Formal Automotive Security Analysis of CAN XL

Formal Automotive Security Analysis of CAN XL


Researchers from Georgia Tech, the Qatar Computing Research Institute (QCRI), and Purdue University have conducted a formal security analysis of CAN XL, the next-generation Controller Area Network protocol poised to underpin in-vehicle communications through the late 2020s and beyond.


Background: The Evolution Toward CAN XL


As automotive architectures shift toward software-defined vehicles, zonal topologies, and higher-bandwidth sensor fusion, legacy CAN and CAN FD face growing limitations in payload size, data rate, and security guarantees. CAN XL, standardized under CiA 601-1 and integrated into ISO 11898-1:2024, addresses these constraints with payloads up to 2,048 bytes, data rates up to 20 Mbit/s, and native support for higher-layer protocols such as IP and Ethernet tunneling.


With 2026 marking broader silicon availability and early OEM adoption of CAN XL nodes, security assurance for the protocol itself has become a pressing concern.


Why Formal Methods?


Informal testing and fuzzing can miss subtle state-machine flaws and timing-dependent vulnerabilities. Formal analysis, by contrast, provides mathematical guarantees over protocol behavior—an increasingly important property as automotive networks become safety-critical attack surfaces subject to ISO/SAE 21434 and UNECE R155/R156 compliance regimes.


Scope of the Research


The Georgia Tech–QCRI–Purdue collaboration applies formal modeling and verification techniques to the CAN XL specification, targeting properties such as:


  • Frame integrity and arbitration correctness under mixed CAN, CAN FD, and CAN XL traffic.
  • Error-confinement behavior, including how the protocol handles malformed frames or maliciously crafted payloads.
  • Priority inversion and denial-of-service resistance in the presence of adversarial nodes.
  • State consistency across the protocol data unit (PDU) and physical coding sublayer (PCS) transitions.

Implications for Automotive Security


The findings are expected to inform:


  1. ECU and transceiver design — providing verified invariants that hardware and firmware implementers can rely on.
  2. Intrusion detection and prevention systems (IDPS) — supplying formal baselines against which anomalies can be detected.
  3. Standards refinement — offering evidence to CiA and ISO working groups as CAN XL deployments scale in 2026 and beyond.
  4. Regulatory compliance — supporting the threat analysis and risk assessment (TARA) activities required under ISO/SAE 21434.

  5. Outlook


    As CAN XL moves from specification to production vehicles, formal security analysis provides a critical foundation for trust. This work exemplifies the broader trend toward mathematically grounded security assurance in automotive networking, complementing—rather than replacing—empirical testing and red-teaming efforts.




    Source: Georgia Institute of Technology, Qatar Computing Research Institute (QCRI), and Purdue University.

    via Semiconductor Engineering

Related