A Formal Security Analysis of CAN XL
By Zhaozhou Tang 1, Khaled Serag 2, Z. Berkay Celik 3, Vijay Ganesh 1, Saman Zonouz 1
1 Georgia Institute of Technology
2 Qatar Computing Research Institute
3 Purdue University

Abstract
For decades, the Controller Area Network (CAN) has been the backbone of in-vehicle communication. As modern vehi cles integrate cameras, LiDARs, and AI components, classic CAN (CAN CC) faces growing limitations in bandwidth, functionality, and security. To fill these gaps, CAN XL was introduced as the next generation of CAN, aiming to offer longer payloads, higher bandwidth, and enhanced security.
CAN XL makes significant standard-level changes across multiple stack layers. It also introduces several security features, but it is unclear whether these are mere add-on extensions or whether the standard redesign itself tackles CAN’s chronic security weakness: the MAC sub-layer. This sub-layer governs frame formats and error handling and has historically enabled many CAN CC attacks. As the industry transitions to CANXL, the security posture of its yet-unexplored MAC sub-layer must be understood before widespread deployment.
This paper presents the first security analysis of the CAN XL standard, focusing on its MAC sub-layer. We develop a bit-precise CAN XL formal model and release it to facilitate future research. We design a formal analysis workflow guided by CAN XL’s field-oriented structure to uncover vulnerabilities. Contrary to expectations, our analysis shows that CAN XL remains vulnerable to all known CAN CC MAC sub-layer issues while introducing seven new vulnerabilities, arguably worsening security. We validate them using commercial CAN XL controllers and demonstrate exploitability via two multi-stage attacks on a testbed simulating real vehicle traffic. Finally, we propose mitigations including formally verifying standard revisions that could prevent several attacks.
To read the full article, click here
Related Semiconductor IP
- CAN-XL Bus Controller IP
- CAN-SEC Bus Controller IP
- CAN XL Controller IP
- CAN XL Controller
- CANsec Acceleration Engine
Related Articles
- Case Study: Can you afford to ignore formal analysis?
- Getting the most out of formal analysis
- Triple play - How FPGAs can tackle the challenges of network security
- Pragmatic Adoption of Formal Analysis
Latest Articles
- A Formal Security Analysis of CAN XL
- A Secure dToF LiDAR SoC with Dual-Domain Fingerprinting and Event-Driven AFE Circuit Achieving Sensor-Level Attack Resilience
- ZTA-Q: an Open-source RISC-V Platform for Accurate Quantized CNN Inference
- Automated Pre-Silicon Verification of High-Speed DDR5 and LPDDR5/6 Memory Controllers: Closed-Loop Timing, Mode Register, and PHY Synchronization in UVM
- U-Sonic: An Open-Source 8-Channel Ultrasound Transmit IP in a 130 nm RISC-V SoC