>
Home5G NRPHY — Physical LayerSSB & Cell Search
📶 PHY — Physical LayerBeginner

SSB & Cell Search — How a Phone Finds a Cell in 5G NR

Power-on to sync: frequency scan & RSSI, the SSB, PSS/SSS and PBCH/MIB — every what, why and how.

📚 3GPP-basedTS 38.211TS 38.213TS 38.304

A UE that has just been switched on knows nothing useful. It does not know what frequency to listen on, it does not know when a symbol starts or when a frame starts, and it does not know the name of any cell around it. Cell search is the procedure that resolves all three from a signal the UE has to find without being told where it is. Everything in this document — the shape of the SS/PBCH block, the three separate frequency rasters, the split of the cell identity across two signals, the beam sweep, the 20 ms assumption — is a trade against how long that blind search takes. This document separates the global, channel and synchronisation rasters properly, because they are constantly conflated; maps the SS/PBCH block resource element by resource element; derives the physical cell identity in both directions; walks the search procedure from the first correlation to SIB1; and closes with eleven figures, nine worked calculations, eleven failure modes and a log-reading checklist.

Contents
  1. 01What the UE Does Not Know at Power-On
  2. 02The Cost of Blind Search, in Seconds
  3. 03Three Rasters, and Why There Have To Be Three
  4. 04The Global Frequency Raster and the NR-ARFCN
  5. 05The Channel Raster: Which ARFCNs May Be a Carrier Centre
  6. 06The Synchronisation Raster and the GSCN
  7. 07Per-Band GSCN Ranges, With n78 Worked Through
  8. 08The SS/PBCH Block, Resource Element by Resource Element
  9. 09PSS: Three Sequences, Found With No Timing At All
  10. 10SSS, and the Cell Identity Completed
  11. 11The Search Procedure, Step by Step
  12. 12The SSB Index: What the DM-RS Says Before the MIB Does
  13. 13The Half-Frame Bit, and Why the SFN Arrives in Three Pieces
  14. 14SSB Burst Sets: Cases A Through E
  15. 15ssb-PositionsInBurst: What Is Actually Transmitted
  16. 16SSB Periodicity and the 20 ms Assumption
  17. 17Where the SSB Sits Relative to the Carrier: k_SSB and offsetToPointA
  18. 18From Search to Measurement: the SSB's Second Job
  19. 19Parameter and Range Reference
  20. 20Failure Modes and What Each One Means
  21. 21Configuration Reference (ASN.1)
  22. 22Nine Worked Calculations
  23. 23Illustrative Message Traces
  24. 24Release Deltas: Rel-15 to Rel-18
  25. 25Reading Cell Search in Logs: A Checklist
  26. 26Glossary
  27. 27References

1. What the UE Does Not Know at Power-On

Start with the honest position. A UE that has just been powered on, or that has just walked out of a tunnel, holds no information about the radio world around it. It does not know which frequency any base station is transmitting on. It does not know when an OFDM symbol begins, so it cannot run a Fourier transform in a way that produces anything but noise. It does not know when a radio frame begins, so even a perfectly decoded message would carry no timestamp it could use. And it does not know the identity of any cell, so it has nothing to tell the network about where it is.

That is four separate unknowns, and they are circular. You cannot demodulate without timing. You cannot get timing without knowing which frequency to look at. You cannot know which frequency to look at without having found something. Cell search is the procedure that breaks the circle, and the way it breaks it is with a signal whose shape is known in advance even though its position is not — a signal a receiver can recognise by correlation rather than by decoding.

That signal is the SS/PBCH block, universally shortened to SSB. SS stands for Synchronisation Signals and PBCH for Physical Broadcast Channel; the block bundles both into one small, rigidly specified rectangle of the time-frequency grid. It is the only thing in NR a UE can find with no prior information whatsoever, and everything else the UE ever does hangs off having found it.

What the UE must end up holdingWhere in the SSB it comes fromHow long it takesWhat it unlocks
A carrier frequency it can tune toThe SSB was found at a known GSCN — a numbered slot on the synchronisation raster (§6) — so the frequency is known the moment the block is detectedThe whole scan, and this is the expensive partEverything. Without it the UE is still deaf
Symbol timing and coarse frequency correctionPSS correlation peak in symbol 0 (§9)A few tens of ms per candidate frequency once a peak existsThe ability to run an FFT that produces meaningful subcarriers
The physical cell identity, 0 to 1007PSS gives 1 of 3, SSS gives 1 of 336, and the two combine (§10)One further SSB occasion after PSSDescrambling of everything else in the cell, and the identity the UE reports in measurements
Which beam of the cell it is hearingThe PBCH DM-RS sequence, and on FR2 three payload bits as well (§12)Free — it falls out of the DM-RS correlation the UE has to do anywayThe right PRACH occasion and preamble group to answer on
Frame and half-frame number6 SFN bits in the MIB, 4 more in the PBCH payload, the half-frame bit, and 2 bits carried by the PBCH scrambling (§13)Up to one 80 ms PBCH periodAny scheduled reception at all — paging, SI windows, PRACH occasions
The MIB, and through it CORESET#0The PBCH payload (companion 18 MIB and SIB1 IEs)One successful Polar decodeSIB1, and with it the whole of the cell's common configuration

Table 1. The six things cell search produces, in the order it produces them. Each row depends on every row above it — this is a chain, not a checklist.

💡
Key point

An analogy, and it is only an analogy. The UE is looking for a radio station on a dial it has never tuned, in a country whose broadcasting plan it has not been given — it knows neither the frequency, nor the programme schedule, nor the station's name. What makes the problem tractable is that the dial has detents: the regulator has agreed in advance that stations may only sit at certain marked positions, so the listener clicks from detent to detent instead of sweeping continuously. The synchronisation raster is that set of detents, and §3 to §7 are about how coarse the detents are and why. The analogy breaks down as soon as beams enter the picture — a broadcast station does not point at you — so it is dropped after §7.

2. The Cost of Blind Search, in Seconds

It is worth being concrete about the search-time problem before looking at any of the machinery, because the machinery only makes sense as an answer to it. Searching for a signal you cannot predict costs time in proportion to the number of guesses you have to make. Every guess about frequency has to be tested by listening for long enough to be confident the signal is genuinely absent rather than merely weak, and "long enough" is measured in whole SSB repetition periods, not in microseconds.

So the search time is roughly the number of candidate frequencies multiplied by the dwell time per candidate. Both factors are design choices, and 3GPP pushed on both:

  • The number of candidate frequencies is bounded by making the synchronisation raster deliberately coarse and then, per band, publishing a short list of the raster points that are actually allowed there. On band n78 that list has 341 entries. If the SSB could sit anywhere on the channel raster it would have about 33 000.
  • The dwell time per candidate is bounded by requiring the SSB to repeat at least every 20 ms for the purposes of initial search TS 38.213 cl. 4.1, regardless of what the cell has actually configured. A UE therefore never has to wait longer than 20 ms to know whether it should have heard something.
Figure 1. One acquisition, from power-on to SIB1. The scan across abandoned GSCN candidates dominates; the whole of PSS, SSS, DM-RS, MIB and SIB1 fits in the last 150 ms. This is why the raster design, not the receiver design, sets initial access latency.
🧮
Worked calculation

The search-time budget, order of magnitude.

Take band n78 and a UE with nothing stored — a genuine cold start.

Candidate frequencies (GSCN points in n78) = 341 (§7)

Assumed SSB periodicity for initial search = 20 ms

Burst sets accumulated before declaring absence ≈ 5

Dwell per candidate = 5 × 20 ms = 100 ms

Serial worst case = 341 × 100 ms ≈ 34 s

Now the same sum if the SSB were allowed anywhere on n78's 15 kHz channel raster:

Candidates = (653333 − 620000) + 1 = 33 334

Serial worst case = 33 334 × 100 ms ≈ 56 minutes

The 98-fold ratio between those two numbers is the entire justification for having a separate, sparser synchronisation raster. Real receivers do far better than the serial figure — they test many candidate frequencies inside one wideband capture — but the number of correlation hypotheses scales with the candidate count either way, and that is what costs silicon, battery and time. Treat both numbers as order of magnitude, not as a specified requirement.

Three consequences follow, and they explain design decisions that look arbitrary in isolation:

Design decisionThe search-time reason for itWhat it would cost to do otherwise
PSS has only three variantsPSS is correlated at every candidate frequency and every possible symbol offset, so its variant count multiplies the most expensive part of the search336 PSS variants would multiply the blind-search correlation load by 112 for no gain — the identity can be carried later, cheaply
The identity is split across PSS and SSSSSS is searched only after timing is known, so its 336 variants cost one correlation window, not a sweepPutting all 1008 identities in one signal makes that signal either expensive to search or too long to be robust
The sync raster step is 1.44 MHz above 3 GHz, not 15 kHzIt cuts the candidate count by roughly two orders of magnitudeThe 56-minute figure above
Per-band GSCN ranges are published, not just the rasterA UE searching n78 tests 341 points, not the 14 757 the raster defines between 3 and 24.25 GHzA 43× longer scan for any band-limited UE
Initial search assumes 20 ms periodicityIt bounds the dwell without forcing every cell to transmit that often foreverAn unbounded dwell: a UE could not distinguish "nothing here" from "something here on a 160 ms cycle"
ssb-PositionsInBurst lets a cell send fewer SSBs than L_maxNot a search-time saving for the UE, but an overhead saving for the cell — a 4-beam cell does not pay for 8 candidate positionsWasted downlink resource, and interference at positions nothing needs

Table 2. Six choices in the SSB and raster design, each traced back to the search-time budget. Section references in the middle column point at where the mechanism is described.

3. Three Rasters, and Why There Have To Be Three

This is the section that exists because the word raster is used for three different things and they get mixed up constantly. A raster, plainly, is an agreed grid of permitted frequencies — a list of the only places something is allowed to sit. NR has three such grids, nested inside one another, each answering a different question:

  1. The global frequency raster. Question: what shall we call this frequency? It is a numbering scheme covering everything from 0 to 100 GHz in fixed steps, so that any frequency the system can name has exactly one number. That number is the NR-ARFCN (NR Absolute Radio Frequency Channel Number). It grants no permission at all; it is a dictionary, not a rule.
  2. The channel raster. Question: where may the centre of a carrier sit? This is a per-band subset of the global raster. Its step size is called ΔF_Raster and it varies by band — 100 kHz for many older FR1 bands, 15 or 30 kHz for the newer mid-band ones. It constrains network planning, and it is what an operator's carrier centre frequency is quoted against.
  3. The synchronisation raster. Question: where may an SSB sit? This is a much sparser grid again, with its own numbering — the GSCN, Global Synchronisation Channel Number. It is the list of detents on the dial from §1, and it is deliberately coarse because a UE has to search it blind.
Figure 2. The same 3 MHz of band n1 drawn against all three rasters. Note what the figure makes unavoidable: neither of the two GSCN points in the window lands on a channel raster point, so an SSB placed there is not at a carrier centre. That mismatch is exactly what k_SSB and offsetToPointA exist to express (§17).
Global rasterChannel rasterSynchronisation raster
AnswersWhat is this frequency called?May a carrier centre go here?May an SSB go here?
NumberingNR-ARFCN, N_REFNR-ARFCN, a subset of N_REFGSCN, its own independent numbering
Step5 / 15 / 60 kHz by frequency rangeΔF_Raster: 100 kHz, or 15 / 30 kHz, per band1.2 MHz (+50 kHz sub-steps) / 1.44 MHz / 17.28 MHz by range
ScopeUniversal, 0 – 100 GHzPer band, from TS 38.101-1 and -2Per range for the grid, then per band for the usable list
Who is constrainedNobody — it is a naming conventionThe operator, when planning carriersBoth: the operator when placing the SSB, and the UE when searching
Points across n78 (3300 – 3800 MHz)33 334 at 15 kHz33 334 at ΔF_Raster 15 kHz, or 16 667 at 30 kHz341
Specified inTS 38.104 cl. 5.4.2.1TS 38.104 cl. 5.4.2.2 and TS 38.101-1 cl. 5.4.2.3TS 38.104 cl. 5.4.3

Table 3. The three rasters side by side. The bottom-but-one row is the one worth memorising: on a single band the three grids differ by two orders of magnitude in density.

⚠️
Common pitfall

The three are related but not nested in the way people assume. The channel raster is a subset of the global raster — every carrier centre is a valid NR-ARFCN. The synchronisation raster is not a subset of the channel raster, and on many bands it is not even a subset of the global raster in any useful sense, because 1.2 MHz plus a 50 kHz M-offset does not have to coincide with a 100 kHz channel raster point. A GSCN is therefore reported as a GSCN, never converted to an ARFCN and quoted as one. An analyser that shows you an "SSB ARFCN" has done a conversion that may not be exact.

4. The Global Frequency Raster and the NR-ARFCN

The global raster is the simplest of the three and the easiest to explain in words: it is a ruler laid along the whole usable spectrum, with marks at regular intervals, and every mark has a number. The numbering starts at zero at DC and counts upward. Because the useful step size is not the same at 700 MHz as it is at 39 GHz — a 5 kHz step would need twenty million numbers to reach 100 GHz — the ruler changes its step twice, at 3 GHz and at 24.25 GHz.

The conversion from number to frequency is one equation TS 38.104 cl. 5.4.2.1:

NR-ARFCN to frequency, TS 38.104 cl. 5.4.2.1
F_REF  =  F_REF_Offs  +  DELTA_F_Global  x  ( N_REF  -  N_REF_Offs )

  F_REF          the RF reference frequency, in Hz
  N_REF          the NR-ARFCN -- the channel number itself
  DELTA_F_Global the global raster step for this frequency range
  F_REF_Offs     the frequency at which this range's counting starts
  N_REF_Offs     the channel number at which this range's counting starts

In plain terms: the ARFCN is just a channel number, and this equation converts it to a frequency in hertz by counting a whole number of fixed-size steps up from a fixed starting point. The two Offs quantities exist only so that the three ranges join up without overlapping or leaving a gap — each range restarts its counting where the previous one stopped.

Frequency rangeΔF_GlobalF_REF_OffsN_REF_OffsN_REF rangeTop frequency reachable
0 – 3000 MHz5 kHz0 MHz00 – 599999599999 × 5 kHz = 2999.995 MHz
3000 – 24250 MHz15 kHz3000 MHz600000600000 – 20166663000 + 1416666 × 15 kHz = 24249.99 MHz
24250 – 100000 MHz60 kHz24250.08 MHz20166672016667 – 327916524250.08 + 1262498 × 60 kHz = 99999.96 MHz

Table 4. The three global raster ranges, TS 38.104 Table 5.4.2.1-1. The last column is the arithmetic check that each range really does reach its stated ceiling — worth doing once, because an off-by-one in N_REF_Offs is a silent 15 kHz error in everything downstream.

📘
Spec detail

Why 24250.08 MHz and not 24250 MHz? Because the 60 kHz range has to start on a frequency that is a whole number of 60 kHz steps above something sensible, and because FR2 channels are defined with a 60 kHz granularity throughout. 24250.08 = 24250 + 0.08 MHz, and 80 kHz is not a multiple of 60 kHz — but 24250.08 MHz is the frequency that makes the subsequent 17.28 MHz synchronisation raster (§6) land on whole numbers of 120 kHz PRBs. The offset is chosen for the sync raster's benefit, not the channel raster's.

