Modern vehicles rely heavily on the Controller Area Network (CAN) to coordinate safety and performance critical functions among Electronic Control Units (ECUs). However, classical CAN provides no built-in support for message authentication or freshness, leaving in-vehicle networks vulnerable to spoofing, injection, and replay attacks that can directly affect braking, steering, and powertrain behaviour. These weak- nesses raise safety concerns, as compromised messages may influence vehicle control decisions. While numerous research efforts aim to secure CAN, many existing approaches rely on multi-frame authentication, additional hardware com- ponents, or modifications to timing or physical layer behaviour, which complicates deployment on legacy platforms constrained by an 8-byte payload and strict real-time schedules. In this work, we present LCAP (Lightweight CAN Authentication Proto- col), a single frame authentication mechanism tailored for classical CAN. LCAP embeds a compact freshness counter and a truncated HMAC-based authentication tag directly into the existing 8-byte payload, providing message integrity and replay protection without altering the CAN frame format, arbitration behaviour, or bus timing. To tolerate realistic op- erating conditions, LCAP incorporates a sliding soft-resynchronisation mechanism that recovers from bounded counter gaps caused by frame loss, arbitration delays, or short disconnections. We implement LCAP on a hardware prototype using Arduino Uno mi- crocontrollers and MCP2515 CAN controllers, and demonstrate that cryptographic authentication is feasible on low-cost automotive ECUs within tight timing constraints, with worst-case verification latency below 420 µs at 250 kbps. These results show that LCAP bridges an important gap between prior CAN security proposals and deployable solutions for legacy in-vehicle networks.
Modern vehicles rely heavily on the Controller Area Network (CAN) to coordinate safety and performance critical functions among Electronic Control Units (ECUs). However, classical CAN provides no built-in support for message authentication or freshness, leaving in-vehicle networks vulnerable to spoofing, injection, and replay attacks that can directly affect braking, steering, and powertrain behaviour. These weak- nesses raise safety concerns, as compromised messages may influence vehicle control decisions. While numerous research efforts aim to secure CAN, many existing approaches rely on multi-frame authentication, additional hardware com- ponents, or modifications to timing or physical layer behaviour, which complicates deployment on legacy platforms constrained by an 8-byte payload and strict real-time schedules. In this work, we present LCAP (Lightweight CAN Authentication Proto- col), a single frame authentication mechanism tailored for classical CAN. LCAP embeds a compact freshness counter and a truncated HMAC-based authentication tag directly into the existing 8-byte payload, providing message integrity and replay protection without altering the CAN frame format, arbitration behaviour, or bus timing. To tolerate realistic op- erating conditions, LCAP incorporates a sliding soft-resynchronisation mechanism that recovers from bounded counter gaps caused by frame loss, arbitration delays, or short disconnections. We implement LCAP on a hardware prototype using Arduino Uno mi- crocontrollers and MCP2515 CAN controllers, and demonstrate that cryptographic authentication is feasible on low-cost automotive ECUs within tight timing constraints, with worst-case verification latency below 420 µs at 250 kbps. These results show that LCAP bridges an important gap between prior CAN security proposals and deployable solutions for legacy in-vehicle networks.
LCAP - A Lightweight CAN Authentication Protocol for Practical Automotive Development
MOHAN, PRASANTH
2025/2026
Abstract
Modern vehicles rely heavily on the Controller Area Network (CAN) to coordinate safety and performance critical functions among Electronic Control Units (ECUs). However, classical CAN provides no built-in support for message authentication or freshness, leaving in-vehicle networks vulnerable to spoofing, injection, and replay attacks that can directly affect braking, steering, and powertrain behaviour. These weak- nesses raise safety concerns, as compromised messages may influence vehicle control decisions. While numerous research efforts aim to secure CAN, many existing approaches rely on multi-frame authentication, additional hardware com- ponents, or modifications to timing or physical layer behaviour, which complicates deployment on legacy platforms constrained by an 8-byte payload and strict real-time schedules. In this work, we present LCAP (Lightweight CAN Authentication Proto- col), a single frame authentication mechanism tailored for classical CAN. LCAP embeds a compact freshness counter and a truncated HMAC-based authentication tag directly into the existing 8-byte payload, providing message integrity and replay protection without altering the CAN frame format, arbitration behaviour, or bus timing. To tolerate realistic op- erating conditions, LCAP incorporates a sliding soft-resynchronisation mechanism that recovers from bounded counter gaps caused by frame loss, arbitration delays, or short disconnections. We implement LCAP on a hardware prototype using Arduino Uno mi- crocontrollers and MCP2515 CAN controllers, and demonstrate that cryptographic authentication is feasible on low-cost automotive ECUs within tight timing constraints, with worst-case verification latency below 420 µs at 250 kbps. These results show that LCAP bridges an important gap between prior CAN security proposals and deployable solutions for legacy in-vehicle networks.| File | Dimensione | Formato | |
|---|---|---|---|
|
Master_Thesis.pdf
accesso aperto
Dimensione
3.54 MB
Formato
Adobe PDF
|
3.54 MB | Adobe PDF | Visualizza/Apri |
The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License
https://hdl.handle.net/20.500.12608/110968