Diese Bedienungsanleitung beschreibt den ordnungsgemäßen Betrieb des Industrie-IoT-Gateways Coldwave Yukiblock CAN der ImagineOn GmbH. Sie richtet sich an Integratoren und Anlagen-Hersteller (elektrotechnisches Fachpersonal), Anlagenbetreiber (Asset Owner) und Servicepersonal.
Sie ist Teil der gemäß Anhang V der EU-Funkanlagenrichtlinie 2014/53/EU (RED) erforderlichen Dokumentation und ist über die gesamte Lebensdauer des Geräts beim Anlagenbetreiber zugänglich aufzubewahren. Eine begleitende Beschreibung der Sicherheitsarchitektur enthält das Security-Whitepaper zum Coldwave Yukiblock CAN.
ImagineOn GmbH
Neusser Str. 27–29
50670 Köln, Deutschland
Kontakt: support@coldwave.io · www.imagineon.de
Das Gerät trägt das CE-Logo auf dem Typenschild. Anwendbare EU-Rechtsakte:
Vorbereitend berücksichtigt: EU-Cyber-Resilience-Act (Verordnung (EU) 2024/2847, volle Anwendbarkeit ab 2027-12-11, Meldepflichten ab 2026-09-11).
| Bereich | Norm |
|---|---|
| Sicherheit | EN 62368-1 |
| EMV | EN 301 489-1, EN 301 489-17, EN 301 489-52 |
| Funk (LTE-M / NB-IoT) | EN 301 908-1, EN 301 908-13 |
| HF-Exposition | EN 50665 |
| Cybersicherheit | EN 18031-1:2024 (Self-Assessment, Modul A) |
| Vorausschauend | ETSI EN 303 645 (Baseline-Anforderungen Consumer-IoT) |
Hinweis: Die Hardware-Plattform (EFR32MG26) enthält einen Bluetooth-LE-Funkbaustein, der in der ausgelieferten Variante CAN/LTE-M per Firmware deaktiviert ist. EN 300 328 wird daher in der vorliegenden Variante nicht als anwendbare Norm geführt; ist sie auf der Beilage aufgeführt, gilt sie als plattformbezogener Vorhalt für künftige Varianten.
Der Coldwave Yukiblock CAN ist ein stationäres Industrie-IoT-Gateway, das die Datenpunkte eines CANopen-Feldbusses (Classic CAN 2.0, über einen externen MCP2518FD-SPI-Controller) erfasst — z. B. Vorlauftemperaturen, Pumpendrehzahlen, Betriebsstunden aus Anlagen der Heizungs-, Lüftungs- und Klimatechnik oder aus kompakten Industrieaggregaten — und diese über Mobilfunk (LTE-M / NB-IoT) verschlüsselt an das Coldwave-Backend überträgt. Das Gerät arbeitet ausschließlich als CANopen-Slave und ist so ausgelegt, dass es den Bus nicht destabilisiert.
Typische Anwendungsfälle:
Auf dem Typenschild (Gehäuserückseite / -seite) finden Sie:
Yukiblock CAN, Produkt-ID YCA2)EFR32MG26-HW2)Die Sendeleistung des integrierten LTE-M-Funkmoduls (Quectel BG77, typisch 20 dBm = 100 mW / Power Class 5) liegt deutlich unter den Grenzwerten der EN 50665. Bei bestimmungsgemäßer Montage (Schaltschrank-/Wandeinbau) und einem Mindestabstand von 20 cm zum Aufenthaltsbereich von Personen werden die Grenzwerte sicher eingehalten.
| Symbol | Bedeutung |
|---|---|
| CE | Konformität mit den anwendbaren EU-Rechtsakten |
| Durchgestrichene Mülltonne | Nicht über Hausmüll entsorgen — siehe §22 |
| SELV-Symbol (III) | Schutzklasse III, Versorgung aus SELV/PELV-Quelle |
| QR „EU-Konformitätserklärung" | DoC online verfügbar |
| QR „Online-Benutzerhandbuch" | Diese Anleitung, jeweils aktuelle Fassung |
Die folgenden Bedien-, Anzeige- und Anschlusselemente sind auf dem Hardware-Quickstart bebildert. Die genaue mechanische Anordnung und Beschriftung entnehmen Sie der Beilage.
| Element | Funktion |
|---|---|
| Reset-/Service-Öffnung | Versenkter Taster für Soft-Reset / Backend-Re-Attach (§15) |
| Power-/Status-LED | DC-Versorgung anliegend / Pufferbetrieb über internen Supercap (§14) |
| Netzwerk-LED | Mobilfunk- und Coldwave-Backend-Status (§14) |
| CAN-Bus-LED | CANopen-Bus-Status (§14) |
| Stromversorgungs-Anschluss | Steckbar, DC (SELV/PELV) [zu bestätigen: Belegung] |
| CAN-Anschluss | CANopen (Classic CAN 2.0), differenzieller Zweidraht-Bus (§7) [zu bestätigen: Belegung/Terminierung] |
| Antennenanschluss | Externe LTE-M-/NB-IoT-Antenne [zu bestätigen: Anschlusstyp] |
Kern des Geräts ist der Mikrocontroller Silicon Labs EFR32MG26 (ARM Cortex-M33 mit Secure Vault). Die CAN-Anbindung erfolgt über einen externen MCP2518FD-SPI-Controller (Classic CAN 2.0). Beim Anlauf führt das Gerät einen internen Loopback-Selbsttest des CAN-Controllers aus.
Der Feldbus-Anschluss ist ein CANopen-Bus nach Classic CAN 2.0: ein differenzieller Zweidraht-Bus (CAN-High / CAN-Low) mit gemeinsamer Bezugsmasse. Die genaue Steckverbinder-Belegung sowie die Ausführung von Terminierung und Isolation entnehmen Sie dem Hardware-Quickstart [zu bestätigen].
Das Gerät arbeitet ausschließlich als CANopen-Slave. Es lauscht am Bus und dekodiert SDO/PDO/NMT/EMCY/Heartbeat-Frames der angeschlossenen Knoten und spiegelt die per Mapping ausgewählten Objektwerte in das Coldwave-Backend. Der SDO-Server ist am Bus erreichbar (CANopenNode-Default), das SDO-Server-Parameter-Objekt 0x1200 ist jedoch busseitig read-only, und es existieren keine remote-schreibbaren Applikations-OD-Parameter — über den CANopen-Bus ist somit keine persistente Konfigurationsänderung möglich.
Bitrate, Node-ID und CAN-Aktivierung werden im Coldwave-Portal gesetzt (siehe §10). Das Gerät verfügt über eine Bus-off-Erkennung mit kontrollierter Recovery (Backoff), sodass es den Bus im Fehlerfall nicht durch wiederholtes Anlaufen destabilisiert.
Die ausführliche Montagesequenz (Befestigung, Antennenmontage, Verkabelung, Abnehmen) ist im Hardware-Quickstart bebildert. Diese Anleitung wiederholt sie nicht.
Der Yukiblock CAN wird mit einer fest aufgelöteten, Coldwave-managed eSIM ausgeliefert; ein eigener Mobilfunkvertrag ist nicht erforderlich (Details §17). Die Zuordnung des Geräts zum Coldwave-Backend erfolgt backend-seitig über die IMEI.
