跳转至

iCellular: Device-Customized Cellular Network Access on Commodity Smartphones

Introduction

Mobile Internet access has become an essential part of our daily life with our smartphones. From the user’s perspective, (s)he demands for high-quality, anytime, and anywhere network access. From the infrastructure’s standpoint, carriers are migrating towards faster technologies (e.g., from 3G to 4G LTE), while boosting network capacity through dense deployment and efficient spectrum utilization. Despite such continuous efforts, no single carrier can ensure complete coverage or highest access quality at any place and anytime.

In addition to infrastructure upgrades from carriers, a promising alternative is to leverage multiple carrier networks at the end device. In reality, most regions are covered by several carriers (say, Verizon, T-Mobile, Sprint, and AT&T in the US). With multi-carrier access, the device may select the best carrier over time and improve its overall access quality. The exciting Google Project Fi [26] has taken the lead to provide 3G/4G multi-carrier access in practice. Other similar efforts through universal SIM card include Apple SIM [14] and Samsung eSIM [24]. The upcoming 5G standards also seek to support multiple, heterogenous access technologies [34].

Our empirical study shows that, the full benefits of multi-carrier access can be constrained by today’s design. We examine Google Project Fi over two carriers (T-Mobile and Sprint), and discover three issues, all of which are independent of its excellent implementations (§3): (P1) The anticipated switch is never triggered even when the serving carrier’s coverage is pretty weak; (P2) The switch takes rather long time (tens of seconds or minutes) and prolongs service unavailability; and (P3) the device fails to choose the high-quality network (e.g., selecting 3G with weaker coverage rather than 4G with stronger coverage).

It turns out that, the above issues can be effectively addressed by using low-level cellular information (e.g., available carriers, which carriers to scan, and radio/QoS profile for each carrier) and mechanisms. However, such fine-grained knowledge is not available to commodity phones in their default operations. This is rooted in the fundamental design of 3G/4G networks. With the single-carrier scenario in mind, 3G/4G follows the design paradigm of “smart core, dumb end”. It thus does not expose its low-level information to the device in normal operations. For multi-carrier access, however, end intelligence is a necessity, since individual carrier does not have global view on all carriers, which can only be constructed at the device through accessing low-level cellular events. Without using such knowledge, today’s carrier selection could encounter issues P1-P3.

While the problem can be solved by the future architecture redesign (say, 5G), it usually takes years to accomplish. Instead, we seek to devise a solution that works with the current 3G/4G network, in line with the ongoing industrial efforts, e.g., Google Project Fi, Apple SIM and Samsung e-SIM. Specifically, we address the following problem: Can we leverage low-level cellular information and mechanisms at the device to further improve multi-carrier access? Our study yields a positive answer.

We propose iCellular, a client-side service to let mobile devices customize their own cellular network access. Complementing the design of Project Fi, iCellular further leverages low-level, runtime cellular information at the device during its carrier selection. iCellular is built on top of current 3G/4G mechanisms at the device, but applies cross-layer adaptations to ensure responsive multi-carrier access with minimal disruption. To facilitate the device to make proper decisions, iCellular exploits online learning to predict the performance of heterogenous carriers, and provides built-in strategies for better usability. It further safeguards access decisions with fault prevention techniques. We implement iCellular on commodity phone models (Nexus 6 and Nexus 6P) and assess its performance with Project Fi. Our evaluation shows that, iCellular can achieve 3.74x throughput improvement and 1.9x latency reduction on average by selecting the best mobile carrier. Meanwhile, iCellular has negligible impacts on the device’s data service and OS resource utilization (less than 2% CPU usage), approximates the lower bounds of responsiveness and switch disruption, and shields its selection strategies from decision faults.

The rest of the paper is organized as follows. §2 introduces the background. §3 describes our findings and uncovers root causes of multi-carrier access. §4, §5, and §6 present the design, implementation and evaluation of iCellular, respectively. §7 discusses remaining issues, and §8 presents the related work. §9 concludes the work.


  1. 背景 1:单一运营商无法覆盖所有地方。

    • 用户希望随时随地都有高质量的网络接入
    • 运营商一直在升级,比如从 3G 迁到 4G、加密基站部署、提高频谱利用率
    • 但仍然没有哪一家能在任何时间、任何地点都保证完整覆盖和最佳质量
  2. 背景 2: 在终端侧利用多运营商接入

    • 大多数地区同时被几家运营商覆盖(美国有 Verizon、T-Mobile、Sprint、AT&T),终端可以随时间挑选最好的那家
    • 工业界已有实践,如 Google Project Fi、Apple SIM、Samsung e-SIM;5G 标准也在考虑支持多种异构接入
  3. 实测发现:多运营商的潜力没有被充分发挥

    • P1:当前运营商信号已经很弱,也不触发切换
    • P2:切换耗时几十秒甚至几分钟,服务长时间中断
    • P3:选错网络,例如选了信号更弱的同运营商 3G,而不是信号更强的另一家 4G
  4. 根因:终端拿不到底层蜂窝信息

    • 这三个问题可以借助底层信息解决,例如当前有哪些运营商可用、该扫描哪些运营商、每家的无线/QoS 配置
    • 但商用手机默认拿不到这些信息! 根源在于 3G/4G 以单运营商为前提,采用 "smart core, dumb end" 的设计,不向终端暴露底层信息
    • 而在多运营商场景下: 单个 运营商 没有全局视图,全局视图只能在 终端 上构建,因此需要终端具备智能
  5. 提出研究问题/方法论:在现有 3G/4G 上解决,而不是等架构重构

