Przejdź do treści
[Architecture · 06]

OBD-II and secure gateways: what the diagnostic connector really is

The 16-pin socket under the dashboard was created for emissions inspection and workshop diagnostics, not as permanent access to the vehicle network. Here is what the standards define, how to check the port with a meter, and why manufacturers keep moving it further away from the buses that run the car.

Reading time
13 min
Updated
7 października 2026
Diagrams
02
Sections
06

This article is not yet available in your language and is shown in English.

A port born from emissions law

OBD-II did not start as a data interface. It started as a regulatory tool: a way to make every vehicle monitor its own emission-related systems, switch on a malfunction indicator lamp (MIL) when something fails, store standardised fault codes and expose all of this through one standard connector, so that inspection stations and independent workshops could read any vehicle with the same equipment. California's Air Resources Board drove the requirement, and the US made it mandatory for passenger cars and light trucks from model year 1996. Europe followed with EOBD under Directive 98/69/EC.

Table 01Milestones that shaped the diagnostic connector
WhenWhereWhat changed
Model year 1996United StatesOBD-II mandatory for passenger cars and light trucks: SAE J1962 connector, standard fault codes, MIL
2000 / 2001European UnionEOBD for petrol passenger cars: new types from 2000, all new registrations from 2001
2003 / 2004European UnionEOBD for diesel passenger cars: new types from 2003, all new registrations from 2004
Model year 2008United StatesCAN per ISO 15765-4 becomes the required OBD protocol for all new light vehicles
July 2022 / July 2024EU and other UNECE R155 contracting partiesCybersecurity management mandatory for new vehicle types, then for all new vehicles
August 2023European UnionSERMI scheme operational for independent access to security-related repair information
Model year 2023 / 2027CaliforniaSAE J1979-2 (OBD on UDS) permitted from 2023, required from 2027

Every later development, from secure gateways to OBD on UDS, has to coexist with this original legal promise: legislated, emission-related diagnostic information must remain readable through the standard connector without special permission.

The SAE J1962 connector, pin by pin

The connector is defined in SAE J1962 and ISO 15031-3: sixteen pins in two rows, located in the passenger compartment within reach of the driver's seat. Type A is used on 12 V vehicles; Type B, with an interrupted centre key, is used on 24 V vehicles so that 12 V-only equipment cannot be plugged in by mistake. Nine pins are defined by the standard; the remaining seven are left to the manufacturer.

Table 02SAE J1962 / ISO 15031-3 pin assignment
PinAssignmentNotes
1Manufacturer discretionaryDoIP Ethernet RX+ in ISO 13400-4 option 2
2SAE J1850 bus +Legacy US protocols (VPW and PWM)
3Manufacturer discretionaryDoIP Ethernet RX+ in ISO 13400-4 option 1
4Chassis groundPower return
5Signal groundReference point for all signal measurements
6CAN-H (ISO 15765-4)Legislated diagnostic CAN
7K-line (ISO 9141-2, ISO 14230-4)Legacy diagnostic line
8Manufacturer discretionaryDoIP activation line (ISO 13400)
9Manufacturer discretionaryDoIP Ethernet RX− in option 2
10SAE J1850 bus −PWM variant only
11Manufacturer discretionaryDoIP Ethernet RX− in option 1
12Manufacturer discretionaryDoIP Ethernet TX+
13Manufacturer discretionaryDoIP Ethernet TX−
14CAN-L (ISO 15765-4)Legislated diagnostic CAN
15L-line (ISO 9141-2, ISO 14230-4)Legacy, rarely used
16Battery positive, unswitchedPermanent supply, terminal 30

Many manufacturers route additional, manufacturer-specific CAN pairs or single-wire buses to the discretionary pins for their own workshop equipment. None of these are part of the legislated interface, and their presence, bitrate and behaviour change between brands and model years.

Meter checks at the connector

The connector is also the most convenient place to check the health of the diagnostic CAN segment with nothing more than a multimeter. Resistance is measured with the battery disconnected, so that no transceiver is powered and the meter sees only the termination network between pins 6 and 14.

