Overview of EPROM Storage in SIMATIC S5 CP Modules
Siemens SIMATIC S5 communication processors (CPs) use EPROM (erasable programmable read-only memory) or EEPROM (electrically erasable programmable read-only memory) modules to retain configuration data, protocol parameters, and bus-parameter sets after power is removed. The general characteristics of EPROM/EEPROM devices, including pinout, programming voltages, and cell architecture, are described in the EEPROM overview on Wikipedia; Siemens S5 CP modules follow the same non-volatile-memory conventions documented for industrial memory products such as the Microchip serial EEPROM family, although the S5 modules use parallel EPROMs sized for the CP's processor bus rather than serial I²C or SPI devices.
Unlike the S7 generation, where the central engineering platform (STEP 7 / TIA Portal) distributes the hardware configuration (HW Config) and the communication blocks (SFBs / SFCs) together with the user program, the S5 family splits this information between the CPU's program memory and the CP's EPROM card. Three categories of data are typically held on an S5 CP EPROM:
- Bus and protocol parameters - baud rate, station address, retry counts, timeouts, character frame.
- Communication relationships - FDL/SAP mapping for PROFIBUS, RK512/3964R driver selection for serial point-to-point.
- CP firmware or microcode - either pre-burned in mask ROM or supplied on the EPROM socket for field-upgradable modules.
The CP EPROM is not a copy of the user PLC program. The user program (AWL, KOP, FUP) is stored on the CPU EPROM or in battery-backed RAM on the CPU. The CP EPROM only contains the data that the CP's own processor needs to start, identify itself on the fieldbus, and serve the CPU's request frames. When backing up an S5 system, both stores must be saved independently.
CP5430 (6GK1543-0AA02) Technical Profile
The 6GK1543-0AA02 is a CP5430 TF variant - a communication processor for SINEC L2 / PROFIBUS networks used in the S5-135U and S5-155U racks. The module occupies one slot in the S5 central or expansion rack and exposes a 9-pin D-sub PROFIBUS connector on the front panel.
| Parameter | Value |
|---|---|
| Order number (MLFB) | 6GK1543-0AA02 |
| Designation | CP5430 TF (Basic variant) |
| Bus system | SINEC L2 / PROFIBUS FDL |
| Max. station count | Depends on FDL configuration (typ. 32 per segment) |
| Transmission rate | 9.6 kbit/s to 1.5 Mbit/s (bus-parameter dependent) |
| Memory for configuration | Socketed EPROM (27C256 or compatible) on the module |
| Connection to CPU | S5 backplane (dual-port RAM mailbox) |
| Configuration tool | COM543 (part of the COM525 family) or COM PROFIBUS |
Content of the CP5430 EPROM:
- Bus parameter set - slot time (Tsl), min. station delay (min Tsd), max. station delay (max Tsd), quiet time (Tqu), setup time (Tset), target rotation time (Ttr), gap factor (G).
- Own station address (0-126).
- FDL service access points (SAPs) mapped to CPU-side mailboxes.
- FDL send/receive list - list of active and passive partners, with CR (communication reference) numbers.
- Token rotation and gap timing parameters derived from the project file.
For complete field-replacement verification, the Ttr, Tsl, and Tqu values must match the master project. The formula for the bus-parameter target rotation time is:
T_tr = max(T_target_idle, sum of T_message_i) + slack
where Ttr must be larger than the longest expected token round-trip on the segment. Mismatched Ttr values are the most common reason for bus retries observed during CP5430 commissioning after EPROM replacement.
