SSB & Cell Search — How a Phone Finds a Cell in 5G NR
Power-on to sync: frequency scan & RSSI, the SSB, PSS/SSS and PBCH/MIB — every what, why and how.
A UE that has just been switched on knows nothing useful. It does not know what frequency to listen on, it does not know when a symbol starts or when a frame starts, and it does not know the name of any cell around it. Cell search is the procedure that resolves all three from a signal the UE has to find without being told where it is. Everything in this document — the shape of the SS/PBCH block, the three separate frequency rasters, the split of the cell identity across two signals, the beam sweep, the 20 ms assumption — is a trade against how long that blind search takes. This document separates the global, channel and synchronisation rasters properly, because they are constantly conflated; maps the SS/PBCH block resource element by resource element; derives the physical cell identity in both directions; walks the search procedure from the first correlation to SIB1; and closes with eleven figures, nine worked calculations, eleven failure modes and a log-reading checklist.
Contents
- 01What the UE Does Not Know at Power-On
- 02The Cost of Blind Search, in Seconds
- 03Three Rasters, and Why There Have To Be Three
- 04The Global Frequency Raster and the NR-ARFCN
- 05The Channel Raster: Which ARFCNs May Be a Carrier Centre
- 06The Synchronisation Raster and the GSCN
- 07Per-Band GSCN Ranges, With n78 Worked Through
- 08The SS/PBCH Block, Resource Element by Resource Element
- 09PSS: Three Sequences, Found With No Timing At All
- 10SSS, and the Cell Identity Completed
- 11The Search Procedure, Step by Step
- 12The SSB Index: What the DM-RS Says Before the MIB Does
- 13The Half-Frame Bit, and Why the SFN Arrives in Three Pieces
- 14SSB Burst Sets: Cases A Through E
- 15ssb-PositionsInBurst: What Is Actually Transmitted
- 16SSB Periodicity and the 20 ms Assumption
- 17Where the SSB Sits Relative to the Carrier: k_SSB and offsetToPointA
- 18From Search to Measurement: the SSB's Second Job
- 19Parameter and Range Reference
- 20Failure Modes and What Each One Means
- 21Configuration Reference (ASN.1)
- 22Nine Worked Calculations
- 23Illustrative Message Traces
- 24Release Deltas: Rel-15 to Rel-18
- 25Reading Cell Search in Logs: A Checklist
- 26Glossary
- 27References
1. What the UE Does Not Know at Power-On
Start with the honest position. A UE that has just been powered on, or that has just walked out of a tunnel, holds no information about the radio world around it. It does not know which frequency any base station is transmitting on. It does not know when an OFDM symbol begins, so it cannot run a Fourier transform in a way that produces anything but noise. It does not know when a radio frame begins, so even a perfectly decoded message would carry no timestamp it could use. And it does not know the identity of any cell, so it has nothing to tell the network about where it is.
That is four separate unknowns, and they are circular. You cannot demodulate without timing. You cannot get timing without knowing which frequency to look at. You cannot know which frequency to look at without having found something. Cell search is the procedure that breaks the circle, and the way it breaks it is with a signal whose shape is known in advance even though its position is not — a signal a receiver can recognise by correlation rather than by decoding.
That signal is the SS/PBCH block, universally shortened to SSB. SS stands for Synchronisation Signals and PBCH for Physical Broadcast Channel; the block bundles both into one small, rigidly specified rectangle of the time-frequency grid. It is the only thing in NR a UE can find with no prior information whatsoever, and everything else the UE ever does hangs off having found it.
| What the UE must end up holding | Where in the SSB it comes from | How long it takes | What it unlocks |
|---|---|---|---|
| A carrier frequency it can tune to | The SSB was found at a known GSCN — a numbered slot on the synchronisation raster (§6) — so the frequency is known the moment the block is detected | The whole scan, and this is the expensive part | Everything. Without it the UE is still deaf |
| Symbol timing and coarse frequency correction | PSS correlation peak in symbol 0 (§9) | A few tens of ms per candidate frequency once a peak exists | The ability to run an FFT that produces meaningful subcarriers |
| The physical cell identity, 0 to 1007 | PSS gives 1 of 3, SSS gives 1 of 336, and the two combine (§10) | One further SSB occasion after PSS | Descrambling of everything else in the cell, and the identity the UE reports in measurements |
| Which beam of the cell it is hearing | The PBCH DM-RS sequence, and on FR2 three payload bits as well (§12) | Free — it falls out of the DM-RS correlation the UE has to do anyway | The right PRACH occasion and preamble group to answer on |
| Frame and half-frame number | 6 SFN bits in the MIB, 4 more in the PBCH payload, the half-frame bit, and 2 bits carried by the PBCH scrambling (§13) | Up to one 80 ms PBCH period | Any scheduled reception at all — paging, SI windows, PRACH occasions |
| The MIB, and through it CORESET#0 | The PBCH payload (companion 18 MIB and SIB1 IEs) | One successful Polar decode | SIB1, and with it the whole of the cell's common configuration |
Table 1. The six things cell search produces, in the order it produces them. Each row depends on every row above it — this is a chain, not a checklist.
An analogy, and it is only an analogy. The UE is looking for a radio station on a dial it has never tuned, in a country whose broadcasting plan it has not been given — it knows neither the frequency, nor the programme schedule, nor the station's name. What makes the problem tractable is that the dial has detents: the regulator has agreed in advance that stations may only sit at certain marked positions, so the listener clicks from detent to detent instead of sweeping continuously. The synchronisation raster is that set of detents, and §3 to §7 are about how coarse the detents are and why. The analogy breaks down as soon as beams enter the picture — a broadcast station does not point at you — so it is dropped after §7.
2. The Cost of Blind Search, in Seconds
It is worth being concrete about the search-time problem before looking at any of the machinery, because the machinery only makes sense as an answer to it. Searching for a signal you cannot predict costs time in proportion to the number of guesses you have to make. Every guess about frequency has to be tested by listening for long enough to be confident the signal is genuinely absent rather than merely weak, and "long enough" is measured in whole SSB repetition periods, not in microseconds.
So the search time is roughly the number of candidate frequencies multiplied by the dwell time per candidate. Both factors are design choices, and 3GPP pushed on both:
- The number of candidate frequencies is bounded by making the synchronisation raster deliberately coarse and then, per band, publishing a short list of the raster points that are actually allowed there. On band n78 that list has 341 entries. If the SSB could sit anywhere on the channel raster it would have about 33 000.
- The dwell time per candidate is bounded by requiring the SSB to repeat at least every 20 ms for the purposes of initial search TS 38.213 cl. 4.1, regardless of what the cell has actually configured. A UE therefore never has to wait longer than 20 ms to know whether it should have heard something.
The search-time budget, order of magnitude.
Take band n78 and a UE with nothing stored — a genuine cold start.
Candidate frequencies (GSCN points in n78) = 341 (§7)
Assumed SSB periodicity for initial search = 20 ms
Burst sets accumulated before declaring absence ≈ 5
Dwell per candidate = 5 × 20 ms = 100 ms
Serial worst case = 341 × 100 ms ≈ 34 s
Now the same sum if the SSB were allowed anywhere on n78's 15 kHz channel raster:
Candidates = (653333 − 620000) + 1 = 33 334
Serial worst case = 33 334 × 100 ms ≈ 56 minutes
The 98-fold ratio between those two numbers is the entire justification for having a separate, sparser synchronisation raster. Real receivers do far better than the serial figure — they test many candidate frequencies inside one wideband capture — but the number of correlation hypotheses scales with the candidate count either way, and that is what costs silicon, battery and time. Treat both numbers as order of magnitude, not as a specified requirement.
Three consequences follow, and they explain design decisions that look arbitrary in isolation:
| Design decision | The search-time reason for it | What it would cost to do otherwise |
|---|---|---|
| PSS has only three variants | PSS is correlated at every candidate frequency and every possible symbol offset, so its variant count multiplies the most expensive part of the search | 336 PSS variants would multiply the blind-search correlation load by 112 for no gain — the identity can be carried later, cheaply |
| The identity is split across PSS and SSS | SSS is searched only after timing is known, so its 336 variants cost one correlation window, not a sweep | Putting all 1008 identities in one signal makes that signal either expensive to search or too long to be robust |
| The sync raster step is 1.44 MHz above 3 GHz, not 15 kHz | It cuts the candidate count by roughly two orders of magnitude | The 56-minute figure above |
| Per-band GSCN ranges are published, not just the raster | A UE searching n78 tests 341 points, not the 14 757 the raster defines between 3 and 24.25 GHz | A 43× longer scan for any band-limited UE |
| Initial search assumes 20 ms periodicity | It bounds the dwell without forcing every cell to transmit that often forever | An unbounded dwell: a UE could not distinguish "nothing here" from "something here on a 160 ms cycle" |
ssb-PositionsInBurst lets a cell send fewer SSBs than L_max | Not a search-time saving for the UE, but an overhead saving for the cell — a 4-beam cell does not pay for 8 candidate positions | Wasted downlink resource, and interference at positions nothing needs |
Table 2. Six choices in the SSB and raster design, each traced back to the search-time budget. Section references in the middle column point at where the mechanism is described.
3. Three Rasters, and Why There Have To Be Three
This is the section that exists because the word raster is used for three different things and they get mixed up constantly. A raster, plainly, is an agreed grid of permitted frequencies — a list of the only places something is allowed to sit. NR has three such grids, nested inside one another, each answering a different question:
- The global frequency raster. Question: what shall we call this frequency? It is a numbering scheme covering everything from 0 to 100 GHz in fixed steps, so that any frequency the system can name has exactly one number. That number is the NR-ARFCN (NR Absolute Radio Frequency Channel Number). It grants no permission at all; it is a dictionary, not a rule.
- The channel raster. Question: where may the centre of a carrier sit? This is a per-band subset of the global raster. Its step size is called ΔF_Raster and it varies by band — 100 kHz for many older FR1 bands, 15 or 30 kHz for the newer mid-band ones. It constrains network planning, and it is what an operator's carrier centre frequency is quoted against.
- The synchronisation raster. Question: where may an SSB sit? This is a much sparser grid again, with its own numbering — the GSCN, Global Synchronisation Channel Number. It is the list of detents on the dial from §1, and it is deliberately coarse because a UE has to search it blind.
k_SSB and offsetToPointA exist to express (§17).| Global raster | Channel raster | Synchronisation raster | |
|---|---|---|---|
| Answers | What is this frequency called? | May a carrier centre go here? | May an SSB go here? |
| Numbering | NR-ARFCN, N_REF | NR-ARFCN, a subset of N_REF | GSCN, its own independent numbering |
| Step | 5 / 15 / 60 kHz by frequency range | ΔF_Raster: 100 kHz, or 15 / 30 kHz, per band | 1.2 MHz (+50 kHz sub-steps) / 1.44 MHz / 17.28 MHz by range |
| Scope | Universal, 0 – 100 GHz | Per band, from TS 38.101-1 and -2 | Per range for the grid, then per band for the usable list |
| Who is constrained | Nobody — it is a naming convention | The operator, when planning carriers | Both: the operator when placing the SSB, and the UE when searching |
| Points across n78 (3300 – 3800 MHz) | 33 334 at 15 kHz | 33 334 at ΔF_Raster 15 kHz, or 16 667 at 30 kHz | 341 |
| Specified in | TS 38.104 cl. 5.4.2.1 | TS 38.104 cl. 5.4.2.2 and TS 38.101-1 cl. 5.4.2.3 | TS 38.104 cl. 5.4.3 |
Table 3. The three rasters side by side. The bottom-but-one row is the one worth memorising: on a single band the three grids differ by two orders of magnitude in density.
The three are related but not nested in the way people assume. The channel raster is a subset of the global raster — every carrier centre is a valid NR-ARFCN. The synchronisation raster is not a subset of the channel raster, and on many bands it is not even a subset of the global raster in any useful sense, because 1.2 MHz plus a 50 kHz M-offset does not have to coincide with a 100 kHz channel raster point. A GSCN is therefore reported as a GSCN, never converted to an ARFCN and quoted as one. An analyser that shows you an "SSB ARFCN" has done a conversion that may not be exact.
4. The Global Frequency Raster and the NR-ARFCN
The global raster is the simplest of the three and the easiest to explain in words: it is a ruler laid along the whole usable spectrum, with marks at regular intervals, and every mark has a number. The numbering starts at zero at DC and counts upward. Because the useful step size is not the same at 700 MHz as it is at 39 GHz — a 5 kHz step would need twenty million numbers to reach 100 GHz — the ruler changes its step twice, at 3 GHz and at 24.25 GHz.
The conversion from number to frequency is one equation TS 38.104 cl. 5.4.2.1:
F_REF = F_REF_Offs + DELTA_F_Global x ( N_REF - N_REF_Offs ) F_REF the RF reference frequency, in Hz N_REF the NR-ARFCN -- the channel number itself DELTA_F_Global the global raster step for this frequency range F_REF_Offs the frequency at which this range's counting starts N_REF_Offs the channel number at which this range's counting starts
In plain terms: the ARFCN is just a channel number, and this equation converts it to a frequency in hertz by counting a whole number of fixed-size steps up from a fixed starting point. The two Offs quantities exist only so that the three ranges join up without overlapping or leaving a gap — each range restarts its counting where the previous one stopped.
| Frequency range | ΔF_Global | F_REF_Offs | N_REF_Offs | N_REF range | Top frequency reachable |
|---|---|---|---|---|---|
| 0 – 3000 MHz | 5 kHz | 0 MHz | 0 | 0 – 599999 | 599999 × 5 kHz = 2999.995 MHz |
| 3000 – 24250 MHz | 15 kHz | 3000 MHz | 600000 | 600000 – 2016666 | 3000 + 1416666 × 15 kHz = 24249.99 MHz |
| 24250 – 100000 MHz | 60 kHz | 24250.08 MHz | 2016667 | 2016667 – 3279165 | 24250.08 + 1262498 × 60 kHz = 99999.96 MHz |
Table 4. The three global raster ranges, TS 38.104 Table 5.4.2.1-1. The last column is the arithmetic check that each range really does reach its stated ceiling — worth doing once, because an off-by-one in N_REF_Offs is a silent 15 kHz error in everything downstream.
Why 24250.08 MHz and not 24250 MHz? Because the 60 kHz range has to start on a frequency that is a whole number of 60 kHz steps above something sensible, and because FR2 channels are defined with a 60 kHz granularity throughout. 24250.08 = 24250 + 0.08 MHz, and 80 kHz is not a multiple of 60 kHz — but 24250.08 MHz is the frequency that makes the subsequent 17.28 MHz synchronisation raster (§6) land on whole numbers of 120 kHz PRBs. The offset is chosen for the sync raster's benefit, not the channel raster's.
Three ARFCN conversions, one per range.
Range 1. N_REF = 431000.
F = 0 + 5 kHz × (431000 − 0) = 2 155 000 kHz = 2155.000 MHz
In band n1 downlink (2110 – 2170 MHz). Divisible by 20, so it is also a valid n1 channel raster point (§5).
