LTE-M, NB-IoT & Cellular Embedded Development

Cellular IoT firmware for LTE-M, NB-IoT, and CAT-1 modem integration — from AT command modem control and PSM power optimization to SIM provisioning, carrier certification, and worldwide deployment with eSIM and multi-IMSI management.

Platform engineering
Platform Capabilities

What We Build on This Platform

LTE-M & NB-IoT Modem Integration

AT command control of u-blox SARA-R4/R5, Quectel EC21/EC25, SIM7080G, and Nordic nRF9160 modems for LTE-M and NB-IoT connectivity, with hardware flow control and URC handling for production firmware stability.

PSM & eDRX Power Optimization

Power Saving Mode (PSM) and Extended Discontinuous Reception (eDRX) configuration for multi-year battery life on cellular IoT sensor nodes, with current measurement validation against carrier-granted timer values.

eSIM & Multi-IMSI Management

eSIM (eUICC) provisioning, profile switching, and multi-IMSI management for global deployment without physical SIM logistics, using GSMA M2M SGP.02 architecture with SM-DP platform integration.

Carrier Certification Support

PTCRB, GCF, and carrier-specific certification (AT&T IoT, T-Mobile, Verizon) for LTE-M and NB-IoT devices entering commercial deployment, including RF band configuration and IMEI registration.

CoAP & DTLS for NB-IoT

CoAP application protocol with DTLS 1.2 for constrained NB-IoT devices where TCP and TLS overhead exceeds the link budget and power budget, including block-wise transfer for firmware payloads.

FOTA over Cellular

Firmware OTA update via cellular with resume-on-disconnect, block verification, streaming flash programming, and FOTA campaign management with rollout control for safe fleet-wide firmware updates.

Band Lock & Network Selection

Band configuration for the target deployment region, PLMN selection, network scan, and automatic network reselection for roaming deployments, including LTE-M to NB-IoT fallback configuration.

nRF9160 SiP Integration

Nordic nRF9160 system-in-package integration with LTE-M/NB-IoT modem, GNSS, and ARM Cortex-M33 application processor — including modem firmware update, LTE link controller API, and nRF Cloud integration.

Platform Integration

How Ankh Uses This Platform

01

Technology Selection: LTE-M vs. NB-IoT vs. CAT-1

LTE-M is selected for mobile or roaming devices — fleet telematics, asset tracking, mobile worker devices — that require handoff between cell towers, voice capability, or higher uplink data rates above 300kbps. NB-IoT is selected for stationary low-data-rate sensors that prioritize maximum battery life, deep indoor penetration, and low module cost; NB-IoT's narrowband operation provides 20dB additional penetration gain over LTE-M in basement and underground deployments. CAT-1 is selected for applications requiring higher throughput, full duplex voice and data, or when the deployment region's carrier has deployed LTE-M/NB-IoT incompletely. Coverage availability for the specific deployment region and carrier is verified against carrier coverage maps and, for critical deployments, with an on-site modem scan before hardware design commits to the technology choice.

02

Modem Selection & Hardware Integration

Module selection is made from u-blox SARA-R410M for LTE-M with established AT command documentation, Quectel EC21 for CAT-1 with integrated GNSS option, SIM7080G for LTE-M and NB-IoT with integrated GNSS on a single module, or Nordic nRF9160 SiP for designs requiring the application processor and LTE modem on a single package. UART interface with hardware flow control RTS/CTS is mandatory for modems that produce large AT responses or URCs during data sessions. Power supply sequencing is designed for the modem's power rail requirements including VCC, VREF, and power-on hold timing. SIM socket design selects between nano-SIM holder for prototypes and MFF2 solder-down form factor for production deployments in harsh vibration environments.

03

PSM & Power Budget

PSM T3412 periodic TAU timer and T3324 active time timer are configured to match the product's reporting interval, with acknowledgment that the carrier may grant different timer values than requested. eDRX cycle value is configured for the balance between paging reception latency and sleep current in applications that require periodic downlink reachability. Current profile is measured on the final hardware at each modem state: PSM sleep current (typically 3-8µA for the modem module), eDRX sleep current, idle registered current, and active data session peak current (40-200mA for LTE-M burst transmission). Battery capacity is calculated from the measured current profile at the carrier-granted timer values, with a derating factor for battery capacity loss at the minimum operating temperature of the deployment environment.

04

Protocol & Security Stack

TLS 1.3 versus DTLS 1.2 selection is made based on transport protocol: TCP connections to MQTT or HTTPS brokers use TLS, UDP-based CoAP uses DTLS. Modem-offloaded TLS is used when the modem supports it — u-blox SARA-R5 and Nordic nRF9160 both support TLS offload, which eliminates the 50KB TLS handshake buffer requirement from the application MCU. AT command sequence for TLS context configuration, CA certificate upload to modem flash, and client certificate provisioning is implemented and tested against the production cloud endpoint. MQTT over TLS is implemented with keepalive tuned to the PSM active window duration, so the keepalive exchange completes within the T3324 active time before the modem enters PSM.

05

Carrier Certification & SIM Provisioning

PTCRB and GCF certification paths are initiated early in the hardware design phase because the certification timeline — typically 8-16 weeks for a new product — must be accounted for in the product launch schedule. RF band configuration is validated for the specific carrier's LTE-M and NB-IoT band plan. SIM provisioning flow is designed for the production volume: carrier SIM in bulk from the carrier's IoT portal, or eSIM profile provisioning from the eSIM management platform (Transatel, KORE, Aeris, or Tele2 IoT) at the factory programming station. APN configuration is validated for each carrier's IoT data plan, since IoT APNs often have different routing, firewall, and NAT behavior than consumer APNs. IMEI registration requirements for MVNO SIM deployment are addressed before SIM cards ship to the factory.