Nach erfolgreicher Zuordnung wird die anlagenspezifische Konfiguration über das Portal ausgerollt:
Im Normalbetrieb arbeitet das Gerät vollkommen autonom. Es liest die im Mapping definierten CANopen-Objektwerte vom Bus, aggregiert sie und überträgt sie im budgetgesteuerten Zyklus (Default-Telemetrie-Takt ca. 5 min, datenbudget-gesteuert) ans Coldwave-Backend. Status- und Diagnosewerte werden mitgeführt:
Die genauen Bezeichnungen dieser Werte und der änderbaren Parameter finden Sie im Coldwave-Portal. Alle änderbaren Konfigurationswerte werden über das Portal gesetzt und im Gerät persistent gespeichert. Ein lokales Konfigurationsinterface (Webinterface, USB-Konfig, Konfigurations-Taster) existiert nicht.
Die Übersetzung zwischen CANopen-Objekten/-Datenpunkten und den Cloud-Datenpunkten erfolgt über ein Mapping, das im Coldwave-Portal verwaltet und vom Backend an das Gerät ausgeliefert wird. Die Mapping-Tabelle ist die einzige Vertrauensgrenze, über die das Backend in die persistente On-Device-Konfiguration schreibt; sie wird bei der Deserialisierung streng validiert.
Der Yukiblock CAN enthält eine eingebettete, PLC-artige Script-VM (coldwave-script-vm) für einfache Logik, Filterung und Vorverarbeitung direkt auf dem Gerät. Typische Anwendungsfälle:
Die Script-VM läuft in einer speicherbegrenzten Sandbox ohne direkten Hardware-/Raw-IO-Zugriff. Skripte werden ausschließlich signiert über die Cloud durch den Anlagen-Hersteller eingespielt, nicht durch den Betreiber. Aktivierung, Skript-Upload und Statusanzeige (laufend / Fehlercode / Speicherbedarf) erfolgen vollständig über das Coldwave-Portal. Die vollständige Skript-Referenz mit Beispielen finden Sie unter https://doc.coldwave.io/script/v1/.
Firmware-Updates erfolgen Over-the-Air über die Mobilfunkverbindung. Der Ablauf ist vollständig automatisiert:
Das Gerät besitzt drei Anzeigefunktionen: eine Power-/Status-LED, eine Netzwerk-LED (Mobilfunk + Backend) und eine CAN-Bus-LED. Die genauen Farb- und Blinkcodes sind auf dem Hardware-Quickstart dokumentiert; die folgende Übersicht beschreibt die Funktion. Abweichungen können durch laufende Updates oder Wartungsfenster auftreten.
Signalisiert die anliegende DC-Versorgung und den Pufferbetrieb über den internen Supercap. Bei einem Versorgungsverlust überbrückt der Supercap kurzzeitig und ermöglicht ein kontrolliertes Herunterfahren (Backend-Sync, Modem-Trennung); bei Rückkehr der Versorgung läuft das Gerät automatisch wieder an. Die genaue Codierung entnehmen Sie dem Quickstart [zu bestätigen].
| LED-Zustand | Bedeutung |
|---|---|
| grün, dauerhaft | Online beim Coldwave-Backend — Normalzustand |
| blinkend | Verbindungsaufbau: Mobilfunk-Attach bzw. Backend-Anmeldung läuft |
| rot | Kein Mobilfunknetz / keine Backend-Verbindung (Booten, Netzsuche, kein Empfang) |
| aus | Modem deaktiviert (z. B. energiesparend nach Versorgungsverlust; Reaktivierung beim Wiederanlauf) |
Exakte Farb-/Blinkcodes (inkl. Schwellwert für schwachen Empfang) siehe Hardware-Quickstart [zu bestätigen].
| LED-Zustand | Bedeutung |
|---|---|
| grün | CANopen-Bus aktiv; Knoten antworten, keine Fehler |
| rot | Bus-Fehler / Bus-off oder über mehrere Sekunden keine gültigen Frames (Verkabelung, Bitrate, Terminierung prüfen) |
| aus | CAN-Betrieb nicht aktiviert oder Mapping leer |
Der Service-Taster ist versenkt und wird mit einem dünnen Stift betätigt. Seine genaue Funktion ist im Hardware-Quickstart dokumentiert [zu bestätigen]; typischerweise löst ein kurzer Druck einen Soft-Reset aus (Neuaufbau der Backend-Verbindung, Konfiguration/Mappings/Skript bleiben erhalten).
Der Yukiblock CAN ist nach EN 18031-1 (Self-Assessment) als „internet-verbundenes Funkgerät" bewertet. Er ist als „Black-Box"-Gerät ausgelegt: Es gibt keine Operator-Konfiguration, kein Webportal, keine SSH/Telnet-Konsole und keinen USB-Konfigurationsanschluss — die Sicherheitskonfiguration ist im Firmware-Image festverdrahtet.
ImagineOn stellt für dieses Produkt mindestens 10 Jahre ab dem ersten Inverkehrbringen sicherheitsrelevante Firmware-Updates bereit. Das Ende der Sicherheits-Update-Versorgung pro Hardware-Revision wird in der CHANGELOG.md und im Coldwave-Cloud-Portal dokumentiert.
Im Gerät ist eine fest verlötete, Coldwave-managed eSIM verbaut. Der Anlagenbetreiber muss keinen eigenen Mobilfunkvertrag abschließen und keine SIM-Karte einlegen. Das Mobilfunkmodul (Quectel BG77) ist auf der Platine verlötet.
Das monatliche Datenkontingent wird beim Kauf festgelegt; Coldwave bietet hierfür mehrere Tarifoptionen. Das Gerät überwacht den Verbrauch laufend und passt die Synchronisationsfrequenz so an, dass das Budget eingehalten wird (Hard-Cap). Das verbleibende Budget des laufenden Monats wird im Coldwave-Portal bei den Diagnosewerten des Geräts angezeigt.
Voraussetzung für den Betrieb ist eine ausreichende LTE-M-/NB-IoT-Netzversorgung am Aufstellort. Das Gerät nutzt eine private Coldwave-APN im Netz der Deutschen Telekom. Aktuellen Status und Abdeckungs-Hinweise finden Sie im Coldwave-Portal (https://app.coldwave.io).
Das Gerät führt periodische Reconnect-Versuche mit Backoff durch; der Connectivity-Supervisor hält den lokalen Bus-Betrieb aufrecht. Nach maximal drei vergeblichen Re-Resets führt das Gerät ein kontrolliertes Modem-Reset und anschließend einen Selbst-Reboot aus. Während der Offline-Phase werden keine Telemetrie und keine Updates übertragen; beide werden bei der nächsten erfolgreichen Verbindung fortgesetzt.
Das Gerät ist im Normalbetrieb wartungsfrei. Eine Ausnahme stellt die RTC-Pufferbatterie dar.
| Typ | Lithium-Knopfzelle [zu bestätigen: Zelltyp aus der Hardware-Dokumentation] |
|---|---|
| Funktion | Puffert die Echtzeituhr (PCF85363) und batteriegepufferte RAM-Slots bei längerem stromlosem Zustand. |
| Typische Lebensdauer | [zu bestätigen] (die Pufferzelle wird nur bei Stromausfall belastet) |
| Tausch | Ausschließlich durch autorisierten Service (Gehäuse-Öffnung). Bitte nicht selbst öffnen. |
| Funkdienst | LTE-M (3GPP Cat-M1, eMTC, Rel. 13) / NB-IoT-Fallback |
|---|---|
| Funkmodul | Quectel BG77 (vorzertifiziert) |
| Unterstützte Bänder | Band-Default im Code: LTE B8 (900 MHz). Vollständige Bandliste: [zu bestätigen: Modulzertifikat / Hardware-Dokumentation] |
| Maximale Sendeleistung | typ. 20 dBm (100 mW) EIRP — Power Class 5 [zu bestätigen: Bestätigung mit Antenne] |
| Modulation | gemäß 3GPP TS 36.211 (BPSK / QPSK / 16-QAM) |
| Kanalbandbreite | 1,4 MHz (LTE-M); 200 kHz (NB-IoT, Fallback) |
| Antenne | Externe LTE-M-/NB-IoT-Antenne [zu bestätigen: Anschlusstyp]. Nur die mitgelieferte oder ausdrücklich vom Hersteller zugelassene Antenne verwenden. |
Für den Betrieb innerhalb der EU/EWR-Mitgliedstaaten und der Schweiz bestehen keine länderspezifischen Einschränkungen. Die Funkanlage nutzt ausschließlich vom Mobilfunknetz zugewiesene Frequenzen.
