Figured it would be interesting to create a threat for more in depth talk about the hardware on these computers, maybe document some of the unknowns in one central place, etc.
I've personally been focusing a lot on the RAM chips and ROMs (MROM, EPROM, EEPROM) and how the cpu interfaces with the chips, features (CART, DUCE, etc). I've been slowly working on a hardware test program to auto detect the chips on the board and test the related features that they support. Up to around early EEC-V era is covered quite nicely on the open eec project page, so tech details on those chips are best to check the documents posted there.
https://github.com/OpenEEC-Project
I've recently notice a chip that has the prefix like a RAM chip (81C) but the board shares a 2nd 81C chip. In the examples I have, it's 96-97 era computers, 81C69, and the known RAM chip 81C66. I haven't traced pins or looked at the bin code yet, but I'd guess the 81C69 relates to OBD2/J1850 PWM communication (older RAM chips tend to be the handler for serial communications so maybe that's why it has the 81C prefix).
Also it's known that the 8065 later became the high pin count EPIC chip. I haven't dove deep into them since I'm still learning the known hardware features of the older chips yet, but based on the fact the 81C chips are gone I'm thinking it combines 8065 and 81C functions into one chip.
Anyway, if anyone wants to talk/geek out over tech info or have an interesting chip, pop in the threat =).
EEC-IV and EEC-V Hardware Notes/talk
-
DWS
- Posts: 250
- Joined: Tue Oct 12, 2021 12:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
EEC-IV and EEC-V Hardware Notes/talk
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file
-
DWS
- Posts: 250
- Joined: Tue Oct 12, 2021 12:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
Re: EEC-IV and EEC-V Hardware Notes/talk
Chip Features:
8762 - 16k ROM + RP
8763 - 32k ROM + RP
87C66 - 56k EPROM + RP
87F66 - 56k EEPROM + RP
81C61 - 800h RAM + 5x IO
81C62 - 800h RAM + 5x IO + CART
81C65 - 800h RAM + CART + DUCE
81C66 - 800h RAM + EBC + DUCE
81C69 - ???
8762 - 16k ROM + RP
8763 - 32k ROM + RP
87C66 - 56k EPROM + RP
87F66 - 56k EEPROM + RP
81C61 - 800h RAM + 5x IO
81C62 - 800h RAM + 5x IO + CART
81C65 - 800h RAM + CART + DUCE
81C66 - 800h RAM + EBC + DUCE
81C69 - ???
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file
-
DWS
- Posts: 250
- Joined: Tue Oct 12, 2021 12:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
Re: EEC-IV and EEC-V Hardware Notes/talk
Chip Part Number References
If I have any details wrong, let me know. Also if you have details to add, always welcome. Photos are always neat too.
Code: Select all
------------------------------------------------------------------------------------------------
| CPU Type | PKG | MFR | PART NUMBER / MARKINGS | NOTES |
------------------------------------------------------------------------------------------------
| 8061 | DIP-40 | Intel | P8062BH 51R40180S10 | - |
| 8061? | CLCC-68 | Intel | 6017FKN016 | Unverified if 8061 |
| 8061 | PFP-68 | Intel | 56CA P8061BH 51-40180S08 A 76005CN | - |
| 8061 | PFP-68 | Intel | 56CB P8061BH 51R40180S08 S 76005CN | - |
| 8061 | PFP-68 | Intel | 56DA P8061BH 51R40180S08 P 76005CN | Pins 1 + 2 missing |
| 8061 | PFP-68 | Intel | 56EA P8061BH 76005CN IBA180S08 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Intel | 56EE P8061BH 76005CN IBA180S08 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Intel | 86EA P8061BH-5 76007CN IBA180S14 | - |
| 8061 | PFP-68 | Motorola | 76005CN RE MAD180S08 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Motorola | 76006CN RC 180S11 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Motorola | 76008CN RE MAD180S08 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Toshiba | 4899 76005CN RL 180S08 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Toshiba | 7899A 76005CN RL 180S08 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Toshiba | 7899-1 76006CN RL 180S11 | Pins 1 + 2 missing |