Fig. 01Interactive
HLControl unit 1Control unit 260ΩOhmmeter
60Ω

Both terminators in place: the bus is healthy.

Measure between CAN-H and CAN-L with the battery disconnected.

Fig. 01With the battery disconnected, an ohmmeter across pins 6 and 14 sees the two 120 Ω terminators of the diagnostic segment in parallel: about 60 Ω.
Table 03Interpreting a resistance reading between pins 6 and 14 (battery disconnected)
ReadingMost likely meaning
About 60 ΩTwo 120 Ω terminators in parallel: normal for a segment terminated at both ends
About 120 ΩOne terminator missing or one branch open; on some designs a single-terminated diagnostic stub, so check OEM documentation
About 40 ΩA third 120 Ω terminator, often added by a plugged-in or retrofitted device
Very high or openBroken wire, damaged pins, or a vehicle that does not use pins 6 and 14 for CAN
Well below 40 Ω or near 0 ΩShort between CAN-H and CAN-L, or several extra terminators

Voltages are measured against pin 5 with the vehicle awake. An idle, recessive high-speed CAN bus sits at about 2.5 V on both lines. With traffic, a multimeter's averaging shows CAN-H slightly above and CAN-L slightly below 2.5 V. A sleeping segment reads close to 0 V on both lines, which is normal: ISO 11898-2 transceivers in low-power mode stop biasing the bus. Note that a diagnostic segment behind a gateway can be awake and completely silent, because diagnostic traffic only appears when a tester is talking. The field diagnostics article covers oscilloscope patterns in detail.

ISO 15765-4: the legislated CAN layer

ISO 15765-4 defines how emission-related diagnostics run over CAN. It allows four combinations, 500 or 250 kbit/s with 11-bit or 29-bit identifiers; passenger cars overwhelmingly use 500 kbit/s. Unlike the rest of the vehicle's CAN traffic, OBD communication is strictly request and response: a tester asks, ECUs answer. Nothing is broadcast on the diagnostic channel unless someone requests it. The identifiers are fixed by the standard:

Table 04ISO 15765-4 diagnostic addressing
Message11-bit identifiers29-bit identifiers
Functional request (to all emission-related ECUs)0x7DF0x18DB33F1
Physical request to ECU n0x7E0 to 0x7E70x18DAxxF1 (xx = ECU address)
Response from ECU n0x7E8 to 0x7EF0x18DAF1xx
Bitrate500 or 250 kbit/s500 or 250 kbit/s

ISO-TP: carrying more than eight bytes

A classic CAN frame carries eight bytes, while a vehicle identification number alone is seventeen characters. ISO 15765-2, commonly called ISO-TP, segments longer messages. The first nibble of the first data byte, the protocol control information (PCI), tells the receiver what kind of frame it is looking at.

Table 05ISO-TP frame types
Frame typePCI nibblePurpose
Single Frame0Complete message of up to 7 bytes on classic CAN (up to 62 bytes on CAN FD)
First Frame1Announces the total length and carries the first bytes
Consecutive Frame2Carries the next 7 bytes, with a sequence number that wraps from 15 to 0
Flow Control3Receiver sets block size (BS) and minimum separation time (STmin) for the sender

With classic addressing, the 12-bit length field in the First Frame limits a message to 4,095 bytes; the 2016 edition of ISO 15765-2 added an escape sequence for lengths up to 4 GiB, which matters for software download. Flow control is what makes ISO-TP gentle on a shared bus: the receiver dictates how many frames may follow and how far apart they must be.

