4G/LTE - PWS/CBS

 

 

 

CMAS

 

CMAS stands for Commercial Mobile Alert System. It is equivalent to CBS(Cell Broadcasting Service) in 2G and 3G. At high level view, CMAS, ETWS, CBS belongs to a system called PWS (Public Warning System).    In LTE, the eNB carries the warning itself in SIB12 and uses paging only to tell the UEs that SIB12 is there. The content inside SIB12 keeps the CBS format of 23.041, so the Message Identifier, the Serial Number and the Data Coding Scheme work as they do in UMTS.

The topics on this page are listed below.

CMAS Message Structure

In LTE, there are three main components getting involved in sending CMAS as follows. The eNB never sends a CMAS warning in a dedicated message, so all three components are broadcast. SIB12 carries the warning, and the other two only tell the UE that it exists and where to find it.

    i) Paging : CMAS Notification.

    ii) SIB 12 : Message Format and Contents

    iii) SIB 1 : Scheduling of SIB 12

Following is Paging, SIB12  showing the field (IEs) related to CMAS. (For the details of ETWS, refer to 3GPP TS23.828 and TS22.268 and TS 36.523 18.1 CMAS on LTE)

Decoded Paging message from a live capture, shown as the decoder printed it. The values are what one network sent, not what the specification requires.

PCCH-Message ::= SEQUENCE
  +-message ::= CHOICE [c1]
    +-c1 ::= CHOICE [paging]
      +-paging ::= SEQUENCE [0001]
        +-pagingRecordList ::= SEQUENCE OF OPTIONAL:Omit
        +-systemInfoModification ::= ENUMERATED OPTIONAL:Omit
        +-etws-Indication ::= ENUMERATED OPTIONAL:Omit
        +-nonCriticalExtension ::= SEQUENCE [01] OPTIONAL:Exist
          +-lateNonCriticalExtension ::= OCTET STRING OPTIONAL:Omit
          +-nonCriticalExtension ::= SEQUENCE [10] OPTIONAL:Exist
            +-cmas-Indication-r9 ::= ENUMERATED [true] OPTIONAL:Exist
            +-nonCriticalExtension ::= SEQUENCE OPTIONAL:Omit

Decoded SIB12 from a live capture, shown as the decoder printed it. The values are what one network sent, not what the specification requires.

BCCH-DL-SCH-Message ::= SEQUENCE
  +-message ::= CHOICE [c1]
    +-c1 ::= CHOICE [systemInformation]
      +-systemInformation ::= SEQUENCE
        +-criticalExtensions ::= CHOICE [systemInformation-r8]
          +-systemInformation-r8 ::= SEQUENCE [0]
            +-sib-TypeAndInfo ::= SEQUENCE OF SIZE(1..maxSIB[32]) [1]
            | +- ::= CHOICE [sib12-v920]
            |   +-sib12-v920 ::= SEQUENCE [10]
            |     +-messageIdentifier-r9 ::= BIT STRING SIZE(16) [0001000100010010]
            |     +-serialNumber-r9 ::= BIT STRING SIZE(16) [0011000000000000]
            |     +-warningMessageSegmentType-r9 ::= ENUMERATED [lastSegment]
            |     +-warningMessageSegmentNumber-r9 ::= INTEGER (0..63) [0]
            |     +-warningMessageSegment-r9 ::= OCTET STRING SIZE(ALIGNED) 
                                                  [01C576597E2EBBC7F950A8D168341A8D46A3D168341
                                                   A8D46A3D168341A8D46A3D168341A8D46A3D168341A
                                                   8D46A3D168341A8D46A3D168341A8D46A3D168341A8
                                                   D46A3D168341A8D46A3D168341A8D46A3D1000A]
            |     +-dataCodingScheme-r9 ::= OCTET STRING SIZE(1) [01] OPTIONAL:Exist
            |     +-lateNonCriticalExtension ::= OCTET STRING OPTIONAL:Omit
            |     +-EXTENSION ::= SEQUENCE
            +-nonCriticalExtension ::= SEQUENCE OPTIONAL:Omit

The Paging capture carries no pagingRecordList, so it pages no UE in particular. Its only content is cmas-Indication-r9 = true, two levels down the nonCriticalExtension chain, because Rel-9 added it after the Rel-8 Paging message was fixed.