    • 5G 那样的架构重设计需要很多年,作者希望方案能直接在现有 3G/4G 网络上工作,并与 Fi 等工业实践兼容
    • 核心问题是:能否利用终端上的底层蜂窝信息和机制来改进多运营商接入?
    • 作者的回答是肯定的
  6. 提出 iCellular:一个客户端服务

    • 基于现有 3G/4G 终端机制,通过跨层适配保证响应快、中断少
    • 用在线学习预测异构运营商的性能
    • 提供内置选网策略,方便普通用户使用
    • 用错误防护技术避免做出错误的切换决策

Mobile Network Access Primer

A cellular carrier deploys and operates its mobile network (called public land mobile network or PLMN) to offer services to its subscribers. Each PLMN has many cells across geographical areas. Each location is covered by multiple cells within one PLMN and across several PLMNs (e.g., Verizon, AT&T, T-Mobile, Sprint).

Single-carrier network access. Today’s cellular network is designed under the premise of single-carrier access. A mobile device is supposed to gain access directly from its home PLMN. It obtains radio access from the serving cell and further connects to the core carrier network and the external Internet, as shown in the left plot of Figure 1. When the current cell can no longer serve the device (e.g., out of its coverage), the device is migrated to another available cell within the same PLMN. This is called handoff.

Roaming between carriers. When the home PLMN cannot serve its subscribers (e.g., in a foreign country), the device may roam to other carriers (visiting networks). This is realized through the PLMN selection procedure between carriers [12], which is a mandatory function for all commodity phones. It supports both automatic (based on a pre-defined PLMN priority list) and manual modes. As shown in the right plot of Figure 1, once triggered by certain events (e.g. no home PLMN service), PLMN selection should first scan the available carriers, and then choose one based on the pre-defined criteria (e.g. preference) or the user manual operation. If the device decides to switch, it will deregister from the current carrier network and then register to a new one. In this process, network access may be temporarily unavailable. This is acceptable since inter-carrier switch is assumed to be infrequent, thus having limited impacts.

Multi-carrier access with universal SIM card. Recent industrial efforts aim at providing mobile device access to multiple carriers with a single SIM card. They include Google Project Fi [26], Apple SIM [14], and Samsung e-SIM [24]. With the SIM card, the device can access multiple cellular carriers (e.g., T-Mobile and Sprint in Project Fi). Given only one cellular interface, the device uses one carrier at a time.


基本概念:PLMN 与覆盖关系

每个运营商部署和运营自己的移动网络,称为 PLMN(Public Land Mobile Network),可以理解为"一个运营商的一张网"。

每个 PLMN 在不同地理区域部署了大量小区(cell,即一个基站扇区覆盖的范围)。同一个位置通常被同一 PLMN 的多个小区覆盖,也被多个 PLMN(Verizon、AT&T、T-Mobile、Sprint)同时覆盖。

alt text

  1. 单运营商接入(现有网络的设计前提) 3G/4G 的设计前提是:终端只从自己的 home PLMN(签约运营商)接入

    • 接入路径是:服务小区提供无线接入,然后接入运营商核心网,再到外部互联网
    • 当当前小区服务不了终端时(比如走出了覆盖范围),终端会被迁移到同一 PLMN 内的另一个小区,这叫 handoff
  2. 跨运营商漫游:PLMN selection 当 home PLMN 服务不了用户时(典型情况是出国),终端可以漫游到其他运营商的网络(visiting network),靠的是 PLMN selection(TS 23.122)。这是所有商用手机都必须支持的功能,有自动模式(按预设的 PLMN 优先级列表选择)和手动模式两种

    • ① 触发:由特定事件触发,例如 home PLMN 无服务(图中 "1. No home PLMN")
    • ② 扫描:扫描周边可用的运营商(图中 "2. Scan carriers")
    • ③ 选择:按预设准则(如优先级)或用户手动选择一个运营商(图中 "3. Select",指向 Other PLMNs)
    • 切换方式:
      • 如果决定切换,先从当前运营商注销(deregister),再到新运营商注册(register),期间网络暂时不可用
      • 设计者认为这可以接受,因为跨运营商切换被假定很少发生,影响有限
  3. 通用 SIM 实现多运营商接入

    • Google Project Fi、Apple SIM、Samsung e-SIM 等工业方案,用一张 SIM 卡就能接入多个运营商(例如 Fi 可以接 T-Mobile 和 Sprint)
    • 但手机只有一个蜂窝接口,所以同一时刻只能使用一个运营商
    • TLDR: 一张通用接PLMN的卡, 但是UE依旧只有一个网口

Multi-carrier Access: Promises & Issues

We run experiments to quantify the benefits of multicarrier access, and identify the downsides of the today’s efforts. The identified limitations are independent of implementations, but rooted in the 3G/4G design.

Methodology. We conduct both controlled experiments and a one-month user study using two Nexus 6 phones with Google Project Fi [26], which was released in May 2015. Project Fi provides access to two U.S. carriers (T-Mobile and Sprint) at this time. It develops an automatic carrier selection on commodity phones using a proprietary mechanism. Unfortunately, details of its switching algorithm have not been published. We contacted Project Fi team and learned that this algorithm aims at optimizing consumer experience, and considers network performance, battery usage and data activity during selection. We further inferred its decision and execution strategies from our experiments.

