EEPROM Map
Full memory map of the Lucas 5AS EEPROM — offsets, encodings, and detailed field descriptions.
Offsets are positions within the EEPROM image.
Quick reference
| Offset | Size | Field | Encoding |
|---|---|---|---|
0x00 bit 0 | flag | Microcontroller security flag | active low |
0x00 bit 1 | flag | EEPROM protection flag | active low |
0x20 | 1 | Passive arm time (ignition & door) | ×1 s |
0x21 | 1 | Passive arm time (no ignition) | ×1 s |
0x36 bit 1 | flag | Hazards flash with alarm | active low |
0x36 bit 2 | flag | Superlocking enabled 1 | active low; inverse of 0x9A bit 2 |
0x37 bit 6 | flag | Passive arming enabled | active low |
0x38 bit 2 | flag | Low battery flash LED on unlock | active high |
0x38 bit 3 | flag | Low battery double key press | active high |
0x3B | 2 | MEMS ECU code | hex, LSB first |
0x3E bit 0 | flag | Switch closed when bonnet open | active high |
0x42 | 4 | Key fob 1 code | hex, LSB first |
0x46 | 4 | Key fob 2 code | hex, LSB first |
0x4A | 4 | Key fob 3 code | hex, LSB first |
0x4E | 4 | Key fob 4 code | hex, LSB first |
0x53 | 1 | Number of key fobs | 1–4 |
0x89 | 1 | LED pattern mask (disarmed) | see encoding |
0x92 | 1 | LED pattern mask (armed) | see encoding; Revill said 0x90 |
0x9A bit 2 | flag | Superlocking enabled 2 | active high; inverse of 0x36 bit 2 |
0x9C | 3 | Alarm serial number 1 (this alarm) | decimal, LSB first; copy at 0xC7 |
0xA0 | 2 | Emergency key access code | BCD, MSB first |
0xAD | 1 | Passive arm time (ignition only) | ×8 s |
0xC7 | 3 | Alarm serial number 2 (template used) | decimal, LSB first; copy at 0x9C |
0xCF | 1 | Week of manufacture | BCD |
0xD0 | 2 | Year of manufacture | BCD, MSB first |
Identification and manufacture
Alarm serial number — 0x9C and 0xC7, 3 bytes each, decimal, LSB first. The serial printed on the case-front label. Stored twice, normally identical; believed informational only. Revill's convention for re-flashed units: this unit's real serial at 0x9C, the donor template's serial at 0xC7.
MEMS ECU code — 0x3B, 2 bytes, hex, LSB first. Unique immobiliser identity sent to the MEMS ECU. Any value except 0x0000, 0xFFFF and 0xF0F0.
Week / year of manufacture — 0xCF (1 byte) and 0xD0 (2 bytes), BCD, MSB digit first. From the case label; believed informational only.
LED flash patterns (in progress — offsets may differ)
Armed at 0x92, disarmed at 0x89, 1 byte each, identical encoding. The mask ranges from permanently off, through one or more flashes per cycle, to permanently on.
| Mask | Bits | Pattern |
|---|---|---|
0x00 | 00000000 | Off (default disarmed) |
0xFF | 11111111 | On 8 ms, off 1016 ms (default armed) |
0xFE | 11111110 | On 16 ms, off 1008 ms |
0xFC | 11111100 | On 32 ms, off 992 ms (preferred armed) |
0xF8 | 11111000 | On 64 ms, off 960 ms |
0xF0 | 11110000 | On 128 ms, off 896 ms |
0xE0 | 11100000 | On 256 ms, off 768 ms |
0xC0 | 11000000 | On 512 ms, off 512 ms |
0xBC | 10111100 | On 32 ms, off 480 ms |
0xA0 | 10100000 | On 256 ms, off 256 ms |
0x90 | 10010000 | On 128 ms, off 128 ms |
0x88 | 10001000 | On 64 ms, off 64 ms |
Decoding:
- Take a 7-bit counter incrementing every 8 ms (wraps after 1024 ms).
- AND the counter with the low 7 bits of the mask.
- If the result is zero, take the mask's high bit; otherwise its inverse.
- That bit is the LED state — 1 = on, 0 = off.
Low battery warning
- Flash LED on unlock —
0x38bit 2, active high. LED double-pulses for a few seconds after unlock when the fob reports low battery. A further setting is believed to control how many consecutive low-battery messages trigger it, but hasn't been located. - Double key press —
0x38bit 3, active high. When the fob reports low battery, its button must be pressed twice, giving the impression it's failing.
Passive arming
Enabled — 0x37 bit 6, active low. When 0, the immobiliser (not the alarm) re-engages automatically after a timeout. When 1, it never re-engages once disengaged, and this persists across power cycles.
Three timeouts apply depending on state. 0 fires immediately (it does not wrap to 256):
- No ignition —
0x21, ×1 s, 1–255 s. Unlocked, ignition never on. Default ~30 s. - Ignition & door —
0x20, ×1 s, 1–255 s. Unlocked, ignition on then off, then driver's door opened. Default ~30 s. (No driver's-door switch on a Caterham, so this case never arises there.) - Ignition only —
0xAD, ×8 s, 8–2040 s. Unlocked, ignition on then off. Default 75 (= 600 s / 10 min). Ticks come from a free-running 8 s clock, so N×8 s actually fires between (N−1)×8 s and N×8 s.
Locking and alarm behaviour
Superlocking — Rover deadlocking, where a double-click of the fob lock button mechanically locks out the doors. Controlled by two bits that are always inverses: 0x36 bit 2 (active low) and 0x9A bit 2 (active high). To disable, set 0x36 bit 2 = 1 and 0x9A bit 2 = 0. Both appear to be required — every unit seen with it disabled has both inverted. Irrelevant on a Caterham.
- Hazards flash with alarm —
0x36bit 1, active low. When 0, the hazards pulse with the alarm. - Switch closed when bonnet open —
0x3Ebit 0, active high. When 1, the bonnet reads as closed when the input is open-circuit (and open when shorted to ground); when 0, the sense is inverted.