High-Level Architecture

Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.

Last updated: 2026-06-29 11:49
RTRFQX Review TeamWorkspace

High-Level Architecture

Product and cybersecurity architecture understanding package generated from Markdown-derived requirements.

One-Screen Architecture Diagram

Architecture Cockpit Overview

flowchart LR subgraph Vehicle["Vehicle / drivetrain domain"] Drivetrain["GW AMT drivetrain"] Network["Vehicle network (CAN / PWM)"] end subgraph ECA["ECA ECU domain"] App["Clutch actuation application"] Sec["Security services"] Boot["Bootloader / update logic"] end subgraph Diagnostic["Diagnostic / service domain"] Tester["Diagnostic tester"] end subgraph OEM["OEM backend / security operations domain"] Backend["Update and evidence backend"] PKI["Key and certificate provisioning"] SecOps["Security operations"] end subgraph Supplier["Supplier engineering domain"] Engineering["Supplier ALM / CI / evidence"] end Drivetrain --> Network Network <-->|commands, status, freshness| App Tester -->|authenticated UDS| Sec Backend -->|signed software / IVD| Boot PKI -->|trust material| Sec Boot --> App Sec --> App App -->|events| SecOps Engineering -->|software and evidence| Backend
Mermaid source
flowchart LR
  subgraph Vehicle["Vehicle / drivetrain domain"]
    Drivetrain["GW AMT drivetrain"]
    Network["Vehicle network (CAN / PWM)"]
  end
  subgraph ECA["ECA ECU domain"]
    App["Clutch actuation application"]
    Sec["Security services"]
    Boot["Bootloader / update logic"]
  end
  subgraph Diagnostic["Diagnostic / service domain"]
    Tester["Diagnostic tester"]
  end
  subgraph OEM["OEM backend / security operations domain"]
    Backend["Update and evidence backend"]
    PKI["Key and certificate provisioning"]
    SecOps["Security operations"]
  end
  subgraph Supplier["Supplier engineering domain"]
    Engineering["Supplier ALM / CI / evidence"]
  end
  Drivetrain --> Network
  Network <-->|commands, status, freshness| App
  Tester -->|authenticated UDS| Sec
  Backend -->|signed software / IVD| Boot
  PKI -->|trust material| Sec
  Boot --> App
  Sec --> App
  App -->|events| SecOps
  Engineering -->|software and evidence| Backend

Component Table

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

ComponentResponsibilityInterfacesSecurity RoleEvidence StatusOpen Decision
Vehicle / Drivetrain DomainProvides CAN/PWM commands and receives ECA status/fault dataVehicle Network InterfacePrimary external runtime boundaryConfirmedConfirm network topology and protected signals
ECA ECU Application SoftwareControls clutch actuation and reports statusCAN, internal security services, diagnosticsValidates commands and enforces fail-safe behaviourConfirmedConfirm final function allocation
ECA ECU Security ServicesProvides auth, crypto, key/certificate, logging and secure communication servicesDiagnostics, update, PKI, vehicle networkCentral protection layerInferredConfirm concrete mechanisms and HSM support
Bootloader / Update LogicHandles flash, IVD and software validity checksUpdate / Flash, diagnostics, security servicesProtects software authenticity and integrityInferredConfirm signing chain and rollback policy
Diagnostic / Service DomainPerforms service, programming and authenticated diagnostic accessDiagnostic Tester InterfacePrivileged access boundaryInferredConfirm role model and service whitelist
OEM Backend / Security OperationsOwns approval, monitoring, update/key decisions and residual-risk workflowOEM Evidence, logging, update, PKIOffboard security governance boundaryInferredConfirm ownership split
Supplier Engineering DomainProduces software, evidence, traceability and review artifactsALM, CI/test, OEM evidence handoffProtects evidence and release integrityConfirmedConfirm evidence repository authority