Detailliert siehe Hardware-Quickstart; hier konsolidierte Übersicht.
| Mikrocontroller | Silicon Labs EFR32MG26 (ARM Cortex-M33 + Secure Vault), HW-ID EFR32MG26-HW2 |
|---|---|
| Versorgungsspannung | SELV/PELV, DC [zu bestätigen: Eingangsbereich] |
| Eingangsstrom / Sicherung | [zu bestätigen] |
| Schutzklasse | III (SELV) |
| Schutzschaltungen | [zu bestätigen] |
| Bus-Isolation | [zu bestätigen: CAN-Bus-Terminierung/Isolation] |
| RTC | PCF85363, batteriegepuffert (Zelltyp [zu bestätigen]) |
| Abmessungen | [zu bestätigen] |
| Gewicht | [zu bestätigen] |
| Schutzart | IP54 |
| Betriebs-/Lagertemperatur | [zu bestätigen] |
| Luftfeuchte | [zu bestätigen], nicht kondensierend |
| EMV-Klasse | A (industriell) |
| Feldbus | CANopen (Classic CAN 2.0) über externen MCP2518FD-SPI-Controller |
| Funk | LTE-M (Cat-M1) / NB-IoT-Fallback, Quectel BG77, Coldwave-managed eSIM (aufgelötet) |
| Sicherheit (SW) | Secure Boot, signierte OTA-Updates (ECDSA-P256), TLS 1.2/1.3, PSA-Keystore |
| Mini-SPS | Coldwave Script-VM (coldwave-script-vm) |
| Symptom | Mögliche Ursache | Maßnahme |
|---|---|---|
| Power-/Status-LED aus | keine Versorgung / verpolter Anschluss | DC-Versorgung prüfen (SELV/PELV), Polarität, Sicherung im vorgelagerten Stromkreis. |
| Netzwerk-LED bleibt blinkend/rot | kein LTE-M-/NB-IoT-Empfang am Standort | Antennensitz prüfen; Aufstellort wechseln; Schaltschrank ggf. mit externer Antenne ausstatten (Servicekontakt). |
| Gerät bleibt im Portal „offline" | Geräte-Zuordnung nicht abgeschlossen / Datenkontingent erschöpft | Zuordnung beim Anlagen-Hersteller prüfen; Datenkontingent im Portal einsehen (§17). |
| CAN-Bus-LED rot | Bus-Fehler / Bus-off / kein gültiger Frame | Verdrahtung, Terminierung (120 Ω an beiden Enden), Bitrate und Node-ID im Portal prüfen. |
| CAN-Bus aktiv, aber keine Daten im Portal | Mapping unvollständig oder falsche Objekte/Adressen | Mapping im Editor öffnen, Objekte/Indizes prüfen. |
| Gerät rebootet zyklisch | Versorgung unter Mindestschwelle, Pufferung erschöpft | Versorgung auf ausreichende Strombelastbarkeit prüfen; ggf. Servicekontakt. |
| Update bricht ab / kein Update verfügbar | geringer Empfang, Datenkontingent erschöpft | Empfang verbessern; Update zu späterem Zeitpunkt erneut anstoßen (Portal). |
| Anliegen | Kontakt |
|---|---|
| Allgemeiner Support | support@coldwave.io |
| Konformitätsanfragen / EU-Konformitätserklärung (DoC) | compliance@imagineon.de |
| Sicherheits-/Schwachstellen-Meldung (PSIRT / CVD) | security@coldwave.io |
Bitte melden Sie vermutete Schwachstellen nicht über öffentliche GitHub-Issues. Sicherheitsmeldungen werden binnen 2 Arbeitstagen bestätigt und koordiniert offengelegt (Coordinated Vulnerability Disclosure). Verschlüsselte Meldung per PGP; der Fingerprint wird unter https://coldwave.io/.well-known/security.txt veröffentlicht (Web-Formular geplant: https://coldwave.io/security/report). Bei einer aktiv ausgenutzten Schwachstelle bitte den Betreff mit [ACTIVE EXPLOIT] kennzeichnen. Erkenntnisse über Schwachstellen fließen in ein nächstes signiertes OTA-Update; betroffene ältere Versionen werden über den Anti-Rollback-Mechanismus gesperrt. ImagineOn stellt sicherheitsrelevante Updates 10 Jahre ab Inverkehrbringen bereit.
Die Firmware des Yukiblock CAN nutzt Open-Source- und vendored-Komponenten (u. a. mbedTLS, FreeRTOS, MCUboot, CANopenNode, MCP2518FD-Treiber, coldwave-script-vm). Die vollständige Liste samt Lizenztexten und Quellhinweisen ist in der Produkt-LICENSE.md aufgeführt; die ImagineOn-Lizenzbedingungen finden Sie unter www.imagineon.de/de/info/licensing-terms. Für jede ausgelieferte Firmware-Version wird zudem eine CycloneDX-SBOM geführt und auf Anfrage bereitgestellt.
| APN | Access Point Name — Einwahlpunkt im Mobilfunknetz |
| Bus-off | CAN-Fehlerzustand, in den ein Knoten bei zu vielen Sendefehlern übergeht |
| CANopen | Höheres Kommunikationsprotokoll (CiA 301) auf Basis von Classic CAN 2.0 |
| Classic CAN 2.0 | Controller Area Network, klassischer Frame (kein CAN FD) |
| COB-ID | Communication Object Identifier — Kennung eines CANopen-Kommunikationsobjekts |
| CVD | Coordinated Vulnerability Disclosure — koordinierte Schwachstellenoffenlegung |
| DoC | Declaration of Conformity — EU-Konformitätserklärung |
| EIRP | Equivalent Isotropically Radiated Power — abgestrahlte Sendeleistung |
| EMCY | Emergency Object — CANopen-Notfall-/Fehlermeldung |
| eSIM | fest verlötete SIM (Embedded SIM) |
| IMEI | International Mobile Equipment Identity — eindeutige Modul-Kennung |
| LTE-M / Cat-M1 | Low-Power-WAN-Variante des LTE-Mobilfunks für IoT |
| MCU | Mikrocontroller |
| MCUboot | Sicherer Bootloader mit Image-Signaturprüfung |
| NB-IoT | Narrowband IoT — Schmalband-LPWAN-Mobilfunk (Fallback) |
| NMT | Network Management — CANopen-Zustandssteuerung der Knoten |
| OD | Object Dictionary — CANopen-Objektverzeichnis |
| OTA | Over-the-Air (Update über Mobilfunk) |
| PDO | Process Data Object — zyklische CANopen-Prozessdaten |
| PSA Crypto | Platform Security Architecture — Schlüsselablage und Krypto-API |
| RED | Radio Equipment Directive 2014/53/EU |
| RTC | Real-Time Clock — batteriegepufferte Echtzeituhr |
| SDO | Service Data Object — azyklischer CANopen-Objektzugriff |
| Secure Boot | Signaturgeprüfter, vertrauenswürdiger Startvorgang |
| SELV / PELV | Schutzkleinspannung |
| TLS | Transport Layer Security — verschlüsselte Transportverbindung |
| Version | Datum | Änderung |
|---|---|---|
| 1.0 | 2026 | Erstausgabe |
© 2026 ImagineOn GmbH. Alle Rechte vorbehalten. Die vorliegende Bedienungsanleitung darf ohne ausdrückliche Genehmigung der ImagineOn GmbH nicht vervielfältigt oder Dritten zugänglich gemacht werden, ausgenommen die Weitergabe an den Endkunden im Rahmen der Lieferkette des Produkts Coldwave Yukiblock CAN.
