A port born from emissions law
OBD-II did not start as a data interface. It started as a regulatory tool: a way to make every vehicle monitor its own emission-related systems, switch on a malfunction indicator lamp (MIL) when something fails, store standardised fault codes and expose all of this through one standard connector, so that inspection stations and independent workshops could read any vehicle with the same equipment. California's Air Resources Board drove the requirement, and the US made it mandatory for passenger cars and light trucks from model year 1996. Europe followed with EOBD under Directive 98/69/EC.
Every later development, from secure gateways to OBD on UDS, has to coexist with this original legal promise: legislated, emission-related diagnostic information must remain readable through the standard connector without special permission.
The SAE J1962 connector, pin by pin
The connector is defined in SAE J1962 and ISO 15031-3: sixteen pins in two rows, located in the passenger compartment within reach of the driver's seat. Type A is used on 12 V vehicles; Type B, with an interrupted centre key, is used on 24 V vehicles so that 12 V-only equipment cannot be plugged in by mistake. Nine pins are defined by the standard; the remaining seven are left to the manufacturer.
Many manufacturers route additional, manufacturer-specific CAN pairs or single-wire buses to the discretionary pins for their own workshop equipment. None of these are part of the legislated interface, and their presence, bitrate and behaviour change between brands and model years.
Meter checks at the connector
The connector is also the most convenient place to check the health of the diagnostic CAN segment with nothing more than a multimeter. Resistance is measured with the battery disconnected, so that no transceiver is powered and the meter sees only the termination network between pins 6 and 14.
Both terminators in place: the bus is healthy.
Measure between CAN-H and CAN-L with the battery disconnected.
Voltages are measured against pin 5 with the vehicle awake. An idle, recessive high-speed CAN bus sits at about 2.5 V on both lines. With traffic, a multimeter's averaging shows CAN-H slightly above and CAN-L slightly below 2.5 V. A sleeping segment reads close to 0 V on both lines, which is normal: ISO 11898-2 transceivers in low-power mode stop biasing the bus. Note that a diagnostic segment behind a gateway can be awake and completely silent, because diagnostic traffic only appears when a tester is talking. The field diagnostics article covers oscilloscope patterns in detail.
ISO 15765-4: the legislated CAN layer
ISO 15765-4 defines how emission-related diagnostics run over CAN. It allows four combinations, 500 or 250 kbit/s with 11-bit or 29-bit identifiers; passenger cars overwhelmingly use 500 kbit/s. Unlike the rest of the vehicle's CAN traffic, OBD communication is strictly request and response: a tester asks, ECUs answer. Nothing is broadcast on the diagnostic channel unless someone requests it. The identifiers are fixed by the standard:
ISO-TP: carrying more than eight bytes
A classic CAN frame carries eight bytes, while a vehicle identification number alone is seventeen characters. ISO 15765-2, commonly called ISO-TP, segments longer messages. The first nibble of the first data byte, the protocol control information (PCI), tells the receiver what kind of frame it is looking at.
With classic addressing, the 12-bit length field in the First Frame limits a message to 4,095 bytes; the 2016 edition of ISO 15765-2 added an escape sequence for lengths up to 4 GiB, which matters for software download. Flow control is what makes ISO-TP gentle on a shared bus: the receiver dictates how many frames may follow and how far apart they must be.
The legislated services
This catalogue is being replaced. SAE J1979-2, also called OBD on UDS, carries the legislated content over UDS services instead of the $01 to $0A modes. California permits it from model year 2023 and requires it from model year 2027. For heavy-duty vehicles, ISO 27145 (WWH-OBD) takes the same UDS-based approach. The connector stays the same; the language spoken through it changes.
UDS: the language of workshop diagnostics
Everything beyond legislated emission data, from reading a body controller's fault memory to coding a replacement part, uses UDS, Unified Diagnostic Services, defined in ISO 14229-1. UDS is independent of the transport: ISO 14229-3 maps it onto CAN through ISO-TP, and ISO 14229-5 onto Ethernet through DoIP (ISO 13400). A positive response echoes the service identifier plus 0x40; a negative response starts with 0x7F, followed by the service identifier and a negative response code (NRC).
