When a UMTS UE sets up an RRC connection, it tells the RNC what it can do. The RNC needs this information before it configures radio bearers, HSPA channels, compressed mode or inter-RAT mobility. This page takes one real capability report from a protocol analyzer log and reads it field by field. The UE in the log supports HSDPA category 14, HSUPA category 6, four UMTS bands, GSM and E-UTRA FDD. Let's first see which message carries the report, and then go through the capture.
- Where does a UMTS UE send its capability ?
- What does the captured RRC Connection Setup Complete carry ?
- Why is the capability spread over so many extension containers ?
- What do the fields in red tell the network ?
- What do the band, security and inter-RAT fields tell the network ?
- Reference
Where does a UMTS UE send its capability ?
A UMTS UE has two ways to deliver its capability, and the capture on this page uses the first one. The message that carries the report decides when the RNC gets it and what the RNC can ask for later.
The first way is the RRC CONNECTION SETUP COMPLETE message. 25.331 clause 8.1.3.6 tells the UE to put its UTRA capability into the IE "UE radio access capability" and its extension. The same clause puts the capability for other systems into the IE "UE system specific capability". So the RNC has the capability as soon as the RRC connection exists, before any NAS message runs over it.
The RNC decides what goes into this report. The RRC CONNECTION SETUP message carries the IE "Capability update requirement" (clause 10.3.3.2). This IE says whether the UE sends its FDD capability. It also lists the other systems whose capability the network wants, which can be GSM, GERAN Iu or E-UTRA. If the IE is absent, the default values request nothing. Clause 8.6.3.12 describes how the UE builds the variable UE_CAPABILITY_REQUESTED from this IE.
The second way is the UE CAPABILITY INFORMATION message (clause 8.1.6). The UE sends it when the RNC asks with a UE CAPABILITY ENQUIRY. The UE can also send it without a request, in CELL_DCH or CELL_FACH, when its capability changes. For this, the RNC must have indicated that it supports such a change. After sending it, the UE starts timer T304 and waits for UE CAPABILITY INFORMATION CONFIRM.
RRC CONNECTION SETUP COMPLETE also carries one item that is not a capability: the START list. The UE sends one 20 bit START value per CN domain. Clause 10.3.3.38 uses START to initialise the 20 most significant bits of every hyper frame number in that domain. These HFNs feed the COUNT-C and COUNT-I values for ciphering and integrity protection. When neither a USIM nor a SIM is present, the UE sets every START to zero.
The capability normally arrives with RRC connection setup : RRC CONNECTION SETUP COMPLETE carries it, so the RNC has it before the first NAS message.The network chooses what the UE reports : the IE "Capability update requirement" in RRC CONNECTION SETUP selects FDD and the other systems.UE CAPABILITY INFORMATION is the second path : it answers a UE CAPABILITY ENQUIRY or reports a change, and T304 guards it.START is security state, not capability : it sets the upper 20 bits of the HFNs for each CN domain.
What does the captured RRC Connection Setup Complete carry ?
The capture below is a single UL-DCCH message, decoded by a protocol analyzer. It runs to more than 500 lines, so it helps to know its layout before reading it.
The message opens with the transaction identifier and the START list. Both START values are 2, one for the CS domain and one for the PS domain. The Release 99 capability follows in ue-RadioAccessCapability, from pdcp-Capability down to ue-positioning-Capability. Next comes ue-RATSpecificCapability, which holds the GSM classmarks. Everything after that sits inside nested non-critical extensions, and a later section explains that structure. The field names in red are the ones that the section on highlighted fields discusses.
Decoded RRC message from a protocol analyzer log,
UL-DCCH-Message
message: rrcConnectionSetupComplete (18)
rrcConnectionSetupComplete
rrc-TransactionIdentifier: 0
startList: 2 items
Item 0
STARTSingle
cn-DomainIdentity: cs-domain (0)
start-Value: 000020 [bit length 20, 4 LSB pad bits, 0000 0000 0000 0000 0010 .... decimal value 2]
Item 1
STARTSingle
cn-DomainIdentity: ps-domain (1)
start-Value: 000020 [bit length 20, 4 LSB pad bits, 0000 0000 0000 0000 0010 .... decimal value 2]
ue-RadioAccessCapability
pdcp-Capability
0... .... losslessSRNS-RelocationSupport: False
supportForRfc2507: notSupported (0)
notSupported: NULL
rlc-Capability
totalRLC-AM-BufferSize: kb1000 (6)
