.008 V10.6.1 (2012-03)
The GPRS update status pertains to a specific subscriber embodied by a SIM/USIM. This status is defined even when
the subscriber is not activated (SIM/USIM removed or connected to a switched off ME). It is stored in a non volatile
memory in the SIM/USIM. The GPRS update status is changed only after execution of a GPRS attach, network initiated
GPRS detach, authentication procedure, or routing area updating procedure.
GU1: UPDATED
The last GPRS attach or routing area updating attempt was successful (correct procedure outcome, and the
answer was accepted by the network). The SIM/USIM contains the RAI of the routing area (RA) to which the
subscriber was attached, and possibly a valid P-TMSI, GPRS GSM ciphering key, GPRS UMTS ciphering key,
GPRS UMTS integrity key and GPRS ciphering key sequence number. Furthermore, if the ME supports any
GEA ciphering algorithm that requires a 128-bit ciphering key and a USIM is in use, then the ME may contain a
valid GPRS GSM Kc128.
The last GPRS attach or routing area updating attempt failed procedurally, i.e. no response was received from the
network. This includes the cases of failures or congestion inside the network.
In this case, the SIM/USIM may contain the RAI of the routing area (RA) to which the subscriber was attached,
and possibly also a valid P-TMSI, GPRS GSM ciphering key, GPRS UMTS ciphering key, GPRS UMTS
integrity key and GPRS ciphering key sequence number. For compatibility reasons, all these fields shall be set to
the "deleted" value if the RAI is deleted. However, the presence of other values shall not be considered an error
by the MS. Furthermore, if the ME supports any GEA ciphering algorithm that requires a 128-bit ciphering key
and a USIM is in use, then the ME shall delete the GPRS GSM Kc128 stored if the RAI is deleted.
The last GPRS attach or routing area updating attempt was correctly performed, but the answer from the network
was negative (because of roaming or subscription restrictions).
In this case, the SIM/USIM may contain the RAI of the routing area (RA) to which the subscriber was attached,
and possibly also a valid P-TMSI, GPRS GSM ciphering key, GPRS UMTS ciphering key, GPRS UMTS
integrity key or GPRS ciphering key sequence number. For compatibility reasons, all these fields shall be set to
the value "deleted" if the RAI is deleted. However, the presence of other values shall not be considered an error
by the MS. Furthermore, if the ME supports any GEA ciphering algorithm that requires a 128-bit ciphering key
and a USIM is in use, then the ME shall delete the GPRS GSM Kc128 stored if the RAI is deleted.
If the MS is attached for emergency bearer services, the MS shall not store the GMM parameters described in this
subclause on the SIM/USIM or in non-volatile memory. Instead the MS shall temporarily store these parameters locally
in the ME and the MS shall delete these parameters when the MS is detached.
However, it should be noted that this subclause does not include a description of the detailed behaviour of the network
in the single states and does not cover abnormal cases. Thus, figure 4.1c/3GPP TS 24.008 is rather intended to give an
overview of the state transitions than to be a complete state transition diagram. A detailed description of the behaviour
of the MS is given in subclause 4.2. Especially, with respect to the behaviour of the MS in abnormal cases it is referred
to subclause 4.7.
4.1.3.3.1.1 GMM-DEREGISTERED
The network has no GMM context or the GMM context is marked as detached, the MS is detached. In this state, the
network may answer to a GPRS attach or combined GPRS attach procedure initiated by the MS.
3GPP
Release 10 62 3GPP TS 24.008 V10.6.1 (2012-03)
4.1.3.3.1.2 GMM-COMMON-PROCEDURE-INITIATED
A common GMM procedure, as defined in subclause 4.1.1, has been started. The network is awaiting the answer from
the MS.
4.1.3.3.1.3 GMM-REGISTERED
The GMM context has been established and the GPRS attach procedure has been successfully performed.
4.1.3.3.1.4 GMM-DEREGISTERED-INITIATED
The network has started a GPRS detach procedure and is awaiting the answer from the MS.
GMM-
DE-REGISTERED-
INITIATED
- MS initiated
DETACH requested
RAU rejected
implicit DETACH
GMM- GMM-
DE-REGISTERED REGISTERED
- ATTACH procedure
successful
GMM-COMMON-
PROCEDURE-INITIATED
4.1.3.3.2.1 GMM-REGISTERED.NORMAL-SERVICE
In this substate, the lower layers shall be prevented of sending user data or signalling information.
3GPP
Release 10 63 3GPP TS 24.008 V10.6.1 (2012-03)
The MM IDLE state is entered when none of the MM procedures are running and no RR connection exists. It is left
when one of the MM procedures are triggered or a RR connection is established.
The specific behaviour in the MM IDLE state depends on the service state of the mobile station as described in
subclause 4.1.2.1.2. The service state depends in particular on the update status which is defined in subclause 4.1.2.2.
How an appropriate service state is chosen after power on is described in subclause 4.2.1, and the specific behaviour of
the mobile station in MM IDLE state is described in subclause 4.2.2. The service state chosen when the MM IDLE state
is returned to from any state except NULL state is described in subclause 4.2.3.
It should be noted that transitions between the various MM idle states are caused by (e.g.):
- cell selection/reselection (see also 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]);
- PLMN search;
- loss of coverage.
How various MM procedures affects the service state and the update status is described in the detailed descriptions of
the procedures in subclauses 4.3 to 4.5.
The service state when the PLMN SEARCH state is left depends on the outcome of the search and on the presence of
the SIM/USIM:
- if no cell has been found, the state is NO CELL AVAILABLE, until a cell is found;
- for an eCall only mobile station (as determined by information configured in USIM), the state is eCALL
INACTIVE.
- if the mobile station has been continuously activated since loosing coverage and then returns to coverage, and if
the selected cell is in the location area where the mobile station is registered and the timer T3212 has not
expired, then the state is NORMAL SERVICE;
- if the selected cell is in the location area where the mobile station is registered and IMSI ATTACH is not
required and timer T3212 has not expired, then the state is NORMAL SERVICE;
- if the mobile station is in automatic network selection mode and the selected cell is in a forbidden PLMN, is in a
forbidden LA, or is a CSG cell whose CSG ID and associated PLMN identity are not in the Allowed CSG list or
in the Operator CSG list stored in the MS, then the mobile station enters the LIMITED SERVICE state;
3GPP
Release 10 64 3GPP TS 24.008 V10.6.1 (2012-03)
- if the mobile station is in manual network selection mode and no cell of the selected PLMN has been found, or
the cell that is found in the selected PLMN is a CSG cell whose CSG ID and associated PLMN identity are not
in the Allowed CSG list or in the Operator CSG list stored in the MS, then the mobile station enters the
LIMITED SERVICE state;
- otherwise, the mobile station enters the LOCATION UPDATE NEEDED state.
- in any state except NO IMSI, NO CELL AVAILABLE, NORMAL SERVICE and RECEIVING GROUP CALL
(NORMAL SERVICE) after the user has asked for a PLMN selection;
- roaming is denied;
- optionally, when the mobile station is in the ATTEMPTING TO UPDATE state and is in Automatic Network
Selection mode and location update attempt counter is greater than or equal to 4.
The service state when the PLMN SEARCH is left depends on the outcome of the search and on the presence of the
SIM/USIM as specified in subclause 4.2.1.1.
- provided that T3246 is not running, perform normal location updating when a new location area is entered;
- provided that T3246 is not running, support requests from the CM layer;
- for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity
procedure at expiry of timer T3242 or timer T3243.
- respond to notification if the GCC or BCC sublayer requests the reception of a voice group or broadcast call for
which no channel description has been received in the notification by the RR sublayer;
- request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the
reception of a voice group or broadcast call for which a channel description has been received in the notification
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (NORMAL SERVICE).
3GPP
Release 10 65 3GPP TS 24.008 V10.6.1 (2012-03)
- perform normal location updating when the location area identification of the serving cell changes, if timer
T3246 is not running;
- if entry into this state was caused by c) or d) or f) (with cause different from "abnormal release, unspecified") or
g) (with cause "retry upon entry into a new cell") of subclause 4.4.4.9, then location updating shall be performed
when a new cell is entered;
- if entry into this state was caused by e) or f) (with cause "abnormal release, unspecified"), g) (with cause
different from "retry upon entry into a new cell"), i) or j) of subclause 4.4.4.9, then location updating shall not be
performed because a new cell is entered;
- use other request from CM layer as triggering of normal location updating procedure (if the location updating
procedure is successful, then the request for MM connection is accepted, see subclause 4.5.1), if timer T3246 is
not running;
- for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity
procedure at expiry of timer T3242 or timer T3243.
- indicate notifications to the GCC or BCC sublayer for which a channel description has been received in the
notification by the RR sublayer;
- reject requests of the GCC or BCC sublayer to respond to notifications for which no channel description has
been received in the notification by the RR sublayer;
- request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the
reception of a voice group or broadcast call for which a channel description has been received in the notification
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (LIMITED SERVICE).
- reject any requests from CM entities for MM connections except for emergency calls;
- perform normal location updating when a cell is entered which may provide normal service (e.g. location area
not in one of the forbidden LAI lists.);
- for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity
procedure at expiry of timer T3242 or timer T3243.
- indicate notifications to the GCC or BCC sublayer for which a channel description has been received in the
notification by the RR sublayer;
3GPP
Release 10 66 3GPP TS 24.008 V10.6.1 (2012-03)
- reject requests of the GCC or BCC sublayer to respond to notifications for which no channel description has
been received in the notification by the RR sublayer;
- request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the
reception of a voice group or broadcast call for which a channel description has been received in the notification
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (LIMITED SERVICE).
- reject any request from CM entities for MM connections except for emergency calls;
- if timer T3211 or T3213 expires in this state perform a location updating procedure at the latest if and when back
to NORMAL SERVICE state and if the cell is not changed;
- if timer T3212 expires in this state perform a periodic location updating procedure at the latest if and when back
to NORMAL SERVICE state;
- for an eCall only mobile station (as determined by information configured in USIM), perform the eCall inactivity
procedure at expiry of timer T3242 or T3243.
- listen as far as possible to notifications and indicate notifications to the GCC or BCC layer;
- respond to notification if the GCC or BCC sublayer requests the reception of a voice group or broadcast call for
which no channel description has been received in the notification by the RR sublayer;
- request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the
reception of a voice group or broadcast call for which a channel description has been received in the notification
by the RR sublayer.
3GPP
Release 10 67 3GPP TS 24.008 V10.6.1 (2012-03)
- reject any request from CM entities for MM connections except emergency calls;
When in state MM IDLE and service state RECEIVING GROUP CALL (NORMAL SERVICE), the mobile station
shall:
- respond to notification if the GCC or BCC sublayer requests the reception of a voice group or broadcast call for
which no channel description has been received in the notification by the RR sublayer;
- request the RR sublayer to receive another voice group or broadcast call if the GCC or BCC sublayer requests
the reception of a voice group or broadcast call for which a channel description has been received in the
notification by the RR sublayer.
When in state MM IDLE and service state RECEIVING GROUP CALL (LIMITED SERVICE), the mobile station
shall:
- reject any requests from CM entities for MM connections except for emergency calls;
- perform normal location updating when a cell is entered which may provide normal service (e.g. location area
not in one of the forbidden LAI lists.);
- indicate notifications to the GCC or BCC sublayer for which a channel description has been received in the
notification by the RR sublayer;
- reject requests of the GCC or BCC sublayer to respond to notifications for which no channel description has
been received in the notification by the RR sublayer;
- request the RR sublayer to receive a voice group or broadcast call if the GCC or BCC sublayer requests the
reception of a voice group or broadcast call for which a channel description has been received in the notification
by the RR sublayer and then go to the service state RECEIVING GROUP CALL (LIMITED SERVICE).
3GPP
Release 10 68 3GPP TS 24.008 V10.6.1 (2012-03)
- reject any requests from CM entities for MM connections except for emergency calls and calls to a non-
emergency MSISDN for test and terminal reconfiguration services;
4.2.3 Service state when back to state MM IDLE from another state
When returning to MM IDLE, e.g., after a location updating procedure, the mobile station selects the cell as specified in
3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]. With one exception, this is a normal cell selection.
An eCall only mobile station (as determined by information configured in USIM), shall start timer T3242 if the return
to MM IDLE state is the result of an emergency services call and shall start timer T3243 if the return to MM IDLE state
is the result of a call to a non-emergency MSISDN for test and terminal reconfiguration services, as described in
subclause 4.4.7.
If this return to idle state is not subsequent to a location updating procedure terminated with reception of cause
"Roaming not allowed in this location area", the service state depends on the result of the cell selection procedure, on
the update status of the mobile station, on the location data stored in the mobile station and on the presence of the
SIM/USIM:
- if no cell has been found, the state is NO CELL AVAILABLE, until a cell is found;
- if no SIM/USIM is present, or if the inserted SIM/USIM is considered invalid by the MS, the state is NO IMSI;
- for an eCall only mobile station (as determined by information configured in USIM), if timer T3242 or timer
T3243 has expired and service state PLMN SEARCH is not required, the state is eCALL INACTIVE and the
eCall inactivity procedure is performed as described in subclause 4.4.7;
- if the selected cell is in the location area where the MS is registered, then the state is NORMAL SERVICE; it
shall be noted that this also includes an abnormal case described in subclause 4.4.4.9;
- (Only applicable for mobile stations supporting VGCS listening or VBS listening.) if the mobile stations was in
the service state RECEIVING GROUP CALL (NORMAL SERVICE) or RECEIVING GROUP CALL
(LIMITED SERVICE) before the location updating procedure and the selected cell is in the location area where
the mobile station is registered, then the state is RECEIVING GROUP CALL (NORMAL SERVICE);
- if the selected cell is in a location area where the mobile station is not registered but in which the MS is allowed
to attempt a location update, then the state is LOCATION UPDATE NEEDED;
- if the selected cell is in a location area where the mobile station is not allowed to attempt a location update, then
the state is LIMITED SERVICE;
- if the selected cell is a CSG cell whose CSG ID and associated PLMN identity are not in the Allowed CSG list or
in the Operator CSG list stored in the MS, then the state is LIMITED SERVICE;
- (Only applicable for MSs supporting VGCS listening or VBS listening.) if the MSs was in the service state
RECEIVING GROUP CALL (NORMAL SERVICE) or RECEIVING GROUP CALL (LIMITED SERVICE)
before the location updating procedure and the selected cell is in the location area where the MS is not allowed
to attempt a location update, then the state is RECEIVING GROUP CALL (LIMITED SERVICE);
- after some abnormal cases occurring during an unsuccessful location updating procedure, as described in
subclause 4.4.4.9, the state is ATTEMPTING TO UPDATE.
In case of a return from a location updating procedure to which was answered "Roaming not allowed in this location
area", the service state PLMN SEARCH is entered as specified in subclause 4.2.1.2.
3GPP
Release 10 69 3GPP TS 24.008 V10.6.1 (2012-03)
- a GMM procedure has failed (except routing area updating, see subclause 4.7.5).
It should be noted that transitions between the various substates of GMM-DEREGISTERED are caused by (e.g.):
- cell selection/reselection (see also 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]);
- PLMN search;
- loss/regain of coverage; or
- change of RA.
How various GMM procedures affect the GMM-DEREGISTERED substates and the GPRS update status is described
in the detailed description of the GMM procedures in subclause 4.7.
4.2.4.1.1 Selection of the substate after power on or enabling the MS's GPRS capability
When the MS is switched on, the substate shall be PLMN-SEARCH in case the SIM/USIM is inserted and valid. See
3GPP TS 23.122 [14] and 3GPP TS 45.008 [34] for further details.
When the GPRS capability in an activated MS has been enabled, the selection of the GMM-DEREGISTERED substate
depends on the MM state and the GPRS update status.
The substate chosen after PLMN-SEARCH, in case of power on or after enabling of the GPRS capability is:
- if a suitable cell supporting GPRS has been found and the PLMN or LA is not in the forbidden list, then the
substate shall be NORMAL-SERVICE;
- if the selected cell supporting GPRS is in a forbidden PLMN, is in a forbidden LA, or is a CSG cell with a CSG
ID and associated PLMN identity that are not in Allowed CSG list or in the Operator CSG list stored in the MS ,
then the MS shall enter the substate LIMITED-SERVICE;
- if the MS is in manual network selection mode and no cell supporting GPRS of the selected PLMN has been
found, the MS shall enter the substate NO-CELL-AVAILABLE.
- when the user has asked for a PLMN selection in any substate except NO IMSI and NO CELL AVAILABLE ;
- when coverage is lost in any substate except NO IMSI and NO CELL AVAILABLE ;
- Roaming is denied;
3GPP
Release 10 70 3GPP TS 24.008 V10.6.1 (2012-03)
- optionally, when the MS is in automatic network selection mode and the maximum allowed number of
subsequently unsuccessful attach attempts controlled by the GPRS attach attempt counter (subclause 4.7.3) have
been performed.
- shall initiate GPRS attach on the expiry of timers T3311, T3302, or T3346;
- shall initiate GPRS attach when entering a new PLMN not in the list of equivalent PLMNs, if the PLMN identity
of the new cell is not in one of the forbidden PLMN lists and the location area this cell is belonging to is not in
one of the lists of forbidden LAs;
- may initiate GPRS attach for emergency bearer services (UTRAN Iu mode only) even if timer T3346 is running;
- shall initiate GPRS attach when the routing area of the serving cell in the current PLMN or equivalent PLMN
has changed, if timer T3346 is not running and the location area this cell is belonging to is not in one of the lists
of forbidden LAs;
- shall if entry into this state was caused by b) or d) with cause "Retry upon entry into a new cell" of
subclause 4.7.3.1.5, perform GPRS attach when a new cell is entered;
- shall if entry into this state was caused by c) or d) with cause different from "Retry upon entry into a new cell" of
subclause 4.7.3.1.5, not perform GPRS attach when a new cell is entered;
- shall use requests from CM layers to trigger the combined GPRS attach procedure, if the network operates in
network operation mode I. Depending on which of the timers T3311 or T3302 is running the MS shall stop the
relevant timer and act as if the stopped timer has expired; and
- shall initiate GPRS attach upon request of the upper layers to establish a PDN connection for emergency bearer
services (UTRAN Iu mode only).
- shall initiate GPRS attach when a cell is entered which may provide normal service (e.g. location area is not in
one of the forbidden lists); and
- may initiate GPRS attach for emergency bearer services (UTRAN Iu mode only).
- may initiate GPRS attach for emergency bearer services (UTRAN Iu mode only).
3GPP
Release 10 71 3GPP TS 24.008 V10.6.1 (2012-03)
- perform cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] and shall choose an
appropriate substate.
The substate depends on the result of the cell selection procedure, the outcome of the previously performed GMM
specific procedures, on the GPRS update status of the MS, on the location area data stored in the MS and on the
presence of the SIM/USIM:
- if no cell has been found, the substate is NO-CELL-AVAILABLE, until a cell is found;
- if no SIM/USIM is present or if the inserted SIM/USIM is considered invalid by the MS, the substate shall be
NO-IMSI;
- if a suitable cell supporting GPRS has been found and the PLMN or LA is not in the forbidden list, the substate
shall be NORMAL-SERVICE;
- if a GPRS attach shall be performed (e.g. network requested reattach), the substate shall be ATTEMPTING-TO-
ATTACH;
- if a PLMN reselection (according to 3GPP TS 23.122 [14]) is needed, the substate shall be PLMN SEARCH;
- if the selected cell is known not to be able to provide normal service, the substate shall be LIMITED-SERVICE.
- a GMM context is established, i.e. the MS is IMSI attached for GPRS services only or for GPRS and non-GPRS
services.
The specific behaviour of the MS in state GMM-REGISTERED is described in subclause 4.2.5.1. The primary substate
when entering the state GMM-REGISTERED is always NORMAL-SERVICE.
It should be noted that transitions between the various substates of GMM-REGISTERED are caused by (e.g.):
- cell selection/reselection (see also 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]);
3GPP
Release 10 72 3GPP TS 24.008 V10.6.1 (2012-03)
- change of RA;
- loss/regain of coverage.
How various GMM procedures affect the GMM-REGISTERED substates is described in the detailed description of the
procedures in subclause 4.7.
- perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98];
- perform periodic routing area updating except when attached for emergency bearer services (see
subclause 4.7.2.2); and
- perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]; and
- choose the appropriate new substate depending on the GPRS update status as soon as the access class control
allows network contact in the selected cell.
- shall initiate routing area updating procedure on the expiry of timers T3311, T3302 or T3346;
- shall initiate routing area updating procedure when entering a new PLMN not in the list of equivalent PLMNs, if
the PLMN identity of the new cell is not in one of the forbidden PLMN lists and the location area this cell is
belonging to is not in one of the lists of forbidden LAs;
3GPP
Release 10 73 3GPP TS 24.008 V10.6.1 (2012-03)
- shall initiate routing area updating procedure when the routing area of the serving cell in the current PLMN or
equivalent PLMN has changed, if timer T3346 is not running and the location area this cell is belonging to is not
in one of the lists of forbidden LAs;
- shall, if entry into this state was caused by b) or d) with cause "Retry upon entry into a new cell" of
subclause 4.7.5.1.5, initiate routing area updating procedure when a new cell is entered;
- shall, if entry into this state was caused by c) or d) with cause different from "Retry upon entry into a new cell"
of subclause 4.7.5.1.5, not initiate routing area updating procedure when a new cell is entered;
- shall use request from CM layers to trigger the combined routing area updating procedure, if the network
operates in network operation mode I. Depending on which of the timers T3311 or T3302 is running the MS
shall stop the relevant timer and act as if the stopped timer has expired;
- shall initiate routing area updating procedure upon request of the upper layers to establish a PDN connection for
emergency bearer services (UTRAN Iu mode only); and
- shall initiate routing area updating procedure in response to paging, if timer T3346 is running.
- shall perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] and
- may initiate GPRS attach for emergency bearer services (UTRAN Iu mode only).;
- perform cell selection/reselection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98];
- initiate routing area update indicating "combined RA/LA updating with IMSI attach" on the expiry of timers
T3311 or T3302;
- initiate routing area update indicating "combined RA/LA updating with IMSI attach" when the routing area of
the serving cell has changed and the location area this cell is belonging to is not in the list of forbidden LAs.
3GPP
Release 10 74 3GPP TS 24.008 V10.6.1 (2012-03)
If the identity confidentiality service is applied for an IMSI, a Temporary Mobile Subscriber Identity (TMSI) is used for
identification within the radio interface signalling procedures.
In a network supporting the feature 'Intra domain connection of RAN nodes to multiple CN nodes' a TMSI shall be
allocated to each IMSI attached mobile station. See 3GPP TS 23.236 [94], subclause 4.3.
The structure of the TMSI is specified in 3GPP TS 23.003 [10]. The TMSI has significance only within a location area.
Outside the location area it has to be combined with the Location Area Identifier (LAI) to provide for an unambiguous
identity.
Usually the TMSI reallocation is performed at least at each change of a location area. (Such choices are left to the
network operator).
The reallocation of a TMSI can be performed either by a unique procedure defined in this subclause or implicitly by a
location updating procedure using the TMSI. The implicit reallocation of a TMSI is described together with that
procedure.
If a TMSI provided by a mobile station is unknown in the network e.g. due to a data base failure, the network may
require the mobile station to provide its International Mobile Subscriber Identity (IMSI). In this case the identification
procedure (see subclause 4.3.3) should be used before the TMSI reallocation procedure may be initiated.
The TMSI reallocation can be initiated by the network at any time whilst a RR connection exists between the network
and the mobile station.
NOTE 2: Normally the TMSI reallocation will take place in conjunction with another procedure, e.g. at location
updating or at call setup (see 3GPP TS 29.002 [37]).
NOTE 3: The explicit TMSI reallocation procedure is started by the network only if the mobile station is updated in
the current location area or if a location updating procedure is ongoing for that particular mobile station,
or if the network wishes to send a non-broadcast LAI according to 3GPP TS 23.236 [94] to the mobile
station.
The TMSI REALLOCATION COMMAND message contains a new combination of TMSI and LAI allocated by the
network or a LAI and the IMSI if the used TMSI shall be deleted. Usually the TMSI-REALLOCATION COMMAND
message is sent to the mobile station using a RR connection in ciphered mode (see 3GPP TS 43.020 [13] and
3GPP TS 33.102 [5a]).
If the RR connection is no more needed, then the network will request the RR sublayer to release it (see
3GPP TS 44.018 [84] subclause 3.5 and 3GPP TS 25.331 [23c]).
3GPP
Release 10 75 3GPP TS 24.008 V10.6.1 (2012-03)
The mobile station shall consider the new TMSI and new LAI, if any, as valid and the old TMSI and old LAI as
deleted as soon as a TMSI REALLOCATION COMMAND or another message containing a new TMSI (e.g.
LOCATION UPDATING ACCEPT) is correctly received. Any RR connection failure at a later stage shall not
have any impact on the TMSI and LAI storage.
Network side:
If the RR connection is lost before the TMSI REALLOCATION COMPLETE message is received, all MM
connections (if any) shall be released and both the old and the new TMSIs should be considered as occupied
for a certain recovery time.
- use the IMSI for paging in the case of network originated transactions on the CM layer. Upon response
from the mobile station the TMSI reallocation is restarted;
- consider the new TMSI as valid if it is used by the mobile station in mobile originated requests for RR
connection;
- use the Identification procedure followed by a new TMSI reallocation if the mobile station uses the old
TMSI.
The TMSI reallocation is supervised by the timer T3250 in the network. At the first expiry of timer T3250 the
network may release the RR connection. In this case, the network shall abort the reallocation procedure
release all MM connections if any, and follow the rules described for RR connection failure above.
First to permit the network to check whether the identity provided by the mobile station is acceptable or not;
Second to provide parameters enabling the mobile station to calculate a new UMTS ciphering key;
Third to provide parameters enabling the mobile station to calculate a new UMTS integrity key;
The cases where the authentication procedure should be used are defined in 3GPP TS 33.102 [5a].
The UMTS authentication procedure is always initiated and controlled by the network. However, there is the possibility
for the MS to reject the UMTS authentication challenge sent by the network.
3GPP
Release 10 76 3GPP TS 24.008 V10.6.1 (2012-03)
A UMTS security context is established in the MS and the network when a UMTS authentication challenge is
performed in A/Gb mode or in Iu mode. After a successful UMTS authentication, the UMTS ciphering key, the UMTS
integrity key, the GSM ciphering key and the ciphering key sequence number, are stored both in the network and the
MS. Furthermore, in A/Gb mode both the ME and the network may derive and store a GSM Kc128 as part of the UMTS
security context as described in the subclause 4.3.2.3a.
First to permit the network to check whether the identity provided by the mobile station is acceptable or not;
Second to provide parameters enabling the mobile station to calculate a new GSM ciphering key.
The cases where the authentication procedure should be used are defined in 3GPP TS 42.009 [5].
The authentication procedure is always initiated and controlled by the network. GSM authentication challenge shall be
supported by a ME supporting GERAN or UTRAN.
A GSM security context is established in the MS and the network when a GSM authentication challenge is performed in
A/Gb mode or in Iu mode. However, in Iu mode the MS shall not accept a GSM authentication challenge, if a USIM is
inserted. After a successful GSM authentication, the GSM ciphering key and the ciphering key sequence number, are
stored both in the network and the MS.
In a GSM authentication challenge, the AUTHENTICATION REQUEST message also contains the GSM ciphering key
sequence number allocated to the key which may be computed from the given parameters.
In a UMTS authentication challenge, the AUTHENTICATION REQUEST message also contains the ciphering key
sequence number allocated to the key set of UMTS ciphering key, UMTS integrity key and GSM ciphering key which
may be computed from the given parameters. Furthermore, the ciphering key sequence number is also linked to a GSM
Kc128 if after the authentication procedure the network in A/Gb mode selects an A5 ciphering algorithm that requires a
128-bit ciphering key.
If a SIM is inserted in the MS, the MS shall ignore the Authentication Parameter AUTN IE if included in the
AUTHENTICATION REQUEST message and shall proceed as in case of a GSM authentication challenge. It shall not
perform the authentication of the network described in subclause 4.3.2.5.1.
In a GSM authentication challenge, the new GSM ciphering key calculated from the challenge information shall
overwrite the previous GSM ciphering key and any previously stored UMTS ciphering key and UMTS integrity key
shall be deleted. The new GSM ciphering key shall be stored on the SIM/USIM together with the ciphering key
sequence number.
In a UMTS authentication challenge, the new UMTS ciphering key, the new GSM ciphering key and the new UMTS
integrity key calculated from the challenge information shall overwrite the previous UMTS ciphering key, GSM
ciphering key and UMTS integrity key. The new UMTS ciphering key, GSM ciphering key and UMTS integrity key are
stored on the USIM together with the ciphering key sequence number. Furthermore, in A/Gb mode when after the
authentication procedure an A5 ciphering algorithm that requires a 128-bit ciphering key is taken into use, then a new
GSM Kc128 shall also be calculated as described in the subclause 4.3.2.3a.
3GPP
Release 10 77 3GPP TS 24.008 V10.6.1 (2012-03)
The SIM/USIM will provide the mobile station with the authentication response, based upon the authentication
challenge given from the ME. A UMTS authentication challenge will result in the USIM passing a RES to the ME. A
GSM authentication challenge will result in the SIM/USIM passing a SRES to the ME.
In order to avoid a synchronisation failure, when the mobile station receives an AUTHENTICATION REQUEST
message, the mobile station shall store the received RAND together with the RES returned from the USIM in the
volatile memory and associate it with CS domain. When the MS receives a subsequent AUTHENTICATION
REQUEST message, if the stored RAND value for the CS domain is equal to the new received value in the
AUTHENTICATION REQUEST message, then the mobile station shall not pass the RAND to the USIM, but shall
immediately send the AUTHENTICATION RESPONSE message with the stored RES for the CS domain. If, for the CS
domain, there is no valid stored RAND in the mobile station or the stored RAND is different from the new received
value in the AUTHENTICATION REQUEST message, the mobile station shall pass the RAND to the USIM, shall
override any previously stored RAND and RES with the new ones and start, or reset and restart timer T3218.
The RAND and RES values stored in the mobile station shall be deleted and timer T3218, if running, shall be stopped:
Upon receipt of the AUTHENTICATION FAILURE message, the network stops the timer T3260. In Synch failure case,
the core network may renegotiate with the HLR/AuC and provide the MS with new authentication parameters.
The ME with a USIM in use shall compute a new GSM Kc128 using the UMTS ciphering key and the UMTS integrity
key from an established UMTS security context as specified in 3GPP TS 33.102 [5a]. The new GSM Kc128 shall be
stored only in the ME. The ME shall overwrite the existing GSM Kc128 with the new GSM Kc128. The ME shall delete
the GSM Kc128 at switch off, when the USIM is disabled as well as under the conditions identified in the
subclause 4.1.2.2 and 4.3.2.4. The ME with a USIM in use shall apply the GSM Kc128 when in A/Gb mode an A5
ciphering algorithm that requires a 128-bit ciphering key is taken into use.
The network shall compute the GSM Kc128 using the UMTS integrity key and the UMTS ciphering key from an
established UMTS security context as specified in 3GPP TS 33.102 [5a] only when in A/Gb mode an A5 ciphering
algorithm that requires a 128-bit ciphering key is to be used.
In a GSM authentication challenge, from a challenge parameter RAND both the authentication response parameter
SRES and the GSM ciphering key can be computed given the secret key associated to the IMSI.
In a UMTS authentication challenge, from a challenge parameter RAND, the authentication response parameter RES
and the UMTS ciphering key and the UMTS integrity key can be computed given the secret key associated to the IMSI.
3GPP
Release 10 78 3GPP TS 24.008 V10.6.1 (2012-03)
In addition, in the USIM a GSM ciphering key can be computed from the UMTS ciphering key and the UMTS integrity
key by means of an unkeyed conversion function. Furthermore, in A/Gb mode if an A5 ciphering algorithm that requires
a 128-bit ciphering key is taken into use, then a GSM Kc128 shall also be calculated as described in the
subclause 4.3.2.3a.
In order to allow start of ciphering on a RR connection without authentication, the ciphering key sequence numbers are
introduced. The ciphering key sequence number is managed by the network in the way that the AUTHENTICATION
REQUEST message contains the ciphering key sequence number allocated to the GSM ciphering key (in case of a GSM
authentication challenge) or the UMTS ciphering key and the UMTS integrity key (in case of a UMTS authentication
challenge) which may be computed from the RAND parameter carried in that message.
If an authentication procedure has been completed successfully and a ciphering key sequence number is stored in the
network, the network shall include a different ciphering key sequence number in the AUTHENTICATION REQUEST
message when it intiates a new authentication procedure.
The mobile station stores the ciphering key sequence number with the GSM ciphering key (in case of a GSM
authentication challenge) and the UMTS ciphering key and the UMTS integrity key (in case of a UMTS authentication
challenge) and indicates to the network in the first message (LOCATION UPDATING REQUEST, CM SERVICE
REQUEST, PAGING RESPONSE, CM RE-ESTABLISHMENT REQUEST) which ciphering key sequence number the
stored GSM ciphering key (in case of a GSM authentication challenge) or set of UMTS ciphering, UMTS integrity,
derived GSM ciphering key, and potentially the derived GSM Kc128 (in case of a UMTS authentication challenge) has.
When the deletion of the ciphering key sequence number is described this also means that the associated GSM
ciphering key, the UMTS ciphering key and the UMTS integrity key shall be considered as invalid and also the GSM
Kc128 shall be deleted if any (i.e. the established GSM security context or the UMTS security context is no longer valid).
In A/Gb mode, the network may choose to start ciphering with the stored GSM ciphering key or GSM Kc 128 (under the
restrictions given in 3GPP TS 42.009 [5]) if the stored ciphering key sequence number and the one given from the
mobile station are equal.
NOTE 1: The decision of starting ciphering with the GSM ciphering key or the GSM Kc128 depends on whether the
network indicates in the CIPHERING MODE COMMAND message an A5 ciphering algorithm which
requires a 64 or 128-bit ciphering key as specified in 3GPP TS 33.102 [5a].
In Iu mode, the network may choose to start ciphering and integrity with the stored UMTS ciphering key and UMTS
integrity key (under the restrictions given in 3GPP TS 42.009 [5] and 3GPP TS 33.102 [5a]) if the stored ciphering key
sequence number and the one given from the mobile station are equal.
NOTE 2: In some specifications the term KSI (Key Set Identifier) might be used instead of the term ciphering key
sequence number.
If the TMSI has been used, the network may decide to initiate the identification procedure. If the IMSI given by the
mobile station then differs from the one the network had associated with the TMSI, the authentication should be
restarted with the correct parameters. If the IMSI provided by the MS is the expected one (i.e. authentication has really
failed), the network should proceed as described below.
If the IMSI has been used, or the network decides not to try the identification procedure, an AUTHENTICATION
REJECT message should be transferred to the mobile station.
After having sent this message, all MM connections in progress (if any) are released and the network should initiate the
RR connection release procedure described in subclause 3.5.of 3GPP TS 44.018 [84] (A/Gb mode only),
3GPP TS 25.331 [23c] (UTRAN Iu mode only), or in 3GPP TS 44.118 [111] (GERAN Iu mode only).
3GPP
Release 10 79 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of an AUTHENTICATION REJECT message, the mobile station shall set the update status in the
SIM/USIM to U3 ROAMING NOT ALLOWED, delete from the SIM/USIM the stored TMSI, LAI and ciphering key
sequence number. The SIM/USIM shall be considered as invalid until switching off or the SIM/USIM is removed.
If the AUTHENTICATION REJECT message is received in the state IMSI DETACH INITIATED the mobile station
shall follow subclause 4.3.4.3.
If the AUTHENTICATION REJECT message is received in any other state the mobile station shall abort any MM
specific, MM connection establishment or call re-establishment procedure, stop any of the timers T3210 or T3230 (if
running), release all MM connections (if any), start timer T3240 and enter the state WAIT FOR NETWORK
COMMAND, expecting the release of the RR connection. If the RR connection is not released within a given time
controlled by the timer T3240, the mobile station shall abort the RR connection. In both cases, either after a RR
connection release triggered from the network side or after a RR connection abort requested by the MS-side, the MS
enters state MM IDLE, substate NO IMSI.
Following a UMTS authentication challenge, the MS may reject the core network, on the grounds of an incorrect AUTN
parameter (see 3GPP TS 33.102 [5a]). This parameter contains two possible causes for authentication failure:
If the MS considers the MAC code (supplied by the core network in the AUTN parameter) to be invalid, it
shall send an AUTHENTICATION FAILURE message to the network, with the reject cause 'MAC failure'.
The MS shall then follow the procedure described in subclause 4.3.2.6 (c).
b) SQN failure:
If the MS considers the SQN (supplied by the core network in the AUTN parameter) to be out of range, it
shall send a AUTHENTICATION FAILURE message to the network, with the reject cause 'Synch failure'
and a re-synchronization token AUTS provided by the USIM (see 3GPP TS 33.102 [5a]). The MS shall then
follow the procedure described in subclause 4.3.2.6 (d).
In UMTS, an MS with a USIM inserted shall reject the authentication challenge if no Authentication Parameter AUTN
IE was present in the AUTHENTICATION REQUEST message (i.e. a GSM authentication challenge has been received
when the MS expects a UMTS authentication challenge). In such a case, the MS shall send the AUTHENTICATION
FAILURE message to the network, with the reject cause "GSM authentication unacceptable". The MS shall then follow
the procedure described in subclause 4.3.2.6 (c).
If the MS returns an AUTHENTICATION_FAILURE message to the network, the MS shall delete any previously
stored RAND and RES and shall stop timer T3218, if running.
Upon detection of a RR connection failure before the AUTHENTICATION RESPONSE is received, the network
shall release all MM connections (if any) and abort any ongoing MM specific procedure.
The authentication procedure is supervised on the network side by the timer T3260. At expiry of this timer the
network may release the RR connection. In this case the network shall abort the authentication procedure and
any ongoing MM specific procedure, release all MM connections if any, and initiate the RR connection release
procedure described in subclause 3.5 of 3GPP TS 44.018 [84] (A/Gb mode only), 3GPP TS 25.331 [23c]
(UTRAN Iu mode only), or in 3GPP TS 44.118 [111] (GERAN Iu mode only).
(c) Authentication failure (reject cause "MAC failure" or "GSM authentication unacceptable"):
The MS shall send an AUTHENTICATION FAILURE message, with reject cause "MAC failure" or "GSM
authentication unacceptable" according to subclause 4.3.2.5.1, to the network and start timer T3214.
3GPP
Release 10 80 3GPP TS 24.008 V10.6.1 (2012-03)
Furthermore, the MS shall stop any of the retransmission timers that are running (e.g. T3210, T3220 or T3230).
Upon the first receipt of an AUTHENTICATION FAILURE message from the MS with reject cause "MAC
failure" or "GSM authentication unacceptable", the network may initiate the identification procedure described
in subclause 4.3.3. This is to allow the network to obtain the IMSI from the MS. The network may then check
that the TMSI originally used in the authentication challenge corresponded to the correct IMSI. Upon receipt of
the IDENTITY REQUEST message from the network, the MS shall send the IDENTITY RESPONSE message.
NOTE: Upon receipt of an AUTHENTICATION FAILURE message from the MS with reject cause "MAC
failure" or "GSM authentication unacceptable", the network may also terminate the authentication
procedure (see subclause 4.3.2.5).
If the TMSI/IMSI mapping in the network was incorrect, the network should respond by sending a new
AUTHENTICATION REQUEST message to the MS. Upon receiving the new AUTHENTICATION REQUEST
message from the network, the MS shall stop the timer T3214, if running, and then process the challenge
information as normal.
If the network is validated successfully (an AUTHENTICATION REQUEST that contains a valid SQN and
MAC is received), the MS shall send the AUTHENTICATION RESPONSE message to the network and shall
start any retransmission timers (e.g. T3210, T3220 or T3230), if they were running and stopped when the MS
received the first failed AUTHENTICATION REQUEST message.
If the MS receives the second AUTHENTICATION REQUEST while T3214 is running, and the MAC value
cannot be resolved or the message contains a GSM authentication challenge, the MS shall follow the procedure
specified in this subclause (c), starting again from the beginning. If the SQN is invalid, the MS shall proceed as
specified in (d).
It can be assumed that the source of the authentication challenge is not genuine (authentication not accepted by
the MS) if any of the following occur:
- after sending the AUTHENTICATION FAILURE message with the reject cause "MAC failure" or "GSM
authentication unacceptable" the timer T3214 expires;
- the MS detects any combination of the authentication failures: "MAC failure", "invalid SQN", and "GSM
authentication unacceptable", during three consecutive authentication challenges. The authentication
challenges shall be considered as consecutive only, if the authentication challenges causing the second and
third authentication failure are received by the MS, while the timer T3214 or T3216 started after the previous
authentication failure is running.
When it has been deemed by the MS that the source of the authentication challenge is not genuine (i.e.
authentication not accepted by the MS), the MS shall behave as described in subclause 4.3.2.6.1.
3GPP
Release 10 81 3GPP TS 24.008 V10.6.1 (2012-03)
MS Network
AUTHENTICATION REQUEST
Start T3260
AUTH FAILURE (cause=’MAC failure’ or ‘GSM
Start T3214 authentication unacceptable’) Stop T3260
IDENTITY REQUEST
Start T3270
The MS shall send an AUTHENTICATION FAILURE message, with reject cause "synch failure", to the
network and start the timer T3216. Furthermore, the MS shall stop any of the retransmission timers that are
running (e.g. T3210, T3220 or T3230). Upon the first receipt of an AUTHENTICATION FAILURE message
from the MS with the reject cause "synch failure", the network shall use the returned AUTS parameter from the
authentication failure parameter IE in the AUTHENTICATION FAILURE message, to re-synchronise. The re-
synchronisation procedure requires the VLR/MSC to delete all unused authentication vectors for that IMSI and
obtain new vectors from the HLR. When re-synchronisation is complete, the network shall initiate the
authentication procedure. Upon receipt of the AUTHENTICATION REQUEST message, the MS shall stop the
timer T3216, if running.
NOTE: Upon receipt of two consecutive AUTHENTICATION FAILURE messages from the MS with reject
cause "synch failure", the network may terminate the authentication procedure by sending an
AUTHENTICATION REJECT message.
If the network is validated successfully (a new AUTHENTICATION REQUEST is received which contains a
valid SQN and MAC) while T3216 is running, the MS shall send the AUTHENTICATION RESPONSE message
to the network and shall start any retransmission timers (e.g. T3210, T3220 or T3230), if they were running and
stopped when the MS received the first failed AUTHENTICATION REQUEST message.
If the MS receives the second AUTHENTICATION REQUEST while T3216 is running, and the MAC value
cannot be resolved or the message contains a GSM authentication challenge, the MS shall proceed as specified in
(c); if the SQN is invalid, the MS shall follow the procedure specified in this subclause (d), starting again fom
the beginning.
The MS shall deem that the network has failed the authentication check and behave as described in
subclause 4.3.2.6.1, if any of the following occurs:
- the MS detects any combination of the authentication failures: "MAC failure", "invalid SQN", and "GSM
authentication unacceptable", during three consecutive authentication challenges. The authentication
challenges shall be considered as consecutive only, if the authentication challenges causing the second and
third authentication failure are received by the MS, while the timer T3214 or T3216 started after the previous
authentication failure is running.
3GPP
Release 10 82 3GPP TS 24.008 V10.6.1 (2012-03)
MS Network
AUTHENTICATION REQUEST Start T3260
T3360
Figure 4.2a/3GPP TS 24.008: Authentication Failure Procedure (reject cause "Synch failure")
4.3.2.6.1 MS behaviour towards a network that has failed the authentication procedure
If the MS deems that the network has failed the authentication check, then it shall request RR or RRC to release the RR
connection and the PS signalling connection, if any, and bar the active cell or cells (see 3GPP TS 25.331 [23c] and
3GPP TS 44.018 [84]). The MS shall start any retransmission timers (e.g. T3210, T3220 or T3230), if they were
running and stopped when the MS received the first AUTHENTICATION REQUEST message containing an invalid
MAC or invalid SQN, or no AUTN when a UMTS authentication challenge was expected.
The ME shall handle the GSM ciphering key and a potential GSM Kc128 according to table 4.3.2.7.1.
GSM security context An ME shall apply the stored GSM ciphering key that was
received from the GSM security context residing in the SIM/USIM
during the latest successful ciphering mode setting or security
mode control procedure before the inter-system change.
UMTS security context If an A5 algorithm is taken into use that requires a 64-bit
ciphering key, then an ME shall apply the stored GSM ciphering
key that was derived by the USIM from the UMTS ciphering key
and the UMTS integrity key and provided by the USIM during the
latest successful ciphering mode setting or security mode control
procedure before the inter-sytem change.
If an A5 algorithm is taken into use that requires a 128-bit
ciphering key, then an ME shall apply the GSM Kc128 derived by
the ME from the UMTS ciphering key and the UMTS integrity key
(see 3GPP TS 33.102 [5a]) provided by USIM during the lastest
successful ciphering mode setting or security mode control
procedure before the inter-system change (see
subclause 4.3.2.3a).
NOTE: A USIM with UMTS security context, passes the UMTS ciphering key, the UMTS integrity key and the
derived GSM ciphering key to the ME independent on the current radio access being UTRAN or
GERAN.
3GPP
Release 10 83 3GPP TS 24.008 V10.6.1 (2012-03)
In A/Gb mode, in the case of an established UMTS security context, the GSM ciphering key shall be loaded from the
USIM and taken into use by the MS when a valid CIPHERING MODE COMMAND is received during an RR
connection (the definition of a valid CIPHERING MODE COMMAND message is given in 3GPP TS 44.018 [84]
subclause 3.4.7.2) which indicates an A5 ciphering algorithm that requires a 64-bit ciphering key. The network shall
derive a GSM ciphering key from the UMTS ciphering key and the UMTS integrity key by using the conversion
function named "c3" defined in 3GPP TS 33.102 [5a].
In A/Gb mode, in the case of an established UMTS security context, the UMTS ciphering key and the UMTS integrity
key shall be loaded from the USIM in order for the ME to derive the GSM Kc128 (see 3GPP TS 33.102 [5a]) and shall be
taken into use by the ME when a valid CIPHERING MODE COMMAND is received during an RR connection (the
definition of a valid CIPHERING MODE COMMAND message is given in 3GPP TS 44.018 [84] subclause 3.4.7.2)
which indicates an A5 ciphering algorithm that requires a 128-bit ciphering key. The network shall derive a GSM Kc 128
from the UMTS ciphering key and the UMTS integrity as defined in 3GPP TS 33.102 [5a].
In Iu mode, in the case of an established GSM security context, the ME shall derive a UMTS ciphering key and a
UMTS integrity key from the GSM ciphering key by using the conversion functions named "c4" and "c5" defined in
3GPP TS 33.102 [5a]. The GSM ciphering key shall be loaded from the SIM/USIM and the derived UMTS ciphering
key and UMTS integrity key shall be taken into use by the MS when a valid SECURITY MODE COMMAND
indicating CS domain is received during an RR connection (the definition of a valid SECURITY MODE COMMAND
message is given in 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]). The network shall derive a UMTS ciphering
key and a UMTS integrity key from the GSM ciphering key by using the conversion functions named "c4" and "c5"
defined in 3GPP TS 33.102 [5a].
In Iu mode, in the case of an established UMTS security context, the UMTS ciphering key and UMTS integrity key
shall be loaded from the USIM and taken into use by the MS when a valid SECURITY MODE COMMAND indicating
CS domain is received during a RR connection (the definition of a valid SECURITY MODE COMMAND message is
given in 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
In Iu mode and A/Gb mode, if the MS received a valid SECURITY MODE COMMAND indicating CS domain in Iu
mode or a valid CIPHERING MODE COMMAND in A/Gb mode before the network initiates a new Authentication
procedure and establishes a new GSM/UMTS security context, the new keys are taken into use in the MS when a new
valid SECURITY MODE COMMAND indicating CS domain in Iu mode, or a new valid CIPHERING MODE
COMMAND in A/Gb mode, is received during the RR connection. In case of Iu mode to Iu mode handover, A/Gb
mode to A/Gb mode handover, or inter-system change to A/Gb mode, the MS and the network shall continue to use the
key from the old key set until a new valid SECURITY MODE COMMAND indicating CS domain in Iu mode, or a new
valid CIPHERING MODE COMMAND in A/Gb mode, is received during the RR connection. In case of inter-system
change to Iu mode, the MS and the network shall continue to use the keys from the old key set until the second valid
SECURITY MODE COMMAND indicating CS domain is received during the RR connection.
NOTE 1: If the MS received a valid SECURITY MODE COMMAND indicating CS domain in Iu mode or a valid
CIPHERING MODE COMMAND in A/Gb mode before the inter-system change to Iu mode occurs, the
first SECURITY MODE COMMAND message after the inter-system change, which indicates CS domain
and includes only an Integrity protection mode IE, is initiated by the UTRAN without receipt of a
corresponding RANAP security mode control procedure from the MSC/VLR. The only purpose of this
SECURITY MODE COMMAND message is to activate the integrity protection, but not to load a new
key set from the SIM/USIM (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
NOTE 2: If the MS did not receive any valid SECURITY MODE COMMAND indicating CS domain in Iu mode or
any valid CIPHERING MODE COMMAND in A/Gb mode before the inter-system change to Iu mode
occurs, the first SECURITY MODE COMMAND message after the inter-system change, which indicates
CS domain, is initiated by the UTRAN on receipt of a RANAP security mode control procedure from the
MSC/VLR. The purpose of this SECURITY MODE COMMAND message is to load a key set from the
SIM/USIM and to activate either integrity protection or ciphering and integrity protection (see
3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
3GPP
Release 10 84 3GPP TS 24.008 V10.6.1 (2012-03)
The ME shall handle the UMTS ciphering key and the UMTS integrity key according to table 4.3.2.8.1.
GSM security context An ME shall derive the UMTS ciphering key and the UMTS
integrity key from the stored GSM ciphering key that was
provided by the SIM/USIM during the latest successful ciphering
mode setting or security mode control procedure before the inter-
system change. The conversion functions named "c4" and "c5" in
3GPP TS 33.102 [5a] are used for this purpose.
UMTS security context An ME shall apply the stored UMTS ciphering key and the stored
UMTS integrity key that were received from the UMTS security
context residing in the USIM during the latest successful
ciphering mode setting or security mode control procedure before
the inter-system change.
NOTE: A USIM with UMTS security context, passes the UMTS ciphering key, the UMTS integrity key and the
derived GSM ciphering key to the ME independent on the current radio access being UTRAN or
GERAN.
4.3.2.9 Void
The MS shall set the CKSN of the derived UMTS security context to the value of the eKSI of the EPS security context
and derive security keys CKSRVCC and IKSRVCC as specified in 3GPP TS 33.401 [123]. The ME shall also derive the
security key GSM ciphering key Kc from CKSRVCC and IKSRVCC using the conversion function c3 as specified in
3GPP TS 33.102 [5a]. The MS shall apply these derived security keys, handle the STARTCS value as specified in
3GPP TS 25.331 [23c] and replace an already established UMTS security context for the CS domain, if any, in the
USIM, when the SRVCC handover from S1 mode has been completed successfully.
NOTE: Because of deriving a new UMTS security context for the CS domain, a new GSM ciphering key needs
also to be derived from the new derived UMTS security keys for the CS domain (i.e. CKSRVCC and
IKSRVCC). Note that the new GSM ciphering key is also part of the new UMTS security context for the CS
domain as well, as any old GSM ciphering key stored in the USIM and in the ME, belongs to an old
UMTS security context for the CS domain and can no longer be used.
The network shall replace an already established UMTS security context for the CS domain, if any, when the SRVCC
handover from S1 mode has been completed successfully.
If the SRVCC handover from S1mode has not been completed successfully, the MS and the network shall delete the
new derived GSM or UMTS security context for the CS domain. Additionally, the network shall delete the already
3GPP
Release 10 85 3GPP TS 24.008 V10.6.1 (2012-03)
established GSM or UMTS security context for the CS domain, if the CKSN of the already established GSM or UMTS
security context is equal to the CKSN of the new derived GSM or UMTS security context for the CS domain.
The ME shall handle the UMTS ciphering key and the UMTS integrity key according to table 4.3.2.11.1.
GSM security context An ME shall derive the GSM ciphering key (Kc’) from the stored
GPRS GSM ciphering key, which was provided by the SIM/USIM
during the latest successful authentication, and the NONCE
received in the command to perform handover (see
3GPP TS 25.331 [23c]) using the key derivation function
specified in 3GPP TS 33.102 [5a]. The ME shall use the derived
GSM ciphering key (Kc’) to derive the UMTS security keys UMTS
ciphering key (CK’) and UMTS integrity key (IK’). The conversion
functions named "c4" and "c5" in 3GPP TS 33.102 [5a] are used
for this purpose. The MS shall set the CKSN of the derived GSM
security context for the CS domain to the value of the GPRS
CKSN of the GSM security context for PS domain. Furthermore,
the ME shall apply the new derived UMTS security keys and
replace an already established GSM security context for the CS
domain, if any, in the SIM/USIM, when the SRVCC handover
from Iu mode has been completed successfully. Furthermore, the
MS shall handle the STARTCS value as specified in
3GPP TS 25.331 [23c]).
UMTS security context An ME shall derive the UMTS security keys UMTS ciphering key
(CK’) and UMTS integrity key (IK’) from the GPRS UMTS
ciphering key and the GPRS UMTS integrity key, which were
received from the UMTS security context for the PS domain
residing in the USIM, and the NONCE received in the command
to perform handover (see 3GPP TS 25.331 [23c]) as specified in
3GPP TS 33.102 [5a]. The ME shall use the derived UMTS
security keys to derive the GSM ciphering key (Kc’) using the "c3"
conversion function as specified in 3GPP TS 33.102 [5a]. The
MS shall set the CKSN of the derived UMTS security context for
the CS domain to the value of the KSI of the UMTS security
context for PS domain. Furthermore, the ME shall apply the
derived UMTS security keys and replace an already established
UMTS security context for the CS domain, if any, in the USIM,
when the SRVCC handover from Iu mode has been completed
successfully. Furthermore, the MS shall handle the STARTCS
value as specified in 3GPP TS 25.331 [23c]).
3GPP
Release 10 86 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: For the case of an established UMTS security context for the PS domain, because of deriving a new
UMTS security context for the CS domain, a new GSM ciphering key needs to be derived from the new
derived UMTS security keys (i.e. CK' and IK'). Note that the new GSM ciphering key is also part of the
new UMTS security context for the CS domain, and therefore any old GSM ciphering key stored in the
USIM and in the ME belongs to an old UMTS security context for the CS domain and can no longer be
taken into use.
The network shall replace an already established GSM or UMTS security context for the CS domain, if any, when the
SRVCC handover from Iu mode to Iu mode has been completed successfully.
If the SRVCC handover from Iu mode to Iu mode has not been completed successfully, the MS and the network shall
delete the new derived GSM or UMTS security context for the CS domain. Additionally, the network shall delete the
already established GSM or UMTS security context for the CS domain, if the CKSN of the already established GSM or
UMTS security context is equal to the CKSN of the new derived GSM or UMTS security context for the CS domain.
The ME shall handle the GSM ciphering key according to table 4.3.2.12.1.
3GPP
Release 10 87 3GPP TS 24.008 V10.6.1 (2012-03)
GSM security context An ME shall derive the GSM ciphering key (Kc’) from the stored
GPRS GSM ciphering key, which was provided by the SIM/USIM
during the latest successful authentication, and the NONCE
received in the command to perform handover (see
3GPP TS 25.331 [23c]) using the key derivation function
specified in 3GPP TS 33.102 [5a]. The MS shall set the CKSN of
the derived GSM security context for the CS domain to the value
of the GPRS CKSN of the GSM security context for PS domain.
Furthermore, the ME shall apply the new derived GSM ciphering
key and replace an already established GSM security context for
the CS domain, if any, in the SIM/USIM when the SRVCC
handover from Iu mode has been completed successfully.
UMTS security context An ME shall derive the UMTS security keys UMTS ciphering key
(CK’) and UMTS integrity key (IK’) from the GPRS UMTS
ciphering key and GPRS UMTS integrity key, which were
received from the UMTS security context for the PS domain
residing in the USIM, and the NONCE received in the command
to perform handover (see 3GPP TS 25.331 [23c]) as specified in
3GPP TS 33.102 [5a]. The ME shall use the derived UMTS
security keys to derive the GSM ciphering key (Kc’) using the "c3"
conversion function as specified in 3GPP TS 33.102 [5a].
Furthermore, the MS shall set the CKSN of the derived UMTS
security context for the CS domain to the value of the KSI of the
UMTS security context for PS domain.
If an A5 algorithm is taken into use that requires a 64-bit long
ciphering key, then the ME shall apply the new derived GSM
ciphering key.
If an A5 algorithm is taken into use that requires a 128-bit long
ciphering key, then the ME shall use the derived UMTS security
keys CK' and IK' to derive a GSM Kc128 (see
3GPP TS 33.102 [5a]). After that, the ME shall apply the new
derived GSM Kc128.
Furthermore, the ME shall replace an already established UMTS
security context for the CS domain, if any, in the USIM, when the
SRVCC handover from Iu mode has been completed
successfully.
The network shall replace an already established GSM or UMTS security context for the CS domain, if any, when the
SRVCC handover from Iu mode to A/Gb mode has been completed successfully.
If the SRVCC handover from Iu mode to A/Gb mode has not been completed successfully, the MS and the network
shall delete the new derived GSM or UMTS security context for the CS domain. Additionally, the network shall delete
the already established GSM or UMTS security context for the CS domain, if the CKSN of the already established
GSM or UMTS security context is equal to the CKSN of the new derived GSM or UMTS security context for the CS
domain.
3GPP
Release 10 88 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of the IDENTITY REQUEST message the mobile station sends back an IDENTITY RESPONSE
message. The IDENTITY RESPONSE message contains the identification parameters as requested by the network.
Upon receipt of the IDENTITY RESPONSE the network shall stop timer T3270.
Upon detection of a RR connection failure before the IDENTITY RESPONSE is received, the network shall
release all MM connections (if any) and abort any ongoing MM specific procedure.
The identification procedure is supervised by the network by the timer T3270. At expiry of the timer T3270 the
network may release the RR connection. In this case, the network shall abort the identification procedure and any
ongoing MM specific procedure, release all MM connections if any, and initiate the RR connection release
procedure as described in 3GPP TS 44.018 [84] subclause 3.5, 3GPP TS 25.331 [23c] (UTRAN Iu mode only),
or in 3GPP TS 44.118 [111] (GERAN Iu mode only).
If the MS cannot encode the requested identity in the IDENTITY RESPONSE message, e.g. because no valid
SIM is available, then it shall encode the identity type as "No identity".
4.3.4.0 General
The IMSI detach procedure may be invoked by a mobile station if the mobile station is deactivated or if the Subscriber
Identity Module (see 3GPP TS 42.017 [7] and 3GPP TS 31.102 [112]) is detached from the mobile station or as part of
the eCall inactivity procedure defined in subclause 4.4.7.
In A/Gb mode and GERAN Iu mode, a flag (ATT) broadcast in the L3-RR SYSTEM INFORMATION TYPE 3
message on the BCCH is used by the network to indicate whether the detach procedure is required. The value of the
ATT flag to be taken into account shall be the one broadcast when the mobile station was in MM idle.
In UTRAN Iu mode, a flag (ATT) in the CS domain specific system information element is used by the network to
indicate whether the detach procedure is required. The value of the ATT flag to be taken into account shall be the one
received when the mobile station was in MM idle.
3GPP
Release 10 89 3GPP TS 24.008 V10.6.1 (2012-03)
If a RR connection exists and the ATT flag indicates that no detach procedure is required, the MM sublayer will release
locally any ongoing MM connections before releasing the RR connection. If a MM specific procedure is active, the
release of the RR connection may be delayed until the MM specific procedure is complete.
The procedure causes the mobile station to be indicated as inactive in the network.
The mobile station is allowed to initiate the IMSI detach procedure even if the timer T3246 is running.
The network proceeds with the IMSI detach procedure even if NAS level mobility management congestion control is
active.
If no RR connection exists, the MM sublayer within the mobile station will request the RR sublayer to establish a RR
connection. If establishment of the RR connection is not possible because a suitable cell is not (or not yet) available
then, the mobile station shall try for a period of at least 5 seconds and for not more than a period of 20 seconds to find a
suitable cell. If a suitable cell is found during this time then, the mobile station shall request the RR sublayer to establish
an RR connection, otherwise the IMSI detach is aborted.
If a RR connection exists, the MM sublayer will release locally any ongoing MM connections before the IMSI
DETACH INDICATION message is sent.
The IMSI detach procedure may not be started if a MM specific procedure is active. If possible, the IMSI detach
procedure is then delayed until the MM specific procedure is finished, else the IMSI detach is omitted.
Only applicable for a network supporting VGCS: If an IMSI DETACH INDICATION message is received from the
talking mobile station in a group call while the network is in service state MM CONNECTION ACTIVE (GROUP
TRANSMIT MODE), the network shall release locally the ongoing MM connection and then go to the service state
GROUP CALL ACTIVE.
If the establishment of an RR connection is unsuccessful, or the RR connection is lost, the IMSI detach is aborted by
the mobile station.
3GPP
Release 10 90 3GPP TS 24.008 V10.6.1 (2012-03)
The signalling procedure for IMSI detach shall not be started. The MS starts the signalling procedure as soon as
possible and if still necessary, i.e. when the barred state is removed or because of a cell change, or performs a
local detach immediately or after an implementation dependent time.
The Cause information element indicates the reason for the abortion. The following cause values may apply:
# 6: Illegal ME
The mobile station shall then wait for the network to release the RR connection - see subclause 4.5.3.1.
The MM information procedure may be invoked by the network at any time during an RR connection.
NOTE: The network may be able to select particular instants where it can send the MM INFORMATION
message without adding delay to, or interrupting, any CM layer transaction, e.g. immediately after the
AUTHENTICATION REQUEST message.
3GPP
Release 10 91 3GPP TS 24.008 V10.6.1 (2012-03)
If the mobile station does not support the MM information message the mobile station shall ignore the contents of the
message and return an MM STATUS message with cause #97.
During the lifetime of a MM specific procedure, if a MM connection establishment is requested by a CM entity, this
request will either be rejected or be delayed until the running MM specific procedure is terminated (this depends on the
implementation).
Any MM common procedure (except IMSI detach) may be initiated during a MM specific procedure.
Unless it has specific permission from the network (follow-on proceed) the mobile station side should await the release
of the RR connection used for a MM specific procedure before a new MM specific procedure or MM connection
establishment is started.
NOTE: The network side may use the same RR connection for MM connection management.
- indicating to the network that due to a manual CSG selection the MS has selected a CSG cell whose CSG
identity and associated PLMN identity are not included in the MS's Allowed CSG list.or in the MS's Operator
CSG list
The normal location updating procedure is used to update the registration of the actual Location Area of a mobile station
in the network. The location updating type information element in the LOCATION UPDATING REQUEST message
shall indicate normal location updating. The conditions under which the normal location updating procedure is used by
a mobile station in the MM IDLE state are defined for each service state in subclause 4.2.2.
Only applicable for mobile stations supporting VGCS listening or VBS listening: A mobile station in RR group receive
mode is in the MM IDLE state, substate RECEIVING GROUP CALL (NORMAL SERVICE) or RECEIVING GROUP
CALL (LIMITED SERVICE). To perform a location updating, the MS in RR group receive mode shall leave the group
receive mode, establish an independent dedicated RR connection to perform the location updating as described above
and return to the RR group receive mode afterwards.
The normal location updating procedure shall also be started if the network indicates that the mobile station is unknown
in the VLR as a response to MM connection establishment request.
The normal location updating procedure shall also be started if the MS is configured to use CS fallback and SMS over
SGs, or SMS over SGs only, and the TIN indicates "RAT-related TMSI",
- when the periodic tracking area update timer T3412 expires and the network operates in network operation mode
II or III; or
- when the MS enters a GERAN or UTRAN cell in network operation mode II or III and the E-UTRAN deactivate
ISR timer T3423 is running.
NOTE 1: The timers T3412 and T3423 are specified in 3GPP TS 24.301 [120].
The normal location updating procedure shall also be started when the MS, configured to use CS fallback and SMS over
SGs, or SMS over SGs only, enters a GERAN or UTRAN cell in network operation mode II or III and the E-UTRAN
deactivate ISR timer T3423 has expired.
3GPP
Release 10 92 3GPP TS 24.008 V10.6.1 (2012-03)
The normal location updating procedure shall also be started when the MS, configured to use CS fallback and SMS over
SGs, or SMS over SGs only, enters a GERAN or UTRAN cell after intersystem change from S1 mode to Iu or A/Gb
mode, if timer T3346 is running, the TIN indicates "GUTI", and the location area of the current cell is the same as the
stored location area.
NOTE 2: If inter-system change is due to a mobile originating CS call, the location updating procedure can be
performed after the RR connection is released unless the MS moves back to E-UTRAN.
The normal location updating procedure shall also be started when the MS is both IMSI attached for GPRS and non-
GPRS services and enters a new routing area where the network operates in network operation mode I and timer T3346
is running.
The normal location updating procedure shall also be started when the network is operating in network operation
mode I, T3346 is running, T3246 is not running, and due to manual CSG selection the MS has selected a CSG cell
whose CSG identity and associated PLMN identity are not included in the Allowed CSG list or in the Operator CSG list
of the MS.
If the MS, configured to use CS fallback and SMS over SGs, enters a GERAN or UTRAN cell, after intersystem change
from S1 mode to Iu or A/Gb mode due to CS fallback, and the location area of the current cell is not available, the MS
may initiate the location updating procedure.
To limit the number of location updating attempts made, where location updating is unsuccessful, an attempt counter is
used. The attempt counter is reset when a mobile station is switched on or a SIM/USIM card is inserted.
Upon successful location updating the mobile station sets the update status to UPDATED in the SIM/USIM, and stores
the Location Area Identification received in the LOCATION UPDATING ACCEPT message in the SIM/USIM. The
attempt counter shall be reset.
The detailed handling of the attempt counter is described in subclauses 4.4.4.6 to 4.4.4.9.
The Mobile Equipment shall contain a list of "forbidden location areas for roaming", as well as a list of "forbidden
location areas for regional provision of service". These lists shall be erased when the MS is switched off or when the
SIM/USIM is removed, and periodically (with period in the range 12 to 24 hours). The location area identification
received on the BCCH that triggered the location updating request shall be added to the suitable list whenever a location
update reject message is received with the cause "Roaming not allowed in this location area", "Location Area not
allowed", or "No suitable cells in Location Area". The lists shall accommodate each 10 or more location area
identifications. When the list is full and a new entry has to be inserted, the oldest entry shall be deleted.
In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The MS
shall construct the Location Area Identification of the cell from this chosen PLMN identity and the LAC received on the
BCCH. If the constructed LAI is different from the stored LAI, the MS shall initiate the location updating procedure.
The chosen PLMN identity shall be indicated to the UTRAN in the RRC INITIAL DIRECT TRANSFER message (see
3GPP TS 25.331 [23c]). Whenever a LOCATION UPDATING REJECT message with the cause "PLMN not allowed"
is received by the MS, the PLMN identity used to construct the LAI which triggered the location updating procedure
shall be stored in the "forbidden PLMN list". Whenever a LOCATION UPDATING REJECT message is received by
the MS with the cause "Roaming not allowed in this location area", "Location Area not allowed", or "No suitable cells
in Location Area", the constructed LAI which triggered the location updating procedure shall be stored in the suitable
list.
The Mobile Equipment shall store a list of "equivalent PLMNs". This list is replaced or deleted at the end of each
location update procedure, routing area update procedure and GPRS attach procedure. The stored list consists of a list of
equivalent PLMNs as downloaded by the network plus the PLMN code of the registered PLMN that downloaded the
list. The stored list shall not be deleted when the MS is switched off. The stored list shall be deleted if the SIM/USIM is
removed. The maximum number of possible entries in the stored list is 16.
The cell selection processes in the different states are described in 3GPP TS 43.022 [82] and 3GPP TS 45.008 [34].
In the case that the mobile station is initiating an emergency call but, due to cell re-selection or redirection by the
network, it moves to a different LAI then the mobile station may delay the location updating procedure in the new LA
until after the emergency call is completed.
3GPP
Release 10 93 3GPP TS 24.008 V10.6.1 (2012-03)
The procedure is controlled by the timer T3212 in the mobile station. The MS indicates in the MS network feature
support IE whether it supports the extended value for timer T3212. If the MS receives the Per MS T3212 IE in the
Location Updating Accept message, the MS shall use this IE to determine the value of T3212 instead of the value of
T3212 that is broadcast. If the MS does not receive the Per MS T3212 IE in the Location Updating Accept message, the
MS shall use the value of T3212 that is broadcast . If the timer is not already started, the timer is started each time the
mobile station enters the MM IDLE substate NORMAL SERVICE or ATTEMPTing TO UPDATE. When the MS leaves
the MM Idle State the timer T3212 shall continue running until explicitly stopped.
The timer is stopped (shall be set to its initial value for the next start) when:
- the first MM message is received, or security mode setting is completed in the case of MM connection
establishment, except when the most recent service state is LIMITED SERVICE;
- the mobile station has responded to paging and thereafter has received the first correct layer 3 message except
RR message;
- the mobile station is deactivated (i.e. equipment powered down or SIM/USIM removed).
When the timer T3212 expires, the location updating procedure is started and the timer shall be set to its initial value for
the next start. If the mobile station is in other state than MM Idle when the timer expires the location updating
procedure is delayed until the MM Idle State is entered.
The conditions under which the periodic location updating procedure is used by a mobile station in the MM IDLE state
are defined for each service state in subclause 4.2.2.
If the mobile station is in service state NO CELL AVAILABLE, LIMITED SERVICE, PLMN SEARCH or PLMN
SEARCH-NORMAL SERVICE when the timer expires the location updating procedure is delayed until this service
state is left.
In A/Gb mode and GERAN Iu mode, the (periodic) location updating procedure is not started if the BCCH information
at the time the procedure is triggered indicates that periodic location shall not be used. The timeout value is broadcasted
in the L3-RR SYSTEM INFORMATION TYPE 3 message on the BCCH, in the Control channel description IE, see
3GPP TS 44.018 [84] subclause 10.5.2.11.
In UTRAN Iu mode, the (periodic) location updating procedure is not started if the information on BCCH or in the last
received dedicated system information at the time the procedure is triggered indicates that periodic location shall not be
used. The timeout value is included in the CS domain specific system information element.
The T3212 timeout value shall not be changed in the NO CELL AVAILABLE, LIMITED SERVICE, PLMN SEARCH
and PLMN SEARCH-NORMAL SERVICE states.
When a change of the broadcast T3212 timeout value has to be taken into account and the timer is running (at change of
the serving cell or, change of the broadcast value of T3212), the MS shall behave as follows: let t1 be the new T3212
timeout value and let t be the current timer value at the moment of the change to the new T3212 timeout value; then the
timer shall be restarted with the value t modulo t1.
When the mobile station is activated, or when a change of the broadcast T3212 timeout value has to be taken into
account and the timer is not running, the mobile station shall behave as follows: let t1 be the new T3212 timeout value,
the new timer shall be started at a value randomly, uniformly drawn between 0 and t1.
3GPP
Release 10 94 3GPP TS 24.008 V10.6.1 (2012-03)
In A/Gb mode and GERAN Iu mode, a flag (ATT) is broadcast in the L3-RR SYSTEM INFORMATION TYPE 3
message. It indicates whether the attach and detach procedures are required to be used or not.
In UTRANmode, a flag (ATT) is included in the CS domain specific system information element. It indicates whether
the attach and detach procedures are required to be used or not.
The IMSI attach procedure is invoked if the detach/attach procedures are required by the network and an IMSI is
activated in a mobile station (i.e. activation of a mobile station with plug-in SIM/USIM, insertion of a card in a card-
operated mobile station etc.) within coverage area from the network or a mobile station with an IMSI activated outside
the coverage area enters the coverage area. The IMSI attach procedure is used only if the update status is UPDATED
and if the stored Location Area Identification is the same as the one which is actually broadcasted on the BCCH of the
current serving cell. In a shared network, the MS shall choose one of the PLMN identities as specified in
3GPP TS 23.122 [14]. The MS shall use the IMSI attach procedure only if the update status is UPDATED and the
stored Location Area Identification is equal to the combination of the chosen PLMN identity and the LAC received on
the BCCH. Otherwise a normal location updating procedure (see subclause 4.4.1) is invoked independently of the ATT
flag indication.
IMSI attach is performed by using the location updating procedure. The location updating type information element in
the LOCATION UPDATING REQUEST message shall in this case indicate IMSI attach.
As no RR connection exists at the time when the location updating procedure has to be started, the MM sublayer within
the mobile station will request the RR sublayer to establish a RR connection and enter state WAIT FOR RR
CONNECTION (LOCATION UPDATE). The procedure for establishing an RR connection is described in
3GPP TS 44.018 [84] subclause 3.3 and 3GPP TS 25.331 [23c].
The mobile station initiates the location updating procedure by sending a LOCATION UPDATING REQUEST message
to the network, starts the timer T3210 and enters state LOCATION UPDATING INITIATED. The location updating
type information element shall indicate what kind of updating is requested.
If the MS is configured for "AttachWithIMSI" as specified in 3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and the
selected PLMN is neither the registered PLMN nor in the list of equivalent PLMNs, the MS shall include the IMSI in
the Mobile identity IE in the LOCATION UPDATING REQUEST message.
If the mobile station is configured to use CS fallback and SMS over SGs, or SMS over SGs only, the mobile station
shall set the TIN to "P-TMSI" unless the mobile station had already received the EMM cause #18 during a combined
attach procedure (see subclause 5.5.1.3.4.3 of 3GPP TS 24.301 [120]) or a combined tracking area updating procedure
(see subclause 5.5.3.3.4.3 of 3GPP TS 24.301 [120]) on the same PLMN, but not disabled the E-UTRAN capability.
3GPP
Release 10 95 3GPP TS 24.008 V10.6.1 (2012-03)
In Iu mode, the security mode control procedure (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]) may be
initiated by the network, e.g., if a new TMSI has to be allocated.
The attempt counter is incremented when a location update procedure fails. The specific situations are specified in
subclause 4.4.4.9.
- a SIM/USIM is inserted;
- location update completed with cause #11, #12,#13, #15 or #25 (see subclause 4.4.4.7).
The attempt counter is used when deciding whether to re-attempt a location update after timeout of timer T3211.
In case the identity confidentiality service is active (see subclauses 4.3.1 and 4.4.4.4), the TMSI reallocation may be
part of the location updating procedure. The TMSI allocated is then contained in the LOCATION UPDATING ACCEPT
message together with the location area identifier LAI. The network shall in this case start the supervision timer T3250
as described in subclause 4.3.1.
In a shared network, if the MS is supporting network sharing, the network shall indicate in the LAI the PLMN identity
of the CN operator that has accepted the location updating; if the MS is not supporting network sharing, the network
shall indicate the PLMN identity of the common PLMN (see 3GPP TS 23.251 [109]).
In a multi-operator core network (MOCN) with common GERAN, the network shall indicate in the LAI the common
PLMN identity (see 3GPP TS 23.251 [109]).
If the network wishes to prolong the RR connection to allow the mobile station to initiate MM connection establishment
(for example if the mobile station has indicated in the LOCATION UPDATING REQUEST that it has a follow-on
request pending) the network shall send "follow on proceed" in the LOCATION UPDATING ACCEPT and start timer
T3255.
If the mobile station has indicated "CS fallback mobile terminating call" in the LOCATION UPDATING REQUEST
message, the network shall maintain the RR connection for an implementation dependent duration to allow for mobile
terminating call establishment. If the mobile station has also indicated in the LOCATION UPDATING REQUEST
message that it has a follow-on request pending, it is implementation dependent whether the network proceeds with the
mobile terminating call establishment or allows for a mobile initiated MM connection establishment.
3GPP
Release 10 96 3GPP TS 24.008 V10.6.1 (2012-03)
The mobile station receiving a LOCATION UPDATING ACCEPT message shall store the received location area
identification LAI, stop timer T3210, reset the attempt counter and set the update status in the SIM/USIM to
UPDATED. If the message contains an IMSI, the mobile station is not allocated any TMSI, and shall delete any TMSI
in the SIM/USIM accordingly. If the message contains a TMSI, the mobile station is allocated this TMSI, and shall store
this TMSI in the SIM/USIM and a TMSI REALLOCATION COMPLETE shall be returned to the network. If neither
IMSI nor TMSI is received in the LOCATION UPDATING ACCEPT message, the old TMSI if any available shall be
kept.
If the MS has initiated the location updating procedure due to manual CSG selection and receives a LOCATION
UPDATING ACCEPT message, and the MS sent the LOCATION UPDATING REQUEST message in a CSG cell, the
MS shall check if the CSG ID and associated PLMN identity of the cell are contained in the Allowed CSG list. If not,
the MS shall add that CSG ID and associated PLMN identity to the Allowed CSG list and the MS may add the HNB
Name (if provided by lower layers) to the Allowed CSG list if the HNB Name is present in neither the Operator CSG
list nor the Allowed CSG list.
If the LAI or PLMN identity contained in the LOCATION UPDATING ACCEPT message is a member of the list of
"forbidden location areas for regional provision of service", the list of "forbidden location areas for roaming" or the
"forbidden PLMN list" then such entries shall be deleted.
The network may also send a list of "equivalent PLMNs" in the LOCATION UPDATING ACCEPT message. Each
entry of the list contains a PLMN code (MCC+MNC). The mobile station shall store the list, as provided by the
network, except that any PLMN code that is already in the "forbidden PLMN list" shall be removed from the
"equivalent PLMNs" list before it is stored by the mobile station. In addition the mobile station shall add to the stored
list the PLMN code of the registered PLMN that sent the list. All PLMNs in the stored list shall be regarded as
equivalent to each other for PLMN selection, cell selection/re-selection and handover. The stored list in the mobile
station shall be replaced on each occurrence of the LOCATION UPDATING ACCEPT message. If no list is contained
in the message, then the stored list in the mobile station shall be deleted. The list shall be stored in the mobile station
while switched off so that it can be used for PLMN selection after switch on.
After that, the mobile station shall act according to the presence of the "Follow-on proceed" information element in the
LOCATION UPDATING ACCEPT; if this element is present and the mobile station has a CM application request
pending, it shall send a CM SERVICE REQUEST to the network and proceed as in subclause 4.5.1.1. Otherwise, it
shall start timer T3240 and enter state WAIT FOR NETWORK COMMAND.
Furthermore, the network may grant authorisation for the mobile station to use GSM-Cordless Telephony System (CTS)
in the Location Area and its immediate neighbourhood. The mobile should memorise this permission in non-volatile
memory. If the "CTS permission" IE is not present in the message, the mobile is not authorised to use GSM-CTS, and
shall accordingly delete any memorised permission.
NOTE 1: the interaction between CTS and GPRS procedures are not yet defined.
The network may also send a list of local emergency numbers in the LOCATION UPDATING ACCEPT, by including
the Emergency Number List IE. The mobile equipment shall store the list, as provided by the network, except that any
emergency number that is already stored in the SIM/USIM shall be removed from the list before it is stored by the
mobile equipment. If there are no emergency numbers stored on the SIM/USIM, then before storing the received list the
mobile equipment shall remove from it any emergency number stored permanently in the ME for use in this case (see
3GPP TS 22.101 [8]). The list stored in the mobile equipment shall be replaced on each receipt of a new Emergency
Number List IE.
The emergency number(s) received in the Emergency Number List IE are valid only in networks with the same MCC as
in the cell on which this IE is received. If no list is contained in the LOCATION UPDATING ACCEPT message, then
the stored list in the mobile equipment shall be kept, except if the mobile equipment has successfully registered to a
PLMN with an MCC different from that of the last registered PLMN.
The mobile equipment shall use the stored list of emergency numbers received from the network in addition to the
emergency numbers stored on the SIM/USIM or ME to detect that the number dialled is an emergency number.
NOTE 2: The mobile equipment may use the emergency numbers list to assist the end user in determining whether
the dialled number is intended for an emergency service or for another destination, e.g. a local directory
service. The possible interactions with the end user are implementation specific.
The list of emergency numbers shall be deleted at switch off and removal of the SIM/USIM. The mobile equipment
shall be able to store up to ten local emergency numbers received from the network.
3GPP
Release 10 97 3GPP TS 24.008 V10.6.1 (2012-03)
Upon the release of the RR connection, the mobile station shall take the following actions depending on the stored
reject cause:
# 3: (Illegal MS); or
# 6: (Illegal ME).
The mobile station shall set the update status to ROAMING NOT ALLOWED (and store it in the SIM/USIM
according to subclause 4.1.2.2), and delete any TMSI, stored LAI and ciphering key sequence number and shall
consider the SIM/USIM as invalid for non-GPRS services until switch-off or the SIM/USIM is removed.
The mobile station shall delete any LAI, TMSI and ciphering key sequence number stored in the SIM/USIM,
reset the attempt counter, and set the update status to ROAMING NOT ALLOWED (and store it in the
SIM/USIM according to subclause 4.1.2.2). The mobile station shall store the PLMN identity in the "forbidden
PLMN list".
The MS shall perform a PLMN selection when back to the MM IDLE state according to 3GPP TS 23.122 [14].
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to performing a
PLMN selection from this list according to 3GPP TS 23.122 [14].
The mobile station shall delete any LAI, TMSI and ciphering key sequence number stored in the SIM/USIM,
reset the attempt counter, and set the update status to ROAMING NOT ALLOWED (and store it in the
SIM/USIM according to subclause 4.1.2.2).
The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service".
The MS shall perform a cell selection when back to the MM IDLE state according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
NOTE 1: The cell selection procedure is not applicable for an MS in GAN mode.
The mobile station shall reset the attempt counter, and set the update status to ROAMING NOT ALLOWED
(and store it in the SIM/USIM according to subclause 4.1.2.2).
The mobile station shall store the LAI in the list of "forbidden location areas for roaming".
The mobile station shall perform a PLMN selection instead of a cell selection when back to the MM IDLE state
according to 3GPP TS 23.122 [14].
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to performing a
PLMN selection from this list according to 3GPP TS 23.122 [14].
The mobile station shall reset the attempt counter, set the update status to ROAMING NOT ALLOWED (and
store it in the SIM/USIM according to subclause 4.1.2.2).
3GPP
Release 10 98 3GPP TS 24.008 V10.6.1 (2012-03)
The mobile station shall store the LAI in the list of "forbidden location areas for roaming".
The mobile station shall search for a suitable cell in another location area or a tracking area in the same PLMN
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121].
NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode.
# 22: (Congestion).
If the T3246 value IE is present in the LOCATION UPDATING REJECT message and the value indicates that
this timer is neither zero nor deactivated, the mobile station shall proceed as described below, otherwise it shall
be considered as an abnormal case and the behaviour of the MS for this case is specified in subclause 4.4.4.9.
The mobile station shall abort the location updating procedure, reset the attempt counter, set the MM update
status to U2 NOT UPDATED and change to state MM IDLE sub-state ATTEMPTING TO UPDATE.
If the LOCATION UPDATING REJECT message is integrity protected, the mobile station shall start timer
T3246 with the value provided in the T3246 value IE.
If the LOCATION UPDATING REJECT message is not integrity protected, the mobile station shall start timer
T3246 with a random value from the default range specified in table 11.1.
The mobile station stays in the current serving cell and applies the normal cell reselection process. The MM
connection establishment is started, if still necessary, when timer T3246 expires or is stopped.
Cause #25 is only applicable in UTRAN Iu mode and when received from a CSG cell. Other cases are
considered as abnormal cases and the specification of the mobile station behaviour is given in subclause 4.4.4.9.
If the LOCATION UPDATING REJECT message with cause #25 was received without integrity protection, then
the MS shall discard the message.
The MS shall reset the attempt counter, and set the update status to ROAMING NOT ALLOWED (and store it in
the SIM/USIM according to subclause 4.1.2.2).
If the CSG ID and associated PLMN identity of the cell where the MS has sent the LOCATION UPDATING
REQUEST message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry
corresponding to this CSG ID and associated PLMN identity from the Allowed CSG list.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the LOCATION UPDATING
REQUEST message are contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS
23.122 [14] subclause 3.1A.
The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
Other values are considered as abnormal cases and the specification of the mobile station behaviour in those cases is
given in subclause 4.4.4.9.
Any release of the RR connection shall be initiated by the network according to subclause 3.5 in 3GPP TS 44.018 [84],
and 3GPP TS 25.331 [23c]. If the RR connection is not released within a given time controlled by the timer T3240, the
mobile station shall abort the RR connection. In both cases, either after a RR connection release triggered from the
network side or after a RR connection abort requested by the MS-side, the MS shall return to state MM IDLE.
3GPP
Release 10 99 3GPP TS 24.008 V10.6.1 (2012-03)
If the MS receives the "Extended wait time" for CS domain from the lower layers when no location updating or CM
service request procedure is ongoing, the MS shall ignore the "Extended wait time".
At transition to state MM IDLE, substates NORMAL SERVICE or RECEIVING GROUP CALL (NORMAL
SERVICE) or ATTEMPTING TO UPDATE either timer T3212 or timer T3211 is started as described in
subclause 4.4.4.9, or, timer T3246 is started as described in subclauses 4.4.4.7, 4.4.4.9 and 4.5.1.1.
The location updating procedure is not started. The mobile station stays in the current serving cell and applies
normal cell reselection process. The procedure is started as soon as possible and if still necessary (when the
barred state is ended or because of a cell change).
b) The answer to random access is an IMMEDIATE ASSIGNMENT REJECT message (A/Gb mode only)
The location updating is not started. The mobile station stays in the chosen cell and applies normal cell selection
process. The waiting timer T3122 is reset when a cell change occurs. The procedure is started as soon as possible
after T3122 timeout if still necessary.
Timer T3213 is started. When it expires the procedure is attempted again if still necessary.
NOTE 1: As specified in 3GPP TS 45.008 [34], a cell reselection then takes place, with return to the cell inhibited
for 5 seconds if there is at least one other suitable cell. Typically the selection process will take the mobile
station back to the cell where the random access failed after 5 seconds.
If at the expiry of timer T3213 a new cell has not been selected due to the lack of valid information (see
3GPP TS 45.008 [34]), the mobile station may as an option delay the repeated attempt for up to 8 seconds to
allow cell re-selection to take place. In this case the procedure is attempted as soon as a new cell has been
selected or the mobile station has concluded that no other cell can be selected.
If random access failure occurs for two successive random access attempts for location updating the mobile
station proceeds as specified below.
d) RR connection failure
The procedure is aborted and the mobile station proceeds as specified below.
e) T3210 timeout
The procedure is aborted, the RR connection is aborted and the MS proceeds as specified below.
The procedure is aborted and the mobile station proceeds as specified below, except in the following
implementation option case f.1.
f.1)RR release in Iu mode (i.e. RRC connection release) with, for example, cause "Normal", "User inactivity" or
"Directed signalling connection re-establishment" (see 3GPP TS 25.331 [32c] and 3GPP TS 44.118 [111])
The location updating procedure shall be initiated again, if the following conditions apply:
i) The original location updating procedure was initiated over an existing RRC connection; and
ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the CS signalling connection (e.g. CS authentication procedures, see subclause 4.3.2), were received after the
LOCATION UPDATING REQUEST message was transmitted.
NOTE 2: The RRC connection release cause that triggers the re-initiation of the location updating procedure is
implementation specific.
3GPP
Release 10 100 3GPP TS 24.008 V10.6.1 (2012-03)
g) Location updating reject, other causes than those treated in subclause 4.4.4.7, and cases of MM cause #22, if
considered as abnormal cases according to subclause 4.4.4.7
Upon reception of the cause codes #22, # 95, # 96, # 97, # 99 and # 111 the MS should set the attempt counter to
4. The MS waits for release of the RR connection as specified in subclause 4.4.4.8, and then proceeds as
specified below.
The procedure is aborted and the mobile station proceeds as specified below.
NOTE 3: Case h) covers all cases when the signalling connection cannot be established, including random access
failure and access reject. As the RRC protocol has error specific retransmission mechanisms (see
3GPP TS 25.331 [23c]), there is no need to distinguish between the different error cases within MM.
The MS shall abort the MM connection establishment and stop timer T3230 if still running.
If the LOCATION UPDATING REQUEST message contained the NAS signalling low priority indication set to
"MS is configured for NAS signalling low priority", the MS shall start timer T3246 with the "Extended wait
time" value.
The MM connection establishment is started, if still necessary, when timer T3246 expires or is stopped.
The MM connection establishment shall not be initiated unless the MS is establishing an emergency call. The
MS stays in the current serving cell and applies normal cell reselection process. The MM connection
establishment is started, if still necessary, when timer T3246 expires or is stopped.
In cases d) to i) (except in the case f.1) above, and, for repeated failures as defined in c) above, and for the case of cause
code #22 received (as described in subclause 4.4.4.7 and 4.5.1.1) the mobile station proceeds as follows. Timer T3210 is
stopped if still running. The RR Connection is aborted in case of timer T3210 timeout. The attempt counter is
incremented. The next actions depend on the Location Area Identities (stored and received from the BCCH of the
current serving cell) and the value of the attempt counter.
– the update status is UPDATED, and the stored LAI is equal to the one received on the BCCH from the current
serving cell and the attempt counter is smaller than 4:
The mobile station shall keep the update status to UPDATED, the MM IDLE sub-state after the RR connection
release is NORMAL SERVICE. The mobile station shall memorize the location updating type used in the
location updating procedure. It shall start timer T3211 (or, if the conditions for cause code #22 specified in
subclause 4.4.4.7 or subclause 4.5.1.1 are met, shall start timer T3246 and not start timer T3211) when the RR
connection is released. When timer T3211 or T3246 expires the location updating procedure is triggered again
with the memorized location updating type;
– either the update status is different from UPDATED, or the stored LAI is different from the one received on the
BCCH from the current serving cell, or the attempt counter is greater or equal to 4:
When the RR connection is released the mobile station shall delete any LAI, TMSI, ciphering key sequence
number stored in the SIM/USIM, and list of equivalent PLMNs, set the update status to NOT UPDATED and
enter the MM IDLE sub-state ATTEMPTING TO UPDATE (see subclause 4.2.2.2 for the subsequent actions) or
optionally the MM IDLE sub-state PLMN SEARCH (see subclause 4.2.1.2) in order to perform a PLMN
selection according to 3GPP TS 23.122 [14]. If the attempt counter is smaller than 4, the mobile station shall
memorize that timer T3211 (or, if the conditions for cause code #22 specified in subclause 4.4.4.7 or
subclause 4.5.1.1 are met, shall start timer T3246 and not start timer T3211) is to be started when the RR
connection is released, otherwise it shall memorize that timer T3212 (or, if the conditions for cause code #22
specified in subclause 4.4.4.7 or subclause 4.5.1.1 are met, shall start timer T3246 and not start timer T3212) is
to be started when the RR connection is released.
3GPP
Release 10 101 3GPP TS 24.008 V10.6.1 (2012-03)
If a RR connection failure occurs during a common procedure integrated with the location updating procedure, the
behaviour of the network should be according to the description of that common procedure.
If a RR connection failure occurs when a common procedure does not exist, the location updating procedure towards
the mobile station should be aborted.
b) protocol error
If the LOCATION UPDATING REQUEST message is received with a protocol error, the network should, if possible,
return a LOCATION UPDATING REJECT message with one of the following Reject causes:
Having sent the response, the network should start the channel release procedure (see subclause 3.5).
4.4.5 Void
4.4.6 Void
While in eCALL INACTIVE state, the mobile station maintains awareness of a potential serving cell in a potential
serving network but initiates no MM signalling with the network and ignores any paging requests.
The mobile station shall leave eCALL INACTIVE state only when one of the following events occur:
- if the SIM or USIM is removed, the mobile station enters the NO IMSI state;
- if the mobile station is deactivated (e.g. powered off) by the user: the mobile station enters the NULL state;
- if there is a CM request for an emergency services call: the mobile station should follow the procedure for return
to state MM-IDLE in subclause 4.2.3 and attempt a location update. The MS then uses the MM and CM
procedures to establish the emergency call at the earliest opportunity; or
3GPP
Release 10 102 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: If an eCall device has not successfully completed a location update procedure, PSAP callback will not be
possible due to its calling line identity being unavailable at the PSAP.
- if there is a CM request for a call to an HPLMN designated non-emergency MSISDN for the purpose of
accessing test and terminal reconfiguration services: the mobile station follows the procedure for return to state
MM-IDLE in subclause 4.2.3 and attempts a normal location update. Once this is complete, further MM and CM
procedures are used to establish the non-emergency call.
The Mobility Management (MM) sublayer is providing connection management services to the different entities of the
upper Connection management (CM) sublayer (see 3GPP TS 24.007 [20]). It offers to a CM entity the possibility to use
an MM connection for the exchange of information with its peer entity. An MM connection is established and released
on request from a CM entity. Different CM entities communicate with their peer entity using different MM connections.
Several MM connections may be active at the same time.
An MM connection requires an RR connection. All simultaneous MM connections for a given mobile station use the
same RR connection.
In the following subclauses, the procedures for establishing, re-establishing, maintaining, and releasing an MM
connection are described, usually separately for the mobile station and the network side.
- An MM connection establishment may only be initiated by the mobile station when the following conditions are
fulfilled:
- The MM sublayer is in one of the states MM IDLE, RR CONNECTION RELEASE NOT ALLOWED or
MM connection active but not in MM connection active (Group call).
An exception from this general rule exists for emergency calls (see subclause 4.5.1.5). A further exception is
defined in the following clause.
- If an MM specific procedure is running at the time the request from the CM sublayer is received, and the
LOCATION UPDATING REQUEST message has been sent, the request will either be rejected or delayed,
depending on implementation, until the MM specific procedure is finished and, provided that the network has
not sent a "follow-on proceed" indication, the RR connection is released. If the LOCATION UPDATING
REQUEST message has not been sent, the mobile station may include a "follow-on request" indicator in the
message. The mobile station shall then delay the request until the MM specific procedure is completed, when it
may be given the opportunity by the network to use the RR connection: see subclause 4.4.4.6.
a) If no RR connection exists, the MM sublayer requests the RR sublayer to establish an RR connection and enters
MM sublayer state WAIT FOR RR CONNECTION (MM CONNECTION). This request contains an
establishment cause and a CM SERVICE REQUEST message. When the establishment of an RR connection is
3GPP
Release 10 103 3GPP TS 24.008 V10.6.1 (2012-03)
indicated by the RR sublayer, the MM sublayer of the mobile station starts timer T3230, gives an indication to
the CM entity that requested the MM connection establishment, and enters MM sublayer state WAIT FOR
OUTGOING MM CONNECTION.
b) If an RR connection is available, the MM sublayer of the mobile station sends a CM SERVICE REQUEST
message to the network, starts timer T3230, stops and resets timer T3241, gives an indication to the CM entity
that requested the MM connection establishment, and enters:
- If an RR connection exists but the mobile station is in the state WAIT FOR NETWORK COMMAND then
any requests from the CM layer that are received will either be rejected or delayed until this state is left.
If a mobile station which is in the MM sublayer state MM IDLE, service state RECEIVING GROUP CALL
(NORMAL SERVICE), receives a request from the GCC sublayer to perform an uplink access, the MM sublayer
requests the RR sublayer to perform an uplink access procedure and enters MM sublayer state WAIT FOR RR
CONNECTION (GROUP TRANSMIT MODE).
When a successful uplink access is indicated by the RR sublayer, the MM sublayer of the mobile station gives an
indication to the GCC sublayer and enters MM sublayer state MM CONNECTION ACTIVE (GROUP
TRANSMIT MODE).
When an uplink access reject is indicated by the RR sublayer, the MM sublayer of the mobile station gives an
indication to the GCC sublayer and enters the MM sublayer state MM IDLE, service state RECEIVING GROUP
CALL (NORMAL SERVICE).
In the network, if an uplink access procedure is performed, the RR sublayer in the network provides an
indication to the MM sublayer together with the mobile subscriber identity received in the TALKER
INDICATION message. The network shall then enter the MM sublayer state MM CONNECTION ACTIVE
(GROUP TRANSMIT MODE).
d) When the MS is IMSI attached for CS services via EMM combined procedures, as described in
3GPP TS 24.301 [120], and the MS is camping on an E-UTRAN cell, and if T3246 is not running, the MM
sublayer requests EMM to initiate a service request procedure for CS fallback. The MM connection
establishment is delayed until the MS changes to a GERAN or UTRAN cell.
If the MS enters a GERAN or UTRAN cell, then the MS shall initiate the MM connection establishment and
send a CM SERVICE REQUEST message. The MS shall include the Additional update parameters information
element indicating "CS fallback mobile originating call". If the MS determines that it is in a different location
area than the stored location area, the MS shall first initiate a normal location updating procedure regardless of
Network Mode of Operation. If the location area of the current cell is not available, the MS may initiate a normal
location updating procedure directly. The MM connection establishment is delayed until successful completion
of the normal location updating procedure. Additionally the MS performs routing area updating as specified in
subclause 4.7.5. If the normal location updating procedure is initiated, the MS shall indicate the "follow-on
request pending", shall include the Additional update parameters information element indicating"CS fallback
mobile originating call", and shall not include the MS network feature support information element in the
LOCATION UPDATING REQUEST message.
- CM service type identifying the requested type of transaction (e.g. mobile originating call establishment,
emergency call establishment, short message service, supplementary service activation, location services).
A MS supporting eMLPP may optionally include a priority level in the CM SERVICE REQUEST message.
3GPP
Release 10 104 3GPP TS 24.008 V10.6.1 (2012-03)
A collision may occur when a CM layer message is received by the mobile station in MM sublayer state WAIT FOR
OUTGOING MM CONNECTION or in WAIT FOR ADDITIONAL OUTGOING MM CONNECTION. In this case
the MM sublayer in the MS shall establish a new MM connection for the incoming CM message as specified in
subclause 4.5.1.3.
Upon receiving a CM SERVICE REQUEST message, the network shall analyse its content. The type of semantic
analysis may depend on other on going MM connection(s). Depending on the type of request and the current status of
the RR connection, the network may start any of the MM common procedures and RR procedures.
In A/Gb mode, the network may initiate the classmark interrogation procedure, for example, to obtain further
information on the mobile station's encryption capabilities.
The identification procedure (see subclause 4.3.3) may be invoked for instance if a TMSI provided by the mobile
station is not recognized.
The network may invoke the authentication procedure (see subclause 4.3.2) depending on the CM service type.
In A/Gb mode, the network decides also if the ciphering mode setting procedure shall be invoked (see subclause 3.4.7 in
3GPP TS 44.018 [84]).
In Iu mode, the network decides also if the security mode control procedure shall be invoked (see
3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
NOTE 1: If the CM_SERVICE_REQUEST message contains a priority level the network may use this to perform
queuing and pre-emption as defined in 3GPP TS 23.067 [88].
In A/Gb mode, an indication from the RR sublayer that the ciphering mode setting procedure is completed, or reception
of a CM SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile station.
In Iu mode, an indication from the RR sublayer that the security mode control procedure is completed, or reception of a
CM SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile station. The
procedures in subclause 4.1.1.1.1 shall always have precedence over this subclause.
In Iu mode, during a MM connection establishment for all services, except for emergency call (see subclause 4.1.1.1.1),
the security mode control procedure with activation of integrity protection shall be invoked by the network unless
integrity protection is already started (see subclause 4.1.1.1.1).
The MM connection establishment is completed, timer T3230 shall be stopped, the CM entity that requested the MM
connection shall be informed, and MM sublayer state MM CONNECTION ACTIVE is entered. The MM connection is
considered to be active.
If the service request cannot be accepted, the network returns a CM SERVICE REJECT message to the mobile station.
The reject cause information element (see subclause 10.5.3.6 and annex G) indicates the reason for rejection. The
following cause values may apply:
#6: Illegal ME
#22: Congestion
If the service request is rejected due to general NAS level mobility management congestion control, the network shall
set the MM cause value to #22 "congestion" and assign a back-off timer T3246 (see 3GPP TS 23.012 [140]).
