Almost every RRC procedure in LTE is guarded by a timer. A timer starts when the UE sends or receives a message, and it stops when the expected answer arrives. If the timer expires first, the UE takes a fixed recovery action. So when a log shows a UE falling back to RRC_IDLE or starting re-establishment, the first question is which timer expired.
This page lists the RRC timers of 36.331 clause 7.3. It starts with the original timers, then adds the timers of later releases, and finally follows the timers that handle a radio link failure.
- What do the original RRC timers do ?
- Which timers have later releases added ?
- How do T310, T311 and T301 take the UE from a radio problem to RRC_IDLE ?
- Reference
What do the original RRC timers do ?
Let's start with the timers of the early releases. Most of them guard connection setup and re-establishment, and three of them release access barring. Each row reads left to right: the event that starts the timer, the events that stop it, and the action at expiry.
Following table is from 36.331 7.3 Timers (Informative)
It is the early version of the table. In 36.331 v19.3.0 the table is in clause 7.3.1, and several of these rows now carry extra conditions, which are listed below the table.
|
Timer |
Start |
Stop |
At expiry |
|
Transmission of RRCConnectionRequest |
Reception of RRCConnectionSetup or RRCConnectionReject message, cell re-selection and upon abortion of connection establishment by upper layers |
Perform the actions as specified in 5.3.3.6 |
|
|
T301 |
Transmission of RRCConnectionReestabilshmentRequest |
Reception of RRCConnectionReestablishment or RRCConnectionReestablishmentReject message as well as when the selected cell becomes unsuitable |
Go to RRC_IDLE |
|
T302 |
Reception of RRCConnectionReject while performing RRC connection establishment |
Upon entering RRC_CONNECTED and upon cell re-selection |
Inform upper layers about barring alleviation as specified in 5.3.3.7 |
|
T303 |
Access barred while performing RRC connection establishment for mobile originating calls |
Upon entering RRC_CONNECTED and upon cell re-selection |
Inform upper layers about barring alleviation as specified in 5.3.3.7 |
|
Reception of RRCConnectionReconfiguration message including the MobilityControl Info or reception of MobilityFromEUTRACommand message including CellChangeOrder |
Criterion for successful completion of handover to EUTRA or cell change order is met (the criterion is specified in the target RAT in case of inter-RAT) |
In case of cell change order from E-UTRA or intra E-UTRA handover, initiate the RRCconnection re-establishment procedure; In case of handover to E-UTRA, perform the actions defined in the specifications applicable for the source RAT. |
|
|
T305 |
Access barred while performing RRCconnection establishment for mobile originating signalling |
Upon entering RRC_CONNECTED and upon cell re-selection |
Inform upper layers about barring alleviation as specified in 5.3.3.7 |
|
Upon detecting physical layer problems i.e. upon receiving N310 consecutive out-of-sync indications from lower layers |
Upon receiving N311 consecutive in-sync indications from lower layers, upon triggering the handover procedure and upon initiating the connection re-establishment procedure |
If security is not activated: go to RRC_IDLE else: initiate the connection re-establishment procedure |
|
|
T311 |
Upon initiating the RRCconnection reestablishmentmprocedure |
Selection of a suitable E-UTRA cell or a cell using another RAT. |
Enter RRC_IDLE |
|
T320 |
Upon receiving t320 or upon cell (re)selection to E-UTRA from another RAT with validity time configured for dedicated priorities (in which case the remaining validity time is applied). |
Upon entering RRC_CONNECTED, when PLMN selection is performed on request by NAS, or upon cell (re)selection to another RAT (in which case the timer is carried on to the other RAT). |
Discard the cell reselection priority information provided by dedicated signalling. |
|
T321 |
Upon receiving measConfig including a reportConfig with the purpose set to reportCGI |
Upon acquiring the information needed to set all fields of cellGlobalId for the requested cell, upon receiving measConfig that includes removal of the reportConfig with the purpose set to reportCGI |
Initiate the measurement reporting procedure, stop performing the related measurements and remove the corresponding measId |
Now compare these rows with v19.3.0. The timer numbers and the expiry actions are the same, but later features added start and stop events. The first change is in T300. It now also starts on RRCConnectionResumeRequest and RRCEarlyDataRequest. RRCConnectionResume, RRCEarlyDataComplete and RRCConnectionRelease for UP-EDT also stop it. The second change is in T302. It also starts on RRCConnectionRelease with waitTime. The third is in T304. It also starts on conditional reconfiguration execution. At expiry, a UE with a DAPS bearer and no RLF in the source PCell starts the failure information procedure instead.