maximumRLC-WindowSize: mws2047 (0)
maximumAM-EntityNumber: am16 (5)
transportChannelCapability
dl-TransChCapability
maxNoBitsReceived: b6400 (5)
maxConvCodeBitsReceived: b6400 (5)
turboDecodingSupport: supported (1)
supported: b6400 (5)
maxSimultaneousTransChs: e8 (1)
maxSimultaneousCCTrCH-Count: 1
maxReceivedTransportBlocks: tb32 (3)
maxNumberOfTFC: tfc128 (5)
maxNumberOfTF: tf64 (1)
ul-TransChCapability
maxNoBitsTransmitted: b6400 (5)
maxConvCodeBitsTransmitted: b6400 (5)
turboEncodingSupport: supported (1)
supported: b6400 (5)
maxSimultaneousTransChs: e8 (2)
modeSpecificInfo: fdd (0)
fdd: NULL
maxTransmittedBlocks: tb32 (4)
maxNumberOfTFC: tfc64 (5)
maxNumberOfTF: tf64 (1)
rf-Capability
physicalChannelCapability
fddPhysChCapability
downlinkPhysChCapability
maxNoDPCH-PDSCH-Codes: 1
maxNoPhysChBitsReceived: b9600 (6)
.... .0.. supportForSF-512: False
.... ..0. dummy: False
dummy2: notSupported (0)
notSupported: NULL
uplinkPhysChCapability
maxNoDPDCH-BitsTransmitted: b9600 (4)
.... 0... dummy: False
ue-MultiModeRAT-Capability
multiRAT-CapabilityList
.... .1.. supportOfGSM: True
.... ..0. supportOfMulticarrier: False
multiModeCapability: fdd (1)
securityCapability
cipheringAlgorithmCap: 0003 [bit length 16, 0000 0000 0000 0011 decimal value 3]
integrityProtectionAlgorithmCap: 0002 [bit length 16, 0000 0000 0000 0010 decimal value 2]
ue-positioning-Capability
.1.. .... standaloneLocMethodsSupported: True
..0. .... ue-BasedOTDOA-Supported: False
networkAssistedGPS-Supported: bothNetworkAndUE-Based (2)
.... .0.. supportForUE-GPS-TimingOfCellFrames: False
.... ..0. supportForIPDL: False
ue-RATSpecificCapability: 1 item
Item 0
InterRAT-UE-RadioAccessCapability: gsm (0)
gsm
gsm-Classmark2: 33035758a6
0... .... = Spare: 0
.10. .... = Revision Level: Used by mobile stations supporting R99 or later versions of the protocol (2)
...1 .... = ES IND: Controlled Early Classmark Sending option is implemented in the MS
.... 0... = A5/1 algorithm supported: encryption algorithm A5/1 available
.... .111 = RF Power Capability: RF Power capability is irrelevant in this information element (7)
0... .... = Spare: 0
.1.. .... = PS capability (pseudo-synchronization capability): PS capability present
..01 .... = SS Screening Indicator: Capability of handling of ellipsis notation
and phase 2 error handling (1)
.... 1... = SM capability (MT SMS pt to pt capability): Mobile station supports mobile terminated point
to point SMS
.... .0.. = VBS notification reception: no VBS capability or no notifications wanted
.... ..0. = VGCS notification reception: no VGCS capability or no notifications wanted
.... ...0 = FC Frequency Capability: The MS does not support the E-GSM or R-GSM band
1... .... = CM3: The MS supports options that are indicated in classmark 3 IE
.0.. .... = Spare: 0
..1. .... = LCS VA capability (LCS value added location request notification capability):
LCS value added location request notification capability supported
...0 .... = UCS2 treatment: the ME has a preference for the default alphabet
.... 0... = SoLSA: The ME does not support SoLSA
.... .1.. = CMSP: CM Service Prompt: Network initiated MO CM connection request
supported for at least one CM protocol
.... ..1. = A5/3 algorithm supported: encryption algorithm A5/3 available
.... ...0 = A5/2 algorithm supported: encryption algorithm A5/2 not available
gsm-Classmark3: 601404ef652302002424
0... .... = Spare bit(s): 0
.110 .... = Multiband supported field: 6
.1.. .... = GSM 1800 Supported: true
..1. .... = E-GSM or R-GSM Supported: true
...0 .... = P-GSM Supported: false
.... 0000 = A5 bits: 0x00
.... 0... = A5/7 algorithm supported: encryption algorithm A5/7 not available
.... .0.. = A5/6 algorithm supported: encryption algorithm A5/6 not available
.... ..0. = A5/5 algorithm supported: encryption algorithm A5/5 not available
.... ...0 = A5/4 algorithm supported: encryption algorithm A5/4 not available
0001 .... = Associated Radio Capability 2: 1
.... 0100 = Associated Radio Capability 1: 4
0... .... = R Support: false
.0.. .... = HSCSD Multi Slot Capability: false
..0. .... = UCS2 treatment: the ME has a preference for the default alphabet
...0 .... = Extended Measurement Capability: false
.... 0... = MS measurement capability: false
.... .1.. = MS Positioning Method Capability present: true
.... ..00 111. .... = MS Positioning Method: 0x07
.... ..0. = MS assisted E-OTD: MS assisted E-OTD not supported
.... ...0 = MS based E-OTD: MS based E-OTD not supported
1... .... = MS assisted GPS: MS assisted GPS supported
.1.. .... = MS based GPS: MS based GPS supported
..1. .... = MS Conventional GPS: Conventional GPS supported