This user manual describes the correct operation of the Coldwave Yukiblock CAN industrial IoT gateway from ImagineOn GmbH. It is intended for integrators and plant manufacturers (qualified electrical personnel), plant operators (asset owners) and service personnel.
It forms part of the documentation required under Annex V of EU Radio Equipment Directive 2014/53/EU (RED) and must remain available at the operator's premises throughout the entire service life of the device. A companion description of the security architecture is provided in the Coldwave Yukiblock CAN Security Whitepaper.
ImagineOn GmbH
Neusser Str. 27–29
50670 Cologne, Germany
Contact: support@coldwave.io · www.imagineon.de
The device carries the CE marking on its type plate. Applicable EU acts:
Considered on a preparatory basis: EU Cyber Resilience Act (Regulation (EU) 2024/2847, fully applicable from 2027-12-11, reporting obligations from 2026-09-11).
| Area | Standard |
|---|---|
| Safety | EN 62368-1 |
| EMC | EN 301 489-1, EN 301 489-17, EN 301 489-52 |
| Radio (LTE-M / NB-IoT) | EN 301 908-1, EN 301 908-13 |
| RF exposure | EN 50665 |
| Cybersecurity | EN 18031-1:2024 (self-assessment, Module A) |
| Forward-looking | ETSI EN 303 645 (baseline requirements for consumer IoT) |
Note: The hardware platform (EFR32MG26) includes a Bluetooth-LE radio component which is disabled by firmware on the shipped CAN/LTE-M variant. EN 300 328 is therefore not listed as an applicable standard for this variant; where it appears on the leaflet it represents a platform-level provision for future variants.
The Coldwave Yukiblock CAN is a stationary industrial IoT gateway that captures the data points of a CANopen field bus (Classic CAN 2.0, via an external MCP2518FD SPI controller) — e.g. flow temperatures, pump speeds, operating hours from heating, ventilation and air-conditioning plants or from compact industrial units — and forwards them, encrypted, to the Coldwave backend over cellular (LTE-M / NB-IoT). The device operates exclusively as a CANopen slave and is designed not to destabilise the bus.
Typical use cases:
The type plate (back / side of the housing) shows:
Yukiblock CAN, product ID YCA2)EFR32MG26-HW2)The output power of the integrated LTE-M radio module (Quectel BG77, typically 20 dBm = 100 mW / Power Class 5) is well below the limits of EN 50665. With the intended installation (control-cabinet / wall mounting) and a minimum distance of 20 cm from any area regularly occupied by persons, the limits are safely respected.
| Symbol | Meaning |
|---|---|
| CE | Conformity with the applicable EU acts |
| Crossed-out wheelie bin | Do not dispose of with household waste — see §22 |
| SELV symbol (III) | Protection class III, supply from a SELV/PELV source |
| QR "EU declaration of conformity" | DoC available online |
| QR "Online user manual" | This manual, latest revision |
The following operating, indicator and connection elements are illustrated on the hardware quick-start. Refer to the leaflet for the exact mechanical arrangement and labelling.
| Element | Function |
|---|---|
| Reset / service opening | Recessed pushbutton for soft-reset / backend re-attach (§15) |
| Power / status LED | DC supply present / buffered operation from the internal supercap (§14) |
| Network LED | Cellular and Coldwave backend status (§14) |
| CAN bus LED | CANopen bus status (§14) |
| Power supply connector | Pluggable, DC (SELV/PELV) [to be confirmed: pinout] |
| CAN connector | CANopen (Classic CAN 2.0), differential two-wire bus (§7) [to be confirmed: pinout/termination] |
| Antenna connector | External LTE-M / NB-IoT antenna [to be confirmed: connector type] |
At the core of the device is the Silicon Labs EFR32MG26 microcontroller (ARM Cortex-M33 with Secure Vault). The CAN connection is provided by an external MCP2518FD SPI controller (Classic CAN 2.0). At start-up the device runs an internal loopback self-test of the CAN controller.
The field-bus connection is a CANopen bus per Classic CAN 2.0: a differential two-wire bus (CAN-High / CAN-Low) with a common reference ground. Refer to the hardware quick-start for the exact connector pinout and for the termination and isolation implementation [to be confirmed].
The device operates exclusively as a CANopen slave. It listens on the bus, decodes SDO/PDO/NMT/EMCY/Heartbeat frames from the connected nodes and mirrors the mapping-selected object values to the Coldwave backend. The SDO server is reachable on the bus (CANopenNode default), but the SDO server parameter object 0x1200 is read-only on the bus and there are no remote-writable application OD parameters — so no persistent configuration change is possible over the CANopen bus.
Bit rate, node ID and CAN activation are set in the Coldwave portal (see §10). The device features bus-off detection with controlled recovery (backoff), so that it does not destabilise the bus through repeated restarts in a fault condition.
The detailed mounting sequence (fixing, antenna mounting, wiring, removal) is illustrated in the hardware quick-start. This manual does not repeat it.
The Yukiblock CAN ships with a soldered, Coldwave-managed eSIM; no separate cellular contract is required (see §17 for details). The device is bound to the Coldwave backend on the backend side via its IMEI.
After successful binding, the installation-specific configuration is rolled out via the portal:
During normal operation the device runs fully autonomously. It reads the CANopen object values defined in the mapping from the bus, aggregates them and forwards them to the Coldwave backend on a budget-governed cycle (default telemetry tick approx. 5 min, governed by the data budget). Status and diagnostic values are reported alongside:
The exact names of these values and of the editable parameters can be found in the Coldwave portal. All editable settings are configured through the portal and persisted on the device. There is no local configuration interface (no web UI, no USB config, no configuration button).
The translation between CANopen objects / data points and the cloud data points is performed via a mapping managed in the Coldwave portal and delivered from the backend to the device. The mapping table is the only trust boundary that writes from the backend into persistent on-device configuration; it is strictly validated on deserialization.
The Yukiblock CAN contains an embedded PLC-style script VM (coldwave-script-vm) for simple logic, filtering and pre-processing directly on the device. Typical use cases:
The script VM runs in a memory-capped sandbox without direct hardware / raw-IO access. Scripts are uploaded signed via the cloud by the plant manufacturer only, not by the operator. Activation, script upload and status reporting (running / error code / memory usage) are all performed through the Coldwave portal. The full script reference with examples is available at https://doc.coldwave.io/script/v1/.