3GPP
Release 10 105 3GPP TS 24.008 V10.6.1 (2012-03)
If no other MM connection is active, the network may start the RR connection release (see subclause 3.5 of
3GPP TS 44.018 [84] (A/Gb mode only), 3GPP TS 25.331 [23c] (UTRAN Iu mode only), or in 3GPP TS 44.118 [111]
(GERAN Iu mode only) when the CM SERVICE REJECT message is sent.
If a CM SERVICE REJECT message is received by the mobile station, timer T3230 shall be stopped, the requesting
CM sublayer entity informed. Then the mobile station shall proceed as follows:
- If the cause value is not #4 or #6 or #25 received from a CSG cell and the MS is in UTRAN Iu mode, the MM
sublayer returns to the previous state (the state where the request was received). Other MM connections shall not
be affected by the CM SERVICE REJECT message.
- If cause value #4 is received, the mobile station aborts any MM connection, deletes any TMSI, LAI and
ciphering key sequence number in the SIM/USIM, changes the update status to NOT UPDATED (and stores it in
the SIM/USIM according to subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR NETWORK
COMMAND. If subsequently the RR connection is released or aborted, this will force the mobile station to
initiate a normal location updating). Whether the CM request shall be memorized during the location updating
procedure, is a choice of implementation.
- If cause value #6 is received, the mobile station aborts any MM connection, deletes any TMSI, LAI and
ciphering key sequence number in the SIM/USIM, changes the update status to ROAMING NOT ALLOWED
(and stores it in the SIM/USIM according to subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR
NETWORK COMMAND. The mobile station shall consider the SIM/USIM as invalid for non-GPRS services
until switch-off or the SIM/USIM is removed.
- If cause value #22 is received, the T3246 value IE is present in the CM SERVICE REJECT message and the
value indicates that this timer is neither zero nor deactivated, the MS shall check whether the CM SERVICE
REJECT message with cause #22 is integrity protected and shall stop timer T3246 if it is running. If the message
is integrity protected, the MS shall start timer T3246 with the value provided in the T3246 value IE. Otherwise,
the MS shall start timer T3246 with a random value from the default range specified in table 11.1.The MS stays
in the current serving cell and applies normal cell reselection process. The service request procedure may be
started by CM layer, if it is still necessary, when timer T3246 expires or is stopped.
If cause value #22 is received, the T3246 value IE is not present in the CM SERVICE REJECT message or if the
T3246 value IE the value indicates that this timer is zero or deactivated, the same actions as on timer expiry in
subclause 4.5.1.2 shall be taken by the mobile station.
- If cause value #25 is received from a CSG cell and the MS is in UTRAN Iu mode, the MS shall check whether
the CM SERVICE REJECT message with cause #25 is integrity protected. If the message is not integrity
protected, the MS shall discard the message. Otherwise, the MS shall abort any MM connection, remove the
entry corresponding to the CSG ID and associated PLMN identity of the cell where the MS has sent the CM
SERVICE REQUEST message from the Allowed CSG list if the CSG ID and associated PLMN identity are
contained in the Allowed CSG list, and enter the MM sublayer state WAIT FOR NETWORK COMMAND. If
the CSG ID and associated PLMN identity of the cell where the MS has sent the CM SERVICE REQUEST
message is contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS 23.122 [14]
subclause 3.1A. Subsequently, after the RR connection is released or aborted, the MS applies normal cell
reselection process.
If cause value #25 is received and the cell is not a CSG cell or the MS is not in UTRAN Iu mode, the MS shall
discard the CM SERVICE REJECT message.
3GPP
Release 10 106 3GPP TS 24.008 V10.6.1 (2012-03)
If an RR connection failure occurs, except in the following implementation option case a.1, or the IMSI is
deactivated during the establishment of an MM connection, the MM connection establishment is aborted, timers
T3230 is stopped, and an indication is given to the CM entity that requested the MM connection establishment.
This shall be treated as a rejection for establishment of the new MM connection, and the MM sublayer shall
release all active MM connections.
a.1) RR connection failure in Iu mode (i.e. RRC connection release) with, for example, cause "Normal", "User
inactivity" or "Directed signalling connection re-establishment" (see 3GPP TS 25.331 [23c] and
3GPP TS 44.118 [111])
The MM connection establishment procedure shall be initiated again, if the following conditions apply:
i) The original MM connection establishment was initiated over an existing RRC connection; and
ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to the
CS signalling connection (e.g. CS authentication procedures, see subclause 4.3.2), were received after the
CM SERVICE REQUEST message was transmitted.
NOTE 1: The RRC connection release cause that triggers the re-initiation of the MM connection establishment
procedure is implementation specific.
b) T3230 expiry
If T3230 expires (i.e. no response is given but a RR connection is available) the MM connection establishment is
aborted and the requesting CM sublayer is informed. If no other MM connection exists then the mobile station
shall proceed as described in subclause 4.5.3.1 for release of the RR connection. Otherwise the mobile station
shall return to the MM sublayer state where the request of an MM connection was received, i.e. to MM sublayer
state MM connection active. Other ongoing MM connections (if any) shall not be affected.
c) Reject cause values #95, #96, #97, #99, #100, #111 received
The same actions as on timer expiry shall be taken by the mobile station.
If the mobile station detects a random access failure or RR connection establishment failure during the
establishment of an MM connection, it aborts the MM connection establishment and gives an indication to the
CM entity that requested the MM connection establishment.
NOTE 2: Further actions of the mobile station depend on the RR procedures and MM specific procedures during
which the abnormal situation has occurred and are described together with those procedures.
The MM connection establishment shall not be initiated. The MS stays in the current serving cell and applies
normal cell reselection process. The MM connection establishment may be initiated by CM layer if it is still
necessary, i.e. when access is granted or because of a cell change.
If EMM indicates that the CS fallback to GERAN or UTRAN failed, the MM sublayer shall abort the MM
connection establishment and inform the requesting CM sublayer.
The MS shall abort the MM connection establishment and stop timer T3230 if still running.
If the CM SERVICE REQUEST message contained the NAS signalling low priority indication set to "MS is
configured for NAS signalling low priority", the MS shall start timer T3246 with the "Extended wait time" value.
3GPP
Release 10 107 3GPP TS 24.008 V10.6.1 (2012-03)
The MM connection establishment is started, if still necessary, when timer T3246 expires or is stopped.
The MM connection establishment shall not be initiated unless the MS is establishing an emergency call. The
MS stays in the current serving cell and applies normal cell reselection process. The MM connection
establishment is started, if still necessary, when timer T3246 expires or is stopped.
Network side:
a) RR connection failure
The actions to be taken upon RR connection failure within a MM common procedure are described together with
that procedure. A RR connection failure occurring outside such MM common procedures, shall trigger the
release of all active MM connections if any.
Upon reception of an invalid initial message or a CM SERVICE REQUEST message with invalid content, a CM
SERVICE REJECT message shall be returned with one of the following appropriate Reject cause indications:
When the CM SERVICE REJECT message has been sent, the network may start RR connection release if no
other MM connections exist or if the abnormal condition also has influence on the other MM connections.
In A/Gb mode, when an RR connection is established (or if it already exists at the time the request is received), the MM
sublayer may initiate any of the MM common procedures (except IMSI detach); it may request the RR sublayer to
perform the RR classmark interrogation procedure, and/or the security mode setting procedure.
In Iu mode, when an RR connection is established (or if it already exists at the time the request is received), the MM
sublayer may initiate any of the MM common procedures (except IMSI detach); it may request the RR sublayer to
perform the security mode control procedure.
When all MM and RR procedures are successfully completed which the network considers necessary, the MM sublayer
will inform the requesting mobile terminating CM sublayer entity on the success of the MM connection establishment.
If an RR connection already exists and no MM specific procedure is running, the network may also establish a new
mobile terminating MM connection by sending a CM message with a new PD/TI combination.
If the MS receives the first CM message in the MM states WAIT FOR NETWORK COMMAND or RR
CONNECTION RELEASE NOT ALLOWED, the MS shall stop and reset the timers T3240 and T3241 and shall enter
the MM state MM CONNECTION ACTIVE.
3GPP
Release 10 108 3GPP TS 24.008 V10.6.1 (2012-03)
In A/Gb mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or
the security mode setting fail, this is indicated to the CM layer with an appropriate error cause.
In Iu mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or the
security mode control fail, this is indicated to the CM layer with an appropriate error cause.
If an RR connection used for a MM specific procedure exists to the mobile station, the CM request may be rejected or
delayed depending on implementation. When the MM specific procedure has been completed, the network may use the
same RR connection for the delayed CM request.
In the MM CONNECTION ACTIVE (GROUP TRANSMIT MODE) the mobile station is in RR Group transmit mode.
There shall be only one MM connection active.
When in MM CONNECTION ACTIVE (GROUP TRANSMIT MODE) state, the MM sublayer in the network shall
reject the request for the establishment of another MM connection by any CM layer.
If the RR sublayer in the network indicates a request to perform a transfer of the mobile station from RR connected
mode to RR Group transmit mode which will result in a transition from MM CONNECTION ACTIVE state to MM
CONNECTION ACTIVE (GROUP TRANSMIT MODE) state in the MM sublayer, the MM sublayer shall not allow
the transition if more than one MM connection is active with the mobile station.
In A/Gb mode, when an RR connection is established (or if it already exists at the time the request is received), the MM
sublayer may initiate any of the MM common procedures (except IMSI detach), it may request the RR sublayer to
perform the RR classmark interrogation procedure and/or the security mode setting procedure.
In Iu mode, when an RR connection is established (or if it already exists at the time the request is received), the MM
sublayer may initiate any of the MM common procedures (except IMSI detach), it may request the RR sublayer to
perform the security mode control procedure.
The network should use the information contained in the Mobile Station Classmark Type 2 IE on the mobile station's
support for "Network Initiated MO CM Connection Request" to determine whether to:
In the case of a "Network Initiated MO CM Connection Request" the network shall use the established RR connection
to send a CM SERVICE PROMPT message to the mobile station.
If the mobile station supports "Network Initiated MO CM Connection Request", the MM sublayer of the MS gives an
indication to the CM entity identified by the CM SERVICE PROMPT message and enters the MM sublayer state
PROCESS CM SERVICE PROMPT. In the state PROCESS CM SERVICE PROMPT the MM sublayer waits for either
the rejection or confirmation of the recall by the identified CM entity. Any other requests from the CM entities shall
either be rejected or delayed until this state is left.
When the identified CM entity informs the MM sublayer, that it has send the first CM message in order to start the CM
recall procedure the MM sublayer enters the state MM CONNECTION ACTIVE.
If the identified CM entity indicates that it will not perform the CM recall procedure and all MM connections are
released by their CM entities the MS shall proceed according to subclause 4.5.3.1.
If the CM SERVICE PROMPT message is received by the MS in MM sublayer states WAIT FOR OUTGOING MM
CONNECTION or in WAIT FOR ADDITIONAL OUTGOING MM CONNECTION then the mobile station shall send
an MM STATUS message with cause " Message not compatible with protocol state".
3GPP
Release 10 109 3GPP TS 24.008 V10.6.1 (2012-03)
A mobile that does not support "Network Initiated MO CM Connection Request" shall return an MM STATUS message
with cause #97 "message type non-existent or not implemented" to the network.
If the mobile station supports "Network Initiated MO CM Connection Request" but the identified CM entity in the
mobile station does not provide the associated support, then the mobile station shall send an MM STATUS message
with cause "Service option not supported". In the case of a temporary CM problem (eg lack of transaction identifiers)
then the mobile station shall send an MM STATUS message with cause "Service option temporarily out of order".
If an RR connection already exists and no MM specific procedure is running, the network may use it to send the CM
SERVICE PROMPT message.
In A/Gb mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or
the security mode setting fail, this is indicated to the CM layer in the network with an appropriate error cause.
In Iu mode, if the establishment of an RR connection is unsuccessful, or if any of the MM common procedures or the
security mode control fail, this is indicated to the CM layer in the network with an appropriate error cause.
If an RR connection used for a MM specific procedure exists to the mobile station, the "Network Initiated MO CM
Connection Request" may be rejected or delayed depending on implementation. When the MM specific procedure has
been completed, the network may use the same RR connection for the delayed "Network Initiated MO CM Connection
Request".
At reception of a paging message, the RR sublayer in the MS shall deliver a paging indication to the MM sublayer if the
paging was initiated by the MM entity in the network (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]) and the
MS shall stop the timer T3246, if running. The MS shall respond with the PAGING RESPONSE message defined in
3GPP TS 44.018 [84], subclause 9.1.25. For reasons of backward compatibility the paging response shall use the RR
protocol discriminator.
If the MS receives a paging request for CS services during an ongoing MM procedure, and the MS has already
requested the establishment of a radio connection, the MS shall ignore the paging request and the MS and the network
shall continue the MM procedure.
At reception of an indication of paging for CS services from EMM, the MS shall stop timer T3246, if it is running. The
MM sublayer in the MS requests EMM to perform the service request procedure for CS fallback.
- In A/Gb mode: ask for the establishment of an RR connection and proceed as if a paging has been received in the
lower layers;
- In Iu mode: ask for the establishment of an RRC connection and respond with the PAGING RESPONSE
message defined in 3GPP TS 44.018 [84], subclause 9.1.25. For reasons of backward compatibility the paging
response shall use the RR protocol discriminator.
If the MS determines, before sending the response to paging, that it is in a different location area than the stored
location area, the MS shall initiate a normal location updating procedure first, regardless of Network Mode of
Operation. Additionally the MS performs routing area updating as specified in subclause 4.7.5. If the location area of
the current cell is not available, the MS may initiate a normal location updating procedure directly.
When initiating the location updating procedure, the MS shall indicate "CS fallback mobile terminating call" in the
Additional update parameters IE and the MS shall not include the MS network feature support IE. The MM connection
establishment is delayed until successful completion of the normal location updating or combined routing area update
3GPP
Release 10 110 3GPP TS 24.008 V10.6.1 (2012-03)
procedure. After the completion of the normal location updating procedure, the MS shall not send the PAGING
RESPONSE message.
NOTE: For the race condition when the mobile station has a CM application request pending, the mobile station
also indicates that it has a follow-on request pending.
If EMM indicates that the CS fallback to GERAN or UTRAN failed, the MM sublayer shall abort the paging
response procedure.
When a user requests an emergency call establishment the mobile station will send a CM SERVICE REQUEST
message to the network with a CM service type information element indicating emergency call establishment. If the
network does not accept the emergency call request, e.g., because IMEI was used as identification and this capability is
not supported by the network, the network will reject the request by returning a CM SERVICE REJECT message to the
mobile station.
The reject cause information element indicates the reason for rejection. The following cause values may apply:
#3 "Illegal MS"
#6 "Illegal ME"
#22 "Congestion"
With the above defined exceptions, the procedures described for MM connection establishment in subclauses 4.5.1.1
and 4.5.1.2 shall be followed.
NOTE: Normally, the mobile station will be identified by an IMSI or a TMSI. However, if none of these
identifiers is available in the mobile station, then the mobile station shall use the IMEI for identification
purposes. The network may in that case reject the request by returning a CM SERVICE REJECT message
with reject cause: #5 "IMEI not accepted".
3GPP
Release 10 111 3GPP TS 24.008 V10.6.1 (2012-03)
delayed until the mobile station changes to a GERAN or UTRAN cell. After this point, the behaviour specified in
subclause 4.5.1.5 applies.
When the MS is not IMSI attached for CS services via EMM combined procedures, as described in
3GPP TS 24.301 [120], and the MS is camping on an E-UTRAN cell, the MS shall perform any cell selection to
GERAN or UTRAN (see 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98]). The MM connection establishment is
delayed until the MS changes to a GERAN or UTRAN cell. After this point, the behaviour specified in
subclause 4.5.1.5 applies.
The re-establishment takes place when a lower layer failure occurs and at least one MM connection is active (i.e. the
mobile station's MM sublayer is either in state 6 "MM CONNECTION ACTIVE" or state 20 "WAIT FOR
ADDITIONAL OUTGOING MM CONNECTION").
NOTE: During a re-establishment attempt the mobile station does not return to the MM IDLE state; thus no
location updating is performed even if the mobile is not updated in the location area of the selected cell.
No call re-establishment shall be performed for voice group and broadcast calls.
If at least one request to re-establish an MM connection is received from a CM entity as a response to the indication that
the MM connection is interrupted (see subclause 4.5.2.3.) the mobile station initiates the call re-establishment
procedure. If several CM entities request re-establishment only one re-establishment procedure is initiated. If any CM
entity requests re-establishment, then re-establishment of all transactions belonging to all Protocol Discriminators that
permit Call Re-establishment shall be attempted.
Upon request of a CM entity to re-establish an MM connection the MM sublayer requests the RR sublayer to establish
an RR connection and enters MM sublayer state WAIT FOR REESTABLISH. This request contains an establishment
cause and a CM RE-ESTABLISHMENT REQUEST message. When the establishment of an RR connection is indicated
by the RR sublayer, the MM sublayer of the mobile station starts timer T3230, gives an indication to all CM entities that
are being re-established, and remains in the MM sublayer state WAIT FOR REESTABLISH.
NOTE: Whether or not a CM entity can request re-establishment depends upon the Protocol Discriminator. The
specifications for Short Message Service (3GPP TS 24.011 [22]), Call Independent Supplementary
Services (3GPP TS 24.010 [21]) and Location Services (3GPP TS 44.071 [23a]) do not currently specify
any re-establishment procedures.
Upon receiving a CM RE-ESTABLISHMENT REQUEST message, the network shall analyse its content. Depending
on the type of request, the network may start any of the MM common procedures and RR procedures.
The network may initiate the classmark interrogation procedure, for example, to obtain further information on the
mobile station's encryption capabilities.
The network may invoke the authentication procedure (see subclause 4.3.2).
3GPP
Release 10 112 3GPP TS 24.008 V10.6.1 (2012-03)
In A/Gb mode, the network decides if the security mode setting procedure shall be invoked (see 3GPP TS 44.018 [84]
subclause 3.4.7).
An indication from the RR sublayer that the security mode setting procedure is completed, or reception of a CM
SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile station.
In Iu mode, the network decides if the security mode control procedure shall be invoked (see 3GPP TS 25.331 [23c] and
3GPP TS 44.118 [111]). An indication from the RR sublayer that the security mode control procedure is completed, or
reception of a CM SERVICE ACCEPT message, shall be treated as a service acceptance indication by the mobile
station.
The MM connection re-establishment is completed, timer T3230 shall be stopped, all CM entities associated with the
re-establishment shall be informed, and MM sublayer state MM CONNECTION ACTIVE is re-entered. All the MM
connections are considered to be active.
If the network cannot associate the re-establishment request with any existing call for that mobile station, a CM
SERVICE REJECT message is returned with the reject cause:
If call re-establishment cannot be performed for other reasons, a CM SERVICE REJECT is returned, the appropriate
reject cause may be any of the following (see annex G):
#6 "illegal ME";
#22 "congestion";
If the service request is rejected due to general NAS level mobility management congestion control, the network shall
set the MM cause value to #22 "congestion" and assign a back-off timer T3246 (see 3GPP TS 23.012 [140]).
Whatever the reject cause a mobile station receiving a CM SERVICE REJECT as a response to the CM RE-
ESTABLISHMENT REQUEST shall stop T3230, release all MM connections and proceed as described in
subclause 4.5.3.1. In addition:
- if cause value #4 is received, the mobile station deletes any TMSI, LAI and ciphering key sequence number in
the SIM/USIM, changes the update status to NOT UPDATED (and stores it in the SIM/USIM according to
subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR NETWORK COMMAND. If subsequently the
RR connection is released or aborted, this will force the mobile station to initiate a normal location updating. The
CM re-establishment request shall not be memorized during the location updating procedure.
- if cause value #6 is received, the mobile station deletes any TMSI, LAI and ciphering key sequence number in
the SIM/USIM, changes the update status to ROAMING NOT ALLOWED (and stores it in the SIM/USIM
according to subclause 4.1.2.2), and enters the MM sublayer state WAIT FOR NETWORK COMMAND. The
MS shall consider the SIM/USIM as invalid for non-GPRS services until switch-off or the SIM/USIM is
removed.
- If cause value # 22 is received and the T3246 value IE is present and the value indicates that this timer is neither
zero nor deactivated, the MS shall abort any MM connection, and proceed as specified in subclause 4.4.4.9. The
MS shall stop timer T3246 if it is running. If the CM SERVICE REJECT message is integrity protected, the MS
shall start timer T3246 with the value provided in the T3246 value IE. If the CM SERVICE REJECT message is
not integrity protected, the MS shall start timer T3246 with a random value from the default range specified in
table 11.1. The MS stays in the current serving cell and applies the normal cell reselection process. The CM RE-
ESTABLISHMENT REQUEST procedure should not be restarted when timer T3246 expires or is stopped.
- if cause value #25 is received from a CSG cell and the mobile station is in UTRAN Iu mode, the MS shall check
whether the CM SERVICE REJECT message with cause #25 is integrity protected. If the message is not
3GPP
Release 10 113 3GPP TS 24.008 V10.6.1 (2012-03)
integrity protected, the MS shall discard the message. Otherwise, the MS shall remove the entry corresponding
to the CSG ID and associated PLMN identity of the cell where the MS has sent the CM SERVICE REQUEST
message from the Allowed CSG list if the CSG ID and associated PLMN identity are contained in the Allowed
CSG list, and enter the MM sublayer state WAIT FOR NETWORK COMMAND. If the CSG ID and associated
PLMN identity of the cell where the MS has sent the CM SERVICE REQUEST message is contained in the
Operator CSG list, the MS shall proceed as specified in 3GPP TS 23.122 [14] subclause 3.1A.
If cause value #25 is received and the cell is not a CSG cell or the MS is not in UTRAN Iu mode, the MS shall
discard the CM SERVICE REJECT message.
If the mobile station detects a random access failure or RR connection establishment failure during the re-
establishment of an MM connection, the re-establishment is aborted and all MM connections are released.
b) RR connection failure
If a RR connection failure occurs, timer T3230 is stopped, the re-establishment is aborted and all active MM
connections are released.
c) IMSI deactivation
If the IMSI deactivated during the re-establishment attempt then timer T3230 is stopped, the re-establishment is
aborted and all MM connections are released.
d) T3230 expires
If T3230 expires (i.e. no response is given but a RR connection is available) the re-establishment is aborted, all
active MM connections are released and the mobile station proceeds as described in subclause 4.5.3.1.
The mobile station shall perform the same actions as if timer T3230 had expired.
Network side:
a) RR connection failure
If a RR connection failure occurs after receipt of the CM RE-ESTABLISHMENT REQUEST the network shall
release all MM connections.
Upon reception an invalid initial of message or a CM RE-ESTABLISHMENT REQUEST message with invalid
content, a CM SERVICE REJECT message shall be returned with one of the following appropriate Reject cause
indications:
When the CM SERVICE REJECT message has been sent, the network shall release the RR connection.
3GPP
Release 10 114 3GPP TS 24.008 V10.6.1 (2012-03)
If the first CM message has already been sent, the normal release procedure defined by the appropriate CM protocol
applies and the CM SERVICE ABORT shall not be sent.
Sending of the CM SERVICE ABORT message is only allowed during the establishment of the first MM connection,
where no other MM connection exists in parallel. If parallel MM connections exist already, a new connection
establishment cannot be aborted and normal MM connection release according to subclause 4.5.3 applies after MM
connection establishment.
Upon transmission of the CM SERVICE ABORT message the mobile station shall set timer T3240 and enter the state
WAIT FOR NETWORK COMMAND, expecting the release of the RR connection.
Upon receipt of the CM SERVICE ABORT message the network shall abort ongoing processes, release the appropriate
resources, and unless another MM connection establishment is pending, initiate a normal release of the RR connection.
If the RR connection is not released within a given time controlled by timer T3240, the mobile station shall abort the
RR connection. In both cases, either after a RR connection release triggered from the network side or after a RR
connection abort requested by the mobile station side the mobile station shall return to state MM IDLE; the service state
depending upon the current update status as specified in subclause 4.2.3.
An MS in MM state MM IDLE shall establish the MM connection locally when it receives an indication from lower
layers that a SRVCC handover was completed successfully.
After completing MM connection establishment, MM layer shall indicate "MM connection establishment due to
SRVCC handover" to upper layer and shall enter state MM CONNECTION ACTIVE.
All MM common procedures may be initiated at any time while MM connections are active. Except for Short Message
Control which uses a separate layer 2 low priority data link, no priority mechanism is defined between the CM, MM
and RR sublayer messages.
If the RR connection failure occurs during a RR or MM common procedure, the consequent actions are
described together with that procedure.
3GPP
Release 10 115 3GPP TS 24.008 V10.6.1 (2012-03)
- Mobile station:
The MM sublayer shall indicate to all CM entities associated with active MM connections that the MM
connection is interrupted, the subsequent action of the MM sublayer (call re-establishment, see 4.5.1.6, or
local release) will then depend on the decisions by the CM entities.
- Network:
The MM sublayer shall locally release all active MM connections. As an option the network may delay the
release of all or some of the MM connections to allow the mobile station to initiate call re-establishment.
If all MM connections are released by their CM entities and an RRLP procedure or LCS procedure over RRC is
ongoing, the MS shall start the timer T3241 and enter the state RR CONNECTION RELEASE NOT ALLOWED.
If the MS is expecting the release of the RR connection in MM state WAIT FOR NETWORK COMMAND and an
RRLP procedure or LCS procedure over RRC is started, the MS shall stop the timer T3240, start the timer T3241 and
enter the state RR CONNECTION RELEASE NOT ALLOWED.
If the MS is in MM state RR CONNECTION RELEASE NOT ALLOWED and the ongoing RRLP procedure or LCS
procedure over RRC is finished, the MS shall stop the timer T3241, reset and start the timer T3240 and shall enter the
state WAIT FOR NETWORK COMMAND.
If the MS receives the "Extended wait time" for CS domain from the lower layers when no location updating or CM
service request procedure is ongoing, the MS shall ignore the "Extended wait time".
In the network, if the last MM connection is released by its user, the MM sublayer may decide to release the RR
connection. The RR connection may be maintained by the network, e.g. in order to establish another MM connection.
If the RR connection is not released within a given time controlled by the timer T3240 or T3241, the mobile station
shall abort the RR connection. In both cases, either after a RR connection release triggered from the network side or
after a RR connection abort requested by the MS-side, the MS shall return to MM IDLE state; the service state
depending upon the current update status as specified in subclause 4.2.3.
If a mobile station which is in the MM sublayer state MM CONNECTION ACTIVE (GROUP TRANSMIT MODE)
receives a request from the GCC sublayer to perform an uplink release, the MM sublayer requests the RR sublayer to
perform an uplink release procedure and enters the MM sublayer state RECEIVING GROUP CALL (NORMAL
SERVICE).
With the exceptions described for the responses to the CM SERVICE PROMPT message, the actions to be taken on
receiving a MM STATUS message in the network are an implementation dependent option.
3GPP
Release 10 116 3GPP TS 24.008 V10.6.1 (2012-03)
-- ATTACH REQUEST;
-- ATTACH REJECT;
-- IDENTITY REQUEST;
-- IDENTITY RESPONSE;
In Iu mode a Radio Network Temporary Identity (RNTI) identifies a user between the MS and the UTRAN or GERAN.
The relationship between RNTI and IMSI is known only in the MS and in the UTRAN, see 3GPP TS 25.301 [128].
3GPP
Release 10 117 3GPP TS 24.008 V10.6.1 (2012-03)
If the MS is configured for "AttachWithIMSI" as specified in 3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and is
entering a new PLMN which is neither the registered PLMN nor in the list of equivalent PLMNs, the MS should
proceed as specified for case ii) below and use a randomly selected random TLLI for the transmission of the ATTACH
REQUEST message.
For all other cases, the MS shall determine the TLLI as follows:
If the MS has stored a valid P-TMSI, the MS shall derive a foreign TLLI from that P-TMSI and shall use it for
transmission of the:
- ATTACH REQUEST message of any GPRS combined/non-combined attach procedure; other GMM
messages sent during this procedure shall be transmitted using the same foreign TLLI until the ATTACH
ACCEPT message or the ATTACH REJECT message is received; and
After a successful GPRS attach or routing area update procedure, independent of whether a new P-TMSI is
assigned, if the MS has stored a valid P-TMSI then the MS shall derive a local TLLI from the stored P-TMSI
and shall use it for addressing at lower layers.
NOTE 1: Although the MS derives a local TLLI for addressing at lower layers, the network should not assume that
it will receive only LLC frames using a local TLLI. Immediately after the successful GPRS attach or
routing area update procedure, the network must be prepared to continue accepting LLC frames from the
MS still using the foreign TLLI.
When the MS has not stored a valid P-TMSI, i.e. the MS is not attached to GPRS, the MS shall use a randomly
selected random TLLI for transmission of the:
The same randomly selected random TLLI value shall be used for all message retransmission attempts and for
the cell updates within one attach attempt.
Upon receipt of an ATTACH REQUEST message, the network shall assign a P-TMSI to the MS. The network
derives a local TLLI from the assigned P-TMSI, and transmits the assigned P-TMSI to the MS.
Upon receipt of the assigned P-TMSI, the MS shall derive the local TLLI from this P-TMSI and shall use it for
addressing at lower layers.
NOTE 2: Although the MS derives a local TLLI for addressing at lower layers, the network should not assume that
it will receive only LLC frames using a local TLLI. Immediately after the successful GPRS attach, the
network must be prepared to continue accepting LLC frames from the MS still using the random TLLI.
In both cases the MS shall acknowledge the reception of the assigned P-TMSI to the network. After receipt of the
acknowledgement, the network shall use the local TLLI for addressing at lower layers.
3GPP
Release 10 118 3GPP TS 24.008 V10.6.1 (2012-03)
a) the TIN indicates "P-TMSI" or "RAT-related TMSI" and the MS holds a valid P-TMSI and a RAI;
c) the TIN is deleted and the MS holds a valid P-TMSI and RAI;
d) the TIN is deleted and the MS holds a valid GUTI, but no valid P-TMSI and RAI; or
In case a) the MS shall derive a foreign TLLI from the P-TMSI and proceed as specified for case i) above.
In case b), the MS shall derive a P-TMSI from the GUTI and then a foreign TLLI from this P-TMSI and proceed as
specified for case i) above.
NOTE 3: The mapping of the GUTI to the P-TMSI is specified in 3GPP TS 23.003 [4].
In case c) the MS shall derive a foreign TLLI from the P-TMSI and proceed as specified for case i) above.
In case d) the MS shall derive a P-TMSI from the GUTI and then a foreign TLLI from this P-TMSI and proceed as
specified for case i) above.
Upon receipt of a GMM message containing a new P-TMSI the MS shall consider the new P-TMSI and new RAI and
also the old P-TMSI and old RAI as valid in order to react to paging requests and downlink transmission of LLC
frames. For uplink transmission of LLC frames the new P-TMSI shall be used.
The MS shall consider the old P-TMSI and old RAI as invalid as soon as an LLC frame is received with the local TLLI
derived from the new P-TMSI.
Upon the transmission of a GMM message containing a new P-TMSI the network shall consider the new P-TMSI and
new RAI and also the old P-TMSI and old RAI as valid in order to be able to receive LLC frames from the MS.
The network shall consider the old P-TMSI and old RAI as invalid as soon as an LLC frame is received with the local
TLLI derived from the new P-TMSI.
Upon receipt of a GMM message containing a new P-TMSI the MS shall consider the new P-TMSI and new RAI as
valid. Old P-TMSI and old RAI are regarded as invalid.
The network shall consider the old P-TMSI and old RAI as invalid as soon as an acknowledge message (e.g. ATTACH
COMPLETE, ROUTING AREA UPDATE COMPLETE and P-TMSI REALLOCATION COMPLETE) is received.
3GPP
Release 10 119 3GPP TS 24.008 V10.6.1 (2012-03)
4.7.1.5.3 Void
4.7.1.5.4 Void
In the following tables below the abbreviations 'Iu mode I' and 'Iu mode II' are used for network operation modes I and
II in Iu mode.
4.7.1.6.1 Change of network mode of operation in A/Gb mode (A/Gb mode only)
Whenever an MS moves to a new RA, the procedures executed by the MS depend on the network mode of operation in
the old and new routing area.
Table 4.7.1.6.1-2/3GPP TS 24.008: Mode B which reverts into mode C in network operation mode III
Table 4.7.1.6.1-3/3GPP TS 24.008: Mode B which reverts into IMSI attached for CS services only in
network operation mode III
3GPP
Release 10 120 3GPP TS 24.008 V10.6.1 (2012-03)
d) In case the MS is capable of operation mode B, but reverts to IMSI attached for CS services only in network
operation mode III, and the MS is currently IMSI attached, the MS shall execute according to table 4.7.1.6.1-4:
Table 4.7.1.6.1-4/3GPP TS 24.008: Mode B which reverts into IMSI attached for CS services only in
network operation mode III while in network mode III
a) A in Iu mode, an MS that changes to GPRS operation mode A or B in A/Gb mode shall execute:
Table 4.7.1.6.5/3GPP TS 24.008: Mode A in Iu mode changing to GPRS mode A or B in A/Gb mode
3GPP
Release 10 121 3GPP TS 24.008 V10.6.1 (2012-03)
b) A in Iu mode, an MS that changes due to MS specific characteristics to GPRS operation mode C in network
operation mode III in A/Gb mode shall execute:
Table 4.7.1.6.6/3GPP TS 24.008: Mode A in Iu mode changing to GPRS mode C in A/Gb mode
c) A in Iu mode, an MS that changes due to MS specific characteristics to IMSI attached for CS services only in
network operation mode III in A/Gb mode shall execute:
Table 4.7.1.6.7/3GPP TS 24.008: Mode A in Iu mode changing to IMSI attached for CS services only in
A/Gb mode
d) C in Iu mode, the MS shall change to GPRS operation mode C in A/Gb mode and shall execute the normal
Routing Area Update procedure.
a) A or B in A/Gb mode, the MS shall change to operation mode A in Iu mode and shall execute:
3GPP
Release 10 122 3GPP TS 24.008 V10.6.1 (2012-03)
b) C in A/Gb mode, an MS that changes to operation mode C in Iu mode shall execute a Normal Routing Area
Update.
c) C in A/Gb mode, an MS that, due to MS specific characteristics operated in GPRS operation mode C in
network operation mode III in A/Gb mode changes to operation mode A in Iu mode shall execute:
d) IMSI attached for non-GPRS services only, an MS that, due to MS specific characteristics, operated in
network operation mode III in A/Gb mode and changes to operation mode A in Iu mode shall execute:
Table 4.7.1.6.10/3GPP TS 24.008: IMSI attached for non-GPRS services only changing to mode A in Iu
mode
The procedures executed by the MS depends on the network mode of operation in the old and new RA. If a
change of the network operation mode has occurred in the new RA, then the MS shall behave as specified in
subclause 4.7.1.6. If no change of the network operation mode has occurred in the new RA, then the MS shall
initiate the normal or combined RA update procedure depending on the network operation mode in the current
RA.
1) If the READY timer is running in the MS in A/Gb mode or the MS is in PMM-CONNECTED mode in Iu
mode, then the MS shall perform a normal or combined RA update procedure depending on the network
mode of operation in the current RA.
2) If the READY timer is not running in the MS in A/Gb mode or the MS is in PMM-IDLE mode in Iu mode,
then the MS shall not perform a RA update procedure (as long as the MS stays within the same RA) until up-
link user data or signalling information needs to be sent from the MS to the network, except case c) or case
b) 3) below is applicable.
- If the MS is in the same access network, A/Gb mode or Iu mode, as when it last sent user data or
signalling messages, the procedures defined for that access system shall be followed. This shall be
sending of an LLC PDU in a A/Gb mode cell or initiating the SERVICE REQUEST procedure in an Iu
mode cell.
3GPP
Release 10 123 3GPP TS 24.008 V10.6.1 (2012-03)
- If the MS is in a different access network, A/Gb mode or Iu mode, as when it last sent user data or
signalling messages, the normal or combined RA update procedure shall be performed depending on the
network operation mode in the current RA, before the sending of user data or signalling messages. If the
signalling message is a DETACH REQUEST containing cause "power off", the RA update procedure
need not to be performed.
- If the periodic routing area update timer expires the MS shall initiate the periodic RA update procedure.
3) If the READY timer is not running in the MS in A/Gb mode or the MS is in PMM-IDLE mode in Iu mode,
then the MS shall perform a normal or combined RA update procedure depending on the network mode of
operation in the current RA if the MS is required to perform routing area updating for IMS voice termination
as specified in annex P.3.
4) If the READY timer is not running in the network in A/Gb mode or the network is in PMM-IDLE mode in Iu
mode, then the network shall page the MS if down-link user data or signalling information needs to be sent
from the network to the MS. This shall include both A/Gb mode and Iu mode cells.
- If the MS receives the paging indication in the same access network, A/Gb mode or Iu mode, as when it
last sent user data or signalling information, the MS shall send any LLC PDU in a A/Gb mode cell or
shall initiate the SERVICE REQUEST procedure indicating service type "paging response" in an Iu mode
cell.
- If the MS receives the paging indication in a different access network, A/Gb mode or Iu mode, as when it
last sent user data or signalling information, the normal or combined RA update procedure shall be
performed depending on the network operation mode in the current RA.
After the successful completion of the handover from an A/Gb mode cell to an Iu mode cell, an MS which has
performed the GPRS suspension procedure in Gb mode (see 3GPP TS 44.018 [84]) (i.e. an MS in MS operation
mode B or an DTM MS in a A/Gb mode cell that does not support DTM) shall perform a normal RA update
procedure in the Iu mode cell in order to resume the GPRS services in the network, before sending any other
signalling messages or user data.
In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The PLMN
identity chosen for a GPRS attach procedure, or the PLMN identity used to construct the RAI that triggered the routing
area updating procedure shall be added to the list of "forbidden PLMNs for GPRS service" whenever such a procedure
is rejected by the network with the cause "GPRS services not allowed in this PLMN". Whenever a GPRS detach is
initiated by the network with the cause "GPRS services not allowed in this PLMN", the chosen PLMN identity shall be
added to the list of "forbidden PLMNs for GPRS service".
The maximum number of possible entries in this list is implementation dependent, but must be at least one entry. When
the list is full and a new entry has to be inserted, the oldest entry shall be deleted.
a) if the TIN indicates "P-TMSI" or "RAT-related TMSI", and the MS holds a valid P-TMSI, the MS NAS shall
provide the lower layers with the P-TMSI;
b) if the TIN indicates "GUTI" and the MS holds a valid GUTI, the MS NAS shall provide the lower layers with the
P-TMSI mapped from the GUTI (see 3GPP TS 23.003 [10]);
3GPP
Release 10 124 3GPP TS 24.008 V10.6.1 (2012-03)
c) if the TIN is not available and the MS holds a valid P-TMSI, the MS NAS shall provide the lower layers with the
P-TMSI; or
d) if the TIN is not available and the MS holds a valid GUTI, but no valid P-TMSI, the MS NAS shall provide the
lower layers with the P-TMSI mapped from the GUTI (see 3GPP TS 23.003 [10]).
a) the MS receives any of the reject cause values #11, #12, #13, #15 or #25;
b) the network indicates "no follow-on proceed" in the ROUTING AREA UPDATE ACCEPT or ATTACH
ACCEPT message; or
c) the MS receives a DETACH ACCEPT message while the T3346 timer is running and the MS has set the detach
type to "IMSI detach" in the DETACH REQUEST message and user plane radio access bearers have not been set
up.
Upon expiry of T3340, the MS shall release the established PS signalling connection (see 3GPP TS 25.331 [23c] and
3GPP TS 44.118 [111]).
In case b, if the MS has signalling pending, then it shall request a new PS signalling connection for further signalling.
In case c,
- upon an indication from the lower layers that radio access bearer(s) is set up, the MS shall stop timer T3340 and
may send uplink signalling via the existing PS signalling connection or user data via radio access bearer(s); or
- upon receipt of a DETACH REQUEST message, the MS shall stop timer T3340 and respond to the network
initiated GPRS detach as specified in subclause 4.7.4.2.
If the MS receives the "Extended wait time" for PS domain from the lower layers when no attach, routing area updating
or service request procedure is ongoing, the MS shall ignore the "Extended wait time".
When the READY timer is running or has been deactivated the MS shall perform cell update each time a new cell is
selected (see 3GPP TS 43.022 [82]). If a routing area border is crossed, a routing area updating procedure shall be
performed instead of a cell update.
- the MS shall perform the routing area updating procedure when a routing area border is crossed;
- the MS shall not perform a cell update when a new cell is selected.
- the network shall page the MS if down-link user data or signalling information needs to be sent to the MS.
All other GMM procedures are not affected by the READY timer.
3GPP
Release 10 125 3GPP TS 24.008 V10.6.1 (2012-03)
- in the MS when the GMM entity receives an indication from lower layers that an LLC frame other than LLC
NULL frame has been transmitted on the radio interface; and
- in the network when the GMM entity receives an indication from lower layers that an LLC frame other than
LLC NULL frame has been successfully received by the network.
Within GMM signalling procedures the network includes a "force to standby" information element, in order to indicate
whether or not the READY timer shall be stopped when returning to the GMM-REGISTERED state. If the "force to
standby" information element is received within more than one message during a ongoing GMM specific procedure, the
last one received shall apply. If the READY timer is deactivated and the network indicates "force to standby" with the
"force to standby" information element, this shall not cause a modification of the READY timer.
The READY timer is not affected by state transitions to and from the GMM-REGISTERED.SUSPENDED sub-state.
The value of the READY timer may be negotiated between the MS and the network using the GPRS attach or GPRS
routing area updating procedure.
- If the MS wishes to indicate its preference for a READY timer value it shall include the preferred values into the
ATTACH REQUEST and/or ROUTING AREA UPDATE REQUEST messages. The preferred values may be
smaller, equal to or greater than the default values or may be equal to the value requesting the READY Timer
function to be deactivated.
- Regardless of whether or not a timer value has been received by the network in the ATTACH REQUEST or
ROUTING AREA UPDATE REQUEST messages, the network may include a timer value for the READY timer
(different or not from the default value) into the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT
messages, respectively. If the READY Timer value was included, it shall be applied for the GMM context by the
network and by the MS.
- When the MS proposes a READY Timer value and the Network does not include any READY Timer Value in its
answer, then the value proposed by the MS shall be applied for the GMM context by the Network and by the
MS.
- When neither the MS nor the Network proposes a READY Timer value into the ATTACH REQUEST/ATTACH
ACCEPT or ROUTING AREA UPDATE REQUEST/ROUTING AREA UPDATE ACCEPT message, then the
default value shall be used.
If the negotiated READY timer value indicates that the ready timer function is deactivated, the READY timer shall
always run without expiry. If the negotiated READY timer value indicates that the ready timer function is deactivated,
and within the same procedure the network indicates "force to standby" with the "force to standby" information
element, the READY timer shall always run without expiry. If the negotiated READY timer value is set to zero, the
READY timer shall be stopped immediately.
To account for the LLC frame uplink transmission delay, the READY timer value should be slightly shorter in the
network than in the MS. This is a network implementation issue.
If a new READY timer value is negotiated, the MS shall upon the reception of the ATTACH ACCEPT or ROUTING
AREA UPDATE ACCEPT message perform an initial cell update (either by transmitting a LLC frame or, if required, a
ATTACH COMPLETE or ROUTING AREA UPDATE COMPLETE message), in order to apply the new READY
timer value immediately. If both the network and the MS support the Cell Notification, the initial cell update shall use
any LLC frame except the LLC NULL frame. If the new READY timer value is set to zero or if the network indicates
"force to standby" with the "force to standby" IE, the initial cell update should not be done.
An MS may indicate a READY timer value to the network in the ATTACH REQUEST and the ROUTING AREA
UPDATE REQUEST messages.
If a READY timer value is received by an MS capable of both Iu mode and A/Gb mode in the ATTACH ACCEPT or the
ROUTING AREA UPDATE ACCEPT messages, then the received value shall be stored by the MS in order to be used
at an intersystem change from Iu mode to A/Gb mode.
3GPP
Release 10 126 3GPP TS 24.008 V10.6.1 (2012-03)
If the T3312 received by the MS in A/Gb mode or received in Iu mode in a message with integrity protection contains
an indication that the timer is deactivated or the timer value is zero, then the periodic routing area update timer is
deactivated and the MS shall not perform periodic routing area updating.
In Iu mode, if the value of timer T3312 is received in a message without integrity protection and the indicated value is
larger than the last received value, or the indicated value is "deactivated" or zero, the MS shall use the last received
value.
In A/Gb mode, the timer T3312 is reset and started with its initial value, when the READY timer is stopped or expires.
The timer T3312 is stopped and shall be set to its initial value for the next start when the READY timer is started. If
after a READY timer negotiation the READY timer value is set to zero, timer T3312 is reset and started with its initial
value. If the initial READY timer value is zero, the timer T3312 is reset and started with its initial value, when the
ROUTING AREA UPDATE REQUEST message is transmitted.
In Iu mode, the timer T3312 is reset and started with its initial value, when the MS goes from PMM-CONNECTED to
PMM-IDLE mode. The timer T3312 is stopped when the MS enters PMM-CONNECTED mode.
If the MS is attached for emergency bearer services, when timer T3312 expires, the MS shall not initiate a periodic
RAU procedure, but shall locally detach from the network.
If the MS is not attached for emergency bearer services, when timer T3312 expires, the periodic routing area updating
procedure shall be started and the timer shall be set to its initial value for the next start.
If the MS is in other state than GMM-REGISTERED.NORMAL-SERVICE when the timer expires the periodic routing
area updating procedure is delayed until the MS returns to GMM-REGISTERED.NORMAL-SERVICE.
In A/Gb mode, if the MS in MS operation mode B is in the state GMM-REGISTERED.SUSPENDED when the timer
expires the periodic routing area updating procedure is delayed until the state is left.
If ISR is activated, the MS shall keep both the periodic tracking area update timer (timer T3412) and the periodic
routeing area update timer (timer T3312). The two separate timers run in the MS for updating MME and SGSN
independently. If the periodic routeing area update timer expires and the timer T3346 is running, the MS shall start the
GERAN/UTRAN Deactivate ISR timer T3323. If the periodic routeing area update timer expires and the MS is in state
GMM-REGISTERED.NO-CELL-AVAILABLE, the MS shall start the GERAN/UTRAN Deactivate ISR timer T3323.
The MS shall initiate the routeing area updating procedure and stop the timer T3323 when the MS enters the state
GMM-REGISTERED.NORMAL-SERVICE before timer T3323 expires. After expiry of timer T3323 the MS shall
deactivate ISR by setting its TIN to "GUTI".
If the GERAN/UTRAN Deactivate ISR timer T3323 expires the MS shall memorize that it has to initiate a routing area
updating procedure when it returns to state GMM-REGISTERED.NORMAL-SERVICE and the timer T3346 is not
running.
The network supervises the periodic routing area updating procedure by means of the Mobile Reachable timer.
If the MS is not attached for emergency bearer services, the Mobile Reachable timer shall be longer than the periodic
RA update timer T3312. In this case, by default, the Mobile Reachable timer is 4 minutes greater than the periodic RA
update timer. If the network includes T3312 extended value IE in the ATTACH ACCEPT message or ROUTING AREA
UPDATE ACCEPT message, the network shall use T3312 extended value IE as the value of timer T3312.
If ISR is not activated, when the Mobile Reachable timer expires, typically the network stops sending paging messages
to the mobile and may take other appropriate actions.
If the MS is attached for emergency bearer services, the SGSN shall set the mobile reachable timer with a value equal to
T3312. When the mobile reachable timer expires, the SGSN shall locally detach the MS.
In A/Gb mode, the Mobile Reachable timer is reset and started with the value as indicated above, when the READY
timer is stopped or expires. The Mobile Reachable timer is stopped when the READY timer is started.
3GPP
Release 10 127 3GPP TS 24.008 V10.6.1 (2012-03)
In A/Gb mode, if after a READY timer negotiation the READY timer value is set to zero the Mobile Reachable timer is
reset and started with its initial value. If the initial READY timer value is zero, the Mobile Reachable is reset and
started with its initial value, when the ROUTING AREA UPDATE REQUEST message is received.
In Iu mode, the Mobile Reachable timer is reset and started with the value as indicated above, when the MS goes from
PMM-CONNECTED to PMM-IDLE mode. The Mobile Reachable timer is stopped when the MS enters PMM-
CONNECTED mode.
If ISR is activated, upon expiry of the Mobile Reachable timer the network shall start the Implicit Detach timer. By
default, the Implicit Detach timer is 4 minutes greater than timer T3323. If the Implicit Detach timer expires before the
MS contacts the network, the network shall implicitly detach the MS and deactivate ISR.
If ISR is not activated, upon expiry of the Mobile Reachable timer the network may start the Implicit Detach timer. The
value of the Implicit Detach timer is network dependent. If the Implicit Detach timer expires before the MS contacts the
network, the network shall implicitly detach the MS.
If the SGSN includes timer T3346 in the ROUTING AREA UPDATE REJECT message or the SERVICE REJECT
message and timer T3346 is greater than timer T3312, the SGSN sets the mobile reachable timer and the implicit detach
timer such that the sum of the timer values is greater than timer T3346.
If the MS is both IMSI attached for GPRS and non-GPRS services, and if the MS lost coverage of the registered PLMN
and timer T3312 expires or timer T3323 expires, then:
a) if the MS returns to coverage in a cell that supports GPRS and that indicates that the network is in network
operation mode I, then the MS shall either perform the combined routing area update procedure indicating
"combined RA/LA updating with IMSI attach"; or
b) if the MS returns to coverage in a cell in the same RA that supports GPRS and that indicates that the network is
in network operation mode II or III, then the MS shall perform the periodic routing area updating procedure
indicating "Periodic updating"; or
c) if the MS was both IMSI attached for GPRS and non-GPRS services in network operation mode I and the MS
returns to coverage in a cell in the same LA that does not support GPRS, then the MS shall perform the periodic
location updating procedure. In addition, the MS shall perform a combined routing area update procedure
indicating "combined RA/LA updating with IMSI attach" when the MS enters a cell that supports GPRS and that
indicates that the network is in network operation mode I; or
d) if the MS returns to coverage in a new RA the description given in subclause 4.7.5 applies.
If this subclause specifies that the MS shall perform a periodic routing area updating procedure, but subclause 4.7.5
specifies the MS shall perform a normal or combined routing area updating procedure, the description in
subclause 4.7.5 takes precedence.
If the MS is both IMSI attached for GPRS and non-GPRS services in a network that operates in network operation
mode I, and if the MS has camped on a cell that does not support GPRS, and timer T3312 expires or timer T3323
expires, then the MS shall start an MM location updating procedure. In addition, the MS shall perform a combined
routing area update procedure indicating "combined RA/LA updating with IMSI attach" when the MS enters a cell that
supports GPRS and indicates that the network is in operation mode I.
If timer T3312 expires or timer T3323 expires during an ongoing CS connection, then a MS operating in MS operation
mode B shall treat the expiry of T3312 when the MM state MM-IDLE is entered, analogous to the descriptions for the
cases when the timer expires out of coverage or in a cell that does not support GPRS.
In A/Gb mode, timer T3312 and timer T3323 shall not be stopped when a GPRS MS enters state GMM-
REGISTERED.SUSPENDED.
An MS shall enter PMM-IDLE mode when the PS signalling connection for packet switched domain between the MS
and the network has been released. The MS shall perform periodic routing area update in PMM-IDLE mode.
3GPP
Release 10 128 3GPP TS 24.008 V10.6.1 (2012-03)
The network shall always indicate Force to standby not indicated in the Force to standby information element.
- normal GPRS attach, performed by the MS to IMSI attach for GPRS services only. The normal GPRS attach
procedure shall be used:
- by GPRS MSs in MS operation modes A or B if the network operates in network operation mode II or III;
and
- by GPRS MSs in MS operation mode A, independent of the network operation mode, if a circuit-switched
transaction is ongoing;
- combined GPRS attach procedure, used by GPRS MSs in MS operation modes A or B to attach the IMSI for
GPRS and non-GPRS services provided that the network operates in network operation mode I.
- GPRS attach for emergency bearer services, performed by the MS to IMSI or IMEI attach to emergency bearer
services.
When the timer T3346 is running, MS is allowed to initiate an attach procedure if:
An eCall only mobile station shall not perform a normal or combined GPRS attach procedure.
Subclause 4.7.3.1 describes the GPRS attach procedure to attach the IMSI only for GPRS services. The combined
GPRS attach procedure used to attach the IMSI for both GPRS and non-GPRS services is described in
subclause 4.7.3.2. GPRS attach for emergency bearer services is described as part of subclause 4.7.3.1.
If an IMSI attach for non-GPRS services is requested and a GMM context exists, the routing area updating procedure
shall be used as described in subclause 4.7.5.2.
3GPP
Release 10 129 3GPP TS 24.008 V10.6.1 (2012-03)
To limit the number of subsequently rejected attach attempts, a GPRS attach attempt counter is introduced. The GPRS
attach attempt counter shall be incremented as specified in subclause 4.7.3.1.5. Depending on the value of the GPRS
attach attempt counter, specific actions shall be performed. The GPRS attach attempt counter shall be reset when:
- a SIM/USIM is inserted;
- a combined GPRS attach procedure is completed for GPRS services only with cause #2, #16, #17 or #22;
- a GPRS attach procedure is completed with cause #11, #12, #13, #14 ,#15 or #25;
- a network initiated detach procedure is completed with cause #11, #12, #13, #14, #15 or #25;
The mobile equipment shall contain a list of "forbidden location areas for roaming", as well as a list of "forbidden
location areas for regional provision of service". The handling of these lists is described in subclause 4.4.1; the same
lists are used by GMM and MM procedures.
The Mobile Equipment shall contain a list of "equivalent PLMNs". The handling of this list is described in
subclause 4.4.1, the same list is used by GMM and MM procedures.
In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The MS
shall construct the Routing Area Identification of the cell from this chosen PLMN identity, and the LAC and the RAC
received on the BCCH. The chosen PLMN identity shall be indicated to the UTRAN in the RRC INITIAL DIRECT
TRANSFER message (see 3GPP TS 25.331 [23c]). Whenever an ATTACH REJECT message with the cause "PLMN
not allowed" is received by the MS, the chosen PLMN indentity shall be stored in the "forbidden PLMN list".
Whenever an ATTACH REJECT message is received by the MS with the cause "Roaming not allowed in this location
area", "Location Area not allowed", or "No suitable cells in Location Area", the LAI that is part of the constructed RAI
shall be stored in the suitable list.
The network informs the MS about the support of specific features, such as LCS-MOLR, MBMS, IMS voice over PS
session, or emergency bearer services in Iu mode in the "Network feature support" Information Element. The
information is either explicitly given by sending the "Network feature support" IE or implicitly by not sending it. The
handling in the network is described in subclause 9.4.2.9. The MS may use the support indications for LCS-MOLR and
MBMS to inform the user about the availability of the appropriate services. The MS shall not request any of these two
services, if the service has not been indicated as available. The indication for MBMS is defined in subclause "MBMS
feature support indication" in 3GPP TS 23.246 [106]. In an MS with IMS voice over PS capability, the IMS voice over
PS session indicator and the emergency bearer services indicator shall be provided to the upper layers. The upper layers
take the IMS voice over PS session indicator into account as specified in 3GPP TS 23.221 [131], subclause 7.2a and
subclause 7.2b, when selecting the access domain for voice sessions or calls in Iu mode. When initiating an emergency
call in Iu mode, the upper layers also take the emergency bearer services indicator into account for the access domain
selection.
The attach type information element shall indicate "GPRS attach". For an MS attaching for emergency bearer services
the attach type information element shall indicate "Emergency attach".
3GPP
Release 10 130 3GPP TS 24.008 V10.6.1 (2012-03)
If the MS is configured for "AttachWithIMSI" as specified in 3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and the
selected PLMN is neither the registered PLMN nor in the list of equivalent PLMNs, the MS shall include the IMSI in
the Mobile identity IE in the ATTACH REQUEST message.
For all other cases, the MS shall handle the Mobile identity IE in the ATTACH REQUEST message as follows:
- the MS capable of both Iu mode and A/Gb mode or only of A/Gb mode shall include a valid P-TMSI, if any is
available, the P-TMSI signature associated with the P-TMSI and the routing area identity associated with the P-
TMSI in the ATTACH REQUEST message. In addition, the MS shall include P-TMSI type IE with P-TMSI type
set to "native P-TMSI". If there is no valid P-TMSI available, the IMSI shall be included instead of the P-TMSI
and P-TMSI signature.
- if the TIN indicates "GUTI" and the MS holds a valid GUTI, the MS shall map the GUTI into the Mobile
identity IE, P-TMSI signature IE and Old routing area identification IE. The MS shall also include P-TMSI type
IE with P-TMSI type set to "mapped P-TMSI". Additionally, if the MS holds a valid P-TMSI and RAI, the MS
shall indicate the P-TMSI in the Additional mobile identity IE and the RAI in the Additional old routing area
identification IE.
NOTE: The mapping of the GUTI to the P-TMSI, P-TMSI signature and RAI is specified in 3GPP TS 23.003 [4].
- If the TIN indicates "P-TMSI" or "RAT-related TMSI" and the MS holds a valid P-TMSI and a RAI, the MS
shall indicate the P-TMSI in the Mobile identity IE and the RAI in the Old routing area identification IE. The
MS shall also include P-TMSI type IE with P-TMSI type set to "native P-TMSI". If a P-TMSI signature is
associated with the P-TMSI, the MS shall include it in the Old P-TMSI signature IE.
- the MS holds a valid P-TMSI and a RAI, the MS shall indicate the P-TMSI in the Mobile identity IE and the
RAI in the Old routing area identification IE. The MS shall also include P-TMSI type IE with P-TMSI type
set to "native P-TMSI". If a P-TMSI signature is associated with the P-TMSI, the MS shall include it in the
Old P-TMSI signature IE; or
- the MS does not hold a valid P-TMSI and RAI, but holds a valid GUTI, the MS shall map the GUTI into the
Mobile identity IE, P-TMSI signature IE and Old routing area identification IE. The MS shall also include P-
TMSI type IE with P-TMSI type set to "mapped P-TMSI"; or
- the MS does not hold a valid P-TMSI, RAI or GUTI, the MS shall include the IMSI in the Mobile identity
IE.
- Otherwise the MS shall include the IMSI in the Mobile identity IE.
In the cases when the MS maps a GUTI into the Mobile identity IE, P-TMSI signature IE and Old routing area
identification IE, then:
- If a current EPS security exists, the P-TMSI signature shall include a truncated NAS token as specified in
3GPP TS 33.401 [119]. In the GPRS ciphering key sequence number IE, the MS shall indicate the value of the
eKSI associated with the current EPS security context. The MS shall derive CK' and IK' from the KASME and the
NAS uplink COUNT value corresponding to the NAS token derived and handle the START value as specified in
3GPP TS 25.331 [23c]. Then, the MS shall store the mapped UMTS security context replacing the established
UMTS security context for the PS domain.
- If a current EPS security does not exist, the MS shall set the truncated NAS token included in the P-TMSI
signature to all zeros and the GPRS ciphering key sequence number to "No key is available".
If the MS is attaching for emergency bearer services and does not hold a valid GUTI, Mobile identity as described
above, the IMEI shall be included in the Mobile identity IE.
3GPP
Release 10 131 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall also indicate within the DRX parameters whether it supports the split pg cycle option on CCCH. The
optional support of the split pg cycle on CCCH by the network is indicated in SI13 or PSI1. Split pg cycle on CCCH is
applied by both the network and the MS when the split pg cycle option is supported by both (see 3GPP TS 45.002 [32]).
In Iu mode, if the MS wishes to prolong the established PS signalling connection after the GPRS attach procedure (for
example, the MS has any CM application request pending), it may set a follow-on request pending indicator on (see
subclause 4.7.13).
An MS attaching for emergency bearer services shall set the follow-on request pending indicator.
The network may initiate GMM common procedures, e.g. the GMM identification and GMM authentication and
ciphering procedure, depending on the received information such as IMSI, CKSN, old RAI, P-TMSI and P-TMSI
signature.
If the GPRS attach request is accepted by the network, an ATTACH ACCEPT message is sent to the MS.
The P-TMSI reallocation may be part of the GPRS attach procedure. When the ATTACH REQUEST includes the IMSI
or IMEI, the SGSN shall allocate the P-TMSI. The P-TMSI that shall be allocated is then included in the ATTACH
ACCEPT message together with the routing area identifier. The network shall, in this case, change to state GMM-
COMMON-PROCEDURE-INITIATED and shall start timer T3350 as described in subclause 4.7.6. Furthermore, the
network may assign a P-TMSI signature for the GMM context which is then also included in the ATTACH ACCEPT
message. If the LAI or PLMN identity that has been transmitted in the ATTACH ACCEPT message is a member of any
of the "forbidden" lists, any such entry shall be deleted. If the attach procedure is for emergency bearer services, the
"forbidden" lists shall remain unchanged. Additionally, the network shall include the radio priority level to be used by
the MS for mobile originated SMS transfer in the ATTACH ACCEPT message. In a shared network, if the MS is
supporting network sharing, the network shall indicate the PLMN identity of the CN operator that has accepted the
GPRS attach request in the RAI contained in the ATTACH ACCEPT message; if the MS is not supporting network
sharing, the network shall indicate the PLMN identity of the common PLMN (see 3GPP TS 23.251 [109]).
In a multi-operator core network (MOCN) with common GERAN, the network shall indicate in the RAI the common
PLMN identity (see 3GPP TS 23.251 [109]).
If the MS has indicated in the ATTACH REQUEST message that it supports PS inter-RAT handover from GERAN to
UTRAN Iu mode, the network may include in the ATTACH ACCEPT message a request to provide the Inter RAT
information container.
If the MS has indicated in the ATTACH REQUEST message that it supports PS inter-RAT HO from GERAN to E-
UTRAN, the network may include in the ATTACH ACCEPT message a request to provide the E-UTRAN inter RAT
information container.
If the MS has included the MS network capability IE or the UE network capability IE or both in the ATTACH
REQUEST message, the network shall store all octets received from the MS, up to the maximum length defined for the
respective information element.
NOTE 1: This information is forwarded to the new SGSN during inter-SGSN handover or to the new MME during
intersystem handover to S1 mode.
3GPP
Release 10 132 3GPP TS 24.008 V10.6.1 (2012-03)
If the DRX parameter was included in the DRX Parameter IE in the ATTACH REQUEST message, the network shall
replace any stored DRX parameter with the received parameter and use it for the downlink transfer of signalling and
user data.
In A/Gb mode, the Cell Notification information element shall be included in the ATTACH ACCEPT message by the
network which indicates that the Cell Notification is supported by the network.
In Iu mode, the network should prolong the PS signalling connection if the mobile station has indicated a follow-on
request pending in ATTACH REQUEST. The network may also prolong the PS signalling connection without any
indication from the mobile terminal.
The MS, receiving an ATTACH ACCEPT message, stores the received routing area identification, stops timer T3310,
reset the GPRS attach attempt counter, reset the routing area updating attempt counter, enters state GMM-
REGISTERED and sets the GPRS update status to GU1 UPDATED.
If the message contains a P-TMSI, the MS shall use this P-TMSI as the new temporary identity for GPRS services. In
this case, an ATTACH COMPLETE message is returned to the network. The MS shall delete its old P-TMSI and shall
store the new one. If no P-TMSI has been included by the network in the ATTACH ACCEPT message, the old P-TMSI,
if any available, shall be kept.
If the message contains a P-TMSI signature, the MS shall use this P-TMSI signature as the new temporary signature for
the GMM context. The MS shall delete its old P-TMSI signature, if any is available, and shall store the new one. If the
message contains no P-TMSI signature, the old P-TMSI signature, if available, shall be deleted.
Upon receiving the ATTACH ACCEPT message an MS supporting S1 mode shall set the TIN to "P-TMSI".
If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover
information or both, the MS shall return an ATTACH COMPLETE message including the Inter RAT handover
information IE or the E-UTRAN inter RAT handover information IE or both to the network.
The network may also send a list of "equivalent PLMNs" in the ATTACH ACCEPT message. Each entry of the list
contains a PLMN code (MCC+MNC). The mobile station shall store the list, as provided by the network, and if the
GPRS attach procedure is not for emergency bearer services, any PLMN code that is already in the "forbidden PLMN"
list shall be removed from the "equivalent PLMNs" list before it is stored by the mobile station. In addition the mobile
station shall add to the stored list the PLMN code of the registered PLMN that sent the list. All PLMNs in the stored list
shall be regarded as equivalent to each other for PLMN selection, cell selection/re-selection and handover. The stored
list in the mobile station shall be replaced on each occurrence of the ATTACH ACCEPT message. If no list is contained
in the message, then the stored list in the mobile station shall be deleted. An MS attached for emergency bearer services
shall delete the stored list when the MS enters the state GMM-DEREGISTERED. The list shall be stored in the mobile
station while switched off so that it can be used for PLMN selection after switch on.
If the ATTACH ACCEPT message contains T3312 extended value IE, then the MS shall use the T3312 extended value
IE as periodic routing area update timer (T3312). If the ATTACH ACCEPT message does not contain T3312 extended
value IE, then the MS shall use the T3312 value IE as periodic routing area update timer (T3312).
In Iu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has
indicated "follow-on request pending" in ATTACH REQUEST message) the network shall indicate the "follow-on
proceed" in the ATTACH ACCEPT message. If the network wishes to release the PS signalling connection, the network
shall indicate "no follow-on proceed" in the ATTACH ACCEPT message.
After that in Iu mode, the mobile station shall act according to the follow-on proceed flag included in the Attach result
information element in the ATTACH ACCEPT message (see subclause 4.7.13).
In A/Gb mode, if the ATTACH ACCEPT message contains the Cell Notification information element, then the MS shall
start to use the LLC NULL frame to perform cell updates. The network receiving an ATTACH COMPLETE message
stops timer T3350, changes to GMM-REGISTERED state and considers the P-TMSI sent in the ATTACH ACCEPT
message as valid.
The network may also send a list of local emergency numbers in the ATTACH ACCEPT, by including the Emergency
Number List IE. The mobile equipment shall store the list, as provided by the network, except that any emergency
number that is already stored in the SIM/USIM shall be removed from the list before it is stored by the mobile
equipment. If there are no emergency numbers stored on the SIM/USIM, then before storing the received list the mobile
equipment shall remove from it any emergency number stored permanently in the ME for use in this case (see 3GPP TS
3GPP
Release 10 133 3GPP TS 24.008 V10.6.1 (2012-03)
22.101 [8]). The list stored in the mobile equipment shall be replaced on each receipt of a new Emergency Number List
IE.
The emergency number(s) received in the Emergency Number List IE are valid only in networks with the same MCC as
in the cell on which this IE is received. If no list is contained in the ATTACH ACCEPT message, then the stored list in
the mobile equipment shall be kept, except if the mobile equipment has successfully registered to a PLMN with an
MCC different from that of the last registered PLMN.
The mobile equipment shall use the stored list of emergency numbers received from the network in addition to the
emergency numbers stored on the SIM/USIM or ME to detect that the number dialled is an emergency number.
NOTE 2: The mobile equipment may use the emergency numbers list to assist the end user in determining whether
the dialled number is intended for an emergency service or for another destination, e.g. a local directory
service. The possible interactions with the end user are implementation specific.
The list of emergency numbers shall be deleted at switch off and removal of the SIM/USIM. The mobile equipment
shall be able to store up to ten local emergency numbers received from the network.
If the MS has initiated the attach procedure due to manual CSG selection and receives an ATTACH ACCEPT message,
and the MS sent the ATTACH REQUEST message in a CSG cell, the MS shall check if the CSG ID and associated
PLMN identity of the cell are contained in the Allowed CSG list. If not, the MS shall add that CSG ID and associated
PLMN identity to the Allowed CSG list and the MS may add the HNB Name (if provided by lower layers) to the
Allowed CSG list if the HNB Name is present in neither the Operator CSG list nor the Allowed CSG list.
If the attach request is rejected due to NAS level mobility management congestion control, the network shall set the
GMM cause value to #22 "congestion" and assign a back-off timer T3346.
The MS shall then take one of the following actions depending upon the reject cause:
#3 (Illegal MS);
#6 (Illegal ME);
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The new GMM state is GMM-DEREGISTERED. The SIM/USIM shall be considered as invalid for
GPRS services until switching off or the SIM/USIM is removed.
If the MS is IMSI attached, the MS shall in addition set the update status to U3 ROAMING NOT ALLOWED,
shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in MS operation mode A
and an RR connection exists, the MS shall abort the RR connection, unless an emergency call is ongoing. The
SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or the SIM/USIM is
removed.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
attach procedure is rejected with the EMM cause with the same value.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM
is removed. The new state is GMM-DEREGISTERED.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
attach procedure is rejected with the EMM cause with the same value.
3GPP
Release 10 134 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The new GMM state is GMM-DEREGISTERED.
The MS shall set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI and
ciphering key sequence number. If the MS is operating in MS operation mode A and an RR connection exists,
the MS shall abort the RR connection, unless an emergency call is ongoing. The SIM/USIM shall be considered
as invalid for GPRS and non-GPRS services until switching off or the SIM/USIM is removed.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and shall change to state GMM-
DEREGISTERED.
The MS shall store the PLMN identity in the "forbidden PLMN list".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE.
The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98].
NOTE 1: The cell selection procedure is not applicable for an MS in GAN mode.
3GPP
Release 10 135 3GPP TS 24.008 V10.6.1 (2012-03)
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE or optionally to GMM-DEREGISTERED.PLMN-SEARCH.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) , shall reset the GPRS attach attempt counter and shall change to state GMM-
DEREGISTERED.
The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list. A GPRS MS operating
in MS operation mode C shall perform a PLMN selection instead of a cell selection.
A GPRS MS operating in MS operation mode A or B in network operation mode II or III, is still IMSI attached
for CS services in the network.
As an implementation option, a GPRS MS operating in operation mode A or B may perform the following
additional action. If no RR connection exists the MS may perform the action immediately. If the MS is operating
in MS operation mode A and an RR connection exists, the MS may only perform the action when the RR
connection is subsequently released:
If an MS in GAN mode performs a PLMN selection, it shall request a PLMN list in GAN (see
3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23.122 [14].
The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause
is:
- On the "User Controlled PLMN Selector with Access Technology " list or,
- On the "Operator Controlled PLMN Selector with Access Technology " list or,
- A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above.
3GPP
Release 10 136 3GPP TS 24.008 V10.6.1 (2012-03)
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
- The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121].
NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the attach procedure is rejected with the EMM cause with the same value.
# 22 (Congestion);
If the T3346 value IE is present in the ATTACH REJECT message and the value indicates that this timer is
neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be considered as an
abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.3.1.5.
The MS shall abort the attach procedure, reset the attach attempt counter, set the GPRS update status to GU2
NOT UPDATED and enter state GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH.
If the ATTACH REJECT message is integrity protected, the MS shall start timer T3346 with the value provided
in the T3346 value IE.
If the ATTACH REJECT message is not integrity protected, the MS shall start timer T3346 with a random value
from the default range specified in table 11.3a.
The MS stays in the current serving cell and applies the normal cell reselection process. The attach procedure is
started if still needed when timer T3346 expires or is stopped.
Cause #25 is only applicable in UTRAN Iu mode and when received from a CSG cell. Other cases are
considered as abnormal cases and the specification of the mobile station behaviour is given in
subclause 4.7.3.1.5.
If the ATTACH REJECT message with cause #25 was received without integrity protection, then the MS shall
discard the message.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2), reset the GPRS attach attempt counter and enter the state GMM-
DEREGISTERED.LIMITED-SERVICE.
3GPP
Release 10 137 3GPP TS 24.008 V10.6.1 (2012-03)
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST
message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry corresponding to
this CSG ID and associated PLMN identity from the Allowed CSG list.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST
message are contained in the Operator CSG list stored in the MS, the MS shall proceed as specified in
3GPP TS 23.122 [14] subclause 3.1A.
The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the attach procedure is rejected with the EMM cause with the same value.
Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is specified in
subclause 4.7.3.1.5.
4.7.3.1.4a GPRS attach for emergency bearer services not accepted by the network
(UTRAN Iu mode only)
If the attach request for emergency bearer services cannot be accepted by the network, an ATTACH REJECT message is
transferred to the MS. The ATTACH REJECT message includes GMM cause #5 "IMEI not accepted" or one of the
GMM cause values as described in subclause 4.7.3.1.4.
NOTE: If GMM cause #11 is sent to a MS of a roaming subscriber attaching for emergency bearer services and
the MS is in automatic network selection mode, it cannot obtain normal service provided by this PLMN.
Upon receiving the ATTACH REJECT message including GMM cause #5, the MS shall enter the state GMM-
DEREGISTERED.NO-IMSI.
Upon receiving the ATTACH REJECT message including one of the other GMM cause values, the MS shall perform
the actions as described in subclause 4.7.3.1.4 with the following addition: upon request from upper layers a CS voice
capable MS may establish the emergency call using the CS domain.
In a shared network, upon receiving the ATTACH REJECT message, the MS shall perform the actions as described in
subclause 4.7.3.1.4 with the following additions:
a) upon request from upper layers a CS voice capable MS may attempt the emergency call using the CS domain; or
b) an MS may try the attach for emergency bearer services to another PLMN in the shared network.
If options a) and b) above are either not applicable or one or both of them have failed an MS may attempt the
emergency call using other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [13D]
that can result in the emergency call being attempted to another IP-CAN.
4.7.3.1.4b Attach for initiating a PDN connection for emergency bearer services not
accepted by the network (UTRAN Iu mode only)
If the network cannot accept the attach request for initiating a PDN connection for emergency bearer services with
attach type not set to "emergency attach", the MS shall perform the procedures as described in subclause 4.7.3.1.4. Then
if the MS is in the same selected PLMN where the last attach request was attempted, the MS shall:
a) inform the upper layers. This could result in the MS attempting a CS emergency call (if not already attempted in
the CS domain) or other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [95]
that can result in the emergency call being attempted to another IP-CAN; or
3GPP
Release 10 138 3GPP TS 24.008 V10.6.1 (2012-03)
The GPRS attach procedure shall not be started. The MS stays in the current serving cell and applies normal cell
reselection process. The GPRS attach procedure is started as soon as possible, i.e. when access is granted or
because of a cell change.
b) Lower layer failure before the ATTACH ACCEPT or ATTACH REJECT message is received
The procedure shall be aborted and the MS shall proceed as described below, except in the following
implementation option cases b.1 and b.2.
b.1) Release of PS signalling connection in Iu mode before the completion of the GPRS attach procedure
If the release of the PS signalling connection occurs before completion of the GPRS attach procedure, then the
GPRS attach procedure shall be initiated again, if the following conditions apply:
i) The original GPRS attach procedure was initiated over an existing PS signalling connection; and
ii) The GPRS attach procedure was not due to timer T3310 expiry; and
iii) No SECURITY MODE COMMAND message and no Non-Access Startum (NAS) messages relating to
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the
ATTACH REQUEST message was transmitted.
b.2) RR release in Iu mode (i.e. RRC connection release) with, for example, cause "Normal", or "User inactivity"
(see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111])
The GPRS attach procedure shall be initiated again, if the following conditions apply:
i) The original GPRS attach procedure was initiated over an existing RRC connection; and
ii) The GPRS attach procedure was not due to timer T3310 expiry; and
iii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the
ATTACH REQUEST message was transmitted.
NOTE 1: The RRC connection release cause that triggers the re-initiation of the GPRS attach procedure is
implementation specific.
c) T3310 time-out
On the first expiry of the timer, the MS shall reset and restart timer T3310 and shall retransmit the ATTACH
REQUEST message. This retransmission is repeated four times, i.e. on the fifth expiry of timer T3310, the MS
shall abort the GPRS attach procedure and, in Iu mode, release the PS signalling connection (see
3GPP TS 25.331 [23c]). The MS shall proceed as described below.
d) ATTACH REJECT, other causes than those treated in subclause 4.7.3.1.4, and cases of GMM cause #22, if
considered as abnormal cases according to subclause 4.7.3.1.4
Upon reception of the cause codes # 95, # 96, # 97, # 99 and # 111 the MS should set the GPRS attach attempt
counter to 5. The MS shall proceed as described below.
If a cell change occurs within the same RA when the MS is in state GMM-REGISTERED-INITIATED, then the
cell update procedure shall be performed before completion of the attach procedure.
3GPP
Release 10 139 3GPP TS 24.008 V10.6.1 (2012-03)
If a cell change into a new routing area occurs before an ATTACH ACCEPT or ATTACH REJECT message has
been received, the GPRS attach procedure shall be aborted and re-initiated immediately. If a routing area border
is crossed when the ATTACH ACCEPT message is received but before an ATTACH COMPLETE message is
sent, the GPRS attach procedure shall be aborted and the routing area updating procedure shall be initiated. If a
P-TMSI was allocated during the GPRS attach procedure, this P-TMSI shall be used in the routing area updating
procedure. If a P-TMSI signature was allocated together with the P-TMSI during the GPRS attach procedure,
this P-TMSI signature shall be used in the routing area updating procedure.
If the MS is in state GMM-REGISTERED-INITIATED, the GPRS attach procedure shall be aborted and the
GPRS detach procedure shall be performed (see subclause 4.7.4.1).
h) Procedure collision
If the MS receives a DETACH REQUEST message from the network in state GMM-REGISTERED-
INITIATED with type of detach 're-attach not required, the GPRS detach procedure shall be progressed and the
GPRS attach procedure shall be aborted. Otherwise the GPRS attach procedure shall be progressed and the
DETACH REQUEST message shall be ignored.
If the ATTACH REQUEST message contained the NAS signalling low priority indication set to "MS is
configured for NAS signalling low priority", the MS shall start timer T3346 with the "Extended wait time" value.
The MS shall abort the attach procedure, reset the attach attempt counter, stay in the current serving cell, change
the state to GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH and apply the normal cell reselection
process.
The GPRS attach procedure is started, if still necessary, when timer T3346 expires or is stopped.
The MS shall not start the GPRS attach procedure unless the MS needs to attach for emergency bearer services.
The MS stays in the current serving cell and applies normal cell reselection process. The GPRS attach procedure
is started, if still necessary, when timer T3346 expires or is stopped.
NOTE 2: It is considered an abnormal case if the MS needs to initiate an attach procedure while timer T3346 is
running independent on whether timer T3346 was started due to an abnormal case or a non successful
case.
In cases b, c and d the MS shall proceed as follows. Timer T3310 shall be stopped if still running. The GPRS attach
attempt counter shall be incremented.
- the MS shall delete any RAI, P-TMSI, P-TMSI signature, list of equivalent PLMNs, and GPRS ciphering key
sequence number, shall set the GPRS update status to GU2 NOT UPDATED, shall start timer T3302. The state is
changed to GMM-DEREGISTERED. ATTEMPTING-TO-ATTACH or optionally to GMM-
DEREGISTERED.PLMN-SEARCH (see subclause 4.2.4.1.2) in order to perform a PLMN selection according
to 3GPP TS 23.122 [14].
- If S1 mode is supported by the MS, the MS shall in addition handle the EMM parameters EMM state, EPS
update status, GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the
abnormal case when a normal attach procedure fails and the attach attempt counter is equal to 5.
3GPP
Release 10 140 3GPP TS 24.008 V10.6.1 (2012-03)
If a low layer failure occurs before the message ATTACH COMPLETE has been received from the MS and a
new P-TMSI (or a new P-TMSI and a new P-TMSI signature) has been assigned, the network shall consider both
the old and new P-TMSI each with its corresponding P-TMSI-signature as valid until the old P-TMSI can be
considered as invalid by the network (see subclause 4.7.1.5) and shall not resent the message ATTACH
ACCEPT. During this period the network may:
- use the identification procedure followed by a P-TMSI reallocation procedure if the old P-TMSI is used by
the MS in a subsequent message.
b) Protocol error
If the ATTACH REQUEST message is received with a protocol error, the network shall return an ATTACH
REJECT message with one of the following reject causes:
c) T3350 time-out
On the first expiry of the timer, the network shall retransmit the ATTACH ACCEPT message and shall reset and
restart timer T3350.
This retransmission is repeated four times, i.e. on the fifth expiry of timer T3350, the GPRS attach procedure
shall be aborted. If a new P-TMSI or a new P-TMSI together with a new P-TMSI signature were allocated in the
ATTACH ACCEPT message, the network shall consider both the old and new P-TMSI each together with the
corresponding P-TMSI signatures as valid until the old P-TMSI can be considered as invalid by the network (see
subclause 4.7.1.5). During this period the network acts as specified for case a.
d.1) ATTACH REQUEST received after the ATTACH ACCEPT message has been sent and before the ATTACH
COMPLETE message is received
- If one or more of the information elements in the ATTACH REQUEST message differ from the ones received
within the previous ATTACH REQUEST message, the previously initiated GPRS attach procedure shall be
aborted if the ATTACH COMPLETE message has not been received and the new GPRS attach procedure shall
be progressed, or
- If the information elements do not differ, then the ATTACH ACCEPT message shall be resent and the timer
T3350 shall be restarted if an ATTACH COMPLETE message is expected. In that case, the retransmission
counter related to T3350 is not incremented.
d.2) More than one ATTACH REQUEST received and no ATTACH ACCEPT or ATTACH REJECT message has
been sent
- If one or more of the information elements in the ATTACH REQUEST message differs from the ones received
within the previous ATTACH REQUEST message, the previously initiated GPRS attach procedure shall be
aborted and the new GPRS attach procedure shall be progressed;
- If the information elements do not differ, then the network shall continue with the previous attach procedure and
shall not treat any further this ATTACH REQUEST message.
If an ATTACH REQUEST message is received in state GMM-REGISTERED the network may initiate the
GMM common procedures; if it turned out that the ATTACH REQUEST message was send by an MS that has
3GPP
Release 10 141 3GPP TS 24.008 V10.6.1 (2012-03)
already been attached, the GMM context, PDP contexts and MBMS contexts, if any, are deleted and the new
ATTACH REQUEST is progressed.
f) ROUTING AREA UPDATE REQUEST message received before ATTACH COMPLETE message.
Timer T3350 shall be stopped. The allocated P-TMSI shall be considered as valid and the routing area updating
procedure shall be progressed as described in subclause 4.7.5.
MS Network
ATTACH REQUEST
Start T3310
or
ATTACH REQUEST
Start T3310
ATTACH REJECT
Stop T3310
Figure 4.7.3/1 3GPP TS 24.008: GPRS attach procedure and combined GPRS attach procedure
4.7.3.2 Combined GPRS attach procedure for GPRS and non-GPRS services
The combined GPRS attach procedure is a GMM procedure used by a GPRS MS operating in MS operation modes A or
B for IMSI attach for GPRS and non-GPRS services if the network operates in network operation mode I.
If a GPRS MS operating in MS operation modes A or B is already attached for non-GPRS services by use of the MM
specific IMSI attach procedure, but additionally wishes to perform an IMSI attach for GPRS services, the combined
GPRS attach procedure shall also be used.
The attach type information element shall indicate "combined GPRS/IMSI attach". In this case, the messages ATTACH
ACCEPT, ATTACH COMPLETE, and ATTACH REJECT used by the combined GPRS attach procedure carry
information for both the GPRS and the non-GPRS services.
A GPRS MS in MS operation mode A shall perform the normal GPRS/IMSI attach procedure during an ongoing circuit-
switched transaction.
The MS shall include a valid P-TMSI, if available, the P-TMSI signature associated with the P-TMSI and the routing
area identity associated with the P-TMSI in the ATTACH REQUEST message. If there is no valid P-TMSI available,
the IMSI shall be included instead of the P-TMSI and P-TMSI signature. Furthermore the MS shall include the TMSI
status IE if no valid TMSI is available.
3GPP
Release 10 142 3GPP TS 24.008 V10.6.1 (2012-03)
If the MS has stored a valid LAI and the MS supports EMM combined procedures, the MS shall include it in the Old
location area identification IE in the ATTACH REQUEST message.
In Iu mode, if the MS wishes to prolong the established PS signalling connection after the GPRS attach (for example,
the MS has any CM application request pending), it may set a follow-on request pending indicator on (see
subclause 4.7.13).
Case 1) The attach result IE value indicates "combined GPRS attach": IMSI attach for GPRS and non-GPRS
services have been successful.
Case 2) The attach result IE value indicates "GPRS only": IMSI attach for GPRS services has been successful but
IMSI attach for non-GPRS services has not been successful.
In Iu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has
indicated "follow-on request pending" in ATTACH REQUEST message) the network shall indicate the "follow-on
proceed" in the ATTACH ACCEPT message. If the network wishes to release the PS signalling connection, the network
shall indicate "no follow-on proceed" in the ATTACH ACCEPT message.
After that in Iu mode, the mobile station shall act according to the follow-on proceed flag included in the Attach result
information element in the ATTACH ACCEPT message (see subclause 4.7.13).
The description for IMSI attach for GPRS services as specified in subclause 4.7.3.1.3 shall be followed. In addition, the
following description for IMSI attach for non-GPRS services applies.
The TMSI reallocation may be part of the combined GPRS attach procedure. The TMSI allocated is then included in the
ATTACH ACCEPT message together with the location area identification (LAI). The network shall, in this case, change
to state GMM-COMMON-PROCEDURE-INITIATED and shall start timer T3350 as described in subclause 4.7.6.
The MS, receiving an ATTACH ACCEPT message, stores the received location area identification, stops timer T3310,
reset the location update attempt counter and sets the update status to U1 UPDATED. If the message contains an IMSI,
the mobile station is not allocated any TMSI, and shall delete any TMSI accordingly. If the message contains a TMSI,
the MS shall use this TMSI as the new temporary identity. The MS shall delete its old TMSI and shall store the new
TMSI. In this case, an ATTACH COMPLETE message is returned to the network. If neither a TMSI nor an IMSI has
been included by the network in the ATTACH ACCEPT message, the old TMSI, if any available, shall be kept. The new
MM state is MM IDLE, the new GMM state is GMM-REGISTERED.
If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover
information or both, the MS shall return an ATTACH COMPLETE message including the Inter RAT handover
information IE or the E-UTRAN inter RAT handover information IE or both to the network.
Any timer used for triggering the location update procedure (e.g T3211, T3212) shall be stopped if running.
The network receiving an ATTACH COMPLETE message stops timer T3350, changes to state GMM-REGISTERED
and considers the new TMSI as valid.
3GPP
Release 10 143 3GPP TS 24.008 V10.6.1 (2012-03)
Apart from the actions on the routing area updating attempt counter, the description for IMSI attach for GPRS services
as specified in subclause 4.7.3.1.3 shall be followed. In addition, the following description for IMSI attach for non-
GPRS services applies.
The MS receiving the ATTACH ACCEPT message takes one of the following actions depending on the reject cause:
The MS shall stop timer T3310 if still running and shall reset the routing area updating attempt counter. The
MS shall set the update status to U3 ROAMING NOT ALLOWED and shall delete any TMSI, LAI and
ciphering key sequence number. The MS shall enter state GMM-REGISTERED.NORMAL-SERVICE. The
new MM state is MM IDLE. The SIM/USIM shall be considered as invalid for non-GPRS services until
switching off or the SIM/USIM is removed.
# 17 (Network failure); or
# 22 (Congestion)
If the routing area updating attempt counter is less than 5, and the stored RAI is equal to the RAI of the
current serving cell and the GMM update status is equal to GU1 UPDATED:
- the MS shall keep the GMM update status GU1 UPDATED and changes state to GMM-
REGISTERED.ATTEMPTING-TO-UPDATE-MM. The MS shall start timer T3311. When timer T3311
expires the combined routing area update procedure indicating "combined RA/LA updating with IMSI
attach" is triggered again.
- the MS shall start timer T3302 and shall change to state GMM-REGISTERED.ATTEMPTING-TO-
UPDATE-MM;
- a GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific
procedure; a GPRS MS operating in MS operation mode B may then proceed with appropriate MM
specific procedures. The MM sublayer shall act as in network operation mode II or III (depending
whether a PCCCH is present) as long as the combined GMM procedures are not successful and no new
RA is entered. The new MM state is MM IDLE.
Other reject cause values and the case that no GMM cause IE was received are considered as abnormal cases. The
combined attach procedure shall be considered as failed for GPRS and non-GPRS services. The behaviour of the MS in
those cases is specified in subclause 4.7.3.2.5.
If the attach request is rejected due to NAS level mobility management congestion control, the network shall set the
MM cause value to #22 "congestion" and assign a back-off timer T3346.
The MS shall then take one of the following actions depending upon the reject cause:
#3 (Illegal MS);
#6 (Illegal ME), or
3GPP
Release 10 144 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The new GMM state is GMM-DEREGISTERED. The new MM state is MM IDLE.
The MS shall set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI and
ciphering key sequence number. The SIM/USIM shall be considered as invalid for GPRS and non-GPRS
services until switching off or the SIM/USIM is removed.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
combined attach procedure is rejected with the EMM cause with the same value.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM
is removed. The new GMM state is GMM-DEREGISTERED; the MM state is MM IDLE.
A GPRS MS operating in MS operation mode A or B which is already IMSI attached for CS services in the
network is still IMSI attached for CS services in the network.
A GPRS MS operating in MS operation mode A or B shall proceed with the appropriate MM specific procedure
according to the MM service state.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
combined attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number stored,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and changes to state GMM-DEREGISTERED.
The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE.
The MS shall store the PLMN identity in the "forbidden PLMN list".
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN
selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the combined attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature GPRS ciphering key sequence number, shall set the
GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE.
The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE.
The MS shall store the LAI in the list of "forbidden location areas for regional provision of service".
The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98].
3GPP
Release 10 145 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the combined attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE or optionally to GMM-DEREGISTERED.PLMN-SEARCH.
The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE.
The mobile station shall store the LAI in the list of "forbidden location areas for roaming".
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN
selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the combined attach procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and shall change to state GMM-
DEREGISTERED.
The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list.
As an implementation option, a GPRS MS operating in operation mode A or B may perform a PLMN selection
according to 3GPP TS 23.122 [14].
If an MS in GAN mode performs a PLMN selection, it shall request a PLMN list in GAN (see
3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23.122 [14].
The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause
is:
- On the "User Controlled PLMN Selector with Access Technology " or,
- On the "Operator Controlled PLMN Selector with Access Technology " list or,
- A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above.
If the MS does not perform a PLMN selection then a GPRS MS operating in MS operation mode A or B which is
not yet IMSI attached for CS services in the network shall then perform an IMSI attach for non-GPRS services
according to the conditions for the MM IMSI attach procedure (see subclause 4.4.3).
A GPRS MS operating in MS operation mode A or B which is already IMSI attached for CS services in the
network is still IMSI attached for CS services in the network.
A GPRS MS operating in MS operation mode A or B shall proceed with the appropriate MM specific procedure
according to the MM service state.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the combined attach procedure is rejected with the EMM cause with the same value.
3GPP
Release 10 146 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE.
The MS shall set the update status to U3 ROAMING NOT ALLOWED, reset the location update attempt
counter and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM IDLE.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN according to
3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121].
NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the combined attach procedure is rejected with the EMM cause with the same value.
# 22 (Congestion);
If the T3346 value IE is present in the ATTACH REJECT message and the value indicates that this timer is
neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be considered as an
abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.3.1.5.
The MS shall abort the attach procedure, reset the attach attempt counter, set the GPRS update status to GU2
NOT UPDATED and enter state GMM-DEREGISTERED.ATTEMPTING-TO-ATTACH.
If the ATTACH REJECT message is integrity protected, the MS shall start timer T3346 with the value provided
in the T3346 value IE.
If the ATTACH REJECT message is not integrity protected, the MS shall start timer T3346 with a random value
from the default range specified in table 11.3a.
The MS stays in the current serving cell and applies the normal cell reselection process. The attach procedure is
started, if still necessary, when timer T3346 expires or is stopped.
Cause #25 is only applicable in UTRAN Iu mode and when received from a CSG cell. Other cases are
considered as abnormal cases and the specification of the mobile station behaviour is given in
subclause 4.7.3.2.5.
If the ATTACH REJECT message with cause #25 was received without integrity protection, then the MS shall
discard the message.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall reset the GPRS attach attempt counter. The state is changed to GMM-
DEREGISTERED.LIMITED-SERVICE.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST
message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry corresponding to
this CSG ID and associated PLMN identity from the Allowed CSG list.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ATTACH REQUEST
message are contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS 23.122 [14]
subclause 3.1A.
3GPP
Release 10 147 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when the combined attach procedure is rejected with the EMM cause with the same value.
Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is specified in
subclause 4.7.3.2.5.
- If the combined attach was successful for GPRS services only and the ATTACH ACCEPT message contained a
cause value not treated in subclause 4.7.3.2.3.2 or the GMM Cause IE is not included in the message, the MS
shall follow the procedure specified in subclause 4.7.3.1.5 step d), with the following modification;
- Otherwise, the abnormal cases specified in subclause 4.7.3.1.5 apply with the following modification.
If the GPRS attach attempt counter is incremented according to subclause 4.7.3.1.5 the next actions depend on the
Location Area Identities (stored on SIM/USIM and the one of the current serving cell) and the value of the attach
attempt counter:
- if the update status is U1 UPDATED, and the stored LAI is equal to the one of the current serving cell and the
attach attempt counter is smaller than 5, then the mobile station shall keep the update status to U1 UPDATED,
the new MM state is MM IDLE substate NORMAL SERVICE;
- if the attach attempt counter is smaller than 5 and, additionally, the update status is different from U1 UPDATED
or the stored LAI is different from the one of the current serving cell, then the mobile station shall delete any
LAI, TMSI, ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs and set the
update status to U2 NOT UPDATED. The MM state remains MM LOCATION UPDATING PENDING; or
- if the attach attempt counter is greater or equal to 5, then the mobile station shall delete any LAI, TMSI,
ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs and set the update status
to U2 NOT UPDATED.
A GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific procedure; a
GPRS MS operating in MS operation mode B may then proceed with appropriate MM specific procedures.
The MM sublayer shall act as in network operation mode II or III (depending whether a PCCCH is present) as
long as the combined GMM procedures are not successful and no new RA is entered. The new MM state is MM
IDLE substate ATTEMPTING TO UPDATE or optionally MM IDLE substate PLMN SEARCH in order to
perform a PLMN selection according to 3GPP TS 23.122 [14].
4.7.4.0 General
The GPRS detach procedure is used:
- to detach the IMSI for GPRS services only. Independent of the network operation mode, this procedure is used
by all kind of GPRS MSs;
- as a combined GPRS detach procedure used by GPRS MSs operating in MS operation mode A or B to detach the
IMSI for GPRS and non-GPRS services or for non-GPRS services only, if the network operates in network
operation mode I and no circuit-switched transaction is ongoing;
3GPP
Release 10 148 3GPP TS 24.008 V10.6.1 (2012-03)
- in the case of a network failure condition to indicate to the MS that a re-attach with successive activation of
previously active PDP contexts shall be performed. In this case, the MS may also perform the procedures needed
in order to activate any previously active multicast service(s); or
After completion of a GPRS detach procedure or combined GPRS detach procedure for GPRS and non-GPRS services
the GMM context is released.
An eCall only mobile station shall not perform any kind of GPRS detach procedure.
The GPRS detach procedure shall be invoked by the MS if the MS is switched off, the SIM/USIM card is removed from
the MS or if the GPRS or non-GPRS capability of the MS is disabled. The procedure may be invoked by the network to
detach the IMSI for GPRS services. The GPRS detach procedure causes the MS to be marked as inactive in the network
for GPRS services, non-GPRS services or both services.
If a detach is requested by the HLR for an MS that has a PDP context for emergency services, the SGSN shall not send
a DETACH REQUEST message to the MS, and shall follow the procedure described in subclause 6.1.3.4.2 for an MS
that has PDP contexts for emergency bearer services.
After the completion of application for which the emergency services were invoked, in order to regain normal services,
an MS attached for emergency bearer services may perform a detach procedure, followed by a subsequent re-attach, if
the MS moves to a new cell that provides normal service.
In A/Gb mode, if the GPRS detach procedure is performed, the PDP contexts and the MBMS contexts, if any, are
deactivated locally without peer to peer signalling between the SM and LLC entities in the MS and the network.
In Iu mode, if the GPRS detach procedure is performed, the PDP contexts and the MBMS contexts, if any, are
deactivated locally without peer to peer signalling between the SM entities in the MS and the network.
If the MS supports S1 mode, the MS shall store the TIN in the non-volatile memory in the ME, as described in
3GPP TS 24.301 [120], annex C, for a subsequent attach procedure.
The MS is allowed to initiate the GPRS detach procedure even if the timer T3346 is running.
The network proceeds with the GPRS detach procedure even if NAS level mobility management congestion control is
active.
If the MS has a valid P-TMSI, the MS shall include the P-TMSI in the DETACH REQUEST message. The MS shall
also include a valid P-TMSI signature, if available.
If the MS is not switched off and the MS is in the state GMM_REGISTERED, timer T3321 shall be started after the
DETACH REQUEST message has been sent. If the detach type information element value indicates "IMSI Detach" the
MS shall enter GMM-REGISTERED.IMSI-DETACH_INITIATED, otherwise the MS shall enter the state GMM-
DEREGISTERED-INITIATED. If the detach type information element value indicates "IMSI Detach" or "GPRS/IMSI
Detach", state MM IMSI DETACH PENDING is entered. If the MS is to be switched off, the MS shall try for a period
of 5 seconds to send the DETACH REQUEST message. If the MS is able to send the DETACH REQUEST message
during this time the MS may be switched off.
If the detach type information element value indicates "GPRS detach without switching off " and the MS is attached for
GPRS and non-GPRS services and the network operates in network operation mode I, then if in the MS the timer T3212
is not already running, the timer T3212 shall be set to its initial value and restarted after the DETACH REQUEST
message has been sent.
3GPP
Release 10 149 3GPP TS 24.008 V10.6.1 (2012-03)
4.7.4.1.2 MS initiated GPRS detach procedure completion for GPRS services only
When the DETACH REQUEST message is received by the network, the network shall send a DETACH ACCEPT
message to the MS, if the detach type IE value indicates that the detach request has not been sent due to switching off. If
switching off was indicated, the procedure is completed when the network receives the DETACH REQUEST message.
The network and the MS shall deactivate the PDP contexts, the MBMS contexts and deactivate the logical link(s), if
any.
The MS is marked as inactive in the network for GPRS services; state GMM-DEREGISTERED is entered in the MS
and the network.
In Iu mode, if the detach has been sent due to switching off, then the network shall release the resources in the lower
layers for this MS (see 3GPP TS 25.331 [23c]).
NOTE: When the DETACH REQUEST message is received by the network, and if the detach type IE value
indicates that the detach is not due to power off, the authentication and ciphering procedure as well as the
identification procedure may be performed.
GPRS/IMSI detach:
The MS is marked as inactive in the network for GPRS and for non-GPRS services. The network and the MS shall
deactivate the PDP contexts, the MBMS contexts and deactivate the logical link(s), if any. The States GMM-
DEREGISTERED and MM NULL are entered in both the MS and the network.
In Iu mode, if the detach has been sent due to switching off, then the network shall release the resources in the lower
layers for this MS (see 3GPP TS 25.331 [23c]).
IMSI detach:
The MS is marked as inactive in the network for non-GPRS services. State MM NULL is entered in the MS and the
network.
a) T3321 time-out
On the first expiry of the timer, the MS shall retransmit the DETACH REQUEST message and shall reset and
restart timer T3321. This retransmission is repeated four times, i.e. on the fifth expiry of timer T3321, the GPRS
detach procedure shall be aborted, the MS shall change to state:
The detach procedure is aborted and the MS shall change to one of the following states, except in the following
implementation option cases b.1, b.2 and b3:
3GPP
Release 10 150 3GPP TS 24.008 V10.6.1 (2012-03)
b.1) Release of PS signalling connection before the completion of the GPRS detach procedure
The release of the PS signalling connection before completion of the GPRS detach procedure shall result in the
GPRS detach procedure being initiated again, if the following conditions apply:
i) The original GPRS detach procedure was initiated over an existing PS signalling connection; and
ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the
DETACH REQUEST message was transmitted.
b.2) RR release in Iu mode (i.e. RRC connection release) with cause different than "Directed signalling
connection re-establishment", for example, "Normal", or"User inactivity" (see 3GPP TS 25.331 [23c] and
3GPP TS 44.118 [111])
The GPRS detach procedure shall be initiated again, if the following conditions apply:
i) The original GPRS detach procedure was initiated over an exisiting RRC connection; and
ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the
DETACH REQUEST message was transmitted.
