Formal Automotive Security Analysis of CAN XL
Researchers from Georgia Tech, the Qatar Computing Research Institute (QCRI), and Purdue University have conducted a formal security analysis of CAN XL, the next-generation Controller Area Network protocol poised to underpin in-vehicle communications through the late 2020s and beyond.
Background: The Evolution Toward CAN XL
As automotive architectures shift toward software-defined vehicles, zonal topologies, and higher-bandwidth sensor fusion, legacy CAN and CAN FD face growing limitations in payload size, data rate, and security guarantees. CAN XL, standardized under CiA 601-1 and integrated into ISO 11898-1:2024, addresses these constraints with payloads up to 2,048 bytes, data rates up to 20 Mbit/s, and native support for higher-layer protocols such as IP and Ethernet tunneling.
With 2026 marking broader silicon availability and early OEM adoption of CAN XL nodes, security assurance for the protocol itself has become a pressing concern.
Why Formal Methods?
Informal testing and fuzzing can miss subtle state-machine flaws and timing-dependent vulnerabilities. Formal analysis, by contrast, provides mathematical guarantees over protocol behavior—an increasingly important property as automotive networks become safety-critical attack surfaces subject to ISO/SAE 21434 and UNECE R155/R156 compliance regimes.
Scope of the Research
The Georgia Tech–QCRI–Purdue collaboration applies formal modeling and verification techniques to the CAN XL specification, targeting properties such as:
- Frame integrity and arbitration correctness under mixed CAN, CAN FD, and CAN XL traffic.
- Error-confinement behavior, including how the protocol handles malformed frames or maliciously crafted payloads.
- Priority inversion and denial-of-service resistance in the presence of adversarial nodes.
- State consistency across the protocol data unit (PDU) and physical coding sublayer (PCS) transitions.
Implications for Automotive Security
The findings are expected to inform:
- ECU and transceiver design — providing verified invariants that hardware and firmware implementers can rely on.
- Intrusion detection and prevention systems (IDPS) — supplying formal baselines against which anomalies can be detected.
- Standards refinement — offering evidence to CiA and ISO working groups as CAN XL deployments scale in 2026 and beyond.
- Regulatory compliance — supporting the threat analysis and risk assessment (TARA) activities required under ISO/SAE 21434.
Outlook
As CAN XL moves from specification to production vehicles, formal security analysis provides a critical foundation for trust. This work exemplifies the broader trend toward mathematically grounded security assurance in automotive networking, complementing—rather than replacing—empirical testing and red-teaming efforts.
Source: Georgia Institute of Technology, Qatar Computing Research Institute (QCRI), and Purdue University.
