Contents: Information about diagnostic devices ↡ Diagnostics of electronic engine…↡ Measuring pulse duty cycle ↡ Reading and clearing flashing codes ↡ Controller for interfacing a…↡
The OBD system includes several diagnostic devices that monitor individual parameters of the toxicity reduction systems and record detected failures in the on-board processor memory in the form of individual fault codes. The system also checks sensors and actuators, monitors vehicle maintenance cycles, and provides the ability to memorize even short-term failures during operation and clear the memory block.
All models described in this Manual are equipped with an on-board diagnostics (OBD) system.
The main element of the system is the on-board processor, more often called the electronic control module (ECM) or the powertrain control module (PCM)
The ECM/PCM is the brain of the engine management system. Input data is supplied to the module from various information sensors and other electronic components (switches, relays, etc.). Based on the analysis of data received from information sensors, and in accordance with the basic parameters stored in the processor memory, the ECM/PCM generates commands to operate various control relays and actuators, thereby adjusting the engine operating parameters and ensuring maximum efficiency with minimum fuel consumption.
Reading of the OBD processor memory data is performed using a special scanner connected to the diagnostic database connector (DLC) or using an auxiliary LED, as well as using codes displayed on the automatic crankcase display.
Information about diagnostic devices
The proper functioning of injection system components and exhaust gas toxicity reduction systems is checked using a universal digital meter (multimeter)
Connecting a multimeter to the engine control unit connectors using an auxiliary splitter
Using a digital meter is preferable for several reasons. Firstly, it is quite difficult to measure the value of an analog meter (sometimes it's impossible), determine the result of the reading with an accuracy of up to hundredths and thousandths, while when examining circuits that include electronic components, such accuracy is of particular importance. The second, no less important, reason is the fact that the internal circuit of the digital multimeter has a fairly high impedance (the internal resistance of the device is 10 mOhm). Since the voltmeter is connected to the circuit being tested in parallel, the accuracy of the measurement is higher, the smaller the current that passes through the device itself. This factor is not significant when measuring relatively high voltage values (9÷12 V), but it becomes decisive when diagnosing elements that produce low-voltage signals, such as, for example, a λ-probe, where we are talking about measuring fractions of a volt.
Parallel monitoring of signal parameters, resistances and voltages in all control circuits is possible using a splitter connected in series to the engine control unit connector. In this case, with the engine off, running or while the car is moving, the signal parameters are measured at the terminals of the splitter, from which a conclusion is made about possible defects.
Special diagnostic scanners or testers with a specific cartridge can be used to diagnose electronic systems of the engine, automatic transmission, ABS, SRS and others (if provided), a universal cable and connector. In addition, for this purpose, you can use an expensive specialized automotive diagnostic computer, specially designed for full diagnostics of most systems of modern cars (for example, ADC2000 from Launch HiTech). Also, for this purpose, you can use scanners and specialized diagnostic analyzers, for example FDS 2000, Bosch FSA 560, KTS500 (0 684 400 500) or a regular personal computer with a special adapter, cable (for example, set 1 687 001 439) and the installed OBD II browser program.
Some scanners, in addition to the usual diagnostic operations, allow, when connected to a personal computer, to print out the basic diagrams of electrical equipment stored in the control unit memory (if pledged), program the anti-theft system, observe signals in the car circuits in real time.
It is necessary to perform several tests on different diagnostic connectors. First of all, check the pulse duty cycle.
Diagnostics of electronic engine control systems, injection and ignition, automatic air conditioning and ABS/ASR/ETS/ESP
Layout and design of diagnostic connectors
Location of diagnostic connectors
2 - 38-pin connector, if installed
3 - Location of the connector
4 - 9-pin connector, if installed
9-pin connector for diagnostics of the control system by the value of the pulse duty cycle, using a device for measuring the so-called duration of the closed state of the breaker contacts (dwell-meter)
1 - TD switch output; 2 - Body; 3 - Diagnostic output; 4 - Pin 1 of ignition coil; 5 - Terminal 15 of the ignition coil; 6 - Output +30; 7 and 9 - Terminals to the TDC sensor; 8 - Screen
Pin assignment of the 38-pin diagnostic connector
38-pin diagnostic connector for retrieving flashing codes
Connect the wires according to the diagram. The wire shown as a broken line is connected to a specific terminal to diagnose a specific system (refer to the contact assignment list):
- To terminal 4 - for injection system diagnostics;
- To pin 8 - for diagnostics of the main unit;
- To terminal 17 - for diagnostics of the ignition system;
- To terminal 19 - to check the diagnostic unit.
