Home › Second-Life Battery › CAN Bus
The battery, the BMS-EV controller and the inverter all talk over Controller Area Network (CAN). This page describes the CAN dialects used by each EV manufacturer, the missing ECU signals BMS-EV must emulate, and the inverter-side protocols the controller re-encodes for.
CAN in one paragraph. Controller Area Network is a differential two-wire serial bus running at 250 or 500 kbps (rarely 1 Mbps or CAN-FD at 2–5 Mbps in newer packs). Every EV BMS broadcasts its state on this bus in a proprietary message map — Tesla, VW MEB, Hyundai E-GMP, BMW, Nissan and Renault each use a different set of CAN IDs, byte layouts and CRCs. Hybrid inverters expect data in yet another dialect (Pylontech, BYD Premium, LG RESU, or a native protocol per inverter brand). The BMS-EV controller sits on both buses, reads one dialect and writes the other in real time.
CAN (ISO 11898-2) is a differential half-duplex serial bus operating on twisted-pair wiring, terminated with 120 Ω at each end. Signals are CAN-H and CAN-L, differentially driven by every node. Frames carry an 11-bit (standard) or 29-bit (extended) identifier, a data payload of 0–8 bytes (classic CAN) or up to 64 bytes (CAN-FD), a CRC and an ACK slot. Arbitration is priority-based: the lower the numerical ID, the higher the priority. Typical EV bit rates are:
Physical connection to a pack differs by manufacturer. Nissan Leaf exposes CAN on 2 pins of the low-voltage service connector. Tesla routes battery CAN through the pack's front-end LV connector (12 or 24 pin), shared with contactor drive lines. BMW i3 uses the SME's dedicated 20-pin diagnostic connector. MEB packs expose CAN + contactor drive + HV request through the vehicle-side pigtail (Rosenberger 12-pin). BMS-EV controllers ship with the appropriate physical connector for the pack they target.
Inside a running EV, several ECUs broadcast on the pack's CAN bus. Removing the pack from the vehicle removes those transmitters — but the BMS still expects to hear them, and will refuse to close its contactors without their heartbeats. The BMS-EV controller emulates the essential subset of the following ECUs:
| Manufacturer | Bit rate | Approx. IDs emulated | CRC scheme | Wake sequence |
|---|---|---|---|---|
| Tesla Model S/X (2012–20) | 500 kbps | ~10 IDs | Simple counter, no CRC on most msgs | Immediate |
| Tesla Model 3/Y | 500 kbps | ~14 IDs | Per-message CRC + counter | ~1 s wake, ~5 s to contactor close |
| BMW i3 (SME1/SME2) | 500 kbps | ~7 IDs | None | Immediate; LIN wake for junction box |
| BMW SP2LL / iX3 / i4 | 500 kbps | ~12 IDs | AUTOSAR E2E Profile 2 | ~3 s wake sequence |
| Nissan Leaf 24/30/40 | 500 kbps | ~5 IDs | None | Immediate (100 ms heartbeat) |
| Nissan Leaf 62 (e+) | 500 kbps | ~8 IDs | None | ~1 s |
| Renault Zoe / Kangoo ZE | 500 kbps | ~6 IDs | None | Immediate |
| VW MEB (ID.3, ID.4, Enyaq, Q4) | 500 kbps | ~15 IDs | AUTOSAR 0x2F | 3 s HV request handshake |
| Audi Taycan / Porsche PPE (J1) | 500 kbps | ~18 IDs | AUTOSAR E2E Profile 2 | Not fully supported — see notes |
| Hyundai / Kia E-GMP (Ioniq 5, EV6, GV60) | 500 kbps | ~12 IDs | Simple checksum + counter | ~2 s wake |
| Kia Niro EV / Soul EV | 500 kbps | ~8 IDs | None | Immediate |
| Mitsubishi Outlander PHEV | 500 kbps | ~5 IDs | None | Immediate |
| Toyota bZ4X / Subaru Solterra | 500 kbps | ~10 IDs | Manufacturer CRC | ~2 s |
| Ford Mustang Mach-E / F-150 Lightning | 500 kbps | ~11 IDs | Manufacturer CRC | ~3 s |
Regardless of manufacturer, the pack-side BMS periodically publishes the same conceptual data — the CAN IDs and byte layouts differ but the semantics do not. BMS-EV reads:
Hybrid inverters do not understand any of the vehicle-side dialects. They expect a battery-side protocol from a supported stationary battery brand, or their own native protocol. The BMS-EV controller re-encodes the data above into one of the following protocols, selectable in firmware:
| Protocol | Bit rate | Used by inverters | Notes |
|---|---|---|---|
| Pylontech LV/HV | 500 kbps | Deye, SOFAR, Growatt, Voltronic, Victron, Sungrow, SolaX (older) | Most widely supported; LV = 48 V systems, HV = high voltage stack protocol |
| BYD Premium HV / LV | 500 kbps | SMA Sunny Tripower, Fronius Symo, Kostal Plenticore, Sungrow SH | Requires precise message timing (200 ms) |
| LG RESU / LG Chem | 500 kbps | SolarEdge, some SMA, Sungrow | Detailed cell reporting expected |
