EEPROM Map

Full memory map of the Lucas 5AS EEPROM — offsets, encodings, and detailed field descriptions.

Offsets are positions within the EEPROM image.

Quick reference

OffsetSizeFieldEncoding
0x00 bit 0flagMicrocontroller security flagactive low
0x00 bit 1flagEEPROM protection flagactive low
0x201Passive arm time (ignition & door)×1 s
0x211Passive arm time (no ignition)×1 s
0x36 bit 1flagHazards flash with alarmactive low
0x36 bit 2flagSuperlocking enabled 1active low; inverse of 0x9A bit 2
0x37 bit 6flagPassive arming enabledactive low
0x38 bit 2flagLow battery flash LED on unlockactive high
0x38 bit 3flagLow battery double key pressactive high
0x3B2MEMS ECU codehex, LSB first
0x3E bit 0flagSwitch closed when bonnet openactive high
0x424Key fob 1 codehex, LSB first
0x464Key fob 2 codehex, LSB first
0x4A4Key fob 3 codehex, LSB first
0x4E4Key fob 4 codehex, LSB first
0x531Number of key fobs1–4
0x891LED pattern mask (disarmed)see encoding
0x921LED pattern mask (armed)see encoding; Revill said 0x90
0x9A bit 2flagSuperlocking enabled 2active high; inverse of 0x36 bit 2
0x9C3Alarm serial number 1 (this alarm)decimal, LSB first; copy at 0xC7
0xA02Emergency key access codeBCD, MSB first
0xAD1Passive arm time (ignition only)×8 s
0xC73Alarm serial number 2 (template used)decimal, LSB first; copy at 0x9C
0xCF1Week of manufactureBCD
0xD02Year of manufactureBCD, MSB first

Identification and manufacture

Alarm serial number0x9C and 0xC7, 3 bytes each, decimal, LSB first. The serial printed on the case-front label. Stored twice, normally identical; believed informational only. Revill's convention for re-flashed units: this unit's real serial at 0x9C, the donor template's serial at 0xC7.

MEMS ECU code0x3B, 2 bytes, hex, LSB first. Unique immobiliser identity sent to the MEMS ECU. Any value except 0x0000, 0xFFFF and 0xF0F0.

Week / year of manufacture0xCF (1 byte) and 0xD0 (2 bytes), BCD, MSB digit first. From the case label; believed informational only.

LED flash patterns (in progress — offsets may differ)

Armed at 0x92, disarmed at 0x89, 1 byte each, identical encoding. The mask ranges from permanently off, through one or more flashes per cycle, to permanently on.

MaskBitsPattern
0x0000000000Off (default disarmed)
0xFF11111111On 8 ms, off 1016 ms (default armed)
0xFE11111110On 16 ms, off 1008 ms
0xFC11111100On 32 ms, off 992 ms (preferred armed)
0xF811111000On 64 ms, off 960 ms
0xF011110000On 128 ms, off 896 ms
0xE011100000On 256 ms, off 768 ms
0xC011000000On 512 ms, off 512 ms
0xBC10111100On 32 ms, off 480 ms
0xA010100000On 256 ms, off 256 ms
0x9010010000On 128 ms, off 128 ms
0x8810001000On 64 ms, off 64 ms

Decoding:

  1. Take a 7-bit counter incrementing every 8 ms (wraps after 1024 ms).
  2. AND the counter with the low 7 bits of the mask.
  3. If the result is zero, take the mask's high bit; otherwise its inverse.
  4. That bit is the LED state — 1 = on, 0 = off.

Low battery warning

  • Flash LED on unlock0x38 bit 2, active high. LED double-pulses for a few seconds after unlock when the fob reports low battery. A further setting is believed to control how many consecutive low-battery messages trigger it, but hasn't been located.
  • Double key press0x38 bit 3, active high. When the fob reports low battery, its button must be pressed twice, giving the impression it's failing.

Passive arming

Enabled0x37 bit 6, active low. When 0, the immobiliser (not the alarm) re-engages automatically after a timeout. When 1, it never re-engages once disengaged, and this persists across power cycles.

Three timeouts apply depending on state. 0 fires immediately (it does not wrap to 256):

  • No ignition0x21, ×1 s, 1–255 s. Unlocked, ignition never on. Default ~30 s.
  • Ignition & door0x20, ×1 s, 1–255 s. Unlocked, ignition on then off, then driver's door opened. Default ~30 s. (No driver's-door switch on a Caterham, so this case never arises there.)
  • Ignition only0xAD, ×8 s, 8–2040 s. Unlocked, ignition on then off. Default 75 (= 600 s / 10 min). Ticks come from a free-running 8 s clock, so N×8 s actually fires between (N−1)×8 s and N×8 s.

Locking and alarm behaviour

Superlocking — Rover deadlocking, where a double-click of the fob lock button mechanically locks out the doors. Controlled by two bits that are always inverses: 0x36 bit 2 (active low) and 0x9A bit 2 (active high). To disable, set 0x36 bit 2 = 1 and 0x9A bit 2 = 0. Both appear to be required — every unit seen with it disabled has both inverted. Irrelevant on a Caterham.

  • Hazards flash with alarm0x36 bit 1, active low. When 0, the hazards pulse with the alarm.
  • Switch closed when bonnet open0x3E bit 0, active high. When 1, the bonnet reads as closed when the input is open-circuit (and open when shorted to ground); when 0, the sense is inverted.