Showing posts with label LTE. Show all posts
Showing posts with label LTE. Show all posts

Tuesday, September 1, 2026

Energy Efficiency Improvements in 3GPP Technologies: From LTE to 5G-Advanced

Energy efficiency has become one of the most important topics in mobile networks. Operators need to support growing traffic, wider bandwidths, massive MIMO, better coverage and new services, while also reducing energy consumption, managing cost and meeting sustainability targets.

We have put together a five-part video series looking at Energy Efficiency Improvements in 3GPP Technologies, starting with LTE and then moving through 5G NR, 5G-Advanced Release 18 and 3GPP Release 19.

The aim of the series is to explain the topic in a structured way. Energy saving in mobile networks is not simply about switching equipment off. It requires careful coordination between radio design, traffic load, user experience, QoS, mobility, device behaviour, RAN hardware, network policies and service requirements.

The five videos in the playlist are:

  1. Energy Efficiency in Mobile Networks: The Basics - This introductory video explains why energy efficiency matters, why the RAN gets most attention, how energy saving differs from energy efficiency, and why measurements and KPIs are essential before optimisation.
  2. How LTE Networks Save Energy - This video looks at LTE energy-saving mechanisms including dormant mode, carrier switch-off, secondary antenna deactivation, common channel power control, Cell DTX, compensation cells, and OAM or signalling-based control.
  3. Why 5G NR Is More Energy Efficient by Design - This part explains the energy-efficiency improvements built into 5G NR, including lean carrier design, sleep opportunities, Bandwidth Parts, carrier aggregation, UE DRX, massive MIMO, beamforming and radio hardware evolution.
  4. 5G-Advanced Release 18 Network Energy Saving - This video looks at Release 18 Network Energy Saving features such as SSB-less SCells, Cell DTX/DRX, CSI enhancements, antenna adaptation, PDSCH power adaptation, Conditional Handover for NES cells and legacy UE handling.
  5. 3GPP Release 19 Energy Efficiency and Energy Saving - The final video looks at Release 19 enhancements including on-demand SSB operation for SCells, on-demand SIB1 for idle/inactive UEs, SSB periodicity adaptation, PRACH and paging adaptation, LP-WUS/WUR, Energy Information Function, OAM, slicing, charging and energy efficiency as a service criterion.

The overall message from the series is that mobile network energy efficiency has evolved from relatively simple resource switch-off mechanisms towards more intelligent, adaptive and service-aware optimisation. LTE introduced many of the early practical ideas. 5G NR provided a more flexible and energy-efficient foundation. 5G-Advanced Release 18 made RAN Network Energy Saving more explicit, and Release 19 expands the topic towards on-demand signalling, UE wake-up efficiency and system-wide energy awareness.

The complete playlist is embedded below.

The main references used for this series include 3GPP article3GPP TR 21.919, 3GPP TR 38.864, 3GPP TR 38.869, NGMN material on 5G energy efficiency best practices, and technical material from Nokia Bell Labs on 5G-Advanced Network Energy Saving.

Related Posts

Tuesday, August 11, 2026

Next Generation eCall Finally Moves to 4G and 5G

Back in 2022, I wrote about the transition from the original eCall system to Next Generation eCall, or NG eCall. At the time, one of the big concerns was what would happen to millions of vehicles relying on 2G and 3G as mobile operators gradually switched off these legacy networks.

Four years later, the transition is no longer something happening in the distant future. 2026 is an important year for NG eCall in Europe.

For anyone unfamiliar with eCall, it is the European emergency calling system built into vehicles. Following a serious accident, the vehicle can automatically call the European emergency number 112, or the call can be triggered manually. Along with establishing a voice connection, the vehicle sends a Minimum Set of Data (MSD) containing information such as its location, direction of travel and other relevant vehicle information. eCall has been required for new M1 and N1 vehicle types in the EU since April 2018.

The problem is that the original eCall architecture was designed around circuit-switched 2G and 3G networks. The MSD is transferred using an in-band modem during the emergency voice call.

NG eCall takes a different approach. It uses packet-switched connectivity and IMS, allowing eCall to operate over 4G LTE and 5G. At the protocol level, it becomes an IMS emergency call, with SIP used for call signalling and the eCall MSD carried as emergency-call data within the SIP-based session.

This transition became much more significant on 1 January 2026. From that date, new M1 and N1 vehicle types in the EU have to support packet-switched eCall. Public Safety Answering Points (PSAPs) that were already deployed are also required to support eCall over packet-switched 4G/5G networks from the beginning of 2026.

The standards have continued to evolve as well. Commission Delegated Regulation (EU) 2025/1871 updated the regulatory references to the newer EN 17184:2024, covering eCall high-level application protocols using IMS over packet-switched networks, and EN 17240:2024, covering end-to-end conformance testing. There are transitional arrangements during 2026, with the newer EN standards becoming mandatory for new type approvals from 1 January 2027.

There is also evidence that the ecosystem is moving from specifications to actual interoperability testing. In June 2026, ETSI organised its latest NG eCall Plugtests in Ljubljana. Testing focused on interoperability between In-Vehicle Systems (IVS) and PSAPs over 4G LTE, and importantly included access to a real Telekom Slovenije mobile network rather than relying entirely on simulated infrastructure. Testing used ETSI TS 103 683, with EN 17240:2024 conformance testing also supported.

However, moving new vehicles to NG eCall does not make the legacy problem disappear.

The existing European vehicle fleet contains a very large number of cars whose eCall systems still depend on 2G/3G. EU rules therefore require PSAPs to continue supporting circuit-switched eCall while at least one circuit-switched mobile network remains operational in the relevant Member State.

A European Commission Joint Research Centre study published in May 2026 highlights the scale of the challenge. Its modelling estimates that there could still be around 66.8 million passenger vehicles equipped with circuit-switched eCall at the end of 2027. The study considers several possible mitigation approaches, including upgrading suitable existing eCall units to 4G, using 4G-capable third-party eCall systems and providing aftermarket solutions for vehicles that cannot otherwise be upgraded.

So, in some ways, we now have two parallel eCall transitions taking place. New vehicles and emergency infrastructure are moving towards IMS-based NG eCall over 4G and 5G, while the industry still has to work out how to keep tens of millions of older vehicles able to contact emergency services as 2G and 3G networks disappear.

