Executive Takeaway

The architecture cockpit presents a working system/security allocation for the Electric Clutch Actuator ECU. It is strong enough for proposal review and planning, but not final baseline approval because customer decisions remain open for diagnostics, update, PKI, secure communication, TARA, and responsibility ownership.

1. System Snapshot

System NameElectric Clutch Actuator (ECA) Control ECU - TRATON GW AMT Gearbox PlatformWorking
Vehicle ContextTRATON GW Automated Manual Transmission (AMT) Gearbox PlatformConfirmed
System TypeSafety-related drivetrain actuator ECU with integrated power-electronics actuation, carrying an automotive cybersecurity engineering scope (ISO/SAE 21434-style concept and TARA input).Inferred
Requirement Count1076Confirmed
Feature Count18Confirmed
Interface Count10Confirmed
Security Capability Count13Confirmed
P1 Decision Count10Open
Traceability GateWARN - Customer Clarification NeededWARN
Customer ReadinessReady for customer clarification workshopWorkshop
OCR StatusfalseConfirmed
PDF Downstream AnalysisfalseConfirmed

2. Product Identity

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

ItemValueConfidenceEvidence
Working system nameElectric Clutch Actuator (ECA) Control ECU - TRATON GW AMT Gearbox PlatformMediumsystem_identity.md
Vehicle platform contextTRATON GW Automated Manual Transmission (AMT) Gearbox PlatformHigh3299216_1.md page 3-4
Main controlled functionCAN/PWM-commanded clutch engagement and disengagementHighsystem_identity.md
ECU involvementECA ECU application, boot/update and security servicesHigharchitecture_overview.md
Cybersecurity scopeDiagnostics, update, key/certificate, secure communication and evidence lifecycleMediumsecurity_concept_overview.md

3. One-Screen Architecture

Architecture Cockpit Overview

flowchart LR subgraph Vehicle["Vehicle / drivetrain domain"] Drivetrain["GW AMT drivetrain"] Network["Vehicle network (CAN / PWM)"] end subgraph ECA["ECA ECU domain"] App["Clutch actuation application"] Sec["Security services"] Boot["Bootloader / update logic"] end subgraph Diagnostic["Diagnostic / service domain"] Tester["Diagnostic tester"] end subgraph OEM["OEM backend / security operations domain"] Backend["Update and evidence backend"] PKI["Key and certificate provisioning"] SecOps["Security operations"] end subgraph Supplier["Supplier engineering domain"] Engineering["Supplier ALM / CI / evidence"] end Drivetrain --> Network Network <-->|commands, status, freshness| App Tester -->|authenticated UDS| Sec Backend -->|signed software / IVD| Boot PKI -->|trust material| Sec Boot --> App Sec --> App App -->|events| SecOps Engineering -->|software and evidence| Backend
Mermaid source
flowchart LR
  subgraph Vehicle["Vehicle / drivetrain domain"]
    Drivetrain["GW AMT drivetrain"]
    Network["Vehicle network (CAN / PWM)"]
  end
  subgraph ECA["ECA ECU domain"]
    App["Clutch actuation application"]
    Sec["Security services"]
    Boot["Bootloader / update logic"]
  end
  subgraph Diagnostic["Diagnostic / service domain"]
    Tester["Diagnostic tester"]
  end
  subgraph OEM["OEM backend / security operations domain"]
    Backend["Update and evidence backend"]
    PKI["Key and certificate provisioning"]
    SecOps["Security operations"]
  end
  subgraph Supplier["Supplier engineering domain"]
    Engineering["Supplier ALM / CI / evidence"]
  end
  Drivetrain --> Network
  Network <-->|commands, status, freshness| App
  Tester -->|authenticated UDS| Sec
  Backend -->|signed software / IVD| Boot
  PKI -->|trust material| Sec
  Boot --> App
  Sec --> App
  App -->|events| SecOps
  Engineering -->|software and evidence| Backend

Vehicle Domain

GW AMT drivetrain, CAN/PWM command path, actuator status and faults.

