CVS154

Responsibility Agreement / CIA / RASIC · Responsibility / Process · Core ECA system behavior

Back to Document Intelligence

Executive Takeaway

Confirmed by requirements: this responsibility agreement / cia / rasic contributes 36 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior. Inferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model.

Confirmed by requirements: supplier positioning is 22 accept; 4 accept with assumption; 7 partially accept; 1 needs customer clarification; 2 informational only. The generated traceability links this document to 9 supplier system requirement records. Inferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.

Requires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).; Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. Do not convert these items into agreed baseline scope until the customer confirms the decision. Confidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Requirements36from this PDF
Critical8ranked
Open Points2linked
Derived SSRs9linked
Concept Impactyesdocument-specific
Estimation Impactyesdocument-specific

Document Abstract

Document Purpose

Confirmed by requirements: this responsibility agreement / cia / rasic contributes 36 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior.

Engineering Interpretation

Inferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model.

Main Requirement Themes

Core ECA system behavior; Cybersecurity concept and evidence; Responsibility and customer approval model; System architecture design; System (showing 5 of 8)

System / Security Impact

Inferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.

Supplier Proposal Impact

Confirmed by requirements: supplier positioning is 22 accept; 4 accept with assumption; 7 partially accept; 1 needs customer clarification; 2 informational only. The generated traceability links this document to 9 supplier system requirement records.

Customer Clarification Impact

Requires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).; Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. Do not convert these items into agreed baseline scope until the customer confirms the decision.

Confidence and Limits

Confidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Main Requirement Themes

ThemeEngineering MeaningRequirement CountRepresentative Requirements
Core ECA system behaviorDefines actuator ECU behavior, drivetrain integration, electrical/mechanical constraints, and verification scope.33REQ-AUTO-00843; REQ-AUTO-00844; REQ-AUTO-00845
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.26REQ-AUTO-00843; REQ-AUTO-00844; REQ-AUTO-00847
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.24REQ-AUTO-00843; REQ-AUTO-00844; REQ-AUTO-00847
System architecture designGroups related document requirements into a single engineering theme.15REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856
SystemGroups related document requirements into a single engineering theme.14REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856
System coreGroups related document requirements into a single engineering theme.14REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856
ConstraintGroups related document requirements into a single engineering theme.3REQ-AUTO-00844; REQ-AUTO-00855; REQ-AUTO-00857
Secure communication and freshness protectionDefines protected communication behavior, freshness/replay checks, and signal or PDU allocation dependencies.3REQ-AUTO-00843; REQ-AUTO-00866; REQ-AUTO-00867

Document Content Structure

SectionRequirementsCriticalOpen PointsSSR Links
1 Scope1001
-- 1.1 Target readers1001
3 Technical content31828
-- 3.1 DSC structure19405
-- -- 3.1.1 VerificationEntry3102
-- -- 3.1.2 EncryptionEntry6003
-- 3.2 DSC ASN.1 definition1110
-- 3.3 DSC sanity check and verification11316
4 Referenced documents and IT-Systems1001
-- 4.2 Informative references1001

What This PDF Is About

FieldValue
Source PDFcustomer-input/pdf/CVS154.pdf
Converted Markdownconverted/markdown/CVS154.md
Document TypeResponsibility Agreement / CIA / RASIC
DomainResponsibility / Process
Scope Summary36 extracted requirements; 9 linked SSRs; 2 linked open points.
Main ThemesCore ECA system behavior; Cybersecurity concept and evidence; Responsibility and customer approval model; System architecture design; System (showing 5 of 8)
Does Not ConfirmCustomer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.
ConfidenceHigh
Evidence BasisMarkdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Key Conclusions From This PDF