...0 .... = ECSD Multi Slot Capability present: false
.... 1... = 8-PSK Struct present: true
.... .111 0110 .... = 8-PSK Struct: 0x76
.... .1.. = Modulation Capability: 8-PSK supported for uplink transmission and downlink reception
.... ..1. = 8-PSK RF Power Capability 1 present: true
.... ...1 0... .... = 8-PSK RF Power Capability 1: Power class E2 (0x02)
.1.. .... = 8-PSK RF Power Capability 2 present: true
..10 .... = 8-PSK RF Power Capability 2: Power class E2 (0x02)
.... 0... = GSM 400 Band Information present: false
.... .1.. = GSM 850 Associated Radio Capability present: true
.... ..01 00.. .... = GSM 850 Associated Radio Capability: 0x04
..1. .... = GSM 1900 Associated Radio Capability present: true
...0 001. = GSM 1900 Associated Radio Capability: 0x01
.... ...1 = UMTS FDD Radio Access Technology Capability: UMTS FDD supported
0... .... = UMTS 3.84 Mcps TDD Radio Access Technology Capability: UMTS 3.84 Mcps TDD not supported
.0.. .... = CDMA 2000 Radio Access Technology Capability: CDMA 2000 not supported
..0. .... = DTM E/GPRS Multi Slot Information present: false
...0 .... = Single Band Support: false
.... 0... = GSM 750 Associated Radio Capability present: false
.... .0.. = UMTS 1.28 Mcps TDD Radio Access Technology Capability: UMTS 1.28 Mcps TDD not supported
.... ..1. = GERAN Feature Package 1: GERAN feature package 1 supported
.... ...0 = Extended DTM E/GPRS Multi Slot Information present: false
0... .... = High Multislot Capability present: false
.0.. .... = GERAN Iu Mode Support: false
..0. .... = GERAN Feature Package 2: GERAN feature package 2 not supported
...0 0... = GMSK Multislot Power Profile: GMSK_MULTISLOT_POWER_PROFILE 0 (0)
.... .00. = 8-PSK Multislot Power Profile: 8-PSK_MULTISLOT_POWER_PROFILE 0 (0)
.... ...0 = T-GSM 400 Band Information present: false
0... .... = T-GSM 900 Associated Radio Capability present: false
.01. .... = Downlink Advanced Receiver Performance: Downlink Advanced Receiver Performance
- phase I supported (1)
...0 .... = DTM Enhancements Capability: The mobile station does not support enhanced DTM CS establishment
and release procedures
.... 0... = DTM E/GPRS High Multi Slot Information present: false
.... .1.. = Repeated ACCH Capability: The mobile station supports Repeated SACCH and Repeated Downlink FACCH
.... ..0. = GSM 710 Associated Radio Capability present: false
.... ...0 = T-GSM 810 Associated Radio Capability present: false
0... .... = Ciphering Mode Setting Capability: The mobile station does not support the Ciphering Mode
Setting IE in the DTM ASSIGNMENT COMMAND message
.0.. .... = Additional Positioning Capabilities: The mobile station does not support
additional positioning capabilities which can be retrieved using RRLP
..1. .... = E-UTRA FDD support: E-UTRA FDD supported
...0 .... = E-UTRA TDD support: E-UTRA TDD not supported
.... 0... = E-UTRA Measurement and Reporting support: E-UTRAN Neighbour Cell measurements
and measurement reporting while having an RR connection not supported
.... .1.. = Priority-based reselection support: Priority-based cell reselection supported
.... ..0. = UTRA CSG Cells Reporting: Reporting of UTRAN CSG cells not supported
.... ...0 = Spare bit(s): 0
v370NonCriticalExtensions
rrcConnectionSetupComplete-v370ext
ue-RadioAccessCapability-v370ext
ue-RadioAccessCapabBandFDDList: 3 items
Item 0
UE-RadioAccessCapabBandFDD
radioFrequencyBandFDD: fdd2100 (0)
fddRF-Capability
ue-PowerClass: class3 (2)
txRxFrequencySeparation: default-TxRx-separation (0)
measurementCapability
compressedModeMeasCapabFDDList: 3 items
Item 0
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: fdd2100 (0)
.... ...1 dl-MeasurementsFDD: True
1... .... ul-MeasurementsFDD: True
Item 1
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: fdd1900 (1)
.... .1.. dl-MeasurementsFDD: True
.... ..1. ul-MeasurementsFDD: True
Item 2
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: bandV (5)
...1 .... dl-MeasurementsFDD: True
.... 1... ul-MeasurementsFDD: True
compressedModeMeasCapabGSMList: 5 items
Item 0
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900E (4)
.... .1.. dl-MeasurementsGSM: True
.... ..1. ul-MeasurementsGSM: True
Item 1
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900P (3)
...1 .... dl-MeasurementsGSM: True
.... 1... ul-MeasurementsGSM: True
Item 2
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1800 (5)
.1.. .... dl-MeasurementsGSM: True
..1. .... ul-MeasurementsGSM: True
Item 3
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1900 (6)
.... ...1 dl-MeasurementsGSM: True
1... .... ul-MeasurementsGSM: True
Item 4
