CVS151

Security Access / RBAC Standard · Security Access / RBAC · Core ECA system behavior

Back to Document Intelligence

Executive Takeaway

Confirmed by requirements: this security access / rbac standard contributes 58 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior. Inferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence.

Confirmed by requirements: supplier positioning is 5 accept; 10 accept with assumption; 42 partially accept; 1 informational only. The generated traceability links this document to 14 supplier system requirement records. Inferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.

Requires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. Do not convert these items into agreed baseline scope until the customer confirms the decision. Confidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Requirements58from this PDF
Critical42ranked
Open Points2linked
Derived SSRs14linked
Concept Impactyesdocument-specific
Estimation Impactyesdocument-specific

Document Abstract

Document Purpose

Confirmed by requirements: this security access / rbac standard contributes 58 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior.

Engineering Interpretation

Inferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence.

Main Requirement Themes

Core ECA system behavior; Responsibility and customer approval model; Cybersecurity concept and evidence; Diagnostics and service access; System architecture design (showing 5 of 8)

System / Security Impact

Inferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.

Supplier Proposal Impact

Confirmed by requirements: supplier positioning is 5 accept; 10 accept with assumption; 42 partially accept; 1 informational only. The generated traceability links this document to 14 supplier system requirement records.

Customer Clarification Impact

Requires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. Do not convert these items into agreed baseline scope until the customer confirms the decision.

Confidence and Limits

Confidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Main Requirement Themes

ThemeEngineering MeaningRequirement CountRepresentative Requirements
Core ECA system behaviorDefines actuator ECU behavior, drivetrain integration, electrical/mechanical constraints, and verification scope.52REQ-AUTO-00785; REQ-AUTO-00786; REQ-AUTO-00787
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.44REQ-AUTO-00785; REQ-AUTO-00786; REQ-AUTO-00788
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.42REQ-AUTO-00786; REQ-AUTO-00788; REQ-AUTO-00791
Diagnostics and service accessDefines UDS service behavior, authorization expectations, safe-state checks, and diagnostic evidence.26REQ-AUTO-00785; REQ-AUTO-00788; REQ-AUTO-00789
System architecture designGroups related document requirements into a single engineering theme.16REQ-AUTO-00785; REQ-AUTO-00787; REQ-AUTO-00789
SystemGroups related document requirements into a single engineering theme.10REQ-AUTO-00785; REQ-AUTO-00787; REQ-AUTO-00790
System coreGroups related document requirements into a single engineering theme.9REQ-AUTO-00787; REQ-AUTO-00790; REQ-AUTO-00795
CybersecurityGroups related document requirements into a single engineering theme.6REQ-AUTO-00788; REQ-AUTO-00808; REQ-AUTO-00818

Document Content Structure

SectionRequirementsCriticalOpen PointsSSR Links
2 Terms, definitions and abbrevations1001
-- 2.1 Document quirks1001
3 Technical content5042211
-- 3.2 Role Based Access Control Configuration9713
-- 3.3 ASN.1 definition1101
-- 3.6 role-configuration9713
-- 3.8 did-rules6514
-- 3.9 rid-rules3312
-- 3.10 Extending the Role Based Access Control Configuration using a certificate2222
-- 3.12 Logic8715
-- 3.14 Requests Specific Requirements121014
-- -- 3.14.1 Diagnostic over USD121014
4 Referenced documents4004
-- 4.1 Normative references4004

What This PDF Is About

FieldValue
Source PDFcustomer-input/pdf/CVS151.pdf
Converted Markdownconverted/markdown/CVS151.md
Document TypeSecurity Access / RBAC Standard
DomainSecurity Access / RBAC
Scope Summary58 extracted requirements; 14 linked SSRs; 2 linked open points.
Main ThemesCore ECA system behavior; Responsibility and customer approval model; Cybersecurity concept and evidence; Diagnostics and service access; System architecture design (showing 5 of 8)
Does Not ConfirmCustomer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.
ConfidenceHigh
Evidence BasisMarkdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Key Conclusions From This PDF

Critical Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

IDScoreCategoryRequirement / ReasonSupplier Position
REQ-AUTO-0078977High risk due to unclear OEM/supplier responsibilityRBAC_INFO 2 Before a client can execute diagnostics services that are under RBAC, the client must perform some type of authorization procedure towards the server/ECU.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0080477High risk due to unclear OEM/supplier responsibilityRBAC_REQ 11 The server shall report the currently stored RBACC’s version via diagnostics.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0080677High risk due to unclear OEM/supplier responsibilityRBAC_REQ 13 The server shall report the currently stored RBACC’s rbacc-id via diagnostics.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0080877High risk due to unclear OEM/supplier responsibilityPage 9 3.7 pattern-rules RBAC_REQ 15 The server shall support for every entry in the pattern-rules one octet for the pattern rule settings followed by the diagnostic pattern of variable length.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0081077High risk due to unclear OEM/supplier responsibilityTable 1 – Pattern Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0081477High risk due to unclear OEM/supplier responsibilityPage 10 Table 2 – DID Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0081777High risk due to unclear OEM/supplier responsibilityPage 11 Table 3 – RID Rule Setting Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0081877High risk due to unclear OEM/supplier responsibilityRBAC_REQ 22 If conflicting/overlapping rules are found between the client certificate D-RBACC extension and any rules in the RBAC-configuration in the RBACC, the server shall enforce the rules in the client certificate D-RBACC extension.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0082177High risk due to unclear OEM/supplier responsibility3.11 ECU-Diagnostics-Role Extension RBAC_REQ 36 The server shall exert the RBACC roles based on the ECU-diagnostics-Role extension on the client’s certificate.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0083277High risk due to unclear OEM/supplier responsibility3.14 Requests Specific Requirements 3.14.1 Diagnostic over USD 3.14.1.1 Authenticate 0x29 RBAC_REQ 28 The server shall always allow reception of UDS authenticate 0x29 requests regardless of the RBACC settings.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0082063High risk due to unclear OEM/supplier responsibilityIt can also be useful if you want to add or remove access rights from a client/tester, that needs access to one or several roles, but should not have access to everything (or should have more access) specified for the assigned roles.security relevant; architecture relevant; Partially Accept; linked open pointPartially Accept
REQ-AUTO-0083363High risk due to unclear OEM/supplier responsibilityRBAC_INFO 42 For 0x29 requests a corresponding matching rule in the RBACC is not required for the server to accept the request.security relevant; architecture relevant; Partially Accept; linked open pointPartially Accept