Firmware updates are delivered over the air through the cellular link. The procedure is fully automated:
The device has three indicator functions: a power / status LED, a network LED (cellular + backend) and a CAN bus LED. The exact colour and blink codes are documented on the hardware quick-start; the overview below describes the function. Deviations may occur during ongoing updates or maintenance windows.
Indicates the presence of the DC supply and buffered operation via the internal supercap. On a supply loss the supercap briefly bridges the gap and allows a controlled shutdown (backend sync, modem disconnect); when the supply returns the device restarts automatically. Refer to the quick-start for the exact coding [to be confirmed].
| LED state | Meaning |
|---|---|
| green, solid | Online with the Coldwave backend — normal state |
| blinking | Connecting: cellular attach or backend registration in progress |
| red | No cellular network / no backend connection (boot, network search, no coverage) |
| off | Modem disabled (e.g. energy-saving after a power loss; reactivates on restart) |
Exact colour / blink codes (incl. the weak-signal threshold) see the hardware quick-start [to be confirmed].
| LED state | Meaning |
|---|---|
| green | CANopen bus active; nodes respond, no errors |
| red | Bus error / bus-off or no valid frames for several seconds (check wiring, bit rate, termination) |
| off | CAN operation not activated or empty mapping |
The service button is recessed and is operated with a thin pin. Its exact function is documented in the hardware quick-start [to be confirmed]; typically a short press triggers a soft reset (re-establishing the backend connection, with configuration / mappings / script preserved).
The Yukiblock CAN is assessed as an "internet-connected radio equipment" under EN 18031-1 (self-assessment). It is designed as a "black-box" device: there is no operator configuration, no web portal, no SSH/Telnet console and no USB configuration port — the security configuration is hard-wired into the firmware image.
ImagineOn provides security-relevant firmware updates for this product for at least 10 years from first placing on the market. The end of security-update provision per hardware revision is documented in the CHANGELOG.md and the Coldwave Cloud portal.
The device contains a soldered, Coldwave-managed eSIM. The operator does not need to take out a separate cellular contract and does not need to insert a SIM card. The cellular module (Quectel BG77) is soldered to the board.
The monthly data quota is defined at the time of purchase; Coldwave offers several tariff options. The device continuously monitors data usage and adapts the synchronisation interval so that the budget is respected (hard cap). The remaining budget for the current month is displayed among the device's diagnostic values in the Coldwave portal.
Operation requires sufficient LTE-M / NB-IoT coverage at the installation site. The device uses a private Coldwave APN on the Deutsche Telekom network. Up-to-date status and coverage notes can be found in the Coldwave portal (https://app.coldwave.io).
The device performs periodic reconnect attempts with backoff; the connectivity supervisor keeps the local bus operation running. After at most three consecutive failed re-resets, the device performs a controlled modem reset followed by a self-reboot. While offline, no telemetry and no updates are transmitted; both resume on the next successful connection.
In normal operation the device is maintenance-free. The only exception is the RTC backup battery.
| Type | Lithium coin cell [to be confirmed: cell type from hardware documentation] |
|---|---|
| Function | Backs up the real-time clock (PCF85363) and battery-backed RAM slots during longer power-off periods. |
| Typical service life | [to be confirmed] (the battery is only used during power outages) |
| Replacement | Authorised service personnel only (housing must be opened). Please do not open the housing yourself. |
| Radio service | LTE-M (3GPP Cat-M1, eMTC, Rel. 13) / NB-IoT fallback |
|---|---|
| Radio module | Quectel BG77 (pre-certified) |
| Supported bands | Band default in code: LTE B8 (900 MHz). Full band list: [to be confirmed: module certificate / hardware documentation] |
| Maximum output power | typ. 20 dBm (100 mW) EIRP — Power Class 5 [to be confirmed: confirmation with antenna] |
| Modulation | per 3GPP TS 36.211 (BPSK / QPSK / 16-QAM) |
| Channel bandwidth | 1.4 MHz (LTE-M); 200 kHz (NB-IoT, fallback) |
| Antenna | External LTE-M / NB-IoT antenna [to be confirmed: connector type]. Only use the supplied antenna or one expressly approved by the manufacturer. |
For operation within the EU/EEA Member States and Switzerland, no country-specific restrictions apply. The radio equipment uses exclusively frequencies assigned by the cellular network.
For full details see the hardware quick-start; consolidated overview here.
| Microcontroller | Silicon Labs EFR32MG26 (ARM Cortex-M33 + Secure Vault), HW ID EFR32MG26-HW2 |
|---|---|
| Supply voltage | SELV/PELV, DC [to be confirmed: input range] |
| Input current / fuse | [to be confirmed] |
| Protection class | III (SELV) |
| Protection circuits | [to be confirmed] |
| Bus isolation | [to be confirmed: CAN bus termination/isolation] |
| RTC | PCF85363, battery-backed (cell type [to be confirmed]) |
| Dimensions | [to be confirmed] |
| Weight | [to be confirmed] |
| Ingress protection | IP54 |
| Operating / storage temperature | [to be confirmed] |
| Humidity | [to be confirmed], non-condensing |
| EMC class | A (industrial) |
| Field bus | CANopen (Classic CAN 2.0) via external MCP2518FD SPI controller |
| Radio | LTE-M (Cat-M1) / NB-IoT fallback, Quectel BG77, Coldwave-managed eSIM (soldered) |
| Security (SW) | Secure Boot, signed OTA updates (ECDSA-P256), TLS 1.2/1.3, PSA keystore |
| Mini-PLC | Coldwave Script-VM (coldwave-script-vm) |
| Symptom | Possible cause | Action |
|---|---|---|
| Power / status LED off | no supply / reverse polarity | Check the DC supply (SELV/PELV), polarity, upstream fuse. |
| Network LED stays blinking/red | no LTE-M / NB-IoT coverage at the site | Check antenna seating; change installation site; consider an external antenna for cabinet installation (contact support). |
| Device stays "offline" in the portal | device binding not completed / data quota exhausted | Check the binding with the plant manufacturer; check the data quota (§17). |
| CAN bus LED red | bus error / bus-off / no valid frame | Check wiring, termination (120 Ω at both ends), bit rate and node ID in the portal. |
| CAN bus active but no data in the portal | mapping incomplete or wrong objects/addresses | Open the mapping editor, check objects/indices. |
| Device reboots cyclically | supply below threshold, buffer exhausted | Check that the supply provides sufficient current; contact service if needed. |
| Update aborts / no update available | poor signal, data quota exhausted | Improve reception; retry the update later (via the portal). |
| Matter | Contact |
|---|---|
| General support | support@coldwave.io |
| Conformity / EU declaration of conformity (DoC) | compliance@imagineon.de |
| Security / vulnerability report (PSIRT / CVD) | security@coldwave.io |
Please do not report suspected vulnerabilities via public GitHub issues. Security reports are acknowledged within 2 business days and disclosed in a coordinated manner (Coordinated Vulnerability Disclosure). Encrypted reporting via PGP; the fingerprint is published at https://coldwave.io/.well-known/security.txt (web form planned: https://coldwave.io/security/report). For an actively exploited vulnerability, please flag the subject with [ACTIVE EXPLOIT]. Findings feed into a subsequent signed OTA update; affected older versions are blocked through the anti-rollback mechanism. ImagineOn provides security-relevant updates for 10 years from first placing on the market.