Critical Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

IDScoreCategoryRequirement / ReasonSupplier Position
REQ-AUTO-0086695High risk due to unclear OEM/supplier responsibility3.2 DSC ASN.1 definition DSC_BASE_REQ 41 The structure version for this document release shall be: Major ‘04’ and Minor ‘00’ DSC_BASE_REQ 42 The server shall have support for the ASN.1 contents as defined: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }security relevant; architecture relevant; Needs Customer Clarification; linked open point; Unknown estimation impact; blocks SSR derivationNeeds Customer Clarification
REQ-AUTO-0087377High risk due to unclear OEM/supplier responsibilityDSC_BASE_INFO 35 The verification of servers support of specified dataRanges in the VerificationEntry, shall be stated for the DSC instance.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0087677High risk due to unclear OEM/supplier responsibilityDSC_BASE_INFO 36 The verification of servers support of specified dataRanges in the EncryptionEntry, shall be stated for the DSC instance.security relevant; architecture relevant; Partially Accept; linked open point; High estimation impactPartially Accept
REQ-AUTO-0084948High risk due to unclear OEM/supplier responsibilityDSC_BASE_REQ 29 The server shall support a DSC containing verificationEntries.security relevant; architecture relevant; Partially AcceptPartially Accept
REQ-AUTO-0085248High risk due to unclear OEM/supplier responsibilityDSC_BASE_REQ 45 The server shall expect an ASN.1 SEQUENCE tag with length zero for verificationEntries that contains no VerificationEntry items in a DSC transmitted by the client.security relevant; architecture relevant; Partially AcceptPartially Accept
REQ-AUTO-0085548High risk due to unclear OEM/supplier responsibilityDSC_BASE_REQ 26 The server shall support an empty DSC containing only Metadata (version and id) and the empty sequences for verificationEntries, encryptionEntries and ItemEntries.security relevant; architecture relevant; Partially AcceptPartially Accept
REQ-AUTO-0085748High risk due to unclear OEM/supplier responsibilityPage 6 DSC_BASE_INFO 33 A DSC containing only version and id states that verification and encryption is not to be performed by the server, although the server shall have the support.security relevant; architecture relevant; Partially AcceptPartially Accept
REQ_DSC_BASE-2048High risk due to unclear OEM/supplier responsibilityREQ_DSC_BASE 20 The version shall be verified with the servers supported Major and Minor version of the DSC logic for compliancy.security relevant; architecture relevant; Partially AcceptPartially Accept
REQ-AUTO-0087544High impact on PKI/key ownershipDSC_BASE_REQ 22 The length of key and iv shall be verified accordingly to the algorithm stipulated in EncryptionEntry.security relevant; architecture relevant; High estimation impactAccept with Assumption
REQ-AUTO-0085830General project impact3.1.1.1 HashCmp DSC_BASE_REQ 5 VerificationEntry hashCmp states that a hash comparison shall be used to verify the data.security relevant; architecture relevantAccept with Assumption
REQ-AUTO-0086030General project impactPage 7 • hashAlgorithm: States which HashAlgorithm (see RFC 6234) shall be used for hashing the data to verify.security relevant; architecture relevantAccept with Assumption
REQ-AUTO-0087830General project impactThe sequence tags for verificationEntries, encryptionEntries and itemEntries are required but empty (zero length).security relevant; architecture relevantAccept with Assumption

Customer Clarifications / Open Points

Total Open Points2document-linked
P10priority
P20priority
Blocking Conceptyesyes/no
Blocking Estimationyesyes/no
Blocking SSRyesyes/no

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Open PointPriorityQuestion / ImpactRequired Customer DecisionRecommended Supplier PositionOwnerStatus
OP-001Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).TARA scope and effort stay open; downstream assets, goals and design may rework.Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).Proceed on the working ECA-ECU interpretation; flag every TARA-scope statement as assumption until confirmed.OEM / CustomerOpen
OP-011Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.Decide whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context.Carry the items as customer-confirmation dependencies and review them in the next clarification workshop.OEM / CustomerOpen

Requirements From This PDF

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

IDRequirement / ProposalSupplier PositionReviewSecurity CapabilityFeature / InterfaceSSROpen PointSource
REQ-AUTO-008663.2 DSC ASN.1 definition DSC_BASE_REQ 41 The structure version for this document release shall be: Major ‘04’ and Minor ‘00’ DSC_BASE_REQ 42 The server shall have support for the ASN.1 contents as defined: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }Proposal: Needs customer clarification. The requirement implies customer-owned infrastructure, approval, or a responsibility split that is not yet available.Needs Customer ClarificationReviewed InternallyNoneBackend and IT integration; Security evidence and traceability
OEM/Customer Review Interface
NoneOP-0113.2 DSC ASN.1 definition
page 9
Source details
Document section

3.2 DSC ASN.1 definition

Section path

3 Technical content > 3.2 DSC ASN.1 definition

Page reference

page 9

REQ-AUTO-00873DSC_BASE_INFO 35 The verification of servers support of specified dataRanges in the VerificationEntry, shall be stated for the DSC instance.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneSystem behavior; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-001OP-0013.3 DSC sanity check and verification
page 11
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 11

REQ-AUTO-00876DSC_BASE_INFO 36 The verification of servers support of specified dataRanges in the EncryptionEntry, shall be stated for the DSC instance.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.Partially AcceptProposal ReadyNoneSystem behavior; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-001OP-0013.3 DSC sanity check and verification
page 11
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 11