CP524 (6ES5524-3UA13) Technical Profile
The 6ES5524-3UA13 is a serial point-to-point communication processor with two independent serial interfaces, designed for S5-115U, S5-135U, and S5-155U racks. The "3UA13" suffix corresponds to the production-state revision that includes the two-TTY interface variant (variant identification is hardware-printed on the front label).
| Parameter | Value |
|---|---|
| Order number (MLFB) | 6ES5524-3UA13 |
| Interface 1 | TTY / 20 mA current loop (active or passive) |
| Interface 2 | TTY / 20 mA current loop (active or passive) |
| Supported protocols | ASCII driver, 3964R, RK512 (3964R with message frame) |
| Baud rate | 300 to 9600 bit/s (default), 19200 bit/s supported by driver |
| Character frame | 7E1, 7O1, 7N2, 8N1, 8E1 (project dependent) |
| Connection to CPU | S5 backplane mailbox |
| Configuration tool | COM525 (CP524 menu tree) |
| Typical application | Weighing systems, barcode scanners, third-party controllers |
Content of the CP524 EPROM:
- Per-port protocol selection (ASCII, 3964R, RK512).
- Per-port character frame - data bits, parity, stop bits.
- Per-port baud rate and modem-control signals (if RS-232 variant used).
- Timeout values - acknowledgment timeout (QVZ), character timeout (ZVZ), block-check-character timeout.
- Default buffer sizes for send/receive mailboxes shared with the CPU.
The character-frame and timeout values are project-specific and depend on the partner device. For a weighing system, typical settings are 9600 bit/s, 8N1, RK512 frame, with a QVZ of 4 s and a ZVZ of 220 ms. These values are stored in the EPROM and are not overwritten by a CPU program download.
COM525: The CP Configuration Utility
COM525 is the offline CP configuration tool in the STEP 5 / S5-DOS toolbox family. It is supplied on floppy disk (5.25" or 3.5" depending on version) and runs under S5-DOS / Windows for Workgroups 3.11. The product family includes:
| Tool | Target CP | Bus |
|---|---|---|
| COM525 | CP524, CP525, CP526, CP527 | Serial point-to-point |
| COM543 | CP5430 | SINEC L2 / PROFIBUS FDL |
| COM544 | CP544 | SINEC H1 (Ethernet, 10Base5) |
| COM PROFIBUS | CP5430/CP5431/IM308C | PROFIBUS FDL, DP master class 1 |
COM525 cannot "go online" to a CP in the way STEP 5 can online to a CPU. The workflow is:
- Open the COM525 project file (
*.S5Dor*.CP5) on the PG's hard disk. - Edit the port / bus parameters in the form-based UI.
- Compile to a binary image (the
*.BINfile). - Burn the binary image to an EPROM using the PG's EPROM programming adapter (e.g. PG 720 / PG 740 with the EPROM socket module).
- Insert the EPROM into the CP with the power OFF, then power up the rack.
Reading the EPROM back from the CP requires the same tool: load the EPROM into the PG's EPROM adapter, select Read EPROM in COM525, and save the image as a binary file. The binary can then be disassembled or compared against the original *.BIN with a hex editor.
How the S5 CPU Discovers and Uses a CP
On S5, the CPU does not maintain a hardware configuration database. The CP module is identified by the S5-AG (Ankoppelung, "coupling") handshake at rack-power-up:
- At power-on, the CPU scans each slot and reads the type identifier word from the module's input area.
- The identifier for a CP contains a module-type code (for example,
0x0Cfamily for serial CPs,0x1Ffamily for PROFIBUS CPs). - The CPU records the slot, the module type, and the size of the mailbox area in its internal coupler table (the "AG-Koppelfeld").
- From this point, the CPU accesses the CP via mailbox writes/reads to the dual-port RAM that occupies the lower 16 byte of the slot's I/O area.
Because the slot/AG information is acquired by polling at power-up, the S5 CPU does not need a "HW Config" download to know that a CP is present. However, the CPU does need the CP to be operational before it can send or receive frames. If the CP EPROM is empty or corrupt, the CP remains in STOP, the AG handshake reports a "CP not ready" status byte, and the CPU's SEND / RECEIVE calls return error code 0x0E (coupler error) in the status word.