Customer Clarifications / Open Points

Total Open Points2document-linked
P10priority
P20priority
Blocking Conceptyesyes/no
Blocking Estimationyesyes/no
Blocking SSRyesyes/no

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Open PointPriorityQuestion / ImpactRequired Customer DecisionRecommended Supplier PositionOwnerStatus
OP-002Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Implement configurable session/security-access on the ECU and request the customer-confirmed service-to-role table.Shared (OEM policy / Supplier ECU)Open
OP-003Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.Provide ECU-side secure storage and provisioning hooks; require OEM confirmation of PKI ownership and the provisioning interface.OEM / Customer (PKI) + Supplier (ECU)Open

Requirements From This PDF

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

IDRequirement / ProposalSupplier PositionReviewSecurity CapabilityFeature / InterfaceSSROpen PointSource
REQ-AUTO-00789RBAC_INFO 2 Before a client can execute diagnostics services that are under RBAC, the client must perform some type of authorization procedure towards the server/ECU.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneHardware platform support
None
SSR-RBAC-005OP-0023.2 Role Based Access Control Configuration
page 4
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 4

REQ-AUTO-00804RBAC_REQ 11 The server shall report the currently stored RBACC’s version via diagnostics.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003OP-0023.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00806RBAC_REQ 13 The server shall report the currently stored RBACC’s rbacc-id via diagnostics.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003OP-0023.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00808Page 9 3.7 pattern-rules RBAC_REQ 15 The server shall support for every entry in the pattern-rules one octet for the pattern rule settings followed by the diagnostic pattern of variable length.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyDiagnostic securityDiagnostic security
None
SSR-RBAC-001OP-0023.8 did-rules
page 9
Source details
Document section

3.8 did-rules

Section path

3 Technical content > 3.8 did-rules

Page reference

page 9

REQ-AUTO-00810Table 1 – Pattern Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-DIAG-003OP-0023.8 did-rules
page 9
Source details
Document section

3.8 did-rules

Section path

3 Technical content > 3.8 did-rules

Page reference

page 9

REQ-AUTO-00814Page 10 Table 2 – DID Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-DIAG-003OP-0023.9 rid-rules
page 10
Source details
Document section

3.9 rid-rules

Section path

3 Technical content > 3.9 rid-rules

Page reference

page 10

REQ-AUTO-00817Page 11 Table 3 – RID Rule Setting Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-DIAG-003OP-0023.10 Extending the Role Based Access Control Configuration using a certificate
page 11
Source details
Document section

3.10 Extending the Role Based Access Control Configuration using a certificate

Section path

3 Technical content > 3.10 Extending the Role Based Access Control Configuration using a certificate

Page reference

page 11

REQ-AUTO-00818RBAC_REQ 22 If conflicting/overlapping rules are found between the client certificate D-RBACC extension and any rules in the RBAC-configuration in the RBACC, the server shall enforce the rules in the client certificate D-RBACC extension.Proposal: Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.Partially AcceptProposal ReadyCertificate handlingCertificate handling
None
SSR-KEY-002OP-0033.10 Extending the Role Based Access Control Configuration using a certificate
page 11
Source details
Document section

3.10 Extending the Role Based Access Control Configuration using a certificate

Section path

3 Technical content > 3.10 Extending the Role Based Access Control Configuration using a certificate

Page reference

page 11

REQ-AUTO-008213.11 ECU-Diagnostics-Role Extension RBAC_REQ 36 The server shall exert the RBACC roles based on the ECU-diagnostics-Role extension on the client’s certificate.Proposal: Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.Partially AcceptProposal ReadyCertificate handlingCertificate handling
None
SSR-KEY-002OP-0023.12 Logic
page 12
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 12

REQ-AUTO-008323.14 Requests Specific Requirements 3.14.1 Diagnostic over USD 3.14.1.1 Authenticate 0x29 RBAC_REQ 28 The server shall always allow reception of UDS authenticate 0x29 requests regardless of the RBACC settings.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyAuthenticationAuthentication
None
SSR-RBAC-002OP-0023.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00820It can also be useful if you want to add or remove access rights from a client/tester, that needs access to one or several roles, but should not have access to everything (or should have more access) specified for the assigned roles.Proposal: Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-COM-003OP-0023.12 Logic
page 12
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 12