In each controlled test, we use a Nexus 6 phone with a Project Fi SIM card, and test with Project Fi’s automatic carrier selection mode. We walk along two routes within the campus buildings at UCLA and OSU at the idle mode (no data/voice, screen off). We walk slowly (< 1 m/s) and record the serving carrier (“T” for TMobile, “S” for Sprint) and its network type (4G or 3G) per second. Meanwhile, we carry other accompanying phones to record the radio signal strength of each access option (T-4G, T-3G, S-4G, S-3G). We run each test 10 times and similar results are consistently observed in all the tests. In the user study (07/31/15 to 09/02/15), we use the Project Fi-enabled phone as usual and collect background device and cellular events with MobileInsight, an in-phone cellular monitoring tool [4]. We have collected 4.9GB logs with MobileInsight in total, with 274,351 messages from radio resource control (RRC), 16,470 messages from mobility management (MM), and 5,365 messages from session management (SM). We next present the results from the controlled experiments as motivating examples. The user study to be described in §4 and §6 confirms that these issues are common in practice.

3.1 Motivating Examples

Merits of multi-carrier access. We first verify that exploiting multiple carriers is indeed beneficial to service availability and access quality. Figure 2a shows the results from the controlled experiments over two routes. On the first route [0s,190s), Sprint gradually becomes weaker and then fades away, but its dead zone is covered by T-Mobile; On the second route [190s, 330s], in contrast, Sprint offers stronger coverage, even at locations with extremely weak coverages from T-Mobile. Multicarrier access indeed helps to enhance network service availability by boosting radio coverage. For example, in [160s, 180s], the phone switches to T-Mobile and retains its radio access while Sprint is not available. Moreover, we confirm that it further improves data access throughput and user experiences. The Project Fi indeed offers a major step forward on mobile Internet access.

Our examples further reveal three issues, which demonstrate that the benefits of multi-carrier access have not been fully achieved.

P1. No anticipated inter-carrier switch. It is desirable for the device to migrate to another available carrier network for better access quality, when the device perceives degraded quality from its current, serving carrier. However, our experiments show that, the device often gets stuck in one carrier network, and misses the better network access (e.g., during [40s, 60s] and [240s, 260s] of Figure 2). As shown in Figure 2b, T-Mobile experiences extremely weak radio coverage (< -130 dBm in 4G and < -110 dBm in 3G), but the phone never makes any attempt to move to Sprint, regardless of how strong Sprint’s radio signal is. As a result, the device fails to improve its access quality. Moreover, we find that the expected switch often occurs until its access to the original carrier (here, T-Mobile) is lost. This is rooted in the fact that the inter-carrier switch is triggered when the serving carrier fails. Therefore, the device becomes out of service in this scenario, although better carrier access remains available.

P2. Long switch time and service disruption. Even when inter-carrier switch is eventually triggered, it may disrupt access for tens of seconds or even several minutes (see Figure 6 for the user-study results). In the example of Figure 2c, the phone starts Sprint→T-Mobile roaming at the 140th second, but it takes 17.3s to gain access to T-Mobile 4G. This duration is much longer than the typical handoff latency (possibly several seconds [42]). It is likely to halt or even abort any ongoing data service. We look into the event logs (Figure 3) to examine why the switch is slow. It turns out that, most of the switch time is wasted on an exhaustive scanning of all possible cells, including nearby cells from AT&T and Verizon. In this example, it spends 14.7s on radio-band scanning and 2.6s on completing the registration (attachment) to the new carrier (here, T-Mobile). Note that, such heavy scanning overhead is not incurred by any implementation glitch. Instead, it is rooted in the Project Fi’s design, which selects a new carrier network only after an exhaustive scanning process. In this work, we want to show that such large latency is unnecessary. It can be reduced without compromising inter-carrier selection.

P3. Unwise decision and unnecessary performance degradation. Our next finding is that, the device fails to migrate to the better choice, thus unable to enjoy the full benefits of multi-carrier access. The phone often moves to 3G offered by the same carrier, rather than the 4G network from the other carrier that yields higher speed. Figure 2d illustrates two such instances. After entering an area without Sprint 4G at the 91st second, the device switches to Sprint 3G, despite stronger radio signals from T-Mobile 4G. This indicates that the intracarrier handoff is preferred over the inter-carrier switch in practice. Unfortunately, such a preference choice prevents the inter-carrier switch from taking effect. Even worse, obstacles still remain even when the network access to the original carrier has been shortly disrupted. For instance, during [267s, 273s], the original carrier (TMobile 3G) is still chosen. In this case, T-Mobile 4G and 3G networks almost have no coverage. In short, the device acts as a single-carrier phone in most cases, even with the multi-carrier access capability. Inter-carrier switch is not triggered as expected.

3.2 Insights

The above examples also shed lights on how to solve the three problems. The key is to leverage low-level cellular information and mechanisms at the device when selecting access from multiple carriers.

Specifically, performing the anticipated switch (P1) states that, the device performs inter-carrier switch upon detecting a better carrier, even when the serving carrier is still available. This further requires the device to learn all available carriers and their quality at runtime. Note that such information can be obtained from the low-level cellular events. However, the default operation on commodity phones will not do so. Moreover, the naive approach of forcing the phone to proactively scan other carriers at any time may lead to temporary disconnection from the current carrier network. We elaborate on how we address these issues in §4.1.

