IP Library Granted Patent US 12,556,400
Granted Patent B2
US 12,556,400 · App. 18/785,735 · Granted Feb 17, 2026

Secure controller area network in vehicles

Inventors: Kumaresh Kalaiselvam (Peachtree City, GA); Muthuganesan Muthiah (Peachtree City, GA)
Assignee: Panasonic Automotive Systems America, LLC.
H04L9/3242H04L9/3234H04L9/3271H04L12/40H04L2012/40215H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,400
App. No.
18/785,735
Granted
Feb 17, 2026
Kind
B2
Abstract

A method includes generating a first key with a first electronic controller unit (ECU) dedicated to control a first electronic component of the vehicle in response to receiving power at the first ECU, sending the first key to a second ECU dedicated to its own respective electronic component, organizing a second key received from the second ECU in a message table to correspond to a second CAN ID of the second ECU, composing a secure CAN message including a first CAN ID and a message payload, encrypting a first CAN ID portion of the secure CAN message using the first key, sending the secure CAN message to the second ECU, receiving a second secure CAN message from the second ECU, and decrypting an encrypted CAN ID portion of the second secure CAN message using the second key stored in the message table associated with the second CAN ID.

Claims (39)

1 . A system for implementing a secure controller area network (CAN) in a vehicle, comprising:

a first electronic controller unit (ECU) dedicated to control a first electronic component of the vehicle, wherein the first ECU comprises a first CAN identification (ID) and a message table associated with a second CAN ID of a second ECU dedicated to control a second electronic component of the vehicle distinct from the first electronic component of the vehicle, wherein the message table comprises the first CAN ID prior to power up of the vehicle, the first ECU configured to:

in response to receiving power, generate and send a first key to the second ECU, and receive a second key from the second ECU, and store the second key in the message table associated with the second CAN ID, wherein the first ECU sends the second ECU the first key prior to the first ECU sending any other messages;

encrypt a CAN ID portion of a message using the first key to generate a first secure CAN message comprising an encrypted CAN ID portion and an unencrypted message payload portion;

transmit the first secure CAN message to the second ECU;

receive a second secure CAN message from the second ECU; and

decrypt an encrypted CAN ID portion of the second secure CAN message using the second key stored in the message table associated with the second CAN ID.

2 . The system of claim 1 , wherein the encryption of the CAN ID portion of the second secure CAN message comprises a logical exclusive OR (xOR) cipher of the second CAN ID and the second key.

3 . The system of claim 2 , wherein the decryption of the encrypted CAN ID portion of the second secure CAN message by the first ECU comprises removal of the xOR cipher by using the second key stored in the message table.

4 . The system of claim 1 , wherein the encryption of the CAN ID portion of the first secure CAN message comprises a logical exclusive OR (xOR) cipher of the first CAN ID and the first key.

5 . The system of claim 1 , wherein the first ECU comprises a key regeneration module, implemented by a processor, that generates a new first key upon each power up of the vehicle.

6 . The system of claim 1 , wherein the first ECU comprises a key regeneration module, implemented by a processor, that generates a new first key upon receipt of a key generation request.

7 . The system of claim 1 , wherein the first ECU sends the second ECU the first key using advanced encryption standard (AES) encryption.

8 . The system of claim 1 , wherein the unencrypted message payload portion is distinct from the CAN ID portion of the first secure CAN message.

9 . A method for implementing a secure controller area network (CAN) in a vehicle comprising:

generating a first key with a first electronic controller unit (ECU) dedicated to control a first electronic component of the vehicle in response to receiving power at the first ECU;

sending the first key to a second ECU dedicated to its own respective electronic component, wherein the first ECU sends the second ECU the first key prior to the first ECU sending any other messages;

organizing a second key received from the second ECU in a message table to correspond to a second CAN ID of the second ECU;

composing a secure CAN message comprising a first CAN ID and a message payload, wherein the message table comprises the first CAN ID prior to power up of the vehicle;

encrypting a first CAN ID portion of the secure CAN message using the first key to generate an encrypted CAN ID portion;

sending, to the second ECU, the secure CAN message comprising the encrypted CAN ID portion and an unencrypted message payload portion of the message payload;

receiving a second secure CAN message from the second ECU; and

decrypting an encrypted CAN ID portion of the second secure CAN message using the second key stored in the message table associated with the second CAN ID.

10 . The method of claim 9 , wherein the message table organizes a unique CAN ID for each of a distributed plurality of electronic controller units preset prior to vehicle powering on.

11 . The method of claim 9 , wherein the encryption of the first CAN ID portion of the secure CAN message comprises a logical exclusive OR (xOR) cipher of the first CAN ID and the first key.