The SIB12 capture shows the CMAS fields in red. The value 0001000100010010 of messageIdentifier-r9 is 1112 hex, or 4370, the CMAS Presidential Level Alert of 23.041 Table 9.4.1.2.2-1. The value 0011000000000000 of serialNumber-r9 is 3000 hex. The whole warning fits in one segment, so warningMessageSegmentType-r9 is lastSegment and warningMessageSegmentNumber-r9 is 0. The dataCodingScheme-r9 value 01 means English in the GSM 7 bit default alphabet (23.038 clause 5).

SIB12 in the Current Release

The capture above is a Rel-9 SIB12, and the IE has grown since then. The listing below is the current definition. Compare it with the capture before you read the field descriptions that follow it.

Following is based on 36.331 v19.3.0 (Release 19)

SystemInformationBlockType12-r9 ::= SEQUENCE {
    messageIdentifier-r9                BIT STRING (SIZE (16)),
    serialNumber-r9                     BIT STRING (SIZE (16)),
    warningMessageSegmentType-r9        ENUMERATED {notLastSegment, lastSegment},
    warningMessageSegmentNumber-r9      INTEGER (0..63),
    warningMessageSegment-r9            OCTET STRING,
    dataCodingScheme-r9                 OCTET STRING (SIZE (1))     OPTIONAL,   -- Cond Segment1
    lateNonCriticalExtension            OCTET STRING                    OPTIONAL,
    ...,
    [[  warningAreaCoordinatesSegment-r15       OCTET STRING    OPTIONAL    -- Need OR
    ]]
}

Rel-15 added warningAreaCoordinatesSegment-r15 in an extension group. It carries the geographical area where the warning is valid, encoded as 23.041 clause 9.3.63 specifies, so the UE can check whether it is inside the alert area. The area is segmented together with the warning message, and warningMessageSegmentNumber and warningMessageSegmentType apply to both.

The field dataCodingScheme-r9 has the condition Segment1, so it is present in the first segment only. The ASN.1 puts no size limit on warningMessageSegment-r9. The SIZE(ALIGNED) in the capture is the decoder's own notation, not a limit from 36.331.

Followings are the description related to warningMessageSegment. (For messageIdentifier, serialNumber, dataCodingScheme, click on the link for the details)

According to 36.331, warningMessageSegmentType, warningMessageSegmentNumber,warningMessageSegment are defined as follows. The descriptions below follow 36.331 v19.3.0.

warningMessageSegment : Carries a segment, with one or more octets, of the Warning Message Contents IE defined in TS 36.413-9.2.1.53. The first octet of the Warning Message Contents IE is equivalent to the first octet of the CB data IE defined in and encoded according to TS 23.041 - 9.4.2.2.5 and so on.

< 36.413-9.2.1.53 Warning Message Contents >

 

IE/Group Name

Prsence

Range

IE Type and Reference

Semantics Description

Warning Message Contents

M

 

OCTET STRING (SIZE(1..9600))

The length of this IE varies between 1 to 9600 bytes.

 

36.413 passes the Warning Message Contents to the eNB as one octet string of up to 9600 octets. Its first octet is the first octet of the CB Data of 23.041 clause 9.4.2.2.5, and 23.041 Table 9.4.2.2.5-1 below gives the layout of that CB Data.

< 23.041-9.4.2.2.5 CB Data >

23.041 Table 9.4.2.2.5-1 CB Data parameters with page count, information pages and lengths

23.041 Table 9.4.2.2.5-1. One octet of page count, then each 82 octet page followed by its one octet length, for up to 15 pages.

  • 84 octets for one page : 1 octet of Number-of-Pages, 82 octets of page and 1 octet of length.
  • Up to 15 pages : the NOTE limits n to 15, so the CB Data is at most 1 + 15 x 83 = 1246 octets.
  • The length counts user information only : 23.041 clause 9.3.20 leaves the padding out of CBS-Message-Information-Length.

warningMessageSegmentNumber : Segment number of the CMAS warning message segment contained in the SIB. A segment number of zero corresponds to the first segment, one corresponds to the second segment, and so on. If warning area coordinates are provided for the warning message, then this field applies to both warning message segment and warning area coordinates segment.

warningMessageSegmentType : Indicates whether the included CMAS warning message segment is the last segment or not. If warning area coordinates are provided for the warning message, then this field applies to both warning message segment and warning area coordinates segment.

warningAreaCoordinatesSegment : If present, carries a segment, with one or more octets, of the geographical area where the CMAS warning message is valid. The first octet of the first warningAreaCoordinatesSegment is equivalent to the first octet of Warning Area Coordinates IE defined in and encoded according to TS 23.041 and so on.