| 8061 | PFP-68 | Toshiba | 7666A 76005CN 180S08 | Pins 1 + 2 missing |
| 8061 | PLCC-68 | Intel | P8061BH-3 51-40180S03 76006CN | - |
| 8065 | PLCC-68 | Intel | N8065EB 76001CCHFA IBA780M01 | - |
| 8065 | PLCC-68 | Intel | N8065EB F8 76001CCHFA | - |
| 8065 | PLCC-68 | Intel | N8065EB F9 76001CCHFA | - |
------------------------------------------------------------------------------------------------
Code: Select all
-------------------------------------------------------------------------------------------------------------------------------------------------
| RAM Type | RAM Add | IO Add | CART Add | EBC Add | DUCE Add | PKG | MFR | PART NUMBER / MARKINGS | NOTES |
-------------------------------------------------------------------------------------------------------------------------------------------------
| 81C61-A | 0100-08FF | 092f | - | - | - | DIP-24 | | 500SC111 | 7.5Mhz,12Mhz |
| 81C61-A | 0100-08FF | 092f | - | - | - | DIP-24 | Motorola | 5003SC111 | 7.5Mhz,12Mhz |
| 81C61-A | 0100-08FF | 092f | - | - | - | DIP-24 | | 81C61-A 5003SC021 | 15Mhz |
| 81C61-A | 0100-08FF | 092f | - | - | - | DIP-24 | | P81C61-A N5030FSC021 | 15Mhz |
| 81C61-B | 0100-04FF | 092f | - | - | - | DIP-24 | | | - |
| | 0800-0BFF | | | | | | | | - |
| 81C62-A | 0100-08FF | 092f | 0900-093F | - | - | DIP-24 | Intel | P81C62A N7500120FSC121 IAA931T05 | 12Mhz,15Mhz |
| 81C65-A | 0100-08FF | - | 0900-093F | - | 0940-097F | DIP-24 | | | - |
| 81C66-D | 0400-0BFF | - | - | 0F00-0F3F | 0940-097F | QFP-44 | | N81C66DB F9 5021SC064 | - |
| 81C69 | ? | ? | ? | ? | ? | QFP-68 | | N81C69BC F8 5018SC066 | DARC |
| 81C69 | ? | ? | ? | ? | ? | QFP-68 | | N81C69BC F9 5018SC066 | DARC |
-------------------------------------------------------------------------------------------------------------------------------------------------
Code: Select all
---------------------------------------------------------------------------------------------------------------------------------------------
| ROM Type | Size | ROM Add | RP Add | PKG | MFR | Chip ID? | PART NUMBER / MARKINGS | NOTES |
---------------------------------------------------------------------------------------------------------------------------------------------
| 8763-0 | 32k | 2000-9FFF | 0930 | DIP-24 | Intel | ? | D8763 N74120FRN S568020 | 15Mhz,Windowed |
| 8763-0 | 32k | 2000-9FFF | 0930 | DIP-24 | TI | ? | N73120FRN | 12Mhz,Windowed |
| 8763-1 | 32k | A000-FFFF | 0934 | DIP-24 | Intel | ? | D8763 N73120FRN S56014 | 12Mhz,Windowed |
| 87C66-A | 56k | 2000-FFFF | 0930 | DIP-24 | Intel | ? | N70513FEC-A S7868 | 18Mhz,Windowed |
| ? | 88k | ? | ? | DIP-24 | ? | 891D | N71544FTCAGA | - |
| ? | 112k | 2000-FFFF x2 | ? | QFP-32 | ? | 891B | N71965FTCHCA | - |
| ? | 216k | 2000-FFFF X4 | ? | QFP-32 | Intel | ? | N70005FWCHCA | - |
| ? | 216k | ? | ? | QFP-32 | Intel | ? | Z70005FWCHCA IBA491U01 ES | From Socketed Prototype Computer |
---------------------------------------------------------------------------------------------------------------------------------------------
Note: Not sure if Chip ID is correct, still collecting info on usage. Older 56k documentation (10-11.1.2) states 1st byte is mfg and 2nd is programming algorithm.
Last edited by DWS on Sat Aug 29, 2026 7:00 am, edited 7 times in total.
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file
-
DWS
- Posts: 250
- Joined: Tue Oct 12, 2021 12:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
Re: EEC-IV and EEC-V Hardware Notes/talk
Welp, I've been poking at hardware long enough that I probably should upgrade equipment. Got a logic analyzer coming, been running off a pico automotive 4 channel scope.
I'll probably restructure the first 3 posts over time. Thinking raw chip features, addresses, markings in one, and maybe pinouts in another. The 216k eeprom I have mapped out for the main bus/control lines, there's around 13 pins left unmapped that I suspect are mostly RP pins like older variations.
