1. Temperature Control Screen Gateway Protocol
1.1. 1. Document information
- Protocol version: V1.1
- The temperature control screen acts as a gateway and is called the server; the MCU or other devices communicate with the temperature control screen via Wi-Fi or 485 and are called clients
- It is recommended to read the overall interaction sequence diagram in Section 6 first to get an overview
1.2. 2. Communication methods
1.2.1. 2.1 485:
Connect to the 485 port of the temperature control screen for communication. Because the temperature control screen has only one 485 port, once it is occupied, the temperature control screen can only use the relay interface on its rear cover for the water system function
485 communication parameters are as follows:
| Item | Parameter value |
|---|---|
| Transmission mode | Half duplex |
| Baud rate | 9600bps by default |
| Data format | 1 start bit, 8 data bits |
| Parity bit | Even |
| Stop bit | 1 bit |
1.2.2. 2.2 Wi-Fi network communication flow
A UDP broadcast discovery + TCP persistent connection mechanism is used. The MCU obtains the temperature control screen gateway's IP address via broadcast, then establishes a TCP link for data exchange
It is recommended to read point 5 of this section (interaction sequence diagram) first to understand the general flow
2.2.1. Device discovery phase (UDP Broadcast)
The MCU sends a UDP broadcast packet to the local network to detect online temperature control screen devices
- Local listening port:
5567 - Target port:
43708 - Broadcast address:
xxx.xxx.xxx.255(for example192.168.1.255) - Broadcast packet definition:
| Byte index | Data (Hex) | Description |
|---|---|---|
| Byte 0 | 0xFF |
Frame header |
| Byte 1 | 0xB0 |
Function code (device discovery) |
| Byte 2-5 | 0x00, 0x00, 0x00, 0x00 |
Reserved/padding |
| Byte 6 | 0xAF |
End byte/checksum byte |
2.2.2. Temperature control screen gateway response phase (UDP Response)
After receiving the broadcast, the temperature control screen gateway replies to the MCU with its own IP address information.
- Response data example:
FF B0 FF FF 52 30 30 30 34 39 32 35 34 32 33 37 38 31 39 34 32 C0 A8 16 85 - Packet structure parsing:
[!TIP] Parsing note: the MCU must extract the gateway's dynamic IP address from the last 4 bytes of the response packet
| Field | Data (Hex) | Description |
|---|---|---|
| Fixed header Byte 0-3 | 0xFF 0xB0 0xFF 0xFF |
Gateway response identifier |
| Device ID Byte 4-19 | 0x52 0x30 0x30 0x30 0x34 0x39 0x32 0x35 0x34 0x32 0x33 0x37 0x38 0x31 0x39 0x34 |
Unique ID R000492542378194 |
| DHCP Byte 20 | 0x1 |
Whether the IP is dynamically assigned |
| IP address Byte 21-24 | 0xC0 0xA8 0x16 0x85 |
Corresponding IP: 192.168.22.133 |
| Checksum Byte 25 | 0xxx ... |
Checksum |
2.2.3. Connection establishment phase (TCP Connection)
After obtaining the IP address, the MCU, acting as the Client, actively initiates the TCP connection
- Target IP: the gateway IP parsed in step 2
- Target port:
9999 - Next action: after the connection succeeds, both parties enter business communication mode.