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm850 (2)
.... .1.. dl-MeasurementsGSM: True
.... ..1. ul-MeasurementsGSM: True
Item 1
UE-RadioAccessCapabBandFDD
radioFrequencyBandFDD: fdd1900 (1)
fddRF-Capability
ue-PowerClass: class3 (2)
txRxFrequencySeparation: default-TxRx-separation (0)
measurementCapability
compressedModeMeasCapabFDDList: 3 items
Item 0
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: fdd2100 (0)
..1. .... dl-MeasurementsFDD: True
...1 .... ul-MeasurementsFDD: True
Item 1
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: fdd1900 (1)
1... .... dl-MeasurementsFDD: True
.1.. .... ul-MeasurementsFDD: True
Item 2
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: bandV (5)
.... ..1. dl-MeasurementsFDD: True
.... ...1 ul-MeasurementsFDD: True
compressedModeMeasCapabGSMList: 5 items
Item 0
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900E (4)
1... .... dl-MeasurementsGSM: True
.1.. .... ul-MeasurementsGSM: True
Item 1
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900P (3)
.... ..1. dl-MeasurementsGSM: True
.... ...1 ul-MeasurementsGSM: True
Item 2
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1800 (5)
.... 1... dl-MeasurementsGSM: True
.... .1.. ul-MeasurementsGSM: True
Item 3
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1900 (6)
..1. .... dl-MeasurementsGSM: True
...1 .... ul-MeasurementsGSM: True
Item 4
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm850 (2)
1... .... dl-MeasurementsGSM: True
.1.. .... ul-MeasurementsGSM: True
Item 2
UE-RadioAccessCapabBandFDD
radioFrequencyBandFDD: bandV (5)
fddRF-Capability
ue-PowerClass: class3 (2)
txRxFrequencySeparation: default-TxRx-separation (0)
measurementCapability
compressedModeMeasCapabFDDList: 3 items
Item 0
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: fdd2100 (0)
.... .1.. dl-MeasurementsFDD: True
.... ..1. ul-MeasurementsFDD: True
Item 1
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: fdd1900 (1)
...1 .... dl-MeasurementsFDD: True
.... 1... ul-MeasurementsFDD: True
Item 2
CompressedModeMeasCapabFDD
radioFrequencyBandFDD: bandV (5)
.1.. .... dl-MeasurementsFDD: True
..1. .... ul-MeasurementsFDD: True
compressedModeMeasCapabGSMList: 5 items
Item 0
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900E (4)
...1 .... dl-MeasurementsGSM: True
.... 1... ul-MeasurementsGSM: True
Item 1
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900P (3)
.1.. .... dl-MeasurementsGSM: True
..1. .... ul-MeasurementsGSM: True
Item 2
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1800 (5)
.... ...1 dl-MeasurementsGSM: True
1... .... ul-MeasurementsGSM: True
Item 3
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1900 (6)
.... .1.. dl-MeasurementsGSM: True
.... ..1. ul-MeasurementsGSM: True
Item 4
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm850 (2)
...1 .... dl-MeasurementsGSM: True
.... 1... ul-MeasurementsGSM: True
v380NonCriticalExtensions
rrcConnectionSetupComplete-v380ext
ue-RadioAccessCapability-v380ext
ue-PositioningCapabilityExt-v380
.... ...0 rx-tx-TimeDifferenceType2Capable: False
dl-PhysChCapabilityFDD-v380ext
v3a0NonCriticalExtensions
rrcConnectionSetupComplete-v3a0ext
ue-RadioAccessCapability-v3a0ext
ue-PositioningCapabilityExt-v3a0
validity-CellPCH-UraPCH: true (0)
laterNonCriticalExtensions
rrcConnectionSetupComplete-r3-add-ext: e2084e1c7ae86899ebb65a003203a03980 [bit length 136]
RRCConnectionSetupComplete-r3-add-ext-IEs
rrcConnectionSetupComplete-v650ext
ue-RadioAccessCapability-v650ext
ue-RadioAccessCapabBandFDDList2: 1 item
Item 0
UE-RadioAccessCapabBandFDD2
radioFrequencyBandFDD2: bandVIII (0)
fddRF-Capability
ue-PowerClass: class3 (2)
txRxFrequencySeparation: default-TxRx-separation (0)
measurementCapability2
compressedModeMeasCapabFDDList: 4 items
Item 0
CompressedModeMeasCapabFDD2
radioFrequencyBandFDD: fdd2100 (0)
...1 .... dl-MeasurementsFDD: True
.... 1... ul-MeasurementsFDD: True
Item 1
CompressedModeMeasCapabFDD2
radioFrequencyBandFDD: fdd1900 (1)
..1. .... dl-MeasurementsFDD: True
...1 .... ul-MeasurementsFDD: True
Item 2
CompressedModeMeasCapabFDD2
radioFrequencyBandFDD: bandV (5)
.1.. .... dl-MeasurementsFDD: True
..1. .... ul-MeasurementsFDD: True
Item 3
CompressedModeMeasCapabFDD2
radioFrequencyBandFDD2: bandVIII (0)
.1.. .... dl-MeasurementsFDD: True
..1. .... ul-MeasurementsFDD: True
compressedModeMeasCapabGSMList: 5 items
Item 0
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900E (4)
...1 .... dl-MeasurementsGSM: True
.... 1... ul-MeasurementsGSM: True
Item 1
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm900P (3)
.1.. .... dl-MeasurementsGSM: True
..1. .... ul-MeasurementsGSM: True
Item 2