NOTE: The RRC connection release cause different than "Directed signalling connection re-establishment" that
triggers the re-initiation of the GPRS detach procedure is implementation specific.
b.3) RR release in Iu mode (i.e. RRC connection release) with cause "Directed signalling connection re-
establishment" (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111])
The routing area updating procedure shall be initiated followed by completion of the GPRS detach procedure if
the following conditions apply:
i) The original GPRS detach procedure was not due to SIM removal; and
ii) The original GPRS detach procedure was not due to a rerun of the procedure due to "Directed signalling
connection reestablishment".
If the MS receives a DETACH REQUEST message before the MS initiated GPRS detach procedure has been
completed, the MS shall treat the message as specified in subclause 4.7.4.2.2 and send a DETACH ACCEPT
message to the network.
- If the MS receives a message used in a GMM common procedure before the GPRS detach procedure has
been completed, this message shall be ignored and the GPRS detach procedure shall continue.
If a cell change occurs within the same RA before a DETACH ACCEPT message has been received, then the cell
update procedure shall be performed before completion of the detach procedure.
3GPP
Release 10 151 3GPP TS 24.008 V10.6.1 (2012-03)
If a cell change into a new routing area occurs before a DETACH ACCEPT message has been received, the
GPRS detach procedure shall be aborted and re-initiated after successfully performing a routing area updating
procedure. If the detach procedure is performed due to the removal of the SIM/USIM the MS shall abort the
detach procedure and enter the state GMM-DEREGISTERED.
The signalling procedure for GPRS detach shall not be started. The MS starts the signalling procedure as soon as
possible and if still necessary, i.e. when the barred state is removed or because of a cell change, or performs a
local detach immediately or after an implementation dependent time.
MS Network
DETACH REQUEST
Start T3321
DETACH ACCEPT
Stop T3321
DETACH REQUEST
a) CSG ID of the CSG cell is not in the Allowed CSG list of the MS which sends the detach request
If the MS initiates a detach procedure in a CSG cell the CSG ID of which is not valid for the MS and the detach
procedure is not due to "switch off", the network shall proceed as follows:
- if the detach type is "IMSI detach" and the MS has a PDN connection for emergency bearer services active,
the SGSN shall send a DETACH ACCEPT message and deactivate all non-emergency PDP contexts, if any,
by initiating a PDP context deactivation procedure;
- otherwise, the network shall initiate the detach procedure. The network shall send a DETACH REQUEST
message including the GMM cause value #25 "not authorized for this CSG", to indicate to the MS to remove
the CSG ID and associated PLMN identity of the cell, where the MS has sent the DETACH REQUEST
message, from the Allowed CSG list.
3GPP
Release 10 152 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: When the detach type indicates "re-attach required", user interaction is necessary in some cases when the
MS cannot re-activate the PDP/MBMS context(s) automatically.
A GPRS MS operating in MS operation mode A or B in network operation mode I, which receives an DETACH
REQUEST message with detach type indicating "re-attach required" or "re-attach not required" and no cause code, is
only detached for GPRS services in the network.
When receiving the DETACH REQUEST message and the detach type IE indicates "IMSI detach", the MS shall not
deactivate the PDP/MBMS contexts. The MS shall set the MM update status to U2 NOT UPDATED. An MS in
operation mode A or B in network operation mode I may send a DETACH ACCEPT message to the network, and shall
re-attach to non-GPRS service by performing the combined routing area updating procedure according to
subclause 4.7.5.2, sending a ROUTING AREA UPDATE REQUEST message with Update type IE indicating
"combined RA/LA updating with IMSI attach". An MS in operation mode A that is in an ongoing circuit-switched
transaction shall initiate the combined routing area updating after the circuit-switched transaction has been released. An
MS in operation mode C, or in MS operation mode A or B in network operation mode II or III, shall send a DETACH
ACCEPT message to the network.
If the detach type IE indicates "IMSI detach", or "re-attach required" then the MS shall ignore the cause code if
received.
If the detach type information element value indicates "re-attach required" or "re-attach not required" and the MS is
attached for GPRS and non-GPRS services and the network operates in network operation mode I, then if in the MS the
timer T3212 is not already running, the timer T3212 shall be set to its initial value and restarted.
When receiving the DETACH REQUEST message and the detach type IE indicates "re-attach not required" and the
cause code is not #2 "IMSI unknown in HLR", the MS shall deactivate the PDP contexts, the MBMS contexts and
deactivate the logical link(s), if any. The MS shall then send a DETACH ACCEPT message to the network and shall
change state to GMM-DEREGISTERED.
If the detach type IE indicates "re-attach not required", then, depending on the received cause code, the MS shall act as
follows:
The MS shall set the update status to U3 ROAMING NOT ALLOWED and shall delete any TMSI, LAI and
ciphering key sequence number. The new MM state is MM IDLE. The SIM/USIM shall be considered as invalid
for non-GPRS services until switching off or the SIM/USIM is removed.
A GPRS MS operating in MS operation mode A or B in network operation mode I, is still IMSI attached for
GPRS services in the network.
#3 (Illegal MS);
#6 (Illegal ME);
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The new GMM state is GMM-DEREGISTERED. The SIM/USIM shall be considered as invalid for
GPRS services until switching off or the SIM/USIM is removed.
A GPRS MS operating in MS operation mode A or B shall in addition set the update status to U3 ROAMING
NOT ALLOWED, shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in MS
operation mode A and an RR connection exists, the MS shall abort the RR connection, unless an emergency call
is ongoing. The SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or the
SIM/USIM is removed.
3GPP
Release 10 153 3GPP TS 24.008 V10.6.1 (2012-03)
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when a
DETACH REQUEST is received with the EMM cause with the same value and with detach type set to "re-attach
not required".
NOTE 2: The possibility to configure an MS so that the radio transceiver for a specific radio access technology is
not active, although it is implemented in the MS, is out of scope of the present specification.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM
is removed. The new state is GMM-DEREGISTERED.
A GPRS MS operating in MS operation mode A or B in network operation mode I shall set the timer T3212 to its
initial value and restart it, if it is not already running.
A GPRS MS operating in MS operation mode A or B in network operation mode I, is still IMSI attached for CS
services in the network.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when a
DETACH REQUEST is received with the EMM cause with the same value and with detach type set to "re-attach
not required".
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The new GMM state is GMM-DEREGISTERED.
The MS shall set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI and
ciphering key sequence number. If the MS is operating in MS operation mode A and an RR connection exists,
the MS shall abort the RR connection, unless an emergency call is ongoing. The SIM/USIM shall be considered
as invalid for GPRS and non-GPRS services until switching off or the SIM/USIM is removed.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when a
DETACH REQUEST is received with the EMM cause with the same value and with detach type set to "re-attach
not required".
The MS shall delete any RAI or LAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall reset the GPRS attach attempt counter. The new GMM state is GMM-
DEREGISTERED.
The MS shall store the PLMN identity in the "forbidden PLMN list".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- A GPRS MS operating in MS operation mode A or B shall set the update status to U3 ROAMING NOT
ALLOWED and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM
IDLE.
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
3GPP
Release 10 154 3GPP TS 24.008 V10.6.1 (2012-03)
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach
type set to "re-attach not required".
The MS shall delete any RAI, P-TMSI, P-TMSI signature GPRS ciphering key sequence number, shall set the
GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE.
The MS shall store the LAI in the list of "forbidden location areas for regional provision of service".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98].
NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach
type set to "re-attach not required".
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE or optionally to GMM-DEREGISTERED.PLMN-SEARCH.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach
type set to "re-attach not required".
3GPP
Release 10 155 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2), shall reset the GPRS attach attempt counter and shall change to state GMM-
DEREGISTERED.
The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list.
A GPRS MS operating in MS operation mode A or B in network operation mode I shall set the timer T3212 to its
initial value and restart it, if it is not already running.
A GPRS MS operating in MS operation mode A or B, is still IMSI attached for CS services in the network.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach
type set to "re-attach not required".
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED(and shall store it according to clause 4.1.3.2) and
shall reset the GPRS attach attempt counter. The state is changed to GMM-DEREGISTERED.LIMITED-
SERVICE.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
- The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121].
NOTE 4: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach
type set to "re-attach not required".
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and store it according to
subclause 4.1.3.2) and shall reset the GPRS attach attempt counter. The state is changed to GMM-
DEREGISTERED.LIMITED-SERVICE.
If the cell where the MS has received the DETACH REQUEST message is a CSG cell and the CSG ID and
associated PLMN identity of the cell are contained in the Allowed CSG list stored in the MS, the MS shall
remove the CSG ID and associated PLMN identity from the Allowed CSG list.
If the cell where the MS has received the DETACH REQUEST message is a CSG cell and the CSG ID and
associated PLMN identity of the cell are contained in the Operator CSG list, the MS shall proceed as specified in
3GPP TS 23.122 [14] subclause 3.1A.
The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
3GPP
Release 10 156 3GPP TS 24.008 V10.6.1 (2012-03)
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and attach attempt counter as specified in 3GPP TS 24.301 [120]
for the case when a DETACH REQUEST is received with the EMM cause with the same value and with detach
type set to "re-attach not required".
Other cause values shall not impact the update status. Further actions of the MS are implementation dependent.
a) T3322 time-out
On the first expiry of the timer, the network shall retransmit the DETACH REQUEST message and shall start
timer T3322. This retransmission is repeated four times, i.e. on the fifth expiry of timer T3322, the GPRS detach
procedure shall be aborted and the network changes to state GMM-DEREGISTERED.
The GPRS detach procedure is aborted and the network changes to state GMM-DEREGISTERED.
If the network receives a DETACH REQUEST message with "switching off" indicated, before the network
initiated GPRS detach procedure has been completed, both procedures shall be considered completed.
If the network receives a DETACH REQUEST message without "switching off" indicated, before the network
initiated GPRS detach procedure has been completed, the network shall send a DETACH ACCEPT message to
the MS.
If the network receives an ATTACH REQUEST message before the network initiated GPRS detach procedure
with type of detach 're-attach not required' has been completed, the network shall ignore the ATTACH
REQUEST message. If the detach type IE value, sent in the DETACH REQUEST message, indicates "re-attach
required" the detach procedure is aborted and the GPRS attach procedure shall be progressed after the PDP
contexts and MBMS contexts, if any, have been deleted. If the detach type IE value, sent in the DETACH
REQUEST message, indicates "IMSI detach" the detach procedure is aborted and the GPRS attach procedure
shall be progressed.
GPRS detach containing detach type "re-attach required" or "re-attach not required":
If the network receives a ROUTING AREA UPDATE REQUEST message before the network initiated
GPRS detach procedure has been completed, the detach procedure shall be progressed, i.e. the ROUTING
AREA UPDATE REQUEST message shall be ignored. If the DETACH REQUEST message contains detach
type "re-attach not required" and GMM cause #2 "IMSI unknown in HLR", the network will follow the
procedure as described below for the detach type "IMSI detach".
If the network receives a ROUTING AREA UPDATE REQUEST message before the network initiated
GPRS detach procedure has been completed, the network shall abort the detach procedure, shall stop T3322
and shall progress the routing area update procedure.
3GPP
Release 10 157 3GPP TS 24.008 V10.6.1 (2012-03)
GPRS detach containing detach type "re-attach required" or "re-attach not required":
If the network receives a SERVICE REQUEST message before the network initiated GPRS detach procedure
has been completed, the network shall progress the detach procedure. If the GPRS Detach Request message
contains detach type "re-attach not required" and GMM cause #2 "IMSI unknown in HLR", the network will
follow the procedure as described below for the detach type "IMSI detach".
If the network receives a SERVICE REQUEST message before the network initiated GPRS detach procedure
has been completed, the network shall progress both procedures.
MS Network
DETACH REQUEST
Start T3322
DETACH ACCEPT
Stop T3322
- normal routing area updating to update the registration of the actual routing area of an MS in the network. This
procedure is used by GPRS MSs in MS operation mode C and by GPRS MSs in MS operation modes A or B that
are IMSI attached for GPRS and non-GPRS services if the network operates in network operation mode II or III;
- combined routing area updating to update the registration of the actual routing and location area of an MS in the
network. This procedure is used by GPRS MSs in MS operation modes A or B that are IMSI attached for GPRS
and non-GPRS services provided that the network operates in network operation mode I;
- periodic routing area updating. This procedure is used by GPRS MSs in MS operation mode C and by GPRS
MSs in MS operation modes A or B that are IMSI attached for GPRS or for GPRS and non-GPRS services
independent of the network operation mode;
- IMSI attach for non-GPRS services when the MS is IMSI attached for GPRS services. This procedure is used by
GPRS MSs in MS operation modes A or B, if the network operates in network operation mode I;
- in A/Gb mode, resuming GPRS services when the RR sublayer indicated a resumption failure after dedicated
mode was left, see 3GPP TS 44.018 [84];
- in A/Gb mode, updating the network with the new MS Radio Access Capability IE when the content of the IE
has changed;
- updating the network with the new DRX parameter IE when the content of the IE has changed;
NOTE 1: Such changes can be used e.g. when the MS activates a PDP context with service requirements that
cannot be met with the current DRX parameter. As PDP context(s) are activated and deactivated, the
GMM context will be updated with an appropriate DRX parameter;
- Iu mode to A/Gb mode and for A/Gb mode to Iu mode intersystem change, see subclause 4.7.1.7;
- in Iu mode, re-synchronizing the PMM mode of MS and network after RRC connection release with cause
"Directed signalling connection re-establishment", see subclause 4.7.2.5;
3GPP
Release 10 158 3GPP TS 24.008 V10.6.1 (2012-03)
- in Iu mode and A/Gb mode after intersystem change from S1 mode, and the GMM receives an indication of
"RRC connection failure" from lower layers due to lower layer failure while in S1 mode;
- S1 mode to Iu mode or S1 mode to A/Gb mode intersystem change and ISR is not activated;
- S1 mode to Iu mode or S1 mode to A/Gb mode intersystem change and ISR is activated, but the MS changes to a
routeing area it has not previously registered with the network;
- indicating to the network that due to a manual CSG selection the MS has selected a CSG cell whose CSG
identity and associated PLMN identity are not included in the MS's Allowed CSG list or in the MS's Operator
CSG list;
- indicating to the network that the mobile station classmark 2, mobile station classmark 3 or the supported codecs
have changed for a MS supporting SRVCC; or
- indicating to the network that the MS's availability for voice calls in the IMS (see 3GPP TS 24.301 [120],
subclause 3.1) has changed to "available".
While an MS has a PDN connection for emergency bearer services, the MS shall not perform manual CSG selection.
The routing area updating procedure shall also be used by a MS which is attached for GPRS services if a new PLMN is
entered (see 3GPP TS 23.122 [14]), unless the MS is configured for "AttachWithIMSI" as specified in
3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and the new PLMN is neither the registered PLMN nor in the list of
equivalent PLMNs.
An eCall only mobile station shall not perform a normal or combined routing area updating procedure.
Subclause 4.7.5.1 describes the routing area updating procedures for updating the routing area only. The combined
routing area updating procedure used to update both the routing and location area is described in subclause 4.7.5.2.
The routing area updating procedure is always initiated by the MS. It is only invoked in state GMM-REGISTERED.
To limit the number of subsequently rejected routing area update attempts, a routing area updating attempt counter is
introduced. The routing area updating attempt counter shall be incremented as specified in subclause 4.7.5.1.5.
Depending on the value of the routing area updating attempt counter, specific actions shall be performed. The routing
area updating attempt counter shall be reset when:
- a combined routing area updating procedure is completed for GPRS services only with cause #2;
- a routing area updating procedure is rejected with cause #11, #12, #13, #14, #15 or #25;
The mobile equipment shall contain a list of "forbidden location areas for roaming", as well as a list of "forbidden
location areas for regional provision of service". The handling of these lists is described in subclause 4.4.1.
The Mobile Equipment shall contain a list of "equivalent PLMNs". The handling of this list is described in
subclause 4.4.1.
In a shared network, the MS shall choose one of the PLMN identities as specified in 3GPP TS 23.122 [14]. The MS
shall construct the Routing Area Identification of the cell from this chosen PLMN identity, and the LAC and the RAC
received on the BCCH. If the constructed RAI is different from the stored RAI, the MS shall initiate the routing area
updating procedure. The chosen PLMN identity shall be indicated to the UTRAN in the RRC INITIAL DIRECT
TRANSFER message (see 3GPP TS 25.331 [23c]). Whenever a ROUTING AREA UPDATING REJECT message with
3GPP
Release 10 159 3GPP TS 24.008 V10.6.1 (2012-03)
the cause "PLMN not allowed" is received by the MS, the chosen PLMN identity shall be stored in the "forbidden
PLMN list". Whenever a ROUTING AREA UPDATING REJECT message is received by the MS with the cause
"Roaming not allowed in this location area", "Location Area not allowed", or "No suitable cells in Location Area", the
LAI that is part of the constructed RAI which triggered the routing area updating procedure shall be stored in the
suitable list.
In A/Gb mode, user data transmission in the MS shall be suspended during the routing area updating procedure, except
if the routing area updating procedure is triggered by a PS handover procedure as described in 3GPP TS 43.129 [113];
user data reception shall be possible. User data transmission in the network may be suspended during the routing area
updating procedure.
In Iu mode, user data transmission and reception in the MS shall not be suspended during the routing area updating
procedure. User data transmission in the network shall not be suspended during the routing area updating procedure.
In Iu mode, when a ROUTING AREA UPDATE REQUEST is received by the SGSN over a new PS signalling
connection while there is an ongoing PS signalling connection (network is already in mode PMM-CONNECTED) for
this MS, the network shall progress the routing area update procedure as normal and release the previous PS signalling
connection when the routing area update procedure has been accepted by the network.
NOTE 2: The re-establishment of the radio bearers of active PDP contexts is done as described in subclause
"Service Request procedure".
The network informs the MS about the support of specific features, such as LCS-MOLR, MBMS, IMS voice over PS
session, or emergency bearer services in Iu mode in the "Network feature support" Information Element. The
information is either explicitly given by sending the "Network feature support" IE or implicitly by not sending it. The
handling in the network is described in subclause 9.4.15.11. The MS may use the support indications for LCS-MOLR
and MBMS to inform the user about the availability of the appropriate services. The MS shall not request any of these
two services, if the service has not been indicated as available. The indication for MBMS is defined in subclause
"MBMS feature support indication" in 3GPP TS 23.246 [106]. In an MS with IMS voice over PS capability, the IMS
voice over PS session indicator and the emergency bearer services indicator shall be provided to the upper layers. The
upper layers take the IMS voice over PS session indicator into account as specified in 3GPP TS 23.221 [131],
subclause 7.2a and subclause 7.2b, when selecting the access domain for voice sessions or calls in Iu mode. When
initiating an emergency call in Iu mode, the upper layers also take the emergency bearer services indicator into account
for the access domain selection.
- when the MS needs to update the network with the new MS Radio Access Capability IE;
- when the MS needs to update the network with the new DRX parameter IE;
- in Iu mode, to re-synchronize the PMM mode of MS and network after RRC connection release with cause
"Directed signalling connection re-establishment", see subclause 4.7.2.5;
- in Iu mode and A/Gb mode, after intersystem change from S1 mode, and the GMM receives an indication of
"RRC connection failure" from lower layers due to lower layer while in S1 mode;
- in A/Gb mode, after intersystem change from S1 mode if the TIN indicates "RAT-related TMSI", but the MS is
required to perform routing area updating for IMS voice termination as specified in annex P.4;
3GPP
Release 10 160 3GPP TS 24.008 V10.6.1 (2012-03)
- when the MS has selected a CSG cell whose CSG identity and associated PLMN identity are not included in the
Allowed CSG list;or in the Operator CSG list;
- when the MS supports SRVCC and changes the mobile station classmark 2, mobile station classmark 3 or the
supported codecs;
- when the UE's usage setting or the voice domain preference for E-UTRAN change in the MS;
- when the MS activates mobility management for IMS voice termination as specified in annex P.2 and the TIN
indicates "RAT-related TMSI"; or
- upon reception of a paging indication, using P-TMSI, if the timer T3346 is running and the MS is in state GMM-
REGISTERED.ATTEMPTING-TO-UPDATE.
The ROUTING AREA UPDATE REQUEST message shall always be the first data sent by the MS when a routing area
border is crossed. The routing area identification is broadcast on the broadcast channel(s).
A normal routing area updating shall abort any ongoing GMM procedure. Aborted GMM procedures may be repeated
after the normal routing area updating procedure has been successfully performed. The value of the update type IE
included in the message shall indicate "RA updating".
If the normal routing area updating procedure is initiated due to the reception of the paging indication while T3346 is
running, the "follow-on request pending" indication shall be set to 1.
- If the TIN indicates "GUTI" and the MS holds a valid GUTI, the MS shall map the GUTI into a P-TMSI,
P-TMSI signature and RAI as specified in 3GPP TS 23.003 [4]. The MS shall include the mapped RAI in the
Old routing area identification IE and the mapped P-TMSI signature in the P-TMSI signature IE. In addition, the
MS shall include the P-TMSI type IE with P-TMSI type set to "mapped P-TMSI". When the routing area
updating procedure is initiated in Iu mode, the MS shall also include the mapped P-TMSI in the P-TMSI IE.
Additionally, in Iu mode and A/Gb mode, if the MS holds a valid P-TMSI and RAI, the MS shall indicate the P-
TMSI in the Additional mobile identity IE and the RAI in the Additional old routing area identification IE.
- If the TIN indicates "P-TMSI" or "RAT-related TMSI" and the MS holds a valid P-TMSI and RAI, the MS shall
indicate the RAI in the Old routing area identification IE. In addition, the MS shall include the P-TMSI type IE
with P-TMSI type set to "native P-TMSI". When the routing area updating procedure is initiated in Iu mode, the
MS shall also include the P-TMSI in the P-TMSI IE.
If the MS does not support S1 mode, the MS shall include the P-TMSI type IE with P-TMSI type set to "native P-
TMSI".
If the routing area updating procedure is not initiated by the MS due to an S1 mode to Iu mode or S1 mode to A/Gb
mode intersystem change, or if it is initiated due to such an intersystem change and the TIN indicates "RAT-related
TMSI", the MS shall use the existing UMTS security context for the PS domain. The ROUTING AREA UPDATE
REQUEST message shall contain the P-TMSI signature when received in a previous ATTACH ACCEPT or ROUTING
AREA UPDATE ACCEPT message. If the MS has a valid UMTS security context, the MS shall indicate it in the GPRS
ciphering key sequence number IE.
If the routing area updating procedure is initiated by the MS due to an S1 mode to Iu mode or S1 mode to A/Gb mode
inter-system change in idle mode and the TIN indicates "GUTI", the MS shall derive a UMTS security context for the
PS domain from the current EPS security context as described in the subclause 4.7.7.10. The ROUTING AREA
UPDATE REQUEST message shall include a P-TMSI signature filled with a NAS token as specified in
3GPP TS 33.401 [119]. Furthermore, the MS shall indicate the eKSI value, which is associated with the derived UMTS
security keys, in the CKSN field of the GPRS GSM ciphering key sequence number IE in the ROUTING AREA
UPDATE REQUEST message.
3GPP
Release 10 161 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: When the MS includes a P-TMSI signature filled with a NAS token, 8 bits of the NAS token will be filled
with bits from the M-TMSI (see 3GPP TS 23.003 [4]).
If the routing area updating procedure is initiated by the MS due to the S1 mode to Iu mode or S1 mode to A/Gb mode
inter-system change in connected mode, the MS shall derive a UMTS security context for the PS domain from the
current EPS security context station as described in the subclause 4.7.7.10. Furthermore, the MS shall indicate the eKSI
value, which is associated with the derived UMTS security keys, in the CKSN field of the GPRS GSM ciphering key
sequence number IE in the ROUTING AREA UPDATE REQUEST message.
In Iu mode, if the MS wishes to prolong the established PS signalling connection after the normal routing area updating
procedure (for example, the MS has any CM application request pending), it may set a follow-on request pending
indicator on (see subclause 4.7.13).
In order to indicate the new DRX parameter while in GERAN or UTRAN coverage, the MS shall send the ROUTING
AREA UPDATE REQUEST message containing the DRX parameter in the DRX parameter IE to the network, with the
exception of the case if the MS had indicated its MS specific DRX parameter (3GPP TS 24.301 [120]) to the network
while in E-UTRAN coverage. In this case, when the MS enters GERAN or UTRAN coverage and initiates a routing
area updating procedure, the MS shall not include the DRX parameter in the DRX parameter IE in the ROUTING
AREA UPDATE REQUEST message.
The network may initiate GMM common procedures, e.g. the GMM authentication and ciphering procedure.
4.7.5.1.3 Normal and periodic routing area updating procedure accepted by the network
If the routing area updating request has been accepted by the network, a ROUTING AREA UPDATE ACCEPT message
shall be sent to the MS. The network may assign a new P-TMSI and/or a new P-TMSI signature for the MS. If a new P-
TMSI and/or P-TMSI signature have been assigned to the MS, it/they shall be included in the ROUTING AREA
UPDATE ACCEPT message together with the routing area identification. In a shared network, if the MS is supporting
network sharing, the network shall indicate the PLMN identity of the CN operator that has accepted the routing area
updating request in the RAI contained in the ROUTING AREA UPDATE ACCEPT message; if the MS is not
supporting network sharing, the network shall indicate the PLMN identity of the common PLMN (see
3GPP TS 23.251 [109]).
In a multi-operator core network (MOCN) with common GERAN, the network shall indicate in the RAI the common
PLMN identity (see 3GPP TS 23.251 [109]).
If a new DRX parameter was included in the ROUTING AREA UPDATE REQUEST message, the network shall store
the new DRX parameter and use it for the downlink transfer of signalling and user data.
If the MS has indicated in the ROUTING AREA UPDATE REQUEST message that it supports PS inter-RAT handover
from GERAN to UTRAN Iu mode, the network may include in the ROUTING AREA UPDATE ACCEPT message a
request to provide the Inter RAT information container.
If the MS has indicated in the ROUTING AREA UPDATE REQUEST message that it supports PS inter-RAT HO from
GERAN to E-UTRAN, the network may include in the ROUTING AREA UPDATE ACCEPT message a request to
provide the E-UTRAN inter RAT information container.
If the MS has included the MS network capability IE or the UE network capability IE or both in the ROUTING AREA
UPDATE REQUEST message, the network shall store all octets received from the MS, up to the maximum length
defined for the respective information element. In case the UE network capability IE indicated new information to the
network, the MS shall set the TIN to "P-TMSI".
NOTE 1: This information is forwarded to the new SGSN during inter-SGSN handover or to the new MME during
intersystem handover to S1 mode.
3GPP
Release 10 162 3GPP TS 24.008 V10.6.1 (2012-03)
In A/Gb mode the Cell Notification information element shall be included in the ROUTING AREA UPDATE ACCEPT
message in order to indicate the ability of the network to support the Cell Notification.
The network shall change to state GMM-COMMON-PROCEDURE-INITIATED and shall start the supervision timer
T3350 as described in subclause 4.7.6.
If the LAI or PLMN identity contained in the ROUTING AREA UPDATE ACCEPT message is a member of any of the
"forbidden" lists and there is no PDN connection for emergency bearer services in the MS then any such entry shall be
deleted.
In Iu mode, the network should prolong the PS signalling connection if the mobile station has indicated a follow-on
request pending in ROUTING AREA UPDATE REQUEST. The network may also prolong the PS signalling connection
without any indication from the mobile terminal.
If the PDP context status information element is included in ROUTING AREA UPDATE REQUEST message, then the
network shall deactivate all those PDP contexts locally (without peer to peer signalling between the MS and the
network), which are not in SM state PDP-INACTIVE on network side but are indicated by the MS as being in state
PDP-INACTIVE.
If the MBMS context status information element is included in the ROUTING AREA UPDATE REQUEST message,
then the network shall deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and
network) which are not in SM state PDP-INACTIVE on the network side, but are indicated by the MS as being in state
PDP-INACTIVE. If no MBMS context status information element is included, then the network shall deactivate all
MBMS contexts locally which are not in SM state PDP-INACTIVE on the network side.
If a ROUTING AREA UPDATE REQUEST message is received from a MS with a LIPA PDN connection, and if:
- a L-GW Transport Layer Address is provided by the lower layer together with the ROUTING AREA UPDATE
REQUEST message, and the GGSN address associated with the PDP context of the LIPA PDN connection is
different from the provided L-GW Transport Layer Address (see 3GPP TS 25.413 [19c]); or
- no L-GW Transport Layer Address is provided together with the ROUTING AREA UPDATE REQUEST
message by the lower layer,
then the SGSN locally deactivates all PDP contexts associated with the LIPA PDN connection. If the ROUTING AREA
UPDATE REQUEST request message is accepted, the SGSN informs the MS via the PDP context status IE in the
ROUTING AREA UPDATE ACCEPT message that PDP contexts were locally deactivated.
If due to regional subscription restrictions or access restrictions the MS is not allowed to access the routing area, but the
MS has a PDN connection for emergency bearer services established, the network may accept the ROUTING AREA
UPDATE REQUEST message and deactivate all non-emergency PDP contexts by initiating an PDP context
deactivation procedure when the RAU is initiated in PMM-CONNECTED mode. When the RAU is initiated in PMM-
IDLE mode, the network locally deactivates all non-emergency PDP contexts and informs the MS via the PDP context
status IE in the ROUTING AREA UPDATE ACCEPT message. The network shall not deactivate the PDP contexts for
emergency bearer services. The network shall consider the MS to be attached for emergency bearer services only.
Upon receipt of a ROUTING AREA UPDATE ACCEPT message, the MS stores the received routing area
identification, stops timer T3330, shall reset the routing area updating attempt counter and sets the GPRS update status
to GU1 UPDATED. If the message contains a P-TMSI, the MS shall use this P-TMSI as new temporary identity for
GPRS services and shall store the new P-TMSI. If no P-TMSI was included by the network in the ROUTING AREA
UPDATING ACCEPT message, the old P-TMSI shall be kept. Furthermore, the MS shall store the P-TMSI signature if
received in the ROUTING AREA UPDATING ACCEPT message. If no P-TMSI signature was included in the message,
the old P-TMSI signature, if available, shall be deleted.
If the ROUTING AREA UPDATE REQUEST message was used to update the network with a new DRX parameter IE,
the MS shall start using the new DRX parameter upon receipt of the ROUTING AREA UPDATE ACCEPT message
and shall set the TIN to "P-TMSI".
If the PDP context status information element is included in ROUTING AREA UPDATE ACCEPT message, then the
MS shall deactivate all those PDP contexts locally (without peer to peer signalling between the MS and network), which
are not in SM state PDP-INACTIVE in the MS but are indicated by the network as being in state PDP-INACTIVE. If
only the PDN connection for emergency bearer services remains established, the MS shall consider itself attached for
emergency bearer services only.
3GPP
Release 10 163 3GPP TS 24.008 V10.6.1 (2012-03)
If the MBMS context status information element is included in the ROUTING AREA UPDATE ACCEPT message, then
the MS shall deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and network)
which are not in SM state PDP-INACTIVE in the MS, but are indicated by the network as being in state PDP-
INACTIVE. If no MBMS context status information element is included, then the MS shall deactivate all those MBMS
contexts locally which are not in SM state PDP-INACTIVE in the MS.
If the ROUTING AREA UPDATE ACCEPT message contains T3312 extended value IE, then the MS shall use the
T3312 extended value IE as periodic routing area update timer (T3312). If the ROUTING AREA UPDATE ACCEPT
message does not contain T3312 extended value IE, then the MS shall use value in T3312 value IE as periodic routing
area update timer (T3312).
In A/Gb mode, if the ROUTING AREA UPDATE ACCEPT message contains the Cell Notification information
element, then the MS shall start to use the LLC NULL frame to perform cell updates.
If the MS has initiated the routing area updating procedure due to manual CSG selection and receives a ROUTING
AREA UPDATE ACCEPT message, and the MS sent the ROUTING AREA UPDATE REQUEST message in a CSG
cell, the MS shall check if the CSG ID and associated PLMN identity of the cell are contained in the Allowed CSG list.
If not, the MS shall add that CSG ID and associated PLMN identity to the Allowed CSG list and the MS may add the
HNB Name (if provided by lower layers) to the Allowed CSG list if the HNB Name is present in neither the Operator
CSG list nor the Allowed CSG list.
The network may also send a list of "equivalent PLMNs" in the ROUTING AREA UPDATE ACCEPT message. Each
entry of the list contains a PLMN code (MCC+MNC). The mobile station shall store the list, as provided by the
network, and if there is no PDN connection for emergency bearers established, the mobile station shall remove from the
list of "equivalent PLMNs" any PLMN code that is already in the "forbidden PLMN" list. If there is a PDN connection
for emergency bearer services established, the MS shall remove from the list of "equivalent PLMNs" any PLMN code
present in the "forbidden PLMN" list when the PDN connection for emergency bearer services is released. In addition
the mobile station shall add to the stored list the PLMN code of the registered PLMN that sent the list. All PLMNs in
the stored list shall be regarded as equivalent to each other for PLMN selection, cell selection/re-selection and handover.
The stored list in the mobile station shall be replaced on each occurrence of the ROUTING AREA UPDATE ACCEPT
message. If no list is contained in the message, then the stored list in the mobile station shall be deleted. An MS attached
for emergency bearer services only shall delete the stored list when the MS enters the state GMM-DEREGISTERED.
The list shall be stored in the mobile station while switched off so that it can be used for PLMN selection after switch
on.
A ROUTING AREA UPDATE COMPLETE message shall be returned to the network if the ROUTING AREA
UPDATE ACCEPT message contained any of:
- a P-TMSI;
- Receive N-PDU Numbers (see 3GPP TS 44.065 [78] and 3GPP TS 25.322 [19b]); or
- a request for the provision of Inter RAT handover information or E-UTRAN inter RAT handover information or
both.
If Receive N-PDU Numbers were included, the Receive N-PDU Numbers values valid in the MS, shall be included in
the ROUTING AREA UPDATE COMPLETE message.
If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover
information or both, the MS shall return a ROUTING AREA UPDATE COMPLETE message including the Inter RAT
handover information IE or E-UTRAN inter RAT handover information IE or both to the network.
NOTE 2: In Iu mode, after a routing area updating procedure, the mobile station can initiate Service Request
procedure to request the resource reservation for the active PDP contexts if the resources have been
released by the network or send upper layer message (e.g. ACTIVATE PDP CONTEXT REQUEST) to
the network via the existing PS signalling connection.
In Iu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has
indicated "follow-on request pending" in ROUTING AREA UPDATE REQUEST message) the network shall indicate
the "follow-on proceed" in the ROUTING AREA UPDATE ACCEPT message. If the network wishes to release the PS
signalling connection, the network shall indicate "no follow-on proceed" in the ROUTING AREA UPDATE ACCEPT
message.
3GPP
Release 10 164 3GPP TS 24.008 V10.6.1 (2012-03)
After that in Iu mode, the mobile station shall act according to the follow-on proceed flag included in the Update result
information element in the ROUTING AREA UPDATE ACCEPT message (see subclause 4.7.13).
The network may also send a list of local emergency numbers in the ROUTING AREA UPDATE ACCEPT, by
including the Emergency Number List IE. The mobile equipment shall store the list, as provided by the network, except
that any emergency number that is already stored in the SIM/USIM shall be removed from the list before it is stored by
the mobile equipment. If there are no emergency numbers stored on the SIM/USIM, then before storing the received list
the mobile equipment shall remove from it any emergency number stored permanently in the ME for use in this case
(see 3GPP TS 22.101 [8]). The list stored in the mobile equipment shall be replaced on each receipt of a new
Emergency Number List IE.
The emergency number(s) received in the Emergency Number List IE are valid only in networks with the same MCC as
in the cell on which this IE is received. If no list is contained in the ROUTING AREA UPDATE ACCEPT message,
then the stored list in the mobile equipment shall be kept, except if the mobile equipment has successfully registered to
a PLMN with an MCC different from that of the last registered PLMN.
The mobile equipment shall use the stored list of emergency numbers received from the network in addition to the
emergency numbers stored on the SIM/USIM or ME to detect that the number dialled is an emergency number.
NOTE 3: The mobile equipment may use the emergency numbers list to assist the end user in determining whether
the dialled number is intended for an emergency service or for another destination, e.g. a local directory
service. The possible interactions with the end user are implementation specific.
The list of emergency numbers shall be deleted at switch off and removal of the SIM/USIM. The mobile equipment
shall be able to store up to ten local emergency numbers received from the network.
In order to indicate to the MS that the GUTI and TAI list assigned to the MS remain registered with the network and are
valid in the MS, the network shall indicate in the Update result IE in the ROUTING AREA UPDATE ACCEPT message
that ISR is activated.
If the MS is attached for emergency bearer services or if the network has deactivated all non-emergency PDP contexts,
the network shall indicate in the update result IE in the ROUTING AREA UPDATE ACCEPT message that ISR is not
activated.
i) no indication that ISR is activated, an MS supporting S1 mode shall set the TIN to "P-TMSI"; or
- if the MS is required to perform tracking area updating for IMS voice termination as specified in annex P.5,
the MS shall set the TIN to "P-TMSI"; or
- the MS shall regard the available GUTI and TAI list as valid and registered with the network. If the TIN
currently indicates "GUTI" and the periodic tracking area update timer T3412 is running, the MS shall set the
TIN to "RAT-related TMSI". If the TIN currently indicates "GUTI" and the periodic tracking area update
timer T3412 has already expired, the MS shall set the TIN to "P-TMSI".
4.7.5.1.4 Normal and periodic routing area updating procedure not accepted by the
network
If the routing area updating cannot be accepted, the network sends a ROUTING AREA UPDATE REJECT message to
the MS. An MS that receives a ROUTING AREA UPDATE REJECT message, stops timer T3330, and for all causes
except #12, #14, #15, #22 and #25 deletes the list of "equivalent PLMNs". If a ROUTING AREA UPDATE REJECT
message is received, the MS shall stop any ongoing transmission of user data.
If the routing area update request is rejected due to general NAS level mobility management congestion control, the
network shall set the GMM cause value to #22 "congestion" and assign a back-off timer T3346.
The MS shall then take different actions depending on the received reject cause value:
#3 (Illegal MS);
#6 (Illegal ME);
3GPP
Release 10 165 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and enter the state GMM-DEREGISTERED. Furthermore, it shall delete any P-TMSI, P-
TMSI signature, RAI and GPRS ciphering key sequence number and shall consider the SIM/USIM as invalid for
GPRS services until switching off or the SIM/USIM is removed.
If the MS is IMSI attached, the MS shall in addition set the update status to U3 ROAMING NOT ALLOWED,
shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in MS operation mode A
and an RR connection exists, the MS shall abort the RR connection, unless an emergency call is ongoing. The
SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or the SIM/USIM is
removed.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
tracking area update procedure is rejected with the EMM cause with the same value.
NOTE 1: The possibility to configure a MS so that the radio transceiver for a specific radio access technology is not
active, although it is implemented in the MS, is out of scope of the present specification.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2.9) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM
is removed. The new state is GMM-DEREGISTERED.
If the update type is "periodic updating", a GPRS MS operating in MS operation mode A or B in network
operation mode I is still IMSI attached for CS services in the network, and shall set the timer T3212 to its initial
value and restart it, if it is not already running. The MS shall then proceed with the appropriate MM specific
procedure according to the MM service state.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
tracking area update procedure is rejected with the EMM cause with the same value.
The MS shall set the GPRS update status to GU2 NOT UPDATED (and shall store it according to
subclause 4.1.3.2), enter the state GMM-DEREGISTERED, and shall delete any P-TMSI, P-TMSI signature,
RAI and GPRS ciphering key sequence number. If the rejected request was not for initiating a PDN connection
for emergency bearer services, the MS may subsequently,automatically initiate the GPRS attach procedure.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
tracking area update procedure is rejected with the EMM cause with the same value.
# 10 (Implicitly detached);
The MS shall change to state GMM-DEREGISTERED.NORMAL-SERVICE. If the rejected request was not for
initiating a PDN connection for emergency bearer services, the MS shall then perform a new attach procedure.
The MS should also activate PDP context(s) to replace any previously active PDP contexts. The MS should also
perform the procedures needed in order to activate any previously active multicast service(s).
If S1 mode is supported in the MS, the MS shall handle the EMM state as specified in 3GPP TS 24.301 [120] for
the case when the tracking area update procedure is rejected with the EMM cause with the same value.
NOTE 2: In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS
context(s) automatically.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2),
shall reset the routing area updating attempt counter and enter the state GMM-DEREGISTERED.
The MS shall store the PLMN identity in the "forbidden PLMN list".
3GPP
Release 10 166 3GPP TS 24.008 V10.6.1 (2012-03)
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in
3GPP TS 24.301 [120] for the case when the tracking area update procedure is rejected with the EMM cause
with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to clause 4.1.3.2),
shall reset the routing area updating attempt counter and shall change to state GMM-
DEREGISTERED.LIMITED-SERVICE.
The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98].
NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in
3GPP TS 24.301 [120] for the case when the tracking area update procedure is rejected with the EMM cause
with the same value.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
clause 4.1.3.2) shall reset the routing area updating attempt counter and shall change to state GMM-
REGISTERED.LIMITED-SERVICE.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall
reset the location update attempt counter. The new MM state is MM IDLE.
3GPP
Release 10 167 3GPP TS 24.008 V10.6.1 (2012-03)
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the tracking area
update procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM-
DEREGISTERED.
The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list. A GPRS MS operating
in MS operation mode C shall perform a PLMN selection instead of a cell selection.
If the update type is "periodic updating" a GPRS MS operating in MS operation mode A or B in network
operation mode I shall set the timer T3212 to its initial value and restart it, if it is not already running.
A GPRS MS operating in MS operation mode A or B in network operation mode II or III, is still IMSI attached
for CS services in the network.
As an implementation option, a GPRS MS operating in operation mode A or B may perform the following
additional action. If no RR connection exists the MS may perform the action immediately. If the MS is operating
in MS operation mode A and an RR connection exists, the MS may only perform the action when the RR
connection is subsequently released:
If an MS in GAN mode performs a PLMN selection, it shall request a PLMN list in GAN (see
3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23.122 [14].
The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause
is:
- On the "User Controlled PLMN Selector with Access Technology " or,
- On the "Operator Controlled PLMN Selector with Access Technology " list or,
- A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in
3GPP TS 24.301 [120] for the case when the tracking area update procedure is rejected with the EMM cause
with the same value.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) shall reset the routing area updating attempt counter and shall change to state GMM-
REGISTERED.LIMITED-SERVICE.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall
reset the location update attempt counter. The new MM state is MM IDLE.
- The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121].
3GPP
Release 10 168 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 4: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the tracking area
update procedure is rejected with the EMM cause with the same value.
#22 (Congestion);
If the T3346 value IE is present in the ROUTING AREA UPDATE REJECT message and the value indicates
that this timer is neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be
considered as an abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.5.1.5.
The MS shall abort the routing area updating procedure, reset the routing area updating attempt counter and set
the GPRS update status to GU2 NOT UPDATED. If the rejected request was not for initiating a PDN connection
for emergency bearer services, the MS shall change to state GMM-REGISTERED.ATTEMPTING-TO-
UPDATE.
If the ROUTING AREA UPDATE REJECT message is integrity protected, the MS shall start timer T3346 with
the value provided in the T3346 value IE.
If the ROUTING AREA UPDATE REJECT message is not integrity protected, the MS shall start timer T3346
with a random value from the default range specified in table 11.3a.
The MS stays in the current serving cell and applies the normal cell reselection process. The routing area
updating procedure is started, if still necessary, when timer T3346 expires or is stopped.
Cause #25 is only applicable in UTRAN Iu mode and when received from a CSG cell. Other cases are
considered as abnormal cases and the specification of the mobile station behaviour is given in
subclause 4.7.5.1.5.
If the ROUTING AREA UPDATE REJECT message with cause #25 was received without integrity protection,
then the MS shall discard the message.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and store it according to
subclause 4.1.3.2) and shall reset the routing area updating attempt counter. The state is changed to GMM-
REGISTERED.LIMITED-SERVICE.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA UPDATE
REQUEST message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry
corresponding to this CSG ID and associated PLMN identity from the Allowed CSG list.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA
UPDATE REQUEST message are contained in the Operator CSG list, the MS shall proceed as specified in
3GPP TS 23.122 [14] subclause 3.1A.
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall
reset the location update attempt counter. The new MM state is MM IDLE.
- The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the tracking area
update procedure is rejected with the EMM cause with the same value.
3GPP
Release 10 169 3GPP TS 24.008 V10.6.1 (2012-03)
Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is described in
subclause 4.7.5.1.5.
4.7.5.1.4a Routing area updating procedure for initiating a PDN connection for emergency
bearer services not accepted by the network (UTRAN Iu mode only)
If the routing area updating request for initiating a PDN connection for emergency bearer services cannot be accepted
by the network, the MS shall perform the procedures as described in subclause 4.7.5.1.4. Then if the MS is in the same
selected PLMN where the last routing area updating was attempted, the MS shall:
a) inform the upper layers. This could result in the MS attempting a CS emergency call (if not already attempted in
the CS domain) or other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [95]
that can result in the emergency call being attempted to another IP-CAN; or
b) detach locally, if not detached already, attempt GPRS attach for emergency bearer services.
The routing area updating procedure shall not be started. The MS stays in the current serving cell and applies the
normal cell reselection process. The procedure is started as soon as possible and if still necessary, i.e. when the
barred state is removed or because of a cell change.
b) Lower layer failure before the ROUTING AREA UPDATE ACCEPT or ROUTING AREA UPDATE REJECT
message is received
The procedure shall be aborted and the MS shall proceed as described below, except in the following
implementation option cases b.1 and b.2.
b.1) Release of PS signalling connection before the completion of the routing area updating procedure
The routing area updating procedure shall be initiated again, if the following conditions apply:
i) The original routing area update procedure was initiated over an existing PS signalling connection; and
ii) The routing area update procedure was not due to timer T3330 expiry; and
iii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the PS signalling connection were (e.g. PS authentication procedure, see subclause 4.7.7) received after the
ROUTING AREA UPDATE REQUEST message was transmitted.
b.2) RR release in Iu mode (i.e. RRC connection release) with, for example, cause "Normal", or "User inactivity"
or "Direct signalling connection re-establishment" (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111])
The routing area updating procedure shall be initiated again, if the following conditions apply:
i) The original routing area update procedure was initiated over an existing RRC connection; and
ii) The routing area update procedure was not due to timer T3330 expiry; and
iii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the PS signalling connection (e.g. PS authentication procedure, see subclause 4.7.7) were received after the
ROUTING AREA UPDATE REQUEST message was transmitted.
NOTE 1: The RRC connection release cause that triggers the re-initiation of the routing area update procedure is
implementation specific.
c) T3330 time-out
The procedure is restarted four times, i.e. on the fifth expiry of timer T3330, the MS shall abort the procedure
and, in Iu mode, release the PS signalling connection (see 3GPP TS 25.331 [23c]). The MS shall proceed as
described below.
3GPP
Release 10 170 3GPP TS 24.008 V10.6.1 (2012-03)
d) ROUTING AREA UPDATE REJECT, other causes than those treated in subclause 4.7.5.1.4, and cases of GMM
cause #22, if considered as abnormal cases according to subclause 4.7.5.1.4
Upon reception of the cause codes # 95, # 96, # 97, # 99 and # 111 the MS should set the routing area updating
attempt counter to 5. The MS shall proceed as described below.
f) In A/Gb mode, if a cell change occurs within the same RA, when the MS is in state GMM-ROUTING-AREA-
UPDATE-INITIATED, the cell update procedure is performed, before completion of the routing area updating
procedure.
If the MS receives a DETACH REQUEST message before the routing area updating procedure has been
completed, the routing area updating procedure shall be aborted and the GPRS detach procedure shall be
progressed. If the DETACH REQUEST message contains detach type "re-attach not required" and GMM
cause #2 "IMSI unknown in HLR", the MS will follow the procedure as described below for the detach type
"IMSI detach".
If the MS receives a DETACH REQUEST message before the routing area updating procedure has been
completed, the routing area updating procedure shall be progressed, i.e. the DETACH REQUEST message
shall be ignored.
If the MS receives a P-TMSI REALLOCATION C0MMAND message before the routing area updating
procedure has been completed, the P-TMSI reallocation procedure shall be aborted and the routing area updating
procedure shall be progressed.
If the ROUTING AREA UPDATE REQUEST message contained the NAS signalling low priority indication set
to "MS is configured for NAS signalling low priority", the MS shall start timer T3346 with the "Extended wait
time" value.
The MS shall abort the routing area updating procedure, reset the routing area updating attempt counter, stay in
the current serving cell, set the GPRS update status to GU2 NOT UPDATED, change the state to GMM-
REGISTERED.ATTEMPTING-TO-UPDATE and apply the normal cell reselection process.
The routing area updating procedure is started, if still necessary, when timer T3346 expires or is stopped.
The MS shall not start the routing area updating procedure unless the MS is in PMM-CONNECTED mode or the
MS receives a paging, has a PDN connection for emergency bearer services established or is establishing a PDN
connection for emergency bearer services. The MS stays in the current serving cell and applies the normal cell
reselection process.
The routing area updating procedure is started, if still necessary, when timer T3346 expires or is stopped.
NOTE 2: It is considered an abnormal case if the MS needs to initiate an routing area updating procedure while
timer T3346 is running independent on whether timer T3346 was started due to an abnormal case or a non
successful case.
If the stored RAI is different to the RAI of the current serving cell or the TIN indicates "GUTI", the MS shall set
the GPRS update status to GU2 NOT UPDATED and change to state GMM-REGISTERED.ATTEMPTING-TO-
UPDATE.
3GPP
Release 10 171 3GPP TS 24.008 V10.6.1 (2012-03)
In cases b, c, d, e, and g with detach type "re-attach required" or "re-attach not required", the MS shall stop any ongoing
transmission of user data.
Timer T3330 shall be stopped if still running. The routing area updating attempt counter shall be incremented.
If the routing area updating attempt counter is less than 5, and the stored RAI is equal to the RAI of the current
serving cell and the GPRS update status is equal to GU1 UPDATED and the TIN does not indicate "GUTI":
- the MS shall keep the GPRS update status to GU1 UPDATED and changes state to GMM-
REGISTERED.NORMAL-SERVICE. The MS shall start timer T3311.
If in addition the ROUTING AREA UPDATE REQUEST message indicated "periodic updating",
- in Iu mode, the timer T3311 may be stopped when the MS enters PMM-CONNECTED mode;
- in A/Gb mode, the timer T3311 may be stopped when the READY timer is started.
If timer T3311 expires the routing area updating procedure is triggered again.
If the routing area updating attempt counter is less than 5, and the stored RAI is different to the RAI of the
current serving cell or the GPRS update status is different to GU1 UPDATED or the TIN indicates "GUTI":
- for the cases i and j, the routing area updating procedure is started, if still necessary, when timer T3346
expires or is stopped;
- for all other cases, the MS shall start timer T3311, shall set the GPRS update status to GU2 NOT UPDATED
and changes state to GMM-REGISTERED.ATTEMPTING-TO-UPDATE.
If S1 mode is supported by the MS, the MS shall in addition handle the EPS update status as specified in
3GPP TS 24.301 [120] for the abnormal case when a normal or periodic tracking area updating procedure
fails and the tracking area updating attempt counter is less than 5 and the EPS update status is different from
EU1 UPDATED.
- the MS shall start timer T3302, shall delete the list of equivalent PLMNs, shall set the GPRS update status to
GU2 NOT UPDATED and shall change to state GMM-REGISTERED.ATTEMPTING-TO-UPDATE or
optionally to GMM-REGISTERED.PLMN-SEARCH(see subclause 4.2.5.1.8) in order to perform a PLMN
selection according to 3GPP TS 23.122 [14].
- If S1 mode is supported by the MS, the MS shall in addition handle the EPS update status as specified in
3GPP TS 24.301 [120] for the abnormal case when a normal or periodic tracking area updating procedure
fails and the tracking area updating attempt counter is equal to 5.
a) If a lower layer failure occurs before the message ROUTING AREA UPDATE COMPLETE has been received
from the MS and a P-TMSI and/or PTMSI signature has been assigned, the network shall abort the procedure
and shall consider both, the old and new P-TMSI and the corresponding P-TMSI signatures as valid until the old
P-TMSI can be considered as invalid by the network (see subclause 4.7.1.5). During this period the network may
use the identification procedure followed by a P-TMSI reallocation procedure if the old P-TMSI is used by the
MS in a subsequent message.
NOTE: Optionally, paging with IMSI may be used if paging with old and new P-TMSI fails. Paging with IMSI
causes the MS to re-attach as described in subclause 4.7.9.1.
b) Protocol error
If the ROUTING AREA UPDATE REQUEST message has been received with a protocol error, the network
shall return a ROUTING AREA UPDATE REJECT message with one of the following reject causes:
3GPP
Release 10 172 3GPP TS 24.008 V10.6.1 (2012-03)
c) T3350 time-out
On the first expiry of the timer, the network shall retransmit the ROUTING AREA UPDATE ACCEPT message
and shall reset and restart timer T3350. The retransmission is performed four times, i.e. on the fifth expiry of
timer T3350, the routing area updating procedure is aborted. Both, the old and the new P-TMSI and the
corresponding P-TMSI signatures shall be considered as valid until the old P-TMSI can be considered as invalid
by the network(see subclause 4.7.1.5). During this period the network acts as described for case a above.
MS Network
Figure 4.7.5/1 3GPP TS 24.008: Routing and combined routing area updating procedure
d.1) ROUTING AREA UPDATE REQUEST received after the ROUTING AREA UPDATE ACCEPT message
has been sent and before the ROUTING AREA UPDATE COMPLETE message is received
- If one or more of the information elements in the ROUTING AREA UPDATE REQUEST message differ from
the ones received within the previous ROUTING AREA UPDATE REQUEST message, the previously initiated
routing area updating procedure shall be aborted if the ROUTING AREA UPDATE COMPLETE message has
not been received and the new routing area updating procedure shall be progressed, or
- If the information elements do not differ, then the ROUTING AREA UPDATE ACCEPT message shall be resent
and the timer T3350 shall be restarted if an ROUTING AREA UPDATE COMPLETE message is expected. In
that case, the retransmission counter related to T3350 is not incremented.
d.2) More than one ROUTING AREA UPDATE REQUEST received and no ROUTING AREA UPDATE
ACCEPT or ROUTING AREA UPDATE REJECT message has been sent
- If one or more of the information elements in the ROUTING AREA UPDATE REQUEST message differs from
the ones received within the previous ROUTING AREA UPDATE REQUEST message, the previously initiated
routing area updating procedure shall be aborted and the new routing area updating procedure shall be
progressed;
- If the information elements do not differ, then the network shall continue with the previous routing area updating
procedure and shall not treat any further this ROUTING AREA UPDATE REQUEST message.
3GPP
Release 10 173 3GPP TS 24.008 V10.6.1 (2012-03)
4.7.5.2.0 General
Within a combined routing area updating procedure the messages ROUTING AREA UPDATE ACCEPT and
ROUTING AREA UPDATE COMPLETE carry information for the routing area updating and the location area
updating.
- when a GPRS MS that is IMSI attached for GPRS and non-GPRS services detects a change of the routing area in
state GMM-REGISTERED and MM-IDLE, unless the MS is configured for "AttachWithIMSI" as specified in
3GPP TS 24.368 [135] or 3GPP TS 31.102 [112] and is entering a routing area in a new PLMN that is neither the
registered PLMN nor in the list of equivalent PLMNs;
- when a GPRS MS that is IMSI attached for GPRS services wants to perform an IMSI attach for non-GPRS
services;
- after termination of a non-GPRS service via non-GPRS channels to update the association if the MS has changed
the RA during that non-GPRS service transaction;
- after termination of a non-GPRS service via non-GPRS channels to update the association if GPRS services were
suspended during the non-GPRS service but no resume is received. See 3GPP TS 23.060 [74] subclause 16.2.1;
- after termination of a non-GPRS service via non-GPRS channels to update the association, if the GPRS MS in
MS operation mode A performed a normal GPRS attach or a normal routing area updating procedure during the
circuit-switched transaction;
- after a CM SERVICE REJECT message with cause value #4 is received by the mobile station (see
subclause 4.5.1.1); in this case the update type IE shall be set to "Combined RA/LA updating with IMSI attach";
- when a GPRS MS needs to update the network with the new MS Radio Access Capability IE;
- when a GPRS MS needs to update the network with a new DRX parameter IE;
- in Iu mode, to re-synchronize the PMM mode of MS and network after RRC connection release with cause
"Directed signalling connection re-establishment", see subclause 4.7.2.5;
- in Iu mode and A/Gb mode, after intersystem change from S1 mode, and the GMM receives an indication of
"RRC connection failure" from lower layers due to lower layer failure while in S1 mode;
- in A/Gb mode, after intersystem change from S1 mode if the TIN indicates "RAT-related TMSI", but the MS is
required to perform routing area updating for IMS voice termination as specified in annex P.4;
- when the MS supports SRVCC and changes the mobile station classmark 2, mobile station classmark 3 or the
supported codecs;
- when the MS is configured to use CS fallback and SMS over SGs, or SMS over SGs only, the TIN indicates
"RAT-related TMSI" and the periodic tracking area update timer T3412 expires;
- when the MS which is configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a
GERAN or UTRAN cell, the TIN indicates "RAT-related TMSI", and the E-UTRAN deactivate ISR timer T3423
is running;
- when the MS which is configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a
GERAN or UTRAN cell and the E-UTRAN deactivate ISR timer T3423 has expired;
- when due to a manual CSG selection the GPRS MS has selected a CSG cell whose CSG identity and associated
PLMN identity are not included in the MS's Allowed CSG list or in the MS's Operator CSG list;
3GPP
Release 10 174 3GPP TS 24.008 V10.6.1 (2012-03)
- when the UE's usage setting or the voice domain preference for E-UTRAN change in the MS;
- when the MS activates mobility management for IMS voice termination as specified in annex P.2 and the TIN
indicates "RAT-related TMSI";
- upon reception of a paging indication using P-TMSI, if the timer T3346 is running and the MS is in state GMM-
REGISTERED.ATTEMPTING-TO-UPDATE; or
- when the MS which is configured to use CS fallback and SMS over SGs, or SMS over SGs only, enters a
GERAN or UTRAN cell, after intersystem change from S1 mode to Iu or A/Gb mode not due to CS fallback,
and the location area of the current cell is different from the location area stored in the MS.
In A/Gb mode, the routing and location area identification are broadcast on the broadcast channel(s). A combined
routing area updating procedure shall abort any ongoing GMM procedure. Aborted GMM procedures shall be repeated
after the combined routing area updating procedure has been successfully performed. The ROUTING AREA UPDATE
REQUEST message shall always be the first message sent from the MS in the new routing area after routing area
change.
In Iu mode, the routing and location area identification are broadcast on the broadcast channel(s) or sent to the MS via
the PS signalling connection. A combined routing area updating procedure shall abort any ongoing GMM procedure.
Aborted GMM procedures may be repeated after the combined routing area updating procedure has been successfully
performed. The ROUTING AREA UPDATE REQUEST message shall always be the first GMM message sent from the
MS in the new routing area after routing area change.
To initiate a combined routing area updating procedure the MS sends the message ROUTING AREA UPDATE
REQUEST to the network, starts timer T3330 and changes to state GMM-ROUTING-UPDATING-INITIATED and
MM LOCATION UPDATING PENDING. The value of the Update type IE in the message shall indicate "combined
RA/LA updating" unless explicitly specified otherwise. If for the last attempt to update the registration of the location
area a MM specific procedure was performed, the value of the Update type IE in the ROUTING AREA UPDATE
REQUEST message shall indicate "combined RA/LA updating with IMSI attach". Furthermore the MS shall include the
TMSI status IE if no valid TMSI is available. If the MS has stored a valid LAI and the MS supports EMM combined
procedures, the MS shall include it in the Old location area identification IE in the ROUTING AREA UPDATE
REQUEST message.
A GPRS MS in MS operation modes B that is in an ongoing circuit-switched transaction, shall initiate the combined
routing area updating procedure after the circuit-switched transaction has been released, if the MS has changed the RA
during the circuit-switched transaction and if the network operates in network operation mode I.
A GPRS MS in MS operation mode A shall initiate the combined routing area updating procedure with IMSI attach after
the circuit-switched transaction has been released, if a normal GPRS attach or a normal routing area updating procedure
was performed during the circuit-switched transaction and provided that the network operates in network operation
mode I.
A GPRS MS in MS operation mode A shall perform the normal routing area update procedure during an ongoing
circuit-switched transaction.
In Iu mode, if the MS wishes to prolong the established PS signalling connection after the normal routing area updating
procedure (for example, the MS has any CM application request pending), it may set a follow-on request pending
indicator on (see subclause 4.7.13).
In Iu mode, when a ROUTING AREA UPDATE REQUEST is received by the SGSN over a new PS signalling
connection while there is an ongoing PS signalling connection (network is already in mode PMM-CONNECTED) for
this MS, the network shall progress the routing area update procedure as normal and release the previous PS signalling
connection when the routing area update procedure has been accepted by the network.
NOTE: The re-establishment of the radio bearers of active PDP contexts is done as described in subclause
"Service Request procedure".
If the combined routing area updating procedure is initiated due to the reception of the paging indication while T3346 is
running, the "follow-on request pending" indication shall be set to 1.
3GPP
Release 10 175 3GPP TS 24.008 V10.6.1 (2012-03)
Case 1) The update result IE value indicates "combined RA/LA": Routing and location area updating is
successful;
Case 2) The update result IE value indicates "RA only": Routing area updating is successful, but location area
updating is not successful.
A ROUTING AREA UPDATE COMPLETE message shall be returned to the network if the ROUTING AREA
UPDATE ACCEPT message containsany of:
- Receive N-PDU Numbers (see 3GPP TS 44.065 [78] and 3GPP TS 25.322 [19b]); or
- a request for the provision of Inter RAT handover information or E-UTRAN inter RAT handover information or
both.
If Receive N-PDU Numbers were included, the Receive N-PDU Numbers that are valid in the MS shall be included in
the ROUTING AREA UPDATE COMPLETE message.
If the network has requested the provision of Inter RAT handover information or E-UTRAN inter RAT handover
information the MS shall return a ROUTING AREA UPDATE COMPLETE message including the Inter RAT handover
information IE or the E-UTRAN inter RAT handover information IE or both, as applicable, to the network.
In Iu mode, if the network wishes to prolong the PS signalling connection (for example, if the mobile station has
indicated "follow-on request pending" in ROUTING AREA UPDATE REQUEST message) the network shall indicate
the "follow-on proceed" in the ROUTING AREA UPDATE ACCEPT message. If the network wishes to release the PS
signalling connection, the network shall indicate "no follow-on proceed" in the ROUTING AREA UPDATE ACCEPT
message.
After that in Iu mode, the mobile station shall act according to the follow-on proceed flag included in the Update result
information element in the ROUTING AREA UPDATE ACCEPT message (see subclause 4.7.13).
If the network supports CS Fallback, and the mobile station has indicated support of EMM combined procedures in MS
network capability, the network shall indicate in the Update result IE in the ROUTING AREA UPDATE ACCEPT
message that ISR is not activated.
The description for normal routing area update as specified in subclause 4.7.5.1.3 shall be followed. In addition, the
following description for location area updating applies.
The handling at the receipt of the ROUTING AREA UPDATE ACCEPT depends on the value received in the update
result IE as specified below.
The TMSI reallocation may be part of the combined routing area updating procedure. The TMSI allocated is then
included in the ROUTING AREA UPDATE ACCEPT message together with the location area identification (LAI). The
network shall, in this case, change to state GMM-COMMON-PROCEDURE-INITIATED and shall start the timer
T3350 as described in subclause 4.7.6.
The MS, receiving a ROUTING AREA UPDATE ACCEPT message, stores the received location area identification,
stops timer T3330, enters state MM IDLE, reset the location update attempt counter and sets the update status to U1
UPDATED. If the ROUTING AREA UPDATE ACCEPT message contains an IMSI, the mobile station is not allocated
any TMSI, and shall delete any TMSI accordingly. If the ROUTING AREA UPDATE ACCEPT message contains a
TMSI, the MS shall use this TMSI as new temporary identity. The MS shall delete its old TMSI and shall store the new
TMSI. In this case, an ROUTING AREA UPDATE COMPLETE message is returned to the network. If neither a TMSI
3GPP
Release 10 176 3GPP TS 24.008 V10.6.1 (2012-03)
nor an IMSI has been included by the network in the ROUTING AREA UPDATE ACCEPT message, the old TMSI, if
any is available, shall be kept.
Any timer used for triggering the location updating procedure (e.g. T3211, T3212) shall be stopped if running.
The network receiving a ROUTING AREA UPDATE COMPLETE message stops timer T3350, changes to GMM-
REGISTERED state and considers the new TMSI as valid.
4.7.5.2.3.2 Combined routing area updating successful for GPRS services only
Apart from the actions on the routing area updating attempt counter, the description for normal routing area update as
specified in subclause 4.7.5.1.3 shall be followed. In addition, the following description for location area updating
applies.
The MS receiving the ROUTING AREA UPDATE ACCEPT message takes one of the following actions depending on
the reject cause:
The MS shall stop timer T3330 if still running and shall reset the routing area updating attempt counter. The MS
shall set the update status to U3 ROAMING NOT ALLOWED and shall delete any TMSI, LAI and ciphering
key sequence number. The MS shall enter state GMM-REGISTERED.NORMAL-SERVICE. The new MM state
is MM IDLE. The SIM/USIM shall be considered as invalid for non-GPRS services until switching off or the
SIM/USIM is removed.
#22 (Congestion).
- the MS shall keep the GMM update status GU1 UPDATED and changes state to GMM-
REGISTERED.ATTEMPTING-TO-UPDATE-MM. The MS shall start timer T3311. When timer T3311
expires the combined routing area update procedure indicating "combined RA/LA updating with IMSI
attach" is triggered again.
- the MS shall start timer T3302 and shall change to state GMM-REGISTERED.ATTEMPTING-TO-
UPDATE-MM;
- a GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific procedure;
a GPRS MS operating in MS operation mode B may then proceed with appropriate MM specific procedures.
The MM sublayer shall act as in network operation mode II or III (depending whether a PCCCH is present)
as long as the combined GMM procedures are not successful and no new RA is entered. The new MM state is
MM IDLE.
Other reject cause values and the case that no GMM cause IE was received are considered as abnormal cases. The
combined routing area updating shall be considered as failed for GPRS and non-GPRS services. The specification of the
MS behaviour in those cases is specified in subclause 4.7.5.2.5.
3GPP
Release 10 177 3GPP TS 24.008 V10.6.1 (2012-03)
If the routing area update request is rejected due to general NAS level mobility management congestion control, the
network shall set the GMM cause value to #22 "congestion" and assign a back-off timer T3346.
The MS shall then take different actions depending on the received reject cause:
#3 (Illegal MS);
#6 (Illegal ME), or
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED and the update status to U3
ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2) and enter the state GMM-
DEREGISTERED. Furthermore, it shall delete any P-TMSI, P-TMSI signature, TMSI, RAI, LAI, ciphering key
sequence number and GPRS ciphering key sequence number and shall consider the SIM/USIM as invalid for
GPRS and non GPRS services until switching off or the SIM/USIM is removed.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
combined tracking area update procedure is rejected with the EMM cause with the same value.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM
is removed. The new state is GMM-DEREGISTERED. If in the MS the timer T3212 is not already running, the
timer shall be set to its initial value and restarted.
A GPRS MS operating in MS operation mode A or B in network operation mode I which is already IMSI
attached for CS services, is still IMSI attached for CS services in the network.
A GPRS MS operating in MS operation mode A or B in network operation mode I shall proceed with the
appropriate MM specific procedure according to the MM service state.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
combined tracking area update procedure is rejected with the EMM cause with the same value.
The MS shall set the GPRS update status to GU2 NOT UPDATED (and shall store it according to
subclause 4.1.3.2), enter the state GMM-DEREGISTERED, and shall delete any P-TMSI, P-TMSI signature,
RAI and GPRS ciphering key sequence number. If the rejected request was not for initiating a PDN connection
for emergency bearer services, the MS may subsequently, automatically initiate the GPRS attach procedure.
A GPRS MS operating in MS operation mode A or B in network operation mode I, is still IMSI attached for CS
services in the network.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
combined tracking area update procedure is rejected with the EMM cause with the same value.
# 10 (Implicitly detached);
A GPRS MS operating in MS operation mode A or B in network operation mode I, is IMSI detached for both
GPRS and CS services in the network.
The MS shall change to state GMM-DEREGISTERED.NORMAL-SERVICE. If the rejected request was not for
initiating a PDN connection for emergency bearer services, the MS shall then perform a new attach procedure.
The MS should also activate PDP context(s) to replace any previously active PDP context(s). The MS should
also perform the procedures needed in order to activate any previously active multicast service(s).
If S1 mode is supported in the MS, the MS shall handle the EMM state as specified in 3GPP TS 24.301 [120] for
the case when the combined tracking area update procedure is rejected with the EMM cause with the same value.
3GPP
Release 10 178 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: In some cases, user interaction may be required and then the MS cannot activate the PDP/MBMS
context(s) automatically.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED and the update status to U3
ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2) and enter the state GMM-
DEREGISTERED. Furthermore, it shall delete any P-TMSI, P-TMSI signature, TMSI, RAI, LAI, ciphering key
sequence number GPRS ciphering key sequence number, and reset the routing area updating attempt counter and
the location update attempt counter.
The MS shall store the PLMN identity in the "forbidden PLMN list".
The MS shall then perform a PLMN selection according to 3GPP TS 23.122 [14].
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN
selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in
3GPP TS 24.301 [120] for the case when the combined tracking area update procedure is rejected with the EMM
cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2),
shall reset the routing area updating attempt counter and shall change to state GMM-
DEREGISTERED.LIMITED-SERVICE.
The MS shall in addition set the update status to U3 ROAMING NOT ALLOWED, shall delete any TMSI, LAI
and ciphering key sequence number and shall reset the location update attempt counter. The new MM state is
MM IDLE.
The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service".
The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98].
NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in
3GPP TS 24.301 [120] for the case when the combined tracking area update procedure is rejected with the EMM
cause with the same value.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
clause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM-
REGISTERED.LIMITED-SERVICE.
The MS shall in addition set the update status to U3 ROAMING NOT ALLOWED and shall reset the location
update attempt counter. The new MM state is MM IDLE.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
The MS shall indicate the Update type IE "combined RA/LA updating with IMSI attach" when performing the
routing area updating procedure following the PLMN selection.
3GPP
Release 10 179 3GPP TS 24.008 V10.6.1 (2012-03)
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a PLMN
selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the combined
tracking area update procedure is rejected with the EMM cause with the same value.
The MS shall delete any RAI, P-TMSI, P-TMSI signature, and GPRS ciphering key sequence number stored,
shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM-
DEREGISTERED. If in the MS the timer T3212 is not already running, the timer shall be set to its initial value
and restarted.
The MS shall store the PLMN identity in the "forbidden PLMNs for GPRS service" list.
A GPRS MS operating in MS operation mode A or B in network operation mode I which is already IMSI
attached for CS services, is still IMSI attached for CS services in the network.
A GPRS MS operating in MS operation mode A or B in network operation mode I shall proceed with the
appropriate MM specific procedure according to the MM service state.
As an implementation option, a GPRS MS operating in operation mode A or B may perform a PLMN selection
according to 3GPP TS 23.122 [14].
If an MS in GAN mode performs a PLMN selection, it shall request a PLMN list in GAN (see
3GPP TS 44.318 [76b]) prior to perform a PLMN selection from this list according to 3GPP TS 23. [14].
The MS shall not perform the optional PLMN selection in the case where the PLMN providing this reject cause
is:
- On the "User Controlled PLMN Selector with Access Technology " or,
- On the "Operator Controlled PLMN Selector with Access Technology " list or,
- A PLMN identified as equivalent to any PLMN, with the same MCC, contained in the lists above.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list, KSI and tracking area updating attempt counter as specified in
3GPP TS 24.301 [120] for the case when the combined tracking area update procedure is rejected with the EMM
cause with the same value.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
clause 4.1.3.2), shall reset the routing area updating attempt counter and shall change to state GMM-
REGISTERED.LIMITED-SERVICE.
The MS shall in addition set the update status to U3 ROAMING NOT ALLOWED and shall reset the location
update attempt counter. The new MM state is MM IDLE.
The MS shall store the LAI in the list of "forbidden location areas for roaming".
The MS shall search for a suitable cell in another location area in the same PLMN according to
3GPP TS 43.022 [82] and 3GPP TS 25.304 [98].
NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode.
The MS shall indicate the Update type IE "combined RA/LA updating with IMSI attach" when performing the
routing area updating procedure.
3GPP
Release 10 180 3GPP TS 24.008 V10.6.1 (2012-03)
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the combined
tracking area update procedure is rejected with the EMM cause with the same value.
#22 (Congestion);
If the T3346 value IE is present in the ROUTING AREA UPDATE REJECT message and the value indicates
that this timer is neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be
considered as an abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.5.2.5.
The MS shall abort the routing area updating procedure, reset the routing area updating attempt counter and set
the GPRS update status to GU2 NOT UPDATED. If the rejected request was not for initiating a PDN connection
for emergency bearer services, the MS shall change to state GMM-REGISTERED.ATTEMPTING-TO-
UPDATE.
If the ROUTING AREA UPDATE REJECT message is integrity protected, the MS shall start timer with the
value provided in the T3346 value IE.
If the ROUTING AREA UPDATE REJECT message is not integrity protected, the ME shall start timer T3346
with a random value from the default range specified in table 11.3a.
The MS stays in the current serving cell and applies the normal cell reselection process. The routing area
updating procedure is started, if still necessary, when timer T3346 expires or is stopped.
Cause #25 is only applicable in UTRAN Iu mode and when received from a CSG cell. Other cases are
considered as abnormal cases and the specification of the mobile station behaviour is given in
subclause 4.7.5.2.5.
If the ROUTING AREA UPDATE REJECT message with cause #25 was received without integrity protection,
then the MS shall discard the message.
The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and store it according to
subclause 4.1.3.2) and shall reset the routing area updating attempt counter. The state is changed to GMM-
REGISTERED.LIMITED-SERVICE.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA UPDATE
REQUEST message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry
corresponding to this CSG ID and associated PLMN identity from the Allowed CSG list.
If the CSG ID and associated PLMN identity of the cell where the MS has sent the ROUTING AREA UPDATE
REQUEST message are contained in the Operator CSG list, the MS shall proceed as specified in
3GPP TS 23.122 [14] subclause 3.1A.
If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall
reset the location update attempt counter. The new MM state is MM IDLE.
- The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status and
tracking area updating attempt counter as specified in 3GPP TS 24.301 [120] for the case when the combined
tracking area update procedure is rejected with the EMM cause with the same value.
Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is described in
subclause 4.7.5.2.5.
3GPP
Release 10 181 3GPP TS 24.008 V10.6.1 (2012-03)
- If the combined routing area update was successful for GPRS services only and the ROUTING AREA UPDATE
ACCEPT message contained a cause value not treated in subclause 4.7.5.2.3.2 or the GMM Cause IE is not
included in the message, the MS shall follow the procedure specified in subclause 4.7.5.1.5 step d) with the
following modification;
- otherwise, the abnormal cases specified in subclause 4.7.5.1.5 apply with the following modification.
If the GPRS routing area updating attempt counter is incremented according to subclause 4.7.5.1.5 the next actions
depend on the Location Area Identities (stored on SIM/USIM and the one of the current serving cell) and the value of
the routing area updating attempt counter.
- if the update status is U1 UPDATED, and the stored LAI is equal to the one of the current serving cell and the
routing area updating attempt counter is smaller than 5, then the mobile station shall keep the update status to U1
UPDATED, the new MM state is MM IDLE substate NORMAL SERVICE;
- if the routing area updating attempt counter is smaller than 5 and, additionally, the update status is different from
U1 UPDATED or the stored LAI is different from the one of the current serving cell, the mobile station shall
delete any LAI, TMSI, ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs
and set the update status to U2 NOT UPDATED. The MM state remains MM LOCATION UPDATING
PENDING; or
- if the routing area updating attempt counter is greater or equal to 5, the mobile station shall delete any LAI,
TMSI, ciphering key sequence number stored in the SIM/USIM and list of equivalent PLMNs and set the update
status to U2 NOT UPDATED.
A GPRS MS operating in MS operation mode A shall then proceed with appropriate MM specific procedure; a
GPRS MS operating in MS operation mode B may then proceed with appropriate MM specific procedures.
The MM sublayer shall act as in network operation mode II or III (depending whether a PCCCH is present) as
long as the combined GMM procedures are not successful and no new RA is entered. The new MM state is MM
IDLE substate ATTEMPTING TO UPDATE or optionally MM IDLE substate PLMN SEARCH in order to
perform a PLMN selection according to 3GPP TS 23.122 [14].
The purpose of the P-TMSI reallocation procedure is to provide identity confidentiality, i.e. to protect a user against
being identified and located by an intruder (see 3GPP TS 42.009 [5] and 3GPP TS 43.020 [13]).
Usually, P-TMSI reallocation is performed at least at each change of a routing area. (Such choices are left to the
network operator).
The reallocation of a P-TMSI is performed by the unique procedure defined in this subclause. This procedure can only
be initiated by the network in state GMM-REGISTERED.
P-TMSI can also be implicitly reallocated in the attach or routing area updating procedures. The implicit reallocation of
a P-TMSI is described in the corresponding subclause s.
NOTE: Normally, the P-TMSI reallocation will take place in conjunction with another GMM procedure, e.g. at
routing area updating (see 3GPP TS 29.002 [37]).
3GPP
Release 10 182 3GPP TS 24.008 V10.6.1 (2012-03)
The P-TMSI REALLOCATION COMMAND message contains a new combination of P-TMSI, RAI and optionally a
P-TMSI signature allocated by the network.
The network may suspend the transmission of user data during the P-TMSI reallocation procedure.
If a P-TMSI signature is present in the P-TMSI REALLOCATION COMMAND message, the MS shall store the new
P-TMSI signature and shall if available delete the old P-TMSI signature. If no P-TMSI signature is present in the P-
TMSI REALLOCATION COMMAND message, the old P-TMSI signature, if available, shall be kept.
In A/Gb mode, the GMM layer shall notify the LLC layer that the P-TMSI has been changed (see
3GPP TS 44.064 [78a]).
If a lower layer failure is detected before the P-TMSI REALLOCATION COMPLETE message is received, the
old and the new P-TMSI shall be considered as occupied until the old P-TMSI can be considered as invalid by
the network (see subclause 4.7.1.5).
may first use the old P-TMSI for paging for an implementation dependent number of paging attempts in the
case of network originated transactions. Upon response from the MS, the network may re-initiate the P-TMSI
reallocation. If no response is received to the paging attempts, the network may use the new P-TMSI for
paging for an implementation dependent number of paging attempts. Upon response from the MS the
network shall consider the new P-TMSI as valid and the old P-TMSI as invalid. If no response is received to
the paging attempts, the network may use the IMSI for paging. for an implementation dependent number of
paging attempts;
NOTE: Paging with IMSI causes the MS to re-attach as described in subclause 4.7.9.1.
- shall consider the new P-TMSI as valid if it is used by the MS (see subclause 4.7.1.5); or
- may use the identification procedure followed by a new P-TMSI reallocation if the MS uses the old P-TMSI.
The P-TMSI reallocation procedure is supervised by the timer T3350. The network shall, on the first expiry of
timer T3350, reset and restart timer T3350 and shall retransmit the P-TMSI REALLOCATION COMMAND.
This retransmission is repeated four times, i.e. on the fifth expiry of timer T3350, the network shall abort the
reallocation procedure and shall follow the rules for case a as described above.
3GPP
Release 10 183 3GPP TS 24.008 V10.6.1 (2012-03)
If the network receives an ATTACH REQUEST message before the ongoing P-TMSI reallocation procedure has
been completed the network shall proceed with the GPRS attach procedure after deletion of the GMM context.
If the network receives a DETACH REQUEST message before the ongoing P-TMSI reallocation procedure has
been completed, the network shall abort the P-TMSI reallocation procedure and shall progress the GPRS detach
procedure.
If the network receives a ROUTING AREA UPDATE REQUEST message before the ongoing P-TMSI
reallocation procedure has been completed, the network shall abort the P-TMSI reallocation procedure and shall
progress the routing area updating procedure. The network may then perform a new P-TMSI reallocation.
If the network receives a SERVICE REQUEST message before the ongoing P-TMSI reallocation procedure
procedure has been completed, the network shall progress both procedures.
If there are different new P-TMSI included in subsequent P-TMSI REALLOCATION COMMAND messages, due to an
aborted or repeated P-TMSI reallocation procedure, the MS always regards the newest and its existing P-TMSI as valid
for the recovery time.
MS Network
P-TMSI REALLOCATION COMMAND
Start T3350
P-TMSI REALLOCATION COMPLETE
Stop T3350
- to permit the network to check whether the identity provided by the MS is acceptable or not;
- to provide parameters enabling the MS to calculate a new GPRS UMTS ciphering key and a new GPRS UMTS
integrity key;
- to let the network set the GSM ciphering mode (ciphering /no ciphering) and GSM ciphering algorithm; and
In Iu mode, and in the case of a UMTS authentication challenge, the authentication and ciphering procedure can be used
for authentication only.
The cases in which the authentication and ciphering procedure shall be used are defined in 3GPP TS 33.102 [5a] and
3GPP TS 42.009 [5].
The authentication and ciphering procedure is always initiated and controlled by the network. However, in the case of a
UMTS authentication challenge, there is the possibility for the MS to reject the network.
3GPP
Release 10 184 3GPP TS 24.008 V10.6.1 (2012-03)
- authentication only;
- setting of the GSM ciphering mode and the GSM ciphering algorithm only; or
- authentication and the setting of the GSM ciphering mode and the GSM ciphering algorithm.
In A/Gb mode, the network should not send any user data during the authentication and ciphering procedure.
A UMTS security context is established in the MS and the network when a UMTS authentication challenge is
performed in A/Gb mode or in Iu mode. After a successful UMTS authentication, the GPRS UMTS ciphering key, the
GPRS UMTS integrity key, the GPRS GSM ciphering key and the GPRS ciphering key sequence number, are stored
both in the network and the MS. Furthermore, in A/Gb mode both the ME and the network may derive and store a
GPRS GSM Kc128 as part of the UMTS security context as described in the subclause 4.7.7.3a.
- to permit the network to check whether the identity provided by the MS is acceptable or not;
- to provide parameters enabling the MS to calculate a new GPRS GSM ciphering key; and
- to let the network set the GSM ciphering mode (ciphering/no ciphering) and GSM ciphering algorithm.
- authentication only;
- setting of the GSM ciphering mode and the GSM ciphering algorithm only; or
- authentication and the setting of the GSM ciphering mode and the GSM ciphering algorithm.
The cases in which the authentication and ciphering procedure shall be used are defined in 3GPP TS 42.009 [5].
In A/Gb mode, the authentication and ciphering procedure is always initiated and controlled by the network. It shall be
performed in a non ciphered mode because of the following reasons:
- to be able to define a specific point in time from which on a new GPRS GSM ciphering key should be used
instead of the old one.
In A/Gb mode, the network should not send any user data during the authentication and ciphering procedure.
A GSM security context is established in the MS and the network when a GSM authentication challenge is performed in
A/Gb mode or in Iu mode. However, in Iu mode the MS shall not accept a GSM authentication challenge, if a USIM is
inserted. After a successful GSM authentication challenge, the GPRS GSM ciphering key and the GPRS ciphering key
sequence number, are stored both in the network and the MS.
After PS handover to Iu mode (see 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]) the network shall activate
integrity protection and shall either assign a ciphering algorithm to be used in the target cell or deactivate ciphering in
the target cell, using the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
3GPP
Release 10 185 3GPP TS 24.008 V10.6.1 (2012-03)
If the GSM ciphering algorithm is changed at PS handover and the routing area updating procedure triggered by the PS
handover procedure is not accepted by the network, the MS shall delete any GPRS ciphering key sequence number and
proceed as specified in subclauses 4.7.5.1.4 and 4.7.5.2.4. If the routing area updating procedure fails, because the radio
resources assigned in the new cell are released before the MS receives a ROUTING AREA UPDATE ACCEPT
message, the MS shall delete any GPRS ciphering key sequence number and proceed as specified in
subclauses 4.7.5.1.5 item b and 4.7.5.2.5, respectively.
- In a GSM authentication challenge, the GPRS ciphering key sequence number and the RAND, or
- In a UMTS authentication challenge, the GPRS ciphering key sequence number, the RAND and the AUTN.
In A/Gb mode, if ciphering is requested, in a GSM authentication challenge or in a UMTS authentication challenge,
then the AUTHENTICATION_AND_CIPHERING REQUEST message shall indicate the GPRS GSM ciphering
algorithm.
The network includes the A&C reference number information element in the AUTHENTICATION_AND_CIPHERING
REQUEST message. Its value is chosen in order to link an AUTHENTICATION_AND_CIPHERING REQUEST in a
RA with its RESPONSE. The A&C reference number value might be based on the RA Colour Code value.
Additionally, the network may request the MS to include its IMEISV in the AUTHENTICATION_AND_CIPHERING
RESPONSE message.
If a SIM is inserted in the MS, the MS shall ignore the Authentication Parameter AUTN IE if included in the
AUTHENTICATION_AND_CIPHERING REQUEST message and perform the GSM authentication challenge. It shall
not perform the authentication of the network described in subclause 4.7.7.5.1.
3GPP
Release 10 186 3GPP TS 24.008 V10.6.1 (2012-03)
In Iu mode, an MS capable of UMTS only shall ignore the Ciphering Algorithm IE in the
AUTHENTICATION_AND_CIPHERING REQUEST message. An MS capable of both Iu mode and A/Gb mode shall
store the received value in the Ciphering Algorithm IE in the AUTHENTICATION_AND_CIPHERING REQUEST
message in order to use it at an inter system change from Iu mode to A/Gb mode.
If the AUTHENTICATION_AND_CIPHERING REQUEST message does not include neither the GSM authentication
parameters (RAND and GPRS CKSN) nor the UMTS authentication parameters (RAND, AUTN and GPRS CKSN),
then upon receipt of the message, the MS replies by sending an AUTHENTICATION_AND_CIPHERING RESPONSE
message to the network.
In A/Gb mode, the GMM layer shall notify the LLC layer if ciphering shall be used or not and if yes which GSM
ciphering algorithm and GPRS GSM ciphering key that shall be used (see 3GPP TS 44.064 [78a]).
The RAND and RES values stored in the mobile station shall be deleted and timer T3316, if running, shall be stopped:
In A/Gb mode, in the case of an established GSM security context, the GMM layer shall notify the LLC sublayer if
ciphering shall be used or not.Furthermore, if ciphering shall be used, then the GMM layer shall also notify the LLC
sublayer which GEA algorithm and GPRS GSM ciphering key that shall be used (see 3GPP TS 44.064 [78a]).
In A/Gb mode, in the case of an established UMTS security context, the GMM layer shall notify the LLC sublayer if
ciphering shall be used or not. Furthermore, if ciphering shall be used, then the GMM layer shall also notify the LLC
sublayer which GEA algorithm and which ciphering key (i.e. GPRS GSM ciphering key or GPRS GSM Kc128) that shall
be used (see 3GPP TS 44.064 [78a]). If the network has selected a GEA ciphering algorithm that requires a 128-bit
ciphering key, then the ME shall derive a GPRS GSM Kc128 as described in the subclause 4.7.7.3a.
3GPP
Release 10 187 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of the AUTHENTICATION AND CIPHERING FAILURE message, the network stops the timer T3360.
In Synch failure case, the core network may renegotiate with the HLR/AuC and provide the MS with new
authentication parameters.
The ME with a USIM in use shall compute a new GPRS GSM Kc128 using the GPRS UMTS ciphering key and the
GPRS UMTS integrity key from an established UMTS security context as specified in 3GPP TS 33.102 [5a]. The new
GPRS GSM Kc128 shall be stored only in the ME. The ME shall overwrite the existing GPRS GSM Kc 128 with the new
GPRS GSM Kc128. The ME shall delete the GPRS GSM Kc128 at switch off, when the USIM is disabled as well as under
the conditions identified in the subclause 4.1.3.2 and 4.7.7.4. The ME with a USIM in use shall apply the GPRS GSM
Kc128 when in A/Gb mode a GEA ciphering algorithm that requires a 128-bit ciphering key is taken into use.
The network shall compute the GPRS GSM Kc128 using the GPRS UMTS integrity key and the GPRS UMTS ciphering
key from an established UMTS security context as specified in 3GPP TS 33.102 [5a] only when in A/Gb mode a GEA
ciphering algorithm that requires a 128-bit ciphering key is to be used.
In a GSM authentication challenge, from a challenge parameter RAND both the authentication response parameter
SRES and the GPRS GSM ciphering key can be computed given the secret key associated to the IMSI.
In a UMTS authentication challenge, from a challenge parameter RAND, the authentication response parameter RES
and the GPRS UMTS ciphering key and the GPRS UMTS integrity key can be computed given the secret key
associated to the IMSI. Furthermore, in the USIM a GPRS GSM ciphering key can be computed from the GPRS UMTS
integrity key and the GPRS UMTS ciphering key by means of an unkeyed conversion function. Furthermore, in A/Gb
mode if a GEA ciphering algorithm that requires a 128-bit ciphering key is taken into use, then a GPRS GSM Kc 128
shall also be calculated as described in the subclause 4.7.7.3a.
In order to allow start of ciphering on a logical link without authentication, GPRS ciphering key sequence numbers are
introduced.
The GPRS ciphering key sequence number is managed by the network such that the AUTHENTICATION
AND CIPHERING REQUEST message contains the GPRS ciphering key sequence number allocated to the GPRS
GSM ciphering key (in case of a GSM authentication challenge) or the GPRS UMTS ciphering key and the GPRS
UMTS integrity key (in case of a UMTS authentication challenge) which may be computed from the RAND parameter
carried in that message.
If an authentication and ciphering procedure has been completed successfully and a GPRS ciphering key sequence
number is stored in the network, the network shall include a different GPRS ciphering key sequence number in the
AUTHENTICATION AND CIPHERING REQUEST message when it intiates a new authentication and ciphering
procedure.
The MS stores the GPRS ciphering key sequence number with the GPRS GSM ciphering key (in case of a GSM
authentication challenge) and the GPRS UMTS ciphering key and the GPRS UMTS integrity key (in case of a UMTS
authentication challenge), and includes the corresponding GPRS ciphering key sequence number in the ROUTING
AREA UPDATE REQUEST, SERVICE REQUEST and ATTACH REQUEST messages.
If the GPRS ciphering key sequence number is deleted, the associated GPRS GSM ciphering key, GPRS UMTS
ciphering key, GPRS UMTS integrity key and GPRS GSM Kc128 shall be deleted if any (i.e. the established GSM
security context or the UMTS security context is no longer valid).
In Iu mode, the network may choose to start ciphering and integrity checking with the stored GPRS UMTS ciphering
key and the stored GPRS UMTS integrity key (under the restrictions given in 3GPP TS 42.009 [5] and
3GPP TS 33.102 [5a]) if the stored GPRS ciphering key sequence number and the one given from the MS are equal.
In A/Gb mode, the network may choose to start ciphering with the stored GPRS GSM ciphering key or GPRS GSM
Kc128 (under the restrictions given in 3GPP TS 42.009 [5]) if the stored GPRS ciphering key sequence number and the
3GPP
Release 10 188 3GPP TS 24.008 V10.6.1 (2012-03)
one given from the MS are equal and the previously negotiated ciphering algorithm is known and supported in the
network. When ciphering is requested at GPRS attach, the authentication and ciphering procedure shall be performed
since the MS does not store the ciphering algorithm at detach.
NOTE 1: The decision of starting ciphering with the GPRS GSM ciphering key or the GPRS GSM Kc128 depends
on whether the network indicates in the AUTHENTICATION AND CIPHERING REQUEST message a
GEA ciphering algorithm which requires a 64 or 128-bit ciphering key as specified in
3GPP TS 33.102 [5a].
Upon GPRS attach, if ciphering is to be used, an AUTHENTICATION AND CIPHERING REQUEST message shall be
sent to the MS to start ciphering.
If the GPRS ciphering key sequence number stored in the network does not match the GPRS ciphering key sequence
number received from the MS in the ATTACH REQUEST message, then the network should authenticate the MS.
In A/Gb mode, the MS starts ciphering after sending the AUTHENTICATION AND CIPHERING RESPONSE
message. The network starts ciphering when a valid AUTHENTICATION AND CIPHERING RESPONSE is received
from the MS.
In Iu mode, the MS starts ciphering and integrity checking according to the conditions specified in specification
3GPP TS 25.331 [23c].
In A/Gb mode, as an option, the network may decide to continue ciphering without sending an AUTHENTICATION
AND CIPHERING REQUEST message after receiving a ROUTING AREA UPDATE REQUEST message with a valid
GPRS ciphering key sequence number. Both the MS and the network shall use the latest ciphering parameters. The
network starts ciphering when sending the ciphered ROUTING AREA UPDATE ACCEPT message to the MS. The MS
starts ciphering after receiving a valid ciphered ROUTING AREA UPDATE ACCEPT message from the network.
NOTE 2: In some specifications the term KSI (Key Set Identifier) is used instead of the term GPRS ciphering key
sequence number.
- If the P-TMSI has been used, the network may decide to initiate the identification procedure. If the IMSI given
by the MS differs from the one the network had associated with the P-TMSI, the authentication should be
restarted with the correct parameters. If the IMSI provided by the MS is the expected one (i.e. authentication has
really failed), the network should proceed as described below.
- If the IMSI has been used, or the network decides not to try the identification procedure, an
AUTHENTICATION AND CIPHERING REJECT message should be transferred to the MS.
Upon receipt of an AUTHENTICATION AND CIPHERING REJECT message, the MS shall set the GPRS update
status to GU3 ROAMING NOT ALLOWED and shall delete the P-TMSI, P-TMSI signature, RAI and GPRS ciphering
key sequence number stored. If available, also the TMSI, LAI and ciphering key sequence number shall be deleted and
the update status shall be set to U3 ROAMING NOT ALLOWED. The SIM/USIM shall be considered as invalid until
switching off or the SIM/USIM is removed.
If S1 mode is supported by the MS, the MS shall in addition handle the EMM parameters EMM state, EPS update
status, last visited registered TAI, TAI list, GUTI and KSIASME as specified in 3GPP TS 24.301 [120] for the case when
an EPS authentication is not accepted by the network.
If the AUTHENTICATION AND CIPHERING REJECT message is received, the MS shall abort any GMM procedure,
shall stop the timers T3310, T3317 and T3330 (if running) and shall enter state GMM-DEREGISTERED.
In UTRAN Iu mode, depending on local regulations or operator preference for emergency bearer services, if the MS has
a PDN connection for emergency bearer services established or is establishing a PDN connection for emergency bearer
services, the SGSN need not follow the procedures specified for the authentication failure in the present subclause, the
SGSN can continue with the ongoing GMM specific procedure or Session Management procedure. Upon completion of
the GMM procedure or Session management procedure, the SGSN shall deactivate all non-emergency PDP contexts, if
any, by initiating a PDP context deactivation procedure. The network shall consider the MS to be attached for
emergency bearer services only.
3GPP
Release 10 189 3GPP TS 24.008 V10.6.1 (2012-03)
Following a UMTS authentication challenge, the MS may reject the core network, on the grounds of an incorrect AUTN
parameter (see 3GPP TS 33.102 [5a]). This parameter contains two possible causes for authentication failure:
If the MS considers the MAC code (supplied by the core network in the AUTN parameter) to be invalid, it shall send a
AUTHENTICATION AND CIPHERING FAILURE message to the network, with the GMM cause 'MAC failure'. The
MS shall then follow the procedure described in subclause 4.7.7.6 (f).
b) SQN failure
If the MS considers the SQN (supplied by the core network in the AUTN parameter) to be out of range, it shall
send a AUTHENTICATION AND CIPHERING FAILURE message to the network, with the GMM cause
'Synch failure' and the re-synchronization token AUTS provided by the USIM (see 3GPP TS 33.102 [5a]).
The MS shall then follow the procedure described in subclause 4.7.7.6 (g).
In Iu mode, an MSwith a USIM inserted shall reject the authentication challenge if no Authentication Parameter AUTN
IE was present in the AUTHENTICATION REQUEST message (i.e. a GSM authentication challenge has been received
when the MS expects a UMTS authentication challenge). In such a case, the MS shall send the AUTHENTICATION
AND CIPHERING FAILURE message to the network, with the GMM cause ‘GSM authentication unacceptable’. The
MS shall then follow the procedure described in subclause 4.7.7.6 (f).
If the MS has a PDN connection for emergency bearer services established or is establishing such a PDN connection,
additional MS requirements are specified in subclause 4.7.7.6, under "for items f and g".
Upon detection of a lower layer failure before the AUTHENTICATION AND CIPHERING RESPONSE is
received, the network shall abort the procedure.
The network shall, on the first expiry of the timer T3360, retransmit the AUTHENTICATION AND
CIPHERING REQUEST and shall reset and start timer T3360. This retransmission is repeated four times, i.e. on
the fifth expiry of timer T3360, the procedure shall be aborted.
If the network receives an ATTACH REQUEST message before the ongoing authentication procedure has been
completed and no GPRS attach procedure is pending on the network (i.e. no ATTACH ACCEPT/REJECT
message has to be sent as an answer to an ATTACH REQUEST message), the network shall abort the
authentication and ciphering procedure and proceed with the new GPRS attach procedure.
d) Collision of an authentication and ciphering procedure with a GPRS attach procedure when the authentication
and ciphering procedure has been caused by a previous GPRS attach procedure
If the network receives an ATTACH REQUEST message before the ongoing authentication procedure has been
completed and a GPRS attach procedure is pending (i.e. an ATTACH ACCEPT/REJECT message has still to be
sent as an answer to an earlier ATTACH REQUEST message), then:
- If one or more of the information elements in the ATTACH REQUEST message differs from the ones
received within the previous ATTACH REQUEST message, the network shall not treat the authentication any
further and proceed with the GPRS attach procedure; or
3GPP
Release 10 190 3GPP TS 24.008 V10.6.1 (2012-03)
- If the information elements do not differ, then the network shall not treat any further this new ATTACH
REQUEST.
If the network receives a DETACH REQUEST message before the ongoing authentication and ciphering
procedure has been completed, the network shall abort the authentication and ciphering procedure and shall
progress the GPRS detach procedure.
If the network receives a DETACH REQUEST message before the ongoing authentication and ciphering
procedure has been completed, the network shall complete the authentication and ciphering procedure and
shall respond to the GPRS detach procedure as described in subclause 4.7.4.
e) Collision of an authentication and ciphering procedure with a routing area updating procedure
If the network receives a ROUTING AREA UPDATE REQUEST message before the ongoing authentication
procedure has been completed, the network shall progress both procedures.
MS Network
AUTHENTICATION AND CIPHERING REQUEST
Start T3360
AUTHENTICATION AND CIPHERING RESPONSE
Stop T3360
(f) Authentication failure (GMM cause #18 "MAC failure" or #21 "GSM authentication unacceptable")
The MS shall send an AUTHENTICATION & CIPHERING FAILURE message, with GMM cause ‘MAC
failure’ or ‘GSM authentication unacceptable’ according to subclause 4.7.7.5.1, to the network and start timer
T3318. Furthermore, the MS shall stop any of the retransmission timers that are running (e.g. T3310, T3321,
T3330 or T3317). Upon the first receipt of an AUTHENTICATION & CIPHERING FAILURE message from
the MS with GMM cause ‘MAC failure’ or ‘GSM authentication unacceptable’ the network may initiate the
identification procedure described in subclause 4.7.8. This is to allow the network to obtain the IMSI from the
MS. The network may then check that the P-TMSI originally used in the authentication challenge corresponded
to the correct IMSI. Upon receipt of the IDENTITY REQUEST message from the network, the MS shall send
the IDENTITY RESPONSE message.
NOTE: Upon receipt of an AUTHENTICATION & CIPHERING FAILURE message from the MS with reject
cause "MAC failure" or "GSM authentication unacceptable", the network may also terminate the
authentication procedure (see subclause 4.7.7.5).