Range 2. N_REF = 638884.
F = 3000 MHz + 15 kHz × (638884 − 600000)
= 3000 MHz + 15 kHz × 38884 = 3000 + 583.26 = 3583.26 MHz
In band n78 (3300 – 3800 MHz). This is the carrier centre used throughout §17 and §22.
Range 3. N_REF = 2079167.
F = 24250.08 MHz + 60 kHz × (2079167 − 2016667)
= 24250.08 + 60 kHz × 62500 = 24250.08 + 3750 = 28000.08 MHz
In band n257 (26500 – 29500 MHz).
Note the shape of all three: subtract the offset, multiply by the step, add the base. Nothing else is going on.
5. The Channel Raster: Which ARFCNs May Be a Carrier Centre
The global raster names every frequency; the channel raster says which of those names an operator is actually allowed to use for the centre of a carrier. It is a filter, nothing more: take the global raster, keep every Nth point, throw the rest away. The keep-every-Nth spacing is called ΔF_Raster and it is fixed per band in TS 38.101-1 for FR1 and TS 38.101-2 for FR2.
Why do bands differ? Because bands were defined at different times, for different technologies, by different regulators. A band that was originally an LTE band inherits LTE's 100 kHz planning grid, because existing licences, existing filters and existing planning tools all assume it. A band defined for NR from the start can afford a finer grid — 15 or 30 kHz, matching the subcarrier spacing — which lets an operator place a carrier so that it fits its licensed block exactly rather than wasting up to 100 kHz at one edge. Finer is better for spectral efficiency and worse for interoperability with anything that predates it.
| Band | Range (MHz) | Duplex | ΔF_Raster | Step in N_REF | Why that value |
|---|---|---|---|---|---|
| n1 | 2110 – 2170 DL | FDD | 100 kHz | 20 | Refarmed IMT-2000 band; inherits the LTE planning grid |
| n3 | 1805 – 1880 DL | FDD | 100 kHz | 20 | Refarmed 1800 MHz; same reason |
| n28 | 758 – 803 | FDD | 100 kHz | 20 | APT700; licences predate NR |
| n41 | 2496 – 2690 | TDD | 15 kHz 30 kHz | 3 6 | NR-era band; two options, chosen to match the deployed SCS |
| n77 | 3300 – 4200 | TDD | 15 kHz 30 kHz | 1 2 | In range 2, so ΔF_Global is already 15 kHz — step 1 means every global raster point is usable |
| n78 | 3300 – 3800 | TDD | 15 kHz 30 kHz | 1 2 | As n77; the workhorse mid-band |
| n79 | 4400 – 5000 | TDD | 15 kHz 30 kHz | 1 3 | As n77; note the 30 kHz option is step 3, not 2 |
| n257 | 26500 – 29500 | TDD | 60 kHz 120 kHz | 1 2 | FR2; ΔF_Global is 60 kHz, so step 1 is the finest possible |
Table 5. Channel raster spacing for a representative spread of bands, from TS 38.101-1 Table 5.4.2.3-1 and TS 38.101-2 Table 5.4.2.3-1. Where two values are listed the band supports two carrier subcarrier spacings and the raster follows. Always read the current table for the band you are actually working on — these change between releases as bands are extended.
Reading a channel raster constraint. Band n1 has ΔF_Raster = 100 kHz and lies in global range 1 where ΔF_Global = 5 kHz. So the N_REF step is 100 / 5 = 20, and a valid n1 carrier centre must have an NR-ARFCN divisible by 20.
N_REF = 431000 → 431000 / 20 = 21550 exactly → valid
N_REF = 431003 → not divisible by 20 → invalid as a carrier centre, though it is a perfectly good NR-ARFCN
Both numbers name real frequencies. Only the first one may be a carrier centre. That distinction is the whole content of the channel raster.
For planning purposes the channel raster interacts with two other constraints that are easy to forget. First, the carrier must fit inside the band: the centre frequency plus half the transmission bandwidth must not exceed the band edge, which pulls the usable centre frequencies in from both ends by half a carrier. Second, the carrier's own resource block grid has to be expressible — the relationship between the carrier centre, the transmission bandwidth in PRBs and the guard bands is fixed by TS 38.101-1 cl. 5.3, and the companion 02 Radio Frame Structure document has the PRB tables.
6. The Synchronisation Raster and the GSCN
Now the raster that matters most for this document. The synchronisation raster is the list of frequencies at which an SSB is permitted to be centred, and it is far coarser than either of the other two. The reason is the one from §2 and it is worth stating flatly: every extra permitted position costs the UE real seconds of blind search, so the specification made the list as short as it could while still leaving operators somewhere sensible to put the block in every band. Coarseness here is not laziness; it is the product.
Each permitted position has a number of its own, the GSCN. The GSCN is not an ARFCN and does not share its numbering — it is a separate, compact index that runs from 2 to 26639 across the entire spectrum. There are three regions, matching the three global raster ranges but with completely different arithmetic TS 38.104 cl. 5.4.3.1:
0 - 3000 MHz
SS_REF = N x 1200 kHz + M x 50 kHz N = 1 .. 2499, M in {1, 3, 5}
GSCN = 3N + (M - 3) / 2 GSCN = 2 .. 7498
3000 - 24250 MHz
SS_REF = 3000 MHz + N x 1.44 MHz N = 0 .. 14756
GSCN = 7499 + N GSCN = 7499 .. 22255
24250 - 100000 MHz
SS_REF = 24250.08 MHz + N x 17.28 MHz N = 0 .. 4383
GSCN = 22256 + N GSCN = 22256 .. 26639In plain terms, all three lines say the same thing: pick an integer, multiply it by a fixed step, add a fixed base, and you have the centre frequency of a permitted SSB position. The GSCN is simply that integer shifted so that the three regions produce one continuous, non-overlapping numbering. Two details deserve their own explanation.
6.1 What M is for, and why it only exists below 3 GHz
Below 3 GHz the step is not really 1.2 MHz. Each 1.2 MHz position is split into three sub-positions 50 kHz apart, selected by M ∈ {1, 3, 5} — that is, at −50 kHz, 0 and +50 kHz relative to the nominal N × 1.2 MHz point, since M = 3 gives 150 kHz and the other two give 50 and 250 kHz. M = 3 is the ordinary case and is what the great majority of deployed cells use.
M exists because the sub-3 GHz bands are almost all refarmed from LTE or earlier, with licensed blocks whose edges do not line up with a 1.2 MHz grid. Without the ±50 kHz freedom there would be bands in which no legal SSB position existed at all inside a narrow licence. Above 3 GHz the bands are wide and NR-native, the problem does not arise, and M was dropped — which is why a GSCN step of 1 means 1.44 MHz above 3 GHz but only 50 kHz below it.
This is the single most common arithmetic mistake with GSCN. A GSCN step of 1 does not mean the same thing in the two regions. Below 3 GHz, consecutive GSCN values walk the M sub-positions: 5276, 5277, 5278 are 50 kHz apart, and only every third one (M = 3) is the "nominal" 1.2 MHz position. Above 3 GHz, consecutive GSCN values are a full 1.44 MHz apart. A per-band GSCN range of 141 entries below 3 GHz is therefore only 47 distinct 1.2 MHz positions, whereas 141 entries above 3 GHz would be 141 genuinely separate frequencies.
6.2 Why the steps above 3 GHz are what they are
The two upper steps look like arbitrary decimals and are not. They are chosen to be whole numbers of resource blocks at the subcarrier spacing that band range uses:
| Region | Sync raster step | In PRBs | Consequence |
|---|---|---|---|
| 3 – 24.25 GHz | 1.44 MHz | 4 PRB at 30 kHz (4 × 360 kHz), or 2 PRB at 60 kHz, or 8 PRB at 15 kHz | An SSB placed on this raster is already nearly aligned to the common resource block grid, so the residual offset k_SSB has to express is at most a few subcarriers (§17) |
| 24.25 – 100 GHz | 17.28 MHz | 12 PRB at 120 kHz (12 × 1.44 MHz), or 24 PRB at 60 kHz | Same argument at FR2 scale. It is also 12 × the lower region's step, which keeps the two regions' arithmetic related |
| 0 – 3 GHz | 1.2 MHz nominal, ±50 kHz | 1.2 MHz = 6⅔ PRB at 15 kHz — not a whole number, and the 50 kHz offsets are not either | The SSB can be badly misaligned to the CRB grid here, which is why k_SSB needs five bits and 15 kHz units in FR1 rather than four bits (§17) |
Table 6. The raster steps are chosen for grid alignment, and the one region where alignment was impossible is the one region where k_SSB needs an extra bit. The two facts are the same fact.
GSCN to frequency, and back again, on n78.
Forward. A log reports the cell's SSB at GSCN 7883.
7883 > 7499, so this is the 3 – 24.25 GHz region.
N = 7883 − 7499 = 384
SS_REF = 3000 MHz + 384 × 1.44 MHz = 3000 + 552.96 = 3552.96 MHz
At 30 kHz SCS the block is 240 × 30 kHz = 7.2 MHz wide, so it spans
3552.96 ± 3.6 MHz = 3549.36 to 3556.56 MHz.
Reverse. A spectrum capture shows an SSB centred on 3679.68 MHz. Which GSCN?
N = (3679.68 − 3000) / 1.44 = 679.68 / 1.44 = 472 exactly
GSCN = 7499 + 472 = 7971
If that division had not come out as an integer, the SSB would not be on the raster and no compliant UE would ever find it — see §20.
7. Per-Band GSCN Ranges, With n78 Worked Through
The raster equations of §6 define far more positions than any UE ever tests. Between 3 and 24.25 GHz alone there are 14 757 of them. A UE searching band n78 does not test 14 757 frequencies; it tests the ones that fall inside n78 and are listed as usable for that band. That list is published per band, as a first value, a step and a last value, in TS 38.104 Table 5.4.3.3-1.
The list is narrower than "every raster point inside the band" for a practical reason: the SSB has to fit inside a carrier, and the carrier has to fit inside the band. A raster point 1 MHz from the band edge is arithmetically fine and physically useless, because no legal carrier of the band's minimum bandwidth could contain an SSB there. So the ends get trimmed.
| Band | Band range (MHz) | SSB SCS | Case | GSCN first – step – last | Points |
|---|---|---|---|---|---|
| n1 | 2110 – 2170 | 15 kHz | A | 5279 – <1> – 5419 | 141 |
| n3 | 1805 – 1880 | 15 kHz | A | 4517 – <1> – 4693 | 177 |
| n78 | 3300 – 3800 | 30 kHz | C | 7711 – <1> – 8051 | 341 |
| n77 | 3300 – 4200 | 30 kHz | C | 7711 – <1> – 8329 | 619 |
| n79 | 4400 – 5000 | 30 kHz | C | 8480 – <16> – 8880 | 26 |
| n257 | 26500 – 29500 | 120 kHz | D | 22388 – <1> – 22558 | 171 |
Table 7. Six bands from TS 38.104 Table 5.4.3.3-1. Bands that support two SSB subcarrier spacings appear twice in the real table, once per SCS, with different GSCN ranges — n41 is the usual example. Always read the entry for the SSB SCS the cell actually uses, and read it from the release your equipment implements: ranges have been extended as bands were widened.
Checking a per-band GSCN range makes sense — n78, both ends.
n78 is 3300 – 3800 MHz. At 30 kHz the SSB is 7.2 MHz wide, so it occupies SS_REF ± 3.6 MHz.
Bottom of the list, GSCN 7711:
N = 7711 − 7499 = 212 → SS_REF = 3000 + 212 × 1.44 = 3305.28 MHz
Block spans 3301.68 – 3308.88 MHz. Inside the band, with 1.68 MHz to spare below.
Top of the list, GSCN 8051:
N = 8051 − 7499 = 552 → SS_REF = 3000 + 552 × 1.44 = 3794.88 MHz
Block spans 3791.28 – 3798.48 MHz. Inside the band, with 1.52 MHz to spare above.
Count: 8051 − 7711 + 1 = 341 candidate frequencies, each a full 1.44 MHz from the next.
The next raster point up, GSCN 8052 at 3796.32 MHz, would still fit its own 7.2 MHz block inside the band — but not a 10 MHz carrier around it, which is why the list stops where it does.
In practice a UE almost never runs the full 341-point scan. It searches in priority order: frequencies stored from the last successful connection first, then frequencies supplied by a previous cell in redirectedCarrierInfo or in measurement configuration, then the band's full list. A log that shows a full band sweep is telling you the UE had nothing stored and nothing was suggested — which is itself worth noticing, because it usually means the previous release or reject carried no redirect. See the companion 01 Registration Process.
8. The SS/PBCH Block, Resource Element by Resource Element
The SSB is a fixed rectangle: four OFDM symbols by 240 contiguous subcarriers. 240 subcarriers is 20 resource blocks, so the block is 7.2 MHz wide at 30 kHz spacing, 3.6 MHz at 15 kHz, 28.8 MHz at 120 kHz. Nothing about that rectangle is configurable. It cannot be, because a UE has to be able to recognise it without having been told anything, and you cannot recognise a shape that varies.
Inside the rectangle, four things share the space: the primary synchronisation signal, the secondary synchronisation signal, the broadcast channel, and the broadcast channel's own reference signal. Their positions are given exactly in TS 38.211 cl. 7.4.3.1, Table 7.4.3.1-1, and the companion 02 Radio Frame Structure document has the same mapping at survey level. What follows adds the two things that survey does not: the guard regions dimensioned, and the reference-signal comb at resource-element resolution.
| Symbol l | k = 0..47 | k = 48..55 | k = 56..182 | k = 183..191 | k = 192..239 |
|---|---|---|---|---|---|
| 0 | zero | zero | PSS (127 sc) | zero | zero |
| 1 | PBCH + DM-RS | PBCH + DM-RS | PBCH + DM-RS | PBCH + DM-RS | PBCH + DM-RS |
| 2 | PBCH + DM-RS | zero (8 sc guard) | SSS (127 sc) | zero (9 sc guard) | PBCH + DM-RS |
| 3 | PBCH + DM-RS | PBCH + DM-RS | PBCH + DM-RS | PBCH + DM-RS | PBCH + DM-RS |
Table 8. TS 38.211 Table 7.4.3.1-1, laid out by subcarrier range. k is counted from the block's own lowest subcarrier, so k = 0 is not a carrier subcarrier index — converting between the two is what §17 is about.
8.1 The guard bands around SSS, and what they cost
The eight subcarriers below the SSS and the nine above it are transmitted as zero. They are there so that PBCH energy in the same symbol does not leak into the SSS correlation through the receiver's channel filter — the SSS is being detected at low signal-to-noise ratio and against 336 hypotheses, and adjacent-subcarrier interference from a signal 20 dB stronger would matter. The asymmetry, eight below and nine above, is simply because 240 − 127 = 113 is odd and the SSS is centred as nearly as it can be.
Those seventeen zeroed subcarriers, plus the requirement to leave the SSS's own 127 alone, are the reason PBCH gets 576 resource elements rather than the 720 that three full symbols would give:
From resource elements to the PBCH code rate.