I've been poking a little at the mbus to get program counter updates working, reading rom data, and ideally get rom programming functional. It seems like not many people have had success writing the EEC-IV era eproms at least in modern day and with out using an expensive 80's era programmer. I might target 216k first since OBD2 flashing exists, so can monitor how the chip is controlled during that process. I'd guess the older eeproms function similarly with similar specs. eproms would be a new world for me but sounds like besides the uv erase, it's effectively the same core concept.
Anyway, I have very basic mbus control working and am able to read rom contents via J3. I know there's other tools that just strobe the contents out, I actually set the program counter then strobe the data out, so I could jump to any address I'd want. Currently only been tested on 32k era 8061 computer.
Ultimately, I'm hoping to help open up the eec4-5 era tuning a bit more and even possible mods like adding more inputs, expanding memory, external cpu processing, etc. A lot could technically be done over J3 from what I'm seeing. From what I can tell the most advance device currently is a quarter horse, but I think more could be possible. Like hardware testing is an area that seems to be lacking for these and they fail a lot, having manual control for every I/O and being able to read live data of any input supported within the hardware I think would be a massive advantage for troubleshooting beyond simple cap replacements. RAM tests, chip feature tests, etc. I suspect most issues are related to power drivers, caps, and physical damage, but I'm sure ram chips fail in bizarre ways that's extra hard to troubleshoot and those boards end up parts boards.
Anyway, this is effectively a hobby project on the side for myself to learn more. I might attempt to build some sort of product down the road, but I know a big limitation is eec-v era chips not being documented, pinouts, etc.
I'll probably restructure the first 3 posts over time. Thinking raw chip features, addresses, markings in one, and maybe pinouts in another. The 216k eeprom I have mapped out for the main bus/control lines, there's around 13 pins left unmapped that I suspect are mostly RP pins like older variations.
I've been poking a little at the mbus to get program counter updates working, reading rom data, and ideally get rom programming functional. It seems like not many people have had success writing the EEC-IV era eproms at least in modern day and with out using an expensive 80's era programmer. I might target 216k first since OBD2 flashing exists, so can monitor how the chip is controlled during that process. I'd guess the older eeproms function similarly with similar specs. eproms would be a new world for me but sounds like besides the uv erase, it's effectively the same core concept.
Anyway, I have very basic mbus control working and am able to read rom contents via J3. I know there's other tools that just strobe the contents out, I actually set the program counter then strobe the data out, so I could jump to any address I'd want. Currently only been tested on 32k era 8061 computer.
Ultimately, I'm hoping to help open up the eec4-5 era tuning a bit more and even possible mods like adding more inputs, expanding memory, external cpu processing, etc. A lot could technically be done over J3 from what I'm seeing. From what I can tell the most advance device currently is a quarter horse, but I think more could be possible. Like hardware testing is an area that seems to be lacking for these and they fail a lot, having manual control for every I/O and being able to read live data of any input supported within the hardware I think would be a massive advantage for troubleshooting beyond simple cap replacements. RAM tests, chip feature tests, etc. I suspect most issues are related to power drivers, caps, and physical damage, but I'm sure ram chips fail in bizarre ways that's extra hard to troubleshoot and those boards end up parts boards.
Anyway, this is effectively a hobby project on the side for myself to learn more. I might attempt to build some sort of product down the road, but I know a big limitation is eec-v era chips not being documented, pinouts, etc.
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file
-
jsa
- Posts: 15
- Joined: Fri Sep 22, 2023 9:32 pm
- cars: Escort RS Cosworth
Re: EEC-IV and EEC-V Hardware Notes/talk
Interesting that they left 2 N.C. pins off but not all N.C. pins.
Digging through the available documents, 81C69 is supposed to be a Dual Access RAM + I/O expansion chip. Do the circuit boards you are referencing have IC numbers printed next the chips?
Digging through the available documents, 81C69 is supposed to be a Dual Access RAM + I/O expansion chip. Do the circuit boards you are referencing have IC numbers printed next the chips?
Cheers
John
John
-
DWS
- Posts: 250
- Joined: Tue Oct 12, 2021 12:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
Re: EEC-IV and EEC-V Hardware Notes/talk
The 8065 F9 board does.
81c69bc -f9 is marked IC97B, also has a 18mhz crystal next to it.
Is there a known pinout for it, or just small references? I have setup for talking on Mbus, so I could poke around at it at some point probably, or sniff memory access on it if the memory map is known.
I'm guessing last letter is reversion number for the IC involved, cpu is on IC1T for that board and the RAM chip matches IC3T (81C66DB F9)
The dual memory access makes a lot of sense, I've seen code references to sensor readings, but couldn't make much sense how those readings ended up in the memory locations. Was before I saw memory maps so don't recall what addresses I was looking at before. Could be something interesting to poke at lol.
