CAN Bus Communication for EV Battery Reuse

The battery, the BMS-EV controller and the inverter all talk over Controller Area Network (CAN). This page describes the CAN dialects used by each EV manufacturer, the missing ECU signals BMS-EV must emulate, and the inverter-side protocols the controller re-encodes for.

CAN in one paragraph. Controller Area Network is a differential two-wire serial bus running at 250 or 500 kbps (rarely 1 Mbps or CAN-FD at 2–5 Mbps in newer packs). Every EV BMS broadcasts its state on this bus in a proprietary message map — Tesla, VW MEB, Hyundai E-GMP, BMW, Nissan and Renault each use a different set of CAN IDs, byte layouts and CRCs. Hybrid inverters expect data in yet another dialect (Pylontech, BYD Premium, LG RESU, or a native protocol per inverter brand). The BMS-EV controller sits on both buses, reads one dialect and writes the other in real time.

What is CAN, physically

CAN (ISO 11898-2) is a differential half-duplex serial bus operating on twisted-pair wiring, terminated with 120 Ω at each end. Signals are CAN-H and CAN-L, differentially driven by every node. Frames carry an 11-bit (standard) or 29-bit (extended) identifier, a data payload of 0–8 bytes (classic CAN) or up to 64 bytes (CAN-FD), a CRC and an ACK slot. Arbitration is priority-based: the lower the numerical ID, the higher the priority. Typical EV bit rates are:

Physical connection to a pack differs by manufacturer. Nissan Leaf exposes CAN on 2 pins of the low-voltage service connector. Tesla routes battery CAN through the pack's front-end LV connector (12 or 24 pin), shared with contactor drive lines. BMW i3 uses the SME's dedicated 20-pin diagnostic connector. MEB packs expose CAN + contactor drive + HV request through the vehicle-side pigtail (Rosenberger 12-pin). BMS-EV controllers ship with the appropriate physical connector for the pack they target.

Which ECUs talk to the BMS in a vehicle

Inside a running EV, several ECUs broadcast on the pack's CAN bus. Removing the pack from the vehicle removes those transmitters — but the BMS still expects to hear them, and will refuse to close its contactors without their heartbeats. The BMS-EV controller emulates the essential subset of the following ECUs:

What BMS-EV must emulate per manufacturer

ManufacturerBit rateApprox. IDs emulatedCRC schemeWake sequence
Tesla Model S/X (2012–20)500 kbps~10 IDsSimple counter, no CRC on most msgsImmediate
Tesla Model 3/Y500 kbps~14 IDsPer-message CRC + counter~1 s wake, ~5 s to contactor close
BMW i3 (SME1/SME2)500 kbps~7 IDsNoneImmediate; LIN wake for junction box
BMW SP2LL / iX3 / i4500 kbps~12 IDsAUTOSAR E2E Profile 2~3 s wake sequence
Nissan Leaf 24/30/40500 kbps~5 IDsNoneImmediate (100 ms heartbeat)
Nissan Leaf 62 (e+)500 kbps~8 IDsNone~1 s
Renault Zoe / Kangoo ZE500 kbps~6 IDsNoneImmediate
VW MEB (ID.3, ID.4, Enyaq, Q4)500 kbps~15 IDsAUTOSAR 0x2F3 s HV request handshake
Audi Taycan / Porsche PPE (J1)500 kbps~18 IDsAUTOSAR E2E Profile 2Not fully supported — see notes
Hyundai / Kia E-GMP (Ioniq 5, EV6, GV60)500 kbps~12 IDsSimple checksum + counter~2 s wake
Kia Niro EV / Soul EV500 kbps~8 IDsNoneImmediate
Mitsubishi Outlander PHEV500 kbps~5 IDsNoneImmediate
Toyota bZ4X / Subaru Solterra500 kbps~10 IDsManufacturer CRC~2 s
Ford Mustang Mach-E / F-150 Lightning500 kbps~11 IDsManufacturer CRC~3 s