REQ-AUTO-00833RBAC_INFO 42 For 0x29 requests a corresponding matching rule in the RBACC is not required for the server to accept the request.Proposal: Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003OP-0023.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-008343.14.1.2 SecuredData Transmission 0x84 RBAC_REQ 29 The server shall evaluate the reported internal service using the RBACC rules whenever it receives a UDS Service 0x84 requests.Proposal: Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.Partially AcceptProposal ReadyNoneApplication software behavior
None
SSR-RBAC-004OP-0023.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00835RBAC_REQ 30 The server shall always allow reception of UDS SecuredDataTransmission 0x84 requests regardless of the RBACC settings.Proposal: Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003OP-0023.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00837Page 20 3.14.1.3 TesterPresent 0x3E RBAC_REQ 31 The server shall always allow reception of UDS TesterPresent 0x3E requests regardless of the RBACC settings.Proposal: Partially accept. Supplier can implement ECU-side UDS/session/security-access behavior; customer must confirm the service-to-role table, diagnostic authorization policy, and acceptance criteria.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003OP-0023.14.1 Diagnostic over USD
page 20
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 20

REQ-AUTO-00828RBAC_REQ 24 The server shall allow requests that are contained in role 0 rules regardless of the client authentication state.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00791RBAC_REQ 2 If conflicting/overlapping rules are found within a role-configuration, the server shall enforce that deny rule takes precedence over the allow rule.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.2 Role Based Access Control Configuration
page 5
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 5

REQ-AUTO-00792RBAC_REQ 3 If a matching allow/deny rule is found and all the rule settings are fulfilled, the server shall accept/deny the request.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.2 Role Based Access Control Configuration
page 5
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 5

REQ-AUTO-00793RBAC_REQ 4 If a matching rule is found and not all the rule settings are fulfilled, the server shall consider the request rejected for that rule.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.2 Role Based Access Control Configuration
page 5
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 5

REQ-AUTO-00794RBAC_REQ 5 The server shall deny a request if no matching rule is found on RBACC.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.2 Role Based Access Control Configuration
page 5
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 5

REQ-AUTO-00796RBAC_REQ 6 The server shall evaluate each role-configuration independently from each other.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.2 Role Based Access Control Configuration
page 6
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 6

REQ-AUTO-00797RBAC_REQ 27 The server shall require that requests are authenticated for allow rules, using e.g., SecuredDataTransmission 0x84 (see CVS31, ISO-14229-1:2020).Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.2 Role Based Access Control Configuration
page 6
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 6

REQ-AUTO-00798Page 7 RBACC Role-configuration role Pattern-rule DENY Pattern-rule ALLOW DID-rule DENY DID-rule ALLOW RID-rule DENY RID-rule ALLOW Figure 2 – Visual representation of the RBACC 3.3 ASN.1 definition RBAC_REQ 7 The server and client shall define the RBACC as per the following ASN.1 definition: RBACC ::= SEQUENCE { version OCTET STRING (SIZE(2)), rbacc-id OCTET STRING (SIZE(16)), role-configurations SEQUENCE (SIZE(0..MAX)) OF Role-configuration } Role-configuration ::= SEQUENCE { role INTEGER(0..MAX), pattern-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), pattern-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(2..MAX)), did-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), did-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-deny SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)), rid-rules-allow SEQUENCE (SIZE(0...MAX)) OF OCTET STRING (SIZE(3)) }Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.3 ASN.1 definition
page 7
Source details
Document section

3.3 ASN.1 definition

Section path

3 Technical content > 3.3 ASN.1 definition

Page reference

page 7

REQ-AUTO-00799RBAC_REQ 8 The server shall support in the version field two octets.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00800RBAC_REQ 9 The server shall support major version value 3 and minor version value 0.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00802RBAC_REQ 10 Before RBACC is stored, the server shall verify that the server supports the structure indicated in the version number.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00805RBAC_REQ 12 The server shall support 16 octets in the rbacc-id field.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00807RBAC_REQ 14 The server shall support role-configurations using 32-bit unsigned integer.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00809RBAC_REQ 16 The server shall support the pattern-rule setting according to Table 1.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.8 did-rules
page 9
Source details
Document section

3.8 did-rules

Section path

3 Technical content > 3.8 did-rules

Page reference

page 9

REQ-AUTO-008114-7 N/A Reserved for future use 3.8 did-rules RBAC_REQ 17 The server shall support for every entry in the did-rules one octet which represents the did-rule settings followed by two octets that represent the DID.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.8 did-rules
page 9
Source details
Document section

3.8 did-rules

Section path

3 Technical content > 3.8 did-rules

Page reference

page 9

REQ-AUTO-00813RBAC_REQ 19 The server shall support the did-rule setting according to Table 2.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.8 did-rules
page 9
Source details
Document section

3.8 did-rules

Section path

3 Technical content > 3.8 did-rules

Page reference

page 9

REQ-AUTO-008154 Read 0 == This rule is not applicable when the DID is being read 1 == This rule is applicable when the DID is being read 5 Write 0 == This rule is not applicable when the DID is being written 1 == This rule is applicable when the DID is being written 6 IO-control 0 == This rule is not applicable when the DID is being used for IO-control 1 == This rule is applicable when the DID is being used for IO-control 7 N/A Reserved for future use 3.9 rid-rules RBAC_REQ 20 The server shall support for every entry in the rid-rules one octet which represents the rid-rule settings followed by two octets that represent the RID.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.9 rid-rules
page 10
Source details
Document section

3.9 rid-rules

Section path

3 Technical content > 3.9 rid-rules

Page reference

page 10

REQ-AUTO-00816RBAC_REQ 21 The server shall support the rid-rule setting according to Table 3.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.9 rid-rules
page 10
Source details
Document section