If the P-TMSI/IMSI mapping in the network was incorrect, the network should respond by sending a new
AUTHENTICATION & CIPHERING REQUEST message to the MS. Upon receiving the new
AUTHENTICATION & CIPHERING REQUEST message from the network, the MS shall stop timer T3318, if
running, and then process the challenge information as normal.
If the network is validated successfully (an AUTHENTICATION & CIPHERING REQUEST message that
contains a valid SQN and MAC is received), the MS shall send the AUTHENTICATION & CIPHERING
RESPONSE message to the network and shall start any retransmission timers (e.g. T3310, T3321, T3330 or
T3317), if they were running and stopped when the MS received the first failed AUTHENTICATION AND
CIPHERING REQUEST message.
If the MS receives the second AUTHENTICATION AND CIPHERING REQUEST while T3318 is running and
3GPP
Release 10 191 3GPP TS 24.008 V10.6.1 (2012-03)
- the message was received in UMTS and contains a GSM authentication challenge,
the MS shall follow the procedure specified in this subclause (f), starting again from the beginning. If the SQN is
invalid, the MS shall proceed as specified in (g).
It can be assumed that the source of the authentication challenge is not genuine (authentication not accepted by
the MS) if any of the following occurs:
- after sending the AUTHENTICATION & CIPHERING FAILURE message with GMM cause ‘MAC failure’
or ‘GSM authentication unacceptable’ the timer T3318 expires;
- the MS detects any combination of the authentication failures: "MAC failure", "invalid SQN", and "GSM
authentication unacceptable", during three consecutive authentication challenges. The authentication
challenges shall be considered as consecutive only, if the authentication challenges causing the second and
third authentication failure are received by the MS, while the timer T3318 or T3320 started after the previous
authentication failure is running.
When it has been deemed by the MS that the source of the authentication challenge is not genuine
(authentication not accepted by the MS), the MS shall behave as described in subclause 4.7.7.6.1.
MS Network
AUTHENTICATION & CIPHERING REQUEST
Start T3360
AUTH & CIPH FAILURE (cause=’MAC failure’ or
Start T3318 ‘GSM authentication unacceptable’) Stop T3360
IDENTITY REQUEST
Start T3370
Figure 4.7.7a/1 3GPP TS 24.008: Authentication failure cause "MAC failure" or "GSM authentication
unacceptable"
The MS shall send an AUTHENTICATION & CIPHERING FAILURE message, with the GMM cause "Synch
failure", to the network and start the timer T3320. Furthermore, the MS shall stop any of the retransmission
timers that are running (e.g. T3310, T3321, T3330 or T3317). Upon the first receipt of an AUTHENTICATION
& CIPHERING message from the MS with the GMM cause "synch failure", the network shall use the returned
AUTS parameter from the authentication & ciphering failure parameter IE in the AUTHENTICATION &
CIPHERING FAILURE message, to re-synchronise. The re-synchronisation procedure requires the SGSN to
delete all unused authentication vectors for that IMSI and obtain new vectors from the HLR. When re-
synchronisation is complete, the network shall initiate the authentication & ciphering procedure. Upon receipt of
the AUTHENTICATION & CIPHERING REQUEST message, the MS shall stop timer T3320, if running.
NOTE: Upon receipt of two consecutive AUTHENTICATION & CIPHERING FAILURE messages from the MS
with reject cause "synch failure", the network may terminate the authentication procedure by sending an
AUTHENTICATION & CIPHERING REJECT message.
3GPP
Release 10 192 3GPP TS 24.008 V10.6.1 (2012-03)
If the network is validated successfully (a new AUTHENTICATION & CIPHERING REQUEST message is
received which contains a valid SQN and MAC) while T3320 is running, the MS shall send the
AUTHENTICATION & CIPHERING RESPONSE message to the network and shall start any retransmission
timers (i.e. T3310, T3321, T3330 or T3317), if they were running and stopped when the MS received the first
failed AUTHENTICATION AND CIPHERING REQUEST message.
If the MS receives the second AUTHENTICATION & CIPHERING REQUEST while T3320 is running and
- the message was received in Iu mode and contains a GSM authentication challenge,
the MS shall proceed as specified in (f). If the SQN is invalid, the MS shall follow the procedure specified in this
subclause (g), starting again from the beginning.
The MS shall deem that the network has failed the authentication check and behave as described in
subclause 4.7.7.6.1, if any of the following occurs:
- the MS detects any combination of the authentication failures: "MAC failure", "invalid SQN", and "GSM
authentication unacceptable", during three consecutive authentication challenges. The authentication
challenges shall be considered as consecutive only, if the authentication challenges causing the second and
third authentication failure are received by the MS, while the timer T3318 or T3320 started after the previous
authentication failure is running.
MS Network
AUTHENTICATION & CIPHERING REQUEST Start T3360
Depending on local requirements or operator preference for emergency bearer services, if the MS has a PDN
connection for emergency bearer services established or is establishing such a PDN connection, the SGSN need
not follow the procedures specified for the authentication failure specified in the present subclause and shall
continue using the current security context, if any. The SGSN shall deactivate all non-emergency PDP contexts,
if any, by initiating a PDP context deactivation procedure. If there is an ongoing session management procedure,
the SGSN shall deactivate all non-emergency PDP contexts upon completion of the session management
procedure. The network shall consider the MS to be attached for emergency bearer services only.
If an MS has a PDN connection for emergency bearer services established or is establishing such a PDN
connection when timer T3318 or T3320 expires, the MS shall not deem that the network has failed the
authentication check and not behave as described in subclause 4.7.7.6.1. Instead the MS shall continue using the
current security context, if any. The MS shall deactivate all non-emergency PDP contexts, if any, by initiating a
PDP context deactivation procedure. If there is an ongoing session management procedure, the MS shall
deactivate all non-emergency PDP contexts upon completion of the session management procedure. The MS
shall consider itself to be attached for emergency bearer services only.
3GPP
Release 10 193 3GPP TS 24.008 V10.6.1 (2012-03)
4.7.7.6.1 MS behaviour towards a network that has failed the authentication procedure
If the MS deems that the network has failed the authentication check, then it shall request RR or RRC to release the RR
connection and the PS signalling connection, if any, and bar the active cell or cells (see 3GPP TS 25.331 [23c] and
3GPP TS 44.018 [84]). The MS shall start any retransmission timers (i.e. T3310, T3321, T3330 or T3317), if they were
running and stopped when the MS received the first AUTHENTICATION AND CIPHERING REQUEST message
containing an invalid MAC or invalid SQN, or no AUTN when a UMTS authentication challenge was expected.
In A/Gb mode, in the case of an established UMTS security context, and if the network indicates in the
AUTHENTICATION AND CIPHERING REQUEST message to the MS that a GEA ciphering algorithm that requires a
64-bit ciphering key shall be taken into use, then the GPRS GSM ciphering key shall be taken into use by the MS before
the AUTHENTICATION AND CIPHERING RESPONSE message is transmitted. The network shall derive a GPRS
GSM ciphering key from the GPRS UMTS ciphering key and the GPRS UMTS integrity key, by using the conversion
function named "c3" defined in 3GPP TS 33.102 [5a].
In A/Gb mode, in the case of an established UMTS security context, and if the network indicates in the
AUTHENTICATION AND CIPHERING REQUEST message to the MS that a GEA ciphering algorithm that requires a
128-bit ciphering key shall be taken into use, then the MS shall take the following actions:
- if authentication is not requested and a GEA ciphering algorithm that requires 64-bit ciphering key is in use, the
MS shall take into use the GPRS GSM Kc128 derived by the ME from the GPRS UMTS ciphering key and GPRS
UMTS integrity key of the established UMTS security context in use (see 3GPP TS 33.102 [5a]) before the
AUTHENTICATION AND CIPHERING RESPONSE message is transmitted;.
- if authentication is not requested and a GEA ciphering algorithm that requires 128-bit ciphering key is in use, the
GPRS GSM Kc128 of the established UMTS security context in use still applies;
otherwise, the MS shall take into use the GPRS GSM Kc128 derived by the ME from the GPRS UMTS ciphering
key and the GPRS UMTS integrity key provided by the USIM during the latest successful authentication
procedure (see subclause 4.7.7.3a) before the AUTHENTICATION AND CIPHERING RESPONSE message is
transmitted.
In A/Gb mode, in the case of an established UMTS security context, and if the network indicates in the
AUTHENTICATION AND CIPHERING REQUEST message to the MS that a GEA ciphering algorithm that requires a
128-bit ciphering key shall be taken into use, then the network shall derive a GPRS GSM Kc 128 (see subclause 4.7.7.3a).
In A/Gb mode, if during an ongoing, already ciphering protected RR connection, the network initiates a new
Authentication and ciphering procedure, the new GPRS GSM ciphering key or GPRS GSM Kc128 shall be taken into use
by the MS before the AUTHENTICATION AND CIPHERING RESPONSE message is transmitted. In case of inter-
system change to Iu mode after receipt of the AUTHENTICATION AND CIPHERING REQUEST message, the MS
and the network shall take the new keys into use immediately after the inter-system change.
In Iu mode, in the case of an established GSM security context, the ME shall derive a GPRS UMTS ciphering key and a
GPRS UMTS integrity key from the GPRS GSM ciphering key by using the conversion functions named "c4" and "c5"
defined in 3GPP TS 33.102 [5a]. The derived GPRS UMTS ciphering key and GPRS UMTS integrity key shall be
taken into use by the MS when a valid SECURITY MODE COMMAND message indicating PS domain is received
during an RR connection (the definition of a valid SECURITY MODE COMMAND message is given in
3GPP TS 25.331 [23c]). The network shall derive a GPRS UMTS ciphering key and a GPRS UMTS integrity key from
the GPRS GSM ciphering key by using the conversion functions named "c4" and "c5" defined in 3GPP TS 33.102 [5a].
In Iu mode, in the case of an established UMTS security context, the GPRS UMTS ciphering key and the GPRS UMTS
integrity key shall be taken into use by the MS when a valid SECURITY MODE COMMAND message indicating PS
domain is received during a PS signalling connection (the definition of a valid SECURITY MODE COMMAND
message is given in 3GPP TS 25.331 [23c]).
In Iu mode, if the MS received a valid SECURITY MODE COMMAND message indicating PS domain in Iu mode or a
valid AUTHENTICATION AND CIPHERING REQUEST message in A/Gb mode before the network initiates a new
authentication and ciphering procedure and establishes a new GSM/UMTS security context, the new GPRS UMTS
3GPP
Release 10 194 3GPP TS 24.008 V10.6.1 (2012-03)
ciphering key and GPRS UMTS integrity key are taken into use by the MS, when a new valid SECURITY MODE
COMMAND message indicating PS domain is received during the PS signalling connection. In case of inter-system
change to A/Gb mode, the MS and the network shall take the new keys into use immediately after the inter-system
change.
The ME shall handle the GPRS GSM ciphering key and a potential GPRS GSM Kc128 according to table 4.7.7.8.1.
In the case of an established GSM security context, before any initial GMM message is sent in the new cell in A/Gb
mode, the GMM layer in the MS shall notify the LLC layer if ciphering shall be used or not. If ciphering shall be used,
then the GPRS GSM ciphering key and the applicable GEA ciphering algorithm according to the stored Ciphering
Algorithm IE in the MS shall also be indicated to the LLC layer (see 3GPP TS 44.064 [78a]).
In the case of an established UMTS security context, before any initial GMM message is sent in the new cell in A/Gb
mode, the GMM layer in the MS shall notify the LLC layer if ciphering shall be used or not. If ciphering shall be used,
then the GPRS GSM ciphering key or GPRS GSM Kc128 and the applicable GEA ciphering algorithm according to the
stored Ciphering Algorithm IE in the MS shall also be indicated to the LLC layer (see 3GPP TS 44.064 [78a]). If the
network has selected a GEA-algorithm that requires a 128-bit ciphering key, then the ME shall apply a GPRS GSM
Kc128 derived from the GPRS UMTS ciphering key and the GPRS UMTS integrity key of the established UTMS
security context as specified in 3GPP TS 33.102 [5a].
GSM security context An ME shall apply the GPRS GSM ciphering key that was
received from the GSM security context created in the SIM/USIM
during the latest successful authentication procedure.
UMTS security context If a GEA algorithm is taken into use that requires a 64-bit long
ciphering key, then an ME shall apply the GPRS GSM ciphering
key that was derived by the USIM from the GPRS UMTS
ciphering key and the GPRS UMTS integrity key during the latest
successful authentication procedure.
If a GEA algorithm is taken into use that requires a 128-bit
ciphering key, then an ME shall apply the GPRS GSM Kc128
derived by the ME from the GPRS UMTS ciphering key and the
GPRS UMTS integrity key (see 3GPP TS 33.102 [5a]) provided
by the USIM during the lastest successful authentication
procedure (see subclause 4.7.7.3a).
NOTE: A USIM with UMTS security context, passes the GPRS UMTS ciphering key, the GPRS UMTS integrity
key and the derived GPRS GSM ciphering key to the ME independent on the current radio access being
UTRAN or GERAN.
The ME shall handle the GPRS UMTS ciphering key and the GPRS UMTS integrity key according to table 4.7.7.9.1.
3GPP
Release 10 195 3GPP TS 24.008 V10.6.1 (2012-03)
GSM security context An ME shall derive the GPRS UMTS ciphering key and the
GPRS UMTS integrity key from the GPRS GSM ciphering key
that was provided by the SIM/USIM during the latest successful
authentication procedure. The conversion functions named "c4"
and "c5" in 3GPP TS 33.102 [5a] are used for this purpose.
UMTS security context An ME shall apply the GPRS UMTS ciphering key and the GPRS
UMTS integrity key that were received from the UMTS security
context created in the USIM during the latest successful
authentication procedure.
NOTE: A USIM with UMTS security context, passes the GPRS UMTS ciphering key, the GPRS UMTS integrity
key and the derived GPRS GSM ciphering key to the ME independent on the current radio access being
UTRAN or GERAN.
The ME shall handle the GPRS UMTS ciphering key, the GPRS UMTS integrity key, the GPRS GSM ciphering key
and a potential GPRS GSM Kc128 according to table 4.7.7.10.1, table 4.7.7.10.2 and table 4.7.7.10.3.
Table 4.7.7.10.1/3GPP TS 24.008: Inter-system change from S1 mode to Iu mode or A/Gb mode in
connected mode.
Security context established in MS and At inter-system change to Iu mode or A/Gb mode in connected
network mode
EPS security context An ME shall derive the UMTS security keys GPRS UMTS
ciphering key (CK') and GPRS UMTS integrity key (IK') from
KASME and the NAS downlink COUNT value as specified in
3GPP TS 33.401 [119]. The ME shall use the derived UMTS
security keys to derive the GPRS GSM ciphering key using the
"c3" conversion function as specified in 3GPP TS 33.102 [119].
At inter-system change from S1 mode to Iu mode, the ME shall
apply the new derived GPRS UMTS integrity key and GPRS
UMTS ciphering key.
At inter-system change from S1 mode to A/Gb mode, the ME
shall apply the new derived GPRS GSM ciphering key.
Furthermore, the ME shall replace an already established UMTS
security context for the PS domain, if any, in the USIM. The MS
shall in addition handle the STARTPS value as specified in
3GPP TS 25.331 [23c].
At inter-system change from S1 mode to A/Gb mode, if a GEA
algorithm is taken into use that requires a 64-bit long ciphering
key, then an ME shall apply the derived GPRS GSM ciphering
key.
At inter-system change from S1 mode to A/Gb mode, if a GEA
algorithm is taken into use that requires a 128-bit long ciphering
key, then an ME shall apply the derived GPRS GSM Kc128 that
was derived by the ME from the derived UMTS security keys (see
subclause 4.7.7.3a).
3GPP
Release 10 196 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: For the case in table 4.7.7.10.1, because of deriving a new UMTS security context for the PS domain, a
new GPRS GSM ciphering key needs to be derived from the new derived UMTS security keys (i.e. CK'
and IK'). Note that the new GPRS GSM ciphering key is also part of the new UMTS security context for
the PS domain, and therefore any old GPRS GSM ciphering key stored in the USIM and in the ME
belongs to an old UMTS security context for the PS domain and can no longer be taken into use.
Table 4.7.7.10.2/3GPP TS 24.008: Inter-system change from S1 mode to Iu mode or A/Gb mode in idle
mode when the TIN indicates "GUTI".
Security context established in MS and At inter-system change to Iu mode or A/Gb mode in idle mode
network when the TIN indicates "GUTI"
EPS security context An ME shall derive the UMTS security keys GPRS UMTS
ciphering key (CK') and GPRS UMTS integrity key (IK') from
KASME and the NAS uplink COUNT value as specified in
3GPP TS 33.401 [119]. The ME shall use the derived UMTS
security keys to derive the GPRS GSM ciphering key using the
"c3" conversion function as specified in 3GPP TS 33.102 [5a].
At inter-system change from S1 mode to Iu mode, the ME shall
apply the new derived GPRS UMTS integrity key and GPRS
UMTS ciphering key.
At inter-system change from S1 mode to A/Gb mode, the ME
shall apply the new derived GPRS GSM ciphering key.
Furthermore, the ME shall replace an already established UMTS
security context for the PS domain, if any, in the USIM. The MS
shall in addition handle the STARTPS value as specified in
3GPP TS 25.331 [23c].
At inter-system change from S1 mode to A/Gb mode, if a GEA
algorithm is taken into use that requires a 64-bit long ciphering
key, then an ME shall apply the derived GPRS GSM ciphering
key.
At inter-system change from S1 mode to A/Gb mode, if a GEA
algorithm is taken into use that requires a 128-bit long ciphering
key, then an ME shall apply the derived GPRS GSM Kc128 that
was derived by the ME from the derived UMTS security keys (see
subclause 4.7.7.3a).
NOTE 2: For the case in table 4.7.7.10.2, because of deriving a new UMTS security context for the PS domain, a
new GPRS GSM ciphering key needs to be derived from the new derived UMTS security keys (i.e. CK'
and IK'). The new GPRS GSM ciphering key is also part of the new UMTS security context for the PS
domain, and therefore any old GPRS GSM ciphering key stored in the USIM and in the ME belongs to an
old UMTS security context for the PS domain and can no longer be taken into use.
Table 4.7.7.10.3/3GPP TS 24.008: Inter-system change from S1 mode to Iu mode or A/Gb mode in idle
mode when the TIN indicates "RAT-related TMSI"
Security context established in MS and At inter-system change to Iu mode or A/Gb mode in idle mode
network when the TIN indicates "RAT-related TMSI"
UMTS security context At inter-system change from S1 mode to Iu mode, the ME shall
apply the GPRS UMTS ciphering key and the GPRS UMTS
integrity key that were received from the UMTS security context
for the PS domain created in the USIM during the latest
successful authentication procedure.
At inter-system change from S1 mode to A/Gb mode, if a GEA
algorithm is taken into use that requires a 64-bit long ciphering
key, then an ME shall apply the GPRS GSM ciphering key that
was received from the GSM security context created in the
SIM/USIM during the latest successful authentication procedure.
At inter-system change from S1 mode to A/Gb mode, if a GEA
algorithm is taken into use that requires a 128-bit long ciphering
key, then an ME shall apply the GPRS GSM Kc128 derived by the
ME from the GPRS UMTS ciphering key and the GPRS UMTS
integrity key (see 3GPP TS 33.102 [5a]) provided by the USIM
during the lastest successful authentication procedure (see
subclause 4.7.7.3a).
3GPP
Release 10 197 3GPP TS 24.008 V10.6.1 (2012-03)
The network shall replace an already established UMTS security context for the PS domain, if any, when a handover
from S1mode to Iu mode or from S1mode to A/Gb mode has been completed successfully.
If the handover from S1mode to Iu mode or S1mode to A/Gb mode has not been completed successfully, the ME and
the network shall delete the new derived UMTS security context for the PS domain. Additionally, the network shall
delete the already established UMTS security context for the PS domain, if the CKSN of the already established UMTS
security context is equal to the CKSN of the new derived security context for the PS domain.
Upon receipt of the IDENTITY REQUEST message the MS sends back an IDENTITY RESPONSE message. The
IDENTITY RESPONSE message shall contain the identification parameters as requested by the network.
If the MS cannot encode the requested identity in the IDENTITY RESPONSE message, e.g. because no valid
SIM is available, then it shall encode the identity type as "No identity".
Upon detection of a lower layer failure before the IDENTITY RESPONSE is received, the network shall abort
any ongoing GMM procedure.
The identification procedure is supervised by the network by the timer T3370. The network shall, on the first
expiry of the timer T3370, retransmit the IDENTITY REQUEST message and reset and restart the timer T3370.
This retransmission is repeated four times, i.e. on the fifth expiry of timer T3370, the network shall abort the
identification procedure and any ongoing GMM procedure.
If the network receives an ATTACH REQUEST message before the ongoing identification procedure has been
completed and no GPRS attach procedure is pending on the network (i.e. no ATTACH ACCEPT/REJECT
message has still to be sent as an answer to an ATTACH REQUEST message), the network shall proceed with
the GPRS attach procedure.
3GPP
Release 10 198 3GPP TS 24.008 V10.6.1 (2012-03)
d) Collision of an identification procedure with a GPRS attach procedure when the identification procedure has
been caused by a GPRS attach procedure
If the network receives an ATTACH REQUEST message before the ongoing identification procedure has been
completed and a GPRS attach procedure is pending (i.e. an ATTACH ACCEPT/REJECT message has to be sent
as an answer to an earlier ATTACH REQUEST message), then:
- If one or more of the information elements in the ATTACH REQUEST message differs from the ones
received within the previous ATTACH REQUEST message, the network shall proceed with the GPRS attach
procedure; or
- If the information elements do not differ, then the network shall not treat any further this new ATTACH
REQUEST.
If the network receives a DETACH REQUEST message before the ongoing identification procedure has been
completed, the network shall abort the identification procedure and shall progress the GPRS detach
procedure.
If the network receives a DETACH REQUEST message before the ongoing identification procedure has been
completed, the network shall complete the identification procedure and shall respond to the GPRS detach
procedure as described in subclause 4.7.4.
If the network receives a ROUTING AREA UPDATE REQUEST message before the ongoing identification
procedure has been completed, the network shall progress both procedures.
If the network receives a SERVICE REQUEST message before the ongoing identification procedure has been
completed, the network shall progress both procedures.
MS Network
IDENTITY REQUEST
Start T3370
IDENTITY RESPONSE
Stop T3370
In Iu mode, paging is used by the network to request the establishment of PS signalling connection or to prompt the
mobile to re-attach if necessary as a result of network failure. If the MS is not GPRS attached when it receives a paging
for GPRS services, the MS shall ignore the paging.
3GPP
Release 10 199 3GPP TS 24.008 V10.6.1 (2012-03)
In Iu mode, to initiate the procedure the GMM entity in the network requests the lower layer to start paging (see
3GPP TS 25.331 [23c] and 3GPP TS 25.413 [19c]) and starts timer T3313. The GMM entity in the network may
provide the lower layer with a list of CSG IDs, including the CSG IDs of both the expired and the unexpired
subscriptions. If there is a PDN connection for emergency bearer services established, the GMM entity in the network
shall not provide the list of CSG IDs to the lower layer.
Upon reception of a paging indication, the MS shall stop the timer T3346, if running, and initiate a service request
procedure to respond to the paging, the MS shall set the service type to "paging response" in the SERVICE REQUEST
message (see 3GPP TS 24.007 [20], 3GPP TS 23.060 [74], 3GPP TS 25.331 [23c] and 3GPP TS 25.413 [19c]). If the
paging request for GPRS services was received during an ongoing MS initiated GMM specific procedure, then the MS
shall progress the GMM specific procedure, and the network shall proceed with the GMM specific procedure.
In A/Gb mode, to initiate the procedure the GMM entity requests the RR sublayer to start paging (see
3GPP TS 44.018 [84], 3GPP TS 44.060 [76]), and starts timer T3313. Upon reception of a paging indication, the MS
shall respond to the paging with any LLC frame (see 3GPP TS 44.064 [78a], 3GPP TS 24.007 [20],
3GPP TS 23.060 [74]).
At intersystem change, an MS not having the READY timer running in A/Gb mode or an MS in PMM-IDLE mode in Iu
mode, being paged in a different access network as when it last sent user data or signalling message, uses ROUTING
AREA UPDATE REQUEST message as paging response, i.e. the RA update procedure shall be performed instead
according to the selective routing area update procedure.
The network shall stop timer T3313 when a response is received from the MS. When the timer T3313 expires the
network may reinitiate paging.
In Iu mode, when a response is received from the MS, the network shall change from PMM-IDLE mode to PMM-
CONNECTED mode.
In A/Gb mode, when a response different from an LLC NULL frame is received from the MS, the network shall start
the READY timer.
The network may initiate paging using IMSI if the P-TMSI is not available due to a network failure.
In Iu mode, to initiate the procedure the GMM entity in the network requests the lower layer to start paging (see
3GPP TS 25.331 [23c] and 3GPP TS 25.413 [19c]).
In A/Gb mode, to initiate the procedure the GMM entity in the network requests the RR sublayer to start paging (see
3GPP TS 44.018 [84], 3GPP TS 44.060 [76]).
Upon reception of a paging indication for GPRS services using IMSI, the MS shall stop the timer T3346, if it is
running, locally deactivate any active PDP context(s), MBMS context(s) and locally detach from GPRS. The local
detach includes deleting any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number stored, setting
the GPRS update status to GU2 NOT UPDATED and changing state to GMM-DEREGISTERED. The MS shall stop all
timers T3396 that are running.
If S1 mode is supported by the MS, the MS shall in addition handle the EMM parameters EMM state, EPS update
status, last visited registered TAI, TAI list, GUTI and KSIASME as specified in 3GPP TS 24.301 [120] for the case when a
paging for EPS services using IMSI is received.
In Iu mode, when an MS receives a paging request for GPRS services using the IMSI from the network before an MS
initiated GMM specific procedure has been completed, then the MS shall abort the GMM specific procedure, and the
MS shall proceed according to the description in this clause.
After performing the local detach, the MS shall then perform a GPRS attach or combined GPRS attach procedure.
3GPP
Release 10 200 3GPP TS 24.008 V10.6.1 (2012-03)
After performing the attach, the MS should activate PDP context(s) to replace any previously active PDP context(s).
The MS should also perform the procedures needed in order to activate any previously active multicast service(s).
NOTE 1: In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS
context(s) automatically.
NOTE 2: The MS does not respond to the paging except with the Attach Request. Hence timer T3313 in the
network is not used when paging with IMSI.
NOTE 3: Paging without DRX parameters may require a considerable extension of the paging duration.
In Iu mode, to initiate the procedure the GMM entity requests the lower layer to start paging (see 3GPP TS 25.331 [23c]
and 3GPP TS 25.413 [19c]) for non-GPRS services.
In A/Gb mode, to initiate the procedure the GMM entity requests the RR sublayer to start paging (see
3GPP TS 44.018 [84] and 3GPP TS 44.060 [76] for non-GPRS services).
The MS identity used for paging shall be the allocated TMSI if acknowledged by the MS, otherwise the IMSI.
4.7.11 Void
If the mobile station does not support the GMM information message the mobile station shall ignore the contents of the
message and return an GMM STATUS message with cause #97.
3GPP
Release 10 201 3GPP TS 24.008 V10.6.1 (2012-03)
- the initiation of CM layer service (e.g. SM or SMS) procedure from the MS in PMM-IDLE mode,
- uplink (in PMM-IDLE or PMM CONNECTED) and downlink (only in PMM-IDLE) user data,
- counting the number of mobile stations in a cell which are interested in a specific MBMS service.
- requesting the establishment of a point-to-point Radio Bearer for receiving a MBMS service.
For downlink transfer of signalling or user data in PMM-IDLE mode, the trigger is given from the network by the
paging request procedure, which is out of scope of the present document.
For pending downlink user data in PMM-CONNECTED mode, the re-establishment of radio access bearers for all
active PDP contexts is done without paging.
For counting the number of mobile stations in PMM-IDLE mode interested in a specific MBMS service, the trigger is
given from the network by the MBMS notification procedure (see 3GPP TS 25.331 [23c]).
For establishing a point-to-point radio bearer to allow MBMS service, the trigger is given from the RRC determining
this need from the MBMS control parameters broadcasted by the network (see 3GPP TS 25.331 [23c]).
Service type can take either of the following values; "signalling", "data", "paging response", "MBMS multicast service
reception" or "MBMS broadcast service reception". Each of the values shall be selected according to the criteria to
initiate the Service request procedure.
If the MS is triggered to send a Service Request message for both MBMS multicast service and MBMS broadcast
service simultaneously, the MS shall include a Service Type indicating "MBMS multicast service reception".
a) the MS has any signalling messages except GMM messages (e.g. for SM or SMS) to be sent to the network in
PMM-IDLE mode (i.e., no secure PS signalling connection has been established). In this case, the service type
shall be set to "signalling".
b) the MS, either in PMM-IDLE or PMM-CONNECTED mode, has pending user data to be sent, no radio access
bearer is established for the corresponding PDP context, and timer T3319 (see subclause 4.7.13.3) is not running
or, optionally, if timer T3319 is running and the flag in the Uplink data status IE for this PDP context has not
been set in the last Service Request. The procedure is initiated by an indication from the lower layers (see
3GPP TS 24.007 [20]). In this case, the service type shall be set to "data".
c) the MS receives a paging request for PS domain from the network in PMM-IDLE mode. In this case, the service
type shall be set to "paging response".
e) the MS in PMM-IDLE mode or PMM-CONNECTED, determines from the broadcast MBMS control parameters
that there is a need to establish a point-to-point Radio Bearer to enable MBMS reception (see
3GPP TS 25.346 [110]). In this case, the service type shall be set to "MBMS multicast service reception" or
"MBMS broadcast service reception", respectively.
If one of the above criteria to invoke the Service request procedure is fulfilled, then the Service request procedure may
only be initiated by the MS when the following conditions are fulfilled:
- its GPRS update status is GU1 UPDATED and the stored RAI is equal to the RAI of the current serving cell; and
If a GMM specific procedure is ongoing at the time a request from CM sublayer, the RRC or the RABM (see
3GPP TS 24.007 [20]) is received and the ATTACH REQUEST or ROUTING AREA UPDATE REQUEST message
has been sent, then, depending on implementation, the MS shall abort the received request or delay it until the GMM
specific procedure is completed. If the ATTACH REQUEST or ROUTING AREA UPDATE REQUEST message has
3GPP
Release 10 202 3GPP TS 24.008 V10.6.1 (2012-03)
not been sent, the MS may indicate "follow-on request pending" in the message (i.e. the MS wishes to prolong the
established PS signalling connection after the GMM specific procedure). Then, the MS shall delay the Service request
procedure until the GMM specific procedure is completed.
If the network indicates "follow-on proceed" in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT
message and the MS has a service request pending, the MS shall react depending on the service type. If the service type
is:
- "signalling": the MS shall abort the Service request procedure and send the pending signalling messages
immediately;
- "data": the MS shall immediately perform the pending Service request procedure using the current PS signalling
connection;
- "paging response": the MS shall abort the Service request procedure. No further specific action is required from
the MS.
If the network indicates "follow-on proceed" and the MS has no service request pending, then no specific action is
required from the MS.
If the network indicates "no follow-on proceed" in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT
message, the MS shall not initiate the pending Service request procedure until the current PS signalling connection is
released.
NOTE: The "follow-on proceed" indication was not defined in earlier versions of the protocol. A network that is
compliant with the earlier versions of the protocol will always encode the respective bit as zero, i.e. as
"follow-on proceed", even if it does not prolong the PS signalling connection.
After completion of a Service request procedure but before re-establishment of radio access bearer, if the PDP and
MBMS context status information elements are included, then the network shall deactivate all those PDP and MBMS
contexts locally (without peer to peer signalling between the MS and the network), which are not in SM state PDP-
INACTIVE on network side but are indicated by the MS as being in state PDP-INACTIVE.
After completion of a Service request procedure, the pending service is resumed and uses then the connection
established by the procedure. If the service type is indicating "data", then the radio access bearers for all activated PDP
contexts are re-established by the network, except for those activated PDP contexts having maximum bit rate value set
to 0 kbit/s for both uplink and downlink and as an option those which have no pending user data. The re-establishment
of radio access bearers for those PDP contexts is specified in subclause 6.1.3.3.
If the PDP context status information element is included in the SERVICE REQUEST message, then the network shall
deactivate all those PDP contexts locally (without peer to peer signalling between the MS and the network) which are
not in SM state PDP-INACTIVE on the network side, but are indicated by the MS as being in state PDP-INACTIVE.
If the MBMS context status information element is included in the SERVICE REQUEST message, then the network
shall deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and network) which
are not in SM state PDP-INACTIVE on the network side, but are indicated by the MS as being in state PDP-
INACTIVE. If no MBMS context status information element is included, then the network shall deactivate all MBMS
contexts locally which are not in SM state PDP-INACTIVE on the network side.
For a Service Request of type "data", the MS may include the Uplink data status information element in the SERVICE
REQUEST message. The Uplink data status information indicates which preserved PDP contexts have pending uplink
data to be sent. If the Uplink data status information element is included in the SERVICE REQUEST message with
service type "data", the network may use this information to determine which of the RABs for the preserved PDP
contexts to re-establish.
3GPP
Release 10 203 3GPP TS 24.008 V10.6.1 (2012-03)
If the SERVICE REQUEST message was sent in PMM-CONNECTED mode, then the reception of the SERVICE
ACCEPT message shall be treated as a successful completion of the procedure. The timer T3317 shall be stopped and
the MS remains in PMM-CONNECTED mode.
If the SERVICE REQUEST message was sent in a CSG cell and the CSG subscription has expired or was removed for
a MS, but the MS has a PDN connection for emergency bearer services established, the network shall accept the
SERVICE REQUEST message and deactivate all non-emergency PDP contexts by initiating PDP context deactivation
procedure. The PDP contexts for emergency services shall not be deactivated.
At successful completion of a service request procedure with Service type "data", the MS shall start timer T3319. The
timer T3319 shall be stopped when the MS returns to PMM-IDLE mode or when the network releases the radio access
bearer of any active PDP context. The MS shall not issue another Service Request with service type "data" while timer
T3319 is running unless the Service request is being generated from a PDP context for which the flag in the Uplink data
status IE has not been set in the last Service Request.
The network may indicate a value for timer T3319 in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT
messages. The last provided value of T3319 shall be used by the MS. If the information element T3319 value is not
included in the ATTACH ACCEPT or ROUTING AREA UPDATE ACCEPT messages, the default value shall be used.
If the T3319 value received by the MS contains an indication that the timer is deactivated or the timer value is zero,
then the MS shall use the default value.
If the PDP context status information element is included in the Service Accept, then the MS shall deactivate locally
(without peer to peer signalling between the MS and the network) all that PDP contexts which are not in SM state PDP-
INACTIVE on MS side but are indicated by the Network as being in state PDP-INACTIVE.
If the MBMS context status information element is included in the SERVICE ACCEPT message, then the MS shall
deactivate all those MBMS contexts locally (without peer to peer signalling between the MS and network) which are
not in SM state PDP-INACTIVE in the MS, but are indicated by the network as being in state PDP-INACTIVE. If no
MBMS context status information element is included, then the MS shall deactivate all those MBMS contexts locally
which are not in SM state PDP-INACTIVE in the MS.
If a service request is received from a MS with a LIPA PDN connection, and if:
- a L-GW Transport Layer Address is provided by the lower layer together with the service request, and the
GGSN address associated with the PDP context of the LIPA PDN connection is different from the provided L-
GW Transport Layer Address (see 3GPP TS 25.413 [19c]); or
- no L-GW Transport Layer Address is provided together with the service request by the lower layer,
then the SGSN explicitly deactivates all PDP contexts associated with the LIPA PDN connection by initiating the PDP
context deactivation procedure.
If the service request for mobile originated services is rejected due to general NAS level mobility management
congestion control, the network shall set the GMM cause value to #22 "congestion" and assign a back-off timer T3346.
An MS that receives a SERVICE REJECT message stops timer T3317. The MS shall then take different actions
depending on the received reject cause value:
3GPP
Release 10 204 3GPP TS 24.008 V10.6.1 (2012-03)
#3 (Illegal MS); or
#6 (Illegal ME);
- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and enter the state GMM-DEREGISTERED. Furthermore, it shall delete any P-TMSI, P-
TMSI signature, RAI and GPRS ciphering key sequence number and shall consider the SIM/USIM as invalid for
GPRS services until switching off or the SIM/USIM is removed.
- A GPRS MS operating in MS operation mode A shall in addition set the update status to U3 ROAMING NOT
ALLOWED, shall delete any TMSI, LAI and ciphering key sequence number. If the MS is operating in MS
operation mode A and an RR connection exists, the MS shall abort the RR connection, unless an emergency call
is ongoing. The SIM/USIM shall be considered as invalid also for non-GPRS services until switching off or the
SIM/USIM is removed.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
service request procedure is rejected with the EMM cause with the same value.
- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2.9) and shall delete any P-TMSI, P-TMSI signature, RAI and GPRS ciphering key sequence
number. The SIM/USIM shall be considered as invalid for GPRS services until switching off or the SIM/USIM
is removed. The new state is GMM-DEREGISTERED.
A GPRS MS operating in MS operation mode A or B in network operation mode I which is already IMSI
attached for CS services is still IMSI attached for CS services in the network, and shall set the timer T3212 to its
initial value and restart it, if it is not already running.
A GPRS MS operating in MS operation mode A or B in network operation mode I shall proceed with the
appropriate MM specific procedure according to the MM service state.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
service request procedure is rejected with the EMM cause with the same value.
- The MS shall set the GPRS update status to GU2 NOT UPDATED (and shall store it according to
subclause 4.1.3.2), enter the state GMM-DEREGISTERED, and shall delete any P-TMSI, P-TMSI signature,
RAI and GPRS ciphering key sequence number. If the rejected request was not for initiating a PDN connection
for emergency bearer services, the MS may subsequently, automatically initiate the GPRS attach procedure.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
service request procedure is rejected with the EMM cause with the same value.
# 10 (Implicitly detached);
- The MS shall change to state GMM-DEREGISTERED.NORMAL-SERVICE. If the rejected request was not for
initiating a PDN connection for emergency bearer services, the MS shall then perform a new attach procedure.
The MS should also activate PDP context(s) to replace any previously active PDP contexts. The MS should also
perform the procedures needed in order to activate any previously active multicast service(s).
If S1 mode is supported in the MS, the MS shall handle the EMM state as specified in 3GPP TS 24.301 [120] for
the case when the the service request procedure is rejected with the EMM cause with the same value.
NOTE 1: In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS
context(s) automatically.
3GPP
Release 10 205 3GPP TS 24.008 V10.6.1 (2012-03)
- The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2)
and enter the state GMM-DEREGISTERED.
- The MS shall store the PLMN identity in the "forbidden PLMN list".
- If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- A GPRS MS operating in MS operation mode A shall set the update status to U3 ROAMING NOT
ALLOWED and shall delete any TMSI, LAI and ciphering key sequence number. The new MM state is MM
IDLE.
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
service request procedure is rejected with the EMM cause with the same value.
- The MS shall delete any RAI, P-TMSI, P-TMSI signature and GPRS ciphering key sequence number, shall set
the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to subclause 4.1.3.2)
and shall change to state GMM-DEREGISTERED.LIMITED-SERVICE.
- The mobile station shall store the LAI in the list of "forbidden location areas for regional provision of service".
- If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED, shall
delete any TMSI, LAI and ciphering key sequence number and shall reset the location update attempt
counter. The new MM state is MM IDLE.
- The MS shall perform a cell selection according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98].
NOTE 2: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state, EPS update status,
GUTI, last visited registered TAI, TAI list and KSI as specified in 3GPP TS 24.301 [120] for the case when the
service request procedure is rejected with the EMM cause with the same value.
- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall change to state GMM-REGISTERED.LIMITED-SERVICE.
- The MS shall store the LAI in the list of "forbidden location areas for roaming".
- If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall
reset the location update attempt counter. The new MM state is MM IDLE.
3GPP
Release 10 206 3GPP TS 24.008 V10.6.1 (2012-03)
An MS in GAN mode shall request a PLMN list in GAN (see 3GPP TS 44.318 [76b]) prior to perform a
PLMN selection from this list according to 3GPP TS 23.122 [14].
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status
as specified in 3GPP TS 24.301 [120] for the case when the service request procedure is rejected with the EMM
cause with the same value.
- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall change to state GMM-REGISTERED.LIMITED-SERVICE.
- The MS shall store the LAI in the list of "forbidden location areas for roaming".
- If no RR connection exists, the MS shall perform the following additional actions immediately. If the MS is
operating in MS operation mode A and an RR connection exists, the MS shall perform these actions when the
RR connection is subsequently released:
- If the MS is IMSI attached, the MS shall set the update status to U3 ROAMING NOT ALLOWED and shall
reset the location update attempt counter. The new MM state is MM IDLE.
- The MS shall search for a suitable cell in another location area or a tracking area in the same PLMN
according to 3GPP TS 43.022 [82] and 3GPP TS 25.304 [98] or 3GPP TS 36.304 [121].
NOTE 3: The cell selection procedure is not applicable for an MS in GAN mode.
If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status
as specified in 3GPP TS 24.301 [120] for the case when the service request procedure is rejected with the EMM
cause with the same value.
#22 (Congestion);
If the T3346 value IE is present in the SERVICE REJECT message and the value indicates that this timer is
neither zero nor deactivated, the MS shall proceed as described below, otherwise it shall be considered as an
abnormal case and the behaviour of the MS for this case is specified in subclause 4.7.13.5.
If the rejected request was not for initiating a PDN connection for emergency bearer services, the MS shall abort
the service request procedure and enter state GMM-REGISTERED, and stop timer T3317 if still running.
If the SERVICE REJECT message is integrity protected, the MS shall start timer T3346 with the value provided
in the T3346 value IE.
If the SERVICE REJECT message is not integrity protected, the MS shall start timer T3346 with a random value
from the default range specified in table 11.3a.
The MS stays in the current serving cell and applies normal cell reselection process. The service request
procedure may be started by CM layer, if it is still necessary, when timer T3346 expires or is stopped.
- Cause #25 is only applicable in UTRAN Iu mode and when received from a CSG cell. Other cases are
considered as abnormal cases and the specification of the mobile station behaviour is given in
subclause 4.7.13.5.
- If the SERVICE REJECT message with cause #25 was received without integrity protection, then the MS shall
discard the message.
- The MS shall set the GPRS update status to GU3 ROAMING NOT ALLOWED (and shall store it according to
subclause 4.1.3.2) and shall change to state GMM-REGISTERED.LIMITED-SERVICE.
3GPP
Release 10 207 3GPP TS 24.008 V10.6.1 (2012-03)
- If the CSG ID and associated PLMN identity of the cell where the MS has sent the SERVICE REQUEST
message are contained in the Allowed CSG list stored in the MS, the MS shall remove the entry corresponding to
this CSG ID and associated PLMN identity from the Allowed CSG list.
- If the CSG ID and associated PLMN identity of the cell where the MS has sent the SERVICE REQUEST
message are contained in the Operator CSG list, the MS shall proceed as specified in 3GPP TS 23.122 [14]
subclause 3.1A.
- The MS shall search for a suitable cell in the same PLMN according to 3GPP TS 43.022 [82] and
3GPP TS 25.304 [98].
- If S1 mode is supported in the MS, the MS shall handle the EMM parameters EMM state and EPS update status
as specified in 3GPP TS 24.301 [120] for the case when the service request procedure is rejected with the EMM
cause with the same value.
- The MS shall deactivate locally all active PDP and MBMS contexts and the MS shall enter the state GMM-
REGISTERED.NORMAL-SERVICE. The MS may also activate PDP context(s) to replace any previously active
PDP contexts. The MS may also perform the procedures needed in order to activate any previously active
multicast service(s).
NOTE 4: In some cases, user interaction may be required and then the MS cannot activate the PDP and MBMS
context(s) automatically.
Other values are considered as abnormal cases. The specification of the MS behaviour in those cases is described in
subclause 4.7.13.5.
4.7.13.4a Service request procedure for initiating a PDN connection for emergency bearer
services not accepted by the network
If the service request for initiating a PDN connection for emergency bearer services cannot be accepted by the network,
the MS shall perform the procedures as described in subclause 4.7.13.4. Then if the MS is in the same selected PLMN
where the last service request was attempted, the MS shall:
a) inform the upper layers. This could result in the MS attempting a CS emergency call (if not already attempted in
the CS domain) or other implementation specific mechanisms, e.g. procedures specified in 3GPP TS 24.229 [95]
that can result in the emergency call being attempted to another IP-CAN; or
b) detach locally, if not detached already, attempt GPRS attach for emergency bearer services.
The Service request procedure shall not be started. The MS stays in the current serving cell and applies normal
cell reselection process. The Service request procedure may be started by CM layer if it is still necessary, i.e.
when access is granted or because of a cell change.
b) Lower layer failure before the security mode control procedure is completed, SERVICE ACCEPT or SERVICE
REJECT message is received
The procedure shall be aborted except in the following implementation option cases b.1, b.2 and b.3.
b.1) Release of PS signalling connection in Iu mode (i.e. RRC connection release) before the completion of the
service request procedure
The service request procedure shall be initiated again, if the following conditions apply:
i) The original service request procedure was initiated over an existing PS signalling connection; and
3GPP
Release 10 208 3GPP TS 24.008 V10.6.1 (2012-03)
ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the PS signalling connection were received after the SERVICE REQUEST message was transmitted.
b.2) RR release in Iu mode (i.e. RRC connection release) with cause different than "Directed signalling
connection re-establishment", for example, "Normal", or "User inactivity" (see 3GPP TS 25.331 [32c] and
3GPP TS 44.118 [111])
The service request procedure shall be initiated again, if the following conditions apply:
i) The original service request procedure was initiated over an existing RRC connection and,
ii) No SECURITY MODE COMMAND message and no Non-Access Stratum (NAS) messages relating to
the PS signalling connection were received after the SERVICE REQUEST messge was transmitted.
NOTE: The RRC connection release cause different than "Directed signalling connection re-establishment" that
triggers the re-initiation of the service request procedure is implementation specific.
b.3) RR release in Iu mode (i.e. RRC connection release) with cause "Directed signalling connection re-
establishment" (see 3GPP TS 25.331 [32c] and 3GPP TS 44.118 [111])
The routing area updating procedure shall be initiated followed by a rerun of the service request procedure if the
following condition applies:
i) The service request procedure was not due to a rerun of the procedure due to "Directed signalling
connection re-establishment".
c) T3317 expired
If the MS is in PMM-IDLE mode then the procedure shall be aborted and the MS shall release locally any
resources allocated for the service request procedure.
d) SERVICE REJECT received, other causes than those treated in subclause 4.7.13.4, and cases of GMM cause
#22, if considered as abnormal cases according to subclause 4.7.13.4
If a cell change into a new routing area occurs and the necessity of routing area update procedure is determined
before the security mode control procedure is completed, a SERVICE ACCEPT or SERVICE REJECT message
has been received, the Service request procedure shall be aborted and the routing area updating procedure is
started immediately. Follow-on request pending may be indicated in the ROUTING AREA UPDATE REQUEST
for the service, which was the trigger of the aborted Service request procedure, to restart the pending service
itself or the Service request procedure after the completion of the routing area updating procedure. If the Service
type of the aborted SERVICE REQUEST was indicating "data", then the routing area update procedure may be
followed by a re-initiated Service request procedure indicating "data", if it is still necessary. If the Service type
was indicating "MBMS multicast service reception", or "MBMS broadcast service reception" the Service request
procedure shall be aborted.
f) Power off
If the MS is in state GMM-SERVICE-REQUEST-INITIATED at power off, the GPRS detach procedure shall be
performed.
g) Procedure collision
GPRS detach containing detach type "re-attach required" or "re-attach not required":
If the MS receives a DETACH REQUEST message from the network in state GMM-SERVICE-REQUEST-
INITIATED, the GPRS detach procedure shall be progressed and the Service request procedure shall be aborted.
If the cause IE, in the DETACH REQUEST message, indicated a "re-attach required", the GPRS attach
procedure shall be performed. If the GPRS Detach Request message contains detach type "re-attach not
3GPP
Release 10 209 3GPP TS 24.008 V10.6.1 (2012-03)
required" and GMM cause #2 "IMSI unknown in HLR", the MS will follow the procedure as described below
for the detach type "IMSI detach".
If the MS receives a DETACH REQUEST message from the network in state GMM-SERVICE-REQUEST-
INITIATED, the network and the MS shall progress both procedures.
The MS shall abort the service request procedure, enter state GMM-REGISTERED, and stop timer T3317 if still
running.
If the SERVICE REQUEST message contained the NAS signalling low priority indication set to "MS is
configured for NAS signalling low priority", the MS shall start timer T3346 with the "Extended wait time" value.
The service request procedure is started, if still necessary, when timer T3346 expires or is stopped.
The MS shall not start the service request procedure unless the MS has a PDN connection for emergency bearer
services established or is establishing a PDN connection for emergency bearer services. The MS stays in the
current serving cell and applies normal cell reselection process. The service request procedure is started, if still
necessary, when timer T3346 expires or is stopped.
If a low layer failure occurs before the security mode control procedure is completed, a SERVICE ACCEPT or
SERVICE REJECT message has been sent to the MS, the network enters/stays in PMM-IDLE.
b) Protocol error
If the SERVICE REQUEST message is received with a protocol error, the network shall return a SERVICE
REJECT message with one of the following reject causes:
c) More than one SERVICE REQUEST received and the procedure has not been completed (i.e., the security mode
control procedure has not been completed or SERVICE ACCEPT, SERVICE REJECT message has not been
sent)
- If one or more of the information elements in the SERVICE REQUEST message differs from the ones
received within the previous SERVICE REQUEST message, the previously initiated Service request
procedure shall be aborted and the new Service request procedure shall be progressed;
- If the information elements do not differ, then the network shall continue with the previous Service request
procedure and shall not treat any further this SERVICE REQUEST message.
d) ATTACH REQUEST received before the security mode control procedure has been completed or an SERVICE
ACCEPT or an SERVICE REJECT message has been sent
3GPP
Release 10 210 3GPP TS 24.008 V10.6.1 (2012-03)
If an ATTACH REQUEST message is received and the security mode control procedure has not been completed
or an SERVICE ACCEPT or an SERVICE REJECT message has not been sent, the network may initiate the
GMM common procedures, e.g. the GMM authentication and ciphering procedure. The network may e.g. after a
succesful GMM authentication and ciphering procedure execution, abort the Service request procedure, the
GMM context, PDP contexts and MBMS contexts, if any, are deleted and the new ATTACH REQUEST is
progressed.
e) ROUTING AREA UPDATE REQUEST message received before the security mode control procedure has been
completed or an SERVICE ACCEPT or an SERVICE REJECT message has been sent
If an ROUTING AREA UPDATE REQUEST message is received and the security mode control procedure has
not been completed or an SERVICE ACCEPT or an SERVICE REJECT message has not been sent, the network
may initiate the GMM common procedures, e.g. the GMM authentication and ciphering procedure. The network
may e.g. after a successful GMM authentication and ciphering procedure execution, abort the Service request
procedure and progress the routing area update procedure.
f) If the Service Type indicates ‘data’ and the network fails to re-establish some or all RAB(s) then the SGSN may
determine if PDP Context Modification or PDP Context Deactivation should be initiated.
The appropriate action is an operator choice and depends on the QoS profile of the PDP Context, and the Uplink
data status.
4.7.14 Void
5.1 Overview
5.1.1 General
This subclause describes the call control (CC) protocol, which is one of the protocols of the Connection Management
(CM) sublayer (see 3GPP TS 24.007 [20]).
Every mobile station must support the call control protocol. If a mobile station does not support any bearer capability at
all then it shall respond to a SETUP message with a RELEASE COMPLETE message as specified in subclause 5.2.2.2.
In Iu mode only, integrity protected signalling (see subclause 4.1.1.1.1 of the present document and in general, see
3GPP TS 33.102 [5a]) is mandatory. In Iu mode only, all protocols shall use integrity protected signalling. Integrity
protection of all CC signalling messages is the responsibility of lower layers. It is the network which activates integrity
protection. This is done using the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
In the call control protocol, more than one CC entity are defined. Each CC entity is independent from each other and
shall communicate with the correspondent peer entity using its own MM connection. Different CC entities use different
transaction identifiers.
With a few exceptions the present document describes the call control protocol only with regard to two peer entities.
The call control entities are described as communicating finite state machines which exchange messages across the
radio interface and communicate internally with other protocol (sub)layers. This description is only normative as far as
the consequential externally observable behaviour is concerned.
Certain sequences of actions of the two peer entities compose "elementary procedures" which are used as a basis for the
description in this subclause. These elementary procedures may be grouped into the following classes:
3GPP
Release 10 211 3GPP TS 24.008 V10.6.1 (2012-03)
- miscellaneous procedures.
The terms "mobile originating" or "mobile originated" (MO) are used to describe a call initiated by the mobile station.
The terms "mobile terminating" or "mobile terminated" (MT) are used to describe a call initiated by the network.
Figure 5.1a/3GPP TS 24.008 gives an overview of the main states and transitions on the mobile station side.
The MS side extension figure 5.1a.1/3GPP TS 24.008 shows how for the Network Initiated MO call the MS reaches
state U1.0 from state U0 $(CCBS)$.
Figure 5.1a.2/3GPP TS 24.008 illustrates the additional state transitions possible in the MS due to SRVCC handovers
from PS to CS.
Figure 5.1b/3GPP TS 24.008 gives an overview of the main states and transitions on the network side.
The Network side extension figure 5.1b.1/3GPP TS 24.008 shows for Network Initiated MO Calls the Network reaches
state N1.0 from state N0 $(CCBS)$.
Figure 5.1b.2/3GPP TS 24.008 illustrates the additional state transitions possible in the network due to SRVCC
handovers from PS to CS.
3GPP
Release 10 212 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 213 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 214 3GPP TS 24.008 V10.6.1 (2012-03)
Figure 5.1a.2/3GPP TS 24.008: Overview call control protocol/MS side, extension for SRVCC from PS
to CS
3GPP
Release 10 215 3GPP TS 24.008 V10.6.1 (2012-03)
DI (CALL CONF)
DR (REL)
MNCC.DISC.IND MNCC. CALL.
CONF.IND
DR (REL)
DI (REL)
DI (DISC)
N12 DISCON-
N3 MO CALL
MNCC ALERT REQ NECT INDICATION
MNCC. PROCEEDING
PROGRESS.
REQ. MNCC.
SETUP. RSP DI (DISC)
DR (ALERT) DR (DIS C) N9 M T CALL
DR (PROGRESS) DI (ALERT)
DI (CONN) _ CONFIRM ED
STATES N1, 3, 4,
7, 8, 9; 10, 28 MNCC. DISC. REQ.
N4 CALL MNCC.ALERT.IND.
DELIVERED
N7 CALL
DR (CONN) RECEIVED
MNCC. SETUP.
COMPL. IND. DR (CONN ACK) DI (CO NN)
N28 CONNECT
DI (CONN ACK) M NCC. SETUP. MNCC.SETUP.CNF
INDICATION N10 N8 CONNECT
COMPL. REQ. REQUEST
NOTE: ACTIVE
DR(MESSAGE) = MM CC_DATA_REQ(MESSAGE)
DI (MESSAGE) = MMCC_DATA_IND (MESSAGE)
3GPP
Release 10 216 3GPP TS 24.008 V10.6.1 (2012-03)
N0
NULL
MNCC.CC_CONN.REQ
MMCC.CC_CONN.REQ
N0.2
CC_CONN_PENDING
DR (CC_ESTABLISH)
N0.4
CC-EST.PESENT
DI (CC_EST_CONF)
N0.5
CC_EST. CONFIRMED
DR (RECALL)
N0.6
RECALL_PRESENT
DI (SETUP)
N1
CALL_INITIATED
Figure 5.1b.2/3GPP TS 24.008: Overview call control protocol/MS side, extension for SRVCC from PS
to CS
3GPP
Release 10 217 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: States U0.1, U0.2, U0.3, U0.4, U0.5, U0.6, U26, and U27 are 3GPP specific. All other states are ITU-T
defined.
3GPP
Release 10 218 3GPP TS 24.008 V10.6.1 (2012-03)
The call states that may exist on the network side of the radio interface are defined in this subclause.
3GPP
Release 10 219 3GPP TS 24.008 V10.6.1 (2012-03)
This state exists for a mobile originating call when the network has sent a recall request but has not yet received a
satisfactory response.
3GPP
Release 10 220 3GPP TS 24.008 V10.6.1 (2012-03)
- the establishment of a CC connection between the mobile station and the network;
Whenever it is specified in the present document clause 5 that the mobile station shall attach the user connection, this
means that the mobile station shall activate the codec or interworking function as soon as an appropriate channel is
available. The mobile station shall de-activate the codec or interworking function whenever an appropriate channel is no
longer available. As soon as an appropriate channel is (again) available, the codec or interworking function shall be re-
activated. If a new order to attach the user connection is received, the new order shall supersede the previous one.
A channel shall be considered as appropriate if it is consistent with the possibly negotiated bearer capability applicable
for the actual phase of the call. The mobile station shall not consider a channel as not appropriate because the type of
the channel (full rate/half rate) is not the preferred one. If:
- the user connection has to be attached but no appropriate channel is available for a contiguous time of 30
seconds; or if
3GPP
Release 10 221 3GPP TS 24.008 V10.6.1 (2012-03)
Upon request of upper layers to establish a call, restricting conditions for the establishment of the call are examined.
These restricting conditions concern the states of parallel CC entities and are defined elsewhere. If these restricting
conditions are fulfilled, the call establishment is rejected. Otherwise a CC entity in state U0, "null", is selected to
establish the call. It initiates the establishment by requesting the MM sublayer to establish an MM connection.
In Iu mode, if the lower layers indicate the release of a radio access bearer, whereas the corresponding call is still active,
the MS shall not automatically initiate the release of that call.
For mobile stations supporting eMLPP basic calls may optionally have an associated priority level as defined in
3GPP TS 23.067 [88]. This information may also lead to specified qualities of service to be provided by the MM
sublayers.
While being in the "MM connection pending" state, the call entity of the mobile station may cancel the call prior to
sending the first call control message according to the rules given in subclause 4.5.1.7.
The mobile station supporting multicall that is initiating an emergency call shall release one or more existing call to
ensure the emergency call can be established if the multicall supported information stored in the mobile station
described in subclauses 5.2.1.2 and 5.2.2.1 indicates the network does not support multicall and some ongoing calls
exists.
Having entered the "MM connection pending" state, upon MM connection establishment, the call control entity of the
mobile station sends a setup message to its peer entity. This setup message is
The mobile station then enters the "call initiated" state. Timer T303 is not stopped.
The setup message shall contain all the information required by the network to process the call. In particular, the
SETUP message shall contain the called party address information.
If the mobile station supports multicall, it shall include the Stream Identifier (SI) information element. For the first call
i.e. when there are no other ongoing calls the SI value shall be 1.
For speech calls the mobile station shall indicate all codecs that it supports for UTRAN in the Supported Codec List
information element. Codecs for GERAN shall be indicated in the Bearer Capability information element, if this
information element is included. Additionally, if the mobile station supports codecs for GERAN and UTRAN, it shall
indicate the codecs for GERAN also in the Supported Codec List information element.
If the call is a redial attempt to switch from speech to multimedia or vice-versa, the SETUP message shall include the
Redial information element.
NOTE: Redial attempt is defined in 3GPP TR 23.903: "Redial solution for voice-video switching"[115].
If the MS supports the enhanced network-initiated in-call modification procedure as specified in subclause 5.3.4.3, the
MS shall indicate this in the Call Control Capabilities IE in the SETUP message.
If timer T303 elapses in the "MM connection pending" state, the MM connection in progress shall be aborted and the
user shall be informed about the rejection of the call.
3GPP
Release 10 222 3GPP TS 24.008 V10.6.1 (2012-03)
When the call control entity of the mobile station is in the "call initiated" state and if it receives:
Abnormal case:
- If timer T303 elapses in the "call initiated" state before any of the CALL PROCEEDING, ALERTING,
CONNECT or RELEASE COMPLETE messages has been received, the clearing procedure described in
subclause 5.4 is performed.
In Iu mode, network shall include the SI received in the SETUP message into the RABid and send it back to the mobile
station. For RABid see 3GPP TS 25.413 [19c] and 3GPP TS 44.118 [111]. If the network receives the SETUP message
with no SI, the network shall set the SI value to 1.
i) If, following the receipt of the setup message, the call control entity of the network determines that the call
information received from the mobile station is invalid (e.g. invalid number), then the network shall initiate call
clearing as defined in subclause 5.4 with one of the following cause values:
# 22 "number changed",
ii) If, following the receipt of the setup message, the call control entity of the network determines that a requested
service is not authorized or is not available, it shall initiate call clearing in accordance with subclause 5.4.2 with
one of the following cause values:
iii) Otherwise, the call control entity of the network shall either:
- send a CALL PROCEEDING message to its peer entity to indicate that the call is being processed; and enter
the "mobile originating call proceeding" state;
- or: send an ALERTING message to its peer entity to indicate that alerting has been started at the called user
side; and enter the "call received" state;
3GPP
Release 10 223 3GPP TS 24.008 V10.6.1 (2012-03)
- or: send a CONNECT message to its peer entity to indicate that the call has been accepted at the called user
side; and enter the "connect request" state.
The call control entity of the network may insert bearer capability information element(s) in the CALL
PROCEEDING message to select options presented by the mobile station in the Bearer Capability information
element(s) of the SETUP message. The bearer capability information element(s) shall contain the same
parameters as received in the SETUP except those presenting a choice. Where choices were offered, appropriate
parameters indicating the results of those choices shall be included.
The CALL_PROCEEDING message shall also contain the priority of the call in the case where the network
supports eMLPP. Mobile stations supporting eMLPP shall indicate this priority level to higher sublayers and
store this information for the duration of the call for further action. Mobile stations not supporting eMLPP shall
ignore this information element if provided in a CALL PROCEEDING message.
NOTE: If the network supports only R98 or older versions of this protocol and the priority is not included in the
CALL PROCEEDING message, this does not imply that the network does not support eMLPP.
- The CALL_PROCEEDING message shall contain the multicall supported information in the network call
control capabilities in the case where the network supports multicall and there are no other ongoing calls to the
MS. Mobile stations supporting multicall shall store this information until the call control state for all calls
returns to null. Mobile stations not supporting multicall shall ignore this information if provided in a CALL
PROCEEDING message. If the multicall supported information is not sent in the CALL_PROCEEDING
message, the mobile station supporting multicall shall regard that the network doesn't support multicall.
The call control entity of the network having entered the "mobile originating call proceeding" state, the network may
initiate the assignment of a traffic channel according to subclause 5.2.1.9 (early assignment).
For speech calls, if the SETUP message or EMERGENCY SETUP message contains a Supported Codec List
information element, the network shall use this list to select the codec for UTRAN. If no Supported Codec List
information element is received, then for UTRAN the network shall select the default UMTS speech codec according to
subclause 5.2.1.11.
Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer
Capability information element is received, then for GERAN the network shall select GSM full rate speech version 1.
Codec information that does not apply to the currently serving radio access shall be used by the network if an inter-
system change occurs.
Figure 5.2/3GPP TS 24.008 Mobile originated call initiation and possible subsequent responses.
- the CALL PROCEEDING message contains a progress indicator IE specifying progress description #1, #2, or
#64; or
3GPP
Release 10 224 3GPP TS 24.008 V10.6.1 (2012-03)
- it has received a PROGRESS message containing a progress indicator IE specifying progress description #1, #2,
or #64 prior to the CALL PROCEEDING message
Abnormal case:
If timer T310 elapses before any of the ALERTING, CONNECT or DISCONNECT messages has been received,
the mobile station shall perform the clearing procedure described in subclause 5.4.
Figure 5.3/3GPP TS 24.008 Call proceeding sequence at mobile originating call establishment
a) in an appropriate call control message, if a state change is required (e.g. ALERTING or CONNECT); or,
This progress indicator information element shall contain one of the following progress description values:
a) #1 "call is not end-to-end PLMN/ISDN; further call progress information may be available in-band".
See also subclauses 5.5.1 and 5.5.6 for further reactions of the mobile station.
a) in an appropriate call control message, if a state change is required (e.g., ALERTING or CONNECT); or
This progress indicator information element shall contain progress description value #32 "Call is end-to-end
ISDN/PLMN". See also subclause 5.5.6 for further reactions of the mobile station.
5.2.1.5 Alerting
Having entered the "mobile originating call proceeding" state, upon receiving an indication that user alerting has been
initiated at the called address, the call control entity of the network shall: send an ALERTING message to its peer entity
at the calling mobile station and enter the "call delivered" state.
3GPP
Release 10 225 3GPP TS 24.008 V10.6.1 (2012-03)
When the call control entity of the mobile station in the "call initiated" state or "mobile originating call proceeding"
state receives an ALERTING message then, the call control entity of the mobile station shall stop timer T303 and T310
(if running) and shall enter the "call delivered" state. In this state:
- for speech calls: an alerting indication should be given to the user. If the mobile station has not attached the user
connection then the mobile station shall internally generate an alerting indication. If the mobile station has
attached the user connection then the network is responsible for generating the alerting indication and the mobile
station need not generate one; and
- for multimedia calls: if the mobile station has not attached the user connection then the mobile station may
internally generate an alerting indication. If the mobile station supports multimedia CAT during the alerting
phase of a mobile originated multimedia call establishment, the network may request the mobile station to attach
the user connection and setup a H.324 call and generate multimedia CAT as specified in subclause 5.3.6.4, in
which case the mobile station need not generatean alerting tone.
Abnormal cases:
On the mobile station side, if timer T310 expires, the call control entity of the mobile station shall initiate call
clearing as described in subclause 5.4.
This message indicates to the call control entity of the calling mobile station that a connection has been established
through the network.
The call control entity of the mobile station in the "call initiated" state, in the "mobile originating call proceeding" state
or in the "call delivered" state, shall, upon receipt of a CONNECT message:
- clear any H.324 call established to receive multimedia CAT during the alerting phase (if applied) , as specified in
subclause 5.3.6.4
Abnormal cases:
On the mobile station side, if timer T303 or T310 expires, the call control entity of the mobile station shall
initiate call clearing as described in subclause 5.4.
NOTE: The mobile station may have applied an additional internal alerting supervision which causes initiation of
call clearing prior to the expiry of T303 or T310.
The call control of the network in the "connect indication" state, shall, upon receipt of a CONNECT ACKNOWLEDGE
message:
3GPP
Release 10 226 3GPP TS 24.008 V10.6.1 (2012-03)
Abnormal cases:
On the network side, if timer T313 elapses before a CONNECT ACKNOWLEDGE message has been received,
the network shall perform the clearing procedure as described in subclause 5.4.
Figure 5.5/3GPP TS 24.008 Call acceptance sequence at mobile originating call establishment
a) Mobile station generates a new SI value at the initiation of an originating call, then a new traffic channel shall be
assigned to the mobile originating call.
b) Mobile station indicates an existing SI value, then the indicated traffic channel shall be used for the mobile
originating call.
Mobile station supporting multicall shall never send an additional SETUP with indication that a new traffic channel is
requested to a network that does not support multicall.
It is a network dependent decision when to initiate the assignment of an appropriate traffic channel during the mobile
originating call establishment phase. Initiation of a suitable RR procedure to assign an appropriate traffic channel does
neither change the state of a call control entity nor affect any call control timer.
NOTE: During certain phases of such an RR procedure, transmission of CC and MM messages may be
suspended, see 3GPP TS 44.018 [84], clause 3 and 3GPP TS 48.008 [85].
The assignment procedure does not affect any call control timer.
The maximum queuing interval is supervised by the network. The limit is a network dependent choice. In case the
network is not able to allocate a traffic channel within the queuing limit, the network will release the call using cause
#34 "no circuit/channel available".
Optionally, e.g. if eMLPP is used, the network may decide to pre-empt existing calls or to place the traffic channel
request at some preferential position within the queue.
Specific indications provided in the network to the remote user are a network dependent choice.
3GPP
Release 10 227 3GPP TS 24.008 V10.6.1 (2012-03)
If the network does not receive a Supported Codec List information element then for speech calls in UTRAN it shall
select the default UMTS speech codec.
For speech calls in GERAN, if the network does not receive a Supported Codec List information element nor a Bearer
Capability information element, the network shall select GSM full rate speech version 1.
The network shall determine the default UMTS speech codec by the following:
i) If no GSM Speech Version codepoints are received in the Supported Codec List IE or in octet 3a etc. of the
Bearer Capabilities IE then a "UMTS only" terminal is assumed and the default UMTS speech codec shall be
UMTS_AMR.
ii) If at least one GSM Speech Version codepoint is received in the Supported Codec List IE or in octet 3a etc. of the
Bearer Capabilities IE then the ME supports GSM and UMTS and the default UMTS speech codec shall be
UMTS_AMR_2.
NOTE 1: In case (ii), if the call is set up in A/Gb or GERAN Iu mode by a R99 ME, call control in the core network
may treat the ME as a "GSM only" ME. The default UMTS speech codec will only become relevant when
an intersystem handover to UTRAN Iu mode is initiated by the radio access network, and can be
determined when this procedure is started.
If the Supported Codec List IE is received, then the network shall use this list to select the codec for Iu mode and
indicate the selected codec to the ME via RANAP and RRC protocol in the NAS Synchronisation Indicator IE. See
3GPP TS 25.413 [19c], 3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111].
The NAS Synchronisation Indicator IE shall be coded as the 4 least significant bits of the selected codec type (CoID)
defined in 3GPP TS 26.103 [83], subclause 6.3.
The network shall determine the preference for the selected codec type; codec type prioritisation is not provided by the
ME.
The ME shall activate the codec type received in the NAS Synchronisation Indicator IE.
If the mobile station does not receive the NAS Synchronisation Indicator IE (RRC protocol)
- during inter-system handover of a speech call from A/Gb or GERAN Iu mode to UTRAN Iu mode; or
NOTE 2: If the network does not support UMTS_AMR_2, it may activate the UMTS_AMR codec and indicate to
the mobile station that it shall select UMTS_AMR_2. According to 3GPP TS 26.103 [83], subclause 5.4,
no interworking problem will occur in this case.
If the mobile station has selected a speech codec for UTRAN Iu mode, it shall keep this codec until
- a new codec is requested by the network by sending a NAS Synchronisation Indicator IE (RRC protocol);
- a new codec is requested by the network during inter-system handover from UTRAN Iu mode to A/Gb or
GERAN Iu mode; or
3GPP
Release 10 228 3GPP TS 24.008 V10.6.1 (2012-03)
For adaptive multirate codec types no indication of subsets of modes is supported in this protocol, from the mobile
station or to the mobile station. It is a pre-condition that the support of such codec types by the mobile station implicitly
includes all modes defined for that codec type.
When the mobile station indicates speech and support of CTM text telephony, the network shall select a speech codec
and additionally CTM text telephony detection/conversion functions as specified in 3GPP TS 23.226 [92] and
3GPP TS 26.226 [93], if such functions are available.
NOTE: If CTM support is indicated by the mobile station, then it supports CTM text telephony together with any
supported speech codec and for any supported radio access.
Upon completion of the MM connection, the call control entity of the network shall: send the SETUP message to its
peer entity at the mobile station, start timer T303 and enter the "call present" state.
The SETUP message shall contain the multicall supported information in the network call control capabilities in the
case where the network supports multicall and there are no other ongoing calls to the MS. Mobile stations supporting
multicall shall store this information until the call control state for all calls returns to null. Mobile stations not
supporting multicall shall ignore this information if provided in a SETUP message. If the multicall supported
information is not sent in the SETUP message, the mobile station supporting multicall shall regard that the network
does not support multicall.
Upon receipt of a SETUP message, the mobile station shall perform compatibility checking as described in
subclause 5.2.2.2. If the result of the compatibility checking was compatibility, the call control entity of the mobile
station shall enter the "call present" state. An incompatible mobile station shall respond with a RELEASE COMPLETE
message in accordance with subclause 5.2.2.3.4.
If there are no bearer capability IEs in the SETUP message, the network may provide information about the requested
service in the backup bearer capability IE.
If no response to the SETUP message is received by the call control entity of the network before the expiry of timer
T303, the procedures described in subclause 5.2.2.3.3 shall apply.
Figure 5.6/3GPP TS 24.008 Mobile terminating call initiation and possible subsequent responses.
3GPP
Release 10 229 3GPP TS 24.008 V10.6.1 (2012-03)
If the mobile station supports multicall, it shall include the Stream Identifier (SI) information element in the CALL
CONFIRMED message.
If the mobile station is located in the network supporting multicall, it shall never include the SI that is in use and
shall include with either of the following two values:
- SI="no bearer";
If the mobile station supporting multicall is located in the network not supporting multicall, it shall include the SI with
value 1.
The call control entity of the mobile station may include in the CALL CONFIRMED message to the network one or two
bearer capability information elements to the network, either preselected in the mobile station or corresponding to a
service dependent directory number (see 3GPP TS 29.007 [38]). The mobile station may also use the backup bearer
capability IE, if provided by the network, to deduce the requested service (see 3GPP TS 27.001 [36], subclause 8.3.3.1).
The mobile station may also include one or two bearer capabilities in the CALL CONFIRMED message to define the
radio channel requirements. In any case the rules specified in subclause 9.3.2.2 shall be followed.
NOTE: The possibility of alternative responses (e.g., in connection with supplementary services) is for further
study.
For speech calls the mobile station shall indicate all codecs that it supports for UTRAN in the Supported Codec List
information element. Codecs for GERAN shall be indicated in the Bearer Capability information element, if this
information element is included. Additionally, if the mobile station supports codecs for GERAN and UTRAN, it shall
indicate the codecs for GERAN also in the Supported Codec List information element.
If the MS supports the enhanced network-initiated in-call modification procedure as specified in subclause 5.3.4.3, the
MS shall indicate this in the Call Control Capabilities IE in the CALL CONFIRMED message.
A busy MS which satisfies the compatibility requirements indicated in the SETUP message shall respond either with a
CALL CONFIRMED message if the call setup is allowed to continue or a RELEASE COMPLETE message if the call
setup is not allowed to continue, both with cause #17 "user busy".
If the mobile user wishes to refuse the call, a RELEASE COMPLETE message shall be sent with the cause #21 "call
rejected".
In the cases where the mobile station responds to a SETUP message with RELEASE COMPLETE message the mobile
station shall release the MM connection and enter the "null" state after sending the RELEASE COMPLETE message.
The network shall process the RELEASE COMPLETE message in accordance with subclause 5.4.
3GPP
Release 10 230 3GPP TS 24.008 V10.6.1 (2012-03)
In Iu mode, network shall include the SI received in the CALL CONFIRMED message into the RABid and send it back
to the mobile station. For RABid see 3GPP TS 25.413 [19c] and 3GPP TS 44.118 [111]. If the network receives the
CALL CONFIRMED message with no SI, the network shall set the SI value to 1.
For speech calls, if the CALL CONFIRMED message contains a Supported Codec List information element, the
network shall use this list to select the codec for UTRAN. If no Supported Codec List information element is received,
then for UTRAN the network shall select the default UMTS speech codec according to subclause 5.2.1.11.
Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer
Capability information element is received, then for GERAN the network shall select GSM full rate speech version 1.
Codec information that does not apply to the currently serving radio access shall be used by the network if an inter-
system change occurs.
The call control entity of the mobile station having entered the "mobile terminating call confirmed" state, if the call is
accepted at the called user side, the mobile station proceeds as described in subclause 5.2.2.5. Otherwise, if the signal
information element was present in the SETUP message user alerting is initiated at the mobile station side; if the signal
information element was not present in the SETUP message, user alerting is initiated when an appropriate channel is
available.
- sending of an ALERTING message by the call control entity of the MS to its peer entity in the network and
entering the "call received" state.
The call control entity of the network in the "mobile terminated call confirmed" state shall, upon receipt of an
ALERTING message: send a corresponding ALERTING indication to the calling user; stop timer T310; start timer
T301, and enter the "call received" state.
In the "mobile terminating call confirmed" state or the "call received" state, if the user of a mobile station is User
Determined User Busy then a DISCONNECT message shall be sent with cause #17 "user busy". In the "mobile
terminating call confirmed" state, if the user of a mobile station wishes to reject the call then a DISCONNECT message
shall be sent with cause #21 "call rejected".
i. If the network does not receive any response to the SETUP message prior to the expiration of timer T303, then
the network shall: initiate clearing procedures towards the calling user with cause #18 "no user responding"; and
initiate clearing procedures towards the called mobile station in accordance with subclause 5.4.4 using cause
#102 "recovery on timer expiry".
ii. If the network has received a CALL CONFIRMED message, but does not receive an ALERTING, CONNECT or
DISCONNECT message prior to the expiration of timer T310, then the network shall:
- initiate clearing procedures towards the calling user with cause #18 "no user responding"; and
- initiate clearing procedures towards the called MS in accordance with subclause 5.4.4 using cause #102
"recovery on timer expiry".
iii. If the network has received an ALERTING message, but does not receive a CONNECT or DISCONNECT
message prior to the expiry of timer T301 (or a corresponding internal alerting supervision timing function), then
the network shall: initiate clearing procedures towards the calling user with cause #19 "user alerting, no answer";
and initiate clearing procedures towards the called mobile station in accordance with subclause 5.4.4, using
cause #102 "recovery on timer expiry" or using cause #31 "normal, unspecified".
NOTE: The choice between cause #31 and cause #102 may have consequences on indications generated by the
mobile station, see 3GPP TS 22.001 [8a].
3GPP
Release 10 231 3GPP TS 24.008 V10.6.1 (2012-03)
5.2.2.3.4 Called mobile station clearing during mobile terminating call establishment
See subclause 5.4.2.
During call establishment the call may enter an PLMN/ISDN environment, e.g., because of interworking with another
network, with a non-PLMN/ISDN user, or with non-PLMN/ISDN equipment within the calling or called user's
premises. When this occurs, the network may include a progress indicator information element to be included in the
SETUP message to be sent to the called mobile station specifying progress description value:
a) #1 "call is not end-to-end PLMN/ISDN; further call progress information may be available in-band" or
See also subclause 5.5.1 for further reactions of the mobile station.
If the call control entity of the mobile station has indicated "No Bearer" as the SI value in the CALL CONFIRMED
message, it shall assign the SI value and include the SI information element in the CONNECT message. Otherwise the
SI information element shall not be included in the CONNECT message.
In the "connect request" state, the call control entity of the mobile station shall, upon receipt of a CONNECT
ACKNOWLEDGE message: stop timer T313 and enter the "active" state.
When timer T313 expires prior to the receipt of a CONNECT ACKNOWLEDGE message, the mobile station shall
initiate clearing in accordance with subclause 5.4.3.
Figure 5.7/3GPP TS 24.008 Call acceptance and active indication at mobile terminating call
establishment
3GPP
Release 10 232 3GPP TS 24.008 V10.6.1 (2012-03)
If a mobile station in the network supporting multicall requires a new traffic channel, it shall:
- send a CALL CONFIRMED message including the SI indicating a new value, not used by any of the existing
traffic channels.
If a mobile station in the network supporting multicall does not require a new traffic channel, it shall:
After the mobile station has send the CALL CONFIRMED with SI="no bearer", the SI value in the CONNECT
message will tell to the network if a user requests a new traffic channel or one of the existing ones will be re-uesd.
If a new traffic channel is requested by the user, the mobile station in the network supporting multicall shall:
- send a CONNECT message containing the SI with a new value, not used by any existing traffic channel.
If the user decides that an existing traffic channel will be reused, the mobile station in the network supporting multicall
shall:
- send a CONNECT message with an SI indicating an existing value used by an existing traffic channel.
It is a network dependent decision when to initiate the assignment of a traffic channel during the mobile terminating call
establishment phase.
Initiation of the assignment phase does not directly change the state of a CC entity nor affect any call control timer, but
may have some secondary effects (see e.g. subclause 5.2.2.3.2).
NOTE: The interworking to the fixed network has to fulfil the network specific requirements.
The mobile station shall attach the user connection at latest when sending the connect message.
The mobile station shall attach the user connection when receiving the CONNECT ACKNOWLEDGE message
from the network.
3GPP
Release 10 233 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: The behaviour of a mobile station that does not support "Network initiated MO call" is described in
clause 4.
5.2.3.1 Initiation
Before call establishment can be initiated in the mobile station, the MM connection shall be established by the network.
After the arrival of an appropriate stimulus (for example a Remote User Free Indication), the corresponding call control
entity in the network shall initiate the MM connection establishment according to clause 4, enter the "CC connection
pending" state and start timer T331. The request to establish the MM connection is passed from the CM sublayer to the
MM sublayer. It contains the necessary routing information derived from the received stimulus.
Upon completion of the MM connection, the call control entity of the mobile station shall send a START CC message to
its peer entity in the network. The mobile station shall then enter the "Wait for network information" state and start
timer T332.
If the network receives a START CC message while in the "CC connection pending" state, the network stops T331,
sends the CC-ESTABLISHMENT message, starts timer T333 and enters the "CC-establishment present" state.
The MM connection establishment may be unsuccessful for a variety of reasons, in which case the MM sublayer in the
network will inform the CC entity in the network with an indication of the reason for the failure. The CC entity shall
then stop all running timers, enter the "Null" state and inform all appropriate entities within the network.
If timer T331 expires, the network shall abort the MM connection establishment attempt, stop all running CC timers,
enter the "Null" state and inform all appropriate entities within the network.
The CC-ESTABLISHMENT message contains information which the mobile station shall use for the subsequent
SETUP message (if any) related to this CC-ESTABLISHMENT.
If no CC-ESTABLISHMENT message is received by the call control entity of the mobile station before the expiry of
timer T332, then the mobile station shall initiate clearing procedures towards the network using a RELEASE
COMPLETE message with cause #102 "recovery on timer expiry" and proceed in accordance with subclause 5.4.2.
Upon receipt of a CC-ESTABLISHMENT message the mobile station shall perform checks on the Setup Container IE
in order to align the contained information with the mobile's present capabilities and configuration. The "recall
alignment procedure" is defined later on in this subclause.
If the recall alignment procedure has succeeded, the call control entity of the Mobile Station shall:
- form and store the SETUP message for sending later in the "Recall present" state,
Exception:
A busy mobile station which has successfully performed the recall alignment procedure shall respond with a CC-
ESTABLISHMENT CONFIRMED message with cause #17 "user busy", and proceed as stated above.
For speech calls the mobile station shall indicate all codecs that it supports for UTRAN in the Supported Codec List
information element of the CC-ESTABLISHMENT CONFIRMED message. Codecs for GERAN shall be indicated in
3GPP
Release 10 234 3GPP TS 24.008 V10.6.1 (2012-03)
the Bearer Capability information element. Additionally, if the mobile station supports codecs for GERAN and
UTRAN, it shall indicate the codecs for GERAN also in the Supported Codec List information element.
A mobile station, for which the recall alignment procedure failed, shall respond with a RELEASE COMPLETE
message in accordance with subclause 5.4.2 with the appropriate cause code as indicated in the description of the recall
alignment procedure.
The SETUP message is constructed from the Setup Container IE received in the CC ESTABLISHMENT MESSAGE.
The mobile station shall assume that the Setup Container IE contains an entire SETUP message with the exception of
the Protocol Discriminator, Transaction ID and Message Type elements. The mobile station may assume that the
contents of the Setup Container IE are the same as were sent from the subscriber in a previous SETUP message of the
mobile originating call establishment attempt. The mobile station shall copy the Setup Container to the SETUP message
and not modify the contents except as defined in the recall alignment procedure and as defined in exceptions below. The
mobile station shall not add other Information Elements to the end of the SETUP message.
Exceptions:
Bearer Capability IE(s), HLC IE(s) and LLC IE(s) (including Repeat Indicator(s), if there are 2 bearer
capabilities), and the Supported Codec List IE require handling as described in the recall alignment procedure
below.
If the CC Capabilities in the Setup Container IE is different to that supported by the mobile station, the mobile
station shall modify the CC Capabilities in the SETUP message to indicate the true capabilities of the mobile
station.
Facility IE(s) and SS Version IE(s) require handling as described in the recall alignment procedure.
If no response to the CC-ESTABLISHMENT message is received by the call control entity of the network before the
expiry of timer T333, then the network shall initiate clearing procedures towards the called mobile station using a
RELEASE COMPLETE message with cause #102 "recovery on timer expiry" and inform all appropriate entities within
the network, proceeding in accordance with subclause 5.4.2.
The mobile station shall check that the Bearer Capability, HLC and LLC and Repeat Indicator fields, which are
embedded in the Setup Container IE, match a basic service group supported by the mobile station.
If this check fails, then the recall alignment procedure has failed. The mobile station shall use the cause #88
"incompatible destination" afterwards.
3GPP
Release 10 235 3GPP TS 24.008 V10.6.1 (2012-03)
Otherwise, the mobile station is allowed to alter the content within the Bearer Capability, HLC and LLC Information
Elements (e.g. the speech codec version(s), the data rate, the radio channel requirement) provided that the basic service
group is not changed. Furthermore, for speech calls the mobile station is allowed to add or remove the Supported Codec
List Information Element, or to alter the contents of this information element dependent on the codecs supported by the
mobile station. The result shall be that the mobile station has derived Bearer Capability, HLC, LLC, and Supported
Codec List Information Elements, which it can use for a later call setup according to its configuration and capabilities.
Facility alignment:
This only applies if the Setup Container contains 1 or more Facility IEs. Each Facility IE within the Setup
Container will be associated with the common SS Version IE, if present. The handling for each Facility IE is
defined below. The mobile station shall align each facility IE contained in the Setup Container. The rules defined
in 3GPP TS 24.010 [21] also apply.
The Facility IE is encoded as 'simple recall alignment', 'advanced recall alignment' or 'recall alignment not essential'
(see 3GPP TS 24.010 [21]). If the encoding indicates, that
- a simple recall alignment is required, the mobile station shall copy the Facility IE and the common SS version IE
from the Setup Container to the SETUP message without modifying the content.
- an advanced recall alignment is required, the mobile station must recognise and support the operation defined in
the facility. If the mobile station does not recognise or support the operation, then the recall alignment procedure
has failed and the mobile station shall use the cause #29 "facility rejected" in the subsequent rejection of the CC
establishment request.
- the recall alignment is not essential, then the facility operation is not an essential part of the SETUP. If the MS
does not recognise the operation then the SS Version IE and Facility IE are discarded, and NOT copied into the
SETUP message.
NOTE: A mobile station may include a Facility IE without an associated SS Version IE. This would indicate that
the SS operation is encoded using Phase 1 protocols.
The mobile station shall check whether the Stream Identifier field is contained in the Setup Container or not.
If the Stream Identifier is contained in the Setup Container, the mobile station shall behave as one of the following.
- the mobile station re-assign the Stream Identifier value, and modify the Stream Identifier field.
If the Stream Identifier is not contained in the Setup Container, the mobile station may behave as follows.
- the mobile station assign the Stream Identifier value, and add the Stream Identifier IE to the end of the SETUP
message.
For speech calls, if the ESTABLISHMENT CONFIRMED message contains a Supported Codec List information
element, the network shall use this list to select the codec for UMTS. If no Supported Codec List information element is
received, then for UMTS the network shall select the default UMTS speech codec according to subclause 5.2.1.11.
Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer
Capability information element is received, then for GERAN the network shall select GSM full rate speech version 1.
Codec information that does not apply to the currently serving radio access shall be used by the network if an inter-
system change occurs.
3GPP
Release 10 236 3GPP TS 24.008 V10.6.1 (2012-03)
In the "CC-establishment confirmed" state, the network sends a RECALL message. This message initiates user alerting
and also shall include the Facility IE (providing additional information to be presented to the user for notification). The
network starts timer T334 and enters the 'recall present' state.
Upon reception of the RECALL message the Mobile station stops T335 and enters the "recall present" state.
- entering the "call initiated" state and proceeding as described in subclause 5.2.1.1.
The MS shall ensure that the contents of the Bearer Capability IE(s) and Supported Codec List IE sent in the SETUP
message are the same as the Bearer Capability IE(s) and Supported Codec List IE in the previous CC-
ESTABLISHMENT CONFIRMED message related to this Network Initiated MO Call.
In the "recall-present" state, if the user of a mobile station is User Determined User Busy then a RELEASE
COMPLETE message shall be sent with cause #17 "user busy" In the "recall-present" state. If the user of a mobile
station wishes to reject the recall then a RELEASE COMPLETE message shall be sent with cause #21 "call rejected".
In either case, the mobile shall release the connection in accordance with subclause 5.4.2
On receipt of the SETUP message in the "recall present" state, the network shall stop timer T334 and proceed as
specified in subclause 5.2.1.2.
If the call control entity of the network does not receive a SETUP message before the expiry of timer T334, then the
network shall send a RELEASE COMPLETE message to the mobile using cause #102 "recovery on timer expiry",
release the MM connection, enter the "null" state and shall inform all appropriate entities within the network.
5.2.3.5 Traffic channel assignment during network initiated mobile originating call
establishment
It is a network dependent decision whether or not to initiate the assignment of a traffic channel during the "CC-
establishment confirmed" state.
3GPP
Release 10 237 3GPP TS 24.008 V10.6.1 (2012-03)
5.2.4.1 General
Before call establishment for SRVCC can be initiated in the mobile station, the MM connection must be established by
the network.
At PS to CS domain change from S1 mode or Iu mode due to SRVCC handover (see 3GPP TS 23.216 [126]), the RR
sublayer in the MS delivers the handover indication to the MM sublayer. At reception of the indication, the MS that
supports SRVCC shall establish an MM connection as specified in subclause 4.5.1.8.
If the MS supports single radio PS to CS access transfer for calls in alerting state as specified in 3GPP TS 24.237 [136]
subclause 12.2.3B, and the MS has a single voice media stream over the PS domain that is handed over to the CS
domain via SRVCC, and the call control entity in "null" state receives an indication "MM connection establishment due
to SRVCC handover", then:
- if the voice media stream is associated with a mobile originated session in the "early" state (defined in
IETF RFC 3261 [137]) according to the conditions specified in 3GPP TS 24.237 [136] subclause 12.2.3B.3.2,
the call control entity of the MS shall enter the "call delivered" state for this transaction. The MS and the
network shall locally set the TI value of the call to "000" and the TI flag value as in mobile originated call; and
- if the voice media stream is associated with a mobile terminating session in the "early" state (defined in
IETF RFC 3261 [137]) according to the conditions specified in 3GPP TS 24.237 [136] subclause 12.2.3B.3.1,
the call control entity of the MS shall enter the "call received" state for this transaction. The MS and the network
shall locally set the TI value of the call to "000" and the TI flag value as in mobile terminated call.
If the MS has additional voice media streams carried over the PS domain that are handed over to the CS domain via
SRVCC, the state for the transactions and the setting of the TI value and TI flag for these additional media streams is
described in 3GPP TS 24.237 [136].
If the MS supports multicall, the MS shall locally set SI value to 1 and the MS shall assume that the network does not
support multicall. The network shall also locally set SI value to 1.
For SRVCC handover, the mobile station shall attach the user connection when the call control entity enters any one of
the following states:
- "active" state;
3GPP
Release 10 238 3GPP TS 24.008 V10.6.1 (2012-03)
The mobile originating notification procedure allows the mobile station to notify the remote user of any appropriate
call-related event during the "active" state of a call by sending a NOTIFY message containing a notification indicator to
the network; upon receipt of this message, the network sends a NOTIFY message containing the same notify indicator
to the other user involved in the call. No state change occurs at any of the interface sides following the sending or the
receipt of this message.
If the negotiation during call establishment leads to the recognition of the above mentioned services, the in-call
modification procedure is allowed to be executed within the current call by changing from one call mode to the other.
In some cases the in-call modification procedure makes it necessary to change the channel configuration by allocating a
new channel and in other cases to change channel configuration parameters while keeping the previously allocated
channel. This change is determined by the network, which initiates either the channel assignment procedure, handover
procedure or channel mode modify procedure (see clause 3).
The capability and the initial mode desired must be identified by the mobile station by identifying each mode of
operation with a separate information element during call establishment. Further the type of change between the modes
must be identified by means of the repeat indicator:
3GPP
Release 10 239 3GPP TS 24.008 V10.6.1 (2012-03)
A low layer compatibility may optionally be specified for each call mode in a low layer compatibility I and low layer
compatibility II information element. In that case:
- the SETUP message shall contain the LLC repeat indicator IE and both low layer compatibility I and low layer
compatibility II information elements. The low layer compatibility I information element then corresponds to the
bearer capability 1 information element and the low layer compatibility II information element to the bearer
capability 2 information element;
- if no low layer compatibility specification applies for one of the two call modes, the corresponding low layer
compatibility IE (low layer compatibility I or low layer compatibility II) shall indicate "not applicable";
- the LLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE.
Similarly, a high layer compatibility may optionally be specified for each call mode in a high layer compatibility i and
high layer compatibility ii information element. In that case:
- the SETUP message shall contain the HLC repeat indicator IE and both high layer compatibility i and high layer
compatibility ii information elements. The high layer compatibility i information element then corresponds to the
bearer capability 1 information element and the high layer compatibility ii information element to the bearer
capability 2 information element;
- if no high layer compatibility specification applies for one of the two call modes, the corresponding high layer
compatibility IE (high layer compatibility i or high layer compatibility ii) shall indicate "not applicable";
- the HLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE.
The receiving entity shall ignore whether the LLC repeat indicator IE or HLC repeat indicator are contained in the
message or not; it shall also ignore the repeat indication of an LLC repeat indicator IE or HLC repeat indicator IE. If
the low layer compatibility II IE is not contained in the message and the low layer compatibility I IE is contained in the
message, the receiving entity shall relate it to a call mode indicated in the message that does not specify speech (if any).
If the high layer compatibility ii IE is not contained in the message and the high layer compatibility i IE is contained in
the message, the receiving entity shall relate it to a call mode indicated in the message that does not specify speech (if
any).
The specific part of the network which is sensitive to the call mode shall examine each mode described in the bearer
capabilities included in the SETUP message by performing compatibility checking as defined in Annex B. If as a result
of this compatibility checking the network decides to reject the call, then the network shall initiate call clearing as
specified in subclause 5.4 with the following causes:
3GPP
Release 10 240 3GPP TS 24.008 V10.6.1 (2012-03)
The destination mobile station shall perform the compatibility checking as defined in Annex B for both required modes
if indicated in the SETUP message. If as a result of compatibility checking the mobile station decides to reject the call,
the mobile station shall initiate call clearing according to the procedures of subclause 5.4 with one of the following
causes:
The mobile station may accept the call if the first mode indicated is free irrespective of whether the other mode is free
or busy.
Either side of the radio interface may act as the requesting user to invoke the in-call modification.
Upon each successful completion of the in-call modification procedure, the call changes to the next mode negotiated
and agreed during the establishment phase of the call.
The in-call modification procedures are completely symmetrical at the radio interface.
If the in-call modification is originated by the mobile station, the mobile station shall reserve any internal resources
necessary to support the next call mode, stop sending Bm-channel information; and stop interpreting received Bm-
channel information according to the old call mode.
If the in-call modification is originated by the network, the network may reserve any internal resources necessary to
support the next call mode. The network shall stop sending Bm-channel information and stop interpreting received Bm-
channel information according to the old call mode at the latest when it changes the channel configuration.
Upon receipt of the MODIFY message, the destination side shall check to ensure that the requested call mode can still
be supported and if so, it shall initiate the reservation of any resources necessary to support the next call mode; start
T324 (mobile station side only) if the in-call modification procedure is triggered as a result of a service change from
speech to UDI/RDI multimedia modes; and enter the "mobile originating modify" (network side) or "mobile terminating
modify" state (mobile station side).
If the requested mode is speech and if during call establishment the network received a Supported Codec List IE, the
network shall use this list to select the codec for UTRAN. If no Supported Codec List information element is received,
then for UTRAN the network shall select the default UMTS speech codec according to subclause 5.2.1.11.
Codecs for GERAN shall be selected from the codecs indicated in the Supported Codec List information element or in
the Bearer Capability information element. If neither a Supported Codec List information element nor a Bearer
Capability information element is received, then for GERAN the network shall select GSM full rate speech version 1.
3GPP
Release 10 241 3GPP TS 24.008 V10.6.1 (2012-03)
If the Supported Codec List IE is received, then the network shall indicate the codec selected for Iu mode to the mobile
station via RANAP and RRC protocol in the NAS Synchronisation Indicator IE (see subclause 5.2.1.11).
If the in-call modification was originated by the mobile station, the mobile station and the network shall proceed as
follows:
If the requested mode is not the actual one and can be supported by the network it shall change the channel
configuration, if required, and step on to any internal resources necessary to support the next call mode. If the
requested mode is a data or facsimile mode, it shall also perform the appropriate means to take the direction of
the data call into account. After successful change of the channel configuration it shall start sending user
information according to the next call mode and start interpreting received user channel information according to
the next call mode; send a MODIFY COMPLETE message with the new call mode included and enter the
"active" state (network side). If the MODIFY message had contained a reverse call setup direction IE, the same
IE shall be included in the MODIFY COMPLETE message.
Upon receipt of the MODIFY COMPLETE message the mobile station shall: initiate the alternation to those
resources necessary to support the next call mode; stop timer T323; and enter the "active" state (mobile station
side).
If the in-call modification was originated by the network, the mobile station and the network shall proceed as follows:
If the requested mode is not the actual one and can be supported by the mobile station it shall reserve any
internal resources necessary to support the next call mode.
NOTE: For a change from speech to a different call mode, user interaction may be required, before the mobile
decides that the requested mode can be supported.
If the requested mode is a data or facsimile mode, it shall also perform the appropriate means to take the
direction of the data call into account. The mobile station shall send a MODIFY COMPLETE message with the
new call mode included, stop timer T324 and enter the "active" state (mobile station side). If the MODIFY
message had contained a reverse call setup direction IE, the same IE shall be included in the MODIFY
COMPLETE message. If the old call mode is speech, the mobile station shall continue sending Bm-channel
information and interpreting received Bm-channel information for speech until the network modifies its channel
configuration.
After receipt of the MODIFY COMPLETE message the network shall: reserve any internal resources necessary
to support the next call mode, stop sending Bm-channel information, and stop interpreting received Bm-channel
information according to the old call mode, unless these actions were already performed earlier. Furthermore, the
network shall change the channel configuration, if required; after successful change of the channel configuration
initiate the alternation to those resources necessary to support the next call mode; stop timer T323; and enter the
"active" state (network side).
The mobile station shall start sending user information according to the next call mode and start interpreting
received user channel information according to the next call mode as soon as a suitable channel for the new
mode is available.
In both cases:
For an alternate speech/facsimile group 3 service (refer to subclause 5.3.4) the old resources may still be kept
reserved.
The reaction of the originating side if it had included a reverse call setup direction IE in the MODIFY message,
but the destination side did not include the IE in the MODIFY COMPLETE message is implementation
dependent.
3GPP
Release 10 242 3GPP TS 24.008 V10.6.1 (2012-03)
If the network cannot support the change to the requested call mode or if the change of the channel configuration fails
the network shall: release the resources which had been reserved for the alternation: send a MODIFY REJECT message
with the old bearer capability and with cause # 58 "bearer capability not presently available" to the initiating mobile
station; and enter the "active" state. If the change of the channel configuration fails, the network shall return to the
internal resources required for the old call mode.
Upon receipt of the MODIFY REJECT message with the old bearer capability the initiating mobile station shall: stop
timer T323; release any resources which had been reserved for the alternation; resume sending user channel information
according to the present call mode; resume interpreting received user channel information according to the present call
mode; and enter the "active" state.
If the mobile station cannot support the change to the requested call mode, the mobile station shall: stop timer T324;
release any resources which had been reserved for the alternation; send a MODIFY REJECT message with the old
bearer capability and cause # 58 "bearer capability not presently available", and enter the "active" state.
Upon receipt of the MODIFY REJECT message the network shall: stop timer T323, release any resources which had
been reserved for the alternation.
Upon expiration of T323 in either the mobile station or the network the procedures for call clearing shall be initiated
(see subclause 5.4) with cause # 102 "recovery on timer expiry".
Upon expiration of T324 the mobile station shall: release any resources which had been reserved for the alternation;
send a MODIFY REJECT message with the old bearer capability and cause #58 "bearer capability not presently
available"; and enter the "active" state.