For an S5-95U, the integrated serial interface uses a different mechanism (the on-board AG of the 95U CPU itself, no separate CP slot), but the same mailbox semantics apply. A CP5430 connected externally to an S5-95U - for example, via the 95U's parallel port or via a 95U-to-135U bridge - still uses the EPROM-loaded FDL configuration.
S5 vs S7: Configuration and Discovery Model
The architectural difference explains why the backup procedure for an S5 system is more involved than for an S7 system.
| Aspect | S5 | S7-300 / S7-400 |
|---|---|---|
| Configuration data store | CPU EPROM + per-CP EPROM | CPU MMC / flash only (HW Config lives in the project + downloaded blocks) |
| Tooling | STEP 5 (CPU) + COM525/COM543 (CP) | STEP 7 HW Config / TIA Portal |
| Online read | CPU: Upload to PG; CP: EPROM adapter only | CPU + CP: single Upload station to PG |
| CP firmware update | Physical EPROM swap (UV erase + re-burn) | Firmware download via online update |
| Coupler / bus parameters | Manually mirrored between CPU FDL block and CP EPROM | Automatically compiled and downloaded as part of HW Config |
| Identifier mechanism | Slot-type word polled at startup | Module identification via slot and HW Config object |
The S7 model is "configuration as data": the project is a single source of truth, and the engineering platform regenerates all CP bus parameters from that project. The S5 model is "configuration as artefact": the project is a set of binary images (CPU EPROM image + one EPROM image per CP) and each image is stored and updated independently. This is why a full S5 backup is a multi-step process and not a single Upload.
Step-by-Step: Backing Up CP EPROM Content
Use this procedure for the CP5430 (6GK1543-0AA02) and the CP524 (6ES5524-3UA13) - the workflow is the same, the COM525 / COM543 menu paths differ.
Prerequisites
- Siemens PG 720 / PG 740 / PG 760 with EPROM programming adapter (or a third-party universal programmer such as HiLo ALL-11 or Data I/O).
- COM525 disk set (5.25" or 3.5") with valid license key disk.
- Blank UV-erased 27C256 (or compatible) EPROMs, one per CP, plus one labelled "MASTER" per rack.
- Anti-static foam and an EPROM eraser (UV, with 254 nm shortwave lamp).
- Original project source on PG hard disk (if still available).
Procedure
- Power down the S5 rack. Mark and remove the CP module. Place it on anti-static foam.
- Locate the EPROM socket on the CP module (for CP5430 it is a 28-pin DIP socket near the front edge; for CP524 it is a 28-pin DIP near the centre of the PCB).
- Using an IC extractor, remove the EPROM. Note the orientation (notch direction) - this is critical for re-insertion.
- Place the EPROM in the PG's programming adapter.
- Launch COM525 (for CP524) or COM543 (for CP5430). Choose File > Read EPROM.
- Select the device type (27C256) and the start address (
0x0000). Accept the default read range (0x0000-0x7FFF). - Save the binary image to the PG's hard disk with a descriptive filename, e.g.
CP5430_AA02_RACK3_S5_155U_2008-11-12.bin. - Generate a checksum (CRC-16 / Modbus polynomial
0xA001) and log it. This is the integrity value you compare on restore. - Re-insert the EPROM into the CP module, observing the notch orientation.
- Re-install the CP module in its slot. Power up the rack. Verify the CP LED transitions from STOP to RUN within 5 s of power-up.
- Repeat for every CP in every rack. Save a copy of each binary image off-site (network share, CD-ROM, or current-generation storage).
Optional: parameter extraction
For documentation, use COM525's File > Open project to load the *.S5D project that produced the EPROM, and re-export a human-readable parameter sheet (baud rate, parity, timeouts, station address). This sheet travels with the binary image for future engineers.