PBCH REs = 240 (symbol 1) + 96 (symbol 2) + 240 (symbol 3) = 576
Symbol 2's 96 = 48 below the guard + 48 above it
DM-RS = 576 / 4 = 144 REs (60 + 24 + 60)
Data REs = 576 − 144 = 432
QPSK, 2 bits per RE → 864 coded bits
Payload = 24 MIB bits + 8 bits added by the physical layer = 32
Plus a 24-bit CRC = 56 bits in, Polar-encoded, rate-matched to 864
Effective code rate ≈ 56 / 864 ≈ 0.065
That is an extraordinarily low code rate — roughly one useful bit per fifteen transmitted. It is deliberate. The MIB must decode at the cell edge, with no channel estimate beyond the block's own DM-RS, no HARQ, no retransmission request and no prior knowledge of anything. Spending fifteen-sixteenths of the channel on redundancy is the cheapest way to get that. The companion 35 Physical Channels document owns the PBCH coding chain in full.
8.2 Where the PBCH DM-RS actually sits
The PBCH's demodulation reference signal is not in a symbol of its own. It is interleaved with the PBCH data at a density of one resource element in four, on subcarriers k = 4n + ν where ν = N_ID^cell mod 4 TS 38.211 cl. 7.4.1.4. In words: the reference signal occupies every fourth subcarrier, and which of the four it occupies is decided by the cell identity.
The comb shift is a four-way separation, not a 1008-way one. Two neighbours with PCI 431 and PCI 435 both have ν = 3 and put their PBCH DM-RS on exactly the same subcarriers. That is fine — the sequences differ — but it removes the frequency-domain separation and leaves only the sequence correlation to do the work. When a PCI plan is being designed, keeping first-tier neighbours distinct modulo 4 as well as modulo 3 costs nothing and buys measurable margin in SSB detection at cell overlap. See §20 on PCI confusion.
The DM-RS sequence itself is initialised from the cell identity and from the candidate SSB index, which is the mechanism by which a UE learns which beam it is looking at before it has decoded a single bit of the MIB. That is §12. The sequence generation is owned by the companion 33 DMRS document and is not repeated here.
9. PSS: Three Sequences, Found With No Timing At All
The primary synchronisation signal is the first thing the UE finds and the only thing it can find with no help. Everything about it is shaped by that. It has to be recognisable when the receiver does not know where a symbol starts, does not know the exact frequency, and has no channel estimate — so it cannot be a coded message, because there is nothing to demodulate against. It has to be a known waveform that the receiver slides along the incoming samples looking for a correlation peak.
An m-sequence — short for maximum-length sequence — is the standard choice for that job. It is a binary sequence generated by a shift register with feedback, and its defining property is that it correlates strongly with itself and weakly with a shifted copy of itself. In plain terms: slide it along a noisy recording and you get one sharp spike where it matches and near-nothing everywhere else. That spike is the symbol timing.
NR's PSS is a length-127 m-sequence, and the three PSS variants are three different cyclic shifts of the same sequence TS 38.211 cl. 7.4.2.2.1:
d_PSS(n) = 1 - 2 x( m ) n = 0, 1, ... , 126
m = ( n + 43 x N_ID_2 ) mod 127
generator: x(i+7) = ( x(i+4) + x(i) ) mod 2
initial: [x(6) x(5) x(4) x(3) x(2) x(1) x(0)] = [1 1 1 0 1 1 0]
N_ID_2 in {0, 1, 2} -> cyclic shifts of 0, 43 and 86
mapped to symbol l = 0, subcarriers k = 56 .. 182In plain terms: one 127-symbol pattern exists, generated by that seven-stage shift register. The three PSS signals are that pattern read starting from position 0, position 43 and position 86. The mapping 1 − 2x turns the binary 0/1 into +1/−1, which is BPSK. And because 43 and 86 are roughly a third and two thirds of 127, the three shifts are spaced as far from each other as three shifts can be — so a receiver that finds a peak for one of them will not accidentally find a significant peak for another.
| Property | Value | Why it is that value |
|---|---|---|
| Sequence length | 127 | 2⁷ − 1: the natural period of a 7-stage maximum-length shift register. Prime, which helps the cyclic-shift orthogonality |
| Number of variants | 3 | Each variant multiplies the blind-search correlation load. Three is enough to complete PCI arithmetic against SSS's 336 and cheap enough to search everywhere (§2) |
| Modulation | BPSK (±1) | Nothing to demodulate coherently, so no benefit from a denser constellation; BPSK maximises the correlation peak per unit energy |
| Position | Symbol 0, k = 56 to 182 | First symbol so that a detection immediately gives the block's start; centred in frequency so the 113 unused subcarriers act as guard on both sides |
| What it yields | Symbol timing, coarse frequency offset, N_ID2 | Timing from the peak position; frequency offset from the peak's phase rotation across repetitions; N_ID2 from which of the three shifts peaked |
| What it does not yield | Frame timing, half-frame, cell identity, beam | A PSS peak tells the UE where a block starts, not where a frame starts — those need SSS, the DM-RS and the PBCH payload |
Table 9. PSS at a glance. The last row is the one people forget: after PSS the UE knows when a symbol begins but has no idea what time it is.
PSS also gives the UE its first frequency correction, and that matters more than it sounds. A UE's crystal oscillator can be off by several parts per million at power-on before it has anything to lock to; at 3.5 GHz, 2 ppm is 7 kHz, which is a quarter of a 30 kHz subcarrier. Detecting PSS across two or more occasions gives a phase rotation from which that offset is estimated and corrected, and only then is the receiver accurate enough for the SSS's 336-way correlation to be reliable. This is precisely why a UE can report "PSS found, SSS failing" — see §20.
10. SSS, and the Cell Identity Completed
By the time the UE looks for the secondary synchronisation signal, it already knows where a symbol boundary is and roughly what the frequency error is. That changes the problem completely. It no longer has to slide a template along an unknown number of sample offsets; it knows exactly which resource elements to look at, because SSS sits in symbol 2 of the same block, on the same 127 subcarriers as PSS. All it has to do is work out which of the possible sequences arrived. That is one correlation window against 336 candidates, which is cheap, and it is why SSS is allowed to carry far more information than PSS.
SSS is built from two different m-sequences multiplied together — a construction called a Gold sequence, which yields many more distinguishable members than a single m-sequence of the same length could TS 38.211 cl. 7.4.2.3.1:
d_SSS(n) = [ 1 - 2 x0( (n + m0) mod 127 ) ]
x [ 1 - 2 x1( (n + m1) mod 127 ) ] n = 0 .. 126
m0 = 15 x FLOOR( N_ID_1 / 112 ) + 5 x N_ID_2
m1 = N_ID_1 mod 112
x0(i+7) = ( x0(i+4) + x0(i) ) mod 2
x1(i+7) = ( x1(i+1) + x1(i) ) mod 2
both initialised to [x(6)..x(0)] = [0 0 0 0 0 0 1]
N_ID_1 in 0 .. 335 -> 3 values of FLOOR(N_ID_1/112) x 112 of (N_ID_1 mod 112) = 336
mapped to symbol l = 2, subcarriers k = 56 .. 182In plain terms: two shift registers with different feedback taps produce two 127-length patterns; the SSS is the element-by-element product of those two patterns, each started at its own offset. The pair of offsets (m0, m1) is what encodes the identity. m1 takes 112 values and the coarse part of m0 takes 3, giving 3 × 112 = 336 distinguishable sequences. Note that m0 also depends on N_ID2 — the SSS sequence is not independent of the PSS, which is a small but real detail: a receiver has to know N_ID2 before it can search SSS efficiently, reinforcing the ordering.
10.1 Putting the two halves together
The physical cell identity — PCI, the number every log, every measurement report and every neighbour relation uses to name a cell — is simply the two halves combined TS 38.211 cl. 7.4.2.1:
N_ID_cell = 3 x N_ID_1 + N_ID_2 N_ID_1 from SSS, 0 .. 335 N_ID_2 from PSS, 0 .. 2 -> N_ID_cell = 0 .. 1007 1008 identities in total and in reverse: N_ID_2 = N_ID_cell mod 3 N_ID_1 = FLOOR( N_ID_cell / 3 )
In plain terms, PCI is a two-digit number in a mixed base: the SSS supplies the high digit in base 336 and the PSS supplies the low digit in base 3. Multiplying the SSS half by three and adding the PSS half is exactly how you reassemble it, and dividing by three with remainder is exactly how you take it apart.
PCI derivation, both directions, with real numbers.
Forward — the network's view. A planner allocates N_ID1 = 143 and N_ID2 = 2.
PCI = 3 × 143 + 2 = 429 + 2 = 431
So this cell transmits PSS shift 43 × 2 = 86, and the SSS with
m0 = 15 × FLOOR(143/112) + 5 × 2 = 15 × 1 + 10 = 25
m1 = 143 mod 112 = 31
And its PBCH DM-RS comb sits on ν = 431 mod 4 = 3 (§8.2).
Reverse — the UE's view. A log reports PCI 431.
N_ID2 = 431 mod 3 = 2 (429 = 3 × 143, remainder 2)
N_ID1 = FLOOR(431 / 3) = 143
Cross-check: 3 × 143 + 2 = 431. ✓
A second case, for the m0 branch. N_ID1 = 289, N_ID2 = 1.
PCI = 3 × 289 + 1 = 868
FLOOR(289/112) = 2, so m0 = 15 × 2 + 5 × 1 = 35
m1 = 289 mod 112 = 289 − 224 = 65
ν = 868 mod 4 = 0
Being able to run this in your head is genuinely useful when reading a PCI plan: PCIs that share a value modulo 3 share a PSS, and a cluster of neighbours all congruent to the same value modulo 3 is a plan that has thrown away the PSS diversity it was given for free.
| PSS | SSS | |
|---|---|---|
| Symbol | 0 | 2 |
| Subcarriers | k = 56 to 182 (127) | k = 56 to 182 (127) |
| Construction | One m-sequence, three cyclic shifts | Product of two m-sequences (a Gold sequence), 336 offset pairs |
| Information carried | log₂ 3 ≈ 1.58 bits | log₂ 336 ≈ 8.39 bits |
| Searched | Blind: every candidate frequency × every timing offset × 3 | Once: known frequency, known symbol, × 336 |
| Detection depends on | Nothing prior | PSS having succeeded — both for the timing and because m0 contains N_ID2 |
| What it yields | Symbol timing, coarse frequency, N_ID2 | N_ID1, and therefore the complete PCI |
Table 10. PSS and SSS compared. The information rows explain the design: 1.58 bits where searching is expensive, 8.39 bits where it is not. Ten bits of identity in total, which is 1024 — of which 1008 are used, because 336 × 3 does not reach 1024.
Why 1008 and not 1024? Because the number falls out of the construction rather than being chosen: 336 SSS sequences × 3 PSS sequences = 1008. The 336 in turn is 3 × 112, and 112 is the number of usable m1 offsets given the length-127 sequences and the need to keep m0's three branches from colliding. Nobody sat down and decided a network needed exactly 1008 cell identities; the number is what the sequence design produced, and it turned out to be plenty.
11. The Search Procedure, Step by Step
With the pieces described, the procedure itself is short to state. The UE works down a list of candidate frequencies, and at each one it listens for the one thing it can recognise blind. When it finds it, it stops scanning and starts a fixed sequence of steps, each of which resolves one more unknown, until it has the MIB and can go and fetch SIB1. If any step fails it either retries with more accumulation or goes back to scanning.
- Build the candidate list. The UE takes the bands it supports, and for each one the GSCN range from TS 38.104 cl. 5.4.3.3. It orders the list: stored frequencies from the last successful connection first, then anything a previous cell suggested, then the full per-band lists. For a cold start on n78 that is up to 341 entries (§7).
- Tune, and correlate for PSS. At each candidate the receiver runs three correlations — one per N_ID2 — across a window long enough to cover the assumed 20 ms periodicity. A peak above threshold gives symbol timing, a coarse frequency correction, and N_ID2. No peak, and the UE moves to the next candidate. This loop is where the seconds go.
- Correlate for SSS. Symbol 2 of the detected block, same 127 subcarriers, 336 hypotheses. Success gives N_ID1 and therefore the complete PCI = 3 × N_ID1 + N_ID2. From this moment the UE can descramble things, because almost every scrambling sequence in the cell is initialised from the PCI.
- Correlate the PBCH DM-RS. The reference-signal sequence is a function of the candidate SSB index, so testing the hypotheses identifies which beam this is — and, when L_max = 4, the half-frame as well (§12). The UE needs this before demodulating PBCH anyway, so the beam identity is free.
- Decode PBCH. Polar decoding of 864 coded bits down to 56, CRC checked. Success yields the MIB: six SFN bits,
subCarrierSpacingCommon,ssb-SubcarrierOffset,dmrs-TypeA-Position,pdcch-ConfigSIB1,cellBarred,intraFreqReselection. Failure means combining the next burst set and trying again. - Assemble the full system frame number. Six bits from the MIB, four more from the PBCH payload, one half-frame bit, and two bits recovered from which scrambling hypothesis worked. Only now does the UE know what time it is (§13).
- Check
cellBarred. If the MIB saysbarred, the UE stops here, bars the cell, and — depending onintraFreqReselection— either looks at other frequencies only or is allowed to try intra-frequency neighbours. This check happens before any attempt at SIB1, which is the point of putting it in the MIB. - Find CORESET#0 and read SIB1.
pdcch-ConfigSIB1plusk_SSBindexes a table that gives the CORESET#0 bandwidth, duration, offset and monitoring pattern; the UE then monitors Type0-PDCCH for a DCI with SI-RNTI and decodes SIB1 from the scheduled PDSCH. All of that arithmetic belongs to the companion 18 MIB and SIB1 IEs document and is not repeated here.
Steps 2 and 3 are often described as "the UE decodes PSS and SSS". It does not decode them — there is nothing to decode. It correlates against a finite set of known waveforms and picks the winner. The practical difference shows up in the failure signatures: a decode fails with a CRC error, whereas a correlation fails by returning a peak that is not convincingly above the noise floor. That is why PSS and SSS problems in logs appear as detection metrics and thresholds rather than as error codes, and why they degrade gradually with SNR rather than falling off a cliff.
| Step | Unknowns resolved | Typical cost | What a failure here looks like |
|---|---|---|---|
| Raster scan | Which frequency | Tens of ms per candidate; the whole list in the worst case | No cell found; UE reports out of service or keeps scanning |
| PSS | Symbol timing, coarse frequency, N_ID2 | 1 – 5 SSB periods | Nothing. The candidate is silently abandoned |
| SSS | N_ID1, so the full PCI | One occasion | PSS detected but no PCI — points at residual frequency error or interference in symbol 2 |
| PBCH DM-RS | SSB index; half-frame when L_max = 4 | Free, folded into demodulation | PBCH will not demodulate; looks like a PBCH failure, not a DM-RS one |
| PBCH decode | The MIB | One occasion, or up to 4 combined | MIB CRC failure — the clearest single indicator in a cell search log |
| SFN assembly | Frame number, half-frame | Up to one 80 ms PBCH period | Half-frame or SFN ambiguity; scheduled receptions land 5 ms or 10 ms out |
cellBarred check | Whether this cell is usable at all | Free | Not a failure — a correct rejection. Frequently misread as one |
| CORESET#0 and SIB1 | The cell's common configuration | Tens of ms | MIB decoded but no SIB1: usually k_SSB signalling no CORESET#0, or CORESET#0 falling outside the carrier |
Table 11. The same eight steps as a diagnostic table. Reading a cell search log means first establishing which of these rows you are in, because the fixes are entirely different.