The short Rohde & Schwarz video below provides a good overview of how eCall and NG eCall work, followed by an explanation of how the technology can be tested from the GNSS module and telematics control unit (TCU) through to complete vehicle-level testing.


Friday, July 10, 2026

From 3GPP MPS to Wi-Fi 7 EPCS

Back in January 2011, I wrote about Enhanced Multimedia Priority Service, or eMPS, in 3GPP Release 10. At the time, the focus was on extending priority treatment beyond basic voice calls to packet data and multimedia sessions over LTE and EPC.

The basic requirement has not changed. During a major incident, commercial communication networks may become heavily congested at exactly the time when certain authorised users most need to communicate. These users may include government personnel, emergency management officials and others assigned National Security or Emergency Preparedness, NS/EP, responsibilities.

3GPP addresses this through Multimedia Priority Service, or MPS, specified in TS 22.153. MPS is not a separate radio system and it should not be confused with public emergency calling. It is a mechanism that gives authorised Service Users priority treatment on commercial networks, increasing the probability that their voice, video or data communications can be successfully established and maintained during congestion.

In my original post, I explained that this required more than simply prioritising user-plane packets. End-to-end priority could involve NAS and AS signalling establishment, session establishment, resource allocation in the radio and core networks and treatment of the media bearers themselves.

Fifteen years later, the interesting development is that this idea is expanding beyond the traditional cellular access network.

The challenge is easy to understand. An authorised priority user may have an MPS subscription with a mobile operator, but that user may be inside a building, transport hub, stadium, campus or other environment where connectivity is provided over Wi-Fi. Even where cellular coverage exists, the device may already be using Wi-Fi because of local coverage, capacity or policy.

The question is therefore no longer just how to prioritise an NS/EP user in LTE or 5G. It is how priority authorisation can follow the user across different access technologies.

There are actually two related but different technical developments taking place.

The first is within 3GPP itself. In Release 19, a change to TS 22.153 added explicit MPS requirements for situations where a UE is using a 3GPP radio access technology, such as NR or E-UTRA, and non-3GPP WLAN access connected to the same EPC or 5GC. The associated work item is MPS_WLAN, or MPS when access to EPC/5GC is WLAN.

This is important, but it is still primarily a 3GPP system view. The WLAN is acting as non-3GPP access towards the mobile core.

The second development goes further. Wi-Fi 7 introduces Emergency Preparedness Communications Service, or EPCS, functionality that can provide preferred or prioritised channel access to authorised users. This means that priority treatment can also be applied on the Wi-Fi access network itself.

This creates a different architectural problem.

Wi-Fi can define how the Access Point, AP, and Station, STA, support prioritised channel access, but the Wi-Fi network still needs to know whether the user is genuinely authorised to receive that treatment.

The network therefore needs to determine whether the user is authenticated, whether the user is authorised for Priority Services, what priority level has been assigned, whether that authorisation is valid in the relevant regulatory jurisdiction and whether the network and device support the required EPCS capabilities.

This is the gap that the current IETF work is attempting to address.

The latest version at the time of writing is draft-gundavelli-radepcs-02, titled RADIUS attributes for National Security and Emergency Preparedness Service. It is an active Internet-Draft and work in progress rather than an approved IETF standard. The draft describes RADIUS extensions for authorising EPCS users so that they can receive preferential access to Wi-Fi network resources during congestion.

The proposed architecture reuses mechanisms already widely deployed for managed and roaming Wi-Fi, including Passpoint, EAP and RADIUS.

A user is first authorised for Priority Services by an appropriate Authorising Entity. The service provider receives this authorisation and stores the relevant priority information against the subscriber profile. Where the service provider is also a cellular operator and Wi-Fi Identity Provider, the priority service subscription information can be mirrored into the Wi-Fi AAA system.

The overall architecture and signalling flow are shown below.

The first part of the process is network discovery. An EPCS-enabled Wi-Fi network advertises an EPCS Roaming Consortium, while the authorised user's device contains a corresponding Passpoint profile. The device can discover the relevant roaming information and select the network using normal Passpoint mechanisms.

After the device associates with the Wi-Fi network, EAP authentication is performed and the AP or Wireless LAN Controller forwards the authentication exchange towards the Identity Provider using RADIUS.

This is where the proposed new RADIUS attributes become important.

EPCS-Capable-Indication allows the Wi-Fi Network Access Server to tell the RADIUS server that it supports EPCS. The capability information can also indicate whether priority treatment is possible only when the user device itself supports EPCS, or whether some treatment, such as downlink prioritisation, may still be possible for a non-EPCS device.

EPCS-Regulatory-Info provides information about the regulatory regime under which priority service is being authorised. This may contain an ISO 3166-1 country code or ISO 3166-2 subdivision code. This matters because priority authorisation and priority levels may be specific to a particular country or jurisdiction.

EPCS-Subscription-Info indicates that the authenticated user is authorised to receive Priority Services and carries the priority level associated with the user's subscription. The priority levels themselves are administered according to the relevant regulatory regime.

The important point is that the Wi-Fi network does not independently decide that a user should receive priority.

The authorisation originates from an external authority and is linked to an authenticated identity or subscription.

Authentication and priority authorisation are therefore separate. Successfully authenticating to a Wi-Fi network does not automatically make someone an EPCS user.

Once the AAA system confirms that the user is authorised, the AP/WLC can enable EPCS Priority Access for the device. Where both the network and device support EPCS, uplink and downlink traffic can receive priority treatment. Depending on the capabilities of the network, downlink traffic may still be prioritised even when the device itself does not support EPCS. The exact mechanism used by the network to prioritise the traffic is vendor-specific and outside the scope of the current IETF draft.

There are several interesting aspects to this architecture.

First, the solution uses the existing Wi-Fi roaming framework rather than creating an entirely separate emergency network discovery and authentication mechanism. Passpoint supports automatic discovery and network selection, EAP handles authentication and RADIUS carries the EPCS authorisation information.

Second, location and regulatory information become part of the authorisation process. A user authorised for a particular level of priority in one jurisdiction may not necessarily be entitled to the same treatment everywhere.