What the BMS broadcasts on the vehicle side

Regardless of manufacturer, the pack-side BMS periodically publishes the same conceptual data — the CAN IDs and byte layouts differ but the semantics do not. BMS-EV reads:

Inverter-side CAN protocols

Hybrid inverters do not understand any of the vehicle-side dialects. They expect a battery-side protocol from a supported stationary battery brand, or their own native protocol. The BMS-EV controller re-encodes the data above into one of the following protocols, selectable in firmware:

ProtocolBit rateUsed by invertersNotes
Pylontech LV/HV500 kbpsDeye, SOFAR, Growatt, Voltronic, Victron, Sungrow, SolaX (older)Most widely supported; LV = 48 V systems, HV = high voltage stack protocol
BYD Premium HV / LV500 kbpsSMA Sunny Tripower, Fronius Symo, Kostal Plenticore, Sungrow SHRequires precise message timing (200 ms)
LG RESU / LG Chem500 kbpsSolarEdge, some SMA, SungrowDetailed cell reporting expected
Native Deye (SUN-*-HP3)500 kbpsDeye HP3 hybrid invertersSimple pack-level messages, easy to emulate
Native SolaX X1 / X3 Hybrid500 kbpsSolaX X1-Hybrid-G4, X3 Hybrid, X3-UltraTheir T-BAT native protocol
Native GoodWe EH/ET500 kbpsGoodWe hybrid invertersCompatible with Lynx-D/U protocol
Native Sungrow SH500 kbpsSungrow SH-RT, SH-RSSungrow SBR protocol
Victron VE.Can (CAN 0.19A)250 or 500 kbpsVictron MultiPlus-II, QuattroNMEA 2000 style
SMA CAN (Sunny Island)500 kbpsSMA Sunny IslandOff-grid systems
Fronius Solar Battery500 kbpsFronius Symo Hybrid, GEN24Similar to BYD

Translation flow — an example

Example: Tesla Model 3 pack driving a Deye SUN-12K-SG04LP3-EU (Pylontech HV mode) Vehicle-side CAN (500 kbps, from Tesla BMS_hp) ──────────────────────────────────────────── ID 0x132 BMS_kwhCounter (8 B) discharge kWh, charge kWh ID 0x212 BMS_hvpStatus (8 B) pack V, pack I, HV enable state ID 0x352 BMS_socLimits (8 B) SoC, SoC min, SoC max ID 0x252 BMS_powerLimits (8 B) max charge W, max discharge W ID 0x292 BMS_thermalStatus (8 B) temp min, temp max ID 0x332 BMS_cellVoltageStats (8 B) cell V min, cell V max ID 0x312 BMS_alerts (8 B) fault bitfield │ ▼ [ BMS-EV firmware ] Read, re-scale, re-encode │ ▼ Inverter-side CAN (500 kbps, Pylontech HV protocol to Deye) ──────────────────────────────────────────── ID 0x351 Charge/discharge limits (V max, I charge max, I discharge max) ID 0x355 SoC / SoH (%) ID 0x356 Voltage, current, temperature ID 0x359 Alarms & warnings (bit-mapped) ID 0x35C Charge/discharge enable request ID 0x35E Battery vendor string ("BMS-EV ") Both sides run in parallel at 100–500 ms period each.

Timing, CRC and heartbeat requirements

Because the vehicle-side BMS validates messages based on both a rolling counter and a CRC (on manufacturers that implement it), timing precision matters. AUTOSAR E2E Profile 2 (used by VW MEB, BMW ≥ 2019, Porsche/Audi PPE) requires that every message ID carries a 4-bit counter in a designated nibble and a byte-level CRC over payload+ID. If a counter skips or a CRC is wrong twice consecutively, the receiver flags an E2E fault. BMS-EV firmware generates counters and CRCs correctly per manufacturer. Nissan Leaf, older Renault, and BMW i3 have no CRC — a plain message at the correct 100 ms cadence suffices. On the inverter side, most stationary protocols (Pylontech, BYD, native) require a message every 200 ms to 1 s; the inverter will alarm and open its DC contactor if the interval exceeds 5 s. BMS-EV firmware maintains both cadences independently.