3.9 rid-rules

Section path

3 Technical content > 3.9 rid-rules

Page reference

page 10

REQ-AUTO-00819Page 12 RBAC_REQ 23 The server shall interpret the extnValue (see snipped above) as of one instance of a RBACC (see 3.3).Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.12 Logic
page 12
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 12

REQ-AUTO-00822Page 13 Figure 3 – Logic Overview RBAC_REQ 35 The server shall implement RBAC internal logic as per Figure 4.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneApplication software behavior
None
SSR-RBAC-004-3.12 Logic
page 13
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 13

REQ-AUTO-00823RBAC_REQ 32 The server shall implement RBAC pattern rule evaluation logic as per Figure 5.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneApplication software behavior
None
SSR-RBAC-004-3.12 Logic
page 15
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 15

REQ-AUTO-00825RBAC_REQ 33 The server shall implement RBAC did rule evaluate as per Figure 6.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.12 Logic
page 16
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 16

REQ-AUTO-00826Page 17 RBAC_REQ 34 The server shall implement RBAC rid rule evaluate as per Figure 7.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.12 Logic
page 17
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 17

REQ-AUTO-00829RBAC_REQ 25 The server shall allow request that are contained in role 0 rule regardless if the request is data authenticated e.g over e.g., SecuredDataTransmission 0x84 (See CVS31, ISO 14229-1:2020).Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00830RBAC_REQ 26 The server shall allow request that are contained in role 0 rule regardless of the value of Confidentiality field setting.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00836RBAC_INFO 43 For 0x84 requests a corresponding matching rule in the RBACC is not required for the server to accept the 0x84 request but the server must find a corresponding matching rule for the internal request contained in the 0x84 prior to execute it.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00838RBAC_INFO 44 For 0x3E requests a corresponding matching rule in the RBACC is not required for the server to accept the request.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration
None
SSR-RBAC-003-3.14.1 Diagnostic over USD
page 20
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 20

REQ-AUTO-00788Page 3 1 Scope Concepts such as secure-update (CVS37) requires Role Based Access Control (RBAC) for diagnostics (UDS).Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Accept with AssumptionProposal ReadyDiagnostic securityDiagnostic security
None
SSR-RBAC-001-2.1 Document quirks
page 3
Source details
Document section

2.1 Document quirks

Section path

2 Terms, definitions and abbrevations > 2.1 Document quirks

Page reference

page 3

REQ-AUTO-00827Meaning, role 0 is particularly useful for defining services, DIDs and RIDs that should be available to all clients/users, regardless of their diagnostics role and/or authorization/authentication status.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Accept with AssumptionProposal ReadyNoneSystem behavior
None
SSR-RBAC-006-3.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00839Page 26 Annex D DynamicallyDefineDataIdentifier When this service is being used, each DID included in the request must be evaluated against the rules that are applicable for the client (the rules in the client’s certificate and in the RBACC).Proposal: Needs customer clarification. Supplier can implement ECU-side certificate/key handling, but ownership of PKI, certificate provisioning, lifecycle management, and backend responsibility must be confirmed through CIA/RASIC.Accept with AssumptionProposal ReadyCertificate handlingCertificate handling
None
SSR-KEY-002-4.1 Normative references
page 26
Source details
Document section

4.1 Normative references

Section path

4 Referenced documents > 4.1 Normative references

Page reference

page 26

REQ-AUTO-00785RBAC for diagnostics Foreword This Commercial Vehicle Standard (“CVS151”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.Proposal: Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.Informational OnlyProposal ReadyNoneNone
None
None-page-1 Page 1
page 1
Source details
Document section

page-1 Page 1

Section path

Page 1

Page reference

page 1

REQ-AUTO-00790RBAC_REQ 1 Each RBACC shall only contain one role-configuration per each supported role.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneSystem behavior
None
SSR-RBAC-006-3.2 Role Based Access Control Configuration
page 4
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 4

REQ-AUTO-00795RBAC_INFO 10 All RBACC ALLOW rules have a setting that dictates if a request, matching the rule, must be 14229-1:2020).Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneSystem behavior
None
SSR-RBAC-006-3.2 Role Based Access Control Configuration
page 5
Source details
Document section

3.2 Role Based Access Control Configuration

Section path

3 Technical content > 3.2 Role Based Access Control Configuration

Page reference

page 5

REQ-AUTO-00801RBAC_INFO 19 If other versions shall be supported is out of the scope of this document and shall be agreed upon between projects in Traton.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneSystem behavior
None
SSR-RBAC-006-3.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00812RBAC_REQ 18 The byte order for DID shall be big endian.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Accept with AssumptionProposal ReadyNoneSystem behavior
None
SSR-RBAC-006-3.8 did-rules
page 9
Source details
Document section

3.8 did-rules

Section path

3 Technical content > 3.8 did-rules

Page reference

page 9

REQ-AUTO-00831RBAC_INFO 40 This means that in role 0 encryption is never required.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneSystem behavior
None
SSR-RBAC-006-3.14.1 Diagnostic over USD
page 19
Source details
Document section

3.14.1 Diagnostic over USD

Section path

3 Technical content > 3.14 Requests Specific Requirements > 3.14.1 Diagnostic over USD

Page reference

page 19

REQ-AUTO-00840The client must have read access for all included DIDs and have access to the service themselves.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneApplication software behavior
None
SSR-SYS-008-4.1 Normative references
page 26
Source details
Document section

4.1 Normative references

Section path

4 Referenced documents > 4.1 Normative references

Page reference

page 26

REQ-AUTO-00842Since reading of DIDs can be allowed by either a pattern-rule (starting with 22 [7]) and/or a DID-rule, both the pattern-rules and the DID-rules must be parsed when evaluating each DID.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneExternal interfaces
External Interfaces
SSR-COM-002-4.1 Normative references
page 26
Source details
Document section