🧮
Worked calculation

Three ARFCN conversions, one per range.

Range 1. N_REF = 431000.

F = 0 + 5 kHz × (431000 − 0) = 2 155 000 kHz = 2155.000 MHz

In band n1 downlink (2110 – 2170 MHz). Divisible by 20, so it is also a valid n1 channel raster point (§5).

Range 2. N_REF = 638884.

F = 3000 MHz + 15 kHz × (638884 − 600000)

= 3000 MHz + 15 kHz × 38884 = 3000 + 583.26 = 3583.26 MHz

In band n78 (3300 – 3800 MHz). This is the carrier centre used throughout §17 and §22.

Range 3. N_REF = 2079167.

F = 24250.08 MHz + 60 kHz × (2079167 − 2016667)

= 24250.08 + 60 kHz × 62500 = 24250.08 + 3750 = 28000.08 MHz

In band n257 (26500 – 29500 MHz).

Note the shape of all three: subtract the offset, multiply by the step, add the base. Nothing else is going on.

5. The Channel Raster: Which ARFCNs May Be a Carrier Centre

The global raster names every frequency; the channel raster says which of those names an operator is actually allowed to use for the centre of a carrier. It is a filter, nothing more: take the global raster, keep every Nth point, throw the rest away. The keep-every-Nth spacing is called ΔF_Raster and it is fixed per band in TS 38.101-1 for FR1 and TS 38.101-2 for FR2.

Why do bands differ? Because bands were defined at different times, for different technologies, by different regulators. A band that was originally an LTE band inherits LTE's 100 kHz planning grid, because existing licences, existing filters and existing planning tools all assume it. A band defined for NR from the start can afford a finer grid — 15 or 30 kHz, matching the subcarrier spacing — which lets an operator place a carrier so that it fits its licensed block exactly rather than wasting up to 100 kHz at one edge. Finer is better for spectral efficiency and worse for interoperability with anything that predates it.

BandRange (MHz)DuplexΔF_RasterStep in N_REFWhy that value
n12110 – 2170 DLFDD100 kHz20Refarmed IMT-2000 band; inherits the LTE planning grid
n31805 – 1880 DLFDD100 kHz20Refarmed 1800 MHz; same reason
n28758 – 803FDD100 kHz20APT700; licences predate NR
n412496 – 2690TDD15 kHz
30 kHz
3
6
NR-era band; two options, chosen to match the deployed SCS
n773300 – 4200TDD15 kHz
30 kHz
1
2
In range 2, so ΔF_Global is already 15 kHz — step 1 means every global raster point is usable
n783300 – 3800TDD15 kHz
30 kHz
1
2
As n77; the workhorse mid-band
n794400 – 5000TDD15 kHz
30 kHz
1
3
As n77; note the 30 kHz option is step 3, not 2
n25726500 – 29500TDD60 kHz
120 kHz
1
2
FR2; ΔF_Global is 60 kHz, so step 1 is the finest possible

Table 5. Channel raster spacing for a representative spread of bands, from TS 38.101-1 Table 5.4.2.3-1 and TS 38.101-2 Table 5.4.2.3-1. Where two values are listed the band supports two carrier subcarrier spacings and the raster follows. Always read the current table for the band you are actually working on — these change between releases as bands are extended.

🧮
Worked calculation

Reading a channel raster constraint. Band n1 has ΔF_Raster = 100 kHz and lies in global range 1 where ΔF_Global = 5 kHz. So the N_REF step is 100 / 5 = 20, and a valid n1 carrier centre must have an NR-ARFCN divisible by 20.

N_REF = 431000 → 431000 / 20 = 21550 exactly → valid

N_REF = 431003 → not divisible by 20 → invalid as a carrier centre, though it is a perfectly good NR-ARFCN

Both numbers name real frequencies. Only the first one may be a carrier centre. That distinction is the whole content of the channel raster.

For planning purposes the channel raster interacts with two other constraints that are easy to forget. First, the carrier must fit inside the band: the centre frequency plus half the transmission bandwidth must not exceed the band edge, which pulls the usable centre frequencies in from both ends by half a carrier. Second, the carrier's own resource block grid has to be expressible — the relationship between the carrier centre, the transmission bandwidth in PRBs and the guard bands is fixed by TS 38.101-1 cl. 5.3, and the companion 02 Radio Frame Structure document has the PRB tables.

6. The Synchronisation Raster and the GSCN

Now the raster that matters most for this document. The synchronisation raster is the list of frequencies at which an SSB is permitted to be centred, and it is far coarser than either of the other two. The reason is the one from §2 and it is worth stating flatly: every extra permitted position costs the UE real seconds of blind search, so the specification made the list as short as it could while still leaving operators somewhere sensible to put the block in every band. Coarseness here is not laziness; it is the product.

Each permitted position has a number of its own, the GSCN. The GSCN is not an ARFCN and does not share its numbering — it is a separate, compact index that runs from 2 to 26639 across the entire spectrum. There are three regions, matching the three global raster ranges but with completely different arithmetic TS 38.104 cl. 5.4.3.1:

Synchronisation raster and GSCN, TS 38.104 cl. 5.4.3.1
0 - 3000 MHz
  SS_REF = N x 1200 kHz  +  M x 50 kHz      N = 1 .. 2499, M in {1, 3, 5}
  GSCN   = 3N + (M - 3) / 2                 GSCN = 2 .. 7498

3000 - 24250 MHz
  SS_REF = 3000 MHz + N x 1.44 MHz          N = 0 .. 14756
  GSCN   = 7499 + N                         GSCN = 7499 .. 22255

24250 - 100000 MHz
  SS_REF = 24250.08 MHz + N x 17.28 MHz     N = 0 .. 4383
  GSCN   = 22256 + N                        GSCN = 22256 .. 26639

In plain terms, all three lines say the same thing: pick an integer, multiply it by a fixed step, add a fixed base, and you have the centre frequency of a permitted SSB position. The GSCN is simply that integer shifted so that the three regions produce one continuous, non-overlapping numbering. Two details deserve their own explanation.

6.1 What M is for, and why it only exists below 3 GHz

Below 3 GHz the step is not really 1.2 MHz. Each 1.2 MHz position is split into three sub-positions 50 kHz apart, selected by M ∈ {1, 3, 5} — that is, at −50 kHz, 0 and +50 kHz relative to the nominal N × 1.2 MHz point, since M = 3 gives 150 kHz and the other two give 50 and 250 kHz. M = 3 is the ordinary case and is what the great majority of deployed cells use.

M exists because the sub-3 GHz bands are almost all refarmed from LTE or earlier, with licensed blocks whose edges do not line up with a 1.2 MHz grid. Without the ±50 kHz freedom there would be bands in which no legal SSB position existed at all inside a narrow licence. Above 3 GHz the bands are wide and NR-native, the problem does not arise, and M was dropped — which is why a GSCN step of 1 means 1.44 MHz above 3 GHz but only 50 kHz below it.

⚠️
Common pitfall

This is the single most common arithmetic mistake with GSCN. A GSCN step of 1 does not mean the same thing in the two regions. Below 3 GHz, consecutive GSCN values walk the M sub-positions: 5276, 5277, 5278 are 50 kHz apart, and only every third one (M = 3) is the "nominal" 1.2 MHz position. Above 3 GHz, consecutive GSCN values are a full 1.44 MHz apart. A per-band GSCN range of 141 entries below 3 GHz is therefore only 47 distinct 1.2 MHz positions, whereas 141 entries above 3 GHz would be 141 genuinely separate frequencies.

6.2 Why the steps above 3 GHz are what they are

The two upper steps look like arbitrary decimals and are not. They are chosen to be whole numbers of resource blocks at the subcarrier spacing that band range uses:

RegionSync raster stepIn PRBsConsequence
3 – 24.25 GHz1.44 MHz4 PRB at 30 kHz (4 × 360 kHz), or 2 PRB at 60 kHz, or 8 PRB at 15 kHzAn SSB placed on this raster is already nearly aligned to the common resource block grid, so the residual offset k_SSB has to express is at most a few subcarriers (§17)
24.25 – 100 GHz17.28 MHz12 PRB at 120 kHz (12 × 1.44 MHz), or 24 PRB at 60 kHzSame argument at FR2 scale. It is also 12 × the lower region's step, which keeps the two regions' arithmetic related
0 – 3 GHz1.2 MHz nominal, ±50 kHz1.2 MHz = 6⅔ PRB at 15 kHz — not a whole number, and the 50 kHz offsets are not eitherThe SSB can be badly misaligned to the CRB grid here, which is why k_SSB needs five bits and 15 kHz units in FR1 rather than four bits (§17)

Table 6. The raster steps are chosen for grid alignment, and the one region where alignment was impossible is the one region where k_SSB needs an extra bit. The two facts are the same fact.

🧮
Worked calculation

GSCN to frequency, and back again, on n78.

Forward. A log reports the cell's SSB at GSCN 7883.

7883 > 7499, so this is the 3 – 24.25 GHz region.

N = 7883 − 7499 = 384

SS_REF = 3000 MHz + 384 × 1.44 MHz = 3000 + 552.96 = 3552.96 MHz

At 30 kHz SCS the block is 240 × 30 kHz = 7.2 MHz wide, so it spans

3552.96 ± 3.6 MHz = 3549.36 to 3556.56 MHz.

Reverse. A spectrum capture shows an SSB centred on 3679.68 MHz. Which GSCN?

N = (3679.68 − 3000) / 1.44 = 679.68 / 1.44 = 472 exactly

GSCN = 7499 + 472 = 7971

If that division had not come out as an integer, the SSB would not be on the raster and no compliant UE would ever find it — see §20.

7. Per-Band GSCN Ranges, With n78 Worked Through

The raster equations of §6 define far more positions than any UE ever tests. Between 3 and 24.25 GHz alone there are 14 757 of them. A UE searching band n78 does not test 14 757 frequencies; it tests the ones that fall inside n78 and are listed as usable for that band. That list is published per band, as a first value, a step and a last value, in TS 38.104 Table 5.4.3.3-1.

The list is narrower than "every raster point inside the band" for a practical reason: the SSB has to fit inside a carrier, and the carrier has to fit inside the band. A raster point 1 MHz from the band edge is arithmetically fine and physically useless, because no legal carrier of the band's minimum bandwidth could contain an SSB there. So the ends get trimmed.

Figure 3. Candidate counts for six representative bands. At roughly 100 ms of dwell per candidate this is 2.6 s of serial scan on n79 against 62 s on n77. n79's 26 points come from a GSCN step of 16 rather than 1 — the band was defined late enough that the search-time cost of a dense list was well understood, and a sparse one was agreed.
BandBand range (MHz)SSB SCSCaseGSCN first – step – lastPoints
n12110 – 217015 kHzA5279 – <1> – 5419141
n31805 – 188015 kHzA4517 – <1> – 4693177
n783300 – 380030 kHzC7711 – <1> – 8051341
n773300 – 420030 kHzC7711 – <1> – 8329619
n794400 – 500030 kHzC8480 – <16> – 888026
n25726500 – 29500120 kHzD22388 – <1> – 22558171

Table 7. Six bands from TS 38.104 Table 5.4.3.3-1. Bands that support two SSB subcarrier spacings appear twice in the real table, once per SCS, with different GSCN ranges — n41 is the usual example. Always read the entry for the SSB SCS the cell actually uses, and read it from the release your equipment implements: ranges have been extended as bands were widened.

🧮
Worked calculation

Checking a per-band GSCN range makes sense — n78, both ends.

n78 is 3300 – 3800 MHz. At 30 kHz the SSB is 7.2 MHz wide, so it occupies SS_REF ± 3.6 MHz.

Bottom of the list, GSCN 7711:

N = 7711 − 7499 = 212 → SS_REF = 3000 + 212 × 1.44 = 3305.28 MHz

Block spans 3301.68 – 3308.88 MHz. Inside the band, with 1.68 MHz to spare below.

Top of the list, GSCN 8051:

N = 8051 − 7499 = 552 → SS_REF = 3000 + 552 × 1.44 = 3794.88 MHz

Block spans 3791.28 – 3798.48 MHz. Inside the band, with 1.52 MHz to spare above.

Count: 8051 − 7711 + 1 = 341 candidate frequencies, each a full 1.44 MHz from the next.

The next raster point up, GSCN 8052 at 3796.32 MHz, would still fit its own 7.2 MHz block inside the band — but not a 10 MHz carrier around it, which is why the list stops where it does.

🔍
What you see in logs

In practice a UE almost never runs the full 341-point scan. It searches in priority order: frequencies stored from the last successful connection first, then frequencies supplied by a previous cell in redirectedCarrierInfo or in measurement configuration, then the band's full list. A log that shows a full band sweep is telling you the UE had nothing stored and nothing was suggested — which is itself worth noticing, because it usually means the previous release or reject carried no redirect. See the companion 01 Registration Process.

8. The SS/PBCH Block, Resource Element by Resource Element

The SSB is a fixed rectangle: four OFDM symbols by 240 contiguous subcarriers. 240 subcarriers is 20 resource blocks, so the block is 7.2 MHz wide at 30 kHz spacing, 3.6 MHz at 15 kHz, 28.8 MHz at 120 kHz. Nothing about that rectangle is configurable. It cannot be, because a UE has to be able to recognise it without having been told anything, and you cannot recognise a shape that varies.

Inside the rectangle, four things share the space: the primary synchronisation signal, the secondary synchronisation signal, the broadcast channel, and the broadcast channel's own reference signal. Their positions are given exactly in TS 38.211 cl. 7.4.3.1, Table 7.4.3.1-1, and the companion 02 Radio Frame Structure document has the same mapping at survey level. What follows adds the two things that survey does not: the guard regions dimensioned, and the reference-signal comb at resource-element resolution.

Figure 4. The exact mapping. Note that symbol 0 is almost entirely empty — 127 of its 240 subcarriers carry PSS and the other 113 are transmitted as zero. That is not waste; it is what keeps the PSS correlation clean, and 127 is 2⁷ − 1, the natural length of the m-sequence PSS is built from (§9).
Symbol lk = 0..47k = 48..55k = 56..182k = 183..191k = 192..239
0zerozeroPSS (127 sc)zerozero
1PBCH + DM-RSPBCH + DM-RSPBCH + DM-RSPBCH + DM-RSPBCH + DM-RS
2PBCH + DM-RSzero (8 sc guard)SSS (127 sc)zero (9 sc guard)PBCH + DM-RS
3PBCH + DM-RSPBCH + DM-RSPBCH + DM-RSPBCH + DM-RSPBCH + DM-RS

Table 8. TS 38.211 Table 7.4.3.1-1, laid out by subcarrier range. k is counted from the block's own lowest subcarrier, so k = 0 is not a carrier subcarrier index — converting between the two is what §17 is about.

8.1 The guard bands around SSS, and what they cost

The eight subcarriers below the SSS and the nine above it are transmitted as zero. They are there so that PBCH energy in the same symbol does not leak into the SSS correlation through the receiver's channel filter — the SSS is being detected at low signal-to-noise ratio and against 336 hypotheses, and adjacent-subcarrier interference from a signal 20 dB stronger would matter. The asymmetry, eight below and nine above, is simply because 240 − 127 = 113 is odd and the SSS is centred as nearly as it can be.

Those seventeen zeroed subcarriers, plus the requirement to leave the SSS's own 127 alone, are the reason PBCH gets 576 resource elements rather than the 720 that three full symbols would give:

🧮
Worked calculation

From resource elements to the PBCH code rate.