The connector terminals have the following purpose:
| Output No | Purpose | |
| 1 | Mass, contour 31 (W12, W15, electronics grounding) | |
| 2 | Voltage, circuit 87 | |
| 3 | Voltage, circuit 30 | |
| 4 | EDS | Electronic injection system (diesel engines) |
| DFI | Fuel injection with electronic distribution (diesel engines) | |
| IFI | Sequential electronic fuel injection (diesel models) | |
| HFM-SFI | Sequential multipoint injection/ignition system HFM (engines 104) | |
| LH-SFI | Sequential distributed injection system LH (engines 104, 119, 120 [right]) | |
| ME-SFI | Sequential distributed injection system ME (engines 119, 120 [right]) | |
| 5 | LH-SFI | Sequential distributed injection system LH (engines 120 [left]) |
| ME-SFI | Sequential distributed injection system ME (engines 120 [left]) | |
| 6 | ABS | Anti-lock brake system |
| ETS | Electronic traction control system | |
| ASR | Adjusting slip during acceleration | |
| ESP | Electronic stabilization program | |
| 7 | EA | Electronic acceleration |
| CC/ISC | Speed control/idle speed stabilization system | |
| 8 | VM | Basic module |
| BAS | Brake assistant | |
| 9 | ASD | Automatic differential lock |
| 10 | ETS | Electronic transmission control (AT 722.6) |
| 11 | ADS | Adaptive damping system |
| 12 | SPS | Speed-sensitive power steering system |
| 13 | TNA signal (petrol models), LH-SFI engines | |
| TN signal (petrol models), HFM (ME)-SFI engines | ||
| 14 | Signal, duty cycle information, engines 119, 120 LH-SFI (right) | |
| 15 | Signal, duty cycle information, 120 LH-SFI engines (left) | |
| IC | Instrument cluster | |
| 16 | A/C | Air conditioning system |
| 17 | DI | Ignition system with distributor, engines 104, 119 and 120 (right) |
| TD signal (time division) (diesel models) | ||
| TN signal, LH-SFI engines | ||
| 18 | DI | Ignition system with distributor, LH-SFI engines |
| 19 | DM | Diagnostic module |
| 20 | PSE | Pneumatic equipment |
| 21 | CF | Comfort |
| 23 | ATA | Anti-theft alarm |
| 24-27 | Not used | |
| 28 | PTS | Parktronic system |
| 29 | Not used | |
| 30 | AB | Airbags/belt tensioners ETR (SRS) |
| 31 | RCL | Remote control of a single lock |
| 32-33 | Not used | |
| 34 | CNS | Communication and navigation system |
| 35-38 | Not used |
Location of the 16-pin diagnostic connector (on USA models)
Identification of the terminals of the 16-pin diagnostic connector of the on-board diagnostic system (on USA models)
The connector terminals have the following purpose:
| Output No | Purpose |
| 1 | — |
| 2 | — |
| 3 | TNA signal |
| 4 | Connection to housing, terminal 31 |
| 5 | Housing - signal output, terminal 31 |
| 6 | CAN data bus high level |
| 7 | Engine Electronics (ME) |
| 8 | Nutrition, class 87 |
| 9 | Traction Control System (ETS) |
| 10 | — |
| 11 | Transmission Control Unit (ETC) |
| 12 | Activity module (AAM - All Activity Module) |
| 13 | Security systems |
| 14 | CAN Data Bus Low Level |
| 15 | IC dashboard |
| 16 | Plus battery via fuse. Live at any ignition switch position, terminal 30 |
Measuring pulse duty cycle
1. First, measure the duty cycle of the pulses characterizing the operation of the mixture quality control system and its malfunctions that have been repeated during the last four engine starts. This will require a device for measuring the so-called duration of the closed state of the breaker contacts (dwell-meter), lambda probe tester or digital multimeter.