The Yukiblock CAN firmware uses open-source and vendored components (incl. mbedTLS, FreeRTOS, MCUboot, CANopenNode, MCP2518FD driver, coldwave-script-vm). The complete list together with the corresponding license texts and source references is provided in the product LICENSE.md; the ImagineOn licensing terms are available at www.imagineon.de/de/info/licensing-terms. A CycloneDX SBOM is also maintained for every shipped firmware version and provided on request.
| APN | Access Point Name — entry point in the cellular network |
| Bus-off | CAN error state a node enters after too many transmit errors |
| CANopen | Higher-layer communication protocol (CiA 301) on top of Classic CAN 2.0 |
| Classic CAN 2.0 | Controller Area Network, classic frame (not CAN FD) |
| COB-ID | Communication Object Identifier — identifier of a CANopen communication object |
| CVD | Coordinated Vulnerability Disclosure |
| DoC | Declaration of Conformity — EU declaration of conformity |
| EIRP | Equivalent Isotropically Radiated Power |
| EMCY | Emergency Object — CANopen emergency / error message |
| eSIM | soldered SIM (Embedded SIM) |
| IMEI | International Mobile Equipment Identity — unique module identifier |
| LTE-M / Cat-M1 | Low-Power-WAN variant of LTE cellular for IoT |
| MCU | Microcontroller |
| MCUboot | Secure bootloader with image signature verification |
| NB-IoT | Narrowband IoT — narrowband LPWAN cellular (fallback) |
| NMT | Network Management — CANopen node state control |
| OD | Object Dictionary — CANopen object dictionary |
| OTA | Over-the-Air (update via cellular) |
| PDO | Process Data Object — cyclic CANopen process data |
| PSA Crypto | Platform Security Architecture — key storage and crypto API |
| RED | Radio Equipment Directive 2014/53/EU |
| RTC | Real-Time Clock — battery-backed real-time clock |
| SDO | Service Data Object — acyclic CANopen object access |
| Secure Boot | Signature-verified, trusted boot process |
| SELV / PELV | Safety / protective extra-low voltage |
| TLS | Transport Layer Security — encrypted transport connection |
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026 | First issue |
© 2026 ImagineOn GmbH. All rights reserved. This user manual may not be reproduced or made available to third parties without the express consent of ImagineOn GmbH, except for distribution to end customers within the supply chain of the Coldwave Yukiblock CAN product.
Le présent manuel d'utilisation décrit l'exploitation correcte de la passerelle IoT industrielle Coldwave Yukiblock CAN d'ImagineOn GmbH. Il s'adresse aux intégrateurs et fabricants d'installations (personnel électrotechnique qualifié), aux exploitants (propriétaires d'actifs) et au personnel de service.
Il fait partie de la documentation requise au titre de l'annexe V de la directive européenne 2014/53/UE relative aux équipements radioélectriques (RED) et doit rester accessible chez l'exploitant pendant toute la durée de vie de l'appareil. Une description complémentaire de l'architecture de sécurité figure dans le livre blanc de sécurité du Coldwave Yukiblock CAN.
ImagineOn GmbH
Neusser Str. 27–29
50670 Cologne, Allemagne
Contact : support@coldwave.io · www.imagineon.de
L'appareil porte le marquage CE sur la plaque signalétique. Actes UE applicables :
Pris en compte à titre préparatoire : règlement européen sur la cyber-résilience (règlement (UE) 2024/2847, pleinement applicable à compter du 2027-12-11, obligations de signalement à compter du 2026-09-11).
| Domaine | Norme |
|---|---|
| Sécurité | EN 62368-1 |
| CEM | EN 301 489-1, EN 301 489-17, EN 301 489-52 |
| Radio (LTE-M / NB-IoT) | EN 301 908-1, EN 301 908-13 |
| Exposition RF | EN 50665 |
| Cybersécurité | EN 18031-1:2024 (auto-évaluation, module A) |
| Appliquée de manière prospective | ETSI EN 303 645 (exigences de base pour l'IoT grand public) |
Remarque : la plateforme matérielle (EFR32MG26) comprend un composant radio Bluetooth-LE qui est désactivé par le micrologiciel sur la variante CAN/LTE-M livrée. EN 300 328 n'est donc pas listée comme norme applicable pour cette variante ; si elle figure sur le feuillet, il s'agit d'une réserve liée à la plateforme pour de futures variantes.
Le Coldwave Yukiblock CAN est une passerelle IoT industrielle fixe qui acquiert les points de données d'un bus de terrain CANopen (Classic CAN 2.0, via un contrôleur SPI MCP2518FD externe) — p. ex. températures de départ, vitesses de pompes, heures de fonctionnement d'installations de chauffage, ventilation et climatisation ou d'agrégats industriels compacts — et les transmet, chiffrées, au backend Coldwave via une liaison cellulaire (LTE-M / NB-IoT). L'appareil fonctionne exclusivement comme esclave CANopen et est conçu pour ne pas déstabiliser le bus.
Cas d'usage typiques :
La plaque signalétique (face arrière / latérale du boîtier) indique :
Yukiblock CAN, ID produit YCA2)EFR32MG26-HW2)La puissance d'émission du module radio LTE-M intégré (Quectel BG77, typiquement 20 dBm = 100 mW / Power Class 5) est bien inférieure aux limites de l'EN 50665. Avec un montage conforme (armoire / mur) et une distance minimale de 20 cm à toute zone de séjour des personnes, les limites sont respectées en toute sécurité.
| Symbole | Signification |
|---|---|
| CE | Conformité aux actes UE applicables |
| Poubelle barrée | Ne pas jeter avec les ordures ménagères — voir §22 |
| Symbole SELV (III) | Classe de protection III, alimentation par source SELV/PELV |
| QR « déclaration UE de conformité » | DoC disponible en ligne |
| QR « manuel d'utilisation en ligne » | Le présent manuel, dernière édition |
Les éléments de commande, de signalisation et de raccordement suivants sont illustrés sur le guide rapide matériel. Reportez-vous au feuillet pour l'agencement mécanique et le repérage exacts.
| Élément | Fonction |
|---|---|
| Orifice de reset / service | Bouton encastré pour soft-reset / ré-attachement backend (§15) |
| LED d'alimentation / d'état | Alimentation DC présente / fonctionnement tamponné sur supercondensateur interne (§14) |
| LED réseau | État cellulaire et backend Coldwave (§14) |
| LED bus CAN | État du bus CANopen (§14) |
| Connecteur d'alimentation | Débrochable, DC (SELV/PELV) [à confirmer : brochage] |
| Connecteur CAN | CANopen (Classic CAN 2.0), bus différentiel deux fils (§7) [à confirmer : brochage/terminaison] |
| Raccord d'antenne | Antenne LTE-M / NB-IoT externe [à confirmer : type de raccord] |
Le cœur de l'appareil est le microcontrôleur Silicon Labs EFR32MG26 (ARM Cortex-M33 avec Secure Vault). Le raccordement CAN est assuré par un contrôleur SPI MCP2518FD externe (Classic CAN 2.0). Au démarrage, l'appareil exécute un auto-test interne en boucle (loopback) du contrôleur CAN.
Le raccordement au bus de terrain est un bus CANopen selon Classic CAN 2.0 : un bus différentiel deux fils (CAN-High / CAN-Low) avec une masse de référence commune. Reportez-vous au guide rapide matériel pour le brochage exact du connecteur ainsi que pour la réalisation de la terminaison et de l'isolement [à confirmer].