4.1 Normative references

Section path

4 Referenced documents > 4.1 Normative references

Page reference

page 26

REQ-AUTO-00786Any review of this CVS151 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-009-page-1 Page 1
page 1
Source details
Document section

page-1 Page 1

Section path

Page 1

Page reference

page 1

REQ-AUTO-00787The User shall apply the latest version of this CVS151.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-page-1 Page 1
page 1
Source details
Document section

page-1 Page 1

Section path

Page 1

Page reference

page 1

REQ-AUTO-00803If the version number does not comply with the server implementation, the server shall reject storing the data.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.6 role-configuration
page 8
Source details
Document section

3.6 role-configuration

Section path

3 Technical content > 3.6 role-configuration

Page reference

page 8

REQ-AUTO-00824E.g: For the evaluate pattern the rule setting Confidentiality is set to 0x01 (Confidentiality is required).Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.12 Logic
page 16
Source details
Document section

3.12 Logic

Section path

3 Technical content > 3.12 Logic

Page reference

page 16

REQ-AUTO-00841When the client is performing the actual read operation (ReadDataByIdentifier [7]), the conditions and rules for all DIDs, aliased by the dynamically defined identifier, must be met, otherwise the request shall be rejected with an appropriate NRC.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-4.1 Normative references
page 26
Source details
Document section

4.1 Normative references

Section path

4 Referenced documents > 4.1 Normative references

Page reference

page 26

Derived Supplier System Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

SSRStatement / TraceFeatureSecurity CapabilityInterfaceResponsibilityStatusVerification
SSR-COM-002External Interfaces — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for External Interfaces, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals.From this PDF: REQ-AUTO-00842. This SSR is also supported by requirements from other PDFs.External InterfacesNoneExternal InterfacesSharedBlocked by Customer ClarificationReview + Test
SSR-COM-003Backend and IT integration — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Backend and IT integration, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals.From this PDF: REQ-AUTO-00820. This SSR is also supported by requirements from other PDFs.Backend and IT integrationNoneNoneSharedBlocked by Customer ClarificationReview + Test
SSR-DIAG-003Backend and IT integration — Diagnostic ServicesThe ECU shall provide the diagnostic services for Backend and IT integration required by the allocated customer requirements, including the specified services, sessions and data identifiers.From this PDF: REQ-AUTO-00810; REQ-AUTO-00814; REQ-AUTO-00817. This SSR is also supported by requirements from other PDFs.Backend and IT integrationNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationTest
SSR-KEY-002Certificate handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Certificate handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle.From this PDF: REQ-AUTO-00818; REQ-AUTO-00821; REQ-AUTO-00839. This SSR is also supported by requirements from other PDFs.Certificate handlingCertificate handlingNoneSharedBlocked by Customer ClarificationReview + Test
SSR-RBAC-001Diagnostic security — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Diagnostic security, restricting security-relevant diagnostic services per the OEM-agreed role model.From this PDF: REQ-AUTO-00788; REQ-AUTO-00808. This SSR is also supported by requirements from other PDFs.Diagnostic securityDiagnostic securityOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test
SSR-RBAC-002Authentication — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Authentication, restricting security-relevant diagnostic services per the OEM-agreed role model.From this PDF: REQ-AUTO-00832. This SSR is also supported by requirements from other PDFs.AuthenticationAuthenticationNoneSharedBlocked by Customer ClarificationReview + Test
SSR-RBAC-003Backend and IT integration — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Backend and IT integration, restricting security-relevant diagnostic services per the OEM-agreed role model.From this PDF: REQ-AUTO-00791; REQ-AUTO-00792; REQ-AUTO-00793; REQ-AUTO-00794; REQ-AUTO-00796; REQ-AUTO-00797; REQ-AUTO-00798; REQ-AUTO-00799; REQ-AUTO-00800; REQ-AUTO-00802; REQ-AUTO-00804; REQ-AUTO-00805; REQ-AUTO-00806; REQ-AUTO-00807; REQ-AUTO-00809; REQ-AUTO-00811; REQ-AUTO-00813; REQ-AUTO-00815; REQ-AUTO-00816; REQ-AUTO-00819; REQ-AUTO-00825; REQ-AUTO-00826; REQ-AUTO-00828; REQ-AUTO-00829; REQ-AUTO-00830; REQ-AUTO-00833; REQ-AUTO-00835; REQ-AUTO-00836; REQ-AUTO-00837; REQ-AUTO-00838. This SSR is also supported by requirements from other PDFs.Backend and IT integrationNoneNoneSharedBlocked by Customer ClarificationReview + Test
SSR-RBAC-004Application software behavior — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Application software behavior, restricting security-relevant diagnostic services per the OEM-agreed role model.From this PDF: REQ-AUTO-00822; REQ-AUTO-00823; REQ-AUTO-00834. This SSR is also supported by requirements from other PDFs.Application software behaviorNoneNoneSharedBlocked by Customer ClarificationReview + Test
SSR-RBAC-005Hardware platform support — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Hardware platform support, restricting security-relevant diagnostic services per the OEM-agreed role model.From this PDF: REQ-AUTO-00789. Hardware platform supportNoneNoneSharedBlocked by Customer ClarificationReview + Test
SSR-RBAC-006System behavior — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for System behavior, restricting security-relevant diagnostic services per the OEM-agreed role model.From this PDF: REQ-AUTO-00790; REQ-AUTO-00795; REQ-AUTO-00801; REQ-AUTO-00812; REQ-AUTO-00827; REQ-AUTO-00831. System behaviorNoneNoneSupplier-OwnedCandidateReview + Test
SSR-SYS-005System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.From this PDF: REQ-AUTO-00787; REQ-AUTO-00824; REQ-AUTO-00841. This SSR is also supported by requirements from other PDFs.System behaviorNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationTest
SSR-SYS-008Application software behavior — System FunctionThe ECU shall implement the Application software behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.From this PDF: REQ-AUTO-00840. This SSR is also supported by requirements from other PDFs.Application software behaviorNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationTest
SSR-SYS-009System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.From this PDF: REQ-AUTO-00786. This SSR is also supported by requirements from other PDFs.System behaviorNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateTest
SSR-TOOL-002Backend and IT integration — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Backend and IT integration.From this PDF: REQ-AUTO-00803. This SSR is also supported by requirements from other PDFs.Backend and IT integrationNoneNoneSharedBlocked by Customer ClarificationReview + Test

