Researchers Conduct First Security Assessment of CAN XL In-Vehicle Communication Protocol's Media Access Layer

Researchers from Georgia Institute of Technology, Qatar Computing Research Institute, and Purdue University have performed the first formal security analysis of the CAN XL standard, focusing specifically on its media access sublayer that governs frame formats and error handling. The study examines whether the next-generation automotive communication protocol adequately addresses historical security vulnerabilities present in classic CAN, particularly at the MAC layer which has been a vector for previous attacks. This analysis is critical as the automotive industry prepares for widespread CAN XL deployment in vehicles integrating advanced sensors and AI components.
The research represents a significant milestone in automotive cybersecurity validation. Historically, the Controller Area Network has powered vehicle communications for decades, but emerging vehicle technologies—including advanced sensors and machine learning systems—have exposed bandwidth and functional limitations. CAN XL was designed to address these constraints while incorporating security improvements, yet researchers discovered the protocol's foundational communication layer retained vulnerabilities from its predecessor.
The study employed formal verification methods to create a precise mathematical model of CAN XL's specifications. Through this rigorous analysis, the team identified not only persistent weaknesses but also seven previously unknown security gaps. Notably, the researchers demonstrated practical exploitation through multi-stage attack scenarios on vehicle network testbeds, then proposed concrete mitigation strategies including formal verification of revised standards.
This research could influence automotive industry standards adoption timelines and manufacturer security practices. Vehicle engineers and suppliers may face decisions about CAN XL implementation urgency versus security hardening. The findings could prompt industry collaboration on standard revisions before widespread deployment in connected and autonomous vehicles. Consumers may eventually benefit from more resilient in-vehicle networks, though remediation could affect production schedules and vehicle costs during transition periods.