EPROM Hardware Programming Notes
CP EPROMs for S5 CPs are typically 27C256 (32 KB x 8) EPROMs, occasionally 27C128 (16 KB x 8) on earlier revisions, and on later CP firmware revisions an EEPROM with the JEDEC-compatible pinout (e.g. 28C256 from Microchip's parallel EEPROM family) is supported. Key programming parameters:
| Parameter | 27C256 | 28C256 (EEPROM) |
|---|---|---|
| Capacity | 32 K x 8 (256 Kbit) | 32 K x 8 (256 Kbit) |
| Programming voltage Vpp | 12.5 V (typical) | 5 V (in-system) |
| Erase | UV, 30 min at 254 nm | Software (chip-erase command) |
| Endurance | 100 erase / program cycles | 10,000 erase / program cycles |
| Read access time | 120 ns to 250 ns | 120 ns to 250 ns |
Pin 1 (Vpp on 27C256) and pin 27 (PGM / not used on read) must be referenced correctly when inserting the EPROM. The socket notch is on the component side, between pins 1 and 28. The CP module silkscreen includes a notch marker on the PCB - align them.
Verification Procedure After Restore
- After burning the EPROM, place it in the programming adapter and read it back. Confirm byte-for-byte match against the source binary (use a hex-diff tool such as
fc /bon Windows orcmp -lon Linux). - Insert the EPROM into the CP and observe the front-panel LED sequence: STOP for approximately 1 s, then RUN with no SF (system fault) LED.
- From the CPU PG, run Online > CPU Information > Coupler Status in STEP 5. The CP should report Ready with the configured station address.
- Send a one-shot test frame to a known partner station. For CP5430, use STEP 5's FDL test function in the COM543 online tool. For CP524, run a 3964R loop-back or a single RK512 SEND/RECEIVE pair from a function block.
- Verify the bus-parameter values stored in the CP match the project file. For CP5430, read the bus-parameter dump via COM543: Online > CP Information. The reported Ttr, Tsl, and Tqu must equal the project values within 0.5% tolerance.
Troubleshooting Matrix
| Symptom | Likely cause | Action |
|---|---|---|
| CP LED stays in STOP after power-up | Empty / corrupt EPROM, or backwards insertion | Re-seat the EPROM with notch aligned; re-read with COM525 and compare CRC |
| CP enters RUN, then SF LED illuminates | Bus-parameter mismatch (Ttr, Tsl) | Re-open the project in COM543, re-export the EPROM image, re-burn |
CPU returns 0x0E from SEND/RECEIVE |
CP not ready or AG handshake failed | Check Coupler Status in STEP 5; verify CP slot and mailbox area |
| COM525 cannot read the EPROM | Wrong device type selected, or 12.5 V Vpp not enabled | Confirm device = 27C256, Vpp = 12.5 V in programmer menu |
| PG reports checksum error on EPROM load | One or more bits have aged out (EPROM data retention exceeded) | Re-program a fresh EPROM from the source *.BIN; retire the old device |
| 3954R block-check-character error (CP524) | Baud rate or parity mismatch with partner | Verify port character frame in COM525 against partner documentation |
| CP5430 not seen by CPU after slot change | Slot-type word differs at new address | Re-run CPU startup; check that the slot is not shared with an I/O card |
| Partner reports "station not found" on PROFIBUS | Station address in EPROM does not match project | Re-export binary from project; re-burn; confirm address with COM543 |
Specifications Summary
| Specification | CP5430 (6GK1543-0AA02) | CP524 (6ES5524-3UA13) |
|---|---|---|
| Family | SINEC L2 / PROFIBUS | Serial point-to-point |
| Processor on module | 16-bit CP processor | 8/16-bit CP processor |
| EPEROM type | 27C256 (32 K x 8) | 27C256 (32 K x 8) |
| Bus parameters stored | Ttr, Tsl, Tqu, Tset, station address, FDL SAP table | Baud rate, parity, protocol, timeouts, per-port |
| Configuration tool | COM543 / COM PROFIBUS | COM525 |
| Backup method | PG EPROM adapter, read binary | PG EPROM adapter, read binary |
| Read-back from CPU online | Not supported | Not supported |
| Slot in S5 rack | 1 slot, S5-135U / S5-155U | 1 slot, S5-115U / S5-135U / S5-155U |
| Connection type | 9-pin D-sub PROFIBUS | 2 x TTY / 20 mA |
Additional Engineering Notes
- CP EPROMs are static-sensitive and should be stored in conductive foam at room temperature. EPROM data retention is rated 10+ years for UV-erasable parts, but high-temperature environments (above 40 °C) accelerate leakage - verify CRC of the MASTER image once per year.