2. Connect the + terminal of the device to the 3rd contact of the 9-pin connector and the negative to the car body.
3. Start and warm up the engine to operating temperature.
4. Stop the engine and turn on the ignition again. Read the % reading of the device and compare it with the decoding below. After starting the engine, the readings of the device should change, otherwise there is a malfunction.
[Article was borrowed from the website: MercedesMan.ru]
Reading and clearing flashing codes
1. Reading codes is done using a simple circuit consisting of a push-button switch and an LED. Depending on the type of diagnostic connector and the system being diagnosed, connect the circuit as shown in the illustration.

2. Turn on the ignition.
3. Press and hold the switch button for 2-4 seconds (or 5-6 sec on models with Bosch ECM -8/93) and release it. After 2 seconds, the LED will display a code, the value of which is equal to the number of flashes. The flash duration is 0.5 sec, the interval is 1 sec. Identify the code according to the decoding indicated below. To read the next code, press the button again. To erase this code, press the button and hold it for 6-8 seconds. (or 8-9 sec on models with Bosch ECM -8/93). In addition, on some models, codes in the memory can be erased by disconnecting the negative terminal of the battery.
4. Turn off the ignition and disconnect the circuit for testing.
Controller for interfacing a personal computer with an on-board OBD II self-diagnostic system according to SAE (PWM and VPW) and ISO 9141-2 protocols
Attention! The controller is not intended for connection to first-generation on-board self-diagnostic systems (OBD I)!
Note: VPW standard is applicable to GM models, PWM - to Ford models, ISO 9141-2 - to Asian and European models.
General information
Organization diagram of the controller interface with the on-board self-diagnostic system OBD II
The device in question is a microcontroller made using CMOS technology. The device acts as a simple scanner and is designed to read diagnostic codes and OBD II system data (engine speed, coolant and intake air temperature, load characteristics, air flow rate entering the engine, etc.) within the framework of the SAE J1979 standard via any type of bus (PWM, VPW and ISO 9141-2).
Main purpose
A 3-wire cable is sufficient for connection to the computer, and a 6-wire cable is used to connect to the diagnostic connector. Power is supplied to the adapter via the 16-pin OBD diagnostic connector.
Recommendations for use
To connect the device to the car, an unshielded cable of no more than 1.2 m in length can be used, which is especially important when using the PWM protocol. When using a longer cable, the resistance of the resistors at the input of the device should be reduced (R8 and R9 or R15). When using a shielded cable, the shield should be disconnected to reduce capacitance.
The cable for connecting to the computer's serial port can also be unshielded. The device works stably with a cable up to 9 m long. With a significantly longer cable, a more powerful RS 232 communicator should be used.
The topology of electrical connections is arbitrary. In case of high humidity, use additional shunt capacitors.
Free software (browser) for reading codes and data can be downloaded from the manufacturers' websites or from our publisher's website arus.spb.ru and is intended for use under DOS. The small size of the software application in the "under DOS" version allows it to be placed on a DOS boot diskette and used even on computers equipped with DOS-incompatible software. Even the presence of a hard disk in the computer is not a mandatory requirement.
General principles of data exchange
Note. Unless otherwise specified, all numbers are in 16-character (hex) format.
Data exchange occurs via a three-wire serial connection without the use of initialization exchange of service messages (handshaking). The device listens to the channel for messages, executes the received commands and transmits the results to the personal computer (PC), after which it immediately returns to the listening mode. The data entering and leaving the controller are organized as a chain of sequential bytes, the first of which is the control one.
Typically the control byte is a number between 0 and 15 dec (in decimal notation) (or 0-F hex), which describes the number of information bytes that follow. For example, a 3-byte command would look like this: 03 (control byte), 1st byte, 2nd byte, 3rd byte.
A similar format is used both for incoming commands to poll the on-board self-diagnostic system and for outgoing messages containing the requested information.
It should be noted that only the four least significant bits are used in the control byte - the most significant bits are reserved for some special commands and can be used by the PC when initializing the connection with the controller and agreeing on the data transfer protocol, as well as by the controller to control transmission errors. In particular, in the event of a transmission error, the controller sets the most significant bit (MSB) of the control byte to one. If the transmission is successful, all four most significant bits are set to zero.