Capability-to-Component Map

flowchart LR subgraph Capabilities["System capabilities"] Actuation["Clutch actuation"] Diagnostics["Secure diagnostics"] UpdateCap["Secure update"] Keys["Key and certificate handling"] Evidence["Cybersecurity evidence"] end subgraph Components["Architecture components"] App["Application software"] DiagSrv["Diagnostic server"] Boot["Bootloader / update logic"] Sec["Security services"] Tooling["Engineering evidence toolchain"] end Actuation --> App Diagnostics --> DiagSrv Diagnostics --> Sec UpdateCap --> Boot UpdateCap --> Sec Keys --> Sec Evidence --> Tooling Evidence --> Sec
Mermaid source
flowchart LR
  subgraph Capabilities["System capabilities"]
    Actuation["Clutch actuation"]
    Diagnostics["Secure diagnostics"]
    UpdateCap["Secure update"]
    Keys["Key and certificate handling"]
    Evidence["Cybersecurity evidence"]
  end
  subgraph Components["Architecture components"]
    App["Application software"]
    DiagSrv["Diagnostic server"]
    Boot["Bootloader / update logic"]
    Sec["Security services"]
    Tooling["Engineering evidence toolchain"]
  end
  Actuation --> App
  Diagnostics --> DiagSrv
  Diagnostics --> Sec
  UpdateCap --> Boot
  UpdateCap --> Sec
  Keys --> Sec
  Evidence --> Tooling
  Evidence --> Sec

Interface Trust Boundary Map

flowchart TB subgraph ECU["ECA ECU trust boundary"] App["Application software"] Sec["Security services"] Boot["Bootloader / update logic"] end Vehicle["Vehicle network boundary"] -->|CAN / PWM / protected data| App Tester["Diagnostic service boundary"] -->|UDS Auth 0x29| Sec Backend["OEM backend boundary"] -->|signed update / logs| Boot PKI["PKI provisioning boundary"] -->|keys / certificates| Sec Tooling["Supplier engineering boundary"] -->|software / evidence| Backend App -->|security events| Backend
Mermaid source
flowchart TB
  subgraph ECU["ECA ECU trust boundary"]
    App["Application software"]
    Sec["Security services"]
    Boot["Bootloader / update logic"]
  end
  Vehicle["Vehicle network boundary"] -->|CAN / PWM / protected data| App
  Tester["Diagnostic service boundary"] -->|UDS Auth 0x29| Sec
  Backend["OEM backend boundary"] -->|signed update / logs| Boot
  PKI["PKI provisioning boundary"] -->|keys / certificates| Sec
  Tooling["Supplier engineering boundary"] -->|software / evidence| Backend
  App -->|security events| Backend

Update and Diagnostics Flow

sequenceDiagram participant Tester as Diagnostic Tester participant Sec as ECA Security Services participant Boot as Bootloader / Update Logic participant App as Clutch Actuation Application participant Backend as OEM Update Backend Tester->>Sec: Start UDS session and authenticate Sec-->>Tester: Authorized diagnostic role Backend->>Boot: Signed software package and IVD Boot->>Sec: Validate signature, certificate and integrity Sec-->>Boot: Validation result Boot->>App: Activate accepted software App-->>Tester: Status, DTCs and update result
Mermaid source
sequenceDiagram
  participant Tester as Diagnostic Tester
  participant Sec as ECA Security Services
  participant Boot as Bootloader / Update Logic
  participant App as Clutch Actuation Application
  participant Backend as OEM Update Backend
  Tester->>Sec: Start UDS session and authenticate
  Sec-->>Tester: Authorized diagnostic role
  Backend->>Boot: Signed software package and IVD
  Boot->>Sec: Validate signature, certificate and integrity
  Sec-->>Boot: Validation result
  Boot->>App: Activate accepted software
  App-->>Tester: Status, DTCs and update result

Key and Certificate Flow

flowchart LR OEMPKI["OEM / TRATON PKI"] -->|certificate profile and trust anchors| Provisioning["Provisioning process"] Supplier["Supplier engineering"] -->|CSR / ECU identity evidence| Provisioning Provisioning -->|keys, certificates, trust anchors| ECU["ECA ECU security services"] ECU -->|certificate validation| Diagnostics["Authenticated diagnostics"] ECU -->|signature validation| Update["Secure update / flash"] ECU -->|MAC / freshness material| Comms["Secure communication"] ECU -->|lifecycle evidence| Review["OEM review and residual-risk decision"]
Mermaid source
flowchart LR
  OEMPKI["OEM / TRATON PKI"] -->|certificate profile and trust anchors| Provisioning["Provisioning process"]
  Supplier["Supplier engineering"] -->|CSR / ECU identity evidence| Provisioning
  Provisioning -->|keys, certificates, trust anchors| ECU["ECA ECU security services"]
  ECU -->|certificate validation| Diagnostics["Authenticated diagnostics"]
  ECU -->|signature validation| Update["Secure update / flash"]
  ECU -->|MAC / freshness material| Comms["Secure communication"]
  ECU -->|lifecycle evidence| Review["OEM review and residual-risk decision"]