Third, the network needs to separate a user's normal access credentials from their entitlement to Priority Services. An ordinary subscriber, an authenticated Wi-Fi user and an authorised EPCS user may all use the same access network but receive very different treatment during congestion.

Finally, this is not simply a matter of giving some packets a higher priority marking.

Real end-to-end priority may involve access to the Wi-Fi medium, AP queues, backhaul networks, interconnected networks and application traffic. The IETF draft identifies authentication, authorisation, traffic identification and prioritisation as separate requirements. Where networks interconnect, priority indicators may also need to be passed securely to downstream networks.

It is also worth stressing the difference between Priority Services and emergency calling.

An ordinary user attempting to call 999, 112 or 911 is not automatically an NS/EP Priority Service user. Emergency calling is about allowing the public to reach emergency services, potentially even when normal cellular coverage or credentials are unavailable.

MPS and EPCS are different. They are intended for authorised users or organisations that have been assigned priority privileges so their communications have a greater probability of success during congestion.

The Wireless Broadband Alliance has been working on both areas through its Mission Critical and Emergency Services programme. Its work covers emergency calling over Wi-Fi, cellular emergency calling over OpenRoaming and NS/EP priority communications. For the priority case, the focus is on using Wi-Fi, Passpoint and roaming mechanisms to extend capabilities traditionally associated with cellular networks.

For me, the interesting part is how the boundaries between cellular and Wi-Fi continue to blur.

3GPP MPS started from the assumption that priority treatment had to be provided across the cellular system, from access signalling through to core network resources and application sessions. 3GPP has now added explicit requirements for MPS when 3GPP and WLAN accesses connect to the same EPC or 5GC.

At the same time, Wi-Fi 7 provides EPCS mechanisms for prioritised channel access, while Passpoint and the proposed RADIUS extensions provide a possible way to discover the service, authenticate the user and transfer priority authorisation into the Wi-Fi network.

The result is not a replacement for cellular MPS, and it is not simply Wi-Fi QoS.

It is the beginning of a more access-independent model in which an authorised user's priority status could potentially follow them across cellular and Wi-Fi networks, with each access technology applying the appropriate mechanisms within its own domain.

That is a much more interesting evolution than simply adding another priority bit to the network.

Tuesday, May 26, 2026

Mid-Band Spectrum Still Matters for 5G and Beyond

Mid-band spectrum has become one of the most important parts of the mobile network story. Low-band spectrum is essential for wide-area coverage and better indoor reach, while high-band spectrum, including mmWave, can provide very high capacity in selected locations. Mid-band sits between these two extremes and provides the practical balance of coverage and capacity that mobile operators need for mainstream LTE and 5G deployments.

A recent GSA report, Mid Band Spectrum Summary Report, May 2026, provides a useful global update on the status of spectrum between 1.71 GHz and 7.125 GHz. This includes familiar bands such as 1800 MHz, 2100 MHz, 2300 MHz, 2600 MHz, C-band, n79 and the upper 6 GHz band. Many of these bands have a long history in 2G, 3G and 4G networks, but they continue to remain valuable as operators refarm spectrum for LTE and 5G.

The 1800 MHz band remains one of the most widely used LTE bands globally, while 2100 MHz is a good example of a band originally associated with 3G that is now being reused for LTE and 5G. The 2300 MHz and 2600 MHz bands add further capacity options, with different FDD and TDD arrangements depending on the market.

For 5G, C-band has become the main global capacity layer. It offers more bandwidth than the lower mobile bands, while still being more practical than mmWave for wide-area deployment. This is why 3.5 GHz and related C-band ranges are central to many 5G network rollouts around the world.

Looking ahead, upper 6 GHz is becoming increasingly important for 5G-Advanced and 6G planning. It could provide an additional capacity layer that sits above today’s C-band deployments, while still being more practical than mmWave in many scenarios. Beyond that, future 6G discussions may add new layers such as upper-midband spectrum in the 7 to 15 GHz range and sub-THz spectrum for very high-throughput use cases.

In the short video below, we provide a quick update on mid-band spectrum, using the GSA report as the main data source and adding our own analysis of how these spectrum layers fit into LTE, 5G, 5G-Advanced and future 6G evolution.

Related Posts

Thursday, April 9, 2026

3GPP Release 19 Description and Summary of Work Items

As the journey towards 3GPP Release 20 and 6G (3GPP Rel-21) continues to gather pace, the recently concluded Release 19 comes with a clearer view of what the next phase of 5G evolution, often referred to as 5G-Advanced, will look like in practice. One of the most useful artefacts in this process is the recently published technical report 3GPP TR 21.919, which offers a consolidated snapshot of the features and work items currently shaping this release.

Rather than focusing on detailed specifications, this report takes a step back and provides accessible summaries of the agreed work items. Each summary is intended to answer two simple but important questions: what problem is being addressed, and what impact the feature will have on the overall system. This makes the document particularly valuable not only for specialists deeply involved in standardisation work, but also for a broader audience trying to keep track of where the industry is heading.

It is worth noting that this is still very much a work in progress (50% complete). At the time of publication, just over 60 summaries have been included, with many more expected in future updates. Even so, the current version already highlights the sheer breadth of activity in Release 19, spanning everything from energy efficiency and non-terrestrial networks to AI, immersive services, and advanced radio capabilities.

In this post, I will not attempt to reinterpret or condense the summaries themselves. Instead, I am sharing the full list of topics covered in the report below, which provides a useful index into the areas that 3GPP worked on as part of Release 19.

It should be noted that the technical report (TR) presents the "initial state" of the Features introduced in Release 19, i.e. as they are by the time of publication of this document. Each Feature is subject to be later modified or enhanced, over several years, by the means of Change Requests (CRs). To further outline a feature at a given time, it is recommended to retrieve all the CRs which relate to the given Feature, as explained in its Reference section. 

Below is the list of all topics covered in this report. Some of the topics may be missing a summary, which will be added later in the later updates.  