Note: There are some exceptions to the rules for using the control byte.
Initialization of the controller and on-board self-diagnostic system
To start data exchange, the PC must establish a connection with the controller, then initialize the controller and the OBD II data channel.
Establishing a connection
After connecting the controller to the PC and the OBD diagnostic connector, it must be initialized to prevent "hangs" associated with noise in the serial lines if they were connected before the controller was powered on. At the same time, a simple check of the interface activity is performed. First, a single-byte signal 20 hex is sent, which the controller perceives as a command to establish a connection. In response, the controller sends a single byte FF hex (255 dec) instead of the control byte and goes into the data reception standby mode. Now the PC can proceed to initializing the data channel.
Note: This case is one of the few where the controller does not use a control byte.
Initialization
At this stage, the protocol by which data will be exchanged is initialized, and in the case of the ISO protocol, the on-board system is initialized. Data is exchanged using one of three protocols: VPW (General Motors), PWM (Ford) and ISO 9141-02 (asian/European manufacturers).
Note: There are many exceptions: for example, when polling some Mazda models, the "Ford" PWM protocol may be used. Therefore, if transmission problems occur, you should first try using some other protocol.
The protocol is selected by transmitting a combination consisting of the control byte 41 hex and the byte immediately following it that determines the protocol type: 0 = VPW, 1 = PWM, 2 = ISO 9141. For example, the command 41 02 hex initializes the ISO 9141 protocol.
In response, the controller sends a control byte and a status byte. Setting the MSB of the control byte indicates that there are problems, and the following status byte will contain the corresponding information. If initialization is successful, a control byte of 01 hex is sent, indicating that a verification status byte follows. In the case of VPW and PWM protocols, the verification byte is a simple echo of the protocol-defining byte (0 or 1, respectively), when initializing the ISO 9141 protocol, this will be a digital key returned by the on-board OBD processor and will determine which of the two slightly different protocol versions will be used.
Note: The digital key has a purely informational purpose. It should be noted that the initialization of the VPW and PWM protocols occurs much faster, since it only requires the transfer of the relevant information to the controller.
On models that comply with the ISO standard, initialization takes about 5 seconds, spent on information exchange between the adapter and the on-board processor, performed at a speed of 5 baud.
The reader should note that on some ISO 9141 family vehicles, protocol initialization is suspended if a data request is not transmitted within a 5 second interval - this means that the PC must automatically issue requests every few seconds, even in idle mode.
After the connection is established and the protocol is initialized, the regular data exchange begins, consisting of requests received from the PC and responses issued by the adapter.
Data exchange procedure
The controller operates in several different scenarios when using the ISO 9141-2 and SAE (VPW and PWM) protocols.
Exchange via SAE protocols (VPW and PWM)
When exchanging data using these protocols, only one data frame is buffered, which means that the frame to be captured or returned must be specified. In some (rare) cases, the onboard processor may transmit packets consisting of more than one frame. In such a situation, the request must be repeated until all frames in the packet have been received.
The request is always formed as follows: [Control Byte], [SAE Standard Request], [Frame Number]. As mentioned above, the control byte is usually a number equal to the total number of bytes that follow it. The request is formed in accordance with the SAE J1950 and J1979 specifications and consists of a header (3 bytes), a sequence of data bytes, and an error check byte (CRC). Note that while the request information is formed in strict accordance with the SAE specifications, the consumer of the control byte and frame number is the interface controller.
If the procedure is successfully completed, the response message always has the following format: [Control byte], [SAE standard response]. The control byte, as before, determines the number of information bytes that follow it. The response, in accordance with the SAE standard, consists of a header (3 bytes), a chain of information bytes, and a CRC byte.
In case of failure, a 2-byte response message is sent: [Control byte], [Status byte]. In this case, the MSB is set in the control byte. The four least significant bits form the number 001, indicating that the control byte is followed by a single byte, the status byte. This situation can occur quite often, since Specifications allow the possibility of the on-board processor not issuing data, as well as transmitting incorrect data in the event that the request does not correspond to the standard supported by the vehicle manufacturers. It is also possible that the requested data is not present in the processor's RAM at the current time. When the controller does not receive the expected response, or receives corrupted data, the MSB of the control byte is set, and the status byte is issued after the control byte.