PBCH REs = 240 (symbol 1) + 96 (symbol 2) + 240 (symbol 3) = 576

Symbol 2's 96 = 48 below the guard + 48 above it

DM-RS = 576 / 4 = 144 REs (60 + 24 + 60)

Data REs = 576 − 144 = 432

QPSK, 2 bits per RE → 864 coded bits

Payload = 24 MIB bits + 8 bits added by the physical layer = 32

Plus a 24-bit CRC = 56 bits in, Polar-encoded, rate-matched to 864

Effective code rate ≈ 56 / 864 ≈ 0.065

That is an extraordinarily low code rate — roughly one useful bit per fifteen transmitted. It is deliberate. The MIB must decode at the cell edge, with no channel estimate beyond the block's own DM-RS, no HARQ, no retransmission request and no prior knowledge of anything. Spending fifteen-sixteenths of the channel on redundancy is the cheapest way to get that. The companion 35 Physical Channels document owns the PBCH coding chain in full.

8.2 Where the PBCH DM-RS actually sits

The PBCH's demodulation reference signal is not in a symbol of its own. It is interleaved with the PBCH data at a density of one resource element in four, on subcarriers k = 4n + ν where ν = N_ID^cell mod 4 TS 38.211 cl. 7.4.1.4. In words: the reference signal occupies every fourth subcarrier, and which of the four it occupies is decided by the cell identity.

Figure 5. One PRB of the block at resource-element resolution, drawn for PCI 431 so ν = 431 mod 4 = 3. The comb shift is what lets a UE separate two overlapping SSBs from different cells before it knows anything about either of them — two cells whose PCIs differ modulo 4 put their pilots on different subcarriers.
⚠️
Common pitfall

The comb shift is a four-way separation, not a 1008-way one. Two neighbours with PCI 431 and PCI 435 both have ν = 3 and put their PBCH DM-RS on exactly the same subcarriers. That is fine — the sequences differ — but it removes the frequency-domain separation and leaves only the sequence correlation to do the work. When a PCI plan is being designed, keeping first-tier neighbours distinct modulo 4 as well as modulo 3 costs nothing and buys measurable margin in SSB detection at cell overlap. See §20 on PCI confusion.

The DM-RS sequence itself is initialised from the cell identity and from the candidate SSB index, which is the mechanism by which a UE learns which beam it is looking at before it has decoded a single bit of the MIB. That is §12. The sequence generation is owned by the companion 33 DMRS document and is not repeated here.

9. PSS: Three Sequences, Found With No Timing At All

The primary synchronisation signal is the first thing the UE finds and the only thing it can find with no help. Everything about it is shaped by that. It has to be recognisable when the receiver does not know where a symbol starts, does not know the exact frequency, and has no channel estimate — so it cannot be a coded message, because there is nothing to demodulate against. It has to be a known waveform that the receiver slides along the incoming samples looking for a correlation peak.

An m-sequence — short for maximum-length sequence — is the standard choice for that job. It is a binary sequence generated by a shift register with feedback, and its defining property is that it correlates strongly with itself and weakly with a shifted copy of itself. In plain terms: slide it along a noisy recording and you get one sharp spike where it matches and near-nothing everywhere else. That spike is the symbol timing.

NR's PSS is a length-127 m-sequence, and the three PSS variants are three different cyclic shifts of the same sequence TS 38.211 cl. 7.4.2.2.1:

PSS generation, TS 38.211 cl. 7.4.2.2.1
d_PSS(n) = 1 - 2 x( m )        n = 0, 1, ... , 126

  m = ( n + 43 x N_ID_2 ) mod 127

  generator:  x(i+7) = ( x(i+4) + x(i) ) mod 2
  initial:    [x(6) x(5) x(4) x(3) x(2) x(1) x(0)] = [1 1 1 0 1 1 0]

  N_ID_2 in {0, 1, 2}   ->   cyclic shifts of 0, 43 and 86
  mapped to symbol l = 0, subcarriers k = 56 .. 182

In plain terms: one 127-symbol pattern exists, generated by that seven-stage shift register. The three PSS signals are that pattern read starting from position 0, position 43 and position 86. The mapping 1 − 2x turns the binary 0/1 into +1/−1, which is BPSK. And because 43 and 86 are roughly a third and two thirds of 127, the three shifts are spaced as far from each other as three shifts can be — so a receiver that finds a peak for one of them will not accidentally find a significant peak for another.

PropertyValueWhy it is that value
Sequence length1272⁷ − 1: the natural period of a 7-stage maximum-length shift register. Prime, which helps the cyclic-shift orthogonality
Number of variants3Each variant multiplies the blind-search correlation load. Three is enough to complete PCI arithmetic against SSS's 336 and cheap enough to search everywhere (§2)
ModulationBPSK (±1)Nothing to demodulate coherently, so no benefit from a denser constellation; BPSK maximises the correlation peak per unit energy
PositionSymbol 0, k = 56 to 182First symbol so that a detection immediately gives the block's start; centred in frequency so the 113 unused subcarriers act as guard on both sides
What it yieldsSymbol timing, coarse frequency offset, N_ID2Timing from the peak position; frequency offset from the peak's phase rotation across repetitions; N_ID2 from which of the three shifts peaked
What it does not yieldFrame timing, half-frame, cell identity, beamA PSS peak tells the UE where a block starts, not where a frame starts — those need SSS, the DM-RS and the PBCH payload

Table 9. PSS at a glance. The last row is the one people forget: after PSS the UE knows when a symbol begins but has no idea what time it is.

💡
Key point

PSS also gives the UE its first frequency correction, and that matters more than it sounds. A UE's crystal oscillator can be off by several parts per million at power-on before it has anything to lock to; at 3.5 GHz, 2 ppm is 7 kHz, which is a quarter of a 30 kHz subcarrier. Detecting PSS across two or more occasions gives a phase rotation from which that offset is estimated and corrected, and only then is the receiver accurate enough for the SSS's 336-way correlation to be reliable. This is precisely why a UE can report "PSS found, SSS failing" — see §20.

10. SSS, and the Cell Identity Completed

By the time the UE looks for the secondary synchronisation signal, it already knows where a symbol boundary is and roughly what the frequency error is. That changes the problem completely. It no longer has to slide a template along an unknown number of sample offsets; it knows exactly which resource elements to look at, because SSS sits in symbol 2 of the same block, on the same 127 subcarriers as PSS. All it has to do is work out which of the possible sequences arrived. That is one correlation window against 336 candidates, which is cheap, and it is why SSS is allowed to carry far more information than PSS.

SSS is built from two different m-sequences multiplied together — a construction called a Gold sequence, which yields many more distinguishable members than a single m-sequence of the same length could TS 38.211 cl. 7.4.2.3.1:

SSS generation, TS 38.211 cl. 7.4.2.3.1
d_SSS(n) = [ 1 - 2 x0( (n + m0) mod 127 ) ]
         x [ 1 - 2 x1( (n + m1) mod 127 ) ]      n = 0 .. 126

  m0 = 15 x FLOOR( N_ID_1 / 112 )  +  5 x N_ID_2
  m1 = N_ID_1 mod 112

  x0(i+7) = ( x0(i+4) + x0(i) ) mod 2
  x1(i+7) = ( x1(i+1) + x1(i) ) mod 2
  both initialised to [x(6)..x(0)] = [0 0 0 0 0 0 1]

  N_ID_1 in 0 .. 335   ->   3 values of FLOOR(N_ID_1/112) x 112 of (N_ID_1 mod 112) = 336
  mapped to symbol l = 2, subcarriers k = 56 .. 182

In plain terms: two shift registers with different feedback taps produce two 127-length patterns; the SSS is the element-by-element product of those two patterns, each started at its own offset. The pair of offsets (m0, m1) is what encodes the identity. m1 takes 112 values and the coarse part of m0 takes 3, giving 3 × 112 = 336 distinguishable sequences. Note that m0 also depends on N_ID2 — the SSS sequence is not independent of the PSS, which is a small but real detail: a receiver has to know N_ID2 before it can search SSS efficiently, reinforcing the ordering.

Figure 6. The identity arriving in two pieces. The split is not a design flourish — it follows from the fact that PSS is searched at every candidate frequency and every timing offset, while SSS is searched once, at a known place. Information is put where it is cheap to carry.

10.1 Putting the two halves together

The physical cell identity — PCI, the number every log, every measurement report and every neighbour relation uses to name a cell — is simply the two halves combined TS 38.211 cl. 7.4.2.1:

Physical cell identity, TS 38.211 cl. 7.4.2.1
N_ID_cell  =  3 x N_ID_1  +  N_ID_2

  N_ID_1  from SSS,  0 .. 335
  N_ID_2  from PSS,  0 .. 2

  ->  N_ID_cell = 0 .. 1007      1008 identities in total

and in reverse:
  N_ID_2 = N_ID_cell mod 3
  N_ID_1 = FLOOR( N_ID_cell / 3 )

In plain terms, PCI is a two-digit number in a mixed base: the SSS supplies the high digit in base 336 and the PSS supplies the low digit in base 3. Multiplying the SSS half by three and adding the PSS half is exactly how you reassemble it, and dividing by three with remainder is exactly how you take it apart.

🧮
Worked calculation

PCI derivation, both directions, with real numbers.

Forward — the network's view. A planner allocates N_ID1 = 143 and N_ID2 = 2.

PCI = 3 × 143 + 2 = 429 + 2 = 431

So this cell transmits PSS shift 43 × 2 = 86, and the SSS with

m0 = 15 × FLOOR(143/112) + 5 × 2 = 15 × 1 + 10 = 25

m1 = 143 mod 112 = 31

And its PBCH DM-RS comb sits on ν = 431 mod 4 = 3 (§8.2).

Reverse — the UE's view. A log reports PCI 431.

N_ID2 = 431 mod 3 = 2 (429 = 3 × 143, remainder 2)

N_ID1 = FLOOR(431 / 3) = 143

Cross-check: 3 × 143 + 2 = 431. ✓

A second case, for the m0 branch. N_ID1 = 289, N_ID2 = 1.

PCI = 3 × 289 + 1 = 868

FLOOR(289/112) = 2, so m0 = 15 × 2 + 5 × 1 = 35

m1 = 289 mod 112 = 289 − 224 = 65

ν = 868 mod 4 = 0

Being able to run this in your head is genuinely useful when reading a PCI plan: PCIs that share a value modulo 3 share a PSS, and a cluster of neighbours all congruent to the same value modulo 3 is a plan that has thrown away the PSS diversity it was given for free.

PSSSSS
Symbol02
Subcarriersk = 56 to 182 (127)k = 56 to 182 (127)
ConstructionOne m-sequence, three cyclic shiftsProduct of two m-sequences (a Gold sequence), 336 offset pairs
Information carriedlog₂ 3 ≈ 1.58 bitslog₂ 336 ≈ 8.39 bits
SearchedBlind: every candidate frequency × every timing offset × 3Once: known frequency, known symbol, × 336
Detection depends onNothing priorPSS having succeeded — both for the timing and because m0 contains N_ID2
What it yieldsSymbol timing, coarse frequency, N_ID2N_ID1, and therefore the complete PCI

Table 10. PSS and SSS compared. The information rows explain the design: 1.58 bits where searching is expensive, 8.39 bits where it is not. Ten bits of identity in total, which is 1024 — of which 1008 are used, because 336 × 3 does not reach 1024.

📘
Spec detail

Why 1008 and not 1024? Because the number falls out of the construction rather than being chosen: 336 SSS sequences × 3 PSS sequences = 1008. The 336 in turn is 3 × 112, and 112 is the number of usable m1 offsets given the length-127 sequences and the need to keep m0's three branches from colliding. Nobody sat down and decided a network needed exactly 1008 cell identities; the number is what the sequence design produced, and it turned out to be plenty.

11. The Search Procedure, Step by Step

With the pieces described, the procedure itself is short to state. The UE works down a list of candidate frequencies, and at each one it listens for the one thing it can recognise blind. When it finds it, it stops scanning and starts a fixed sequence of steps, each of which resolves one more unknown, until it has the MIB and can go and fetch SIB1. If any step fails it either retries with more accumulation or goes back to scanning.

Figure 7. The whole procedure. The important structural fact is the shape: one expensive loop at the top, repeated once per GSCN candidate, and then a short linear chain. Optimising the chain buys milliseconds; shortening the loop buys seconds.
  1. Build the candidate list. The UE takes the bands it supports, and for each one the GSCN range from TS 38.104 cl. 5.4.3.3. It orders the list: stored frequencies from the last successful connection first, then anything a previous cell suggested, then the full per-band lists. For a cold start on n78 that is up to 341 entries (§7).
  2. Tune, and correlate for PSS. At each candidate the receiver runs three correlations — one per N_ID2 — across a window long enough to cover the assumed 20 ms periodicity. A peak above threshold gives symbol timing, a coarse frequency correction, and N_ID2. No peak, and the UE moves to the next candidate. This loop is where the seconds go.
  3. Correlate for SSS. Symbol 2 of the detected block, same 127 subcarriers, 336 hypotheses. Success gives N_ID1 and therefore the complete PCI = 3 × N_ID1 + N_ID2. From this moment the UE can descramble things, because almost every scrambling sequence in the cell is initialised from the PCI.
  4. Correlate the PBCH DM-RS. The reference-signal sequence is a function of the candidate SSB index, so testing the hypotheses identifies which beam this is — and, when L_max = 4, the half-frame as well (§12). The UE needs this before demodulating PBCH anyway, so the beam identity is free.
  5. Decode PBCH. Polar decoding of 864 coded bits down to 56, CRC checked. Success yields the MIB: six SFN bits, subCarrierSpacingCommon, ssb-SubcarrierOffset, dmrs-TypeA-Position, pdcch-ConfigSIB1, cellBarred, intraFreqReselection. Failure means combining the next burst set and trying again.
  6. Assemble the full system frame number. Six bits from the MIB, four more from the PBCH payload, one half-frame bit, and two bits recovered from which scrambling hypothesis worked. Only now does the UE know what time it is (§13).
  7. Check cellBarred. If the MIB says barred, the UE stops here, bars the cell, and — depending on intraFreqReselection — either looks at other frequencies only or is allowed to try intra-frequency neighbours. This check happens before any attempt at SIB1, which is the point of putting it in the MIB.
  8. Find CORESET#0 and read SIB1. pdcch-ConfigSIB1 plus k_SSB indexes a table that gives the CORESET#0 bandwidth, duration, offset and monitoring pattern; the UE then monitors Type0-PDCCH for a DCI with SI-RNTI and decodes SIB1 from the scheduled PDSCH. All of that arithmetic belongs to the companion 18 MIB and SIB1 IEs document and is not repeated here.
🔍
What you see in logs

Steps 2 and 3 are often described as "the UE decodes PSS and SSS". It does not decode them — there is nothing to decode. It correlates against a finite set of known waveforms and picks the winner. The practical difference shows up in the failure signatures: a decode fails with a CRC error, whereas a correlation fails by returning a peak that is not convincingly above the noise floor. That is why PSS and SSS problems in logs appear as detection metrics and thresholds rather than as error codes, and why they degrade gradually with SNR rather than falling off a cliff.