5 Rel-19 Energy Efficiency, Energy Saving
5.1   Enhancements of Network energy savings for NR
5.2   Low-power wake-up signal and receiver for NR (LP-WUS/WUR)
5.3   Energy Efficiency as Service Criteria

6   Rel-19 Satellite (5GSAT), NTN, UAS, Aerial
6.1   Satellite access Phase 3
6.1.1   Security Aspects of 5G Satellite Access Phase 3
6.1.2   Charging aspects of satellite access Phase 3
6.2   Non-Terrestrial Networks (NTN) for NR Phase 3
6.3   Enhancements for Air-to-ground network for NR
6.4   Inter-RAT mode mobility support from E-UTRAN TN to NR NTN
6.5   Non-Terrestrial Networks (NTN) for Internet of Things (IoT) Phase 3 (for LTE)
6.6   Introduction of IoT-NTN TDD mode
6.7   Enhanced requirements and test methodology for NR NTN and IoT NTN
6.8   On-demand broadcast of GNSS assistance data
6.9   Uncrewed Aerial System Phase 3
6.10   Support for PWS in Satellite E-UTRAN and Satellite NG-RAN
6.11   Introduction of BDS (BeiDou Navigation Satellite System) B2b Signal in A-GNSS for LTE and NR
6.12   Introduction of A-GNSS support for NavIC (Navigation with Indian Constellation) L1 SPS (Standard Positioning Service) in NR & LTE
6.13   Management Aspects of Rel-18's NTN Phase 2
6.14   Lower Selection-priority for PLMN Selection
6.15   New LTE band for 5G broadcast for region 3 utilizing a geosynchronous satellite
6.16   Satellite band-related items
6.16.1   Introduction of Ku bands for NR NTN
6.16.2   Introduction of additional operating NR bands for HAPS (High Altitude Platform Station)
6.16.3   Introduction of another NR NTN S-band (MSS band 2000-2020 MHz UL and 2180-2200 MHz DL)
6.16.4   New NR NTN bands to support Extended L-band and combined MSS L-band and Extended L-band ranges
6.16.5   Introduction of another IoT-NTN S-band (MSS band 2000-2020 MHz UL and 2180-2200 MHz DL)

7   Rel-19 Internet of Things (IoT) and Reduced Capability (RedCap) UE
7.1   NR power class 2 RedCap (Reduced Capability) UE in FR1
7.2   NAS layer overhead reduction for data transfer using CP CIoT
7.3   Management Aspects of RedCap features

8   Ambient power-enabled Internet of Things (IoT)
8.1   Ambient power-enabled Internet of Things (IoT) (SA and CT)
8.1.1   Charging for Ambient power-enabled Internet of Things
8.1.2   Security Aspects of Ambient IoT Services in 5G for Isolated Private Networks
8.2   Solutions for Ambient IoT (Internet of Things) in NR

9   Rel-19 Artificial Intelligence (AI)/Machine Learning (ML)
9.1   AI/ML Model Transfer Phase 2
9.2   Core Network Enhanced Support for Artificial Intelligence (AI)/Machine Learning (ML)
9.3   Application enablement for AI/ML services
9.4   Artificial Intelligence (AI)/Machine Learning (ML) for NR air interface
9.5   Artificial Intelligence (AI)/Machine Learning (ML) for NR air interface
9.6   Enhancements for Artificial Intelligence (AI)/Machine Learning (ML) for NG-RAN
9.7   AI/ML Management Phase 2
9.8   Protocol for AI Data Collection from UPF

10   Rel-19 Verticals and Non Public Network
10.1   Rel-19 Enhancements of 3GPP Northbound and Application Layer Interfaces and APIs
10.2   SEAL DD (Data Delivery) Phase 2
10.3   Common Application Programming Interface (API) Framework (CAPIF) Phase 3
10.4   Enhanced OAM for management service exposure to external consumers through CAPIF
10.5   Non-Public Network (NPN) security considerations
10.6   Security for PLMN hosting a NPN
10.7   Interconnect of SNPN
10.8   ProSe support in NPN

11   Rel-19 communications services
11.1   Media Messaging Enhancements
11.2   Terminal Audio quality performance and Test methods for Immersive Audio Services, Phase 2
11.3   EVS Codec Extension for Immersive Voice and Audio Services, Phase 2
11.4   5GMSG Service phase 3
11.5   Video Operating Points - Harmonization and Stereo MV-HEVC
11.6   Advanced Media Delivery
11.7   5G Real-time Transport Protocol Configurations, Phase 2
11.8   Next Generation Real time Communication services Phase 2
11.8.1   System architecture for Next Generation Real time Communication services Phase 2
11.8.2   Security support for the Next Generation Real Time Communication services Phase 2
11.8.3   Application enablement aspects for MMTel

12   Rel-19 XR (eXtended Reality), Augmented Reality (AR), Metaverse, Edge Computing
12.1   Localized Mobile Metaverse Services
12.2   Extended Reality and Media
12.3   XR (eXtended Reality) for NR Phase 3
12.4   Avatar Communications in AR Calls
12.5   Split rendering over IMS
12.6   Enhancement of support for Edge Computing in 5G Core network - Phase 3
12.7   Edge Computing for Industrial Scenarios
12.8   Edge Computing Considering the Operational Needs of Service Hosting Environment
12.9   Architecture for enabling Edge Applications Phase 3

13   Rel-19 High Power UEs (HPUE)
13.1   Rel-19 High power UE (power class 1.5 or 2) for NR intra-band CA or NR inter-band CA/DC band combinations with/without NR Supplementary Uplink (UL)
13.2   Rel-19 High power UE (power class 1.5 and 2) for NR FR1 TDD/FDD single band for handheld/FWA UEs, and high power UE operation (power class 1) for FWVM (fixed-wireless/vehicle-mounted) use cases in a single NR band
13.3   Introduction of Power Class 2 and UE 40MHz Channel Bandwidth in NR band n28
13.4   Rel-19 High power UE (power class 1.5 or 2) for DC combinations of LTE band(s) and NR band(s)
13.5   Rel-19 High power UE (power class 2) and high power operation (power class 1) for fixed-wireless/vehicle-mounted use cases in a single LTE band

14   Rel-19 RAN topology
14.1   5G NR Femto
14.2   Additional topological enhancements for NR
14.3   Vehicle Mounted Relays Phase 2

15   Rel-19 Sidelink, Proximity
15.1   NR sidelink multi-hop relay
15.2   UE-to-UE multi-hop relay
15.3   NR Sidelink: Intra-band Carrier Aggregation in ITS band
15.4   Charging Aspects of Ranging and Sidelink Positioning
15.5   Multi-path relay
15.6   Proximity-based Services in 5GS Phase 3