REQ-AUTO-00849DSC_BASE_REQ 29 The server shall support a DSC containing verificationEntries.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00852DSC_BASE_REQ 45 The server shall expect an ASN.1 SEQUENCE tag with length zero for verificationEntries that contains no VerificationEntry items in a DSC transmitted by the client.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00855DSC_BASE_REQ 26 The server shall support an empty DSC containing only Metadata (version and id) and the empty sequences for verificationEntries, encryptionEntries and ItemEntries.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00857Page 6 DSC_BASE_INFO 33 A DSC containing only version and id states that verification and encryption is not to be performed by the server, although the server shall have the support.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneBackend and IT integration; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-002-3.1.1 VerificationEntry
page 6
Source details
Document section

3.1.1 VerificationEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.1 VerificationEntry

Page reference

page 6

REQ_DSC_BASE-20REQ_DSC_BASE 20 The version shall be verified with the servers supported Major and Minor version of the DSC logic for compliancy.Proposal: Partially accept. Supplier can implement the ECU-side behaviour, but OEM-owned backend/PKI/fleet responsibilities require customer confirmation.Partially AcceptProposal ReadyNoneApplication software behavior
None
SSR-SYS-008-3.3 DSC sanity check and verification
page 10
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 10

REQ-AUTO-00875DSC_BASE_REQ 22 The length of key and iv shall be verified accordingly to the algorithm stipulated in EncryptionEntry.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyKey managementKey management
None
SSR-KEY-001-3.3 DSC sanity check and verification
page 11
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 11

REQ-AUTO-008583.1.1.1 HashCmp DSC_BASE_REQ 5 VerificationEntry hashCmp states that a hash comparison shall be used to verify the data.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneSystem behavior; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-001-3.1.1 VerificationEntry
page 6
Source details
Document section

3.1.1 VerificationEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.1 VerificationEntry

Page reference

page 6

REQ-AUTO-00860Page 7 • hashAlgorithm: States which HashAlgorithm (see RFC 6234) shall be used for hashing the data to verify.Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.1.2 EncryptionEntry
page 7
Source details
Document section

3.1.2 EncryptionEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.2 EncryptionEntry

Page reference

page 7

REQ-AUTO-00878The sequence tags for verificationEntries, encryptionEntries and itemEntries are required but empty (zero length).Proposal: Accept. Implement as part of the cybersecurity concept and map to verification evidence, assuming the customer confirms responsibility allocation and method.Accept with AssumptionProposal ReadyNoneSystem behavior; Security evidence and traceability
OEM/Customer Review Interface
SSR-VV-001-4.2 Informative references
page 14
Source details
Document section

4.2 Informative references

Section path

4 Referenced documents and IT-Systems > 4.2 Informative references

Page reference

page 14

REQ-AUTO-00861• dataRanges: sequence of Range items - Range: Information on which data chunks that shall be verified.Proposal: Accept. Provide the cybersecurity concept as a supplier work product covering scope, assumptions, risk-treatment traceability, cybersecurity goals/requirements, mitigation strategy, V&V approach, and open responsibility dependencies.AcceptProposal ReadyNoneSystem behavior
None
SSR-CON-002-3.1.2 EncryptionEntry
page 7
Source details
Document section

3.1.2 EncryptionEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.2 EncryptionEntry

Page reference

page 7

REQ-AUTO-00863DSC_BASE_REQ 39 For crypto agility reasons, both of the choices shall be supported by the server.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1.2 EncryptionEntry
page 7
Source details
Document section

3.1.2 EncryptionEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.2 EncryptionEntry

Page reference

page 7

REQ-AUTO-00859However, the instance specification may state specialized actions: • Server processes each VerificationEntry one by one.Proposal: Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.Informational OnlyProposal ReadyNoneSecurity evidence and traceability
None
None-3.1.1 VerificationEntry
page 6
Source details
Document section

3.1.1 VerificationEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.1 VerificationEntry

Page reference

page 6

REQ-AUTO-00843Data Security Container base definition Foreword This Commercial Vehicle Standard (“CVS154”) contains requirement specifications for TRATON Group and may be referred to by any of its commercial vehicle Affiliates.Proposal: Informational only. Keep as context; do not treat as an implementation requirement unless the customer confirms applicability.Informational OnlyProposal ReadyNoneNone
None
None-page-1 Page 1
page 1
Source details
Document section

page-1 Page 1

Section path

Page 1

Page reference

page 1

REQ-AUTO-00844Any review of this CVS154 shall only be done in agreement with the involved TRATON Group commercial vehicle Affiliates stated in the table below under section “Technical responsibility”.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-009-page-1 Page 1
page 1
Source details
Document section

page-1 Page 1

Section path

Page 1

Page reference

page 1

REQ-AUTO-00845The User shall apply the latest version of this CVS154.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-page-1 Page 1
page 1
Source details
Document section

page-1 Page 1

Section path

Page 1

Page reference

page 1

REQ-AUTO-00846This document shall be used accompanied with these specifications.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-1.1 Target readers
page 3
Source details
Document section