Decision Dependency Map

flowchart TB Boundary["P1: item boundary and variants"] --> TARA["TARA / asset allocation"] Interfaces["P1: interface and signal scope"] --> Comms["SecOC / SDT allocation"] Diagnostics["P1: diagnostic role model"] --> DiagSec["Secure diagnostics baseline"] Update["P1: update and signing ownership"] --> UpdateSec["Secure update baseline"] PKI["P1: PKI, HSM and key hierarchy"] --> Crypto["Crypto and trust baseline"] TARA --> Closure["Architecture / security baseline closure"] Comms --> Closure DiagSec --> Closure UpdateSec --> Closure Crypto --> Closure
Mermaid source
flowchart TB
  Boundary["P1: item boundary and variants"] --> TARA["TARA / asset allocation"]
  Interfaces["P1: interface and signal scope"] --> Comms["SecOC / SDT allocation"]
  Diagnostics["P1: diagnostic role model"] --> DiagSec["Secure diagnostics baseline"]
  Update["P1: update and signing ownership"] --> UpdateSec["Secure update baseline"]
  PKI["P1: PKI, HSM and key hierarchy"] --> Crypto["Crypto and trust baseline"]
  TARA --> Closure["Architecture / security baseline closure"]
  Comms --> Closure
  DiagSec --> Closure
  UpdateSec --> Closure
  Crypto --> Closure
Architecture Overview Evidence

High-Level Architecture

Component Table

ComponentResponsibilityInterfacesSecurity RoleEvidence StatusOpen Decision
Vehicle / Drivetrain DomainProvides CAN/PWM commands and receives ECA status/fault dataVehicle Network InterfacePrimary external runtime boundaryConfirmedConfirm network topology and protected signals
ECA ECU Application SoftwareControls clutch actuation and reports statusCAN, internal security services, diagnosticsValidates commands and enforces fail-safe behaviourConfirmedConfirm final function allocation
ECA ECU Security ServicesProvides auth, crypto, key/certificate, logging and secure communication servicesDiagnostics, update, PKI, vehicle networkCentral protection layerInferredConfirm concrete mechanisms and HSM support
Bootloader / Update LogicHandles flash, IVD and software validity checksUpdate / Flash, diagnostics, security servicesProtects software authenticity and integrityInferredConfirm signing chain and rollback policy
Diagnostic / Service DomainPerforms service, programming and authenticated diagnostic accessDiagnostic Tester InterfacePrivileged access boundaryInferredConfirm role model and service whitelist
OEM Backend / Security OperationsOwns approval, monitoring, update/key decisions and residual-risk workflowOEM Evidence, logging, update, PKIOffboard security governance boundaryInferredConfirm ownership split
Supplier Engineering DomainProduces software, evidence, traceability and review artifactsALM, CI/test, OEM evidence handoffProtects evidence and release integrityConfirmedConfirm evidence repository authority

Executive Architecture Interpretation

Classification: Inferred from Requirements

The architecture should be read as an ECU/component security architecture with a supplier evidence wrapper around it. The product boundary contains system core behavior, application software, hardware platform, security services, diagnostic/update handling, and logging. Outside the boundary are vehicle networks, diagnostic tools, backend/IT systems, PKI/provisioning, development/ALM tooling, security operations, and OEM/customer approval.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010 (sample: 10 of 641)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 163)
  • Confidence level: Low
  • Classification: Inferred from Requirements

System Boundary

Classification: Inferred from Requirements

The system boundary is the Electric Clutch Actuator ECU security scope plus supplier-controlled lifecycle evidence. Exact vehicle-function allocation remains open.

External Actors

Classification: Inferred from Requirements

OEM/customer, vehicle network/other ECUs, diagnostic/service tools, backend/cloud/IT systems, PKI/provisioning, development/ALM tooling, and security operations.

Major Subsystems

Classification: Inferred from Requirements

System Core, Application Software, Hardware Platform, Security Services, External Interfaces, Backend and IT Systems, Engineering Toolchain, and Compliance Process.

