TCU Protocol SH7055S (not DensoBoot)

Discussion about TCU protocols

Moderator: Global Moderator

Post Reply
Zombie47
Newbie
Posts: 33
Joined: Thu Oct 30, 2025 12:02 am

TCU Protocol SH7055S (not DensoBoot)

Post by Zombie47 »

Hi MiikaS, Regarding the DensoBoot protocol, we figured it out and fixed it together. Now I'm curious to understand the protocol that is not DensoBoot. Is it simply called "Subaru boot," or what is its correct name?

The Subaru ECU with the SH7058 can be read in FastECU via CAN using IDs 7E0 and 7E8 (ssmk_can_sh7058.bin). Everything works fine, here is the beginning of the reading log from FastEcu:

Code: Select all

"[2025-11-24 03:52:36.336] (DD) J2534: Interface opened succesfully!"
"[2025-11-24 03:52:37.601] (II) Connecting to Subaru 07+ 32-bit CAN bootloader, please wait..."
"[2025-11-24 03:52:37.601] (II) Checking if kernel is already running..."
"[2025-11-24 03:52:37.605] (II) Requesting kernel ID"
"[2025-11-24 03:52:37.605] (DD) Sent: 00 00 07 e0 be ef 00 01 01 00 00 00 "
"[2025-11-24 03:52:38.612] (DD) Response: "
"[2025-11-24 03:52:38.612] (EE) No valid response from ECU"
"[2025-11-24 03:52:38.612] (II) No response from kernel, initialising ECU..."
"[2025-11-24 03:52:38.612] (II) Initialising connection..."
"[2025-11-24 03:52:38.612] (DD) Sent: 00 00 07 e0 01 00 "
"[2025-11-24 03:52:38.663] (DD) Response: 00 00 07 e8 41 00 80 00 00 00 "
"[2025-11-24 03:52:38.664] (II) Requesting ECU ID"
"[2025-11-24 03:52:38.664] (DD) Sent: 00 00 07 e0 aa "
"[2025-11-24 03:52:38.715] (DD) Response: 00 00 07 e8 ea a2 10 0f 52 04 50 40 07 f3 fa c9 8c 0b 83 fe "
"[2025-11-24 03:52:38.715] (II) ECU ID: 5204504007"
"[2025-11-24 03:52:38.715] (II) Requesting VIN"
"[2025-11-24 03:52:38.715] (DD) Sent: 00 00 07 e0 09 02 "
"[2025-11-24 03:52:40.774] (DD) Response: "
"[2025-11-24 03:52:40.774] (EE) No valid response from ECU"
"[2025-11-24 03:52:40.775] (II) Requesting CAL ID"
"[2025-11-24 03:52:40.775] (DD) Sent: 00 00 07 e0 09 04 "
"[2025-11-24 03:52:40.825] (DD) Response: 00 00 07 e8 49 04 02 41 32 54 42 31 30 30 41 00 00 00 00 00 "
"[2025-11-24 03:52:40.826] (II) CAL ID: A2TB100A"
"[2025-11-24 03:52:40.826] (II) Requesting CVN"
"[2025-11-24 03:52:40.826] (DD) Sent: 00 00 07 e0 09 06 "