1.1 Target readers

Section path

1 Scope > 1.1 Target readers

Page reference

page 3

REQ-AUTO-00847DSC_BASE_REQ 37 The server shall support a DSC Metadata block containing version and id fields.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00848DSC_BASE_REQ 43 The server shall support the Major and Minor version as specified in 3.2.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00850DSC_BASE_REQ 30 The server shall support a DSC containing encryptionEntries.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00851DSC_BASE_REQ 31 The server shall support a DSC containing itemEntries.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00853DSC_BASE_REQ 46 The server shall expect an ASN.1 SEQUENCE tag with length zero for encryptionEntries that contains no EncryptionEntry items in a DSC transmitted by the client.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00854DSC_BASE_REQ 49 The server shall expect an ASN.1 SEQUENCE tag with length zero for ItemEntries that contains no items in a DSC transmitted by the client.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00856DSC_BASE_INFO 44 An empty DSC issued by client means that in addition to Metadata, the syntax must be correct in accordance with Annex B.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.1 DSC structure
page 5
Source details
Document section

3.1 DSC structure

Section path

3 Technical content > 3.1 DSC structure

Page reference

page 5

REQ-AUTO-00862DSC_BASE_REQ 47 The server shall support the SHA512 HashAlgorithm as referred in 3.2 ASN1 definition.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.1.2 EncryptionEntry
page 7
Source details
Document section

3.1.2 EncryptionEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.2 EncryptionEntry

Page reference

page 7

REQ-AUTO-00864DSC_BASE_REQ 11 The initial counter value shall be set to 0 (zero).Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.1.2 EncryptionEntry
page 7
Source details
Document section

3.1.2 EncryptionEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.2 EncryptionEntry

Page reference

page 7

REQ-AUTO-00865Range: Information on which data chunks that shall be decrypted.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.1.2 EncryptionEntry
page 8
Source details
Document section

3.1.2 EncryptionEntry

Section path

3 Technical content > 3.1 DSC structure > 3.1.2 EncryptionEntry

Page reference

page 8

REQ-AUTO-00867DSC_BASE_REQ 19 Upon reception of a DSC to the server, before the DSC is stored in NVM, the DSC shall be semantically verified by parsing all its content.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSecure communication and freshness protection; Backend and IT integration
None
SSR-COM-006-3.3 DSC sanity check and verification
page 10
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 10

REQ-AUTO-00868DSC_BASE_REQ 51 The length of the version field shall be verified.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.3 DSC sanity check and verification
page 10
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 10

REQ-AUTO-00870DSC_BASE_REQ 34 The length of the id field shall be verified.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.3 DSC sanity check and verification
page 10
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 10

REQ-AUTO-00871DSC_BASE_REQ 27 The hashAlgorithm shall be supported by the server.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.3 DSC sanity check and verification
page 10
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 10

REQ-AUTO-00872Page 11 DSC_BASE_REQ 50 The length of every referenceHash shall be consistent with the output size of the hash algorithm specified in the hashAlgorithm.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneSystem behavior
None
SSR-SYS-005-3.3 DSC sanity check and verification
page 11
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 11

REQ-AUTO-00874DSC_BASE_REQ 28 The EncryptionEntry algorithm shall be supported by the server.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.3 DSC sanity check and verification
page 11
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 11

REQ-AUTO-00877DSC_BASE_REQ 48 If the DSC instance is rejected by the server (see Annex A) when transmitted with EMP, an error code shall be returned to the client.Proposal: Accept. Implement the ECA ECU behavior against the mapped feature/interface and verify through supplier test evidence, subject to customer-confirmed responsibility and acceptance criteria.AcceptProposal ReadyNoneBackend and IT integration
None
SSR-TOOL-002-3.3 DSC sanity check and verification
page 11
Source details
Document section