To reduce the switch time (P2), the device should refrain from exhaustive search of all carriers at all times. This requires the device to perform fine-grained control on which carriers should be scanned. It can be done by configuring the low-level mechanism for monitoring.

To make a wise selection decision (P3), the device should treat all intra-carrier handoffs and inter-carrier switches equally, and select the best carrier network. This requires the device to directly initiate the intercarrier switch when needed. This also calls for leveraging the low-level cellular mechanism.

In summary, low-level domain knowledge can be exploited to effectively address all three issues. However, the default operation mode on commodity phones does not expose such fine-grained cellular information and mechanisms to higher layers. The reason is that, the 3G/4G network follows the design paradigm of “smart core, dumb end” with the single-carrier usage scenario in mind. The end device does not need to exploit such information when selecting its carrier access. Since such low-level, cellular-specific domain knowledge is not available for the default operation mode, it might be the reason why Project Fi has not explored this direction in its current design.


  1. 多运营商接入确实有用 如 Fig. 2a 所示:

    • alt text
    • 路线 1:Sprint 信号逐渐减弱直至消失,但它的盲区被 T-Mobile 覆盖
    • 路线 2:情况相反,在 T-Mobile 信号极弱的地方,Sprint 覆盖更好
    • 具体例子:在 [160s, 180s],Sprint 不可用,手机切到 T-Mobile,保住了网络连接
    • 结论是多运营商接入能提升可用性和接入质量,Project Fi 是重要的一步
  2. P1:该切换的时候不切换

    • 现象:手机经常"卡"在一家运营商上,比如 Fig. 2a 中的 [40s, 60s] 和 [240s, 260s]
    • alt text
    • 例子:如 Fig. 2b 所示,T-Mobile 信号已经极弱(4G 低于 -130 dBm,3G 低于 -110 dBm),无论 Sprint 信号多强,手机都没有尝试切过去
    • 原因:
      • 跨运营商切换要等当前运营商完全失去服务才会触发,所以手机会先经历一段无服务,而更好的运营商其实一直可用
  3. P2:切换慢,服务中断长

    • 现象:如 Fig. 2c 所示,手机在第 140 秒开始从 Sprint 切到 T-Mobile,用了 17.3 秒才接入 T-Mobile 4G,远超常规 handoff 的几秒。用户研究中,这类中断可达几十秒甚至几分钟(见 Fig. 6)
    • 时间去哪了:Fig. 3 的事件日志给出了拆解:
      • alt text
    • 原因:
      • 大部分时间浪费在穷举扫描所有运营商的小区上,包括手机根本不会去用的 AT&T 和 Verizon
      • 这不是实现上的 bug,而是 Fi 的设计本身:先把所有网络扫完,才选择新运营商
      • 作者认为这种时延没有必要,可以在不影响选网效果的情况下降下来
  4. P3:选错网络,性能白白下降

    • alt text
    • 第 91 秒:手机离开 Sprint 4G 覆盖区,选择了 Sprint 3G,而旁边的 T-Mobile 4G 信号更强。这说明: 同运营商内的 handoff 优先于跨运营商切换
    • 结论是: 手机在大多数情况下仍然表现得像一部单运营商手机

启示:每个问题需要什么能力

(1) 解决 P1 需要感知所有运营商

  • 在当前运营商仍然可用时,只要发现更好的运营商就应该切换
  • 这要求终端在运行时了解所有可用运营商及其质量
    • 难点1: 这些信息可以从底层蜂窝事件中获得,但手机默认不这么做
    • 难点2: 简单地强制手机随时扫描其他运营商,又会导致手机暂时与当前运营商断开

(2) 解决 P2 需要控制扫描范围

不要每次都穷举搜索所有运营商,需要细粒度地控制扫描哪些运营商,方法是配置底层的监测机制

(3) 解决 P3 需要终端直接发起切换

把同运营商内的 handoff 和跨运营商切换放在同等地位,选择真正最好的网络。

这要求终端能直接发起跨运营商切换,同样要借助底层机制。

Root Cause Analysis

三个问题都可以用底层领域知识解决,但 3G/4G 遵循 "smart core, dumb end" 的范式,而且是按单运营商场景设计的!!!

终端本来不需要这些信息,所以默认模式下没有暴露给上层

作者推测,这也可能是 Project Fi 当前设计没有朝这个方向走的原因

iCellular Design

总体设计思路

(1) 为什么要在 PLMN selection 之上构建,以及要改掉什么

为了能在现有手机上逐步部署,iCellular 建立在 PLMN selection 之上,因为这是所有手机都必须支持的标准机制。但原生的 PLMN selection 本身就会导致 P1–P3,因为它是为单运营商场景设计的,有三个特征:

  • 被动触发和监测:
    • 被一家运营商服务时,不监测其他运营商,直到当前运营商失去覆盖才触发选网。这对应 P1
  • 网络控制选择:
    • 按 home 运营商预设、存在 SIM 卡里的优先级来选。这对应 P3
  • 硬切换:
    • 先从旧运营商注销,再到新运营商注册。这对应 P2