Diagnostic access — CAN monitoring

All BMS-EV controllers expose an auxiliary "monitor" CAN output on a separate pair, matching the inverter-side protocol. This allows the installer to attach a laptop with a USB-CAN adapter (Peak-System PCAN, Kvaser, or the low-cost CANable) and observe the traffic being sent to the inverter — useful for commissioning, troubleshooting and integration with home-automation gateways. Wi-Fi enabled variants also publish the same values over MQTT for direct integration with Home Assistant, Node-RED or the Battery Emulator Cloud dashboard.

Frequently asked questions

Can I attach my laptop directly to the pack's CAN bus?

Yes for read-only sniffing (Nissan Leaf, BMW i3, older Renault). For CRC-protected buses (MEB, E-GMP, Tesla post-2019, BMW ≥ 2019) you can sniff but you cannot inject messages that the BMS will accept — the CRC requires per-manufacturer knowledge. This is why the BMS-EV controller exists.

Do I need a separate CAN bus for each side, or does one bus work?

Two physically separate buses. The vehicle-side dialect (say, Tesla) and the inverter-side dialect (say, Pylontech) both use 500 kbps but different IDs and payloads. Putting them on one wire would result in message collisions and both sides would reject each other's traffic.

How is the CAN bus terminated?

120 Ω resistors at each physical end of the bus. Battery packs terminate internally at the BMS end; the BMS-EV controller terminates at the other end. On the inverter side the inverter terminates internally, the BMS-EV controller terminates at its end. Do not add extra termination in the middle.

What CAN cable should I use?

Twisted pair, 120 Ω characteristic impedance, low-capacitance. Belden 3105A, Lapp Unitronic BUS CAN or equivalent. Cable length below 40 m at 500 kbps; realistic residential installations are well under 5 m. Route away from HV DC cables to avoid inductive coupling.

Can two BMS-EV controllers share one inverter for two packs?

No — the inverter expects a single battery-side transmitter on its CAN. To combine two packs, use two inverters (or an inverter that supports battery banks with an external combiner), or await our upcoming multi-pack aggregator firmware. For LV Leaf-style parallelisation the packs are combined on the DC side and one BMS-EV aggregates messages.

What is CAN-FD and do I need it?

CAN-FD (Flexible Data-Rate) allows payloads up to 64 bytes and arbitration up to 2–5 Mbps. Some 2022+ premium vehicles run CAN-FD on their vehicle backbone, but the pack's internal bus is still classic CAN 500 kbps. No inverter today uses CAN-FD, so BMS-EV uses classic CAN 500 kbps on both sides.

What happens if the inverter's CAN wiring is disconnected during operation?

The inverter loses its heartbeat, ramps down power within 1–2 s, opens its DC contactor and enters "battery communication lost" alarm state. BMS-EV separately detects the loss and, after a 5 s timeout with no ACKs, opens the main contactor at the battery. No damage occurs but the system requires a restart.

Where can I find message maps for my specific pack?

The open-source Battery Emulator project (dalathegreat/Battery-Emulator on GitHub) publishes decoded CAN maps for many packs. BMS-EV firmware is a productized derivative for one specific battery + inverter pair, validated end-to-end, with contactor drive and precharge included.

Find your battery + inverter combination
CAN protocol translation, precharge and HVIL — all in one pre-configured controller
Last updated: 2026-09-18
Current firmware: 15.0.14
Technical author: BMS-EV engineering team (Clima Boost sp. z o.o., Poland)
Reviewer: Jakub Lipiński, founder/lead engineer BMS-EV
Revision: 2026-09-18 — aligned with firmware 15.0.14, SOFAR 180–800 V DC verification, Kia EV6 + SOFAR HYD 15KTL case study reference
Related: EV Battery BMS · Safety Architecture · Compatibility Matrix