- For S5-95U systems, the integrated serial port is part of the CPU EPROM image and is therefore included in the standard Upload to PG backup. A separate CP EPROM backup is only required for externally-attached CPs such as the CP5430.
- When migrating from S5 to S7, the bus parameters stored on the CP EPROM must be re-entered in STEP 7 HW Config. The COM543 export function can produce an ASCII dump of Ttr, Tsl, and station addresses, which speeds up the manual translation.
- Siemens Industry Online Support retains a legacy product archive for SIMATIC S5, including the COM525 manual and the S5-115U / S5-135U / S5-155U system manuals. Search the document database with order numbers 6ES5 ... and 6GK1 ... to find the corresponding PDF manuals.
- Always label EPROMs with the order number (for example, 6GK1543-0AA02), the rack, the slot, and the project revision. A labelling convention saves hours during a future rebuild.
FAQ
What is stored on the EPROM of an S5 CP module?
The CP EPROM stores configuration data only - bus parameters (Ttr, Tsl, Tqu), the CP's own station address, FDL/SAP mapping for PROFIBUS CPs, or serial protocol/character-frame settings for point-to-point CPs. The user PLC program is not on the CP EPROM; it is on the CPU EPROM and must be backed up separately.
Can I read the CP5430 EPROM via the S5 CPU online connection?
No. The CPU's online functions address the CPU EPROM only. The CP5430 EPROM must be physically removed and read with a PG EPROM adapter (e.g. on a PG 720 / PG 740) using the COM543 / COM525 tool's Read EPROM function.
Which software reads the CP524 EPROM?
COM525, part of the STEP 5 / S5-DOS toolbox. Insert the EPROM in the PG programming adapter, launch COM525, and choose File > Read EPROM. The resulting binary image can be saved as a *.BIN file and compared with the original using a hex-diff tool.
How does the S5 CPU know that a CP is installed in a slot?
At power-up the CPU polls each slot and reads a module-type identifier word. The CP reports its type code, slot, and mailbox size; the CPU stores this in its internal coupler table (the AG-Koppelfeld) and uses mailbox reads/writes to the CP's dual-port RAM for all subsequent communication.
What is the difference between COM525 and COM543?
COM525 is for serial point-to-point CPs (CP524, CP525, CP526, CP527); COM543 is for the CP5430 (SINEC L2 / PROFIBUS). The two tools share the same look-and-feel and both read/write EPROM images, but their bus-parameter editors and SAP tables differ because the protocols are different.
What type of EPROM is used in the CP5430 and CP524?
Most CP5430 and CP524 modules use a 27C256 (32 K x 8) UV-erasable EPROM. Later revisions support a JEDEC-compatible 28C256 EEPROM with software-erase, which simplifies field updates. The CP module's PCB silkscreen shows the notch orientation for pin-1 alignment.
Why does the CP LED stay in STOP after a battery change on the CPU?
The CPU's battery and the CP EPROM are independent non-volatile stores. A battery change or CPU program download does not affect the CP EPROM. If the CP is in STOP after a CPU restart, the issue is at the CP - check that the EPROM is correctly seated, the notch aligned, and that the bus parameters match the project.