L'appareil fonctionne exclusivement comme esclave CANopen. Il écoute le bus, décode les trames SDO/PDO/NMT/EMCY/Heartbeat des nœuds raccordés et reflète les valeurs d'objets sélectionnées par le mappage vers le backend Coldwave. Le serveur SDO est accessible sur le bus (défaut CANopenNode), mais l'objet paramètre du serveur SDO 0x1200 est en lecture seule côté bus et il n'existe aucun paramètre OD applicatif inscriptible à distance — aucune modification de configuration persistante n'est donc possible via le bus CANopen.
Le débit, le node-ID et l'activation CAN se définissent dans le portail Coldwave (voir §10). L'appareil dispose d'une détection bus-off avec reprise contrôlée (backoff), de sorte qu'il ne déstabilise pas le bus par des redémarrages répétés en cas de défaut.
La séquence de montage détaillée (fixation, montage de l'antenne, câblage, dépose) est illustrée dans le guide rapide matériel. Le présent manuel ne la répète pas.
Le Yukiblock CAN est livré avec une eSIM soudée, gérée par Coldwave ; aucun contrat cellulaire séparé n'est requis (voir §17 pour les détails). L'appareil est rattaché au backend Coldwave côté backend via son IMEI.
Après rattachement réussi, la configuration spécifique à l'installation est déployée via le portail :
En exploitation normale, l'appareil fonctionne de manière entièrement autonome. Il lit les valeurs d'objets CANopen définies dans le mappage depuis le bus, les agrège et les transmet au backend Coldwave à une cadence pilotée par le budget (cadence de télémétrie par défaut env. 5 min, ajustée au budget de données). Les valeurs d'état et de diagnostic sont jointes :
Les libellés exacts de ces valeurs et des paramètres modifiables figurent dans le portail Coldwave. Toutes les valeurs de configuration modifiables sont définies via le portail et conservées de manière persistante sur l'appareil. Il n'existe aucune interface de configuration locale (pas d'interface web, pas de configuration USB, pas de bouton de configuration).
La conversion entre objets / points de données CANopen et points de données dans le cloud s'effectue via un mappage géré dans le portail Coldwave et livré du backend vers l'appareil. La table de mappage est la seule frontière de confiance qui écrit depuis le backend dans la configuration persistante embarquée ; elle est strictement validée lors de la désérialisation.
Le Yukiblock CAN intègre une Script-VM embarquée de type API (coldwave-script-vm) pour la logique simple, le filtrage et le prétraitement directement à bord. Cas d'usage typiques :
La Script-VM s'exécute dans un bac à sable à mémoire limitée, sans accès matériel / raw-IO direct. Les scripts sont téléversés signés via le cloud par le fabricant d'installation uniquement, non par l'exploitant. L'activation, le téléversement du script et la visualisation d'état (en cours d'exécution / code d'erreur / mémoire utilisée) s'effectuent entièrement via le portail Coldwave. La référence complète du script et des exemples sont disponibles à l'adresse https://doc.coldwave.io/script/v1/.
Les mises à jour sont fournies par voie hertzienne via la liaison cellulaire. Le déroulement est entièrement automatisé :
L'appareil possède trois fonctions de signalisation : une LED d'alimentation / d'état, une LED réseau (cellulaire + backend) et une LED bus CAN. Les codes exacts de couleur et de clignotement sont documentés sur le guide rapide matériel ; l'aperçu ci-dessous en décrit la fonction. Des écarts sont possibles pendant les mises à jour ou les fenêtres de maintenance.
Indique la présence de l'alimentation DC et le fonctionnement tamponné sur le supercondensateur interne. En cas de perte d'alimentation, le supercondensateur assure brièvement le relais et permet un arrêt contrôlé (synchronisation backend, déconnexion du modem) ; au retour de l'alimentation, l'appareil redémarre automatiquement. Reportez-vous au guide rapide pour le codage exact [à confirmer].
| État LED | Signification |
|---|---|
| vert, fixe | En ligne avec le backend Coldwave — état normal |
| clignotant | Connexion en cours : attachement cellulaire ou enregistrement backend |
| rouge | Aucun réseau cellulaire / aucune connexion backend (démarrage, recherche de réseau, hors couverture) |
| éteinte | Modem désactivé (p. ex. économie d'énergie après une coupure ; réactivation au redémarrage) |
Codes exacts de couleur / clignotement (y compris le seuil de signal faible) : voir le guide rapide matériel [à confirmer].
| État LED | Signification |
|---|---|
| vert | Bus CANopen actif ; les nœuds répondent, aucune erreur |
| rouge | Erreur de bus / bus-off ou aucune trame valide pendant plusieurs secondes (vérifier câblage, débit, terminaison) |
| éteinte | Fonctionnement CAN non activé ou mappage vide |
Le bouton de service est encastré et s'actionne avec une pointe fine. Sa fonction exacte est documentée dans le guide rapide matériel [à confirmer] ; typiquement, un appui court déclenche un soft-reset (rétablissement de la connexion backend, la configuration / les mappages / le script étant conservés).
Le Yukiblock CAN est évalué selon EN 18031-1 (auto-évaluation) en tant qu'« équipement radio connecté à Internet ». Il est conçu comme un appareil « boîte noire » : il n'y a pas de configuration exploitant, pas de portail web, pas de console SSH/Telnet et pas de port de configuration USB — la configuration de sécurité est câblée en dur dans l'image du micrologiciel.
ImagineOn fournit pour ce produit des mises à jour de sécurité pendant au moins 10 ans à compter de la première mise sur le marché. La fin de la fourniture de mises à jour de sécurité par révision matérielle est documentée dans le CHANGELOG.md et le portail Coldwave Cloud.
L'appareil contient une eSIM soudée, gérée par Coldwave. L'exploitant n'a pas besoin de souscrire un contrat cellulaire séparé ni d'insérer une carte SIM. Le module cellulaire (Quectel BG77) est soudé sur la carte.
Le quota mensuel de données est défini à l'achat ; Coldwave propose plusieurs options tarifaires. L'appareil surveille en continu la consommation et adapte l'intervalle de synchronisation pour respecter le budget (plafond strict). Le budget restant du mois en cours est affiché parmi les valeurs de diagnostic de l'appareil dans le portail Coldwave.
L'exploitation suppose une couverture LTE-M / NB-IoT suffisante sur le site. L'appareil utilise une APN Coldwave privée sur le réseau de Deutsche Telekom. Pour l'état actuel et les indications de couverture, consultez le portail Coldwave (https://app.coldwave.io).
L'appareil effectue des tentatives de reconnexion périodiques avec back-off ; le superviseur de connectivité maintient l'exploitation locale du bus. Après au plus trois ré-initialisations infructueuses consécutives, l'appareil effectue un reset contrôlé du modem puis un redémarrage. Hors ligne, aucune télémétrie ni mise à jour n'est transmise ; les deux reprennent à la prochaine connexion réussie.