Main Interfaces

Classification: Inferred from Requirements

OEM/customer cybersecurity approval and evidence interface; Diagnostic/service tool to ECU interface; Vehicle network secure data communication interface; Secure update, flash, and IVD interface; Certificate and key provisioning interface; Backend/cloud/IT operational interface; Development, ALM, and evidence tooling interface; Security operations and vulnerability reporting interface; Application software to security services interface; Hardware platform and key storage interface

Main Data Flows

Classification: Inferred from Requirements

Requirements/evidence flow, diagnostic access flow, vehicle data flow, secure update/flash flow, key/certificate flow, security event/logging flow, and vulnerability/incident flow.

Security Architecture Logic

Classification: Recommendation

Protect the highest-risk boundaries first: diagnostics, vehicle network communication, update/flash, key/certificate handling, and backend/tooling evidence. Use traceability and customer approval to keep inferred architecture distinct from confirmed requirements.

What Is Explicitly Required

Classification: Explicit Requirement

Cybersecurity concept documentation, risk assessment input, control derivation and traceability, verification/validation evidence, diagnostic/security controls, key/certificate handling, logging/audit elements, vulnerability and incident handling elements.

What Is Inferred

Classification: Inferred from Requirements

Layered ECU security services, backend/update actors, PKI/provisioning flow, security operations flow, and componentized architecture views.

Key Assumptions

Classification: Expert Assumption

The item is treated as one or more ECUs/E/E components until the customer confirms the exact product item definition.

Open Architecture Decisions

Classification: Needs Customer Clarification

Confirm item definition, network topology, diagnostic roles, update mechanism, PKI ownership, HSM capability, backend ownership, and final TARA outputs.

Classification: Recommendation

Hold an item-definition workshop, confirm boundary diagrams, allocate interfaces and assets, perform TARA, confirm security mechanisms, and update traceability with customer-approved decisions.

Logical Architecture

Classification: Inferred from Requirements

The logical architecture decomposes the Electric Clutch Actuator ECU into System Core, Application Software, Hardware Platform, Security Services, External Interfaces, Backend/IT, Engineering Toolchain, and Compliance Process.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010 (sample: 10 of 641)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 163)
  • Confidence level: Low
  • Classification: Inferred from Requirements
Cybersecurity Architecture

Classification: Inferred from Requirements

The cybersecurity architecture protects diagnostic access, vehicle communication, update/flash, certificate/key handling, platform integrity, logging, monitoring, vulnerability handling, and evidence traceability.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010 (sample: 10 of 641)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 163)
  • Confidence level: Low
  • Classification: Inferred from Requirements
Data Flow View

Classification: Inferred from Requirements

The data-flow view tracks requirements/evidence, diagnostic traffic, vehicle data, software/update packages, key/certificate data, security events, and vulnerability/incident records.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010 (sample: 10 of 641)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 163)
  • Confidence level: Low
  • Classification: Inferred from Requirements
Trust Boundaries

Classification: Inferred from Requirements

The trust-boundary view separates the Electric Clutch Actuator ECU, vehicle network, diagnostic, backend/cloud, tooling, customer/OEM, and unknown deployment zones.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0004; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010 (sample: 10 of 641)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 163)
  • Confidence level: Low
  • Classification: Inferred from Requirements
Design Drill-Down

System Context

Overview

Classification: Inferred from Requirements

System Context is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019 (sample: 18 of 1009)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 228)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011 (sample: 10 of 1009)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 228)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Logical Components

Overview

Classification: Inferred from Requirements

Logical Components is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0022; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025 (sample: 18 of 207)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 101)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015 (sample: 10 of 207)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 101)
  • Confidence level: Low
  • Classification: Inferred from Requirements

External Interfaces

Overview

Classification: Inferred from Requirements

External Interfaces is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025 (sample: 18 of 214)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 103)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014 (sample: 10 of 214)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 103)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Internal Interfaces

Overview

Classification: Inferred from Requirements

Internal Interfaces is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025 (sample: 18 of 227)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 110)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014 (sample: 10 of 227)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 110)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Security-Relevant Interfaces

Overview

Classification: Inferred from Requirements

Security-Relevant Interfaces is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0027 (sample: 18 of 203)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 96)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015 (sample: 10 of 203)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 96)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Trust Boundaries

Overview

Classification: Inferred from Requirements

Trust Boundaries is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0027 (sample: 18 of 194)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 93)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015 (sample: 10 of 194)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 93)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Data Flows

Overview

Classification: Inferred from Requirements

Data Flows is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0027 (sample: 18 of 381)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 152)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015 (sample: 10 of 381)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 152)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Security Capabilities