3.3 DSC sanity check and verification

Section path

3 Technical content > 3.3 DSC sanity check and verification

Page reference

page 11

Derived Supplier System Requirements

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

SSRStatement / TraceFeatureSecurity CapabilityInterfaceResponsibilityStatusVerification
SSR-COM-006Secure communication and freshness protection — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure communication and freshness protection, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals.From this PDF: REQ-AUTO-00867. This SSR is also supported by requirements from other PDFs.Secure communication and freshness protectionNoneNoneSharedBlocked by Customer ClarificationReview + Test
SSR-CON-002System behavior — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering System behavior.From this PDF: REQ-AUTO-00861. System behaviorNoneNoneSupplier-OwnedReady for Internal ReviewReview + Test
SSR-KEY-001Key management — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key management across provisioning, storage, use, renewal and revocation per the agreed key lifecycle.From this PDF: REQ-AUTO-00875. This SSR is also supported by requirements from other PDFs.Key managementKey managementOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test
SSR-SYS-005System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.From this PDF: REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856; REQ-AUTO-00860; REQ-AUTO-00864; REQ-AUTO-00865; REQ-AUTO-00868; REQ-AUTO-00870; REQ-AUTO-00872. This SSR is also supported by requirements from other PDFs.System behaviorNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationTest
SSR-SYS-008Application software behavior — System FunctionThe ECU shall implement the Application software behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.From this PDF: REQ_DSC_BASE-20. This SSR is also supported by requirements from other PDFs.Application software behaviorNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationTest
SSR-SYS-009System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.From this PDF: REQ-AUTO-00844. This SSR is also supported by requirements from other PDFs.System behaviorNoneOEM/Customer Review InterfaceSupplier-OwnedCandidateTest
SSR-TOOL-002Backend and IT integration — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Backend and IT integration.From this PDF: REQ-AUTO-00847; REQ-AUTO-00848; REQ-AUTO-00850; REQ-AUTO-00851; REQ-AUTO-00853; REQ-AUTO-00854; REQ-AUTO-00862; REQ-AUTO-00863; REQ-AUTO-00871; REQ-AUTO-00874; REQ-AUTO-00877. This SSR is also supported by requirements from other PDFs.Backend and IT integrationNoneNoneSharedBlocked by Customer ClarificationReview + Test
SSR-VV-001System behavior — Verification and ValidationThe supplier shall verify and validate System behavior per the agreed cybersecurity verification and validation plan.From this PDF: REQ-AUTO-00858; REQ-AUTO-00873; REQ-AUTO-00876; REQ-AUTO-00878. This SSR is also supported by requirements from other PDFs.System behaviorNoneOEM/Customer Review InterfaceSharedBlocked by Customer ClarificationReview + Test
SSR-VV-002Backend and IT integration — Verification and ValidationThe supplier shall verify and validate Backend and IT integration per the agreed cybersecurity verification and validation plan.From this PDF: REQ-AUTO-00849; REQ-AUTO-00852; REQ-AUTO-00855; REQ-AUTO-00857. This SSR is also supported by requirements from other PDFs.Backend and IT integrationNoneOEM/Customer Review InterfaceSharedReady for Customer AlignmentReview + Test

System / Security Design Impact

Impact AreaEvidence From This PDF
Impacted system featuresApplication software behavior; Backend and IT integration; Backend and IT integration; Security evidence and traceability; Key management; Secure communication and freshness protection; Backend and IT integration; Security evidence and traceability; System behavior; System behavior; Security evidence and traceability
Impacted interfacesOEM/Customer Review Interface
Impacted security capabilitiesKey management
Impacted architecture elementsApplication Software; Backend and IT Systems; Backend and IT Systems; OEM/Customer Review Interface; Compliance Process; Security Services; System Core; System Core; OEM/Customer Review Interface
Impacted work productsCybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; Requirement traceability record; System/architecture design
Tools / IT / hardware / testHigh/High/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium; Medium/Low/Medium
Design assumptions introducedSecurity-relevant requirement the ECU can own once responsibility/method is confirmed.
Design decisions requiredSend linked open point to the customer for decision.; Agree responsibility split (DIA) for the non-ECU portion.

Estimation / Resource / Tooling Impact

ImpactStatus
Estimation impactyes
Resource/tool/IT/HW/test impactHigh/High/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium; Medium/Low/Medium

Document Impact Diagram

Document Impact

Generated from document-specific requirement, traceability, SSR, and open-point evidence.