16   NR and LTE Dual Connectivity (DC)
16.1   UE RF enhancements for NR FR1/FR2 and EN-DC, Phase 4
16.2   Support of intra-band non-collocated EN-DC/NR-CA deployment Phase2: new receiver type(s)
16.3   Rel-19 downlink interruption for NR and EN-DC band combinations at dynamic Tx Switching in Uplink
16.4   Rel-19 DC of x LTE band(s), y NR band(s) (1<=x<6, 1<=y<6, x+y<=6) and single or two NR Supplementary Uplink (SUL) bands
16.5   Simultaneous Rx/Tx band combinations for NR CA/DC, NR SUL and LTE/NR DC in Rel-19
16.6   UE Conformance - Rel-19 NR CA and DC; and NR and LTE DC Configurations

17   Rel-19 Other NR and LTE Radio
17.1   Adding channel bandwidth(s) support to existing NR bands and CA/ENDC combinations in REL-19
17.2   Data collection for SON (Self-Organising Networks)/MDT (Minimization of Drive Tests) in NR standalone and MR-DC (Multi-Radio Dual Connectivity) Phase 4

18   Rel-19 NR Radio
18.1   NR mobility enhancements Phase 4
18.2   Evolution of NR duplex operation: Sub-band full duplex (SBFD)
18.3   NR Radio Resource Management (RRM) Phase 5
18.4   Multi-carrier enhancements for NR Phase 3
18.5   NR demodulation performance Phase 5
18.6   NR MIMO Phase 5
18.7   FR1 TRP, TRS and MIMO OTA testing enhancement Phase 3
18.8   Rel-19 NR CA/DC for x bands DL with y bands UL (x<7, y<3) and SUL/CA band combinations with a single SUL or two SUL cells
18.9   Low band carrier aggregation via switching
18.10  NR channel BW less than 5MHz for FR1 Phase 2
18.11  mmWave in NR: UE spurious emissions and EESS (Earth Exploration Satellite Service) protection
18.12  NR base station (BS) RF requirement evolution for FR1/FR2 and testing
18.13  UE Conformance - New Rel-19 NR licensed bands and extension of existing NR bands
18.14  Other band-related items
18.14.1   7MHz Channel Bandwidth for n26 and n5
18.14.2   Introduction of the NR FDD 1.4 GHz band
18.14.3   Introduction of NR bands n87 and n88
18.14.4   Introduction of NR band n68
18.14.5   Additional NR bands for NR features in Rel-19
18.15  Study on spatial channel model for demodulation performance requirements for NR

19   Rel-19 LTE Radio
19.1   LTE-based 5G Broadcast Phase 2
19.2   Rel-19 LTE-Advanced Carrier Aggregation for x bands (1<=x<= 6) DL with y bands (y=1, 2) UL
19.3   Band-related items
19.3.1   New bands for LTE based 5G terrestrial broadcast for early deployments
19.3.2   Introduction of LTE FDD band in 1800–1830 MHz for Canada

20   Rel-19 Mission Critical, eCall, Emergency
20.1   Enhanced Mission Critical Architecture
20.2   Enhanced Mission Critical Location Management
20.3   Alignment of eCall over IMS with CEN
20.4   UE Conformance - Alignment of eCall over IMS with CEN
20.5   Multiple Location Procedure for Emergency LCS Routing
20.6   Multimedia Priority Service (MPS) for Messaging services
20.7   Mission Critical (MC) services for generic support on Isolated Operation for Public Safety (IOPS) mode of operation
20.8   Sharing of administrative configuration between interconnected MC service systems
20.9   Future Railway Mobile Communication System (FRMCS) Phase 5
20.10   Mission critical security enhancements for release 19
20.11   Protocol enhancements for Mission Critical Services

21   Rel-19 Network Slicing
21.1   Network Controlled Network Slice Selection

22   Rel-19 Service-Based Architecture (SBA)
22.1   UPF enhancement for Exposure And SBA Phase 2
22.2   Automatic Certificate Management Environment (ACME) for the Service Based Architecture (SBA)
22.3   Reducing Information Exposure over SBI
22.4   Service Based Interface Protocol Improvements Release 19

23   Rel-19 QoS and Policy
23.1   Rel-19 Enhancements of UE Policy
23.2   Rel-19 Enhancements of Session Management (SM) Policy
23.3   Minimize the Number of Policy Associations
23.4   Spending Limits for UE Policies in Roaming scenario
23.5   Enhancing Parameter Provisioning with static UE IP address and UP security policy
23.6   Providing per-subscriber VLAN instructions from UDM and DN-AAA
23.7   QoS monitoring enhancement

24   Rel-19 multi-access
24.1   Upper layer traffic steering and switching over dual 3GPP access
24.2   Multi-Access (ATSSS_Ph4)
24.3   ATSSS Rule Provisioning via 3GPP access connected to EPC
24.4   Local traffic routing for multi-access UE

25   Other topics
25.1   Deferred 5GC-MT-LR Procedure for Periodic Location Events based NRPPa Periodic Measurement Reports
25.2   Subscription control for reference time distribution in EPS
25.3   Rel-19 IMS:
25.3.1   PS Data Off for IMS Data Channel Service
25.3.2   IMS Disaster Prevention and Restoration Enhancement
25.3.3   IMS Stage-3 IETF Protocol Alignment
25.4   Identifying non-3GPP Devices Connecting behind a UE or 5G-RG
25.5   Integrated Sensing and Communication
25.6   Rel-19 Application Data Analytics Enablement Service
25.7   Interworking of Non-3GPP Digital Terrestrial Broadcast Networks with 5GS Multicast Broadcast Services
25.8   Minimization of Service Interruption During Core Network Failure Phase 2
25.9   Measurement Data Collection
25.10  Enhanced application layer support for location services
25.11  NF discovery and selection by target PLMN
25.12  MSISDN verification operation support to Nnef_UEId Service
25.13  Rel-19 Enhancements of Network Automation Enablers
25.14  Enhancement of controlling RAT utilization
25.15  CT Aspects for IP Domain usage
25.16  Indirect Network Sharing
25.17  Management of Network Sharing Phase 3
25.18  Roaming Value-Added Services
25.19  Monitoring of signalling traffic in 5G
25.20  Roaming traffic offloading via session breakout in HPLMN
25.21  Stage-3 5GS NAS protocol development 18
25.22  Stage-3 SAE Protocol Development
25.23  Harmonization of test case definitions for cross-RAT usability
25.24  Data management regarding subscriptions and reporting
25.25  PRU Usage Extension supported by Core Network