因此需要利用底层信令,把这套机制改造成适合多运营商的版本。

(2) 架构总览

alt text

  • 上层 API:Monitor()、Predictor()、SwitchTo()。
  • 中间守护进程,包含四个模块:
    • 自适应主动监测(Adaptive Active Monitor),见 §4.1
    • 自适应直接切换(Adaptive Direct Switch),见 §4.2
    • 预测服务和异构 profile(Prediction Service + Heterogeneity Profile),见 §4.3
    • 决策错误防护(Decision Fault Prevention),见 §4.4
  • 底层蜂窝接口:现有的 Manual Net Search 和 PLMN Selection 机制
    • 两个方向的数据流是:守护进程向下发命令和配置(Cmd/config),底层向上返回蜂窝事件反馈(Feedback)
    • 设计原则是在标准允许的范围内调整终端的配置和操作,不改硬件和网络,也不引入大量额外信令

(3) 各模块用到的信令事件

如 Table 1 所示,事件分为测量类(Meas)和配置类(Config):

alt text

自适应监测

解决 P1、P3 的前提:先知道有哪些运营商可选

基础机制:manual network search

在商用手机上,唯一可行的做法是复用 manual network search。它原本用于用户手动搜网:扫描邻近运营商的频段,从广播的 SIB(系统信息块,基站周期性广播的网络信息,如 PLMN ID、接入限制)中读取网络状态,并测量信号质量。这个过程只接收广播,不产生额外信令。

但直接使用它有两个问题,而且只靠应用层信息都解决不了,需要跨层适配:

  • 会打断业务:
    • 扫描其他运营商时,射频要重新同步到别的频率,这期间收发不了当前运营商的数据。
  • 天然穷举:
    • 不关心的运营商也会被扫描(比如没有漫游协议的运营商),拖慢决策,也更耗电。

对这两个 Challenges, 我们给出两个对应的 solution:

  1. 避免中断:只在 DRX 睡眠时扫描

    • 问题:要在没有业务流量时才扫描
      • 上行流量终端自己知道,但下行数据什么时候到达无法预知
      • 如果恰好在扫描别家时到达,就会延迟或丢失
    • 做法:
      • 3G/4G 的下行接收受 paging cycle 约束(4G 中叫 DRX,非连续接收)
      • 基站和终端约定一个周期,终端周期性醒来检查寻呼信道上有没有自己的下行数据,没有就继续睡眠
      • iCellular 从 RRC 配置消息里读出这个周期,只在睡眠时段扫描,这样不会打断任何寻呼
    • 可行性:
      • 如 Fig. 5 所示(一个月内 4G 单小区扫描时间的 CDF,图中竖线标出了 T-Mobile/Sprint 的 paging cycle),79.2% 的小区能在一个 paging cycle 内扫完,其余的需要跨几个周期完成。
      • alt text
    • 测量结果会不会过时:作者认为不太会
      • 一是流量大多是突发性的,空闲时间足够做后台监测
      • 二是网络性能变化平滑
      • 此外,超过时间窗(比如 1 分钟)的测量结果直接丢弃
  2. 最小化搜索:只扫感兴趣的运营商

    • 问题:manual search 没有"只扫指定运营商"的选项
    • 做法:
      1. 把感兴趣的运营商设为最高 PLMN 优先级,让它们先被扫描
      2. 同时监听蜂窝事件(每个小区的无线测量结果、带 PLMN ID 的 SIB),判断当前正在扫哪家
      3. 一旦目标运营商都扫完了,就主动终止搜索
  3. 监测与决策并行 不必等全部扫描完成。比如用户偏好 4G,扫到一个好的 4G 就可以直接决定切换,不用等 3G 的结果 iCellular 在每次有新结果时都触发一次决策回调,允许基于部分结果做决策*

直接跨运营商切换

解决 P2

  1. 切换时不再扫描

    • 问题:前面分析过,中断时间大部分来自切换时的频段扫描。
    • 做法:有了主动监测,切换前已经知道目标在哪。切换时把目标运营商设为最高优先级,然后触发 manual PLMN selection 指向它,直接切过去,跳过对其他运营商的扫描。
  2. 接近理论下界

    • 下界是多少:切换至少要从旧网注销(detach)、再在新网注册(attach)。按 TS 24.301,detach 可以不和旧网交互,时间可以忽略,所以下界约等于 attach 时间:T_switch,min ≈ T_attach
    • iCellular 的实际耗时:因为仍然基于 PLMN selection,对目标运营商本身的扫描还保留着,所以:
    • \(T_{switch,iCellular} = n_t \times T_t + T_{attach} = n_t \times T_t + T_{switch,min}\)
    • 其中 \(n_t\) 是目标运营商的小区数,\(T_t\) 是单个小区的扫描时间。这部分额外开销相对 attach 时间通常可以忽略。
    • 验证:
      • 如 Fig. 6 所示(基于一个月后台日志得到的切换时间 CDF,三条曲线分别是 Bound、iCellular、Project Fi),iCellular 的曲线基本贴着下界,而 Project Fi 明显偏右,也就是更慢
      • alt text

异构运营商的性能预测

解决 P3 中 "该选哪家"

为什么要预测:

理想情况是实测每个候选运营商的吞吐或时延再做选择,但不注册到某个运营商,就测不了它的性能,终端只能测当前服务网络。

因此改为预测:用回归树建模 y = f(x1, x2)

为什么不能只看信号强度:不同运营商的无线技术和资源配置不一样,同样的信号强度可能对应完全不同的性能

(1) 预测目标 y

  • 可选指标:可以是网络层指标(链路吞吐、无线时延),也可以是应用层指标(网页加载时间、视频卡顿时长),具体获取方法见附录 B
  • 发现:不同应用的指标往往导向同一个选网决策,因为一个运营商网络的性能特征对所有应用的影响方向是一致的