ECA ECU Domain

Application software, boot/update logic, diagnostics and security services.

Diagnostic Domain

UDS tester, authenticated service sessions, programming and audit path.

OEM Backend Domain

Update, PKI, security operations, approval and residual-risk workflow.

Supplier Engineering Domain

ALM, CI/test, software release, traceability and evidence package.

4. Main System Capabilities

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

CapabilityPurposeMain InterfacesSecurity RelevanceStatus
Clutch Actuation ControlCore actuator controlVehicle Network Interface (CAN)Safety-relevant command/status handlingConfirmed
Vehicle Integration and CAN CommunicationVehicle command/status exchangeVehicle Network Interface (CAN), PWM wake-upMessage authenticity/freshness allocationConfirmed
Secure Diagnostics and Role-Based AccessControlled service and engineering accessDiagnostic Tester InterfacePrivileged access controlInferred
Secure Software Update and FlashMaintain trusted ECU softwareUpdate / Flash Interface, Diagnostic Tester InterfaceSoftware authenticity and integrityInferred
Key and Certificate HandlingTrust-material lifecyclePKI / Provisioning InterfaceRoot of trust for diagnostics, update and secure communicationInferred
Secure Data Transfer / Communication BoundaryProtected security-relevant data exchangeVehicle Network Interface, Secure Data Transfer InterfaceAuthenticity, integrity and freshnessInferred
Security Logging and Event HandlingSecurity evidence and response inputLogging / Event Reporting InterfaceAuditability and incident supportInferred
Cybersecurity Lifecycle and EvidenceApproval-ready security caseSupplier Evidence, OEM Approval InterfaceTraceable residual-risk argumentConfirmed

5. Interfaces and Trust Boundaries

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

InterfaceConnected PartiesData / Control FlowTrust BoundaryProtection NeededStatus
Vehicle Network Interface (CAN)Transmission control / vehicle ECUs -> ECA application softwareCAN demand, PWM wake-up, actuator status and DTCsVehicle network to ECUSignal validation, freshness, authenticity where allocatedRequires Confirmation
Diagnostic Tester InterfaceService / engineering tester -> ECA diagnostic serverUDS requests, Auth 0x29, sessions and programmingExternal service tool to ECUAuthentication, authorization, lockout, rate limiting and auditRequires Confirmation
Software Update / Flash InterfaceProgramming tool or update backend -> Bootloader / update logicSigned packages, IVD data and programming resultsOffboard update source to ECUSignature validation, integrity checks, rollback control and loggingRequires Confirmation
Key and Certificate Provisioning InterfacePKI / provisioning authority -> ECA security servicesKeys, certificates and trust anchorsTrust authority to ECUProtected storage, certificate validation and lifecycle controlRequires Confirmation
Secure Data Transfer InterfaceVehicle network peers -> ECA security/application servicesSecOC/SDT protected messages, counters and MACsECU-to-ECU data boundaryFreshness, replay protection, MAC verification and discard rulesRequires Confirmation
Security Logging / Event Reporting InterfaceECA ECU -> Backend / security operationsSecurity events, diagnostic attempts and update resultsECU to offboard operationsEvent integrity, retention, access control and privacy treatmentRequires Confirmation
Supplier Development / Evidence InterfaceSupplier ALM / CI / test environment -> Evidence repository and release processRequirements, tests, builds, traceability and release artifactsEngineering environment to evidence baselineAccess control, artifact integrity and audit trailRequires Confirmation
OEM Approval / Evidence InterfaceSupplier security engineering -> TRATON / OEM review boardCybersecurity concept, V&V evidence, risks and decisionsSupplier to OEM governance boundaryControlled evidence handoff and decision loggingRequires Confirmation

