This page walks through a successful LTE NB-IoT attach over a simulated non-terrestrial network. The decoded messages come from an Amarisoft Callbox sample and show how Release 17 NTN assistance is added to the established NB-IoT and EPC procedures.
NOTE: The excerpts retain the fields needed to explain the procedure and omit temporary UE identity and NAS security data. Amarisoft provides the associated interactive sample-log tutorial.
Test Profile
The test profile establishes the radio, network, UE, and bearer context for the sample. These values describe this simulated trace and are not universal configuration requirements for NB-IoT NTN deployments.
Item | Value observed in the sample |
|---|---|
Radio access | LTE NB-IoT with Release 17 NTN extensions, operating in band 7 |
Network identity | PLMN 001/01, tracking area code 0002 |
NTN assistance | SIB31-NB orbital ephemeris, common NTA, uplink synchronization validity, and K offset |
UE capability | Release 17, NB1/NB2 capability, multi-tone support, NTN EPC connectivity, and NTN TA reporting |
Core and bearer | EPC attach with EPS bearer identity 5 mapped to DRB1 |
Call Flow Overview
The overview follows system-information acquisition, narrowband random access, RRC establishment, EPS authentication and security, UE capability exchange, bearer configuration, and completion of the EPC attach.
Step |
Phase |
Direction |
Message |
|---|---|---|---|
System information | Network to UE | MIB-NB | |
System information | Network to UE | SIB1-NBNTN: SIB1-NB schedules SIB31-NB and separately marks the NTN cell as not barred. | |
System information | Network to UE | SIB2-NBNTN: The common configuration enables TA reporting and sets the Release 17 RLF timer | |
System information | Network to UE | SIB31-NBNTN: SIB31-NB broadcasts satellite ephemeris, common NTA, uplink synchronization validity, and | |
Random access | UE to Network | NPRACH preambleNTN: The UE applies SIB31-NB timing and satellite-motion assistance before transmitting NPRACH. | |
Random access | Network to UE | Random Access ResponseNTN: The RAR provides the residual TA correction and Msg3 uplink grant after NTN pre-compensation. | |
RRC connection | UE to Network | RRCConnectionRequest-NBNTN: The RRC payload has no NTN-specific IE; transmission uses the NTN-adjusted uplink timing. | |
RRC connection | Network to UE | RRCConnectionSetup-NBNTN-related: Long RLC timers and an infinite time-alignment timer accommodate the satellite delay; these are not NTN-specific IEs. | |
NTN timing | UE to Network | TA_REPORT MAC CENTN: The UE reports its UE-specific timing contribution as enabled by SIB2-NB. | |
RRC connection | UE to Network | RRCConnectionSetupComplete-NB carrying Attach Request | |
EPS security | UE and Network | Authentication and Security Mode procedures | |
NTN timing | Network to UE | K_OFFSET MAC CENTN: The network sends a UE-specific scheduling offset; the decoded MAC CE reports | |
Capability | Network to UE | UECapabilityEnquiry-NB | |
Capability | UE to Network | UECapabilityInformation-NBNTN: The UE explicitly reports EPC connectivity over NTN and NTN TA-report support. | |
Bearer setup | Network to UE | RRCConnectionReconfiguration-NBNTN: The network configures | |
NTN timing | UE to Network | TA_REPORT MAC CENTN: A further TA report follows the dedicated offset-threshold configuration. | |
Bearer setup | UE to Network | RRCConnectionReconfigurationComplete-NB | |
Attach | UE and Network | Attach completion |
Detailed Message Sequence
The following sections expand the overview with selected decoded fields from the legacy sample. They distinguish standard NB-IoT and EPC signaling from Release 17 NTN system information, MAC control elements, and UE capabilities.
1. MIB-NB, SIB1-NB, SIB2-NB, and SIB31-NB
After acquiring MIB-NB, the UE decodes SIB1-NB for cell access and system-information scheduling. SIB1-NB schedules SIB31-NB and provides a separate NTN cell-barred indication. SIB2-NB configures the normal NB-IoT radio resources plus common NTN TA reporting. SIB31-NB supplies the satellite and timing assistance.