Hopefully I'll be able to translate this into the teensy I'm getting and be able to mbus sniff live and in theory disable ROM and inject code on demand etc.
81c69bc -f9 is marked IC97B, also has a 18mhz crystal next to it.
Is there a known pinout for it, or just small references? I have setup for talking on Mbus, so I could poke around at it at some point probably, or sniff memory access on it if the memory map is known.
I'm guessing last letter is reversion number for the IC involved, cpu is on IC1T for that board and the RAM chip matches IC3T (81C66DB F9)
The dual memory access makes a lot of sense, I've seen code references to sensor readings, but couldn't make much sense how those readings ended up in the memory locations. Was before I saw memory maps so don't recall what addresses I was looking at before. Could be something interesting to poke at lol.
Hopefully I'll be able to translate this into the teensy I'm getting and be able to mbus sniff live and in theory disable ROM and inject code on demand etc.
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file
-
jsa
- Posts: 15
- Joined: Fri Sep 22, 2023 9:32 pm
- cars: Escort RS Cosworth
Re: EEC-IV and EEC-V Hardware Notes/talk
The EEC handbook on github/openeec has pin assignments for the DARC chip. Further detail can be found in the CDAN2 and CRAI8 strategy docs, also on openeec.
Yes, IC letter suffix indicates a revision version.
Yes, IC letter suffix indicates a revision version.
Cheers
John
John
-
DWS
- Posts: 250
- Joined: Tue Oct 12, 2021 12:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
Re: EEC-IV and EEC-V Hardware Notes/talk
That was way too useful, I didn't even notice the DARC was in the handbook, very little reference to it anywhere besides the strategy docs.
I think next task is to sniff the 2nd mbus and see what's talking on there and how. Gonna guess AICE, and I wonder if there's a setup process, or if like a boot loader is put into DARC, or if the processer instructions are internal etc. If it's 8065 based, even if it's internal rom, if it works like normal the instructions would still show up on the mbus which means I can reconstruct the code it runs in theory.
I also ordered a FPGA dev board, so that should be fun to play with. From what I read it's an extremely steep learning curve, and especially hard for people used to programming like me. It should be plenty fast enough to interface at mbus speeds and be able to code inject, etc on demand. Of course most basic thing is translating mbus to exposed address and data lines, pure logic gate setup and should be more or less what all the J3 chip FPGA's do.
Never thought buying a gaylord of ford computers would turn into wanting to dev on a FPGA lol, always wanted to play around with one, just never had a task in mind.
I think next task is to sniff the 2nd mbus and see what's talking on there and how. Gonna guess AICE, and I wonder if there's a setup process, or if like a boot loader is put into DARC, or if the processer instructions are internal etc. If it's 8065 based, even if it's internal rom, if it works like normal the instructions would still show up on the mbus which means I can reconstruct the code it runs in theory.
I also ordered a FPGA dev board, so that should be fun to play with. From what I read it's an extremely steep learning curve, and especially hard for people used to programming like me. It should be plenty fast enough to interface at mbus speeds and be able to code inject, etc on demand. Of course most basic thing is translating mbus to exposed address and data lines, pure logic gate setup and should be more or less what all the J3 chip FPGA's do.
Never thought buying a gaylord of ford computers would turn into wanting to dev on a FPGA lol, always wanted to play around with one, just never had a task in mind.
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file
-
jsa
- Posts: 15
- Joined: Fri Sep 22, 2023 9:32 pm
- cars: Escort RS Cosworth
Re: EEC-IV and EEC-V Hardware Notes/talk
AICE communicates with the uP via SFR's based on how the code works.
Cheers
John
John
-
DWS
- Posts: 250
- Joined: Tue Oct 12, 2021 12:04 am
- cars: Tons of Toyotas, 2003 cavi derby car, ford trucks, etc.
- Location: USA
Re: EEC-IV and EEC-V Hardware Notes/talk
I found a reference where AICE talks to the cpu via "SLAP". I have to look over the pinouts to see if I can identify that, be neat to at least get a capture, could be useful for identifying versions later etc. Is the hardware watchdog known on the 8065 era boards? Back when I was poking at them I was having reset problems, I was handling the cpu watchdog the same way as stock bins, but didn't work out the 2nd one. On EEC-IV I found LSO6 was used so on that era of board I can have a bare min program that doesn't get reset. If I recall correctly, pulse timing of stock bin was around 1-3ms and didn't matter what idle state is (high vs low), the pulse worked both directions in my testing.