If a MODIFY COMPLETE message indicating a call mode which does not correspond to the requested one is received
or if a MODIFY REJECT message indicating a call mode which does not correspond to the actual one is received then
the received message shall be discarded and no action shall be taken.
If a MODIFY message indicating a call mode which does not belong to those negotiated and agreed during the
establishment phase of the call, is received, then a MODIFY REJECT message with the actual call mode and with cause
# 57 "bearer capability not authorized" shall be sent back.
3GPP
Release 10 243 3GPP TS 24.008 V10.6.1 (2012-03)
5.3.5 User initiated service level up- and downgrading (A/Gb mode and
GERAN Iu mode only)
The user initiated service level up- and downgrading is applicable for non-transparent multislot data services, only. By
means of this procedure the user can request a change of the "maximum number of traffic channels" and/or "wanted air
interface user rate" parameters, to be assigned by the network.
- send a MODIFY message including the wanted value of the "maximum number of traffic channels" and/or the
"wanted air interface user rate" parameters;
- not change any of the other, possibly negotiated, parameters of the bearer capability information element;
Any internal resources necessary to support the next service parameters shall be reserved. If a dual service was
negotiated at call setup, the mobile station shall initiate the service level up- or down-grading only during the data phase
of the dual service.
Upon receipt of the MODIFY message, the network shall check if the indicated maximum number of traffic channels
can be supported and enter the "mobile originating modify" state.
As a response to the MODIFY message the network sends a MODIFY COMPLETE message including the bearer
capability negotiated at call setup and enters the "active" state.
Upon receipt of the MODIFY COMPLETE message the mobile station shall stop timer T323 and enter the "active"
state.
- send a MODIFY REJECT message with bearer capability negotiated at call setup and with cause #58 "bearer
capability not presently available";
3GPP
Release 10 244 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of the MODIFY REJECT message with the bearer capability negotiated at call setup, the mobile station
shall: stop timer T323 and enter the "active" state.
At the multimedia call setup the required call type, 3G-324M, is indicated, for the network to be able to invoke
appropriate interworking functionality. In the peer end the H.324 information is used to invoke the terminal application.
In addition to H.324 indication the terminal must select Information Transfer Capability (ITC) for the multimedia call.
The 'correct' ITC depends on the peer end and the transporting networks; an all-ISDN call is a UDI/RDI call, and a call,
which involves PSTN, is an analog "3.1 kHz audio" call.
For the case when the setup of a multimedia call is not successful, fallback to speech is specified.
Users may also request a service change between UDI/RDI multimedia and speech modes during a call (see 3GPP TS
23.172 [97]).
For further description of the function of MSC/IWF in the following clauses, see 3GPP TS 29.007 [38].
For analogue multimedia, the support of a fallback to speech is requested by including two bearer capability IEs,
multimedia first and speech as the second BC in the SETUP message. The MS shall indicate fallback to speech by these
two BC IEs and the associated Repeat Indicator set to "support of fallback".
For UDI/RDI multimedia, the support of a fallback and service change is requested by including two bearer capability
IEs, with the first BC as the preferred service in the SETUP message. The MS shall indicate service change and fallback
by these two BC IEs and the associated Repeat Indicator set to "support of service change and fallback".
If the bearer capability IE is received from the MS either in A/Gb or GERAN Iu mode and indicates no A/Gb mode
support for the requested bearer service, the network shall consider it as a request to perform an inter-system handover
to UTRAN Iu mode, as described in 3GPP TS 23.009 [114] subclause 14.2.
If the MS requested for an analogue multimedia call with fallback to speech, or for a UDI/RDI multimedia call with
fallback and service change, and the network accepts the call, the network has the following options for the inclusion of
bearer capability IEs in the CALL PROCEEDING message:
- if the network accepts the requested analogue multimedia call and supports fallback to speech, both multimedia
and speech bearer capability IEs shall be included;
- if the network accepts the requested UDI/RDI multimedia call and supports fallback and service change, both
multimedia and speech bearer capability IEs shall be included. The order of the bearer capability IEs determines
3GPP
Release 10 245 3GPP TS 24.008 V10.6.1 (2012-03)
the preferred service, and the network may reverse the order of these IEs (see 3GPP TS 23.172 [97],
subclause 4.2.1);
- if the network accepts a multimedia (only) call, a multimedia bearer capability IE shall be included;
- if the network accepts a speech (only) call, a speech bearer capability IE shall be included;
- for a UDI/RDI multimedia call, if the network accepts the requested speech call and supports service change,
both multimedia and speech bearer capability IEs shall be included. The order of the bearer capability IEs
determines the preferred service, and the network may reverse the order of these IEs (see 3GPP TS 23.172 [97],
subclause 4.2.1);
- if the network received a UDI/RDI multimedia bearer capability IE with FNUR equal to 32kbit/s and a speech
bearer capability IE in the SETUP message, the network shall not release the call, but shall reply with one
bearer capability IE only, as specified in 3GPP TS 23.172 [97].
NOTE: Service change and fallback for UDI/RDI multimedia calls is not supported with Fixed Network User
Rate set to 32 kbit/s (see 3GPP TS 23.172 [97]).
If the MS requested for a multimedia call only, and the network accepts the call, the network shall always include a
single multimedia bearer capability IE in the CALL PROCEEDING message.
The originating user shall determine (possibly by pre-configuration of the terminal) whether a digital connection is
required or if the call will be an analog modem call. If the call is expected to be digital the multimedia bearer capability
IE parameter ITC is set to UDI/RDI. In an analog call the multimedia bearer capability IE parameter ITC is set to
"3,1 kHz audio ex PLMN". Additionally required modem type is indicated (Other Modem Type = V.34).
5.3.6.2.1.1 Fallback
If the network, during the setup of an H.324-call, detects that the transit network or the called end does not support an
H.324 call (e.g. because of a failure in the modem handshaking in case of an analogue multimedia call), then the
network initiates the in-call modification procedure (see subclause 5.3.4.3) towards the MS to modify the call mode to
speech, if the MS had included a speech bearer capability IE in the SETUP message.
In case of a UDI/RDI multimedia call with service change and fallback, if the network detects that the called end does
not support speech, then it initiates an in-call modification procedure towards the MS to modify the call mode to
multimedia, if the first bearer capability IE was for a speech call.
For analogue multimedia, if the network supports fallback to speech and the subscriber has subscription to speech, two
bearer capability IEs, multimedia first and speech as the second BC are included in the SETUP message. The network
shall indicate fallback to speech by these two BC IEs and the associated Repeat Indicator set to "support of fallback".
For UDI/RDI multimedia, if the network supports fallback and service change, and the subscriber has subscription to
speech, two bearer capability IEs, with the first BC as the preferred service are included in the SETUP message. The
network shall indicate service change and fallback by these two BC IEs and the associated Repeat Indicator set to
"service change and fallback".
If the bearer capability IE is received from the MS either in A/Gb or GERAN Iu mode and indicates no A/Gb mode
support for the requested bearer service, the network shall consider it as a request to perform an inter-system handover
to UTRAN Iu mode, as described in 3GPP TS 23.009 [114] subclause 14.2.
The bearer capability IE(s) may (in the case of the single numbering scheme) be missing from the SETUP message.
The MS shall indicate the supported call type(s) in the CALL CONFIRMED message, which is the acknowledgement to
SETUP. If the network offered an analogue multimedia call with fallback to speech, or a UDI/RDI multimedia call with
3GPP
Release 10 246 3GPP TS 24.008 V10.6.1 (2012-03)
fallback and service change, the MS has the following options for the inclusion of bearer capability IEs in the CALL
CONFIRMED message:
- if the MS/user accepts the offered analogue multimedia call and supports fallback to speech, both multimedia
and speech bearer capability IEs shall be included;
- if the MS/user accepts the offered UDI/RDI multimedia call, and supports fallback and service change, both
multimedia and speech bearer capability IEs shall be included. The order of the BC IEs determines the preferred
service, and the MS/user may reverse the order of these IEs;
- if the MS/user accepts the offered multimedia call, but does not support fallback or service change, only a
multimedia bearer capability IE shall be included;
- if the MS/user wishes a speech (only) call a speech bearer capability IE is included;
- for a UDI/RDI multimedia call, if the MS/user accepts the offered speech call and supports service change, both
speech and multimedia bearer capability IEs shall be included. The order of the BC IEs determines the preferred
service, and the MS/user may reverse the order of these IEs.
If the network offered a multimedia call only, and the MS/user accepts the call, the MS shall always include a single
multimedia bearer capability IE in the CALL CONFIRMED message.
If the SETUP contained no bearer capability IE the network shall perform compatibility checking of the CALL
CONFIRMED message in the same way as the compatibility checking of the SETUP message in the mobile originating
call case, described in subclause 5.3.6.2.1.
If modem handshaking fails (in a modem call), the call mode will be modified to speech if a speech bearer capability
IE was included. The modem signalling is inband, so the call must have reached the active state, when these
conclusions about the presence of modems can be done. The call modifications are realized through the in-call
modification procedure, by which the network requests the MS to modify the call mode (see subclause 5.3.4.3).
NOTE: Fallback from digital (UDI) H.324-call to speech after call setup is not a valid case at the terminating
side.
- trigger a service change between speech and UDI/RDI multimedia modes, when service change has been agreed
at call setup;
- trigger a network-initiated service upgrade from speech to UDI/RDI multimedia modes (see
3GPP TS 23.172 [97]). The network shall initiate this procedure only if the mobile station indicated support of
the enhanced network-initiated in-call modification procedure in the Call Control Capabilities IE at call
establishment. In this case, the MODIFY message shall include the Network-initiated Service Upgrade indicator
IE; or
- modify the multimedia bearer capability for an analogue multimedia call (restricted to the network initiated in-
call modification only). In this case, the network shall send a MODIFY message including the new Bearer
Capability to be changed to. The following bearer capability parameters can be modified with the procedure (see
3GPP TS 29.007 [38]):
3GPP
Release 10 247 3GPP TS 24.008 V10.6.1 (2012-03)
5.3.6.3.1 Void
5.3.6.3.2 Void
5.3.6.3.3 Void
5.3.6.3.3.1 Void
5.3.6.3.3.2 Void
5.3.6.4 Multimedia CAT during the alerting phase of a mobile originated call
A mobile station supporting multimedia CAT during the alerting phase of a mobile originated multimedia call
establishment shall indicate support of this capability to the network in the Call Control Capabilities information
element in the SETUP message.
The network may generate a multimedia CAT to such a mobile station before it has reached the "active" state of a call.
To do so, the network shall through connect the traffic channel towards the source of the multimedia CAT and send a
progress indicator IE indicating user attachment with progress description #9 "In-band multimedia CAT available" in
either an ALERTING message or a PROGRESS message that is sent to the mobile station during call establishment.
On reception of an ALERTING or a PROGRESS message the mobile station shall proceed as specified elsewhere in
clause 5; if the progress indicator IE indicated user attachment with progress description #9 "In-band multimedia CAT
available", the mobile station shall:
- attach the user connection for multimedia as soon as an appropriate channel in multimedia mode is available; and
It is up to the network to ensure that no undesired end-to-end through connection with the called party takes place
during the establishment of a mobile terminated call.
The mobile station shall not abort the call if an error or H.324 call clearing occurs during the setup or the lifetime of the
H.324 call during the alerting phase; the call control entity of the calling mobile station shall remain in its current state.
Upon reception of a new request from the network to attach the user connection with progress description #9 "In-band
multimedia CAT available", the mobile station shall release any on-going H.324 call, and set up a new H.324 call.
NOTE: The network can request the mobile station to restart a new H.324 call during the alerting phase of the call
e.g. during call forwarding scenarios to transmit to the calling party the multimedia CAT of the
forwarded-to party.
The network may initiate the in-call modification procedure (see subclause 5.3.4.3) towards the MS in the "call
delivered" state to modify the call mode to speech, if service change has been agreed at call setup.
Upon receiving an indication that the call has been accepted, the call control entity of the network shall send a
CONNECT message to its peer entity at the calling mobile station; start timer T313 and enter the "connect indication"
state. This message indicates to the call control entity of the calling mobile station that a connection has been
established through the network.
On reception of a CONNECT message, the mobile station shall proceed as specified elsewhere in clause 5; the mobile
station shall release any on-going H.324 call and set up a new H.324 call towards the called party.
Mobile stations supporting multimedia CAT during the alerting phase of a mobile originated multimedia call
establishment should also support the Media Oriented Negotiation Acceleration procedures specified in ITU-
T H.324 annex K (see [117] and [118]).
3GPP
Release 10 248 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: DTMF can be used to convey to the network the end user request to stop or copy an on-going multimedia
CAT.
- A traffic channel (see 3GPP TS 44.003 [16]) is "connected" when the channel is part of a circuit-switched
connection established according to the present document.
- A traffic channel is "disconnected" when the channel is no longer part of a circuit-switched connection, but is not
yet available for use in a new connection.
As an exception to the above rule, the call control entity of the mobile station or of the network, in response to a SETUP
or START CC or CC-ESTABLISHMENT CC-ESTABLISHMENT CONFIRMED or RECALL message, can reject a
call by stopping all running call control timers, responding with a RELEASE COMPLETE message, releasing the MM
connection, and returning to the "null" state, provided no other response has previously been sent.
As a further exception, the call control entity of the network may initiate call clearing by stopping all running call
control timers, sending a RELEASE message, starting timer T308, and entering the "release request" state.
NOTE: This way to initiate call clearing by sending a RELEASE message should not be used by the network:
- if in-band tones/announcements are provided and the network decides to use the procedure described
in subclause 5.4.4.1.1.1 or 5.4.4.2.1;
- if the network wants to have the opportunity to respond to information sent by the mobile station
during call clearing, e.g. when the network indicates that "CCBS activation is possible".
A call control entity shall accept an incoming RELEASE COMPLETE message used to initiate the call clearing even
though the cause information element is not included.
A control entity shall accept an incoming RELEASE message used to initiate the call clearing even though the cause
information element is not included.
Furthermore, a call control entity shall regard an incoming RELEASE COMPLETE message as consistent with any of
its states; a call control entity shall regard an incoming RELEASE message as consistent with any of its states except
the null state: a call control entity of the mobile station shall regard an incoming DISCONNECT message as consistent
with any of its call control states except the "null" state, the "release request" state, and the "disconnect indication" state;
a call control entity of the network shall regard an incoming DISCONNECT message as consistent with any of its call
control states except the "null" state and the "release request" state.
NOTE: This allows the introduction of shorter call clearing procedures in the future.
3GPP
Release 10 249 3GPP TS 24.008 V10.6.1 (2012-03)
- initiate procedures to clear the network connection and the call to the remote user;
NOTE: The RELEASE message has only local significance and does not imply an acknowledgement of clearing
from the remote user.
The call control entity of the network in the "release request" state, shall, at first expiry of timer T308, retransmit the
RELEASE message, start timer T308, and stay in the "release request" state. At second expiry of timer T308, the call
control entity of the network shall: release the MM connection; and return to the "null" state.
NOTE: When the network initiates clearing by sending a RELEASE message, the procedures described in
subclauses 5.4.3., 5.4.3.4 and 5.4.3.5 are followed.
A mobile station that does not support the "Prolonged Clearing Procedure" shall comply with the requirements of
subclause 5.4.4.1 and shall ignore subclause 5.4.4.2. A mobile station that supports the "Prolonged Clearing Procedure"
shall comply with the requirements of subclauses 5.4.4.2 and shall ignore subclause 5.4.4.1.
5.4.4.1 Clearing initiated by the network: mobile does not support "Prolonged
Clearing Procedure"
Sublause 5.4.4.1 only applies to mobile stations that do not support the "Prolonged Clearing Procedure" option.
3GPP
Release 10 250 3GPP TS 24.008 V10.6.1 (2012-03)
5.4.4.1.1.1 Receipt of a DISCONNECT message with progress indicator #8 from the network
The call control entity of the MS in any state except the "null" state, the "disconnect indication" state, and the "release
request" state, shall, upon receipt of a DISCONNECT message with progress indicator #8:
i) if an appropriate speech traffic channel is not connected, continue clearing as defined in subclause 5.4.4.1.2.1
without connecting to the in-band tone/announcement;
ii) if an appropriate speech traffic channel is connected, attach the user connection for speech if it is not yet attached
and enter the "disconnect indication" state. In that state, if upper layers request the clearing of the call, the call
control entity of the MS shall proceed as defined in subclause 5.4.4.1.2.1.
The call control entity of the network, having entered the "disconnect indication" state after sending a disconnect
message with the progress indicator #8, shall, upon expiry of timer T306, continue clearing by sending a RELEASE
message with the cause number originally contained in the DISCONNECT message; starting timer T308; and entering
the "release request" state.
The call control entity of the mobile station in any state except the "null" state, the "disconnect indication" state, and the
"release request" state, shall, upon the receipt of a DISCONNECT message without progress indicator information
element or with progress indicator different from #8:
The call control entity of the network in any state except the "null" state and the "release request" state, shall, upon
receipt of a RELEASE message: stop all running call control timers; send a RELEASE COMPLETE message; release
the MM connection; and return to the "null" state.
The call control entity of the network, having entered the "disconnect indication" state after sending a DISCONNECT
message without progress indicator or with progress indicator different from #8, shall upon expiry of timer T305: send a
RELEASE message to the mobile station with the cause number originally contained in the DISCONNECT message;
start timer T308; and enter the "release request" state. In addition to the original clearing cause, the RELEASE message
may contain a second cause information element with cause #102 "recovery on timer expiry".
3GPP
Release 10 251 3GPP TS 24.008 V10.6.1 (2012-03)
The call control entity of the mobile station in the "release request" state shall at first expiry of timer T308 retransmit
the RELEASE message and restart timer T308. At second expiry of timer T308, the call control entity of the mobile
station shall: release the MM connection; and return to the "null" state.
5.4.4.2.1 Clearing when tones/announcements provided and the network does not indicate
that "CCBS activation is possible"
When in-band tones/announcements are provided (see subclause 5.5.1) and CCBS is not applicable, the call control
entity of the network may initiate clearing by sending a DISCONNECT message containing progress indicator #8 "in-
band information or appropriate pattern now available", either not containing an Allowed Actions IE or containing an
Allowed Actions IE indicating "CCBS activation is not possible", starting timer T306, and entering the "disconnect
indication" state.
The call control entity of the MS in any state except the "null" state, the "disconnect indication" state, and the "release
request" state, shall, upon receipt of a DISCONNECT message with progress indicator #8 and, either not containing an
Allowed Actions IE or containing an Allowed Actions IE indicating "CCBS activation is not possible":
ii) if an appropriate speech traffic channel is connected, attach the user connection for speech if it is not yet attached
and enter the "disconnect indication" state. In that state, if upper layers request the clearing of the call, the call
control entity of the MS shall:
The call control entity of the network, having entered the "disconnect indication, shall, upon expiry of timer T306,
continue clearing by sending a RELEASE message with the cause number originally contained in the DISCONNECT
message; starting timer T308; and entering the "release request" state.
3GPP
Release 10 252 3GPP TS 24.008 V10.6.1 (2012-03)
5.4.4.2.2 Clearing when the network indicates that "CCBS activation is possible"
When Activation of CCBS is possible, the call control entity of the network may initiate clearing by sending a
DISCONNECT message containing the Allowed Actions IE with an indication that "Activation of CCBS is possible"
and starting T338. Optionally, progress indicator #8 "in-band information or appropriate pattern now available" may
also be contained in the DISCONNECT message (in which case, T338 shall not be greater than T306).
- The call control entity of the MS in the "null" state, the "disconnect indication" state and the "release request"
state, shall, upon receipt of a DISCONNECT message react as described in clause 8.
- The call control entity of the MS in the "disconnect request" state, shall, upon receipt of a DISCONNECT
message:
- The call control entity of the MS in any other states, shall, upon receipt of a DISCONNECT message with an
Allowed Actions IE indicating "Activation of CCBS is possible" pass the "Activation of CCBS is possible"
indication to the upper layer, enter the "disconnect indication" state, stop all running call control timers and await
a response from the upper layers.
If the DISCONNECT message contained the progress indicator #8 "in-band information or appropriate pattern now
available" and an appropriate speech traffic channel is connected, then the MS shall attach the user connection for
speech if it is not yet attached. If the DISCONNECT message did not contain the progress indicator #8 "in-band
information or appropriate pattern now available" any connected speech traffic channel shall be disconnected.
i) If the upper layers request the clearing of the call, the call control entity of the MS shall:
ii) If the upper layers request that the "CCBS activation is to be attempted" then the MS shall
If an appropriate speech traffic channel is connected, transmission of this RELEASE message shall not cause it
to be disconnected.
The call control entity of the network, having entered the "disconnect indication" state after sending a DISCONNECT
message with an Allowed Actions IE indicating "Activation of CCBS is possible" shall, upon expiry of timer T338,
3GPP
Release 10 253 3GPP TS 24.008 V10.6.1 (2012-03)
continue clearing by sending a RELEASE message with the cause number originally contained in the DISCONNECT
message; starting timer T308; and entering the "release request" state.
5.4.4.2.3 Clearing when tones/announcements are not provided and the network does not
indicate that "CCBS activation is possible"
When in-band tones and announcements are not provided, and, the network does not wish to indicate in the Allowed
Actions IE that "CCBS is possible", the call control entity of the network shall initiate call clearing by stopping all
running call control timers, sending a DISCONNECT message without progress indicator, either without the Allowed
Actions IE or with the Allowed Actions IE indicating that "CCBS is not possible", starting timer T305 and entering the
"disconnect indication" state.
The call control entity of the mobile station in any state except the "null" state, the "disconnect indication" state, and the
"release request" state, shall, upon the receipt of a DISCONNECT message either without progress indicator
information element or with progress indicator different from #8, and, either without the Allowed Actions IE or with the
Allowed Actions IE indicating that "CCBS is not possible":
The call control entity of the network, having entered the "disconnect indication", shall upon expiry of timer T305: send
a RELEASE message to the mobile station with the cause number originally contained in the DISCONNECT message;
start timer T308; and enter the "release request" state.
For a network that does not support the "CCBS activation" option:
The call control entity of the network in any state except the "null" state and the "release request" state, shall,
upon receipt of a RELEASE message: stop all running call control timers; send a RELEASE COMPLETE
message; release the MM connection; and return to the "null" state.
The call control entity of the network in any state except the "null" state and the "release request" state, shall,
upon receipt of a RELEASE message without a Facility IE including an Invoke=CCBSRequest: stop all running
call control timers; send a RELEASE COMPLETE message; release the MM connection; and return to the "null"
state.
For a network that does not support the "CCBS activation" option:
The call control entity of the network in any state except the "null" state and the "release request" state, shall,
upon receipt of a RELEASE message: stop all running call control timers; send a RELEASE COMPLETE
message; release the MM connection; and return to the "null" state.
The call control entity of the network in any state except the "null" state and the "release request" state, shall,
upon receipt of a RELEASE message containing a Facility IE including an Invoke=CCBSRequest: stop all
running call control timers; then attempt to activate the recall; then send a RELEASE COMPLETE message
3GPP
Release 10 254 3GPP TS 24.008 V10.6.1 (2012-03)
indicating the success or failure of the recall activation attempt; release the MM connection; and return to the
"null" state.
The call control entity of the mobile station in the "release request" state shall at first expiry of timer T308 retransmit
the RELEASE message and restart timer T308. At second expiry of timer T308, the call control entity of the mobile
station shall: release the MM connection; and return to the "null" state.
The retransmitted RELEASE message need not contain the Facility IE including an Invoke=CCBSRequest, even if the
original RELEASE message did contain this IE.5.4.5Clear collision
Clear collision occurs when both the mobile station and the network simultaneously transfer DISCONNECT messages
specifying the same call.
The behaviour of the network call control entity receiving a DISCONNECT message whilst in the "disconnect
indication" state is specified in subclause 5.4.3. The behaviour of the MS call control entity receiving a DISCONNECT
message whilst in the "disconnect request" state is defined in subclause 5.4.4.
Clear collision can also occur when both sides simultaneously transfer RELEASE messages related to the same call.
The entity receiving such a RELEASE message whilst within the "release request" state shall: stop timer T308; release
the MM connection; and enter the "null" state (without sending a RELEASE COMPLETE message).
- Either it includes the IE in a SETUP, CALL PROCEEDING, ALERTING, or CONNECT message that is send
during call establishment
A progress indicator IE indicates user attachment if it specifies a progress description in the set {1, 2, 3} or in the set
{6, 7, 8, ..., 20}.
On reception of a SETUP, CALL PROCEEDING, ALERTING, CONNECT, or PROGRESS message the mobile station
shall proceed as specified elsewhere in clause 5; if the progress indicator IE indicated user attachment and a speech
mode traffic channel is appropriate for the call the mobile station shall in addition: attach the user connection for speech
as soon as an appropriate channel in speech mode is available. (If a new order to attach the user connection is received
before the attachment has been performed, the new order shall supersede the previous one.)
Under certain conditions the MS will have to attach the user connection before the CONNECT message. It is up to the
network to ensure that no undesired end-to-end through connection takes place during the establishment of a MT call.
NOTE: This allows the use of progress indicator IEs independently from the channel modes appropriate for the
call.
3GPP
Release 10 255 3GPP TS 24.008 V10.6.1 (2012-03)
The network may generate multimedia CAT to a mobile station supporting multimedia CAT during the alerting phase of
a mobile originated multimedia call establishment as specified in subclause 5.3.6.4.
NOTE: This may, in particular, apply to procedural error conditions described in clause 8.
A call control entity initiates the status enquiry procedure by sending the STATUS ENQUIRY message and starting
timer T322. While timer T322 is running, the call control entity shall not send further STATUS ENQUIRY messages.
Upon receipt of a STATUS ENQUIRY message, the receiver shall respond with a STATUS message, reporting the
current call state and cause value #30 "response to STATUS ENQUIRY". Receipt of the STATUS ENQUIRY shall not
result in a state change relating to any protocol and connection of the receiver.
If a STATUS message is received that contains cause value #30 "response to status enquiry", timer T322 shall be
stopped and further appropriate actions taken, based on the information in that STATUS message, relative to the current
state of the receiver of the STATUS message. These further "appropriate actions" are implementation dependent.
However, the actions prescribed in subclause 5.5.3.2 shall apply.
If a clearing message is received while timer T322 is running, timer T322 shall be stopped, and call clearing shall
continue.
If timer T322 expires, the STATUS ENQUIRY message may be retransmitted maximally once. If T322 expires after the
STATUS ENQUIRY has been transmitted the maximum number of times, clearing of the call shall be initiated with
cause value #41, "temporary failure", in the first call clearing message.
3GPP
Release 10 256 3GPP TS 24.008 V10.6.1 (2012-03)
This indicates that the transmitter of the STATUS message was unable to accept some information sent by the recipient
of the STATUS message. This allow the recipient to retransmit some or all of the information. Other actions are possible
and are implementation dependent; they may include releasing the call.
In the case the MS receives a STATUS message with the cause #100 due to the presence of a Repeat Indicator with the
value “service change and fallback” in a SETUP message, it may then resend a new SETUP message with a single BC-
IE (no Repeat Indicator is included). The actual behaviour is dependent on the implementation.
In the case the network receives a STATUS message with the cause #100 due to the presence of a Repeat Indicator with
the value “service change and fallback” in a SETUP message, it shall then resend a new SETUP message, with either
the BC-IE of the preferred service or the speech BC-IE (fallback to speech) as the only BC (no Repeat Indicator is
included). The preferred behaviour is decided by configuration.
If the call is in the call establishment or call clearing phase, i.e. any state other than the "active" state or the
"mobile originating modify" state, call control shall release the MM connection
b) Re-establishment required
If the call is in the "active" state or "mobile originating modify" state, the indication from MM that re-
establishment is possible shall cause call control to request re-establishment from the MM connection,
suspend any further message to be sent and await the completion of the re-establishment procedure.
3GPP
Release 10 257 3GPP TS 24.008 V10.6.1 (2012-03)
5.5.6 Progress
At any time during the establishment or release of a call and during an active call the network may send a PROGRESS
message to the mobile station.
On receipt of a PROGRESS message during the establishment or release of a call the mobile station shall stop all call
control timers related to that call.
NOTE: If the PROGRESS has been received before the receipt of a CALL PROCEEDING message, the mobile
station will not start timer T310 on receipt of a CALL PROCEEDING message, see subclause 5.2.1.1.3.
The mobile station shall be capable of transmitting DTMF messages as specified in this subclause if and only if the
mobile station has the user connection for speech attached and an appropriate channel is available.
The transaction identifier used by the DTMF messages shall be that of the attached speech call.
NOTE 1: The present document means that DTMF messages can generally be sent in the active state of a call in
speech transmission mode or when a traffic channel is available during setup or release and the progress
indicator IE has been received.
NOTE 2: Since the DTMF protocol messages are sent in a store and forward mode on the signalling channels the
control of the device at the far end may be delayed dependent on the load or quality of the channels.
NOTE 3: The procedures described in this paragraph support DTMF only in the direction mobile station to
network.
A mobile station supporting multimedia CAT during the alerting phase of a mobile originated multimedia call
establishment should also be capable of transmitting DTMFs during a multimedia call as specified in subclause 5.3.6.5.
Where a previous START DTMF message has been sent, another START DTMF message shall only be sent by the MS
following receipt of its STOP DTMF ACKNOWLEDGE message (see subclause 5.5.7.4) or a START DTMF REJECT
message from the network (see subclause 5.5.7.2) or following the expiry of timers T336 and T337.
If timer T336 expires, the MS shall terminate the ongoing DTMF procedure without any retransmissions, and is free to
begin another DTMF procedure (e.g. another START DTMF message).
3GPP
Release 10 258 3GPP TS 24.008 V10.6.1 (2012-03)
- convert the received digit into a DTMF tone which is applied toward the remote user, or
- send the DTMF digit as an out-of-band message (see 3GPP TS 23.205 [96])
and return a START DTMF ACKNOWLEDGE message to the mobile station. This acknowledgement may be used in
the mobile station to generate an indication as a feedback for a successful transmission.
If the network cannot accept the START DTMF message a START DTMF REJECT message will be sent to the mobile
station. Upon receipt of a START DTMF ACK message or a START DTMF REJECT message, the MS shall stop timer
T336.
The MS shall only send a STOP DTMF message if a START DTMF ACKNOWLEDGE message has been received
from the network (see subclause 5.5.7.2).
If timer T337 expires, the MS shall terminate the ongoing DTMF procedure without any retransmissions, and is free to
begin another DTMF procedure. (e.g. another START DTMF message).
and return a STOP DTMF ACKNOWLEDGE message to the mobile station. Upon receipt of a STOP DTMF
ACKNOWLEDGE message, the MS shall stop timer T337.
NOTE 1: In ETSI ES 201 235-2 [12a] the minimum duration of a DTMF tone is 65ms.
NOTE 2: In ETSI ES 201 235-2 [12a] the minimum gap between DTMF tones is 65ms.
There is no defined maximum length to the tone, which will normally cease when a STOP DTMF message is received
from the MS. However, the operator may choose to put a pre-defined time limit on the duration of tones sent.
The appropriate sequencing of DTMF control messages is shown in figures 5.8 and 5.9.
NOTE 3: The network may implement the time limit option where the DTMF tone duration is controlled by the
network irrespective of the receipt of a STOP DTMF message from the mobile station.
3GPP
Release 10 259 3GPP TS 24.008 V10.6.1 (2012-03)
SM procedures for identified access can only be performed if a GMM context has been established between the MS and
the network. If no GMM context has been established, the MM sublayer has to initiate the establishment of a GMM
context by use of the GMM procedures as described in chapter 4. After GMM context establishment, SM uses services
offered by GMM (see 3GPP TS 24.007 [20]). Ongoing SM procedures are suspended during GMM procedure
execution.
The SM procedures for identified MBMS context activation and deactivation can only be performed, if in addition to
the GMM context the MS has a PDP context activated.
In Iu mode only, integrity protected signalling (see subclause 4.1.1.1.1 of the present document and in general, see
3GPP TS 33.102 [5a]) is mandatory. In Iu mode only, all protocols shall use integrity protected signalling. Integrity
protection of all SM signalling messages is the responsibility of lower layers. It is the network which activates integrity
protection. This is done using the security mode control procedure (3GPP TS 25.331 [23c] and 3GPP TS 44.118 [111]).
For the session management protocol, the extended TI mechanism may be used (see 3GPP TS 24.007 [20]).
3GPP
Release 10 260 3GPP TS 24.008 V10.6.1 (2012-03)
6.1.2.1.1 PDP-INACTIVE
This state indicates that neither PDP context nor MBMS context exist.
6.1.2.1.2 PDP-ACTIVE-PENDING
This state exists when PDP context activation was requested by the MS.
6.1.2.1.3 PDP-INACTIVE-PENDING
This state exists when deactivation of the PDP contexts was requested by the MS.
6.1.2.1.4 PDP-ACTIVE
This state indicates that the PDP context is active.
6.1.2.1.5 PDP-MODIFY_PENDING
This state exists when modification of the PDP context was requested by the MS.
6.1.2.1.6 MBMS-ACTIVE-PENDING
This state exists when the MS has requested the network to activate an MBMS context.
6.1.2.1.7 MBMS-ACTIVE
This state indicates that the MBMS context is active.
3GPP
Release 10 261 3GPP TS 24.008 V10.6.1 (2012-03)
DR (DEACTIV. PDP
CONTX. ACC)
DR (ACTIV. PDP DR (DEACTIV. PDP
CONTX. REQ) CONTX. ACC)
DR (DEACTIV. PDP
CONTX. REQ)
Figure 6.1/3GPP TS 24.008: Session management states for PDP context handling in the MS
(overview)
It shall be noted, that Figure 6.1/3GPP TS 24.008 applies to both the PDP context activation procedure and the
secondary PDP context activation procedure, though the distinction in messages regarding the activation of PDP
contexts is not shown here for simplicity.
3GPP
Release 10 262 3GPP TS 24.008 V10.6.1 (2012-03)
MBMS-ACTIVE
Figure 6.1a/3GPP TS 24.008: Session management states for MBMS context handling in the MS
(overview)
6.1.2.2.1 PDP-INACTIVE
This state indicates that the PDP context or MBMS context is not active.
6.1.2.2.2 PDP-ACTIVE-PENDING
This state exists when the PDP context activation was initiated by the network.
6.1.2.2.3 PDP-INACTIVE-PENDING
This state exists when deactivation of the PDP context was requested by the network.
6.1.2.2.4 PDP-ACTIVE
This state indicates that the PDP context is active.
6.1.2.2.5 PDP-MODIFY-PENDING
This state exists when modification of the PDP context was requested by the network.
3GPP
Release 10 263 3GPP TS 24.008 V10.6.1 (2012-03)
6.1.2.2.6 MBMS-ACTIVE-PENDING
This state exists when the network has initiated MBMS context activation.
6.1.2.2.7 MBMS-INACTIVE-PENDING
This state exists when the network has requested the MS to deactivate an MBMS context.
6.1.2.2.8 MBMS-ACTIVE
This state indicates that the MBMS context is active.
PDP-ACTIVE-
PEND
DR (MOD PDP
CONTXT ACC) DI (ACTIV. PDP CONTX. REQ) DI (REQ PDP CONTX. ACTIV. REJ)
DR (MOD PDP
CONTXT REJ)
DR (ACTIV. PDP DR (REQ PDP CONTX. ACTIV)
CONTX. ACC)
DR (DEACTIV. PDP
CONTX. ACC)
DI (DEACTIV. PDP CONTX. REQ)
PDP-INACTIVE-
PEND
PDP-MODIFY-
PEND
DI (DEACTIV. PDP CONTX. REQ)
Figure 6.2/3GPP TS 24.008: Session management states for PDP context handling on the network
side (overview)
It shall be noted, that figure 6.2/3GPP TS 24.008 applies to both the PDP context activation procedure and the
secondary PDP context activation procedure, though the distinction in messages regarding the activation of PDP
contexts is not shown here for simplicity.
3GPP
Release 10 264 3GPP TS 24.008 V10.6.1 (2012-03)
MBMS-ACTIVE-
PEND
MBMS-INACTIVE-
PEND
Figure 6.2a/3GPP TS 24.008: Session management states for MBMS context handling on the network
side (overview)
6.1.2A.1 General
PDP addresses are handled differently for PDN interworking of type PPP and IP (IPv4 or IPv6).
The MS can obtain an IPv4 address or an IPv6 prefix via an IETF-based IP address allocation mechanism once the PDP
context is established.
The following IETF-based IP address/prefix allocation methods are specified for GPRS (the corresponding procedures
are specified in 3GPP TS 29.061 [130]):
a) /64 IPv6 default prefix allocation via IPv6 stateless address autoconfiguration. Optionally, allocation of
additional IPv6 prefix(es) with length /64 or shorter via stateful DHCPv6 Prefix Delegation (see
IETF RFC 3633 [139]);
Upon deactivation of a default PDP context, the MS shall locally release any IPv4 address or IPv6 prefix allocated to
the MS for the corresponding PDN connection.
3GPP
Release 10 265 3GPP TS 24.008 V10.6.1 (2012-03)
If the MS wants to use DHCPv4 for IPv4 address assignment, it shall indicate that to the network within the Protocol
Configuration Options IE in the ACTIVATE PDP CONTEXT REQUEST.
If the MS requests allocation of an IPv6 address, the network constructs it of two parts: a /64 IPv6 prefix and an
interface identifier of 64 bits length. The IPv6 prefix part is not used immediately by the MS; however, the network
shall use the same IPv6 prefix in subsequent procedures for IETF-based IP address allocation. The interface identifier is
only used for building a unique link-local IPv6 address.
An MS attached for emergency bearer services shall only request a PDP context with request type set to "emergency". If
there already is a PDN connection for emergency bearer services established, the MS shall not request an additional
PDN connection for emergency bearer services. The MS shall not request emergency bearer services in A/Gb mode or
in GERAN Iu mode.
Each PDP address may be described by one or more PDP contexts in the MS or the network. The PDP Context
Activation procedure is used to activate the default PDP context for a given PDP address and APN, i.e. a PDN
connection, whereas all additional contexts associated to the same PDP address and APN are activated with the
secondary PDP context activation procedure. An MS supporting S1 mode shall keep the default PDP context activated
during the lifetime of the PDN connection. An MS not supporting S1 mode should apply the same behaviour (see
3GPP TS 23.060 [74]). When more than one PDP context is associated to a PDP address, there shall be a Traffic Flow
Template (TFT), including one or more packet filters, for each or all but one context. The downlink and uplink packet
filters are considered separately. If present, the TFT shall be sent transparently either from the MS via the SGSN to the
GGSN to enable packet classification and policing for downlink data transfer in the GGSN or from the GGSN via the
SGSN to the MS to be used in a network requested secondary PDP context activation procedure (see subclause 6.1.3.2)
and enable packet classification and policing for uplink data transfer in the MS (see 3GPP TS 23.060 [74]).
For the purpose of requesting IP address allocation the MS shall set the PDP type number in the Requested PDP address
information element in the ACTIVATE PDP CONTEXT REQUEST message based on its IP stack configuration (e.g.
the per APN settings specified in 3GPP TS 23.060 [74]) as follows:
- has not been allocated an IP address for this APN, shall set the PDP type number to "IPv4v6 address";
- has been allocated an IPv4 address for this APN and received the SM cause #52, "single address bearers only
allowed", and is requesting an IPv6 address, shall set the PDP type number to "IPv6 address";
- has been allocated an IPv6 address for this APN and received the SM cause #52, "single address bearers only
allowed", and is requesting an IPv4 address, shall set the PDP type number to "IPv4 address".
b) An MS, which is only IPv4 capable, shall set the PDP type number to "IPv4 address".
c) An MS, which is only IPv6 capable, shall set the PDP type number to "IPv6 address".
d) When the IP version capability of the MS is unknown in the MS (as in the case when the MT and TE are
separated and the capability of the TE is not known in the MT), the MS shall set the PDP type number to
"IPv4v6 address".
3GPP
Release 10 266 3GPP TS 24.008 V10.6.1 (2012-03)
On receipt of the ACTIVATE PDP CONTEXT REQUEST message sent by the MS, the network when allocating an IP
address shall take into account the PDP type number, the operator policies of the home and visited network, and the
user's subscription data.
- If the MS requests PDP type IPv4v6, but the network configuration dictates the use of IPv4 addressing only or
IPv6 addressing only for this APN, the network shall override the PDP type requested by the MS to a single
address PDP type (IPv4 or IPv6). In the ACTIVATE PDP CONTEXT ACCEPT message sent to the MS, the
network sets the PDP type number to either "IPv4 address" or "IPv6 address" and the SM cause to #50, "PDP
type IPv4 only allowed", or #51, "PDP type IPv6 only allowed", respectively (see subclause 6.1.3.1.1). The MS
shall not subsequently request another PDP context to get a PDP Type different from the one allowed by the
network.
- If the MS requests PDP type IPv4v6, but the operator uses single addressing per PDP context due to
interworking with nodes of earlier releases, the network shall override the PDP type requested by setting the PDP
type in the ACTIVATE PDP CONTEXT ACCEPT message sent to the MS to a single address PDP type. In the
ACTIVATE PDP CONTEXT ACCEPT message sent to the MS, the network sets the PDP type number to either
"IPv4 address" or "IPv6 address" and the SM cause to #52, "single address bearers only allowed" (see
subclause 6.1.3.1.1). The MS should subsequently request another PDP context for the other PDP type to the
same APN with a single address PDP type (IPv4 or IPv6) other than the one already activated.
NOTE 1: If the MT and TE are separated, the MS might not be able to use SM cause #52 "single address bearers
only allowed" as a trigger for activating a second single-IP-stack PDP context.
The MS, in a pre release 8 network not supporting IPv4/v6, could encounter other network reactions:
- If the MS requests PDP type IPv4v6, and the PDP type is changed to PDP type IPv4 and no SM cause is
included the MS should request another PDP context for PDP type IPv6 to the same APN.
NOTE 2: Some networks can respond with ACTIVATE PDP CONTEXT REJECT with SM cause #28 "unknown
PDP address or PDP type". In that instance, the MS can attempt to establish dual-stack connectivity by
performing two PDP context activation request procedures to activate an IPv4 PDP context and an IPv6
PDP context, both to the same APN.
The MS shall set the request type to "initial request" when the MS is establishing connectivity to an additional PDN for
the first time, i.e. when it is an initial attach to that PDN. The MS shall set the request type to "handover" when the
connectivity to a PDN is established upon handover from a non-3GPP access network and the MS was connected to that
PDN before the handover to the 3GPP access network. If the MS is establishing connectivity for emergency bearer
services it shall set the request type to "emergency" and not include an APN in the ACTIVATE PDP CONTEXT
REQUEST message.
Upon receipt of the ACTIVATE PDP CONTEXT REQUEST message with request type set to "emergency" the network
shall use the APN or the GGSN/PDN GW configured for emergency bearer services.
Upon receipt of an ACTIVATE PDP CONTEXT REQUEST message with a PDP type number "IPv4v6 address" in the
Requested PDP address information element, the network shall on sending the ACTIVATE PDP CONTEXT ACCEPT
message:
- include the SM cause information element with cause #50 ("PDP type IPv4 only allowed"), if the requested PDN
connectivity is accepted with the restriction that only PDP type IPv4 is allowed; or
- include the SM cause information element with cause #51 ("PDP type IPv6 only allowed"), if the requested PDN
connectivity is accepted with the restriction that only PDP type IPv6 is allowed; or
3GPP
Release 10 267 3GPP TS 24.008 V10.6.1 (2012-03)
- include the SM cause information element with cause #52 ("single address bearers only allowed"), if the
requested PDN connectivity is accepted with the restriction that only single IP version bearers are allowed.
Upon receipt of an ACTIVATE PDP CONTEXT REQUEST message, the network selects a radio priority level based on
the QoS negotiated and may reply with an ACTIVATE PDP CONTEXT ACCEPT message.
If the ACTIVATE PDP CONTEXT REQUEST message included an NAS signalling low priority indication set to "MS
is configured for NAS signalling low priority", the network shall store the NAS signalling low priority indication within
the default PDP context.
Upon receipt of the message ACTIVATE PDP CONTEXT ACCEPT the MS shall stop timer T3380, shall enter the state
PDP-ACTIVE. If the protocol configuration options information element is present, the network may indicate the
Bearer Control Mode that shall be used. If the protocol configuration options information element is not present or the
Selected Bearer Control Mode parameter is not present in the protocol configuration options information element, the
MS shall apply Bearer Control Mode 'MS only' for all active PDP contexts sharing the same PDP Address and APN. If
the offered QoS parameters received from the network differ from the QoS requested by the MS, the MS shall either
accept the negotiated QoS or initiate the PDP context deactivation procedure. If the Request type information element is
not present, the network shall assume that the request type is "initial request".
NOTE 1: If the MS requested a value for a QoS parameter that is not within the range specified by
3GPP TS 23.107 [81], the network should negotiate the parameter to a value that lies within the specified
range.
If the lower layers provide a L-GW Transport Layer Address value together with the ACTIVATE PDP CONTEXT
REQUEST message and a PDN connection is established as a LIPA PDN connection due to the ACTIVATE PDP
CONTEXT REQUEST message, then the SGSN shall store the L-GW Transport Layer Address value as the GGSN
address in the PDP context of the LIPA PDN connection. If connectivity with the requested APN is accepted and the
network considers this PDN connection a LIPA PDN connection, then subject to operator policy the SGSN shall include
in the ACTIVATE PDP CONTEXT ACCEPT message the Connectivity type IE indicating "the PDN connection is
considered a LIPA PDN connection".
In A/Gb mode, the MS shall initiate establishment of the logical link for the LLC SAPI indicated by the network with
the offered QoS and selected radio priority level if no logical link has been already established for that SAPI. If the
offered QoS parameters received from the network differ from the QoS requested by the MS, the MS shall either accept
the negotiated QoS or initiate the PDP context deactivation procedure. If the LLC SAPI indicated by the network can
not be supported by the MS, the MS shall initiate the PDP context deactivation procedure.
In Iu mode, both the network and the MS shall store the LLC SAPI and the radio priority in the PDP context. If a Iu
mode to A/Gb mode system change is performed, the new SGSN shall initiate establishment of the logical link using the
negotiated QoS profile, the negotiated LLC SAPI, and selected radio priority level stored in the PDP context as in a
A/Gb mode to A/Gb mode Routing Area Update.
An MS, which is capable of operating in A/Gb mode, shall use a valid LLC SAPI, while an MS which is not capable of
operating in A/Gb mode shall indicate the LLC SAPI value as "LLC SAPI not assigned" in order to avoid unnecessary
value range checking and any other possible confusion in the network. When the MS uses a valid LLC SAPI, the
network shall return a valid LLC SAPI. The network shall return the "LLC SAPI not assigned" value only when the MS
uses the "LLC SAPI not assigned" value.
NOTE 2: The radio priority level and the LLC SAPI parameters, though not used in Iu mode, shall be included in
the messages, in order to support handover between Iu mode and A/Gb mode networks.
Upon receipt of the ACTIVATE PDP CONTEXT ACCEPT message with the Connectivity type IE indicating "the PDN
connection is considered a LIPA PDN connection", the MS provides an indication to the upper layers that the
connectivity is provided by a LIPA PDN connection.
Upon receipt of a REQUEST PDP CONTEXT ACTIVATION message if an APN is indicated in the message and the
timer T3396 is running for the APN, the MS shall stop the timer T3396, and then either initiate the PDP context
activation procedure as described in the previous subclause or reject the activation request by sending a REQUEST PDP
3GPP
Release 10 268 3GPP TS 24.008 V10.6.1 (2012-03)
CONTEXT ACTIVATION REJECT message as described in subclause 6.1.3.1.4. If the REQUEST PDP CONTEXT
ACTIVATION message did not contain an APN, then the MS shall stop the timer T3396 associated with a message that
was sent without an APN. The value of the reject cause IE of the REQUEST PDP CONTEXT ACTIVATION REJECT
message shall indicate the reason for rejection, e.g. "insufficient resources to activate another context".
The ACTIVATE PDP CONTEXT REQUEST message sent by the MS in order to initiate the PDP context activation
procedure shall contain the PDP address, PDP Type and APN requested by the network in the REQUEST PDP
CONTEXT ACTIVATION message.
Upon receipt of the ACTIVATE PDP CONTEXT REQUEST message, the network shall stop timer T3385.
The same procedures then apply as described for MS initiated PDP context activation.
# 35: NSAPI already used. The network shall not send this cause code (see note 1);
If the SM cause value is #26 "insufficient resources" or #27 "missing or unknown APN", the network may include a
value for timer T3396 in the ACTIVATE PDP CONTEXT REJECT message. If the SM cause value is #26 "insufficient
resources" and if the request type in the ACTIVATE PDP CONTEXT REQUEST was set to "emergency", the network
shall not include a value for timer T3396.
Upon receipt of an ACTIVATE PDP CONTEXT REJECT message, the MS shall stop timer T3380 and enter/remain in
state PDP-INACTIVE.
If the SM cause value is #26 "insufficient resources" and T3396 value IE is included:
- the MS shall take different actions depending on the timer value received for timer T3396:
i) if the timer value of the timer T3396 indicates neither zero nor deactivated, the MS shall start timer T3396
and:
3GPP
Release 10 269 3GPP TS 24.008 V10.6.1 (2012-03)
- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent
by the MS, until timer T3396 expires, the timer T3396 is stopped, the MS is switched off or the
SIM/USIM is removed; and
- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN was
not included in the ACTIVATE PDP CONTEXT REQUEST message, until timer T3396 expires, the MS
is switched off or the SIM/USIM is removed;
ii) if the timer value indicates that this timer is deactivated, the MS:
- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent
by the MS, until the MS is switched off or the SIM/USIM is removed or the MS receives a REQUEST
PDP CONTEXT ACTIVATION or REQUEST SECONDARY PDP CONTEXT ACTIVATION or
MODIFY PDP CONTEXT REQUEST message with the same APN from the network; and
- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN was
not included in the ACTIVATE PDP CONTEXT REQUEST message, until the MS is switched off or the
SIM/USIM is removed; and
iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT
REQUEST message for the same APN;
- if the MS is switched off when the timer T3396 is running, the MS shall behave as follows when the MS is
switched on:
- let t1 be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off
and switch on. If t1 is greater than t, then the timer shall be restarted with the value t1 – t. If t1 is equal to or
less than t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall
restart the timer with the value t1.
If the SM cause value is #27 "missing or unknown APN" and T3396 value IE is included:
- the MS shall take different actions depending on the timer value received for timer T3396:
i) if the timer value of the timer T3396 indicates neither zero nor deactivated, the MS shall start timer T3396
and:
- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent
by the MS, until timer T3396 expires, the MS is switched off or the SIM/USIM is removed; and
- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN was
not included in the ACTIVATE PDP CONTEXT REQUEST message, until timer T3396 expires, the MS
is switched off or the SIM/USIM is removed;
ii) if the timer value indicates that this timer is deactivated, the MS:
- shall not send another ACTIVATE PDP CONTEXT REQUEST message for the same APN that was sent
by the MS, until the MS is switched off or the SIM/USIM is removed; and
- shall not send another ACTIVATE PDP CONTEXT REQUEST message without an APN if the APN was
not included in the ACTIVATE PDP CONTEXT REQUEST message, until the MS is switched off or the
SIM/USIM is removed; and
iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT
REQUEST message for the same APN;
If the T3396 value IE is not included, the MS may send an ACTIVATE PDP CONTEXT REQUEST message for the
same APN. If the APN was not included in the previous ACTIVATE PDP CONTEXT REQUEST message, the MS may
send an ACTIVATE PDP CONTEXT REQUEST message without an APN.
The MS may initiate a PDP context activation procedure for emergency bearer services even if the timer T3396 is
running.
3GPP
Release 10 270 3GPP TS 24.008 V10.6.1 (2012-03)
The network shall stop timer T3385 and enter state PDP-INACTIVE.
a) Expiry of timers
On the first expiry of the timer T3380, the MS shall resend the ACTIVATE PDP CONTEXT REQUEST and
shall reset and restart timer T3380. This retransmission is repeated four times, i.e. on the fifth expiry of timer
T3380, the MS shall release all resources possibly allocated for this invocation and shall abort the procedure;
no automatic PDP context activation re-attempt shall be performed.
On the first expiry of the timer T3385, the network shall resend the message REQUEST PDP CONTEXT
ACTIVATION and shall reset and restart timer T3385. This retransmission is repeated four times, i.e. on the
fifth expiry of timer T3385, the network shall release possibly allocated resources for this activation and shall
abort the procedure.
If the MS uses dynamic PDP addressing that turns out to collide with the network requested PDP address, then
there is no detection of collision specified but left for network implementation.
A collision of an MS initiated and a network requested PDP context activation procedure is identified by the
MS when a REQUEST PDP CONTEXT ACTIVATION message is received from the network after the MS
has sent an ACTIVATE PDP CONTEXT REQUEST message, the MS has not yet received an ACTIVATE
PDP CONTEXT ACCEPT or ACTIVATE PDP CONTEXT REJECT message, and
i) the MS is able to compare the PDP type, PDP address and APN requested in the ACTIVATE PDP
CONTEXT REQUEST message with those requested in the REQUEST PDP CONTEXT ACTIVATION
message and these parameters are equal; or
NOTE: In general, the MS is unable to test if the PDP type, PDP address and APN in the REQUEST PDP
CONTEXT ACTIVATION message are the same as those for the PDN to which it is attempting to
activate a context. This is because the MS may have omitted one or more of the parameters in the
ACTIVATE PDP CONTEXT REQUEST message, since it is relying on default values to be provided by
the network.
- In the case of such a collision, the MS initiated PDP context activation shall take precedence over the
network requested PDP context activation. In case (i), the MS shall discard the REQUEST PDP CONTEXT
3GPP
Release 10 271 3GPP TS 24.008 V10.6.1 (2012-03)
ACTIVATION message and shall wait for the network response to its ACTIVATE PDP CONTEXT
REQUEST message. In case (ii), the MS shall send a REQUEST PDP CONTEXT ACTIVATION REJECT
message with the cause 'insufficient resources' to the network, and wait for the network response to its
ACTIVATE PDP CONTEXT REQUEST message.
A collision is detected by the network in the case where the PDP address, PDP type and APN derived
(according to 3GPP TS 23.060 [74] annex A) from the ACTIVATE PDP CONTEXT REQUEST message
received from the MS match those in the REQUEST PDP CONTEXT ACTIVATION message sent to the
MS.
- In the case of such a collision, the MS initiated PDP context activation shall take precedence over the
network requested PDP context activation. The network shall terminate the network requested PDP context
activation procedure, and proceed with the MS initiated PDP context activation procedure.
c) MS initiated PDP context activation request for an already activated PDP context (on the network side)
i) If the network receives a ACTIVATE PDP CONTEXT REQUEST message with the same combination of
APN, PDP type and PDP address as an already activated PDP context, the network shall deactivate the
existing PDP context and, if any, all the linked PDP contexts (matching the combination of APN, PDP
type and PDP address), locally without notification to the MS and proceed with the requested PDP
context activation.
ii) Alternatively (different combination of APN, PDP type and PDP address), if the NSAPI matches that of
an already activated PDP context, then the network shall deactivate only the existing PDP context locally
without notification to the MS and proceed with the requested PDP context activation.
It is an implementation option if the parameters used for comparison described in clause i) and ii) are the
parameters provided in the (current and previous) ACTIVATE PDP CONTEXT REQUESTs or the parameters
which are the result of the application of the selection rules defined in 3GPP TS 23.060 [74] Annex A.2.
The parameter provided in the current ACTIVATE PDP CONTEXT REQUEST can not be compared to the
actually used parameters (result of application of selection rules defined in 3GPP TS 23.060 [74] Annex A.2) of
the previously activated PDP contexts.
If the network receives an ACTIVATE PDP CONTEXT REQUEST message with request type "emergency" and
there already is a PDN connection for emergency bearer services existing, the network shall reject the request
with cause code #31 "activation rejected, unspecified".
d) Network initiated PDP context activation request for an already activated PDP context (on the mobile station
side)
If the MS receives a REQUEST PDP CONTEXT ACTIVATION message with the same combination of
APN, PDP type and PDP address as an already activated PDP context, the MS shall deactivate the existing
PDP context and, if any, all the linked PDP contexts (matching the combination of APN, PDP type and PDP
address) locally without notification to the network and proceed with the requested PDP context activation.
e) Additional MS initiated PDP context activation request received from an MS that is attached for emergency
bearer services:
If the MS is attached for emergency bearer services the network shall only accept the PDP context activation
request for emergency services. The network shall reject any other PDP context activation request with cause
code #31 "activation rejected, unspecified".
f) Reception of the ACTIVATE PDP CONTEXT ACCEPT message and Bearer Control Mode violation
If the Selected Bearer Control Mode indicates other value than 'MS only' in the ACTIVATE PDP CONTEXT
ACCEPT message although the protocol configuration options information element was not present or the MS
Support of Network Requested Bearer Control indicator was not present in the protocol configuration options
information element of the corresponding ACTIVATE PDP CONTEXT REQUEST message, the MS shall ignore
the Selected Bearer Control Mode parameter received from the network and apply Bearer Control Mode 'MS
only' for all active PDP contexts sharing the same PDP Address and APN.
3GPP
Release 10 272 3GPP TS 24.008 V10.6.1 (2012-03)
MS Network
ACTIVATE PDP CONTEXT REQUEST
Start T3380
ACTIVATE PDP CONTEXT ACCEPT
Stop T3380
or
MS Network
or
3GPP
Release 10 273 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of an ACTIVATE SECONDARY PDP CONTEXT REQUEST, the network shall validate the message by
verifying the TI given in the Linked TI IE to be any of the active PDP context(s). The same GGSN address shall be used
by the SGSN as for the already established PDP context(s) for that PDP address. The network shall select a radio
priority level based on the QoS negotiated and shall reply with an ACTIVATE SECONDARY PDP CONTEXT
ACCEPT message, if the request can be accepted.
NOTE 1: If the MS requested a value for a QoS parameter that is not within the range specified by 3GPP TS 23.107
[81], the network should negotiate the parameter to a value that lies within the specified range.
Upon receipt of the message ACTIVATE SECONDARY PDP CONTEXT ACCEPT, the MS shall stop timer T3380 and
enter the state PDP-ACTIVE. If the offered QoS parameters received from the network differ from the QoS requested
by the MS, the MS shall either accept the negotiated QoS or initiate the PDP context deactivation procedure.
In A/Gb mode the MS shall initiate establishment of the logical link for the LLC SAPI indicated by the network with
the offered QoS and selected radio priority level if no logical link has been already established for that SAPI. If the LLC
SAPI indicated by the network can not be supported by the MS, the MS shall initiate the PDP context deactivation
procedure.
In Iu mode, both SGSN and MS shall store the LLC SAPI and the radio priority in the PDP context. If an Iu mode to
A/Gb mode Routing Area Update is performed, the new SGSN shall initiate establishment of the logical link using the
negotiated LLC SAPI, the negotiated QoS profile and selected radio priority level stored in the PDP context as in an
A/Gb mode to A/Gb mode Routing Area Update.
An MS, which is capable of operating in A/Gb mode, shall use a valid LLC SAPI, while an MS which is not capable of
operating in A/Gb mode shall indicate the LLC SAPI value as "LLC SAPI not assigned" in order to avoid unnecessary
value range checking and any other possible confusion in the network. When the MS uses a valid LLC SAPI, the
network shall return a valid LLC SAPI. The network shall return the “LLC SAPI not assigned” value only when the MS
uses the “LLC SAPI not assigned” value.
NOTE 2: The radio priority level and the LLC SAPI parameters, though not used in Iu mode, shall be included in
the messages, in order to support handover between Iu mode and A/Gb mode networks.
Upon receipt of a REQUEST SECONDARY PDP CONTEXT ACTIVATION message, the MS shall stop the timer
T3396 if it is running for the APN associated with the PDP context and then either initiate the secondary PDP context
activation procedure as described in the subclause 6.1.3.2.1 or shall reject the activation request by sending a
REQUEST SECONDARY PDP CONTEXT ACTIVATION REJECT message as described in subclause 6.1.3.2.2a. The
value of the reject cause IE of the REQUEST SECONDARY PDP CONTEXT ACTIVATION REJECT message shall
indicate the reason for rejection, e.g. "insufficient resources to activate another context".
The ACTIVATE SECONDARY PDP CONTEXT REQUEST message sent by the MS in order to initiate the secondary
PDP context activation procedure shall contain the QoS and Linked TI required in the REQUEST SECONDARY PDP
CONTEXT ACTIVATION message. The MS shall also include a TFT with the downlink packet filters as specified in
the REQUEST SECONDARY PDP CONTEXT ACTIVATION message.
3GPP
Release 10 274 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of the ACTIVATE SECONDARY PDP CONTEXT REQUEST message, the network shall stop timer
T3385.
The same procedures then apply as described for MS initiated secondary PDP context activation.
If the SM cause value is #26 "insufficient resources", the network may include a value for timer T3396 value IE in the
ACTIVATE SECONDARY PDP CONTEXT REJECT message.
If the ACTIVATE SECONDARY PDP CONTEXT REQUEST message is related to an already active LIPA PDN
connection, then the network shall reply with an ACTIVATE SECONDARY PDP CONTEXT REJECT message with
cause code "bearer handling not supported".
Upon receipt of an ACTIVATE SECONDARY PDP CONTEXT REJECT message, the MS shall stop timer T3380 and
enter the state PDP-INACTIVE.
If the SM cause value is #26 "insufficient resources" and T3396 value IE is included:
- the MS takes different actions depending on the timer value received for T3396 value IE:
i) if the timer value of T3396 value IE indicates neither zero nor deactivated, the MS shall start timer T3396
and not try to send another ACTIVATE PDP CONTEXT REQUEST, ACTIVATE SECONDARY PDP
CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN until timer
T3396 expires, the timer T3396 is stopped, the MS is switched off or the SIM/USIM is removed;
ii) if the timer value indicates that this timer is deactivated, the MS shall not send another ACTIVATE PDP
CONTEXT REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP
CONTEXT REQUEST messages for the same APN until the MS is switched off or the SIM/USIM is
removed or the MS receives a REQUEST PDP CONTEXT ACTIVATION or REQUEST SECONDARY PDP
3GPP
Release 10 275 3GPP TS 24.008 V10.6.1 (2012-03)
CONTEXT ACTIVATION or MODIFY PDP CONTEXT REQUEST message for the same APN from the
network; or
iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT
REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT
REQUEST messages for the same APN.
If the T3396 value IE is not included, the MS may send an ACTIVATE PDP CONTEXT REQUEST, ACTIVATE
SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN.
If the MS is switched off when the timer T3396 is running, the MS behaves as follows when the MS is switched on:
- let t1 be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off and
switch on. If t1 is greater than t, then the timer shall be restarted with the value t1 – t. If t1 is equal to or less than
t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall restart the
timer with the value t1.
The network shall stop timer T3385 and enter state PDP-INACTIVE.
a) Expiry of timers
On the first expiry of the timer T3380, the MS shall resend the ACTIVATE SECONDARY PDP
CONTEXT REQUEST and shall reset and restart timer T3380. This retransmission is repeated four times,
i.e. on the fifth expiry of timer T3380, the MS shall release all resources possibly allocated for this
invocation and shall abort the procedure; no automatic PDP context activation re-attempt shall be
performed.
3GPP
Release 10 276 3GPP TS 24.008 V10.6.1 (2012-03)
On the first expiry of the timer T3385, the network shall resend the message REQUEST SECONDARY
PDP CONTEXT ACTIVATION and shall reset and restart timer T3385. This retransmission is repeated
four times, i.e. on the fifth expiry of timer T3385, the network shall release possibly allocated resources
for this activation and shall abort the procedure.
b) MS initiated secondary PDP context activation procedure for an already activated PDP context (On the network
side)
If the NSAPI matches that of an already activated PDP context, the network shall deactivate the existing PDP
context locally without notification to the MS and proceed with the requested PDP context activation. The case
of a TI match is described in subclause 8.3.2.
The network shall then check whether there is an activated PDP context for the TI given in the Linked TI IE
in the ACTIVATE SECONDARY PDP CONTEXT REQUEST message. If there is no active PDP context for
the specified TI, the network shall reply with an ACTIVATE SECONDARY PDP CONTEXT REJECT
message, cause code indicating "unknown PDP context".
d) no PDP context with Linked TI activated (on the mobile station side)
The MS shall check whether there is an activated PDP context for the TI given in the Linked TI IE in the
REQUEST SECONDARY PDP CONTEXT ACTIVATION message. If there is no active PDP context for the
specified TI, the MS shall reply with a REQUEST SECONDARY PDP CONTEXT ACTIVATION REJECT
message, cause code indicating "unknown PDP context".
e) MS initiated secondary PDP context activation procedure for a PDN connection established for emergency
bearer services (on the network side)
If the MS initiated secondary PDP context activation procedure is for a PDN connection established for
emergency bearer services the network shall reply with an ACTIVATE SECONDARY PDP CONTEXT
REJECT message, cause code indicating "activation rejected, unspecified".
If there exists a PDP context for the TI given in the Linked TI IE, then the TFT in the request message is checked for
different types of TFT IE errors as follows:
1) When the TFT operation is an operation other than "Create a new TFT" or "No TFT operation".
The network shall reject the activation request with cause "semantic error in the TFT operation".
The MS shall reject the activation request with cause "semantic error in the TFT operation".
1) When the TFT operation = "Create a new TFT" and the packet filter list in the TFT IE is empty.
2) When the TFT operation = "No TFT operation" with a non-empty packet filter list in the TFT IE.
3) When there are other types of syntactical errors in the coding of the TFT IE, such as a mismatch
between the number of packet filters subfield, and the number of packet filters in the packet filter list.
The network shall reject the activation request with cause "syntactical error in the TFT operation".
The MS shall reject the activation request with cause "syntactical error in the TFT operation".
1) When a packet filter consists of conflicting packet filter components which would render the packet
filter ineffective, i.e. no IP packet will ever fit this packet filter. How the network determines a
semantic error in a packet filter is outside the scope of the present document.
The network shall reject the activation request with cause "semantic errors in packet filter(s)".
The MS shall reject the activation request with cause "semantic errors in packet filter(s)".
3GPP
Release 10 277 3GPP TS 24.008 V10.6.1 (2012-03)
1) When the TFT operation = "Create a new TFT" and two or more packet filters in the resultant TFT
would have identical packet filter identifiers.
2) When the TFT operation = "Create a new TFT" and two or more packet filters in all TFTs associated
with this PDP address and APN would have identical packet filter precedence values.
3) When there are other types of syntactical errors in the coding of packet filters, such as the use of a
reserved value for a packet filter component identifier.
In case 2) the network shall not diagnose an error, further process the new activation request and, if it was
processed successfully, delete the old packet filters which have identical filter precedence values.
Furthermore, by means of explicit peer-to-peer signalling between the MS and the network, the network shall
deactivate the PDP context(s) for which it has deleted the packet filters.
In cases 1) and 3) the network shall reject the activation request with cause "syntactical errors in packet
filter(s)".
In case 2) the MS shall not diagnose an error, further process the new activation request and, if it was
processed successfully, delete the old packet filters which have identical filter precedence values.
Furthermore, by means of explicit peer-to-peer signalling between the network and the MS, the MS shall
deactivate the PDP context(s) for which it has deleted the packet filters.
In cases 1) and 3) the MS shall reject the activation request with cause "syntactical errors in packet filter(s)".
Otherwise, the network shall accept the activation request by replying to the MS with an ACTIVATE SECONDARY
PDP CONTEXT ACCEPT message. In case of network requested secondary PDP context activation procedure the MS
shall accept the activation request by replying to the network with an ACTIVATE SECONDARY PDP CONTEXT
REQUEST message.
MS Network
ACTIVATE SECONDARY PDP CONTEXT REQUEST
Start T3380
or
3GPP
Release 10 278 3GPP TS 24.008 V10.6.1 (2012-03)
Figure 6.5a/3GPP TS 24.008: Network requested secondary PDP context activation procedure
The PDP context modification procedure may also be invoked by the MS, in order to upgrade the maximum bit rate and
to trigger the re-establishment of the radio access bearer for an activated PDP context which is preserved in the MS with
maximum bit rate values of 0kbit/s for both uplink and downlink (see 3GPP TS 23.060 [74]).
NOTE 1: As described in 3GPP TS 23.060 [74], the MS only preserves PDP contexts with a TFT including packet
filter(s) set by the MS.
If
- the PDP Context Modification request is accepted by the network but the radio access bearer is not established;
or
- the PDP Context Modification request is rejected with cause "insufficient resources" (see subclause 6.1.3.3.3),
then the MS is not required to start a new PDP Context Modification procedure or to start a Service Request procedure
in order to trigger the re-establishment of the radio access bearer.
If there is a PDN connection for emergency bearer services established, the MS shall not request a modification of
bearer resources for this PDN connection.
3GPP
Release 10 279 3GPP TS 24.008 V10.6.1 (2012-03)
The network requested PDP context modification procedure may also be used to update the PDP address when external
PDP address allocation is performed, in which case the MS receives the PDP address in the MODIFY PDP CONTEXT
REQUEST (Network to MS direction) message.
NOTE 2: The procedure may be initiated by the network due to an inter-SGSN Routing Area Updating when a PDP
context is active.
The network informs the MS about the Bearer Control Mode to be applied for all active PDP contexts sharing the same
PDP Address and APN by including the selected Bearer Control Mode parameter in the protocol configuration options
information element. This information is either explicitly given in the MODIFY PDP CONTEXT REQUEST message
or implicitly given by not being present. The MS shall act according to the presence of the protocol configuration
options information element and the value of the selected Bearer Control Mode parameter in the MODIFY PDP
CONTEXT REQUEST message:
- if the protocol configuration options information element is not present, the MS shall apply Bearer Control Mode
'MS only' for all active PDP contexts sharing the same PDP Address and APN.
- if the selected Bearer Control Mode parameter is not present in the protocol configuration options information
element, the MS shall apply Bearer Control Mode 'MS only' for all active PDP contexts sharing the same PDP
Address and APN.
- if the selected Bearer Control Mode parameter is present in the protocol configuration options information
element, the MS shall apply Bearer Control Mode according to the value of this parameter for all active PDP
contexts sharing the same PDP Address and APN.
Upon receipt of the MODIFY PDP CONTEXT REQUEST message the MS shall stop the timer T3396 if it is running
for the APN associated with the PDP context and reply with the MODIFY PDP CONTEXT ACCEPT message, if the
MS accepts the new QoS and the indicated LLC SAPI.
The network shall upon receipt of the MODIFY PDP CONTEXT ACCEPT message stop timer T3386.
In A/Gb mode, the network shall establish, reconfigure or continue using the logical link with the new QoS for the LLC
SAPI indicated in the MODIFY PDP CONTEXT REQUEST message.
In Iu mode, if the Radio Access Bearer supporting the PDP context is active, then the network shall reconfigure and
continue using the Radio Access Bearer with the new QoS indicated in the MODIFY PDP CONTEXT REQUEST
message; if the PDP context is preserved, then the network may re-establish a Radio Access Bearer with the new QoS
indicated in the MODIFY PDP CONTEXT REQUEST message.
Upon receipt of the MODIFY PDP CONTEXT REQUEST message, the network may reply with the MODIFY PDP
CONTEXT ACCEPT message in order to accept the context modification. The reply message may contain the
negotiated QoS and the radio priority level based on the new QoS profile and the negotiated LLC SAPI that shall be
used in A/Gb mode by the logical link.
3GPP
Release 10 280 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of the MODIFY PDP CONTEXT ACCEPT message, the MS shall stop the timer T3381. If the offered
QoS parameters received from the network differs from the QoS requested by the MS, the MS shall either accept the
negotiated QoS or initiate the PDP context deactivation procedure.
If a modification of QoS is requested by the MS, which the network can not accept, being unable to provide the
requested QoS, it should maintain the QoS negotiated as previously negotiated or propose a new QoS. That means that
the network should not reject the MS initiated PDP context modification request due to the unavailability of the QoS. If
the MS requested a value for a QoS parameter that is not within the range specified by 3GPP TS 23.107[81], the
network should negotiate the parameter to a value that lies within the specified range.
If upon the reception of a MODIFY PDP CONTEXT REQUEST message the network fails to re-establish the radio
access bearer for a PDP context whose maximum bit rate in uplink and downlink is set to 0kbit/s, the network shall
reply with MODIFY PDP CONTEXT REJECT with cause "insufficient resources".
If a TFT modification was requested and the requested new TFT is not available, then MODIFY PDP CONTEXT
REJECT shall be sent.
The network shall reply with MODIFY PDP CONTEXT REJECT with cause "request rejected, Bearer Control Mode
violation", if
- the selected Bearer Control Mode is 'MS/NW' and the MS requests to create a TFT for a PDP context that was
established without TFT;
- the selected Bearer Control Mode is 'MS/NW' and the MS requests to upgrade the QoS of a PDP context without
downlink packet filters, unless uplink packet filters already exist for the PDP context and the MS requests with
the same MODIFY PDP CONTEXT REQUEST message to create downlink packet filters ;
- the selected Bearer Control Mode is 'MS/NW' and the MS requests to modify the QoS, but does not include a
TFT with at least apacket filter identifiers to indicate which packet filters in the TFT that is associated with the
QoS change; or
- the selected Bearer Control Mode is 'MS/NW' and the MS requests to modify the QoS for a PDP context
associated with a TFT containing packet filters established by both the MS and the network and the MS tries to
modify other parameters than the bitrate parameters in the QoS profile of that PDP context.
If the MS has requested to modify the QoS of a default PDP context, the network shall reply with MODIFY PDP
CONTEXT REJECT with cause code "QoS not accepted".
3GPP
Release 10 281 3GPP TS 24.008 V10.6.1 (2012-03)
If the MS has requested to modify the PDP context of a LIPA PDN connection, then the network shall reply with a
MODIFY PDP CONTEXT REJECT message with cause code "bearer handling not supported".
The TFT in the request message is checked by the receiver for different types of TFT IE errors as follows:
1) TFT operation = "Create a new TFT" when there is already an existing TFT for the PDP context.
2) When the TFT operation is an operation other than "Create a new TFT" and there is no TFT for the PDP
context.
3) TFT operation = "Delete existing TFT" when there is already another PDP context with the same PDP
address and APN without a TFT.
4) TFT operation = "Delete packet filters from existing TFT" when it would render the TFT empty.
In these cases the receiver shall not diagnose an error and perform the following actions to resolve the
inconsistency:
In case 1) the receiver shall further process the new activation request and, if it was processed successfully,
delete the old TFT.
- further process the new request and, if no error according to list items b), c), and d) was detected, consider
the TFT as successfully deleted, if the TFT operation is "Delete existing TFT" or "Delete packet filters from
existing TFT";
- process the new request as an activation request, if the TFT operation is "Add packet filters in existing TFT"
or "Replace packet filters in existing TFT".
In case 3) the receiver shall process the new deletion request and, after successful deletion of the TFT, deactivate
the old PDP context with the same PDP address and APN without a TFT by explicit peer-to-peer signalling
between the MS and the network.
In case 4) the receiver shall further process the new request and, if no error according to list items b), c), and d)
was detected, delete the existing TFT. After successful deletion of the TFT, if there was already another PDP
context with the same PDP address and APN without a TFT, the receiver shall deactivate this old PDP context
without a TFT by explicit peer-to-peer signalling between the MS and the network.
1) When the TFT operation is an operation other than "Delete existing TFT" or "No TFT operation" and the
packet filter list in the TFT IE is empty.
2) TFT operation = "Delete existing TFT" or "No TFT operation" with a non-empty packet filter list in the TFT
IE.
3) TFT operation = "Replace packet filters in existing TFT" when a to be replaced packet filter does not exist in
the original TFT.
4) TFT operation = "Delete packet filters from existing TFT" when a to be deleted packet filter does not exist in
the original TFT.
5) TFT operation = "Delete packet filters from existing TFT" with a packet filter list also including packet
filters in addition to the packet filter identifiers.
6) When there are other types of syntactical errors in the coding of the TFT IE, such as a mismatch between the
number of packet filters subfield, and the number of packet filters in the packet filter list.
In case 3) the receiver shall not diagnose an error, further process the replace request and, if no error according to
list items c) and d) was detected, include the packet filters received to the existing TFT.
In case 4) the receiver shall not diagnose an error, further process the deletion request and, if no error according
to list items c) and d) was detected, consider the respective packet filter as successfully deleted.
3GPP
Release 10 282 3GPP TS 24.008 V10.6.1 (2012-03)
Otherwise the receiver shall reject the modification request with cause "syntactical error in the TFT operation".
When a packet filter consists of conflicting packet filter components which would render the packet filter
ineffective, i.e. no IP packet will ever fit this packet filter. How the receiver determines a semantic error in a
packet filter is outside the scope of the present document.
The receiver shall reject the modification request with cause "semantic errors in packet filter(s)".
1) When the TFT operation = "Create a new TFT" or "Add packet filters to existing TFT" and two or more
packet filters in the resultant TFT would have identical packet filter identifiers.
2) When the TFT operation = "Create a new TFT" or "Add packet filters to existing TFT" or "Replace packet
filters in existing TFT" and two or more packet filters in all TFTs associated with this PDP address and APN
would have identical packet filter precedence values.
3) When there are other types of syntactical errors in the coding of packet filters, such as the use of a reserved
value for a packet filter component identifier.
In case 1), if two or more packet filters with identical packet filter identifiers are contained in the new request,
the receiver shall reject the modification request with cause "syntactical errors in packet filter(s)". Otherwise, the
receiver shall not diagnose an error, further process the new request and, if it was processed successfully, delete
the old packet filters which have the identical packet filter identifiers.
In case 2) the receiver shall not diagnose an error, further process the new request and, if it was processed
successfully, delete the old packet filters which have identical filter precedence values. Furthermore, by means of
explicit peer-to-peer signalling between the MS and the network, the receiver shall deactivate the PDP context(s)
for which it has deleted the packet filters.
Otherwise the receiver shall reject the modification request with cause "syntactical errors in packet filter(s)".
If the SM cause value is #26 "insufficient resources", the network may include a value for timer T3396 value IE in the
MODIFY PDP CONTEXT REJECT message.
Upon receipt of a MODIFY PDP CONTEXT REJECT message, the MS shall stop timer T3381 and enter the state PDP-
ACTIVE.
- the MS takes different actions depending on the timer value received for T3396 value IE:
i) if the timer value of T3396 value IE indicates neither zero nor deactivated, the MS shall start timer T3396
and not try to send another ACTIVATE PDP CONTEXT REQUEST, ACTIVATE SECONDARY PDP
CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN until timer
T3396 expires, the timer T3396 is stopped, the MS is switched off or the SIM/USIM is removed;
ii) if the timer value indicates that this timer is deactivated, the MS shall not try to send another ACTIVATE
PDP CONTEXT REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP
CONTEXT REQUEST messages for the same APN until the MS is switched off or the SIM/USIM is
removed or the MS receives REQUEST PDP CONTEXT ACTIVATION or REQUEST SECONDARY PDP
CONTEXT ACTIVATION or MODIFY PDP CONTEXT REQUEST message for the same APN from the
network; or
iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE PDP CONTEXT
REQUEST, ACTIVATE SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT
REQUEST messages for the same APN.
If the T3396 value IE is not included, the MS may send an ACTIVATE PDP CONTEXT REQUEST, ACTIVATE
SECONDARY PDP CONTEXT REQUEST or MODIFY PDP CONTEXT REQUEST messages for the same APN.
If the MS is switched off when the timer T3396 is running, the MS behaves as follows when the MS is switched on:
3GPP
Release 10 283 3GPP TS 24.008 V10.6.1 (2012-03)
- let t1 be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off and
switch on. If t1 is greater than t, then the timer shall be restarted with the value t1 – t. If t1 is equal to or less than
t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall restart the
timer with the value t1.
The MS may reject the network initiated PDP context modification request by sending a MODIFY PDP CONTEXT
REJECT message to the network. The message shall contain a cause code that typically indicates one of the following:
The MS shall reply with MODIFY PDP CONTEXT REJECT with cause "request rejected, Bearer Control Mode
violation", if the selected Bearer Control Mode is 'MS only' and the network requests to modify or delete a TFT
The TFT in the request message is checked by the receiver for different types of TFT IE errors as specified in
subclause 6.1.3.3.3.
Upon receipt of a MODIFY PDP CONTEXT REJECT message, the network shall stop timer T3386 and enter the state
PDP-ACTIVE.
On the first expiry of timer T3386, the network shall resend the MODIFY PDP CONTEXT REQUEST
message reset and restart timer T3386. This retransmission is repeated four times, i.e. on the fifth expiry of
timer T3386, the network may continue to use the previously negotiated QoS or it may initiate the PDP
context deactivation procedure.
In the MS:
On the first expiry of timer T3381, the MS shall resend the MODIFY PDP CONTEXT REQUEST message
reset and restart timer T3381. This retransmission is repeated four times, i.e. on the fifth expiry of timer
T3381, the MS may continue to use the previously negotiated QoS or it may initiate the PDP context
deactivation procedure.
A collision of a MS and network initiated PDP context modification procedures is identified by the MS if a
MODIFY PDP CONTEXT REQUEST message is received from the network after the MS has sent a MODIFY
PDP CONTEXT REQUEST message itself, and both messages contain the same TI and the MS has not yet
received a MODIFY PDP CONTEXT ACCEPT message from the network.
A collision is detected by the network in case a MODIFY PDP CONTEXT REQUEST message is received from
the MS with the same TI as the MODIFY PDP CONTEXT REQUEST message sent to the MS.
3GPP
Release 10 284 3GPP TS 24.008 V10.6.1 (2012-03)
In the case of such a collision, the network initiated PDP context modification shall take precedence over the MS
initiated PDP context modification. The MS shall terminate internally the MS initiated PDP context modification
procedure, enter the state PDP-Active and proceed with the network initiated PDP context modification
procedure by sending a MODIFY PDP CONTEXT ACCEPT message. The network shall ignore the MODIFY
PDP CONTEXT REQUEST message received in the state PDP-MODIFY-PENDING. The network shall
proceed with the network initiated PDP context modification procedure as if no MODIFY PDP CONTEXT
REQUEST message was received from the MS.
c) Collision of MS initiated PDP Context Modification Procedures and Network initiated Deactivate PDP Context
Request Procedures
A collision of a MS initiated PDP context modification procedures and a network initiated PDP context
deactivation procedures is identified by the MS if a DEACTIVATE PDP CONTEXT REQUEST message is
received from the network after the MS has sent a MODIFY PDP CONTEXT REQUEST message, and the MS
has not yet received a MODIFY PDP CONTEXT ACCEPT message from the network.
In the case of such a collision, the network initiated PDP context deactivation shall take precedence over the MS
initiated PDP context modification. The MS shall terminate internally the MS initiated PDP context modification
procedure, and proceed with the network initiated PDP context deactivation procedure by sending a
DEACTIVATE PDP CONTEXT ACCEPT, enter the state PDP-INACTIVE. The network shall ignore the
MODIFY PDP CONTEXT REQUEST message received in the state PDP-INACTIVE-PENDING. The network
shall proceed with the network initiated PDP context deactivation procedure as if no MODIFY PDP CONTEXT
REQUEST message was received from the MS.
d) MS initiated PDP context modification procedure for a PDN connection established for emergency bearer
services.
The network shall reply with a MODIFY PDP CONTEXT REJECT message with a cause code indicating
"activation rejected by GGSN, Serving GW or PDN GW".
MS Network
MODIFY PDP CONTEXT REQUEST
Start T3386
MS Network
MODIFY PDP CONTEXT REQUEST
Start T3381
or
3GPP
Release 10 285 3GPP TS 24.008 V10.6.1 (2012-03)
be included in the DEACTIVATE PDP CONTEXT REQUEST message in order to indicate whether only the PDP
context associated with this specific TI or all active PDP contexts sharing the same PDP address and APN as the PDP
context associated with this specific TI shall be deactivated. If the tear down is requested, all other active PDP contexts
sharing the same PDP address and APN as the PDP context associated with this specific TI shall be deactivated locally
without peer-to-peer signalling. If the tear down indicator information element is not included in the DEACTIVATE
PDP CONTEXT REQUEST message, only the PDP context associated with this specific TI shall be deactivated.
An MS supporting S1 mode shall always include the tear down indicator when deactivating the default PDP context. An
MS not supporting S1 mode should apply the same behavior (see 3GPP TS 23.060 [74]).
After successful PDP context deactivation, the associated NSAPI and TI values are released and can be reassigned to
another PDP context.
If one or more MBMS contexts are linked to a PDP context that has been deactivated, the MS shall deactivate all those
MBMS contexts locally (without peer to peer signalling between the MS and the network).
The MS is allowed to initiate the PDP context deactivation procedure even if the timer T3396 is running.
The network shall reply with the DEACTIVATE PDP CONTEXT ACCEPT message. Upon receipt of the
DEACTIVATE PDP CONTEXT ACCEPT message, the MS shall stop timer T3390.
In A/Gb mode, both the MS and the network shall initiate local release of the logical link if it is not used by another
PDP context.
In Iu mode, the network shall initiate the release of Radio Access Bearer associated with this PDP context.
If the selected Bearer Control Mode is 'MS/NW' the MS should not deactivate a PDP context, if it is the only PDP
context without TFT within a group of active PDP contexts sharing the same PDP address and APN.
NOTE 1: A configuration with more than one PDP context without TFT within a group of active PDP contexts
sharing the same PDP address and APN can occur during a network initiated PDP context modification
due to asynchronous TFT states in the MS and in the network (see e.g. subclause 6.1.3.3.3 bullet a.3).
NOTE 2: If the MS deactivates the last PDP context without TFT within a group of active PDP contexts sharing the
same PDP address and APN, the network will initiate the re-establishment of this PDP context using the
network requested secondary PDP context activation procedure.
3GPP
Release 10 286 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall, upon receipt of this message, reply with a DEACTIVATE PDP CONTEXT ACCEPT message. Upon
receipt of the DEACTIVATE PDP CONTEXT ACCEPT message, the network shall stop the timer T3395.
If the DEACTIVATE PDP CONTEXT REQUEST message includes the cause #39 "reactivation requested" and the PDP
context was activated by the MS, the MS should stop timer T3396 if it is running for the APN associated with the PDP
context, and re-activate the PDP context. Additionally, the MS should re-activate the PDP contexts that were originally
activated by the MS and released by the network as a result of this PDP context deactivation procedure.
NOTE: User interaction is necessary in some cases when the MS cannot re-activate the PDP context(s)
automatically.
If a detach is requested by the HLR for an MS that has PDP contexts for emergency services, the SGSN shall send a
DEACTIVATE PDP CONTEXT REQUEST message to the MS for all the PDP contexts that are not PDP contexts for
emergency services.
In A/Gb mode, both the MS and the network shall initiate local release of the logical link if it is not used by another
PDP context.
In Iu mode, the network shall initiate the release of Radio Access Bearer associated with this PDP context.
a) Expiry of timers
On the first expiry of timer T3390, the MS shall resent the message DEACTIVATE PDP CONTEXT
REQUEST and shall reset and restart the timer T3390. This retransmission is repeated four times, i.e. on the
fifth expiry of timer T3390, the MS shall release all resources allocated and shall erase the PDP context
related data.
On the first expiry of timer T3395, the network shall resent the message DEACTIVATE PDP CONTEXT
REQUEST and shall reset and restart timer T3395. This retransmission is repeated four times, i.e. on the fifth
expiry of timer T3395, the network shall erase the PDP context related data for that MS.
If the MS and the network initiated PDP context deactivation requests collide, the MS and the network shall each
reply with the messages DEACTIVATE PDP CONTEXT ACCEPT and shall stop timer T3390 and T3395,
respectively.
MS Network
3GPP
Release 10 287 3GPP TS 24.008 V10.6.1 (2012-03)
MS Network
6.1.3.4a Void
6.1.3.5 Void
6.1.3.5a.1 General
The network can use the notification procedure to inform the MS about events which are relevant for the upper layer
which is using a PDP context or has requested a session management procedure.
If the MS has indicated that it supports the notification procedure, the network may initiate the procedure at any time
while a PDP context is activated or another session management procedure is ongoing.
MS Network
NOTIFICATION
3GPP
Release 10 288 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall abort any ongoing SM procedure related to the received transaction identifier value, stop any
related timer, and deactivate the corresponding PDP or MBMS context locally (without peer to peer signalling
between the MS and the network).
If one or more MBMS contexts are linked to a PDP context that has been deactivated, the MS shall deactivate all
those MBMS Contexts locally (without peer to peer signalling between the MS and the network).
The MS shall abort any ongoing SM procedure related to the received transaction identifier value and stop any
related timer.
If the SM entity of the MS receives a SM STATUS message with any other SM cause value no state transition and no
specific action shall be taken as seen from the radio interface, i.e. local actions are possible.
If the SM entity of the network receives an SM STATUS message the network shall take different actions depending on
the received SM cause value:
The network shall abort any ongoing SM procedure related to the received transaction identifier value, stop any
related timer, and deactivate the corresponding PDP or MBMS context locally (without peer to peer signalling
between the MS and the network).
If one or more MBMS contexts are linked to a PDP context that has been deactivated, the MS shall deactivate all
those MBMS Contexts locally (without peer to peer signalling between the MS and the network).
The network shall abort any ongoing SM procedure related to the received transaction identifier value and stop
any related timer.
The actions to be taken in the network on receiving a SM STATUS message with any other SM cause value are an
implementation dependent option.
3GPP
Release 10 289 3GPP TS 24.008 V10.6.1 (2012-03)
Upon receipt of a REQUEST MBMS CONTEXT ACTIVATION message, the MS shall validate the message by
verifying the NSAPI given in the Linked NSAPI IE to be one of the active PDP context(s), stop the timer T3396 if it is
running for the APN indicated in the message and send an ACTIVATE MBMS CONTEXT REQUEST, enter state
MBMS-ACTIVE-PENDING and start timer T3380. The message shall contain an IP multicast address and an APN,
which shall be the same as the IP multicast address and the APN requested by the network in the REQUEST MBMS
CONTEXT ACTIVATION message. Furthermore, the MS shall include the Supported MBMS bearer capabilities, i.e.
the maximum downlink bit rate the MS can handle.
Upon receipt of the ACTIVATE MBMS CONTEXT REQUEST message, the network shall stop timer T3385. If the
network accepts the request, it shall reply with an ACTIVATE MBMS CONTEXT ACCEPT message.
Upon receipt of the message ACTIVATE MBMS CONTEXT ACCEPT the MS shall stop timer T3380 and shall enter
the state MBMS-ACTIVE.
If the SM cause value is #26 "insufficient resources" or #27 "missing or unknown APN", the network may include a
value for timer T3396 in the ACTIVATE MBMS CONTEXT REJECT message.
Upon receipt of an ACTIVATE MBMS CONTEXT REJECT message, the MS shall stop timer T3380 and enter/remain
in state PDP-INACTIVE.
If the SM cause value is #26 "insufficient resources" and T3396 value IE is included:
- the MS shall take different actions depending on the timer value received for timer T3396:
i) if the timer value indicates neither zero nor deactivated, the MS shall start timer T3396 and not send another
ACTIVATE MBMS CONTEXT REQUEST message for the same APN until timer T3396 expires, the timer
T3396 is stopped, the MS is switched off or the SIM/USIM is removed;
ii) if the timer value indicates that this timer is deactivated, the MS shall not send another ACTIVATE MBMS
CONTEXT REQUEST message for the same APN until the MS is switched off or the SIM/USIM is removed
3GPP
Release 10 290 3GPP TS 24.008 V10.6.1 (2012-03)
or the MS receives REQUEST MBMS CONTEXT ACTIVATION message for the same APN from the
network;
iii) if the timer value indicates that this timer is zero, the MS may send another ACTIVATE MBMS CONTEXT
REQUEST message for the same APN; and
- if the MS is switched off when the timer T3396 is running, the MS shall behave as follows when the MS is
switched on:
- let t1 be the time remaining for T3396 timeout at switch off and let t be the time elapsed between switch off
and switch on. If t1 is greater than t, then the timer shall be restarted with the value t1 – t. If t1 is equal to or
less than t, then the timer need not be restarted. If the MS is not capable of determining t, then the MS shall
restart the timer with the value t1.
If the SM cause value is #27 "missing or unknown APN" and T3396 value IE is included:
- the MS shall take different actions depending on the timer value received for timer T3396:
i) if the timer value of the timer T3396 indicates neither zero nor deactivated, the MS shall start timer T3396
and not send an ACTIVATE MBMS CONTEXT REQUEST message for the same APN until timer T3396
expires, the MS is switched off or the SIM/USIM is removed;
ii) if the timer value indicates that this timer is deactivated, the MS shall not send another ACTIVATE MBMS
CONTEXT REQUEST message for the same APN until the MS is switched off or the SIM/USIM is
removed; and
iii) if the timer value indicates that this timer is zero, the MS may send an ACTIVATE MBMS CONTEXT
REQUEST message for the same APN.
If the T3396 value IE is not included, the MS may send an ACTIVATE MBMS CONTEXT REQUEST message for the
same APN. If the APN was not included in the previous ACTIVATE MBMS CONTEXT REQUEST message, the MS
may send an ACTIVATE MBMS CONTEXT REQUEST message without an APN.
The network shall stop timer T3385 and enter in state PDP-INACTIVE.
a) Expiry of timers in the mobile station: On the first expiry of the timer T3380, the MS shall resend the
ACTIVATE MBMS CONTEXT REQUEST and shall reset and restart timer T3380. This retransmission is
repeated four times, i.e. on the fifth expiry of timer T3380, the MS shall release all resources possibly allocated
for this invocation and shall abort the procedure; no automatic MBMS context activation re-attempt shall be
performed.
b) Expiry of timers on the network side: On the first expiry of the timer T3385, the network shall resend the
message REQUEST MBMS CONTEXT ACTIVATION and shall reset and restart timer T3385. This
retransmission is repeated four times, i.e. on the fifth expiry of timer T3385, the network shall release possibly
allocated resources for this activation and shall abort the procedure.
3GPP
Release 10 291 3GPP TS 24.008 V10.6.1 (2012-03)
c) MBMS context activation request for an already activated MBMS context (on the mobile station side): If the
MS receives a REQUEST MBMS CONTEXT ACTIVATION message with the same combination of APN and
IP multicast address (i.e. PDP type and PDP address) as an already activated MBMS context, the MS shall
deactivate the existing MBMS context locally without notification to the network and proceed with the requested
MBMS context activation.
d) MBMS context activation request for an already activated MBMS context (on the network side): If the network
receives an ACTIVATE MBMS CONTEXT REQUEST message with the same combination of APN and IP
multicast address (i.e. PDP type and PDP address) as an already activated MBMS context, the network shall
deactivate the existing MBMS context locally without notification to the MS and proceed with the requested
MBMS context activation.
MS Network
or
REQUEST MBMS CONTEXT ACTIVATION REJECT
Stop T3385
After a successful MBMS context deactivation, the associated MBMS NSAPI and TI values shall be released in both
the MS and the network and can be reassigned to another MBMS context.
The MBMS context deactivation procedure makes use of the messaging and signalling of the PDP context deactivation
procedure as described in the subclauses 6.1.3.9.1 and 6.1.3.9.2.
3GPP
Release 10 292 3GPP TS 24.008 V10.6.1 (2012-03)
The MS shall reply with a DEACTIVATE PDP CONTEXT ACCEPT message and enter the state PDP-INACTIVE.
Upon receipt of the DEACTIVATE PDP CONTEXT ACCEPT message, the network shall stop the timer T3395 and
enter the state PDP-INACTIVE.
a) Expiry of timers:
On the first expiry of the timer T3395, the network shall resend the message DEACTIVATE PDP CONTEXT
REQUEST and shall reset and restart the timer T3395. This retransmission is repeated, i.e. on the fifth expiry
of the timer T3395, the network shall erase the MBMS context related data for that MS.
MS Network
The MBMS protocol configuration options information element is transparent to the SGSN.
6.2 void
- upon modification of any PDP context which was activated before the ISR is activated in the MS;
3GPP
Release 10 293 3GPP TS 24.008 V10.6.1 (2012-03)
- at the time when the MS changes from A/Gb mode or Iu mode to S1 mode, if any PDP context activated after the
ISR was activated in the MS exists; or
- upon deactivation of last non-emergency PDP context in the MS, if the MS has only a PDN connection for
emergency bearer services remaining.
NOTE: The MS might store the provided MSISDN in the corresponding USIM file (see 3GPP TS 31.102 [112]
subclause 4.2.26) and such an MS could check this USIM file to determine whether to query the network.
The network shall provide only one MSISDN. As a result, a provided MSISDN shall supercede any MSISDN that was
previously provided in the protocol configuration options information element. The MSISDN provided is for user
information only, and the MS shall not use the MSISDN in any NAS signalling procedure. If the MSISDN is stored in
the ME, the ME shall retain the MSISDN at power off. The MSISDN stored in the ME, if any, can only be used if the
IMSI from the USIM matches the IMSI stored in non-volatile memory, else the MS shall delete the MSISDN.
8.1 General
The procedures specified in 3GPP TS 24.008 and call-related supplementary service handling in 3GPP TS 24.010 [21]
apply to those messages which pass the checks described in this subclause.
This subclause also specifies procedures for the handling of unknown, unforeseen, and erroneous protocol data by the
receiving entity. These procedures are called "error handling procedures", but in addition to providing recovery
mechanisms for error situations they define a compatibility mechanism for future extensions of the protocols.
Error handling concerning the value part of the Facility IE and of the SS Version Indicator IE are not in the scope of the
present document. It is defined in 3GPP TS 24.010 [21] and the 3GPP TS 24.08x series.
Most error handling procedures are mandatory for the mobile station.
Detailed error handling procedures in the network are implementation dependent and may vary from PLMN to PLMN.
However, when extensions of this protocol are developed, networks will be assumed to have the error handling that is
indicated in this subclause as mandatory ("shall") and that is indicated as strongly recommended ("should").
Subclauses 8.2, 8.3, 8.4, 8.5 and 8.7.2 do not apply to the error handling in the network applied to the receipt of initial
layer 3 message: If the network diagnoses an error described in one of these subclauses in the initial layer 3 message
received from the mobile station, it shall either:
- try to recognize the classmark and then take further implementation dependent actions; or
3GPP
Release 10 294 3GPP TS 24.008 V10.6.1 (2012-03)
Also, the error handling of the network is only considered as mandatory or strongly recommended when certain
thresholds for errors are not reached during a dedicated connection.
For definition of semantical and syntactical errors see 3GPP TS 24.007 [20], subclause 11.4.2.
The mobile station and network shall reject a SETUP, EMERGENCY SETUP or START CC message received with
octet 1 part of the TI value coded as "111" by sending RELEASE COMPLETE with cause #81 "Invalid transaction
identifier value" The TI value in RELEASE COMPLETE shall be the complete TI value including the extension octet
from the message that caused the rejection.
Any message other than SETUP, EMERGENCY SETUP or START CC received with octet 1 part of the TI value coded
as "111" shall be ignored.
For a call control message received with octet 1 part of the TI value not coded as "111", the following procedures shall
apply:
a) For a network that does not support the "Network initiated MO call" option and for all mobile stations:
Whenever any call control message except EMERGENCY SETUP, SETUP or RELEASE COMPLETE is
received specifying a transaction identifier which is not recognized as relating to an active call or to a call in
progress, the receiving entity shall send a RELEASE COMPLETE message with cause #81 "invalid transaction
identifier value" using the received transaction identifier value and remain in the Null state.
For a network that does support the "Network initiated MO call" option $(CCBS)$:
Whenever any call control message except EMERGENCY SETUP, SETUP, START CC or RELEASE
COMPLETE is received specifying a transaction identifier which is not recognized as relating to an active call or
to a call in progress, the receiving entity shall send a RELEASE COMPLETE message with cause #81 "invalid
transaction identifier value" using the received transaction identifier value and remain in the Null state.
b) When a RELEASE COMPLETE message is received specifying a transaction identifier which is not recognized
as relating to an active call or to a call in progress, the MM connection associated with that transaction identifier
shall be released.
c) For a network that does not support the "Network initiated MO call" option and for all mobile stations:
When an EMERGENCY SETUP or, a SETUP message is received specifying a transaction identifier which is
not recognized as relating to an active call or to a call in progress, and with a transaction identifier flag
incorrectly set to "1", this message shall be ignored.