2.2.4. Business Communication
During communication, the MCU periodically sends heartbeat PING packets; if the gateway is online, it replies with a heartbeat PONG packet
PING packet
| Field | Data (Hex) | Description |
|---|---|---|
| Fixed header Byte 0-1 | 0x12 0x34 |
Heartbeat identifier |
| Device ID Byte 2-17 | 0x52 0x30 0x30 0x30 0x34 0x39 0x32 0x35 0x34 0x32 0x33 0x37 0x38 0x31 0x39 0x34 |
Unique ID R000492542378194 |
| Address Byte 18-25 | 0x0 0x0 ... |
Reserved, defaults to 0 |
| Checksum Byte 26 | 0xxx ... |
Checksum |
PONG packet
| Field | Data (Hex) | Description |
|---|---|---|
| Fixed header Byte 0-1 | 0x12 0x34 |
Heartbeat identifier |
| Device ID Byte 2-17 | 0x52 0x30 0x30 0x30 0x34 0x39 0x32 0x35 0x34 0x32 0x33 0x37 0x38 0x31 0x39 0x34 |
Unique ID R000492542378194 |
| Address Byte 18-25 | 0x0 0x0 ... |
Reserved, defaults to 0 |
| Checksum Byte 26 | 0xxx ... |
Checksum |
2.2.5. Interaction sequence diagram
sequenceDiagram
participant MCU as MCU (Client)
participant GW as Temperature control screen gateway (Server)
Note over MCU: Listen on UDP 5567
MCU->>GW: UDP broadcast (Port: 43708)
Note right of MCU: Send {0xFF, 0xB0...0xAF}
GW-->>MCU: UDP response (contains the gateway IP)
Note left of GW: To UDP port 5567, return {0xFF, 0xB0, 0xFF, 0xFF, IP...}
MCU->>GW: TCP connection request (Port: 9999)
GW-->>MCU: TCP ACK (connection established)
MCU->>GW: TCP heartbeat PING (Port: 9999)
GW-->>MCU: TCP ACK (heartbeat PONG)
Note over MCU, GW: Start normal business communication
1.3. 3. Data structure
1.3.1. 3.1 Command sent (MCU -> temperature control screen gateway)
| Temperature control screen address | Function code | Function parameter | HVAC device count | HVAC device address | Checksum |
|---|---|---|---|---|---|
| 1 byte | 1 byte | 1 byte | 1 byte | count × 2 byte | 1 byte |
1.3.2. 3.2 Data feedback (temperature control screen gateway -> MCU)
| Temperature control screen address | Function code | Function parameter | HVAC device count | HVAC device address + status value | Checksum |
|---|---|---|---|---|---|
| 1 byte | 1 byte | 1 byte | 1 byte | count × 10 byte | 1 byte |
- Temperature control screen address: the temperature control screen's own 485 address, 0x01 by default
- Function code: query and control commands
- Function parameter: the parameter value of the function code
- HVAC device address definition:
- Address length: composed of 2 bytes
- Air conditioner address: composed of (outdoor unit address, indoor unit address). 01 ????
- Fresh air address: the first byte is fixed to
0x41(65), the second byte is the fresh air 485 address - Floor heating address: the first byte is fixed to
0x42(66), the second byte is the floor heating 485 address
- HVAC device status value:
- Length: composed of 8 bytes
- Room: defaults to 00
| Power | Temperature | Mode | Fan speed | Room | Checksum | (Fault) | Air direction |
|---|---|---|---|---|---|---|---|
| 1 byte | 1 byte | 1 byte | 1 byte | 1 byte | 1 byte | 1 byte | 1 byte |
- Checksum calculation: the sum of all data bytes from the "temperature control screen address" up to (but not including) the "checksum", keeping the low 8 bits (overflow ignored)
1.3.3. 3.3 Active status report (temperature control screen gateway -> MCU)
When the status of a device behind the temperature control screen gateway changes, it proactively sends the status to the MCU; the data format is the same as in Section 3.2, with the HVAC device count in the data being 1
1.4. 4. Query command set
| Function code | Function parameter | Meaning |
|---|---|---|
| 0x50-Query AC status | 0xFF | Active query by the MCU |
| 0x51-Query fresh air status | 0xFF | Active query by the MCU |
| 0x52-Query floor heating status | 0xFF | Active query by the MCU |
| 0x10-Query temperature control screen gateway temperature and humidity | 0xFF | Active query by the MCU, frequent querying is prohibited, it will cause bus conflicts |