The legislated services

Table 06Legislated OBD services (SAE J1979 / ISO 15031-5)
ServiceNamePurpose
$01Current powertrain dataReadiness status and live emission-related values
$02Freeze frame dataConditions stored when a fault code was set
$03Confirmed DTCsEmission-related fault codes that switched on the MIL
$04Clear diagnostic informationClears codes, freeze frames and readiness
$05Oxygen sensor monitoringNot used on CAN; results are reported through $06
$06On-board monitoring resultsTest results of non-continuous monitors
$07Pending DTCsFaults found during the current or last driving cycle
$08Control of on-board systemsRequests a specific on-board test
$09Vehicle informationVIN, calibration IDs and calibration verification numbers
$0APermanent DTCsCodes that cannot be cleared by a tester, only by the vehicle's own monitors

This catalogue is being replaced. SAE J1979-2, also called OBD on UDS, carries the legislated content over UDS services instead of the $01 to $0A modes. California permits it from model year 2023 and requires it from model year 2027. For heavy-duty vehicles, ISO 27145 (WWH-OBD) takes the same UDS-based approach. The connector stays the same; the language spoken through it changes.

UDS: the language of workshop diagnostics

Everything beyond legislated emission data, from reading a body controller's fault memory to coding a replacement part, uses UDS, Unified Diagnostic Services, defined in ISO 14229-1. UDS is independent of the transport: ISO 14229-3 maps it onto CAN through ISO-TP, and ISO 14229-5 onto Ethernet through DoIP (ISO 13400). A positive response echoes the service identifier plus 0x40; a negative response starts with 0x7F, followed by the service identifier and a negative response code (NRC).

Table 07Core UDS services (ISO 14229-1)
SIDServiceTypical use
0x10DiagnosticSessionControlSwitch between default, programming and extended sessions
0x11ECUResetRestart an ECU after coding or programming
0x14ClearDiagnosticInformationClear stored fault codes
0x19ReadDTCInformationRead fault codes, status bits and snapshots
0x22ReadDataByIdentifierRead identification, configuration and live values
0x27SecurityAccessSeed-and-key unlock before protected services
0x28CommunicationControlSilence normal application traffic, for example during programming
0x29AuthenticationCertificate-based authentication, added in ISO 14229-1:2020
0x2EWriteDataByIdentifierWrite coding and configuration data
0x31RoutineControlStart, stop and query routines such as actuator tests or adaptations
0x34 / 0x36 / 0x37RequestDownload / TransferData / RequestTransferExitSoftware download
0x3ETesterPresentKeep a non-default session alive
0x85ControlDTCSettingSuspend fault code storage during workshop procedures

Why the connector moved behind the gateway

In many early CAN vehicles, pins 6 and 14 were wired straight onto a powertrain bus. The diagnostic connector was simply a stub on a live control network. That was convenient and fragile at the same time. Anything plugged into the port could transmit onto a safety-relevant bus, a long or poorly made adapter cable degraded signal quality, and a badly behaved device could load the bus or hold it dominant. As vehicles gained cellular and wireless connectivity, the port also became an obvious part of the attack surface; a widely publicised remote attack on a production SUV in 2015 led to a recall of 1.4 million vehicles and accelerated the industry's move to segmentation.

In current architectures the diagnostic connector is wired to its own segment, owned by the central gateway. The gateway accepts diagnostic requests, routes them to the addressed ECU on whichever internal bus it lives, and routes the responses back. The broadcast traffic of the powertrain, chassis and body domains stays where it is. Seen from the connector, a modern vehicle is quiet until a tester speaks.

Fig. 02Interactive
Diagnostic tool12345678910111213141516OBD-II portDiagnostic requests pass the gatewaySecure gatewayPowertrain CANChassis CANBody CANInfotainment CANInternal networks stay behind it
SAE J1962 connector
Fig. 02The diagnostic connector sits on its own segment. The gateway forwards diagnostic requests inward and responses outward, while each domain's broadcast traffic stays inside its own network.

Secure gateways and authenticated access

A secure gateway adds authentication to that routing. Reading legislated data and emission-related fault codes remains open, as the law requires. Clearing codes, running actuator tests, coding and programming require a tester that has authenticated itself, typically through an online account with the manufacturer or an authorised intermediary, or through certificates checked by the UDS Authentication service. Stellantis (then FCA) introduced secure gateway modules on some models from 2018; the Volkswagen Group followed in 2020 with its SFD diagnostic protection; Mercedes-Benz, Renault and Nissan are among the other manufacturers that restrict diagnostic access in a similar way.

