Skip to content

Interfaces

Summary
  • Establishing a PDU session (or, in LTE, a PDP context) over the air only gets IP connectivity as far as the modem — that connectivity still has to reach whatever actually wants to use it: a laptop's OS, an embedded Linux board, or the application processor inside a phone talking to its own onboard baseband chip.
  • ECM, RNDIS, NCM, MBIM, and QMI/RmNet are the different standards (mostly USB-based) that solve this exact problem — each making the modem's data connection show up as something the host's networking stack already understands.
  • They're not really competitors so much as a lineage: NCM is ECM's more efficient successor, MBIM is NCM plus a proper cellular control channel, and RmNet is Qualcomm's own high-throughput answer to the same problem.1

Think of these as:

"Translators — each one takes 'I have an active cellular data session' and translates it into a shape the host OS's ordinary networking stack already knows how to drive, whether that shape is 'pretend Ethernet card' or something purpose-built for cellular."

If you are confused...

This page picks up exactly where the air-interface side of this site leaves off — a PDU session or PDP context is the result the modem gets over the network; everything here is about getting that result out of the modem and onto whatever's asking for it. It also connects directly to two items on the Embedded roadmap: AT Commands (the older, text-based sibling to the binary control protocols below) and USB Device (since almost everything on this page is a specific kind of USB device class).

The AP/Modem Split

In almost every cellular device — a USB dongle, an embedded module soldered onto a carrier board, or the baseband chip inside a phone — the part that actually speaks NR/LTE to the network is a separate processor from the one running your applications or OS. That link between them (commonly USB, sometimes PCIe) needs a standardized way to carry two different kinds of traffic:

  • Control — commands and status: register on the network, activate a data session, check signal strength, manage the SIM
  • Data — the actual IP packets flowing in and out of that data session

Every protocol on this page is really just a different answer to "how do I carry those two things over this physical link, in a way the host's existing OS drivers already understand?"

The Interfaces at a Glance

Interface Origin Introduced Host Support Multi-Session Linux Driver
ECM USB-IF (CDC subclass) 2007 (Linux) Broad, generic No cdc_ether
RNDIS Microsoft (built on NDIS) ~2001 Native on Windows No rndis_host
NCM USB-IF (CDC subclass) 2010 (Linux) Broad, generic No cdc_ncm
MBIM USB-IF + Microsoft 2012 (with Windows 8) Native on Windows 8+ Yes cdc_mbim
QMI + RmNet Qualcomm 2012 (Linux qmi_wwan) Linux-native, Windows via vendor driver Yes qmi_wwan

Table 1. Modem-to-Host Interfaces at a Glance

ECM (Ethernet Control Model)

CDC-ECM is one of the original USB-IF Communications Device Class subclasses — it makes the modem present itself as a generic Ethernet network adapter. It's simple and widely supported, but it has two real limitations for cellular use: it carries no cellular-specific signalling of its own (network registration, session activation, and so on all have to happen out-of-band, typically over AT commands), and it has known latency issues at higher throughput.2

RNDIS

RNDIS (Remote NDIS) is Microsoft's protocol for making a USB device look like a network adapter to Windows' NDIS (Network Driver Interface Specification) stack — the same interface real Ethernet/Wi-Fi cards use internally. Because it's native to Windows, a lot of consumer USB dongles default to it for the "it just works, no driver install" experience. The tradeoff: it's tightly coupled to Microsoft's own driver model, and Microsoft's own specification documentation has historically been incomplete, with real Windows implementations issuing requests outside what's documented — which makes RNDIS a genuinely harder protocol to implement correctly on non-Windows systems, even though Linux, FreeBSD, NetBSD, and OpenBSD all support it.2

NCM (Network Control Model)

CDC-NCM is USB-IF's follow-up to ECM, designed specifically to fix ECM's throughput and latency problems — it can pack multiple network packets into a single USB transfer instead of one-packet-per-transfer, which matters a lot once data rates climb into LTE/5G territory. Like ECM, though, it's still not cellular-specific on its own — no built-in session/PDN management, no SIM or signal status. That's exactly the gap MBIM fills.