{
"SIB1-NB": {
"plmn": "001/01",
"trackingAreaCode-r13": "0002",
"cellIdentity-r13": "1A2D102",
"cellBarred-r13": "barred",
"freqBandIndicator-r13": 7,
"sib-MappingInfo-v1530": ["sibType31-NB-r17"],
"cellAccessRelatedInfo-NTN-r17": {
"cellBarred-NTN-r17": "notBarred"
}
},
"SIB2-NB": {
"timeAlignmentTimerCommon-r13": "infinity",
"ntn-ConfigCommon-r17": {
"ta-Report-r17": "enabled",
"t318-r17": "ms2000"
}
},
"SIB31-NB-r17": {
"servingSatelliteInfo-r17": {
"ephemerisInfo-r17": {
"type": "orbitalParameters",
"semiMajorAxis-r17": 8394210402,
"eccentricity-r17": 0,
"periapsis-r17": 0,
"longitude-r17": 242097885,
"inclination-r17": 0,
"anomaly-r17": 193139
},
"nta-CommonParameters-r17": {
"nta-Common-r17": 7776350
},
"ul-SyncValidityDuration-r17": "s240",
"k-Offset-r17": 1023
}
}
}
cellBarred-NTN-r17allows NTN access even though the terrestrial NB-IoT cell-barred field is set.nta-Common-r17provides the network timing advance common to UEs in the satellite service area.- The orbital ephemeris and
ul-SyncValidityDuration-r17let the UE maintain uplink timing and frequency pre-compensation for the advertised interval. k-Offset-r17extends NB-IoT scheduling timelines for the satellite round-trip delay.
2. NPRACH and Random Access Response
The UE starts random access with an NPRACH preamble after applying the SIB31-NB assistance. The network detects preamble index 8 with TA 25 and returns a RAR containing the residual timing correction, Msg3 grant, and temporary C-RNTI.
{
"NPRACH": {
"n_init": 8,
"ta": 25,
"snr": 41.3,
"configId": 0,
"repetitions": 1,
"subframes": 6,
"startingSubcarrier": 0
},
"RandomAccessResponse": {
"rapid": 8,
"timingAdvance": 25,
"uplinkGrant": {
"subcarrierSpacing": 1,
"i_sc": 0,
"i_delay": 0,
"i_rep": 0,
"mcs": 2
},
"temporaryCRnti": "0x0101"
}
}
3. RRC connection establishment
The UE sends RRCConnectionRequest-NB on Msg3 with a mobile-originated signaling cause. The network answers with RRCConnectionSetup-NB, establishing the signaling bearer and dedicated NPDCCH, RLC, and MAC parameters.
{
"RRCConnectionRequest-NB": {
"establishmentCause-r13": "mo-Signalling",
"multiToneSupport-r13": true,
"earlyContentionResolution-r14": true,
"cqi-NPDCCH-r14": "noMeasurements"
},
"RRCConnectionSetup-NB": {
"rrc-TransactionIdentifier": 0,
"srbToAdd": [1],
"rlcConfig": {
"mode": "AM",
"t-PollRetransmit-r13": "ms6000",
"maxRetxThreshold-r13": "t32"
},
"macMainConfig": {
"periodicBSR-Timer-r13": "pp16",
"retxBSR-Timer-r13": "pp64",
"timeAlignmentTimerDedicated-r13": "infinity"
},
"npdcchConfigDedicated": {
"repetitions": "r8",
"startSubframe": "v4",
"offset": "zero"
}
}
}
4. Initial TA Report and RRCConnectionSetupComplete-NB
With TA reporting enabled in SIB2-NB, the UE sends a TA_REPORT MAC CE after RRC setup. It then confirms the connection and carries the EPS Attach Request in RRCConnectionSetupComplete-NB. The source page identifies the TA_REPORT occurrence but does not expose its decoded numeric payload.
{
"TA_REPORT": {
"protocol": "MAC CE",
"direction": "UL",
"occurrence": "after RRCConnectionSetup-NB",
"decodedValue": "not shown in source excerpt"
},
"RRCConnectionSetupComplete-NB": {
"direction": "UL",
"dedicatedInfoNAS": "AttachRequest"
}
}
5. EPS authentication and security
The EPC performs the normal EPS authentication and NAS security procedures, followed by access-stratum security activation. These messages do not add NTN-specific IEs; they are transported over the timing-adjusted NB-IoT radio connection.
Direction | Message |
|---|---|
Network to UE | Authentication Request |
UE to Network | Authentication Response |
Network to UE | NAS Security Mode Command |
UE to Network | NAS Security Mode Complete |
Network to UE | RRC SecurityModeCommand-NB |
UE to Network | RRC SecurityModeComplete-NB |
6. K_OFFSET MAC CE
The network sends the Release 17 K_OFFSET MAC CE to update the UE-specific scheduling offset after access. This complements the cell-level K offset broadcast in SIB31-NB.