System / Security Design Impact

Impact AreaEvidence From This PDF
Impacted system featuresApplication software behavior; Authentication; Backend and IT integration; Certificate handling; Diagnostic security; External interfaces; Hardware platform support; System behavior
Impacted interfacesExternal Interfaces
Impacted security capabilitiesAuthentication; Certificate handling; Diagnostic security
Impacted architecture elementsApplication Software; Backend and IT Systems; Compliance Process; External Interfaces; Hardware Platform; Security Services; System Core
Impacted work productsCybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; Requirement traceability record; System/architecture design
Tools / IT / hardware / testHigh/High/Medium; High/Low/Medium; Low/High/Low; Low/Low/Low; Medium/High/High; Medium/High/Low; Medium/High/Medium; Medium/Low/Low; Medium/Low/Medium
Design assumptions introducedSecurity-relevant requirement the ECU can own once responsibility/method is confirmed.
Design decisions requiredAgree responsibility split (DIA) for the non-ECU portion.

Estimation / Resource / Tooling Impact

ImpactStatus
Estimation impactyes
Resource/tool/IT/HW/test impactHigh/High/Medium; High/Low/Medium; Low/High/Low; Low/Low/Low; Medium/High/High; Medium/High/Low; Medium/High/Medium; Medium/Low/Low; Medium/Low/Medium

Document Impact Diagram

Document Impact

Generated from document-specific requirement, traceability, SSR, and open-point evidence.

flowchart LR doc["CVS151.pdf"] d0["Authentication"] doc --> d0 d1["Certificate handling"] doc --> d1 d2["Diagnostic security"] doc --> d2 f0["Feature: Application software behavior"] doc --> f0 f1["Feature: Authentication"] doc --> f1 f2["Feature: Backend and IT integration"] doc --> f2 i0["Interface: External Interfaces"] doc --> i0 s0["SSR: SSR-COM-002"] doc --> s0 s1["SSR: SSR-COM-003"] doc --> s1 s2["SSR: SSR-DIAG-003"] doc --> s2 o0["Open point: OP-002"] doc --> o0 o1["Open point: OP-003"] doc --> o1
Mermaid source
flowchart LR
  doc["CVS151.pdf"]
  d0["Authentication"]
  doc --> d0
  d1["Certificate handling"]
  doc --> d1
  d2["Diagnostic security"]
  doc --> d2
  f0["Feature: Application software behavior"]
  doc --> f0
  f1["Feature: Authentication"]
  doc --> f1
  f2["Feature: Backend and IT integration"]
  doc --> f2
  i0["Interface: External Interfaces"]
  doc --> i0
  s0["SSR: SSR-COM-002"]
  doc --> s0
  s1["SSR: SSR-COM-003"]
  doc --> s1
  s2["SSR: SSR-DIAG-003"]
  doc --> s2
  o0["Open point: OP-002"]
  doc --> o0
  o1["Open point: OP-003"]
  doc --> o1

Traceability

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Customer RequirementSSRDispositionConfidenceReason
REQ-AUTO-00785NoneInformational Onlyn/aNon-binding; not derived.
REQ-AUTO-00786SSR-SYS-009Covered by Existing Supplier System RequirementHighAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00787SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00788SSR-RBAC-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00789SSR-RBAC-005Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00790SSR-RBAC-006Derive Supplier System RequirementMediumAccepted requirement; seed of its SSR cluster.
REQ-AUTO-00791SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00792SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00793SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00794SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00795SSR-RBAC-006Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00796SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00797SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00798SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00799SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00800SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00801SSR-RBAC-006Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00802SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00803SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00804SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00805SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00806SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00807SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00808SSR-RBAC-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00809SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00810SSR-DIAG-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00811SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00812SSR-RBAC-006Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00813SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00814SSR-DIAG-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00815SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00816SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00817SSR-DIAG-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00818SSR-KEY-002Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00819SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00820SSR-COM-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00821SSR-KEY-002Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00822SSR-RBAC-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00823SSR-RBAC-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00824SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00825SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00826SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00827SSR-RBAC-006Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00828SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00829SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00830SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00831SSR-RBAC-006Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00832SSR-RBAC-002Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00833SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00834SSR-RBAC-004Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00835SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00836SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00837SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00838SSR-RBAC-003Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00839SSR-KEY-002Covered by Existing Supplier System RequirementLowAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00840SSR-SYS-008Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00841SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00842SSR-COM-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.