| Native Deye (SUN-*-HP3) | 500 kbps | Deye HP3 hybrid inverters | Simple pack-level messages, easy to emulate |
| Native SolaX X1 / X3 Hybrid | 500 kbps | SolaX X1-Hybrid-G4, X3 Hybrid, X3-Ultra | Their T-BAT native protocol |
| Native GoodWe EH/ET | 500 kbps | GoodWe hybrid inverters | Compatible with Lynx-D/U protocol |
| Native Sungrow SH | 500 kbps | Sungrow SH-RT, SH-RS | Sungrow SBR protocol |
| Victron VE.Can (CAN 0.19A) | 250 or 500 kbps | Victron MultiPlus-II, Quattro | NMEA 2000 style |
| SMA CAN (Sunny Island) | 500 kbps | SMA Sunny Island | Off-grid systems |
| Fronius Solar Battery | 500 kbps | Fronius Symo Hybrid, GEN24 | Similar to BYD |
Because the vehicle-side BMS validates messages based on both a rolling counter and a CRC (on manufacturers that implement it), timing precision matters. AUTOSAR E2E Profile 2 (used by VW MEB, BMW ≥ 2019, Porsche/Audi PPE) requires that every message ID carries a 4-bit counter in a designated nibble and a byte-level CRC over payload+ID. If a counter skips or a CRC is wrong twice consecutively, the receiver flags an E2E fault. BMS-EV firmware generates counters and CRCs correctly per manufacturer. Nissan Leaf, older Renault, and BMW i3 have no CRC — a plain message at the correct 100 ms cadence suffices. On the inverter side, most stationary protocols (Pylontech, BYD, native) require a message every 200 ms to 1 s; the inverter will alarm and open its DC contactor if the interval exceeds 5 s. BMS-EV firmware maintains both cadences independently.
All BMS-EV controllers expose an auxiliary "monitor" CAN output on a separate pair, matching the inverter-side protocol. This allows the installer to attach a laptop with a USB-CAN adapter (Peak-System PCAN, Kvaser, or the low-cost CANable) and observe the traffic being sent to the inverter — useful for commissioning, troubleshooting and integration with home-automation gateways. Wi-Fi enabled variants also publish the same values over MQTT for direct integration with Home Assistant, Node-RED or the Battery Emulator Cloud dashboard.
Yes for read-only sniffing (Nissan Leaf, BMW i3, older Renault). For CRC-protected buses (MEB, E-GMP, Tesla post-2019, BMW ≥ 2019) you can sniff but you cannot inject messages that the BMS will accept — the CRC requires per-manufacturer knowledge. This is why the BMS-EV controller exists.
Two physically separate buses. The vehicle-side dialect (say, Tesla) and the inverter-side dialect (say, Pylontech) both use 500 kbps but different IDs and payloads. Putting them on one wire would result in message collisions and both sides would reject each other's traffic.
120 Ω resistors at each physical end of the bus. Battery packs terminate internally at the BMS end; the BMS-EV controller terminates at the other end. On the inverter side the inverter terminates internally, the BMS-EV controller terminates at its end. Do not add extra termination in the middle.
Twisted pair, 120 Ω characteristic impedance, low-capacitance. Belden 3105A, Lapp Unitronic BUS CAN or equivalent. Cable length below 40 m at 500 kbps; realistic residential installations are well under 5 m. Route away from HV DC cables to avoid inductive coupling.
No — the inverter expects a single battery-side transmitter on its CAN. To combine two packs, use two inverters (or an inverter that supports battery banks with an external combiner), or await our upcoming multi-pack aggregator firmware. For LV Leaf-style parallelisation the packs are combined on the DC side and one BMS-EV aggregates messages.
CAN-FD (Flexible Data-Rate) allows payloads up to 64 bytes and arbitration up to 2–5 Mbps. Some 2022+ premium vehicles run CAN-FD on their vehicle backbone, but the pack's internal bus is still classic CAN 500 kbps. No inverter today uses CAN-FD, so BMS-EV uses classic CAN 500 kbps on both sides.
The inverter loses its heartbeat, ramps down power within 1–2 s, opens its DC contactor and enters "battery communication lost" alarm state. BMS-EV separately detects the loss and, after a 5 s timeout with no ACKs, opens the main contactor at the battery. No damage occurs but the system requires a restart.
The open-source Battery Emulator project (dalathegreat/Battery-Emulator on GitHub) publishes decoded CAN maps for many packs. BMS-EV firmware is a productized derivative for one specific battery + inverter pair, validated end-to-end, with contactor drive and precharge included.