Automotive Experiences

Articles

Enhancing CAN Bus Security via Lightweight Hardware‑Based Identifier Randomization

Mohammed Saad Darouiche , Elbachir Tazi

Abstract

The controller area network (CAN) communication protocol used in vehicles relies on fixed message identifiers, which makes it vulnerable against frame injection and replay attacks. This study proposes an efficient lightweight hardware method that randomizes the identifier while preserving the priority rules that control bus arbitration. The design is implemented in a hardware description language (Verilog) and uses a linear feedback shift register (LFSR) as the randomization engine. The upper four bits of the identifier are kept unchanged to retain priority, where the lower seven bits are randomized. The module supports reseeding from a cryptographically secure random source. However, for the baseline statistical evaluation, reseeding was intentionally disabled to measure the intrinsic distribution. The design was evaluated using Xilinx Vivado environment. Statistical analysis was performed on 8,188 randomized ID, achieving a Shannon entropy of 6.999978 bits (maximum 7), and a chi‑square goodness‑of‑fit test that showed no detectable deviation from a uniform distribution (  = 0.2482, -value ≈ 1). Synthesis to a Artix-7 field‑programmable device reported only 15 lookup tables and 23 flip-flops (<0.1% of resources), with a maximum operating frequency of 482 MHz, indicating a minimal hardware footprint. The mechanism was further validated on a physical CAN testbed confirming protection against replay and spoofing attempts, while the mechanism added no measurable bus or timing overhead. These results show that simple, hardware‑level identifier randomization can strengthen in‑vehicle communication while keeping arbitration behaviour intact and without requiring protocol changes.