T310 changed the most. It now refers to the PCell, and it also stops when the UE starts the MCG failure information procedure. At expiry with security active, the UE starts either the MCG failure information procedure or re-establishment. Finally, T321 now also stops when the UE detects that the cell does not broadcast SIB1. The barring timers T302, T303 and T305 and the priority timer T320 also gained stop events for EDT and PUR. Only T301 and T311 are unchanged.
Every row has a start, a stop and an expiry action : the expiry action tells you what the UE does when the expected message never comes.T300, T301 and T311 guard connection setup and re-establishment : their expiry ends in the actions of 5.3.3.6 or in RRC_IDLE.T302, T303 and T305 release access barring : the UE informs upper layers about barring alleviation when they expire or stop.The early table is still valid in outline : the current rows add Resume, EDT, conditional handover, DAPS and MCG failure information cases.
Which timers have later releases added ?
The timer list grew with every release, because each new feature needed its own guard or its own prohibit timer. The list is long, but most rows belong to a single feature. A UE runs a timer only when the network has configured the feature that uses it.
The table below lists the timers that 36.331 v19.3.0 adds to the early table. The start and expiry entries are shortened from clause 7.3.1, so check the clause for the exact stop conditions.
Timer | Area | Start | At expiry |
T306 | Access barring | Access barred for mobile originating CS fallback | Inform upper layers about barring alleviation |
T307 | Dual connectivity | RRCConnectionReconfiguration with MobilityControlInfoSCG | SCG failure information procedure |
T308 | Access barring | Access barred due to ACDC | Inform upper layers about barring alleviation for ACDC |
T309 | Access barring | Access attempt barred for an Access Category, one instance per category | Actions of 5.3.16.4 |
T312 | Radio link monitoring | Measurement report for a measId with useT312 while T310 runs | MCG failure information or re-establishment |
T313 | Dual connectivity | N313 consecutive out-of-sync indications for the PSCell | SCG failure information procedure |
T314 | Radio link monitoring | N310 consecutive early-out-of-sync indications for the PCell | UEAssistanceInformation on early physical layer problems |
T315 | Radio link monitoring | N311 consecutive early-in-sync indications for the PCell | UEAssistanceInformation on physical layer improvements |
T316 | Radio link monitoring | Transmission of MCGFailureInformation | Actions of 5.6.26.5 |
T317 | NTN | epochTime of SystemInformationBlockType31, or a handover to the target cell | Actions of 5.3.18 |
T318 | NTN | Start of SystemInformationBlockType31 acquisition in RRC_CONNECTED | RRC_IDLE or re-establishment |
T322 | Idle mode priority | redirectedCarrierOffsetDedicated in RedirectedCarrierInfo | Release redirectedCarrierOffsetDedicated |
T323 | Idle mode priority | Reception of t323 | Discard altFreqPriorities and use the broadcast priorities |
T325 | Idle mode priority | RRCConnectionReject with deprioritisationTimer | Stop the deprioritisation |
T326 | NB-IoT measurement | Entering RRC_CONNECTED, or an update to NRSRPRef | Stop connected mode neighbour cell measurement |
T330 | Logged MDT | Reception of LoggedMeasurementConfiguration | Actions of 5.6.6.4 |
T331 | Idle measurement | RRCConnectionRelease with measIdleConfig | Actions of 5.6.20.3 |
T340 | UE assistance | UEAssistanceInformation with powerPrefIndication set to normal | No action |
T341 | UE assistance | UEAssistanceInformation with bw-Preference | No action |
T342 | UE assistance | UEAssistanceInformation with delayBudgetReport | No action |
T343 | UE assistance | UEAssistanceInformation with RLM-Report including earlyOutOfSync | No action |
T344 | UE assistance | UEAssistanceInformation with RLM-Report including earlyInSync | No action |
T345 | UE assistance | UEAssistanceInformation with overheatingAssistance | No action |
T346 | UE assistance | UEAssistanceInformation with scg-DeactivationPreference | No action |
T350 | WLAN interworking | Entering RRC_IDLE with t350 received in wlan-OffloadInfo | Actions of 5.6.12.4 |
T351 | WLAN interworking | associationTimer in WLAN-MobilityConfig | WLAN connection status reporting |
T360 | Load redistribution | Redistribution target selection of 36.304 | Stop treating the frequency or cell as redistribution target |
T370 | Sidelink discovery | SL-DiscConfig with discSysInfoToReportConfig set to setup | Release discSysInfoToReportConfig |
T380 | RRC_INACTIVE | periodic-RNAU-timer in RRCConnectionRelease | RAN notification area update |
T390 | NTN | GNSS validity duration expiry with ul-TransmissionExtensionEnabled | Actions of 5.3.3.21 |
T395 | Access barring | Access barred for disaster roaming in EPS | Inform upper layers about barring alleviation for disaster roaming |
Look at the T34x rows. Their expiry action is No action, and that is not an error in the table. These are prohibit timers. The UE starts one when it sends a UEAssistanceInformation report of a given type. While the timer runs, the UE does not send another report of that type, so the timers limit how often the UE reports.
