Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

BLE Protocol

This chapter summarizes the Qingping CGD1 BLE protocol as implemented by cgd1-rs. For the full reverse-engineered specification, see BLE.md.

GATT Service & Characteristics

Custom Primary Service

22210000-554a-4546-5542-46534450466d

Characteristics

NameUUIDDirection
Auth Write00000001-0000-1000-8000-00805f9b34fbHost → Device
Auth Notify00000002-0000-1000-8000-00805f9b34fbDevice → Host
Data Write0000000b-0000-1000-8000-00805f9b34fbHost → Device
Data Notify0000000c-0000-1000-8000-00805f9b34fbDevice → Host
Sensor Notify00000100-0000-1000-8000-00805f9b34fbDevice → Host

Standard Services

ServiceUUIDCharacteristicUUIDFormat
Battery0x180fBattery Level0x2a191 byte (0–100%)

Frame Format

Every frame follows the same structure:

Request:  [Length] [Command] [Payload...]
ACK:      04 ff [Command] [Status] [Payload 1B]

The length byte counts the bytes that follow it. An ACK is always exactly 5 bytes: 04 ff [Command] [Status] [Payload]. Status 00 means success.

Command Summary

LengthCommandOperationCharacteristic
0x110x01Auth InitAuth Write
0x110x02Auth ConfirmAuth Write
0x050x09Time SyncAuth Write
0x010x0dRead FirmwareAuth Write
0x010x02Read SettingsData Write
0x130x01Set SettingsData Write
0x020x03Set BrightnessData Write
0x010x04Preview Ringtone (current vol)Data Write
0x020x04Preview Ringtone (specific vol)Data Write
0x010x06Read AlarmsData Write
0x070x05Set/Delete AlarmData Write
0x080x10Audio InitData Write
0x810x08Audio Data PacketData Write

Connection Lifecycle

graph TD
    Scan["Scan (FDCD)"] --> Connect["Connect (GATT)"]
    Connect --> Auth["Auth (Token)"]
    Auth --> SyncTime["Sync Time"]
    SyncTime --> ReadConfig["Read Config / Sensors"]
    ReadConfig --> Operate["Operate Alarms / Settings"]
    Operate --> Idle["Idle"]
    Idle --> Disconnect["Disconnect"]
    Disconnect --> Scan

Passive vs Connected

  • Passive (no connection): Sensor data (temperature, humidity, battery) via BLE advertisements with FDCD service-data UUID. No authentication required.
  • Connected: Authentication required for all write operations. Sensor data also available via real-time notify characteristic. Battery via standard GATT battery service.

For protocol details on each operation, see the dedicated chapters: Authentication, Alarms, Settings, Sensors & Battery, Audio Upload.