
This particular 9926 BBUv2 represents the pinnacle of Alcatel-Lucent’s LTE RAN portfolio, being fully-loaded with a bCAM2 controller/modem board and three bCEM2 modem boards. Alcatel introduced these this eNodeB in early 2015 touting a 260% increased capacity while reducing power usage by 50% over previous generations. This top-of-the-line configuration supported 24 20MHz LTE cells, up to 16,000 users, and was designed for “a smooth transition… to a 5G family of solutions”.1
Sharp-eyed readers will notice the mixed branding on the left. Nokia purchased Alcatel-Lucent (ALU) in early 2016 for €15.6 billion.2 Alcatel RAN products survived for a few years before being killed in favor of Nokia’s competing AirScale line.3 Needless to say, the Alcatel transition-to-5G promise was never fulfilled.
Building Blocks
The 9926 BBU is a 2U rack-mount chassis holding power, mechanicals, and four slide-in boards. Each board is either a “Core Controller Module” (CCM) with responsibility for timing, synchronization, backhaul handling, core network communication, and operations-and-management (OAM), or a “Channel Element Module” (CEM) handling baseband processing and radio protocol L1/L2. The most recent controller board, 2015’s bCAM2 (“Controller And Modem”), combines both functions in the same unit.4
Distributed Digital Unit (d2U)
The chassis itself, or Distributed Digital Unit “shelf” (“d2U” for short)5 connects all the building blocks together. Its right-hand side holds a slide-in power supply unit (PSU) while the rest of the shelf holds the CEM and CCM boards. At the back is the Rack Back Plane (RBP) which routes Gigabit Ethernet and HSSL between the slide-in boards, and power between the boards and power supply unit (PSU). It also routes 1-wire alarm signaling and inventory data between the CCM board and the PSU.
Alcatel produced five revisions of the d2U shelf which progressively expand the backplane signaling capacity to support more capable CCM and CEM boards. The 9926 BBU uses d2U versions 3, 4, or 5 while earlier versions were used with the 9326 UMTS nodeB product from which the 9926 evolved. v5 specifically adds another set of high-speed links for all boards and physical connectors for a second CCM board.
Documentation claims up to two identical CCMs can be installed in a v5 d2U, with one CCM board in the bottom slot and a second in the top slot. This allows three configurations: dual-technology (eg WCDMA + LTE), controller redundancy (fail-over to backup CCM), and RAN sharing (two active CCMs).6 All examples I’ve seen have only a single CCM so it’s unclear how often this capability was used in the field, or if was ever actually shipped.
Power Supply Unit
The slide-in PSU (also called a “Rack User Commissioning” (RUC) unit) contains two integrated fans, two RJ-45 alarm connectors, and some flash memory used for inventory management and commissioning.7 One RJ-45 alarm port connects to the CCM board’s alarm port and the other to an optional external alarm aggregation module. The PSU comes in either -48V or -24V variants, though TDD BBUs only support -48V for some reason.
ALU’s BBUs are unique in that the power supply’s footprint extends well beyond the chassis and that the PSU/alarm signaling requires a cable rather than being handled via the backplane like similar generation BBUs from Nokia, Samsung, and Ericsson. ALU also chose a left/right airflow pattern like Samsung, in contrast to Nokia and Ericsson’s front/back designs.
Board Generations
The 9926 BBU was the last of ALU’s compact d2U RAN product line which spanned a decade of evolution from GSM/CDMA to UTMS and LTE. From the mid-2000s until 2015 ALU upgraded CCM and CEM boards about every two years to increase capability and capacity. The increase in processing power and density grows quite rapidly after 2010, perhaps to enable the continuous evolution of LTE standards, the march to 5G, and the marketing arms race.
Alcatel remained loyal to Freescale’s PowerPC products for the life of the 9926. Many Alcatel remote radios included Freescale PowerPC SoCs for control and management.8 Other RAN vendors like ZTE9 and Ericsson10 occasionally used Freescale SoCs but as far as I can tell were not as dedicated to the cause.
My focus here is the 9926 BBU, its associated boards, and RRHs. Earlier boards such as the iCCM/iCCM2 exist but are GSM/UMTS-only and don’t appear to run Linux.