12. The SSB Index: What the DM-RS Says Before the MIB Does
A cell does not transmit one SSB. It transmits several, in quick succession, each pointed in a different direction — this is the beam sweep, and §14 covers it properly. For now the point is that the UE has to know which of them it received, because the answer determines which PRACH occasion it should answer on and which beam the cell will use to reply. That number is the SSB index, and the UE needs it before it has decoded anything.
The mechanism is elegant and worth understanding, because it explains a log line that otherwise looks impossible: an analyser reporting an SSB index next to a MIB that contains no such field. The index is not in the MIB. It is carried by the initialisation of the PBCH DM-RS sequence TS 38.211 cl. 7.4.1.4.1. The UE has to correlate against that sequence in order to demodulate PBCH at all; making the sequence a function of the index means that same correlation also reveals which beam this is, at zero additional resource cost.
c_init = 2^11 x ( i_SSB + 1 ) x ( FLOOR( N_ID_cell / 4 ) + 1 )
+ 2^6 x ( i_SSB + 1 )
+ ( N_ID_cell mod 4 )
L_max = 4 i_SSB = ( SSB index mod 4 ) + 4 x n_hf
L_max = 8 or 64 i_SSB = SSB index mod 8
n_hf = half-frame number, 0 or 1
-- The UE tests each i_SSB hypothesis; the one that yields a good PBCH
-- decode is the answer. For L_max = 64 the three most significant bits
-- of the index come from the PBCH payload instead.Read the two L_max cases carefully, because they are different in kind. Where L_max is 4 there are only four candidate positions, so two bits of index are enough — and the spare capacity in i_SSB is spent carrying the half-frame bit as well, folded in as the +4 × n_hf term. Where L_max is 8, all three bits go to the index and the half-frame has to come from the PBCH payload. Where L_max is 64, the DM-RS carries the three least significant bits and the payload carries the three most significant.
| L_max | Where it applies | Index bits from DM-RS | Index bits from PBCH payload | Half-frame from |
|---|---|---|---|---|
| 4 | FR1 below 3 GHz | 2 (index mod 4) | none | The DM-RS as well, via +4 × n_hf |
| 8 | FR1, 3 to 7.125 GHz | 3 (index mod 8) | none | A dedicated bit in the PBCH payload |
| 64 | FR2 | 3 (index mod 8) | 3 (the MSBs) | A dedicated bit in the PBCH payload |
Table 12. Three different arrangements for the same information, chosen per frequency range so that no bits are wasted. This is why an analyser that reports an SSB index for an FR2 cell has done strictly more work than one reporting it for FR1 — it had to decode the payload as well as correlate the pilot.
The half-frame at L_max = 4 is the case that catches people. Below 3 GHz there is no half-frame bit to read in the payload in the usual place — it is inside the DM-RS hypothesis. A UE that gets the i_SSB hypothesis right but interprets it as a pure index, ignoring the +4, ends up with the correct beam and the wrong half of the frame: every subsequent scheduled reception is 5 ms out. In a log this shows as a UE that acquires the cell, decodes the MIB, and then misses its first paging occasion or PRACH occasion by exactly 5 ms.
The consequence for beam management is that the SSB index is available before the MIB, which is what makes the SSB-to-PRACH-occasion association work during initial access — the UE has to know which beam it chose in order to pick the right occasion, and it needs that at random-access time, not after SIB1. See the companion 03 Random Access document for the association itself, and 33 DMRS for the sequence generation.
13. The Half-Frame Bit, and Why the SFN Arrives in Three Pieces
Knowing what time it is turns out to be surprisingly awkward. The system frame number — SFN — is the 10-bit counter that names each 10 ms radio frame, cycling every 1024 frames or 10.24 seconds. Every periodic thing in the cell is defined against it: paging occasions, system information windows, PRACH occasions, measurement gaps. A UE that does not know the SFN cannot receive anything scheduled, so the SFN has to be part of what cell search delivers.
The awkwardness is that the SFN is not sent as a 10-bit field. It arrives in three pieces, from three different places, and there is a reason for each split:
| Piece | Bits | Where it comes from | Why it is there and not elsewhere |
|---|---|---|---|
| SFN most significant bits | 6 | systemFrameNumber in the MIB itself | These change slowly — once every 160 ms — so they can live in the coded payload without forcing a re-encode every frame |
| SFN least significant bits | 4 | Added to the PBCH payload by the physical layer, outside the MIB | These change every frame. Keeping them out of the MIB means four consecutive frames can share one encoded MIB and differ only in the added bits |
| Two of those 4 LSBs, again | (2) | Recovered from which scrambling hypothesis decoded successfully | See below — the PBCH scrambling phase depends on them, so they cannot be read from the payload before they are known |
| Half-frame, n_hf | 1 | PBCH payload, except at L_max = 4 where it is folded into the DM-RS hypothesis (§12) | 5 ms resolution is needed because an SSB burst set occupies one half of a frame, and the UE must know which half |
Table 13. The SFN in pieces. The third row is the one that costs time: it is why acquisition takes up to 80 ms after the first PBCH occasion rather than one occasion.
13.1 The scrambling trick, and the 80 ms it costs
Here is the circularity that the third row resolves. The PBCH payload is scrambled before encoding, and the scrambling sequence's starting position depends on the low bits of the SFN TS 38.212 cl. 7.1.1, 7.1.2. That means the same MIB content produces four different transmitted waveforms across an 80 ms period — one per 20 ms burst set. A UE that does not know those bits cannot descramble; so it tries all four hypotheses, and the hypothesis that decodes successfully is itself the answer. The bits that select the scrambling are therefore excluded from the scrambling, which would otherwise be impossible to unwind.
In plain terms: two bits of timing are communicated not by transmitting them but by which version of the transmission you are looking at. It costs nothing in resource elements, and it costs up to 80 ms in acquisition latency, because in the worst case the UE has to observe four burst sets to find the one whose hypothesis fits.
Assembling an SFN from a real set of pieces.
MIB systemFrameNumber = 0b101101 (6 bits, SFN[9:4])
PBCH payload SFN LSBs = 0b0011 (4 bits, SFN[3:0])
Half-frame bit n_hf = 1
SFN = 0b1011010011 = 723
check: 0b101101 = 45, so SFN = 45 × 16 + 3 = 720 + 3 = 723 ✓
n_hf = 1 → this burst set is in the second 5 ms of frame 723,
i.e. subframes 5 to 9, so the block began at 723 × 10 ms + 5 ms = 7235 ms into the SFN cycle.
Note that the two bits recovered from the scrambling hypothesis are part of the four payload LSBs — they are not extra bits. The four LSBs are 0b0011; two of them (SFN[3:2] = 0b00) are what the scrambling hypothesis told the UE, and the other two arrive in the payload proper. Getting this wrong by treating them as separate is a common source of off-by-four SFN errors in hand analysis.
The MIB is transmitted with a 80 ms period of unchanging content — the same 24 bits repeat, and the network may only change them on an 80 ms boundary. That is why a UE can safely combine energy across four burst sets, and it is also why a MIB content change takes effect no faster than 80 ms. A cell that flaps cellBarred faster than that is producing behaviour no UE is specified to follow.
14. SSB Burst Sets: Cases A Through E
A cell that transmits one SSB in one direction can only be found by UEs in that direction. Above a couple of gigahertz that is a real problem, because coverage at those frequencies depends on beamforming — energy concentrated into a narrow direction — and a broadcast signal cannot be beamformed to everyone at once. The answer is to send the same block several times in quick succession, each time pointed somewhere else, and sweep across the cell. That set of transmissions is a burst set, and its purpose is simply that a UE anywhere in the cell hears at least one of them.
So a burst set is a beam sweep. Each transmission within it is at a different candidate position — a specific first-symbol index within the half-frame at which an SSB is permitted to start — and each candidate position carries a different beam. The whole set is confined to one 5 ms half-frame, never straddling the boundary, which is why the half-frame bit of §13 exists.
| Quantity | Meaning in ordinary words | Values |
|---|---|---|
| Candidate position | A permitted starting symbol for an SSB inside the half-frame. Fixed by the specification, not configurable | Given by the Case, below |
| L_max | How many candidate positions exist in the half-frame for this frequency range — the ceiling on how many beams a cell may sweep | 4 below 3 GHz, 8 from 3 to 7.125 GHz, 64 above 6 GHz |
| SSB index | Which candidate position a particular block occupied. What a UE reports when it says which beam it found | 0 to L_max − 1 |
ssb-PositionsInBurst | A bitmap saying which of the candidate positions the cell actually uses. A 4-beam cell in an L_max = 8 range sets four bits (§15) | 4, 8 or 64 bits |
| Burst set periodicity | How often the whole sweep repeats | 5 to 160 ms (§16) |
Table 14. The five quantities that describe a burst set. Confusing L_max with the number of transmitted SSBs is the most frequent error, and ssb-PositionsInBurst is the field that separates them.
14.1 The five cases
Which candidate positions exist depends on the SSB subcarrier spacing and the frequency range, and the specification names the five resulting patterns Case A through Case E TS 38.213 cl. 4.1. Each is expressed as a set of first symbols plus a repeat offset — the notation {2, 8} + 14n means "symbols 2 and 8, and then symbols 2 and 8 of every subsequent slot, for the listed values of n".
| Case | SSB SCS | First symbols | n values | L_max | Where it applies |
|---|---|---|---|---|---|
| A | 15 kHz | {2, 8} + 14n | 0, 1 (≤ 3 GHz) 0, 1, 2, 3 (3 – 7.125 GHz) | 4 8 | FR1 low bands with 15 kHz SSB — n1, n3, n28 |
| B | 30 kHz | {4, 8, 16, 20} + 28n | 0 (≤ 3 GHz) 0, 1 (3 – 7.125 GHz) | 4 8 | FR1 bands with 30 kHz SSB packed two candidates per slot |
| C | 30 kHz | {2, 8} + 14n | 0, 1 (≤ 3 GHz paired, ≤ 2.4 GHz unpaired) 0, 1, 2, 3 (above that, to 7.125 GHz) | 4 8 | The common FR1 mid-band case — n41, n77, n78, n79 |
| D | 120 kHz | {4, 8, 16, 20} + 28n | 0–3, 5–8, 10–13, 15–18 (16 values) | 64 | FR2 above 6 GHz — n257, n258, n260, n261 |
| E | 240 kHz | {8, 12, 16, 20, 32, 36, 40, 44} + 56n | 0–3, 5–8 (8 values) | 64 | FR2 above 6 GHz where 240 kHz SSB is supported |
Table 15. The five candidate-position patterns. Which case a band uses is fixed per band in TS 38.104 cl. 5.4.3.3 — it is not an operator choice, and it follows from the SSB subcarrier spacing the band's table entry specifies. Note there is no 60 kHz case: SSB is never 60 kHz.
Case C candidate symbol positions, worked for L_max = 8.
Pattern is {2, 8} + 14n with n = 0, 1, 2, 3. Substituting each n in turn gives symbols 2 and 8, then 16 and 22, then 30 and 36, then 44 and 50:
Candidate first symbols = 2, 8, 16, 22, 30, 36, 44, 50
At 30 kHz a slot is 0.5 ms and holds 14 symbols, so symbol s falls in slot FLOOR(s/14) at symbol s mod 14:
SSB 0 → symbol 2 → slot 0, symbol 2
SSB 1 → symbol 8 → slot 0, symbol 8
SSB 2 → symbol 16 → slot 1, symbol 2
SSB 3 → symbol 22 → slot 1, symbol 8
SSB 4 → symbol 30 → slot 2, symbol 2
SSB 5 → symbol 36 → slot 2, symbol 8
SSB 6 → symbol 44 → slot 3, symbol 2
SSB 7 → symbol 50 → slot 3, symbol 8
So the whole sweep lives in slots 0 to 3 of the half-frame and slots 4 to 9 hold no candidates at all. In time, SSB 0 starts at 2/14 × 0.5 ms = 71 µs and SSB 7 ends at (50 + 4)/14 × 0.5 ms = 1.93 ms — the sweep occupies under 40 % of the half-frame, leaving the rest for data. Symbols 0–1 and 12–13 of each SSB slot stay clear, which is where CORESET#0 goes.
Case D candidate symbol positions, worked at both ends.
Pattern is {4, 8, 16, 20} + 28n over 16 values of n, giving 4 × 16 = 64 candidates. At 120 kHz a slot is 0.125 ms.
First candidate. n = 0, base 4 → symbol 4.
Slot = FLOOR(4/14) = 0, symbol 4 → starts at 4/14 × 0.125 ms = 36 µs
Last candidate. n = 18, base 20 → symbol 28 × 18 + 20 = 524.
Slot = FLOOR(524/14) = 37, symbol 524 − 518 = 6
Starts at 37 × 0.125 + 6/14 × 0.125 = 4.625 + 0.054 = 4.679 ms
Ends 4 symbols later at 4.714 ms — just inside the 5 ms half-frame.
Why n skips 4, 9, 14, 19. Each n consumes 28 symbols = 2 slots. n = 4 would occupy symbols 112 to 132, i.e. slots 8 and 9. Skipping it leaves slots 8–9, 18–19, 28–29 and 38–39 free. Compare with FR1's Case C, where the whole sweep finished at 1.93 ms: on FR2 a full 64-beam sweep uses 94 % of the half-frame. There is no slack, which is why the skipped slots had to be engineered in rather than left over.
L_max = 64 does not mean an FR2 cell transmits 64 SSBs. It means it may. A typical FR2 sector transmits somewhere between 8 and 32, chosen against its antenna array and its coverage target, and signals which ones in ssb-PositionsInBurst. Reading L_max off the frequency range and assuming 64 transmissions will make every overhead calculation for that cell wrong by a factor of two to eight.
15. ssb-PositionsInBurst: What Is Actually Transmitted
The candidate positions of §14 are what the specification permits. What a particular cell actually sends is a subset, and the cell announces that subset as a bitmap: one bit per candidate position, set if that position carries an SSB. The field is called ssb-PositionsInBurst and it is the single most useful field for reconciling "how many beams does this cell have" with what a UE reports.
| Encoding | Where | Size | Meaning |
|---|---|---|---|
shortBitmap | ServingCellConfigCommon, L_max = 4 | 4 bits | One bit per candidate position, MSB first = candidate 0 |
mediumBitmap | ServingCellConfigCommon, L_max = 8 | 8 bits | As above, eight positions |
longBitmap | ServingCellConfigCommon, L_max = 64 | 64 bits | One bit per candidate position. Used in dedicated signalling, where 64 bits is affordable |
groupPresence + inOneGroup | ServingCellConfigCommonSIB, L_max = 64 | 8 + 8 bits | The 64 positions are treated as 8 groups of 8. groupPresence says which groups exist; inOneGroup says which positions within every present group. Total transmitted = (bits set in groupPresence) × (bits set in inOneGroup) |
Table 16. ssb-PositionsInBurst encodings, TS 38.331. The SIB1 form for L_max = 64 exists to save broadcast bits and imposes a real constraint in exchange: the pattern within each group must be the same for every group.