Why segment at all? An SI message goes out in a single transport block, so its size is limited. A long warning, or a warning with area coordinates, can exceed that limit, and the eNB then splits it into up to 64 segments, numbered 0 to 63.

36.331 clause 5.2.2.19 tells the UE how to put the segments back together. The UE collects segments for each pair of messageIdentifier and serialNumber. When all segments have arrived, it forwards the warning to upper layers. It should discard an incomplete set after 3 hours. The eNB also does not interleave two CMAS notifications, so all segments of one notification go out before those of the next (36.331 clause 5.2.1.5).

  • Paging only wakes the UE up : cmas-Indication-r9 carries no UE identity and no warning content.
  • SIB1 points, SIB12 carries : the UE finds SIB12 through schedulingInfoList in SIB1.
  • Message ID and Serial Number identify the warning : 4370 is a Presidential Level Alert, and the Serial Number tells a new warning from a repeat.
  • Segments are reassembled per messageIdentifier and serialNumber : Rel-15 area coordinates follow the same segment numbering.

CMAS Message Sequence Example

The table below puts the three components in the order that a live network sent them. Notice that SIB12 is already on air before the Paging arrives. The Paging only makes the UE read it now, instead of waiting for the next modification period.

 

Step

Direction

Message

Comments

1

UE <-- NW

SIB1

Indicate SIB12 is scheduled

2

UE <-- NW

SIB12

Transmit CMAS message

3

UE <-- NW

Paging

CMAS indication is present

4

UE

 

Detect the Paging with CMAS Indication

5

UE

 

Decode SIB1 and find SIB12 is scheduled

6

UE

 

Decode SIB12

 

NOTE : If you want to get an example of full log for ETWS, check out this tutorial from Amarisoft TechAcademy

According to 36.331-5.3.2.3, the procedure to receiving CMAS is described as follows.

When UE recieved the Paging message,

    • Check if the cmas-Indication is included and the UE is CMAS capable:
      • if true, re-acquire SystemInformationBlockType1 immediately, i.e., without waiting until the next system information modification period boundary;
        • Check if the schedulingInfoList in SIB1 indicates that SystemInformationBlockType12 is present:
          • if true, acquire SystemInformationBlockType12;

The UE does not have to be in RRC_IDLE for this. 36.331 clause 5.2.1.5 uses the Paging message for CMAS capable UEs in RRC_IDLE, and in RRC_CONNECTED for UEs other than BL UEs, UEs in CE and NB-IoT UEs. A BL UE or a UE in CE in RRC_CONNECTED gets the same indication as Direct Indication information on MPDCCH, where bit 3 is cmas-Indication (36.331 clause 6.6).

Step 1 - SIB 1

SIB1 decides whether the UE looks for SIB12 at all. In this capture, the third entry of schedulingInfoList maps sibType12-v920 to an SI message with si-Periodicity rf32. The decoder marks that line in red.

Decoded SIB1 from a live capture, shown as the decoder printed it. The values are what one network sent, not what the specification requires.