StepUnknowns resolvedTypical costWhat a failure here looks like
Raster scanWhich frequencyTens of ms per candidate; the whole list in the worst caseNo cell found; UE reports out of service or keeps scanning
PSSSymbol timing, coarse frequency, N_ID21 – 5 SSB periodsNothing. The candidate is silently abandoned
SSSN_ID1, so the full PCIOne occasionPSS detected but no PCI — points at residual frequency error or interference in symbol 2
PBCH DM-RSSSB index; half-frame when L_max = 4Free, folded into demodulationPBCH will not demodulate; looks like a PBCH failure, not a DM-RS one
PBCH decodeThe MIBOne occasion, or up to 4 combinedMIB CRC failure — the clearest single indicator in a cell search log
SFN assemblyFrame number, half-frameUp to one 80 ms PBCH periodHalf-frame or SFN ambiguity; scheduled receptions land 5 ms or 10 ms out
cellBarred checkWhether this cell is usable at allFreeNot a failure — a correct rejection. Frequently misread as one
CORESET#0 and SIB1The cell's common configurationTens of msMIB decoded but no SIB1: usually k_SSB signalling no CORESET#0, or CORESET#0 falling outside the carrier

Table 11. The same eight steps as a diagnostic table. Reading a cell search log means first establishing which of these rows you are in, because the fixes are entirely different.

12. The SSB Index: What the DM-RS Says Before the MIB Does

A cell does not transmit one SSB. It transmits several, in quick succession, each pointed in a different direction — this is the beam sweep, and §14 covers it properly. For now the point is that the UE has to know which of them it received, because the answer determines which PRACH occasion it should answer on and which beam the cell will use to reply. That number is the SSB index, and the UE needs it before it has decoded anything.

The mechanism is elegant and worth understanding, because it explains a log line that otherwise looks impossible: an analyser reporting an SSB index next to a MIB that contains no such field. The index is not in the MIB. It is carried by the initialisation of the PBCH DM-RS sequence TS 38.211 cl. 7.4.1.4.1. The UE has to correlate against that sequence in order to demodulate PBCH at all; making the sequence a function of the index means that same correlation also reveals which beam this is, at zero additional resource cost.

PBCH DM-RS initialisation, TS 38.211 cl. 7.4.1.4.1
c_init = 2^11 x ( i_SSB + 1 ) x ( FLOOR( N_ID_cell / 4 ) + 1 )
       + 2^6  x ( i_SSB + 1 )
       + ( N_ID_cell mod 4 )

  L_max = 4        i_SSB = ( SSB index mod 4 ) + 4 x n_hf
  L_max = 8 or 64  i_SSB = SSB index mod 8

  n_hf = half-frame number, 0 or 1

-- The UE tests each i_SSB hypothesis; the one that yields a good PBCH
-- decode is the answer. For L_max = 64 the three most significant bits
-- of the index come from the PBCH payload instead.

Read the two L_max cases carefully, because they are different in kind. Where L_max is 4 there are only four candidate positions, so two bits of index are enough — and the spare capacity in i_SSB is spent carrying the half-frame bit as well, folded in as the +4 × n_hf term. Where L_max is 8, all three bits go to the index and the half-frame has to come from the PBCH payload. Where L_max is 64, the DM-RS carries the three least significant bits and the payload carries the three most significant.

L_maxWhere it appliesIndex bits from DM-RSIndex bits from PBCH payloadHalf-frame from
4FR1 below 3 GHz2 (index mod 4)noneThe DM-RS as well, via +4 × n_hf
8FR1, 3 to 7.125 GHz3 (index mod 8)noneA dedicated bit in the PBCH payload
64FR23 (index mod 8)3 (the MSBs)A dedicated bit in the PBCH payload

Table 12. Three different arrangements for the same information, chosen per frequency range so that no bits are wasted. This is why an analyser that reports an SSB index for an FR2 cell has done strictly more work than one reporting it for FR1 — it had to decode the payload as well as correlate the pilot.

⚠️
Common pitfall

The half-frame at L_max = 4 is the case that catches people. Below 3 GHz there is no half-frame bit to read in the payload in the usual place — it is inside the DM-RS hypothesis. A UE that gets the i_SSB hypothesis right but interprets it as a pure index, ignoring the +4, ends up with the correct beam and the wrong half of the frame: every subsequent scheduled reception is 5 ms out. In a log this shows as a UE that acquires the cell, decodes the MIB, and then misses its first paging occasion or PRACH occasion by exactly 5 ms.

The consequence for beam management is that the SSB index is available before the MIB, which is what makes the SSB-to-PRACH-occasion association work during initial access — the UE has to know which beam it chose in order to pick the right occasion, and it needs that at random-access time, not after SIB1. See the companion 03 Random Access document for the association itself, and 33 DMRS for the sequence generation.

13. The Half-Frame Bit, and Why the SFN Arrives in Three Pieces

Knowing what time it is turns out to be surprisingly awkward. The system frame number — SFN — is the 10-bit counter that names each 10 ms radio frame, cycling every 1024 frames or 10.24 seconds. Every periodic thing in the cell is defined against it: paging occasions, system information windows, PRACH occasions, measurement gaps. A UE that does not know the SFN cannot receive anything scheduled, so the SFN has to be part of what cell search delivers.

The awkwardness is that the SFN is not sent as a 10-bit field. It arrives in three pieces, from three different places, and there is a reason for each split:

PieceBitsWhere it comes fromWhy it is there and not elsewhere
SFN most significant bits6systemFrameNumber in the MIB itselfThese change slowly — once every 160 ms — so they can live in the coded payload without forcing a re-encode every frame
SFN least significant bits4Added to the PBCH payload by the physical layer, outside the MIBThese change every frame. Keeping them out of the MIB means four consecutive frames can share one encoded MIB and differ only in the added bits
Two of those 4 LSBs, again(2)Recovered from which scrambling hypothesis decoded successfullySee below — the PBCH scrambling phase depends on them, so they cannot be read from the payload before they are known
Half-frame, n_hf1PBCH payload, except at L_max = 4 where it is folded into the DM-RS hypothesis (§12)5 ms resolution is needed because an SSB burst set occupies one half of a frame, and the UE must know which half

Table 13. The SFN in pieces. The third row is the one that costs time: it is why acquisition takes up to 80 ms after the first PBCH occasion rather than one occasion.

13.1 The scrambling trick, and the 80 ms it costs

Here is the circularity that the third row resolves. The PBCH payload is scrambled before encoding, and the scrambling sequence's starting position depends on the low bits of the SFN TS 38.212 cl. 7.1.1, 7.1.2. That means the same MIB content produces four different transmitted waveforms across an 80 ms period — one per 20 ms burst set. A UE that does not know those bits cannot descramble; so it tries all four hypotheses, and the hypothesis that decodes successfully is itself the answer. The bits that select the scrambling are therefore excluded from the scrambling, which would otherwise be impossible to unwind.

In plain terms: two bits of timing are communicated not by transmitting them but by which version of the transmission you are looking at. It costs nothing in resource elements, and it costs up to 80 ms in acquisition latency, because in the worst case the UE has to observe four burst sets to find the one whose hypothesis fits.

🧮
Worked calculation

Assembling an SFN from a real set of pieces.

MIB systemFrameNumber = 0b101101 (6 bits, SFN[9:4])

PBCH payload SFN LSBs = 0b0011 (4 bits, SFN[3:0])

Half-frame bit n_hf = 1

SFN = 0b1011010011 = 723

check: 0b101101 = 45, so SFN = 45 × 16 + 3 = 720 + 3 = 723 ✓

n_hf = 1 → this burst set is in the second 5 ms of frame 723,

i.e. subframes 5 to 9, so the block began at 723 × 10 ms + 5 ms = 7235 ms into the SFN cycle.

Note that the two bits recovered from the scrambling hypothesis are part of the four payload LSBs — they are not extra bits. The four LSBs are 0b0011; two of them (SFN[3:2] = 0b00) are what the scrambling hypothesis told the UE, and the other two arrive in the payload proper. Getting this wrong by treating them as separate is a common source of off-by-four SFN errors in hand analysis.

📘
Spec detail

The MIB is transmitted with a 80 ms period of unchanging content — the same 24 bits repeat, and the network may only change them on an 80 ms boundary. That is why a UE can safely combine energy across four burst sets, and it is also why a MIB content change takes effect no faster than 80 ms. A cell that flaps cellBarred faster than that is producing behaviour no UE is specified to follow.

14. SSB Burst Sets: Cases A Through E

A cell that transmits one SSB in one direction can only be found by UEs in that direction. Above a couple of gigahertz that is a real problem, because coverage at those frequencies depends on beamforming — energy concentrated into a narrow direction — and a broadcast signal cannot be beamformed to everyone at once. The answer is to send the same block several times in quick succession, each time pointed somewhere else, and sweep across the cell. That set of transmissions is a burst set, and its purpose is simply that a UE anywhere in the cell hears at least one of them.

So a burst set is a beam sweep. Each transmission within it is at a different candidate position — a specific first-symbol index within the half-frame at which an SSB is permitted to start — and each candidate position carries a different beam. The whole set is confined to one 5 ms half-frame, never straddling the boundary, which is why the half-frame bit of §13 exists.

QuantityMeaning in ordinary wordsValues
Candidate positionA permitted starting symbol for an SSB inside the half-frame. Fixed by the specification, not configurableGiven by the Case, below
L_maxHow many candidate positions exist in the half-frame for this frequency range — the ceiling on how many beams a cell may sweep4 below 3 GHz, 8 from 3 to 7.125 GHz, 64 above 6 GHz
SSB indexWhich candidate position a particular block occupied. What a UE reports when it says which beam it found0 to L_max − 1
ssb-PositionsInBurstA bitmap saying which of the candidate positions the cell actually uses. A 4-beam cell in an L_max = 8 range sets four bits (§15)4, 8 or 64 bits
Burst set periodicityHow often the whole sweep repeats5 to 160 ms (§16)

Table 14. The five quantities that describe a burst set. Confusing L_max with the number of transmitted SSBs is the most frequent error, and ssb-PositionsInBurst is the field that separates them.

14.1 The five cases

Which candidate positions exist depends on the SSB subcarrier spacing and the frequency range, and the specification names the five resulting patterns Case A through Case E TS 38.213 cl. 4.1. Each is expressed as a set of first symbols plus a repeat offset — the notation {2, 8} + 14n means "symbols 2 and 8, and then symbols 2 and 8 of every subsequent slot, for the listed values of n".

CaseSSB SCSFirst symbolsn valuesL_maxWhere it applies
A15 kHz{2, 8} + 14n0, 1 (≤ 3 GHz)
0, 1, 2, 3 (3 – 7.125 GHz)
4
8
FR1 low bands with 15 kHz SSB — n1, n3, n28
B30 kHz{4, 8, 16, 20} + 28n0 (≤ 3 GHz)
0, 1 (3 – 7.125 GHz)
4
8
FR1 bands with 30 kHz SSB packed two candidates per slot
C30 kHz{2, 8} + 14n0, 1 (≤ 3 GHz paired, ≤ 2.4 GHz unpaired)
0, 1, 2, 3 (above that, to 7.125 GHz)
4
8
The common FR1 mid-band case — n41, n77, n78, n79
D120 kHz{4, 8, 16, 20} + 28n0–3, 5–8, 10–13, 15–18 (16 values)64FR2 above 6 GHz — n257, n258, n260, n261
E240 kHz{8, 12, 16, 20, 32, 36, 40, 44} + 56n0–3, 5–8 (8 values)64FR2 above 6 GHz where 240 kHz SSB is supported

Table 15. The five candidate-position patterns. Which case a band uses is fixed per band in TS 38.104 cl. 5.4.3.3 — it is not an operator choice, and it follows from the SSB subcarrier spacing the band's table entry specifies. Note there is no 60 kHz case: SSB is never 60 kHz.

Figure 8. Cases A, B and C for L_max = 8, all three plotted against one common time axis so the durations can be compared directly. Case A takes twice as long as Case C to sweep the same eight beams, purely because its symbols are twice as long — the same pattern on a slower numerology.
🧮
Worked calculation

Case C candidate symbol positions, worked for L_max = 8.

Pattern is {2, 8} + 14n with n = 0, 1, 2, 3. Substituting each n in turn gives symbols 2 and 8, then 16 and 22, then 30 and 36, then 44 and 50:

Candidate first symbols = 2, 8, 16, 22, 30, 36, 44, 50

At 30 kHz a slot is 0.5 ms and holds 14 symbols, so symbol s falls in slot FLOOR(s/14) at symbol s mod 14:

SSB 0 → symbol 2 → slot 0, symbol 2

SSB 1 → symbol 8 → slot 0, symbol 8

SSB 2 → symbol 16 → slot 1, symbol 2

SSB 3 → symbol 22 → slot 1, symbol 8

SSB 4 → symbol 30 → slot 2, symbol 2

SSB 5 → symbol 36 → slot 2, symbol 8

SSB 6 → symbol 44 → slot 3, symbol 2

SSB 7 → symbol 50 → slot 3, symbol 8

So the whole sweep lives in slots 0 to 3 of the half-frame and slots 4 to 9 hold no candidates at all. In time, SSB 0 starts at 2/14 × 0.5 ms = 71 µs and SSB 7 ends at (50 + 4)/14 × 0.5 ms = 1.93 ms — the sweep occupies under 40 % of the half-frame, leaving the rest for data. Symbols 0–1 and 12–13 of each SSB slot stay clear, which is where CORESET#0 goes.

Figure 9. All 64 Case D candidate positions in an FR2 half-frame. The empty slot pairs come from the skipped n values — 4, 9, 14 and 19 are absent from the pattern, which leaves every fifth slot pair free for the TDD downlink-to-uplink switch and for control.
🧮
Worked calculation

Case D candidate symbol positions, worked at both ends.

Pattern is {4, 8, 16, 20} + 28n over 16 values of n, giving 4 × 16 = 64 candidates. At 120 kHz a slot is 0.125 ms.

First candidate. n = 0, base 4 → symbol 4.

Slot = FLOOR(4/14) = 0, symbol 4 → starts at 4/14 × 0.125 ms = 36 µs

Last candidate. n = 18, base 20 → symbol 28 × 18 + 20 = 524.

Slot = FLOOR(524/14) = 37, symbol 524 − 518 = 6

Starts at 37 × 0.125 + 6/14 × 0.125 = 4.625 + 0.054 = 4.679 ms

Ends 4 symbols later at 4.714 ms — just inside the 5 ms half-frame.

Why n skips 4, 9, 14, 19. Each n consumes 28 symbols = 2 slots. n = 4 would occupy symbols 112 to 132, i.e. slots 8 and 9. Skipping it leaves slots 8–9, 18–19, 28–29 and 38–39 free. Compare with FR1's Case C, where the whole sweep finished at 1.93 ms: on FR2 a full 64-beam sweep uses 94 % of the half-frame. There is no slack, which is why the skipped slots had to be engineered in rather than left over.

⚠️
Common pitfall

L_max = 64 does not mean an FR2 cell transmits 64 SSBs. It means it may. A typical FR2 sector transmits somewhere between 8 and 32, chosen against its antenna array and its coverage target, and signals which ones in ssb-PositionsInBurst. Reading L_max off the frequency range and assuming 64 transmissions will make every overhead calculation for that cell wrong by a factor of two to eight.

15. ssb-PositionsInBurst: What Is Actually Transmitted

The candidate positions of §14 are what the specification permits. What a particular cell actually sends is a subset, and the cell announces that subset as a bitmap: one bit per candidate position, set if that position carries an SSB. The field is called ssb-PositionsInBurst and it is the single most useful field for reconciling "how many beams does this cell have" with what a UE reports.

