Detailed Explanation of Modbus ASCII Data Message Structure

freeFree Technical Resource

This content is free to read, suitable for basic learning and search traffic.

Detailed Explanation of Modbus ASCII Data Message Structure

Modbus ASCII is a type of message frame in Modbus. Compared to RTU, ASCII transmission is based on character transmission, and the amount of data transmitted will be larger than that of RTU. Therefore, RTU is generally used when the data volume is large, and ASCII is only used when the data volume is small. Then, the ASCII protocol frame adds start and end, and changes the verification algorithm. Below is a detailed introduction to the ASCII protocol

frame format

Modbus ASCII The communication frame format in the mode is as follows:

NameLength (byte)Description
Start1Using a colon : beginning, ASCII The hexadecimal value is 3A
Address2Hexadecimal Node Address, Character representation
Function2Hexadecimal function code, Character representation
Datan x 2n It is the number of data bytes, It depends on the function code
LRC2LRCRedundancy check code
End2CR / LF

Note:address, Function, data and LRC All indicate 8 Place value (0-255) Uppercase hexadecimal readable character pairsThat is: in Modbus ASCII In the middle,Each data byte is divided into two representing hexadecimal values ASCII Two bytes of a character.

ComponentDescriptioncharacter countASCIIexpress
StartMessage begins1 CHAR:
AddressNode Address (Hexadecimal representation) 2 CHARS
Functionfunction code (Hexadecimal representation) 2 CHARS
Datadata (According to changes in the function code, Hexadecimal representation) n CHARS
LRC CHECKVertical redundancy check code (LRC) 2 CHARS
ENDMessage ends, carriage return and line feed2 CHARSCRLF

in ASCII Under the mode, Modbus Each part of the message appears in a specific number of characters and format, as shown below:

:AA BB CC...DD EE<CRLF>
  • : - The starting symbol of a message.
  • AA - Node Address, Hexadecimal representation.
  • BB - function code, Hexadecimal representation.
  • CC...DD - data field, Change in length of data to be transmitted based on function code.
  • EE - LRC Verification code, Used for error detection.
  • <CRLF> - End symbol of message, Represents carriage return and line break (Carriage Return Line Feed) .
Detailed Explanation of Modbus ASCII Data Message StructureFigure

ASCIITransmission status of frames

Detailed Explanation of Modbus ASCII Data Message StructureFigure1

The information that can be obtained from the state diagram above:

1) “free” State is a normal state where there are no messages to be sent or received for processing.

2) Every time received ":" Characters represent the beginning of a new message. If the character is received during the reception process of a message, The current message is considered incomplete and discarded. And a new receiving buffer is reallocated.

3) After detecting the end of the frame, Complete LRC Calculation and verification. then, Analyze the address domain to determine if the frame is being sent to this device, if not, Discard this frame. In order to reduce the receiving and processing time, The address domain can be analyzed immediately upon receipt, And there's no need to wait until the end of the entire frame.

ASCIIFrame based message transmission

Due toASCIIMessage frames andRTUMessage frames have significant differences, ASCIIMessage frames have start and end identifiersButRTUThe frame does not have such an identifier. SoASCIIReceiving message frames is much simpler and more convenient, I don't need anything eithert3.5The frame interval time.

But then, To ensure the continuity of the received message frames, It is still possible to agree on the transmission time between characters. It is generally believed, The time interval between characters in the message can reach one second, If this time interval is exceeded, Just assume that an error has occurred, To discard this frame of message data, Restart receiving.

function code

ASCII The most commonly used functional codes in the mode and RTU The functional code definitions in the mode are the same. Here are some basic function codes and their descriptions:

Access addressmapped addressDescriptionFunctionR/W
1 ~ 10000address-1Coils01/05/15R/W
10001 ~ 20000address-10001Discrete Inputs02R
30001 ~ 40000address-30001Input Registers04R
40001 ~ 50000address-40001Holding Registers03/06/16R/W

ASCIITransmission Example

for example, To read the address 0x20C1 The two registers, Need to send the following ASCII message:

:010420C1000218<CRLF>

Request:

  • : - Message begins - 0x3A
  • 01 - slave address - 0x01
  • 04 - function code (Read input register) - 0x04
  • 20C1 - Register address to be read - 0x20C1
  • 0002 - The length of the register to be read (must be 2) - 0x0002
  • 18 - LRC Verification code
  • <CRLF> - Message ends, carriage return and line feed - 0x0D0A