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1800 (5)
.... ...1 dl-MeasurementsGSM: True
1... .... ul-MeasurementsGSM: True
Item 3
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm1900 (6)
.... .1.. dl-MeasurementsGSM: True
.... ..1. ul-MeasurementsGSM: True
Item 4
CompressedModeMeasCapabGSM
radioFrequencyBandGSM: gsm850 (2)
...1 .... dl-MeasurementsGSM: True
.... 1... ul-MeasurementsGSM: True
ue-RadioAccessCapabBandFDDList-ext: 3 items
Item 0
UE-RadioAccessCapabBandFDD-ext
radioFrequencyBandFDD: fdd2100 (0)
compressedModeMeasCapabFDDList-ext: 1 item
Item 0
CompressedModeMeasCapabFDD-ext
radioFrequencyBandFDD2: bandVIII (0)
..1. .... dl-MeasurementsFDD: True
...1 .... ul-MeasurementsFDD: True
Item 1
UE-RadioAccessCapabBandFDD-ext
radioFrequencyBandFDD: fdd1900 (1)
compressedModeMeasCapabFDDList-ext: 1 item
Item 0
CompressedModeMeasCapabFDD-ext
radioFrequencyBandFDD2: bandVIII (0)
.... ..1. dl-MeasurementsFDD: True
.... ...1 ul-MeasurementsFDD: True
Item 2
UE-RadioAccessCapabBandFDD-ext
radioFrequencyBandFDD: bandV (5)
compressedModeMeasCapabFDDList-ext: 1 item
Item 0
CompressedModeMeasCapabFDD-ext
radioFrequencyBandFDD2: bandVIII (0)
..1. .... dl-MeasurementsFDD: True
...1 .... ul-MeasurementsFDD: True
v680NonCriticalExtensions
rrcConnectionSetupComplete-v680ext
ue-RadioAccessCapability-v680ext
multiModeRAT-Capability-v680ext
v7e0NonCriticalExtensions
rrcConnectionSetupComplete-v7e0ext
ue-RadioAccessCapability
supportForTwoDRXSchemesInPCH: true (0)
supportEDPDCHPowerInterpolation: true (0)
v3g0NonCriticalExtensions
rrcConnectionSetupComplete-v3g0ext
v4b0NonCriticalExtensions
rrcConnectionSetupComplete-v4b0ext
ue-RadioAccessCapability-v4b0ext
pdcp-Capability-r4-ext
supportForRfc3095: notSupported (0)
notSupported: NULL
v590NonCriticalExtensions
rrcConnectionSetupComplete-v590ext
ue-RadioAccessCapability-v590ext
dl-CapabilityWithSimultaneousHS-DSCHConfig: kbps64 (1)
pdcp-Capability-r5-ext
...0 .... supportForRfc3095ContextRelocation: False
rlc-Capability-r5-ext
physicalChannelCapability
fdd-hspdsch: supported (0)
supported
hsdsch-physical-layer-category: 10
.... 0... dummy: False
.... .0.. dummy2: False
tdd384-hspdsch: unsupported (1)
unsupported: NULL
tdd128-hspdsch: unsupported (1)
unsupported: NULL
multiModeRAT-Capability-v590ext
1... .... supportOfUTRAN-ToGERAN-NACC: True
v5c0NonCriticalExtensions
rrcConnectionSetupComplete-v5c0ext
v690NonCriticalExtensions
rrcConnectionSetupComplete-v690ext
ueCapabilityContainer: 45f9228d64806118385010610310468083081882b4041840...
[bit length 256]
UE-CapabilityContainer-IEs
ue-RadioAccessCapability-v690ext
physicalchannelcapability-edch
fdd-edch: supported (0)
supported
edch-PhysicalLayerCategory: 6
v6b0NonCriticalExtensions
ue-RadioAccessCapability-v6b0ext
supportForSIB11bis: true (0)
v6e0NonCriticalExtensions
ue-RadioAccessCapability-v6e0ext
supportForFDPCH: true (0)
v770NonCriticalExtensions
ue-RadioAccessCapability-v770ext
rlc-Capability
.0.. .... supportOfTwoLogicalChannel: False
physicalChannelCapability
fddPhysChCapability
downlinkPhysChCapability
hsdsch-physical-layer-category-ext: 14
enhancedFdpch: true (0)
uplinkPhysChCapability
discontinuousDpcchTransmission: true (0)
slotFormat4: true (0)
multiModeRAT-Capability
ue-PositioningCapability
mac-ehsSupport: true (0)
v790NonCriticalExtensions
ue-RadioAccessCapability-v790ext
v860NonCriticalExtensions
ue-RadioAccessCapability-v860ext
physicalChannelCapability
fddPhysChCapability
downlinkPhysChCapability
multiModeRAT-Capability
supportOfEUTRAFDD: doesSupportEUTRAFDD (0)
eutraFeatureGroupIndicators: 80 ....
ue-PositioningCapability
ue-RadioAccessCapabBandFDDList3: 4 items
Item 0
UE-RadioAccessCapabBandFDD3
radioFrequencyBandFDD: fdd2100 (0)
measurementCapability3
compressedModeMeasCapabEUTRAList: 5
Item 1
UE-RadioAccessCapabBandFDD3
radioFrequencyBandFDD: fdd1900 (1)
measurementCapability3
compressedModeMeasCapabEUTRAList: 5
Item 2
UE-RadioAccessCapabBandFDD3
radioFrequencyBandFDD: bandV (5)
measurementCapability3
compressedModeMeasCapabEUTRAList: 5
Item 3
UE-RadioAccessCapabBandFDD3
radioFrequencyBandFDD2: bandVIII (0)
measurementCapability3
compressedModeMeasCapabEUTRAList: 5
v880NonCriticalExtensions
ue-RadioAccessCapability-v880ext
supportForPriorityReselectionInUTRAN: true (0)
Let's read the Release 99 part first, because every UMTS network understands it. The UE supports turbo coding in both directions. At any time instant, the sum of all its received or transmitted transport blocks can reach 6400 bits (b6400). It handles up to 8 transport channels at once and 64 transport formats. The downlink allows 128 TFCs, and the uplink allows 64.