26   Rel-19 miscellaneous Security
26.1   Security Assurance Specification for maintenance of 5G features
26.2   5G Security Assurance Specification (SCAS) for the Unified Data Repository (UDR)
26.3   5G Security Assurance Specification (SCAS) for the Short Message Service Function (SMSF)
26.4   Addition of 256-bit security Algorithms
26.5   Addition of Milenage-256 algorithm
26.6   Roaming and interconnect authorization aspects in indirect communication
26.7   Public key distribution and Issuer claim verification of the Access Token
26.8   3GPP profiles for cryptographic algorithms and security protocols
26.9   Mobility over non-3GPP access to avoid full primary authentication
26.10  LI Handling of Protected Services
26.11  Lawful Interception Rel-19
26.12  Lawful Interception Guidance Rel-19
26.13  Specification of example algorithm for alternative f5* (f5**) function

27   Rel-19 miscellaneous OAM&charging
27.1   Charging aspects for Multi-Operator Core Network (MOCN) Network Sharing
27.2   Service Based Management Architecture enhancement phase 3
27.3   Management Data Analytics phase 3
27.4   Intent driven management services for mobile network phase 3
27.5   Management of planned configurations
27.6   Management aspects of Network Digital Twins
27.7   Closed Control Loop Management
27.8   Data management phase 2
27.9   5G performance measurements and KPIs phase 4
27.10  5G Advanced NRM features phase 3
27.11  Subscriber and Equipment Trace and QoE collection management
27.12  Management of IAB nodes
27.13  Enhancement of Management Aspects Related of NWDAF Phase 2
27.14  CHF Segmentation
27.15  Subscriber Data Migration

You can download the latest version of the specs from here.

Related Post

Tuesday, January 20, 2026

Telecom Security Realities from 2025 and Lessons for 2026

Telecom security rarely stands still. Each year brings new technologies, new attack paths, and new operational realities. Yet 2025 was not defined by dramatic new exploits or spectacular network failures. Instead, it became a year that highlighted how persistent, patient and methodical modern telecom attackers have become.

The recent SecurityGen Year-End Telecom Security Webinar offered a detailed look back at what the industry experienced during 2025. The session pulled together research findings, real world incidents and practical lessons from across multiple domains, including legacy signalling, eSIM ecosystems, VoLTE vulnerabilities and the emerging world of satellite-based mobile connectivity.

For anyone working in mobile networks, the message was clear. The threats are evolving, but many of the core problems remain stubbornly familiar.

A Year of Stealth Rather Than Spectacle

One of the most important themes from the webinar was that 2025 did not bring a wave of highly visible disruptive telecom attacks. Instead, it was characterised by quiet, low profile intrusions that often went undetected for long periods.

Operators around the world reported that attackers increasingly favoured living-off-the-land techniques. Rather than deploying noisy malware, intruders looked for ways to gain legitimate access to core systems and remain hidden. Lawful interception platforms, subscriber databases such as HLR and HSS, and internal management platforms were all targeted.

The primary objective in many cases was intelligence collection. Attackers were interested in call data, subscriber information and network topology rather than immediate disruption. This shift in motivation makes detection far more difficult, as there are often few obvious signs of compromise.

At the same time, automation has become a defining feature on both sides of the security battle. Operators are investing heavily in AI and machine learning to identify abnormal behaviour. Attackers are doing exactly the same, using automation to scale phishing campaigns and to accelerate exploit development.

Despite all this technology, basic security discipline continues to be a major challenge. A significant proportion of incidents still originate from human error, poor operational practices or simple failure to apply patches. The industry continues to invest billions in cybersecurity, but much of that effort is consumed by reporting and compliance activities rather than direct threat mitigation.

eSIM Security Comes into Sharp Focus

The transition from physical SIM cards to eSIM and remote provisioning is one of the most significant structural changes in the mobile industry. It offers clear benefits in terms of flexibility and user experience. However, the webinar highlighted that it also introduces entirely new security concerns.

Traditional SIM security models relied heavily on physical control. Fraudsters needed access to large numbers of real SIM cards to operate at scale. With eSIM, many of those physical constraints disappear. Remote provisioning expands the number of parties involved in the connectivity chain, including resellers and intermediaries who may not always operate under strict regulatory oversight.

During 2025 several major SIM farm operations were dismantled by law enforcement. These infrastructures contained tens of thousands of active SIM cards and were used for large scale fraud, smishing campaigns and automated account creation. While such operations existed long before eSIM, the technology has the potential to make them even easier to deploy and manage.

Research discussed in the session pointed to additional concerns. Analysis of travel eSIM services revealed issues such as cross-border routing of management traffic, excessive levels of control granted to resellers, and lifecycle management weaknesses that could potentially be abused by attackers. In some cases, resellers were found to have capabilities similar to full mobile operators, but without equivalent governance or transparency.

The conclusion was not that eSIM is inherently insecure. The technology itself uses strong encryption and robust mechanisms. The problem lies in the wider ecosystem of trust boundaries, partners and processes that surround it. Securing eSIM therefore requires cooperation between operators, vendors, regulators and service providers.

SS7 Remains a Persistent Weak Point

Few topics in telecom security generate as much ongoing concern as SS7. Despite being a technology from a previous era, it remains deeply embedded in global mobile infrastructure. The webinar dedicated significant attention to why SS7 continues to be exploited in 2025 and why it is likely to remain a problem for many years to come.

Throughout the year, media reports and research papers continued to demonstrate practical abuses of SS7 signalling. Attackers probed networks, attempted to bypass signalling firewalls and looked for new ways to manipulate protocol behaviour. Techniques such as parameter manipulation and protocol parsing tricks were highlighted as methods that can sometimes evade existing protections.

One particularly interesting demonstration showed how SS7 messages could be used as a covert channel for data exfiltration. By embedding information inside otherwise legitimate signalling transactions, attackers can potentially move data across networks without triggering traditional security alarms.

