Industrial Wireless RS485 Modbus Transmitter API Overview

Explore The Industrial Wireless RS485 Modbus Transmitter Capabilities

Device Overview

The NCD Industrial Wireless RS485 Modbus Transmitter (PR55-88F) transforms Modbus devices into seamless wireless nodes, enabling effortless integration into the NCD wireless network and eliminating the need for cumbersome wired connections. .

Instead of relying on a central gateway to constantly request data, the Industrial Wireless RS485 Modbus Transmitter operates as the “Master” of its own RS485 loop. It bridges the gap between legacy hardware and modern wireless networks by operating autonomously on a user-defined schedule.

Features:

  • Industrial Grade IoT Modbus RS485 To Wireless Converter
  • Works With VFD, PLC, SCADA systems
  • Works With HVAC Control Systems
  • Ideal For MODBUS-RTU Communication Over Wireless
  • Convert any RS485 Sensor/Device into a Wireless Sensor/Device
  • API communication over Wireless for Robust Reliability
  • Operating Temperature Range -40 to +85 °C
  • 5V-24VDC Input Voltage Range

Frame Structure

Frame Communication at Power Up

When the device powers up, depending on the mode it is going to work in, it will have a different Power Up Frame 

Figure 3 provides an outline of the frame structure at Power Up, where the bytes highlighted in Red denote which mode the device has started in (Run, Configuration or Factory Default). You can look up the corresponding codes in Table 2.

If we further examine the Payload, we can use the Node ID and Sensor Type fields to determine the exact sensor that is sending the data.

A shown in the second column in Table 2, the sensor configures its PAN ID automatically depending upon the mode it is working in. During factory reset it sets the PAN ID to the value given in table therefore the factory reset frame will only be received if your Modem/Gateway PAN ID matches this ID. All 3 types of frames are shown in Figure 3, Figure 4 and Figure 5.

Figure 3: Communication Procedure - Power Up
Mode TypePAN ID set by Sensor (ASCII)Frame fieldOffset (Payload section)Value
RunID save by user / DefaultMode bytes70x52
80x55
90x4E
Configuration7BCDMode bytes70x50
80x47
90x4D
Factory Reset7FFFMode bytes70x50
80x55
90x4D

Run Mode Frame

FieldNumber of bytesDescription
7E 00 1C 90 00 13 A2 00 42 35 89 86 FF FE C2 7A 01 00 02 1B 00 00 52 55 4E 00 00 00 00 00 00 79Example frame
0x7E1Delimiter
0x001C2Length
0x901Frame Type (Power Up)
0x0013A200425364538Source Address
0xFFFE2Reserved
0xC21R. Option
0x7A1Header with Power Up value
0x001Node ID
0x001Separator
0x021B2Sensor Type
0x00002Separator
0x52554E3Mode Byte for Run Mode
0x0000000000006Reserved
0x791Checksum

Configuration Mode Frame

FieldNumber of bytesDescription
7E 00 44 90 00 13 A2 00 42 35 89 86 FF FE C2 4F 00 00 19 07 02 1B 00 00 01 AF 55 88 00 7F FF 00 00 FF FF 00 00 00 03 84 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 07 D0 00 00 03 00 01 5FExample frame
0x7E1Delimiter
0x00442Length
0x901Frame Type
0x0013A200425364538Source Address
0xFFFE2Reserved
0xC21R. Option
4F1Header
00002Reserved
171Core Engine Version
0B1Firmware Version
007F2Sensor Type
000000014Tx Life Counter
633D003Hardware ID
7FFF2Network ID
0000FFFF4Destination Address
001Node ID
0000000A4Report Rate
011Register to Read
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000
32Modbus Registers Address
001Baud Rate
001Bootup Time
011Slave Address ID
00 012RS485 Rx Timeout
011Sub Device Type
011Number of Read Retries
011Modbus Function Code
001Parity Bit
001Stop Bit
5F1Checksum

