CAIBA: Multicast Source Authentication for CAN Through Reactive Bit Flipping

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wagner, Eric, Basels, Frederik, Bauer, Jan, Zimmermann, Till, Wehrle, Klaus, Henze, Martin
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909590044540928
author Wagner, Eric
Basels, Frederik
Bauer, Jan
Zimmermann, Till
Wehrle, Klaus
Henze, Martin
author_facet Wagner, Eric
Basels, Frederik
Bauer, Jan
Zimmermann, Till
Wehrle, Klaus
Henze, Martin
contents Controller Area Networks (CANs) are the backbone for reliable intra-vehicular communication. Recent cyberattacks have, however, exposed the weaknesses of CAN, which was designed without any security considerations in the 1980s. Current efforts to retrofit security via intrusion detection or message authentication codes are insufficient to fully secure CAN as they cannot adequately protect against masquerading attacks, where a compromised communication device, a so-called electronic control units, imitates another device. To remedy this situation, multicast source authentication is required to reliably identify the senders of messages. In this paper, we present CAIBA, a novel multicast source authentication scheme specifically designed for communication buses like CAN. CAIBA relies on an authenticator overwriting authentication tags on-the-fly, such that a receiver only reads a valid tag if not only the integrity of a message but also its source can be verified. To integrate CAIBA into CAN, we devise a special message authentication scheme and a reactive bit overwriting mechanism. We achieve interoperability with legacy CAN devices, while protecting receivers implementing the AUTOSAR SecOC standard against masquerading attacks without communication overhead or verification delays.
format Preprint
id arxiv_https___arxiv_org_abs_2504_16695
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle CAIBA: Multicast Source Authentication for CAN Through Reactive Bit Flipping
Wagner, Eric
Basels, Frederik
Bauer, Jan
Zimmermann, Till
Wehrle, Klaus
Henze, Martin
Cryptography and Security
Controller Area Networks (CANs) are the backbone for reliable intra-vehicular communication. Recent cyberattacks have, however, exposed the weaknesses of CAN, which was designed without any security considerations in the 1980s. Current efforts to retrofit security via intrusion detection or message authentication codes are insufficient to fully secure CAN as they cannot adequately protect against masquerading attacks, where a compromised communication device, a so-called electronic control units, imitates another device. To remedy this situation, multicast source authentication is required to reliably identify the senders of messages. In this paper, we present CAIBA, a novel multicast source authentication scheme specifically designed for communication buses like CAN. CAIBA relies on an authenticator overwriting authentication tags on-the-fly, such that a receiver only reads a valid tag if not only the integrity of a message but also its source can be verified. To integrate CAIBA into CAN, we devise a special message authentication scheme and a reactive bit overwriting mechanism. We achieve interoperability with legacy CAN devices, while protecting receivers implementing the AUTOSAR SecOC standard against masquerading attacks without communication overhead or verification delays.
title CAIBA: Multicast Source Authentication for CAN Through Reactive Bit Flipping
topic Cryptography and Security
url https://arxiv.org/abs/2504.16695