Modern vehicles rely heavily on the Controller Area Network (CAN) to coordinate safety and performance critical functions among Electronic Control Units (ECUs). However, classical CAN provides no built-in support for message authentication or freshness, leaving in-vehicle networks vulnerable to spoofing, injection, and replay attacks that can directly affect braking, steering, and powertrain behaviour. These weak- nesses raise safety concerns, as compromised messages may influence vehicle control decisions. While numerous research efforts aim to secure CAN, many existing approaches rely on multi-frame authentication, additional hardware com- ponents, or modifications to timing or physical layer behaviour, which complicates deployment on legacy platforms constrained by an 8-byte payload and strict real-time schedules. In this work, we present LCAP (Lightweight CAN Authentication Proto- col), a single frame authentication mechanism tailored for classical CAN. LCAP embeds a compact freshness counter and a truncated HMAC-based authentication tag directly into the existing 8-byte payload, providing message integrity and replay protection without altering the CAN frame format, arbitration behaviour, or bus timing. To tolerate realistic op- erating conditions, LCAP incorporates a sliding soft-resynchronisation mechanism that recovers from bounded counter gaps caused by frame loss, arbitration delays, or short disconnections. We implement LCAP on a hardware prototype using Arduino Uno mi- crocontrollers and MCP2515 CAN controllers, and demonstrate that cryptographic authentication is feasible on low-cost automotive ECUs within tight timing constraints, with worst-case verification latency below 420 µs at 250 kbps. These results show that LCAP bridges an important gap between prior CAN security proposals and deployable solutions for legacy in-vehicle networks.

Modern vehicles rely heavily on the Controller Area Network (CAN) to coordinate safety and performance critical functions among Electronic Control Units (ECUs). However, classical CAN provides no built-in support for message authentication or freshness, leaving in-vehicle networks vulnerable to spoofing, injection, and replay attacks that can directly affect braking, steering, and powertrain behaviour. These weak- nesses raise safety concerns, as compromised messages may influence vehicle control decisions. While numerous research efforts aim to secure CAN, many existing approaches rely on multi-frame authentication, additional hardware com- ponents, or modifications to timing or physical layer behaviour, which complicates deployment on legacy platforms constrained by an 8-byte payload and strict real-time schedules. In this work, we present LCAP (Lightweight CAN Authentication Proto- col), a single frame authentication mechanism tailored for classical CAN. LCAP embeds a compact freshness counter and a truncated HMAC-based authentication tag directly into the existing 8-byte payload, providing message integrity and replay protection without altering the CAN frame format, arbitration behaviour, or bus timing. To tolerate realistic op- erating conditions, LCAP incorporates a sliding soft-resynchronisation mechanism that recovers from bounded counter gaps caused by frame loss, arbitration delays, or short disconnections. We implement LCAP on a hardware prototype using Arduino Uno mi- crocontrollers and MCP2515 CAN controllers, and demonstrate that cryptographic authentication is feasible on low-cost automotive ECUs within tight timing constraints, with worst-case verification latency below 420 µs at 250 kbps. These results show that LCAP bridges an important gap between prior CAN security proposals and deployable solutions for legacy in-vehicle networks.

LCAP - A Lightweight CAN Authentication Protocol for Practical Automotive Development

MOHAN, PRASANTH
2025/2026

Abstract

Modern vehicles rely heavily on the Controller Area Network (CAN) to coordinate safety and performance critical functions among Electronic Control Units (ECUs). However, classical CAN provides no built-in support for message authentication or freshness, leaving in-vehicle networks vulnerable to spoofing, injection, and replay attacks that can directly affect braking, steering, and powertrain behaviour. These weak- nesses raise safety concerns, as compromised messages may influence vehicle control decisions. While numerous research efforts aim to secure CAN, many existing approaches rely on multi-frame authentication, additional hardware com- ponents, or modifications to timing or physical layer behaviour, which complicates deployment on legacy platforms constrained by an 8-byte payload and strict real-time schedules. In this work, we present LCAP (Lightweight CAN Authentication Proto- col), a single frame authentication mechanism tailored for classical CAN. LCAP embeds a compact freshness counter and a truncated HMAC-based authentication tag directly into the existing 8-byte payload, providing message integrity and replay protection without altering the CAN frame format, arbitration behaviour, or bus timing. To tolerate realistic op- erating conditions, LCAP incorporates a sliding soft-resynchronisation mechanism that recovers from bounded counter gaps caused by frame loss, arbitration delays, or short disconnections. We implement LCAP on a hardware prototype using Arduino Uno mi- crocontrollers and MCP2515 CAN controllers, and demonstrate that cryptographic authentication is feasible on low-cost automotive ECUs within tight timing constraints, with worst-case verification latency below 420 µs at 250 kbps. These results show that LCAP bridges an important gap between prior CAN security proposals and deployable solutions for legacy in-vehicle networks.
2025
LCAP - A Lightweight CAN Authentication Protocol for Practical Automotive Development
Modern vehicles rely heavily on the Controller Area Network (CAN) to coordinate safety and performance critical functions among Electronic Control Units (ECUs). However, classical CAN provides no built-in support for message authentication or freshness, leaving in-vehicle networks vulnerable to spoofing, injection, and replay attacks that can directly affect braking, steering, and powertrain behaviour. These weak- nesses raise safety concerns, as compromised messages may influence vehicle control decisions. While numerous research efforts aim to secure CAN, many existing approaches rely on multi-frame authentication, additional hardware com- ponents, or modifications to timing or physical layer behaviour, which complicates deployment on legacy platforms constrained by an 8-byte payload and strict real-time schedules. In this work, we present LCAP (Lightweight CAN Authentication Proto- col), a single frame authentication mechanism tailored for classical CAN. LCAP embeds a compact freshness counter and a truncated HMAC-based authentication tag directly into the existing 8-byte payload, providing message integrity and replay protection without altering the CAN frame format, arbitration behaviour, or bus timing. To tolerate realistic op- erating conditions, LCAP incorporates a sliding soft-resynchronisation mechanism that recovers from bounded counter gaps caused by frame loss, arbitration delays, or short disconnections. We implement LCAP on a hardware prototype using Arduino Uno mi- crocontrollers and MCP2515 CAN controllers, and demonstrate that cryptographic authentication is feasible on low-cost automotive ECUs within tight timing constraints, with worst-case verification latency below 420 µs at 250 kbps. These results show that LCAP bridges an important gap between prior CAN security proposals and deployable solutions for legacy in-vehicle networks.
CAN - Networks
Network security
In - Vehicle
Automative
Cybersecurity
File in questo prodotto:
File Dimensione Formato  
Master_Thesis.pdf

accesso aperto

Dimensione 3.54 MB
Formato Adobe PDF
3.54 MB Adobe PDF Visualizza/Apri

The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.12608/110968