Factory Reset Mode Frame

FieldNumber of bytesDescription
7E 00 1C 90 00 13 A2 00 42 53 64 53 FF FE C2 7A 00 00 02 1B 00 00 50 55 4D 00 00 00 00 00 00 D1Example frame
0x7E1Delimiter
0x001C2Length
0x901Frame Type
0x0013A200425364538Source Address
0xFFFE2Reserved
0xC21R. Option
0x7A1Header
0x001Node ID
0x001Separator
0x021B2Sensor Type
0x00002Separator
0x50554D3Mode Byte for Factory Reset Mode
0x0000000000006Reserved
0xD11Checksum

Sync Check In Frame

FieldNumber of bytesDescription
7E 00 44 90 00 13 A2 00 42 35 89 86 FF FE C2 6F 00 00 19 07 02 1B 00 00 01 AF 55 88 00 7F FF 00 00 FF FF 00 00 00 03 84 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 07 D0 00 00 03 00 01Example frame
0x7E1Delimiter
0x001C2Length
0x901Frame Type
0x0013A200425364538Source Address
0xFFFE2Reserved
0x001R. Option
6F1Header
00002Reserved
171Core Engine Version
0B1Firmware Version
00182Sensor Type
000000014Tx Life Counter
633D003Hardware ID
7FFF2Network ID
0000FFFF4Destination Address
001Node ID
0000000A4Report Rate
011Register to Read
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000
32Modbus Registers Address
001Baud Rate
001Bootup Time
011Slave Address ID
00 012RS485 Rx Timeout
011Sub Device Type
011Number of Read Retries
011Modbus Function Code
001Parity Bit
001Stop Bit
5F1Checksum

Sync Acknowledgment Frame

FieldNumber of bytesDescription
7E 00 44 90 00 13 A2 00 42 35 89 86 FF FE C2 5F 00 00 19 07 02 1B 00 00 01 AF 55 88 00 7F FF 00 00 FF FF 00 00 00 03 84 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 01 07 D0 00 00 03 00 01 D6Example frame
0x7E1Delimiter
0x001C2Length
0x901Frame Type
0x0013A200425364538Source Address
0xFFFE2Reserved
0x001R. Option
5F1Header
00002Reserved
171Core Engine Version
0B1Firmware Version
02 1B2Sensor Type
000000014Tx Life Counter
633D003Hardware ID
7FFF2Network ID
0000FFFF4Destination Address
001Node ID
0000000A4Report Rate
011Register to Read
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000
32Modbus Registers Address
001Baud Rate
001Bootup Time
011Slave Address ID
00 012RS485 Rx Timeout
011Sub Device Type
011Number of Read Retries
011Modbus Function Code
001Parity Bit
001Stop Bit
5F1Checksum

Assertion Reason Frame

FieldNumber of bytesDescription
77 00 00 00 6E 00 00 00 08 C3 61 70 70 5F 73 74 61 72 74 5F 66 6C 79 5F 74 69 6D 65 72 00 00 00 00 00 00 00 00 00Example frame
0x771Delimiter
0x002Node ID
0x00002Reserved
0x007F2Sensor Type
0x000008C34Line Number
0x00Function Name

Run mode is the default mode of operation of this sensor. In this mode, the sensor sends periodic packets with the sensor measurement data. During the time it is not sending it enters deep-sleep to conserve power. The sensor’s X-bee Radio module operates in API mode and sends packets to the saved destination address on the network specified by the saved PAN ID. Figure 4 illustrates the API transmission/reception procedure.

