Hardening the Backbone: Addressing Security Flaws in CAN XL for SDVs

Researchers have uncovered critical security vulnerabilities in the CAN XL protocol, the backbone of next-generation software-defined vehicles. The findings highlight the urgent need for formal verification in automotive hardware to prevent remote exploits.

Share
Hardening the Backbone: Addressing Security Flaws in CAN XL for SDVs

As vehicles transition into high-performance computers on wheels, the underlying communication protocols are becoming prime targets for cyberattacks. Researchers from Georgia Tech, QCRI, and Purdue have published a formal security analysis of CAN XL—the latest evolution of the Controller Area Network (CAN) bus intended to power the next generation of software-defined vehicles (SDVs).

CAN XL was designed to handle the massive data throughput required for modern ADAS and infotainment systems, but the research team has identified flaws that could allow for sophisticated spoofing and denial-of-service attacks. In an SDV, where steering, braking, and engine management are controlled via software commands, a breach of the internal communication bus isn't just a data leak—it is a safety catastrophe.

The study advocates for a "Secure by Design" approach, utilizing formal verification methods to ensure that hardware abstractions match real-world physical devices. As automakers move toward centralized computing architectures, the integrity of the CAN XL protocol is paramount. This research serves as a wake-up call for the industry to prioritize cryptographic security at the hardware level before these vulnerabilities are exploited in the wild.


Source: Semiconductor Engineering