Figure 10. The three encodings. The L_max = 64 form in SIB1 is the interesting one: rather than a 64-bit string it is two 8-bit strings multiplied together, which encodes a regular beam layout in 16 bits instead of 64 — and cannot encode an irregular one at all.
EncodingWhereSizeMeaning
shortBitmapServingCellConfigCommon, L_max = 44 bitsOne bit per candidate position, MSB first = candidate 0
mediumBitmapServingCellConfigCommon, L_max = 88 bitsAs above, eight positions
longBitmapServingCellConfigCommon, L_max = 6464 bitsOne bit per candidate position. Used in dedicated signalling, where 64 bits is affordable
groupPresence + inOneGroupServingCellConfigCommonSIB, L_max = 648 + 8 bitsThe 64 positions are treated as 8 groups of 8. groupPresence says which groups exist; inOneGroup says which positions within every present group. Total transmitted = (bits set in groupPresence) × (bits set in inOneGroup)

Table 16. ssb-PositionsInBurst encodings, TS 38.331. The SIB1 form for L_max = 64 exists to save broadcast bits and imposes a real constraint in exchange: the pattern within each group must be the same for every group.

🧮
Worked calculation

Decoding the group form.

groupPresence = 1100 0001 → groups 0, 1 and 7 exist (3 groups)

inOneGroup = 1111 0000 → positions 0–3 within each (4 positions)

Transmitted SSBs = 3 × 4 = 12

Their indices: group g contributes 8g + p for each set p, so

group 0 → 0, 1, 2, 3

group 1 → 8, 9, 10, 11

group 7 → 56, 57, 58, 59

Encoded in 16 bits rather than 64.

And here is the constraint this buys: there is no way to express "positions 0–3 of group 0 and positions 4–7 of group 1" in SIB1. inOneGroup applies to every present group identically. A cell whose physical beam layout needs an irregular pattern must either regularise it or transmit SSBs it does not need.

🔍
What you see in logs

The bitmap is the answer to "the UE reports fewer beams than this cell is supposed to have". Check ssb-PositionsInBurst before checking anything about the antenna. A cell provisioned for eight beams but broadcasting mediumBitmap = 1101 0000 is transmitting three, and every UE will correctly report three. It is also the field that governs measurement: a UE only measures the positions the bitmap declares, so a beam transmitted at a position the bitmap says is empty is invisible to measurement even though it is on the air (§20).

One further use of the bitmap is worth knowing. Positions the bitmap declares as not carrying an SSB are still not freely usable for PDSCH in the general case — the UE's rate-matching around the SSB is driven by the declared positions, and a scheduler that puts PDSCH where the UE believes an SSB might be gets a decode failure that looks like a coverage problem. The companion 35 Physical Channels document owns the rate-matching rules.

16. SSB Periodicity and the 20 ms Assumption

The burst set repeats. How often is configurable, and the trade is simple to state: transmitting the sweep more often makes cells easier and quicker to find, and costs downlink resource that could have carried data. Transmitting it less often saves that resource and makes every UE that is looking for the cell wait longer.

There is a complication that turns this from a smooth trade into a cliff edge. A UE performing initial cell selection has not read SIB1 yet — it cannot have, since SIB1 is what carries the configured periodicity — so it has no idea how often to expect the burst set. The specification resolves this by fiat: for the purposes of initial cell selection the UE may assume a 20 ms periodicity TS 38.213 cl. 4.1. That is not a convention; it is what a compliant UE is entitled to do.

ssb-periodicityServingCellOverhead relative to ms20Effect on a UE already connectedEffect on initial search
ms5Fastest measurement and beam tracking; most resource consumedNo benefit — the UE is already assuming 20 ms and cannot exploit the extra bursts it does not know about
ms10Fast measurementNo benefit, same reason
ms201× (reference)The usual choice. Matches the initial-search assumption exactlyOptimal. Every assumed occasion is a real occasion
ms400.5×Slower measurement; SMTC must be widened to matchHalves the hit rate. The UE looks every 20 ms and finds something every other time, so dwell has to double for the same confidence
ms800.25×Slower still; noticeable in handover measurement latencyQuarter hit rate. Initial search takes about 4× longer
ms1600.125×Minimum overhead; measurement latency is now the dominant mobility constraintEighth hit rate. Initial access becomes slow and highly variable

Table 17. ssb-periodicityServingCell, TS 38.331. The right-hand column is the one that gets forgotten during overhead optimisation, and it is asymmetric — going below 20 ms buys a connected UE something and buys a searching UE nothing, while going above 20 ms costs the searching UE directly.

⚠️
Common pitfall

Configuring ms40 or longer is entirely legal and saves real downlink resource. What it does not do is stay invisible. A UE arriving from RRC_IDLE searches on a 20 ms assumption; on an ms80 cell it finds a burst set on roughly one attempt in four, so its acquisition time quadruples and — because which attempt succeeds is essentially random — becomes highly variable. In aggregate KPIs that appears as slow, erratic initial access, which looks exactly like a coverage problem and is not one. If accessibility statistics degrade after an overhead optimisation exercise, check the SSB periodicity before checking anything else.

🧮
Worked calculation

What a longer periodicity costs, quantified.

Assume a UE needs to accumulate 5 burst sets to declare presence or absence at its detection threshold.

On ms20: 5 × 20 ms = 100 ms per candidate frequency

On ms40: the UE's 20 ms windows hit half the time, so it needs 10 windows = 5 × 40 ms = 200 ms

On ms80: 5 × 80 ms = 400 ms

On ms160: 5 × 160 ms = 800 ms

Across n78's 341 candidates in a serial scan:

ms20 → 34 s

ms40 → 68 s

ms80 → 136 s

ms160 → 273 s

Those are worst-case serial numbers and a real UE is much faster, but the ratios hold regardless of receiver cleverness: ms160 is eight times the search cost of ms20, for a 12.5 % overhead saving on the SSB. Treat the absolute figures as illustrative.

17. Where the SSB Sits Relative to the Carrier: k_SSB and offsetToPointA

This is where hand analysis goes wrong most often, so it is worth being slow about it. The problem is that the SSB and the carrier are placed by two different rules. The SSB has to sit on the synchronisation raster, whose steps are 1.2 or 1.44 or 17.28 MHz. The carrier has to sit on the channel raster, whose steps are 15 or 30 or 100 kHz. There is no reason for those two to coincide, and in general they do not — so the SSB is not at the centre of the carrier, and its subcarriers are not necessarily aligned with the carrier's resource block boundaries.

Two fields express that misalignment, and they express two different parts of it:

  • ssb-SubcarrierOffset, giving k_SSB. The fine offset: how far the SSB's lowest subcarrier sits above the lowest subcarrier of the resource block that contains it. It is a handful of subcarriers, and it is in the MIB — so the UE gets it immediately, from the block it just found.
  • offsetToPointA. The coarse offset: how many resource blocks lie between point A — the origin of the cell's common resource block grid, the reference against which every resource block in the cell is numbered — and the bottom of that containing resource block. It is in SIB1, because it is not needed until the UE wants to address resources.

Put together, they let a UE work downward from the only frequency it actually knows — the SSB's, because it found it at a known GSCN — to point A, and from there address every resource block in the cell. The companion 02 Radio Frame Structure document owns point A and the common resource block grid; this section owns the chain from the SSB to it.

Figure 11. The two offsets against the resource block grid, drawn for the worked example below. The detail that catches people is at the top and bottom of the green block: with a non-zero k_SSB the SSB straddles 21 resource blocks, not 20, occupying part of the one at each end.
FieldWhereRangeUnitsWhat it measures
ssb-SubcarrierOffsetMIB, 4 bits, plus 1 bit from the PBCH payload in FR10 – 23 in FR1 (5 bits); 0 – 11 in FR2 (4 bits)15 kHz subcarriers in FR1; subcarriers of subCarrierSpacingCommon in FR2SSB lowest subcarrier above the containing CRB's lowest subcarrier
offsetToPointAFrequencyInfoDL / FrequencyInfoDL-SIB in SIB10 – 2199Resource blocks of 15 kHz in FR1, 60 kHz in FR2Point A up to the lowest subcarrier of the lowest CRB that overlaps the SSB used for initial cell selection
offsetToCarrierSCS-SpecificCarrier0 – 2199Resource blocks of the carrier's own SCSPoint A up to the start of this particular carrier — a separate offset, often confused with the one above

Table 18. The three offsets that position things relative to point A. Note that offsetToPointA is anchored to the SSB, whereas offsetToCarrier is anchored to the carrier — they answer different questions and are not interchangeable.

🧮
Worked calculation

The full chain: GSCN to point A to carrier centre. Band n78, 30 kHz, 100 MHz carrier, subCarrierSpacingCommon = 30 kHz.

1. GSCN to SSB centre.

GSCN 7883 → N = 384 → SS_REF = 3000 + 384 × 1.44 = 3552.96 MHz

2. SSB centre to SSB lowest subcarrier.

240 subcarriers × 30 kHz = 7.2 MHz wide, so half is 3.6 MHz

Lowest SSB subcarrier = 3552.96 − 3.6 = 3549.36 MHz

3. Apply k_SSB to find the containing CRB.

ssb-SubcarrierOffset = 8, so k_SSB = 8 × 15 kHz = 120 kHz

Bottom of that CRB = 3549.36 − 0.12 = 3549.24 MHz

(120 kHz is 4 subcarriers at 30 kHz, so the SSB starts 4 subcarriers up into the CRB, and therefore ends 4 subcarriers up into the CRB above the 20th — 21 CRBs touched.)

4. Apply offsetToPointA.

offsetToPointA = 84, in 15 kHz PRBs → 84 × 180 kHz = 15.12 MHz

Point A = 3549.24 − 15.12 = 3534.12 MHz

5. Carrier centre, as a check.

273 PRB at 30 kHz = 273 × 360 kHz = 98.28 MHz; offsetToCarrier = 0

Carrier spans 3534.12 to 3632.40 MHz, centre = 3583.26 MHz

As an NR-ARFCN: (3583.26 − 3000) / 0.015 = 38884 → N_REF = 638884 — the same value worked in §4.

The punchline. 3583.26 − 3552.96 = 30.30 MHz. The SSB sits over 30 MHz below the carrier centre, roughly 84 resource blocks in. Anyone assuming the SSB is at carrier centre is out by that much.

⚠️
Common pitfall

offsetToPointA is counted in 15 kHz resource blocks in FR1 regardless of what subCarrierSpacingCommon is. On a cell where the common spacing is 30 kHz, a 30 kHz CRB boundary is 360 kHz wide = two 15 kHz PRBs — so offsetToPointA must be even, or it points at a frequency that is not a 30 kHz CRB boundary at all. 84 is even, which is why the arithmetic above closes. An odd offsetToPointA on a 30 kHz cell is a configuration error, and its symptom is a UE that decodes the MIB, reads SIB1, and then addresses every resource block half a PRB out — which usually manifests as SIB1 decoding but nothing after it working.

The reason k_SSB is measured in 15 kHz units in FR1 even when the SSB is 30 kHz is the sub-3 GHz raster from §6.2. There, the raster's 1.2 MHz step and 50 kHz M-offsets are not whole numbers of resource blocks at any spacing, so the residual misalignment can be large and can be a non-integer number of 30 kHz subcarriers. Using 15 kHz as the unit, and spending five bits rather than four, covers it. Above 3 GHz the raster step is a whole number of PRBs and k_SSB is consequently almost always small — which is a useful sanity check: a large k_SSB on an n78 cell is worth a second look.

🔍
What you see in logs

A value of ssb-SubcarrierOffset outside the valid k_SSB range — above 23 in FR1 — is not corruption. It is the encoding that says this SSB has no associated CORESET#0, so there is no SIB1 to be found here and the UE must look elsewhere. Such SSBs exist to help measurement and synchronisation without advertising a servable cell. A cell search log showing repeated successful MIB decodes with no SIB1 attempt at all is usually reading exactly this, and it is correct behaviour. The companion 18 MIB and SIB1 IEs document owns the CORESET#0 lookup that this value gates.

18. From Search to Measurement: the SSB's Second Job

Everything so far has been about a UE that knows nothing. Once it is connected, the same SSB gets used again for a completely different purpose — measuring neighbours so that mobility decisions can be made — and it is worth being explicit that this is a much easier problem, because almost all of the unknowns are gone.

A connected UE measuring a neighbour has been told where to look. The serving cell supplies the neighbour frequency in measurement configuration, so there is no raster scan. It supplies a list of PCIs to expect, so the SSS search is narrowed or skipped. And it supplies a timing window — the SMTC, SSB Measurement Timing Configuration — that says when the neighbour's burst sets occur, so the UE does not have to keep its receiver open continuously.

Initial cell searchNeighbour measurement under an SMTC
FrequencyUnknown. Scan the band's GSCN listGiven in measObjectNR as an absolute frequency
TimingUnknown. Assume 20 ms periodicity and watchGiven: SMTC periodicity, offset and duration bound the window
IdentityUnknown. 3 PSS × 336 SSS hypothesesUsually narrowed by a neighbour PCI list; a blind PCI search is possible but exceptional
What is being extractedPCI, SSB index, MIB, then SIB1RSRP, RSRQ and SINR per SSB and per cell — no decoding at all in the normal case
Receiver duty cycleContinuous during the scanOpen only inside the SMTC window, typically 1 to 5 ms out of every 20 to 160
CostSecondsA few percent of receiver time
Failure looks likeNo cell found; out of serviceA neighbour that is on the air but never reported

Table 19. The same signal, two problems. Everything that makes initial search expensive is information the network can supply once a UE is connected — which is exactly what measurement configuration does.

The SMTC window is the mechanism that makes neighbour measurement affordable, and it has one property that generates a lot of field trouble: it has to actually align with the neighbour's burst sets. An SMTC whose periodicity or offset does not match the neighbour's SSB transmission means the UE opens its receiver at the wrong times and reports nothing, indistinguishable from the neighbour being absent. The companion 21 Measurement Gaps and SMTC document owns the window arithmetic, and 20 Measurements and Events owns what is done with the results.

💡
Key point

One asymmetry is worth carrying away. In initial search, an SSB periodicity longer than 20 ms costs the UE time but eventually works, because the UE keeps looking. In neighbour measurement, an SMTC that does not match costs the UE everything — it never sees the neighbour at all, however long it looks, because it is looking at the wrong instants. Initial search degrades; measurement fails silently. When a handover is not happening and the target is demonstrably on the air, the SMTC is the first thing to check.

19. Parameter and Range Reference

Everything that positions, shapes or schedules an SSB, in one place. Where a field is derived rather than signalled that is said explicitly, because the derived ones are the ones that cannot be fixed by changing a configuration value.