Figure 4: Communication Procedure - Run Mode

Sensor Data Frame

Frame FieldOffset (Payload section)Fixed Value (if any)LengthDescription
Header00x7F1Header to differentiate various types of packets
Node ID10x001Node ID to differentiate up to 256 nodes in a network. User configurable values
Firmware20x011Used to determine firmware version programmed in the device
Battery VoltageMSB 30x032Battery Voltage = 0.00322*(03*FF+FE)
LSB 40xFEBattery Voltage = ((Battery Voltage MSB x 256) + Battery Voltage LSB) x 0.00322 V
Packet Counter5-1It is an 8-bit counter that increments with each packet transmission. It can be used to detect missing packets
Sensor TypeMSB 60x022Two bytes to determine sensor type. It can be used in conjunction with Node ID to create sensor networks of up to 256 nodes for a single type of sensor and multiple such networks can coexist and can be differentiated in processing software on PC end.
LSB 70x1BSensor Type 539
Error/Reserved byte80x001Bit 7: Reserved
Bit 6: Reserved
Bit 5: Reserved
Bit 4: Reserved
Bit 3: Reserved
Bit 2: Reserved
Bit 1: Reserved
Bit 0: Reserved
Sub Device Type9/ Data[0]-1
Number of Registers10/ Data[0]-1
Register Status11/ Data[0]-
12/ Data[1]-
13/ Data[2]-
14/ Data[3]-4Each bit describes status of a register (0 --> fail, 1-->success)
Register Data15/ Data[0]-
n/Data[n]up to 64 Bytes2 bytes each register --> Total length 64 bytes

Configuration Mode

To put an NCD.io wireless sensor into manual configuration mode, you can do the following:

Using Buttons

1. Press and release the RESET button
2. Immediately press and hold the CONFIGURATION button
3. Hold the CONFIGURATION button for about 5–8 seconds
4. Release the CONFIGURATION button

In configuration mode, the device sets its X-bee pan id to 7BCD. Also, the destination address used by the sensor is extracted from the incoming packet (source address). This ensures that once you put a device in configuration mode you just need to change the PAN ID you are sending to in your Modem/Gateway to match with the sensor and start configuring your device.

A standard configuration packet and its fields are explained in Figure 5. Its possible responses are also shown. The complete set of commands supported by this sensor are shown in тхе Appendix, these can be used in the Parameters field of the Payload section. The sensor responds to these commands with an acknowledgement if the process completed successfully or with an error if it failed to setup a parameter. The respective Data and Reserve section length and values are shown in Table 6 for the case of acknowledgement. In the case of error, the reserved section will be fixed and not used, while the Error number byte will determine the type of error returned. These errors are in a separate section in the Appendix.

Figure 5: Communication Procedure - Configuration Mode

Sync/Config Mode

This specific device also supports SYNC mode, which allows you to configure the sensor without needing physical access to it (no need to press buttons or trigger a magnetic switch).

By default, the device automatically enters SYNC mode every hour and transmits a SYNC packet (described below). This packet serves two main purposes:

  • Current Settings: It includes all the active settings, allowing you to easily verify or read the sensor’s current configuration.

  • Configuration Window: It signals that the sensor is temporarily in configuration mode. During this brief time window, you can transmit a Master Command to update the settings.

Once the time window closes, the device automatically returns to its normal operation (Run mode).

Example Configuration Command

The following is an example on how to read and change some of the parameters that affect the operation of the NCD Sensor.

Master Command

The Master Command is a comprehensive command that allows you to configure all of the device’s settings in a single transmission.

Below, you will find the structure of the master command, along with a detailed payload description for each byte.

				
					7E 00 38 10 01 00 00 00 00 00 00 FF FF FF FE 00 00 6C 00 00 7F FF 00 00 FF FF 00 00 00 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 01 07 D0 00 00 03 00 01 C9
				
			

Complete Payload

				
					6C 00 00 7F FF 00 00 FF FF 00 00 00 00 3C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
00 00 00 00 00 04 00 01 07 D0 00 00 03 00 01
				
			

Master Command Payload Description

ByteSize (bytes)SettingValid OptionsDescription
6C1 Header
00 002 Reserved
7F FF2 Network ID0x00 -- 0x7FFFNetwork ID Valid Range: 0-0x7FFF.
00 00 FF FF4 Destination AddressDefault value: 0000FFFF for Broadcast Mode
Example of targeted address: 41D5EC37
Sets the Destination Address of the sensor.