For a network that does support the "Network initiated MO call" option $(CCBS)$:
When an EMERGENCY SETUP, a START CC or, a SETUP message is received specifying a transaction
identifier which is not recognised as relating to an active call or to a call in progress, and with a transaction
identifier flag incorrectly set to "1", this message shall be ignored.
d) When a SETUP message is received by the mobile station specifying a transaction identifier which is recognized
as relating to an active call or to a call in progress, this SETUP message shall be ignored.
3GPP
Release 10 295 3GPP TS 24.008 V10.6.1 (2012-03)
e) For a network that does not support the "Network initiated MO call" option:
When an EMERGENCY SETUP message or a SETUP message is received by the network specifying a
transaction identifier which is recognized as relating to an active call or to a call in progress, this message need
not be treated and the network may perform other actions.
For a network that does support the "Network initiated MO call" option $(CCBS)$:
When an EMERGENCY SETUP message or a START CC message is received by the network specifying a
transaction identifier which is recognised as relating to an active call or to a call in progress, this message need
not be treated and the network may perform other actions.
The same applies to a SETUP message unless the transaction has been established by a START_CC message and
the network is in the "recall present" state (N0.6).
a) Whenever any session management message except ACTIVATE PDP CONTEXT REQUEST, ACTIVATE
SECONDARY PDP CONTEXT REQUEST, or SM-STATUS is received by the network specifying a transaction
identifier which is not recognized as relating to an active PDP context or MBMS context,or to a PDP context or
MBMS context that is in the process of activation or deactivation, the network shall send a SM-STATUS
message with cause #81 "invalid transaction identifier value" using the received transaction identifier value
including the extension octet and remain in the PDP-INACTIVE state.
b) Whenever any session management message except REQUEST PDP CONTEXT ACTIVATION, REQUEST
SECONDARY PDP CONTEXT ACTIVATION, REQUEST MBMS CONTEXT ACTIVATION, or SM-STATUS
is received by the MS specifying a transaction identifier which is not recognized as relating to an active context
or to a context that is in the process of activation or deactivation, the MS shall send a SM-STATUS message with
cause #81 "invalid transaction identifier value" using the received transaction identifier value including the
extension octet and remain in the PDP-INACTIVE state.
c) When a REQUEST PDP CONTEXT ACTIVATION message, REQUEST SECONDARY PDP CONTEXT
ACTIVATION message or REQUEST MBMS CONTEXT ACTIVATION message is received by the MS with a
transaction identifier flag set to "1", this message shall be ignored.
d) When an ACTIVATE PDP CONTEXT REQUEST message is received by the network specifying a transaction
identifier which is not recognized as relating to a PDP context that is in the process of activation, and with a
transaction identifier flag set to "1", this message shall be ignored.
f) Whenever a REQUEST PDP CONTEXT ACTIVATION message or REQUEST SECONDARY PDP CONTEXT
ACTIVATION message is received by the MS specifying a transaction identifier relating to a PDP context or
MBMS context not in state PDP-INACTIVE, the MS shall locally deactivate the old PDP context or MBMS
context relating to the received transaction identifier. Furthermore, the MS shall continue with the activation
procedure of a new PDP context as indicated in the received message.
3GPP
Release 10 296 3GPP TS 24.008 V10.6.1 (2012-03)
g) When an ACTIVATE SECONDARY PDP CONTEXT REQUEST message is received by the network specifying
a transaction identifier which is not recognized as relating to a PDP context that is in the process of activation
and with a transaction identifier flag set to "1", this message shall be ignored.
If a mobile station receives an RR, MM or CC message with message type not defined for the PD or not implemented
by the receiver in acknowledged mode, it shall return a status message (STATUS, MM STATUS depending on the
protocol discriminator) with cause # 97 "message type non-existent or not implemented".
If a mobile station receives a GMM message or SM message with message type not defined for the PD or not
implemented by the receiver, it shall return a status message (GMM STATUS or SM STATUS depending on the
protocol discriminator) with cause # 97 "message type non-existent or not implemented".
If the network receives an MM message with message type not defined for the PD or not implemented by the receiver in
a protocol state where reception of an unsolicited message with the given PD from the mobile station is not foreseen in
the protocol, the network actions are implementation dependent. Otherwise, if the network receives a message with
message type not defined for the PD or not implemented by the receiver, it shall ignore the message except that it
should return a status message (STATUS, MM STATUS, GMM STATUS or SM STATUS depending on the protocol
discriminator) with cause #97 "message type non-existent or not implemented".
NOTE: A message type not defined for the PD in the given direction is regarded by the receiver as a message type
not defined for the PD, see 3GPP TS 24.007 [20].
If the mobile station receives a message not compatible with the protocol state, the mobile station shall ignore the
message except for the fact that, if an RR connection exists, it returns a status message (STATUS, MM STATUS
depending on the protocol discriminator) with cause #98 "Message type not compatible with protocol state". When the
message was a GMM message the GMM-STATUS message with cause #98 "Message type not compatible with
protocol state" shall be returned. When the message was a SM message the SM-STATUS message with cause #98
"Message type not compatible with protocol state" shall be returned.
If the network receives a message not compatible with the protocol state, the network actions are implementation
dependent.
NOTE: The use by GMM and SM of unacknowledged LLC may lead to messages "not compatible with the
protocol state".
- an IE unknown in the message, but encoded as "comprehension required" (see 3GPP TS 24.007 [20]); or
- an out of sequence IE encoded as "comprehension required" (see 3GPP TS 24.007 [20]) is received,
If the message is not one of the messages listed in subclauses 8.5.1, 8.5.2, 8.5.3, 8.5.4 and 8.5.5 a), b) or f), the
mobile station shall ignore the message except for the fact that, if an RR connection exists, it shall return a status
message (STATUS, MM STATUS depending on the protocol discriminator) with cause # 96 "Invalid mandatory
information". If the message was a GMM message the GMM-STATUS message with cause #96 " Invalid
3GPP
Release 10 297 3GPP TS 24.008 V10.6.1 (2012-03)
mandatory information" shall be returned. If the message was an SM message the SM-STATUS message with
cause # 96 "invalid mandatory information" shall be returned.
When the message is not one of the messages listed in subclause 8.5.3 b), c), d) or e) and 8.5.5 a), c), d), e) or
g), the network shall either:
- try to treat the message (the exact further actions are implementation dependent), or
- ignore the message except that it should return a status message (STATUS, or MM STATUS (depending
on the protocol discriminator), GMM STATUS, or SM STATUS) with cause # 96 "Invalid mandatory
information".
b) If the message is a DISCONNECT message, a RELEASE message shall be returned with cause value # 96
"invalid mandatory information" and subclause 5.4. "call clearing" applies as normal.
c) If the message is a RELEASE message, a RELEASE COMPLETE message shall be returned with cause value #
96 "invalid mandatory information".
d) If the message is a RELEASE COMPLETE message, it shall be treated as a normal RELEASE COMPLETE
message.
e) If the message is a HOLD REJECT or RETRIEVE REJECT message, it shall be treated as a normal HOLD
REJECT or RETRIEVE REJECT message.
f) If the message is a STATUS message and received by the network, a RELEASE COMPLETE message may be
returned with cause value # 96 "invalid mandatory information".
b) If the message is a REQUEST PDP CONTEXT ACTIVATION, a REQUEST PDP CONTEXT ACTIVATION
REJECT message with cause # 96 "Invalid mandatory information" shall be returned.
c) If the message is an ACTIVATE PDP CONTEXT REQUEST, an ACTIVATE PDP CONTEXT REJECT message
with cause # 96 "Invalid mandatory information" shall be returned.
e) If the message is a MODIFY PDP CONTEXT REQUEST, a MODIFY PDP CONTEXT REJECT message with
cause # 96 "Invalid mandatory information" shall be returned.
3GPP
Release 10 298 3GPP TS 24.008 V10.6.1 (2012-03)
g) If the message is an ACTIVATE MBMS CONTEXT REQUEST, an ACTIVATE MBMS CONTEXT REJECT
message with cause # 96 "Invalid mandatory information" shall be returned.
- conditional IE errors.
3GPP
Release 10 299 3GPP TS 24.008 V10.6.1 (2012-03)
When the MS upon receipt of a GMM or SM message diagnoses a "missing conditional IE" error or an "unexpected
conditional IE" error or when it receives a GMM or SM message containing at least one syntactically incorrect
conditional IE, it shall ignore the message and it shall return a status message (GMM STATUS or SM STATUS
depending on the PD) with cause value # 100 "conditional IE error".
When the network receives a message and diagnose a "missing conditional IE" error or an "unexpected conditional IE"
error or when it receives a message containing at least one syntactically incorrect conditional IE, the network shall
either
- try to treat the message (the exact further actions are implementation dependent), or
- ignore the message except that it should return a status message (STATUS, MM STATUS, GMM STATUS or
SM STATUS depending on the protocol discriminator) with cause # 100 "conditional IE error".
The network should follow the same procedure except that a status message is not normally transmitted.
Semantic checking of the Facility information element value part (defined in 3GPP TS 24.080 [24]) is the subject of the
technical specifications 3GPP TS 24.010 [21] and the 3GPP TS 24.08x series.
a) a brief description of the message direction and use, including whether the message has:
2. Access significance, i.e. relevant in the originating and terminating access, but not in the network;
3. Dual significance, i.e. relevant in either the originating or terminating access and in the network; or
4. Global significance, i.e. relevant in the originating and terminating access and in the network.
b) a table listing the information elements known in the message and their order of their appearance in the message.
In messages for circuit-switched call control also a shift information element shall be considered as known even
if not included in the table. All information elements that may be repeated are explicitly indicated. (V and LV
formatted IEs, which compose the imperative part of the message, occur before T, TV, and TLV formatted IEs
which compose the non-imperative part of the message, cf. 3GPP TS 24.007 [20].) In a (maximal) sequence of
consecutive information elements with half octet length, the first information element with half octet length
occupies bits 1 to 4 of octet N, the second bits 5 to 8 of octet N, the third bits 1 to 4 of octet N+1 etc. Such a
sequence always has an even number of elements.
1. the information element identifier, in hexadecimal notation, if the IE has format T, TV, or TLV. Usually, there
is a default IEI for an information element type; default IEIs of different IE types of the same protocol are
different. If the IEI has half octet length, it is specified by a notation representing the IEI as a hexadecimal
digit followed by a "-" (example: B-).
3GPP
Release 10 300 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: The same IEI may be used for different information element types in different messages of the same
protocol.
NOTE 2: In the CC protocol the IEI of the locking shift and non-locking shift information elements is the same in
all messages and is not used for any other information elements.
2. the name of the information element (which may give an idea of the semantics of the element). The name of
the information element (usually written in italics) followed by "IE" or "information element" is used in
3GPP TS 24.008 as reference to the information element within a message.
3. the name of the type of the information element (which indicates the coding of the value part of the IE), and
generally, the referenced subclause of clause 10 of 3GPP TS 24.008 describing the value part of the
information element.
4. the presence requirement indication (M, C, or O) for the IE as defined in 3GPP TS 24.007 [20].
5. The format of the information element (T, V, TV, LV, TLV) as defined in 3GPP TS 24.007 [20].
6. The length of the information element (or permissible range of lengths), in octets, in the message, where "?"
means that the maximum length of the IE is only constrained by link layer protocol, and in the case of the
Facility IE by possible further conditions specified in 3GPP TS 24.010 [21]. This indication is non-
normative.
c.) subclauses specifying, where appropriate, conditions for IEs with presence requirement C or O in the relevant
message which together with other conditions specified in 3GPP TS 24.008 define when the information
elements shall be included or not, what non-presence of such IEs means, and - for IEs with presence requirement
C - the static conditions for presence and/or non-presence of the IEs (see 3GPP TS 24.007 [20]).
3GPP
Release 10 301 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
3GPP
Release 10 302 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
In UMTS, the MS shall reject the AUTHENTICATION REQUEST message as specified in subclause 4.3.2.5.1 if this
IE is not present and a USIM is inserted in the MS.
Significance: dual
3GPP
Release 10 303 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
3GPP
Release 10 304 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
NOTE: In A/Gb mode, the maximum number of octets that can be transferred is 20.
3GPP
Release 10 305 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
This message is sent by the network to the mobile station to request the mobile to establish a service for the specified
CM protocol using the specified SAPI, e.g. circuit switched connection establishment on SAPI 0, supplementary
services activation on SAPI 0, or short message transfer on SAPI 3. See Table 9.2.7/3GPP TS 24.008.
Significance: dual
Significance: dual
3GPP
Release 10 306 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
9.2.8 Abort
This message is sent by the network to the mobile station to initiate the abortion of all MM connections and to indicate
the reason for the abortion. See table 9.2.10/3GPP TS 24.008.
Significance: dual
3GPP
Release 10 307 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
9.2.9.2 Priority
May be included by mobile station supporting eMLPP to indicate the priority requested.
This information element is only meaningful when the CM service type is:
3GPP
Release 10 308 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Significance: dual
Significance: dual
3GPP
Release 10 309 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
3GPP
Release 10 310 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Significance: dual
3GPP
Release 10 311 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: In A/Gb mode, the maximum number of octets that can be transferred is 20.
3GPP
Release 10 312 3GPP TS 24.008 V10.6.1 (2012-03)
9.2.15a MM information
This message is sent by the network to the mobile station to provide the mobile station with subscriber specific
information. See table 9.2.18/3GPP TS 24.008.
Significance: dual
If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE
Network Daylight Saving Time.
If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE
Network Daylight Saving Time.
3GPP
Release 10 313 3GPP TS 24.008 V10.6.1 (2012-03)
9.2.16 MM Status
This message is sent by the mobile station or the network at any time to report certain error conditions listed in clause 8.
See table 9.2.19/3GPP TS 24.008.
Significance: local
Direction: both
Significance: dual
3GPP
Release 10 314 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
9.2.19 MM Null
This message is sent in mobile to network direction.
This message is not used on the radio interface. When received by the network it shall be ignored.
3GPP
Release 10 315 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.1 Alerting
Significance: global
3GPP
Release 10 316 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.55/3GPP TS 24.008: ALERTING message content (network to mobile station direction)
9.3.1.1.1 Facility
This information element may be used for functional operation of supplementary services.
- in order to pass information about the call in progress, e.g., in the event of interworking;
- to make the mobile station attach the user connection for speech; and/or
- to make a mobile station supporting multimedia CAT during the alerting phase of a mobile originated
multimedia call establishment attach the user connection and setup an H.324 call.
9.3.1.1.3 User-user
This information element may be included by the network if the called remote user included a user-user information
element in the ALERTING message.
Significance: global
3GPP
Release 10 317 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.55a/3GPP TS 24.008: ALERTING message content (mobile station to network direction)
9.3.1.2.1 Facility
This information element may be used for functional operation of supplementary services.
9.3.1.2.2 User-user
This information element may be included when the called mobile station wants to return information to the calling
remote user.
9.3.1.2.3 SS version
This information element shall not be included if the facility information element is not present in this message.
This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21].
Significance: local
3GPP
Release 10 318 3GPP TS 24.008 V10.6.1 (2012-03)
- the mobile station wishes another bearer capability than that given by the bearer capability 1 information
element of the incoming SETUP message;
- the bearer capability 1 information element is missing or not fully specified in the SETUP message;
- the bearer capability 1 information element received in the SETUP message is accepted and the "radio channel
requirement" of the mobile station is other than "full rate support only mobile station";
- the bearer capability 1 information element received in the SETUP message indicates speech and is accepted
and the mobile station supports CTM text telephony;
- the bearer capability 1 information element received in the SETUP message indicates speech and is accepted
and the mobile station supports other codecs for GERAN than GSM speech version 1;
- the bearer capability 1 information element received in the SETUP message included the "fixed network user
rate" parameter.
When the bearer capability 1 information element is followed by the bearer capability 2 IE in the SETUP, the above
rules apply to both bearer capability 1 IE and bearer capability 2 IE. Except those cases identified in 3GPP TS
27.001 [36], if either bearer capability needs to be included, both shall be included.
Furthermore, both bearer capability information elements may be present if the mobile station wishes to reverse the
order of occurrence of the bearer capability information elements (which is referred to in the repeat indicator
information element, see subclause 10.5.4.22) in cases identified in 3GPP TS 27.001 [36].
If the mobile station wishes to indicate capability for an alternative call mode, which can be entered during the call
through in-call modification, this is indicated by adding a bearer capability information element (bearer capability 2
information element, see subclause 5.3.6).
3GPP
Release 10 319 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.2.3 Cause
This information element is included if the mobile station is compatible but the user is busy.
9.3.2.4 CC Capabilities
This information element may be included by the mobile station to indicate its call control capabilities.
Significance: local
3GPP
Release 10 320 3GPP TS 24.008 V10.6.1 (2012-03)
When the bearer capability 1 information element is followed by the bearer capability 2 IE in the SETUP, the above
rule applies to both bearer capability 1 IE and bearer capability 2 IE. Except those cases identified in
3GPP TS 27.001 [36], if either bearer capability needs to be included, both shall be included.
9.3.3.3 Facility
This information element may be used for functional operation of supplementary services.
- in order to pass information about the call in progress e.g. in the event of interworking; and/or
NOTE: This message has local significance, but may carry information of global significance.
3GPP
Release 10 321 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.4.1 Cause
This information element is included if the user to user information has been discarded as a result of the congestion
situation.
9.3.5 Connect
Significance: global
9.3.5.1.1 Facility
This information element may be used for functional operation of supplementary services.
- in order to pass information about the call in progress e.g. in the event of interworking; and/or
9.3.5.1.3 User-user
This information element may be included by the network if the remote user awarded the call included a user- user
information element in the CONNECT message.
3GPP
Release 10 322 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Table 9.59a/3GPP TS 24.008: CONNECT message content (mobile station to network direction)
9.3.5.2.1 Facility
This information element may be used for functional operation of supplementary services.
9.3.5.2.2 User-user
This information element is included when the answering mobile station wants to return user information to the calling
remote user.
9.3.5.2.3 SS version
This information element shall not be included if the facility information element is not present in this message.
This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21].
Significance: local
Direction: both
3GPP
Release 10 323 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.7 Disconnect
Significance: global
Table 9.61/3GPP TS 24.008: DISCONNECT message content (network to mobile station direction)
9.3.7.1.1 Facility
This information element may be used for functional operation of supplementary services, such as the user-user service.
9.3.7.1.3 User-user
This information element may be included by the network when the remote user initiates call clearing and included a
user-user information element in the DISCONNECT message.
3GPP
Release 10 324 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Table 9.61a/3GPP TS 24.008: DISCONNECT message content (mobile station to network direction)
9.3.7.2.1 Facility
This information element may be used for functional operation of supplementary services, such as the user-user service.
9.3.7.2.2 User-user
This information element is included when the mobile station initiates call clearing and wants to pass user information
to the remote user at call clearing time.
9.3.7.2.3 SS version
This information element shall not be included if the facility information element is not present in this message.
This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21].
Significance: global
3GPP
Release 10 325 3GPP TS 24.008 V10.6.1 (2012-03)
This information element shall be included by an ME supporting CTM text telephony or supporting at least one speech
version for GERAN other than GSM FR speech version 1.
If this information element is included, it shall indicate the selected emergency call category.
If the element is not included, the network shall by default assume a non-specific emergency call.
9.3.9 Facility
3GPP
Release 10 326 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.62a/3GPP TS 24.008: FACILITY message content (network to mobile station direction)
NOTE 1: This message has local significance; however, it may carry information of global significance.
NOTE 2: The facility information element has no upper length limit except that given by the maximum number of
octets in a L3 message, see 3GPP TS 44.006 [19].
Table 9.62b/3GPP TS 24.008: FACILITY message content (mobile station to network direction)
NOTE 1: This message has local significance; however, it may carry information of global significance.
NOTE 2: The facility information element has no upper length limit except that given by the maximum number of
octets in a L3 message, see 3GPP TS 44.006 [19].
9.3.9.2.1 SS version
This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21].
3GPP
Release 10 327 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.10 Hold
This message is sent by the mobile user to request the hold function for an existing call.
See table 9.62c/3GPP TS 24.008 for the content of the HOLD message.
Significance: local
See table 9.62d/3GPP TS 24.008 for the content of the HOLD ACKNOWLEDGE message.
Significance: local
See table 9.62e/3GPP TS 24.008 for the content of the HOLD REJECT message.
Significance: local
3GPP
Release 10 328 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.13 Modify
This message is sent by the mobile station to the network or by the network to the mobile station to request a change in
bearer capability for a call.
Significance: global
Direction: both
3GPP
Release 10 329 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.13.4 Void
Significance: global
Direction: both
Significance: global
3GPP
Release 10 330 3GPP TS 24.008 V10.6.1 (2012-03)
Direction: both
9.3.16 Notify
This message is sent either from the mobile station or from the network to indicate information pertaining to a call, such
as user suspended.
Significance: access
Direction: both
9.3.17 Progress
This message is sent from the network to the mobile station to indicate the progress of a call in the event of
interworking or in connection with the provision of in-band information/patterns.
3GPP
Release 10 331 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
9.3.17.1 User-user
This information element is included when the PROGRESS message is sent by the network when the call has been
cleared by the remote user before it reached the active state to indicate that the remote user wants to pass user
information at call clearing time.
- in order to pass information about the call in progress, e.g., in the event of interworking;
- to make the mobile station attach the user connection for speech; and/or
- to make a mobile station supporting multimedia CAT during the alerting phase of a mobile originated
multimedia call establishment attach the user connection and setup an H.324 call.
This message is sent from the network to the mobile station to provide information on the call that the mobile station
should attempt to establish.
Significance: local
3GPP
Release 10 332 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.17a.1 Void
This message is sent by the mobile station to the network to indicate the requested channel characteristics for the call
which may be initiated by the mobile station.
Significance: local
3GPP
Release 10 333 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.17b.3 Cause
This information element is included if the mobile station is compatible but the user is busy.
9.3.18 Release
Table 9.68/3GPP TS 24.008: RELEASE message content (network to mobile station direction)
NOTE: This message has local significance; however, it may carry information of global significance when used
as the first call clearing message.
9.3.18.1.1 Cause
This information element shall be included if this message is used to initiate call clearing.
3GPP
Release 10 334 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.18.1.3 Facility
This information element may be included for functional operation of supplementary services.
9.3.18.1.4 User-user
This information element may be included in the network to mobile station direction, when the RELEASE message is
used to initiate call clearing, in order to transport user-user information from the remote user.
Table 9.68a/3GPP TS 24.008: RELEASE message content (mobile station to network direction)
NOTE: This message has local significance; however, it may carry information of global significance when used
as the first call clearing message.
9.3.18.2.1 Cause
This information element shall be included if this message is used to initiate call clearing.
9.3.18.2.3 Facility
This information element may be included for functional operation of supplementary services.
3GPP
Release 10 335 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.18.2.4 User-user
This information element is included when the RELEASE message is used to initiate call clearing and the mobile
station wants to pass user information to the remote user at call clearing time.
9.3.18.2.5 SS version
This information element shall not be included if the facility information element is not present in this message.
This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21].
This message is sent from the network to the mobile station to initiate the sending of the SETUP message. In addition it
provides information for user notification.
Significance: local
9.3.18a.2 Facility
The information element shall be included for functional operation of supplementary services.
3GPP
Release 10 336 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.69/3GPP TS 24.008: RELEASE COMPLETE message content (network to mobile station
direction)
NOTE: This message has local significance; however, it may carry information of global significance when used
as the first call clearing message.
9.3.19.1.1 Cause
This information element shall be included if the message is used to initiate call clearing.
9.3.19.1.2 Facility
This information element may be included for functional operation of supplementary services.
9.3.19.1.3 User-user
This information element is included in the network to mobile station direction, when the RELEASE COMPLETE
message is used to initiate call clearing, in order to transport user-user information from the remote user.
3GPP
Release 10 337 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.69a/3GPP TS 24.008: RELEASE COMPLETE message content (mobile station to network
direction)
NOTE: This message has local significance; however, it may carry information of global significance when used
as the first call clearing message.
9.3.19.2.1 Cause
This information element shall be included if the message is used to initiate call clearing.
9.3.19.2.2 Facility
This information element may be included for functional operation of supplementary services.
9.3.19.2.3 User-user
This information element is included in the mobile station to network direction when the RELEASE COMPLETE
message is used to initiate call clearing and the mobile station wants to pass user information to the remote user at call
clearing time.
9.3.19.2.4 SS version.
This information element shall not be included if the facility information element is not present in this message.
This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21].
9.3.20 Retrieve
This message is sent by the mobile user to request the retrieval of a held call.
See table 9.69b/3GPP TS 24.008 for the content of the RETRIEVE message.
3GPP
Release 10 338 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: local
See table 9.69c/3GPP TS 24.008 for the content of the RETRIEVE ACKNOWLEDGE message.
Significance: local
See table 9.69d/3GPP TS 24.008 for the content of the RETRIEVE REJECT message.
Significance: local
3GPP
Release 10 339 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.23 Setup
Significance: global
3GPP
Release 10 340 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.70/3GPP TS 24.008: SETUP message content (network to mobile station direction)
3GPP
Release 10 341 3GPP TS 24.008 V10.6.1 (2012-03)
If the MSC wishes to indicate capability for an altenative call mode, which can be entered through fallback, this is
indicated by adding a bearer capability information element (bearer capability) 2 element (see subclause 5.3.6).
9.3.23.1.3 Facility
This information element may be included for functional operation of supplementary services.
- in order to pass information about the call in progress e.g. in the event of interworking and/or
If included, the LLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE.
If included, the HLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE.
3GPP
Release 10 342 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.23.1.12 User-user
May be included in the network to called mobile station direction when the calling remote user included a user-user
information element in the SETUP message.
9.3.23.1.15 Priority
May be included by the network to indicate the priority of the incoming call if eMLPP is used.
When both Calling Party BCD number IE and Cause of No CLI IE are included in SETUP message then the Cause of
No CLI IE provides additional information on why the number digits are not present.
NOTE: The MSC may use the backup bearer capability IE if it is not able to provide a complete bearer
capability IE.
Significance: global
3GPP
Release 10 343 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.70a/3GPP TS 24.008: SETUP message content (mobile station to network direction)
3GPP
Release 10 344 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.23.2.2 Facility
The information element may be included for functional operation of supplementary services.
Three different codings of this IE exist, for further details see 3GPP TS 24.010 [21].
If included, the LLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE.
If included, the HLC repeat indicator shall specify the same repeat indication as the BC repeat indicator IE.
9.3.23.2.9 User-user
The information element is included in the calling mobile station to network direction when the calling mobile station
wants to pass user information to the called remote user.
9.3.23.2.10 SS version
This information element shall not be included if the facility information element is not present in this message.
This information element shall be included or excluded as defined in 3GPP TS 24.010 [21]. This information element
should not be transmitted unless explicitly required by 3GPP TS 24.010 [21].
3GPP
Release 10 345 3GPP TS 24.008 V10.6.1 (2012-03)
9.3.23.2.13 CC Capabilities
This information element may be included by the mobile station to indicate its call control capabilities.
9.3.23.2.17 Redial
This information element shall be included if the mobile station is attempting to set up a call to switch from speech to
multimedia or vice-versa.
This message is sent by the mobile station to the network to open a Call Control transaction which the network has
requested the mobile station to open.
Significance: local
9.3.23a.1 CC Capabilities
This information element may be included by the mobile station to indicate its call control capabilities
3GPP
Release 10 346 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: local
Significance: local
3GPP
Release 10 347 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: local
9.3.27 Status
This message is sent by the mobile station or the network at any time during a call to report certain error conditions
listed in clause 8. It shall also be sent in response to a STATUS ENQUIRY message.
Significance: local
Direction: both
Significance: local
3GPP
Release 10 348 3GPP TS 24.008 V10.6.1 (2012-03)
Direction: both
Significance: local
Significance: local
3GPP
Release 10 349 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: access
Direction: both
9.3.31.1 User-user
Some networks may only support a maximum length of 35 octets. Procedures for interworking are not currently defined
and are for further study.
R98 and earlier versions of this protocol specified a minimum length of 3 octets for this information element (not
counting the IEI). To avoid interworking problems with mobile stations supporting only R98 or earlier versions of the
protocol, the network shall deliver the User information message to these mobile stations only if the length of the User-
user IE is greater or equal to 3 octets (not counting the IEI).
Significance: dual
Direction: MS to network
3GPP
Release 10 350 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 351 3GPP TS 24.008 V10.6.1 (2012-03)
- if the MS supports CS fallback and SMS over SGs, or the MS is configured to support IMS voice, or both; and
3GPP
Release 10 352 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: network to MS
3GPP
Release 10 353 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 354 3GPP TS 24.008 V10.6.1 (2012-03)
9.4.2.4 MS identity
This IE may be included to assign or unassign a TMSI to an MS in case of a combined GPRS attach.
- a P-TMSI and/or a TMSI was included within the attach accept message; or
3GPP
Release 10 355 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: MS to network
Significance: dual
Direction: network to MS
3GPP
Release 10 356 3GPP TS 24.008 V10.6.1 (2012-03)
In Iu mode, if the MS is not attaching for emergency services, the network shall not include this IE if this message is to
be sent non-integrity protected. If the MS is attaching for emergency bearer services, the network may include this IE if
this message is to be sent non-integrity protected.
In Iu mode, if the MS is not attaching for emergency services, the MS shall ignore the contents of this IE if this message
is received without integrity protection. If the MS is attaching for emergency bearer services, the MS shall use the
received contents of this IE if this message is received without integrity protection.
If this IE is not included or if in Iu mode the message is not integrity protected, the MS shall use the default value.
Significance: dual
Direction: network to MS
Significance: dual
Direction: MS to network
3GPP
Release 10 357 3GPP TS 24.008 V10.6.1 (2012-03)
9.4.5.2.1 P-TMSI
This IE shall be included by the MS, if the P-TMSI is available.
Significance: dual
Direction: MS to network
Significance: dual
Direction: network to MS
3GPP
Release 10 358 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: network to MS
Significance: dual
Direction: MS to network
3GPP
Release 10 359 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: network to MS
3GPP
Release 10 360 3GPP TS 24.008 V10.6.1 (2012-03)
In UMTS, the MS shall reject the AUTHENTICATION & CIPHERING REQUEST message as specified in
subclause 4.7.7.5.1 if this IE is not present and a USIM is inserted in the MS.
Significance: dual
Direction: MS to network
9.4.10.2 IMEISV
This IE is included if requested within the corresponding authentication and ciphering request message.
Significance: dual
3GPP
Release 10 361 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: network to MS
Significance: dual
Direction: network to MS
3GPP
Release 10 362 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: MS to network
Significance: dual
Direction: MS to network
3GPP
Release 10 363 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 364 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 365 3GPP TS 24.008 V10.6.1 (2012-03)
- if the MS supports CS fallback and SMS over SGs, or the MS is configured to support IMS voice, or both, and
Significance: dual
Direction: network to MS
3GPP
Release 10 366 3GPP TS 24.008 V10.6.1 (2012-03)
9.4.15.3 MS identity
This IE may be included to assign or unassign a TMSI to a MS in case of a combined routing area updating procedure.
3GPP
Release 10 367 3GPP TS 24.008 V10.6.1 (2012-03)
In Iu mode, if the MS is not attached for emergency bearer services, the network shall not include this IE if this message
is to be sent non-integrity protected. If the MS is attached for emergency bearer services, the network may include this
IE if this message is to be sent non-integrity protected.
In Iu mode, if this message is received without integrity protection the MS not attached for emergency bearer services
shall ignore the contents of this IE and use the last received value if available. If there is no last received value, the MS
shall use the default value. If the MS is attached for emergency bearer services, the MS shall use the received contents
of this IE if this message is received without integrity protection.
If this IE is not included in the message in A/Gb mode or if in Iu mode this IE is not included in an integrity protected
message, the MS shall use the default value.
3GPP
Release 10 368 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: MS to network
3GPP
Release 10 369 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: network to MS
In Iu mode, if the MS is not attached for emergency bearer services, the network shall not include this IE if this message
is to be sent non-integrity protected. If the MS is attached for emergency bearer services, the network may include this
IE if this message is to be sent non-integrity protected.
In Iu mode, the MS not attached for emergency bearer services shall ignore the contents of this IE if this message is
received without integrity protection. If the MS is attached for emergency bearer services, the MS shall use the received
contents of this IE if this message is received without integrity protection.
If this IE is not included or if in Iu mode the message is not integrity protected, the MS shall use the default value.
Significance: local
3GPP
Release 10 370 3GPP TS 24.008 V10.6.1 (2012-03)
Direction: both
Significance: local
Direction: network to MS
3GPP
Release 10 371 3GPP TS 24.008 V10.6.1 (2012-03)
If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE
Network Daylight Saving Time.
If the local time zone has been adjusted for Daylight Saving Time, the network shall indicate this by including the IE
Network Daylight Saving Time.
Significance: dual
Direction: MS to network
3GPP
Release 10 372 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: dual
Direction: network to MS
Significance: dual
Direction: network to MS
3GPP
Release 10 373 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: MS to network
3GPP
Release 10 374 3GPP TS 24.008 V10.6.1 (2012-03)
This IE shall be included if the MS supports Network Requested Bearer Control procedures.
Significance: global
Direction: network to MS
3GPP
Release 10 375 3GPP TS 24.008 V10.6.1 (2012-03)
If the MS has not indicated PFC procedure support, then it shall ignore this IE, if received.
9.5.2.4 SM cause
This IE shall be included if the network accepts the requested PDN connectivity with restrictions.
- the network is configured to indicate when a PDN connection is a LIPA PDN connection; and
Significance: global
Direction: network to MS
3GPP
Release 10 376 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: MS to network
Table 9.5.4/3GPP TS 24.008: ACTIVATE SECONDARY PDP CONTEXT REQUEST message content
9.5.4.1 TFT
This IE shall be included if a linked PDP context without TFT has already been activated.
Significance: global
Direction: network to MS
3GPP
Release 10 377 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.5.5/3GPP TS 24.008: ACTIVATE SECONDARY PDP CONTEXT ACCEPT message content
If the MS has not indicated PFC procedure support, then it shall ignore this IE, if received.
Significance: global
Direction: network to MS
Table 9.5.6/3GPP TS 24.008: ACTIVATE SECONDARY PDP CONTEXT REJECT message content
3GPP
Release 10 378 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: network to MS
Significance: global
Direction: MS to network
3GPP
Release 10 379 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.5.8/3GPP TS 24.008: REQUEST PDP CONTEXT ACTIVATION REJECT message content
Significance: global
Direction: network to MS
Table 9.5.9/3GPP TS 24.008: MODIFY PDP CONTEXT REQUEST (Network to MS direction) message
content
3GPP
Release 10 380 3GPP TS 24.008 V10.6.1 (2012-03)
in the MODIFY PDP CONTEXT REQUEST message once the address has been actually allocated, in order to update
the PDP context in the MS.
If this IE is not included, the MS shall keep the old Packet Flow Identifier value. If the MS has not indicated PFC
procedure support, then it shall ignore this IE, if received.
9.5.9.4 TFT
This IE is included in the message to provide the MS with uplink and downlink packet filters when the protocol
configuration options information element indicates the selected Bearer Control Mode 'MS/NW'.
Significance: global
Direction: MS to network
Table 9.5.10/3GPP TS 24.008: MODIFY PDP CONTEXT REQUEST (MS to network direction) message
content
3GPP
Release 10 381 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: MS to network
Table 9.5.11/3GPP TS 24.008: MODIFY PDP CONTEXT ACCEPT (MS TO NETWORK DIRECTION)
message content
Significance: global
Direction: Network to MS
3GPP
Release 10 382 3GPP TS 24.008 V10.6.1 (2012-03)
Table 9.5.12/3GPP TS 24.008: MODIFY PDP CONTEXT ACCEPT (NETWORK to MS direction) message
content
If this IE is not included, the MS shall keep the old Packet Flow Identifier value.If the MS has not indicated PFC
procedure support, then it shall ignore this IE, if received.
Significance: global
Direction: both
3GPP
Release 10 383 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: both
3GPP
Release 10 384 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: both
Significance: global
3GPP
Release 10 385 3GPP TS 24.008 V10.6.1 (2012-03)
Direction: network to MS
Table 9.5.15a/3GPP TS 24.008: REQUEST SECONDARY PDP CONTEXT ACTIVATION message content
9.5.15.1a TFT
This IE shall be included if a linked PDP context without TFT has already been activated. This IE provides the MS with
uplink and downlink packet filters.
Significance: global
Direction: MS to network
3GPP
Release 10 386 3GPP TS 24.008 V10.6.1 (2012-03)
9.5.16 Void
9.5.16a Notification
This message is sent by the network to inform the MS about events which are relevant for the upper layer using the PDP
context or having requested a session management procedure. See table 9.5.16a/3GPP TS 24.008.
Significance: local
Direction: network to MS
9.5.17 Void
9.5.18 Void
9.5.19 Void
9.5.20 Void
9.5.21 SM Status
This message is sent by the network or the MS to pass information on the status of the indicated context and report
certain error conditions (eg. as listed in clause 8). See table 9.5.21/3GPP TS 24.008.
Significance: local
Direction: both
3GPP
Release 10 387 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: MS to network
NOTE: The MBMS NSAPI will be used in Iu mode when the network chooses a point-to-point MBMS bearer for
the transfer of MBMS data in the user plane.
Significance: global
Direction: network to MS
3GPP
Release 10 388 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: network to MS
3GPP
Release 10 389 3GPP TS 24.008 V10.6.1 (2012-03)
Significance: global
Direction: network to MS
Significance: global
Direction: MS to network
3GPP
Release 10 390 3GPP TS 24.008 V10.6.1 (2012-03)
10.1 Overview
Within the Layer 3 protocols defined in 3GPP TS 24.008, every message is a standard L3 message as defined in 3GPP
TS 24.007 [20]. This means that the message consists of the following parts:
a) protocol discriminator;
b) transaction identifier;
c) message type;
Unless specified otherwise in the message descriptions of clause 9, a particular information element shall not be present
more than once in a given message.
The term "default" implies that the value defined shall be used in the absence of any assignment, or that this value
allows negotiation of alternative values in between the two peer entities.
When a field extends over more than one octet, the order of bit values progressively decreases as the octet number
increases. The least significant bit of the field is represented by the lowest numbered bit of the highest numbered octet
of the field.
3GPP
Release 10 391 3GPP TS 24.008 V10.6.1 (2012-03)
For the session management protocol, the extended TI mechanism may be used (see 3GPP TS 24.007 [20]).
For the call control protocol, the extended TI mechanism shall be supported for the purpose of protocol error handling
as specified in subclause 8.3.1
8 7 6 5 4 3 2 1
x x 0 0 - - - - Registration messages:
0 0 0 1 - IMSI DETACH INDICATION
0 0 1 0 - LOCATION UPDATING ACCEPT
0 1 0 0 - LOCATION UPDATING REJECT
1 0 0 0 - LOCATION UPDATING REQUEST
x x 0 1 - - - - Security messages:
0 0 0 1 - AUTHENTICATION REJECT
0 0 1 0 - AUTHENTICATION REQUEST
0 1 0 0 - AUTHENTICATION RESPONSE
1 1 0 0 - AUTHENTICATION FAILURE…………..
1 0 0 0 - IDENTITY REQUEST
1 0 0 1 - IDENTITY RESPONSE
1 0 1 0 - TMSI REALLOCATION COMMAND
1 0 1 1 - TMSI REALLOCATION COMPLETE
x x 1 1 - - - - Miscellaneous messages:
0 0 0 0 - MM NULL
0 0 0 1 - MM STATUS
0 0 1 0 - MM INFORMATION
3GPP
Release 10 392 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: This value was allocated but never used in earlier phases of the protocol.
When the radio connection started with a core network node of earlier than R99, bit 8 shall be set to 0 and bit 7 is
reserved for the send sequence number in messages sent from the mobile station. In messages sent from the network,
bits 7 and 8 are coded with a "0". See 3GPP TS 24.007 [20].
When the radio connection started with a core network node of R'99 or later, bits 7 and 8 are reserved for the send
sequence number in messages sent from the mobile station. In messages sent from the network, bits 7 and 8 are coded
with a "0". See 3GPP TS 24.007 [20].
Table 10.3/3GPP TS 24.008: Message types for Call Control and call related SS messages
8 7 6 5 4 3 2 1
x x 0 0 0 0 0 0 escape to nationally specific
message types; see 1) below
x x 1 1 - - - - Miscellaneous messages:
1 0 0 1 - CONGESTION CONTROL
1 1 1 0 - NOTIFY
1 1 0 1 - STATUS
0 1 0 0 - STATUS ENQUIRY
0 1 0 1 - START DTMF
0 0 0 1 - STOP DTMF
0 0 1 0 - STOP DTMF ACKNOWLEDGE
0 1 1 0 - START DTMF ACKNOWLEDGE
0 1 1 1 - START DTMF REJECT
1 0 1 0 - FACILITY
1): When used, the message type is defined in the following octet(s), according to the national specification.
3GPP
Release 10 393 3GPP TS 24.008 V10.6.1 (2012-03)
When the radio connection started with a core network node of earlier than R99, bit 8 shall be set to 0 and bit 7 is
reserved for the send sequence number in messages sent from the mobile station. In messages sent from the network,
bits 7 and 8 are coded with a "0". See 3GPP TS 24.007 [20].
When the radio connection started with a core network node of R'99 or later, bits 7 and 8 are reserved for the send
sequence number in messages sent from the mobile station. In messages sent from the network, bits 7 and 8 are coded
with a "0". See 3GPP TS 24.007 [20].
Bits
8 7 6 5 4 3 2 1
0 0 0 0 0 0 0 1 Attach request
0 0 0 0 0 0 1 0 Attach accept
0 0 0 0 0 0 1 1 Attach complete
0 0 0 0 0 1 0 0 Attach reject
0 0 0 0 0 1 0 1 Detach request
0 0 0 0 0 1 1 0 Detach accept
0 0 0 0 1 1 0 0 Service Request
0 0 0 0 1 1 0 1 Service Accept
0 0 0 0 1 1 1 0 Service Reject
3GPP
Release 10 394 3GPP TS 24.008 V10.6.1 (2012-03)
Bits
8 7 6 5 4 3 2 1
0 1 0 1 0 1 0 1 SM Status
0 1 0 1 1 1 0 1 Notification
The first octet of an information element in the non-imperative part contains the IEI of the information element. If this
octet does not correspond to an IEI known in the message, the receiver shall determine whether this IE is of type 1 or 2
(i.e. it is an information element of one octet length) or an IE of type 4 (i.e. that the next octet is the length indicator
indicating the length of the remaining of the information element) (see 3GPP TS 24.007 [20]).
This allows the receiver to jump over unknown information elements and to analyse any following information
elements.
The information elements which are common for at least two of the three protocols Radio Resources management,
Mobility Management and Call Control, are listed in subclause 10.5.1.
The information elements for the protocols Mobility Management and Call Control are listed in subclauses 10.5.3 and
10.5.4 respectively. Default information element identifiers are listed in annex K.
3GPP
Release 10 395 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: Different information elements may have the same default information element identifier if they belong to
different protocols.
The descriptions of the information element types in subclauses 10.5.1, 10.5.3, and 10.5.4 are organized in alphabetical
order of the IE types. Each IE type is described in one subclause.
- possibly indicating the length that the information element has if it is either type 5 or if it is used in format TV
(type 1 and 3) or TLV (type 4).
- possibly the position and length of the IEI. (However it depends on the message in which the IE occurs whether
the IE contains an IEI.);
- possibly the position and length of the length indicator. (However it depends on the IE type whether the IE
contains a length indicator or not.);
- possibly octet numbers of the octets that compose the IE (see clause a) below).
Finally, the subclause contains tables defining the structure and value range of the fields that compose the IE value part.
The order of appearance for information elements in a message is defined in clause 9.
The order of the information elements within the imperative part of messages has been chosen so that information
elements with 1/2 octet of content (type 1) go together in succession. The first type 1 information element occupies bits
1 to 4 of octet N, the second bits 5 to 8 of octet N, the third bits 1 to 4 of octet N + 1 etc. If the number of type 1
information elements is odd then bits 5 to 8 of the last octet occupied by these information elements contains a spare
half octet IE in format V.
Where the description of information elements in the present document contains bits defined to be "spare bits", these
bits shall set to the indicated value (0 or 1) by the sending side, and their value shall be ignored by the receiving side.
With few exceptions, spare bits are indicated as being set to "0" in 3GPP TS 24.008.
The Cell Identity information element is coded as shown in figure 10.5.1/3GPP TS 24.008 and table 10.5.1/3GPP TS
24.008.
8 7 6 5 4 3 2 1
Cell Identity IEI octet 1
CI value octet 2
3GPP
Release 10 396 3GPP TS 24.008 V10.6.1 (2012-03)
In the CI value field bit 8 of octet 2 is the most significant bit and bit 1 of octet 3 the
least significant bit.
The coding of the cell identity is the responsibility of each administration. Coding
using full hexadecimal representation may be used.
The cell identity consists of 2 octets.
The ciphering key sequence number is allocated by the network and sent with the AUTHENTICATION REQUEST or
AUTHENTICATION AND CIPHERING REQUEST message to the mobile station where it is stored together with the
calculated keys, e.g. Kc, CK, IK, Kc128.
The Ciphering Key Sequence Number information element is coded as shown in figure 10.5.2/3GPP TS 24.008 and
table 10.5.2/3GPP TS 24.008.
In a UMTS authentication challenge, the purpose of the Ciphering Key Sequence Number information element is to
make it possible for the network to identify the ciphering key CK and integrity key IK which are stored in the MS
without invoking the authentication procedure. CK and IK form a Key Set Identifier (KSI) (see 3GPP TS 33.102 [5a])
which is encoded the same as the CKSN and is therefore included in the CKSN field.
8 7 6 5 4 3 2 1
Ciphering Key key sequence octet 1
Sequence Number 0
IEI spare
Bits
3 2 1
0 0 0
through Possible values for the ciphering key
1 1 0 sequence number
The Location Area Identification information element is coded as shown in figure 10.5.3/3GPP TS 24.008 and
table 10.5.3/3GPP TS 24.008.
3GPP
Release 10 397 3GPP TS 24.008 V10.6.1 (2012-03)
The Location Area Identification is a type 3 information element with 6 octets length.
8 7 6 5 4 3 2 1
LAC octet 5
3GPP
Release 10 398 3GPP TS 24.008 V10.6.1 (2012-03)
If the LAI is deleted the MCC and MNC shall take the value from the deleted LAI.
In abnormal cases, the MCC stored in the mobile station can contain elements not
in the set {0, 1 ... 9}. In such cases the mobile station should transmit the stored
values using full hexadecimal encoding. When receiving such an MCC, the network
shall treat the LAI as deleted.
NOTE 1: In earlier versions of this protocol, the possibility to use a one digit MNC
in LAI was provided on the radio interface. However as this was not used
this possibility has been deleted.
In abnormal cases, the MNC stored in the mobile station can have:
- digit 1 or 2 not in the set {0, 1 ... 9}, or
- digit 3 not in the set {0, 1 ... 9, F} hex.
In such cases the mobile station shall transmit the stored values using full
hexadecimal encoding. When receiving such an MNC, the network shall treat the
LAI as deleted.
The same handling shall apply for the network, if a 3-digit MNC is sent by the
mobile station to a network using only a 2-digit MNC.
The IMSI shall not exceed 15 digits, the TMSI/P-TMSI/M-TMSI is 4 octets long, and the IMEI is composed of 15
digits, the IMEISV is 16 digits (see 3GPP TS 23.003 [10]). The TMGI is at maximum 6 octets long and is defined in
subclause 10.5.6.13. The MBMS Session Identity, if included, is 1 octet long (see 3GPP TS 48.018 [86]).
3GPP
Release 10 399 3GPP TS 24.008 V10.6.1 (2012-03)
For packet paging the network shall select the mobile identity type with the following priority:
For MBMS (pre-)notification (see 3GPP TS 44.018 [84] and 3GPP TS 44.060 [76]) the network shall select the mobile
identity type "TMGI and optional MBMS Session Identity".
NOTE 1: The type of identity "TMGI and optional MBMS Session Identity" is only used by the MBMS
(pre-)notification procedure in of A/Gb mode.
- emergency call establishment, emergency call re-establishment, mobile terminated call establishment, the
identification procedure, the GMM identification procedure, the GMM authentication, GPRS attach, routing area
updating, and ciphering procedure and the ciphering mode setting procedure; and
- location updating when the MS is configured for "AttachWithIMSI" as specified in 3GPP TS 24.368 [135] or
3GPP TS 31.102 [112] and the selected PLMN is neither the registered PLMN nor in the list of equivalent
PLMNs;
the mobile station and the network shall select the mobile identity type with the following priority:
For mobile terminated call establishment the mobile station shall select the same mobile identity type as received from
the network in the PAGING REQUEST message. In case of enhanced DTM CS establishment (see 3GPP TS 44.018
[84]) the mobile station shall select the mobile identity type with the following priority in the PAGING RESPONSE
message:
For the PAGING RESPONSE message sent as a response to a paging for CS fallback, the MS shall:
- select the TMSI as mobile identity type if the network has, in E-UTRAN,
- indicated TMSI in the CS SERVICE NOTIFICATION message (see 3GPP TS 24.301 [120]);
- select the IMSI as mobile identity type if the network has, in E-UTRAN,
- indicated IMSI in the CS SERVICE NOTIFICATION message (see 3GPP TS 24.301 [120]).
For emergency call establishment and re-establishment the mobile station shall select the mobile identity type with the
following priority:
1- TMSI: The TMSI shall be used if it is available and if the location update status is UPDATED, and the stored
LAI is equal to the one received on the BCCH from the current serving cell.
2- IMSI: The IMSI shall be used in cases where no TMSI is available or TMSI is available but either the update
status is different from UPDATED, or the stored LAI is different from the one received on the BCCH from
the current serving cell.
3- IMEI: The IMEI shall be used in cases where no SIM/USIM is available or the SIM/USIM is considered as
not valid by the mobile station or no IMSI or TMSI is available.
In the identification procedure and in the GMM identification procedure the mobile station shall select the mobile
identity type which was requested by the network, if available. If the requested identity is not available, then the mobile
station shall indicate the identity type "No Identity".
3GPP
Release 10 400 3GPP TS 24.008 V10.6.1 (2012-03)
In the ciphering mode setting procedure and in the GMM authentication and ciphering procedure the mobile shall select
the IMEISV.
The Mobile Identity information element is coded as shown in figure 10.5.4/3GPP TS 24.008 and table 10.5.4/3GPP TS
24.008.
The Mobile Identity is a type 4 information element with a minimum length of 3 octet and 11 octets length maximal.
Further restriction on the length may be applied, e.g. number plans.
8 7 6 5 4 3 2 1
Mobile Identity IEI octet 1
8 7 6 5 4 3 2 1
Mobile Identity IEI octet 1
Length of Mobile Identity contents octet 2
0 0 MBMS MCC/ odd/
Sess MNC even Type of identity octet 3
spare Id indic indic indic
octet 4
MBMS Service ID octet 5
octet 6
Figure 10.5.4a/3GPP TS 24.008: Mobile Identity information element for type of identity "TMGI and
optional MBMS Session Identity"
3GPP
Release 10 401 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 402 3GPP TS 24.008 V10.6.1 (2012-03)
For the IMSI, IMEI and IMEISV this field is coded using BCD coding. If the number
of identity digits is even then bits 5 to 8 of the last octet shall be filled with an end
mark coded as "1111".
For Type of identity "No Identity", the Identity digit bits shall be encoded with all 0s
and the Length of mobile identity contents parameter shall be set to one of the
following values:
- "1" if the identification procedure is used (see subclause 9.2.11);
- "3" if the GMM identification procedure is used (see subclause 9.4.13)
- "3" if the EMM identification procedure is used (see 3GPP TS 24.301 [120])
For type of identity "TMGI and optional MBMS Session Identity" the coding of octet
3 etc is as follows:
The contents of the MBMS Service ID field are coded as octets 3 to 5 of the
Temporary Mobile Group Identity IE in Figure 10.5.154/3GPP TS 24.008. Therefore,
bit 8 of octet 4 is the most significant bit and bit 1 of octet 6 the least significant bit.
The coding of the MBMS Service ID is the responsibility of each administration.
Coding using full hexadecimal representation may be used. The MBMS Service ID
consists of 3 octets.
3GPP
Release 10 403 3GPP TS 24.008 V10.6.1 (2012-03)
The coding of this field is the responsibility of each administration but BCD coding
shall be used. The MNC shall consist of 2 or 3 digits. If a network operator decides
to use only two digits in the MNC, bits 5 to 8 of octet 6b shall be coded as "1111".
The contents of the MCC and MNC digits are coded as octets 6 to 8 of the
Temporary Mobile Group Identity IE in Figure 10.5.154/3GPP TS 24.008.
The MBMS Session Identity field is encoded as the value part of the MBMS
Session Identity IE as specified in 3GPP TS 48.018 [86].
NOTE 1: This can be used in the case when a fill paging message without any
valid identity has to be sent on the paging subchannel and when the
requested identity is not available at the mobile station during the identity
request procedure.
The Mobile Station Classmark 1 information element is coded as shown in figure 10.5.5/3GPP TS 24.008 and
table 10.5.5/3GPP TS 24.008.
The Mobile Station Classmark 1 is a type 3 information element with 2 octets length.
8 7 6 5 4 3 2 1
Mobile Station Classmark 1 IEI octet 1
0 Revision ES A5/1 RF power
spare level IND capability octet 2
3GPP
Release 10 404 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 405 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: The value of the ES IND gives the implementation in the MS. It's value is not
dependent on the broadcast SI 3 Rest Octet <Early Classmark Sending
Control> value.
When the GSM 1800 or GSM 1900 band is used (for exceptions see 3GPP TS 44.018
[84], sub-clause 3.4.18), the MS shall indicate the RF power capability of the band used
(see table):
When UMTS is used, a single band GSM 1800 or GSM 1900 MS shall indicate the RF
power capability corresponding to the (GSM) band it supports (see table). In this case,
information on which single band is supported is found in classmark 3.
Bits
3 2 1
0 0 0 class 1
0 0 1 class 2
0 1 0 class 3
All other values are reserved.
When UMTS is used, an MS not supporting any GSM band or a multiband GSM MS
shall code this field as follows (see table):
Bits
3 2 1
1 1 1 RF power capability is irrelevant in this information element.
All other values are reserved.
NOTE 2: The requirements for the support of the A5 algorithms in the MS are specified
in 3GPP TS 43.020 [13].
3GPP
Release 10 406 3GPP TS 24.008 V10.6.1 (2012-03)
The Mobile Station Classmark 2 information element is coded as shown in figure 10.5.6/3GPP TS 24.008,
table 10.5.6a/3GPP TS 24.008 and table 10.5.6b/3GPP TS 24.008.
The Mobile Station Classmark 2 is a type 4 information element with 5 octets length.
8 7 6 5 4 3 2 1
Mobile station classmark 2 IEI octet 1
NOTE 1: Owing to backward compatibility problems, bit 8 of octet 4 should not be used unless it is also checked
that the bits 8, 7 and 6 of octet 3 are not "0 0 0".
NOTE 1: The value of the ES IND gives the implementation in the MS. It's value is not
dependent on the broadcast SI 3 Rest Octet <Early Classmark Sending Control> value
3GPP
Release 10 407 3GPP TS 24.008 V10.6.1 (2012-03)
When the GSM 1800 or GSM 1900 band is used (for exceptions see 3GPP TS 44.018 [84]) The
MS shall indicate the RF power capability of the band used (see table).
When UMTS or E-UTRAN is used, a single band GSM 1800 or GSM 1900 MS shall indicate the
RF power capability corresponding to the (GSM) band it supports (see table). In this case,
information on which single band is supported is found in classmark 3
Bits
3 2 1
0 0 0 class 1
0 0 1 class 2
0 1 0 class 3
All other values are reserved.
When UMTS or E-UTRAN is used, an MS not supporting any GSM band or a multiband GSM MS
shall code this field as follows (see table):
Bits
3 2 1
1 1 1 RF Power capability is irrelevant in this information element
All other values are reserved.
3GPP
Release 10 408 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 2: This bit conveys no information about support or non support of the E-GSM or R-GSM
bands when T-GSM 400, GSM 400, GSM 700, T-GSM 810, GSM 850, GSM 1800, GSM 1900
band or UMTS or E-UTRAN is used.
When a GSM 900 band is used (for exceptions see 3GPP TS 44.018 [84]):
Bit 1
0 The MS does not support the E-GSM or R-GSM band (For definition of frequency
bands see 3GPP TS 45.005 [33])
1 The MS does support the E-GSM or R-GSM (For definition of frequency bands see
3GPP TS 45.005 [33])
NOTE 3: For mobile station supporting the R-GSM band further information can be found in MS
Classmark 3.
0 The MS does not support any options that are indicated in CM3
1 The MS supports options that are indicated in classmark 3 IE
LCS VA capability (LCS value added location request notification capability) (octet 5,bit 6)
This information field indicates the support of the LCS value added location request notification via
CS domain as defined in 3GPP TS 23.271 [105].
0 location request notification via CS domain not supported
1 location request notification via CS domain supported
This information field indicates the likely treatment by the mobile station of UCS2 encoded
character strings. For backward compatibility reasons, if this field is not included, the value 0 shall
be assumed by the receiver.
0 the ME has a preference for the default alphabet (defined in 3GPP TS 23.038 [8b]) over
UCS2.
1 the ME has no preference between the use of the default alphabet and the use of
UCS2.
3GPP
Release 10 409 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 4: The requirements for the support of the A5 algorithms in the MS are specified in
3GPP TS 43.020 [13].
NOTE 2: Additional mobile station capability information might be obtained by invoking the classmark
interrogation procedure when GSM is used.
The Mobile Station Classmark 3 is a type 4 information element with a maximum of 34 octets length.
The value part of a Mobile Station Classmark 3 information element is coded as shown in figure 10.5.7/3GPP TS
24.008 and table 10.5.7/3GPP TS 24.008.
NOTE: The 34 octet limit is so that the CLASSMARK CHANGE message will fit in up to two layer 2 frames.
SEMANTIC RULE: a multiband mobile station shall provide information about all frequency bands it can support. A
single band mobile station shall not indicate the band it supports in the Multiband Supported, GSM 400 Bands
Supported, GSM 710 Associated Radio Capability, GSM 750 Associated Radio Capability, T-GSM 810 Associated
Radio Capability, GSM 850 Associated Radio Capability or GSM 1900 Associated Radio Capability fields in the
Mobile Station Classmark 3. Due to shared radio frequency channel numbers between GSM 1800 and GSM 1900, the
mobile should indicate support for either GSM 1800 band OR GSM 1900 band.
SEMANTIC RULE: a mobile station shall include the MS Measurement Capability field if the Multi Slot Class field
contains a value of 19 or greater (see 3GPP TS 45.002 [32]).
Typically, the number of spare bits at the end is the minimum to reach an octet boundary. The receiver may add any
number of bits set to "0" at the end of the received string if needed for correct decoding.
3GPP
Release 10 410 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 411 3GPP TS 24.008 V10.6.1 (2012-03)
< UMTS 1.28 Mcps TDD Radio Access Technology Capability : bit >
< GERAN Feature Package 1 : bit >
0 -- The value '1' was allocated in an earlier version of the protocol and shall not be used.
3GPP
Release 10 412 3GPP TS 24.008 V10.6.1 (2012-03)
< UTRA CSG Cells Reporting : bit > -- Release 9 starts here
< VAMOS Level : bit(2) >
<R Support>::=
< R-GSM band Associated Radio Capability : bit(3) > ;
3GPP
Release 10 413 3GPP TS 24.008 V10.6.1 (2012-03)
Band 1 supported
Bit 1
0 P-GSM not supported
1 P-GSM supported
Band 2 supported
Bit 2
0 E-GSM or R-GSM not supported
1 E-GSM or R-GSM supported
Band 3 supported
Bit 3
0 GSM 1800 not supported
1 GSM 1800 supported
The indication of support of P-GSM band or E-GSM or R-GSM band is mutually exclusive.
When the 'Band 2 supported' bit indicates support of E-GSM or R-GSM, the presence of the <R Support> field,
see below, indicates if the E-GSM or R-GSM band is supported.
In this version of the protocol, the sender indicates in this field either none, one or two of these 3 bands
supported.
For single band mobile station or a mobile station supporting none of the GSM 900 bands(P-GSM, E-GSM and
R-GSM) and GSM 1800 bands, all bits are set to 0.
A5/4
0 Encryption algorithm A5/4 not available
1 Encryption algorithm A5/4 available
A5/5
0 Encryption algorithm A5/5 not available
1 Encryption algorithm A5/5 available
A5/6
0 Encryption algorithm A5/6 not available
1 Encryption algorithm A5/6 available
A5/7
0 Encryption algorithm A5/7 not available
1 Encryption algorithm A5/7 available
If either of P-GSM or E-GSM or R-GSM is supported, the radio capability 1 field indicates the radio capability for
P-GSM, E-GSM or R-GSM, and the radio capability 2 field indicates the radio capability for GSM 1800 if
supported, and is spare otherwise.
If none of P-GSM or E-GSM or R-GSM are supported, the radio capability 1 field indicates the radio capability
for GSM 1800, and the radio capability 2 field is spare.
The radio capability contains the binary coding of the power class associated with the band indicated in
multiband support bits (see 3GPP TS 45.005 [33]).
(continued...)
3GPP
Release 10 414 3GPP TS 24.008 V10.6.1 (2012-03)
In case where the R-GSM band is supported the R-GSM band associated radio capability field contains the
binary coding of the power class associated (see 3GPP TS 45.005 [33]) (regardless of the number of GSM
bands supported). A mobile station supporting the R-GSM band shall also when appropriate, (see 10.5.1.6)
indicate its support in the 'FC' bit in the Mobile Station Classmark 2 information element.
NOTE: The coding of the power class for P-GSM, E-GSM, R-GSM and GSM 1800 in radio capability 1 and/or 2
is different to that used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements.
In case the MS supports the use of multiple timeslots for HSCSD then the HSCSD Multi Slot Class field is coded
as the binary representation of the multislot class defined in 3GPP TS 45.002 [32].
This information field indicates the likely treatment by the mobile station of UCS2 encoded character strings. If
not included, the value 0 shall be assumed by the receiver.
0 the ME has a preference for the default alphabet (defined in 3GPP TS 23.038 [8b]) over UCS2.
1 the ME has no preference between the use of the default alphabet and the use of UCS2.
This bit indicates whether the mobile station supports 'Extended Measurements' or not
0 the MS does not support Extended Measurements
1 the MS supports Extended Measurements
3GPP
Release 10 415 3GPP TS 24.008 V10.6.1 (2012-03)
MS based E-OTD
Bit 4
0 MS based E-OTD not supported
1 MS based E-OTD supported
MS assisted GPS
Bit 3
0 MS assisted GPS not supported
1 MS assisted GPS supported
MS based GPS
Bit 2
0 MS based GPS not supported
1 MS based GPS supported
MS Conventional GPS
Bit 1
0 conventional GPS not supported
1 conventional GPS supported
An MS that supports ECSD shall include this field to indicate its ECSD capability. Whether the MS is capable of
8-PSK modulation in uplink is indicated by the value of the Modulation Capability field in the 8-PSK struct. The
ECSD Multi Slot Class field is coded as the binary representation of the multislot class defined in 3GPP TS
45.002 [32].
8-PSK struct
The MS shall include the 8-PSK struct if it supports ECSD or DTM EGPRS or both.
Modulation Capability
The Modulation Capability field indicates the modulation scheme the MS supports in addition to GMSK.
0 8-PSK supported for downlink reception only
1 8-PSK supported for uplink transmission and downlink reception
The respective 8-PSK RF Power Capability 1 and 8-PSK RF Power Capability 2 fields contain the following
coding of the 8-PSK modulation power class (see 3GPP TS 45.005 [33]):
Bits 2 1
00 Reserved
01 Power class E1
10 Power class E2
11 Power class E3
3GPP
Release 10 416 3GPP TS 24.008 V10.6.1 (2012-03)
The radio capability contains the binary coding of the power class associated with the band indicated in GSM
400 Bands Supported bits (see 3GPP TS 45.005 [33]).
NOTE: The coding of the power class for GSM 450 and GSM 480 in GSM 400 Associated Radio Capability is
different to that used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements.
The radio capability contains the binary coding of the power class associated with the GSM 850 band (see
3GPP TS 45.005 [33]).
Note: the coding of the power class for GSM 850 in GSM 850 Associated Radio Capability is different to that
used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements.
The radio capability contains the binary coding of the power class associated with the GSM 1900 band (see
3GPP TS 45.005 [33]).
Note: the coding of the power class for GSM 1900 in GSM 1900 Associated Radio Capability is different to that
used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements.
3GPP
Release 10 417 3GPP TS 24.008 V10.6.1 (2012-03)
UMTS 3.84 Mcps TDD Radio Access Technology Capability (1 bit field)
0 UMTS 3.84 Mcps TDD not supported
1 UMTS 3.84 Mcps TDD supported
If a multislot class type 1 MS indicates the support of a DTM GPRS multislot class for which three uplink
timeslots can be assigned, the mobile station shall support Extended Dynamic Allocation.
This field shall contain one of the following values if the DTM GPRS High Multi Slot Class field is present:
- Multislot class 9 if DTM GPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
- Multislot class 11 if DTM GPRS High Multi Slot Class is set to indicate Classes
32/37, 33/38 or Classes 42, 43, 44.
An MS indicating support for Extended DTM GPRS multislot class or Extended DTM EGPRS multislot class
shall set this bit to ‘1’. The network may ignore the bit in this case.
If a multislot class type 1 MS indicates the support of a DTM EGPRS multislot class for which three uplink
timeslots can be assigned, the mobile station shall support Extended Dynamic Allocation.
This field shall contain one of the following values if the DTM EGPRS High Multi Slot Class field is present:
- Multislot class 9 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
- Multislot class 11 if DTM EGPRS High Multi Slot Class is set to indicate Classes
32/37, 33/38 or Classes 42, 43, 44.
3GPP
Release 10 418 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: When this field is received, the associated RF power capability is found in Classmark 1 or 2.
The radio capability contains the binary coding of the power class associated with the GSM 750 band (see
3GPP TS 45.005 [33]).
NOTE: The coding of the power class for GSM 750 in GSM 750 Associated Radio Capability is different to that
used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements.
UMTS 1.28 Mcps TDD Radio Access Technology Capability (1 bit field)
0 UMTS 1.28 Mcps TDD not supported
1 UMTS 1.28 Mcps TDD supported
The presence of this field indicates that the MS supports combined fullrate and halfrate GPRS channels in the
downlink.When this field is not present, the MS supports the multislot class indicated by the DTM GPRS Multi
Slot Class field.
If this field is included, it shall contain one of the following values if the DTM GPRS High Multi Slot Class field is
present:
- Multislot class 10 if DTM GPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
- Multislot class 11 if DTM GPRS High Multi Slot Class is set to indicate Classes
32/37, 33/38 or Classes 42, 43, 44.
3GPP
Release 10 419 3GPP TS 24.008 V10.6.1 (2012-03)
EGPRS Multi Slot Class field. This field is coded as the Extended DTM GPRS Multi Slot Class field. The
presence of this field indicates that the MS supports combined fullrate and halfrate GPRS channels in the
downlink. When this field is not present, the MS supports the multislot class indicated by the DTM EGPRS Multi
Slot Class field.
If this field is included, it shall contain one of the following values if the DTM EGPRS High Multi Slot Class field
is present:
- Multislot class 10 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
- Multislot class 11 if DTM EGPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or
Classes 42, 43, 44.
Bits
21
00 GMSK_MULTISLOT_POWER_PROFILE 0
01 GMSK_MULTISLOT_POWER_PROFILE 1
10 GMSK_MULTISLOT_POWER_PROFILE 2
11 GMSK_MULTISLOT_POWER_PROFILE 3
Bits
21
00 8-PSK_MULTISLOT_POWER_PROFILE 0
01 8-PSK_MULTISLOT_POWER_PROFILE 1
10 8-PSK_MULTISLOT_POWER_PROFILE 2
11 8-PSK_MULTISLOT_POWER_PROFILE 3
3GPP
Release 10 420 3GPP TS 24.008 V10.6.1 (2012-03)
If either T-GSM 410 or T-GSM 380 or both is supported, the T-GSM 400 Associated Radio Capability field
indicates the radio capability for T-GSM 410 and/or T-GSM 380.
The radio capability contains the binary coding of the power class associated with the band indicated in T-GSM
400 Bands Supported bits (see 3GPP TS 45.005 [33]).
NOTE: The coding of the power class for T-GSM 410 and T-GSM 380 in T-GSM 400 Associated Radio
Capability is different to that used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information
elements.
0 The mobile station does not support enhanced DTM CS establishment and enhanced DTM CS release
procedures.
1 The mobile station supports enhanced DTM CS establishment and enhanced DTM CS release
procedures.
Bit
321
000 Unused. If received, the network shall interpret this as ‘0 0 1’
001 Multislot class 31 or 36 supported
010 Multislot class 32 or 37 supported
011 Multislot class 33 or 38 supported
100 Multislot class 41 supported
101 Multislot class 42 supported
110 Multislot class 43 supported
111 Multislot class 44 supported
The presence of this field indicates that the MS supports the DTM extension to high multislot classes. When this
field is not present, the MS supports the DTM multislot class indicated by the DTM GPRS Multi Slot Class field.
The values '0 0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM GPRS multislot class 36, 37 or 38
respectively if the Offset required field indicates that the offset t0 is required; in all other cases those codepoints
shall be interpreted as indicating DTM GPRS multislot class 31, 32 or 33 respectively.
The values '0 0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM EGPRS multislot class 36, 37 or 38
respectively if the Offset required field indicates that the Timing Advance offset t0 is required; in all other cases
those codepoints shall be interpreted as indicating DTM EGPRS multislot class 31, 32 or 33 respectively.
3GPP
Release 10 421 3GPP TS 24.008 V10.6.1 (2012-03)
An MS that only supports Repeated Downlink FACCH shall set this bit field to ‘0’.
The radio capability contains the binary coding of the power class associated with the GSM 710 band (see
3GPP TS 45.005 [33]).
NOTE: The coding of the power class for GSM 710 in GSM 710 Associated Radio Capability is different to that
used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements.
The radio capability contains the binary coding of the power class associated with the T-GSM 810 band (see
3GPP TS 45.005 [33]).
NOTE: The coding of the power class for T-GSM 810 in T-GSM 810 Associated Radio Capability is different to
that used in the Mobile Station Classmark 1 and Mobile Station Classmark 2 information elements.
0 The mobile station does not support the Ciphering Mode Setting IE in the
DTM ASSIGNMENT COMMAND message
1 The mobile station supports the Ciphering Mode Setting IE in the DTM ASSIGNMENT COMMAND
message
0 The mobile station does not support additional positioning capabilities which can be retrieved using
RRLP
1 The mobile station supports additional positioning capabilities which can be retrieved using RRLP.
Bit
0 E-UTRAN Neighbour Cell measurements and measurement reporting while having an RR connection
3GPP
Release 10 422 3GPP TS 24.008 V10.6.1 (2012-03)
not supported
1 E-UTRAN Neighbour Cell measurements and measurement reporting while having an RR connection
supported
Bit
0 Priority-based cell reselection not supported
1 Priority-based cell reselection supported
Bits
21
00 VAMOS not supported
01 VAMOS I supported
10 VAMOS II supported
11 Unused. If received, the network shall interpret this as ’10’.
Bits
21
00 TIGHTER not supported
01 TIGHTER supported for speech and signalling channels only
10 TIGHTER supported for speech and signalling channels and for GPRS and EGPRS, but not for EGPRS2
11 TIGHTER supported for speech and signalling channels and for GPRS, EGPRS and EGPRS2
Bit
0 Selective Ciphering of Downlink SACCH not supported
1 Selective Ciphering of Downlink SACCH supported
The Descriptive Group or Broadcast Call Reference information element is coded as shown in figure 10.5.8/3GPP TS
24.008 and Table10.5.8/3GPP TS 24.008
3GPP
Release 10 423 3GPP TS 24.008 V10.6.1 (2012-03)
The Descriptive Group or Broadcast Call Reference is a type 3 information element with 6 octets length.
8 7 6 5 4 3 2 1
Group or broadcast call reference IEI octet 1
octet 3
octet 4
3GPP
Release 10 424 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 425 3GPP TS 24.008 V10.6.1 (2012-03)
The Group Cipher Key Number information element is coded as shown in figure 10.5.9/3GPP TS 24.008 and
Table10.5.9/3GPP TS 24.008
The Group Cipher Key Number is a type 1 information element with 1 octet length.
8 7 6 5 4 3 2 1
Group cipher key number
IEI Group cipher key number
The PD and SAPI information element is coded as shown in figure 10.5.10/3GPP TS 24.008 and table 10.5.10/3GPP TS
24.008.
8 7 6 5 4 3 2 1
PD and SAPI IEI octet 1
0 0 SAPI PD
spare spare octet 2
Figure10.5.10/3GPP TS 24.008
PD and SAPI information element
3GPP
Release 10 426 3GPP TS 24.008 V10.6.1 (2012-03)
Bits
6 5
0 0 SAPI 0
0 1 reserved
1 0 reserved
1 1 SAPI 3
The Priority Level information element is coded as shown in figure 10.5.11/3GPP TS 24.008 and table 10.5.11/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
Priority Level 0 call priority
IEI spare octet 1
NOTE: These IEs do not have an IEI or a length indicator, because these IEs are never present in any layer 3
messages, Hence these IEs do not conform to the general IE rules defined in 3GPP TS 24.007 [20].
3GPP
Release 10 427 3GPP TS 24.008 V10.6.1 (2012-03)
The content of the CN common GSM-MAP NAS system information element is coded as shown in
figure 10.5.1.12.1/3GPP TS 24.008 and table 10.5.1.12.1/3GPP TS 24.008.
The length of this element content is two octets. The MS shall ignore any additional octets received.
8 7 6 5 4 3 2 1
LAC octet 1
octet 2
For CS domain, the content of the CN domain specific GSM-MAP NAS system information element is coded as shown
in figure 10.5.1.12.2/3GPP TS 24.008 and table 10.5.1.12.2/3GPP TS 24.008. The length of this element content is two
octets. The MS shall ignore any additional octets received.
8 7 6 5 4 3 2 1
T3212 octet 1
Spare ATT octet 2
The bits 2 – 8 of octet 2 are spare and shall be coded all zeros.
3GPP
Release 10 428 3GPP TS 24.008 V10.6.1 (2012-03)
For PS domain, the content of the CN domain specific GSM-MAP NAS system information element is coded as shown in
figure 10.5.1.12.3/3GPP TS 24.008 and table 10.5.1.12.3/3GPP TS 24.008. The length of this element content is two
octets. The MS shall ignore any additional octets received.
8 7 6 5 4 3 2 1
RAC octet 1
Spare NMO I NMO octet 2
The bits 3 – 8 of octet 2 are spare and shall be coded all zeros.
The PLMN List information element is coded as shown in figure 10.5.13/3GPP TS 24.008 and table 10.5.13/3GPP TS
24.008.
The PLMN List is a type 4 information element with a minimum length of 5 octets and a maximum length of 47 octets.
3GPP
Release 10 429 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
The content of the NAS container for PS HO information element is coded as shown in figure 10.5.1.14/3GPP TS
24.008 and table 10.5.1.14/3GPP TS 24.008. The length of this information element is 5 octets. The MS shall ignore any
additional octets received.
8 7 6 5 4 3 2 1
0 0 0 old 0 Type of ciphering octet 1
spare spare spare XID spare algorithm
IOV-UI value (High-order octet) octet 2
IOV-UI value (continued) octet 3
IOV-UI value (continued) octet 4
IOV-UI value (Low-order octet) octet 5
3GPP
Release 10 430 3GPP TS 24.008 V10.6.1 (2012-03)
Bit 5
0 The MS shall perform a Reset of LLC and SNDCP without old XID indicator as specified in
3GPP TS 44.064 [78a] and 3GPP TS 44.065 [78].
1 The MS shall perform a Reset of LLC and SNDCP with old XID indicator as specified in
3GPP TS 44.064 [78a] and 3GPP TS 44.065 [78].
The bits 6 – 8 of octet 1 are spare and shall be coded all zeroes.
The MS network feature support information element is coded as shown in figure 10.5.1.15/3GPP TS 24.008 and
table 10.5.1.15/3GPP TS 24.008.
8 7 6 5 4 3 2 1
MS network feature support 0 0 0 extend octet 1
IEI Spare Spare Spare ed
periodi
c
timers
3GPP
Release 10 431 3GPP TS 24.008 V10.6.1 (2012-03)
Bit
1
0 MS does not support the extended periodic timer in this domain
1 MS supports the extended periodic timer in this domain
The relevant extended periodic timer is T3212 for MM messages, T3312 for GMM
messages, and T3412 for EMM messages.
The Authentication Parameter RAND information element is coded as shown in figure 10.5.75/3GPP TS 24.008 and
table 10.5.89/3GPP TS 24.008.
The Authentication Parameter RAND is a type 3 information element with 17 octets length.
8 7 6 5 4 3 2 1
Authentication parameter RAND IEI octet 1
octet 17
The Authentication Parameter AUTN information element is coded as shown in figure 10.5.75.1/3GPP TS 24.008 and
table 10.5.89.1/3GPP TS 24.008.
The Authentication Parameter AUTN is a type 4 information element with a length of 18 octets.
3GPP
Release 10 432 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Authentication Parameter AUTN IEI octet 1
Length of AUTN contents octet 2
octet 3
AUTN
octet 18
Figure 10.5.75.1/3GPP TS 24.008 Authentication Parameter AUTN information element (UMTS and
EPS authentication challenge)
Table 10.5.89.1/3GPP TS 24.008 Authentication Parameter AUTN information element (UMTS and EPS
authentication challenge)
Bit 8 of octet 9 is the "separation bit" of the AMF field (see 3GPP TS 33.401 [123]).
The Authentication Parameter SRES information element is coded as shown in figure 10.5.76/3GPP TS 24.008 and
tables 10.5.90 a & b /3GPP TS 24.008.
The Authentication Response Parameter is a type 3 information element with 5 octets length. In a GSM authentication
challenge, the response calculated in the SIM/USIM (SRES) is 4 bytes in length, and is placed in the Authentication
Response Parameter information element.
In a UMTS authentication challenge, the response calculated in the USIM (RES) may be up to 16 octets in length. The 4
most significant octets shall be included in the Authentication Response Parameter information element. The remaining
part of the RES shall be included in the Authentication Response Parameter (extension) IE (see subclause 10.5.3.2.1)
8 7 6 5 4 3 2 1
Authentication Response parameter IEI octet 1
3GPP
Release 10 433 3GPP TS 24.008 V10.6.1 (2012-03)
The Authentication Response parameter (extension) IE is coded as shown in figure 10.5.76.1/3GPP TS 24.008 and table
10.5.90.1/3GPP TS 24.008.
The Authentication Response parameter (extension) IE is a type 4 information element with a minimum length of 3
octets and a maximum length of 14 octets.
8 7 6 5 4 3 2 1
Authentication Response (extension) IEI octet 1
Length of Authentication Response contents octet 2
RES (all but 4 most significant octets) octet 3
:
:
octet 14
The Authentication Failure parameter IE is coded as shown in figure 10.5.76.2/3GPP TS 24.008 and table
10.5.90.2/3GPP TS 24.008.
The Authentication Failure parameter IE is a type 4 information element with a length of 16 octets.
3GPP
Release 10 434 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Authentication Failure parameter IEI octet 1
Length ofAuthentication Failure parameter contents octet 2
Authentication Failure parameter octet 3
:
:
octet 16
Figure 10.5.76.2/3GPP TS 24.008 Authentication Failure parameter information element (UMTS and
EPS authentication challenge)
The CM Service Type information element is coded as shown in figure 10.5.77/3GPP TS 24.008 and table 10.5.91/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
CM service type IEI service type octet 1
The Identity Type information element is coded as shown in figure 10.5.78/3GPP TS 24.008 and table 10.5.92/3GPP TS
24.008.
3GPP
Release 10 435 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Identity type IEI 0 type of identity octet 1
spare
The Location Updating Type information element is coded as shown in figure 10.5.79/3GPP TS 24.008 and
table 10.5.93/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Location updating FOR 0 LUT octet 1
type IEI spare
LUT (octet 1)
Bits
2 1
0 0 Normal location updating
0 1 Periodic updating
1 0 IMSI attach
1 1 Reserved
FOR (octet 1)
The Follow-On Request bit (FOR) is coded as follows:
Bits
4
0 No follow-on request pending
1 Follow-on request pending
3GPP
Release 10 436 3GPP TS 24.008 V10.6.1 (2012-03)
The Network Name information element is coded as shown in figure 10.5.80/3GPP TS 24.008 and table 10.5.94/3GPP
TS 24.008.
If the coding scheme UCS2 is used and Chinese-Japanese-Korean-Vietnamese (CJKV) ideographs as defined in
ISO/IEC 10646 [72] are received in the text string, the MS shall use the MCC of the PLMN from which it received the
network name information element to determine the language for those CJKV ideographs as specified in
table 10.5.93a/3GPP TS 24.008:
NOTE: This is due to CJKV ideograph language ambiguity in UCS2, in the sense that the same hexadecimal code
can be mapped to different character displays dependent on the used language. The coding of CJKV
ideographs itself does not allow to discriminate the CJKV ideograph language.
The Network Name is a type 4 information element with a minimum length of 3 octets. No upper length limit is
specified except for that given by the maximum number of octets in a L3 message (see 3GPP TS 44.006 [19]).
8 7 6 5 4 3 2 1
Network Name IEI octet 1
octet 4
Text String
octet n
3GPP
Release 10 437 3GPP TS 24.008 V10.6.1 (2012-03)
2 1
0 0 1 bit 8 is spare and set to "0" in octet n
0 1 0 bits 7 and 8 are spare and set to "0" in octet n
0 1 1 bits 6 to 8(inclusive) are spare and set to "0" in octet n
1 0 0 bits 5 to 8(inclusive) are spare and set to "0" in octet n
1 0 1 bits 4 to 8(inclusive) are spare and set to "0" in octet n
1 1 0 bits 3 to 8(inclusive) are spare and set to "0" in octet n
1 1 1 bits 2 to 8(inclusive) are spare and set to "0" in octet n
0 0 0 this field carries no information about the number of spare bits in octet n
0 The MS should not add the letters for the Country's Initials to the text string
1 The MS should add the letters for the Country's Initials and a separator
(e.g. a space) to the text string
0 0 0 Cell Broadcast data coding scheme, GSM default alphabet, language unspecified, defined in 3GPP TS
23.038 [8b]
0 0 1 UCS2 (16 bit) [72]
0 1 0
to reserved
1 1 1
The Reject Cause information element is coded as shown in figure 10.5.81/3GPP TS 24.008 and
table 10.5.95/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Reject cause IEI octet 1
3GPP
Release 10 438 3GPP TS 24.008 V10.6.1 (2012-03)
Any other value received by the mobile station shall be treated as 0010 0010,
'Service option temporarily out of order'. Any other value received by the network
shall be treated as 0110 1111, 'Protocol error, unspecified'.
The Follow-on Proceed information element is coded as shown in figure 10.5.82/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Follow-on Proceed IEI octet 1
3GPP
Release 10 439 3GPP TS 24.008 V10.6.1 (2012-03)
The Time Zone information element is coded as shown in figure 10.5.83/3GPP TS 24.008 and
table 10.5.96/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Time Zone IEI octet 1
Time Zone
octet 2
The purpose of the time part of this information element is to encode the universal time at which this information
element may have been sent by the network.
The Time Zone and Time information element is coded as shown in figure 10.5.84/3GPP TS 24.008 and
table 10.5.97/3GPP TS 24.008.
The Time Zone and Time is a type 3 information element with a length of 8 octets.
8 7 6 5 4 3 2 1
Time Zone and Time IEI octet 1
Year
octet 2
Month
octet 3
Day
octet 4
Hour
octet 5
Minute
octet 6
Second
octet 7
Time zone
octet 8
3GPP
Release 10 440 3GPP TS 24.008 V10.6.1 (2012-03)
This field uses the same format as the Year field used in the TP-Service-Centre-Time-Stamp, which is defined in 3GPP
TS 23.040 [90], and its value shall be set as defined in 3GPP TS 22.042 [89]
NOTE: Due to ambiguities in earlier versions of the protocol specifications, some mobile stations may interpret
the received NITZ time as local time. This may result in incorrect time settings in the mobile.
8 7 6 5 4 3 2 1
CTS Permission IEI octet 1
3GPP
Release 10 441 3GPP TS 24.008 V10.6.1 (2012-03)
The LSA Identifier information element is coded as shown in figure 10.68c/3GPP TS 24.008.
8 7 6 5 4 3 2 1
LSA Identifier IEI octet 1
Length of LSA Identifier contents
octet 2
LSA ID
octet 3
LSA ID cont.
octet 4
LSA ID cont.
octet 5
If the Length = 0, then no LSA ID is included. This is used to indicate that the MS has moved to an area
where there is no LSA available for that MS.
Octets 3-5 are coded as specified in 3GPP TS 23.003 [10], 'Identification of Localised Service Area'. Bit 8 of octet 3 is
the most significant bit.
The Daylight Saving Time information element is coded as shown in figure 10.5.84b/3GPP TS 24.008 and
table 10.5.97a/3GPP TS 24.008.
The Daylight Saving Time is a type 4 information element with a length of 3 octets.
8 7 6 5 4 3 2 1
Daylight Saving Time IEI octet 1
3GPP
Release 10 442 3GPP TS 24.008 V10.6.1 (2012-03)
The Emergency Number List information element is coded as shown in figure 10.5.84c/3GPP TS 24.008.
The Emergency Number List IE is a type 4 information element with a minimum length of 5 octets and a maximum
length of 50 octets.
8 7 6 5 4 3 2 1
Emergency Number List IEI octet 1
Length of Emergency Number List IE contents octet 2
Length of 1st Emergency Number information note 1) octet 3
spare Emergency Service Category Value (see octet 4
0 0 0 Table 10.5.135d/3GPP TS 24.008)
Number digit 2 Number digit 1 octet 5
note 2)
Number digit 4 Number digit 3 octet 6*
: : :
: : :
. .
. .
. .
Length of xth Emergency Number information note 1) octet n*
spare Emergency Service Category Value (see Octet n+1*
0 0 0 Table 10.5.135d/3GPP TS 24.008)
Number digit 2 Number digit 1 octet n+2*
note 2)
Number digit 4 Number digit 3 octet n+3*
: : :
NOTE 1: The length contains the number of octets used to encode the Emergency Service Category Value and the
Number digits.
NOTE 2: The number digit(s) in octet 5 precedes the digit(s) in octet 6 etc. The number digit, which would be
entered first, is located in octet 5, bits 1 to 4. The contents of the number digits are coded as shown in
table 10.5.118/3GPP TS 24.008.
NOTE 3: If the emergeny number contains an odd number of digits, bits 5 to 8 of the last octet of the respective
emergency number shall be filled with an end mark coded as "1111".
3GPP
Release 10 443 3GPP TS 24.008 V10.6.1 (2012-03)
The Additional update parameters information element is coded as shown in figure 10.5.84d/3GPP TS 24.008 and
table 10.5.97b/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Additional update parameters 0 0 CSMO CSMT octet 1
IEI Spare Spare
Bit
1
0 No additional information.
1 CS fallback mobile terminating call
Bit
2
0 No additional information.
1 CS fallback mobile originating call
Bits 4 and 3 of octet 1 are spare and shall be all coded as zero.
10.5.3.15 Void
10.5.3.16 MM Timer
The purpose of the MM timer information element is to specify MM specific timer values, e.g. for the timer T3247.
The MM timer information element is coded as shown in figure 10.5.3.16-1/3GPP TS 24.008 and table 10.5.3.16-
1/3GPP TS 24.008.
8 7 6 5 4 3 2 1
MM Timer IEI octet 1
Length of MM Timer contents octet 2
MM Timer value octet 3
3GPP
Release 10 444 3GPP TS 24.008 V10.6.1 (2012-03)
Bits 6 to 8 defines the timer value unit for the MM timer as follows:
Bits
876
0 0 0 value is incremented in multiples of 2 seconds
0 0 1 value is incremented in multiples of 1 minute
0 1 0 value is incremented in multiples of decihours
1 1 1 value indicates that the timer is deactivated.
The value indicated is contructed by multiplying the value in bits 5 to 1 with the timer
value unit in bits 8 to 6, unless the timer value unit indicates the timer being
deactivated.
One value in the type 1 format is specified for shift operations described below. One other value in both the type 3 & 4
and type 1 format is reserved. This leaves 133 information element identifier values available for assignment.
It is possible to expand this structure to eight codesets of 133 information element identifier values each. One common
value in the type 1 format is employed in each codeset to facilitate shifting from one codeset to another. The contents of
this shift information element identifies the codeset to be used for the next information element or elements. The
codeset in use at any given time is referred to as the "active codeset". By convention, codeset 0 is the initially active
codeset.
Two codeset shifting procedures are supported: locking shift and non-locking shift.
Codeset 6 is reserved for information elements specific to the local network (either public or private).
The coding rules specified in subclause 10.5 shall apply for information elements belonging to any active codeset.
The mobile station and the network shall not apply the "comprehension required" scheme (see 3GPP TS 24.007 [20]) to
information elements belonging to codesets different from codeset 0.
IEIs with bits 5, 6, 7 and 8 all set to zero should not be allocated for new optional information elements in codesets
different from codeset 0, because there are legacy mobile stations that apply the "comprehension required" scheme also
to these information elements, e.g. if such a mobile station receives a SETUP message containing an unknown
information element from codeset 5 with an IEI with bits 5, 6, 7 and 8 all set to zero, then the mobile station will release
the call.
Transitions from one active codeset to another (i.e. by means of the locking shift procedure) may only be made to a
codeset with a higher numerical value than the codeset being left.
3GPP
Release 10 445 3GPP TS 24.008 V10.6.1 (2012-03)
An information element belonging to codeset 5, 6 or 7 may appear together with information elements belonging to
codeset 0, by using the non-locking shift procedure (see subclause 10.5.4.3).
A user or network equipment shall have the capability to recognize a shift information element and to determine the
length of the following information element, although the equipment need not be able to interpret and act on the content
of the information element. This enables the equipment to determine the start of the subsequent information element.
The locking shift is valid only within that message which contains the locking shift information element. At the start of
every message content analysis, the active codeset is codeset 0.
The locking shift information element uses the type 1 information element format and coding shown in
figure 10.5.85/3GPP TS 24.008 and table 10.5.98/3GPP TS 24.008.
8 7 6 5 4 3 2 1
1 0 0 1 0 New codeset octet 1
(Shift identifier) identification
A locking shift information element shall not follow directly a non-locking shift information element. If this
combination is received, it shall be interpreted as though a locking shift information element had been received.
The non-locking shift information element uses the type 1 information format and coding shown in figure 10.5.86/3GPP
TS 24.008 and table 10.5.99/3GPP TS 24.008.
3GPP
Release 10 446 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
1 0 0 1 1 Temporary codeset octet 1
(Shift identifier) identification
The auxiliary states information element is coded as shown in figure 10.5.87/3GPP TS 24.008, table 10.5.100/3GPP TS
24.008 and table 10.5.101/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Auxiliary states IEI octet 1
Bits
4 3
0 0 idle Note 1
0 1 hold request Note 1
1 0 call held Note 1
1 1 retrieve request Note 1
3GPP
Release 10 447 3GPP TS 24.008 V10.6.1 (2012-03)
The backup bearer capability IE is coded as shown in figure 10.5.87a/3GPP TS 24.008 and
tables 10.5.101a/3GPP TS 24.008 to 10.5.101m/3GPP TS 24.008.
The backup bearer capability is a type 4 information element with a minimum length of 3 octets and a maximum length
of 15 octets.
8 7 6 5 4 3 2 1
Backup bearer capability IEI octet 1
3GPP
Release 10 448 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: The coding of the octets of the backup bearer capability IE is not conforming to the coding of the bearer
capability IE in ITU Q.931.
Bits 6 and 7 are spare bits. The sending side (i.e. the network) shall set bit 7 to value 0 and bit 6 to
value 1.
3GPP
Release 10 449 3GPP TS 24.008 V10.6.1 (2012-03)
Compression (octet 4)
Bit 7 is spare and shall be set to “0”.
Structure (octet 4)
Bits
65
00 service data unit integrity
11 unstructured
Configuration (octet 4)
Bit
3
0 point-to-point
NIRR (octet 4)
(Negotiation of Intermediate Rate Requested)
In A/Gb mode and GERAN Iu mode, i.e. not applicable for UTRAN Iu modedata services.
Bit 2 is spare and shall be set to “0”.
Establishment (octet 4)
Bit
1
0 demand
Bits
321
0 0 1 I.440/450
3GPP
Release 10 450 3GPP TS 24.008 V10.6.1 (2012-03)
Bit
76
00 restricted digital information
Bit
54
00 V.120
01 H.223 & H.245
10 PIAFS
Synchronous/asynchronous (octet 6)
Bit
1
0 synchronous
1 asynchronous
3GPP
Release 10 451 3GPP TS 24.008 V10.6.1 (2012-03)
Bits
4321
0000 User rate unknown
0001 0.3 kbit/s Recommendation X.1 and V.110
0010 1.2 kbit/s Recommendation X.1 and V.110
0011 2.4 kbit/s Recommendation X.1 and V.110
0100 4.8 kbit/s Recommendation X.1 and V.110
0101 9.6 kbit/s Recommendation X.1 and V.110
0110 12.0 kbit/s transparent (non compliance with X.1 and V.110)
0111 reserved: was allocated in earlier phases of the protocol.
For facsimile group 3 calls the user rate indicates the first and maximum speed the mobile station
is using.
3GPP
Release 10 452 3GPP TS 24.008 V10.6.1 (2012-03)
Bits
76
00 reserved
01 reserved
10 8 kbit/s
11 16 kbit/s
Network independent clock (NIC) on transmission (Tx) (octet 6b) (See Rec. V.110 and X.30).
In A/Gb mode and GERAN Iu mode only.
Bit
5
0 does not require to send data with network independent clock
1 requires to send data with network independent clock
Network independent clock (NIC) on reception (Rx) (octet 6b) (See Rec. V.110 and X.30)
In A/Gb mode and GERAN Iu mode only.
Bit
4
0 cannot accept data with network independent clock (i.e. sender does not support this optional
procedure)
1 can accept data with network independent clock (i.e. sender does support this optional
procedure)
3GPP
Release 10 453 3GPP TS 24.008 V10.6.1 (2012-03)
The network should use the 4 values depending on its capabilities to support the different modes.
Modem type (octet 6c)
Bits
54321
0 0 0 0 0 none
0 0 0 0 1 V.21 (note 1)
0 0 0 1 0 V.22 (note 1)
0 0 0 1 1 V.22 bis (note 1)
0 0 1 0 0 reserved: was allocated in earlier phases of the protocol
0 0 1 0 1 V.26 ter (note 1)
0 0 1 1 0 V.32
0 0 1 1 1 modem for undefined interface
0 1 0 0 0 autobauding type 1
The value 31.2 kbit/s Recommendation V.34 shall be used only by the network to inform the MS
about FNUR modification due to negotiation between the modems in a 3.1 kHz multimedia call.
3GPP
Release 10 454 3GPP TS 24.008 V10.6.1 (2012-03)
765
000 User initiated modification not allowed/applicable
001 User initiated modification up to 1 TCH/F allowed/may be requested
010 User initiated modification up to 2 TCH/F allowed/may be requested
011 User initiated modification up to 3 TCH/F allowed/may be requested
100 User initiated modification up to 4 TCH/F allowed/may be requested
All other values shall be interpreted as "User initiated modification up to 4 TCH/F may be requested".
Bits
54321
0 0 1 1 0 reserved: was allocated in earlier phases of the protocol
0 1 0 0 0 ISO 6429, codeset 0 (DC1/DC3)
0 1 0 0 1 reserved: was allocated but never used in earlier phases of the protocol
0 1 0 1 0 videotex profile 1
0 1 1 0 0 COPnoFlCt (Character oriented Protocol with no Flow Control
mechanism)
0 1 1 0 1 reserved: was allocated in earlier phases of the protocol
3GPP
Release 10 455 3GPP TS 24.008 V10.6.1 (2012-03)
If the information transfer capability field (octet 3) indicates a value different from "speech", octets 4 and 5shall be
included, octets 6, 6a, 6b, 6c, 6d, 6e, 6f and 6g are optional. In case octet 6 is included, octets 6a, 6b, and 6c shall also
be included. In case octet 6d is included, octets 6e, 6f and 6g may be included. If the information transfer capability
field (octet 3) indicates "facsimile group 3" and octet 6c is included, the modem type field (octet 6c) shall indicate
"none".
If the information transfer capability field (octet 3) indicates "other ITC" or the rate adaption field (octet 5) indicates
"other rate adaption", octet 5a shall be included.
The modem type field (octet 6c) shall not indicate "autobauding type 1" unless the connection element field (octet 6c)
indicates "non transparent".
The bearer capability information element is coded as shown in figure 10.5.88/3GPP TS 24.008 and
tables 10.5.102/3GPP TS 24.008 to 10.5.115/3GPP TS 24.008.
The bearer capability is a type 4 information element with a minimum length of 3 octets and a maximum length of
16 octets.
3GPP
Release 10 456 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Bearer capability IEI octet 1
0/1 0 0 0
ext co- spare spare Speech version octet 3b etc*
ding Indication
1 comp dupl. confi NIRR esta-
ext -ress. structure mode gur. bli. octet 4*
0/1 0 0 rate signalling
ext access id. adaption access protocol octet 5*
0/1 Other rate 0 0 0
ext Other ITC adaption Spare octet 5a*
1 Hdr/ Multi Mode LLI Assig Inb. 0
ext noHdr frame nor/e neg Spare octet 5b*
0/1 0 1 User information sync/
ext layer 1 id. layer 1 protocol async octet 6*
0/1 numb. nego- numb.
ext stop tia- data user rate octet 6a*
bits tion bits
0/1 intermed. NIC NIC
ext rate on TX on RX Parity octet 6b*
0/1 connection
ext element modem type octet 6c*
0/1 Other
ext modem type Fixed network user rate octet 6d*
0/1 Acceptable Maximum number of
ext channel traffic channels octet 6e*
codings
0/1 UIMI Wanted air interface
ext user rate octet 6f*
1 Acceptable 0 0
ext channel codings Asymmetry
extended Indication Spare octet 6g*
1 1 0 User information
ext layer 2 id. layer 2 protocol octet 7*
NOTE 1: The coding of the octets of the bearer capability information element is not conforming to ITU Q.931.
An MS shall encode the Bearer Capability infomation element according to A/Gb mode call control requirements also if
it is requesting for a service in Iu mode, with the following exceptions:
1. A mobile station not supporting A/Gb mode and GERAN Iu mode for the requested bearer service shall set
the following parameters to the value "0":
- Maximum number of traffic channels (octet 6e, bits 1-3)
- Acceptable Channel coding(s) (octet 6e, bits 4, 5 and 7)
2. Furthermore, a mobile station not supporting A/Gb mode and GERAN Iu mode for the requested bearer
service shall also set the following parameters to the value "0", if the respective octets have to be included in
the bearer capability information element according to subclause 10.5.4.5.1 and 3GPP TS 27.001 [36]:
- UIMI, User initiated modification indication (octet 6f, bits 5-7)
- Acceptable Channel Codings extended (octet 6g, bits 5-7)
For UTRAN Iu mode the following parameters are irrelevant for specifying the radio access bearer, because multiple
traffic channels (multislot) are not deployed, see 3GPP TS 23.034 [104]. However, the parameters if received, shall be
3GPP
Release 10 457 3GPP TS 24.008 V10.6.1 (2012-03)
stored in the MSC, and used for handover to A/Gb or GERAN Iu mode:
- Maximum number of traffic channels (octet 6e, bits 1-3)
- Acceptable Channel coding(s) (octet 6e, bits 4, 5 and 7)
- UIMI, User initiated modification indication (octet 6f, bits 5-7)
- Acceptable Channel Codings extended (octet 6g, bits 5-7)
NOTE 2: The following parameters are relevant in UTRAN Iu mode for non transparent data calls for deciding
which RLP version to negotiate in order to avoid renegotiation of RLP version in case of inter-system
handover from UTRAN Iu mode to A/Gb or GERAN Iu mode, see 3GPP TS 24.022 [9]:
- Maximum number of traffic channels (octet 6e, bits 1-3)
- Wanted air interface user rate (octet 6f, bits 1- 4)
- UIMI, User initiated modification indication (octet 6f, bits 5-7).