Keywords

CAN bus; Identifier randomization; LFSR; Statistical analysis; Cyber security

References

  1. [1] Bosch GmbH, “CAN Specification Version 2.0,” 1991.
  2. [2] International Organization for Standardization, “ISO 11898-1:2003 — Road vehicles — Controller area network (CAN) — Part 1: Data link layer and physical signalling,” 2003.
  3. [3] F. Hartwich, “CAN with flexible data-rate,” Hambach Castle: 13th International CAN Conference (iCC), 2012.
  4. [4] K. Koscher et al., “Experimental Security Analysis of a Modern Automobile,” in 2010 IEEE Symposium on Security and Privacy, IEEE, 2010, pp. 447–462. doi: 10.1109/SP.2010.34.
  5. [5] S. Checkoway et al., “Comprehensive experimental analyses of automotive attack surfaces,” Usenix. [Online]. Available: https://www.usenix.org/conference/usenix-security-11/comprehensive-experimental-analyses-automotive-attack-surfaces
  6. [6] J. Petit and S. E. Shladover, “Potential Cyberattacks on Automated Vehicles,” IEEE Transactions on Intelligent Transportation Systems, pp. 1–11, 2014, doi: 10.1109/TITS.2014.2342271.
  7. [7] C. Miller and C. Valasek, “Remote exploitation of an unaltered passenger vehicle,” Las Vegas: Black Hat USA, 2015.
  8. [8] S. Woo, H. J. Jo, and D. H. Lee, “A Practical Wireless Attack on the Connected Car and Security Protocol for In-Vehicle CAN,” IEEE Transactions on Intelligent Transportation Systems, pp. 1–14, 2014, doi: 10.1109/TITS.2014.2351612.
  9. [9] K.-T. Cho and K. G. Shin, “Error Handling of In-vehicle Networks Makes Them Vulnerable,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA: ACM, Oct. 2016, pp. 1044–1055. doi: 10.1145/2976749.2978302.
  10. [10] T. Hoppe, S. Kiltz, and J. Dittmann, “Security threats to automotive CAN networks—Practical examples and selected short-term countermeasures,” Reliability Engineering & System Safety, vol. 96, no. 1, pp. 11–25, Jan. 2011, doi: 10.1016/j.ress.2010.06.026.
  11. [11] S. Nie, L. Liu, and Y. Du, “Free-fall: Hacking Tesla from wireless to CAN bus,” Black Hat USA, 2017, pp. 1–16.
  12. [12] W. Xu, S. Yang, and X. Yan, “A Lightweight Intrusion Detection System for In-Vehicle Bus Networks,” in 2024 4th International Conference on Intelligent Communications and Computing (ICICC), IEEE, Oct. 2024, pp. 149–153. doi: 10.1109/ICICC63565.2024.10780754.
  13. [13] M.-J. Kang and J.-W. Kang, “Intrusion Detection System Using Deep Neural Network for In-Vehicle Network Security,” PLOS ONE, vol. 11, no. 6, p. e0155781, Jun. 2016, doi: 10.1371/journal.pone.0155781.
  14. [14] S. Khandelwal and S. Shreejith, “A Lightweight FPGA-based IDS-ECU Architecture for Automotive CAN,” in 2022 International Conference on Field-Programmable Technology (ICFPT), IEEE, Dec. 2022, pp. 1–9. doi: 10.1109/ICFPT56656.2022.9974508.
  15. [15] K. Karray, J.-L. Danger, S. Guilley, and M. A. Elaabid, “Identifier Randomization: An Efficient Protection Against CAN-Bus Attacks,” in Cyber-Physical Systems Security, Cham: Springer International Publishing, 2018, pp. 219–254. doi: 10.1007/978-3-319-98935-8_11.
  16. [16] B. Lampe and W. Meng, “Intrusion Detection in the Automotive Domain: A Comprehensive Review,” IEEE Communications Surveys & Tutorials, vol. 25, no. 4, pp. 2356–2426, 2023, doi: 10.1109/COMST.2023.3309864.
  17. [17] AUTOSAR Consortium, “Specification of Secure Onboard Communication (SecOC),” 2017.
  18. [18] E. Aliwa, O. Rana, C. Perera, and P. Burnap, “Cyberattacks and Countermeasures for In-Vehicle Networks,” ACM Computing Surveys, vol. 54, no. 1, pp. 1–37, Jan. 2022, doi: 10.1145/3431233.
  19. [19] G. I. Mary, Z. C. Alex, and L. Jenkins, “Response Time Analysis of Messages in Controller Area Network: A Review,” Journal of Computer Networks and Communications, vol. 2013, pp. 1–11, 2013, doi: 10.1155/2013/148015.
  20. [20] E. Avaroğlu, İ. Koyuncu, A. B. Özer, and M. Türk, “Hybrid pseudo-random number generator for cryptographic systems,” Nonlinear Dynamics, vol. 82, no. 1–2, pp. 239–248, Oct. 2015, doi: 10.1007/s11071-015-2152-8.
  21. [21] P. Chandravanshi, J. K. Meka, V. Mongia, R. P. Singh, and S. Prabhakar, “LFSR based RNG on low-cost FPGA for QKD applications,” 2023, arXiv. doi: arXiv:2307.16431.
  22. [22] C. E. Shannon, The Mathematical Theory of Communication. Urbana, IL, USA: University of Illinois Press, 1949.
  23. [23] Y. Wu, J. P. Noonan, and S. Agaian, “Shannon entropy based randomness measurement and test for image encryption,” 2011. doi: 10.48550/arXiv.1103.5520.
  24. [24] L. E. Bassham et al., “A statistical test suite for random and pseudorandom number generators for cryptographic applications,” Gaithersburg, MD, MD, 2010. doi: 10.6028/NIST.SP.800-22r1a.
  25. [25] P. Kietzmann, T. C. Schmidt, and M. Wählisch, “A Guideline on Pseudorandom Number Generation (PRNG) in the IoT,” ACM Computing Surveys, vol. 54, no. 6, pp. 1–38, Jul. 2022, doi: 10.1145/3453159.
  26. [26] J. Massey, “Shift-register synthesis and BCH decoding,” IEEE Transactions on Information Theory, vol. 15, no. 1, pp. 122–127, Jan. 1969, doi: 10.1109/TIT.1969.1054260.
  27. [27] A. J. Menezes, P. C. van Oorschot, and S. A. Vanstone, Handbook of Applied Cryptography. Boca Raton: CRC Press, 1996.
  28. [28] K. Han, A. Weimerskirch, and K. G. Shin, “A practical solution to achieve real-time performance in the automotive network by randomizing frame identifier,” in European Embedded Security in Cars (ESCAR), 2015, pp. 13–29.
  29. [29] N. Hediyal, B. P. Divakar, and K. Narayanaswamy, “SCAN-C: a lightweight cryptographic algorithm to secure CAN communications in modern vehicles,” Cybersecurity, vol. 8, no. 1, p. 49, Jul. 2025, doi: 10.1186/s42400-024-00291-z.