ParameterWhere it comes fromRangeTypicalEffect
GSCNDerived from the SSB frequency; per-band list in TS 38.104 Table 5.4.3.3-12 – 26639band dependentThe SSB's centre frequency. Outside the band's list, no UE will find the cell
NR-ARFCN (absoluteFrequencySSB)SIB1 / FrequencyInfoDL0 – 3279165band dependentThe SSB frequency expressed as an ARFCN, for signalling. Must correspond to a valid GSCN
absoluteFrequencyPointASIB1 / FrequencyInfoDL-SIB0 – 3279165band dependentPoint A as an ARFCN, the alternative to deriving it from offsetToPointA
ssb-SubcarrierOffset (k_SSB)MIB, 4 bits + 1 payload bit in FR10 – 15 as encoded; k_SSB 0 – 23 FR1, 0 – 11 FR20 – 12Fine frequency offset of the SSB from the CRB grid. Out-of-range means no CORESET#0
offsetToPointASIB1 / FrequencyInfoDL-SIB0 – 219940 – 200Coarse offset, in 15 kHz PRBs (FR1) from point A to the SSB's lowest CRB. Must be even when common SCS is 30 kHz
ssb-SubcarrierSpacingSIB1 / ServingCellConfigCommonSIBkHz15, kHz30, kHz120, kHz240kHz30 in FR1, kHz120 in FR2Selects the Case together with the band. There is no 60 kHz option
L_maxDerived from the frequency range4, 8 or 648 in FR1Ceiling on candidate positions, and the length of ssb-PositionsInBurst
ssb-PositionsInBurstSIB1 (group form at L_max = 64) or ServingCellConfigCommon4, 8, 64 bits, or 8 + 8matches the beam countWhich candidate positions carry an SSB. Governs both detection and measurement
ssb-periodicityServingCellSIB1 / ServingCellConfigCommonSIBms5, ms10, ms20, ms40, ms80, ms160ms20Burst set repetition. Initial search assumes ms20 regardless (§16)
Half-frame bit n_hfPBCH payload, or the DM-RS hypothesis at L_max = 40 or 10Which 5 ms half of the frame the burst set occupies. Not an RRC field
ss-PBCH-BlockPowerSIB1 / ServingCellConfigCommonSIB−60 – 50 dBm10 – 20 dBm per REThe transmit power the UE assumes per SSB resource element, used for pathloss estimation — not for detection
cellBarredMIBbarred, notBarrednotBarredChecked before any SIB1 attempt. barred stops acquisition dead
intraFreqReselectionMIBallowed, notAllowedallowedWhether a UE rejecting this cell may try intra-frequency neighbours or must change frequency
subCarrierSpacingCommonMIBscs15or60, scs30or120scs30or120 in FR1 mid-bandThe SCS of SIB1, initial BWP and paging — and the grid offsetToPointA is measured against
smtc periodicity / offset / durationmeasObjectNR in measurement configurationsf5 – sf160 / 0 – periodicity−1 / sf1 – sf5sf20 / — / sf5The neighbour measurement window (§18). Owned by companion 21

Table 20. The full parameter set. Typical values are what many vendors ship rather than anything specified; the ranges are normative.

20. Failure Modes and What Each One Means

Cell search fails in a small number of characteristic ways, and they are worth separating carefully because several of them look identical from the outside — "the UE does not attach" — and have entirely different causes and fixes. What follows is ordered roughly by how far into the procedure the failure occurs.

FailureWho detects itWhat the UE doesLog signature and what it points at
SSB transmitted at a GSCN outside the band's searched list. The cell is on the air and radiating fine, but at a frequency no compliant UE will tryNobody, on either side. The gNB sees no access attempts; the UE sees no cellNever finds the cell. Keeps scanning, then reports out of service or camps on another operatorA cell with normal transmit power and zero RACH attempts, ever. Cross-check the configured SSB frequency against TS 38.104 Table 5.4.3.3-1 for the band: compute N = (F − F_base) / step and confirm it is an integer inside the published first–step–last range
SSB on a valid GSCN but outside the carrier, so PDSCH and the SSB cannot both be addressedThe UE, after SIB1, when the arithmetic does not closeMIB decodes, SIB1 may decode, then nothing worksoffsetToPointA and absoluteFrequencySSB inconsistent with carrierBandwidth. Recompute the chain in §17 and check the SSB's 7.2 MHz falls inside the carrier's PRBs
PSS detected but SSS never succeeds. Usually residual frequency error: the 336-way correlation is far more sensitive to it than the 3-way oneThe UE, as a failed correlation with no error codeAbandons the candidate and continues scanningRepeated PSS detections at the same GSCN with no PCI reported. Points at UE oscillator error at cold start, large Doppler, or strong narrowband interference landing in symbol 2. Distinguishable from coverage by the fact that PSS did succeed
MIB CRC failure. PBCH does not decode despite PSS, SSS and DM-RS all succeedingThe UE, cleanly, from the 24-bit CRCCombines the next burst set and retries; abandons after severalPCI reported but no MIB. At the very low PBCH code rate this needs genuinely poor SNR, so it points at real coverage limitation, at a collision with another cell's SSB at the same position, or at PDSCH being scheduled over the SSB's resource elements
cellBarred set to barred.The UE, from the MIB, before any SIB1 attemptBars the cell for 300 s and reselects; if intraFreqReselection is notAllowed it will not even try intra-frequency neighboursMIB decoded, cellBarred barred, no SIB1 attempt. This is correct behaviour, not a fault — but a cell left barred after maintenance is a very common cause of a cell that looks healthy and carries no traffic
PCI collision. Two cells with the same PCI are both audible to one UENeither, directly. The UE sees one confused cellMeasurements average two cells; handover targets become ambiguous; descrambling of one is wrong for the otherTwo cells reporting one PCI in the same measurement report, or RSRP that does not fall off with distance. The tell is a PCI whose reported RSRP is inconsistent between adjacent samples
PCI confusion. Two different neighbours of one cell share a PCI, so a handover request is ambiguousThe serving gNB, when it tries to resolve a reported PCI to a targetNothing — the UE reported correctly. The network picks a target and may pick the wrong oneHandover failures concentrated on one reported PCI, with the target cell reporting no incoming attempt. Fixed by ANR / CGI reporting, not by anything in this document
k_SSB inconsistent with offsetToPointA. The fine and coarse offsets do not compose to the SSB's actual frequencyThe UE, silently, by addressing the wrong resource blocksDecodes MIB and SIB1, then fails on everything scheduledSIB1 read successfully and then nothing: no successful RACH, or RACH on the wrong PRBs. Recompute §17 step by step; check offsetToPointA parity against subCarrierSpacingCommon
ssb-PositionsInBurst disagrees with what is transmitted. Beams on the air at positions the bitmap says are empty, or the reverseNobody. Both sides believe themselves correctMeasures and reports only the declared positions. A real beam at an undeclared position is invisible; a declared position with nothing on it produces a persistent non-detectionUE reports fewer SSB indices than the cell is provisioned for, or a declared index that never appears in any report. Compare the bitmap against the antenna configuration before suspecting the antenna
SSB periodicity longer than the UE's assumption. ms40 or beyondNobody. Nothing is wrongTakes proportionally longer to find the cell, with high varianceSlow and erratic initial access; accessibility KPIs degrade after an overhead optimisation. §16 has the numbers
Half-frame ambiguity. The UE gets the index right and n_hf wrong, or vice versa, typically at L_max = 4 where the two are folded togetherEventually the UE, when scheduled receptions do not arriveEverything scheduled lands 5 ms out. May recover by re-acquiringA UE that acquires cleanly and then misses its first paging occasion or PRACH occasion by exactly 5 ms. At L_max = 4, check that the i_SSB = (index mod 4) + 4 × n_hf decomposition was done (§12)

Table 21. Eleven failure modes. The first, fifth and tenth rows are all cases where nothing is broken and no alarm fires — those are the expensive ones, because they are found by noticing an absence rather than by reading an error.

⚠️
Common pitfall

Three of these produce a cell that looks completely healthy from the network side: an SSB off the searched raster, cellBarred left set, and a ssb-PositionsInBurst mismatch. In all three the gNB transmits normally, reports no faults, and receives no access attempts. If a cell has good transmit power, no alarms and no traffic, work down those three before touching anything RF.

21. Configuration Reference (ASN.1)

The structures below are abridged from TS 38.331 — fields not relevant to SSB and cell search are elided with ... and that is marked. Field names and types are as specified; comments are added here.

21.1 MIB

MIB ::= SEQUENCE {
    systemFrameNumber            BIT STRING (SIZE (6)),
        -- SFN bits 9..4. The four LSBs are added by L1, not here
    subCarrierSpacingCommon      ENUMERATED {scs15or60, scs30or120},
        -- SCS of SIB1, the initial BWP, paging and Msg2/Msg4
    ssb-SubcarrierOffset         INTEGER (0..15),
        -- k_SSB, low 4 bits. FR1 takes a 5th bit from the PBCH
        -- payload; a resulting value above 23 (FR1) means there is
        -- no CORESET#0 associated with this SSB
    dmrs-TypeA-Position          ENUMERATED {pos2, pos3},
    pdcch-ConfigSIB1             PDCCH-ConfigSIB1,
        -- 8 bits: controlResourceSetZero + searchSpaceZero.
        -- Decoded in the companion 18 MIB and SIB1 IEs document
    cellBarred                   ENUMERATED {barred, notBarred},
    intraFreqReselection         ENUMERATED {allowed, notAllowed},
    spare                        BIT STRING (SIZE (1))
}
-- 24 bits exactly. The physical layer adds 8 more before encoding:
--   4 x SFN LSB,  1 x half-frame,  and 3 whose use depends on L_max
--   (SSB index MSBs at L_max = 64; k_SSB MSB + reserved otherwise)

Listing 1. The MIB, complete — it is small enough not to need abridging. The companion 18 MIB and SIB1 IEs document decodes every field; here only ssb-SubcarrierOffset and cellBarred are in scope.

21.2 The SSB fields of ServingCellConfigCommon

ServingCellConfigCommon ::= SEQUENCE {
    physCellId                        PhysCellId          OPTIONAL,
        -- PhysCellId ::= INTEGER (0..1007)   <- the 1008 of section 10
    downlinkConfigCommon              DownlinkConfigCommon OPTIONAL,
    ...
    ssbPositionsInBurst               CHOICE {
        shortBitmap                     BIT STRING (SIZE (4)),
        mediumBitmap                    BIT STRING (SIZE (8)),
        longBitmap                      BIT STRING (SIZE (64))
    }                                                     OPTIONAL,
    ssb-periodicityServingCell        ENUMERATED {ms5, ms10, ms20,
                                                 ms40, ms80, ms160,
                                                 spare2, spare1}
                                                          OPTIONAL,
    dmrs-TypeA-Position               ENUMERATED {pos2, pos3},
    ...
    ssbSubcarrierSpacing              SubcarrierSpacing   OPTIONAL,
        -- kHz15 | kHz30 | kHz120 | kHz240.  Never kHz60
    ...
    ss-PBCH-BlockPower                INTEGER (-60..50),
    ...
}

Listing 2. Dedicated signalling, abridged. Note that the 64-bit longBitmap is available here but not in SIB1 — dedicated signalling can afford the bits.

21.3 The same fields as broadcast in SIB1

ServingCellConfigCommonSIB ::= SEQUENCE {
    downlinkConfigCommon              DownlinkConfigCommonSIB,
    ...
    ssb-PositionsInBurst              SEQUENCE {
        inOneGroup                      BIT STRING (SIZE (8)),
        groupPresence                   BIT STRING (SIZE (8))
                                                          OPTIONAL
        -- groupPresence is present only when L_max = 64.
        -- Transmitted SSBs = (bits set in groupPresence)
        --                  x (bits set in inOneGroup)
    },
    ssb-PeriodicityServingCell        ENUMERATED {ms5, ms10, ms20,
                                                 ms40, ms80, ms160},
    ...
    ss-PBCH-BlockPower                INTEGER (-60..50),
    ...
}

FrequencyInfoDL-SIB ::= SEQUENCE {
    frequencyBandList                 MultiFrequencyBandListNR-SIB,
    offsetToPointA                    INTEGER (0..2199),
        -- 15 kHz PRBs in FR1, 60 kHz PRBs in FR2.  Measured from
        -- point A to the lowest subcarrier of the lowest CRB that
        -- overlaps the SSB used for initial cell selection
    scs-SpecificCarrierList           SEQUENCE (SIZE (1..maxSCSs))
                                        OF SCS-SpecificCarrier
}

SCS-SpecificCarrier ::= SEQUENCE {
    offsetToCarrier                   INTEGER (0..2199),
    subcarrierSpacing                 SubcarrierSpacing,
    carrierBandwidth                  INTEGER (1..maxNrofPhysicalResourceBlocks),
    ...
}

Listing 3. The broadcast forms, abridged. offsetToPointA and offsetToCarrier sit in different structures and answer different questions — see the table in §17.

21.4 SSB-MTC, for completeness

SSB-MTC ::= SEQUENCE {
    periodicityAndOffset              CHOICE {
        sf5                             INTEGER (0..4),
        sf10                            INTEGER (0..9),
        sf20                            INTEGER (0..19),
        sf40                            INTEGER (0..39),
        sf80                            INTEGER (0..79),
        sf160                           INTEGER (0..159)
    },
    duration                          ENUMERATED {sf1, sf2, sf3,
                                                  sf4, sf5}
}
-- The measurement window of section 18. Owned in full by the
-- companion 21 Measurement Gaps and SMTC document; quoted here only
-- so the relationship to ssb-periodicityServingCell is visible:
-- the SMTC periodicity must be a multiple of, or equal to, the
-- neighbour's actual SSB periodicity, or windows and bursts drift
-- past each other.

Listing 4. SSB-MTC as it appears in measObjectNR. Included to make the §18 point concrete: the window and the burst set are configured independently and nothing checks that they agree.

22. Nine Worked Calculations

The arithmetic of this document, collected and carried through to answers. Six of these appear in the sections above; three are new. All use consistent numbers, so they compose: the n78 cell is the same cell throughout, with PCI 431, GSCN 7883 and carrier ARFCN 638884.

22.1 to 22.3 NR-ARFCN to frequency, one per global raster range

🧮
Worked calculation

Formula: F_REF = F_REF_Offs + ΔF_Global × (N_REF − N_REF_Offs)

Range 1, below 3 GHz. N_REF = 431000

ΔF_Global = 5 kHz, F_REF_Offs = 0, N_REF_Offs = 0

F = 0 + 5 kHz × 431000 = 2155.000 MHz (band n1 downlink)

Range 2, 3 to 24.25 GHz. N_REF = 638884

ΔF_Global = 15 kHz, F_REF_Offs = 3000 MHz, N_REF_Offs = 600000

F = 3000 + 15 kHz × 38884 = 3000 + 583.26 = 3583.26 MHz (n78)

Range 3, above 24.25 GHz. N_REF = 2079167

ΔF_Global = 60 kHz, F_REF_Offs = 24250.08 MHz, N_REF_Offs = 2016667

F = 24250.08 + 60 kHz × 62500 = 24250.08 + 3750 = 28000.08 MHz (n257)

22.4 GSCN to SS_REF on n78, and the reverse

🧮
Worked calculation

Forward. GSCN 7883, so region 2 (7499 ≤ GSCN ≤ 22255).

N = 7883 − 7499 = 384

SS_REF = 3000 MHz + 384 × 1.44 MHz = 3552.96 MHz

Block occupies 3552.96 ± 3.6 = 3549.36 to 3556.56 MHz at 30 kHz

Reverse. An SSB is measured centred at 3679.68 MHz.

N = (3679.68 − 3000) / 1.44 = 679.68 / 1.44 = 472 (exact)

GSCN = 7499 + 472 = 7971

Sanity: 7971 is inside n78's published range 7711 – 8051 ✓

A negative case, to show what failure looks like. An SSB measured at 3680.00 MHz.