Decoding the group form.
groupPresence = 1100 0001 → groups 0, 1 and 7 exist (3 groups)
inOneGroup = 1111 0000 → positions 0–3 within each (4 positions)
Transmitted SSBs = 3 × 4 = 12
Their indices: group g contributes 8g + p for each set p, so
group 0 → 0, 1, 2, 3
group 1 → 8, 9, 10, 11
group 7 → 56, 57, 58, 59
Encoded in 16 bits rather than 64.
And here is the constraint this buys: there is no way to express "positions 0–3 of group 0 and positions 4–7 of group 1" in SIB1. inOneGroup applies to every present group identically. A cell whose physical beam layout needs an irregular pattern must either regularise it or transmit SSBs it does not need.
The bitmap is the answer to "the UE reports fewer beams than this cell is supposed to have". Check ssb-PositionsInBurst before checking anything about the antenna. A cell provisioned for eight beams but broadcasting mediumBitmap = 1101 0000 is transmitting three, and every UE will correctly report three. It is also the field that governs measurement: a UE only measures the positions the bitmap declares, so a beam transmitted at a position the bitmap says is empty is invisible to measurement even though it is on the air (§20).
One further use of the bitmap is worth knowing. Positions the bitmap declares as not carrying an SSB are still not freely usable for PDSCH in the general case — the UE's rate-matching around the SSB is driven by the declared positions, and a scheduler that puts PDSCH where the UE believes an SSB might be gets a decode failure that looks like a coverage problem. The companion 35 Physical Channels document owns the rate-matching rules.
16. SSB Periodicity and the 20 ms Assumption
The burst set repeats. How often is configurable, and the trade is simple to state: transmitting the sweep more often makes cells easier and quicker to find, and costs downlink resource that could have carried data. Transmitting it less often saves that resource and makes every UE that is looking for the cell wait longer.
There is a complication that turns this from a smooth trade into a cliff edge. A UE performing initial cell selection has not read SIB1 yet — it cannot have, since SIB1 is what carries the configured periodicity — so it has no idea how often to expect the burst set. The specification resolves this by fiat: for the purposes of initial cell selection the UE may assume a 20 ms periodicity TS 38.213 cl. 4.1. That is not a convention; it is what a compliant UE is entitled to do.
ssb-periodicityServingCell | Overhead relative to ms20 | Effect on a UE already connected | Effect on initial search |
|---|---|---|---|
ms5 | 4× | Fastest measurement and beam tracking; most resource consumed | No benefit — the UE is already assuming 20 ms and cannot exploit the extra bursts it does not know about |
ms10 | 2× | Fast measurement | No benefit, same reason |
ms20 | 1× (reference) | The usual choice. Matches the initial-search assumption exactly | Optimal. Every assumed occasion is a real occasion |
ms40 | 0.5× | Slower measurement; SMTC must be widened to match | Halves the hit rate. The UE looks every 20 ms and finds something every other time, so dwell has to double for the same confidence |
ms80 | 0.25× | Slower still; noticeable in handover measurement latency | Quarter hit rate. Initial search takes about 4× longer |
ms160 | 0.125× | Minimum overhead; measurement latency is now the dominant mobility constraint | Eighth hit rate. Initial access becomes slow and highly variable |
Table 17. ssb-periodicityServingCell, TS 38.331. The right-hand column is the one that gets forgotten during overhead optimisation, and it is asymmetric — going below 20 ms buys a connected UE something and buys a searching UE nothing, while going above 20 ms costs the searching UE directly.
Configuring ms40 or longer is entirely legal and saves real downlink resource. What it does not do is stay invisible. A UE arriving from RRC_IDLE searches on a 20 ms assumption; on an ms80 cell it finds a burst set on roughly one attempt in four, so its acquisition time quadruples and — because which attempt succeeds is essentially random — becomes highly variable. In aggregate KPIs that appears as slow, erratic initial access, which looks exactly like a coverage problem and is not one. If accessibility statistics degrade after an overhead optimisation exercise, check the SSB periodicity before checking anything else.
What a longer periodicity costs, quantified.
Assume a UE needs to accumulate 5 burst sets to declare presence or absence at its detection threshold.
On ms20: 5 × 20 ms = 100 ms per candidate frequency
On ms40: the UE's 20 ms windows hit half the time, so it needs 10 windows = 5 × 40 ms = 200 ms
On ms80: 5 × 80 ms = 400 ms
On ms160: 5 × 160 ms = 800 ms
Across n78's 341 candidates in a serial scan:
ms20 → 34 s
ms40 → 68 s
ms80 → 136 s
ms160 → 273 s
Those are worst-case serial numbers and a real UE is much faster, but the ratios hold regardless of receiver cleverness: ms160 is eight times the search cost of ms20, for a 12.5 % overhead saving on the SSB. Treat the absolute figures as illustrative.
17. Where the SSB Sits Relative to the Carrier: k_SSB and offsetToPointA
This is where hand analysis goes wrong most often, so it is worth being slow about it. The problem is that the SSB and the carrier are placed by two different rules. The SSB has to sit on the synchronisation raster, whose steps are 1.2 or 1.44 or 17.28 MHz. The carrier has to sit on the channel raster, whose steps are 15 or 30 or 100 kHz. There is no reason for those two to coincide, and in general they do not — so the SSB is not at the centre of the carrier, and its subcarriers are not necessarily aligned with the carrier's resource block boundaries.
Two fields express that misalignment, and they express two different parts of it:
ssb-SubcarrierOffset, giving k_SSB. The fine offset: how far the SSB's lowest subcarrier sits above the lowest subcarrier of the resource block that contains it. It is a handful of subcarriers, and it is in the MIB — so the UE gets it immediately, from the block it just found.offsetToPointA. The coarse offset: how many resource blocks lie between point A — the origin of the cell's common resource block grid, the reference against which every resource block in the cell is numbered — and the bottom of that containing resource block. It is in SIB1, because it is not needed until the UE wants to address resources.
Put together, they let a UE work downward from the only frequency it actually knows — the SSB's, because it found it at a known GSCN — to point A, and from there address every resource block in the cell. The companion 02 Radio Frame Structure document owns point A and the common resource block grid; this section owns the chain from the SSB to it.
k_SSB the SSB straddles 21 resource blocks, not 20, occupying part of the one at each end.| Field | Where | Range | Units | What it measures |
|---|---|---|---|---|
ssb-SubcarrierOffset | MIB, 4 bits, plus 1 bit from the PBCH payload in FR1 | 0 – 23 in FR1 (5 bits); 0 – 11 in FR2 (4 bits) | 15 kHz subcarriers in FR1; subcarriers of subCarrierSpacingCommon in FR2 | SSB lowest subcarrier above the containing CRB's lowest subcarrier |
offsetToPointA | FrequencyInfoDL / FrequencyInfoDL-SIB in SIB1 | 0 – 2199 | Resource blocks of 15 kHz in FR1, 60 kHz in FR2 | Point A up to the lowest subcarrier of the lowest CRB that overlaps the SSB used for initial cell selection |
offsetToCarrier | SCS-SpecificCarrier | 0 – 2199 | Resource blocks of the carrier's own SCS | Point A up to the start of this particular carrier — a separate offset, often confused with the one above |
Table 18. The three offsets that position things relative to point A. Note that offsetToPointA is anchored to the SSB, whereas offsetToCarrier is anchored to the carrier — they answer different questions and are not interchangeable.
The full chain: GSCN to point A to carrier centre. Band n78, 30 kHz, 100 MHz carrier, subCarrierSpacingCommon = 30 kHz.
1. GSCN to SSB centre.
GSCN 7883 → N = 384 → SS_REF = 3000 + 384 × 1.44 = 3552.96 MHz
2. SSB centre to SSB lowest subcarrier.
240 subcarriers × 30 kHz = 7.2 MHz wide, so half is 3.6 MHz
Lowest SSB subcarrier = 3552.96 − 3.6 = 3549.36 MHz
3. Apply k_SSB to find the containing CRB.
ssb-SubcarrierOffset = 8, so k_SSB = 8 × 15 kHz = 120 kHz
Bottom of that CRB = 3549.36 − 0.12 = 3549.24 MHz
(120 kHz is 4 subcarriers at 30 kHz, so the SSB starts 4 subcarriers up into the CRB, and therefore ends 4 subcarriers up into the CRB above the 20th — 21 CRBs touched.)
4. Apply offsetToPointA.
offsetToPointA = 84, in 15 kHz PRBs → 84 × 180 kHz = 15.12 MHz
Point A = 3549.24 − 15.12 = 3534.12 MHz
5. Carrier centre, as a check.
273 PRB at 30 kHz = 273 × 360 kHz = 98.28 MHz; offsetToCarrier = 0
Carrier spans 3534.12 to 3632.40 MHz, centre = 3583.26 MHz
As an NR-ARFCN: (3583.26 − 3000) / 0.015 = 38884 → N_REF = 638884 — the same value worked in §4.
The punchline. 3583.26 − 3552.96 = 30.30 MHz. The SSB sits over 30 MHz below the carrier centre, roughly 84 resource blocks in. Anyone assuming the SSB is at carrier centre is out by that much.
offsetToPointA is counted in 15 kHz resource blocks in FR1 regardless of what subCarrierSpacingCommon is. On a cell where the common spacing is 30 kHz, a 30 kHz CRB boundary is 360 kHz wide = two 15 kHz PRBs — so offsetToPointA must be even, or it points at a frequency that is not a 30 kHz CRB boundary at all. 84 is even, which is why the arithmetic above closes. An odd offsetToPointA on a 30 kHz cell is a configuration error, and its symptom is a UE that decodes the MIB, reads SIB1, and then addresses every resource block half a PRB out — which usually manifests as SIB1 decoding but nothing after it working.
The reason k_SSB is measured in 15 kHz units in FR1 even when the SSB is 30 kHz is the sub-3 GHz raster from §6.2. There, the raster's 1.2 MHz step and 50 kHz M-offsets are not whole numbers of resource blocks at any spacing, so the residual misalignment can be large and can be a non-integer number of 30 kHz subcarriers. Using 15 kHz as the unit, and spending five bits rather than four, covers it. Above 3 GHz the raster step is a whole number of PRBs and k_SSB is consequently almost always small — which is a useful sanity check: a large k_SSB on an n78 cell is worth a second look.
A value of ssb-SubcarrierOffset outside the valid k_SSB range — above 23 in FR1 — is not corruption. It is the encoding that says this SSB has no associated CORESET#0, so there is no SIB1 to be found here and the UE must look elsewhere. Such SSBs exist to help measurement and synchronisation without advertising a servable cell. A cell search log showing repeated successful MIB decodes with no SIB1 attempt at all is usually reading exactly this, and it is correct behaviour. The companion 18 MIB and SIB1 IEs document owns the CORESET#0 lookup that this value gates.
18. From Search to Measurement: the SSB's Second Job
Everything so far has been about a UE that knows nothing. Once it is connected, the same SSB gets used again for a completely different purpose — measuring neighbours so that mobility decisions can be made — and it is worth being explicit that this is a much easier problem, because almost all of the unknowns are gone.
A connected UE measuring a neighbour has been told where to look. The serving cell supplies the neighbour frequency in measurement configuration, so there is no raster scan. It supplies a list of PCIs to expect, so the SSS search is narrowed or skipped. And it supplies a timing window — the SMTC, SSB Measurement Timing Configuration — that says when the neighbour's burst sets occur, so the UE does not have to keep its receiver open continuously.
| Initial cell search | Neighbour measurement under an SMTC | |
|---|---|---|
| Frequency | Unknown. Scan the band's GSCN list | Given in measObjectNR as an absolute frequency |
| Timing | Unknown. Assume 20 ms periodicity and watch | Given: SMTC periodicity, offset and duration bound the window |
| Identity | Unknown. 3 PSS × 336 SSS hypotheses | Usually narrowed by a neighbour PCI list; a blind PCI search is possible but exceptional |
| What is being extracted | PCI, SSB index, MIB, then SIB1 | RSRP, RSRQ and SINR per SSB and per cell — no decoding at all in the normal case |
| Receiver duty cycle | Continuous during the scan | Open only inside the SMTC window, typically 1 to 5 ms out of every 20 to 160 |
| Cost | Seconds | A few percent of receiver time |
| Failure looks like | No cell found; out of service | A neighbour that is on the air but never reported |
Table 19. The same signal, two problems. Everything that makes initial search expensive is information the network can supply once a UE is connected — which is exactly what measurement configuration does.
The SMTC window is the mechanism that makes neighbour measurement affordable, and it has one property that generates a lot of field trouble: it has to actually align with the neighbour's burst sets. An SMTC whose periodicity or offset does not match the neighbour's SSB transmission means the UE opens its receiver at the wrong times and reports nothing, indistinguishable from the neighbour being absent. The companion 21 Measurement Gaps and SMTC document owns the window arithmetic, and 20 Measurements and Events owns what is done with the results.
One asymmetry is worth carrying away. In initial search, an SSB periodicity longer than 20 ms costs the UE time but eventually works, because the UE keeps looking. In neighbour measurement, an SMTC that does not match costs the UE everything — it never sees the neighbour at all, however long it looks, because it is looking at the wrong instants. Initial search degrades; measurement fails silently. When a handover is not happening and the target is demonstrably on the air, the SMTC is the first thing to check.