- Query AC status:
| Temperature control screen address | Function code | Function parameter | HVAC device count | HVAC device address | Checksum |
|---|---|---|---|---|---|
| 1 byte | 0X50 | 0XFF | 0XFF | 0XFF 0XFF | 1 byte |
- Query fresh air status:
| Temperature control screen address | Function code | Function parameter | HVAC device count | HVAC device address | Checksum |
|---|---|---|---|---|---|
| 1 byte | 0X51 | 0XFF | 0XFF | 0XFF 0XFF | 1 byte |
- Query floor heating status:
| Temperature control screen address | Function code | Function parameter | HVAC device count | HVAC device address | Checksum |
|---|---|---|---|---|---|
| 1 byte | 0X52 | 0XFF | 0XFF | 0XFF 0XFF | 1 byte |
- Query temperature control screen temperature and humidity:
Command
| Temperature control screen address | Function code | Function parameter | Checksum |
|---|---|---|---|
| 1 byte | 0X10 | 0XFF | 1 byte |
Response
| Temperature control screen address | Function code | Function parameter | Temperature | Humidity | Checksum |
|---|---|---|---|---|---|
| 1 byte | 0X10 | 0XFF | 2 bytes | 2 bytes | 1 byte |
[!TIP] Actual temperature/humidity value (one decimal place) = (temperature|humidity) / 10
1.5. 5. Control command set
1.5.1. 5.1 Air conditioner control
| Function code | Function parameter | Meaning |
|---|---|---|
| 0x31-Control power | 0x01 | Power on |
| 0x00 | Power off | |
| 0x32-Control temperature | 0x10~0x1E | Temperature 16~30°C |
| 0x33-Control mode | 0x01 | Cooling |
| 0x02 | Dehumidification | |
| 0x04 | Fan | |
| 0x08 | Heating | |
| 0x34-Control fan speed | 0x00 | Auto |
| 0x01 | High | |
| 0x02 | Medium | |
| 0x04 | Low | |
| 0x35-Control air direction | Front/back and left/right air direction, 1 byte, controlled bit by bit | See the table below, air direction parameters |
Air direction parameters
| Air direction type | Bit range | Rule description |
|---|---|---|
| Front/back air direction | Bit7~Bit4 (upper four bits) | 0: swing 1-6: position 1-position 6 F: keep unchanged |
| Left/right air direction | Bit3~Bit0 (lower four bits) | 0: swing 1-6: position 1-position 6 F: keep unchanged |
1.5.2. 5.2 Fresh air control
| Function code | Function parameter | Meaning |
|---|---|---|
| 0x71-Control power | 0x01 | Power on |
| 0x00 | Power off | |
| 0x73-Control mode | 0x01 | Ventilation |
| 0x02 | Exhaust | |
| 0x74-Control fan speed | 0x00 | Auto |
| 0x01 | High | |
| 0x02 | Medium | |
| 0x04 | Low |
1.5.3. 5.3 Floor heating control
| Function code | Function parameter | Meaning |
|---|---|---|
| 0x81-Control power | 0x01 | Power on |
| 0x00 | Power off | |
| 0x82-Control temperature | 0x5~0x5A | Temperature 5~90°C |
1.5.4. 6. Interaction sequence diagram
sequenceDiagram
participant MCU as MCU (Client)
participant GW as Temperature control screen gateway (Server)
MCU->>GW: 0x50-Query AC status, obtain all AC information
GW-->>MCU: Send all AC information
MCU->>GW: Send control command
GW-->>MCU: Reply with AC status changes
1.6. 7. Command sending examples
1.6.1. 7.1 Query example
- Query all AC parameters under the temperature control screen gateway with address 01:
Send: 01 50 FF FF FF FF 4D
Receive: 01 50 FF 06
01 01 01 14 02 03 20 00 00 00 (10-byte status of indoor unit 01-01)
01 02 00 14 02 01 23 00 00 00 (10-byte status of indoor unit 01-02)
01 03 01 14 02 03 24 00 00 00 (10-byte status of indoor unit 01-03)
02 00 01 14 03 01 20 00 00 00 (10-byte status of indoor unit 02-00)
02 01 00 14 02 03 20 00 00 00 (10-byte status of indoor unit 02-01)
02 02 00 14 03 01 20 00 00 00 (10-byte status of indoor unit 02-02)
3C
1.6.2. 7.2 Control command examples
- Power on the AC at address 1-3:
Send: 01 31 01 01 01 03 38
Receive: 01 31 01 01 01 03 38
- Set the temperature of the AC at address 1-3 to 26°C:
Send: 01 32 1A 01 01 03 52
Receive: 01 32 1A 01 01 03 52