The RLC entry offers a total buffer of 1000 kBytes for RLC AM and MAC-hs or MAC-ehs reordering. The maximum AM window is 2047, which is the smaller of the two values that 25.331 allows. The UE can run 16 AM entities. PDCP header compression is not supported, because supportForRfc2507 and the later supportForRfc3095 are both notSupported. The physical channel entry allows one DPCH code on the downlink and 9600 physical channel bits (b9600) in both directions.
These numbers describe dedicated channels only. The HSPA capability, the extra bands and E-UTRA support all arrive in the extensions. A decoder that stops after ue-RATSpecificCapability would therefore show a Release 99 UE. Also note two lines that the decoder does not fully expand. The two bit strings rrcConnectionSetupComplete-r3-add-ext and ueCapabilityContainer show their raw hex first and their decoded contents after. The value "5" after each compressedModeMeasCapabEUTRAList is most likely the number of E-UTRA bands in the list, and the decoder does not show the bands themselves.
The Release 99 part describes a DCH UE : turbo coding, 6400 bits per time instant, one downlink DPCH code and no header compression.Both START values are 2 : so the CS and PS HFNs start from the same upper 20 bits.Most of the useful information is in the extensions : a Release 99 view of this message hides HSPA, Band VIII and E-UTRA.
Why is the capability spread over so many extension containers ?
About 350 of the capture lines sit inside non-critical extensions. This comes from the way RRC grows. A later release cannot insert a new field into the original sequence, because an RNC built to an older version would then decode the message wrongly.
25.331 clause 10.1.1 answers this with non-critical extensions. A receiver processes a message with non-critical extensions it does not understand as if the extensions were absent. Each new extension is appended at the end of the previous one, and its name gives the specification version that added it. The third character counts past 9 with letters, so v3a0 is version 3.10.0, v4b0 is 4.11.0 and v7e0 is 7.14.0.
Appending at the end has one problem. A feature can be added to Release 99 after Release 4 is already frozen, and the end of the message then belongs to Release 4. For this case 25.331 defines "variable length extension containers", which are BIT STRINGs with a length in front. The IE rrcConnectionSetupComplete-r3-add-ext is such a container. It sits in the Release 99 part of the chain, ahead of the Release 4 extension v4b0. In the capture it carries v650 with Band VIII, v680 with no visible content, and v7e0 with the DRX and E-DPDCH interpolation fields.
The IE ueCapabilityContainer in v690 is a second container. The ASN.1 comment says it carries capability information "not related to features for which early implementation is desired". In the capture it carries E-DCH category 6, F-DPCH, HS-DSCH category extension 14, CPC related fields, E-UTRA FDD support and the UTRA priority reselection flag. The listing below shows the top level of the message in the current release.
Following is based on
RRCConnectionSetupComplete ::= SEQUENCE { -- TABULAR: Integrity protection shall not be performed on this message. -- User equipment IEs rrc-TransactionIdentifier RRC-TransactionIdentifier, startList STARTList, ue-RadioAccessCapability UE-RadioAccessCapability OPTIONAL, -- Other IEs ue-RATSpecificCapability InterRAT-UE-RadioAccessCapabilityList OPTIONAL, -- Non critical extensions v370NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v370ext RRCConnectionSetupComplete-v370ext, v380NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v380ext RRCConnectionSetupComplete-v380ext-IEs, -- Reserved for future non critical extension v3a0NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v3a0ext RRCConnectionSetupComplete-v3a0ext-IEs, laterNonCriticalExtensions SEQUENCE { -- Container for additional R99 extensions rrcConnectionSetupComplete-r3-add-ext BIT STRING (CONTAINING RRCConnectionSetupComplete-r3-add-ext-IEs) OPTIONAL, v3g0NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v3g0ext RRCConnectionSetupComplete-v3g0ext-IEs, v4b0NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v4b0ext RRCConnectionSetupComplete-v4b0ext-IEs, v590NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v590ext RRCConnectionSetupComplete-v590ext-IEs, v5c0NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v5c0ext RRCConnectionSetupComplete-v5c0ext-IEs, v690NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-v690ext RRCConnectionSetupComplete-v690ext-IEs, v770NonCriticalExtensions SEQUENCE { rrcConectionSetupComplete-v770ext RRCConnectionSetupComplete-v770ext-IEs, va40NonCriticalExtensions SEQUENCE { rrcConectionSetupComplete-va40ext RRCConnectionSetupComplete-va40ext-IEs, vb50NonCriticalExtensions SEQUENCE { rrcConnectionSetupComplete-vb50ext RRCConnectionSetupComplete-vb50ext-IEs, nonCriticalExtensions SEQUENCE {} OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL }
Compare this listing with the capture. The capture follows the same path down to v690, but the message then ends. The current release adds v770 with deferredMeasurementControlReading, and then va40 and vb50. Inside the r3-add-ext container, the current release also continues after v7e0 with v7f0 and va40. The UE in the capture simply did not include these optional extensions. The same applies inside ueCapabilityContainer, which the listing below defines.