6. Security Capability Map

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Security CapabilityProtectsApplied ToEvidence StrengthOpen Decision
Secure Diagnostics and RBACDiagnostic access state and privileged servicesDiagnostic Tester Interface / Diagnostic ServerStrongConfirm final role model and service list
Secure Software UpdateECU software and firmware authenticityBootloader / Update LogicStrongConfirm signing chain, rollback and campaign ownership
Data Authenticity and Integrity VerificationSecurity-relevant vehicle dataVehicle Network / Secure Data Transfer InterfaceModerateConfirm protected signal allocation
Key and Certificate HandlingKeys, certificates and trust anchorsSecurity Services / Hardware Platform / PKIStrongConfirm HSM capability and PKI ownership
Communication Boundary ControlVehicle and offboard interface boundariesExternal Interfaces / Security ServicesModerateConfirm exact boundaries and failure policy
Security LoggingSecurity event evidenceLogging / Event Reporting InterfaceModerateConfirm event set and reporting channel
Vulnerability and Incident HandlingField security postureSecurity Operations / Compliance ProcessStrongConfirm reporting channels and responsibilities
Cybersecurity Evidence and DIAApproval and residual-risk caseEngineering Toolchain / OEM Approval InterfaceStrongConfirm DIA split and authority

7. Requirement Evidence Coverage

Total Requirements1076Markdown-derived baseline
Security Requirements109Cybersecurity category
Architecture Drivers1109Architecture mapping rows
Interface-Related Requirements47Interface category
Assumptions1Tracked, not confirmed
Clarifications64Customer decision queue

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Coverage ItemCountInterpretation
Total Requirements1076Markdown-derived baseline
Security Requirements109Cybersecurity category
Architecture Drivers1109Architecture mapping rows
Interface-Related Requirements47Interface category
Assumptions1Tracked, not confirmed
Clarifications64Customer decision queue

7.1 Supplier System Requirement Coverage

Customer Requirements1076total
Active Requirements966in baseline
Derived Supplier System Requirements74many-to-many
Customer Requirements Mapped to SSRs947derivable mapped
Unmapped Active Requirements0derivable gap
Blocked by Clarification6open
Derivation Coverage %100.0%of derivable

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Coverage ItemCountInterpretation
Customer Requirements1076total
Active Requirements966in baseline
Derived Supplier System Requirements74many-to-many
Customer Requirements Mapped to SSRs947derivable mapped
Unmapped Active Requirements0derivable gap
Blocked by Clarification6open
Derivation Coverage %100.0%of derivable

8. Open Decisions

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

DecisionPriorityQuestionAreaOwner
CQ-BOUNDARY-01P1Confirm the customer decision needed to baseline this requirement item: Note: The vehicle manufacturer and...System boundary / item definitionJoint
CQ-BOUNDARY-04P1Confirm the customer decision needed to baseline this requirement item: Message contents to be agreed with...System boundary / item definitionJoint
CQ-BOUNDARY-06P1Confirm the customer decision needed to baseline this requirement item: Internally stored parameters may be...System boundary / item definitionJoint
CQ-BOUNDARY-16P1Confirm whether this software-update/bootloader item is binding for the ECA ECU baseline or informative gui...System boundary / item definitionJoint
CQ-BOUNDARY-19P1Confirm whether this software-update/bootloader item is binding for the ECA ECU baseline or informative gui...System boundary / item definitionJoint
CQ-BOUNDARY-23P1Confirm whether this software-update/bootloader item is binding for the ECA ECU baseline or informative gui...System boundary / item definitionJoint
CQ-BOUNDARY-24P1Confirm the customer decision needed to baseline this requirement item: 4 Terms, definitions and abbreviati...System boundary / item definitionJoint
CQ-BOUNDARY-28P1Confirm whether this software-update/bootloader item is binding for the ECA ECU baseline or informative gui...System boundary / item definitionJoint
CQ-BOUNDARY-31P1Confirm the customer decision needed to baseline this requirement item: Internal Page 52 (90) Byte Descript...System boundary / item definitionJoint
CQ-BOUNDARY-38P1Confirm the customer decision needed to baseline this requirement item: 3.2 DSC ASN.1 definition DSC_BASE_R...System boundary / item definitionJoint