I'm pretty sure I've seen a couple different variations in production bins, but this is the easiest pattern to remember. I think the center cpu watch dog instructions are purely to waste time for the pulse width to the hw watchdog. It's interesting that LSO6 bit gets labeled as CPU_OK instead of LSO6 or as R2 is normally labeled LSO_Port, so B6_LSO_Port ^= 1; . When I was digging through the code I looked for LSO, found the LSO_Port naming, and searched that and had no references to bit 6 till I went to the R2 search lol. Not sure if LSO6 is a thing for all EEC-IV, but I know it's a common design.
I did a capture on the DARC chip on the 2nd mbus, or at least the pins are labeled like the ref guide. Turns out the SPI uses the mbus pins as the chip select for the 8 channels, at least on the board I'm poking at. Would be interesting seeing a 2nd mbus in action since that should mean effectively a slave cpu of some sort and mbus would have instructions etc on it to sniff. At power on the control pins do pulse, so DARC might operate as the master/cpu on the 2nd mbus or maybe it can be setup for either operating mode, defo interesting.
Anyway, the SPI isn't the direction I was looking to go, so saving the capture and moving back towards the eeprom. Would be nice to work out the actual flash process even if it required removing the chip, of course not talking about over OBD2. Later, looking into the setup etc of the SPI of each chip type would be interesting to document and attempt to work out per chip type. I added a super zoomed out view showing the 8 way SPI capture. Each burst is 2 bytes, small gap, then 2 more bytes. The clock speed is ~1.2mhz, looking at the short burst, word transfer is ~27.6KB/s.
I don't think I mentioned before, but I have functional mbus control as long as the cpu is disabled (reset + pause low, or physically not present). I've read/wrote to 81c61-a ram for example and controlled the IO pins, and have interfaced with a few ROM chips can jump to an address and read from it as instruction requests. Of course an Arduino mega is way slower than native 8065 speeds, but it's functional for testing so far. The FPGA should unlock any speed limitations and should be able to pull off some fancy stuff not normally possible, like dynamic code injection.
Interfacing with the ROM chip is of course possible over J3 port, RAM however on the board I checked has it's reset line tied to the cpu reset line, so can't talk to ram directly with out pulling the chip and talking to it on a bread board.
I'm pretty sure I've seen a couple different variations in production bins, but this is the easiest pattern to remember. I think the center cpu watch dog instructions are purely to waste time for the pulse width to the hw watchdog. It's interesting that LSO6 bit gets labeled as CPU_OK instead of LSO6 or as R2 is normally labeled LSO_Port, so B6_LSO_Port ^= 1; . When I was digging through the code I looked for LSO, found the LSO_Port naming, and searched that and had no references to bit 6 till I went to the R2 search lol. Not sure if LSO6 is a thing for all EEC-IV, but I know it's a common design.
Code: Select all
66b8: 95,40,02 xorb R2,40 CPU_OK ^= 1;
66bb: 17,05 incb R5 WDG_Timer++;
66bb: 17,05 incb R5 WDG_Timer++;
66c0: 95,40,02 xorb R2,40 CPU_OK ^= 1;
Anyway, the SPI isn't the direction I was looking to go, so saving the capture and moving back towards the eeprom. Would be nice to work out the actual flash process even if it required removing the chip, of course not talking about over OBD2. Later, looking into the setup etc of the SPI of each chip type would be interesting to document and attempt to work out per chip type. I added a super zoomed out view showing the 8 way SPI capture. Each burst is 2 bytes, small gap, then 2 more bytes. The clock speed is ~1.2mhz, looking at the short burst, word transfer is ~27.6KB/s.
I don't think I mentioned before, but I have functional mbus control as long as the cpu is disabled (reset + pause low, or physically not present). I've read/wrote to 81c61-a ram for example and controlled the IO pins, and have interfaced with a few ROM chips can jump to an address and read from it as instruction requests. Of course an Arduino mega is way slower than native 8065 speeds, but it's functional for testing so far. The FPGA should unlock any speed limitations and should be able to pull off some fancy stuff not normally possible, like dynamic code injection.
Interfacing with the ROM chip is of course possible over J3 port, RAM however on the board I checked has it's reset line tied to the cpu reset line, so can't talk to ram directly with out pulling the chip and talking to it on a bread board.
You do not have the required permissions to view the files attached to this post.
Ford EEC-V Tuner Site
- Immo Off, PATS, Security only currently
- Bank Swapping
- View VIN and other info about the bin file