Printing PressAI
← Back to front page
Robotics, Hardware & Infrastructure

Formal Automotive Security Analysis Of CAN XL (Georgia Tech, QCRI, Purdue)

Original reporting by Semiconductor Engineering

Image via Semiconductor Engineering

CAN XL refers to the next-generation Controller Area Network standard, designed to address the growing limitations of classic CAN, the longstanding backbone of in-vehicle communication. As modern vehicles integrate advanced components like cameras and AI, classic CAN has struggled with bandwidth, functionality, and persistent security weaknesses, particularly at its MAC sub-layer. CAN XL was introduced with promises of higher bandwidth, longer payloads, and significantly enhanced security, leading many to expect a robust solution to its predecessor's chronic vulnerabilities. The key question centered on whether CAN XL’s fundamental redesign genuinely tackled the MAC sub-layer’s issues or merely added superficial security extensions.

A Worsening Picture

A recent paper by researchers from Georgia Institute of Technology, Qatar Computing Research Institute, and Purdue University presents the first formal security analysis of CAN XL, with a deep dive into its MAC sub-layer. Their findings, published in "A Formal Security Analysis of CAN XL," are stark: far from resolving its predecessor's flaws, CAN XL retains all known classic CAN MAC sub-layer vulnerabilities and introduces seven entirely new ones. The team not only developed a bit-precise formal model but validated these new exploits through multi-stage attacks on a testbed simulating real vehicle traffic, demonstrating that CAN XL's security posture is arguably worse. The research concludes by proposing critical mitigations, including formal verification of standard revisions to prevent these newly identified attacks.

The formal security analysis of CAN XL by researchers from Georgia Tech, QCRI, and Purdue reveals a critical challenge for the automotive industry. Far from merely being an incremental update, the next-generation in-vehicle communication standard, intended to enhance security, surprisingly retains all known MAC sub-layer vulnerabilities from classic CAN while introducing seven new ones. This finding underscores a significant regression in the security posture of modern vehicles, demanding immediate attention from standard bodies and manufacturers. The paper's robust methodology, including validation on commercial controllers and demonstration of multi-stage attacks, leaves little doubt about the practical exploitability of these flaws.

The Road Ahead

The implications of this research are profound. As vehicles become increasingly complex, integrating AI components, cameras, and LiDARs, their communication backbone must be robust against cyber threats. The current state of CAN XL, as analyzed, poses a substantial risk to vehicle safety, data privacy, and the integrity of autonomous functions. Widespread deployment without addressing these fundamental weaknesses could open the door to a new generation of sophisticated automotive attacks, with potentially severe real-world consequences. This study is not just a warning; it’s a clarion call for a paradigm shift in how automotive communication standards are designed and secured. It highlights the urgent need for formally verified standard revisions, collaborative industry efforts, and proactive security-by-design principles to safeguard the future of mobility. The integrity of tomorrow's vehicles hinges on learning from these critical findings and acting decisively today.

Frequently asked questions

What is CAN XL, and why is it replacing the classic Controller Area Network (CAN CC)?
CAN XL (Controller Area Network XL) is the next-generation in-vehicle communication protocol designed to address the limitations of classic CAN (CAN CC). It was developed to support higher bandwidth, longer data payloads, and enhanced security features necessary for modern vehicles integrating advanced components like cameras, LiDAR, and AI systems. It aims to be the backbone for future automotive communication architectures.
Has the new CAN XL communication standard improved the security of in-vehicle networks?
Despite its design aiming for enhanced security, analyses indicate that CAN XL retains all known MAC sub-layer vulnerabilities from classic CAN. Additionally, it introduces seven new security weaknesses, suggesting that its security posture might be worse than its predecessor. These vulnerabilities can be exploited through multi-stage attacks, posing risks to modern vehicle communication systems.
What are the primary security vulnerabilities found in the new CAN XL communication protocol?
The primary security vulnerabilities in CAN XL reside within its MAC sub-layer, which governs frame formats and error handling. It carries forward all known security issues from classic CAN's MAC sub-layer and introduces seven additional, previously unknown vulnerabilities. These weaknesses make CAN XL susceptible to various attacks, potentially compromising the integrity and safety of in-vehicle communications, despite its intended security enhancements.
Intro and outro generated by Printing Press AI from the source article above. Always consult the original reporting for verbatim quotes and primary sources.