9. Review Navigation

Architecture cockpit evidence markdown

Architecture Cockpit

1. System Snapshot

MetricValueStatus
System NameElectric Clutch Actuator (ECA) Control ECU - TRATON GW AMT Gearbox PlatformWorking interpretation
Vehicle ContextTRATON GW Automated Manual Transmission (AMT) Gearbox PlatformConfirmed function context
System TypeSafety-related drivetrain actuator ECU with integrated power-electronics actuation, carrying an automotive cybersecurity engineering scope (ISO/SAE 21434-style concept and TARA input).Inferred security scope
Requirement Count1076Markdown-derived
Feature Count18Generated from requirement clusters
Interface Count10Generated from interface model
Security Capability Count13Generated from security model
P1 Decision Count10Open customer decisions
Traceability GateWARN - Customer Clarification NeededDo not force PASS while decisions are open
Customer ReadinessReady for customer clarification workshopWorkshop-ready
OCR StatusfalseMust remain false
PDF Downstream AnalysisfalseMarkdown-derived only

2. Product Identity

ItemValueConfidenceEvidence
Working system nameElectric Clutch Actuator (ECA) Control ECU - TRATON GW AMT Gearbox PlatformMediumsystem_identity.md; function wording in cleaned Markdown
Vehicle platform contextTRATON GW Automated Manual Transmission (AMT) Gearbox PlatformHigh3299216_1.md page 3-4 and system_identity.md
Main controlled functionCAN/PWM-commanded clutch engagement and disengagementHighREQ_SEC_0036; REQ-AUTO-00064; REQ-AUTO-00065; REQ-AUTO-00066; REQ-AUTO-00068; REQ-AUTO-00071; REQ-AUTO-00078; REQ-AUTO-00079 (showing 8 of 108)
ECU involvementECA has its own embedded ECU/control scopeHighREQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023; REQ-AUTO-00011 (showing 8 of 209)
Cybersecurity scopeDiagnostics, update/flash, key/certificate, secure communication, evidence and residual-risk workflowMediumREQ-AUTO-00001; REQ_SEC_0001; REQ_SEC_0002; REQ_SEC_0003; REQ_SEC_0022; REQ-AUTO-00009; REQ_SEC_0023; REQ-AUTO-00011 (showing 8 of 109)

3. One-Screen Architecture

Diagram source: architecture/architecture_cockpit_overview.mmd.

Conclusion: the review baseline is an ECA ECU security architecture with vehicle, diagnostic, OEM/backend and supplier engineering boundaries kept explicit.

4. Main System Capabilities

CapabilityPurposeMain InterfacesSecurity RelevanceStatus
Clutch Actuation ControlCore actuator controlVehicle Network Interface (CAN)Safety-relevant command/status handlingConfirmed
Vehicle Integration and CAN CommunicationVehicle command/status exchangeVehicle Network Interface (CAN), PWM wake-upMessage authenticity/freshness allocationConfirmed
Secure Diagnostics and Role-Based AccessControlled service and engineering accessDiagnostic Tester InterfacePrivileged access controlInferred
Secure Software Update and FlashMaintain trusted ECU softwareUpdate / Flash Interface, Diagnostic Tester InterfaceSoftware authenticity and integrityInferred
Key and Certificate HandlingTrust-material lifecyclePKI / Provisioning InterfaceRoot of trust for diagnostics, update and secure communicationInferred
Secure Data Transfer / Communication BoundaryProtected security-relevant data exchangeVehicle Network Interface, Secure Data Transfer InterfaceAuthenticity, integrity and freshnessInferred
Security Logging and Event HandlingSecurity evidence and response inputLogging / Event Reporting InterfaceAuditability and incident supportInferred
Cybersecurity Lifecycle and EvidenceApproval-ready security caseSupplier Evidence, OEM Approval InterfaceTraceable residual-risk argumentConfirmed