Table 08Typical access behaviour of a secure gateway
FunctionWithout authenticationWith an authenticated tester
Read legislated OBD data and emission DTCsAvailableAvailable
Read manufacturer-specific DTCsUsually available, manufacturer-dependentAvailable
Clear DTCsOften blockedAvailable
Actuator tests and routinesBlockedAvailable
Coding and configuration writesBlockedAvailable
Software downloadBlockedAvailable, usually with further checks

Regulation shapes the gateway

Two regulatory forces pull in opposite directions, and the secure gateway is where they meet. UNECE R155 requires manufacturers to manage cybersecurity risks across the vehicle lifecycle, which strongly favours closing every unnecessary path to safety-relevant ECUs. EU type-approval law (Regulation (EU) 2018/858) requires manufacturers to give independent operators non-discriminatory access to repair and maintenance information, including diagnostics. For security-related functions such as keys and immobilisers, the SERMI scheme, operational since August 2023, provides a path for vetted independent professionals. The result is a connector that is open for reading, gated for writing and auditable for both.

Implications for aftermarket devices

Insurance dongles, fleet trackers and other plug-in devices made the OBD connector a popular installation point. The architecture described above explains why that choice has become harder to defend for anything meant to stay in the vehicle:

  • Limited view. Behind a gateway, the port carries diagnostic dialogue, not the vehicle's internal broadcast traffic.
  • Every answer costs a request. Request-and-response diagnostics add load, can keep ECUs awake, and can collide with a workshop tester or an inspection device using the same channel.
  • Gated functions. On secure-gateway vehicles, anything beyond legislated reading needs authentication that a permanently installed device does not have.
  • Permanent power. Pin 16 is live at all times, so the device's own consumption and its effect on network sleep become the vehicle owner's problem.
  • Mechanical exposure. The connector is designed for a tester that is plugged in for a session, not for a device hanging under the dashboard for years, exposed to knees, vibration and cleaning.
  • Access for others. Workshops, roadside checks and periodic inspections need the port free and working.
  • Security posture. A plug-in device with a radio link becomes part of the vehicle's attack surface, and post-R155 vehicles may log or flag unknown participants on the diagnostic segment.
Does a secure gateway stop me from reading fault codes?

No. Legislated OBD data and emission-related fault codes must stay readable without special permission. Secure gateways restrict clearing codes, actuator tests, coding and programming to authenticated testers.

Why do pins 6 and 14 measure 60 Ω even when there is no traffic at the connector?

Because the diagnostic segment is terminated at both ends like any high-speed CAN segment, but behind a gateway it only carries traffic while a tester is communicating. A quiet port with a correct 60 Ω reading is normal.

Why does the same plug-in device work on one vehicle and not on another?

The legislated layer allows four CAN variants, manufacturers place different gateway policies in front of the port, secure gateways restrict access, and newer vehicles move workshop functions to DoIP or to OBD on UDS. Each of these changes what a device sees at the connector.

Is DoIP replacing CAN at the diagnostic connector?

Not for legislated OBD in light vehicles today. DoIP uses otherwise discretionary pins of the same connector and is mainly used for fast workshop access such as software download, while pins 6 and 14 continue to carry diagnostic CAN.

What changes with OBD on UDS?

The legislated content moves from the classic $01 to $0A services to UDS services, the same protocol workshops use for manufacturer diagnostics. California requires it from model year 2027. Testers need to support both for years to come.

End of articleUpdated 7 października 2026
[Santim SC-1]

Every CAN vehicle. Ready from day one.

Santim SC-1 supports every classic CAN and CAN FD vehicle on the market. When a new vehicle launches, it is compatible instantly. No waiting, no requests. A next-generation CAN device.

The Santim SC-1 CAN device