Sep.2026 04
Views: 776
CAN, CAN-FD and UDS Diagnostics: How a T-Box Reads and Flashes the Vehicle
Introduction
How the T-Box monitors CAN traffic, scales signals with a DBC, and runs the ISO 14229 UDS 0x10 to 0x37 flashing sequence over CAN or DoIP.
Details

T-Box CAN CAN-FD bus and UDS diagnostic protocol explained

A T-Box is only useful if it can read what the vehicle knows. Almost everything the telematics platform reports — state of charge, cell voltages, speed, fault codes, crash flags — is gathered from the in-vehicle buses through the CAN protocol, and almost every remote action, from unlocking to flashing firmware, travels back down the same path using UDS diagnostics. This article explains how CAN frames move around the vehicle, how the T-Box listens without disturbing the bus, and how the ISO 14229 UDS sequence used for remote flashing actually works.

CAN and CAN-FD: The Vehicle's Nervous System

Controller Area Network is a differential, multi-master serial bus: every node sees every frame, and arbitration by message identifier lets higher-priority frames win the wire without collisions. A classic CAN frame carries an 11-bit (or extended 29-bit) identifier, a control field, up to 8 data bytes, a CRC and acknowledge bits. CAN-FD raises the payload to 64 bytes and switches to a faster bit-rate for the data phase, which modern EV architectures need for high-resolution battery and ADAS signals. The T-Box's CAN transceivers convert the differential PHY signals to UART-like frames for its MCU, often across two or three isolated bus channels.

animated CAN frame fields traveling between vehicle ECUs and the T-Box

How the T-Box Listens: Passive Monitoring vs Active Requests

Most telemetry is gathered passively: the T-Box subscribes to periodic broadcast frames — for example the BMS publishing pack voltage every 100 ms — scales the raw bytes using the vehicle's CAN database (DBC), and timestamps them against GNSS time. Passive listening is safe because it adds no traffic. When the platform needs data nobody broadcasts, the T-Box becomes an active diagnostic tester, sending requests addressed to a specific ECU and reading its replies. Remote commands — preconditioning the cabin, locking doors — are issued the same way, gated by authentication and secure on-board communication so a compromised T-Box cannot inject unauthorised frames.

UDS: ISO 14229 Diagnostic Services

Unified Diagnostic Services is the standardized client-server language spoken between a tester (here, the T-Box) and ECUs. Each service has a service identifier (SID). The services a telematics engineer meets most often are:

  • 0x10 DiagnosticSessionControl — moves an ECU from default into extended or programming sessions, which unlock privileged services.
  • 0x27 SecurityAccess — a seed-and-key challenge proving the tester is authorised before writes or flashing.
  • 0x22 ReadDataByIdentifier — reads a DID such as VIN, software version or battery serial.
  • 0x19 ReadDTCInformation — retrieves diagnostic trouble codes and freeze frames for remote health reports.
  • 0x2E WriteDataByIdentifier and 0x31 RoutineControl — write parameters and invoke routines such as flash erase or self-test.
  • 0x3E TesterPresent — a heartbeat that stops the ECU timing out of its session.

The UDS Flashing Sequence Behind Every OTA Update

Remote firmware download is the most choreographed UDS workflow. The T-Box receives the image over cellular, verifies it, then drives the target ECU through a fixed sequence:

animated UDS reflash sequence 0x10 0x27 0x34 0x36 0x37 0x31 0x11

  • 0x10 enter programming session, then periodic 0x3E keep-alive begins.
  • 0x27 security access: request seed, compute the key with the ECU's challenge algorithm, send it back.
  • 0x28 / 0x85 (optional) silence normal communication and DTC logging during the flash window.
  • 0x34 RequestDownload declares memory address and size; the ECU replies with its maximum block length.
  • 0x36 TransferData streams the image block by block, each block acknowledged with sequence counters.
  • 0x37 RequestTransferExit closes transfer; the ECU checks the hash and signature.
  • 0x31 routine control validates the new image and activates it, then 0x11 ECUReset restarts into the new firmware.

Over IP-based architectures the same services run on DoIP (ISO 13400) over automotive Ethernet; the service logic is identical, only the transport changes.

Reliability and Safety in Practice

Bus loading, message timeouts and partial-network wake-up must be engineered so telemetry never starves safety traffic. Flashing is designed to be resumable and power-loss tolerant: an ECU interrupted mid-update must boot into its bootloader and accept re-transfer rather than bricking. Functional addressing (one request to many ECUs) is reserved for TesterPresent and coordinated resets — never for write services, where simultaneous responses would collide. Disciplined use of these rules is what separates a telematics platform that updates 100,000 vehicles cleanly from one that bricks a fleet.

Weijiang Power: Power Integrity for Always-Connected Terminals

UDS flashing and continuous bus monitoring demand a T-Box supply that never browns out. Weijiang Power supplies the wide-temperature NiMH and lithium backup cells and custom packs that keep telematics units alive through ignition cycles, supply dips and crash-induced power loss — with matched internal-resistance binning, welded interconnects and full transport/ safety documentation. Send us your rail architecture and worst-case current profile, and we will engineer the backup power around it.

Lastest News
Unlock the power of lithium batteries for lasting performance in handheld vacuum cleaners. Weijiang Li-on Battery leads the charge in innovation.
READ MORE
A NiMH battery pack is a collection of individual NiMH batteries connected in series or parallel to create a higher voltage or capacity battery.
READ MORE
REQUEST MORE DETAILS
Please fill out the form below and click the button to request more information about
Name*
Whatsapp/Phone
Email*
Message*
Professional battery factory, support OEM & ODM customization.
REQUEST MORE DETAILS
Please fill out the form below and click the button to request more information about
Company Name*
Email Address*
WhatsApp / Phone*
Message & Requirements*