N = 680.00 / 1.44 = 472.22 — not an integer

This frequency is not on the synchronisation raster. A compliant UE will never test it, and the cell is undiscoverable. This is failure mode one in §20.

22.5 GSCN points to scan on n78, and the search-time cost

🧮
Worked calculation

n78's published range is 7711 – <1> – 8051.

Points = 8051 − 7711 + 1 = 341

Spacing = 1.44 MHz, so they span 341 × 1.44 = 491 MHz of the band's 500 MHz

Serial search cost, at the initial-search assumption of 20 ms periodicity and 5 burst sets accumulated per candidate:

Dwell per candidate = 5 × 20 ms = 100 ms

Total = 341 × 100 ms = 34.1 s

Contrast, if the SSB were allowed on n78's 15 kHz channel raster instead:

Points = (653333 − 620000) + 1 = 33 334

Total = 33 334 × 100 ms = 3333 s ≈ 56 minutes

Ratio = 33 334 / 341 = 97.8×. Both figures are order of magnitude and worst-case-serial; a real receiver tests many candidates inside one wideband capture, which changes the wall-clock time but not the number of correlation hypotheses.

22.6 PCI derivation, both directions

🧮
Worked calculation

Forward. N_ID1 = 143 (from SSS), N_ID2 = 2 (from PSS).

PCI = 3 × N_ID1 + N_ID2 = 3 × 143 + 2 = 431

PSS cyclic shift = 43 × 2 = 86

SSS offsets: m0 = 15 × FLOOR(143/112) + 5 × 2 = 15 + 10 = 25

m1 = 143 mod 112 = 31

PBCH DM-RS comb: ν = 431 mod 4 = 3

Reverse. A log reports PCI 431.

N_ID2 = 431 mod 3 = 2

N_ID1 = FLOOR(431 / 3) = 143

Check: 3 × 143 + 2 = 431 ✓

Second forward case. N_ID1 = 289, N_ID2 = 1.

PCI = 3 × 289 + 1 = 868

m0 = 15 × FLOOR(289/112) + 5 × 1 = 15 × 2 + 5 = 35

m1 = 289 mod 112 = 65

ν = 868 mod 4 = 0

22.7 Case C candidate symbol positions for L_max = 8

Case C, L_max = 8: every candidate position resolved
Pattern {2, 8} + 14n, n = 0..3, at 30 kHz -- 0.5 ms slots, 14 symbols
Candidate first symbols: 2, 8, 16, 22, 30, 36, 44, 50

  index  symbol  slot  sym-in-slot  start (ms)   end (ms)
  -----  ------  ----  -----------  ----------  ---------
    0       2      0        2          0.071       0.214
    1       8      0        8          0.286       0.429
    2      16      1        2          0.571       0.714
    3      22      1        8          0.786       0.929
    4      30      2        2          1.071       1.214
    5      36      2        8          1.286       1.429
    6      44      3        2          1.571       1.714
    7      50      3        8          1.786       1.929

start = (symbol / 14) x 0.5 ms;  each block is 4 symbols = 0.143 ms
🧮
Worked calculation

Sweep duration = 1.929 − 0.071 = 1.86 ms of a 5 ms half-frame, so the burst set occupies under 40 % of the half it sits in. Slots 4 through 9 carry no candidate positions at all, and symbols 0–1 and 12–13 of each SSB slot stay clear — which is where CORESET#0 goes.

22.8 k_SSB and offsetToPointA to an absolute frequency

🧮
Worked calculation

The full chain for the n78 cell, condensed from §17.

GSCN 7883 → SS_REF = 3552.96 MHz

− 3.6 MHz (half of 240 × 30 kHz) → lowest SSB sc = 3549.36 MHz

− k_SSB 8 × 15 kHz = 0.12 MHz → bottom of CRB 42 = 3549.24 MHz

− offsetToPointA 84 × 0.18 MHz → point A = 3534.12 MHz

+ 273 PRB × 0.36 MHz / 2 = 49.14 MHz → carrier centre = 3583.26 MHz

→ N_REF = 600000 + (583.26 / 0.015) = 600000 + 38884 = 638884

SSB centre is 3583.26 − 3552.96 = 30.30 MHz below carrier centre

Parity check: subCarrierSpacingCommon is 30 kHz, so a CRB is 360 kHz = two 15 kHz PRBs. offsetToPointA must be even. 84 ✓

22.9 SSB overhead as a fraction of the downlink

🧮
Worked calculation

How much of the cell the sweep actually costs. n78, 100 MHz, 273 PRB at 30 kHz, Case C, 8 SSBs transmitted, ms20 periodicity.

Per SSB: 4 symbols × 20 PRB = 4 × 240 = 960 REs

Per burst set: 8 × 960 = 7680 REs

Available in 20 ms at 30 kHz:

20 ms = 40 slots; 40 × 14 symbols × 273 PRB × 12 sc

= 40 × 14 × 3276 = 1 834 560 REs

Overhead = 7680 / 1 834 560 = 0.42 %

Now the same cell on ms160: 0.42 / 8 = 0.05 %, at eight times the initial-search cost (§16). And an FR2 cell sweeping 64 beams at ms20 pays 8 × that per burst set — still under 4 % of a 400 MHz carrier, which is why FR2 can afford 64 candidate positions at all.

The number worth remembering is the first one: under half a percent. SSB overhead is almost never the reason to lengthen the periodicity, and the search-time cost of doing so is large. Figures exclude the guard symbols a scheduler typically leaves around the block, which roughly doubles the practical cost.

23. Illustrative Message Traces

🔍
ABOUT THESE TRACES

Illustrative trace. Field names and encodings follow 3GPP; the values are constructed for this document and are not a capture from any deployed or lab network.

Five traces, all for the same cell: band n78, GSCN 7883, PCI 431, Case C with L_max = 8, ssb-PositionsInBurst = 1101 0000, ssb-periodicityServingCell = ms20. The final one is a failure path.

23.1 A raster scan, with one hit

[PHY] Synchronisation raster scan
09:41:02.104  [PHY-SRCH] cell search started  reason=powerOn
              stored frequency list ......... empty
              band list .................... n78
              GSCN range for n78 ........... 7711 - <1> - 8051  (341 pts)
              assumed SSB periodicity ...... 20 ms  (TS 38.213 cl. 4.1)
              dwell per candidate .......... 100 ms (5 burst sets)

09:41:02.104  [PHY-SRCH] GSCN 7711  f=3305.28 MHz  PSS corr peak -- / -- / --
09:41:02.206  [PHY-SRCH] GSCN 7712  f=3306.72 MHz  no peak above threshold
09:41:02.308  [PHY-SRCH] GSCN 7713  f=3308.16 MHz  no peak above threshold
                         ... GSCN 7714 .. 7881 elided, all negative ...
09:41:19.462  [PHY-SRCH] GSCN 7882  f=3551.52 MHz  no peak above threshold
09:41:19.564  [PHY-SRCH] GSCN 7883  f=3552.96 MHz
              PSS correlation  N_ID2=0 .... 2.1 dB   (below threshold)
              PSS correlation  N_ID2=1 .... 1.8 dB   (below threshold)
              PSS correlation  N_ID2=2 ... 14.6 dB   ** PEAK **
              peak sample offset ........... 118 774
              coarse freq offset est ....... -1.9 kHz
              -> N_ID2 = 2, symbol timing acquired, scan halted

09:41:19.566  [PHY-SRCH] scan summary  candidates tried 173 of 341, elapsed 17.46 s

Listing 5. A cold start with nothing stored. 173 candidates tried before a hit — roughly half the list, which is what you would expect on average for a randomly placed cell. The elapsed time is the number §2 predicts.

23.2 PSS and SSS, with the PCI derived

[PHY] PSS and SSS detection
09:41:19.566  [PHY-SYNC] PSS accepted  N_ID2=2  GSCN 7883
              applying coarse frequency correction -1.9 kHz

09:41:19.586  [PHY-SYNC] SSS search  symbol l=2, k=56..182
              hypotheses tested ............ 336
              best  N_ID1=143   metric 11.9 dB
              2nd   N_ID1=087   metric  3.2 dB   (8.7 dB margin)
              -> N_ID1 = 143

09:41:19.586  [PHY-SYNC] PCI = 3 x N_ID1 + N_ID2
                            = 3 x 143 + 2 = 431
              derived: PSS cyclic shift .... 43 x 2 = 86
              derived: SSS m0 .............. 15 x FLOOR(143/112) + 5x2 = 25
              derived: SSS m1 .............. 143 mod 112 = 31
              derived: PBCH DM-RS comb nu .. 431 mod 4 = 3
              SS-RSRP ...................... -91.4 dBm

09:41:19.586  [PHY-SYNC] frequency now known, identity now known;
              frame timing still unknown

Listing 6. The 8.7 dB margin between the best and second-best SSS hypothesis is the number to look at. A margin under about 3 dB means the PCI should be treated as provisional — that is the signature of the collision case in §20.

23.3 The SSB index from the DM-RS, then PBCH and the MIB

[PHY] SSB index, PBCH decode, MIB
09:41:19.588  [PHY-PBCH] DM-RS hypothesis test, L_max=8 -> i_SSB = index mod 8
              c_init = 2^11 x (i_SSB+1) x (FLOOR(431/4)+1)
                     + 2^6  x (i_SSB+1) + (431 mod 4)
              i_SSB=0 .. corr 1.2 dB      i_SSB=4 .. corr 0.9 dB
              i_SSB=1 .. corr 0.8 dB      i_SSB=5 .. corr 1.1 dB
              i_SSB=2 .. corr 9.8 dB  **  i_SSB=6 .. corr 1.4 dB
              i_SSB=3 .. corr 1.0 dB      i_SSB=7 .. corr 0.7 dB
              -> SSB index = 2   (candidate first symbol 16, slot 1 sym 2)

09:41:19.588  [PHY-PBCH] descramble hypothesis  2 SFN bits unknown
              hyp 0 (SFN[3:2]=00) .. CRC FAIL
              hyp 1 (SFN[3:2]=01) .. CRC FAIL
              hyp 2 (SFN[3:2]=10) .. CRC OK
              -> SFN[3:2] = 10

09:41:19.588  [PHY-PBCH] PBCH decoded  Polar, 864 -> 56 bits, CRC-24 OK
              MIB
                systemFrameNumber ........ 101101      -- SFN[9:4] = 45
                subCarrierSpacingCommon .. scs30or120  -- 30 kHz here
                ssb-SubcarrierOffset ..... 8           -- k_SSB, low 4 bits
                dmrs-TypeA-Position ...... pos2
                pdcch-ConfigSIB1 ......... 0x60        -- to companion 18
                cellBarred ............... notBarred
                intraFreqReselection ..... allowed
                spare .................... 0
              L1-added bits
                SFN LSBs ................. 1011        -- SFN[3:0]
                halfFrameBit n_hf ........ 0
                k_SSB MSB ................ 0           -- k_SSB = 8, in range

09:41:19.588  [PHY-PBCH] SFN = 101101 1011 = 731
              n_hf = 0 -> burst set in subframes 0..4 of frame 731
              frame timing acquired

Listing 7. The two halves of the SFN joining up: 0b101101 = 45 as the high six bits, 0b1011 = 11 as the low four, giving 45 × 16 + 11 = 731. Note that hypothesis 2 gave SFN[3:2] = 10, which is consistent with the payload's 1011.

23.4 The burst set, once the cell is being measured

[PHY] Burst set measurement against the declared bitmap
09:41:19.640  [PHY-SSB] burst set observed, frame 731, half-frame 0
              Case C, 30 kHz, L_max = 8
              ssb-PositionsInBurst (from SIB1) = 1101 0000

              idx  first sym  slot/sym  declared  measured  SS-RSRP
               0        2       0 / 2      yes      yes     -94.8 dBm
               1        8       0 / 8      yes      yes     -91.4 dBm
               2       16       1 / 2      no        --         --
               3       22       1 / 8      yes      yes    -103.2 dBm
               4       30       2 / 2      no        --         --
               5       36       2 / 8      no        --         --
               6       44       3 / 2      no        --         --
               7       50       3 / 8      no        --         --

09:41:19.640  [PHY-SSB] best beam = idx 1  (-91.4 dBm)
              cell-level SS-RSRP (linear avg of declared) = -93.6 dBm
              -- NOTE: acquisition at 09:41:19.588 reported idx 2, which
              -- the bitmap declares as NOT transmitted. See 23.5.

Listing 8. A three-beam cell in an eight-position range. The inconsistency flagged in the last two lines is the subject of the failure trace below — the UE found a beam the cell says it does not send.

23.5 Failure path: a bitmap that does not match the air

[PHY/MAC/RRC] ssb-PositionsInBurst mismatch
09:41:19.700  [PHY-SSB] consistency check
              acquisition SSB index ........ 2
              ssb-PositionsInBurst bit 2 ... 0  (declared absent)
              -> acquired on an undeclared candidate position

09:41:19.700  [MAC]     SSB-to-RACH association lookup for SSB index 2
              ssb-perRACH-OccasionAndCB-PreamblesPerSSB = one
              association built from DECLARED positions only: {0, 1, 3}
              index 2 not present in association map
              -> no PRACH occasion derivable for the acquired beam

09:41:19.702  [MAC]     falling back: reselect best DECLARED SSB
              -> SSB index 1, SS-RSRP -91.4 dBm, above rsrp-ThresholdSSB
              -> PRACH occasion from association for index 1

09:41:19.740  [MAC-UL]  MSG1 preamble 19, RA-RNTI 1417
09:41:19.752  [MAC]     ra-ResponseWindow expired, no RAR
09:41:19.790  [MAC-UL]  MSG1 preamble 44, RA-RNTI 1417, +4 dB
09:41:19.802  [MAC]     ra-ResponseWindow expired, no RAR
                        ... attempts 3..8 elided, all timing out ...
09:41:20.104  [MAC]     PREAMBLE_TRANSMISSION_COUNTER = preambleTransMax
09:41:20.104  [MAC]     -> Random Access problem indication to RRC
09:41:20.104  [RRC]     T300 running -> connection establishment failure
09:41:20.105  [RRC]     -> RRC_IDLE, cell reselection

-- Diagnosis: the cell is transmitting a beam at candidate position 2
-- that ssb-PositionsInBurst declares absent. The UE acquired on it,
-- could not map it to a PRACH occasion, fell back to index 1 -- and
-- index 1's beam does not actually cover this UE's location, so the
-- preamble is never heard. Nothing in the RF chain is faulty.

Listing 9. The bitmap mismatch of §20, followed all the way to a connection establishment failure. Note how far the symptom is from the cause: the visible failure is a RACH timeout, and the fix is a 4-bit broadcast field.

🔍
What you see in logs

The shape of 23.5 is the reason this document exists. Every observable symptom — preamble timeouts, T300 expiry, connection establishment failure — points at random access or at coverage. The actual cause is four bits in SIB1. When RACH fails on a cell whose SSB acquisition succeeded, compare the acquired SSB index against ssb-PositionsInBurst before anything else; it is a two-second check that rules out a whole class of misdiagnosis. See the companion 03 Random Access document for the association itself.

24. Release Deltas: Rel-15 to Rel-18

The SSB and the rasters have been unusually stable — they are the foundation everything else stands on, and changing them breaks every deployed UE. What has changed is mostly additive: new frequency ranges needing new numerologies, and new operating modes that transmit the SSB differently or not at all.