En exploitation normale, l'appareil ne nécessite aucun entretien, à l'exception de la pile de sauvegarde RTC.
| Type | Pile bouton lithium [à confirmer : type de pile d'après la documentation matérielle] |
|---|---|
| Fonction | Sauvegarde l'horloge temps réel (PCF85363) et des emplacements RAM à batterie pendant les coupures prolongées. |
| Durée de vie typique | [à confirmer] (la pile n'est sollicitée que lors des coupures) |
| Remplacement | Uniquement par un service autorisé (ouverture du boîtier). Ne pas ouvrir vous-même. |
| Service radio | LTE-M (3GPP Cat-M1, eMTC, Rel. 13) / repli NB-IoT |
|---|---|
| Module radio | Quectel BG77 (pré-certifié) |
| Bandes supportées | Bande par défaut dans le code : LTE B8 (900 MHz). Liste complète des bandes : [à confirmer : certificat de module / documentation matérielle] |
| Puissance d'émission max. | typ. 20 dBm (100 mW) PIRE — Power Class 5 [à confirmer : confirmation avec antenne] |
| Modulation | selon 3GPP TS 36.211 (BPSK / QPSK / 16-QAM) |
| Largeur de canal | 1,4 MHz (LTE-M) ; 200 kHz (NB-IoT, repli) |
| Antenne | Antenne LTE-M / NB-IoT externe [à confirmer : type de raccord]. N'utiliser que l'antenne fournie ou expressément autorisée par le fabricant. |
Pour l'exploitation au sein des États membres de l'UE/EEE et de la Suisse, aucune restriction nationale ne s'applique. L'équipement radio n'utilise que les fréquences attribuées par le réseau cellulaire.
Détails dans le guide rapide matériel ; ici le récapitulatif consolidé.
| Microcontrôleur | Silicon Labs EFR32MG26 (ARM Cortex-M33 + Secure Vault), ID matériel EFR32MG26-HW2 |
|---|---|
| Tension d'alimentation | SELV/PELV, DC [à confirmer : plage d'entrée] |
| Courant d'entrée / fusible | [à confirmer] |
| Classe de protection | III (SELV) |
| Protections | [à confirmer] |
| Isolement du bus | [à confirmer : terminaison/isolement du bus CAN] |
| RTC | PCF85363, sauvegardée par pile (type de pile [à confirmer]) |
| Dimensions | [à confirmer] |
| Poids | [à confirmer] |
| Indice de protection | IP54 |
| Température de service / stockage | [à confirmer] |
| Humidité | [à confirmer], sans condensation |
| Classe CEM | A (industriel) |
| Bus de terrain | CANopen (Classic CAN 2.0) via contrôleur SPI MCP2518FD externe |
| Radio | LTE-M (Cat-M1) / repli NB-IoT, Quectel BG77, eSIM gérée par Coldwave (soudée) |
| Sécurité (logiciel) | Secure Boot, mises à jour OTA signées (ECDSA-P256), TLS 1.2/1.3, keystore PSA |
| Mini-API | Script-VM Coldwave (coldwave-script-vm) |
| Symptôme | Cause possible | Action |
|---|---|---|
| LED d'alimentation / d'état éteinte | absence d'alimentation / polarité inversée | Vérifier l'alimentation DC (SELV/PELV), la polarité, le fusible amont. |
| LED réseau reste clignotante/rouge | pas de couverture LTE-M / NB-IoT sur site | Vérifier le serrage de l'antenne ; changer de lieu ; envisager une antenne déportée pour les armoires (contacter le service). |
| Appareil reste « hors ligne » dans le portail | rattachement non finalisé / quota épuisé | Vérifier le rattachement auprès du fabricant d'installation ; consulter le quota (§17). |
| LED bus CAN rouge | erreur de bus / bus-off / aucune trame valide | Vérifier le câblage, la terminaison (120 Ω aux deux extrémités), le débit et le node-ID dans le portail. |
| Bus CAN actif mais pas de données dans le portail | mappage incomplet ou objets/adresses erronés | Ouvrir l'éditeur de mappage, vérifier les objets/index. |
| Redémarrages cycliques | alimentation sous le seuil, tampon épuisé | Vérifier la capacité de l'alimentation à fournir le courant nécessaire ; au besoin, contacter le service. |
| Mise à jour interrompue / aucune disponible | réception faible, quota épuisé | Améliorer la réception ; relancer la mise à jour ultérieurement (depuis le portail). |
| Objet | Contact |
|---|---|
| Support général | support@coldwave.io |
| Conformité / déclaration UE de conformité (DoC) | compliance@imagineon.de |
| Sécurité / signalement de vulnérabilité (PSIRT / CVD) | security@coldwave.io |
Merci de ne pas signaler les vulnérabilités suspectées via des issues GitHub publiques. Les signalements de sécurité sont accusés réception sous 2 jours ouvrés et divulgués de manière coordonnée (Coordinated Vulnerability Disclosure). Signalement chiffré par PGP ; l'empreinte est publiée sur https://coldwave.io/.well-known/security.txt (formulaire web prévu : https://coldwave.io/security/report). Pour une vulnérabilité activement exploitée, veuillez marquer l'objet par [ACTIVE EXPLOIT]. Les constats alimentent une mise à jour OTA signée ultérieure ; les versions antérieures affectées sont bloquées par le mécanisme anti-rollback. ImagineOn fournit des mises à jour de sécurité pendant 10 ans à compter de la première mise sur le marché.
Le micrologiciel du Yukiblock CAN utilise des composants open source et intégrés (dont mbedTLS, FreeRTOS, MCUboot, CANopenNode, pilote MCP2518FD, coldwave-script-vm). La liste complète ainsi que les textes de licence et les références aux sources figurent dans le LICENSE.md du produit ; les conditions de licence ImagineOn sont disponibles à l'adresse www.imagineon.de/de/info/licensing-terms. Une SBOM CycloneDX est en outre tenue à jour pour chaque version de micrologiciel livrée et fournie sur demande.
| APN | Access Point Name — point d'entrée dans le réseau cellulaire |
| Bus-off | État d'erreur CAN dans lequel un nœud passe après trop d'erreurs d'émission |
| CANopen | Protocole de communication de couche haute (CiA 301) sur Classic CAN 2.0 |
| Classic CAN 2.0 | Controller Area Network, trame classique (pas de CAN FD) |
| COB-ID | Communication Object Identifier — identifiant d'un objet de communication CANopen |
| CVD | Coordinated Vulnerability Disclosure — divulgation coordonnée de vulnérabilités |
| DoC | Declaration of Conformity — déclaration UE de conformité |
| PIRE | Puissance Isotrope Rayonnée Équivalente |
| EMCY | Emergency Object — message d'urgence / d'erreur CANopen |
| eSIM | SIM soudée (Embedded SIM) |
| IMEI | International Mobile Equipment Identity — identifiant unique du module |
| LTE-M / Cat-M1 | Variante LPWAN du LTE pour IoT |
| MCU | Microcontrôleur |
| MCUboot | Bootloader sécurisé avec vérification de signature d'image |
| NB-IoT | Narrowband IoT — cellulaire LPWAN à bande étroite (repli) |
| NMT | Network Management — commande d'état des nœuds CANopen |
| OD | Object Dictionary — dictionnaire d'objets CANopen |
| OTA | Over-the-Air (mise à jour cellulaire) |
| PDO | Process Data Object — données de process cycliques CANopen |
| PSA Crypto | Platform Security Architecture — stockage de clés et API crypto |
| RED | Directive Équipements Radioélectriques 2014/53/UE |
| RTC | Real-Time Clock — horloge temps réel sauvegardée par pile |
| SDO | Service Data Object — accès acyclique aux objets CANopen |
| Secure Boot | Démarrage de confiance vérifié par signature |
| SELV / PELV | Très basse tension de sécurité / de protection |
| TLS | Transport Layer Security — connexion de transport chiffrée |
| Version | Date | Modification |
|---|---|---|
| 1.0 | 2026 | Première édition |
© 2026 ImagineOn GmbH. Tous droits réservés. Le présent manuel ne peut être reproduit ou communiqué à des tiers sans autorisation expresse d'ImagineOn GmbH, exception faite de la transmission au client final dans le cadre de la chaîne de distribution du produit Coldwave Yukiblock CAN.