{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T19:27:02Z","timestamp":1783711622929,"version":"3.55.0"},"reference-count":38,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T00:00:00Z","timestamp":1632873600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation","award":["1738662"],"award-info":[{"award-number":["1738662"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["J. Emerg. Technol. Comput. Syst."],"published-print":{"date-parts":[[2022,1,31]]},"abstract":"<jats:p>Within vehicles, the Controller Area Network (CAN) allows efficient communication between the electronic control units (ECUs) responsible for controlling the various subsystems. The CAN protocol was not designed to include much support for secure communication. The fact that so many critical systems can be accessed through an insecure communication network presents a major security concern. Adding security features to CAN is difficult due to the limited resources available to the individual ECUs and the costs that would be associated with adding the necessary hardware to support any additional security operations without overly degrading the performance of standard communication. Replacing the protocol is another option, but it is subject to many of the same problems. The lack of security becomes even more concerning as vehicles continue to adopt smart features. Smart vehicles have a multitude of communication interfaces an attacker could exploit to gain access to the networks. In this work, we propose a security framework that is based on physically unclonable functions (PUFs) and lightweight cryptography (LWC). The framework does not require any modification to the standard CAN protocol while also minimizing the amount of additional message overhead required for its operation. The improvements in our proposed framework result in major reduction in the number of CAN frames that must be sent during operation. For a system with 20 ECUs, for example, our proposed framework only requires 6.5% of the number of CAN frames that is required by the existing approach to successfully authenticate every ECU.<\/jats:p>","DOI":"10.1145\/3442443","type":"journal-article","created":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T19:16:42Z","timestamp":1632943002000},"page":"1-18","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Fortifying Vehicular Security through Low Overhead Physically Unclonable Functions"],"prefix":"10.1145","volume":"18","author":[{"given":"Carson","family":"Labrado","sequence":"first","affiliation":[{"name":"University of Kentucky, Lexington, KY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Himanshu","family":"Thapliyal","sequence":"additional","affiliation":[{"name":"University of Kentucky, Lexington, KY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Saraju P.","family":"Mohanty","sequence":"additional","affiliation":[{"name":"University of North Texas, Denton, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,9,29]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2905055.2905328"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.3390\/s17071517"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74735-2_31"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the 18th International Conference on Sciences and Techniques of Automatic Control and Computer Engineering (STA\u201917)","author":"Buttigieg R.","unstructured":"R. Buttigieg , M. Farrugia , and C. Meli . 2017. Security issues in controller area networks in automobiles . In Proceedings of the 18th International Conference on Sciences and Techniques of Automatic Control and Computer Engineering (STA\u201917) . 93\u201398. R. Buttigieg, M. Farrugia, and C. Meli. 2017. Security issues in controller area networks in automobiles. In Proceedings of the 18th International Conference on Sciences and Techniques of Automatic Control and Computer Engineering (STA\u201917). 93\u201398."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2849324"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOMSTD.2017.1700015"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2016.7448561"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-48797-6_10"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11241-007-9012-7"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517968.2517972"},{"key":"e_1_2_1_12_1","volume-title":"Cryptology and Network Security","author":"Groza Bogdan","unstructured":"Bogdan Groza , Stefan Murvay , Anthony van Herrewege , and Ingrid Verbauwhede . 2012. LiBrA-CAN: A lightweight broadcast authentication protocol for controller area networks . In Cryptology and Network Security . Springer Berlin , 185\u2013200. Bogdan Groza, Stefan Murvay, Anthony van Herrewege, and Ingrid Verbauwhede. 2012. LiBrA-CAN: A lightweight broadcast authentication protocol for controller area networks. In Cryptology and Network Security. Springer Berlin, 185\u2013200."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.5555\/2033036.2033053"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ReConFig.2010.24"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-019-00677-x"},{"key":"e_1_2_1_16_1","volume-title":"Information Technology \u2013 Lightweight Cryptography \u2013 Part 2: Block ciphers. Standard","author":"IEC","unstructured":"ISO\/ IEC 29192-2:2019. 2019. Information Technology \u2013 Lightweight Cryptography \u2013 Part 2: Block ciphers. Standard . International Organization for Standardization , Geneva, CH . ISO\/IEC 29192-2:2019. 2019. Information Technology \u2013 Lightweight Cryptography \u2013 Part 2: Block ciphers. Standard. International Organization for Standardization, Geneva, CH."