Perhaps the most striking point raised was how little progress has been made in eliminating SS7 dependencies. Analysis of global network deployments showed that only a handful of countries operate mobile networks entirely without SS7. Everywhere else, the protocol remains a foundational element of roaming and interconnect.

As a result, even operators that have invested heavily in 4G and 5G security can still be undermined by weaknesses in this legacy layer. The uncomfortable reality is that SS7 vulnerabilities will continue to be exploited well into 2026 and beyond.

VoLTE and Modern Core Network Risks

While legacy protocols remain a problem, modern technologies are not immune. VoLTE infrastructure in particular was identified as an increasingly attractive target.

VoLTE relies on complex interactions between signalling systems, IP multimedia subsystems and subscriber databases. Weaknesses in configuration or interconnection can open the door to call interception, fraud or denial of service. Several real world incidents during 2025 demonstrated that attackers are actively exploring these paths.

The move toward fully virtualised and cloud-native mobile cores also introduces new operational challenges. Telecom networks now resemble large IT environments, complete with the same risks around misconfiguration, insecure APIs and exposed management interfaces.

The Emerging Security Challenge of 5G Satellites

One of the most forward-looking parts of the webinar focused on non-terrestrial networks and direct-to-device satellite connectivity. What was once a concept for the distant future is rapidly becoming a commercial reality.

Satellite integration promises to extend 5G coverage to remote areas, oceans and disaster zones. However, it also changes the security model in fundamental ways. Satellites can act either as simple relay systems or as active components of the mobile radio access network. In both cases, new threat vectors emerge.

Potential issues discussed included the risk of denial of service against shared satellite resources, difficulties in applying traditional radio security controls in space-based equipment, and the possibility of more precise user tracking due to the way satellite systems handle location information.

Experts from the space cybersecurity community explained how vulnerabilities in mission control software and ground segment infrastructure could be exploited. Much of this software was originally designed for isolated environments and is only now being connected to wider networks and the internet.

As telecom networks expand beyond the boundaries of the Earth, security responsibilities extend with them. Operators will need to think not only about terrestrial threats but also about risks originating from space-based components.

The Human Factor and the Skills Gap

Technology was only part of the story. Another recurring theme was the global shortage of skilled telecom cybersecurity professionals.

Studies referenced in the session suggested that millions of additional specialists are needed worldwide, yet only a fraction of that demand can currently be filled. Many security teams are overwhelmed by the sheer volume of alerts and data they must process.

This shortage has real consequences. When teams are stretched thin, patching is delayed, anomalies are missed and complex investigations become difficult to sustain. The panel emphasised that throwing more tools at the problem is not enough. Organisations must focus on training, automation and smarter operational processes.

Automation and AI-driven analysis were presented as essential enablers. Given the scale of modern mobile networks, it is simply not feasible for human analysts to monitor every signalling protocol, every core interface and every emerging technology manually.

Preparing for 2026

Looking ahead, the experts agreed on several broad trends. Attacks on legacy systems such as SS7 will continue. Fraudsters will increasingly target eSIM provisioning processes. VoLTE and 5G core components will face growing scrutiny. Satellite-based connectivity will introduce new and unfamiliar security questions.

Perhaps most importantly, the line between traditional telecom security and general cybersecurity will continue to blur. Mobile networks are now large, distributed IT platforms, and they inherit all the complexities that come with that transformation.

Operators, regulators and vendors must therefore adopt a holistic view. Investment must go beyond compliance reporting and focus on practical defences, real time monitoring and collaborative intelligence sharing.

Final Reflections

The SecurityGen webinar provided a valuable snapshot of an industry at a crossroads. Telecom networks are becoming more advanced and more capable, but also more complex and interconnected than ever before.

2025 demonstrated that attackers do not always need new vulnerabilities. Often they succeed simply by exploiting old weaknesses in smarter ways. The challenge for 2026 is to close those gaps while also preparing for the technologies that are only just beginning to emerge.

For those involved in telecom security, the full discussion is well worth watching. The complete webinar recording can be viewed below:

Related Posts:

Thursday, May 8, 2025

3GPP Release 18 Signal level Enhanced Network Selection (SENSE) for Smarter Network Selection in Stationary IoT

As 5G evolves and the number of deployed IoT devices increases globally, efficient and reliable network selection becomes ever more critical. Particularly for stationary devices deployed in remote, deep-indoor or roaming environments, traditional selection mechanisms have struggled to provide robust connectivity. This has led to operational challenges, especially for use cases involving low-power or hard-to-reach sensors. In response, 3GPP Release 18 introduces a new capability under the SA2 architecture work, Signal level Enhanced Network Selection (SENSE), designed to tackle this exact issue.

In today’s cellular systems, when a User Equipment (UE), including IoT modules, switches on or recovers from a loss of coverage, it performs automatic network selection. This typically prioritises networks based on preferences such as PLMN priority lists and broadcast cell selection criteria, while largely ignoring the actual signal strength at the device’s location. This approach works reasonably well for mobile consumer devices that can adapt through user movement or manual intervention. However, for stationary IoT UEs, which are often unmanned and deployed permanently in locations with limited or fluctuating radio conditions, this method can result in persistent suboptimal connectivity.

The issue becomes most evident when a device latches onto a visited PLMN (VPLMN) with higher priority despite poor signal quality. The UE might remain connected to this weak network, struggling to maintain bearer sessions or repeatedly failing data transfers. These failures often go undetected by the operator's monitoring systems and may require expensive manual intervention in the field. The cumulative impact of such maintenance activities adds significantly to operational expenditure, especially in mass-scale IoT deployments.

SENSE aims to fix this problem by making signal level an integral part of the automatic network selection and reselection process. Rather than simply following preconfigured priority rules, UEs enabled with SENSE will now assess the received signal quality during network selection. This allows them to favour networks that offer stronger and more stable radio conditions, even if they have lower priority, when such conditions are essential for reliable connectivity.

The capability is particularly targeted at stationary IoT UEs that support NB-IoT, EC-GSM-IoT, or LTE Cat-M1/M2. These devices are often used in applications such as water level monitoring, power grid sensors, and remote metering, installations where physical access post-deployment may be difficult or even infeasible.