(2) 特征 x 与训练样本

  • 样本采集:训练样本在后台收集,不干扰正常使用。每当产生一个新的 y 观测值(比如物理层吞吐、一次网页加载时间、VoIP 每秒时延),就同时记录当前服务网络的 x
  • x1 是无线质量:4G 取 RSRP(参考信号接收功率),3G 取 RSCP,都来自 §4.1 的主动监测
  • x2 是网络 profile,分两类:
    • QoS profile:来自会话管理中的数据承载上下文,包括 traffic class、delay class、峰值/最大速率
    • 无线参数:来自 RRC 配置消息,包括物理层和 MAC 层配置

(3) 在线预测与更新

  • 预测:
    • 树的每个内部节点是对 x 的一个条件判断(针对无线测量或 profile 字段)。
    • 对每个候选网络估计 y,选排名最高的那个
  • 初始化:启动时加载一棵离线训练好的树
  • 更新:新样本 (x, y) 到来时:
    1. 先用现有的树算出预测值 y'
    2. 如果 |y − y'| 已经等于所在叶子的最小误差,说明样本和模型吻合,不更新
    3. 否则,寻找最能划分样本的新字段(以最小二乘为标准,最小化两个子节点的不纯度),生成一对新叶子
  • 好处:不需要永久保存全部样本,存储和计算开销都可控

决策错误防护

为什么需要防护: 让终端自定义选网策略是一把双刃剑:策略不当会导致错误切换和意外的服务中断。Fig. 7 画出了三类错误,每行表示从 Sprint 4G 切到 T-Mobile 4G 之后出的问题,而且这三类错误都只有借助底层信息才能发现

  • Failure 1:无法接入

    • 目标网络暂时拒绝接入。用户研究中观察到一个 Sprint 4G 基站因维护关闭接入 10 分钟。在 Fig. 7 第一行中,目标网络被标为 "Non-accessible"
    • alt text
  • Failure 2:无语音服务

    • T-Mobile 4G 对 Fi 用户不提供 VoLTE,打电话要通过 CSFB(电路域回落,通话时把终端退回 3G 用传统电路域打电话)。如果当地没有 T-Mobile 3G 覆盖(比如按 TS 25.304 信号低于 -95 dBm),切到 T-Mobile 4G 后就无法打电话
    • 在 Fig. 7 第二行中,CSFB 箭头指向不存在的 T-Mobile 3G,标注为 "No 3G cells exist"
      • alt text
    • Fig. 8 是用户研究中的实例:手机切到 T-4G 后拨号,拨号失败;下方的信号曲线显示当时 T-3G 没有信号
      • alt text
  • Failure 3:意外降速

    • 用户的选择未必会被目标运营商的移动性规则尊重。用户想切到 T-Mobile 4G,但在当前条件下,T-Mobile 的小区重选规则会立刻把 4G 用户推到 3G。结果既没拿到想要的网络,又白白中断了一次。
      • alt text
    • Fig. 9 的事件日志展示了完整过程:
      • alt text

防护机制:先画像,再在运行时逐个检查:

  • 画像:iCellular 先为每个运营商收集三类信息:
    • 从 RRC SIB 中取接入控制列表,用于判断 F1;
    • 从注册和位置更新消息中取数据/语音偏好配置,用于判断 F2;
    • 从 RRC 配置中取网络侧移动性规则,用于判断 F3。
  • 检查:运行时对每个候选运营商检查三个条件:
    1. 是否在禁止接入列表中;
    2. 是否只能靠 3G 提供语音,而当地 3G 质量不达标;
    3. 是否满足了它会触发进一步切换的重选条件。
    4. 只要满足任意一条,就把它从监测结果的候选列表里剔除

蜂窝事件采集

现有工具为什么不够用: 上面所有功能都依赖底层蜂窝事件,包括终端与网络之间的信令消息,以及无线质量和负载测量。其中一部分事件(比如 paging)必须实时获取。但商用手机不会把这些事件暴露给操作系统或应用。

现有的 QXDM(商用工具)和 LTEye(研究项目)都需要外接平台(笔记本或 USRP),限制了移动性,也满足不了实时性要求。

iCellular 的方案:MobileInsight。 利用基带已有的诊断模式:

alt text

  1. 在手机上开启诊断模式
  2. 修改对应的虚拟设备(需要 root)
  3. 把事件实时暴露给 iCellular

整个方案不需要改动硬件,可以在商用手机上运行

Implementation

  1. 实现平台 在两款手机上实现:

    • Motorola Nexus 6:Android 5.1,高通 Snapdragon 805;
    • Huawei Nexus 6P:Android 6.0,高通 Snapdragon 810。
    • 两款都支持 4G LTE、3G(HSPA/UMTS/CDMA)和 2G GSM,插入 Project Fi SIM 后可以接入 T-Mobile 和 Sprint 的 3G/4G
  2. 整体部署方式 iCellular 作为守护进程运行在 root 过的手机上。为了和蜂窝接口(基带)交互,需要做三件事:在 bootloader 中激活基带调试工具,打开诊断模式,打开 AT 指令接口