BCCH-DL-SCH-Message
    message: c1 (0)
        c1: systemInformationBlockType1 (1)
            systemInformationBlockType1
                cellAccessRelatedInfo
                    plmn-IdentityList: 1 item
                        Item 0
                            PLMN-IdentityInfo
                                plmn-Identity
                                    mcc: 3 items
                                        Item 0
                                            MCC-MNC-Digit: 0
                                        Item 1
                                            MCC-MNC-Digit: 0
                                        Item 2
                                            MCC-MNC-Digit: 1
                                    mnc: 2 items
                                        Item 0
                                            MCC-MNC-Digit: 0
                                        Item 1
                                            MCC-MNC-Digit: 1
                                cellReservedForOperatorUse: notReserved (1)
                    trackingAreaCode: 0000 [bit length 16, 0000 0000  0000 0000 decimal value 0]
                    cellIdentity: 00000000
                    cellBarred: notBarred (1)
                    intraFreqReselection: notAllowed (1)
                    .... ..0. csg-Indication: False
                cellSelectionInfo
                    q-RxLevMin: -110dBm (-55)
                p-Max: 23dBm
                freqBandIndicator: 4
                schedulingInfoList: 3 items
                    Item 0
                        SchedulingInfo
                            si-Periodicity: rf16 (1)
                            sib-MappingInfo: 0 items
                    Item 1
                        SchedulingInfo
                            si-Periodicity: rf32 (2)
                            sib-MappingInfo: 1 item
                                Item 0
                                    SIB-Type: sibType3 (0)
                    Item 2
                        SchedulingInfo
                            si-Periodicity: rf32 (2)
                            sib-MappingInfo: 1 item
                                Item 0
                                    SIB-Type: sibType12-v920 (9)
                si-WindowLength: ms20 (5)
                systemInfoValueTag: 0
                nonCriticalExtension
                    nonCriticalExtension
                        ims-EmergencySupport-r9: true (0)

rf32 means the SI message repeats every 32 radio frames, which is 320 ms, inside a 20 ms SI window, si-WindowLength ms20. So a UE that reacts to the Paging finds SIB12 within one SI period. The last field, ims-EmergencySupport-r9, is not part of CMAS. It tells the UE that the cell supports IMS emergency calls.

Step 2 - SIB 12

This is the warning itself. The value 4370 of messageIdentifier-r9 marks a Presidential Level Alert, which 23.041 lists as not settable by MMI, so the user cannot switch it off. The Serial Number gives Geographical Scope 0, cell wide with immediate display, Message Code 768 and Update Number 0.

Decoded SIB12 from a live capture, shown as the decoder printed it. The values are what one network sent, not what the specification requires.

BCCH-DL-SCH-Message
    message: c1 (0)
        c1: systemInformation (0)
            systemInformation
                criticalExtensions: systemInformation-r8 (0)
                    systemInformation-r8
                        sib-TypeAndInfo: 1 item
                            Item 0
                                sib-TypeAndInfo item: sib12-v920 (10)
                                    sib12-v920
                                        messageIdentifier-r9: CMAS Identifier for CMAS Presidential Level Alerts (4370)
                                        serialNumber-r9: 3000 [bit length 16, 0011 0000  0000 0000 decimal value 12288]
                                            00.. .... .... .... = Geographical Scope: Display mode immediate, cell wide (0)
                                            ..11 0000 0000 .... = Message Code: 768
                                            .... .... .... 0000 = Update Number: 0
                                        warningMessageSegmentType-r9: lastSegment (1)
                                        warningMessageSegmentNumber-r9: 0
                                        warningMessageSegment-r9: 0154747a0e4acf416137a8d82ecbcf65f7388...
                                        dataCodingScheme-r9: 01
                                            0000 .... = Coding Group: Coding Group 0
                                                             (Language using the GSM 7 bit default alphabet) (0)
                                            .... 0001 = Language: English (1)

The decoder shortens warningMessageSegment-r9 with '...', so the text of this warning cannot be read from the capture. The next section shows a SIB12 with the full segment.

Step 3 - Paging

The Paging message comes last in this log. It carries cmas-Indication-r9 = true and nothing else. So any CMAS capable UE that reads this Paging message re-acquires SIB1 at once, and then acquires SIB12.

Decoded Paging message from a live capture, shown as the decoder printed it. The values are what one network sent, not what the specification requires.

PCCH-Message
    message: c1 (0)
        c1: paging (0)
            paging
                nonCriticalExtension
                    nonCriticalExtension
                        cmas-Indication-r9: true (0)
                            [Expert Info (Warn/Sequence): Commercial Mobile Alert System Indication!]
                                [Commercial Mobile Alert System Indication!]
                                [Severity level: Warn]
                                [Group: Sequence]

NOTE : This paing would not carry specific UE ID since this Paging is broadcasting (i.e, for every UE in the cell)

  • SIB12 can be on air before the Paging : the Paging tells the UE to look now, not that the warning starts now.
  • The UE re-acquires SIB1 at once : it does not wait for the modification period boundary (36.331 clause 5.3.2.3).
  • BL UEs and UEs in CE use Direct Indication in connected mode : bit 3 of the Direct Indication information on MPDCCH is cmas-Indication.