Overview

Classification: Inferred from Requirements

Security Capabilities is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0023; RFQX-1001379436-P10-000-01-0024; RFQX-1001379436-P10-000-01-0025; RFQX-1001379436-P10-000-01-0027 (sample: 18 of 194)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 93)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015 (sample: 10 of 194)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 93)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Lifecycle and Operations

Overview

Classification: Inferred from Requirements

Lifecycle and Operations is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019 (sample: 18 of 638)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 209)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011 (sample: 10 of 638)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 209)
  • Confidence level: Low
  • Classification: Inferred from Requirements

Tooling and Evidence Flow

Overview

Classification: Inferred from Requirements

Tooling and Evidence Flow is treated as a design view needed to understand the product before detailed requirement allocation.

Design Intent

Keep customer-confirmed requirements separate from inferred design structure while exposing the security reasoning.

Requirement Basis

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019 (sample: 18 of 639)
  • Source document sections: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 209)

Security Relevance

This view shows where an asset, interface, trust boundary, or evidence obligation could create security risk.

Constraints

No final TARA, topology, algorithm, or implementation ownership is claimed unless a requirement explicitly supports it.

Open Questions

Confirm customer ownership, exact item boundary, allocated mechanisms, and verification evidence for this view.

Evidence Basis:

  • Related requirements: RFQX-1001379436-P10-000-01-0001; RFQX-1001379436-P10-000-01-0002; RFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0006; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011 (sample: 10 of 639)
  • Source document: source document page 3; source document page 5; source document page 6; source document page 7; source document page 8; source document page 9; source document page 10; source document page 11(sample: 8 of 209)
  • Confidence level: Low
  • Classification: Inferred from Requirements
Architecture Decisions
Decision IDDecision statementClassificationSource requirement IDsSource documentConfidenceHuman review requiredReason for human review
ADR-001Include Application Software in the customer-review baseline architecture.Explicit RequirementRFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0021; RFQX-3299216-1-0061; RFQX-3299216-1-0075; RFQX-3299216-1-0137; RFQX-3299216-1-0139; RFQX-3299216-1-0142; RFQX-3299216-1-0214; RFQX-3299216-1-0218; RFQX-3299216-1-0220; RFQX-3299216-1-0285; RFQX-3299216-1-0306 (sample: 12 of 169)source document page 5; source document page 6; source document page 15; source document page 19(sample: 4 of 82)HighyesCustomer clarification linked to one or more requirements.
ADR-002Include Backend and IT Systems in the customer-review baseline architecture.Explicit RequirementRFQX-3299216-1-0024; RFQX-3299216-1-0033; RFQX-3299216-1-0036; RFQX-3299216-1-0038; RFQX-3299216-1-0039; RFQX-3299216-1-0040; RFQX-3299216-1-0043; RFQX-3299216-1-0049; RFQX-3299216-1-0052; RFQX-3299216-1-0055; RFQX-3299216-1-0058; RFQX-3299216-1-0079 (sample: 12 of 216)source document page 9; source document page 10; source document page 11; source document page 12(sample: 4 of 103)HighyesCustomer clarification linked to one or more requirements.
ADR-003Include Compliance Process in the customer-review baseline architecture.Explicit RequirementRFQX-1001379436-P10-000-01-0047; RFQX-1001379436-P10-000-01-0049; RFQX-1001379436-P10-000-01-0050; RFQX-3299216-1-0070; RFQX-3299216-1-0185; RFQX-3299216-1-0189; RFQX-3299216-1-0280; RFQX-3299216-1-0281; RFQX-3299216-1-0283; RFQX-CVS123-2-0002; RFQX-CVS123-2-0320; RFQX-CVS124-0003 (sample: 12 of 55)source document page 10; source document page 16; source document page 36; source document page 49(sample: 4 of 33)Highnonone
ADR-004Include Engineering Toolchain in the customer-review baseline architecture.Explicit RequirementRFQX-3299216-1-0035source document page 10Highnonone