12 . The method of claim 9 , wherein the decryption of the encrypted CAN ID portion of the second secure CAN message comprises removing a xOR cipher of the second secure CAN message by using the second key stored in the message table.

13 . The method of claim 9 , wherein the first ECU comprises a key regeneration module that generates a new key upon each power up of the vehicle.

14 . The method of claim 9 , wherein the first ECU comprises a key regeneration module that generates a new key upon receipt of a key generation request.

15 . A tangible, non-transitory, computer-readable medium comprising instructions that, when executed by a processor, implements a secure controller area network (CAN) in a vehicle, the instructions to direct the processor to:

generate a first key in response to receiving power;

send, prior to sending any other messages, the first key to a second ECU dedicated to its own respective electronic component;

organize a second key received from the second ECU in a message table to correspond to the second ECU;

compose a first secure CAN message comprising a first CAN ID portion and a message payload portion, wherein the message table comprises the first CAN ID portion prior to power up of the vehicle;

encrypt the first CAN ID portion of the first secure CAN message using the first key to generate an encrypted first CAN ID portion;

send, to the second ECU, the first secure CAN message comprising the encrypted CAN ID portion and an unencrypted message payload portion; and

decrypt an encrypted CAN ID portion of a received second secure CAN message from the second ECU with the received second key in the message table.

16 . The tangible, non-transitory, computer-readable medium of claim 15 , wherein the message table organizes a unique CAN ID for each of a distributed plurality of electronic controller units preset prior to vehicle powering on.

17 . The tangible, non-transitory, computer-readable medium of claim 15 , wherein the encryption of the first CAN ID portion of the received second secure CAN message comprises a logical exclusive OR (xOR) cipher of the first CAN ID and the first key.

18 . The tangible, non-transitory, computer-readable medium of claim 15 , wherein the decryption of the received second secure CAN message comprises: removing a xOR cipher of the received second secure CAN message by using the received second key stored in the message table.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE SUPPORTIVE DOCUMENTS PREVIOUSLY RECORDED ON REEL 72222 FRAME 267. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 23, 2025
From: PANASONIC CORPORATION OF NORTH AMERICA
To: PANASONIC AUTOMOTIVE SYSTEMS AMERICA, LLC.
Reel/Frame 072930/0871 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2025
From: PANASONIC CORPORATION OF NORTH AMERICA
To: PANASONIC AUTOMOTIVE SYSTEMS AMERICA, LLC
Reel/Frame 072222/0267 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2024
From: KALAISELVAM, KUMARESH; MUTHIAH, MUTHUGANESAN
To: PANASONIC AUTOMOTIVE SYSTEMS COMPANY OF AMERICA, DIVISION OF PANASONIC CORPORATION OF NORTH AMERICA
Reel/Frame 068176/0769 →
Continuity (3)
Continuation 16585491 · Sep 27, 2019
Provisional Application 62740536 · Oct 3, 2018
Related Publication 20240388441A1 · Nov 21, 2024
References Cited (22)
US 9923722B2 · Nanjundappa · 2018 [cited by examiner]
US 10218499B1 · El Idrissi · 2019 [cited by examiner]
US 10419408B1 · Herzberg · 2019 [cited by examiner]
US 20060115085A1 · Iwamura · 2006 [cited by examiner]
US 20140181521A1 · Hemphill · 2014 [cited by examiner]
US 20160315766A1 · Ujiie · 2016 [cited by examiner]
US 20170093659A1 · Elend · 2017 [cited by examiner]
US 20170134164A1 · Haga · 2017 [cited by examiner]
US 20170353302A1 · Fernandez · 2017 [cited by examiner]
US 20180004964A1 · Litichever · 2018 [cited by examiner]
US 20180091525A1 · Ichihara · 2018 [cited by examiner]
US 20180359226A1 · Martinez · 2018 [cited by examiner]
US 20200044842A1 · Usui · 2020 [cited by examiner]
US 20210184844A1 · Okano · 2021 [cited by examiner]
CN 103404112A · 2013 [cited by examiner]
CN 105745862A · 2016 [cited by examiner]
CN 107683583A · 2018 [cited by examiner]
CN 108781164A · 2018 [cited by examiner]
CN 110785961B · 2022 [cited by examiner]
JP 2011188176A · 2011 [cited by examiner]
Junko Takahashi, Masashi Tanaka, Hitoshi Fuji, Toshio Narita, Shunsuke Matsumoto and Hiroki Sato; (Abnormal Vehicle Behavior Induced Using Only Fabricated Informative CAN Messages); pp. 4; IEEE (Year: 2018). [cited by examiner]
Liis Jaks; (Security Evaluation of the Electronic Control Unit Software Update Process); pp. 94; School of Information and Communication Technology Kungliga Tekniska Hgskolan; Stockholm (Year: 2014). [cited by examiner]