Additional Examples of SIB 12 Message

This second SIB12 capture shows the full warningMessageSegment in hex. With the full hex, you can decode the CB Data by hand and see where the text, the padding and the length octet sit.

Example 01

The decode below comes from the same kind of log as Step 2, but the Update Number is 7 and the segment is complete. The two hex dumps after it are the whole BCCH message and the warningMessageSegment-r9 alone.

Decoded SIB12 from a live capture, shown as the decoder printed it. The values are what one network sent, not what the specification requires.

BCCH-DL-SCH-Message
    message: c1 (0)
        c1: systemInformation (0)
            systemInformation
                criticalExtensions: systemInformation-r8 (0)
                    systemInformation-r8
                        sib-TypeAndInfo: 1 item
                            Item 0
                                sib-TypeAndInfo item: sib12-v920 (10)
                                    sib12-v920
                                        messageIdentifier-r9:
                                               CMAS Identifier for CMAS Presidential Level Alerts (4370)
                                        serialNumber-r9: 3007
                                               [bit length 16, 0011 0000  0000 0111 decimal value 12295]
                                            00.. .... .... .... = Geographical Scope:
                                                Display mode immediate, cell wide (0)
                                            ..11 0000 0000 .... = Message Code: 768
                                            .... .... .... 0111 = Update Number: 7
                                        warningMessageSegmentType-r9: lastSegment (1)
                                        warningMessageSegmentNumber-r9: 0
                                        warningMessageSegment-r9:
                                           01c576597e2ebbc7f950a8d168341a8d46a3d168341a8d46...
                                            [1 Fragment (84 bytes): #1(84)]
                                                [Frame: 1, payload: 0-83 (84 bytes)]
                                                [Fragment Count: 1]
                                                [Reassembled Length: 84]
                                                [Reassembled Data:
                                                    01c576597e2ebbc7f950a8d168341a8d46a3d168341a8d46...]
                                        dataCodingScheme-r9: 01
                                            0000 .... = Coding Group:
                                             Coding Group 0(Language using the GSM 7 bit default alphabet)(0)
                                            .... 0001 = Language: English (1)

HEX (BCCH) :

Hex dump of the BCCH-DL-SCH message from the same capture. The octets are what one network sent.

00 40 2E 21 11 23 00 78 0A 80 38 AE CB 2F C5 D7 78 FF 2A 15 1A 2D 06 83 51 A8 D4 7A 2D 06 83 51 A8
D4 7A 2D 06 83 51 A8 D4 7A 2D 06 83 51 A8 D4 7A 2D 06 83 51 A8 D4 7A 2D 06 83 51 A8 D4 7A 2D 06 83
51 A8 D4 7A 2D 06 83 51 A8 D4 7A 2D 06 83 51 A8 D4 7A 2D 06 83 51 A8 D4 7A 20 01 40 20 00

HEX (warningMessageSegment-r9) :

Hex dump of warningMessageSegment-r9 from the same capture. The octets are what one network sent.

01 C5 76 59 7E 2E BB C7 F9 50 A8 D1 68 34 1A 8D 46 A3 D1 68 34 1A 8D 46 A3 D1 68 34 1A 8D 46 A3 D1
68 34 1A 8D 46 A3 D1 68 34 1A 8D 46 A3 D1 68 34 1A 8D 46 A3 D1 68 34 1A 8D 46 A3 D1 68 34 1A 8D 46
A3 D1 68 34 1A 8D 46 A3 D1 68 34 1A 8D 46 A3 D1 00 0A

    => According to 23.041-9.4.2.2.5 CB Data, the decoded result is as follows

      01 : Number of Page = 1

      0A : Message Information Length = 10

      Contents of the Message : C5 76 59 7E 2E BB C7 F9 50 A8  ==> Emergency!!

Let's check that decoding against 23.041 Table 9.4.2.2.5-1. The segment is 84 octets: 01 for Number-of-Pages, 82 octets of page, and 0A as the length octet. So the length is 10 octets. The text Emergency!! has 11 characters, and 11 characters of 7 bits fill 77 bits, which ends inside the 10th octet. 23.041 clause 9.3.20 counts the octets up to that boundary, so the length is 10 while the character count is 11.