In case of collisions in the bus, the interface generates a single byte 40 hex, which is a control byte with the least significant bit set to zero. Such a situation can occur quite often when loading the car bus with messages of higher priority than diagnostic data - the computing device must repeat the original request.
Exchange according to ISO 9141-2 protocols
The ISO 9141-2 standard is used by most Asian and European automotive manufacturers. The structure of the request generated by the PC is not much different from that used in the SAE standards, with the only difference being that the adapter does not need information about the frame number and the corresponding data should not be present in the packet. Thus, the request always consists of a control byte and a chain of information bytes following it, including a checksum. As a response message, the controller simply retransmits the signals generated by the on-board processor. There is no control byte in the response message, so the PC perceives the incoming information as a continuous stream until the chain is interrupted by a 55-millisecond pause indicating the end of the information packet. Thus, the response message may consist of one or more frames in accordance with the requirements of the SAE J1979 specifications. The controller does not analyze frames, does not discard non-diagnostic frames, etc. The PC must independently process the incoming data in order to isolate individual frames by analyzing the header bytes.
Note: Responses to most queries consist of a single frame.
Modifications of the latest controller versions
Note: All data bytes are transmitted in hexadecimal format (hex).
Note: The XX character indicates an undefined, reserved, or unrecognized byte.
Below are the main differences in the data transfer process using the SAE and ISO 9141 protocols, typical for the latest versions of interface controllers, as well as the procedure for data transfer using the ISO 14230 protocol:
- 1) ISO 9141 Standard: Added Address Byte;
- 2) ISO 9141 standard: Not one, but both key bytes are returned; (the extra byte is also returned in SAE modes, but is not used here).
- 3) Added support for ISO 14230 protocol.
Establishing a connection
The connection setup procedure has not changed:
| Dispatch: | 20 |
| Reception: | FF |
Selecting a protocol
The protocol is selected as follows:
| VPW: | |
| Dispatch: | 41, 00 |
| Reception: | 02, 01, XX |
PWM: | |
| Dispatch: | 41, 01 |
| Reception: | 02, 01, XX |
ISO 9141: | |
| Dispatch: | 42, 02, adr, where: adr is the address byte (usually 33 hex) |
| Reception: | 02, K1, K2, where K1, K2 are ISO key bytes Or: 82, XX, XX (iSO 9141 initialization error) |
ISO 14230 (fast initialization): | |
| Dispatch: | 46, 03, R1, R2, R3, R4, R5, where: R1÷R5 - ISO 14230 connection setup request start message, usually R1÷R5 = C1, 33, F1, 81, 66 |
| Reception: | S1, S2, ………, where S1, S2, ……… - ISO 14230 connection setup response start message |
Note: More than one ECU may be transmitted in succession. A negative response code may be used as a response.
A typical positive response looks like this:
S1, S2, ……. = 83, F1, 10, C1, E9, 8F, BD ISO 14230 (slow initialization): | Similar to ISO 9141 |
Note and comments
If the controller is planned to be used to transmit data only via one or two of the protocols, unnecessary components can be excluded.
For example, when organizing a circuit for the VPW (GM) protocol, only three wires of electrical wiring will be required in the wire connecting the controller to the car (terminals 16, 5 and 2).
If the PWM protocol is not used, elements R4, R6, R7, R8, R9, R10, T1, T2 and D1 can be excluded.
When refusing to exchange via the ISO protocol, the following elements are subject to exclusion: R15, R16, R17, R18, R19, R21, T4 and T5.
By not using the VPW protocol, the following elements can be eliminated: R13, R14, R23, R24, D2, D3 and T3.
Carbon film resistors with 5% resistance tolerance are used.
Please note that there is no emergency reset button (RESET) - if necessary, such a reset can be performed by disconnecting the controller from the vehicle connector (the interface processor will reboot automatically). Restarting the software on the PC will re-initialize the interface.