5. Interfaces and Trust Boundaries

InterfaceConnected PartiesData / Control FlowTrust BoundaryProtection NeededStatus
Vehicle Network Interface (CAN)Transmission control / vehicle ECUs -> ECA application softwareCAN demand, PWM wake-up, actuator status and DTCsVehicle network to ECUSignal validation, freshness, authenticity where allocatedRequires Confirmation
Diagnostic Tester InterfaceService / engineering tester -> ECA diagnostic serverUDS requests, Auth 0x29, sessions and programmingExternal service tool to ECUAuthentication, authorization, lockout, rate limiting and auditRequires Confirmation
Software Update / Flash InterfaceProgramming tool or update backend -> Bootloader / update logicSigned packages, IVD data and programming resultsOffboard update source to ECUSignature validation, integrity checks, rollback control and loggingRequires Confirmation
Key and Certificate Provisioning InterfacePKI / provisioning authority -> ECA security servicesKeys, certificates and trust anchorsTrust authority to ECUProtected storage, certificate validation and lifecycle controlRequires Confirmation
Secure Data Transfer InterfaceVehicle network peers -> ECA security/application servicesSecOC/SDT protected messages, counters and MACsECU-to-ECU data boundaryFreshness, replay protection, MAC verification and discard rulesRequires Confirmation
Security Logging / Event Reporting InterfaceECA ECU -> Backend / security operationsSecurity events, diagnostic attempts and update resultsECU to offboard operationsEvent integrity, retention, access control and privacy treatmentRequires Confirmation
Supplier Development / Evidence InterfaceSupplier ALM / CI / test environment -> Evidence repository and release processRequirements, tests, builds, traceability and release artifactsEngineering environment to evidence baselineAccess control, artifact integrity and audit trailRequires Confirmation
OEM Approval / Evidence InterfaceSupplier security engineering -> TRATON / OEM review boardCybersecurity concept, V&V evidence, risks and decisionsSupplier to OEM governance boundaryControlled evidence handoff and decision loggingRequires Confirmation

6. Security Capability Map

Security CapabilityProtectsApplied ToEvidence StrengthOpen Decision
Secure Diagnostics and RBACDiagnostic access state and privileged servicesDiagnostic Tester Interface / Diagnostic ServerStrongConfirm final role model and service list
Secure Software UpdateECU software and firmware authenticityBootloader / Update LogicStrongConfirm signing chain, rollback and campaign ownership
Data Authenticity and Integrity VerificationSecurity-relevant vehicle dataVehicle Network / Secure Data Transfer InterfaceModerateConfirm protected signal allocation
Key and Certificate HandlingKeys, certificates and trust anchorsSecurity Services / Hardware Platform / PKIStrongConfirm HSM capability and PKI ownership
Communication Boundary ControlVehicle and offboard interface boundariesExternal Interfaces / Security ServicesModerateConfirm exact boundaries and failure policy
Security LoggingSecurity event evidenceLogging / Event Reporting InterfaceModerateConfirm event set and reporting channel
Vulnerability and Incident HandlingField security postureSecurity Operations / Compliance ProcessStrongConfirm reporting channels and responsibilities
Cybersecurity Evidence and DIAApproval and residual-risk caseEngineering Toolchain / OEM Approval InterfaceStrongConfirm DIA split and authority

7. Requirement Evidence Coverage

Coverage ItemCountInterpretation
Total Requirements1076Markdown-derived extracted baseline
Security Requirements109Security-relevant requirement class
Architecture Drivers1109Mapped architecture rows
Interface-Related Requirements47Interface category
Assumptions25Tracked, not treated as confirmed
Clarifications64Customer-decision queue

8. Open Decisions

DecisionPriorityAreaImpactOwner
CQ-BOUNDARY-01P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-04P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-06P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-16P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-19P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-23P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-24P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-28P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-31P1System boundary / item definitionBlocks architecture baselineJoint
CQ-BOUNDARY-38P1System boundary / item definitionBlocks architecture baselineJoint

9. Review Navigation

ViewUse
Architecture CockpitBoard-level architecture/security summary
System OverviewConcise product and security definition
High-Level ArchitectureComponent and flow diagrams
Security Architecture MapSecurity controls, assets and attack surfaces
Traceability DashboardCoverage and gap summary
Review Board SummaryManagement review one-screen summary