Following is based on
UE-CapabilityContainer-IEs ::= SEQUENCE { -- Container for transparent transfer of capability information not related to -- features for which early implementation is desired ue-RadioAccessCapability-v690ext UE-RadioAccessCapability-v690ext, ue-RATSpecificCapability-v690ext InterRAT-UE-RadioAccessCapability-v690ext OPTIONAL, v6b0NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v6b0ext UE-RadioAccessCapability-v6b0ext-IEs, v6e0NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v6e0ext UE-RadioAccessCapability-v6e0ext-IEs, v770NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v770ext UE-RadioAccessCapability-v770ext-IEs, v790NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v790ext UE-RadioAccessCapability-v790ext-IEs, v860NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v860ext UE-RadioAccessCapability-v860ext-IEs, ue-RATSpecificCapability-v860ext InterRAT-UE-RadioAccessCapability-v860ext OPTIONAL, v880NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v880ext UE-RadioAccessCapability-v880ext-IEs, v890NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v890ext UE-RadioAccessCapability-v890ext-IEs, v920NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v920ext UE-RadioAccessCapability-v920ext-IEs, v970NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-v970ext UE-RadioAccessCapability-v970ext-IEs, va40NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-va40ext UE-RadioAccessCapability-va40ext-IEs, va60NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-va60ext UE-RadioAccessCapability-va60ext-IEs, va80NonCriticalExtensions SEQUENCE { ue-RadioAccessCapability-va80ext UE-RadioAccessCapability-va80ext-IEs, laterNonCriticalExtensions UE-RadioAccessCapability-LaterNonCriticalExtensions OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL } OPTIONAL }
The capture stops after v880 inside this container. A UE of a later release continues with v890, v920 and so on, up to laterNonCriticalExtensions. So the depth of the extension chain gives a first hint about the release of the UE. This one stops at the Release 8 extensions.
Non-critical extensions are appended, never inserted : an older RNC ignores what it does not understand and still decodes the rest.The name of an extension is a spec version : v7e0 means 25.331 version 7.14.0.BIT STRING containers carry late additions : r3-add-ext holds late Release 99 fields, and ueCapabilityContainer holds most Release 6 to 8 fields.The last extension present hints at the UE release : this UE stops at v880, so it is a Release 8 UE or behaves like one.
What do the fields in red tell the network ?
The author marked thirteen field names in red inside the capture. Most of them decide how the RNC can configure HSPA and CPC for this UE. The table below lists each field with its location in the extension chain and its meaning from 25.331.
Field in red | Extension | Value | Meaning |
rx-tx-TimeDifferenceType2Capable | v380 | False | The UE cannot perform the Rx-Tx time difference type 2 measurement for positioning. |
validity-CellPCH-UraPCH | v3a0 | true | UE positioning assisted GPS measurements stay valid in CELL_PCH and URA_PCH. |
supportForTwoDRXSchemesInPCH | v7e0 | true | The UE supports two DRX schemes in URA_PCH and CELL_PCH. |
supportEDPDCHPowerInterpolation | v7e0 | true | The UE supports the E-DPDCH power interpolation formula when 16QAM is not configured. |
hsdsch-physical-layer-category | v590 | 10 | HS-DSCH category for an RNC that does not read the extension. |
edch-PhysicalLayerCategory | v690 | 6 | E-DCH category, 4 codes down to SF2, 10 ms and 2 ms TTI. |
supportForFDPCH | v6e0 | true | The UE supports F-DPCH. |
hsdsch-physical-layer-category-ext | v770 | 14 | HS-DSCH category with 64QAM, 15 codes. |
enhancedFdpch | v770 | true | The UE supports enhanced F-DPCH. |
discontinuousDpcchTransmission | v770 | true | The UE supports DPCCH discontinuous transmission, the uplink DTX part of CPC. |
slotFormat4 | v770 | true | The UE supports uplink DPCCH slot format #4. |
mac-ehsSupport | v770 | true | The UE supports MAC-ehs. |
supportForPriorityReselectionInUTRAN | v880 | true | The UE supports absolute priority based cell re-selection to UTRA inter-frequency. |
The two HS-DSCH categories belong together. 25.331 says that a UE which signals category extension 14 shall signal category 10 in the older field. An RNC that does not read v770 therefore still sees a valid category. 25.306 Table 5.1a gives category 10 up to 15 HS-PDSCH codes and a transport block of 27952 bits per 2 ms TTI. That is about 14.0 Mbps. Category 14 keeps the 15 codes and adds 64QAM, and its largest transport block of 42192 bits gives about 21.1 Mbps. 25.306 also says that a UE of category 13 or higher supports MAC-ehs, and mac-ehsSupport is true in the capture.
On the uplink, E-DCH category 6 is the highest category that uses QPSK only. 25.306 Table 5.1g gives it 4 codes, two at SF2 and two at SF4. The largest transport block is 11484 bits per 2 ms TTI, about 5.74 Mbps, and 20000 bits per 10 ms TTI, which is 2 Mbps. The capture carries no edch-PhysicalLayerCategory-extension. So the UE does not support category 7, which adds 16QAM on the 2 ms TTI.
The v770 fields together describe CPC support. F-DPCH and enhanced F-DPCH let the RNC replace the downlink DPCH with a fractional DPCH that carries only TPC commands. DPCCH discontinuous transmission lets the UE switch off its uplink DPCCH in a pattern when it has no data to send. Slot format #4 is the uplink DPCCH format with 6 pilot bits and 4 TPC bits and no TFCI or FBI field (25.211 Table 2). The RNC should configure slot format #4 only for a UE that sets this flag.