MBIM (Mobile Broadband Interface Model)

MBIM is best understood as NCM's efficient data path, plus a proper cellular control channel bolted on.3 It was introduced alongside Windows 8 in 2012, jointly with USB-IF, specifically to give mobile broadband devices a standardized, vendor-agnostic model — one Windows (and other OSes) could drive with a single generic driver, instead of every vendor needing a custom one. Beyond IP data, MBIM's control channel also covers SMS, USSD, SIM toolkit interactions, and — critically — multiple simultaneous sessions, so one physical modem can expose more than one active PDN/PDU session at once over a single USB connection.1

Qualcomm's Stack: QMI + RmNet

On Qualcomm-chipset devices — which is most of the cellular module market — the dominant pairing is QMI for control and RmNet for data:4

  • QMI (Qualcomm MSM Interface) exposes a control character device (/dev/cdc-wdm0 on Linux) that userspace tools like libqmi/mmcli talk to — activating sessions, checking registration status, managing the SIM — without needing AT commands at all.
  • RmNet is the actual high-throughput data path underneath, using a framing scheme called MAP (Multiplexing and Aggregation Protocol): each PDN gets a multiplexer ID, multiple PDNs' traffic can be aggregated together for throughput, and the rmnet driver de-aggregates incoming MAP frames and routes each one to the right PDN based on that ID.4

This combination is why qmi_wwan — the Linux driver implementing this — has become one of the most common WWAN drivers in existence: it's genuinely built for exactly this job, at exactly the throughput cellular data now demands.

Real-World Usage

On real commercial modules, these usually aren't fixed — they're selectable USB modes. A Quectel RM510Q-GL 5G module, for example, ships with four selectable modes: RmNet/QMI, ECM, MBIM, and RNDIS, chosen based on what the host OS needs.5

The default preference order, if you let software choose

Tools like ModemManager, when a device exposes more than one option, generally prefer MBIM first (it's the most standardized/generic), falling back toward QMI, then plainer options like NCM, if MBIM isn't available.6

Interface Typical Linux interface name
ECM / RNDIS usb0, eth1, etc. (looks like any other Ethernet interface)
NCM / MBIM Exposed under the wwan subsystem, e.g. wwan0
QMI / RmNet rmnet0, rmnet_ipa0, or similar, with a paired wwan0qmi0 control port

Typical Linux Interface Naming

Useful Resources


  1. 524wifi. (n.d.). Network drivers for cellular modules – ECM, NDIS, RNDIS, MBIM, RMNET, QMI. https://524wifi.net/network-drivers-for-cellular-modules-ecm-ndis-rndis-mbim-rmnet-qmi/ ↩↩

  2. Kamisu66 Blog. (2022, May 8). RM510Q-GL 5G LTE OpenWrt modem USB/PCI-E how-to. https://www.kamisu66.com/2022/05/08/RM510Q-GL-5G-LTE-OpenWrt-Modem-USB-PCI-E-how-to/ ↩↩

  3. Juul. (n.d.). How to use 4G LTE modems like the MC7455 on both Debian/Ubuntu and OpenWRT using MBIM [Gist]. GitHub. https://gist.github.com/Juul/e42c5b6ec71ce11923526b36d3f1cb2c ↩

  4. Blog, N. (2022, June 10). How to use RM510Q-GL 5G LTE modem with OpenWrt. Eyes, JAPAN Blog. https://blog.nowhere.co.jp/archives/20220610-30659.html ↩↩

  5. Quectel. (n.d.). UMTS/LTE/5G Linux USB driver user guide. https://quectel.com/content/uploads/2024/02/Quectel_UMTS_LTE_5G_Linux_USB_Driver_User_Guide_V3.1.pdf ↩

  6. ModemManager. (n.d.). WWAN device types. https://modemmanager.org/docs/modemmanager/wwan-device-types/ ↩