Can Network Security Protocol of Autonomous Vehicle Based on FPGA in the Loop
| dc.contributor.advisor | Ganesan, Subramaniam | |
| dc.contributor.author | Lagnf, Farag Mohamed E | |
| dc.contributor.other | Liu, Anyi | |
| dc.contributor.other | Alawneh, Shadi | |
| dc.contributor.other | Deng, Xiaodong | |
| dc.date.accessioned | 2026-09-28T19:05:38Z | |
| dc.date.available | 2026-09-28T19:05:38Z | |
| dc.date.issued | 2026-01-01 | |
| dc.description.abstract | In Software-Defined Vehicles (SDVs) the transition towards zonal topologies decreases the attack surface and improves the security requirements of in-vehicle communication networks such as CAN FD. This dissertation introduces a lightweight FPGA-based security frame designed to mitigate replay attacks and spoofing threats with a deterministic synchronized Freshness Value (FV) derived from a non linear function. The FV is transformed into a cryptographically balanced bitstream and integrated with AES 128 Encryption and lightweight authentication methods to make sure secrecy, integrity, and freshness verification with low computing burden. The proposed architecture was executed and verified by an FPGA-in-the-Loop (FIL) codesign approach on a Xilinx Arty A7 platform. MATLAB and VHDL integration have been utilized. With loss of 30 % of CAN FD messages, experimental findings indicated that precise synchronization has achieved between transmitter (Tx) and receiver Rx) at 100 MHz, with observed latencies of 170 ns for Tx and 160 ns for Rx, resulting in an overall throughput of roughly 123 bps. encryption, ensures freshness and reduces replay attacks, thereby overcoming the limitations of conventional freshness mechanisms. In order to accomplish this, we suggest a hardware architecture that is predicated on an FPGA (Arty 7A), which has been verified by our simulation results to provide high throughput and minimal payload. The real-time hardware implementation effectively limits replay attacks and protects data integrity and authenticity. Furthermore, the message counter and sequences with SHA-512 are integrated as part of the improved security method for CAN XL. Although the default security measures of CAN XL are still in the process of evolving, our method guarantees the freshness of messages by utilizing a cross-correlation function to maintain them within a specified time frame, thereby preventing replay attacks. This necessitated modifications to FPGA based architecture, which was validated using MATLAB and VHDL. This demonstrated its superiority over CAN FD's security measures in effectively mitigating replay and denial-of-service attacks. As contributions of this work introduces a non-linear sequence function to increase the unpredictability of freshness values, thereby preventing adversaries from predicting communication sequences or deducing message patterns. This method eliminates the necessity of transmitting freshness messages at predetermined intervals and enables multiple nodes to maintain unique freshness values, thereby further reducing vulnerabilities. To further reduce resource utilization, a lightweight XOR-based authentication tag was designed and integrated. This 1-byte tag combines the FV, one ciphertext byte, and a keyschedule byte to provide an integrity indicator with minimal hardware overhead. Despite its small size, the tag maintained high randomness (entropy ≈ 7.26 bits) and demonstrated 100% replay resistance during simulation, confirming that the underlying FV entropy ensures message integrity and uniqueness even under constrained hardware conditions. Our FPGA-in-the-loop (FIL) validation guarantees the real-time testing of cryptographic protocols in a hardware-accelerated environment, thereby facilitating the practical deployment of the security architecture for real-time embedded systems. In order to verify the protocol's robustness, we implement replay attacks that illustrate effective threat mitigation and protection. | |
| dc.format | Text | |
| dc.identifier.uri | https://hdl.handle.net/10323/22203 | |
| dc.relation.department | Electrical and Computer Engineering | |
| dc.title | Can Network Security Protocol of Autonomous Vehicle Based on FPGA in the Loop |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Lagnf_oakland_0446E_10604.pdf
- Size:
- 3.89 MB
- Format:
- Adobe Portable Document Format