flowchart LR doc["CVS154.pdf"] d0["Key management"] doc --> d0 f0["Feature: Application software behavior"] doc --> f0 f1["Feature: Backend and IT integration"] doc --> f1 f2["Feature: Backend and IT integration; Security evidence and traceability"] doc --> f2 i0["Interface: OEM/Customer Review Interface"] doc --> i0 s0["SSR: SSR-COM-006"] doc --> s0 s1["SSR: SSR-CON-002"] doc --> s1 s2["SSR: SSR-KEY-001"] doc --> s2 o0["Open point: OP-001"] doc --> o0 o1["Open point: OP-011"] doc --> o1
Mermaid source
flowchart LR
  doc["CVS154.pdf"]
  d0["Key management"]
  doc --> d0
  f0["Feature: Application software behavior"]
  doc --> f0
  f1["Feature: Backend and IT integration"]
  doc --> f1
  f2["Feature: Backend and IT integration; Security evidence and traceability"]
  doc --> f2
  i0["Interface: OEM/Customer Review Interface"]
  doc --> i0
  s0["SSR: SSR-COM-006"]
  doc --> s0
  s1["SSR: SSR-CON-002"]
  doc --> s1
  s2["SSR: SSR-KEY-001"]
  doc --> s2
  o0["Open point: OP-001"]
  doc --> o0
  o1["Open point: OP-011"]
  doc --> o1

Traceability

This table is horizontally scrollable. Use the bottom scrollbar to view all columns.

Customer RequirementSSRDispositionConfidenceReason
REQ-AUTO-00843NoneInformational Onlyn/aNon-binding; not derived.
REQ-AUTO-00844SSR-SYS-009Covered by Existing Supplier System RequirementHighAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00845SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00846SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00847SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00848SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00849SSR-VV-002Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00850SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00851SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00852SSR-VV-002Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00853SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00854SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00855SSR-VV-002Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00856SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00857SSR-VV-002Shared Responsibility / CIA NeededLowPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00858SSR-VV-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00859NoneInformational Onlyn/aNon-binding; not derived.
REQ-AUTO-00860SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00861SSR-CON-002Derive Supplier System RequirementHighAccepted requirement; seed of its SSR cluster.
REQ-AUTO-00862SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00863SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00864SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00865SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00866NoneBlocked by Customer Clarificationn/aNeeds customer clarification before derivation.
REQ-AUTO-00867SSR-COM-006Covered by Existing Supplier System RequirementLowAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00868SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ_DSC_BASE-20SSR-SYS-008Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00870SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00871SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00872SSR-SYS-005Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00873SSR-VV-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00874SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00875SSR-KEY-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00876SSR-VV-001Shared Responsibility / CIA NeededMediumPartially accepted; ECU portion mapped, OEM portion needs CIA/RASIC.
REQ-AUTO-00877SSR-TOOL-002Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.
REQ-AUTO-00878SSR-VV-001Covered by Existing Supplier System RequirementMediumAccepted requirement; covered by a clustered SSR.

Detailed Evidence

Document intelligence markdown

CVS154

  • Source PDF: customer-input/pdf/CVS154.pdf
  • Converted Markdown: converted/markdown/CVS154.md
  • Document type: Responsibility Agreement / CIA / RASIC
  • Domain: Responsibility / Process
  • Confidence: High
  • Evidence basis: Markdown-derived requirements and generated RFQX registers; no downstream PDF analysis.

Executive Summary

Confirmed by requirements: this responsibility agreement / cia / rasic contributes 36 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior. Inferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model.

Confirmed by requirements: supplier positioning is 22 accept; 4 accept with assumption; 7 partially accept; 1 needs customer clarification; 2 informational only. The generated traceability links this document to 9 supplier system requirement records. Inferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.

Requires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).; Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. Do not convert these items into agreed baseline scope until the customer confirms the decision. Confidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Document Abstract

FieldInterpretation
Document PurposeConfirmed by requirements: this responsibility agreement / cia / rasic contributes 36 Markdown-derived RFQ requirements with the strongest evidence in core eca system behavior.
Engineering InterpretationInferred from requirement pattern: for RFQX it affects the Electric Clutch Actuator ECU on the TRATON GW AMT platform by shaping core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model.
Supplier Proposal ImpactConfirmed by requirements: supplier positioning is 22 accept; 4 accept with assumption; 7 partially accept; 1 needs customer clarification; 2 informational only. The generated traceability links this document to 9 supplier system requirement records.
System / Security ImpactInferred from mapped features, capabilities, and interfaces: the main design/security impact is core eca system behavior; cybersecurity concept and evidence; responsibility and customer approval model. These themes should drive concept updates, verification evidence, and supplier proposal assumptions only where the linked requirements support them.
Customer Clarification ImpactRequires customer confirmation: 2 document-linked open point(s) remain, mainly: Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).; Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline. Do not convert these items into agreed baseline scope until the customer confirms the decision.
Confidence and LimitsConfidence and limits: High confidence. Evidence is limited to Markdown-derived requirements, registers, open points, and SSR links; no downstream PDF analysis or AI-generated conclusion is claimed.