Detailed Evidence

Document intelligence markdown

CVS151

  • Source PDF: customer-input/pdf/CVS151.pdf
  • Converted Markdown: converted/markdown/CVS151.md
  • Document type: Security Access / RBAC Standard
  • Domain: Security Access / RBAC
  • Confidence: High
  • Evidence basis: Markdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Executive Summary

Confirmed by requirements: this security access / rbac standard contributes 58 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior. Inferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence.

Confirmed by requirements: supplier positioning is 5 accept; 10 accept with assumption; 42 partially accept; 1 informational only. The generated traceability links this document to 14 supplier system requirement records. Inferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.

Requires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. Do not convert these items into agreed baseline scope until the customer confirms the decision. Confidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Document Abstract

FieldInterpretation
Document PurposeConfirmed by requirements: this security access / rbac standard contributes 58 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior.
Engineering InterpretationInferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence.
Supplier Proposal ImpactConfirmed by requirements: supplier positioning is 5 accept; 10 accept with assumption; 42 partially accept; 1 informational only. The generated traceability links this document to 14 supplier system requirement records.
System / Security ImpactInferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; responsibility and customer approval model; cybersecurity concept and evidence. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.
Customer Clarification ImpactRequires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.; Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier. Do not convert these items into agreed baseline scope until the customer confirms the decision.
Confidence and LimitsConfidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Main Requirement Themes

ThemeSummaryRequirement CountRepresentative Requirements
Core ECA system behaviorDefines actuator ECU behavior, drivetrain integration, electrical/mechanical constraints, and verification scope.52REQ-AUTO-00785; REQ-AUTO-00786; REQ-AUTO-00787
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.44REQ-AUTO-00785; REQ-AUTO-00786; REQ-AUTO-00788
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.42REQ-AUTO-00786; REQ-AUTO-00788; REQ-AUTO-00791
Diagnostics and service accessDefines UDS service behavior, authorization expectations, safe-state checks, and diagnostic evidence.26REQ-AUTO-00785; REQ-AUTO-00788; REQ-AUTO-00789
System architecture designGroups related document requirements into a single engineering theme.16REQ-AUTO-00785; REQ-AUTO-00787; REQ-AUTO-00789
SystemGroups related document requirements into a single engineering theme.10REQ-AUTO-00785; REQ-AUTO-00787; REQ-AUTO-00790
System coreGroups related document requirements into a single engineering theme.9REQ-AUTO-00787; REQ-AUTO-00790; REQ-AUTO-00795
CybersecurityGroups related document requirements into a single engineering theme.6REQ-AUTO-00788; REQ-AUTO-00808; REQ-AUTO-00818

Document Content Structure

SectionRequirementsCriticalOpen PointsSSR Links
2 Terms, definitions and abbrevations1001
-- 2.1 Document quirks1001
3 Technical content5042211
-- 3.2 Role Based Access Control Configuration9713
-- 3.3 ASN.1 definition1101
-- 3.6 role-configuration9713
-- 3.8 did-rules6514
-- 3.9 rid-rules3312
-- 3.10 Extending the Role Based Access Control Configuration using a certificate2222
-- 3.12 Logic8715
-- 3.14 Requests Specific Requirements121014
-- -- 3.14.1 Diagnostic over USD121014
4 Referenced documents4004
-- 4.1 Normative references4004

What this document does not confirm

Customer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.

Critical Requirements

IDScoreCategoryReasonStatement
REQ-AUTO-0078977High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactRBAC_INFO 2 Before a client can execute diagnostics services that are under RBAC, the client must perform some type of authorization procedure towards the server/ECU.
REQ-AUTO-0080477High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactRBAC_REQ 11 The server shall report the currently stored RBACC’s version via diagnostics.
REQ-AUTO-0080677High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactRBAC_REQ 13 The server shall report the currently stored RBACC’s rbacc-id via diagnostics.
REQ-AUTO-0080877High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPage 9 3.7 pattern-rules RBAC_REQ 15 The server shall support for every entry in the pattern-rules one octet for the pattern rule settings followed by the diagnostic pattern of variable length.
REQ-AUTO-0081077High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactTable 1 – Pattern Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.
REQ-AUTO-0081477High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPage 10 Table 2 – DID Rule Settings Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.
REQ-AUTO-0081777High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPage 11 Table 3 – RID Rule Setting Bit index Name Description 0 Reserved Reserved 1 UDS 0 == This rule is not valid for a UDS-server 1 == This rule is valid for a UDS-server This bit shall always assume value 1 2 Reserved Reserved 3 Confidentiality 0 == No confidentiality is required on the diagnostics request 1 == Confidentiality is required on the diagnostics request e.g., 0x84 (CVS32) Note: This bit is supported but not used for deny rules.
REQ-AUTO-0081877High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactRBAC_REQ 22 If conflicting/overlapping rules are found between the client certificate D-RBACC extension and any rules in the RBAC-configuration in the RBACC, the server shall enforce the rules in the client certificate D-RBACC extension.
REQ-AUTO-0082177High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impact3.11 ECU-Diagnostics-Role Extension RBAC_REQ 36 The server shall exert the RBACC roles based on the ECU-diagnostics-Role extension on the client’s certificate.
REQ-AUTO-0083277High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impact3.14 Requests Specific Requirements 3.14.1 Diagnostic over USD 3.14.1.1 Authenticate 0x29 RBAC_REQ 28 The server shall always allow reception of UDS authenticate 0x29 requests regardless of the RBACC settings.