After the text, the page repeats D1 68 34 1A 8D 46 A3. That is the 7-bit character CR, packed again and again. 23.038 pads a Cell Broadcast page with CR characters, and 82 octets hold 93 characters with 5 zero bits left over, which is why the page ends in 00. The UE drops the padding with the help of the length octet.

  • One page, 10 octets of text : Number-of-Pages = 01 and length = 0A, which is 10.
  • 11 characters in 10 octets : the GSM 7 bit default alphabet packs 8 characters into 7 octets.
  • CR fills the rest of the page : the repeating D1 68 34 1A 8D 46 A3 is padding, not message text.
  • Serial Number 3007 : Geographical Scope 0, Message Code 768 and Update Number 7, so the same warning has been updated seven times since Update Number 0.

Decoding / Encoding the warningMessageSegment

The contents of CMAS(warningMessageSegment) is encoded in various different method as described in DCS page. Since there are too many different coding scheme, it would be hard to find a tool that can encode/decode every coding scheme. But if the message uses the two most common coding scheme called GSM 7bit and UCS, you can use the on-line tool called SMS Server Tools 3. As the name implies, this tool is not specifically designed for CMAS. It is designed for encoding / decoding SMS. But the coding scheme for SMS and CMAS is similar, you can use this tool to encode / decode CMAS message.

Here goes short tips on how to use this tool.

Encoding - Text To HEX, GSM 7 bit

The encoder side is useful when you build a test CMAS message for a test system. The screenshot below follows the five steps of the list, and the circled numbers match the steps.

    (1) Select '7' at Alphabet Size

    (2) type in the text you want to send as CMAS message

    (3) press [Convert>] button

    (4) the resulting AT command to send this message

    (5) the resulting HEX string for the message

SMS Server Tools 3 PDU creator encoding the text Emergency!! as GSM 7 bit packed hex

Encoding Emergency!! with the 7 bit alphabet. The USSD box gives the packed hex C576597E2EBBC7F95008.

  • Characters: 11 / 160 : the tool counts 11 characters, the same count as the decoded capture.
  • The AT command in box 4 is for SMS : for CMAS, only the packed hex in box 5 matters.
  • The last octet reads 08 here and A8 in the capture : the tool fills the last 3 bits with zeros. In the capture, those bits hold the start of the first CR padding character. Both versions decode to the same 11 characters.

Decoding - HEX to Text, GSM 7 bit

The decoder side is the one you need when a log shows only hex. Paste only the octets that the length octet counts, not the whole page. Otherwise the result also shows the CR padding characters.

    (1) Select '7' at Alphabet Size

    (2) Select 'GSM 7bit packed'

    (3) type in HEX string for the text you want to send as CMAS message

    (4) press [Convert>] button

    (5) the result text

SMS Server Tools 3 decoding GSM 7 bit packed hex into the text Emergency!!

Decoding C5 76 59 7E 2E BB C7 F9 50 A8, the 10 octets that the length octet names. The result is Emergency!! with Length 11.

  • Length: 11 counts characters : the input is 10 octets, the output 11 characters.
  • Select GSM 7bit packed : the same hex read as UCS2 gives different text.
  • The tool works for CMAS : SMS and CMAS use the same 7 bit packing, although a CBS page adds CR padding.

Reference

[1] Appendix: GSM 7-bit Default Alphabet Table (with Character Codes of ISO 8859 Latin 1)

[2] SMS Server Tools 3

[3] 3GPP TS 36.331 v19.3.0 - clauses 5.2.1.5, 5.2.2.19, 5.3.2.3 and 6.6, SystemInformationBlockType12 and Paging

[4] 3GPP TS 36.413 v19.2.0 - clause 9.2.1.53, Warning Message Contents

[5] 3GPP TS 23.041 v20.0.0 - clauses 9.3.19, 9.3.20, 9.4.1.2.2 and 9.4.2.2.5, CBS message parameters and CB Data

[6] 3GPP TS 23.038 v20.0.0 - clauses 5 and 6.1.2.2, CBS Data Coding Scheme and CBS packing