Main Requirement Themes

ThemeSummaryRequirement CountRepresentative Requirements
Core ECA system behaviorDefines actuator ECU behavior, drivetrain integration, electrical/mechanical constraints, and verification scope.33REQ-AUTO-00843; REQ-AUTO-00844; REQ-AUTO-00845
Cybersecurity concept and evidenceDrives cybersecurity concept, risk treatment, verification evidence, and traceability obligations.26REQ-AUTO-00843; REQ-AUTO-00844; REQ-AUTO-00847
Responsibility and customer approval modelCreates supplier/OEM allocation decisions for work products, backend infrastructure, approvals, and residual risk.24REQ-AUTO-00843; REQ-AUTO-00844; REQ-AUTO-00847
System architecture designGroups related document requirements into a single engineering theme.15REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856
SystemGroups related document requirements into a single engineering theme.14REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856
System coreGroups related document requirements into a single engineering theme.14REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856
ConstraintGroups related document requirements into a single engineering theme.3REQ-AUTO-00844; REQ-AUTO-00855; REQ-AUTO-00857
Secure communication and freshness protectionDefines protected communication behavior, freshness/replay checks, and signal or PDU allocation dependencies.3REQ-AUTO-00843; REQ-AUTO-00866; REQ-AUTO-00867

Document Content Structure

SectionRequirementsCriticalOpen PointsSSR Links
1 Scope1001
-- 1.1 Target readers1001
3 Technical content31828
-- 3.1 DSC structure19405
-- -- 3.1.1 VerificationEntry3102
-- -- 3.1.2 EncryptionEntry6003
-- 3.2 DSC ASN.1 definition1110
-- 3.3 DSC sanity check and verification11316
4 Referenced documents and IT-Systems1001
-- 4.2 Informative references1001

What this document does not confirm

Customer-owned responsibility, final customer decisions, and unresolved open points remain unconfirmed.

Critical Requirements

IDScoreCategoryReasonStatement
REQ-AUTO-0086695High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Needs Customer Clarification; linked open point; Unknown estimation impact; blocks SSR derivation3.2 DSC ASN.1 definition DSC_BASE_REQ 41 The structure version for this document release shall be: Major ‘04’ and Minor ‘00’ DSC_BASE_REQ 42 The server shall have support for the ASN.1 contents as defined: DataSecurityContainer ::= SEQUENCE { version OCTET STRING (SIZE(2)), id OCTET STRING (SIZE(16)), verificationEntries SEQUENCE (SIZE(0..MAX)) OF VerificationEntry, encryptionEntries SEQUENCE (SIZE(0..MAX)) OF EncryptionEntry, itemEntries SEQUENCE (SIZE(0..MAX)) OF ItemEntry } VerificationEntry ::= CHOICE { hashCmp [0] EXPLICIT HashCmp }
REQ-AUTO-0087377High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactDSC_BASE_INFO 35 The verification of servers support of specified dataRanges in the VerificationEntry, shall be stated for the DSC instance.
REQ-AUTO-0087677High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially Accept; linked open point; High estimation impactDSC_BASE_INFO 36 The verification of servers support of specified dataRanges in the EncryptionEntry, shall be stated for the DSC instance.
REQ-AUTO-0084948High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially AcceptDSC_BASE_REQ 29 The server shall support a DSC containing verificationEntries.
REQ-AUTO-0085248High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially AcceptDSC_BASE_REQ 45 The server shall expect an ASN.1 SEQUENCE tag with length zero for verificationEntries that contains no VerificationEntry items in a DSC transmitted by the client.
REQ-AUTO-0085548High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially AcceptDSC_BASE_REQ 26 The server shall support an empty DSC containing only Metadata (version and id) and the empty sequences for verificationEntries, encryptionEntries and ItemEntries.
REQ-AUTO-0085748High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially AcceptPage 6 DSC_BASE_INFO 33 A DSC containing only version and id states that verification and encryption is not to be performed by the server, although the server shall have the support.
REQ_DSC_BASE-2048High risk due to unclear OEM/supplier responsibilitysecurity relevant; architecture relevant; Partially AcceptREQ_DSC_BASE 20 The version shall be verified with the servers supported Major and Minor version of the DSC logic for compliancy.
REQ-AUTO-0087544High impact on PKI/key ownershipsecurity relevant; architecture relevant; High estimation impactDSC_BASE_REQ 22 The length of key and iv shall be verified accordingly to the algorithm stipulated in EncryptionEntry.
REQ-AUTO-0085830General project impactsecurity relevant; architecture relevant3.1.1.1 HashCmp DSC_BASE_REQ 5 VerificationEntry hashCmp states that a hash comparison shall be used to verify the data.