Bits 6 and 7 are spare bits. The sending side (i.e. the network) shall set bit 7 to value 0 and bit 6 to
value 1.
When information transfer capability (octet 3) indicates other values than speech:
Bits
76
00 reserved
01 full rate support only MS
10 dual rate support MS/half rate preferred
11 dual rate support MS/full rate preferred
When information transfer capability (octet 3) indicates the value speech and no speech version
indication is present in octet 3a etc.:
Bits
76
00 reserved
01 full rate support only MS/fullrate speech version 1 supported
1 0 dual rate support MS/half rate speech version 1 preferred, full rate speech version 1 also
supported
1 1 dual rate support MS/full rate speech version 1 preferred, half rate speech version 1 also
supported
When information transfer capability (octet 3) indicates the value speech and speech version
indication(s) is(are) present in octet 3a etc.:
Bits
76
00 reserved
0 1 the mobile station supports at least full rate speech version 1 but does not support half rate
speech version 1. The complete voice codec preference is specified in octet(s) 3a etc.
1 0 The mobile station supports at least full rate speech version 1 and half rate speech version
1. The mobile station has a greater preference for half rate speech version 1 than for full
rate speech version 1. The complete voice codec preference is specified in octet(s) 3a etc.
1 1 The mobile station supports at least full rate speech version 1 and half rate speech version
1. The mobile station has a greater preference for full rate speech version 1 than for half
rate speech version 1. The complete voice codec preference is specified in octet(s) 3a etc.
(continued...)
3GPP
Release 10 458 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 459 3GPP TS 24.008 V10.6.1 (2012-03)
Coding
Bit
7
0 octet used for extension of information transfer capability
1 octet used for other extension of octet 3
When information transfer capability (octet 3) indicates speech and coding (bit 7 in octet 3a etc.) is
coded as 0, bits 1 through 6 are coded:
NOTE 1: This value shall only be used by an MS supporting CTM text telephony, but not
supporting A/Gb or GERAN Iu mode.
If octet 3 is extended with speech version indication(s) (octets 3a etc.), all speech versions
supported shall be indicated and be included in order of preference (the first octet (3a) has the
highest preference and so on).
If information transfer capability (octet 3) indicates speech and coding (bit 7 in octet 3a etc.) is
coded as 1, or the information transfer capability does not indicate speech, then the extension
octet shall be ignored.
3GPP
Release 10 460 3GPP TS 24.008 V10.6.1 (2012-03)
Structure (octet 4)
Bits
65
0 0 service data unit integrity
1 1 unstructured
Configuration (octet 4)
Bit
3
0 point-to-point
NIRR (octet 4)
(Negotiation of Intermediate Rate Requested)
In A/Gb mode and GERAN Iu mode, i.e. not applicable for UTRAN Iu mode data services.
Bit
2
0 No meaning is associated with this value.
1 Data up to and including 4.8 kb/s, full rate, non-transparent, 6 kb/s radio interface rate is
requested.
Establishment (octet 4)
Bit
1
0 demand
3GPP
Release 10 461 3GPP TS 24.008 V10.6.1 (2012-03)
Bits
321
001 I.440/450
010 reserved: was allocated in earlier phases of the protocol
011 reserved: was allocated in earlier phases of the protocol
100 reserved: was allocated in earlier phases of the protocol.
101 reserved: was allocated in earlier phases of the protocol
110 reserved: was allocated in earlier phases of the protocol
Bit
76
0 0 restricted digital information
Bit
54
0 0 V.120
0 1 H.223 & H.245
1 0 PIAFS
3GPP
Release 10 462 3GPP TS 24.008 V10.6.1 (2012-03)
Bit
7
0 Rate adaption header not included
1 Rate adaption header included
Bit
6
0 Multiple frame establishment not supported, only UI frames allowed
1 Multiple frame establishment supported
Bit
5
0 Bit transparent mode of operation
1 Protocol sensitive mode of operation
Bit
4
0 Default, LLI=256 only
1 Full protocol negotiation, (note: A connection over which protocol negotiation will
be executed is indicated in bit 2 of octet 5b)
Bit
3
0 Message originator is "default assignee"
1 Message originator is "assignor only"
Bit
2
0 Negotiation is done in-band using logical link zero
1 Negotiation is done with USER INFORMATION messages on a temporary
signalling connection
3GPP
Release 10 463 3GPP TS 24.008 V10.6.1 (2012-03)
Synchronous/asynchronous (octet 6)
Bit
1
0 synchronous
1 asynchronous
Bits
4321
0001 0.3 kbit/s Recommendation X.1 and V.110
0010 1.2 kbit/s Recommendation X.1 and V.110
0011 2.4 kbit/s Recommendation X.1 and V.110
0100 4.8 kbit/s Recommendation X.1 and V.110
0101 9.6 kbit/s Recommendation X.1 and V.110
0110 12.0 kbit/s transparent (non compliance with X.1 and V.110)
0111 reserved: was allocated in earlier phases of the protocol.
For facsimile group 3 calls the user rate indicates the first and maximum speed the mobile station
is using.
3GPP
Release 10 464 3GPP TS 24.008 V10.6.1 (2012-03)
Bits
76
0 0 reserved
0 1 reserved
1 0 8 kbit/s
1 1 16 kbit/s
Network independent clock (NIC) on transmission (Tx) (octet 6b) (See Rec. V.110 and X.30).
In A/Gb mode and GERAN Iu mode only.
Bit
5
0 does not require to send data with network independent clock
1 requires to send data with network independent clock
Network independent clock (NIC) on reception (Rx) (octet 6b) (See Rec. V.110 and X.30)
In A/Gb mode and GERAN Iu mode only.
Bit
4
0 cannot accept data with network independent clock (i.e. sender does not support this optional
procedure)
1 can accept data with network independent clock (i.e. sender does support this optional
procedure)
3GPP
Release 10 465 3GPP TS 24.008 V10.6.1 (2012-03)
The requesting end (e.g. the one sending the SETUP message) should use the 4 values
depending on its capabilities to support the different modes. The answering party shall only use
the codings 00 or 01, based on its own capabilities and the proposed choice if any. If both MS and
network support both transparent and non transparent, priority should be given to the MS
preference.
3GPP
Release 10 466 3GPP TS 24.008 V10.6.1 (2012-03)
The value 31.2 kbit/s Recommendation V.34 shall be used only by the network to inform the MS
about FNUR modification due to negotiation between the modems in a 3.1 kHz multimedia call.
3GPP
Release 10 467 3GPP TS 24.008 V10.6.1 (2012-03)
Bit
7
0 TCH/F14.4 not acceptable
1 TCH/F14.4 acceptable
Bit
6
0 Spare
Bit
5
0 TCH/F9.6 not acceptable
1 TCH/F9.6 acceptable
Bit
4
0 TCH/F4.8 not acceptable
1 TCH/F4.8 acceptable
Bits
321
000 1 TCH
001 2 TCH
010 3 TCH
011 4 TCH
100 5 TCH
101 6 TCH
110 7 TCH
111 8 TCH
3GPP
Release 10 468 3GPP TS 24.008 V10.6.1 (2012-03)
765
000 User initiated modification not allowed/required/applicable
001 User initiated modification up to 1 TCH/F allowed/may be requested
010 User initiated modification up to 2 TCH/F allowed/may be requested
011 User initiated modification up to 3 TCH/F allowed/may be requested
100 User initiated modification up to 4 TCH/F allowed/may be requested
All other values shall be interpreted as "User initiated modification up to 4 TCH/F may be requested".
3GPP
Release 10 469 3GPP TS 24.008 V10.6.1 (2012-03)
Bits
54321
0 0 1 1 0 reserved: was allocated in earlier phases of the protocol
0 1 0 0 0 ISO 6429, codeset 0 (DC1/DC3)
0 1 0 0 1 reserved: was allocated but never used in earlier phases of the protocol
0 1 0 1 0 videotex profile 1
0 1 1 0 0 COPnoFlCt (Character oriented Protocol with no Flow Control
mechanism)
0 1 1 0 1 reserved: was allocated in earlier phases of the protocol
Acceptable Channel Codings extended (octet 6g) mobile station to network direction:
Bit
7
0 TCH/F28.8 not acceptable
1 TCH/F28.8 acceptable
Bit
6
0 TCH/F32.0 not acceptable
1 TCH/F32.0 acceptable
Bit
5
0 TCH/F43.2 not acceptable
1 TCH/F43.2 acceptable
Channel Coding Asymmetry Indication
Bits
43
00 Channel coding symmetry preferred
10 Downlink biased channel coding asymmetry is preferred
01 Uplink biased channel coding asymmetry is preferred
11 Unused, if received it shall be interpreted as "Channel coding symmetry preferred"
3GPP
Release 10 470 3GPP TS 24.008 V10.6.1 (2012-03)
If the information transfer capability field (octet 3) indicates "speech", octet 3a etc. shall be included only if the mobile
station supports CTM text telephony or if it supports at least one speech version for GERAN other than:
If the information transfer capability field (octet 3) indicates a value different from "speech", octets 4, 5, 6, 6a, 6b, and
6c shall be included, octets 6d, 6e, 6f and 6g are optional. In the network to MS direction in case octet 6d is included,
octets 6e, 6f and 6g may be included. In the MS to network direction in case octet 6d is included octet 6e shall also be
included and 6f and 6g may be included.
If the information transfer capability field (octet 3) indicates "facsimile group 3", the modem type field (octet 6c) shall
indicate "none".
If the information transfer capability field (octet 3) indicates "other ITC" or the rate adaption field (octet 5) indicates
"other rate adaption", octet 5a shall be included.
If the rate adaption field (octet 5) indicates "other rate adaption" and the other rate adaption field (octet 5a) indicates
"V.120", octet 5b shall be included.
The modem type field (octet 6c) shall not indicate "autobauding type 1" unless the connection element field (octet 6c)
indicates "non transparent".
The Call Control Capabilities information element is coded as shown in figure 10.5.89/3GPP TS 24.008 and
table 10.5.116/3GPP TS 24.008.
The Call Control Capabilities is a type 4 information element with a length of 4 octets.
8 7 6 5 4 3 2 1
Call Control Capabilities IEI octet 1
Length of Call Control Capabilities contents octet 2
Maximum number of supported MCAT ENICM PCP DTMF octet3
bearers
0 0 0 0 Maximum number of
spare speech bearers octet 4
3GPP
Release 10 471 3GPP TS 24.008 V10.6.1 (2012-03)
All values are interpreted as the binary representation of the number of bearers
supported.
Bit 5 of octet 3 is the least significant bit and bit 8 of octet 3 is the most significant bit.
All values are interpreted as the binary representation of the number of bearers
supported.
Bit 1 of octet 4 is the least significant bit and bit 4 of octet 4 is the most significant bit.
Note: In this version of the protocol, the MS should not indicate more than one
speech bearer.
The call state information element is coded as shown in figure 10.5.90/3GPP TS 24.008 and
table 10.5.117/3GPP TS 24.008.
8 7 6 5 4 3 2 1
call state IEI octet 1
coding
standard call state value (coded in binary) octet 2
3GPP
Release 10 472 3GPP TS 24.008 V10.6.1 (2012-03)
Coding standards other than "1 1 - Standard defined for the GSM PLMNS" shall not be
used if the call state can be represented with the GSM standardized coding.
The mobile station or network need not support any other coding standard than
"1 1 - Standard defined for the GSM PLMNS".
If a call state IE indicating a coding standard not supported by the receiver is received,
call state "active" shall be assumed.
The called party BCD number information element is coded as shown in figure 10.5.91/3GPP TS 24.008 and
table 10.5.118/3GPP TS 24.008.
The called party BCD number is a type 4 information element with a minimum length of 3 octets and a maximum
length of 43 octets. For PCS 1900 the maximum length is 19 octets.
3GPP
Release 10 473 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Called party BCD number IEI octet 1
NOTE 1: The number digit(s) in octet 4 precedes the digit(s) in octet 5 etc. The number digit which would be
entered first is located in octet 4, bits 1 to 4.
NOTE 2: If the called party BCD number contains an odd number of digits, bits 5 to 8 of the last octet shall be
filled with an end mark coded as "1111".
Since the information element must contain the complete called party BCD number there is no need for an additional
complete indication.
Bits
7 6 5
0 0 0 unknown (Note 2)
0 0 1 international number (Note 3, Note 5)
0 1 0 national number (Note 3)
0 1 1 network specific number (Note 4)
1 0 0 dedicated access, short code
1 0 1 reserved
1 1 0 reserved
1 1 1 reserved for extension
NOTE 1: For the definition of "number" see ITU-T Recommendation I.330 and 3GPP TS 23.003 [10].
NOTE 2: The type of number "unknown" is used when the user or the network has no knowledge of the type of
number, e.g. international number, national number, etc. In this case the number digits field is organized
according to the network dialling plan, e.g. prefix or escape digits might be present.
NOTE 4: The type of number "network specific number" is used to indicate administration/service number specific
to the serving network, e.g. used to access an operator.
NOTE 5: The international format shall be accepted by the MSC when the call is destined to a destination in the
same country as the MSC.
3GPP
Release 10 474 3GPP TS 24.008 V10.6.1 (2012-03)
Number plan (applies for type of number = 000, 001, 010 and 100)
Bits
4 3 2 1
0 0 0 0 unknown
0 0 0 1 ISDN/telephony numbering plan (Rec. E.164/E.163)
0 0 1 1 data numbering plan (Recommendation X.121)
0 1 0 0 telex numbering plan (Recommendation F.69)
1 0 0 0 national numbering plan
1 0 0 1 private numbering plan
1 0 1 1 reserved for CTS (see 3GPP TS 44.056 [91])
1 1 1 1 reserved for extension
- When an MS is the recipient of number information from the network, any incompatibility between the number
digits and the number plan identification shall be ignored and a STATUS message shall not be sent to the
network.
- In the case of numbering plan "unknown", the number digits field is organized according to the network dialling
plan; e.g. prefix or escape digits might be present.
1 0 1 0 *
1 0 1 1 #
1 1 0 0 a
1 1 0 1 b
1 1 1 0 c
1 1 1 1 used as an endmark in the case of an odd number of
number digits
The Called party subaddress information element is coded as shown in figure 10.5.92/3GPP TS 24.008 and
Table 10.5.119/3GPP TS 24.008.
The called party subaddress is a type 4 information element with a minimum length of 2 octets and a maximum length
of 23 octets.
3GPP
Release 10 475 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Called party Subaddress IEI octet 1
Bits
7 6 5
0 0 0 NSAP (X.213/ISO 8348 AD2)
0 1 0 User specified
All other values are reserved
NOTE 1: The odd/even indicator is used when the type of subaddress is "user
specified" and the coding is BCD.
For User-specific subaddress, this field is encoded according to the user specification,
subject to a maximum length of 20 octets.
NOTE 2: It is recommended that users apply NSAP subaddress type since this
subaddress type allows the use of decimal, binary and IA5 characters in a
standardised manner.
The calling party BCD number information element is coded as shown in figure 10.5.93/3GPP TS 24.008 and
table 10.5.120/3GPP TS 24.008.
The calling party BCD number is a type 4 information element. In the network to mobile station direction it has a
minimum length of 3 octets and a maximum length of 14 octets. (This information element is not used in the mobile
station to network direction.).
3GPP
Release 10 476 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Calling party BCD number IEI octet 1
The contents of octets 3, 4, etc. are coded as shown in table 10.5.118. The coding of octet 3a is defined in table 10.5.120
below.
If the calling party BCD number contains an odd number of digits, bits 5 to 8 of the last octet shall be filled with an end
mark coded as "1111".
Bits
2 1
0 0 User-provided, not screened
0 1 User-provided, verified and passed
1 0 User-provided, verified and failed
1 1 Network provided
If octet 3a is omitted the value "0 0 - User provided, not screened" is assumed.
The Calling party subaddress information element is coded as shown in figure 10.5.94/3GPP TS 24.008 and
table 10.5.121/3GPP TS 24.008.
The calling party subaddress is a type 4 information element with a minimum length of 2 octets and a maximum length
of 23 octets.
3GPP
Release 10 477 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Calling party Subaddress IEI octet 1
Bits
7 6 5
0 0 0 NSAP (X.213/ISO 8348 AD2)
0 1 0 User specified
All other values are reserved
The odd/even indicator is used when the type of subaddress is "user specified" and the
coding is BCD
For User-specific subaddress, this field is encoded according to the user specification,
subject to a maximum length of 20 octets.
NOTE: It is recommended that users apply NSAP subad dress type since this
subaddress type allows the use of decimal, binary and IA5 characters in a
standardised manner.
10.5.4.11 Cause
The purpose of the cause information element is to describe the reason for generating certain messages, to provide
diagnostic information in the event of procedural errors and to indicate the location of the cause originator.
The cause information element is coded as shown in figure 10.5.95/3GPP TS 24.008 and tables 10.5.122 and
10.5.123/3GPP TS 24.008.
The cause is a type 4 information element with a minimum length of 4 octets and a maximum length of 32 octets.
3GPP
Release 10 478 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Cause IEI octet 1
octet N*
If the default value applies for the recommendation field, octet 3a shall be omitted.
Coding standards other than "1 1 - Standard defined for the GSM PLMNS" shall not be
used if the cause can be represented with the GSM standardized coding.
The mobile station or network need not support any other coding standard than "1 1 -
Standard defined for the GSM PLMNS".
If a cause IE indicating a coding standard not supported by the receiver is received,
cause "interworking, unspecified" shall be assumed.
Location (octet 3)
Bits
4 3 2 1
0 0 0 0 user
0 0 0 1 private network serving the local user
0 0 1 0 public network serving the local user
0 0 1 1 transit network
0 1 0 0 public network serving the remote user
0 1 0 1 private network serving the remote user
0 1 1 1 international network
1 0 1 0 network beyond interworking point
If the coding standard is different from "1 1 - Standard defined for GSM PLMNS", the
coding of octet 3a, if included, and octets 4 to N is according to that coding standard.
3GPP
Release 10 479 3GPP TS 24.008 V10.6.1 (2012-03)
The cause value is divided in two fields: a class (bits 5 through 7) and a value within
the class (bits 1 through 4).
The cause values are listed in Table 10.5.123/3GPP TS 24.008 below and defined in
Annex H.
Diagnostic(s) (octet 5)
Diagnostic information is not available for every cause, see Table 10.5.123/3GPP TS
24.008 below.
When available, the diagnostic(s) is coded in the same way as the corresponding
information element in clause 10.
3GPP
Release 10 480 3GPP TS 24.008 V10.6.1 (2012-03)
(continued)
3GPP
Release 10 481 3GPP TS 24.008 V10.6.1 (2012-03)
All other values in the range 96 to 111 shall be treated as cause 111.
All other values in the range 112 to 127 shall be treated as cause 127.
octet 5, bit 8:
This is an extension bit as defined in the preliminary part of subclause 10.5. In this version of this
protocol, this bit shall be set to 1. If it is set to zero, the contents of the following octets shall be ignored.
3GPP
Release 10 482 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 2: The incompatible parameter is composed of the incompatible information element identifier.
NOTE 3: The format of the diagnostic field for cause numbers 57, 58 and 65 is as shown in figure 10.5.88/3GPP TS
24.008 and tables 10.5.102/3GPP TS 24.008 to 10.5.115/3GPP TS 24.008.
NOTE 4: The user supplied diagnostics field is encoded according to the user specification, subject to the
maximum length of the cause information element. The coding of user supplied diagnostics should be
made in such a way that it does not conflict with the coding described in note 9 below.
NOTE 5: The new destination is formatted as the called party BCD number information element, including
information element identifier.
NOTE 6: Locking and non-locking shift procedures described in subclause 10.5.4.2 and clause 3 are applied. In
principle, information element identifiers are ordered in the same order as the information elements in the
received message.
NOTE 7: When only the locking shift information element is included and no information element identifier
follows, it means that the codeset in the locking shift itself is not implemented.
NOTE 8: The timer number is coded in IA5 characters, e.g., T308 is coded as "3" "0" "8". The following coding is
used in each octet:
bit 8 :1
00 - unknown
01 - permanent
10 - transient
The CLIR suppression information element is coded as shown in figure 10.5.96/3GPP TS 24.008.
8 7 6 5 4 3 2 1
CLIR suppression IEI octet 1
3GPP
Release 10 483 3GPP TS 24.008 V10.6.1 (2012-03)
The CLIR invocation information element is coded as shown in figure 10.5.97/3GPP TS 24.008.
8 7 6 5 4 3 2 1
CLIR invocation IEI octet 1
The congestion level information element is coded as shown in figure 10.5.98/3GPP TS 24.008 and
table 10.5.124/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Congestion level Congestion level octet 1
IEI
The connected number information element is coded as shown in figure 10.5.99/3GPP TS 24.008.
The connected number is a type 4 information element with a minimum length of 3 octets and a maximum length of 14
octets.
3GPP
Release 10 484 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Connected number IEI octet 1
Length of connected number contents octet 2
0/1 Type of number Number plan octet 3
ext identification note 1)
1 Presentation 0 0 0 Screening octet 3a*
ext indicator Spare indicator note 1)
Number digit 2 Number digit 1 octet 4*
note 1)
Number digit 4 Number digit 3 octet 5*
note 1)
note 2) :
:
NOTE 1: The contents of octets 3,4,5, etc. ... are coded as shown in table 10.5.118/3GPP TS 24.008. The coding of
octet 3a is defined in table 10.5.120/3GPP TS 24.008.
NOTE 2: If the connected number contains an odd number of digits, bits 5 to 8 of the last octet shall be filled with
the end mark coded as "1111".
The connected subaddress information element is coded as shown in figure 10.5.100/3GPP TS 24.008.
The connected subaddress is a type 4 information element with a minimum length of 2 octets and a maximum length of
23 octets.
8 7 6 5 4 3 2 1
Connected subaddress IEI octet 1
Length of connected subaddress contents octet 2
Type of odd/even 0 0 0 octet 3*
subaddress indicator Spare
Subaddress information octet 4*
:
: etc.
The coding for Type of subaddress, odd/even indicator, and subaddress information is in table 10.5.119/3GPP TS
24.008.
10.5.4.15 Facility
The purpose of the facility information element is to transport supplementary service related information. Within the
scope of 3GPP TS 24.008 the content of the Facility information field is an array of octets. The usage of this
transportation mechanism is defined in 3GPP TS 24.080 [24].
The facility is a type 4 information element with a minimum length of 2 octets. No upper length limit is specified except
for that given by the maximum number of octets in a L3 message (see 3GPP TS 44.006 [19]).
3GPP
Release 10 485 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Facility IEI octet 1
Length of facility contents octet 2
Facility information (see 3GPP TS 24.080 [24]) octet 3-?*
The high layer compatibility information element is coded as shown in figure 10.5.102/3GPP TS 24.008 and
table 10.5.125/3GPP TS 24.008.
The high layer compatibility is a type 4 information element with a minimum length of 2 octets and a maximum length
of 5 octets.
NOTE: The high layer compatibility information element is transported transparently by a PLMN between a call
originating entity (e.g. a calling user) and the addressed entity (e.g. a remote user or a high layer function
network node addressed by the call originating entity). However, if explicitly requested by the user (at
subscription time), a network which provides some capabilities to realize teleservices may interpret this
information to provide a particular service.
8 7 6 5 4 3 2 1
High layer compatibility IEI octet 1
NOTE: Octet 4a may be present e.g. when octet 4 indicates Maintenance or Management, or audio visual.
Interpretation (octet 3)
see ITU Recommendation Q.931.
3GPP
Release 10 486 3GPP TS 24.008 V10.6.1 (2012-03)
The keypad facility information element is coded as shown in figure 10.5.103/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Keypad facility IEI octet 1
Spare
0 Keypad information (IA5 character) octet 2
NOTE: In the 3GPP system this information element is only used to transfer one DTMF digit (0, 1, ... , 9, A, B, C,
D, *, #) as one IA5 character.
Except for the information element identifier, the low layer compatibility information element is coded as in ITU
recommendation Q.931.
For backward compatibility reasons coding of the modem type field according to ETS 300 102-1 (12-90) shall also be
supported.
The low layer compatibility is a type 4 information element with a minimum length of 2 octets and a maximum length
of 18 octets.
8 7 6 5 4 3 2 1
Low layer compatibility IEI octet 1
Length of the low layer compatibility contents octet 2
octet 3*
The following octets are coded
as described in :
ITU Recommendation Q.931 :
(Coding of the modem type according to both Q.931 and :
ETS 300 102-1 (12-90) shall be accepted)
3GPP
Release 10 487 3GPP TS 24.008 V10.6.1 (2012-03)
remote user/mobile station that another USER INFORMATION message will follow containing information belonging
to the same block.
The use of the more data information element is not supervised by the network.
The more data information element is coded as shown in figure 10.5.105/3GPP TS 24.008.
8 7 6 5 4 3 2 1
More data IEI octet 1
The notification indicator element is coded as shown in figure 10.5.106/3GPP TS 24.008 and table 10.5.126/ 3GPP TS
24.008.
8 7 6 5 4 3 2 1
Notification indicator IEI octet 1
1 octet 2
ext Notification description
The progress indicator information element is coded as shown in figure 10.5.107/3GPP TS 24.008 and
table 10.5.127/3GPP TS 24.008.
3GPP
Release 10 488 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Progress indicator IEI octet 1
Coding standards other than "1 1 - Standard defined for the GSM PLMNS" shall not be
used if the progress description can be represented with the GSMßstandardized
coding.
The mobile station or network need not support any other coding standard than "1 1 -
Standard defined for the GSM PLMNS".
If a progress indicator IE indicating a coding standard not supported by the receiver is
received, progress description "Unspecific" shall be assumed.
Location (octet 3)
Bits
4 3 2 1
0 0 0 0 User
0 0 0 1 Private network serving the local user
0 0 1 0 Public network serving the local user
0 1 0 0 Public network serving the remote user
0 1 0 1 Private network serving the remote user
1 0 1 0 Network beyond interworking point
Note: Depending on the location of the users, the local public network and remote
public network may be the same network.
3GPP
Release 10 489 3GPP TS 24.008 V10.6.1 (2012-03)
The recall type information element is coded as shown in Figure 10.5.108/3GPP TS 24.008 and Table 10.5.128/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
recall type IEI octet 1
spare recall type
0 0 0 0 0 octet 2
The redirecting party BCD number information element is coded as shown in figure 10.5.108a/3GPP TS 24.008.
The redirecting party BCD number is a type 4 information element. In the network to mobile station direction it has a
minimum length of 3 octets and a maximum length of 19 octets.
8 7 6 5 4 3 2 1
Redirecting party BCD number IEI octet 1
Note 2) :
NOTE 1: The contents of octets 3, 4, etc. are coded as shown in table 10.5.118/3GPP TS 24.008. The coding of
octet 3a is defined in table 10.5.120/3GPP TS 24.008.
NOTE 2: If the redirecting party BCD number contains an odd number of digits, bits 5 to 8 of the last octet shall be
filled with an end mark coded as "1111".
3GPP
Release 10 490 3GPP TS 24.008 V10.6.1 (2012-03)
The Redirecting party subaddress information element is coded as shown in figure 10.5.108b/3GPP TS 24.008 and
table 10.5.121/3GPP TS 24.008.
The Redirecting party subaddress is a type 4 information element with a minimum length of 2 octets and a maximum
length of 23 octets.
8 7 6 5 4 3 2 1
Redirecting party Subaddress IEI octet 1
The repeat indicator information element is coded as shown in figure 10.5.109/3GPP TS 24.008 and
table 10.5.129/3GPP TS 24.008.
8 7 6 5 4 3 2 1
repeat indicator repeat indication octet 1
IEI
3GPP
Release 10 491 3GPP TS 24.008 V10.6.1 (2012-03)
The reverse call setup direction information element is coded as shown in figure 10.5.110/3GPP TS 24.008.
8 7 6 5 4 3 2 1
reverse call setup direction IEI octet 1
The SETUP Container information element is coded as shown in figure 10.5.111/3GPP TS 24.008.
The SETUP Container is a type 4 information. No upper length limit is specified except for that given by the maximum
number of octets in a L3 message (see 3GPP TS 44.006 [19]).
8 7 6 5 4 3 2 1
SETUP Container IEI octet 1
Length of SETUP container contents octet 2
Figure 10.5.111/3GPP TS 24.008 Octet j (j = 3, 4 ... n) is the unchanged octet j of the SETUP message.
10.5.4.23 Signal
The purpose of the signal information element is to allow the network to convey information to a user regarding tones
and alerting signals (see subclauses 5.2.2.3.2 and 7.3.3.).
The signal information element is coded as shown in figure 10.5.112/3GPP TS 24.008 and
table 10.5.130/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Signal IEI octet 1
3GPP
Release 10 492 3GPP TS 24.008 V10.6.1 (2012-03)
The SS version indicator information element is coded as shown in figure 10.5.113/3GPP TS 24.008.
The SS version indicator is a type 4 information element with a minimum length of 2 octets. No upper length limit is
specified except for that given by the maximum number of octets in a L3 message (see 3GPP TS 44.006 [19]).
8 7 6 5 4 3 2 1
SS version indicator IEI octet 1
Length of SS version indicator contents octet 2
SS version information (see 3GPP TS 24.080 [24]) octet 3*
: *
: *
NOTE: Usually, this information element has only one octet of content.
10.5.4.25 User-user
The purpose of the user-user information element is to convey information between the mobile station and the remote
ISDN user.
The user-user information element is coded as shown in figure 10.5.114/3GPP TS 24.008 and table 10.5.131/
3GPP TS 24.008. There are no restrictions on the content of the user-user information field.
The user-user is a type 4 information element with a minimum length of 3 octets and a maximum length of either 35 or
131 octets. In the SETUP message the user-user information element has a maximum size of 35 octets in a
GSM PLMN. In the USER INFORMATION, ALERTING, CONNECT, DISCONNECT, PROGRESS, RELEASE and
RELEASE COMPLETE messages the user-user information element has a maximum size of 131 octets in a
GSM PLMN.
In other networks than GSM PLMNs the maximum size of the user-user information element is 35 or 131 octets in the
messages mentioned above. The evolution to a single maximum value is the long term objective; the exact maximum
value is the subject of further study.
NOTE: The user-user information element is transported transparently through a GSM PLMN.
3GPP
Release 10 493 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
User-user IEI octet 1
octet N*
0 1 0 0 0 0 0 0
through National use
0 1 0 0 1 1 1 0
0 1 0 0 1 1 1 1 3GPP capability exchange protocol (NOTE 4)
The Alerting Pattern information element is coded as shown in figure 10.5.115/3GPP TS 24.008 and
table 10.5.132/3GPP TS 24.008.
3GPP
Release 10 494 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Alerting Pattern IEI octet 1
length of alerting pattern content octet 2
0 0 0 0 Alerting Pattern
spare value octet 3
0 0 0 0 alerting pattern 1
0 0 0 1 alerting pattern 2
0 0 1 0 alerting pattern 3
0 1 0 0 alerting pattern 5
0 1 0 1 alerting pattern 6
0 1 1 0 alerting pattern 7
0 1 1 1 alerting pattern 8
1 0 0 0 alerting pattern 9
The Allowed actions information element is coded as shown in figure 10.5.116/3GPP TS 24.008 and
table 10.5.133/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Allowed Actions IEI octet 1
Bits
8
0 Activation of CCBS not possible
1 Activation of CCBS possible
3GPP
Release 10 495 3GPP TS 24.008 V10.6.1 (2012-03)
The Stream identifier information element is coded as shown in figure 10.5.117/3GPP TS 24.008 and
table 10.5.134/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Stream Identifier IEI octet 1
Bit
8 7 6 5 4 3 2 1
0 0 0 0 0 0 0 0 No bearer
0 0 0 0 0 0 0 1 1
:
:
1 1 1 1 1 1 1 1 255
The Network Call Control Capabilities information element is coded as shown in figure 10.5.118/3GPP TS 24.008 and
table 10.5.135/3GPP TS 24.008.
The Network Call Control Capabilities is a type 4 information element with a length of 3 octets.
8 7 6 5 4 3 2 1
Network Call Control Capabilities IEI octet 1
3GPP
Release 10 496 3GPP TS 24.008 V10.6.1 (2012-03)
The Cause of No CLI information element is coded as shown in figure 10.5.118a/3GPP TS 24.008 and
table 10.5.135a/3GPP TS 24.008.
The Cause of No CLI is a type 4 information element with the length of 3 octets.
8 7 6 5 4 3 2 1
Cause of No CLI IEI octet 1
Length of Cause of No CLI contents octet 2
Cause of No CLI octet 3
10.5.4.31 Void
The Supported Codec List information element is coded as shown in figure 10.5.118c/3GPP TS 24.008.
The Supported Codec List information element is a type 4 information element with a minimum length of 5 octets and a
maximum length of m+3 octets.
Speech codec information belonging to GERAN and UTRAN shall be conveyed by this information element.
3GPP
Release 10 497 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Supported Codec List IEI octet 1
Length Of Supported Codec list octet 2
Octets (5 & 6), (j+2 & j+3), (m+2 & m+3) etc
The coding of the Codec Bitmap is defined in 3GPP TS 26.103 [83].
NOTE: If the Codec Bitmap for a SysID is 1 octet, it is an indication that all codecs
of the 2nd octet are not supported. If the Codec Bitmap for a SysID is more than 2
octets, the network shall ignore the additional octet(s) of the bitmap and process
the rest of the information element.
The Service category information element is coded as shown in figure 10.5.118d/3GPP TS 24.008 and
table 10.5.135d/3GPP TS 24.008
The Service category is a type 4 information element with a minimum length of 3 octets.
8 7 6 5 4 3 2 1
Service Category IEI octet 1
Length of Service Category octet 2
0 Emergency Service Category Value octet 3
spare
3GPP
Release 10 498 3GPP TS 24.008 V10.6.1 (2012-03)
If no bit is set to "1", the MSC shall route the Emergency call to an operator defined default emergency centre.
A mobile station initiating an eCall shall set either bit 6 or bit 7 to “1”. The network may use the information indicated in bit
6 and bit 7 to route the manually or automatically initiated eCall to an operator defined emergency call centre.
10.5.4.34 Redial
The purpose of the Redial information element is to indicate to the network that a call is the result of a redial attempt to
switch from speech to multimedia or vice-versa.
8 7 6 5 4 3 2 1
Redial IEI octet 1
The Network- initiated Service Upgrade indicator information element is coded as shown in figure 10.5.118f/3GPP TS
24.008.
The Network-initiated Service Upgrade indicator is a type 2 information element with a length of 1 octet.
8 7 6 5 4 3 2 1
Network-initiated Service Upgrade indicator IEI octet 1
3GPP
Release 10 499 3GPP TS 24.008 V10.6.1 (2012-03)
The attach result information element is coded as shown in figure 10.5.117a/3GPP TS 24.008 and table 10.5.134a/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
Attach result FOP Result of octet 1
IEI attach
The attach type information element is coded as shown in figure 10.5.117b/3GPP TS 24.008 and table 10.5.135b/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
Attach type FOR Type of attach octet 1
IEI
3GPP
Release 10 500 3GPP TS 24.008 V10.6.1 (2012-03)
All other values are interpreted as GPRS attach in this version of the protocol.
NOTE 1: The code point “010” if received by the network, it shall be interpreted as
"Combined GPRS/IMSI attach".
The ciphering algorithm information element is coded as shown in figure 10.5.119/3GPP TS 24.008 and
table 10.5.136/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Ciphering algorithm 0 Type of octet 1
IEI spare algorithm
3GPP
Release 10 501 3GPP TS 24.008 V10.6.1 (2012-03)
The TMSI status information element is coded as shown in figure 10.5.120/3GPP TS 24.008 and
table 10.5.137/3GPP TS 24.008.
8 7 6 5 4 3 2 1
TMSI status 0 0 0 TMSI octet 1
IEI spare flag
The detach type information element is coded as shown in figure 10.5.121/3GPP TS 24.008 and
table 10.5.138/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Detach type Power Type of detach octet 1
IEI off
3GPP
Release 10 502 3GPP TS 24.008 V10.6.1 (2012-03)
All other values are interpreted as Combined GPRS/IMSI detach by this version of the
protocol.
All other values are interpreted as re-attach not required by this version of the protocol.
In the network to MS direction the Power off bit shall be spare and set to zero.
The value part of a DRX parameter information element is coded as shown in table 10.5.139/3GPP TS 24.008.
8 7 6 5 4 3 2 1
DRX parameter IEI octet 1
SPLIT PG CYCLE CODE octet 2
CN Specific DRX cycle length SPLIT non-DRX
coefficient on timer octet 3
and CCCH
DRX value for S1 mode
3GPP
Release 10 503 3GPP TS 24.008 V10.6.1 (2012-03)
All other values are reserved and shall be interpreted as 1 by this version of the
protocol.
3GPP
Release 10 504 3GPP TS 24.008 V10.6.1 (2012-03)
CN Specific DRX cycle length coefficient and DRX value for S1 mode, octet 3
This field represents two separate values. For Iu mode, it represents the 'CN domain
specific DRX cycle length' as defined in 3GPP TS 25.331 [23c]. For S1 mode, it
represents the DRX cycle parameter 'T' as defined in 3GPP TS 36.304 [121].
bit
8 7 6 5 Iu and S1 mode specific
0 0 0 0 For Iu mode, CN Specific DRX cycle length coefficient not specified by
the MS, ie. the system information value 'CN domain specific DRX cycle
length' is used . For S1 mode, DRX value not specified by the MS.
0 1 1 0 CN Specific DRX cycle length coefficient 6 and T = 32
0 1 1 1 CN Specific DRX cycle length coefficient 7 and T = 64
1 0 0 0 CN Specific DRX cycle length coefficient 8 and T = 128
1 0 0 1 CN Specific DRX cycle length coefficient 9 and T = 256
All other values shall be interpreted as "CN Specific DRX cycle length coefficient not
specified by the MS " and "DRX value not specified by the MS" by this version of the
protocol.
NOTE: For Iu mode and S1 mode, this field (octet 3 bits 8 to 5) is used, but was
spare in earlier versions of this protocol.
In Iu mode, the network shall always indicate force to standby not indicated in the force to standby information element.
The force to standby information element is coded as shown in figure 10.5.123/3GPP TS 24.008 and
table 10.5.140/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Force to standby 0 Force to octet 1
IEI spare standby value
Bits
3 2 1
0 0 0 Force to standby not indicated
0 0 1 Force to standby indicated
3GPP
Release 10 505 3GPP TS 24.008 V10.6.1 (2012-03)
The P-TMSI signature information element is coded as shown in figure 10.5.124/3GPP TS 24.008 and
table 10.5.141/3GPP TS 24.008.
8 7 6 5 4 3 2 1
P-TMSI signature IEI octet 1
octet 2
P-TMSI signature value
octet 4
Bit 1 of octet 4 is the least significant bit and bit 8 of octet 2 is the most significant bit.
The P-TMSI signature 2 information element is coded as shown in figure 10.5.124a/3GPP TS 24.008 and
table 10.5.141a/3GPP TS 24.008.
8 7 6 5 4 3 2 1
P-TMSI signature 2 IEI octet 1
Length of P-TMSI signature 2 contents octet 2
octet 3
P-TMSI signature 2 value
octet 5
The identity type 2 information element is coded as shown in figure 10.5.125/3GPP TS 24.008 and table 10.5.142/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
Identity type 2 0 Type of octet 1
IEI spare identity
3GPP
Release 10 506 3GPP TS 24.008 V10.6.1 (2012-03)
All other values are interpreted as IMSI by this version of the protocol.
The IMEISV request information element is coded as shown in figure 10.5.126/3GPP TS 24.008 and
table 10.5.143/3GPP TS 24.008.
8 7 6 5 4 3 2 1
IMEISV request 0 IMEISV request octet 1
IEI spare value
All other values are interpreted as IMEISV not requested by this version of the protocol.
The Receive N-PDU Number list is a type 4 information element with a length of 4 to 19 octets.
The value part of a Receive N-PDU Number list information element is coded as shown in figure 10.5.127/3GPP TS
24.008 and table 10.5.144/3GPP TS 24.008.
3GPP
Release 10 507 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Receive N-PDU Number list IEI octet 1
Length of Receive N-PDU Number list contents
octet 3
Receive N-PDU Number-list octet 4
octet n*
{
< Receive N-PDU Number -list >
< Padding bits>
};
< Receive N-PDU Number-list > ::= < sapi : bit-string(4) > < Receive N-PDU
Number-value : bit-string(8) > { < Receive N-PDU Number-list> | < null > } ;
The MS network capability is a type 4 information element with a maximum of 10 octets length.
The value part of a MS network capabilityinformation element is coded as shown in figure 10.5.128/3GPP TS 24.008
and table 10.5.145/3GPP TS 24.008.
NOTE: The requirements for the support of the GEA algorithms in the MS are specified in 3GPP TS 43.020 [13].
3GPP
Release 10 508 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
MS network capability IEI octet 1
Length of MS network capability contents octet 2
MS network capability value octet 3-10
3GPP
Release 10 509 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 510 3GPP TS 24.008 V10.6.1 (2012-03)
<GEA1 bits>
<SM capabilities via dedicated channels: bit>
<SM capabilities via GPRS channels: bit>
<UCS2 support: bit>
<SS Screening Indicator: bit string(2)>
<SoLSA Capability : bit>
<Revision level indicator: bit>
<PFC feature mode: bit>
<Extended GEA bits>
<LCS VA capability: bit>
<PS inter-RAT HO from GERAN to UTRAN Iu mode capability: bit>
<PS inter-RAT HO from GERAN to E-UTRAN S1 mode capability: bit>
<EMM Combined procedures Capability: bit>
<ISR support: bit>
<SRVCC to GERAN/UTRAN capability: bit>
<EPC capability: bit>
<Extended GEA bits> ::= <GEA/2:bit><GEA/3:bit>< GEA/4:bit >< GEA/5:bit >< GEA/6:bit ><GEA/7:bit>;
<Spare bits> ::= null | {<spare bit> < Spare bits >};
SS Screening Indicator
0 0 defined in 3GPP TS 24.080 [24]
UCS2 support
This information field indicates the likely treatment by the mobile station of UCS2 encoded character strings.
0 the ME has a preference for the default alphabet (defined in 3GPP TS 23.038 [8b])
over UCS2.
1 the ME has no preference between the use of the default alphabet and the
use of UCS2.
SoLSA Capability
0 The ME does not support SoLSA.
1 The ME supports SoLSA.
3GPP
Release 10 511 3GPP TS 24.008 V10.6.1 (2012-03)
GEA/2
0 encryption algorithm GEA/2 not available
1 encryption algorithm GEA/2 available
GEA/3
0 encryption algorithm GEA/3 not available
1 encryption algorithm GEA/3 available
GEA/4
0 encryption algorithm GEA/4 not available
1 encryption algorithm GEA/4 available
GEA/5
0 encryption algorithm GEA/5 not available
1 encryption algorithm GEA/5 available
GEA/6
0 encryption algorithm GEA/6 not available
1 encryption algorithm GEA/6 available
GEA/7
0 encryption algorithm GEA/7 not available
1 encryption algorithm GEA/7 available
ISR support
0 The mobile station does not support ISR.
1 The mobile station supports ISR.
EPC capability
This information field indicates if the MS supports access to the EPC via access networks other than GERAN or
UTRAN.The network can use this information to decide whether to select a PDN Gateway or a GGSN. The MS shall set
the indication to "0" if a SIM is inserted in the MS.
0 EPC not supported
1 EPC supported
3GPP
Release 10 512 3GPP TS 24.008 V10.6.1 (2012-03)
NF capability
This information field indicates if the MS supports the notification procedure.
0 Mobile station does not support the notification procedure.
1 Mobile station supports the notification procedure.
The MS Radio Access capability is a type 4 information element, with a maximum length of 52 octets.
The MS Radio Access capability information element is coded as shown in figure 10.5.128a/3GPP TS 24.008 and table
10.5.146/3GPP TS 24.008.
For the indication of the radio access capabilities the following conditions shall apply:
- Among the three Access Type Technologies GSM 900-P, GSM 900-E and GSM 900-R only one shall be present.
- Due to shared radio frequency channel numbers between GSM 1800 and GSM 1900, the mobile station should
provide the relevant radio access capability for either GSM 1800 band OR GSM 1900 band, not both.
- The MS shall indicate its supported Access Technology Types during a single MM procedure.
- If the alternative coding by using the Additional access technologies struct is chosen by the mobile station, the
mobile station shall indicate its radio access capability for the serving BCCH frequency band in the first included
Access capabilities struct, if this information element is not sent in response to an Access Technologies Request
from the network or if none of the requested Access Technology Types is supported by the MS. Otherwise, the
mobile station shall include the radio access capabilities for the frequency bands it supports in the order of
priority requested by the network (see 3GPP TS 44.060 [76]).
If a received Access Technology Type is unknown to the receiver, it shall ignore all the corresponding fields.
If within a known Access Technology Type a receiver recognizes an unknown field it shall ignore it.
For more details about error handling of MS radio access capability see 3GPP TS 48.018 [86].
NOTE: The requirements for the support of the A5 algorithms in the MS are specified in 3GPP TS 43.020 [13].
8 7 6 5 4 3 2 1
MS Radio Access Capability IEI octet 1
Length of MS Radio Access Capability contents octet 2
MS RA capability value part octet 3-52
3GPP
Release 10 513 3GPP TS 24.008 V10.6.1 (2012-03)
<MS RA capability value part struct >::= --recursive structure allows any number of Access technologies
{ { < Access Technology Type: bit (4) > exclude 1111
< Access capabilities : <Access capabilities struct> > }
| { < Access Technology Type: bit (4) == 1111 >-- structure adding Access technologies with same capabilities
< Length : bit (7) > -- length in bits of list of Additional access technologies and spare bits
{ 1 < Additional access technologies: < Additional access technologies struct > > } ** 0
<spare bits>** } }
3GPP
Release 10 514 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 515 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 516 3GPP TS 24.008 V10.6.1 (2012-03)
<A5 bits> ::= < A5/1 : bit> <A5/2 : bit> <A5/3 : bit> <A5/4 : bit> <A5/5 : bit> <A5/6 : bit> <A5/7 : bit>; -- bits for circuit
mode ciphering algorithms. These fields are not used by the network and may be excluded by the MS.
Bits
4321
0000 GSM P
0001 GSM E --note that GSM E covers GSM P
0010 GSM R --note that GSM R covers GSM E and GSM P
0011 GSM 1800
0100 GSM 1900
0101 GSM 450
0110 GSM 480
0111 GSM 850
1000 GSM 750
1001 GSM T 380
1010 GSM T 410
1011 -- This value was allocated in an earlier version of the protocol and shall not be used.
1100 GSM 710
1101 GSM T 810
1111 Indicates the presence of a list of Additional access technologies
All other values are treated as unknown by the receiver.
A MS which does not support any GSM access technology type shall set this field to '0000'.
A MS which does not support any GSM access technology type shall set this field to '000'.
The presence of this field also indicates 8PSK modulation capability in the uplink.
3GPP
Release 10 517 3GPP TS 24.008 V10.6.1 (2012-03)
This field indicates the radio capability for 8-PSK modulation. The following coding is used (see 3GPP TS 45.005
[33]):
Bits 2 1
00 8PSK modulation not supported for uplink
01 Power class E1
10 Power class E2
11 Power class E3
A5/1
0 encryption algorithm A5/1 not available
1 encryption algorithm A5/1 available
A5/2
The MS shall set this bit to ‘0’.
The network shall accept any received value.
0 encryption algorithm A5/2 not available
1 Not used. This value was allocated in earlier versions of the protocol.
A5/3
0 encryption algorithm A5/3 not available
1 encryption algorithm A5/3 available
A5/4
0 encryption algorithm A5/4 not available
1 encryption algorithm A5/4 available
A5/5
0 encryption algorithm A5/5 not available
1 encryption algorithm A5/5 available
A5/6
0 encryption algorithm A5/6 not available
1 encryption algorithm A5/6 available
A5/7
0 encryption algorithm A5/7 not available
1 encryption algorithm A5/7 available
3GPP
Release 10 518 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 519 3GPP TS 24.008 V10.6.1 (2012-03)
PS – (Pseudo Synchronisation)
0 PS capability not present
1 PS capability present
If a multislot class type 1 MS indicates in the GPRS Multi Slot Class field the support of a multislot class for which
three or more uplink timeslots can be assigned, Extended Dynamic Allocation for GPRS shall be implemented in the
mobile station.
If a multislot class type 1 MS indicates in the EGPRS Multi Slot Class field the support of a multislot class for which
three or more uplink timeslots can be assigned, Extended Dynamic Allocation for EGPRS and EGPRS2 (if supported)
shall be implemented in the mobile station.
3GPP
Release 10 520 3GPP TS 24.008 V10.6.1 (2012-03)
...
1111 16/4 timeslot (~2307 microseconds)
3GPP
Release 10 521 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 522 3GPP TS 24.008 V10.6.1 (2012-03)
This field shall contain one of the following values if the DTM GPRS High Multi Slot Class field is present:
Multislot class 9 if DTM GPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
Multislot class 11 if DTM GPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 44.
An MS indicating support for Extended DTM GPRS multislot class or Extended DTM EGPRS multislot class shall
set this bit to ‘1’. The network may ignore the bit in this case.
This field shall contain one of the following values if the DTM EGPRS High Multi Slot Class field is present:
Multislot class 9 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
Multislot class 11 if DTM EGPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 44.
UMTS 3.84 Mcps TDD Radio Access Technology Capability (1 bit field)
Bit
0 UMTS 3.84 Mcps TDD not supported
1 UMTS 3.84 Mcps TDD supported
UMTS 1.28 Mcps TDD Radio Access Technology Capability (1 bit field)
Bit
0 UMTS 1.28 Mcps TDD not supported
1 UMTS 1.28 Mcps TDD supported
3GPP
Release 10 523 3GPP TS 24.008 V10.6.1 (2012-03)
The presence of this field indicates that the MS supports combined fullrate and halfrate GPRS channels in the
downlink. When this field is not present, the MS supports the multislot class indicated by the DTM GPRS Multi Slot
Class field.
If this field is included, it shall contain one of the following values if the DTM GPRS High Multi Slot Class field is
present:
Multislot class 10 if DTM GPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
Multislot class 11 if DTM GPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 44.
If this field is included, it shall contain one of the following values if the DTM EGPRS High Multi Slot Class field is
present:
Multislot class 10 if DTM EGPRS High Multi Slot Class is set to indicate Class 31/36 or Class 41;
Multislot class 11 if DTM EGPRS High Multi Slot Class is set to indicate Classes 32/37, 33/38 or Classes 42, 43, 44.
3GPP
Release 10 524 3GPP TS 24.008 V10.6.1 (2012-03)
Bit
321
000 Unused. If received, the network shall interpret this as ‘0 0 1’
001 Multislot class 31 or 36 supported
010 Multislot class 32 or 37 supported
3GPP
Release 10 525 3GPP TS 24.008 V10.6.1 (2012-03)
The presence of this field indicates that the MS supports the DTM extension to high multislot classes. When this
field is not present, the MS supports the DTM multislot class indicated by the DTM GPRS Multi Slot Class field.
The values '0 0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM GPRS multislot class 36, 37 or 38
respectively in case the MS indicates support for one of the GPRS multislot classes 35 to 39; in all other cases
those codepoints shall be interpreted as indicating DTM GPRS multislot class 31, 32 or 33 respectively.
This field shall be ignored if the High Multislot Capability field is not present.
The values '0 0 1', '0 1 0' and '0 1 1' shall be interpreted as indicating DTM EGPRS multislot class 36, 37 or 38
respectively in case the MS indicates support for one of the EGPRS multislot classes 35 to 39; in all other cases
those codepoints shall be interpreted as indicating DTM EGPRS multislot class 31, 32 or 33 respectively.
This field shall be ignored if the High Multislot Capability field is not present.
Bit
321
000 No reduction
001 The MS supports 1 timeslot fewer than the maximum number of receive timeslots
010 The MS supports 2 timeslots fewer than the maximum number of receive timeslots
011 The MS supports 3 timeslots fewer than the maximum number of receive timeslots
100 The MS supports 4 timeslots fewer than the maximum number of receive timeslots
101 The MS supports 5 timeslots fewer than the maximum number of receive timeslots
110 The MS supports 6 timeslots fewer than the maximum number of receive timeslots
111 Reserved for future use
The presence of this field also indicates that the mobile station supports dual carrier in the downlink for EGPRS.
Bit
0 The mobile station does not support DTM during downlink dual carrier operation
1 The mobile station supports DTM during downlink dual carrier operation
3GPP
Release 10 526 3GPP TS 24.008 V10.6.1 (2012-03)
If the mobile station supports DTM during downlink dual carrier operation as indicated by this field, the Multislot
Capability Reduction for Downlink Dual Carrier field provided in the MS Radio Access Capability IE is applicable to
EGPRS DTM support as well.
0 The mobile station does not support Reduced TTI configurations and Fast Ack/Nack Reporting
1 The mobile station supports Reduced TTI configurations and Fast Ack/Nack Reporting
A mobile station whose multislot class does not allow the support of Reduced TTI configurations in packet transfer
mode due to a limited number of uplink or downlink timeslots (see 3GPP TS 45.002 [32]) shall set the Reduced
Latency Capability field to '0'.
Bit
21
00 The mobile station does not support either EGPRS2-A or EGPRS2-B in the uplink
01 The mobile station supports EGPRS2-A in the uplink
10 The mobile station supports both EGPRS2-A and EGPRS2-B in the uplink
11 This value is not used in this release/version of the specifications. If received it shall be interpreted
as ‘10’
Bit
21
00 The mobile station does not support either EGPRS2-A or EGPRS2-B in the downlink
01 The mobile station supports EGPRS2-A in the downlink
10 The mobile station supports both EGPRS2-A and EGPRS2-B in the downlink
11 This value is not used in this release/version of the specifications. If received it shall be interpreted
as ‘10’
3GPP
Release 10 527 3GPP TS 24.008 V10.6.1 (2012-03)
This field indicates the capabilities supported by the mobile station in packet transfer mode for GERAN to E-UTRA
interworking. If both "E-UTRA FDD support" and "E-UTRA TDD support" bits are set to '0', the bit field shall be set
to '0 0'. If one or both of "E-UTRA FDD support" and "E-UTRA TDD support" bits are set to '1', the bit field may be
any of the listed values. The bit field is coded as follows:
Bit
21
00 None
01 E-UTRAN Neighbour Cell measurements and MS autonomous cell reselection to E-UTRAN supported
10 CCN towards E-UTRAN, E-UTRAN Neighbour Cell measurement reporting and Network controlled cell
reselection to E-UTRAN supported in addition to capabilities indicated by '01'
11 PS Handover to E-UTRAN supported in addition to capabilities indicated by '01' and '10'
Bit
4321
0000 No Alternative EFTA multislot class is indicated. Use (DTM) EGPRS (high) multislot class only.
0001 Alternative EFTA multislot class is Multislot class 19
0010 Alternative EFTA multislot class is Multislot class 20
0011 Alternative EFTA multislot class is Multislot class 21
0100 Alternative EFTA multislot class is Multislot class 22
0101 Alternative EFTA multislot class is Multislot class 23
0110 Alternative EFTA multislot class is Multislot class 24
0111 Alternative EFTA multislot class is Multislot class 25
1000 Alternative EFTA multislot class is Multislot class 26
1001 Alternative EFTA multislot class is Multislot class 27
1010 Alternative EFTA multislot class is Multislot class 28
1011 Alternative EFTA multislot class is Multislot class 29
1100 Unused. If received, it shall be interpreted as ’0000’
1101 Unused. If received, it shall be interpreted as ’0000’
1110 Unused. If received, it shall be interpreted as ’0000’
1111 Unused. If received, it shall be interpreted as ’0000’
EFTA Multislot Capability Reduction for Downlink Dual Carrier (3 bit field)
This field indicates the receive multislot capability reduction of a dual carrier capable mobile station applicable to
EGPRS and EGPRS2 support when Enhanced Flexible Timeslot Assignment is used (see 3GPP TS 45.002 [32]).
This reduction applies to the maximum number of downlink timeslots for dual carrier operation derived from the
Alternative EFTA Multislot Class field. The coding of this field is the same as the coding of the Multislot Capability
Reduction for Downlink Dual Carrier field.
This field shall be ignored if a mobile station does not support Downlink Dual Carrier.
Indication of Upper Layer PDU Start Capability for RLC UM (1 bit field)
This field indicates whether the mobile station supports "Indication of Upper Layer PDU Start for RLC UM” (see
3GPP TS 44.060 [76]) for RLC unacknowledged mode of operation. The field is coded as follows:
0 The mobile station does not support "Indication of Upper Layer PDU Start for RLC UM”
1 The mobile station supports "Indication of Upper Layer PDU Start for RLC UM”
3GPP
Release 10 528 3GPP TS 24.008 V10.6.1 (2012-03)
This field indicates whether the mobile station supports multiple TTI (MTTI) configurations (see
3GPP TS 44.060 [76])
Bit
0 MTTI configurations not supported
1 MTTI configurations supported
Bits
21
00 TIGHTER not supported
01 TIGHTER supported for speech and signalling channels only
10 TIGHTER supported for speech and signalling channels and for GPRS and EGPRS, but not for EGPRS2
11 TIGHTER supported for speech and signalling channels and for GPRS, EGPRS and EGPRS2
10.5.5.13 Spare
This is intentionally left spare.
The GMM cause information element is coded as shown in figure 10.5.129/3GPP TS 24.008 and table 10.5.147/3GPP
TS 24.008.
3GPP
Release 10 529 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
GMM cause IEI octet 1
Cause value octet 2
Any other value received by the mobile station shall be treated as 0110 1111, "Protocol
error, unspecified". Any other value received by the network shall be treated as 0110
1111, "Protocol error, unspecified".
The routing area identification is a type 3 information element with 7 octets length.
3GPP
Release 10 530 3GPP TS 24.008 V10.6.1 (2012-03)
The routing area identification information element is coded as shown in figure 10.5.130/3GPP TS 24.008 and
table 10.5.148/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Routing Area Identification IEI octet 1
MCC digit 2 MCC digit 1 octet 2
MNC digit 3 MCC digit 3 octet 3
MNC digit 2 MNC digit 1 octet 4
LAC octet 5
LAC cont'd octet 6
RAC octet 7
3GPP
Release 10 531 3GPP TS 24.008 V10.6.1 (2012-03)
In abnormal cases, the MCC stored in the mobile station can contain elements not in the set {0, 1 ... 9}. In such
cases the mobile station should transmit the stored values using full hexadecimal encoding. When receiving such
an MCC, the network shall treat the RAI as deleted.
The coding of this field is the responsibility of each administration but BCD coding shall be used. The MNC shall
consist of 2 or 3 digits. For PCS 1900 for NA, Federal regulation mandates that a 3-digit MNC shall be used.
However a network operator may decide to use only two digits in the MNC in the RAI over the radio interface. In
this case, bits 5 to 8 of octet 3 shall be coded as "1111". Mobile equipment shall accept RAI coded in such a way.
NOTE 1: In earlier versions of this protocol, the possibility to use a one digit MNC in RAI was provided on the
radio interface. However as this was not used this possibility has been deleted.
NOTE 2: In earlier versions of this protocol, bits 5 to 8 of octet 3 were coded as "1111". Mobile equipment
compliant with these earlier versions of the protocol may be unable to understand the 3-digit MNC
format of the RAI, and therefore unable to register on a network broadcasting the RAI in this format.
In abnormal cases, the MNC stored in the mobile station can have:
- digit 1 or 2 not in the set {0, 1 ... 9}, or
- digit 3 not in the set {0, 1 ... 9, F} hex.
In such cases the mobile station shall transmit the stored values using full hexadecimal encoding. When
receiving such an MNC, the network shall treat the RAI as deleted.
The same handling shall apply for the network, if a 3-digit MNC is sent by the mobile station to a network using
only a 2-digit MNC.
In the LAC field bit 8 of octet 5 is the most significant bit and bit 1 of octet 6 the least significant bit.
The coding of the location area code is the responsibility of each administration except that two values are used
to mark the LAC, and hence the RAI, as deleted. Coding using full hexadecimal representation may be used. The
location area code consists of 2 octets.
If a RAI has to be deleted then all bits of the location area code shall be set to one with the exception of the least
significant bit which shall be set to zero. If a SIM/USIM is inserted in a Mobile Equipment with the location area
code containing all zeros, then the Mobile Equipment shall recognise this LAC as part of a deleted RAI.
In the RAC field bit 8 of octet 7 is the most significant. The coding of the routing area code is the responsibility of
each administration. Coding using full hexadecimal representation may be used. The routing area code consists
of 1 octet.
The Routing area identification 2 is a type 4 information element with a length of 8 octets.
The Routing area identification 2 information element is coded as shown in figure 10.5.130a/3GPP TS 24.008 and
table 10.5.148a/3GPP TS 24.008.
3GPP
Release 10 532 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Routing area identification 2 IEI octet 1
Length of routing area identification 2 IEI octet 2
octet 3
Routing area identification 2 value
octet 8
The routing area identification 2 value is coded as octet 2 to 7 of the Routing area identification information
element.
10.5.5.16 Spare
This is intentionally left spare.
The update result information element is coded as shown in figure 10.5.131/3GPP TS 24.008 and table 10.5.149/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
Update result FOP Update result octet 1
IEI value
3GPP
Release 10 533 3GPP TS 24.008 V10.6.1 (2012-03)
The update type information element is coded as shown in figure 10.5.132/3GPP TS 24.008 and table 10.5.150/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
Update type FOR Update type octet 1
IEI value
Bits
3 2 1
0 0 0 RA updating
0 0 1 combined RA/LA updating
0 1 0 combined RA/LA updating with IMSI attach
0 1 1 Periodic updating
4
0 No follow-on request pending
1 Follow-on request pending
The A&C reference number information element is coded as shown in figure 10.5.134/3GPP TS 24.008 and
table 10.5.152/3GPP TS 24.008.
8 7 6 5 4 3 2 1
A&C reference number A&C reference number octet 1
IEI value
3GPP
Release 10 534 3GPP TS 24.008 V10.6.1 (2012-03)
The service type information element is coded as shown in figure 10.5.135/3GPP TS 24.008 and table 10.5.153a/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
Service type 0 Service type octet 1
IEI spare
Bits
3 2 1
0 0 0 Signalling
0 0 1 Data
0 1 0 Paging Response
0 1 1 MBMS Multicast Service Reception
1 0 0 MBMS Broadcast Service Reception
The Cell Notification information element is coded as shown in figure 10.5.135a/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Cell Notification IEI octet 1
3GPP
Release 10 535 3GPP TS 24.008 V10.6.1 (2012-03)
The PS LCS Capability element is coded as shown in figure 10.5.135b/3GPP TS 24.008 and table 10.5.153b/3GPP TS
24.008.
8 7 6 5 4 3 2 1
3GPP
Release 10 536 3GPP TS 24.008 V10.6.1 (2012-03)
The network feature support information element is coded as shown in figure 10.5.135c/3GPP TS 24.008 and
table 10.5.153c/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Network feature support LCS- MBMS IMS EMC octet 1
IEI MOLR VoPS BS
Bit
4
0 LCS-MOLR via PS domain not supported
1 LCS-MOLR via PS domain supported
Bit
3
0 MBMS not supported
1 MBMS supported
Bit
2
0 IMS voice over PS session in Iu mode and A/Gb mode not supported
1 IMS voice over PS session supported in Iu mode, but not supported in
A/Gb mode
Bit
1
0 Emergency bearer services in Iu mode and A/Gb mode not supported
1 Emergency bearer services supported in Iu mode, but not supported in
A/Gb mode
The Inter RAT information container information element is coded as shown in figure 10.5.150/3GPP TS 24.008.
The Inter RAT information container information element is a type 4 information element with a minimum length of 3
octets and a maximum length of 250 octets.
3GPP
Release 10 537 3GPP TS 24.008 V10.6.1 (2012-03)
- mobile station security information to be used after handover to Iu mode, which includes the START-PS value
that is stored by the MS at handover from Iu mode to A/Gb mode (see 3GPP TS 33.102 [5a]); and/or
- the specific Iu mode radio capabilities of the mobile station, i.e. UE RAC (see 3GPP TS 25.331 [23c]).
8 7 6 5 4 3 2 1
Inter RAT information container IEI octet 1
Length of inter RAT information container octet 2
Inter RAT information container value part octet 3-250
The value part of the Inter RAT information container information element is the INTER RAT HANDOVER INFO as
defined in 3GPP TS 25.331 [23c]. If this field includes padding bits, they are defined in 3GPP TS 25.331 [23c].
The Requested MS information information element is coded as shown in figure 10.5.151/3GPP TS 24.008 and
table 10.5.166/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Requested MS information I-RAT I-RAT2 0 0 octet 1
IEI Spare
Bit
4
0 Inter RAT information container IE not requested
1 Inter RAT information container IE requested
3GPP
Release 10 538 3GPP TS 24.008 V10.6.1 (2012-03)
The E-UTRAN inter RAT information container information element is coded as shown in figure
10.5.151/3GPP TS 24.008.
The E-UTRAN inter RAT information container information element is a type 4 information element with a minimum
length of 3 octets and an upper length limit of 257 octets.
8 7 6 5 4 3 2 1
E-UTRAN Inter RAT information container IEI octet 1
Length of E-UTRAN Inter RAT information container octet 2
E-UTRAN Inter RAT information container value part octet 3-257
Figure 10.5.151/3GPP TS 24.008: E-UTRAN inter RAT information container information element
The value part of the E-UTRAN inter RAT information container information element is formatted and coded according
to the UE-EUTRA-Capability IE defined in 3GPP TS 36.331 [129].
The UE's usage setting bit indicates the value configured on the ME as defined in 3GPP TS 23.221 [131].
The voice domain preference for E-UTRAN bit indicates the value configured on the ME of the Voice domain
preference for E-UTRAN as defined in 3GPP TS 24.167 [134].
The Voice domain preference and UE's usage setting information element is coded as shown in
figure 10.5.151A/3GPP TS 24.008 and table 10.5.166A/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Voice domain preference and UE's usage setting IEI octet 1
Length of Voice domain preference and UE's usage setting contents octet 2
0 0 0 0 0 UE's Voice domain octet 3
Spare Spare Spare Spare Spare usage preference for
setting E-UTRAN
Figure 10.5.151A/3GPP TS 24.008: Voice domain preference and UE's usage setting information
element
3GPP
Release 10 539 3GPP TS 24.008 V10.6.1 (2012-03)
Table 10.5.166A/3GPP TS 24.008: Voice domain preference and UE's usage setting information
element
Voice domain preference and UE's usage setting value (octet 3, bit 1 to 3)
Bit
3
0 Voice centric
1 Data centric
Bit
2 1
0 0 CS Voice only
0 1 IMS PS Voice only
1 0 CS voice preferred, IMS PS Voice as secondary
1 1 IMS PS voice preferred, CS Voice as secondary
The P-TMSI type information element information element is coded as shown in figure 10.5.5.29.1 and
table 10.5.5.29.1.
8 7 6 5 4 3 2 1
P-TMSI type IEI 0 0 0 P- octet 1
spare TMSI
type
The Location Area Identification 2 information element is coded as shown in figure 10.5.5.30/3GPP TS 24.008 and
table 10.5.5.30/3GPP TS 24.008.
3GPP
Release 10 540 3GPP TS 24.008 V10.6.1 (2012-03)
The Location Area Identification 2 is a type 4 information element with 7 octets length.
8 7 6 5 4 3 2 1
Location Area Identification 2 IEI octet 1
Length of Location Area Identification 2 contents octet 2
octet 3
Location Area Identification 2 value
octet 7
The Location Area Identification 2 value is coded as octet 2 to 6 of the Location Area Identification information
element.
The Access point name is a label or a fully qualified domain name according to DNS naming conventions (see
3GPP TS 23.003 [10]).
The Access point name is a type 4 information element with a minimum length of 3 octets and a maximum length of
102 octets.
The Access point name information element is coded as shown in figure 10.5.152/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Access point name IEI octet 1
Length of access point name contents octet 2
Access point name value octet 3
octet n*
The Network service access point identifier is a type 3 information element with a length of 2 octets.
The value part of a Network service access point identifier information element is coded as shown in
figure 10.5.153/3GPP TS 24.008 and table 10.5.167/3GPP TS 24.008.
8 7 6 5 4 3 2 1
NSAPI IEI octet 1
0 0 0 0 NSAPI octet 2
Spare value
3GPP
Release 10 541 3GPP TS 24.008 V10.6.1 (2012-03)
Figure 10.5.153/3GPP TS 24.008: Network service access point identifier information element
Table 10.5.167/3GPP TS 24.008: Network service access point identifier information element
Bits
4 3 2 1
0 0 0 0 reserved
0 0 0 1 reserved
0 0 1 0 reserved
0 0 1 1 reserved
0 1 0 0 reserved
0 1 0 1 NSAPI 5
0 1 1 0 NSAPI 6
0 1 1 1 NSAPI 7
1 0 0 0 NSAPI 8
1 0 0 1 NSAPI 9
1 0 1 0 NSAPI 10
1 0 1 1 NSAPI 11
1 1 0 0 NSAPI 12
1 1 0 1 NSAPI 13
1 1 1 0 NSAPI 14
1 1 1 1 NSAPI 15
- transfer external network protocol options associated with a PDP context activation, and
- transfer additional (protocol) data (e.g. configuration parameters, error codes or messages/events) associated
with an external protocol or an application.
The protocol configuration options is a type 4 information element with a minimum length of 3 octets and a maximum
length of 253 octets.
The protocol configuration options information element is coded as shown in figure 10.5.136/3GPP TS 24.008 and
table 10.5.154/3GPP TS 24.008.
3GPP
Release 10 542 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Protocol configuration options IEI octet 1
Length of protocol config. options contents octet 2
1 0 0 0 0 Configuration octet 3
ext Spare protocol
Protocol ID 1 octet 4
octet 5
Length of protocol ID 1 contents octet 6
octet 7
Protocol ID 1 contents
octet m
Protocol ID 2 octet m+1
octet m+2
Length of protocol ID 2 contents octet m+3
octet m+4
Protocol ID 2 contents
octet n
octet n+1
...
octet u
Protocol ID n-1 octet u+1
octet u+2
Length of protocol ID n-1 contents octet u+3
octet u+4
Protocol ID n-1 contents
octet v
Protocol ID n octet v+1
octet v+2
Length of protocol ID n contents octet v+3
octet v+4
Protocol ID n contents
octet w
Container ID 1 octet w+1
octet w+2
Length of container ID 1 contents octet w+3
Container ID 1 contents octet w+4
octet x
octet x+1
...
octet y
Container ID n octet y+1
octet y+2
Length of container ID n contents octet y+3
Container ID n contents octet y+4
octet z
3GPP
Release 10 543 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 544 3GPP TS 24.008 V10.6.1 (2012-03)
All other values are interpreted as PPP in this version of the protocol.
After octet 3, i.e. from octet 4 to octet z, two logical lists are defined:
The configuration protocol options list contains a variable number of logical units,
they may occur in an arbitrary order within the configuration protocol options list.
The protocol identifier field contains the hexadecimal coding of the configuration
protocol identifier. Bit 8 of the first octet of the protocol identifier field contains the
most significant bit and bit 1 of the second octet of the protocol identifier field
contains the least significant bit.
If the configuration protocol options list contains a protocol identifier that is not
supported by the receiving entity the corresponding unit shall be discarded.
The length of the protocol identifier contents field contains the binary coded
representation of the length of the protocol identifier contents field of a unit. The first
bit in transmission order is the most significant bit.
The protocol identifier contents field of each unit contains information specific to the
configuration protocol specified by the protocol identifier.
At least the following protocol identifiers (as defined in RFC 3232 [103]) shall be
supported in this version of the protocol:
- C021H (LCP);
- C023H (PAP);
- C223H (CHAP); and
- 8021H (IPCP).
The detailed coding of the protocol identifier contents field is specified in the RFC
that is associated with the protocol identifier of that unit.
The additional parameters list is included when special parameters and/or requests
(associated with a PDP context) need to be transferred between the MS and the
network. These parameters and/or requests are not related to a specific
configuration protocol (e.g. PPP), and therefore are not encoded as the "Packets"
contained in the configuration protocol options list.
The additional parameters list contains a list of special parameters, each one in a
separate container. The type of the parameter carried in a container is identified by a
specific container identifier. In this version of the protocol, the following container
identifiers are specified:
3GPP
Release 10 545 3GPP TS 24.008 V10.6.1 (2012-03)
MS to network direction:
- 0006H (Reserved);
- 000FH (IFOM-Support-Request);
Network to MS direction:
- 0006H (Reserved);
- 000AH (Reserved);
- 000BH (Reserved);
- 000EH (MSISDN);
- 000FH (IFOM-Support);
3GPP
Release 10 546 3GPP TS 24.008 V10.6.1 (2012-03)
If the additional parameters list contains a container identifier that is not supported
by the receiving entity the corresponding unit shall be discarded.
The container identifier field is encoded as the protocol identifier field and the length
of container identifier contents field is encoded as the length of the protocol identifier
contents field.
When the container identifier indicates P-CSCF IPv6 Address Request, DNS Server
IPv6 Address Request, or MSISDN Request, the container identifier contents field is
empty and the length of container identifier contents indicates a length equal to zero.
If the container identifier contents field is not empty, it shall be ignored.
When the container identifier indicates IM CN Subsystem Signaling Flag (see 3GPP
TS 24.229 [95]), the container identifier contents field is empty and the length of
container identifier contents indicates a length equal to zero. If the container
identifier contents field is not empty, it shall be ignored. In Network to MS direction
this information may be used by the MS to indicate to the user whether the
requested dedicated signalling PDP context was successfully established.
When the container identifier indicates P-CSCF IPv6 Address, the container
identifier contents field contains one IPv6 address corresponding to a P-CSCF
address (see 3GPP TS 24.229 [95]). This IPv6 address is encoded as an 128-bit
address according to RFC 3513 [99]. When there is need to include more than one
P-CSCF address, then more logical units with container identifier indicating P-CSCF
Address are used.
When the container identifier indicates DNS Server IPv6 Address, the container
identifier contents field contains one IPv6 DNS server address (see 3GPP TS
27.060 [36a]). This IPv6 address is encoded as an 128-bit address according to
RFC 3513 [99]. When there is need to include more than one DNS server address,
then more logical units with container identifier indicating DNS Server Address are
used.
When the container identifier indicates Policy Control rejection code, the container
identifier contents field contains a Go interface related cause code from the GGSN
to the MS (see 3GPP TS 29.207 [100]). The length of container identifier contents
indicates a length equal to one. If the container identifier contents field is empty or its
actual length is greater than one octect, then it shall be ignored by the receiver.
When the container identifier indicates Selected Bearer Control Mode, the container
identifier contents field contains the selected bearer control mode, where ‘01H’
indicates that ‘MS only’ mode has been selected and ‘02H’ indicates that ‘MS/NW’
mode has been selected. The length of container identifier contents indicates a
length equal to one. If the container identifier contents field is empty or its actual
length is greater than one octect, then it shall be ignored by the receiver.
When the container identifier indicates DSMIPv6 Home Agent Address Request, the
container identifier contents field is empty and the length of container identifier
contents indicates a length equal to zero. If the container identifier contents field is
not empty, it shall be ignored.
When the container identifier indicates DSMIPv6 Home Network Prefix Request, the
container identifier contents field is empty and the length of container identifier
contents indicates a length equal to zero. If the container identifier contents field is
not empty, it shall be ignored.
When the container identifier indicates DSMIPv6 IPv4 Home Agent Address
Request, the container identifier contents field is empty and the length of container
identifier contents indicates a length equal to zero. If the container identifier contents
field is not empty, it shall be ignored.
3GPP
Release 10 547 3GPP TS 24.008 V10.6.1 (2012-03)
When the container identifier indicates DSMIPv6 Home Agent Address, the
container identifier contents field contains one IPv6 address corresponding to a
DSMIPv6 HA address (see 3GPP TS 24.303 [124] and 3GPP TS 24.327 [125]). This
IPv6 address is encoded as an 128-bit address according to IETF RFC 3513 [99].
When the container identifier indicates DSMIPv6 Home Network Prefix, the
container identifier contents field contains one IPv6 Home Network Prefix (see
3GPP TS 24.303 [124] and 3GPP TS 24.327 [125]). This IPv6 prefix is encoded as
an IPv6 address according to RFC 3513 [99] followed by 8 bits which specifies the
prefix length.
When the container identifier indicates DSMIPv6 IPv4 Home Agent Address, the
container identifier contents field contains one IPv4 address corresponding to a
DSMIPv6 IPv4 Home Agent address (see 3GPP TS 24.303 [124] and
3GPP TS 24.327 [125]).
When the container identifier indicates P-CSCF IPv4 Address Request, the
container identifier contents field is empty and the length of container identifier
contents indicates a length equal to zero. If the container identifier contents field is
not empty, it shall be ignored.
When the container identifier indicates DNS Server IPv4 Address Request, the
container identifier contents field is empty and the length of container identifier
contents indicates a length equal to zero. If the container identifier contents field is
not empty, it shall be ignored.
When the container identifier indicates P-CSCF IPv4 Address, the container
identifier contents field contains one IPv4 address corresponding to the P-CSCF
address to be used.
When the container identifier indicates DNS Server IPv4 Address, the container
identifier contents field contains one IPv4 address corresponding to the DNS server
address to be used.
P-CSCF IPv4 Address Request, P-CSCF IPv4 Address, DNS Server IPv4 Address
Request and DNS Server IPv4 Address are applicable only in S1-mode.
When the container identifier indicates IP address allocation via NAS signalling, the
container identifier contents field is empty and the length of container identifier
contents indicates a length equal to zero. If the container identifier contents field is
not empty, it shall be ignored.
When the container identifier indicates IP address allocation via DHCPv4, the
container identifier contents field is empty and the length of container identifier
contents indicates a length equal to zero. If the container identifier contents field is
not empty, it shall be ignored.
When the container identifier indicates MSISDN, the container identifier contents
field contains the MSISDN (see 3GPP TS 23.003 [10]) assigned to the MS. Use of
the MSISDN provided is defined in subclause 6.4.
When the container identifier indicates IFOM Support, the container identifier
contents field is empty and the length of container identifier contents indicates a
length equal to zero. If the container identifier contents field is not empty, it shall be
ignored. This information indicates that the Home Agent supports IFOM.
When the container identifier indicates IPv4 Link MTU Request, the container
identifier contents field is empty and the length of container identifier contents
indicates a length equal to zero. If the container identifier contents field is not empty,
it shall be ignored.
When the container identifier indicates IPv4 Link MTU, the length of container
identifier contents indicates a length equal to two. The container identifier contents
field contains the binary coded representation of the IPv4 link MTU size in octets. Bit
8 of the first octet of the container identifier contents field contains the most
3GPP
Release 10 548 3GPP TS 24.008 V10.6.1 (2012-03)
significant bit and bit 1 of the second octet of the container identifier contents field
contains the least significant bit. If the length of container identifier contents is
different from two octets, then it shall be ignored by the receiver.
When the container identifier indicates operator specific use, the Container contents
starts with MCC and MNC of the operator providing the relevant application and can
be followed by further application specific information. The coding of MCC and MNC
is as in octet 2 to 4 of the Location Area Identification information element in
subclause 10.5.1.3.
NOTE 1: The additional parameters list and the configuration protocol options list
are logically separated since they carry different type of information. The beginning
of the additional parameters list is marked by a logical unit, which has an identifier
(i.e. the first two octets) equal to a container identifier (i.e. it is not a protocol
identifier).
The packet data protocol address is a type 4 information element with minimum length of 4 octets and a maximum
length of 24 octets.
The packet data protocol address information element is coded as shown in figure 10.5.137/3GPP TS 24.008 and
table 10.5.155/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Packet data protocol address IEI octet 1
Length of PDP address contents octet 2
0 0 0 0 PDP type organisation octet 3
spare
PDP type number octet 4
octet 5
Address information
octet n
In network to MS direction :
3GPP
Release 10 549 3GPP TS 24.008 V10.6.1 (2012-03)
In MS to network direction:
If bits 4,3,2,1 of octet 3 are coded 1 1 1 1
PDP type number value (octet 4)
bits 8 to 1 are spare and shall be coded all 0.
If PDP type number indicates IPv4, the Address information in octet 5 to octet 8 contains the IPv4 address. Bit 8 of
octet 5 represents the most significant bit of the IP address and bit 1 of octet 8 the least significant bit.
If PDP type number indicates IPv6, the Address information in octet 5 to octet 20 contains the IPv6 address. Bit 8 of
octet 5 represents the most significant bit of the IP address and bit 1 of octet 20 the least significant bit.
If PDP type number indicates IPv4 or IPv4v6 and DHCPv4 is to be used to allocate the IPv4 address, the IPv4 address
shall be coded as 0.0.0.0.
The QoS IE is defined to allow backward compatibility to earlier version of Session Management Protocol.
The quality of service is a type 4 information element with a minimum length of 14 octets and a maximum length of 18
octets. The QoS requested by the MS shall be encoded both in the QoS attributes specified in octets 3-5 and in the QoS
attributes specified in octets 6-14.
In the MS to network direction and in the network to MS direction the following applies:
- Octets 15-18 are optional. If octet 15 is included, then octet 16 shall also be included, and octets 17 and 18 may
be included.
3GPP
Release 10 550 3GPP TS 24.008 V10.6.1 (2012-03)
- A QoS IE received without octets 6-18, without octets 14-18, without octets 15-18, or without octets 17-18 shall
be accepted by the receiving entity.
NOTE: This behavior is required for interworking with entities supporting an earlier version of the protocol, or
when the Maximum bit rate for downlink or for downlink and uplink is negotiated to a value lower than
8700 kbps.
The quality of service information element is coded as shown in figure 10.5.138/3GPP TS 24.008 and
table 10.5.156/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Quality of service IEI octet 1
Length of quality of service IE Octet 2
0 0 Delay Reliability octet 3
spare class class
Peak 0 Precedence octet 4
throughput spare class
0 0 0 Mean octet 5
spare throughput
Traffic Class Delivery order Delivery of erroneous Octet 6
SDU
Maximum SDU size Octet 7
Maximum bit rate for uplink Octet 8
Maximum bit rate for downlink Octet 9
Residual BER SDU error ratio Octet 10
Transfer delay Traffic Handling Octet 11
priority
Octet 12
Guaranteed bit rate for uplink
Guaranteed bit rate for downlink Octet 13
0 0 0 Signal- Source Statistics Descriptor Octet 14
spare ling
Indicat-
ion
Maximum bit rate for downlink (extended) Octet 15
Guaranteed bit rate for downlink (extended) Octet 16
Maximum bit rate for uplink (extended) Octet 17
Guaranteed bit rate for uplink (extended) Octet 18
3GPP
Release 10 551 3GPP TS 24.008 V10.6.1 (2012-03)
All other values are interpreted as Unacknowledged GTP and LLC; Acknowledged RLC, Protected data in this version of
the protocol.
If network supports EPS, then it should not assign Reliability class value ‘010’.
Delay class, octet 3 (see 3GPP TS 22.060 [73] and 3GPP TS 23.107 [81])
Bits
654
In MS to network direction:
0 0 0 Subscribed delay class
In network to MS direction:
0 0 0 Reserved
In MS to network direction and in network to MS direction:
0 0 1 Delay class 1
0 1 0 Delay class 2
0 1 1 Delay class 3
1 0 0 Delay class 4 (best effort)
1 1 1 Reserved
3GPP
Release 10 552 3GPP TS 24.008 V10.6.1 (2012-03)
All other values are interpreted as Delay class 4 (best effort) in this version
of the protocol.
Bit 7 and 8 of octet 3 are spare and shall be coded all 0.
Precedence class, octet 4 (see 3GPP TS 23.107 [81])
Bits
321
In MS to network direction:
0 0 0 Subscribed precedence
In network to MS direction:
0 0 0 Reserved
In MS to network direction and in network to MS direction:
0 0 1 High priority
0 1 0 Normal priority
0 1 1 Low priority
1 1 1 Reserved
All other values are interpreted as Normal priority in this version of the protocol.
3GPP
Release 10 553 3GPP TS 24.008 V10.6.1 (2012-03)
In MS to network direction:
00000 Subscribed mean throughput
In network to MS direction:
00000 Reserved
In MS to network direction and in network to MS direction:
00001 100 octet/h
00010 200 octet/h
00011 500 octet/h
00100 1 000 octet/h
00101 2 000 octet/h
00110 5 000 octet/h
00111 10 000 octet/h
01000 20 000 octet/h
01001 50 000 octet/h
01010 100 000 octet/h
01011 200 000 octet/h
01100 500 000 octet/h
01101 1 000 000 octet/h
01110 2 000 000 octet/h
01111 5 000 000 octet/h
10000 10 000 000 octet/h
10001 20 000 000 octet/h
10010 50 000 000 octet/h
11110 Reserved
11111 Best effort
The value Best effort indicates that throughput shall be made available to the MS on a per need and availability basis.
All other values are interpreted as Best effort in this
version of the protocol.
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of this protocol.
3GPP
Release 10 554 3GPP TS 24.008 V10.6.1 (2012-03)
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of this protocol.
For values in the range 00000001 to 10010110 the Maximum SDU size value is binary coded in 8 bits, using a
granularity of 10 octets, giving a range of values from 10 octets to 1500 octets.
Values above 10010110 are as below:
10010111 1502 octets
10011000 1510 octets
10011001 1520 octets
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of this protocol.
01000000 The maximum bit rate is 64 kbps + ((the binary coded value in 8 bits –01000000) * 8 kbps)
01111111 giving a range of values from 64 kbps to 568 kbps in 8 kbps increments.
10000000 The maximum bit rate is 576 kbps + ((the binary coded value in 8 bits –10000000) * 64 kbps)
11111110 giving a range of values from 576 kbps to 8640 kbps in 64 kbps increments.
11111111 0kbps
If the sending entity wants to indicate a Maximum bit rate for uplink higher than 8640 kbps, it shall set octet 8 to
”11111110”, i.e. 8640 kbps, and shall encode the value for the Maximum bit rate in octet 17.
3GPP
Release 10 555 3GPP TS 24.008 V10.6.1 (2012-03)
Maximum bit rate for downlink, octet 9 (see 3GPP TS 23.107 [81])
If the sending entity wants to indicate a Maximum bit rate for downlink higher than 8640 kbps, it shall set octet 9 to
”11111110”, i.e. 8640 kbps, and shall encode the value for the Maximum bit rate in octet 15.
In this version of the protocol, for messages specified in the present document, the sending entity shall not request 0
kbps for both the Maximum bitrate for downlink and the Maximum bitrate for uplink at the same time. Any entity receiving
a request for 0 kbps in both the Maximum bitrate for downlink and the Maximum bitrate for uplink shall consider that as a
syntactical error (see clause 8).
Residual Bit Error Rate (BER), octet 10 (see 3GPP TS 23.107 [81])
Bits
8765
In MS to network direction:
0000 Subscribed residual BER
In network to MS direction:
0000 Reserved
In MS to network direction and in network to MS direction:
The Residual BER value consists of 4 bits. The range is from 5*10-2 to 6*10-8.
0001 5*10-2
0010 1*10-2
0011 5*10-3
0100 4*10-3
0101 1*10-3
0110 1*10-4
0111 1*10-5
1000 1*10-6
1001 6*10-8
1111 Reserved
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of the protocol.
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of the protocol.
3GPP
Release 10 556 3GPP TS 24.008 V10.6.1 (2012-03)
In network to MS direction:
00 Reserved
In MS to network direction and in network to MS direction:
01 Priority level 1
10 Priority level 2
11 Priority level 3
The Traffic handling priority value is ignored if the Traffic Class is Conversational class, Streaming class or Background
class.
In MS to network direction:
000000 Subscribed transfer delay
In network to MS direction:
000000 Reserved
In MS to network direction and in network to MS direction:
010000 The transfer delay is 200 ms + ((the binary coded value in 6 bits – 010000) * 50 ms)
011111 giving a range of values from 200 ms to 950 ms in 50ms increments
100000 The transfer delay is 1000 ms + ((the binary coded value in 6 bits – 100000) * 100 ms)
111110 giving a range of values from 1000 ms to 4000 ms in 100ms increments
111111 Reserved
The Transfer delay value is ignored if the Traffic Class is Interactive class or Background class.
Guaranteed bit rate for uplink, octet 12 (See 3GPP TS 23.107 [81])
If the sending entity wants to indicate a Guaranteed bit rate for uplink higher than 8640 kbps, it shall set octet 12 to
”11111110”, i.e. 8640 kbps, and shall encode the value for the Guaranteed bit rate in octet 18.
The Guaranteed bit rate for uplink value is ignored if the Traffic Class is Interactive class or Background class, or
Maximum bit rate for uplink is set to 0 kbps.
Guaranteed bit rate for downlink, octet 13(See 3GPP TS 23.107 [81])
If the sending entity wants to indicate a Guaranteed bit rate for downlink higher than 8640 kbps, it shall set octet 13 to
”11111110”, i.e. 8640 kbps, and shall encode the value for the Guaranteed bit rate in octet 16.
The Guaranteed bit rate for downlink value is ignored if the Traffic Class is Interactive class or Background class, or
Maximum bit rate for downlink is set to 0 kbps.
In network to MS direction
Bits 4 to 1 of octet 14 are spare and shall be coded all 0.
3GPP
Release 10 557 3GPP TS 24.008 V10.6.1 (2012-03)
The Source Statistics Descriptor value is ignored if the Traffic Class is Interactive class or Background class.
If set to '1' the QoS of the PDP context is optimised for signalling
The Signalling Indication value is ignored if the Traffic Class is Conversational class, Streaming class or Background
class.
For all other values: Ignore the value indicated by the Maximum bit rate for downlink in octet 9
and use the following value:
0 0 0 0 0 0 0 1 The maximum bit rate is 8600 kbps + ((the binary coded value in 8 bits) * 100 kbps),
0 1 0 0 1 0 1 0 giving a range of values from 8700 kbps
to 16000 kbps in 100 kbps increments.
01001011 The maximum bit rate is 16 Mbps + ((the binary coded value in 8 bits - 01001010) * 1 Mbps),
10111010 giving a range of values from 17 Mbps to 128 Mbps in 1 Mbps increments.
10111011 The maximum bit rate is 128 Mbps + ((the binary coded value in 8 bits - 10111010) * 2 Mbps),
11111010 giving a range of values from 130 Mbps to 256 Mbps in 2 Mbps increments.
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of the protocol.
The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol.
For all other values: Ignore the value indicated by the Guaranteed bit rate for downlink in octet 9
and use the following value:
00000001 The guaranteed bit rate is 8600 kbps + ((the binary coded value in 8 bits) * 100 kbps),
01001010 giving a range of values from 8700 kbps to 16000 kbps in 100 kbps increments.
01001011 The guaranteed bit rate is 16 Mbps + ((the binary coded value in 8 bits - 01001010) * 1 Mbps),
10111010 giving a range of values from 17 Mbps to 128 Mbps in 1 Mbps increments.
10111011 The guaranteed bit rate is 128 Mbps + ((the binary coded value in 8 bits - 10111010) * 2 Mbps),
11111010 giving a range of values from 130 Mbps to 256 Mbps in 2 Mbps increments.
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of the protocol.
The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol.
This field is an extension of the Maximum bit rate for uplink in octet 8. The coding is identical to that of the Maximum bit
rate for downlink (extended).
3GPP
Release 10 558 3GPP TS 24.008 V10.6.1 (2012-03)
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of the protocol.
The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol.
This field is an extension of the Guaranteed bit rate for uplink in octet 12. The coding is identical to that of the
Guaranteed bit rate for downlink (extended).
The network shall map all other values not explicitly defined onto one of the values defined in this version of the protocol.
The network shall return a negotiated value which is explicitly defined in this version of the protocol.
The MS shall map all other values not explicitly defined onto the maximum value defined in this version of the protocol.
10.5.6.6 SM cause
The purpose of the SM cause information element is to indicate the reason why a session management request is
rejected.
The SM cause information element is coded as shown in figure 10.5.139/3GPP TS 24.008 and table 10.5.157/3GPP TS
24.008.
8 7 6 5 4 3 2 1
SM cause IEI octet 1
Cause value octet 2
3GPP
Release 10 559 3GPP TS 24.008 V10.6.1 (2012-03)
Any other value received by the mobile station shall be treated as 0010 0010, "Service
option temporarily out of order”. Any other value received by the network shall be treated as
0110 1111, "Protocol error, unspecified".
10.5.6.6A SM cause 2
The purpose of the SM cause 2 information element is to provide further information when PDP context activation
initiated by the mobile station is successful.
The SM cause 2 information element is coded as shown in figure 10.5.139a/3GPP TS 24.008 and table 10.5.157a/3GPP
TS 24.008.
3GPP
Release 10 560 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
SM cause 2 IEI octet 1
Length of SM cause 2 contents octet 2
SM cause 2 value octet 3
10.5.6.7 Linked TI
The purpose of the Linked TI information element is to specify the active PDP context from which the PDP address for
the new PDP context could be derived by the network.
The Linked TI is a type 4 information element with a minimum length of 3 octets and a maximum length of 4 octets.
8 7 6 5 4 3 2 1
Linked TI IEI octet 1
Length of Linked TI IE octet 2
0000
TI flag TI value octet 3
Spare
1
TI value octet 4
EXT
The coding of the TI flag, the TI value and the EXT bit is defined in 3GPP TS 24.007[20].
10.5.6.8 Spare
The LLC service access point identifier is a type 3 information element with a length of 2 octets.
The value part of a LLC service access point identifier information element is coded as shown in figure 10.5.141/3GPP
TS 24.008 and table 10.5.159/3GPP TS 24.008.
8 7 6 5 4 3 2 1
LLC SAPI IEI octet 1
0 0 0 0 LLC SAPI octet 2
Spare value
Figure 10.5.141/3GPP TS 24.008: LLC service access point identifier information element
3GPP
Release 10 561 3GPP TS 24.008 V10.6.1 (2012-03)
Table 10.5.159/3GPP TS 24.008: LLC service access point identifier information element
Bit
4321
0000 LLC SAPI not assigned
0011 SAPI 3
0101 SAPI 5
1001 SAPI 9
1011 SAPI 11
The tear down indicator information element is coded as shown in figure 10.5.142/3GPP TS 24.008 and
table 10.5.160/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Tear down indicator 0 0 0 TDI octet 1
IEI spare flag
Bit
1
0 tear down not requested
1 tear down requested
The Packet Flow Identifier is a a type 4 information element with 3 octets length.
The Packet Flow Identifier information element is coded as shown in figure 10.5.143/3GPP TS 24.008 and
table 10.5.161/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Packet Flow Identifier IEI octet 1
Length of Packet Flow Identifier IE octet 2
Spare Packet Flow Identifier value octet 3
0
3GPP
Release 10 562 3GPP TS 24.008 V10.6.1 (2012-03)
0000100 }
to } reserved
0000111 }
0001000 }
to } dynamically assigned
1111111 }
The traffic flow template is a type 4 information element with a minimum length of 3 octets. The maximum length for
the IE is 257 octets.
NOTE 1: The IE length restriction is due to the maximum length that can be encoded in a single length octet.
NOTE 2: A maximum size IPv4 packet filter can be 32 bytes. Therefore, 7 maximum size IPv4 type packet filters,
plus the last packet filter which can contain max 30 octets can fit into one TFT IE, i.e. if needed not all
packet filter components can be defined into one message. A maximum size IPv6 packet filter can be 60
bytes. Therefore, only 4 maximum size IPv6 packet filters can fit into one TFT IE. However, using "Add
packet filters to existing TFT", it's possible to create a TFT data structure including 16 maximum size
IPv4 or IPv6 filters.
The traffic flow template information element is coded as shown in figure 10.5.144/3GPP TS 24.008 and table
10.5.162/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Traffic flow template IEI Octet 1
Length of traffic flow template IE Octet 2
TFT operation code E bit Number of packet filters Octet 3
Octet 4
Packet filter list
Octet z
Octet z+1
Parameters list
Octet v
3GPP
Release 10 563 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Packet filter identifier 1 Octet 4
Packet filter identifier 2 Octet 5
…
Packet filter identifier N Octet N+3
Figure 10.5.144a/3GPP TS 24.008: Packet filter list when the TFT operation is "delete packet filters
from existing TFT" (z=N+3)
8 7 6 5 4 3 2 1
Packet filter identifier 1 Octet 4
Packet filter evaluation precedence 1 Octet 5
Length of Packet filter contents 1 Octet 6
Packet filter contents 1 Octet 7
Octet m
Packet filter identifier 2 Octet m+1
Packet filter evaluation precedence 2 Octet m+2
Length of Packet filter contents 2 Octet m+3
Packet filter contents 2 Octet m+4
Octet n
… Octet n+1
Octet y
Packet filter identifier N Octet y+1
Packet filter evaluation precedence N Octet y+2
Length of Packet filter contents N Octet y+3
Packet filter contents N Octet y+4
Octet z
Figure 10.5.144b/3GPP TS 24.008: Packet filter list when the TFT operation is "create new TFT", or
"add packet filters to existing TFT" or "replace packet filters in existing TFT"
8 7 6 5 4 3 2 1
Parameter identifier 1 Octet z+1
Length of Parameter contents 1 Octet z+2
Parameter contents 1 Octet z+3
Octet k
Parameter identifier 2 Octet k+1
Length of Parameter contents 2 Octet k+2
Parameter contents 2 Octet k+3
Octet p
… Octet p+1
Octet q
Parameter identifier N Octet q+1
Length of Parameter contents N Octet q+2
Parameter contents N Octet q+3
Octet v
3GPP
Release 10 564 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 565 3GPP TS 24.008 V10.6.1 (2012-03)
The TFT operation code "No TFT operation" shall be used if a parameters list is
included but no packet filter list is included in the traffic flow template information
element.
For the "create new TFT", "add packet filters to existing TFT" and "replace packet
filters in existing TFT" operations, the packet filter list shall contain a variable
number of packet filters. This number shall be derived from the coding of the
number of packet filters field in octet 3.
The packet filter identifier field is used to identify each packet filter in a TFT. The
least significant 4 bits are used.
The packet filter direction is used to indicate, in bits 5 and 6, for what traffic direction
the filter applies:
The packet filter evaluation precedence field is used to specify the precedence for
the packet filter among all packet filters in all TFTs associated with this PDP
address. Higher the value of the packet filter evaluation precedence field, lower the
precedence of that packet filter is. The first bit in transmission order is the most
significant bit.
3GPP
Release 10 566 3GPP TS 24.008 V10.6.1 (2012-03)
The length of the packet filter contents field contains the binary coded
representation of the length of the packet filter contents field of a packet filter. The
first bit in transmission order is the most significant bit.
The packet filter contents field is of variable size and contains a variable number (at
least one) of packet filter components. Each packet filter component shall be
encoded as a sequence of a one octet packet filter component type identifier and a
fixed length packet filter component value field. The packet filter component type
identifier shall be transmitted first.
In each packet filter, there shall not be more than one occurrence of each packet
filter component type. Among the "IPv4 remote address type" and "IPv6 remote
address type" packet filter components, only one shall be present in one packet
filter. Among the "single local port type" and "local port range type" packet filter
components, only one shall be present in one packet filter. Among the "single
remote port type" and "remote port range type" packet filter components, only one
shall be present in one packet filter.
The term local refers to the MS and the term remote refers to an external network
entity.
For "IPv4 remote address type", the packet filter component value field shall be
encoded as a sequence of a four octet IPv4 address field and a four octet IPv4
address mask field. The IPv4 address field shall be transmitted first.
For "IPv6 remote address type", the packet filter component value field shall be
encoded as a sequence of a sixteen octet IPv6 address field and a sixteen octet
IPv6 address mask field. The IPv6 address field shall be transmitted first.
For "Protocol identifier/Next header type", the packet filter component value field
shall be encoded as one octet which specifies the IPv4 protocol identifier or IPv6
next header.
For "Single local port type" and "Single remote port type", the packet filter
component value field shall be encoded as two octet which specifies a port number.