19. Parameter and Range Reference
Everything that positions, shapes or schedules an SSB, in one place. Where a field is derived rather than signalled that is said explicitly, because the derived ones are the ones that cannot be fixed by changing a configuration value.
| Parameter | Where it comes from | Range | Typical | Effect |
|---|---|---|---|---|
| GSCN | Derived from the SSB frequency; per-band list in TS 38.104 Table 5.4.3.3-1 | 2 – 26639 | band dependent | The SSB's centre frequency. Outside the band's list, no UE will find the cell |
NR-ARFCN (absoluteFrequencySSB) | SIB1 / FrequencyInfoDL | 0 – 3279165 | band dependent | The SSB frequency expressed as an ARFCN, for signalling. Must correspond to a valid GSCN |
absoluteFrequencyPointA | SIB1 / FrequencyInfoDL-SIB | 0 – 3279165 | band dependent | Point A as an ARFCN, the alternative to deriving it from offsetToPointA |
ssb-SubcarrierOffset (k_SSB) | MIB, 4 bits + 1 payload bit in FR1 | 0 – 15 as encoded; k_SSB 0 – 23 FR1, 0 – 11 FR2 | 0 – 12 | Fine frequency offset of the SSB from the CRB grid. Out-of-range means no CORESET#0 |
offsetToPointA | SIB1 / FrequencyInfoDL-SIB | 0 – 2199 | 40 – 200 | Coarse offset, in 15 kHz PRBs (FR1) from point A to the SSB's lowest CRB. Must be even when common SCS is 30 kHz |
ssb-SubcarrierSpacing | SIB1 / ServingCellConfigCommonSIB | kHz15, kHz30, kHz120, kHz240 | kHz30 in FR1, kHz120 in FR2 | Selects the Case together with the band. There is no 60 kHz option |
| L_max | Derived from the frequency range | 4, 8 or 64 | 8 in FR1 | Ceiling on candidate positions, and the length of ssb-PositionsInBurst |
ssb-PositionsInBurst | SIB1 (group form at L_max = 64) or ServingCellConfigCommon | 4, 8, 64 bits, or 8 + 8 | matches the beam count | Which candidate positions carry an SSB. Governs both detection and measurement |
ssb-periodicityServingCell | SIB1 / ServingCellConfigCommonSIB | ms5, ms10, ms20, ms40, ms80, ms160 | ms20 | Burst set repetition. Initial search assumes ms20 regardless (§16) |
| Half-frame bit n_hf | PBCH payload, or the DM-RS hypothesis at L_max = 4 | 0 or 1 | 0 | Which 5 ms half of the frame the burst set occupies. Not an RRC field |
ss-PBCH-BlockPower | SIB1 / ServingCellConfigCommonSIB | −60 – 50 dBm | 10 – 20 dBm per RE | The transmit power the UE assumes per SSB resource element, used for pathloss estimation — not for detection |
cellBarred | MIB | barred, notBarred | notBarred | Checked before any SIB1 attempt. barred stops acquisition dead |
intraFreqReselection | MIB | allowed, notAllowed | allowed | Whether a UE rejecting this cell may try intra-frequency neighbours or must change frequency |
subCarrierSpacingCommon | MIB | scs15or60, scs30or120 | scs30or120 in FR1 mid-band | The SCS of SIB1, initial BWP and paging — and the grid offsetToPointA is measured against |
smtc periodicity / offset / duration | measObjectNR in measurement configuration | sf5 – sf160 / 0 – periodicity−1 / sf1 – sf5 | sf20 / — / sf5 | The neighbour measurement window (§18). Owned by companion 21 |
Table 20. The full parameter set. Typical values are what many vendors ship rather than anything specified; the ranges are normative.
20. Failure Modes and What Each One Means
Cell search fails in a small number of characteristic ways, and they are worth separating carefully because several of them look identical from the outside — "the UE does not attach" — and have entirely different causes and fixes. What follows is ordered roughly by how far into the procedure the failure occurs.
| Failure | Who detects it | What the UE does | Log signature and what it points at |
|---|---|---|---|
| SSB transmitted at a GSCN outside the band's searched list. The cell is on the air and radiating fine, but at a frequency no compliant UE will try | Nobody, on either side. The gNB sees no access attempts; the UE sees no cell | Never finds the cell. Keeps scanning, then reports out of service or camps on another operator | A cell with normal transmit power and zero RACH attempts, ever. Cross-check the configured SSB frequency against TS 38.104 Table 5.4.3.3-1 for the band: compute N = (F − F_base) / step and confirm it is an integer inside the published first–step–last range |
| SSB on a valid GSCN but outside the carrier, so PDSCH and the SSB cannot both be addressed | The UE, after SIB1, when the arithmetic does not close | MIB decodes, SIB1 may decode, then nothing works | offsetToPointA and absoluteFrequencySSB inconsistent with carrierBandwidth. Recompute the chain in §17 and check the SSB's 7.2 MHz falls inside the carrier's PRBs |
| PSS detected but SSS never succeeds. Usually residual frequency error: the 336-way correlation is far more sensitive to it than the 3-way one | The UE, as a failed correlation with no error code | Abandons the candidate and continues scanning | Repeated PSS detections at the same GSCN with no PCI reported. Points at UE oscillator error at cold start, large Doppler, or strong narrowband interference landing in symbol 2. Distinguishable from coverage by the fact that PSS did succeed |
| MIB CRC failure. PBCH does not decode despite PSS, SSS and DM-RS all succeeding | The UE, cleanly, from the 24-bit CRC | Combines the next burst set and retries; abandons after several | PCI reported but no MIB. At the very low PBCH code rate this needs genuinely poor SNR, so it points at real coverage limitation, at a collision with another cell's SSB at the same position, or at PDSCH being scheduled over the SSB's resource elements |
cellBarred set to barred. | The UE, from the MIB, before any SIB1 attempt | Bars the cell for 300 s and reselects; if intraFreqReselection is notAllowed it will not even try intra-frequency neighbours | MIB decoded, cellBarred barred, no SIB1 attempt. This is correct behaviour, not a fault — but a cell left barred after maintenance is a very common cause of a cell that looks healthy and carries no traffic |
| PCI collision. Two cells with the same PCI are both audible to one UE | Neither, directly. The UE sees one confused cell | Measurements average two cells; handover targets become ambiguous; descrambling of one is wrong for the other | Two cells reporting one PCI in the same measurement report, or RSRP that does not fall off with distance. The tell is a PCI whose reported RSRP is inconsistent between adjacent samples |
| PCI confusion. Two different neighbours of one cell share a PCI, so a handover request is ambiguous | The serving gNB, when it tries to resolve a reported PCI to a target | Nothing — the UE reported correctly. The network picks a target and may pick the wrong one | Handover failures concentrated on one reported PCI, with the target cell reporting no incoming attempt. Fixed by ANR / CGI reporting, not by anything in this document |
| k_SSB inconsistent with offsetToPointA. The fine and coarse offsets do not compose to the SSB's actual frequency | The UE, silently, by addressing the wrong resource blocks | Decodes MIB and SIB1, then fails on everything scheduled | SIB1 read successfully and then nothing: no successful RACH, or RACH on the wrong PRBs. Recompute §17 step by step; check offsetToPointA parity against subCarrierSpacingCommon |
ssb-PositionsInBurst disagrees with what is transmitted. Beams on the air at positions the bitmap says are empty, or the reverse | Nobody. Both sides believe themselves correct | Measures and reports only the declared positions. A real beam at an undeclared position is invisible; a declared position with nothing on it produces a persistent non-detection | UE reports fewer SSB indices than the cell is provisioned for, or a declared index that never appears in any report. Compare the bitmap against the antenna configuration before suspecting the antenna |
SSB periodicity longer than the UE's assumption. ms40 or beyond | Nobody. Nothing is wrong | Takes proportionally longer to find the cell, with high variance | Slow and erratic initial access; accessibility KPIs degrade after an overhead optimisation. §16 has the numbers |
| Half-frame ambiguity. The UE gets the index right and n_hf wrong, or vice versa, typically at L_max = 4 where the two are folded together | Eventually the UE, when scheduled receptions do not arrive | Everything scheduled lands 5 ms out. May recover by re-acquiring | A UE that acquires cleanly and then misses its first paging occasion or PRACH occasion by exactly 5 ms. At L_max = 4, check that the i_SSB = (index mod 4) + 4 × n_hf decomposition was done (§12) |
Table 21. Eleven failure modes. The first, fifth and tenth rows are all cases where nothing is broken and no alarm fires — those are the expensive ones, because they are found by noticing an absence rather than by reading an error.
Three of these produce a cell that looks completely healthy from the network side: an SSB off the searched raster, cellBarred left set, and a ssb-PositionsInBurst mismatch. In all three the gNB transmits normally, reports no faults, and receives no access attempts. If a cell has good transmit power, no alarms and no traffic, work down those three before touching anything RF.
21. Configuration Reference (ASN.1)
The structures below are abridged from TS 38.331 — fields not relevant to SSB and cell search are elided with ... and that is marked. Field names and types are as specified; comments are added here.
21.1 MIB
MIB ::= SEQUENCE {
systemFrameNumber BIT STRING (SIZE (6)),
-- SFN bits 9..4. The four LSBs are added by L1, not here
subCarrierSpacingCommon ENUMERATED {scs15or60, scs30or120},
-- SCS of SIB1, the initial BWP, paging and Msg2/Msg4
ssb-SubcarrierOffset INTEGER (0..15),
-- k_SSB, low 4 bits. FR1 takes a 5th bit from the PBCH
-- payload; a resulting value above 23 (FR1) means there is
-- no CORESET#0 associated with this SSB
dmrs-TypeA-Position ENUMERATED {pos2, pos3},
pdcch-ConfigSIB1 PDCCH-ConfigSIB1,
-- 8 bits: controlResourceSetZero + searchSpaceZero.
-- Decoded in the companion 18 MIB and SIB1 IEs document
cellBarred ENUMERATED {barred, notBarred},
intraFreqReselection ENUMERATED {allowed, notAllowed},
spare BIT STRING (SIZE (1))
}
-- 24 bits exactly. The physical layer adds 8 more before encoding:
-- 4 x SFN LSB, 1 x half-frame, and 3 whose use depends on L_max
-- (SSB index MSBs at L_max = 64; k_SSB MSB + reserved otherwise)Listing 1. The MIB, complete — it is small enough not to need abridging. The companion 18 MIB and SIB1 IEs document decodes every field; here only ssb-SubcarrierOffset and cellBarred are in scope.
21.2 The SSB fields of ServingCellConfigCommon
ServingCellConfigCommon ::= SEQUENCE {
physCellId PhysCellId OPTIONAL,
-- PhysCellId ::= INTEGER (0..1007) <- the 1008 of section 10
downlinkConfigCommon DownlinkConfigCommon OPTIONAL,
...
ssbPositionsInBurst CHOICE {
shortBitmap BIT STRING (SIZE (4)),
mediumBitmap BIT STRING (SIZE (8)),
longBitmap BIT STRING (SIZE (64))
} OPTIONAL,
ssb-periodicityServingCell ENUMERATED {ms5, ms10, ms20,
ms40, ms80, ms160,
spare2, spare1}
OPTIONAL,
dmrs-TypeA-Position ENUMERATED {pos2, pos3},
...
ssbSubcarrierSpacing SubcarrierSpacing OPTIONAL,
-- kHz15 | kHz30 | kHz120 | kHz240. Never kHz60
...
ss-PBCH-BlockPower INTEGER (-60..50),
...
}Listing 2. Dedicated signalling, abridged. Note that the 64-bit longBitmap is available here but not in SIB1 — dedicated signalling can afford the bits.
21.3 The same fields as broadcast in SIB1
ServingCellConfigCommonSIB ::= SEQUENCE {
downlinkConfigCommon DownlinkConfigCommonSIB,
...
ssb-PositionsInBurst SEQUENCE {
inOneGroup BIT STRING (SIZE (8)),
groupPresence BIT STRING (SIZE (8))
OPTIONAL
-- groupPresence is present only when L_max = 64.
-- Transmitted SSBs = (bits set in groupPresence)
-- x (bits set in inOneGroup)
},
ssb-PeriodicityServingCell ENUMERATED {ms5, ms10, ms20,
ms40, ms80, ms160},
...
ss-PBCH-BlockPower INTEGER (-60..50),
...
}
FrequencyInfoDL-SIB ::= SEQUENCE {
frequencyBandList MultiFrequencyBandListNR-SIB,
offsetToPointA INTEGER (0..2199),
-- 15 kHz PRBs in FR1, 60 kHz PRBs in FR2. Measured from
-- point A to the lowest subcarrier of the lowest CRB that
-- overlaps the SSB used for initial cell selection
scs-SpecificCarrierList SEQUENCE (SIZE (1..maxSCSs))
OF SCS-SpecificCarrier
}
SCS-SpecificCarrier ::= SEQUENCE {
offsetToCarrier INTEGER (0..2199),
subcarrierSpacing SubcarrierSpacing,
carrierBandwidth INTEGER (1..maxNrofPhysicalResourceBlocks),
...
}Listing 3. The broadcast forms, abridged. offsetToPointA and offsetToCarrier sit in different structures and answer different questions — see the table in §17.
21.4 SSB-MTC, for completeness
SSB-MTC ::= SEQUENCE {
periodicityAndOffset CHOICE {
sf5 INTEGER (0..4),
sf10 INTEGER (0..9),
sf20 INTEGER (0..19),
sf40 INTEGER (0..39),
sf80 INTEGER (0..79),
sf160 INTEGER (0..159)
},
duration ENUMERATED {sf1, sf2, sf3,
sf4, sf5}
}
-- The measurement window of section 18. Owned in full by the
-- companion 21 Measurement Gaps and SMTC document; quoted here only
-- so the relationship to ssb-periodicityServingCell is visible:
-- the SMTC periodicity must be a multiple of, or equal to, the
-- neighbour's actual SSB periodicity, or windows and bursts drift
-- past each other.Listing 4. SSB-MTC as it appears in measObjectNR. Included to make the §18 point concrete: the window and the burst set are configured independently and nothing checks that they agree.
22. Nine Worked Calculations
The arithmetic of this document, collected and carried through to answers. Six of these appear in the sections above; three are new. All use consistent numbers, so they compose: the n78 cell is the same cell throughout, with PCI 431, GSCN 7883 and carrier ARFCN 638884.
22.1 to 22.3 NR-ARFCN to frequency, one per global raster range
Formula: F_REF = F_REF_Offs + ΔF_Global × (N_REF − N_REF_Offs)
Range 1, below 3 GHz. N_REF = 431000
ΔF_Global = 5 kHz, F_REF_Offs = 0, N_REF_Offs = 0
F = 0 + 5 kHz × 431000 = 2155.000 MHz (band n1 downlink)
Range 2, 3 to 24.25 GHz. N_REF = 638884
ΔF_Global = 15 kHz, F_REF_Offs = 3000 MHz, N_REF_Offs = 600000
F = 3000 + 15 kHz × 38884 = 3000 + 583.26 = 3583.26 MHz (n78)
Range 3, above 24.25 GHz. N_REF = 2079167
ΔF_Global = 60 kHz, F_REF_Offs = 24250.08 MHz, N_REF_Offs = 2016667
F = 24250.08 + 60 kHz × 62500 = 24250.08 + 3750 = 28000.08 MHz (n257)
22.4 GSCN to SS_REF on n78, and the reverse
Forward. GSCN 7883, so region 2 (7499 ≤ GSCN ≤ 22255).
N = 7883 − 7499 = 384
SS_REF = 3000 MHz + 384 × 1.44 MHz = 3552.96 MHz
Block occupies 3552.96 ± 3.6 = 3549.36 to 3556.56 MHz at 30 kHz
Reverse. An SSB is measured centred at 3679.68 MHz.
N = (3679.68 − 3000) / 1.44 = 679.68 / 1.44 = 472 (exact)
GSCN = 7499 + 472 = 7971
Sanity: 7971 is inside n78's published range 7711 – 8051 ✓
A negative case, to show what failure looks like. An SSB measured at 3680.00 MHz.
N = 680.00 / 1.44 = 472.22 — not an integer
This frequency is not on the synchronisation raster. A compliant UE will never test it, and the cell is undiscoverable. This is failure mode one in §20.