| Year | Board | SoC | Specs | SoC TDP | Arch |
|---|---|---|---|---|---|
| 200811 | xCCM-U | 1 x MPC8555 (130nm) | 1c @ ~1GHz | 13W12 | ppc32 |
| 201013 | eCCM-U | 1 x MPC8548 (90nm) | 1c @ 1.5GHz | 13W14 | ppc32 |
| 201215 | eCCM2 | 1 x P4080 (45nm) | 8c @ 1.5GHz | <30W16 | ppc32 |
| 2015 | bCAM2 | 3 x B4860 (28nm) | 4c/8t @ 1.6GHz | ~38W17 | ppc64 |
Until the final bCAM2 generation, only CCM boards had SFP cages for CPRI links to remote radio units. They also had connectors for a GPS antenna, local ethernet management ports, RS232 serial ports, backhaul Ethernet ports (SFP and RJ45, and E1/T1 for the eCCM and xCCM), and alarm connectors. CEM boards usually had only local ethernet management and RS232, with radio traffic apparently routed from CPRI ports on the CCM over the backplane’s HSSL links to the CEM, processed by the DSPs there, and then back to the CCM. Curious choice; contemporary Nokia, Ericsson, and Samsung setups handled CPRI on modem boards, not control ones.
The bCEM2 board finally breaks with tradition by including six SFP cages for direct CPRI links, and the bCAM2 is even more capable. It combines a CCM and a CEM into a single board with a whole bunch of compute and DSP. According to Wikipedia each thread of the bCAM2’s Freescale B4860 performs as well or better than one core of the eCCM2’s P4080, giving the bCAM2 a 3x compute advantage. Which is probably where ALU gets their “260% increased capacity” marketing bullet point and the “designed for 5G” tag.
While it’s impressive that a top-of-the-line 9926 packed 48 efficient dual-threaded cores between the bCAM2 and three bCEM2s, the Freescale B4860 compared poorly to a contemporary Intel Xeon E3-1230L v3 in raw compute18 and has about 5x slower single-core performance than an Apple M4 Pro.19 But raw compute wasn’t really the point because it’s not efficient for an eNodeB’s main job: signal processing. The B4860 instead made up the difference by hardening logic into silicon with all the onboard I/O, accelerators, and DSP cores. Xeons included none of that and would have required multiple discrete ICs to match the 4860’s capabilities, increasing power and cost.
Storage
Main storage resides on eUSB for eCCM2, bCEM, bCAM2, and bCEM2 boards. The older eCCM control board uses CompactFlash while its sibling eCEM modem uses NOR flash for all storage.
| Board | Main Storage | Boot Storage |
|---|---|---|
| bCAM2 | 4GB eUSB | 8MB NOR |
| bCEM2 | 2GB eUSB | 8MB NOR |
| eCCM2 | 4GB eUSB | 8MB NOR |
| bCEM | 2GB eUSB | 64MB NOR |
| eCCM | 1GB CompactFlash | 8MB NOR |
| eCEM | 256MB NOR | (same as main) |
Partitions
Alcatel’s OS uses two partitions: active software at /ffs0 and passive at /ffs1. This allows failsafe upgrades by installing the update to the passive partition, upgrading the database and configuration, and finally rebooting into the updated partition. If the updated software is unable to boot, the board will eventually reboot to the known-good partition. It also allows easy switching to a second RAN technology with just a reboot, though it seems unlikely an actual provider would do this.

The “store” partition contains home directories for administrative users (initial_nem, enb0dev, swFileXfer, etc), modem board software updates, configuration data, and log files. Later boards have an “scd” partition stores security-related info like certificates, IPsec and sshd configuration, backup shadow password files, and security-related log files.
NOR Flash
Initial boot begins by executing U-Boot from the NOR flash which trains the DDR, initializes some basic hardware, loads U-Boot into RAM, executes it, and eventually loads Linux from main storage. All boards have active and passive U-Boot areas for update resilience as with the dual main OS partitions. Beyond these U-Boot areas, layout evolves for each generation of hardware.
The original eCCM control board has 6MB of unused space, while its sibling eCEM modem board stores everything in 256MB of NOR flash (including the OS and configuration databases) that other boards store on CompactFlash or eUSB.
The subsequent eCCM2 adds a temporary area and a Release Configuration Word (RCW) area, which contains settings like DDR timing, voltage levels, interconnect frequencies, and other hardware properties.
Finally the bCAM2 and bCEM2 split the RCW area into active and passive (just like U-Boot and the OS) and add new environment storage and inventory management areas. These changes appear to show an intentional progression of update robustness engineering and a recognition that some hardware-level settings (eg RCW) need to change between different OS versions.
Defined by Software?
Firmware files, Linux logs, and early product roadmaps refer to the bCAM2 as SD-CAMLR (Software Defined Controller And Modem – lightRadioTM), playing up the flexible architecture’s support of multiple radio standards on the same hardware. Though marketing documents used “software-defined” for the earlier control and modem boards as far back as 2010, the new claim makes a bit of sense if you squint real hard.
Each of the bCAM2’s StarCore 3900FP DSP cores (six per B4860 SoC so 18 per board) is at least twice as fast as each StarCore 3850 DSP core in the older bCEM (three MSC8156 DSPs20 with six cores each thus also 18 per board) and adds floating-point functions too. Plus the bCAM2 has 3x more CPU cores and its FPGA has 42% more gates (355k) than the older eCCM2’s (251k).