Open Points

Open PointPriorityQuestionImpactStatus
OP-001Confirm the exact ECU designation/variant and the agreed item definition and boundary used for the risk analysis (TARA).TARA scope and effort stay open; downstream assets, goals and design may rework.Open
OP-011Confirm whether each listed requirement is binding supplier scope, customer-owned scope, or evidence-only context for the ECA ECU baseline.Supplier position, estimation, and affected design allocation remain conditional for the listed requirements.Open

Supplier System Requirements

SSRTitleStatementReqs From This PDFOther PDFsStatus
SSR-COM-006Secure communication and freshness protection — Secure Communication and Boundary ControlThe ECU shall restrict and protect communication for Secure communication and freshness protection, exposing only OEM-agreed services and applying authenticity/integrity/freshness and boundary controls on allocated signals.REQ-AUTO-00867yesBlocked by Customer Clarification
SSR-CON-002System behavior — Cybersecurity Concept and EvidenceThe supplier shall produce and maintain the cybersecurity concept and verification evidence covering System behavior.REQ-AUTO-00861noReady for Internal Review
SSR-KEY-001Key management — Key and Certificate HandlingThe ECU shall manage key and certificate material for Key management across provisioning, storage, use, renewal and revocation per the agreed key lifecycle.REQ-AUTO-00875yesBlocked by Customer Clarification
SSR-SYS-005System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.REQ-AUTO-00845; REQ-AUTO-00846; REQ-AUTO-00856; REQ-AUTO-00860; REQ-AUTO-00864; REQ-AUTO-00865; REQ-AUTO-00868; REQ-AUTO-00870; REQ-AUTO-00872yesBlocked by Customer Clarification
SSR-SYS-008Application software behavior — System FunctionThe ECU shall implement the Application software behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.REQ_DSC_BASE-20yesBlocked by Customer Clarification
SSR-SYS-009System behavior — System FunctionThe ECU shall implement the System behavior behaviour required by its allocated customer requirements, including the specified functions, signals, states and timing.REQ-AUTO-00844yesCandidate
SSR-TOOL-002Backend and IT integration — Tooling / IT / Evidence StorageThe supplier shall provide the tooling, IT infrastructure and evidence storage required for Backend and IT integration.REQ-AUTO-00847; REQ-AUTO-00848; REQ-AUTO-00850; REQ-AUTO-00851; REQ-AUTO-00853; REQ-AUTO-00854; REQ-AUTO-00862; REQ-AUTO-00863; REQ-AUTO-00871; REQ-AUTO-00874; REQ-AUTO-00877yesBlocked by Customer Clarification
SSR-VV-001System behavior — Verification and ValidationThe supplier shall verify and validate System behavior per the agreed cybersecurity verification and validation plan.REQ-AUTO-00858; REQ-AUTO-00873; REQ-AUTO-00876; REQ-AUTO-00878yesBlocked by Customer Clarification
SSR-VV-002Backend and IT integration — Verification and ValidationThe supplier shall verify and validate Backend and IT integration per the agreed cybersecurity verification and validation plan.REQ-AUTO-00849; REQ-AUTO-00852; REQ-AUTO-00855; REQ-AUTO-00857yesReady for Customer Alignment

Design Impact

  • Impacted System Features: Application software behavior; Backend and IT integration; Backend and IT integration; Security evidence and traceability; Key management; Secure communication and freshness protection; Backend and IT integration; Security evidence and traceability; System behavior; System behavior; Security evidence and traceability
  • Impacted Interfaces: OEM/Customer Review Interface
  • Impacted Security Capabilities: Key management
  • Impacted Architecture Elements: Application Software; Backend and IT Systems; Backend and IT Systems; OEM/Customer Review Interface; Compliance Process; Security Services; System Core; System Core; OEM/Customer Review Interface
  • Impacted Work Products: Cybersecurity concept; Cybersecurity verification report; DIA / cybersecurity case; Requirement traceability record; System/architecture design
  • Impacted Tools It Hardware Test: High/High/Low; High/Low/Medium; Low/High/Low; Low/High/Medium; Low/Low/Low; Low/Low/Medium; Medium/Low/Medium
  • Impacted Supplier System Requirements: SSR-COM-006; SSR-CON-002; SSR-KEY-001; SSR-SYS-005; SSR-SYS-008; SSR-SYS-009; SSR-TOOL-002; SSR-VV-001 (showing 8 of 9)
  • Design Assumptions Introduced: Security-relevant requirement the ECU can own once responsibility/method is confirmed.
  • Design Decisions Required: Send linked open point to the customer for decision.; Agree responsibility split (DIA) for the non-ECU portion.