For "Local port range type" and "Remote port range type", the packet filter
component value field shall be encoded as a sequence of a two octet port range low
limit field and a two octet port range high limit field. The port range low limit field
shall be transmitted first.
For "Security parameter index", the packet filter component value field shall be
encoded as four octet which specifies the IPSec security parameter index.
For "Type of service/Traffic class type", the packet filter component value field shall
be encoded as a sequence of a one octet Type-of-Service/Traffic Class field and a
one octet Type-of-Service/Traffic Class mask field. The Type-of-Service/Traffic Class
field shall be transmitted first.
For "Flow label type", the packet filter component value field shall be encoded as
three octet which specifies the IPv6 flow label. The bits 8 through 5 of the first octet
shall be spare whereas the remaining 20 bits shall contain the IPv6 flow label.
Parameters list (octets z+1 to v)
3GPP
Release 10 567 3GPP TS 24.008 V10.6.1 (2012-03)
Each parameter included in the parameters list is of variable length and consists of:
- a parameter identifier (1 octet);
- the length of the parameter contents (1 octet); and
- the parameter contents itself (v octets).
The parameter identifier field is used to identify each parameter included in the
parameters list and it contains the hexadecimal coding of the parameter identifier.
Bit 8 of the parameter identifier field contains the most significant bit and bit 1
contains the least significant bit. In this version of the protocol, the following
parameter identifiers are specified:
- 01H (Authorization Token);
- 02H (Flow Identifier); and
- 03H (Packet Filter Identifier).
If the parameters list contains a parameter identifier that is not supported by the
receiving entity the corresponding parameter shall be discarded.
The length of parameter contents field contains the binary coded representation of
the length of the parameter contents field. The first bit in transmission order is the
most significant bit.
When the parameter identifier indicates Authorization Token, the parameter contents
field contains an authorization token, as specified in 3GPP TS 29.207 [100]. The first
octet is the most significant octet of the authorization token and the last octet is the
least significant octet of the authorization token.
The parameters list shall be coded in a way that an Authorization Token (i.e. a
parameter with identifier 01H) is always followed by one or more Flow Identifiers (i.e.
one or more parameters with identifier 02H).
If the parameters list contains two or more consecutive Authorization Tokens without
any Flow Identifiers in between, the receiver shall treat this as a semantical TFT
error.
When the parameter identifier indicates Flow Identifier, the parameter contents field
contains the binary representation of a flow identifier. The Flow Identifier consists of
four octets. Octets 1 and 2 contains the Media Component number as specified in
3GPP TS 29.207 [100]. Bit 1 of octet 2 is the least significant bit, and bit 8 of octet 1
is the most significant bit. Octets 3 and 4 contains the IP flow number as specified in
3GPP TS 29.207 [100]. Bit 1 of octet 4 is the least significant bit, and bit 8 of octet 3
is the most significant bit.
When the parameter identifier indicates Packet Filter Identifier, the parameter
contents field contains the binary representation of one or more packet filter
identifiers. Each packet filter identifier is encoded in one octet, in the 4 least
significant bits. This parameter is used by the MS to identify one or more packet
filters in a TFT when modifying the QoS of a PDP context without modifying the
packet filter itself.
The TMGI information element is a type 4 information element with a minimum length of 5 octets and a maximum
length of 8 octets. If octet 6 is included, then octets 7 and 8 shall also be included.
The content of the TMGI element is shown in Figure 10.5.154/3GPP TS 24.008 and table 10.5.168/3GPP TS 24.008.
3GPP
Release 10 568 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Temporary Mobile Group Identity IEI Octet 1
Length of Temporary Mobile Group Identity contents Octet 2
Octet 3
MBMS Service ID Octet 4
Octet 5
MCC digit 2 MCC digit 1 Octet 6*
MNC digit 3 MCC digit 3 Octet 7*
MNC digit 2 MNC digit 1 Octet 8*
In the MBMS Service ID field bit 8 of octet 3 is the most significant bit and bit 1 of octet 5 the least significant bit.
The coding of the MBMS Service ID is the responsibility of each administration. Coding using full hexadecimal
representation may be used. The MBMS Service ID consists of 3 octets.
The coding of this field is the responsibility of each administration but BCD coding shall be used. The MNC shall
consist of 2 or 3 digits. If a network operator decides to use only two digits in the MNC, bits 5 to 8 of octet 7 shall
be coded as "1111".
NOTE: The information element indicates the static physical capabilities of the MS, independent of the radio
access (UTRAN or GERAN), the radio conditions, or other CS or PS services possibly activated by the
MS.
The MBMS bearer capabilities is a type 4 information element with a maximum length of 4 octets.
The MBMS bearer capabilities information element is coded as shown in figure 10.5.155/3GPP TS 24.008 and
table 10.5.169/3GPP TS 24.008.
8 7 6 5 4 3 2 1
MBMS bearer capabilities IEI Octet 1
Length of MBMS bearer capabilities IE Octet 2
Maximum bit rate for downlink Octet 3
Maximum bit rate for downlink (extended) Octet 4
3GPP
Release 10 569 3GPP TS 24.008 V10.6.1 (2012-03)
Maximum bit rate for downlink, octet 3 (see 3GPP TS 23.107 [81])
The coding is identical to that of the maximum bit rate for downlink, octet 9, in the Quality of service information element
(see subclause 10.5.6.5).
If the sending entity wants to indicate a maximum bit rate for downlink higher than 8640 kbps, it shall set octet 3 to
”11111110”, i.e. 8640 kbps, and shall encode the value for the maximum bit rate in octet 4.
The coding is identical to that of the maximum bit rate for downlink (extended), octet 15, in the Quality of service
information element (see subclause 10.5.6.5).
- transfer protocol options associated with the bearer level of an MBMS context activation, and
- transfer additional MBMS bearer related (protocol) data (e.g. configuration parameters, error codes or
messages/events).
The MBMS protocol configuration options is a type 4 information element with a minimum length of 3 octets and a
maximum length of 253 octets.
The MBMS protocol configuration options information element is coded as shown in figure 10.5.156/3GPP TS 24.008
and table 10.5.170/3GPP TS 24.008.
8 7 6 5 4 3 2 1
MBMS protocol configuration options IEI octet 1
Length of MBMS protocol configuration options contents octet 2
0 0 0 0 0 0 0 0 octet 3
Spare
NOTE: The reason for defining the information element is to have a transparent
mechanism in the SGSN available from the introduction of MBMS. This
will ensure that MS – GGSN communication is possible if new MBMS
bearer service related parameters are defined.
The Enhanced network service access point identifier is a type 3 information element with a length of 2 octets.
The value part of an Enhanced network service access point identifier information element is coded as shown in
figure 10.5.157/3GPP TS 24.008 and table 10.5.171/3GPP TS 24.008.
3GPP
Release 10 570 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Enhanced NSAPI IEI octet 1
Enhanced NSAPI octet 2
value
Figure 10.5.157/3GPP TS 24.008: Enhanced network service access point identifier information
element
Table 10.5.171/3GPP TS 24.008: Enhanced network service access point identifier information
element
Bits
8 7 6 5 4 3 2 1
0 0 0 0 0 0 0 0 Reserved
through
0 1 1 1 1 1 1 1 Reserved
1 1 1 1 1 1 1 1 Reserved (NOTE)
NOTE: NSAPI 255 is reserved for use by lower layers in the point-to-point radio bearer
allocation message for Multimedia Broadcast/Multicast Service (MBMS)
Broadcast mode (see 3GPP TS 25.331 [23c]).
The Request type information element is also used to indicate that the MS is requesting connectivity to a PDN that
provides emergency bearer services.
The Request type information element is coded as shown in figure 10.5.158/3GPP TS 24.008 and
table 10.5.173/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Request type IEI 0 Request type value octet 1
Spare
3GPP
Release 10 571 3GPP TS 24.008 V10.6.1 (2012-03)
The Notification indicator information element is coded as shown in figure 10.5.159/3GPP TS 24.008 and
table 10.5.174/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Notification indicator IEI octet 1
Length of notification indicator contents octet 2
Notification indicator value octet 3
Bits
8 7 6 5 4 3 2 1
0 0 0 0 0 0 0 1 SRVCC handover cancelled, IMS session re-
establishment required (see 3GPP TS 23.216 [126])
0 0 0 0 0 0 1 0
to Unused, shall be ignored if received by the MS
0 1 1 1 1 1 1 1
The Connectivity type information element is coded as shown in figure 10.5.6.19-1/3GPP TS 24.008 and
table 10.5.6.19-1/3GPP TS 24.008.
3GPP
Release 10 572 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
Connectivity type Connectivity type octet 1
IEI value
All other values shall be interpreted as "the PDN connection type is not
indicated".
The PDP context status information element is a type 4 information element with 4 octets length.
The PDP context status information element is coded as shown in figure 10.5.148/3GPP TS 24.008 and
table 10.5.164/3GPP TS 24.008.
8 7 6 5 4 3 2 1
PDP context status IEI octet 1
Length of PDP context status contents Octet 2
NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI octet 3
(7) (6) (5) (4) (3) (2) (1) (0)
NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI octet 4
(15) (14) (13) (12) (11) (10) (9) (8)
NSAPI(0) - NSAPI(4):
are coded as '0' and shall be treated as spare in this version of the protocol.
NSAPI(5) – NSAPI(15):
0 indicates that the SM state of the corresponding PDP context is PDP-INACTIVE.
1 indicates that the SM state of the corresponding PDP context is not PDP-INACTIVE.
3GPP
Release 10 573 3GPP TS 24.008 V10.6.1 (2012-03)
The radio priority information element is coded as shown in figure 10.5.145/3GPP TS 24.008 and
table 10.5.161/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Radio priority IEI 0 Radio priority octet 1
spare level value
The GPRS timer information element is coded as shown in figure 10.5.146/3GPP TS 24.008 and table 10.5.172/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
GPRS Timer IEI octet 1
Unit Timer value octet 2
3GPP
Release 10 574 3GPP TS 24.008 V10.6.1 (2012-03)
Bits 6 to 8 defines the timer value unit for the GPRS timer as follows:
Bits
876
0 0 0 value is incremented in multiples of 2 seconds
0 0 1 value is incremented in multiples of 1 minute
0 1 0 value is incremented in multiples of decihours
1 1 1 value indicates that the timer is deactivated.
The GPRS timer 2 information element is coded as shown in figure 10.5.147/3GPP TS 24.008 and table 10.5.163/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
GPRS Timer 2 IEI octet 1
Length of GPRS Timer 2 contents octet 2
GPRS Timer 2 value octet 3
GPRS Timer 2 value is coded as octet 2 of the GPRS timer information element.
The GPRS timer 3 information element is coded as shown in figure 10.5.147a/3GPP TS 24.008 and
table 10.5.163a/3GPP TS 24.008.
8 7 6 5 4 3 2 1
GPRS Timer 3 IEI octet 1
Length of GPRS Timer 3 contents octet 2
Unit Timer value octet 3
3GPP
Release 10 575 3GPP TS 24.008 V10.6.1 (2012-03)
Bits 6 to 8 defines the timer value unit for the GPRS timer as follows:
Bits
876
0 0 0 value is incremented in multiples of 10 minutes
0 0 1 value is incremented in multiples of 1 hour
0 1 0 value is incremented in multiples of 10 hours
0 1 1 value is incremented in multiples of 2 seconds
1 0 0 value is incremented in multiples of 30 seconds
1 0 1 value is incremented in multiples of 1 minute
1 1 1 value indicates that the timer is deactivated.
The radio priority 2 information element is coded as shown in figure 10.5.148/3GPP TS 24.008 and
table 10.5.164/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Radio priority 2 IEI 0 Radio priority octet 1
spare level value
Bits
3 2 1
0 0 1 priority level 1 (highest)
0 1 0 priority level 2
0 1 1 priority level 3
1 0 0 priority level 4 (lowest)
All other values are interpreted as priority level 4 by this version of the protocol.
3GPP
Release 10 576 3GPP TS 24.008 V10.6.1 (2012-03)
The MBMS context status information element is a type 4 information element with a minimum length of 2 octets and a
maximum length of 18 octets.
The MBMS context status information element is coded as shown in figure 10.5.149/3GPP TS 24.008 and
table 10.5.165/3GPP TS 24.008.
8 7 6 5 4 3 2 1
MBMS context status IEI octet 1
Length of MBMS context status contents octet 2
NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI octet 3
(135) (134) (133) (132) (131) (130) (129) (128)
NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI octet 4
(143) (142) (141) (140) (139) (138) (137) (136)
If octets are not included in the information element, the receiver shall interprete the NSAPI(x) values of these
octets as set to 0.
The Uplink data status information element is a type 4 information element with 4 octets length.
The Uplink data status information element is coded as shown in figure 10.5.149/3GPP TS 24.008 and
table 10.5.166/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Uplink data status IEI octet 1
Length of Uplink data status contents octet 2
NSAPI NSAPI NSAPI Spare Spare Spare Spare Spare octet 3
(7) (6) (5) (0) (0) (0) (0) (0)
NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI NSAPI octet 4
(15) (14) (13) (12) (11) (10) (9) (8)
3GPP
Release 10 577 3GPP TS 24.008 V10.6.1 (2012-03)
The Device properties information element is coded as shown in figure 10.5.7.8.1/3GPP TS 24.008 and
table 10.5.7.8.1/3GPP TS 24.008.
8 7 6 5 4 3 2 1
Device properties 0 0 0 Low octet 1
IEI Spare Spare Spare priority
Bit
1
0 MS is not configured for NAS signalling low priority
1 MS is configured for NAS signalling low priority
The value "0" can also be used by an MS configured for NAS signalling low priority for
the exception cases specified in subclause 1.8.
3GPP
Release 10 578 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 579 3GPP TS 24.008 V10.6.1 (2012-03)
LOCATION UPDATE
REJECTED
3GPP
Release 10 580 3GPP TS 24.008 V10.6.1 (2012-03)
T3241 RR CONNECTION 300s see subclause 11.2.1 see subclause 11.2.1 abort the RR
RELEASE NOT connection
ALLOWED
T3242 All except NULL 12 eCall only MS enters - Removal of eCall only Perform eCall
hours MM IDLE state after restriction Inactivity
an emergency call procedure in
subclause 4.4.7
T3243 All except NULL 12 eCall only MS enters - Removal of eCall only Perform eCall
hours MM IDLE state after restriction Inactivity
a procedure in
test/reconfiguration subclause 4.4.7
call
T3245 All except NULL Note 2 - SIM/USIM is removed
see subclause 4.1.1.6 see subclause
(A/Gb or Iu mode 4.1.1.6 (A/Gb or Iu
only) mode only)
see subclause 5.3.7a see subclause
in 3GPP TS 5.3.7a in 3GPP TS
24.301[120] (S1 24.301[120] (S1
mode only) mode only)
AUTHENT-
FAILURE
received
T3270 IDENTIFICATION 12s IDENTITY IDENTITY Optionally
INITIATED REQUEST sent RESPONSE Release RR
received connection
3GPP
Release 10 581 3GPP TS 24.008 V10.6.1 (2012-03)
- the mobile station receives a LOCATION UPDATING ACCEPT message completing a location updating
procedure in the cases specified in subclauses 4.4.4.6 and 4.4.4.8;
- the mobile station receives a LOCATION UPDATING REJECT message in the cases specified in
subclause 4.4.4.7;
- the mobile station has sent a CM SERVICE ABORT message as specified in subclause 4.5.1.7;
- the mobile station has released or aborted all MM connections in the cases specified in 4.3.2.5, 4.3.5.2, 4.5.1.1,
and 4.5.3.1.
Timer T3240 is stopped and reset (but not started) at receipt of a CM message that initiates establishment of an CM
connection (an appropriate SETUP, REGISTER, or CP-DATA message as defined in 3GPP TS 24.008, 3GPP TS 24.010
[21] or 3GPP TS 24.011 [22]).
Timer T3241 is started in the mobile station when entering MM state RR CONNECTION RELEASE NOT
ALLOWED.
Timer T3241 is stopped and reset (but not started) when the MM state RR CONNECTION RELEASE NOT
ALLOWED is left.
If timer T3241 expires, the MS shall abort the RR connection and enter the MM state MM IDLE.
3GPP
Release 10 582 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 583 3GPP TS 24.008 V10.6.1 (2012-03)
Enter GMM-
DEREG or
GMM-NULL
T3318 20s GMM- AUTHENTICATION & AUTHENTICATION On first expiry, the
REG-INIT CIPHERING FAILURE & CIPHERING MS should consider
GMM-REG (cause=’MAC failure’ or ‘GSM REQUEST received the network as false
authentication unacceptable’) sent and will follow
GMM-DEREG- subclause 4.7.7.6.1,
INIT if the MS is not
GMM-RA- attached for
UPDATING-INT emergency bearer
services.
GMM-SERV-
REQ-INIT (Iu On the first expiry,
mode only) the MS will follow
subclause 4.7.7.6,
under "for items f
and g", if the MS is
attached for
emergency bearer
services.
3GPP
Release 10 584 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: The conditions for which this applies are described in subclause 4.7.5.1.5.
3GPP
Release 10 585 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 586 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 587 3GPP TS 24.008 V10.6.1 (2012-03)
T3346 NOTE 7 GMM- ATTACH REJECT, ROUTING Paging received Initiation of attach
DEREGISTERE AREA UPDATE REJECT or procedure, routing
D. SERVICE REJECT received with area updating
ATTEMPTING- a timer value for T3346; procedure or
TO-ATTACH "Extended wait time" for PS service request
GMM- domain from the lower layers procedure,
REGISTERED. (defined in dependent on GMM
ATTEMPTING- 3GPP TS 25.331 [23c]). state and GPRS
TO-UPDATE update status.
ATTACH REJECT, TRACKING
GMM- AREA UPDATE REJECT or Initiation of attach
REGISTERED SERVICE REJECT (defined in procedure, tracking
EMM- 3GPP TS 24.301 [120]) received area updating
DEREGISTERE with a timer value for T3346; procedure or
D. "Extended wait time" for PS service request
ATTEMPTING- domain from the lower layers. procedure,
TO-ATTACH (defined in 3GPP TS 36.331 [22]) dependent on EMM
EMM- state and EPS
REGISTERED. update status.
ATTEMPTING- (defined in
TO-UPDATE 3GPP TS 24.301 [1
EMM- 20])
REGISTERED
(defined in
3GPP TS 24.30
1 [120])
NOTE 1: The value of this timer is used if the network does not indicate another value in a GMM signalling
procedure.
NOTE 2: The default value of this timer is used if neither the MS nor the Network send another value, or if the
Network sends this value, in a signalling procedure.
NOTE 3: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in
the corresponding procedure description.
NOTE 4: The purpose of this timer is to prevent the MS from repeating the SERVICE REQUEST message with
service type "data" too early in case the request to setup the radio access bearer is queued by the radio
access network.
NOTE 5: In Iu mode, the default value of this timer is used if the network provides a value for this timer in a non-
integrity protected Iu mode GMM message.
NOTE 6: The value of this timer may be provided by the network to the MS in the ATTACH ACCEPT message and
ROUTING AREA UPDATE ACCEPT message. The default value of this timer is identical to the value of
timer T3312.
NOTE 7: The timer value is provided by the network in an ATTACH REJECT, ROUTING AREA UPDATE
REJECT, TRACKING AREA UPDATE REJECT or SERVICE REJECT message or as a "Extended wait
time" value by the lower layers, or chosen randomly from a default value range of 15 – 30 minutes.
3GPP
Release 10 588 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 2: The default value of this timer is used if neither the MS nor the Network send another value, or if the
Network sends this value, in a signalling procedure. The value of this timer should be slightly shorter in
the network than in the MS, this is a network implementation issue.
NOTE 3: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in
the corresponding procedure description.
3GPP
Release 10 589 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 4: The default value of this timer is 4 minutes greater than T3312. If T3346 is larger than T3312 and the
SGSN includes timer T3346 in the ROUTING AREA UPDATE REJECT message or the SERVICE
REJECT message, the value of the Mobile Reachable timer is 4 minutes greater than T3346. If the MS is
attached for emergency bearer services, the value of this timer is set equal to T3312.
NOTE 5: The value of this timer is network dependent. If ISR is activated, the default value of this timer is 4
minutes greater than T3323.
3GPP
Release 10 590 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 591 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 592 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in
the corresponding procedure description.
NOTE: Typically, the procedures are aborted on the fifth expiry of the relevant timer. Exceptions are described in
the corresponding procedure description.
3GPP
Release 10 593 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: T310 is not started if progress indicator #1, #2, or #64 has been delivered in the CALL PROCEEDING
message or in a previous PROGRESS message.
3GPP
Release 10 594 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: The network may already have applied an internal alerting supervision function; e.g. incorporated within
call control. If such a function is known to be operating on the call, then timer T301 is not used.
NOTE 3: When applied to the supplementary service CCBS, the timer T334 can either represent the recall timer T4
or the notification timer T10 (see 3GPP TS 23.093 [88a]). Thus the timer T334 can take two different
values. 3GPP TS 23.093 [88a] defines the range of these values.
3GPP
Release 10 595 3GPP TS 24.008 V10.6.1 (2012-03)
Annex A (informative):
Example of subaddress information element coding
This annex gives an example of how the Called Party Subaddress IE is encoded to carry subaddress digits that use IA5
characters. This example is also applicable to the Calling Party Subaddress IE.
8 7 6 5 4 3 2 1 octet
0 1 1 0 1 1 0 1 1
called party subaddress IEI
0 0 0 0 0 1 1 1 2
Length
1 0 0 0 X 0 0 0 3
not NSAP odd/ev
ext (X.213/ISO 8348 AD2) note 1 note 2
0 1 0 1 0 0 0 0 4
AFI (note 3)
IA5 Character (note 4) 5
IA5 Character (note 4) 6
NOTE 1: The value of this bit has no significance when the type of subaddress is "NSAP".
NOTE 3: The Authority and Format Identifier code 50 (in BCD) indicates that the subaddress consists of IA5
characters (see ISO standard 8348 AD2).
NOTE 4: IA5 character as defined in ITU-T Recommendation T.50/ISO 646 and then encoded into two semi-octets
according to the "preferred binary encoding" defined in X.213/ISO 8348 AD2. (Each character is
converted into a number in the range 32 to 127 using the ISO 646 encoding with zero parity and the parity
bit in the most significant position. This number is then reduced by 32 to give a new number in the range
0 to 95. The new number is then treated as a pair of decimal digits with the value of each digit being
encoded in a semi-octet.)
NOTE 5: the number of IA5 characters in the subaddress may vary, subject to an upper limit of 19 IA5 characters.
3GPP
Release 10 596 3GPP TS 24.008 V10.6.1 (2012-03)
Annex B (normative):
Compatibility checking
B.1 Introduction
This annex describes the various compatibility checks which shall be carried out to ensure that the best matched MS and
network capabilities are achieved on a call between a PLMN and the ISDN.
NOTE: In this context and throughout this annex the term "called user" is the end point entity which is explicitly
addressed.
For details on the coding of the information required for compatibility checking, see annex C.
- if the SETUP message contained two bearer capability information elements for only one of which a mismatch is
detected, the network shall either:
- under the conditions specified in 3GPP TS 27.001 [36] (e.g. TS 61 and TS 62), accept the SETUP message
with a CALL PROCEEDING message containing the, possibly negotiated, bearer capability information
element for which no mismatch is detected, or
- otherwise the network shall reject the call using one of the causes listed in annex H.
Network services are described in 3GPP TS 22.002 [3] and 3GPP TS 22.003 [4] as bearer services and teleservices,
respectively.
3GPP
Release 10 597 3GPP TS 24.008 V10.6.1 (2012-03)
a) if the MS has a DDI number or a sub-address, then the information in any Called Party BCD Number or any
Called Party subaddress information elements of the incoming SETUP message shall be checked by the MS
against the corresponding part of the number assigned to the user (e.g. for DDI) or the user's own sub-address.
In the cases of a mismatch, the MS shall release the call. In the case of a match, the compatibility checking
described in B.3.2 and B.3.3 shall be performed.
b) if the MS has no DDI number and no sub-address, then the Called Party BCD Number and Called Party Sub-
address information element shall be ignored for the purposes of compatibility checking. The compatibility
checking described in B.3.2 and B.3.3 shall be performed.
NOTE: According to the user's requirements, compatibility checking can be performed in various ways from the
viewpoint of execution order and information to be checked, e.g. first DDI number/sub-address and then
bearer capability or vice versa.
- if the SETUP message contained two bearer capability information elements for only one of which a mismatch is
detected, the MS shall either:
- under the conditions specified in 3GPP TS 27.001 [36] (e.g. TS 61 and TS 62), accept the SETUP message
with a CALL CONFIRMED message containing the, possibly negotiated, bearer capability information
element for which no mismatch is detected, or
- otherwise the MS shall reject the offered call using a RELEASE COMPLETE message with cause No. 88
"incompatible destination".
When interworking with existing networks, limitations in network or distant user signalling (e.g. in the case of an
incoming call from a PSTN or a call from an analogue terminal) may restrict the information available to the called MS
in the incoming SETUP message (e.g. missing Bearer Capability Information Element or missing High Layer
Compatibility Information Element). For compatibility checking, and handling of such calls see 3GPP TS 27.001 [36].
3GPP
Release 10 598 3GPP TS 24.008 V10.6.1 (2012-03)
Annex C (normative):
Low layer information coding principles
C.1 Purpose
This annex describes principles that shall be used when the calling MS specifies information during call setup regarding
low layer capabilities required in the network and by the destination terminal. Refer also to 3GPP TS 27.001 [36].
NOTE: In this context and throughout this annex the term "called user" is the end point entity which is explicitly
addressed. This may also be an explicitly addressed interworking unit (IWU) (see ITU-T I.500-Series
Recommendations and ITU-T Recommendation X.31 case a).
C.2 Principles
a) type I information is information about the calling terminal which is only used at the destination end to allow a
decision regarding terminal compatibility. An example would be the user information layer 3 protocol. Type I
information is encoded in octets 5 to 7 of the low layer compatibility information element;
b) type II information is only used by the network (PLMN) to which the calling user is connected for selection of
PLMN specific network resources, e.g. channel type or specific functionality within the interworking function
(IWF, see 3GPP TS 23.093 [88a]). This type of information is always present. An example is the connection
element. Type II information is coded in:
i) octet 3 of the bearer capability information element when the information transfer capability required by the
calling user is speech ;
ii) octets 3, 4, 5, and optionally octet 7 of the bearer capability information element when the information
transfer capability required by the calling user is not speech;
c) type III information is required for selection of a basic service from the choice of basic services offered by the
network and together with type II information for selection of an appropriate interworking function (IWF, see
3GPP TS 29.007 [38]), as well as for terminal compatibility checking at the destination terminal. An example is
the information transfer capability. Type III information is always present and is encoded in:
i) octet 3 of the bearer capability information element when the information transfer capability required by the
calling user is speech ;
ii) octets 3, 5, 6, 6a, 6b and 6c of the bearer capability information element when the information transfer
capability required by the calling user is not speech;
NOTE: In the case of a mobile terminated call, if the type II and type III information is not sufficient for the
selection of an appropriate interworking function, the type I information will also examined by the
network.
3GPP
Release 10 599 3GPP TS 24.008 V10.6.1 (2012-03)
In any case a modification of the bearer capability information element has to be performed when interworking to the
fixed network (e.g. ISDN) is required, where the signalling of the radio interface has to be mapped to fixed network
signalling (e.g. mapping of GSM BCIE to ISDN BCIE, see 3GPP TS 29.007 [38]).
NOTE: If as a result of duplication, a contradiction occurs at the terminating side between the bearer capability
information element and the low layer compatibility information element at the terminating side, the
receiving entity shall ignore the conflicting information in the low layer compatibility information
element.
3GPP
Release 10 600 3GPP TS 24.008 V10.6.1 (2012-03)
Annex D (informative):
Examples of bearer capability information element coding
This annex gives examples of the coding of bearer capability information elements for various telecommunication
services. This annex is included for information purposes only. In the case of any inconsistency between this annex and
3GPP TS 27.001 [36], then 3GPP TS 27.001 [36] shall take precedence over this annex.
D.1 Coding for speech for a full rate support only mobile
station
8 7 6 5 4 3 2 1
0 0 0 0 0 1 0 0 octet 1
Bearer capability IEI
0 0 0 0 0 0 0 1
Length of the bearer capability contents octet 2
1 0 1 0 0 0 0 0
not full rate GSM circ. speech octet 3
ext only mode
8 7 6 5 4 3 2 1
0 0 0 0 0 1 0 0 octet 1
Bearer capability IEI
0 0 0 0 0 0 0 1
Length of the bearer capability contents octet 2
1 0 1 0 0 0 0 0
not spare spare GSM circ. speech octet 3
ext mode
3GPP
Release 10 601 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
0 0 0 0 0 1 0 0 octet 1
Bearer capability IEI
0 0 0 0 0 1 1 1
Length of the bearer capability contents octet 2
1 1 0 0 0 0 1 0
not dual, half GSM circ. 3.1 kHz audio octet 3
ext preferred mode ex PLMN
1 1 0 0 1 0 0 0
not comp- SDU full pt to pt no de- octet 4
ext ress. integrity dupl. NIRR mand
1 0 0 0 0 0 0 1
not access id. no rate I.440/450 octet 5
ext adaption
0 0 1 0 0 0 0 1
ext layer 1 default layer 1 async octet 6
0 0 0 1 0 0 1 1
ext 1 bit no neg 2.4 kbit/s octet 6a
8 bits
0 1 1 0 0 0 1 1
ext 16 kbit/s no no (parity) none octet 6b
inter. rate NICtx NICrx
1 0 1 0 0 0 1 1
not non trans V.22 bis octet 6c
ext RLP)
3GPP
Release 10 602 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
0 0 0 0 0 1 0 0 octet 1
Bearer capability IEI
0 0 0 0 0 1 1 1
Length of the bearer capability contents octet 2
1 0 1 0 0 0 1 0
not spare spare GSM circ. 3.1 kHz audio octet 3
ext mode ex PLMN
1 1 0 0 1 0 0 0
not comp- SDU full pt to pt no de- octet 4
ext ress. integrity dupl. NIRR mand
1 0 0 0 0 0 0 1
not access id. no rate I.440/450 octet 5
ext adaption
0 0 1 0 0 0 0 1
ext layer 1 default layer 1 async octet 6
0 0 0 1 0 0 1 1
ext 1 bit no 8 bits 2.4 kbit/s octet 6a
neg
0 1 1 0 0 0 1 1
ext 16 kbit/s no no (parity) none octet 6b
inter. rate NICtx NICrx
1 0 1 0 0 0 1 1
not non trans V.22 bis octet 6c
ext (RLP)
3GPP
Release 10 603 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
0 0 0 0 0 1 0 0 octet 1
Bearer capability IEI
0 0 0 0 0 1 1 1
Length of the bearer capability contents octet 2
1 0 1 0 0 0 1 1
not full rate GSM circ. facsimile octet 3
ext only MS mode group 3
1 0 1 1 1 0 0 0
not comp- unstructured full pt to no de- octet 4
ext ress. dupl. pt NIRR mand
1 0 0 0 0 0 0 1
not access id. no rate I.440/450 octet 5
ext adaption
0 0 1 0 0 0 0 0
ext layer 1 default layer 1 sync octet 6
0 0 0 1 0 1 0 1
ext (syn) no (syn) 9.6 kbit/s octet 6a
neg
0 1 1 0 0 0 1 1
ext 16 kbit/s no no (parity) none octet 6b
inter. rate NICtx NICrx
1 0 0 0 0 0 1 1
not transparent none octet 6c
ext (modem type)
3GPP
Release 10 604 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
0 0 0 0 0 1 0 0 octet 1
Bearer capability IEI
0 0 0 0 0 1 1 1
Length of the bearer capability contents octet 2
1 0 1 0 0 0 1 1
not spare spare GSM circ. facsimile octet 3
ext mode group 3
1 0 1 1 1 0 0 0
not comp- unstructured full pt to no de- octet 4
ext ress. dupl. pt NIRR mand
1 0 0 0 0 0 0 1
not access id. no rate I.440/450 octet 5
ext adaption
0 0 1 0 0 0 0 0
ext layer 1 default layer 1 sync octet 6
0 0 0 1 0 1 0 1
ext (syn) no (syn) 9.6 kbit/s octet 6a
neg
0 1 1 0 0 0 1 1
ext 16 kbit/s no no (parity) none octet 6b
inter. rate NICtx NICrx
1 0 0 0 0 0 0 0
not transparent none octet 6c
ext (modem type)
3GPP
Release 10 605 3GPP TS 24.008 V10.6.1 (2012-03)
Annex E (informative):
Comparison between call control procedures specified in
3GPP TS 24.008 and ITU-T Recommendation Q.931
This annex summarizes a comparison of the procedures for call control as specified in ITU-T Recommendation Q.931
(blue book) and 3GPP TS 24.008.
If no comment is given, it means that the procedures specified in ITU-T Recommendation Q.931 and 3GPP TS 24.008
are similar. However, it should be noted that even in such cases the procedures may be described in slightly different
ways in the two documents.
3GPP
Release 10 606 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 607 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 608 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 609 3GPP TS 24.008 V10.6.1 (2012-03)
Annex F (informative):
A/Gb mode specific cause values for radio resource
management
See 3GPP TS 44.018 [84].
3GPP
Release 10 610 3GPP TS 24.008 V10.6.1 (2012-03)
Annex G (informative):
3GPP specific cause values for mobility management
This annex describes the cause values for the mobility management procedures for non-GPRS services (MM) and
GPRS services (GMM). Clauses G1 to G5 are valid for both MM and GMM. However, the following codes are
applicable for non-GPRS services only:
This cause is sent to the MS if the MS is not known (registered) in the HLR. This cause code does not affect
operation of the GPRS service, although is may be used by a GMM procedure.
This cause is sent to the MS when the network refuses service to the MS either because an identity of the MS is
not acceptable to the network or because the MS does not pass the authentication check, i.e. the SRES received
from the MS is different from that generated by the network. When used by an MM procedure, except the
authentication procedure, this cause does not affect operation of the GPRS service.
This cause is sent to the MS when the given IMSI is not known at the VLR.
This cause is sent to the MS if the network does not accept emergency call establishment using an IMEI or not
accept attach procedure for emergency services using an IMEI.
This cause is sent to the MS if the ME used is not acceptable to the network, e.g. blacklisted. When used by an
MM procedure, this cause does not affect operation of the GPRS service.
This cause is sent to the MS if it requests location updating in a PLMN where the MS, by subscription or due to
operator determined barring is not allowed to operate.
This cause is sent to the MS if it requests location updating in a location area where the HPLMN determines that
the MS, by subscription, is not allowed to operate.
NOTE: If cause #12 is sent to a roaming subscriber the subscriber is denied service even if other PLMNs are
available on which registration was possible.
This cause is sent to an MS which requests location updating in a location area of a PLMN which by
subscription offers roaming to that MS but not in that Location Area.
3GPP
Release 10 611 3GPP TS 24.008 V10.6.1 (2012-03)
This cause is sent to the MS if it requests location updating in a location area where the MS, by subscription, is
not allowed to operate, but when it should find another allowed location area in the same PLMN.
NOTE: Cause #15 and cause #12 differ in the fact that cause #12 does not trigger the MS to search for another
allowed location area on the same PLMN.
This cause is sent to the MS if it requests access in a CSG cell where the MS either has no subscription to
operate or the MS's subscription has expired and it should find another cell in the same PLMN.
NOTE: The MS not supporting CSG will not receive cause# 25, as such a MS is not supposed to try to access a
CSG cell.
This cause is sent to the network if the USIM detects that the MAC in the AUTHENTICATION REQUEST or
AUTHENTICATION_AND_CIPHERING REQUEST message is not fresh (see 3GPP TS 33.102 [5a]).
This cause is sent to the network if the USIM detects that the SQN in the AUTHENTICATION REQUEST or
AUTHENTICATION_AND_CIPHERING REQUEST message is out of range (see 3GPP TS 33.102 [5a]).
This cause is sent to the MS if the MSC cannot service an MS generated request because of PLMN failures, e.g.
problems in MAP.
This cause is sent if the service request or LOCATION UPDATING REQUEST message cannot be actioned
because of congestion (e.g. congestion of the MSC or SGSN or GGSN or PDN Gateway; no channel; facility
busy/congested etc.).
This cause is sent to the network in Iu mode if a USIM is inserted in the MS and there is no Authentication
Parameter AUTN IE present in the AUTHENTICATION REQUEST or
AUTHENTICATION_AND_CIPHERING REQUEST message.
This cause is sent when the MS requests a service/facility in the CM SERVICE REQUEST message which is not
supported by the PLMN.
This cause is sent when the MS requests a service option for which it has no subscription.
This cause is sent when the MSC cannot service the request because of temporary outage of one or more
functions required for supporting the service.
3GPP
Release 10 612 3GPP TS 24.008 V10.6.1 (2012-03)
This cause is sent when the network cannot identify the call associated with a call re-establishment request.
This cause is sent to the MS when it is not allowed to operate GPRS services.
This cause is sent to the MS when it is not allowed to operate either GPRS or non-GPRS services.
This cause is sent to the MS when the network cannot derive the MS's identity from the P-TMSI in case of inter-
SGSN routing area update.
This cause is sent to the MS either if the network has implicitly detached the MS, e.g. some while after the
Mobile reachable timer has expired, or if the GMM context data related to the subscription dose not exist in the
SGSN e.g. because of a SGSN restart.
This cause is sent to the MS which requests GPRS service in a PLMN which does not offer roaming for GPRS
services to that MS.
3GPP
Release 10 613 3GPP TS 24.008 V10.6.1 (2012-03)
This cause is sent to the MS if it requests a combined GPRS attach or routing are updating in a PLMN where the
MSC is temporarily not reachable via the GPRS part of the network.
This cause is sent to the MS if the MS requests an establishment of the radio access bearers for all active PDP
contexts by sending a SERVICE REQUEST message indicating "data" to the network, but the SGSN does not
have any active PDP context(s).
3GPP
Release 10 614 3GPP TS 24.008 V10.6.1 (2012-03)
Annex H (informative):
3GPP specific cause values for call control
Under normal situations, the source of this cause is not the network.
3GPP
Release 10 615 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 616 3GPP TS 24.008 V10.6.1 (2012-03)
It is noted that the particular type of access information discarded is optionally included in the diagnostic.
3GPP
Release 10 617 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 618 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 619 3GPP TS 24.008 V10.6.1 (2012-03)
H.6.6 Cause No. 101 "message not compatible with protocol state"
This cause indicates that a message has been received which is incompatible with the protocol state or that a
STATUS message has been received indicating an incompatible call state.
3GPP
Release 10 620 3GPP TS 24.008 V10.6.1 (2012-03)
Annex I (informative):
GPRS specific cause values for GPRS Session
Management
This cause code is used by the network to indicate that the requested service was rejected by the SGSN due to
Operator Determined Barring.
This cause code is used by the network to indicate that an MBMS context activation request was rejected by the
network, because the MBMS bearer capabilities are insufficient for the MBMS service.
This cause code is used by the network to indicate that the requested service was rejected by the external packet
data network because the access point name was not included although required or if the access point name
could not be resolved.
This cause code is used by the network to indicate that the requested service was rejected by the external packet
data network because the PDP address or type could not be recognised.
This cause code is used by the network to indicate that the requested service was rejected by the external packet
data network due to a failed user authentication.
This cause code is used by the network to indicate that the requested service was rejected by the GGSN, Serving
GW or PDN GW.
This cause code is used by the network or by the MS to indicate that the requested service was rejected due to
unspecified reasons.
This cause code is used by the network when the MS requests a service which is not supported by the PLMN.
3GPP
Release 10 621 3GPP TS 24.008 V10.6.1 (2012-03)
This cause code may be used by a network to indicate that the NSAPI requested by the MS in the PDP context
activation request is already used by another active PDP context of this MS.
Never to be sent, but can be received from a R97/R98 network at PDP context activation
This cause code is used to indicate a regular MS or network initiated PDP context deactivation or a regular
network initiated MBMS context deactivation.
This cause code is used by the MS if the new QoS cannot be accepted that were indicated by the network in the
PDP Context Modification procedure.
This cause code is used by the network to indicate that the PDP context deactivation or the MBMS context
deactivation is caused by an error situation in the network.
This cause code is used by the network to request a PDP context reactivation (e.g. after a GGSN restart or after
selection of a different GGSN by the network for Selected IP Traffic Offload).
This cause code is used by the MS to indicate that the PDP context activation or the MBMS context activation
initiated by the network is not supported by the MS.
This cause code is used by the network or the MS to indicate that there is a semantic error in the TFT operation
included in a secondary PDP context activation request or an MS-initiated PDP context modification or a
network requested secondary PDP context activation.
This cause code is used by the network or the MS to indicate that there is a syntactical error in the TFT operation
included in a secondary PDP context activation request or an MS-initiated PDP context modification or a
network requested secondary PDP context activation.
This cause code is used by the network or the MS to indicate that the PDP context identified by the Linked TI IE
in the secondary PDP context activation request or a network requested secondary PDP context activation is not
active.
This cause code is used by the network or the MS to indicate that there is one or more semantic errors in packet
filter(s) of the TFT included in a secondary PDP context activation request or an MS-initiated PDP context
modification or a network requested secondary PDP context activation.
This cause code is used by the network or the MS to indicate that there is one or more syntactical errors in packet
filter(s) of the TFT included in a secondary PDP context activation request or an MS-initiated PDP context
modification or a network requested secondary PDP context activation.
3GPP
Release 10 622 3GPP TS 24.008 V10.6.1 (2012-03)
This cause code is used by the network or the MS to indicate that it has already activated a PDP context without
TFT.
This cause code is used by the network to indicate that the MBMS context is deactivated because the timer
supervising the IGMP group membership interval (see RFC 3376 [107], subclause 8.4) or the MLD multicast
listener interval (see RFC 2710 [108], subclause 7.4) expired.
This cause code is used by the network or the MS to indicate that the requested service was rejected because of
Bearer Control Mode violation.
This cause is used by the network to indicate that the requested PDN connectivity is accepted with the restriction
that only PDP type IPv4 is allowed.
This cause is used by the network to indicate that the requested PDN connectivity is accepted with the restriction
that only PDP type IPv6 is allowed.
This cause is used by the network to indicate that the requested PDN connectivity is accepted with the restriction
that only single IP version bearers are allowed.
This cause code is used by the network to indicate that the MS-initiated request was rejected since the network
has requested a secondary PDP context activation for the same service using a network-initiated procedure.
This cause code is used by the network to indicate that the procedure requested by the MS was rejected because
the bearer handling is not supported.
Cause value = 112 APN restriction value incompatible with active PDP context.
This cause code is used by the network to indicate that the PDP context(s) or MBMS context(s) have an APN
restriction value that is not allowed in combination with a currently active PDP context. Restriction values are
defined in 3GPP TS 23.060 [74], subclause 15.4.
3GPP
Release 10 623 3GPP TS 24.008 V10.6.1 (2012-03)
I.3 Void
3GPP
Release 10 624 3GPP TS 24.008 V10.6.1 (2012-03)
Annex J (informative):
Algorithm to encode frequency list information elements
See 3GPP TS 44.018 [84].
3GPP
Release 10 625 3GPP TS 24.008 V10.6.1 (2012-03)
Annex K (informative):
Default Codings of Information Elements
The information in this annex does NOT define the value of any IEI for any particular message. This annex exists to aid
the design of new messages, in particular with regard to backward compatibility with phase 1 mobile stations.
Reference
clause
8 7 6 5 4 3 2 1
1 1 1 1 - - - - Note 1
0 0 0 1 0 0 0 1 Note 1
0 0 0 1 0 0 1 1 Location Area Identification 10.5.1.3
0 0 0 1 0 1 1 1 Mobile Identity 10.5.1.4
0 0 0 1 1 0 0 0 Note 1
0 0 0 1 1 1 1 1 Note 1
0 0 1 0 0 0 0 0 Mobile Station classmark 3 10.5.1.7
NOTE 1: These values were allocated but never used in earlier phases of the protocol.
NOTE 2: For GPRS common information elements no default values are defined:
3GPP
Release 10 626 3GPP TS 24.008 V10.6.1 (2012-03)
Table K.3/3GPP TS 24.008: Default information element identifier coding for mobility management
information elements
Reference
clause
8 7 6 5 4 3 2 1
NOTE: These values were allocated but never used in earlier versions of the protocol
3GPP
Release 10 627 3GPP TS 24.008 V10.6.1 (2012-03)
Table K.4/3GPP TS 24.008: Default information element identifier coding for call control information
elements
Reference
clause
8 7 6 5 4 3 2 1
1 : : : - - - - Type 1 info elements
0 0 1 - - - - shift 10.5.4.2 and
.3
0 1 1 - - - - Note
1 0 1 - - - - Repeat indicator 10.5.4.22
NOTE: These values were allocated but never used in earlier phases of the protocol.
3GPP
Release 10 628 3GPP TS 24.008 V10.6.1 (2012-03)
Annex L (normative):
Establishment cause (Iu mode only)
When GMM requests the establishment of a PS signalling connection, the RRC establishment cause used by the MS
shall be selected according to the PS NAS procedure as specified in Table L.1.2.
3GPP
Release 10 629 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 630 3GPP TS 24.008 V10.6.1 (2012-03)
If the ATTACH REQUEST has Attach type set to "Emergency attach" or if the
ATTACH REQUEST has Attach type not set to "Emergency attach" but the MS
initiates the attach procedure on receiving request from upper layer to establish
emergency bearer services, the RRC establishment cause shall be set to
Emergency call. (See Note 2)
Routing Area Update – for the case If the MS does not have a PDN connection established for emergency bearer
of ‘Directed Signalling Connection services, the RRC establishment cause shall be set to Call Re-Establishment.
Re-Establishment (see chapter
4.7.2.5.) If the MS has a PDN connection established for emergency bearer services, the
RRC establishment cause shall be set to Emergency call. (See Note 2)
Routing area Update – all cases If the MS does not have a PDN connection established for emergency bearer
other than ‘Directed Signalling services, the RRC establishment cause shall be set to Registration.
Connection Re-Establishment
If the MS has a PDN connection established for emergency bearer services, the
RRC establishment cause shall be set to Emergency call. (See Note 2)
If the request is to re-establish RABs for emergency bearer services, the RRC
establishment cause shall be set to Emergency call. (See Note 2)
If the ACTIVATE PDP CONTEXT REQUEST has the Request Type set to
"emergency", the RRC establishment cause shall be set to Emergency call. (See
Note 2)
If the MS has a PDN connection established for emergency bearer services, the
RRC establishment cause shall be set to Emergency call. (See Note 2)
3GPP
Release 10 631 3GPP TS 24.008 V10.6.1 (2012-03)
NOTE 1: For classification of "most demanding" Traffic Class the following ranking order applies: "Conversational"
followed by "Streaming" followed by "Interactive" followed by "Background", where "Conversational" is the most
demanding Traffic class in terms of being delay sensitive.
In choosing the "most demanding" Traffic Class all already active PDP Context together with the PDP Context
to be activated shall be considered
NOTE 2: The emergency bearer services are only supported in UTRAN Iu mode.
NOTE: The RRC establishment cause may be used by the network to prioritise the connection establishment
request from the MS at high load situations in the network.
3GPP
Release 10 632 3GPP TS 24.008 V10.6.1 (2012-03)
Annex M (normative):
Additional Requirements for backward compatibility with
PCS 1900 for NA revision 0 ME
This annex provides additional requirements to support network mechanisms for backward compatibility with PCS
1900 for NA revision 0 mobile equipments (applicable until July 1, 1998).
PCS 1900 for NA revision 0 mobile equipments are defined to understand Mobile Network Codes made of up to 2
digits. However federal regulation mandates that a 3-digit MNC shall be allocated by each administration to network
operators. Therefore each network operator is identified by a 3-digit Mobile Country Code and a 3-digit Mobile
Network Code. An operator whose network code complies to the allocation principle specified for PCS 1900 for NA
and wants to achieve for a transition period of time the backward compatibility with PCS 1900 for NA revision 0
mobile equipments shall apply the following:
- The network shall send over the air interface the 3-digit Mobile Country Code and only the two most significant
digits of the Mobile Network Code (the value of the "digit" sent instead of the 3rd digit is specified in 3GPP TS
24.008, subclause 10.5.1.3) (see note).
When a PCS 1900 for NA (revision greater than 0) mobile equipment recognizes over the air the Mobile Country Code
and the two most significant digits of the Mobile Network Code as being the HPLMN codes of the current IMSI, the
mobile equipment shall take into account the value of the sixth IMSI digit read from the SIM/USIM. If this value
matches to a value contained in the limited set of values for the least significant MNC digit assigned by the number
administration bodies for PCS 1900 for NA then the following applies for the mobile equipment:
- The value sent over the air instead of the 3rd MNC digit in the Location Area Identification (for coding see 3GPP
TS 24.008, subclause 10.5.1.3) shall be interpreted as the value of the sixth IMSI digit read from the SIM/USIM.
NOTE: It is still a network operator option to apply this requirement after July 1, 1998. However, in this case the
following shall be considered:
- Networks overlapping to the HPLMN, identified over the radio interface by an identical combination
MCC1 MCC2 MCC3 MNC1 MNC2 (possible after July 1, 1998) may be selectable by PCS 1900 for
NA mobile equipments revision 0 with the same priority as the HPLMN or presented to the user as the
HPLMN.
2 Roaming considerations:
- Roamers (SIM/USIM) from networks identified by an identical combination MCC1 MCC2 MCC3
MNC1 MNC2 (possible after July 1, 1998) when roaming into the operator network with PCS 1900
for NA mobile equipments revision 0, may cause these equipments to exhibit an unpredictable
behaviour (e.g. looping in the HPLMN selection and registration procedures).
- Home subscribers (SIM/USIM) roaming with PCS 1900 for NA mobile equipments revision 0 into
networks identified by an identical combination MCC1 MCC2 MCC3 MNC1 MNC2 (possible after
July 1, 1998), may consider being attached to the HPLMN.
Annex N (normative):
Ranking of reject causes for Location Registration (MM and
GMM) in a shared network
This annex describes how the reject cause is determined:
- for a Network Sharing non-supporting MS in a shared network with multi-operator core network (MOCN)
configuration; or
3GPP
Release 10 633 3GPP TS 24.008 V10.6.1 (2012-03)
when a location registration request from the MS is redirected among CN operators via the shared RAN (see 3GPP TS
23.251 [109]) and is rejected by all core networks. In the following, the term 'location registration' is used for location
area updating, GPRS attach, combined GPRS attach, routing area updating, and combined routing area updating.
i) If the location registration request was accepted, or if the location registration request was rejected with a reject
cause different from #11, #12, #13, #14, and #15:
- in UTRAN Iu mode, the MSC or SGSN shall not include a redirection indication in the RANAP DIRECT
TRANSFER message transmitting the location registration accept message or location registration reject
message to the RNC. According to 3GPP TS 25.413 [19c], the RNC will then forward the location
registration accept message or the location registration reject message to the MS.
- in A/Gb mode, the MSC shall use DTAP message and SGSN shall use BSSGP DL-UNIDATA message to
carry the location registration accept message or location registration reject message to the BSC. According
to 3GPP TS 48.008 [85] and 3GPP TS 48.018 [86], the BSC will then forward the location registration accept
message or location registration reject message to the MS.
ii) If the location registration request was rejected with one of the reject causes #11, #12, #13, #14, and #15:
- in UTRAN Iu mode, the MSC or SGSN shall include a redirection indication in the RANAP DIRECT
TRANSFER message transmitting the location registration reject message to the RNC. According to 3GPP
TS 25.413 [19c], the RNC will then initiate the redirection procedure towards the next CN operator and treat
the response from the core network according to (i) and (ii).
- in A/Gb mode, the MSC shall use BSSMAP Reroute Command message and SGSN shall use BSSGP DL-
UNIDATA message to transmit the location registration reject message to the BSC with a redirection
indication. According to 3GPP TS 48.008 [85] and 3GPP TS 48.018 [86], the BSC will then initiate the
redirection procedure towards the next CN operator and treat the response from the core network according
to (i), (ii) and (iii).
iii) If the location registration request was rejected with one of the reject causes #11, #12, #13, #14, and #15 by all
CN operators taking part in the network sharing, the RNC for UTRAN Iu mode or the BSC for A/Gb mode shall
determine the reject cause with the highest rank from the received reject causes and send a location registration
reject message containing this reject cause to the MS.
The ranking of the reject causes, from the lowest rank to the highest rank, is given by:
iv) If the location registration request was rejected with one of the reject causes #11, #12, #13, #14, and #15 by all
CN operators taking part in the network sharing in a specific location area, but there is at least one additional CN
operator taking part in the network sharing in another location area of the shared network defined by the same
common PLMN identity, the RNC for UTRAN Iu mode or the BSC for A/Gb mode shall send a location
registration reject message with the reject cause #15 to the MS.
Annex O (normative):
3GPP capability exchange protocol
O.1 Scope
This annex specifies the protocol data units used by the 3GPP capability exchange protocol and procedures for the
handling of unknown, unforeseen, and erroneous protocol data by the receiving MS.
3GPP
Release 10 634 3GPP TS 24.008 V10.6.1 (2012-03)
The 3GPP capability exchange protocol provides services for the end-to-end exchange of capabilities between MSs. It is
a separate protocol which uses the user-to-user signalling service 1 of the layer 3 call control protocol as a means of
transport.
Functional procedures which use the 3GPP capability exchange protocol in the context of CSI are specified in
3GPP TS 24.279 [116].
The user-user protocol contents is structured like the non-imperative part of a standard L3 message (see
3GPP TS 24.007 [20], subclause 11.2) and is composed of a variable number of information elements of type 1, 2, 3 and
4. The different formats (TV, TLV) and the categories of information elements (type 1, 2, 3 and 4) are defined in
3GPP TS 24.007 [20].
Within the user-user protocol contents the information elements may occur in an arbitrary order.
8 7 6 5 4 3 2 1
Information element 1 octet 4*
octet 5*
octet k*
Information element 2 octet k+1*
octet l*
… octet l+1*
octet m*
Information element K octet m+1*
octet n*
Figure O.1/3GPP TS 24.008 User-user information when the user-user protocol indicator is set to
"3GPP capability exchange protocol"
For the information elements defined in subclause O.4, the coding of the information element identifier bits is defined
in table O.2/3GPP TS 24.008.
For a method to determine from the information element identifier whether an unknown information element is of type
1 or 2 (i.e. it is an information element of one octet length) or type 4 (i.e. the next octet is the length indicator indicating
the length of the remaining of the information element) see 3GPP TS 24.007 [20], subclause 11.2.4.
3GPP
Release 10 635 3GPP TS 24.008 V10.6.1 (2012-03)
Table O.1/3GPP TS 24.008: Information element identifier coding for user-user protocol information
elements
Reference
clause
8 7 6 5 4 3 2 1
NOTE: As the personal ME identifier is generated randomly, it is not guaranteed that it uniquely identifies a
specific ME used by the same user.
The personal ME identifier has the form PMI-XXXX, where XXXX is a 4-digit hexadecimal number. Only the
hexadecimal number XXXX is coded in the personal ME identifier information element.
The personal ME identifier information element is coded as shown in figure O.2/3GPP TS 24.008 and table O.2/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
3GPP
Release 10 636 3GPP TS 24.008 V10.6.1 (2012-03)
The radio environment capability information element is coded as shown in figure O.3/3GPP TS 24.008 and
table O.3/3GPP TS 24.008.
The radio environment capability is a type 1 information element with 1 octet length.
8 7 6 5 4 3 2 1
3GPP
Release 10 637 3GPP TS 24.008 V10.6.1 (2012-03)
The UE capability version information element is coded as shown in figure O.4/3GPP TS 24.008 and table O.4/3GPP
TS 24.008.
The UE capability version has the form UCV-XX, where XX is a 2-digit hexadecimal number. Only the hexadecimal
number XX is coded in the UE capability version information element.
The UE capability version information element is coded as shown in figure O.4/3GPP TS 24.008 and table O.4/3GPP
TS 24.008.
8 7 6 5 4 3 2 1
O.4.4 IM Status
The purpose of the IM Status is to provide information about the IMS capability and registration state of a specific
public user identity and it MS.
NOTE: The definition of what is a public user identity can be found in 3GPP TS 23.003 [10].
The IM Status information element is coded as shown in figure O.5/3GPP TS 24.008 and table O.5/3GPP TS 24.008.
3GPP
Release 10 638 3GPP TS 24.008 V10.6.1 (2012-03)
8 7 6 5 4 3 2 1
IM Status IEI 0 0 IM
Spare spare Status octet 1
IM Status (octet 1)
Bits
2 1
0 0 MS is not IM subsystem capable
0 1 MS is IM subsystem registered
1 0 MS is IM subsystem capable and willing to register to IM subsystem (NOTE 1)
1 1 MS is IM subsystem capable but will not register to IM subsystem (NOTE 2)
NOTE 1: This value indicates that a terminal can be configured to allow IMS registration
without user intervention when required, for example when prompted by receiving
an IM Status of "MS is IM subsystem registered" or “MS is IM subsystem capable
and willing to register to IM subsystem” during establishment of a CS call.
NOTE 2: This value indicates that the terminal will not IMS register without user permission.
O.5.1 General
The following subclauses specifies procedures for the handling of unknown, unforeseen, and erroneous protocol data by
the receiving MS. These procedures are called "error handling procedures", but in addition to providing recovery
mechanisms for error situations they define a compatibility mechanism for future extensions of the protocols.
For the definition of semantical and syntactical errors see 3GPP TS 24.007 [20], subclause 11.4.2.
Where the description of information elements in the present document contains bits defined to be "spare bits", these
bits shall set to the indicated value (usually 0) by the sending side, and their value shall be ignored by the receiving side.
3GPP
Release 10 639 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 640 3GPP TS 24.008 V10.6.1 (2012-03)
Annex P (normative):
Mobility management for IMS voice termination
P.1 Introduction
The present annex specifies additional requirements for GMM and EMM in the MS for the support of terminating
access domain selection for voice calls or voice sessions by the network.
Support of these mobility management procedures can be configured in the MS. Whether the "Mobility Management
for IMS Voice Termination" setting is stored in the IMS management object as defined in 3GPP TS 24.167 [134] or in
the MS is an implementation option. If this setting is missing, then "Mobility Management for IMS Voice Termination"
is disabled.
1) the MS's availability for voice calls in the IMS (see 3GPP TS 24.301 [120], subclause 3.1) changes from "not
available" to "available";
2) the MS is configured with "Mobility Management for IMS Voice Termination" enabled as defined in
3GPP TS 24.167 [134];
3) the IMS voice over PS session indicator received for Iu mode has the value
- "IMS voice over PS session supported in Iu mode, but not supported in A/Gb mode", or
the IMS voice over PS session indicator received for S1 mode has the value
4) at least one of the two parameters voice domain preference for UTRAN and voice domain preference for
E-UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only".
The MS deactivates mobility management for IMS voice termination when the MS's availability for voice calls in the
IMS (see 3GPP TS 24.301 [120], subclause 3.1) changes from "available" to "not available".
1) the upper layers have indicated that the MS is available for voice calls in the IMS (see 3GPP TS 24.301 [120],
subclause 3.1);
2) the MS is configured with "Mobility Management for IMS Voice Termination" enabled as defined in
3GPP TS 24.167 [134];
3) the "IMS voice over PS session indicator" received for Iu mode has the value "IMS voice over PS session
supported in Iu mode, but not supported in A/Gb mode"; and
4) the voice domain preference for UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only".
3GPP
Release 10 641 3GPP TS 24.008 V10.6.1 (2012-03)
2) the "IMS voice over PS session indicator" received for S1 mode has the value "IMS voice over PS session in
S1 mode supported"; and
3) the voice domain preference for E-UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only".
a) the IMS voice over PS session indicators received for Iu mode and S1 mode have the values
- "IMS voice over PS session supported in Iu mode, but not supported in A/Gb mode" and
the voice domain preference for UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only";
b) the IMS voice over PS session indicators received for Iu mode and S1 mode have the values
- "IMS voice over PS session in Iu mode and A/G mode not supported" and
the voice domain preference for E-UTRAN as defined in 3GPP TS 24.167 [134] is not "CS voice only"; or
c) the IMS voice over PS session indicators received for Iu mode and S1 mode have the values
- "IMS voice over PS session supported in Iu mode, but not supported in A/Gb mode" and
exactly one of the voice domain preferences for UTRAN and E-UTRAN as defined in 3GPP TS 24.167 [134]
is "CS voice only".
3GPP
Release 10 642 3GPP TS 24.008 V10.6.1 (2012-03)
Annex Q (informative):
Change History
Release 4 for 3GPP TS 24.008 v4.0.0 is based on 3GPP TS 24.008 version 3.5.0.
3GPP
Release 10 643 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 644 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 645 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 646 3GPP TS 24.008 V10.6.1 (2012-03)
12-2004 NP-26 NP-040504 908 2 NSAPI at MBMS context activation 6.6.0 6.7.0
12-2004 NP-26 NP-040510 922 Addition of DTM enhancements capability 6.6.0 6.7.0
12-2004 NP-26 NP-040513 Location registration in a shared network when multiple PLMNs 6.6.0 6.7.0
926 2 are broadcast
12-2004 NP-26 NP-040513 927 1 Reject cause ranking during rerouting in MOCN 6.6.0 6.7.0
12-2004 NP-26 NP-040514 910 2 Correction of terminology -GSM and UMTS 6.6.0 6.7.0
12-2004 NP-26 NP-040514 911 1 Paging for GPRS Services in GSM 6.6.0 6.7.0
12-2004 NP-26 NP-040514 913 1 Service request - Abnormal cases in the MS 6.6.0 6.7.0
12-2004 NP-26 NP-040514 920 1 Correction of the description of causes #7 and #8 in Annex G.6 6.6.0 6.7.0
12-2004 NP-26 NP-040514 923 Handling of zero T3312 timer value 6.6.0 6.7.0
12-2004 NP-26 NP-040514 924 Introduction of new references for DTMF 6.6.0 6.7.0
03-2005 NP-27 933 2 Defining TMGI and MBMS Session Id in the mobile identity field
NP-050070 6.7.0 6.8.0
03-2005 NP-27 934 1 Correct GPRS SM List and MBMS IE Descriptions
NP-050070 6.7.0 6.8.0
03-2005 NP-27 Mapping of ‘MBMS notification response’ to RRC establishment
958 cause
NP-050070 6.7.0 6.8.0
03-2005 NP-27 931 1 Synchronization of MBMS context status between UE and SGSN
NP-050071 6.7.0 6.8.0
03-2005 NP-27 954 1 MBMS Session Management clarifications
NP-050071 6.7.0 6.8.0
03-2005 NP-27 956 1 Introduction of MBMS in clause 8
NP-050071 6.7.0 6.8.0
03-2005 NP-27 952 1 Detach for PS and CS during a ongoing CS connection
NP-050076 6.7.0 6.8.0
03-2005 NP-27 951 1 GPRS attach type while in DTM
NP-050076 6.7.0 6.8.0
03-2005 NP-27 953 1 Condition for Combined RAU after a DTM connection
NP-050076 6.7.0 6.8.0
03-2005 NP-27 935 1 Missing Messages in MM and CC Summary Tables
NP-050076 6.7.0 6.8.0
03-2005 NP-27 932 Correction of the heading of subclause 4.7.3.1.6, bullet d.1
NP-050076 6.7.0 6.8.0
03-2005 NP-27 Modification of MS Behaviour under GPRS Attach with Reject
957 2 Cause #14
NP-050077 6.7.0 6.8.0
3GPP
Release 10 647 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 648 3GPP TS 24.008 V10.6.1 (2012-03)
3GPP
Release 10 649 3GPP TS 24.008 V10.6.1 (2012-03)
12-2007 CP-38 CP-070815 1152 1 Correction of misleading comments in the MS Classmark 3 and 7.10.0 8.0.0
MS Radio Access Capability
03-2008 CP-39 CP-080034 1168 TMGI misalignment between figure and table text 8.0.0 8.1.0
03-2008 CP-39 CP-080136 1165 Handling of NAS-layer cause value when in GAN 8.0.0 8.1.0
06-2008 CP-40 CP-080339 1177 Correction of description of security handling during inter-system 8.1.0 8.2.0
handover
06-2008 CP-40 CP-080347 1174 1 Correction of handling unkown or unforseen transaction identifier 8.1.0 8.2.0
in session management
06-2008 CP-40 CP-080347 1191 Downlink Dual Carrier capability signalling for DTM 8.1.0 8.2.0
06-2008 CP-40 CP-080361 1186 2 RAU attempt counter and PLMN-SEARCH substate 8.1.0 8.2.0
06-2008 CP-40 CP-080361 1184 Correction of MM states in the tables in the timer section 8.1.0 8.2.0
06-2008 CP-40 CP-080361 1178 Correction to CS messages and tables 8.1.0 8.2.0
06-2008 CP-40 CP-080363 1169 3 eCall identifier for differential routing 8.1.0 8.2.0
09-2008 CP-41 CP-080534 1189 4 Avoidance of MM signalling for an eCall only terminal 8.2.0 8.3.0
3GPP
Release 10 650 3GPP TS 24.008 V10.6.1 (2012-03)
09-2008 CP-41 CP-080536 1201 1 Correction for IMSI detach procedure during dedicated mode 8.2.0 8.3.0
09-2008 CP-41 CP-080519 1203 1 Latency Reduction support for non RTTI capable MSs 8.2.0 8.3.0
09-2008 CP-41 CP-080519 1205 1 Stage 2 alignment related to Network bearer control 8.2.0 8.3.0
09-2008 CP-41 CP-080529 1207 1 Clarification of access control for PPAC 8.2.0 8.3.0
09-2008 CP-41 CP-080536 1209 1 TMSI reallocation in a location area where the UE isn’t updated 8.2.0 8.3.0
12-2008 CP-42 CP-080834 1213 1 Multimedia CAT in the CS domain 8.3.0 8.4.0
12-2008 CP-42 CP-080867 1214 3 Paging response for CS Fallback 8.3.0 8.4.0
12-2008 CP-42 CP-080837 1216 Indication of mobile station's E-UTRAN capability 8.3.0 8.4.0
12-2008 CP-42 CP-080838 1218 3 CSG access control for HNB - defining new cause value and UE 8.3.0 8.4.0
behavior
12-2008 CP-42 CP-080866 1227 2 NAS recovery specification in TS 24.008 8.3.0 8.4.0
12-2008 CP-42 CP-080866 1228 1 DRX Parameter support for S1 mode 8.3.0 8.4.0
12-2008 CP-42 CP-080873 1229 1 Corrections for GPRS attach attempt counter and routing area 8.3.0 8.4.0
update attempt counter
12-2008 CP-42 CP-080866 1233 1 P-TMSI signature handling due to S1 mode to Iu or A/Gb mode 8.3.0 8.4.0
intersystem change
12-2008 CP-42 CP-080866 1238 1 Support of EPS NAS protocols 8.3.0 8.4.0
12-2008 CP-42 CP-080866 1240 1 PCO for IP address allocation options 8.3.0 8.4.0
12-2008 CP-42 CP-080868 1242 2 Indication of HSPA SRVCC capability 8.3.0 8.4.0
03-2009 CP-43 CP-090125 1243 2 Additon of E-UTRAN support in MS Network Capability 8.4.0 8.5.0
03-2009 CP-43 CP-090130 1246 1 Security context handling on inter RAT mobility to 8.4.0 8.5.0
GERAN/UTRAN
03-2009 CP-43 CP-090125 1247 2 AMF coding for EPS 8.4.0 8.5.0
03-2009 CP-43 CP-090130 1248 2 SM and GMM sublayers coordination for supporting ISR 8.4.0 8.5.0
03-2009 CP-43 CP-090131 1249 2 UE specific DRX Parameters handling in ATTACH/RAU 8.4.0 8.5.0
procedure
03-2009 CP-43 CP-090159 1253 1 Corrections for attach and RAU attempt counters 8.4.0 8.5.0
03-2009 CP-43 CP-090153 1254 1 ISR local deactivation in the UE 8.4.0 8.5.0
03-2009 CP-43 CP-090159 1255 2 Miscellaneous corrections for 24.008 8.4.0 8.5.0
03-2009 CP-43 CP-090156 1257 2 CC and MM procedures for SRVCC 8.4.0 8.5.0
03-2009 CP-43 CP-090157 1266 1 Invoking detach procedure through a CSG cell 8.4.0 8.5.0
03-2009 CP-43 CP-090157 1268 1 LU/RAU after manual selection of CSG cell 8.4.0 8.5.0
03-2009 CP-43 CP-090159 1270 2 Correction of initial conditions when UE registered for CS 8.4.0 8.5.0
3GPP
Release 10 651 3GPP TS 24.008 V10.6.1 (2012-03)
03-2009 CP-43 CP-090153 1274 1 Additon of CS Fallback capability support in MS Network 8.4.0 8.5.0
Capability
03-2009 CP-43 CP-090129 1275 NAS recovery on/off mechanism(3G) 8.4.0 8.5.0
03-2009 CP-43 CP-090125 1277 1 Add new subclause which describes coordination between GMM 8.4.0 8.5.0
and EMM
03-2009 CP-43 CP-090129 1278 1 Proposal of UE EMM behavior on reception of error cause #9 8.4.0 8.5.0
when UE executed RAU, combined RAU and Service Request
03-2009 CP-43 CP-090126 1279 2 Clarifications for request type 8.4.0 8.5.0
03-2009 CP-43 CP-090131 1280 3 Use of S-TMSI for the GPRS attach procedure 8.4.0 8.5.0
03-2009 CP-43 CP-090157 1281 2 Update of CSG list in manual mode 8.4.0 8.5.0
03-2009 CP-43 CP-090123 1283 1 Enhancement of inter RAT information container 8.4.0 8.5.0
03-2009 CP-43 CP-090128 1284 2 Introducing E-UTRAN UE RAC Information 8.4.0 8.5.0
03-2009 CP-43 CP-090130 1285 Removal of EN for RAU reject (cause #12) 8.4.0 8.5.0
03-2009 CP-43 CP-090131 1286 2 Update the PDN type with IPv4v6 8.4.0 8.5.0
03-2009 CP-43 CP-090125 1290 1 Attach and routing area update abnormal cases: interaction with 8.4.0 8.5.0
EMM
03-2009 CP-43 CP-090153 1292 1 T3280 removal and corrections to procedures for CS fallback 8.4.0 8.5.0
03-2009 CP-43 CP-090157 1295 1 Clarification on CSG related NAS behavior 8.4.0 8.5.0
03-2009 CP-43 CP-090130 1297 1 Proposal of UE EMM behavior on reception of error cause #10 8.4.0 8.5.0
when UE executed RAU, combined RAU and Service Request
06-2009 CP-44 CP-090410 1298 Combined RAU Reject(cause #12) 8.5.0 8.6.0
06-2009 CP-44 CP-090410 1299 Authentication failure parameter applicability 8.5.0 8.6.0
06-2009 CP-44 CP-090424 1303 1 Subclause on PDP address allocation 8.5.0 8.6.0
06-2009 CP-44 CP-090421 1304 2 Mobile Id for Paging Response 8.5.0 8.6.0
06-2009 CP-44 CP-090424 1306 1 Clarification of TMSI reallocation procedure 8.5.0 8.6.0
06-2009 CP-44 CP-090410 1308 1 Introduction of "reserved" code points for Request type IE 8.5.0 8.6.0
06-2009 CP-44 CP-090410 1314 1 Correction for the main state change in the MS 8.5.0 8.6.0
06-2009 CP-44 CP-090421 1317 New trigger for location area updating procedure 8.5.0 8.6.0
06-2009 CP-44 CP-090421 1318 MM state when MS is under E-UTRAN coverage 8.5.0 8.6.0
06-2009 CP-44 CP-090424 1321 1 Behaviour of GPRS MS operating in MS operation mode A or B 8.5.0 8.6.0
on Service Reject with cause #7
06-2009 CP-44 CP-090410 1327 Replacing TRACKING AREA UPDATE REQUEST by ROUTING 8.5.0 8.6.0
AREA UPDATE REQUEST
09-2009 CP-45 CP-090652 1307 3 Protocol Configuration Options support of PAP CHAP in EPS 8.6.0 8.7.0
09-2009 CP-45 CP-090652 1311 7 Providing the MSISDN to the MS 8.6.0 8.7.0
3GPP
Release 10 652 3GPP TS 24.008 V10.6.1 (2012-03)
09-2009 CP-45 CP-090653 1328 1 Security corrections to the RAU procedure 8.6.0 8.7.0
09-2009 CP-45 CP-090677 1332 1 Clarifications related to manual CSG selection 8.6.0 8.7.0
09-2009 CP-45 CP-090773 1333 3 Correction of security key handling for SR VCC 8.6.0 8.7.0
09-2009 CP-45 CP-090677 1337 Correction to abnormal cases on the network side 8.6.0 8.7.0
09-2009 CP-45 CP-090652 1339 2 Interaction between A/Gb or Iu mode and S1 mode 8.6.0 8.7.0
09-2009 CP-45 CP-090652 1340 1 Local ISR deactivation upon last PDP context deactivation 8.6.0 8.7.0
09-2009 CP-45 CP-090652 1344 2 Inclusion of DNS server and P-CSCF IPv4 addresses in PCO 8.6.0 8.7.0
09-2009 CP-45 CP-090650 1345 Align the description of default bearer 8.6.0 8.7.0
09-2009 CP-45 CP-090668 1350 1 Amendments to mobility management procedures 8.6.0 8.7.0
09-2009 CP-45 CP-090651 1357 2 Corrections to the figure of the GMM main states in the MS 8.6.0 8.7.0
09-2009 CP-45 CP-090653 1358 1 Security for inter-system RAU from S1 mode 8.6.0 8.7.0
09-2009 CP-45 CP-090651 1360 Corrections for description of cause #25 8.6.0 8.7.0
09-2009 CP-45 CP-090651 1361 1 Correction on SM error cause #30 8.6.0 8.7.0
09-2009 CP-45 CP-090668 1368 1 Determination of "eCall only" mode of operation 8.6.0 8.7.0
09-2009 CP-45 CP-090675 1372 1 Parameters for SMS over SGs charging 8.6.0 8.7.0
09-2009 CP-45 CP-090689 1330 1 Introducing reject cause value for emergency service over GPPS 8.7.0 9.0.0
09-2009 CP-45 CP-090690 1334 3 PDN Connection request type for emergency 8.7.0 9.0.0
09-2009 CP-45 CP-090682 1336 1 Periodic routing area updating: editorial correction 8.7.0 9.0.0
09-2009 CP-45 CP-090689 1346 2 GPRS Attach for emergency services 8.7.0 9.0.0
09-2009 CP-45 CP-090689 1347 1 GPRS detach for emergency services 8.7.0 9.0.0
09-2009 CP-45 CP-090682 1353 2 Enhanced Flexible Timeslot Assignment 8.7.0 9.0.0
09-2009 CP-45 CP-090682 1354 1 Modification of Length Indicator Usage 8.7.0 9.0.0
09-2009 CP-45 CP-090689 1367 2 HLR detach request and PDP context deactivation by the SGSN 8.7.0 9.0.0
09-2009 CP-45 CP-090692 1371 1 Introduction of 128-bit ciphering key for A5/4 and GEA/4 8.7.0 9.0.0
12-2009 CP-46 CP-090918 1374 1 Correction for detach procedure 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1375 2 Add paging optimization procedure for CSG cell 9.0.0 9.1.0
12-2009 CP-46 CP-090935 1376 3 Clarification on the Closed mode CSG cell 9.0.0 9.1.0
12-2009 CP-46 CP-090922 1377 3 UE voice capabilities/settings in MS network capability 9.0.0 9.1.0
3GPP
Release 10 653 3GPP TS 24.008 V10.6.1 (2012-03)
12-2009 CP-46 CP-090922 1378 5 Triggering conditions update for RAU 9.0.0 9.1.0
12-2009 CP-46 CP-090899 1382 1 Handling of cause #15 in UE with S1 mode support 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1386 1 Detach on Timeout of Periodical Upate Timer 9.0.0 9.1.0
12-2009 CP-46 CP-090917 1388 1 Clarification on setting SI value after SRVCC handover 9.0.0 9.1.0
12-2009 CP-46 CP-090915 1396 2 LAU clarification for ISR and CSFB interworking 9.0.0 9.1.0
12-2009 CP-46 CP-090935 1397 5 Processing the reject cause code #25 for the Operator CSG List 9.0.0 9.1.0
12-2009 CP-46 CP-090920 1399 PDP type IPv4v6 address length corrections 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1400 2 PDP Context activation and modification for emergency bearer 9.0.0 9.1.0
services
12-2009 CP-46 CP-090922 1401 1 Correction to conditions for GMM initiating service request 9.0.0 9.1.0
12-2009 CP-46 CP-090915 1403 1 Missing establishment cause code mapping for CS fallback 9.0.0 9.1.0
12-2009 CP-46 CP-090922 1410 Introduction of Enhanced Multiplexing for Single TBF capability 9.0.0 9.1.0
12-2009 CP-46 CP-090899 1413 Key derivation in idle mode inter-RAT mobility 9.0.0 9.1.0
12-2009 CP-46 CP-090898 1414 Correction for Seperation bit of AMF 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1420 GMM state machine on the UE side for emergency attach 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1421 2 GMM context handling for emergency attach 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1424 2 Deactivate non-EMC bearers with CSG ID not in allowed CSG 9.0.0 9.1.0
list
12-2009 CP-46 CP-090930 1425 1 Handling of the forbidded list 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1426 2 Authentication procedure for EMC attach 9.0.0 9.1.0
12-2009 CP-46 CP-090922 1427 1 Introduction of generic notification procedure 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1428 Checks restrictions on attach for emergency bearer services 9.0.0 9.1.0
12-2009 CP-46 CP-090930 1437 1 GPRS update status while UE is attached for emergency bearer 9.0.0 9.1.0
services
12-2009 CP-46 CP-090939 1438 128-bit ciphering key for SRVCC 9.0.0 9.1.0
12-2009 CP-46 CP-090939 1439 Correction to the definition of the UMTS security context and 9.0.0 9.1.0
faulty message
12-2009 CP-46 CP-091052 1441 2 Alignment with TS23.401 caused by changing the term CSFB to 9.0.0 9.1.0
"CSFB and SMS over SGs".
12-2009 CP-46 CP-090919 1409 4 Protecting the allowed CSG list 9.0.0 9.1.0
03-2010 CP-47 CP-100144 1392 5 Normal and Periodic Routing Area Update Procedure 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1418 3 Deactive ISR for UE attached for emergency bearer services 9.1.0 9.2.0
03-2010 CP-47 CP-100103 1445 Removal of T-GSM 900 capability 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1446 1 Disabling Integrity Checking for GMM, SM messages 9.1.0 9.2.0
03-2010 CP-47 CP-100140 1448 1 Clarification to key derivation at SRVCC 9.1.0 9.2.0
03-2010 CP-47 CP-100134 1450 1 Correction on CSG Id removal from Allowed CSG list 9.1.0 9.2.0
3GPP
Release 10 654 3GPP TS 24.008 V10.6.1 (2012-03)
03-2010 CP-100106 1452 2 GPRS Kc handling at inter-system change from E-UTRAN to 9.1.0 9.2.0
CP-47 UTRAN/GERAN
03-2010 CP-47 CP-100144 1455 1 Definition of attached for emergency bearer service 9.1.0 9.2.0
03-2010 CP-47 CP-100134 1456 1 Selective camping capability correction 9.1.0 9.2.0
03-2010 CP-47 CP-100134 1457 2 Defining Selective camping capability IE 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1458 2 RRC establishment cause for EMC of Iu mode 9.1.0 9.2.0
03-2010 CP-47 CP-100126 1460 2 Handling of Paging Response for CSFB 9.1.0 9.2.0
03-2010 CP-47 CP-100134 1461 Handling of CSFB mobile originating call 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1462 1 Handling authentication failure for EMC during RAU 9.1.0 9.2.0
03-2010 CP-47 CP-100126 1467 1 Alignment term "CSFB and SMS over SGs" with TS23.401 (Part 9.1.0 9.2.0
II)
03-2010 CP-47 CP-100106 1469 2 Clarification on routing parameter for access stratum 9.1.0 9.2.0
03-2010 CP-47 CP-100135 1470 2 Operator specific values for PCO 9.1.0 9.2.0
03-2010 CP-47 CP-100148 1471 1 Use of Cause #25 when MS's subscription to CSG has expired – 9.1.0 9.2.0
24.008
03-2010 CP-47 CP-100134 1473 Handling of inter RAT information container and E-UTRAN inter 9.1.0 9.2.0
RAT information container
03-2010 CP-47 CP-100126 1476 1 Removing triggers for rau after S1 mode to UTRAN Iu mode 9.1.0 9.2.0
intersystem change due to CS fallback without PS handover
03-2010 CP-47 CP-100126 1478 1 Corrections on periodic routeing area update timer and 9.1.0 9.2.0
GERAN/UTRAN Deactivate ISR timers in the UE
03-2010 CP-47 CP-100134 1483 1 Using NAS-token in Attach Request 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1486 2 Emergency secondary PDP context activation 9.1.0 9.2.0
03-2010 CP-47 CP-100130 1488 1 MM cause #25 for MM connection establishment 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1489 Definition of non-emergency PDP context 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1491 2 Attach for emergency bearer services to a network not 9.1.0 9.2.0
supporting EM BS
03-2010 CP-47 CP-100134 1493 1 Corrections to Network Feature Support IE. 9.1.0 9.2.0
03-2010 CP-47 CP-100126 1498 2 Correction of CSFB capability indicator 9.1.0 9.2.0
03-2010 CP-47 CP-100144 1499 2 Mobility aspects of Emergency attached UEs 9.1.0 9.2.0
03-2010 CP-47 CP-100132 1501 Introduction of indication of support of GERAN to UTRAN 9.1.0 9.2.0
priority-based cell reselection – Option 1
03-2010 CP-47 CP-100211 1504 2 Correct terminating domain selection for IMS voice UEs 9.1.0 9.2.0
06-2010 CP-48 CP-100371 1509 2 Correction of LAU initiation during CSFB 9.2.0 9.3.0
06-2010 CP-48 CP-100354 1510 2 Correction of LAU for CSFB in NMO I 9.2.0 9.3.0
06-2010 CP-48 CP-100351 1514 Requested QoS in PDP context activation procedure 9.2.0 9.3.0
06-2010 CP-48 CP-100355 1515 1 GPRS Kc128 handling at inter-system change from E-UTRAN to 9.2.0 9.3.0
UTRAN/GERAN
06-2010 CP-48 CP-100360 1517 3 GMM Authentication procedure for emergency services 9.2.0 9.3.0
3GPP
Release 10 655 3GPP TS 24.008 V10.6.1 (2012-03)
06-2010 CP-48 CP-100355 1521 Multiple TTI TBF capability 9.2.0 9.3.0
06-2010 CP-48 CP-100355 1522 Interpretation of Multislot Class Parameters for EFTA 9.2.0 9.3.0
06-2010 CP-48 CP-100354 1525 1 Correction of conditions for RAU and ISR deactivation for T-ADS 9.2.0 9.3.0
06-2010 CP-48 CP-100360 1536 2 Some corrections to the EMC procedure. 9.2.0 9.3.0
06-2010 CP-48 CP-100350 1538 2 Clarification to network initiated detach procedure with cause 9.2.0 9.3.0
#25
06-2010 CP-48 CP-100355 1544 1 Correction to MS Radio Access Capability Information Element 9.2.0 9.3.0
encoding
06-2010 CP-48 CP-100349 1547 1 Derivation of the security context for CS domain because of 9.2.0 9.3.0
SRVCC
06-2010 CP-48 CP-100354 1548 1 Correction to the applicability of security key for inter-sytem 9.2.0 9.3.0
change from S1 to Iu
06-2010 CP-48 CP-100365 1549 1 Correction to the derivation of GPRS GSM Kc128 for inter-sytem 9.2.0 9.3.0
change from S1 to Gb
06-2010 CP-48 CP-100365 1550 1 Correction to 128-bit ciphering key handling 9.2.0 9.3.0
06-2010 CP-48 CP-100360 1551 2 Emergency attach reject from GMM in shared networks 9.2.0 9.3.0
09-2010 CP-49 CP-100501 1532 2 Corrections for Selective Camping 9.3.0 9.4.0
09-2010 CP-49 CP-100491 1553 4 Correction to timer T3242 and T3243 values (eCall only MS) 9.3.0 9.4.0
09-2010 CP-49 CP-100506 1554 2 Clarification to the T3302 timer value when a UE is emergency 9.3.0 9.4.0
attached without security procedure.
09-2010 CP-49 CP-100506 1555 2 Handling of Detach Procedure for IMSI services on a CSG cell 9.3.0 9.4.0
which is no longer valid for the UE.and IMS EMG call is active.
09-2010 CP-49 CP-100506 1560 1 Clarification to timer T3318 and T3320 timer description in the 9.3.0 9.4.0
EMC case.
09-2010 CP-49 CP-100485 1581 1 Correction to the protocol configuration options IEI 9.3.0 9.4.0
09-2010 CP-49 CP-100501 1585 4 Handling of location updating after CS fallback for mobile 9.3.0 9.4.0
terminating calls
09-2010 CP-49 CP-100507 1593 2 Introduction of MS CSG interworking capabilities 9.3.0 9.4.0
09-2010 CP-49 CP-100501 1595 Correction of implementation error of CR1372R1 9.3.0 9.4.0
09-2010 CP-49 CP-100501 1598 2 Handling of collision of a Network Initiated Detach procdure with 9.3.0 9.4.0
a Service Request procedure and a RAU procedure.
09-2010 CP-49 CP-100495 1603 1 Location updating during CS fallback 9.3.0 9.4.0
09-2010 CP-49 CP-100506 1604 1 Correction on storage of equivalent PLMNs list 9.3.0 9.4.0
09-2010 CP-49 CP-100520 1613 Corrections to UE mode of operation selection taking into 9.3.0 9.4.0
account the UE's availability for voice calls in the IMS
09-2010 CP-49 CP-100501 1621 2 Alignment with 23.060 for SM cause value #52 "single address 9.3.0 9.4.0
bearers only allowed"
09-2010 CP-49 CP-100517 1528 2 Local ISR deactivation in the UE when T3412 has expired 9.4.0 10.0.0
09-2010 CP-49 CP-100514 1562 5 PDN connection redirection in SIPTO scenario 9.4.0 10.0.0
09-2010 CP-49 CP-100514 1563 1 Clarification on PDP Context re-activation 9.4.0 10.0.0
3GPP
Release 10 656 3GPP TS 24.008 V10.6.1 (2012-03)
09-2010 CP-49 CP-100517 1566 2 Correction for implicit detach timer 9.4.0 10.0.0
09-2010 CP-49 CP-100520 1573 1 eCALL INACTIVE state and ATT flag 9.4.0 10.0.0
09-2010 CP-49 CP-100642 1579 2 Maximum number of packet filters 9.4.0 10.0.0
09-2010 CP-49 CP-100520 1594 Introduction of Dynamic Timeslot Reduction capability 9.4.0 10.0.0
09-2010 CP-49 CP-100517 1599 1 TIN setting after location updating 9.4.0 10.0.0
09-2010 CP-49 CP-100520 1600 2 Handling of cause #27 (missing or unknown APN) 9.4.0 10.0.0
09-2010 CP-49 CP-100517 1605 1 Correction on network initiated GPRS detach with cause #2 9.4.0 10.0.0
09-2010 CP-49 CP-100520 1608 Clarifying the updation of forbidden LA list 9.4.0 10.0.0
09-2010 CP-49 CP-100520 1610 1 Clarification on READY timer behaviour 9.4.0 10.0.0
09-2010 CP-49 CP-100520 1617 Correction to UTRAN Network sharing 9.4.0 10.0.0
12-2010 CP-50 CP-100760 1629 7 Extended Routing Area Update Timer 10.0.0 10.1.0
12-2010 CP-50 CP-100760 1630 4 Rejection due to per APN congestion 10.0.0 10.1.0
12-2010 CP-50 CP-100760 1631 3 Modified GMM Cause values for NIMTC 10.0.0 10.1.0
12-2010 CP-50 CP-100761 1632 Authentication not accepted by the network 10.0.0 10.1.0
12-2010 CP-50 CP-100742 1635 1 Correction of conditions for setting the CMST flag 10.0.0 10.1.0
12-2010 CP-50 CP-100761 1638 1 Deleting unnecessary trigger for initiating LAU procedure 10.0.0 10.1.0
12-2010 CP-50 CP-100761 1649 1 Enhanced Multiplexing for a Single RLC Entity (EMSR) 10.0.0 10.1.0
12-2010 CP-50 CP-100760 1655 1 NMOI indicator for MTC 10.0.0 10.1.0
12-2010 CP-50 CP-100761 1657 1 Correctin to the use of label ”UMTS only” in various procedure. 10.0.0 10.1.0
12-2010 CP-50 CP-100736 1660 1 Correction of normal stop conditions for eCall and other timers 10.0.0 10.1.0
12-2010 CP-50 CP-100758 1669 3 Cause value for terminating eMPS CS Fallback calls 10.0.0 10.1.0
12-2010 CP-50 CP-100760 1670 4 RAU procedure when Low Priority indicator in MS changes 10.0.0 10.1.0
12-2010 CP-50 CP-100761 1672 2 Explicit signalling of native vs mapped P-TMSI during RAU 10.0.0 10.1.0
12-2010 CP-50 CP-100760 1673 2 Adding NAS signalling priority indication in Attach Request 10.0.0 10.1.0
3GPP
Release 10 657 3GPP TS 24.008 V10.6.1 (2012-03)
12-2010 CP-50 CP-100760 1681 3 Clarifying the APN congestion control for EMC attached MS 10.0.0 10.1.0
12-2010 CP-50 CP-100747 1685 1 Correction on GMM authentication failure for EMC services 10.0.0 10.1.0
12-2010 CP-50 CP-100760 1686 1 SM procedures for low priority 10.0.0 10.1.0
12-2010 CP-50 CP-100761 1690 Correction of bearer capability length 10.0.0 10.1.0
12-2010 CP-50 CP-100753 1641 4 PDN disconnection for LIPA 10.0.0 10.1.0
03-2011 CP-51 CP-110195 1691 3 Clarification to the handling of SM cause value 27 10.1.0 10.2.0
03-2011 CP-51 CP-110193 1692 3 Clarification to the handling of timer T3245 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1696 2 Explicit Signalling Indication During Attach 10.1.0 10.2.0
03-2011 CP-51 CP-110183 1704 3 Corrections to the PDP Context Deactivation 10.1.0 10.2.0
03-2011 CP-51 CP-110193 1706 2 Integrity protection of periodic updates 10.1.0 10.2.0
03-2011 CP-51 CP-110193 1710 1 Attach with IMSI Alignment of Terminology 10.1.0 10.2.0
03-2011 CP-51 CP-110193 1711 1 Specific requirements Alignment of Terminology 10.1.0 10.2.0
03-2011 CP-51 CP-110193 1717 3 Storage and handling of the NAS signalling low priority indicator 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1720 2 Correction on GPRS detach and service request collision 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1722 2 Correction to reject cause value 48 name 10.1.0 10.2.0
03-2011 CP-51 CP-110193 1725 4 Adding NAS signalling priority indication in SM messages 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1727 3 Correction of the handling of the P-TMSI type IE 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1728 1 Maximum Transmission Unit in Protocol configuration options 10.1.0 10.2.0
03-2011 CP-51 CP-110199 1731 1 Allocation of TI and assignment of CC state to alerting call for 10.1.0 10.2.0
3GPP
Release 10 658 3GPP TS 24.008 V10.6.1 (2012-03)
03-2011 CP-51 CP-110195 1734 GMM state after lower layers failure during TAU when TIN=GUTI 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1735 3 Stopping T3311 when UE moves to PMM-CONNECTED mode 10.1.0 10.2.0
03-2011 CP-51 CP-110253 1744 1 Changing “P-TMSI or IMSI” Information Element to “Mobile 10.1.0 10.2.0
Identity”
03-2011 CP-51 CP-110171 1747 Correction to detection of CSG cell based on CSG ID 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1753 1 Correction on PPAC description to include GPRS Attach 10.1.0 10.2.0
procedure
03-2011 CP-51 CP-110195 1756 1 Radio resource sublayer address TLLI handling 10.1.0 10.2.0
03-2011 CP-51 CP-110193 1758 2 SM Backoff timer, Editor’s note removal 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1761 1 MS initiated PDP Context Activation without PDP address 10.1.0 10.2.0
03-2011 CP-51 CP-110183 1762 3 Restriction on the use of PDN connection for LIPA 10.1.0 10.2.0
03-2011 CP-51 CP-110195 1763 Editorial correction on Congestion level IE definition 10.1.0 10.2.0
03-2011 CP-51 CP-110253 1765 1 RRC establishment cause for emergency PDP after normal 10.1.0 10.2.0
GPRS attach
03-2011 CP-51 CP-110195 1766 Missing handling of undefined values for MBR and GBR by the 10.1.0 10.2.0
MS
03-2011 CP-51 CP-110206 1700 4 Mobility management congestion control and back-off timer 10.1.0 10.2.0
03-2011 CP-51 CP-110305 1699 3 Device properties and RRC establishment cause = Delay 10.1.0 10.2.0
tolerant – 24.008
06-2011 CP-52 CP-110462 1776 1 Corrections for overload behavior 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1779 1 Clearly specify conditions for UE actions at switch off for T3245, 10.2.0 10.3.0
T3346 and T3396.
06-2011 CP-52 CP-110462 1780 1 Further clarification of PLMN reselection and handling of MM 10.2.0 10.3.0
back-off timer
06-2011 CP-52 CP-110466 1782 1 Modifications to Emergency Number List IE. 10.2.0 10.3.0
06-2011 CP-52 CP-110466 1785 Support of IPv6 Prefix Delegation 10.2.0 10.3.0
06-2011 CP-52 CP-110446 1788 Manipulation of CSG ID entries (in ACL and OCL) and the 10.2.0 10.3.0
associated PLMNID - 3G
06-2011 CP-52 CP-110462 1792 Specification of missing timer identities 10.2.0 10.3.0
06-2011 CP-52 CP-110476 1793 Correct conditions for including the connectivity type IE 10.2.0 10.3.0
06-2011 CP-52 CP-110476 1794 1 Correct the trigger of the LIPA PDN disconnection 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1795 1 Reference to NAS configuration in USIM 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1798 2 Handling Network initiated procedure when backoff timer is 10.2.0 10.3.0
running
06-2011 CP-52 CP-110462 1799 2 Emergency attach during backoff 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1801 1 alignment about MM congestion control 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1808 2 Correction on MS behavior for SM cause #26 and #27 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1812 1 Clarification about APN based congestion control procedure 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1815 2 Correction of T3396 handling for PDN connection reactivation 10.2.0 10.3.0
3GPP
Release 10 659 3GPP TS 24.008 V10.6.1 (2012-03)
06-2011 CP-110464 1818 2 Clarification to condition of sending the Network feature durning 10.2.0 10.3.0
CP-52 periodic RAU procedure.
06-2011 CP-52 CP-110462 1820 1 Per MS T3212 rather than T3212 multiplier 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1822 2 Attach with IMSI in CS domain at PLMN change for MTC devices 10.2.0 10.3.0
06-2011 CP-52 CP-110466 1790 Introduction of fast downlink frequency switching capability 10.2.0 10.3.0
06-2011 CP-52 CP-110462 1791 2 Addition of MM backoff timer for CS 10.2.0 10.3.0
06-2011 CP-52 CP-110466 1806 1 Preservation and network controlled QoS 10.2.0 10.3.0
06-2011 CP-52 CP-110463 1807 1 NAS signalling low priority indication for exception cases 10.2.0 10.3.0
09-2011 CP-53 CP-110680 1770 4 Handling mobile reachable timer for back-off UE with emergency 10.3.0 10.4.0
PDN connection
09-2011 CP-53 CP-110680 1821 6 Call forwarding, paging and long periodic timers 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1832 1 Handling Timers T3246, T3346 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1833 1 Timer Table Update with EPS details 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1834 2 Handling NAS Low Priority Indication 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1835 4 Correction and clarification on the terminologies of NAS level 10.3.0 10.4.0
congestion control
09-2011 CP-53 CP-110682 1847 1 Clarification of UE behavior when combined RAU is not accepted 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1850 1 Clarify the bit in the device properties 10.3.0 10.4.0
09-2011 CP-53 CP-110683 1854 2 Clarification on periodic routing area update 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1856 1 Scope of SM APN congestion control 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1859 2 Handling of paging for MT in CS when a MM back-off timer is 10.3.0 10.4.0
running
09-2011 CP-53 CP-110680 1861 4 Clarification of RAU triggered after paging 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1862 1 Establishing emergency services when T3246 or T3346 is 10.3.0 10.4.0
running
09-2011 CP-53 CP-110680 1882 1 Correction to cause #22 handling 10.3.0 10.4.0
09-2011 CP-53 CP-110680 1908 1 Clarification on paging response for CSFB when a MM back-off 10.3.0 10.4.0
timer is running
09-2011 CP-53 CP-110680 1910 1 T3323 may not be started 10.3.0 10.4.0
09-2011 CP-53 CP-110665 1914 2 Reject Cause handling while MS attaching for emergency bearer 10.3.0 10.4.0
services
09-2011 CP-53 CP-110680 1917 1 Value of timer T3312 in the network 10.3.0 10.4.0
09-2011 CP-53 CP-110708 1855 5 Correction to network-initiated detach procedure 10.3.0 10.4.0
12-2011 CP-54 CP-110874 1841 3 Coordination between SM and GMM for supporting ISR 10.4.0 10.5.0
12-2011 CP-54 CP-110851 1892 4 PSAP Callback for eCalls 10.4.0 10.5.0
12-2011 CP-54 CP-110871 1924 4 Setting Mobile Reachable timer, Implicit Detach Timer 10.4.0 10.5.0
3GPP
Release 10 660 3GPP TS 24.008 V10.6.1 (2012-03)
12-2011 CP-54 CP-110879 1949 1 Clarifications for user connection attachment for SRVCC 10.4.0 10.5.0
12-2011 CP-54 CP-110871 1962 Correction of MM back-off timer reference 10.4.0 10.5.0
12-2011 CP-54 CP-110871 1964 1 Clarification on SM backoff while paged using IMSI 10.4.0 10.5.0
12-2011 CP-54 CP-110871 1966 2 Correction of LAU trigger when EMM/GMM backoff 10.4.0 10.5.0
12-2011 CP-54 CP-110860 1972 START value storage on USIM at SRVCC handover 10.4.0 10.5.0
12-2011 CP-54 CP-110875 1974 1 Introduction of Selective Ciphering on SACCH 10.4.0 10.5.0
12-2011 CP-54 CP-110871 1978 1 Default Value for SM back-off timer 10.4.0 10.5.0
12-2011 CP-54 CP-110859 1986 5 Old LAI in Attach/RAU procedure 10.4.0 10.5.0
12-2011 CP-54 CP-110871 2000 1 LAU trigger when GMM backoff timer running 10.4.0 10.5.0
12-2011 CP-54 CP-110871 2019 2 Correction on the MO CSFB procedure during T3246 running 10.4.0 10.5.0
03-2012 CP-55 CP-120100 2029 1 Removal of LLC Acknowledged mode 10.5.0 10.6.0
03-2012 CP-55 CP-120102 2033 2 Re-attach for emergency bearer service 10.5.0 10.6.0
03-2012 CP-55 CP-120098 2043 1 Correction of Combined RA/LA update triggers by CSFB UE 10.5.0 10.6.0
03-2012 CP-55 CP-120111 2053 2 Release of NAS signalling connection with EWT 10.5.0 10.6.0
03-2012 CP-55 CP-120111 2066 Location Update when T3346 is running in NMO1 10.5.0 10.6.0
03-2012 CP-55 CP-120111 2072 3 Handling NAS signalling low priority indication 10.5.0 10.6.0
03-2012 CP-55 CP-120111 2075 3 Correction to the handling of wait time from AS 10.5.0 10.6.0
03-2012 CP-55 CP-120106 2078 3 Call Control state modelling for aSRVCC 10.5.0 10.6.0
03-2012 CP-55 CP-120111 2081 1 Back-off timer handling in connected mode mobility 10.5.0 10.6.0
3GPP