I guess you could say that’s more software-defined than before? Maybe?
Yeah, Software
Major software updates rolled out about every year with different builds for each RAN technology and hardware variation. UMTS, LTE FDD, and LTE TDD variants followed different schedules and packaging until 2013 when they were somewhat unified in response to competitive pressure during the converged RAN craze of the early 2010s21. What was previously LA7.0 (FDD) and TLA7.0 (TDD)22 in product roadmaps combined, at least in name, to become LR13 in 2013.23
Even within LTE the TDD builds lagged the FDD ones until 2012’s LA5 when Alcatel was able to converge the schedules, if not the actual software builds.24 Like Nokia at the time, FDD and TDD variants continued to be separate installs and the BBU had to pick which mode to boot into, though at least Nokia resolved that problem by 2016 with their “Single RAN” (SBTS) software releases.
| Release Train | RAN Technology | Years Active |
|---|---|---|
| UA4.x – UA9.x | UMTS | 200425 – 2012 |
| (T)LA1.x – (T)LA6.x | LTE FDD & (T)DD | 200926 – 2013 |
| LR13.x – LR17.x | LTE & UMTS | 2013 – 2019 |
Recent release naming follows a year-based scheme with an “LR” prefix (remember, LightRadio!). For example, LR13 was released at the end of 2013. A sub-version number followed to indicate point-releases, such as LR13.1 or LR13.3. Finally, the technology was indicated at the end with a G (GSM/GPRS), W (WCDMA/UMTS), or L (LTE) giving a full version string like LR13.3.W or LR16.1.L.
Major releases ceased in 2017 with the LR17 series, presumably because it made business sense for Nokia to move everyone to AirScale hardware. Maintenance updates of LR16 and LR17 continued sporadically through late 2019, and technical support ended in late 2021.27

OS Heritage
eCCM and eCCM2 boards use 32-bit PowerPC processors thus their kernel and userland are also 32-bit. They both run a 2.6.x grsecurity-enhanced kernel, while their companion eCEM and bCEM modem boards run the same kernel with PREEMPT_RT enabled. These older boards’ software is based off Wind River Linux 5 from 2014 and was never rebased including their terminal LR17 release in 2019.
The newest bCAM2 and bCEM2 boards, owing to their shared modem functionality, both run a 3.10.55-based kernel with PREEMPT_RT enabled. Since they use 64-bit processors their kernel is 64-bit but Alcatel opted to keep the 32-bit userland rather than use multi-arch or full 64-bit everywhere. These boards’ software is based off Wind River Linux 6.0.0.14 from November 2014 and Nokia does not appear to have upgraded to subsequent Wind River Linux versions as the terminal LR16.x releases from 2017 (FDD) and 2019 (TDD) are still built from the same 6.0.0.14.
Regardless of the base OS’s WindRiver heritage, upgrades use Debian packages as the source of software installation, even if the base OS is not a Debian system. Any ppc32 Debian package from before the multi-arch change in 2012 and Wheezy’s switch to XZ compression can be installed with dpkg --admindir=/active/config/db. Wheezy chroots created with debootstrap work and allow running newer software.
While the OS uses the standard /sbin/init process it only manages a small set of services with it, instead using a custom /bin/launcher similar in scope to systemd for all critical system services. /bin/launcher manages a service’s environment, CPU affinity, cgroups, termination behavior, required kernel modules, and more, and provides an RPC interface to the rest of the system.
What Comes Next?
