EPEVER SCCs: Difference between revisions
Symbioquine (talk | contribs) No edit summary |
Symbioquine (talk | contribs) |
||
| (5 intermediate revisions by the same user not shown) | |||
| Line 27: | Line 27: | ||
Tracer8420AN/Tracer10420AN | Tracer8420AN/Tracer10420AN | ||
|Solar Charge Controller | |Solar Charge Controller | ||
|STM32F051C8T7 | |[https://www.st.com/en/microcontrollers-microprocessors/stm32f051c8.html STM32F051C8T7] | ||
[https://www.ti.com/lit/ds/symlink/tms320f28023.pdf TMS320F28023PT] | |||
|J2 | |J2 | ||
|- | |- | ||
| Line 42: | Line 42: | ||
Tracer3210AN/Tracer4210AN | Tracer3210AN/Tracer4210AN | ||
|Solar Charge Controller | |Solar Charge Controller | ||
|STM32F030C8T6 | |[https://www.st.com/en/microcontrollers-microprocessors/stm32f030c8.html STM32F030C8T6] | ||
|J6 | |J6 | ||
|- | |- | ||
| Line 50: | Line 50: | ||
TRIRON4210N/TRIRON4215N | TRIRON4210N/TRIRON4215N | ||
|Solar Charge Controller | |Solar Charge Controller | ||
|STM32F030C8T6 | |[https://www.st.com/en/microcontrollers-microprocessors/stm32f030c8.html STM32F030C8T6] | ||
|J6 | |J6 | ||
|- | |- | ||
| Line 68: | Line 68: | ||
XTRA3415N/XTRA4415N | XTRA3415N/XTRA4415N | ||
|Solar Charge Controller | |Solar Charge Controller | ||
|STM32F030C8T6 | |[https://www.st.com/en/microcontrollers-microprocessors/stm32f030c8.html STM32F030C8T6] | ||
|J6 | |J6 | ||
|- | |- | ||
| Line 84: | Line 84: | ||
| | | | ||
|- | |- | ||
|MT50 | |MT50 | ||
|Configuration Tool / Display | |Configuration Tool / Display | ||
|STM32F030C8T6 | |[https://www.st.com/en/microcontrollers-microprocessors/stm32f051k8.html STM32F051K8] | ||
|F2/F9 | |||
|- | |||
|MT52 | |||
|Configuration Tool / Display | |||
|[https://www.st.com/en/microcontrollers-microprocessors/stm32f030c8.html STM32F030C8T6] | |||
|F2/F9 | |F2/F9 | ||
|- | |- | ||
| Line 96: | Line 101: | ||
|PAL-ADP-50AN | |PAL-ADP-50AN | ||
|Synchronization Accessory | |Synchronization Accessory | ||
|STM32F030C8T6 | |[https://www.st.com/en/microcontrollers-microprocessors/stm32f030c8.html STM32F030C8T6] | ||
|J1 | |J1 | ||
|} | |} | ||
===Decrypting Firmware Update (.prg) Files=== | |||
Bytes 18 thru the end of the file can be decrypted with AES CBC IV=[all zeroes] keys below. Pad with pkcs7 16 byte block size. | |||
'''Key for Larger 50A - 100A units''' | |||
::<code>54726163 72414e43 0cdd527b 05c16b01 ff17cd6f 8c1e3e09 cf1f0c78 87ef8aec</code> | |||
'''Key for Smaller 10A - 40A units''' | |||
::<code>54726952 6f6e2eda 0cdd527b 05c16b01 ff17cd6f 8c1e3e09 cf1f0c78 87ef8aec</code> | |||
https://gist.github.com/symbioquine/88e7148b4df143822f3b0d565619f80b | |||
===Dumping Firmware=== | |||
Works with https://github.com/racerxdl/stm32f0-pico-dump (See SWD pins in top table) | |||
===Unlocking SWD=== | |||
<syntaxhighlight lang="bash"> | |||
openocd -s $(pwd) -f interface/stlink-dap.cfg -f target/stm32f0x.cfg | |||
telnet localhost 4444 | |||
reset init | |||
stm32f0x unlock 0 | |||
flash erase_address unlock 0x08000000 0x10000 | |||
</syntaxhighlight> | |||
::Power cycle & reconnect st-link | |||
<syntaxhighlight lang="bash"> | |||
flash write_image /path/to/dumped_firmware.bin 0x08000000 | |||
reset | |||
</syntaxhighlight> | |||
===Dumping Running RAM=== | |||
<syntaxhighlight lang="bash"> | |||
halt | |||
dump_image /path/to/save/tracer6420an_running_ram.bin 0x20000000 0x2000 | |||
resume | |||
</syntaxhighlight> | |||
=== Protocol Documentation === | |||
{| class="wikitable" | |||
|[https://diysolarforum.com/resources/epever-scc-modbus-protocol-docs.512/version/878/download?file=329342 1733_modbus_protocol.pdf] | |||
|V1.1 | |||
|FENG | |||
|2013-11-25 | |||
|234.2 KB | |||
|86c05193b7f6e1945eb67616c6658366ef4033b110f506a33c1eeef03b0eafbf | |||
|- | |||
|[https://diysolarforum.com/resources/epever-scc-modbus-protocol-docs.512/version/878/download?file=329340 EpeverBSeriesControllerProtocolV2.3.pdf] | |||
|V2.3 | |||
|sunb | |||
|2015-10-22 | |||
|374.8 KB | |||
|a3fccf914928118def85223482e3091956d046810a01c20152006e6f68c61b70 | |||
|- | |||
|[https://diysolarforum.com/resources/epever-scc-modbus-protocol-docs.512/version/878/download?file=329339 MODBUS-Protocol-v25.pdf] | |||
|V2.5 | |||
|sunb | |||
|2018-09-27 | |||
|847.6 KB | |||
|d0f9f08be06b5125134c3be24d9acc1430dcd4e9e82478df68d451489aaa77fb | |||
|- | |||
|[https://diysolarforum.com/resources/epever-scc-modbus-protocol-docs.512/version/928/download?file=387834 DuoRacer SeriesControllerProtocolv2.6.pdf] | |||
|V2.6 | |||
|sunb | |||
|2021-11-24 | |||
|638.9 KB | |||
|6c7e98387d9dd8372fd63b5ee499bef706e63fd0d5a0986ea657de27c83cfe91 | |||
|- | |||
|[https://diysolarforum.com/resources/epever-scc-modbus-protocol-docs.512/version/878/download?file=329341 A or BSeriesControllerProtocolv2.6.pdf] | |||
|V2.6 | |||
|sunb | |||
|2021-12-21 | |||
|711.9 KB | |||
|3c2cf42f5f440d06db36280d41f0a8dd632da32396b820529db76eef53fd4351 | |||
|} | |||
Modbus Protocol Investigation: https://diysolarforum.com/threads/epever-tracer-modbus-digging-deeper.108305/ | |||