ReleaseChangeWhy it matters when reading cell search
Rel-15The baseline: three global raster ranges, GSCN and the synchronisation raster, Cases A through E, L_max 4/8/64, 1008 PCIs, the 24-bit MIB, ssb-PositionsInBurst in all three formsEverything in §3 to §17 is Rel-15 and has not moved
Rel-15 latePer-band GSCN ranges extended as bands were widened (notably the n77 and n78 ranges)A range read from an early specification version can be short. If a cell's GSCN looks out of range, check the version before concluding misconfiguration
Rel-16NR-U: SSB transmitted inside a discovery burst transmission window subject to listen-before-talk, so its position in time is no longer deterministicOn unlicensed spectrum the SSB may simply not be transmitted in a given period because the channel was busy. A missing burst set is not evidence of a fault
Rel-16NR-U candidate SSB index extended beyond L_max with a QCL relationship parameter, so several candidate positions can carry the same beamTwo different SSB indices in an NR-U log can be the same beam. Do not count distinct indices as distinct beams there
Rel-16Cross-carrier and cross-link improvements to SSB-based measurement; ssb-PositionQCL signallingMeasurement configuration gains QCL context the earlier releases lacked
Rel-17SSB-less SCell operation for intra-band carrier aggregation: an SCell may transmit no SSB at all and rely on the PCell's timing and the SCell's TRSA carrier with no SSB is now legitimate. Absence of an SSB on a configured carrier is not automatically a fault — check whether it is an SSB-less SCell. See the companion 29 Carrier Aggregation
Rel-1752.6 – 71 GHz support: SSB subcarrier spacings of 480 and 960 kHz, with additional candidate-position patterns beyond Case E, and an extended sync raster regionA UE reporting an SSB SCS outside {15, 30, 120, 240} kHz is on FR2-2. The Case letters and n-value sets there are additions, not replacements — read TS 38.213 cl. 4.1 for the release in use
Rel-17RedCap: no change to the SSB itself, but a separate initial uplink BWP and separate PRACH resourcesTwo UE classes can acquire the same SSB and then diverge completely. The SSB index means the same thing to both
Rel-17NTN: SSB unchanged, but Doppler and propagation delay are orders of magnitude largerPSS frequency-offset estimation carries far more of the burden, and the "PSS found, SSS failing" signature of §20 becomes much more common and much less diagnostic
Rel-18Network energy saving: cell DTX/DRX and adapted SSB transmission, including spatial and temporal adaptation of the burst setA cell may legitimately reduce or shift its SSB transmission to save power. ssb-PositionsInBurst no longer fully describes what is on the air at every instant
Rel-18LTM (L1/L2-triggered mobility): candidate cells' SSB and TRS are measured and reported at L1, and a cell switch may involve no RRC signallingA mobility event may show no RRC messages at all — the SSB measurements are the only trace of it. See companion 25 Conditional HO and DAPS for the neighbouring mechanisms
Rel-18Further NTN and non-terrestrial refinements; expanded per-band tables for newly allocated spectrumPer-band GSCN ranges continue to be added. Always read the current table

Table 22. SSB and cell-search relevant changes by release. Feature presence should be confirmed against the UE capability exchange — see the companion 26 UE Capability document — rather than assumed from the release the software claims.

25. Reading Cell Search in Logs: A Checklist

  1. Establish whether the UE was searching blind or was told where to look. A log that lists GSCN candidates in ascending order is a cold start (§7). A log that goes straight to one frequency was given it — by stored information, by redirectedCarrierInfo, or by measurement configuration. The two have completely different expected durations, and judging a directed search by cold-start timings will make a healthy UE look slow.
  2. Check the GSCN against the band's published range before anything else. Compute N = (F − F_base) / step and confirm it is an integer inside the range from TS 38.104 cl. 5.4.3.3. A non-integer means the SSB is not on the raster and no UE will ever find it; an integer outside the range means the SSB is on the raster but not where UEs searching that band will look. Both produce a cell with zero traffic and no alarms (§20).
  3. Separate the three rasters in your head before quoting any frequency. A GSCN is not an ARFCN. If a tool has shown you an "SSB ARFCN", it has performed a conversion that may not be exact — go back to the GSCN and run the SS_REF equation (§6).
  4. Read how far the acquisition chain got. PSS peak only, PSS plus PCI, PCI plus SSB index, or a decoded MIB. Each stopping point implicates different causes (the table at the end of §11), and only the first two can be helped by more transmit power.
  5. When PSS succeeded but SSS did not, suspect frequency error, not coverage. SSS's 336-way correlation is far more sensitive to residual frequency offset than PSS's 3-way one. Look for a cold-start oscillator error, high Doppler, or narrowband interference sitting in symbol 2 (§9, §20).
  6. Check the SSS detection margin, not just the winner. A best-to-second-best margin under about 3 dB means the PCI is provisional. That is the signature of a PCI collision, and it will also produce erratic RSRP for that PCI between adjacent samples (§20, trace 23.2).
  7. Recompute the PCI decomposition. N_ID2 = PCI mod 3, N_ID1 = FLOOR(PCI/3), ν = PCI mod 4. If a plan has first-tier neighbours all congruent modulo 3, it has thrown away the PSS diversity; if they are congruent modulo 4 as well, they are also sharing the PBCH DM-RS comb (§8.2, §10.1).
  8. Compare the acquired SSB index against ssb-PositionsInBurst before investigating a RACH failure. An index the bitmap declares absent cannot be mapped to a PRACH occasion, and the resulting failure looks exactly like a coverage problem. Trace 23.5 walks the whole path.
  9. Count the reported SSB indices against the cell's provisioned beam count. Fewer reported than provisioned is usually the bitmap, not the antenna. At L_max = 64 in SIB1, remember that the count is groupPresence bits set × inOneGroup bits set, not a 64-bit string (§15).
  10. Verify the SFN assembly arithmetic explicitly when timing looks wrong: six MIB bits as SFN[9:4], four payload bits as SFN[3:0], and the half-frame bit separately. A missed paging or PRACH occasion by exactly 5 ms is a half-frame error; by a multiple of 40 ms it is an SFN LSB error (§13).
  11. Check ssb-periodicityServingCell against the accessibility statistics whenever initial access has become slow or erratic without any RF change. ms40 and beyond cost search time in direct proportion and are frequently introduced during overhead optimisation without anyone connecting the two (§16).
  12. Recompute the k_SSB and offsetToPointA chain when SIB1 reads and nothing after it works. Check offsetToPointA parity against subCarrierSpacingCommon, and check that the SSB's full 240 subcarriers fall inside the carrier's PRBs (§17, §20).
  13. For a neighbour that is on the air but never reported, check the SMTC first. An SMTC that does not align with the neighbour's actual burst sets fails silently and completely, unlike initial search which merely degrades (§18). The companion 21 Measurement Gaps and SMTC has the window arithmetic.

26. Glossary

Every term is glossed as it is first used in the body as well; this is for looking things up afterwards.

TermExpansionMeaning in this document
SSBSS/PBCH BlockThe four-symbol by 240-subcarrier block carrying PSS, SSS, PBCH and the PBCH DM-RS. The only thing a UE can find with no prior information
RasterAn agreed grid of permitted frequencies. NR has three, and they answer three different questions (§3)
NR-ARFCNNR Absolute Radio Frequency Channel NumberThe number that names a point on the global frequency raster. A dictionary entry, not a permission
ΔF_GlobalGlobal raster step5 kHz below 3 GHz, 15 kHz to 24.25 GHz, 60 kHz above. Sets how finely frequencies can be named
ΔF_RasterChannel raster stepPer band. The spacing of permitted carrier centre frequencies — a subset of the global raster
GSCNGlobal Synchronisation Channel NumberThe number of a permitted SSB centre position. Its own numbering, 2 to 26639, unrelated to ARFCN
SS_REFSynchronisation raster reference frequencyThe centre frequency a GSCN corresponds to
MThe sub-3 GHz raster sub-position selector∈ {1, 3, 5}, giving ±50 kHz around each nominal 1.2 MHz point. Exists only below 3 GHz, to fit refarmed bands (§6.1)
m-sequenceMaximum-length sequenceA shift-register-generated binary sequence that correlates strongly with itself and weakly with any shift of itself. PSS is one of length 127
Gold sequenceThe product of two m-sequences at chosen offsets, which yields far more distinguishable members than one m-sequence. SSS is one, giving 336 members
PSSPrimary Synchronisation SignalSymbol 0, k = 56..182. Three cyclic shifts of one m-sequence. Yields symbol timing, coarse frequency, and N_ID2
SSSSecondary Synchronisation SignalSymbol 2, same subcarriers. 336 Gold sequences. Yields N_ID1
N_ID2 / N_ID1PSS and SSS identity components0 to 2 and 0 to 335. Combine as PCI = 3 × N_ID1 + N_ID2
PCIPhysical Cell Identity0 to 1007. The number every log and measurement report uses to name a cell. Not globally unique — it is reused, which is why collisions and confusion happen (§20)
Half-frameFive subframes: half-frame 0 is subframes 0–4, half-frame 1 is 5–9. An SSB burst set is always confined to one of them
n_hfHalf-frame bit0 or 1, saying which half-frame the burst set occupies. Carried in the PBCH payload, or folded into the DM-RS hypothesis at L_max = 4
Burst setSSB burst setThe group of SSBs a cell transmits in one half-frame — one per beam. A beam sweep (§14)
Candidate positionA specification-fixed first-symbol index at which an SSB may start inside the half-frame. Given by the Case
Case A – ESSB candidate position patternsFive patterns of candidate positions, selected by SSB subcarrier spacing and frequency range (§14.1)
L_maxThe number of candidate positions in the half-frame: 4 below 3 GHz, 8 to 7.125 GHz, 64 above 6 GHz. A ceiling, not a count
SSB indexWhich candidate position a particular SSB occupied. Recovered from the PBCH DM-RS, plus payload bits on FR2 (§12)
k_SSBssb-SubcarrierOffsetThe fine frequency offset between the SSB's lowest subcarrier and the resource block containing it. 15 kHz units in FR1
offsetToPointAThe coarse offset, in resource blocks, from point A up to the lowest CRB overlapping the SSB used for initial cell selection
Point AThe origin of the cell's common resource block grid; every CRB in the cell is numbered from it. Owned by companion 02
CRBCommon Resource BlockA resource block numbered from point A, as opposed to a PRB numbered from the start of a bandwidth part
CORESET#0The control resource set used to schedule SIB1, indexed from pdcch-ConfigSIB1 and k_SSB. Owned by companions 18 and 30
SMTCSSB Measurement Timing ConfigurationThe window during which a connected UE opens its receiver to measure a neighbour's SSBs. Owned by companion 21
SS-RSRPSSB Reference Signal Received PowerPower measured on the SSB's SSS and, optionally, PBCH DM-RS resource elements. What a measurement report carries

27. References

  • 3GPP TS 38.104Base Station radio transmission and reception. Clause 5.4.2 (frequency channel raster: 5.4.2.1 the global raster and the NR-ARFCN equation, 5.4.2.2 the channel raster), clause 5.4.3 (synchronisation raster: 5.4.3.1 the SS_REF and GSCN equations for all three ranges, 5.4.3.2 the mapping between SS_REF and the SSB, 5.4.3.3 the per-band GSCN ranges — Table 5.4.3.3-1 is the one to read for any specific band).
  • 3GPP TS 38.101-1UE radio transmission and reception, Range 1. Clause 5.2 (operating bands), clause 5.3 (channel bandwidths and transmission bandwidth in PRBs), clause 5.4.2.3 (per-band ΔF_Raster and NR-ARFCN ranges).
  • 3GPP TS 38.101-2UE radio transmission and reception, Range 2. The same clause structure for FR2, including the 60 and 120 kHz channel rasters and the FR2 band table.
  • 3GPP TS 38.211Physical channels and modulation. Clause 7.4.1.4 (PBCH DM-RS, including 7.4.1.4.1 sequence generation and the c_init expression), clause 7.4.2 (synchronisation signals: 7.4.2.1 the PCI composition, 7.4.2.2 PSS, 7.4.2.3 SSS), clause 7.4.3 (SS/PBCH block: 7.4.3.1 the resource element mapping and Table 7.4.3.1-1, 7.4.3.1.1 the time-frequency structure).
  • 3GPP TS 38.212Multiplexing and channel coding. Clause 7.1 (broadcast channel: 7.1.1 the PBCH payload generation and the eight added bits, 7.1.2 the scrambling and which bits are excluded from it, 7.1.3 the CRC, 7.1.4 the Polar encoding, 7.1.5 the rate matching).
  • 3GPP TS 38.213Physical layer procedures for control. Clause 4.1 (cell search: the SSB candidate positions for Cases A through E, L_max by frequency range, and the 20 ms periodicity a UE may assume for initial cell selection), clause 13 (the CORESET#0 and searchSpaceZero tables and the k_SSB validity rules).
  • 3GPP TS 38.331RRC protocol specification. MIB, ServingCellConfigCommon, ServingCellConfigCommonSIB, FrequencyInfoDL, FrequencyInfoDL-SIB, SCS-SpecificCarrier, SSB-MTC, MeasObjectNR, PhysCellId.
  • 3GPP TS 38.300NR overall description. Clause 9.2.6 and clause 5.2 for where cell search sits in the access procedure and the state model.
  • 3GPP TS 38.133Requirements for support of radio resource management. The cell identification delay and measurement accuracy requirements that turn the search-time discussion of §2 and §16 into conformance numbers.

Companion documents in this set

  • 01 Registration Process — what happens after SIB1: the first RACH, the NAS registration, and where redirectedCarrierInfo comes from that shortens the next search (§7).
  • 02 Radio Frame Structure — the resource grid, the numerologies, frames, half-frames, the SFN, point A and the common resource block grid. It owns everything this document measures offsets against, and it gives the SSB and the sync raster at survey level; this document is the deep treatment (§8, §13, §17).
  • 03 Random Access — the SSB-to-PRACH-occasion association that makes the SSB index matter, and the preamble procedure that trace 23.5 ends in.
  • 17 System Information — the SI acquisition procedure, the SI windows, and on-demand SI, all of which begin where §11 stops.
  • 18 MIB and SIB1 IEs — the MIB decoded field by field, pdcch-ConfigSIB1 decomposed, the CORESET#0 and searchSpaceZero tables, cellSelectionInfo and the S-criteria, and uac-BarringInfo. This document hands over to it at step 8 of §11 (§17, §21.1).
  • 19 Paging — the paging occasion arithmetic, which is the first thing a correctly assembled SFN and half-frame are used for (§13).
  • 20 Measurements and Events — what is done with SS-RSRP once the SSB is being measured rather than searched for (§18).
  • 21 Measurement Gaps and SMTC — the SMTC window arithmetic, and the gap patterns that let a UE measure another frequency at all (§18).
  • 29 Carrier Aggregation — SSB-less SCell operation, where a configured carrier legitimately carries no SSB (§24).
  • 30 CORESET and Search Space — where PDCCH candidates live, including CORESET#0 as a special case of the general structure.
  • 33 DMRS — every reference signal in the system, including the PBCH DM-RS sequence generation this document uses but does not derive (§8.2, §12).
  • 35 Physical Channels — PBCH as one of the six physical channels, with its coding chain in full, and the rate-matching rules that keep PDSCH off the SSB's resource elements (§8.1, §15).