Response:

:01040400001234B1<CRLF>

Response:

  • : - Message begins - 0x3A
  • 01 - slave address - 0x01
  • 04 - function code (Read input register) - 0x04
  • 04 - Read data length (4 byte) - 0x04
  • 00001234 - from VAR1 Read value - 0x00001234
  • B1 - LRC Verification code
  • <CRLF> - Message ends, carriage return and line feed - 0x0D0A

Common Function Code Operations

Here is Modbus Common function codes and their request and response examples:

Function 01 (01H) Reading coils

  • Request: Read the coil from the slave machine ON/OFF Status.
Detailed Explanation of Modbus ASCII Data Message StructureFigure2
  • Response: The coil status response message is packaged into data fields where each bit represents a coil.
Detailed Explanation of Modbus ASCII Data Message StructureFigure3

Function 02 (02H) Read discrete input

  • Request: Read discrete inputs from the slave machine ON/OFF Status.
Detailed Explanation of Modbus ASCII Data Message StructureFigure4
  • Response: The construction of discrete input state response messages is the same as that of coil states.
Detailed Explanation of Modbus ASCII Data Message StructureFigure5

Function 03 (03H) Read and hold register

  • Request: Read the binary content of the register held in the slave machine.
Detailed Explanation of Modbus ASCII Data Message StructureFigure6
  • Response: Keep register data packaged into two bytes in each register.
Detailed Explanation of Modbus ASCII Data Message StructureFigure7

Function 04 (04H) Read input register

  • Request: Read the binary content of the input register from the slave machine.
Detailed Explanation of Modbus ASCII Data Message StructureFigure8
  • Response: The construction of response messages for reading input register data is the same as reading hold registers.
Detailed Explanation of Modbus ASCII Data Message StructureFigure9

Function 05 (05H) Write a single coil

  • Request: Write a single coil into ON or OFF.
Detailed Explanation of Modbus ASCII Data Message StructureFigure10
  • Response: The normal response is the echo of the request.
Detailed Explanation of Modbus ASCII Data Message StructureFigure11

Function 06 (06H) Write a single hold register

  • Request to write a value into a single hold register. When broadcasting, This function sets the same register reference on all attached slaves. Request message to specify the register reference to be written (Specify address and numerical value) .
Detailed Explanation of Modbus ASCII Data Message StructureFigure12
  • Response

    The normal response is the echo of the request, Return after writing the contents of the hold register.

Detailed Explanation of Modbus ASCII Data Message StructureFigure13

Function 15 (0FH) Write multiple coils

  • Request: Write each coil in a coil sequence ON or OFF.
Detailed Explanation of Modbus ASCII Data Message StructureFigure14
  • Response: Normal response returned from address, Function code, Starting address and number of coils written.
Detailed Explanation of Modbus ASCII Data Message StructureFigure15

Function 16 (10H) Write multiple hold registers

  • Request: Write the value into a hold register sequence.
Detailed Explanation of Modbus ASCII Data Message StructureFigure16
  • Response: Normal response returned from address, Function code, Starting address and number of registers written.
Detailed Explanation of Modbus ASCII Data Message StructureFigure17

LRCVerification

LRC The calculation method of the verification code is as follows:

unsigned char ucMBLRC( unsigned char * pucFrame, unsigned short usLen )
{
    unsigned char ucLRC = 0;  /* LRC char initialized */

    while( usLen-- )
    {
        ucLRC += *pucFrame++;   /* Add buffer byte without carry */
    }

    /* Return twos complement */
    ucLRC = ( UCHAR ) ( -( ( CHAR ) ucLRC ) );
    return ucLRC;
}
Put this resource to use in a real project?

Go to the Tool Center for message parsing, CRC verification and device debugging, or submit your requirements for selection and integration advice.

Engineer Membership

Turn this article into actionable debugging resources

After activation, you can use advanced message parsing, resource pack downloads, code examples, engineering cases and priority technical support, suitable for real project delivery.

Unlimited Advanced Tools
Resource & Code Packs
Complete Engineering Case Library
Priority Technical Support

Leave a Reply

Your email address will not be published. Required fields are marked *.