To implement SENSE, the Home PLMN (HPLMN) can configure the UE to apply Operator Controlled Signal Thresholds (OCST) for each supported access technology. These thresholds are stored within the USIM and define the minimum signal quality required for a network to be considered viable. The OCST settings can be provisioned before deployment or updated later via standard NAS signalling mechanisms, including the Steering of Roaming (SoR) feature.

When a SENSE-enabled UE attempts to select a network, it checks whether the signal level from any candidate network meets or exceeds the configured OCST for its supported radio access technologies. If it does, the UE proceeds to register with that PLMN. If no suitable network meets the signal thresholds, the UE falls back to the legacy selection process, which excludes signal strength as a factor. This dual-iteration method ensures backward compatibility while enabling more robust performance where SENSE is supported.

Additionally, SENSE influences periodic network reselection. If the average signal quality from a registered PLMN drops below the OCST threshold over time, the UE will proactively seek alternative PLMNs whose signals meet the configured criteria. This continuous evaluation helps avoid long-term connectivity issues that may otherwise remain unnoticed.

SENSE is not intended to disrupt roaming steering or PLMN preferences altogether. Instead, it introduces a smart, context-aware filter that empowers the UE to make better decisions when radio conditions are poor. By integrating signal level awareness early in the selection logic, operators gain a powerful new tool to reduce failure rates and minimise costly field maintenance.

As the IoT landscape expands across industries and geographies, features like SENSE will play a vital role in supporting dependable, scalable and autonomous deployments. In Release 18, 3GPP has taken a meaningful step towards improving network availability for devices that need to just work, no matter where they are.

Related Posts

Thursday, December 19, 2024

Evolution and Impact of Cellular Location Services (LCS)

Location Services (LCS) have been standardized by 3GPP across all major generations of cellular technology, including 2G (GSM), 3G (UMTS), 4G (LTE), and 5G. These services enable applications to determine the geographical location of mobile devices, facilitating crucial functions such as emergency calls, navigation, and location-based advertising. The consistent adoption of standardized protocols ensures interoperability, scalability, and reliability, empowering mobile operators and device manufacturers to implement location services in a globally consistent manner.

The evolution of LCS technology has seen remarkable advancements with each generation of cellular networks. Early implementations in 2G and 3G relied on basic techniques such as Cell-ID, Timing Advance, and triangulation, which offered limited accuracy and were suitable only for rudimentary use cases. 

The introduction of LTE in 3GPP Release 9 marked a significant improvement, integrating support for regulatory services like emergency call localization and commercial applications such as mapping. LTE networks commonly employ global navigation satellite systems (GNSS), like GPS, to determine locations. However, alternative methods using the LTE air interface are crucial in scenarios where GNSS signals are obstructed, such as indoors or in dense urban environments. An LTE network can support horizontal positioning accuracy of 50m for 80% of mobiles and a vertical positioning accuracy of 5m and an end-to-end latency of 30 seconds.


In 5G, the introduction of high-bandwidth, low-latency communication and new architectural enhancements allows for even more accurate and responsive location services. These improvements support critical use cases like autonomous vehicles, smart cities, and industrial IoT applications. 

5G networks have further improved LCS with high-bandwidth, low-latency communication and architectural enhancements. These innovations enable critical applications like autonomous vehicles, smart cities, and industrial IoT. In Release 15, 5G devices support legacy LTE location protocols through the Gateway Mobile Location Centre (GMLC). From Release 16, the Network Exposure Function (NEF) streamlines location requests for modern applications. A 5G network is expected to deliver a horizontal positioning accuracy of 3m indoors and 10m outdoors, a vertical positioning accuracy of 3m in both environments and an end-to-end latency of one second.

The standardization efforts of 3GPP have ensured that location services meet stringent requirements for accuracy, privacy, and security. Emergency services, for instance, benefit from these standards through Enhanced 911 (E911) in the United States and similar mandates globally, which require precise location reporting for mobile callers. Furthermore, standardization fosters innovation by providing a common foundation on which developers can create new location-based services and applications. As cellular networks continue to evolve, 3GPP’s standardized LCS will remain a cornerstone in bridging connectivity with the physical world, enabling smarter, safer, and more connected societies.

Mpirical recently shared a video exploring the concepts and drivers of Location Services (LCS). It's embedded below:

If you want to learn more about LCS, check out Mpirical's training course on this topic which seeks to provide an end to end exploration of the techniques and technologies involved, including the driving factors, standardization, requirements, architectural elements, protocols and protocol stacks, 2G-5G LCS operation and location finding techniques (overview and specific examples).

Mpirical is a leading provider of telecoms training, specializing in mobile and wireless technologies such as 5G, LTE, and IoT. They boast a course catalogue of wide ranging topics and technologies for all levels, with each course thoughtfully broken down into intuitive learning modules. 

Related Posts

Thursday, October 24, 2024

4G/LTE, 5G and Private Networks in Africa

The Global mobile Suppliers Association (GSA) recently released its "Regional Spotlight Africa – October 2024" report. It tracks 604 public mobile networks across North and Sub-Saharan Africa, including LTE, LTE-Advanced, 5G, and fixed wireless access networks. The report gives an up-to-date view of 4G and 5G deployment in Africa, using the latest data and insights from GSA's various reports on mobile networks and satellite services.

Africa has seen major progress in telecommunications in recent years. The expansion of 4G LTE networks has improved data speeds, enhanced connectivity, and supported the spread of mobile broadband services. Looking ahead, 5G technology promises even faster speeds, lower latency, and stronger security, opening the door to new possibilities in connectivity.

The report covers key areas of mobile network development, such as:

  • The current state of LTE and 5G rollouts
  • LTE-Advanced advancements
  • 5G standalone networks
  • The growth of private networks
  • Phasing out 2G and 3G technologies
  • Progress in satellite services

Alongside the report, GSA hosted a regional webinar where the research team shared insights on:

  • The status of LTE and LTE-Advanced in Africa and how it compares globally
  • Whether 5G development is being delayed by ongoing LTE rollouts and older devices
  • Recent spectrum auctions and assignments
  • The transition from 2G and 3G networks
  • The potential for satellite non-terrestrial (NTN) services in Africa and how operators are responding

The webinar video is available below.

Related Posts: