Direkt zum Inhalt
[Fundamentals · 02]

CAN frames and arbitration: how a bus without a master decides who speaks

CAN has no master, no token and no time slots, yet every node agrees on who transmits next within a single bit time. The mechanism is the frame format itself. Once you can read a frame bit by bit, you can reason about latency, bus load and every class of error the protocol reports.

Reading time
13 min
Updated
7. Oktober 2026
Diagrams
03
Sections
09

This article is not yet available in your language and is shown in English.

A bus without a master

Any node on a CAN network may start transmitting whenever the bus is idle. There is no central scheduler and no receiver addressing: a frame carries an identifier that names its content and sets its priority, every node receives every frame, and each decides locally whether that frame concerns it. The data link layer that makes this work is specified in ISO 11898-1, whose 2024 edition covers all three protocol generations: classical CAN, CAN FD and CAN XL.

Two properties of the physical layer, described in CAN physical layer, carry the whole design. A dominant bit always overwrites a recessive one, and every transmitter reads the bus back while it sends. Together they allow several nodes to start at once and resolve the conflict without corrupting a single bit of the winning frame.

Anatomy of a classical data frame

A classical CAN data frame in base format carries 0 to 8 data bytes wrapped in 44 bits of protocol overhead, followed by a short gap before the next frame can start. From left to right:

Fig. 01Interactive
bits
11
Identifier

Names the message and sets its priority. The lower the value, the higher the priority.

Use Tab and the arrow keys to explore.

Fig. 01The classical base-format data frame: start of frame, arbitration field, control field, data field, CRC field, acknowledgement field and end of frame.
Table 01Fields of a classical CAN base-format data frame
FieldBitsLevel or contentPurpose
Start of frame (SOF)1DominantMarks the start; every node hard-synchronises on its edge
Identifier11AnyNames the content and sets the priority; the lower value wins
RTR1Dominant in data framesRemote transmission request; recessive marks a remote frame
IDE1Dominant in base formatIdentifier extension; recessive announces a 29-bit identifier
r01DominantReserved; ISO 11898-1:2015 names this position FDF, the FD format bit
DLC40–8Data length code: the number of data bytes
Data0–64AnyPayload, most significant bit first
CRC sequence15CalculatedCyclic redundancy check from SOF to the end of the data
CRC delimiter1RecessiveFixed-form separator
ACK slot1Sent recessive, overwritten dominantReceivers confirm a correct frame
ACK delimiter1RecessiveFixed-form separator
End of frame (EOF)7RecessiveCloses the frame
Intermission3RecessiveMinimum gap before the next frame

Start of frame and identifier

A frame may begin only after the bus has been recessive for the intermission period. The single dominant SOF bit creates a recessive-to-dominant edge on which every receiver realigns its bit clock, a hard synchronisation. The identifier follows, most significant bit first. In base format it is 11 bits wide, giving 2,048 values from 0x000 to 0x7FF.

The identifier is not an address. It describes what the frame contains, and its numerical value is the frame's priority: the lower the number, the higher the priority. Each data identifier must have exactly one transmitter. If two nodes sent data frames with the same identifier and different content, arbitration could not separate them and the collision would surface as bit errors in the data field.

Control field and data length

The control field tells receivers how to read the rest of the frame. IDE distinguishes base from extended format, the reserved bit stays dominant in classical frames, and the four-bit data length code gives the number of data bytes. In classical CAN, codes 0 to 8 map directly to 0 to 8 bytes; codes 9 to 15 are legal on the wire but still mean 8 bytes. CAN FD gives those upper codes new meanings, explained in Classic CAN vs CAN FD.

CRC, acknowledgement and end of frame

The transmitter computes a 15-bit CRC over every bit from SOF to the end of the data field, before stuffing. Receivers repeat the calculation, and a mismatch is a CRC error. The generator polynomial is fixed by ISO 11898-1:

Formula
g(x) = x¹⁵ + x¹⁴ + x¹⁰ + x⁸ + x⁷ + x⁴ + x³ + 1 (0x4599)
The CRC-15 of classical CAN: within the length of a CAN frame it detects any combination of up to five randomly distributed bit errors and any burst error shorter than 15 bits.

Next comes the only bit that the transmitter expects someone else to write. It sends the ACK slot recessive, and every receiver that has found the frame correct up to that point drives it dominant. A dominant ACK therefore tells the transmitter that at least one node received the frame intact, though not which node or how many. A recessive ACK slot is an acknowledgement error, and the transmitter tries again. Seven recessive EOF bits close the frame, and three bits of intermission follow.

11-bit and 29-bit identifiers

CAN 2.0B introduced the extended format with a 29-bit identifier. It splits the identifier into an 11-bit base part and an 18-bit extension, separated by two recessive bits: SRR (substitute remote request) and IDE, which announces the extension.

Table 02Base and extended format compared
PropertyBase format (CAN 2.0A)Extended format (CAN 2.0B)
Identifier length11 bits29 bits (11 + 18)
Identifier values2,048536,870,912
Frame with 8 data bytes, without stuffing108 bits + 3 intermission128 bits + 3 intermission
Worst case with stuffing and intermission135 bits160 bits
Typical usersMost passenger-car networks; ISO 15765-4 diagnosticsSAE J1939, ISO 11783; ISO 15765-4 diagnostics (29-bit option)

Both formats can share one bus, and arbitration treats them consistently. When a base frame and an extended frame share the same first 11 identifier bits, the base frame wins: its dominant RTR bit meets the extended frame's recessive SRR bit, and its dominant IDE meets the recessive IDE of the extended frame.

Heavy-duty vehicles use the 29-bit format to build structure into the identifier itself. SAE J1939 divides it into a priority, a parameter group number and a source address, as explained in SAE J1939 for trucks, buses and machinery.

Bitwise arbitration, step by step

When the bus becomes idle, every node with a pending frame may start at the same SOF. Each transmitter then sends its identifier bit by bit while monitoring the bus. As long as the bus level matches what it sent, it continues. A node that sends recessive and reads dominant has lost: another node is sending a lower identifier. It stops transmitting at once, receives the rest of the frame like any other node, and tries again when the bus is next idle.

Nothing is lost in the process. The winning frame is never corrupted, because the losing nodes only ever contributed recessive bits that the dominant level overwrote. This is why CAN arbitration is called non-destructive, and why the highest-priority pending frame always gets the bus, delayed by nothing more than the frame already in progress.

Fig. 02Interactive
0 is dominant and overwrites 1. A node that sends 1 but reads 0 stops and listens.
Identifier (hex)109876543210
01010100100
01010100000
01111110000
Bus···········

Press Step or Play to start arbitration.

0 is dominant and overwrites 1. A node that sends 1 but reads 0 stops and listens.

Fig. 02Three nodes start together; each drops out at the first bit where it sends recessive and reads dominant, leaving the lowest identifier to complete its frame.
Table 03Worked example: three nodes arbitrating (0 = dominant, 1 = recessive; identifier bit 10 is sent first)
Node109876543210
A, 0x12300100100011
B, 0x12F00100101 (lost)–––
C, 0x3A001 (lost)–––––––––
Bus level00100100011

Node C drops out at bit 9 and node B at bit 3, and node A completes its frame without having noticed the contest. B and C rejoin as soon as the bus is idle again. B now arbitrates against whatever else is pending and, unless a lower identifier is waiting, transmits next.

What arbitration guarantees, and what it does not

  • Priority is strict. The lowest pending identifier always wins. On a heavily loaded bus a low-priority frame can be delayed indefinitely, so priorities must follow real deadlines.
  • Transmission is not pre-emptive. An urgent frame that becomes ready one bit after another frame started must wait for it to finish: up to 135 bit times for a base-format frame with 8 data bytes, which is 270 µs at 500 kbit/s.
  • Data frames beat remote frames with the same identifier, because the data frame's RTR bit is dominant.
  • Arbitration needs a round trip within one bit. Every node must see the combined bus level before it samples, which ties the maximum bus length to the bit rate. CAN FD works around this limit by switching to a faster rate only after arbitration; see Bitrates and bus types.

Remote frames

A remote frame is a data frame without data, sent with a recessive RTR bit, that asks the owner of an identifier to transmit. It survives in the standard but is rare in modern vehicles. Most networks transmit cyclically or on change, CANopen guidance discourages remote frames, J1939 uses a dedicated request message instead, and CAN FD removed remote frames altogether, replacing the RTR position with the always-dominant RRS bit.

Bit stuffing and frame length

CAN uses non-return-to-zero coding: a long run of identical bits produces no edges, and without edges receivers cannot keep their clocks aligned. Bit stuffing solves this. After five consecutive bits of the same level, the transmitter inserts one bit of the opposite level, and receivers remove it again. Stuffing applies from SOF to the end of the CRC sequence; the delimiters, the ACK field and EOF are never stuffed.

Stuffing has two consequences. It guarantees a recessive-to-dominant edge at least every 10 bits, which bounds the clock drift receivers must absorb. And it makes six identical consecutive bits illegal inside a frame, which is exactly the property error flags exploit. The price is a frame length that depends on the data. For a frame with n data bytes, the worst case is:

Formula
Base format: L_max = 8n + 47 + ⌊(34 + 8n − 1) / 4⌋ · Extended format: L_max = 8n + 67 + ⌊(54 + 8n − 1) / 4⌋
Worst-case frame length in bits, including the 3-bit intermission. For n = 8: 135 bits (base) and 160 bits (extended).
Table 04Duration of a frame with 8 data bytes
Bit rateBit timeBase, no stuffing (111 bits)Base, worst case (135 bits)Extended, worst case (160 bits)
125 kbit/s8 µs888 µs1,080 µs1,280 µs
250 kbit/s4 µs444 µs540 µs640 µs
500 kbit/s2 µs222 µs270 µs320 µs
1 Mbit/s1 µs111 µs135 µs160 µs

Worked example: bus load

Bus load is the share of time the bus is occupied. Take a 500 kbit/s powertrain network carrying 15 frames every 10 ms and 40 frames every 100 ms, all in base format with 8 data bytes:

  1. 01
    Frames per second

    15 × 100 + 40 × 10 = 1,900 frames per second.

  2. 02
    Bits per frame

    Without stuffing each frame occupies 111 bit times including intermission; in the worst case, 135.

  3. 03
    Load

    1,900 × 111 = 210,900 bit/s, or 42 % of 500 kbit/s. With worst-case stuffing: 1,900 × 135 = 256,500 bit/s, or 51 %.

  4. 04
    Interpretation

    Real traffic lands between the two figures. Because lower-priority frames queue behind everything above them, latency at the bottom of the priority list rises steeply as load grows. Network designers therefore keep generous headroom and verify worst-case response times, not typical ones.

Five ways to catch an error

Every node checks every frame, including the ones it sends itself. ISO 11898-1 defines five error types:

Table 05CAN error types
ErrorDetected byCondition
Bit errorTransmitterThe level read back differs from the level sent (outside arbitration and the ACK slot)
Stuff errorAll nodesSix consecutive identical bits where stuffing applies
CRC errorReceiversThe received CRC does not match the calculated one
Form errorAll nodesA fixed-form bit (CRC delimiter, ACK delimiter, EOF) has the wrong level
Acknowledgement errorTransmitterNo dominant level in the ACK slot

A node that detects an error does not quietly discard the frame. It transmits an error flag: six dominant bits that deliberately break the stuffing rule, so every other node detects an error as well. A local error becomes a global one, all nodes discard the frame together, and the transmitter repeats it automatically. With very rare exceptions involving the last bit of the frame, either every node accepts a frame or none does.

On the wire, an error frame consists of the error flag followed by an eight-bit recessive error delimiter. Because other nodes respond with their own flags, the dominant part can stretch from six to twelve bits. A CRC error is signalled only after the ACK delimiter, so that frame is visibly complete before it is rejected.