Engineering Depth

Deep Technical Capability

01

PSM Timer Negotiation and Battery Life Calculation for Cellular IoT

PSM operates through a two-timer negotiation: the device requests T3412 (periodic TAU interval, up to 186 hours) and T3324 (active time after registration, 0 to ~620 seconds) via the NAS Attach or TAU Request message. The network responds with granted timer values that may differ from the requested values — some carriers do not support T3324 values shorter than 60 seconds, and some networks cap T3412 at 24 hours despite the specification permitting 186 hours. A device designed for a 1-hour reporting interval with a 10-second active window may receive a 60-second active window from a carrier enforcing a minimum T3324, increasing average current by a factor of six and reducing battery life from three years to six months. This is invisible in a development lab using a test network SIM that grants short T3324 values production network cells reject. Ankh measures granted PSM timer values on the actual carrier network in the deployment region using a production SIM on the production APN, designs firmware to operate correctly at the worst-case granted values, and calculates battery life from the measured current profile at those granted timers — not from the requested values in the datasheet.

02

eSIM Profile Management for Global Cellular IoT Deployments

Consumer eSIM follows the GSMA RSP architecture (SGP.22), where profiles are managed through a Local Profile Assistant on the device and downloaded from an SM-DP+ server via a QR code or activation code. IoT eSIM follows the older GSMA M2M architecture (SGP.02), which is designed for devices without a display or user interaction: profiles are managed by a remote Subscription Manager Data Preparation (SM-DP) server, and profile switching is executed via AT commands to the eUICC through the modem. Multi-IMSI is a distinct mechanism: rather than downloading a new profile, the SIM presents a different IMSI to the network by switching between multiple IMSI ranges programmed into a single profile, enabling seamless carrier switching without any AT command interaction or SM-DP server transaction. For a global deployment where devices are manufactured in Shenzhen and deployed in Germany, Brazil, Japan, and the United States, multi-IMSI removes the SIM logistics problem entirely: the same physical SIM, programmed at the factory, selects the best available carrier in each country based on network scan results. Ankh designs the eSIM provisioning flow including SM-DP platform selection, factory programming AT command sequence, multi-IMSI roaming logic in firmware, and profile lifecycle management for the product's 10-year deployment horizon.

03

AT Command Modem Control Reliability in Production Firmware

AT command interfaces are documented as simple request-response: send AT+COMMAND, receive OK or ERROR. Production firmware reveals the complexity documentation obscures. AT commands with network interaction — CEREG polling, socket open, data send — have timeout behaviors ranging from 100ms to 300 seconds depending on network conditions; a naive implementation that waits indefinitely will block the application for minutes during an outage. Unsolicited result codes (URCs) arrive asynchronously at any time, including during the window between an AT command transmission and its response: a +CREG URC mid-response breaks a parser expecting the response to be the next line after the command echo. After a power glitch the modem may enter an undefined AT state that does not recover from ATZ and requires a hardware reset via the power-on pin, with a mandatory delay between assertion and deassertion that varies by module and is sometimes incorrectly documented. Ankh implements a state machine AT command engine with a dedicated UART receive task, URC dispatch to registered handlers, hardware flow control to prevent FIFO overflow during large AT responses, and a watchdog-supervised modem reset sequence that recovers from hang without a full device power cycle.

01

Cellular firmware tested against real carrier networks, not modem simulators

Modem simulators and carrier test networks grant PSM timer values and network registration behaviors that differ from production carrier network cells in the actual deployment region. A firmware design that achieves 3-year battery life in the lab against a test network granting 10-second T3324 active time may achieve 8-month battery life in production against a carrier that enforces 60-second minimum T3324. Ankh tests cellular firmware against production SIMs on production carrier networks in the target deployment region before hardware is committed to production, measuring granted timer values, data session setup latency, and URC behavior under real network congestion — not against documented specifications that don't reflect live network policy.

02

PSM power budgets calculated from measured timer grants, not datasheet estimates

Battery life calculations for cellular IoT products are only as accurate as the current measurements and timer values they are built from. Module datasheets provide PSM sleep current for ideal temperature and supply voltage conditions; production hardware adds PCB regulator efficiency losses, temperature derating at the deployment environment's minimum temperature, and the current overhead of the application MCU keeping the modem powered during the T3324 active window. Ankh builds the power budget from current measurements on the final PCB at the minimum and maximum operating temperature, using the carrier-granted timer values measured on the production network, with explicit accounting for battery capacity derating at temperature — producing a battery life estimate with an engineering basis rather than a marketing basis.

03

eSIM deployments that survive carrier network changes without a truck roll

Deploying thousands of IoT devices with physical SIM cards creates a logistical liability: when a carrier terminates an IoT service tier, changes APN routing, or exits a market, every device in the field requires a SIM swap that costs $50-100 per device in labor. Ankh designs eSIM provisioning and multi-IMSI roaming architectures that allow carrier profile changes to be executed remotely via the SM-DP management platform, with firmware AT command sequences that switch profiles or IMSI ranges without on-site access. The provisioning architecture is designed from the initial hardware bring-up, because adding eSIM capability to an existing cellular product design often requires modem module replacement — a costly late-stage change.

Connected Expertise

Related Platforms & Services

Quote your project

Ready to build on this platform?Let's get the implementation right.