Open Points

Open PointPriorityQuestionImpactStatus
OP-002Confirm the diagnostic role model, the authorized services per role, and which party owns the diagnostic authorization policy.Security-access design and verification scope cannot be frozen; risk of an unprotected diagnostic service.Open
OP-003Confirm ownership and provisioning flow for keys/certificates (generation, injection, storage, renewal, revocation) between OEM and supplier.ECU secure-storage and provisioning design is blocked; production-line and PKI dependencies stay open.Open

Supplier System Requirements

SSRTitleStatementReqs From This PDFOther PDFsStatus
SSR-COM-002External Interfaces — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for External Interfaces, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals.REQ-AUTO-00842yesBlocked by Customer Clarification
SSR-COM-003Backend and IT integration — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Backend and IT integration, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals.REQ-AUTO-00820yesBlocked by Customer Clarification
SSR-DIAG-003Backend and IT integration — Diagnostic ServicesThe ECU shall provide the diagnostic services for Backend and IT integration required by the allocated customer requirements, including the specified services, sessions and data identifiers.REQ-AUTO-00810; REQ-AUTO-00814; REQ-AUTO-00817yesBlocked by Customer Clarification
SSR-KEY-002Certificate handling — Key and Certificate HandlingThe ECU shall manage key and certificate material for Certificate handling across provisioning, storage, use, renewal and revocation per the agreed key lifecycle.REQ-AUTO-00818; REQ-AUTO-00821; REQ-AUTO-00839yesBlocked by Customer Clarification
SSR-RBAC-001Diagnostic security — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Diagnostic security, restricting security-relevant diagnostic services per the OEM-agreed role model.REQ-AUTO-00788; REQ-AUTO-00808yesBlocked by Customer Clarification
SSR-RBAC-002Authentication — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Authentication, restricting security-relevant diagnostic services per the OEM-agreed role model.REQ-AUTO-00832yesBlocked by Customer Clarification
SSR-RBAC-003Backend and IT integration — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Backend and IT integration, restricting security-relevant diagnostic services per the OEM-agreed role model.REQ-AUTO-00791; REQ-AUTO-00792; REQ-AUTO-00793; REQ-AUTO-00794; REQ-AUTO-00796; REQ-AUTO-00797; REQ-AUTO-00798; REQ-AUTO-00799; REQ-AUTO-00800; REQ-AUTO-00802; REQ-AUTO-00804; REQ-AUTO-00805; REQ-AUTO-00806; REQ-AUTO-00807; REQ-AUTO-00809; REQ-AUTO-00811; REQ-AUTO-00813; REQ-AUTO-00815; REQ-AUTO-00816; REQ-AUTO-00819; REQ-AUTO-00825; REQ-AUTO-00826; REQ-AUTO-00828; REQ-AUTO-00829; REQ-AUTO-00830; REQ-AUTO-00833; REQ-AUTO-00835; REQ-AUTO-00836; REQ-AUTO-00837; REQ-AUTO-00838yesBlocked by Customer Clarification
SSR-RBAC-004Application software behavior — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Application software behavior, restricting security-relevant diagnostic services per the OEM-agreed role model.REQ-AUTO-00822; REQ-AUTO-00823; REQ-AUTO-00834yesBlocked by Customer Clarification
SSR-RBAC-005Hardware platform support — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for Hardware platform support, restricting security-relevant diagnostic services per the OEM-agreed role model.REQ-AUTO-00789noBlocked by Customer Clarification
SSR-RBAC-006System behavior — Secure Diagnostics / RBACThe ECU shall enforce authenticated, role-authorised access for System behavior, restricting security-relevant diagnostic services per the OEM-agreed role model.REQ-AUTO-00790; REQ-AUTO-00795; REQ-AUTO-00801; REQ-AUTO-00812; REQ-AUTO-00827; REQ-AUTO-00831noCandidate
SSR-SYS-005System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.REQ-AUTO-00787; REQ-AUTO-00824; REQ-AUTO-00841yesBlocked by Customer Clarification
SSR-SYS-008Application software behavior — System FunctionThe ECU shall implement the Application software behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.REQ-AUTO-00840yesBlocked by Customer Clarification
SSR-SYS-009System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.REQ-AUTO-00786yesCandidate
SSR-TOOL-002Backend and IT integration — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Backend and IT integration.REQ-AUTO-00803yesBlocked by Customer Clarification

Design Impact

  • Impacted System Features: Application software behavior; Authentication; Backend and IT integration; Certificate handling; Diagnostic security; External interfaces; Hardware platform support; System behavior
  • Impacted Interfaces: External Interfaces
  • Impacted Security Capabilities: Authentication; Certificate handling; Diagnostic security
  • Impacted Architecture Elements: Application Software; Backend and IT Systems; Compliance Process; External Interfaces; Hardware Platform; Security Services; System Core
  • Impacted Work Products: Cybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; Requirement traceability record; System/architecture design
  • Impacted Tools It Hardware Test: High/High/Medium; High/Low/Medium; Low/High/Low; Low/Low/Low; Medium/High/High; Medium/High/Low; Medium/High/Medium; Medium/Low/Low (showing 8 of 9)
  • Impacted Supplier System Requirements: SSR-COM-002; SSR-COM-003; SSR-DIAG-003; SSR-KEY-002; SSR-RBAC-001; SSR-RBAC-002; SSR-RBAC-003; SSR-RBAC-004 (showing 8 of 14)
  • Design Assumptions Introduced: Security-relevant requirement the ECU can own once responsibility/method is confirmed.
  • Design Decisions Required: Agree responsibility split (DIA) for the non-ECU portion.