The sensor will send Run mode Data packets to this Address
001 Node ID0x00 -- 0xFFSets the Device node ID and Data Transmission Interval.

The node id value can go from 0-255 and The Data transmission value can go from 3-0xFFFFFF Seconds
00 00 00 3C1 Report RateValid Range:
0x01 -- 0xFFFFFFFF
Sets the Data Transmission Interval
001Register to ReadValid Range:
0x01 -- 0x20
Set the total number of registers to read on interval in the Register Reads field. Set the individual Registers to read below in the correspond Register field.
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000000000000000
00000000
64Modbus Registersthe Modbus Register Address (0-based offset).
041Baud Rate0x00 -- 4800
0x01 -- 9600
0x02 -- 19200
0x03 -- 38400
0x04 -- 115200
001Bootup TimeValid Range:
0x01 -- 0xFF
Sets the delay interval (in seconds) that the NCD transmitter waits after powering on the connected Modbus device before issuing the first command. This delay ensures the external Modbus device has sufficient time to complete its internal initialization sequence before the transmitter begins polling.
011Slave addressValid Range:
0x01 -- 0xFF
07D02Response Timeout (in milliseconds)Valid Range:
0x01 -- 0xFFFF
Sets the maximum time (in milliseconds) that the device will wait to receive a response from the RS485 field device via the serial port after it sends command.
001Slave IDValid Range:
0x01 -- 0xFF
Configures the unique Slave Modbus device address (Slave ID) for the transmitter.
001Number of Read RetriesValid Range:
0x01 -- 0x03
Sets the maximum number of attempts the device will make to perform a Modbus RTU register query.
031Modbus Function Code. 0x03 -- Read Holding Register (0x03)
0x04 -- Read Input Register (0x03)
001Set Parity0x00 -- None
0x01 -- Even
0x02 -- Odd
011Set Stop Bit0x00 -- Half
0x01 -- 1 bit
0x02 -- 1.5 bit
0x03 -- 2 bit

Read Sensor Settings

Sync

By using the SYNC packet, you can easily check the current settings configured on your sensor. The SYNC message includes the exact bytes that correspond to your active configuration values (you can find an example of a SYNC packet at the beginning of this document).

If you ever need to manually trigger a SYNC message, simply press the reset button. When you do this, the sensor will respond by sending a quick sequence of three messages: RUN, followed by sensor_data, and finally SYNC.

Additionally, the sensor will automatically transmit a SYNC message every hour by default to keep everything updated.

Read Wireless Sensor Transmission Power Level​

This Command may be used to read the wireless radio transmission power. This value will indicate how much RF power the radio is emitting. The higher the value, the higher the radiated wireless power, resulting in a longer range and decreased battery life (please note that all battery ratings are shown at maximum wireless transmission power).  Lower values are desirable in application that may benefit from greatly improve battery life, especially when high power data transmissions are not required.

Read Sensor Power Command:

				
					7E 00 13 10 00 00 00 00 00 00 00 FF FF FF FE 00 00 F7 16 00 00 00 E7
				
			

Sensor will respond with the Power Level value:

				
					7E 00 1C 90 00 13 A2 00 41 91 1B 83 FF FE C1 7C 00 09 00 0E 00 00 04 00 00 00 00 00 00 00 00 F5
				
			

From the above command, the following data may be extracted:

A. Sensor MAC Address

				
					00 13 A2 00 41 91 1B 83
				
			

B. Sensor Payload 

				
					7C 00 09 00 0E 00 00 04 00 00 00 00 00 00 00 00
				
			

C. Power Level

				
					0x04 (data byte 23)
				
			

The sensor will respond with a value from 0x00 to 0x04.  The default value is 0x04, allowing for the greatest possible transmission range and the shortest battery life.