},{"key":"e_1_2_1_17_1","volume-title":"Information Technology \u2013 Security Techniques \u2013 Lightweight Cryptography \u2013 Part 5: Hash-functions. Standard","author":"IEC","unstructured":"ISO\/ IEC 29192-5:2016. 2016. Information Technology \u2013 Security Techniques \u2013 Lightweight Cryptography \u2013 Part 5: Hash-functions. Standard . International Organization for Standardization , Geneva, CH . ISO\/IEC 29192-5:2016. 2016. Information Technology \u2013 Security Techniques \u2013 Lightweight Cryptography \u2013 Part 5: Hash-functions. Standard. International Organization for Standardization, Geneva, CH."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2015.7389805"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.mejo.2019.104605"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCNC.2017.7876236"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.34"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3390771"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.3390\/s19183905"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.3390\/app10196692"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1873548.1873557"},{"key":"e_1_2_1_26_1","volume-title":"Black Hat USA 2015","author":"Miller Charlie","year":"2015","unstructured":"Charlie Miller and Chris Valasek . 2015 . Remote exploitation of an unaltered passenger vehicle . Black Hat USA 2015 (2015), 91. Charlie Miller and Chris Valasek. 2015. Remote exploitation of an unaltered passenger vehicle. Black Hat USA 2015 (2015), 91."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCE.2019.2928577"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3355402.3355414"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2017.2665968"},{"key":"e_1_2_1_30_1","volume-title":"Garcia","author":"Radu Andreea-Ina","year":"2016","unstructured":"Andreea-Ina Radu and Flavio D . Garcia . 2016 . LeiA: A lightweight authentication protocol for CAN. In Computer Security \u2013 ESORICS 2016, Ioannis Askoxylakis, Sotiris Ioannidis, Sokratis Katsikas, and Catherine Meadows (Eds.). Springer International Publishing , 283\u2013300. Andreea-Ina Radu and Flavio D. Garcia. 2016. LeiA: A lightweight authentication protocol for CAN. In Computer Security \u2013 ESORICS 2016, Ioannis Askoxylakis, Sotiris Ioannidis, Sokratis Katsikas, and Catherine Meadows (Eds.). Springer International Publishing, 283\u2013300."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.25046\/aj0203165"},{"key":"e_1_2_1_32_1","unstructured":"The National Institute of Standards and Technology (NIST) Computer Security Resource Center (CSRC). 2017. Lightweight Cryptography. Retrieved from https:\/\/csrc.nist.gov\/projects\/lightweight-crypt ography.  The National Institute of Standards and Technology (NIST) Computer Security Resource Center (CSRC). 2017. Lightweight Cryptography. Retrieved from https:\/\/csrc.nist.gov\/projects\/lightweight-crypt ography."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2018.1701047"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the IEEE International Conference on Consumer Electronics (ICCE\u201919)","author":"Uddin Mesbah","unstructured":"Mesbah Uddin , Aysha S. Shanta , Md Badruddoja Majumder , Md Sakib Hasan , and Garrett S. Rose . 2019. Memristor crossbar PUF based lightweight hardware security for IoT . In Proceedings of the IEEE International Conference on Consumer Electronics (ICCE\u201919) . IEEE, 1\u20134. Mesbah Uddin, Aysha S. Shanta, Md Badruddoja Majumder, Md Sakib Hasan, and Garrett S. Rose. 2019. Memristor crossbar PUF based lightweight hardware security for IoT. In Proceedings of the IEEE International Conference on Consumer Electronics (ICCE\u201919). IEEE, 1\u20134."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.3390\/electronics8010052"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.5555\/2691365.2691419"},{"key":"e_1_2_1_37_1","first-page":"2","article-title":"A practical wireless attack on the connected car and security protocol for in-vehicle CAN","volume":"16","author":"Woo S.","year":"2015","unstructured":"S. Woo , H. J. Jo , and D. H. Lee . 2015 . A practical wireless attack on the connected car and security protocol for in-vehicle CAN . IEEE Trans. Intell. Transport. Syst. 16 , 2 (Apr. 2015), 993\u20131006. S. Woo, H. J. Jo, and D. H. Lee. 2015. A practical wireless attack on the connected car and security protocol for in-vehicle CAN. IEEE Trans. Intell. Transport. Syst. 16, 2 (Apr. 2015), 993\u20131006.","journal-title":"IEEE Trans. Intell. Transport. Syst."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSPCC.2016.7753631"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2019.2926192"}],"container-title":["ACM Journal on Emerging Technologies in Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442443","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3442443","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3442443","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:36Z","timestamp":1750195476000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3442443"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,29]]},"references-count":38,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,1,31]]}},"alternative-id":["10.1145\/3442443"],"URL":"https:\/\/doi.org\/10.1145\/3442443","relation":{},"ISSN":["1550-4832","1550-4840"],"issn-type":[{"value":"1550-4832","type":"print"},{"value":"1550-4840","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,29]]},"assertion":[{"value":"2020-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-09-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}