Category 10 and category 14 describe one UE : the older field keeps a pre Release 7 RNC working, and the extension adds 64QAM.This UE peaks at about 21.1 Mbps down and 5.74 Mbps up : those are the transport block limits of categories 14 and 6.The red v770 fields are the CPC toolkit : F-DPCH, enhanced F-DPCH, DPCCH DTX and slot format #4.An absent field means unsupported : most of these IEs are ENUMERATED { true } OPTIONAL, so no line in the capture means no support.
What do the band, security and inter-RAT fields tell the network ?
The rest of the capture answers three practical questions for the RNC. Which bands can the UE use, which algorithms can protect the connection, and where can the UE go when UMTS coverage ends?
Start with the bands. The v370 list carries fdd2100, fdd1900 and bandV, which are Band I, Band II and Band V. Band VIII arrives later in the v650 list inside the r3-add-ext container. It uses the type RadioFrequencyBandFDD2, because the original band enumeration stops at Band VII. Every band entry shows ue-PowerClass class3 and the default Tx-Rx frequency separation.
Each band entry also carries a compressed mode matrix. For each band in that matrix, the UE states whether it needs downlink and uplink compressed mode to measure there. 25.331 defines TRUE as "the UE requires DL compressed mode in order to perform measurements". Every entry in this capture is True, for all UMTS bands and all five GSM bands. So the RNC must open transmission gaps for every inter-frequency and inter-RAT measurement. The v650 list and the -ext lists add the same matrix for Band VIII, in both directions.
Security comes next. The bit string cipheringAlgorithmCap is 0003. In the ASN.1, bit 15 is uea0 and bit 14 is uea1, so the UE supports no ciphering and UEA1. The bit string integrityProtectionAlgorithmCap is 0002, and bit 14 is uia1. So this UE supports neither UEA2 nor UIA2, and the RNC must use the UEA1 and UIA1 algorithms.
For GSM, 25.331 clause 10.3.8.7 carries two classmarks. Mobile Station Classmark 2 is sent as TLV, so 33035758a6 is the IEI 33H, the length 3 and three value octets. Mobile Station Classmark 3 is sent as the value part only. The classmarks show GSM 850, E-GSM, DCS 1800 and PCS 1900, 8-PSK in both directions, and the A5/1 and A5/3 ciphering algorithms. The FC bit in Classmark 2 says that E-GSM is not supported, while Classmark 3 says that it is. This is not a conflict. 24.008 requires FC = 0 when UMTS or another listed band is in use. The optional MS Radio Access Capability is absent, so the UE indicates nothing here about PS handover to GPRS.
Finally, E-UTRA. Classmark 3 and v860 both indicate E-UTRA FDD support, but the UE sent no UE-EUTRA-Capability. This means the RRC CONNECTION SETUP before this message listed GSM, but not E-UTRA, in the IE "Capability update requirement". The decoder shows eutraFeatureGroupIndicators as 80, which is the 4 bit string 1000. Annex E of 25.331 defines the first bit as reselection from CELL_PCH and URA_PCH to E-UTRA. The second bit covers E-UTRA measurements and reporting in connected mode, and this UE leaves it at zero. So the network ignores the E-UTRA compressed mode lists, and it cannot configure E-UTRA measurements for this UE in connected mode.
Annex E also states that all UEs that support E-UTRA support reselection in idle mode and redirection at RRC release and RRC reject. This UE can therefore reach LTE by reselection or by redirection. It cannot reach LTE by PS handover, because supportOfInterRATHOToEUTRAFDD is absent from v860. In the current release, a UE that supports E-UTRAN sets all four feature group bits. This UE sets only the first bit, so it has not implemented or tested the other three groups.
Band VIII needs the second band enumeration : RadioFrequencyBandFDD stops at Band VII, so Band VIII is signalled in v650 with RadioFrequencyBandFDD2.This UE needs compressed mode for every measurement : all dl and ul compressed mode flags are True.Only KASUMI based algorithms are offered : UEA0, UEA1 and UIA1, with no UEA2 or UIA2.The FC bit of Classmark 2 is 0 by rule : Classmark 3 is the place to read E-GSM support.E-UTRA support here means reselection and redirection only : feature group bit 2 is zero and PS handover to E-UTRA FDD is not indicated.
Reference
- 3GPP TS 25.331 v19.0.1 : clauses 8.1.3.6, 8.1.6, 8.6.3.12, 10.1.1, 10.3.3.2, 10.3.3.25, 10.3.3.34, 10.3.3.37, 10.3.3.38, 10.3.3.40, 10.3.3.41, 10.3.3.42, 10.3.3.45, 10.3.8.7, Annex E, and the ASN.1 of clause 11
- 3GPP TS 25.306 v19.0.0 : Table 5.1a, FDD HS-DSCH physical layer categories, and Table 5.1g, FDD E-DCH physical layer categories
- 3GPP TS 25.211 v19.0.0 : Table 2, DPCCH fields
- 3GPP TS 24.008 v20.0.0 : clause 10.5.1.6, Mobile Station Classmark 2, and clause 10.5.1.7, Mobile Station Classmark 3