    • 下层是蜂窝接口(基带处理器),对外暴露两个端口:
      • AT-cmd Port(用来下发命令和配置)和 Diagnostic Mode Port(用来回传信令事件)
    • 上层是 Android OS,里面并列运行 Project Fi Service 和 iCellular Daemon
      • 守护进程内包含:Direct Switch、Active Monitor、Prediction Service + Heterogeneity Profile、Decision Fault Tolerance 和 MobileInsight
  3. 三个基础 API

    • Monitor():主动监测,对应 §4.1
    • Predictor():性能预测,对应 §4.3
    • SwitchTo():直接切换,对应 §4.2
    • 决策错误防护(§4.4)默认开启,不需要单独调用
  4. 易用性与灵活性的权衡:内置策略 基础 API 允许最灵活地自定义策略,但普通用户没必要从零写起。所以 iCellular 在 API 之上预置了三种策略,供用户直接选用:

    • prediction-based:基于预测,是默认策略
    • radio-only:只看信号强度
    • profile-only:只看运营商 profile
  5. 主动监测 Monitor()

    • 用 AT 查询指令 AT+COPS=? 发起 manual network search
    • 在此基础上,利用 Table 1 中列出的事件,实现两项适配:不打断业务(只在 DRX 睡眠期扫描),以及最小化搜索(只扫目标运营商)
  6. 直接切换 SwitchTo():实现上的关键妥协

    • 理想做法:直接用 AT+COPS=manual,carrier,network 手动指定目标运营商。但 Nexus 6/6P 的蜂窝接口禁止了这条指令。
    • 替代做法:用 Android API setPreferredNetworkType 修改首选网络制式,再通过 Project Fi 的暗码切换运营商。如 Fig. 10 所示,切换路径要经过 Project Fi Service。
    • 代价:作者承认这会带来额外的切换开销,但认为可以接受。§6.2 的结果表明,这个额外开销主要来自 SIM 卡重配置,平均约 7.3s,是切换时间的主要瓶颈。
  7. 预测服务 Predictor() 分两步实现:

    • 在线样本采集:把无线测量、RRC 配置和 QoS profile 作为特征;另外定义一个回调,用来采集网络层或应用层的性能指标 y
    • 在线回归树:用于训练和预测
  8. 决策错误防护 实现为 主动监测与基础 API 之间的一层 shim(垫片层):

    • 根据监测结果和运营商画像,识别可能导致错误切换的运营商,把它们从监测结果中剔除
    • 在 SwitchTo() 中另加一个运行时检查,禁止选择不在扫描结果里的运营商,防止用户策略绕过防护
  9. 蜂窝事件采集 直接使用 MobileInsight 内置的实时日志模块:写一个代理守护进程接管诊断端口 /dev/diag,把信令事件重定向到手机内存,供 iCellular 实时读取。

AT command

AT 全称: ATtention

一句话:AT 指令是手机"应用处理器"(跑 Android 的那颗芯片)用来给"基带"(负责打电话、上网的通信芯片)下命令的一套文本命令语言。 可以把它理解成基带的命令行接口(CLI)

(1) 为什么需要它:手机里其实有两台"电脑"

  • 应用处理器(AP):运行 Android 和各种 App
  • 基带处理器(Baseband / Modem):独立运行自己的固件,负责和基站通信,包括搜网、注册、选运营商、收发无线信号

两者是分开的。Android 想让基带做事,比如"搜一下附近有哪些运营商",就需要一种约定好的沟通方式。AT 指令就是其中最经典、最标准化的一种

写法 含义 例子
AT+XXX=? 查询这条命令支持哪些选项或取值(在 COPS 上就是"列出可选运营商") AT+COPS=?
AT+XXX? 读取当前状态 AT+COPS?(当前连的是哪家运营商)
AT+XXX=... 设置参数、执行动作 AT+COPS=1,2,"310260"(手动选某家运营商)

(2) 普通 App 无法控制"连哪家运营商",Android 不开放这个权限!!!

iCellular 通过 root 打开基带的 AT 指令端口,相当于绕过 Android,直接对基带下命令。它和另一个端口分工明确:

  • AT 指令端口负责"控制":让基带去搜网、去切运营商
  • 诊断端口(/dev/diag,MobileInsight 使用)负责"观察":实时读出基带内部的信令日志,比如 SIB、RRC 配置、paging

