ISO-TP (ISO 15765-2)
ISO-TP (ISO 15765-2) splits UDS messages into CAN frames: single, first, consecutive and flow-control frames. How it works and why malformed frames crash ECUs.
Updated This page as Markdown
In short
ISO-TP is the transport protocol from ISO 15765-2 that carries diagnostic messages longer than one CAN frame. It splits a message into a first frame and consecutive frames, and the receiver paces the transfer with flow-control frames (block size and separation time STmin). Messages that fit go in a single frame. Every UDS request on CAN or CAN FD travels over ISO-TP, so its parser is the first code in the ECU that touches attacker-controlled bytes.
What is ISO-TP?
ISO-TP is the network and transport layer that lets a diagnostic message longer than one CAN frame travel over CAN or CAN FD. The first nibble of each frame, the protocol control information (PCI), says what kind of frame it is:
| PCI | Frame | Meaning |
|---|---|---|
0x0N | Single frame | Whole message, N bytes (up to 7 on classic CAN) |
0x1N NN | First frame | Start of a segmented message, 12-bit total length |
0x2N | Consecutive frame | Next segment, sequence number N from 1 to F, then 0 again |
0x30 / 0x31 / 0x32 | Flow control | Continue, wait, overflow; followed by block size and STmin |
Reading a 20-byte VIN response looks like this with normal addressing. The tester sends 03 22 F1 90 55 55 55 55 (single frame, padding 55). The ECU answers with a first frame 10 14 62 F1 90 57 56 57 (0x014 = 20 bytes), the tester replies 30 00 00 (continue, no block limit, no gap) and the ECU sends 21 ... and 22 ... with the remaining 14 bytes.
Where is it defined?
ISO 15765-2 defines the frame types, the addressing formats (normal, extended, mixed, and normal fixed for 29-bit identifiers), the flow-control parameters and the timers N_As, N_Bs, N_Cr and the others. The 2016 edition added CAN FD support and the escape sequences for longer single and first frames; the current edition is ISO 15765-2:2024. CAN itself is ISO 11898-1, and UDS on top is ISO 14229.
What it means in practice
ISO-TP is where an ECU first parses bytes that a tester, or an attacker, controls. The reassembly code allocates a buffer from the length in the first frame, counts sequence numbers and runs timers, all before the UDS layer sees anything. That makes it a classic place for memory bugs.
We regularly see ECUs that reset or hang when a first frame announces a length the buffer cannot hold, when the announced length is smaller than the data already sent, when consecutive frames arrive out of sequence or when a sender ignores STmin. On power-electronics ECUs we have seen a single malformed first frame stop the diagnostic stack until a power cycle. Wrong padding and a mismatched addressing format are the other common bench problems: the ECU simply stays silent, which looks like “no diagnostics” until you try the right format.
How AutoST tests it
AutoST finds ISO-TP endpoints during enumeration by probing request and response identifier pairs, then runs every UDS test over the transport. The UDS fuzzing engine sends payloads up to 128 bytes, which forces segmented transfers with first, consecutive and flow-control frames, and a TesterPresent liveness check after every iteration flags an ECU whose transport stopped answering.
Common misunderstandings
ISO-TP does not add security. Flow control is a pacing mechanism, not an access check, and a frame that breaks the rules is supposed to be ignored, not to crash the ECU. Also, a silent ECU is not proof that diagnostics are disabled: the addressing format or padding may simply not match.
FAQ
Frequently asked questions
What is the maximum message length in ISO-TP?
With the classic 12-bit length field in the first frame, 4095 bytes. Since the 2016 edition, a first frame with length 0 is followed by a 32-bit length (the escape sequence), which allows much longer messages, mainly used with CAN FD and for flashing.
What do block size and STmin mean?
Both are sent by the receiver in the flow-control frame. Block size says how many consecutive frames the sender may send before waiting for the next flow control (0 means all of them). STmin is the minimum gap between consecutive frames: 0x00 to 0x7F are milliseconds, 0xF1 to 0xF9 are 100 to 900 microseconds.
Is ISO-TP only used for UDS?
It is mostly used for UDS and OBD diagnostics on CAN, but any protocol that needs longer messages on CAN can use it. Over Ethernet, DoIP replaces it, because TCP already handles segmentation.
Sources
- ISO 15765-2:2024 Road vehicles, Diagnostic communication over CAN (DoCAN), Part 2: Transport protocol and network layer services
- ISO 14229-1:2020 Road vehicles, Unified diagnostic services (UDS), Part 1: Application layer
- ISO 11898-1:2015 Road vehicles, Controller area network (CAN), Part 1: Data link layer and physical signalling
Related pages
- GlossaryCAN Bus (Controller Area Network)CAN (ISO 11898) is the broadcast bus most ECUs share: identifiers, arbitration, error handling. Why any node can send any frame and what that means for security testing.
- GlossaryCAN FD (CAN with Flexible Data Rate)CAN FD extends classic CAN to 64 data bytes and a faster data phase. How the DLC, BRS bit and bit timing work and what changes for diagnostics and fuzzing.
- GlossaryUDS (Unified Diagnostic Services)UDS (ISO 14229) is the diagnostic protocol of most automotive ECUs: sessions, services, DIDs and SecurityAccess. What it defines and why it is the first attack surface.
- Free toolsISO-TP Frame CalculatorHow many CAN frames does a UDS message need? Enter the payload length, pick classic CAN or CAN FD and flow control: first, consecutive and flow-control frames and timing.
- InsightsA UDS fuzzing methodology that finds real bugsHow to fuzz an ECU over UDS without wasting runs: where to inject, how to detect a crash, how to make a finding reproducible, and how to stay on the bench.
- PlatformBreak it on the bench, not in the field.AutoST fuzzes ECUs over UDS and CAN with reproducible seeds and live crash detection via TesterPresent and DTC monitoring. Built for benches, never for the road.
