2 ms·
Thank you. Let's say we want to create a CAN bus which makes it impossible to listen to / inject non-authorized input even when the adversary has physical acce
by java-man 7y ago
Thank you.
Let's say we want to create a CAN bus which makes it impossible to listen to / inject non-authorized input even when the adversary has physical access to the bus.
This means encrypted traffic and a (possibly shared) key maintained by each device on the bus, or only the critical devices.
There is still a possibility of DoS attack on the bus, or tampering with the packets by injecting noise.
Does anyone know if the capability to encrypt CAN bus traffic even exists?
- davismwfl 7y agoTo be fair, there are multiple forms of CAN now in usage too. With CAN FD being the latest IIRC. So some of this will depend on which standard is being followed, although at their core they function nearly the same. The overall nature of CAN is if you have access to it you can listen, so it isn't designed to prevent participation itself. There isn't a way of excluding a node without custom hardware/software as every node sees all data in a standard CAN bus. Yes, you can do a DoS attack on the bus, tampering with the packets is tougher but not impossible. There are essentially CAN firewalls that can be setup which can limit the damage and there are some companies that make software/hardware that act like a sink to control/stop a bad node or unauthorized access. The most common thing is during CAN connection to require registration and some form of a key infrastructure. Without that your node is essentially ignored, although the network is still subject to your node essentially DoS the network by holding the lines low/high. This is how I have handled basic security and node control prior. But you can do things like a firewall with network segmentation, which works really well too. Encrypting CAN can be done, but by design CAN is not a super high throughput bus (new FD is fairly fast) and is designed for multiplex messaging, so it can be quite costly to encrypt data going across it. But there are solutions for encrypting CAN and it is done.