Read Wireless Sensor Retries​

The following command may be used to read the number of retires.  The number of retries is one of the most useful settings for NCD wireless sensors. 

Lets say the number of retires is set to 5. In a normal case, the sensor will wake up, gather data, send data to the modem, and go back to sleep.  But due to some environmental issues (lets say a few trucks were driving by and they came in between the sensor and the modem) the modem didn’t receive the data. In that case, the sensor will try 4 more times to send the data.  If the modem still doesn’t get the data after all 5 tries, the sensor will quite trying and will go back to sleep.  The Machine Uptime sensor will wake up after the predefined sleep time and will try again. 

The highest number of retries allowed is 10.

Read The number of Sensor Retries:

				
					7E 00 13 10 00 00 00 00 00 00 00 FF FF FF FE 00 00 F7 17 00 00 00 E6
				
			

Sensor will respond with the Retries value:

				
					7E 00 1C 90 00 13 A2 00 41 91 1B 83 FF FE C1 7C 00 1B 00 0E 00 00 0A 00 00 00 00 00 00 00 00 DD
				
			

From the above command, the following data may be extracted:

A. Sensor MAC Address

				
					00 13 A2 00 41 91 1B 83
				
			

B. Complete Sensor Payload 

				
					7C 00 1B 00 0E 00 00 0A 00 00 00 00 00 00 00 00
				
			

C. Retries Number

				
					0x0A (data byte 23)
				
			

Error Code Descriptions

Here a summary is provided of what the different error codes mean (in case a valid Ack has not been received).

Error NumberDescription
0x01Invalid command
0x02Sensor Type mismatch
0x03Node ID mismatch
0x04Apply change command failed during X-bee parameter update
0x05Invalid API packet command response received after Apply change command
0x06Write command failed during X-bee parameter update
0x07Invalid API packet command response received after Write command
0x08Parameter change command failed during X-bee parameter update
0x09Invalid Parameter change command response packet received after Write command
0x0AInvalid/Incomplete packet received
0x0FInvalid parameter for setup/saving

Frame Checksum Calculation

In order to successfully communicate over the API protocol, the checksum is of vital importance. The X-bee at either end of the link will reject packets if the checksum does not match.

Calculation for transmission

For sending packets, the checksum calculation works as follows:

1. Not including the frame delimiter and length, add all the bytes and keep the lower 8 bits of result

2. Subtract this value from 0xFF (hex)

3. The resultant value is the checksum

4. Append this byte to the original packet for sending

Consider the example for the command Set Broadcast shown in APPENDIX A and see that the calculated checksum matches with the checksum sent by the terminal/LabVIEW. Let us break the example command below:

				
					7E00 1310 0000 0000 0000 00FF FFFF FE00 00F7 0100 0001 FB
				
			

If we extract the relevant bytes from the command we get:

				
					10 0000 0000 0000 00FF FFFF FE00 00F7 0100 0001
				
			

Adding the bytes and taking the last 8 bits yields:

				
					0x04
				
			

Substract the value obtained (0x04) from 0xFF

				
					0xFF-0x04=0xFB
				
			

We get a value matching the one in the packet checksum field.

Calculation for reception

Although checksum is matched by the X-bee itself, but for understanding follow these steps to match checksum at reception

1.     Not including the frame delimiter and length, add all the bytes including the received checksum

2.     Keep only the last 8 bits

3.      If the result is 0xFF, the checksum is correct and the packet can be processed.

Consider the example for the command Set Broadcast shown in APPENDIX A and see that the received packet checksum verifies since the result is 0xFF.

				
					7E00 1C90 1310 A200 4158 1CCB FFFE C17C 000D 0001 0000 FF00 0000 0000 0000 00F3
				
			

If we extract the relevant bytes from the command we get:

				
					90 1310 A200 4158 1CCB FFFE C17C 000D 0001 0000 FF00 0000 0000 0000 00F3
				
			

Adding the bytes and taking the last 8 bits yields:

				
					0xFF