Two notes under the table in clause 7.3.1 also matter. Only the timers marked NOTE1 apply to NB-IoT. These are T300, T301, T309, T310, T311, T317, T318, T322, T326 and T390. And clause 7.3.2 says that a timer with the value zero starts and expires at once, unless the procedure text says otherwise.
New features brought new timers : CS fallback, dual connectivity, ACDC, RRC_INACTIVE, NTN and UE assistance each added their own.The T34x timers are prohibit timers : they have no expiry action and only limit how often the UE sends UEAssistanceInformation.NB-IoT uses a short subset : only the ten timers marked NOTE1 apply to it.A timer value of zero expires at once : so a configured value of 0 is not the same as no timer.
How do T310, T311 and T301 take the UE from a radio problem to RRC_IDLE ?
The timers in the tables are easier to understand as a chain. A radio link failure is the most common case in a field log, and it uses four timers in sequence. So let's follow one UE from the first out-of-sync indication to RRC_IDLE.
The first step is detection. Layer 1 reports out-of-sync and in-sync indications to RRC. After N310 consecutive out-of-sync indications for the PCell, the UE starts T310. It does this only while none of T300, T301, T304, T311 and T316 is running. If N311 consecutive in-sync indications arrive while T310 runs, the UE stops T310 and keeps the connection without any signalling.
The second step is the failure itself. The UE declares radio link failure when T310 expires. It also declares it on T312 expiry, on a random access problem from MAC, or when RLC reaches the maximum number of retransmissions. T312 is the early exit. The network enables it for a measurement with useT312, so a UE that has already triggered a measurement report can give up on the serving cell sooner than T310 allows.
The third step is recovery. With AS security active, the UE starts re-establishment and starts T311 while it searches for a suitable cell. When it selects a cell, it stops T311, starts T301 and sends RRCConnectionReestablishmentRequest. If T311 expires, or T301 expires, or the selected cell becomes unsuitable, the UE goes to RRC_IDLE. Without AS security the UE skips re-establishment and goes to RRC_IDLE directly.
The values come from SystemInformationBlockType2. Its ue-TimersAndConstants carries t300, t301, t310, n310, t311 and n311. The network can override the radio link values for one UE with rlf-TimersAndConstants-r9 in RadioResourceConfigDedicated. So when you compare a log with the table, check the dedicated values first.
T310 is the grace period : the UE waits for N311 in-sync indications before it gives up on the PCell.T312 shortens the wait : it runs only after a measurement report, so a UE that is already leaving the cell fails faster.T311 limits the cell search and T301 limits the answer : either expiry sends the UE to RRC_IDLE.Security decides the path : without AS security there is no re-establishment, and radio link failure leads straight to RRC_IDLE.Dedicated values override SIB2 : rlf-TimersAndConstants-r9 replaces the broadcast values for one UE.
Reference
- 3GPP TS 36.331 v19.3.0 : Evolved Universal Terrestrial Radio Access (E-UTRA); Radio Resource Control (RRC); Protocol specification. Clause 7.3.1 Timers, 7.3.2 Timer handling, 7.4 Constants, 5.3.7 RRC connection re-establishment and 5.3.11 Radio link failure related actions.