Why the connector moved behind the gateway
In many early CAN vehicles, pins 6 and 14 were wired straight onto a powertrain bus. The diagnostic connector was simply a stub on a live control network. That was convenient and fragile at the same time. Anything plugged into the port could transmit onto a safety-relevant bus, a long or poorly made adapter cable degraded signal quality, and a badly behaved device could load the bus or hold it dominant. As vehicles gained cellular and wireless connectivity, the port also became an obvious part of the attack surface; a widely publicised remote attack on a production SUV in 2015 led to a recall of 1.4 million vehicles and accelerated the industry's move to segmentation.
In current architectures the diagnostic connector is wired to its own segment, owned by the central gateway. The gateway accepts diagnostic requests, routes them to the addressed ECU on whichever internal bus it lives, and routes the responses back. The broadcast traffic of the powertrain, chassis and body domains stays where it is. Seen from the connector, a modern vehicle is quiet until a tester speaks.
Secure gateways and authenticated access
A secure gateway adds authentication to that routing. Reading legislated data and emission-related fault codes remains open, as the law requires. Clearing codes, running actuator tests, coding and programming require a tester that has authenticated itself, typically through an online account with the manufacturer or an authorised intermediary, or through certificates checked by the UDS Authentication service. Stellantis (then FCA) introduced secure gateway modules on some models from 2018; the Volkswagen Group followed in 2020 with its SFD diagnostic protection; Mercedes-Benz, Renault and Nissan are among the other manufacturers that restrict diagnostic access in a similar way.
Regulation shapes the gateway
Two regulatory forces pull in opposite directions, and the secure gateway is where they meet. UNECE R155 requires manufacturers to manage cybersecurity risks across the vehicle lifecycle, which strongly favours closing every unnecessary path to safety-relevant ECUs. EU type-approval law (Regulation (EU) 2018/858) requires manufacturers to give independent operators non-discriminatory access to repair and maintenance information, including diagnostics. For security-related functions such as keys and immobilisers, the SERMI scheme, operational since August 2023, provides a path for vetted independent professionals. The result is a connector that is open for reading, gated for writing and auditable for both.
Implications for aftermarket devices
Insurance dongles, fleet trackers and other plug-in devices made the OBD connector a popular installation point. The architecture described above explains why that choice has become harder to defend for anything meant to stay in the vehicle:
- Limited view. Behind a gateway, the port carries diagnostic dialogue, not the vehicle's internal broadcast traffic.
- Every answer costs a request. Request-and-response diagnostics add load, can keep ECUs awake, and can collide with a workshop tester or an inspection device using the same channel.
- Gated functions. On secure-gateway vehicles, anything beyond legislated reading needs authentication that a permanently installed device does not have.
- Permanent power. Pin 16 is live at all times, so the device's own consumption and its effect on network sleep become the vehicle owner's problem.
- Mechanical exposure. The connector is designed for a tester that is plugged in for a session, not for a device hanging under the dashboard for years, exposed to knees, vibration and cleaning.
- Access for others. Workshops, roadside checks and periodic inspections need the port free and working.
- Security posture. A plug-in device with a radio link becomes part of the vehicle's attack surface, and post-R155 vehicles may log or flag unknown participants on the diagnostic segment.
Does a secure gateway stop me from reading fault codes?
No. Legislated OBD data and emission-related fault codes must stay readable without special permission. Secure gateways restrict clearing codes, actuator tests, coding and programming to authenticated testers.
Why do pins 6 and 14 measure 60 Ω even when there is no traffic at the connector?
Because the diagnostic segment is terminated at both ends like any high-speed CAN segment, but behind a gateway it only carries traffic while a tester is communicating. A quiet port with a correct 60 Ω reading is normal.
Why does the same plug-in device work on one vehicle and not on another?
The legislated layer allows four CAN variants, manufacturers place different gateway policies in front of the port, secure gateways restrict access, and newer vehicles move workshop functions to DoIP or to OBD on UDS. Each of these changes what a device sees at the connector.
Is DoIP replacing CAN at the diagnostic connector?
Not for legislated OBD in light vehicles today. DoIP uses otherwise discretionary pins of the same connector and is mainly used for fast workshop access such as software download, while pins 6 and 14 continue to carry diagnostic CAN.
What changes with OBD on UDS?
The legislated content moves from the classic $01 to $0A services to UDS services, the same protocol workshops use for manufacturer diagnostics. California requires it from model year 2027. Testers need to support both for years to come.