22.5 GSCN points to scan on n78, and the search-time cost
n78's published range is 7711 – <1> – 8051.
Points = 8051 − 7711 + 1 = 341
Spacing = 1.44 MHz, so they span 341 × 1.44 = 491 MHz of the band's 500 MHz
Serial search cost, at the initial-search assumption of 20 ms periodicity and 5 burst sets accumulated per candidate:
Dwell per candidate = 5 × 20 ms = 100 ms
Total = 341 × 100 ms = 34.1 s
Contrast, if the SSB were allowed on n78's 15 kHz channel raster instead:
Points = (653333 − 620000) + 1 = 33 334
Total = 33 334 × 100 ms = 3333 s ≈ 56 minutes
Ratio = 33 334 / 341 = 97.8×. Both figures are order of magnitude and worst-case-serial; a real receiver tests many candidates inside one wideband capture, which changes the wall-clock time but not the number of correlation hypotheses.
22.6 PCI derivation, both directions
Forward. N_ID1 = 143 (from SSS), N_ID2 = 2 (from PSS).
PCI = 3 × N_ID1 + N_ID2 = 3 × 143 + 2 = 431
PSS cyclic shift = 43 × 2 = 86
SSS offsets: m0 = 15 × FLOOR(143/112) + 5 × 2 = 15 + 10 = 25
m1 = 143 mod 112 = 31
PBCH DM-RS comb: ν = 431 mod 4 = 3
Reverse. A log reports PCI 431.
N_ID2 = 431 mod 3 = 2
N_ID1 = FLOOR(431 / 3) = 143
Check: 3 × 143 + 2 = 431 ✓
Second forward case. N_ID1 = 289, N_ID2 = 1.
PCI = 3 × 289 + 1 = 868
m0 = 15 × FLOOR(289/112) + 5 × 1 = 15 × 2 + 5 = 35
m1 = 289 mod 112 = 65
ν = 868 mod 4 = 0
22.7 Case C candidate symbol positions for L_max = 8
Pattern {2, 8} + 14n, n = 0..3, at 30 kHz -- 0.5 ms slots, 14 symbols
Candidate first symbols: 2, 8, 16, 22, 30, 36, 44, 50
index symbol slot sym-in-slot start (ms) end (ms)
----- ------ ---- ----------- ---------- ---------
0 2 0 2 0.071 0.214
1 8 0 8 0.286 0.429
2 16 1 2 0.571 0.714
3 22 1 8 0.786 0.929
4 30 2 2 1.071 1.214
5 36 2 8 1.286 1.429
6 44 3 2 1.571 1.714
7 50 3 8 1.786 1.929
start = (symbol / 14) x 0.5 ms; each block is 4 symbols = 0.143 msSweep duration = 1.929 − 0.071 = 1.86 ms of a 5 ms half-frame, so the burst set occupies under 40 % of the half it sits in. Slots 4 through 9 carry no candidate positions at all, and symbols 0–1 and 12–13 of each SSB slot stay clear — which is where CORESET#0 goes.
22.8 k_SSB and offsetToPointA to an absolute frequency
The full chain for the n78 cell, condensed from §17.
GSCN 7883 → SS_REF = 3552.96 MHz
− 3.6 MHz (half of 240 × 30 kHz) → lowest SSB sc = 3549.36 MHz
− k_SSB 8 × 15 kHz = 0.12 MHz → bottom of CRB 42 = 3549.24 MHz
− offsetToPointA 84 × 0.18 MHz → point A = 3534.12 MHz
+ 273 PRB × 0.36 MHz / 2 = 49.14 MHz → carrier centre = 3583.26 MHz
→ N_REF = 600000 + (583.26 / 0.015) = 600000 + 38884 = 638884
SSB centre is 3583.26 − 3552.96 = 30.30 MHz below carrier centre
Parity check: subCarrierSpacingCommon is 30 kHz, so a CRB is 360 kHz = two 15 kHz PRBs. offsetToPointA must be even. 84 ✓
22.9 SSB overhead as a fraction of the downlink
How much of the cell the sweep actually costs. n78, 100 MHz, 273 PRB at 30 kHz, Case C, 8 SSBs transmitted, ms20 periodicity.
Per SSB: 4 symbols × 20 PRB = 4 × 240 = 960 REs
Per burst set: 8 × 960 = 7680 REs
Available in 20 ms at 30 kHz:
20 ms = 40 slots; 40 × 14 symbols × 273 PRB × 12 sc
= 40 × 14 × 3276 = 1 834 560 REs
Overhead = 7680 / 1 834 560 = 0.42 %
Now the same cell on ms160: 0.42 / 8 = 0.05 %, at eight times the initial-search cost (§16). And an FR2 cell sweeping 64 beams at ms20 pays 8 × that per burst set — still under 4 % of a 400 MHz carrier, which is why FR2 can afford 64 candidate positions at all.
The number worth remembering is the first one: under half a percent. SSB overhead is almost never the reason to lengthen the periodicity, and the search-time cost of doing so is large. Figures exclude the guard symbols a scheduler typically leaves around the block, which roughly doubles the practical cost.
23. Illustrative Message Traces
Illustrative trace. Field names and encodings follow 3GPP; the values are constructed for this document and are not a capture from any deployed or lab network.
Five traces, all for the same cell: band n78, GSCN 7883, PCI 431, Case C with L_max = 8, ssb-PositionsInBurst = 1101 0000, ssb-periodicityServingCell = ms20. The final one is a failure path.
23.1 A raster scan, with one hit
09:41:02.104 [PHY-SRCH] cell search started reason=powerOn
stored frequency list ......... empty
band list .................... n78
GSCN range for n78 ........... 7711 - <1> - 8051 (341 pts)
assumed SSB periodicity ...... 20 ms (TS 38.213 cl. 4.1)
dwell per candidate .......... 100 ms (5 burst sets)
09:41:02.104 [PHY-SRCH] GSCN 7711 f=3305.28 MHz PSS corr peak -- / -- / --
09:41:02.206 [PHY-SRCH] GSCN 7712 f=3306.72 MHz no peak above threshold
09:41:02.308 [PHY-SRCH] GSCN 7713 f=3308.16 MHz no peak above threshold
... GSCN 7714 .. 7881 elided, all negative ...
09:41:19.462 [PHY-SRCH] GSCN 7882 f=3551.52 MHz no peak above threshold
09:41:19.564 [PHY-SRCH] GSCN 7883 f=3552.96 MHz
PSS correlation N_ID2=0 .... 2.1 dB (below threshold)
PSS correlation N_ID2=1 .... 1.8 dB (below threshold)
PSS correlation N_ID2=2 ... 14.6 dB ** PEAK **
peak sample offset ........... 118 774
coarse freq offset est ....... -1.9 kHz
-> N_ID2 = 2, symbol timing acquired, scan halted
09:41:19.566 [PHY-SRCH] scan summary candidates tried 173 of 341, elapsed 17.46 sListing 5. A cold start with nothing stored. 173 candidates tried before a hit — roughly half the list, which is what you would expect on average for a randomly placed cell. The elapsed time is the number §2 predicts.
23.2 PSS and SSS, with the PCI derived
09:41:19.566 [PHY-SYNC] PSS accepted N_ID2=2 GSCN 7883
applying coarse frequency correction -1.9 kHz
09:41:19.586 [PHY-SYNC] SSS search symbol l=2, k=56..182
hypotheses tested ............ 336
best N_ID1=143 metric 11.9 dB
2nd N_ID1=087 metric 3.2 dB (8.7 dB margin)
-> N_ID1 = 143
09:41:19.586 [PHY-SYNC] PCI = 3 x N_ID1 + N_ID2
= 3 x 143 + 2 = 431
derived: PSS cyclic shift .... 43 x 2 = 86
derived: SSS m0 .............. 15 x FLOOR(143/112) + 5x2 = 25
derived: SSS m1 .............. 143 mod 112 = 31
derived: PBCH DM-RS comb nu .. 431 mod 4 = 3
SS-RSRP ...................... -91.4 dBm
09:41:19.586 [PHY-SYNC] frequency now known, identity now known;
frame timing still unknownListing 6. The 8.7 dB margin between the best and second-best SSS hypothesis is the number to look at. A margin under about 3 dB means the PCI should be treated as provisional — that is the signature of the collision case in §20.
23.3 The SSB index from the DM-RS, then PBCH and the MIB
09:41:19.588 [PHY-PBCH] DM-RS hypothesis test, L_max=8 -> i_SSB = index mod 8
c_init = 2^11 x (i_SSB+1) x (FLOOR(431/4)+1)
+ 2^6 x (i_SSB+1) + (431 mod 4)
i_SSB=0 .. corr 1.2 dB i_SSB=4 .. corr 0.9 dB
i_SSB=1 .. corr 0.8 dB i_SSB=5 .. corr 1.1 dB
i_SSB=2 .. corr 9.8 dB ** i_SSB=6 .. corr 1.4 dB
i_SSB=3 .. corr 1.0 dB i_SSB=7 .. corr 0.7 dB
-> SSB index = 2 (candidate first symbol 16, slot 1 sym 2)
09:41:19.588 [PHY-PBCH] descramble hypothesis 2 SFN bits unknown
hyp 0 (SFN[3:2]=00) .. CRC FAIL
hyp 1 (SFN[3:2]=01) .. CRC FAIL
hyp 2 (SFN[3:2]=10) .. CRC OK
-> SFN[3:2] = 10
09:41:19.588 [PHY-PBCH] PBCH decoded Polar, 864 -> 56 bits, CRC-24 OK
MIB
systemFrameNumber ........ 101101 -- SFN[9:4] = 45
subCarrierSpacingCommon .. scs30or120 -- 30 kHz here
ssb-SubcarrierOffset ..... 8 -- k_SSB, low 4 bits
dmrs-TypeA-Position ...... pos2
pdcch-ConfigSIB1 ......... 0x60 -- to companion 18
cellBarred ............... notBarred
intraFreqReselection ..... allowed
spare .................... 0
L1-added bits
SFN LSBs ................. 1011 -- SFN[3:0]
halfFrameBit n_hf ........ 0
k_SSB MSB ................ 0 -- k_SSB = 8, in range
09:41:19.588 [PHY-PBCH] SFN = 101101 1011 = 731
n_hf = 0 -> burst set in subframes 0..4 of frame 731
frame timing acquiredListing 7. The two halves of the SFN joining up: 0b101101 = 45 as the high six bits, 0b1011 = 11 as the low four, giving 45 × 16 + 11 = 731. Note that hypothesis 2 gave SFN[3:2] = 10, which is consistent with the payload's 1011.
23.4 The burst set, once the cell is being measured
09:41:19.640 [PHY-SSB] burst set observed, frame 731, half-frame 0
Case C, 30 kHz, L_max = 8
ssb-PositionsInBurst (from SIB1) = 1101 0000
idx first sym slot/sym declared measured SS-RSRP
0 2 0 / 2 yes yes -94.8 dBm
1 8 0 / 8 yes yes -91.4 dBm
2 16 1 / 2 no -- --
3 22 1 / 8 yes yes -103.2 dBm
4 30 2 / 2 no -- --
5 36 2 / 8 no -- --
6 44 3 / 2 no -- --
7 50 3 / 8 no -- --
09:41:19.640 [PHY-SSB] best beam = idx 1 (-91.4 dBm)
cell-level SS-RSRP (linear avg of declared) = -93.6 dBm
-- NOTE: acquisition at 09:41:19.588 reported idx 2, which
-- the bitmap declares as NOT transmitted. See 23.5.Listing 8. A three-beam cell in an eight-position range. The inconsistency flagged in the last two lines is the subject of the failure trace below — the UE found a beam the cell says it does not send.
23.5 Failure path: a bitmap that does not match the air
09:41:19.700 [PHY-SSB] consistency check
acquisition SSB index ........ 2
ssb-PositionsInBurst bit 2 ... 0 (declared absent)
-> acquired on an undeclared candidate position
09:41:19.700 [MAC] SSB-to-RACH association lookup for SSB index 2
ssb-perRACH-OccasionAndCB-PreamblesPerSSB = one
association built from DECLARED positions only: {0, 1, 3}
index 2 not present in association map
-> no PRACH occasion derivable for the acquired beam
09:41:19.702 [MAC] falling back: reselect best DECLARED SSB
-> SSB index 1, SS-RSRP -91.4 dBm, above rsrp-ThresholdSSB
-> PRACH occasion from association for index 1
09:41:19.740 [MAC-UL] MSG1 preamble 19, RA-RNTI 1417
09:41:19.752 [MAC] ra-ResponseWindow expired, no RAR
09:41:19.790 [MAC-UL] MSG1 preamble 44, RA-RNTI 1417, +4 dB
09:41:19.802 [MAC] ra-ResponseWindow expired, no RAR
... attempts 3..8 elided, all timing out ...
09:41:20.104 [MAC] PREAMBLE_TRANSMISSION_COUNTER = preambleTransMax
09:41:20.104 [MAC] -> Random Access problem indication to RRC
09:41:20.104 [RRC] T300 running -> connection establishment failure
09:41:20.105 [RRC] -> RRC_IDLE, cell reselection
-- Diagnosis: the cell is transmitting a beam at candidate position 2
-- that ssb-PositionsInBurst declares absent. The UE acquired on it,
-- could not map it to a PRACH occasion, fell back to index 1 -- and
-- index 1's beam does not actually cover this UE's location, so the
-- preamble is never heard. Nothing in the RF chain is faulty.Listing 9. The bitmap mismatch of §20, followed all the way to a connection establishment failure. Note how far the symptom is from the cause: the visible failure is a RACH timeout, and the fix is a 4-bit broadcast field.
The shape of 23.5 is the reason this document exists. Every observable symptom — preamble timeouts, T300 expiry, connection establishment failure — points at random access or at coverage. The actual cause is four bits in SIB1. When RACH fails on a cell whose SSB acquisition succeeded, compare the acquired SSB index against ssb-PositionsInBurst before anything else; it is a two-second check that rules out a whole class of misdiagnosis. See the companion 03 Random Access document for the association itself.
