What is CanShield?
CANShield is a Qt-based tool for CAN/CAN-FD monitoring, ISO-TP/UDS automation, and tool-side cybersecurity: encryption/decryption, MAC generation/validation, secure flash, and secure diagnosis. Can work offline with PCAN-USB and CANable 2.0 using software crypto (OpenSSL).
CANShield accelerates ECU bring-up, diagnostics, and secured updates. It combines a low-latency CAN/CAN-FD monitor/logger with ISO-TP transport, UDS automation (0x10/0x27/0x29), and tool-side cryptography for secure communication exercises, secure flash, and secure diagnosis. It runs fully offline, maintains audit-quality traces, and integrates cleanly with PCAN-USB and CANable 2.0.
Live CAN/CAN-FD observability, automated UDS, and a built-in cybersecurity engine—built for lab, bench, and HIL.

USP — Tool-side cybersecurity & cryptography
- Encryption / decryption (software crypto via OpenSSL) for exercising secure communication flows during testing.
- Message authentication with AES-CMAC: generate and verify MACs; reject on mismatch with clear reasons.
- Freshness/counters: configurable 32-bit counters and validation rules to mirror ECU expectations.
- Secure flash support: package signing (RSA-2048 or ECDSA-P256), integrity checks, post-flash verification.
- Secure diagnosis: guided panels for 0x10 (Session Control), 0x27 (Security Access seed/key), and 0x29 (Authentication).
- Evidence bundles: export artifacts (frames, timing, MAC/signature outcomes) for audit and reproducibility.
(Tool-side crypto is for testing/validation; align schemes and keys with ECU/security policy.)
What it is
- Desktop application (Qt)
Real-time bus view, filters, timelines, and automation panels for flashing, diagnosis, and security exercises. - Transport & protocols
ISO-TP (normal addressing; Single-Frame today, Full multi-frame in active development), UDS 0x10/0x27/0x29 with a customizable request queue. - Security engine (software crypto)
OpenSSL-based AES-CMAC, RSA/ECC signature verify, counters/freshness handling. - Safe by design
Separation of capture vs actuation, validation prompts for risky actions, comprehensive logging for audit and replay.
Platforms & interfaces
- OS: Windows and Linux (Qt 5.15+).
- Hardware: PCAN-USB, CANable 2.0.
- Buses: Classical CAN & CAN-FD (payloads up to 64 bytes).
- Modes: Connected hardware and loopback for development.
Core capabilities
Live CAN/CAN-FD monitor & logger
- High-rate capture with hardware timestamps (where supported).
- Direction-aware Rx/Tx panes and a unique CAN-ID table (ID, type, DLC, latest data, count, frequency/cycle time).
ISO-TP transport
- Single-Frame (SF) encode/decode for quick diagnostics.
- Full multi-frame (FF/CF) with Flow Control (configurable BS, STmin)
- Clear diagnostics on sequence errors, timeouts, and PCI (Protocol Control Information) mismatches.
UDS automation (ISO 14229 over ISO-TP)
- Panels for 0x10, 0x27, 0x29 with step-by-step guidance.
- Custom UDS queue: chain requests and auto-advance on positive responses; capture NRCs with hints.
- Timing control: P2/P2* timers, retry policies, response guards.
Secure communication
- Hybrid flow: RSA-encrypted session key + AES-CMAC authenticated messages.
- Message layout: [4B Counter] + [Plaintext or Ciphertext] + [16B CMAC].
- Keys from file or generated; roles and policies configurable.
- Works in loopback and with PCAN-USB
Secure flash
- Firmware packaging with metadata and signature (RSA-2048 / ECDSA-P256).
- Chunked transfers with progress, retry, and resume; post-flash checksum/hash verify and ECU ACK logging.
- Signature scheme is selectable—align with ECU acceptance criteria.
Outcomes
- Faster ECU bring-up with fewer manual steps and clearer traces.
- Repeatable tests via profiles and scripted queues.
- Traceable security operations (seed/key, auth, flash) with evidence packages.
- Flashing and diagnostics using ISO 14229 UDS services (sessions 0x10/0x11, Security Access 0x27, programming 0x34/0x36/0x37, Authentication 0x29 are supported)
Want to see CANShield on your bench? Request a live demo or pilot with your ECU, channel settings, and target workflows. We’ll tailor a focused session to your acceptance criteria and lab environment.