Next we’ll take an in-depth look at the bCAM2 and bCEM2 hardware and dive a bit further into Alcatel-Lucent’s RAN software. Stay tuned…
Footnotes and Sources
- Alcatel-Lucent. Alcatel-Lucent introduces LTE radio access network portfolio to transition operators smoothly to next-generation technologies. PR Newswire, 2015. ↩︎
- Nokia. NOKIA AND ALCATEL-LUCENT TO COMBINE TO CREATE AN INNOVATION LEADER IN NEXT GENERATION TECHNOLOGY AND SERVICES FOR AN IP CONNECTED WORLD. Nokia, 2015. ↩︎
- The last release of software for eCCM & eCCM2 boards was LR17.1, a maintenance release built in mid-2018. The last release for bCAM2 boards was LR16.1 MNCL4, a maintenance release built in late 2018. No new 9926 hardware was released after the bCAM2/bCEM2 in early-2015, right before the Nokia acquisition. Nokia’s 2015-era AirScale ASIA modules, however, received regular software releases through 2025 and possibly later. ↩︎
- Alcatel-Lucent. Alcatel-Lucent 9926 BBUv2 (Base Band Unit) Product Description. Document number CMN/BTS/INF/032451 issue 1.06. Alcatel-Lucent, 2014, p. 15. ↩︎
- Alcatel-Lucent. 9400 LTE RAN TLA3.0-LA4.0 Technical Overview STUDENT GUIDE. Document number TMO18213_V4.0-SG Edition 10. Alcatel-Lucent, 2012, section 1, module 3, p. 12-13. ↩︎
- John Ozkurt. Alcatel – Lucent’s LTE Solutions Overview. Alcatel-Lucent, 2011, slide 8. ↩︎
- Alcatel-Lucent. 9400 LTE RAN TLA3.0-LA4.0 Technical Overview STUDENT GUIDE.Document number TMO18213_V4.0-SG Edition 10. Alcatel-Lucent, 2012, section 1, module 3, p. 15. ↩︎
- Per inspection of RRU firmware, the main SoC was often lower-end PowerQUICC chips like the MPC8313 or MPC8343. ↩︎
- Freescale Semiconductor. ZTE Chooses Freescale’s QorIQ Qonverge B4860 SoC for LTE-Advanced Base Stations. BusinessWire, 2015. ↩︎
- Freescale’s MPC8308 is used in the TPS 0601 Transponder Unit SFP and the QorIQ P2020 is the main processor in the PMU 0101 Photonics Management Unit, per firmware analysis and visual inspection. ↩︎
- Alcatel-Lucent. Alcatel-Lucent 9326 digital 2U V2 Node B Product Description. Document number UMT/BTS/INF/024277 issue 2.0. Alcatel-Lucent, 2008, p. 15. ↩︎
- Freescale Semiconductor. MPC8555E PowerQUICC™ III Integrated Communications Processor Hardware Specification. Freescale Semiconductor, 2005, p. 12. ↩︎
- Alcatel-Lucent. Alcatel-Lucent 9926 Digital 2U eNode B BASEBAND UNIT. Document number CPG1649091104. Alcatel-Lucent, 2010, p. 2. ↩︎
- Freescale Semiconductor. MPC8548E PowerQUICC III Integrated Processor Hardware Specifications. Document number MPC8548EEC revision 10. Freescale Semiconductor, 2014, p. 15. ↩︎
- Mingho Ling. RADIO ACCESS NETWORK HARDWARE PRODUCT PORTFOLIO. Alcatel-Lucent, 2012, slide 9. ↩︎
- Freescale Semiconductor. QorIQ™ P4080 Communications Processor Product Brief. Document number P4080PB revision 1. Freescale Semiconductor, 2008, p. 3. ↩︎
- diankuixu. “Need suggestion about B4860 vdd power supply.” NXP community forum, 20 November 2018. https://community.nxp.com/t5/Qonverge/Need-suggestion-about-B4860-vdd-power-supply/m-p/850380 ↩︎
- R. Clauberg and R.P. Luijten. DOME Microserver: Performance Evaluation of suitable processors. Rolf Clauberg, 2017, p. 10. ↩︎
- 7z single-core compress benchmark R/U MIPS for the B4860 @ 1.6GHz was measured at 915 versus an M4 Pro @ 4GHz was measured at 9227, yielding about 5x difference when taking clock speed into account. Decompress was measured at 1536 vs. 8171, yielding about 2.5x difference when taking clock speed into account. ↩︎
- Alcatel-Lucent. LA5/LA6 capacity & bCEM. Alcatel-Lucent, 2011, slide 3. ↩︎
- Al Williams. LTE Competitive Analysis Huawei’s LTE RAN. Alcatel-Lucent, 2010, slide 7. ↩︎
- Alcatel-Lucent. LTE SOLUTION ORANGE QAD PLM. Alcatel-Lucent, 2012, slide 13. ↩︎
- Nokia. GDR technical bulletin for LTE_A eNodeB Secure Software Upgrade. Nokia, 2017, slide 3. ↩︎
- Alcatel-Lucent. LTE SOLUTION ORANGE QAD PLM. Alcatel-Lucent, 2012, slides 13 & 23. ↩︎
- Alcatel-Lucent. Iub Transport Engineering Guide. Document number UMT/IRC/APP/0164 issue 12.01/EN. Alcatel-Lucent, 2013, p. 6. ↩︎
- Alcatel-Lucent. RF Troubleshooting Guideline LA1.1. Document number LTE/IRC/APP/032278 issue V01.03/EN. Alcatel-Lucent, 2010. ↩︎
- Nokia. GDR Technical BULLETIN; LTE_A eNodeB Secure Upgrade Release LR15.1L & LR16.x.L. Edition 17.2. Nokia, 2017, p. 1. ↩︎
