ECUReset (0x11)
UDS ECUReset (0x11) restarts an ECU. The reset types, the request and response bytes, which session it needs and what to validate on the bench.
Updated This page as Markdown
In short
ECUReset (0x11) tells a UDS server to restart. The sub-function selects the type: hardReset (01), keyOffOnReset (02), softReset (03) and others. The request 11 01 asks for a hard reset, the positive response 51 01 confirms it before the ECU reboots. It usually requires the extended session. A reset ends the session and drops every session-dependent state, which makes it a key step in session-handling tests.
What is ECUReset (0x11)?
ECUReset is the UDS service that restarts an ECU under tester control. The sub-function byte selects the reset type. The ECU sends the positive response first and then performs the reset, so the tester can see the acknowledgement before the server disappears for a moment.
A normal exchange:
| Direction | Bytes | Meaning |
|---|---|---|
| Request | 11 01 | hardReset |
| Positive response | 51 01 | reset accepted, ECU reboots |
| Negative response | 7F 11 33 | securityAccessDenied |
Other typical negative responses are 7F 11 7F (serviceNotSupportedInActiveSession, reset requested from the default session when the ECU requires the extended session), 7F 11 12 (subFunctionNotSupported for an unknown reset type), 7F 11 13 (incorrectMessageLengthOrInvalidFormat) and 7F 11 22 (conditionsNotCorrect, for example the engine is running).
Where is it defined?
ISO 14229-1:2020 defines ECUReset (0x11) in the Diagnostic and communication management functional unit. The standard lists the reset types, the response format including the powerDownTime byte for rapid power shutdown, and the rule that a reset returns the server to the default session. On CAN the transport is ISO 15765-2.
What it means in practice
Most ECUs allow ECUReset only in the extended or programming session, and often behind SecurityAccess, because an uncontrolled reset of a running controller is dangerous. In validation, engineers check:
- the service answers only in the sessions and at the security level the specification allows;
- a wrong length (
11alone or11 01 00) gives NRC 0x13; - an unknown sub-function gives NRC 0x12;
- the ECU actually comes back after the reset and in the default session;
- conditions such as a running engine correctly produce conditionsNotCorrect instead of a reset.
On the bench, reset handling is where session bugs surface. We regularly see ECUs that hang or need a power cycle after a soft reset, and ECUs that do not drop a security unlock across a keyOffOnReset, which they must.
How AutoST tests it
AutoST flags ECUReset during enumeration as a risky service, records in which sessions it answers and with which negative response codes, and confirms the ECU returns cleanly to the default session. In fuzzing, a TesterPresent liveness check after every iteration catches an ECU that reset or hung in response to a payload, and the exact payload that preceded it is stored so the reset can be replayed.
FAQ
Frequently asked questions
What reset types does ISO 14229-1 define?
hardReset (0x01), keyOffOnReset (0x02), softReset (0x03), enableRapidPowerShutDown (0x04) and disableRapidPowerShutDown (0x05). Values 0x40 to 0x5F and 0x60 to 0x7E are reserved for manufacturers and suppliers.
What does the ECU send back for enableRapidPowerShutDown?
The positive response to sub-function 0x04 adds one byte, powerDownTime in seconds, for example 51 04 0A. The other reset types answer with two bytes, 51 plus the reset type.
Does a reset drop a security unlock?
Yes. A reset returns the ECU to the default session, and every session-dependent state, including an unlocked security level, DTC setting and communication control, returns to its default.
Sources
Related pages
- GlossaryUDS (Unified Diagnostic Services)UDS (ISO 14229) is the diagnostic protocol of most automotive ECUs: sessions, services, DIDs and SecurityAccess. What it defines and why it is the first attack surface.
- GlossaryDiagnostic session (DiagnosticSessionControl 0x10)UDS DiagnosticSessionControl (0x10) switches an ECU between default, extended and programming session. Bytes, timing parameters and what to validate.
- GlossaryTesterPresent (0x3E)UDS TesterPresent (0x3E) keeps a non-default session alive. Request and response bytes, the suppress bit, the S3 server timer, and the session bugs it exposes.
- PlatformKnow every door into the ECU.AutoST enumerates an ECU over UDS: diagnostic endpoints, sessions, all 255 services and readable DIDs, plus XCP/CCP discovery. Risky services are flagged automatically.
- InsightsECU reset and session handling bugs, and how to test themHow to test UDS session and reset handling: session fallback, S3 timeout, security state after reset, TesterPresent keeping a session alive, and what each result means.
- Free toolsUDS Negative Response Code DecoderDecode a UDS negative response in a second: paste 7F 27 35 or a bare code and get the ISO 14229 name, the rejected service and what it means on the bench. Full NRC table.