{
"K_OFFSET": {
"protocol": "MAC CE",
"direction": "DL",
"value": 63,
"macSubPdus": [
{ "lcid": 3, "length": 2 },
{ "lcid": 3, "length": 41 },
{ "type": "padding", "length": 3 }
]
}
}
7. UE capability exchange
The network requests the NB-IoT capability container. The UE reports Release 17 support, NB-IoT category and RF features, plus the NTN capabilities needed for EPC connectivity and TA reporting.
{
"UECapabilityInformation-NB": {
"accessStratumRelease-r13": "rel17",
"ue-Category-NB-r13": "nb1",
"ue-Category-NB-r14": "nb2",
"multipleDRB-r13": "supported",
"multiTone-r13": "supported",
"supportedBandList-r13": [
{
"band-r13": 7,
"powerClassNB-20dBm-r13": "supported"
}
],
"rlc-UM-r15": "supported",
"nprach-Format2-r15": "supported",
"ntn-Parameters-r17": {
"ntn-Connectivity-EPC-r17": "supported",
"ntn-TA-Report-r17": "supported"
}
}
}
8. RRC reconfiguration, TA Report, and completion
The network creates EPS bearer 5 on DRB1 and supplies dedicated PDCP, RLC, logical-channel, and MAC parameters. The Release 17 TA-offset threshold controls when the UE sends the next TA_REPORT MAC CE.
{
"RRCConnectionReconfiguration-NB": {
"rrc-TransactionIdentifier": 0,
"drbToAdd": [
{
"eps-BearerIdentity-r13": 5,
"drb-Identity-r13": 1,
"logicalChannelIdentity-r13": 4,
"pdcpConfig": {
"discardTimer-r13": "infinity",
"headerCompression-r13": "notUsed"
},
"rlcConfig": {
"mode": "AM",
"t-PollRetransmit-r13": "ms6000",
"maxRetxThreshold-r13": "t32"
}
}
],
"macMainConfig": {
"timeAlignmentTimerDedicated-r13": "infinity",
"offsetThresholdTA-r17": {
"action": "setup",
"value": "ms1"
}
}
},
"TA_REPORT": {
"direction": "UL",
"trigger": "configured TA offset threshold"
},
"RRCConnectionReconfigurationComplete-NB": {
"direction": "UL"
}
}
9. Attach completion
After radio-bearer reconfiguration completes, the UE finishes the EPS attach exchange. The UE is registered with the EPC and DRB1 is available for NB-IoT user-plane traffic over the NTN radio link.
What Is NTN-Specific in This Flow?
Most RRC establishment, EPS security, and bearer-management signaling is inherited from terrestrial NB-IoT. The table below isolates the Release 17 assistance and MAC behavior that adapts the procedure to a moving satellite link.
Feature | Where it appears | Purpose |
|---|---|---|
SIB31-NB | Before random access | Broadcasts satellite ephemeris, common NTA, synchronization validity, and cell K offset. |
NTN cell access | SIB1-NB | Separates NTN cell availability from the terrestrial NB-IoT cell-barred indication. |
Common TA reporting | SIB2-NB | Enables UE-specific TA reports and configures the NTN RLF timer. |
TA_REPORT MAC CE | After RRC setup and reconfiguration | Reports the UE-specific component of the NTN uplink timing correction. |
K_OFFSET MAC CE | After security activation | Updates the UE-specific scheduling offset used with the satellite propagation delay. |
NTN UE capability | UECapabilityInformation-NB | Declares NTN EPC connectivity and TA-report support. |
Dedicated TA threshold | RRCConnectionReconfiguration-NB | Controls when timing change is large enough to trigger another TA report. |
Delay-oriented timers | RRC setup and reconfiguration | Long RLC timers and infinite alignment timers tolerate the extended link delay; they are not NTN-specific IEs. |
References
The following ShareTechnote material and 3GPP specifications provide the protocol definitions and supporting background for the decoded LTE RRC, MAC, EPS NAS, and S1AP procedures used in this analysis.
- LTE NB-IoT NTN system information - SIB31-NB serving-satellite information and related timing fields.
- NR NTN Call Flow - corresponding 5G NR Standalone procedure.
- 3GPP TS 36.331 - E-UTRA Radio Resource Control protocol.
- 3GPP TS 36.321 - E-UTRA Medium Access Control protocol.
- 3GPP TS 24.301 - EPS NAS protocol.
- 3GPP TS 36.413 - S1 Application Protocol.
Selected decoded fields are taken from the original Amarisoft NB-IoT NTN sample represented by this page. Values vary with satellite orbit, service link, UE implementation, and network configuration.