DoIP (Diagnostics over Internet Protocol)
DoIP (ISO 13400) carries UDS over Ethernet: vehicle discovery, routing activation and diagnostic messages on port 13400. How it works and where gateways go wrong.
Updated This page as Markdown
In short
DoIP (Diagnostics over Internet Protocol) is the transport defined in ISO 13400-2 that carries UDS over Ethernet and IP. A tester finds the vehicle over UDP, opens a TCP connection to port 13400, activates routing with its source address and then sends diagnostic messages addressed to a logical ECU address. A DoIP entity, usually a central gateway, forwards them to ECUs on CAN or Ethernet. The gateway routing decision is a security boundary and is often weaker than intended.
What is DoIP?
DoIP is a thin header on top of TCP and UDP that carries UDS between a tester and a vehicle. Every DoIP message starts with an 8-byte generic header: protocol version, its inverse, a 2-byte payload type and a 4-byte payload length. The important payload types are 0x0001 vehicle identification request, 0x0004 vehicle announcement, 0x0005 routing activation request, 0x0006 routing activation response, 0x8001 diagnostic message and 0x8002/0x8003 positive and negative acknowledgement.
A routing activation request from tester address 0x0E00 looks like 02 FD 00 05 00 00 00 07 0E 00 00 00 00 00 00: version 02, inverse FD, type 0005, length 7, source address, activation type 00, four reserved bytes. After a positive response, 02 FD 80 01 00 00 00 07 0E 00 10 01 22 F1 90 sends ReadDataByIdentifier for the VIN to the ECU with logical address 0x1001.
Where is it defined?
ISO 13400-2 defines the protocol: header, payload types, vehicle discovery, routing activation, alive check, diagnostic messages and their acknowledgement codes. ISO 13400-3 covers the wired physical layer and the activation line on the diagnostic connector. ISO 14229 defines the UDS content, and ISO 14229-5 maps UDS onto IP.
What it means in practice
DoIP moves diagnostics onto a network. The gateway that terminates DoIP decides which target addresses a tester may reach, from which source address and after which activation type. That decision is where we regularly find problems: gateways that route to ECUs that should be blocked from the external port, routing activation accepted for any source address, or diagnostics available on interfaces other than the diagnostic connector.
On a vehicle-level penetration test the DoIP gateway was the quickest route from the OBD connector to ECUs that were well protected on their own CAN bus. The UDS findings are the same as on CAN; the reach is larger.
How AutoST tests it
AutoST performs vehicle discovery over UDP, handles routing activation and then runs the transport-generic UDS engine over the DoIP link: session and service enumeration, DID and routine scanning and SecurityAccess checks. It also tests DoIP gateway routing, so you see which logical addresses answer through the gateway and which should not.
Common misunderstandings
DoIP is not a different diagnostic protocol; it is a transport for UDS. A positive routing activation is not authentication unless the OEM adds a check behind activation type 0xE0 or uses TLS. And protecting an ECU on CAN does not protect it when a gateway forwards DoIP traffic to it.
FAQ
Frequently asked questions
Which ports does DoIP use?
UDP and TCP port 13400. Vehicle identification and announcements use UDP, diagnostic communication uses TCP. The 2019 edition of ISO 13400-2 also describes a TLS-secured variant on a separate port.
What is routing activation?
The first message on a new TCP connection. The tester sends its source address and an activation type (payload type 0x0005), and the DoIP entity answers with a response code (payload type 0x0006); 0x10 means routing is active. Only then are diagnostic messages forwarded.
Is DoIP more secure than diagnostics on CAN?
Not by default. DoIP adds addressing and routing, not authentication or encryption, unless the TLS variant or an OEM-specific activation check is used. It also makes diagnostics reachable over a network that may connect to more of the vehicle than a single CAN bus.
Sources
Related pages
- GlossaryUDS (Unified Diagnostic Services)UDS (ISO 14229) is the diagnostic protocol of most automotive ECUs: sessions, services, DIDs and SecurityAccess. What it defines and why it is the first attack surface.
- GlossaryGateway ECU (Central Gateway)The gateway ECU connects the vehicle networks and decides which messages cross between them. Why it is the key security boundary and how its diagnostic routing fails.
- GlossarySOME/IP (Scalable service-Oriented MiddlewarE over IP)SOME/IP is the AUTOSAR middleware for services on automotive Ethernet: header, methods, events and service discovery. What it is and why exposed services are a finding.
- InsightsDoIP test setup: from Ethernet link to UDS over IPA practical DoIP bench setup: addressing, vehicle discovery, routing activation and running UDS over IP, with the byte-level exchanges you need to get a link up.
- PlatformFollow the ECU onto the network.AutoST tests automotive Ethernet: UDS over IP, DoIP routing activation and vehicle discovery, and SOME/IP service discovery with service and method mapping.
