Within vehicles, the Controller Area Network (CAN) allows efficient\ncommunication between the electronic control units (ECUs) responsible for\ncontrolling the various subsystems. The CAN protocol was not designed to\ninclude much support for secure communication. The fact that so many critical\nsystems can be accessed through an insecure communication network presents a\nmajor security concern. Adding security features to CAN is difficult due to the\nlimited resources available to the individual ECUs and the costs that would be\nassociated with adding the necessary hardware to support any additional\nsecurity operations without overly degrading the performance of standard\ncommunication. Replacing the protocol is another option, but it is subject to\nmany of the same problems. The lack of security becomes even more concerning as\nvehicles continue to adopt smart features. Smart vehicles have a multitude of\ncommunication interfaces would an attacker could exploit to gain access to the\nnetworks. In this work we propose a security framework that is based on\nphysically unclonable functions (PUFs) and lightweight cryptography (LWC). The\nframework does not require any modification to the standard CAN protocol while\nalso minimizing the amount of additional message overhead required for its\noperation. The improvements in our proposed framework results in major\nreduction in the number of CAN frames that must be sent during operation. For a\nsystem with 20 ECUs for example, our proposed framework only requires 6.5% of\nthe number of CAN frames that is required by the existing approach to\nsuccessfully authenticate every ECU.\n