"[2025-11-24 03:52:40.877] (DD) Response: 00 00 07 e8 49 06 01 fa 64 99 f3 "
"[2025-11-24 03:52:40.877] (II) CVN: FA6499F3"
"[2025-11-24 03:52:40.877] (II) Requesting session mode"
"[2025-11-24 03:52:40.877] (DD) Sent: 00 00 07 e0 10 03 "
"[2025-11-24 03:52:40.927] (DD) Response: 00 00 07 e8 7f 10 22 "
"[2025-11-24 03:52:40.927] (EE) Wrong response from ECU: Conditions not correct"
"[2025-11-24 03:52:40.928] (DD) Sent: 00 00 07 e0 10 43 "
"[2025-11-24 03:52:40.978] (DD) Response: 00 00 07 e8 50 43 "
"[2025-11-24 03:52:40.978] (II) Requesting seed"
"[2025-11-24 03:52:40.978] (DD) Sent: 00 00 07 e0 27 01 "
"[2025-11-24 03:52:41.029] (DD) Response: 00 00 07 e8 67 01 23 44 cc 43 "
"[2025-11-24 03:52:41.029] (II) Seed request ok"
"[2025-11-24 03:52:41.029] (II) Using stock seed key algo"
"[2025-11-24 03:52:41.029] (II) Seed: 0x2344cc43"
"[2025-11-24 03:52:41.029] (II) Seed key: 0xa5a1b8f6"
"[2025-11-24 03:52:41.029] (II) Sending seed key"
"[2025-11-24 03:52:41.029] (DD) Sent: 00 00 07 e0 27 02 a5 a1 b8 f6 "
"[2025-11-24 03:52:41.079] (DD) Response: 00 00 07 e8 67 02 "
"[2025-11-24 03:52:41.079] (II) Seed key ok"
"[2025-11-24 03:52:41.079] (II) Set session mode"
"[2025-11-24 03:52:41.079] (DD) Sent: 00 00 07 e0 10 42 "
"[2025-11-24 03:52:41.130] (DD) Response: 00 00 07 e8 50 42 "
"[2025-11-24 03:52:41.130] (II) Succesfully set to programming session"
"[2025-11-24 03:52:41.130] (DD) void MainWindow::external_logger(QString)"
" Preparing, please wait..."
"[2025-11-24 03:52:41.130] (II) Initializing Subaru 07+ 32-bit CAN kernel upload, please wait..."
"[2025-11-24 03:52:41.130] (DD) Start address to upload kernel: 0xffff3000"
"[2025-11-24 03:52:41.131] (II) Initialize kernel upload"
"[2025-11-24 03:52:41.132] (DD) Sent: 00 00 07 e0 34 04 33 ff 30 00 00 19 80 "
"[2025-11-24 03:52:41.183] (DD) Response: 00 00 07 e8 74 20 00 84 "
"[2025-11-24 03:52:41.183] (II) Uploading kernel, please wait..."
The full log is in the attached screenshot:
readA2TB100Aok.jpg
readA2TB100Aok.jpg (466.55 KiB) Viewed 45011 times
However, for the Subaru TCU with the SH7055s (which, as we know, is 180nm), I only see one suitable protocol: sub_tcu_denso_sh7055_can. But this is definitely not the correct protocol because I see this in the log:

Code: Select all

"[2025-11-24 03:17:33.661] (II) Requesting kernel ID"
"[2025-11-24 03:17:33.661] (DD) Sent: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:33.668] (II) Kernel ID request: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:34.577] (DD) Response: "
"[2025-11-24 03:17:34.577] (II) Kernel ID response: "
"[2025-11-24 03:17:34.577] (DD) Sent: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:34.584] (II) Kernel ID request: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:35.497] (DD) Response: "
"[2025-11-24 03:17:35.497] (II) Kernel ID response: "
"[2025-11-24 03:17:35.497] (DD) Sent: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:35.503] (II) Kernel ID request: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:36.405] (DD) Response: "
"[2025-11-24 03:17:36.405] (II) Kernel ID response: "
"[2025-11-24 03:17:36.405] (DD) Sent: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:36.412] (II) Kernel ID request: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:37.320] (DD) Response: "
"[2025-11-24 03:17:37.320] (II) Kernel ID response: "
"[2025-11-24 03:17:37.320] (DD) Sent: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:37.327] (II) Kernel ID request: 00 00 07 e1 7a a0 00 00 00 00 00 00 "
"[2025-11-24 03:17:38.240] (DD) Response: "
"[2025-11-24 03:17:38.240] (II) Kernel ID response: "
"[2025-11-24 03:17:38.240] (EE) No valid response from ECU"
"[2025-11-24 03:17:38.240] (II) No response from kernel, initialising ECU..."
"[2025-11-24 03:17:38.240] (II) Requesting ECU ID"
"[2025-11-24 03:17:38.240] (DD) Sent: 00 00 07 e1 aa "
"[2025-11-24 03:17:38.291] (DD) Response: 00 00 07 e9 ea a2 10 21 97 d1 60 62 00 01 00 80 04 00 00 00 "
"[2025-11-24 03:17:38.292] (II) ECU ID: 97D1606200"
"[2025-11-24 03:17:38.292] (II) Requesting CAL ID"
"[2025-11-24 03:17:38.292] (DD) Sent: 00 00 07 e1 09 04 "
"[2025-11-24 03:17:38.342] (DD) Response: 00 00 07 e9 49 04 01 50 46 44 31 36 57 41 32 00 00 00 00 00 "
"[2025-11-24 03:17:38.342] (II) CAL ID: PFD16WA2"
"[2025-11-24 03:17:38.342] (II) Requesting session mode"
"[2025-11-24 03:17:38.342] (DD) Sent: 00 00 07 e1 10 03 "
"[2025-11-24 03:17:38.392] (DD) Response: 00 00 07 e9 7f 10 22 "
"[2025-11-24 03:17:38.392] (EE) Wrong response from TCU: Conditions not correct"
"[2025-11-24 03:17:38.392] (DD) void MainWindow::external_logger(QString)"
" Finished"
Why can't FastECU read this TCU? I see that it doesn't even request the seed/key, but in manual mode, I can request the seed.
Here is the file:
PFD16WA2 30919AA850_SH_4AT_SIDRIVE.bin.rar
(512 KiB) Downloaded 448 times
This is not a RAR file, please change the extension.
I have been analyzing the code in IDA. At first glance, I can see some differences in the commands and the security table. For example:
ROM_PFD16WA2:00001D5C seed_table: .word 0xC85B,0x32C0,0xE282,0x92A0
However, the SBOX_Table appears to be the same:
ROM_PFD16WA2:00001D64 SBOX_Table: .byte 5, 6, 7, 1, 9, 0xC, 0xD, 8
ROM_PFD16WA2:00001D6C .byte 0xA, 0xD, 2, 0xB, 0xF, 4, 0, 3
ROM_PFD16WA2:00001D74 .byte 0xB, 4, 6, 0, 0xF, 2, 0xD, 9
ROM_PFD16WA2:00001D7C .byte 5, 0xC, 1, 0xA, 3, 0xD, 0xE, 8
How can I help? What information should I provide to fix this issue and to further improve FastECU for reading and flashing these TCUs?
I assume that the protocol is somewhat similar to the SH7058 ECU protocol. The differences likely lie in the flash memory size, the CAN IDs used, some specific commands, and the seed/key algorithm, particularly since the table is not made of 16 words but of 4.
Zombie47
Newbie
Posts: 33
Joined: Thu Oct 30, 2025 12:02 am

Re: TCU Protocol SH7055S (not DensoBoot)

Post by Zombie47 »

Sorry for the desinformation, but I found that there are two initial value tables. The main one is:
ROM_PFD16WA2:00050D50 Initial value table: .word 0x78B1,0x4625,0x201C,0x9EA5,0xAD6B,0x35F4,0xFD21,0x5E71,0xB046,0x7F4A,0x4B75,0x93F9,0x1895,0x8961,0x3ECC,0x862B
It is identical to the SH7058 ECU.
MiikaS
Administrator
Posts: 973
Joined: Sat Jul 04, 2020 7:13 pm
Location: Mikkeli, Finland

Re: TCU Protocol SH7055S (not DensoBoot)

Post by MiikaS »

I'm bit busy for few days, but try to look at this as soon as I have free time.

I think those 4 word values are used for data encryption, other set is for security access.
rimwall
Sr. Member
Posts: 313
Joined: Tue Jul 16, 2024 3:03 am

Re: TCU Protocol SH7055S (not DensoBoot)

Post by rimwall »

The successful ECU log shows it tries 0x10 0x03, which fails, and then tries 0x10 0x43 which works

The TCU log only tries 0x10 0x03 and then bombs out. My guess is that sub_tcu_denso_sh7055_can needs an update to also try 0x10 0x43 if 0x10 0x03 fails.
Post Reply