Error counters, error passive and bus-off

A node that keeps destroying frames because its own transceiver or wiring is faulty must not be allowed to block the network. CAN's fault confinement gives every node two counters, a transmit error counter (TEC) and a receive error counter (REC). Errors raise them, successful frames lower them, and their values set the node's state:

Table 06Fault-confinement states
StateConditionBehaviour
Error activeTEC ≤ 127 and REC ≤ 127Normal operation; signals errors with active (dominant) error flags
Error passiveTEC > 127 or REC > 127Still communicates, but signals errors with passive (recessive) flags that cannot destroy other nodes' frames, and waits 8 extra bits before transmitting again
Bus-offTEC > 255Disconnected; transmits nothing until it has recovered
  • A transmitter that detects an error adds 8 to its TEC; each successful transmission subtracts 1.
  • A receiver that detects an error generally adds 1 to its REC, and 8 in specific cases such as a dominant bit straight after its own error flag; each successful reception subtracts 1.
  • The balance is therefore eight to one: a transmitter that fails more often than roughly one frame in nine climbs steadily towards bus-off.
  • A bus-off node may rejoin only after observing 128 occurrences of 11 consecutive recessive bits, and it restarts with both counters at zero.

The counters also explain why physical-layer faults show up as intermittent symptoms. A node that loses one frame in a hundred recovers its counters between errors and never leaves the error-active state. A node with a worse connection climbs to error passive, then to bus-off, disappears, recovers and reappears, and each disappearance is typically stored by the other ECUs as a lost-communication fault.

What frames look like on an oscilloscope

A two-channel oscilloscope on CAN-H and CAN-L, or a single differential probe, shows the structures described above without any protocol decoding:

Fig. 03Interactive
CH1 · CAN-H · 1 V/divCH2 · CAN-L · 1 V/div2 µs/div0 V

CAN-H rises and CAN-L falls by the same amount around 2.5 V. Edges are sharp and the recessive level is flat.

Fig. 03CAN-H and CAN-L on a two-channel scope: every dominant bit pushes the lines apart around 2.5 V. Compare a healthy bus with missing termination, a short to ground and swapped wires.
  • Start of frame: the first dominant bit after a long recessive idle. Trigger on a rising edge of CAN-H, with a minimum idle time if the scope offers one.
  • Bit width: the narrowest pulse in a frame is one bit time, 2 µs at 500 kbit/s. Stuffing guarantees that no run inside the frame exceeds five identical bits.
  • Acknowledgement slot: a single dominant bit near the end of the frame, often with a slightly different amplitude, because a receiver rather than the transmitter drives it.
  • End of frame: at least eleven recessive bits (ACK delimiter, seven EOF bits, three intermission bits) before the next SOF can appear.
  • Error flags: six or more dominant bits in a row. Valid traffic cannot contain them, so every such run proves that some node detected an error.

These visual checks complement the resistance and voltage measurements in Field diagnostics. They tell you whether frames complete and are acknowledged, which is often enough to decide whether a fault is electrical or lies elsewhere.

Frequently asked questions

Does a lower identifier mean a more important frame?

It means higher bus priority, which network designers assign according to timing deadlines. A frame with a high identifier can still carry safety-relevant content if its deadline is relaxed.

Can two ECUs send the same identifier?

Not as data frames with different content. Arbitration could not separate them, and the collision would appear as bit errors in the data field. Each data identifier on a network has exactly one transmitter.

Does an acknowledgement prove that the intended receiver got the frame?

No. It only confirms that at least one node received the frame without error. Where end-to-end confirmation matters, higher-layer protocols provide it, for example UDS responses or the acknowledgements of the J1939 transport protocol.

How many error frames are acceptable?

On a healthy vehicle network, practically none in normal operation. A few can occur during power transitions such as cranking or wake-up, but a continuous error rate always points to a physical or configuration problem.

Why does the same fault cause different symptoms on different days?

Because fault confinement is a running balance. Temperature, vibration and bus load change how often a marginal node fails, and with it whether the node stays error active, drifts to error passive or reaches bus-off.

End of articleUpdated 7. Oktober 2026
[Santim SC-1]

Every CAN vehicle. Ready from day one.

Santim SC-1 supports every classic CAN and CAN FD vehicle on the market. When a new vehicle launches, it is compatible instantly. No waiting, no requests. A next-generation CAN device.

The Santim SC-1 CAN device