ADR-005Include External Interfaces in the customer-review baseline architecture.Explicit RequirementRFQX-1001379436-P10-000-01-0058; RFQX-3299216-1-0031; RFQX-3299216-1-0084; RFQX-3299216-1-0091; RFQX-3299216-1-0092; RFQX-3299216-1-0094; RFQX-3299216-1-0096; RFQX-3299216-1-0102; RFQX-3299216-1-0103; RFQX-3299216-1-0104; RFQX-3299216-1-0106; RFQX-3299216-1-0135 (sample: 12 of 48)source document page 11; source document page 10; source document page 21; source document page 22(sample: 4 of 27)Highnonone
ADR-006Include Hardware Platform in the customer-review baseline architecture.Explicit RequirementRFQX-1001379436-P10-000-01-0022; RFQX-1001379436-P10-000-01-0029; RFQX-1001379436-P10-000-01-0030; RFQX-1001379436-P10-000-01-0036; RFQX-1001379436-P10-000-01-0060; RFQX-1001379436-P10-000-01-0062; RFQX-1001379436-P10-000-01-0063; RFQX-1001379436-P10-000-01-0065; RFQX-1001379436-P10-000-01-0066; RFQX-3299216-1-0004; RFQX-3299216-1-0019; RFQX-3299216-1-0041 (sample: 12 of 48)source document page 7; source document page 8; source document page 11; source document page 12(sample: 4 of 39)HighyesCustomer clarification linked to one or more requirements.
ADR-007Include OEM/Customer Review Interface in the customer-review baseline architecture.Inferred from RequirementsRFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0021 (sample: 12 of 140)source document page 3; source document page 5; source document page 6; source document page 7(sample: 4 of 62)HighyesConfirm exact OEM/customer evidence and approval workflow.
ADR-008Include Security Services in the customer-review baseline architecture.Explicit RequirementRFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0013; RFQX-1001379436-P10-000-01-0014; RFQX-1001379436-P10-000-01-0015; RFQX-1001379436-P10-000-01-0016; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019 (sample: 12 of 96)source document page 3; source document page 5; source document page 6; source document page 7(sample: 4 of 54)HighyesCustomer clarification linked to one or more requirements.
ADR-009Include System Core in the customer-review baseline architecture.Explicit RequirementRFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0026; RFQX-1001379436-P10-000-01-0028; RFQX-1001379436-P10-000-01-0031; RFQX-1001379436-P10-000-01-0032; RFQX-1001379436-P10-000-01-0033; RFQX-1001379436-P10-000-01-0034; RFQX-1001379436-P10-000-01-0035; RFQX-1001379436-P10-000-01-0038; RFQX-1001379436-P10-000-01-0039; RFQX-1001379436-P10-000-01-0040 (sample: 12 of 354)source document page 5; source document page 7; source document page 8; source document page 9(sample: 4 of 143)Highnonone
Architecture Open Decisions
  • Needs Customer Clarification: Confirm exact ECU item definition, product designation, and variants.
  • Needs Customer Clarification: Confirm vehicle network topology, SecOC/SDT applicability, signals, and protection profiles.
  • Needs Customer Clarification: Confirm diagnostic service list, UDS Authentication 0x29 role model, certificate use, lockout, and audit expectations.
  • Needs Customer Clarification: Confirm secure update/flash/IVD mechanism, signing chain, backend ownership, and rollback behavior.
  • Needs Customer Clarification: Confirm key hierarchy, HSM/protected storage capability, PKI ownership, revocation, renewal, and provisioning process.
  • Needs Customer Clarification: Confirm security monitoring, incident response handoff, and vulnerability reporting channels.
  • Needs Customer Clarification: Confirm final TARA results and customer residual-risk acceptance workflow.
Unsupported/Assumption-Based Elements

Unsupported Architecture Elements

No unresolved unsupported architecture placeholders remain.

Resolved Former Placeholder

Former elementResolutionClassificationEvidence basisCustomer clarification
Customer / external systemsReplaced by OEM/Customer Review Interface and OEM customer / vehicle manufacturer actor in diagrams and narratives.Inferred from RequirementsRFQX-1001379436-P10-000-01-0003; RFQX-1001379436-P10-000-01-0005; RFQX-1001379436-P10-000-01-0007; RFQX-1001379436-P10-000-01-0008; RFQX-1001379436-P10-000-01-0009; RFQX-1001379436-P10-000-01-0010; RFQX-1001379436-P10-000-01-0011; RFQX-1001379436-P10-000-01-0012; RFQX-1001379436-P10-000-01-0017; RFQX-1001379436-P10-000-01-0018; RFQX-1001379436-P10-000-01-0019; RFQX-1001379436-P10-000-01-0021 (sample: 12 of 140)Confirm exact customer/OEM workflow, approval authority, and evidence handoff.