24. Release Deltas: Rel-15 to Rel-18
The SSB and the rasters have been unusually stable — they are the foundation everything else stands on, and changing them breaks every deployed UE. What has changed is mostly additive: new frequency ranges needing new numerologies, and new operating modes that transmit the SSB differently or not at all.
| Release | Change | Why it matters when reading cell search |
|---|---|---|
| Rel-15 | The baseline: three global raster ranges, GSCN and the synchronisation raster, Cases A through E, L_max 4/8/64, 1008 PCIs, the 24-bit MIB, ssb-PositionsInBurst in all three forms | Everything in §3 to §17 is Rel-15 and has not moved |
| Rel-15 late | Per-band GSCN ranges extended as bands were widened (notably the n77 and n78 ranges) | A range read from an early specification version can be short. If a cell's GSCN looks out of range, check the version before concluding misconfiguration |
| Rel-16 | NR-U: SSB transmitted inside a discovery burst transmission window subject to listen-before-talk, so its position in time is no longer deterministic | On unlicensed spectrum the SSB may simply not be transmitted in a given period because the channel was busy. A missing burst set is not evidence of a fault |
| Rel-16 | NR-U candidate SSB index extended beyond L_max with a QCL relationship parameter, so several candidate positions can carry the same beam | Two different SSB indices in an NR-U log can be the same beam. Do not count distinct indices as distinct beams there |
| Rel-16 | Cross-carrier and cross-link improvements to SSB-based measurement; ssb-PositionQCL signalling | Measurement configuration gains QCL context the earlier releases lacked |
| Rel-17 | SSB-less SCell operation for intra-band carrier aggregation: an SCell may transmit no SSB at all and rely on the PCell's timing and the SCell's TRS | A carrier with no SSB is now legitimate. Absence of an SSB on a configured carrier is not automatically a fault — check whether it is an SSB-less SCell. See the companion 29 Carrier Aggregation |
| Rel-17 | 52.6 – 71 GHz support: SSB subcarrier spacings of 480 and 960 kHz, with additional candidate-position patterns beyond Case E, and an extended sync raster region | A UE reporting an SSB SCS outside {15, 30, 120, 240} kHz is on FR2-2. The Case letters and n-value sets there are additions, not replacements — read TS 38.213 cl. 4.1 for the release in use |
| Rel-17 | RedCap: no change to the SSB itself, but a separate initial uplink BWP and separate PRACH resources | Two UE classes can acquire the same SSB and then diverge completely. The SSB index means the same thing to both |
| Rel-17 | NTN: SSB unchanged, but Doppler and propagation delay are orders of magnitude larger | PSS frequency-offset estimation carries far more of the burden, and the "PSS found, SSS failing" signature of §20 becomes much more common and much less diagnostic |
| Rel-18 | Network energy saving: cell DTX/DRX and adapted SSB transmission, including spatial and temporal adaptation of the burst set | A cell may legitimately reduce or shift its SSB transmission to save power. ssb-PositionsInBurst no longer fully describes what is on the air at every instant |
| Rel-18 | LTM (L1/L2-triggered mobility): candidate cells' SSB and TRS are measured and reported at L1, and a cell switch may involve no RRC signalling | A mobility event may show no RRC messages at all — the SSB measurements are the only trace of it. See companion 25 Conditional HO and DAPS for the neighbouring mechanisms |
| Rel-18 | Further NTN and non-terrestrial refinements; expanded per-band tables for newly allocated spectrum | Per-band GSCN ranges continue to be added. Always read the current table |
Table 22. SSB and cell-search relevant changes by release. Feature presence should be confirmed against the UE capability exchange — see the companion 26 UE Capability document — rather than assumed from the release the software claims.
25. Reading Cell Search in Logs: A Checklist
- Establish whether the UE was searching blind or was told where to look. A log that lists GSCN candidates in ascending order is a cold start (§7). A log that goes straight to one frequency was given it — by stored information, by
redirectedCarrierInfo, or by measurement configuration. The two have completely different expected durations, and judging a directed search by cold-start timings will make a healthy UE look slow. - Check the GSCN against the band's published range before anything else. Compute N = (F − F_base) / step and confirm it is an integer inside the range from TS 38.104 cl. 5.4.3.3. A non-integer means the SSB is not on the raster and no UE will ever find it; an integer outside the range means the SSB is on the raster but not where UEs searching that band will look. Both produce a cell with zero traffic and no alarms (§20).
- Separate the three rasters in your head before quoting any frequency. A GSCN is not an ARFCN. If a tool has shown you an "SSB ARFCN", it has performed a conversion that may not be exact — go back to the GSCN and run the SS_REF equation (§6).
- Read how far the acquisition chain got. PSS peak only, PSS plus PCI, PCI plus SSB index, or a decoded MIB. Each stopping point implicates different causes (the table at the end of §11), and only the first two can be helped by more transmit power.
- When PSS succeeded but SSS did not, suspect frequency error, not coverage. SSS's 336-way correlation is far more sensitive to residual frequency offset than PSS's 3-way one. Look for a cold-start oscillator error, high Doppler, or narrowband interference sitting in symbol 2 (§9, §20).
- Check the SSS detection margin, not just the winner. A best-to-second-best margin under about 3 dB means the PCI is provisional. That is the signature of a PCI collision, and it will also produce erratic RSRP for that PCI between adjacent samples (§20, trace 23.2).
- Recompute the PCI decomposition. N_ID2 = PCI mod 3, N_ID1 = FLOOR(PCI/3), ν = PCI mod 4. If a plan has first-tier neighbours all congruent modulo 3, it has thrown away the PSS diversity; if they are congruent modulo 4 as well, they are also sharing the PBCH DM-RS comb (§8.2, §10.1).
- Compare the acquired SSB index against
ssb-PositionsInBurstbefore investigating a RACH failure. An index the bitmap declares absent cannot be mapped to a PRACH occasion, and the resulting failure looks exactly like a coverage problem. Trace 23.5 walks the whole path. - Count the reported SSB indices against the cell's provisioned beam count. Fewer reported than provisioned is usually the bitmap, not the antenna. At L_max = 64 in SIB1, remember that the count is
groupPresencebits set ×inOneGroupbits set, not a 64-bit string (§15). - Verify the SFN assembly arithmetic explicitly when timing looks wrong: six MIB bits as SFN[9:4], four payload bits as SFN[3:0], and the half-frame bit separately. A missed paging or PRACH occasion by exactly 5 ms is a half-frame error; by a multiple of 40 ms it is an SFN LSB error (§13).
- Check
ssb-periodicityServingCellagainst the accessibility statistics whenever initial access has become slow or erratic without any RF change.ms40and beyond cost search time in direct proportion and are frequently introduced during overhead optimisation without anyone connecting the two (§16). - Recompute the k_SSB and offsetToPointA chain when SIB1 reads and nothing after it works. Check
offsetToPointAparity againstsubCarrierSpacingCommon, and check that the SSB's full 240 subcarriers fall inside the carrier's PRBs (§17, §20). - For a neighbour that is on the air but never reported, check the SMTC first. An SMTC that does not align with the neighbour's actual burst sets fails silently and completely, unlike initial search which merely degrades (§18). The companion 21 Measurement Gaps and SMTC has the window arithmetic.
26. Glossary
Every term is glossed as it is first used in the body as well; this is for looking things up afterwards.
| Term | Expansion | Meaning in this document |
|---|---|---|
| SSB | SS/PBCH Block | The four-symbol by 240-subcarrier block carrying PSS, SSS, PBCH and the PBCH DM-RS. The only thing a UE can find with no prior information |
| Raster | — | An agreed grid of permitted frequencies. NR has three, and they answer three different questions (§3) |
| NR-ARFCN | NR Absolute Radio Frequency Channel Number | The number that names a point on the global frequency raster. A dictionary entry, not a permission |
| ΔF_Global | Global raster step | 5 kHz below 3 GHz, 15 kHz to 24.25 GHz, 60 kHz above. Sets how finely frequencies can be named |
| ΔF_Raster | Channel raster step | Per band. The spacing of permitted carrier centre frequencies — a subset of the global raster |
| GSCN | Global Synchronisation Channel Number | The number of a permitted SSB centre position. Its own numbering, 2 to 26639, unrelated to ARFCN |
| SS_REF | Synchronisation raster reference frequency | The centre frequency a GSCN corresponds to |
| M | The sub-3 GHz raster sub-position selector | ∈ {1, 3, 5}, giving ±50 kHz around each nominal 1.2 MHz point. Exists only below 3 GHz, to fit refarmed bands (§6.1) |
| m-sequence | Maximum-length sequence | A shift-register-generated binary sequence that correlates strongly with itself and weakly with any shift of itself. PSS is one of length 127 |
| Gold sequence | — | The product of two m-sequences at chosen offsets, which yields far more distinguishable members than one m-sequence. SSS is one, giving 336 members |
| PSS | Primary Synchronisation Signal | Symbol 0, k = 56..182. Three cyclic shifts of one m-sequence. Yields symbol timing, coarse frequency, and N_ID2 |
| SSS | Secondary Synchronisation Signal | Symbol 2, same subcarriers. 336 Gold sequences. Yields N_ID1 |
| N_ID2 / N_ID1 | PSS and SSS identity components | 0 to 2 and 0 to 335. Combine as PCI = 3 × N_ID1 + N_ID2 |
| PCI | Physical Cell Identity | 0 to 1007. The number every log and measurement report uses to name a cell. Not globally unique — it is reused, which is why collisions and confusion happen (§20) |
| Half-frame | — | Five subframes: half-frame 0 is subframes 0–4, half-frame 1 is 5–9. An SSB burst set is always confined to one of them |
| n_hf | Half-frame bit | 0 or 1, saying which half-frame the burst set occupies. Carried in the PBCH payload, or folded into the DM-RS hypothesis at L_max = 4 |
| Burst set | SSB burst set | The group of SSBs a cell transmits in one half-frame — one per beam. A beam sweep (§14) |
| Candidate position | — | A specification-fixed first-symbol index at which an SSB may start inside the half-frame. Given by the Case |
| Case A – E | SSB candidate position patterns | Five patterns of candidate positions, selected by SSB subcarrier spacing and frequency range (§14.1) |
| L_max | — | The number of candidate positions in the half-frame: 4 below 3 GHz, 8 to 7.125 GHz, 64 above 6 GHz. A ceiling, not a count |
| SSB index | — | Which candidate position a particular SSB occupied. Recovered from the PBCH DM-RS, plus payload bits on FR2 (§12) |
| k_SSB | ssb-SubcarrierOffset | The fine frequency offset between the SSB's lowest subcarrier and the resource block containing it. 15 kHz units in FR1 |
offsetToPointA | — | The coarse offset, in resource blocks, from point A up to the lowest CRB overlapping the SSB used for initial cell selection |
| Point A | — | The origin of the cell's common resource block grid; every CRB in the cell is numbered from it. Owned by companion 02 |
| CRB | Common Resource Block | A resource block numbered from point A, as opposed to a PRB numbered from the start of a bandwidth part |
| CORESET#0 | — | The control resource set used to schedule SIB1, indexed from pdcch-ConfigSIB1 and k_SSB. Owned by companions 18 and 30 |
| SMTC | SSB Measurement Timing Configuration | The window during which a connected UE opens its receiver to measure a neighbour's SSBs. Owned by companion 21 |
| SS-RSRP | SSB Reference Signal Received Power | Power measured on the SSB's SSS and, optionally, PBCH DM-RS resource elements. What a measurement report carries |
27. References
- 3GPP TS 38.104 — Base Station radio transmission and reception. Clause 5.4.2 (frequency channel raster: 5.4.2.1 the global raster and the NR-ARFCN equation, 5.4.2.2 the channel raster), clause 5.4.3 (synchronisation raster: 5.4.3.1 the SS_REF and GSCN equations for all three ranges, 5.4.3.2 the mapping between SS_REF and the SSB, 5.4.3.3 the per-band GSCN ranges — Table 5.4.3.3-1 is the one to read for any specific band).
- 3GPP TS 38.101-1 — UE radio transmission and reception, Range 1. Clause 5.2 (operating bands), clause 5.3 (channel bandwidths and transmission bandwidth in PRBs), clause 5.4.2.3 (per-band ΔF_Raster and NR-ARFCN ranges).
- 3GPP TS 38.101-2 — UE radio transmission and reception, Range 2. The same clause structure for FR2, including the 60 and 120 kHz channel rasters and the FR2 band table.
- 3GPP TS 38.211 — Physical channels and modulation. Clause 7.4.1.4 (PBCH DM-RS, including 7.4.1.4.1 sequence generation and the c_init expression), clause 7.4.2 (synchronisation signals: 7.4.2.1 the PCI composition, 7.4.2.2 PSS, 7.4.2.3 SSS), clause 7.4.3 (SS/PBCH block: 7.4.3.1 the resource element mapping and Table 7.4.3.1-1, 7.4.3.1.1 the time-frequency structure).
- 3GPP TS 38.212 — Multiplexing and channel coding. Clause 7.1 (broadcast channel: 7.1.1 the PBCH payload generation and the eight added bits, 7.1.2 the scrambling and which bits are excluded from it, 7.1.3 the CRC, 7.1.4 the Polar encoding, 7.1.5 the rate matching).
- 3GPP TS 38.213 — Physical layer procedures for control. Clause 4.1 (cell search: the SSB candidate positions for Cases A through E, L_max by frequency range, and the 20 ms periodicity a UE may assume for initial cell selection), clause 13 (the CORESET#0 and searchSpaceZero tables and the k_SSB validity rules).
- 3GPP TS 38.331 — RRC protocol specification.
MIB,ServingCellConfigCommon,ServingCellConfigCommonSIB,FrequencyInfoDL,FrequencyInfoDL-SIB,SCS-SpecificCarrier,SSB-MTC,MeasObjectNR,PhysCellId. - 3GPP TS 38.300 — NR overall description. Clause 9.2.6 and clause 5.2 for where cell search sits in the access procedure and the state model.
- 3GPP TS 38.133 — Requirements for support of radio resource management. The cell identification delay and measurement accuracy requirements that turn the search-time discussion of §2 and §16 into conformance numbers.
Companion documents in this set
- 01 Registration Process — what happens after SIB1: the first RACH, the NAS registration, and where
redirectedCarrierInfocomes from that shortens the next search (§7). - 02 Radio Frame Structure — the resource grid, the numerologies, frames, half-frames, the SFN, point A and the common resource block grid. It owns everything this document measures offsets against, and it gives the SSB and the sync raster at survey level; this document is the deep treatment (§8, §13, §17).
- 03 Random Access — the SSB-to-PRACH-occasion association that makes the SSB index matter, and the preamble procedure that trace 23.5 ends in.
- 17 System Information — the SI acquisition procedure, the SI windows, and on-demand SI, all of which begin where §11 stops.
- 18 MIB and SIB1 IEs — the MIB decoded field by field,
pdcch-ConfigSIB1decomposed, the CORESET#0 andsearchSpaceZerotables,cellSelectionInfoand the S-criteria, anduac-BarringInfo. This document hands over to it at step 8 of §11 (§17, §21.1). - 19 Paging — the paging occasion arithmetic, which is the first thing a correctly assembled SFN and half-frame are used for (§13).
- 20 Measurements and Events — what is done with SS-RSRP once the SSB is being measured rather than searched for (§18).
- 21 Measurement Gaps and SMTC — the SMTC window arithmetic, and the gap patterns that let a UE measure another frequency at all (§18).
- 29 Carrier Aggregation — SSB-less SCell operation, where a configured carrier legitimately carries no SSB (§24).
- 30 CORESET and Search Space — where PDCCH candidates live, including CORESET#0 as a special case of the general structure.
- 33 DMRS — every reference signal in the system, including the PBCH DM-RS sequence generation this document uses but does not derive (§8.2, §12).
- 35 Physical Channels — PBCH as one of the six physical channels, with its coding chain in full, and the rate-matching rules that keep PDSCH off the SSB's resource elements (§8.1, §15).