NovaS a écrit : ebt25 - What exactly are you looking for in the frame? Maybe I can extract it directly from DDT. If I need the canalyzer I will do it in the weekend.
PS: Sorry for the delay, I was away with business :)
There are no frames in DDT for reading and writing the software.
For this you need CAN Analyzer / CAN Sniffer or any interface that allows you to view frames in the CAN network.
(Do not try this at home because you can damage the module)
During the firmware upload, the following frames are sent:
At the beginning, the daignostic session:
1081 or 1086 (I do not remember)
then there is security access:
2781
and confirmation together with the key:
2782 XXXXXXXX (where XX .. is the key)
the next step is to load the bootloader:
3181 YYYYYY (yy .. probably a bootloader type)
and confirmation:
318101
After that, we send data using flow control.
for example.
10 88 34 82 00 00 00 80
21 82 07 D2 F5 00 00 00
22 00 00 00 00 00 00 00
23 00 00 82 07 C4 E4 00
e.t.c.
We're finishing changing the bootlader
318200
318201
Now what I need is these frames when reading. For sure there will be a diagnostic session (1081/1086) for sure there will be security access 27
can be another bootlader 31 YYYYYYY - I need to know
After that, the data should be read through 23AAAAAAAABBBB
where AAAAAAAA - Memory Address
BBBB - Memory Size of reading.