VW Audi SFD2 Diagnostic Command Reference: Hex‑Level Low‑Level Operation & Channel Unlocking Practical Guide
MQB Evo / MEB Platform · Diagnostic Low‑Level Hands‑On
From 2E write operations to SFD1 / SFD2 unlocking — Understand the underlying logic behind the latest VAG security gateway.
SFD2 for vehicle diagnostics is not simply an extra lock. Instead, every single channel is individually locked.
Starting from 2024, the Volkswagen Group rolled out the SFD2 (Schutz der Fahrzeugdiagnose 2) security gateway across MQB Evo and MEB‑platform vehicles, covering Volkswagen, Audi, Škoda and SEAT.
For technicians and tuners, the most obvious change is that coding and adaptation tasks which used to be simple are now frequently rejected by the security gateway.
Important Technical & Legal Disclaimer
This article covers UDS diagnostic protocol knowledge for technical research and education purposes only.
Unauthorised bypass, cracking or tampering with SFD security gateways, ECU coding or factory calibrations may void vehicle warranty, violate local automotive regulations and may lead to permanent ECU lock‑up, drivability faults or safety hazards. Only official ODIS‑E with valid OEM GeKo server authorisation provides legally authorised diagnostic access.
1. What Exactly Does SFD2 Lock?
Many users treat SFD2 as just a minor version upgrade. In reality it implements a multi‑layer authorisation validation chain.
- Gateway‑level filtering (PVD2 diagnostic filter)
- SFD1 module‑level Challenge‑Response authorisation (90‑minute session access)
- SFD2 per‑channel signature validation for every protected write operation
Analogy: SFD1 unlocks the main entrance door; SFD2 adds an independent lock on every single interior room. Even if you open the main door, each room still requires its own valid key.
2. Core Hex Command Quick Reference (Low‑Level UDS Operations)
All commands are VAG‑extended UDS services, formatted as Service ID + DID / Parameter. One‑byte error will cause full operation failure.
Diagnostic Session Control (Service 0x10)
Must switch session before any write or unlock operation.
-
10 01‑ Default session (factory default, write operations blocked) -
10 03‑ Extended diagnostic session (mandatory for write access) -
10 40‑ Programming session (flash‑only)
PVD2 Diagnostic Filter Control (WriteDataByIdentifier Service 0x2E, DID 0x031D)
Common pitfall: many technicians reverse these two values.
-
2E 03 1D 00‑ Disable PVD2 diagnostic filter (required for DID scanning / coding modification) -
2E 03 1D 01‑ Enable PVD2 diagnostic filter (restore after work complete)
Read / Write & Persist Parameters (VAG Routine Control Service 0x31)
-
31 01 C0 08 07‑ Read parameter -
31 01 C0 11‑ Parameter write routine -
31 01 C0 12 01‑ Save parameters to non‑volatile NVM memory (must run after writing) -
31 01 05 43 00‑ 360° surround view camera calibration routine
Coding Read & Write
-
22 06 00‑ Read long coding (ReadDataByIdentifier DID 0x0600) -
2E 06 00‑ Write long coding (WriteDataByIdentifier DID 0x0600)
ECU Reset (Service 0x11)
-
11 02‑ ECU soft reset; apply new coding / parameters
3. SFD1 Unlocking Principle (Challenge‑Response)
- Send routine
31 01 C0 04→ ECU generates a cryptographic Challenge value. - Diagnostic tool sends VIN + Challenge to Volkswagen OEM GeKo security server.
- GeKo returns cryptographically signed Response token.
- Token is passed back to ECU for validation. Upon success, SFD1 authorisation activates for approx. 90 minutes.
- Send
31 01 C0 05to manually revoke SFD1 access before timeout.
Critical note: SFD1 only opens module‑level diagnostic session. SFD2‑protected channels still require an independent per‑write signature token, even with active SFD1.
4. Practical Workflow Examples
Scenario A: Coding modification on older SFD1‑only platforms (non‑Evo MQB)
-
10 03Enter extended diagnostic session -
22 06 00Read and backup original long coding -
2E 06 00 + [new coding payload]Write new coding -
11 02ECU soft reset -
22 06 00Read‑back and verify coding was applied
Scenario B: Full workflow for MQB‑Evo / MEB SFD2 vehicles
Prerequisite: Valid OEM‑authorised GeKo access for SFD1 token and individual SFD2 per‑write tokens for target DID.
-
10 03Switch to extended diagnostic session -
31 01 C0 08 02Query current SFD1 status -
31 01 C0 04Trigger SFD1 unlock → obtain Challenge, fetch SFD1 token from GeKo -
2E 03 1D 00Disable PVD2 diagnostic filter - Request dedicated SFD2 signature token for the target protected DID
-
2E 06 00 + [new coding payload]Execute coding write (SFD2 token will be validated) -
31 01 C0 12 01Persist parameters into NVM -
11 02Perform ECU soft reset -
22 06 00Read‑back DID 0600 to confirm coding applied - Post‑operation cleanup:
2E 03 1D 01Re‑enable PVD2 filter;31 01 C0 05Revoke SFD1 authorisation
ODIS trace log example shows sequential PDU traffic: Read → Write → Save → Read‑back verification.
5. Core Challenges with SFD2
- Granular per‑write authorisation: Unlike SFD1 90‑minute session access, every write to an SFD2‑protected DID requires a separate cryptographic token. Multiple parameter changes on one ECU need multiple independent SFD2 tokens.
- Requires live online communication with Volkswagen GeKo server. Offline operation cannot complete SFD2‑protected writes.
- Third‑party tool limitations: VCDS, OBDeleven and similar aftermarket tools have partial read‑only capabilities. Full SFD2 write access is only natively supported by official ODIS‑E with valid GeKo connection.
- Negative response codes do not explicitly label “SFD2 error”. Technicians must interpret UDS negative response codes.
Common UDS Negative Response Codes (NRC)
| NRC Hex | Meaning | Typical SFD‑related Cause |
|---|---|---|
0x10 |
General reject | Unsupported service or wrong diagnostic session |
0x22 |
Conditions not met | Not in extended session; PVD filter still active |
0x34 |
Security access error | Invalid / mismatched SFD2 token |
0x35 |
Security access denied | SFD1 not unlocked or token expired |
0x7F |
Service not supported | Service blocked in current session |
6. Tooling & Risk Summary
Risks
- Incorrect hex payload writes can corrupt ECU NVM memory and permanently brick control units.
- Attempting writes to SFD2‑protected DIDs without valid tokens triggers gateway anti‑tamper locking. ECU may become unrecoverable.
- Modified factory coding voids OEM vehicle warranty and may conflict with regional road‑legal requirements.
- Network drop‑out during live GeKo signing can interrupt writes and cause storage corruption.
Available Diagnostic Tools
✅ Official: ODIS / ODIS‑E — Native GeKo integration, full SFD1 + SFD2 support.
Aftermarket tools (limited SFD2 functionality):
- VCDS Beta: Read‑only for many DIDs; no genuine SFD2 write capability.
- OBDeleven: Partial OEM‑authorised channel for selected operations.
- Carista: Limited access to non‑protected DIDs only.
Quick Memorisation Cheat‑Sheet
Switch session 10 03 → backup coding 22 06 00 → disable filter 2E 03 1D 00 → obtain SFD1 token → obtain per‑channel SFD2 signature → perform write → persist 31 01 C0 12 01 → reset 11 02 → read‑back validation.