CAN FD (CAN with Flexible Data Rate)
CAN FD extends classic CAN to 64 data bytes and a faster data phase. How the DLC, BRS bit and bit timing work and what changes for diagnostics and fuzzing.
Updated This page as Markdown
In short
CAN FD (CAN with Flexible Data Rate) is the extension of CAN in ISO 11898-1:2015 that carries up to 64 data bytes per frame and can switch to a higher bitrate for the data phase. Arbitration still runs at the nominal rate, so CAN FD and classic CAN share the same identifier logic. For diagnostics, ISO-TP gets larger frames; for security testing, longer payloads and a second set of bit timing mean more parser paths and more ways to get the bench setup wrong.
What is CAN FD?
CAN FD keeps the arbitration of classic CAN and changes the rest of the frame. Three control bits matter: FDF marks the frame as CAN FD, BRS (bit rate switch) tells receivers that the data phase runs at the faster data bitrate, and ESI signals that the sender is error passive. The data field grows to 64 bytes, and the DLC values 9 to 15 no longer mean 8 bytes but 12, 16, 20, 24, 32, 48 and 64. The CRC grows to 17 or 21 bits and includes a stuff bit count.
A CAN FD frame on the bench in candump notation: 7E0##1 followed by up to 64 data bytes, where ##1 means FD with BRS set. Payload lengths between the valid sizes are padded, so a 30-byte message travels in a 32-byte frame.
Where is it defined?
ISO 11898-1:2015 defines CAN FD alongside classic CAN, including the frame format, CRC and the two bit timing configurations. ISO 15765-2 adds the CAN FD variants of ISO-TP: single frames with an escape byte (00 LL) for payloads above 7 bytes, and consecutive frames up to 64 bytes.
What it means in practice
More bytes per frame means more input per frame. Receivers that were written for 8-byte frames and later moved to CAN FD sometimes copy the full DLC into a buffer sized for less. ISO-TP over CAN FD has its own single-frame format, so a stack can be correct on classic CAN and wrong on FD. SecOC also benefits: the larger frame leaves room for a longer MAC, which classic CAN often cannot spare.
The most common bench problem is timing. Nominal bitrate, data bitrate and both sample points have to match the network; a mismatch shows up as error frames only in the data phase, which is confusing because arbitration looks fine. Interfaces also have to be set to ISO CAN FD, not the older non-ISO variant.
How AutoST tests it
AutoST supports CAN FD with configurable data bitrate and sample point on SocketCAN and Vector XL interfaces. UDS enumeration and fuzzing run over ISO-TP on CAN FD, and the CAN fuzzing engine sends random FD frames on arbitration identifiers from your DBC, checking liveness with TesterPresent after each iteration.
Common misunderstandings
CAN FD is not faster at arbitration; only the data phase speeds up. It is also not secure by itself: like classic CAN it has no sender authentication. And a successful test on classic CAN does not cover the FD path of the same ECU.
FAQ
Frequently asked questions
Can classic CAN and CAN FD nodes share a bus?
Only if the classic nodes are FD-tolerant. A classic CAN controller that is not FD-tolerant treats an FD frame as a format error and sends an error frame, which disturbs the whole bus. In mixed networks FD traffic is therefore often kept on separate segments behind a gateway.
What is the difference between ISO CAN FD and non-ISO CAN FD?
The original Bosch CAN FD lacked the stuff bit counter in the CRC field that ISO 11898-1:2015 added. The two are not compatible, and many interfaces let you choose. Vehicles today use ISO CAN FD.
What data bitrates are typical?
Arbitration usually stays at 500 kbit/s, and the data phase commonly runs at 2 Mbit/s, sometimes higher. The data phase sample point is set separately from the nominal one and has to match the network.
Sources
Related pages
- GlossaryCAN Bus (Controller Area Network)CAN (ISO 11898) is the broadcast bus most ECUs share: identifiers, arbitration, error handling. Why any node can send any frame and what that means for security testing.
- GlossaryISO-TP (ISO 15765-2)ISO-TP (ISO 15765-2) splits UDS messages into CAN frames: single, first, consecutive and flow-control frames. How it works and why malformed frames crash ECUs.
- GlossarySecOC (Secure Onboard Communication)SecOC is the AUTOSAR mechanism that authenticates in-vehicle messages with a MAC and a freshness value. How it works on CAN and what a bus test can check.
- Free toolsISO-TP Frame CalculatorHow many CAN frames does a UDS message need? Enter the payload length, pick classic CAN or CAN FD and flow control: first, consecutive and flow-control frames and timing.
- InsightsChoosing a CAN interface for ECU security testingWhat matters in a CAN interface for security testing: SocketCAN vs Vector XL, CAN FD, timing control and error-frame visibility, and how to pick one for your bench.
- PlatformSpeaks the buses your ECUs speak.AutoST supports CAN, CAN FD, ISO-TP, UDS, XCP, CCP, DoIP and SOME/IP, with SocketCAN, Vector XL and comma.ai Panda adapters on Windows and Linux.