一个现实限制是:基带厂商或手机厂商可以决定哪些 AT 指令开放、哪些禁用,Nexus 禁用手动选网就是例子。这也是这类终端侧方案在可部署性上的一个软肋。

Discussion

议题 核心观点 具体说明
与网络侧方案协同 iCellular 虽然是终端侧方案,但可以和运营商侧机制配合,获得更好的效果 ① 网络侧帮终端:跨运营商切换期间,可以借助 网络侧对下行流量的缓存(buffering)与隧道转发(tunneling),让迁移更无缝
② 终端帮网络侧:iCellular 能把终端看到的"所有可用运营商"的 信息反馈给各运营商,改进它们自己的网络侧方案
③ 控制权边界:运营商仍保留最终决定权,可以拒绝终端发起的切换请求
对未来网络(如 5G)的设计启示 iCellular 的设计经验可以用于未来的多运营商接入设计 ① 自适应监测(§4.1)+ 直接切换(§4.2):可以作为参考,设计一种超越现有 PLMN selection 的新型跨运营商切换机制
② 异构性能预测(§4.3)+ 决策错误防护(§4.4):可以直接用于 5G
类别 代表工作 做法 / 特点 局限,或与 iCellular 的区别
网络侧:多运营商共享无线资源 [22] 运营商间网络共享的需求 trace 研究(CSWS'14)
[28] 运营商间共享主频谱 + D2D 试验(MobiCom'14 Demo)
[36] 移动网络资源共享方案对比(IEEE TWC'13)
多个运营商共享频谱等无线资源 目标是降低运营商的部署成本,属于运营商之间的合作;iCellular 从终端侧出发,不需要运营商合作
网络侧:多运营商共享基础设施 [17] 基于 EPS 解决 MVNO 问题(ICIN'11)
[18] 无线接入网虚拟化(IEEE ComMag'13)
[29] NVS 无线资源虚拟化(IEEE/ACM ToN'12)
[44] LTE 网络虚拟化(MONET'11)
基础设施共享、网络虚拟化 同上,也是网络侧、以降本为目标
终端侧:多 SIM 卡(从头设计的方案) [1] 双卡手机
[20] MOTA,运营商无关的移动服务(MobiCom'11)
用多张 SIM 卡接入多个运营商 能接入的运营商数量受 SIM 卡数量限制,受能耗和射频干扰约束,通常只有 2 张
终端侧:单张通用 SIM [14] Apple SIM
[24] Samsung e-SIM
[26] Google Project Fi
一张 SIM 卡接入多个运营商 iCellular 补充这条路线,可以增量部署;不同之处在于:①利用底层蜂窝信息;②由终端定义选网策略;③切换响应快、中断少
多物理接口:WiFi + 蜂窝 WiFi 卸载:[16] 用 WiFi 增强 3G(MobiSys'10)、[21] WiFi/LTE 多宿主性能测量(IMC'14)、[23] 经 WiFi 卸载蜂窝流量(MASS'11)
多路径 TCP:[35] 用 MPTCP 做移动网络/WiFi 切换(CellNet'12)、[43] MPTCP 拥塞控制(NSDI'11)
同时使用多个物理网络接口(WiFi + 蜂窝) iCellular 只使用单个蜂窝接口,做的是多个蜂窝运营商之间的选择
对 Project Fi 切换问题的观察 [15] 关于 Google Fi 网络切换的博客(2015) 报告了类似的切换问题 只报告了现象;iCellular 进一步找出了根因(PLMN selection 的单运营商设计)
单运营商内部的切换问题 [39] 3GPP 语音通话切换机制(IEEE ComMag'09)
[40] 切换相关的自组织机制交互(MSWiM'14)
[45] 飞蜂窝与宏蜂窝间的切换(ICCSN'10)
研究同一运营商内的 handoff 问题 这些问题源于运营商自身的管理不当;iCellular 针对的是跨运营商迁移,并让终端自定义选网策略

iCellular 的定位总结: 终端侧、单张通用 SIM、单个蜂窝接口、基于底层信令,与现有 3G/4G 标准兼容、可增量部署。

Conclusion

The current design of cellular networks limits the device’s ability to fully explore multi-carrier access. The fundamental problem is that, existing 3G/4G mobile networks place most decisions and operational complexity on the infrastructure side. This network-centric design is partly inherited from the legacy telecom-based architecture paradigm. As a result, the increasing capability of user devices is not properly exploited. In the multicarrier access context, devices may suffer from low-quality access while incurring unnecessary service disruption. In this work, we describe iCellular, which seeks to leverage the fine-grained cellular information and the available mechanism at the device. It thus dynamically selects better mobile carrier through adaptive monitoring and online learning. Our initial evaluation validates the feasibility of this approach.

  1. 背景(BGD)

    • 单一运营商无法做到处处覆盖、处处最优,于是 Project Fi 这类"一张 SIM 接多家运营商"的方案出现了
    • 但它的跨运营商切换只能复用为漫游设计的 PLMN selection
      • 这套机制按"智能在网络、终端只管执行"(smart core, dumb end)和单运营商的前提设计:被动触发、按运营商预设优先级选网、先注销再注册的硬切换
  2. 问题与动机(Problem & Motivation) 多运营商接入的收益被严重打折,具体表现为三类问题:

    • P1 不切: 当前运营商信号极弱也不切换,直到掉线 ("选择固执")
    • P2 切得慢: 穷举扫描所有运营商,一次切换中断 17s 以上 ("暴力扫描")
    • P3 切错: 宁可降到本运营商 3G,也不选信号更强的另一家 4G ("选择粘性")
    • 这些问题的根源在架构本身,而不是实现 bug。等 5G 重新设计要很多年,而现有 3G/4G 用户此刻就在承受掉线和降速,所以值得在现有网络上立即解决
  3. 方法论(Key Insight + Methodology + Design)

    • Key Insight:只有终端能看到所有运营商的全局视图
      • 三个问题都可以借助 终端基带里本就存在、但默认不暴露的底层信令(SIB、RRC 配置、QoS 承载等)来解决
    • Methodology:不改网络和硬件,在标准允许的范围内,对 PLMN selection 做跨层改造
    • Design:通过诊断口实时获取信令,在此基础上构建四个模块
      • DRX 睡眠期定向扫描:只在睡眠时段、只扫目标运营商,解决 P1
      • 直接切换:跳过扫描,切换时间逼近 attach 下界,解决 P2
      • 在线回归树预测:用"信号强度 + 稳定的运营商 profile"预测各运营商性能,解决 P3
      • 错误防护:剔除无法接入、无语音、会被网络重选降级的候选运营商,防止切错